HNHacker News
TopNewBestAskShowJobs

bangaladore

1,236 karma · joined March 27, 2024

submissionscomments
bangaladore··on Show HN: I built a Cargo-like build tool for C/C++
Yup, I read "— think Cargo, but for C/C++." and closed the tab.
bangaladore··on Our commitment to Windows quality
> Microsofts esteemed moat (office) is “Web only” on the lowest tier.

If you've ever used it before, you'd quickly come to the conclusion that web only Office is only useful for someone writing essays for school.

The moment you need to do anything more complex than that, the document renders completely differently on web vs app-- not to mention there are tons of critical features that aren't even available on the web version.

bangaladore··on CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root
The bigger problem here is it seems like the rust utilities were rushed to be released without extensive testing or security analysis because simply because they are written in rust. And this isn't the first serious flaw because of that.

Doesn't surprise me coming from Canonical though.

At least that's the vibe I'm getting from [1] and definitely [2]

[1] https://cdn2.qualys.com/advisory/2026/03/17/snap-confine-sys... [2] https://bugs.launchpad.net/ubuntu/+source/rust-coreutils/+bu...

bangaladore··on Show HN: Moonshine Open-Weights STT models – higher accuracy than WhisperLargev3
There is a license blurb in the readme.

> This code, apart from the source in core/third-party, is licensed under the MIT License, see LICENSE in this repository.

> The English-language models are also released under the MIT License. Models for other languages are released under the Moonshine Community License, which is a non-commercial license.

> The code in core/third-party is licensed according to the terms of the open source projects it originates from, with details in a LICENSE file in each subfolder.

bangaladore··on We hid backdoors in ~40MB binaries and asked AI + Ghidra to find them
What's the point of posting what is clearly an AI generated comment.
bangaladore··on IronClaw: a Rust-based clawd that runs tools in isolated WASM sandboxes
Afaik Anthropic is not giving pretty much any provider model weights, so any inference of Opus is certainly not private. Either going through Anthropic or Bedrock, or Vertex.

Of the three Bedrock is probably the best for trust, but still not private by any means.

bangaladore··on Deno Sandbox
Another common tell nowadays is the apostrophe type (’ vs ').

I don't know personally how to even type ’ on my keyboard. According to find in chrome, they are both considered the same character, which is interesting.

I suspect some word processors default to one or the other, but it's becoming all too common in places like Reddit and emails.

bangaladore··on Parametric CAD in Rust
> That's the beauty of constraint-based parametric modeling as opposed to, say, modeling in Blender.

I was thinking the same thing. This looks more like an API that makes 3d modeling look closer to CAD, but without realizing that CAD is about constraints, parametrizing, and far more.

bangaladore··on Ask HN: Why can't I apply custom fonts to HN?
CSP is inherently a client-side browser security feature, so yes.
bangaladore··on Shared Claude: A website controlled by the public
That's certainly one of the things to be concerned with. Not certain how that's implemented, but I can still see there being holes in that strategy.
bangaladore··on Shared Claude: A website controlled by the public
True. I suspect they will ban you depending on refusal frequency and severity.
bangaladore··on Claude Code's new hidden feature: Swarms
Very much so. It feels like it can't have been that common in the original training corpus. Probably more common now given that we are training slop generators with slop.
bangaladore··on Shared Claude: A website controlled by the public
More concerned (for the author) of someone trying to host/show illegal material. AI guardrails can only be so effective.
bangaladore··on Show HN: Sweep, Open-weights 1.5B model for next-edit autocomplete
So SFT cost less only low hundreds of dollars? (1-10$ per hour per H100 if I'm seeing this correctly).

What about SFT?

Presumably basing this of Qwen is the reason it can be done for so cheap?

bangaladore··on TPM on embedded systems: Pitfalls and caveats to watch out for
It doesn't help that the TPM spec is so full of optional features (and the N spec versions), so it's often annoying to find out what the vendor even supports without signing an NDA + some.

TPMs work great when you have a mountain of supporting libraries to abstract them from you. Unfortunately, that's often not the case in the embedded world.

bangaladore··on TPM on embedded systems: Pitfalls and caveats to watch out for
In many industries, once someone has physical access to a device, all bets are off. And when used correctly, TPMs can provide tons of value even when not encrypting the bus.
bangaladore··on Eurostar AI vulnerability: When a chatbot goes off the rails
Which is stupid as those are the vulnerabilities worth determining if they exist.

I can understand in a heavily regulated industry (e.g. Medical) that a company couldn't due to liability give you the go ahead to poke into other user's data in attempt to find a vulnerability, but they could always publish a dummy account detail that can be identified with fake data.

