HNHacker News
TopNewBestAskShowJobs

berkes

6,099 karma · joined February 24, 2011

Ruby and Rust Developer.

[ my public key: https://keybase.io/berkes; my proof: https://keybase.io/berkes/sigs/uXC3DKS9jat3AILQSm_fIb03uxFV1JSKz8MqCKwzD90 ]

submissionscomments
berkes··on I asked Meta’s Muse for its filesystem and it sent me 6.8GB
Exactly my thought.

If you get access to a VM, it's not a "security vulnerability" if you then have access to that VM. This was the whole point, the product.

It's almost like returning a car after you bought it with the reason "When I open the door with my key, the door is open and anyone can get in".

berkes··on MCP was always a bad idea?
Follow up, because people asked me about it.

The scripts that were generated included code to determine if joplin was running, and to launch it if not. It included a proxy server, that would listen on a localhost:xxxx and if a HTTP request came in, this proxy would auto-launch joplin and then forward the request/response. It then included quite some code to de/serialize json to/from datatypes.

Part of this "overengineering" came from a "skill" that claude found globally which I wrote for myself when working on a few python tools. The skill required strict typing, demanded refactoring, insisted on doing everything over http (and not local commands).

Basically, the agent could not perform its task over an MCP and should've stopped. But I suspect either tuning or some system-prompt made claude go on instead. It decided to use python, and then found my "requirements for when writing python", followed that, and burned a lot of tokens to make one or two HTTP requests.

berkes··on Can gzip be a language model?
I've been pondering on something related: can an LLM be a chat?

Some models are reproducible, in that the same prompt will generate the same output. Say that we could wire up such a model to generate some code.

In that case, we could create a prompt that generates, say, an entire codebase, or a large piece of text. The prompt (or really, the tokens) would then be the compressed version of the codebase or the text.

I am not talking about an "AI agent", but really a model that we call in a reproducible manner. Preferably one call, with one prompt. An agent could just run `git clone` to "decompress" a codebase, which conflates the idea of compression. If that were compression, then the "compressed version of the git kernel" would be a single line of text: `git clone https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin...`. I am really talking about having an LLM re-generate text based on a prompt.

Does that make sense? I can imagine that this is highly impractical and inefficient. But would this count as "compression" at all?

berkes··on MCP was always a bad idea?
Aside from the actual protocol, it makes a lot of sense to have a standardized, discoverable protocol.

Because the alternative, as proposed in the article, is that an agent researches an API/CLI/UI, builds software to interact with it, and then runs that. Every time again. Not only very inefficient, it's unpredictable, and often slow.

Just last week I had an MCP that was down (my mistake) and the agent "decided" that in order to finish my request, it needed to create a python script, refactor that, debug that, and then use that, so it could access my notes (Joplin) over the API and write it's weekly update markdown there. Somehow the thread produced a python tool with over 400 lines of code, five files. It, at some point, even considered putting all that in a git repo. And went on a side-quest to run docker containers.

With the MCP, this job typically takes between $0.05 (Mistral) or $0.90 (Claude Opus). It now cost me $17.00. It took nearly 30 minutes. To write a note in Joplin!

MCPs, or any de-facto standard/pre-known protocol, makes operating on external tools and resources cheaper, faster and above all more predictable.

berkes··on AI-generated posters don’t have to be horrible
Low effort, or low friction?

If I send a single email "subject: poster" "make me a poster for our event, details below, we need 200 printed" that's also low effort. If I do this on fiverr, it's also "unwillingness or inability to spend resources"

> your product or brand.

I think you are conflating a wide audience with a narrow idea. We aren't talking about just the large coorporations, or the popular rockband. There are local bookclubs, a carbootsale, a group of hobby-foo-bars showing their foo-bars at the local pub next month. A concert by "amateurs". Someone looking for an appartment. A cat that got lost.

Do all of these need to show high-effort and/or willingness to spend resources?

berkes··on Spain orders blocks on Archive.today and its mirrors
Misinformation is unfortunately also available. And contrary to "information to build bombs and bioweapons", it's doing actual harm. To societies, economies and above all, to individuals.
berkes··on AI-generated posters don’t have to be horrible
The blog also mentions, several times, that it wasn't the goal to be indistinguishable.

I think it's actually a feature when people can recognize it as AI.

