HNHacker News
TopNewBestAskShowJobs

ad_fontes

135 karma · joined July 17, 2026

submissionscomments
ad_fontes··on Court agrees with EFF: Utah's VPN law demands a technical impossibility
Depends on how you define "reliably". You can get pretty damn close by triangulating on traffic patterns and browser fingerprinting. There is a lot of research in this area. But it'll never be perfect.
ad_fontes··on Automatic Transmission – a data-privacy study of connected vehicles
IIRC, they don't have a cellular radio in the vehicle (or even a FM radio). All the connectivity is done via Bluetooth with a mobile app.

It's been a while since I read up on them and things might have changed, but I have a lot respect for what they're doing. Full embracing right to repair and customer privacy when the entire industry is moving at lightning speed in the opposite direction.

ad_fontes··on Automatic Transmission – a data-privacy study of connected vehicles
You might want to check out Slate. It's about the closest thing to an open vehicle platform I can imagine.
ad_fontes··on Pi 1.0
Can you explain your workflow a bit please? Do any of these tools work with Claude/Codex subscriptions or are they API only?

I actually built my own tool that maintains a work graph (DAG-like) with task leases. It allows me to copy and paste pre-written prompts into Claude Code, Codex, or OpenCode and all the agents self-coordinate through MCP calls.

I built this after trying hermes and Openclaw but not liking the lack of human-in-the-loop judgement. So I'm wondering if I should keep refining my tool, or evaluate something like pi?

ad_fontes··on MicroLLM Lab – Try 7 tiny LLM's in the browser
Same issue. Latest version of Firefox 156.0 on Ubuntu GNOME. AMD Radeon 860M.

Unticking the WebGPU checkbox and reloading didn't do anything.

ad_fontes··on Parley: Federated, decentralised chat that speaks plain IRC
This is pretty much just a reinvented Matrix protocol. Nearly identical.
ad_fontes··on Fifteen years later, the Apple Cards origin story
Assuming that is an actual Jobs quote, it's pretty on-brand for him. Carpenters don't make furniture.

That's typical executive lack of awareness of the skills and roles of the little people charged with fulfilling their grand vision.

ad_fontes··on AI coding has made CI a bottleneck, so we reworked ours to keep up
Man, what a weird thing to complain about.

Most days I feel like I must be the dumbest person on HN. I don't understand what 80%+ of submissions are about. But if it sounds interesting, I'll dig into it a bit and learn a few things along the way.

ad_fontes··on Show HN: Share your AI Setup, Learn from others
Yeah, there is... Post your tooling to GitHub and link to it with a human-written description in a place like HN or Reddit.

I don't know why this has to be reinvented?

ad_fontes··on Debian votes to allow "responsible use of generative AI"
> it's still your code

I wholly agree with your comment, but is it legally "your code"? Copyright is implicit at the moment of human creation. But there isn't yet settled law on AI-assisted creation.

So it might be a problem for projects to accept contributions where it's not clear who actually owns that work.

ad_fontes··on I used AWS cognito for a startup. I wouldn't do it again
Not really. The term is a shortened version of "sucks eggs", which is originally from Shakespeare and used to describe an odious creature or habit (a weasel in Shakespeare's case).
ad_fontes··on I Used AWS Cognito for a Startup. I Wouldn't Do It Again
Asking as someone who's only every rolled his own or used Cognito: What's the problem with Auth0?
ad_fontes··on I used AWS cognito for a startup. I wouldn't do it again
Auth is a bit of a different beast when it comes to the build vs buy debate though. A competent auth provider has the infrastructure (and necessary data) to deflect against DDoS attacks, bots, etc.
ad_fontes··on The Vibe Tax
You're correct. A consuming application doesn't have anything to do with Reg Z. However, the regulations do dictate the behavior or interface that I can expect from banks, almost like an API contract. It might make more sense if I explain the incident that caused me to add it:

My wife intentionally overpaid on a credit card statement balance in order to gain some credit limit headroom in the current month. Using made up numbers: The balance said we owed $1,000, but she paid $2,000 to make room for a big purchase that month. My application rejected that overpayment as a data integrity error because it would have pushed the credit card balance to -$1,000.

This is a valid state though and Reg Z actually specifies the rules around that case. A bank has to refund a positive balance upon request or automatically after X number of days (I forget the amount).

So now, anytime my agents touch any code associated with credit instruments, they have to run a Reg Z audit to ensure that the data model reflects how banks actually operate in the real world.

ad_fontes··on Disruption with Some GitHub Services
> Update - We've identified an issue with a database primary and are failing over to a replica immediately

Seems like a weird thing to post on a status page. Shouldn't this have happened automatically and therefore precluded the need to inform users of it?

ad_fontes··on Show HN: A techno machine in one HTML file, with verifiable renders
This is the coolest web thing I've seen this month. Thanks for sharing.
ad_fontes··on The Vibe Tax
Already posted above. And I wish I had thought of your gist idea before posting it.
ad_fontes··on The Vibe Tax
Because it's complex and I'm stuffing 30-50 PRs a day through it. 7 GHA workflows across four self-hosted runners.

I'm on my third iteration, after constantly log jamming previous versions. Most steps aren't "run pytest", they're gates that guard against an LLM's bias to continuously add more and more complexity to a system.