Something like:

It is strictly forbidden to probe arbitrary user data. However, if a vulnerability is suspected to allow access to user data, the user with GUID 'xyzw' is permitted to probe.

Now you might say that won't help. The people who want to follow the rules probably will, and the people who don't want to won't anyways.

bangaladore··on Eurostar AI vulnerability: When a chatbot goes off the rails
The best part is if you consider it a vulnerability, it is one you can't fix.

It reminds me of SQL injection techniques where you have to exfiltrate the data using weird data types. Like encoding all emails as dates or numbers using (semi) complex queries.

If the L(L)M has the data, it can provide it back to you, maybe not verbatim, but certainly can in some format.

bangaladore··on Eurostar AI vulnerability: When a chatbot goes off the rails
Is the idea that you'd have to guess the GUID of a future chat? If so that is impossible in practice. And even if you could, what's the outcome? Get someone to miss a train?

Certainly not "clear" based off what was described in this post.

bangaladore··on iOS allows alternative browser engines in Japan
Your "substance" is "trust Apple will enforce something correctly where there isn't a correct answer". I don't agree with that. Apple has a history of interpreting things favorably for themselves and locking 3rd parties from doing the same things for wave hands reasons.

If you are going to make guidelines, make them evaluable. These aren't. If you care about memory safety, either say use a memory safe language or point to an exact reference guide to use to allow XYZ language to satisfy it.

bangaladore··on iOS allows alternative browser engines in Japan
> It’s literally their project and seems to meet their requirements.

This is meaningless. Apple can carve out special exceptions for themselves all day long.

bangaladore··on iOS allows alternative browser engines in Japan
Sorry if I wasn't clear. I meant the WebKit guidelines were from the commenter, not from the apple page.

> or features that improve memory safety within other languages, within the alternative web browser engine at a minimum for all code that processes web content;

This can't be analyzed in any real way, so its just another way that Apple will restrict web engines and claim it was due to "not enough use of memory safety language features"

bangaladore··on iOS allows alternative browser engines in Japan
That's the commenter, not from the Apple page as far as I can tell.

My point is the requirement is too broad. It cannot be meaningfully enforced.

bangaladore··on iOS allows alternative browser engines in Japan
> Use memory-safe programming languages, or features that improve memory safety within other languages, within the alternative web browser engine at a minimum for all code that processes web content;

There is absolutely zero way to satisfy the latter part here. It's at best non-enforceable. If I'm using C++ and use std::span instead of a c-style array, is that good enough?

bangaladore··on Rob Pike goes nuclear over GenAI
My question is why are multiple people commenting that "Rob Pike" in particular should use this feature.
bangaladore··on Rob Pike goes nuclear over GenAI
What do you mean? I did some quick googling and am unsure what you are implying here.
bangaladore··on Rob Pike goes nuclear over GenAI
A platform that allows hiding of text locked behind a login is, in my opinion, garbage. This is done for the same reason Threads blocks all access without a login and mostly twitter to. Its to force account creation, collection of user data and support increased monetization. Any user helping to further that is naive at best.

I have no problem with blocking interaction with a login for obvious reasons, but blocking viewing is completely childish. Whether or not I agree with what they are saying here (which, to be clear I fully agree with the post), it just seems like they only want an echochamber to see their thoughts.

bangaladore··on Rob Pike goes nuclear over GenAI
Must sign in to read? Wow bluesky has already enshittified faster than expected.

(for the record, the downvoters are the same people who would say this to someone who linked a twitter post, they just don't realize that)

bangaladore··on Graphite is joining Cursor
The problem is companies like OpenAI have the upper hand here as they show with the Codex models.

Which is what I was mentioning elsewhere. They build huge models with infinite money and distill them for certain tasks. Cursor doesn't have the funding, nor would it be wise, to try to replicate that.

bangaladore··on Graphite is joining Cursor
As the other commenter stated, I don't use CLIs for development. I use VSCode.

I'm very pro IDE. I've built up an entire collection of VSCode extensions and workflows for programming, building, customizing build & debugging embedded systems within VSCode. But I still prefer CLI based AI (when talking about an agent to the IDE version).

> Composer 1

My bet is their model doesn't realistically compare to any of the frontier models. And even if it did, it would become outdated very quickly.

It seems somewhat clear (at least to me) that economics of scale heavily favor AI model development. Spend billions making massive models that are unusable due to cost and speed and distill their knowledge + fine tune them for stuff like tools. Generalists are better than specialists. You make one big model and produce 5 models that are SOTA in 5 different domains. Cursor can't do that realistically.

Page 1 of 17Next →