Why would someone want it to be unrecognizable as AI? What is the reason people want to hide AI usage ? (other than when "cheating" in studies or examns or such, obv)

berkes··on Nvidia announces native GPU programming in Rust
The way I understood it, rust would become an option next to Vulkan, WGPU (and opengl etc?).

But only for compute tasks. So, practically an alternative language to write compute shaders in.

berkes··on Mistral X Mozilla: Private, Multilingual AI Browsing
I get that for Mozilla. But what has Mistral done?
berkes··on Apple Reference Image: A New Approach for Verified Photography
Very much agreed.

I believe many of the problems we have, need social and human solutions, especially when the technical solutions are hard or impossible.

Like here, where we can no longer trust images to depict reality and act as proof. While its admirable that people look for technical solutions, the obvious social solution is to admit that images are no longer absolute proof and will become less and less trustworthy¹.

And, by admitting that, change our relation to these artifacts. Sure, that will change journalism, police work, legal systems, etc etc.

But pretending that we can rely on images might allow journalists, police, judges to continue relying on them as if they're authentic, which is a far bigger problem over a longer period.

Social solutions require effort, demand flexibility, take time and are messy. But this is what humans are and do. Not everything has a technical solution. Not every technical solution is the best option.

¹ we already saw this when people claimed "someone must have hacked my iphone and put it there". For decades we've seen this with images that are deliberately taken in a way to spin a story (like the illusion of a large crowd or spacious room through carefull angles or fancy lenses). And I predict we will see this with security footage, "live streams" or even bodycams with "ai enhancement". Just imagine a bodycam or a dashcam that manipulates the output to benefit the owner. "A dashcam that will prove your innocence in assumed traffic violations" or such.

berkes··on Autistici/Inventati's main .org domain goes dark after US terrorism designation
This is much bigger than the banning of a volunteer webhost.

It shows the US government won't go through usual channels when Europeans do things that under european law, are probably¹ allowed.

It shows, again, that US infrastructure is unreliable (in a non-technical sense) and is everywhere.

An Italian bank "sacrificed" their customer because of the risk of losing access to Visa/USD network for international payments. The I in ICANN is not. It is US. Etc.

¹maybe they did break laws. In which case the US would usually ask Italy to deal with it. But either the US government decided this is too much hassle, or they knew Italy wasn't going to help, because under Italian law, everything was fine: we'll never know. But we do know that the US government will reach into European countries to stop NGOs operating there.

berkes··on Play Store blocks AuroraStore, hurting GrapheneOS users
Also, EU is pushing towards more "open" app-stores through anti-trust.

Not that it requires Google to "open up" their play-store, but that they must allow other app-stores to work on the same level. So basically allowing devs and users to move elsewhere.

berkes··on Play Store blocks AuroraStore, hurting GrapheneOS users
What is an "official API"?

Honest question, because AFAIK there's no guarantee or (legal) requirement to support any API. Whether that's fully documented, has SDKs or whether it's something reversed-engineered doesn't matter WRT the support the company owning the API is supposed or required to give.

Or am I wrong there?

berkes··on GIMP Development Update
> most programming languages internal memory representations

Often heard wrt JSON but incorrect. It maps to the primitive types in JavaScript. But almost all programming languages treat floats and integers different, make distinction between char and strings and many have some form of date/time. JSON has neither.

In that direction, XML is much closer since every node is a triple (name, value, attributes) so can have type info, json is a tuple. And Protobuf, while not popular, gets this completely right.

berkes··on GIMP Development Update
So you compress a format that inflates binaries with 30%?

That not only ends up larger than "just the binary", it also eats a lot of extra CPU to (de)compress AND encode-decode.

This idea is novel, but wasteful.

(edit: I thought you were serious, so I answered serious. You were not ;)

berkes··on GIMP Development Update
> Culture is important

Which brings us back to why so many people dislike Gimp, and/or see it as a posterchild example of bad FOSS alternatives.

I agree, and Culture IS important. And I think the culture around many Open Source "Alternatives" is harming themselves and the overall FOSS community. From Mastodon via Gimp to Nextcloud.

berkes··on GIMP Development Update
> with git

I suddenly imagine a zip format with built-in git. Does this already exist?

Basically a file-format that has built-in history, rollback, logs etc. Enabling all these "zipped XML" formats to get this feature "for free".

Could be as simple as adding the .git to the zip and ensuring the software that writes the content to the zip also runs the correct git operations.