I'm aware of the irony of having a complex system to mitigate complexity, but the key difference is these rules bound complexity growth. If you're legitimately interested in the details, let me know. I'm too tired to write up much more but would be willing to drop in a LLM-authored summary of the details.

ad_fontes··on The Vibe Tax
Not satire. But I can understand why my comment seemed contradictory.

I've been designing software for a long time, but I'm nowhere near as good as most career SDEs I know (my career path has been SDE-adjacent). So it's not like I sat down and independently told various LLMs how to build out all these guardrails. I make high level architecture decisions and nudge them in the right direction ("use RabbitMQ", "trunk-based branching, not gitflow", etc).

A lot of this stuff evolved piecemeal and organically. But at no point was a churning out garbage and I never had a runaway agent completely derail the project (or my budget). But, thinking about it more, I guess there are some things I might have done differently than most people:

- I started with documentation: user interview --> user stories --> functional spec --> frozen design contract. These were all done before I wrote any code.

- I specified the tech stack and the architecture in broad strokes, rather than let the LLMs make that decision. I went with boring choices because that's what I know best: Flask/Jinja, Alpine.js, Postgres.

- I've constantly gone back and refactored accumulated tech debt and have added hard CI gates for things like cyclomatic complexity, ensuring that docs don't drift from the underlying code, and an "apparatus ledger" that keeps track of all the rules and constraints that keep getting added.

- I make sure that each session proves that it's tests can fail before shipping a PR, so it's not writing meaningless tests.

Maybe I'm underestimating how impactful all those things add up to shape the behavior of the LLM agents? Because individually, I wouldn't expect them to have saved my from nearly all the AI pitfalls I read about.

ad_fontes··on The Vibe Tax
My wife was a diehard YNAB user before we met but it went by the wayside once we merged finances. She wanted to get back to better managing our money and started using Google Sheets and then got stuck. She asked me for help trying to create a pivot table and like any good engineer, I built her an entirely new application instead.

In my defense though, it does way more than a spreadsheet. Stuff like OCRing screenshots of bank transactions with a specialized, locally-hosted LLM to avoid data harvesters like Plaid. This became an entirely separate subsystem with verification, automated model benchmarking, prompt provenance, etc.

You'd be surprised at how quickly edge cases start to pile up when an accounting system makes contact with the real world. (If you buy something on a credit card and then return it after your statement closes but before your payment is due, do you still owe a minimum payment based on that purchase? Well... depends on your bank. Capital One and Chase: yes, US Bank: no.)

> Just how much functionality are you getting out of that?

I'm still dogfooding it. It's a pretty opinionated app that has things a month-end closing ceremony, reconciliation processes, envelope-based budgeting cycles. So unfortunately my feedback cycle is largely locked to the calendar. But my wife absolutely loves it so far.

ad_fontes··on The Vibe Tax
I feel like I'm living in a parallel universe when I read these types of posts.

My agents have never created code that is straight-up garbage and I have never flushed a week's worth of tokens down the toilet. I just can't identify with all the constant complaints about AI-assisted coding.

And my biggest project isn't some hello world app. It's a self-hosted, privacy-focused personal financial management application that I intend to open source. It's about 126k LOC against 240k LOC of regression tests and 30k LOC of CI/CD pipeline. I'm doing 24x7 mutation testing on a dedicated box against the accounting engine and temporal systems. I even have specialized agents doing audits against Regulation Z (US banking law) criteria so the app models the required behavior of banks.

Most of my complaints about everything are nits, like the overly verbose and dense way LLMs communicate with me. Or their predisposition to add, add, and add more stuff when proper engineering practices are more often about subtraction (but I've built mitigation guardrails against a lot of that).

ad_fontes··on A website for debloated open source alternatives
I like Tailscale, but it's difficult to argue with a straight face that it's not seriously suffered from product creep.

This is the inherent problem with tech start-ups. Once they solve the problem they were founded to solve, then what? It's feature complete, but investors insist that the line must go up. Can you imagine if `sed` or `vim` was brought to market by a venture-backed company?

IMHO, capitalism and FOSS are fundamentally incompatible.

ad_fontes··on A website for debloated open source alternatives
How do you define "AI generated slop"?

There's also an implicit judgment in your question. Is well-designed, well-tested AI-generated code worse than poorly written, but hand-typed code?

ad_fontes··on Browser De-Slop
It's an intellectually lazy "No true Scotsman." I personally clicked away from the page as soon as I read that line because the author lost my trust in that moment.
ad_fontes··on Cursor launches Origin, GitHub alternative
Well, shit. I guess it's back to Slashdot then.
ad_fontes··on Incident with Github.com [resolved]
https://mrshu.github.io/github-statuses/

They're struggling to maintain a single nine these days.

ad_fontes··on 2,085 Tests, and None of Them Opens the Front Door
That doesn't really sound like an indictment of unit tests. I don't really understand why someone would meticulously write a bunch of unit tests and then wait to prove them on a production deploy?

Unit and integration tests serve different purposes and one isn't necessarily better than the other.

ad_fontes··on Mistral OCR 4.1
I've been experimenting with using NuExtract this week on locally OCRing bank statements that don't have a predefined document structure. It's way better than Tesseract or a generic vision-enabled model. It runs great on a single RTX 4090 at the modest throughput I need.

Their hosted, API-based service is something like a third of the cost of this model.