But could also be a simplified subset and adding git-ability to the (de)compress libs and bins, which can operate on the compressed .git. Simplified, because it won't need networking/remotes probably not even branches.

berkes··on A physicist rigged his pet hamster’s wheel to upload to Strava
yea. I have some of these dumb ones too. After a few days I found one crawled into the pizza oven to sleep.
berkes··on A physicist rigged his pet hamster’s wheel to upload to Strava
Yes. We used to have these. And i turned it to most conservative twighlight.

It worked most of the times, until in winter, twice, some chickens were locked out. First time I saw it in time. Second time I only found feathers the next morning and one chicken less in the coop.

While on an especially cloudy (snowy) evenings, the door would be open when it was almost pitch dark out there and I caught a fox near already.

"The Real World" is just messier than a mathematical representation can be. I use https://sunclock.net/ and have built a watchface like that for my fitbit like that. The mathematical model is perfect as guidance. But it's not reliable enough to bet the lives of my chickens on it.

berkes··on A physicist rigged his pet hamster’s wheel to upload to Strava
For that you need wifi and/or power. I have neither at the coop.

Most commercial automated doors work on solar + a battery.

berkes··on A physicist rigged his pet hamster’s wheel to upload to Strava
> crepuscular

So not specifically at 5AM, but around twilight. In my area, and for my cats, that changes a lot between summer and winter.

Same for my chickens, which is why "automatic chicken doors" are difficult/impossible around here: It'd need to calculate sunset and sundown, and then also consider clouds and trees: in winter the sun sets around 16:30, but the low angle makes sunlight more blocked by clouds, particles and trees and such. My chickens often decide its bedtime before 16:00 already.

berkes··on Why Book Corners won't sync contributions back to OpenStreetMap
This was international. And it was a long while ago, so I don't have anything online to point to anymore. Sorry.

If "Map Notes clog the map" then there still is something needed in OSM to allow data that's not directly geographical, to be kept up to date, the POI data.

Aside from technicalities: if we want a free, open, etc etc alternative to Google Maps, we need to ensure POI data is of high quality, up to date, and comprehensive.

While it's very useful for many to have all traffic-lights, bike-lanes or waterways mapped, in practice, osmand, maps.me, organic-maps etc etc aren't used when Google maps shows accurate list of Bakeries (or campsites, or anything really) but the OSM-sourced ones don't.

Users, like me, only accept driving to e.g. a campsite that's been closed for over a year a very few times before grabbing Google Maps again. I'll edit OSM in these cases. Open Openingstijden was one of a few experiments where I researched "improving and maintaining POI data".

If we consider the amount of "alternatives to Google Maps" that now don't contribute back to OSM, because of technicalities, legal things etc etc, we miss a lot of good POI data that makes these alternatives viable in areas where Google Maps is the one and only king atm.

berkes··on Why Book Corners won't sync contributions back to OpenStreetMap
> I completely understand that they only want high quality data

I worked on "openopeningstijden", where my aim was to improve the data for businesses in OSM and to disclose that in apis and uis.

There were other reasons why I had to pull the plug, but a big difficulty was the understandable conservatism of OSM. I didn't even want any tagging schemes changed, or the insane dsl for "opening hours" improved, at that time.

All I wanted was to allow obviously "wrong" data to be flagged with a note. Where "wrong" could easily be proven with links to other resources. "The shop is permanently closed. See this url at archive org about their announcement" or "contact details wrong. See their website at url and cross check with BigFoodDeliveryPlatform entry at ..."

Again. Reluctance for such automation is understandable wrt intelectual property rights. It becomes too easy for editors to copy in data that's not allowed.

But the result is that businesses on OSM are poorly represented, often many are missing. That data is hopelessly outdated. And that consumers use proprietary sources and apps to find e.g. a vegetarian restaurant in an unknown city, or to find out if the hairdresser is open at noon.

berkes··on AI in Linux
No, sorry. It's simply not true.

Energy prices, and electricity prices are rising, indexed for inflation. For households and for commerce.

E.g. https://fred.stlouisfed.org/graph/?g=UUeu

berkes··on AI in Linux
> Economies of scale -> more energy = bigger electric plants = cheaper energy.

This isn't true. Certainly not globally. Because electricity in 2026 is converting finite and scares resources. Plants need fuel to burn, water to cool, material to build, land to sit on, etc. Yes, even Nuclear plants¹ need increasingly more scarce resources like "coolant".

What has been bringing electricity prices down is renewables: insane amounts of solar and wind being installed hourly. But even with that, we are still lagging, globally: energy prices are -on average- rising, projects halted or stalled because of lack of electrical capacity and ever increasing amounts of CO2 pumped into the atmosphere. Not less. Not cheaper. Not more supply.

¹ https://www.france24.com/en/france/20260712-france-temporari...

berkes··on AI in Linux
> Pandora's box is open.

And it's not Linux' task to close that, even if it could, which it cannot. How is that disingenuous?

I agree that we should keep discussing the merits and dangers of AI-aided software development. Broad, so indeed also CO2 etc. But that discussion is not something that Linux should push forward. It's a discussion that should take place outside the context of specific projects and in the context of the AI tools and providers, IMO.

berkes··on AI in Linux
Are you a lawyer or an interlectual-property legal expert?

Because if so, please, please elaborate on

> I do not see how AI could be legally used on a GPL project.

Too many people "believe" or "are convinced" about matters with AI and Open Source without any backup or sources.

berkes··on Stop Killing the Internet: No Digital ID and No Age Verification
I'm "berkes" almost everywhere. And my domain is my handle as well: berk.es.

So I do the same as you. But I am quite sure e.g. The Great Musk In All His Wisdom will one day either find me annoying and hand over the now discontinued x.com/berkes to someone who agrees better whith His views. Or decides his politics are better served by raising accounts from the deaths and making some AI voice act like me, that spew political messages.

I own "berkes" about everywhere. But nowhere do I really own it. Not even the domain name. The only handle I truly own is some bc1q....... address. One that has -by design- no reputation and one that's impossible to write in pen on the back of a beermat after a nice discussion in a bar.

berkes··on Stop Killing the Internet: No Digital ID and No Age Verification
My point is that you don't own your handle. Therefore you aren't your handle.

Edit: to clarify: You aren't your handle, because it can be taken away from you, can be injected, blocked, overridden, etc.

My technical rambling then went on about how or when we can make this "handle" decentralized so it cannot be taken away from you. Hard. As proven in practice. Almost impossible.

My name is maintained by a government. It is a "handle" that could be taken away too, but is governed in lots of rules, systems and regulations. My face (an extension of my DNA, I guess) is decentralized and owned by me: its the only handle that afaik no one can take from me.

So in social interactions, you're right: reputation, bound to "me", my face, my DNA is all that matters. But online we don't have this. The closest we can probably get is "my name", controlled by governments.

berkes··on Stop Killing the Internet: No Digital ID and No Age Verification
We've moved "identity" to a few large monopolists. Who lack all incentive to properly "enforce" it. And whose interest are perpendicular to people owning their identities (being able to take them elsewhere).

"Persistent" reputation won't change that. Because on the internet nothing is persistent, without a central party enforcing it to be so. And as said above, the ones in charge of it now, don't want to enforce it really. You don't own your domain, you don't own your IP, you don't own your feeds, "content" etc. The infrastructure that routes people to your correct "reputation", isn't yours, it's controlled and owned by Big Tech, governments, and some smaller companies. Your feed can be taken offline or away from you in a whim. Access to your blog isn't yours. Not even if you host it on a rasberry-pi in your cupboard.

Aside from maybe some blockchain shenanigans, that is. Bitcoin and maybe Ethereum are the only decentralized "pseudonymous" identity providers that could step into this, but both are ridiculously costly and complex. And wholly unsuited to route content. Systems designed for this, like Tor, aren't really up to the task either. Just look at how insanely hard it is for "Content" that governments oppose, to remain online (e.g. on the tor network). Possible, but so complex, so fragile, that it's not a practical system to use en masse. Yet it's the only working system that comes closest to really owning content in the broad sense.

So it makes perfect sense to turn to the systems that have done this "persistent reputation", aka "identity" for centuries now: Governments. Compared to Big Tech, they're more decentralized - there are far more governments worldwide "doing identities" than there are FAANG corporations. Hell, even within the US or within my country alone, there are more. Compared with all other systems, we can control them, push them into a direction we want them to go - democracy. Far from perfect. Bad even. But the least worst way to have some "persistent identity" we can get. Unfortunately.

Page 1 of 34Next →