HNHacker News
TopNewBestAskShowJobs

bryceneal

306 karma · joined February 10, 2012

submissionscomments
bryceneal··on Solving Factorio Quality
For some reason I never had a problem with the biters on the default difficulty. I got the sense they were there as another ball to juggle rather than a primary antagonist. Simply building turrets around structures was enough to fend them off in the early game until I could proactively destroy their nests in the pollution zone. After I started doing that, they never bothered me again.
bryceneal··on Solving Factorio Quality
I had the exact same experience as you until I finally tried it for a third time. After working through the tutorial I was completely hooked. I had quite a few hours of fun until I decided I was playing too much and had to delete it. I would agree the learning curve is fairly steep. It's not complicated, just dense.
bryceneal··on GLM-5.3: Frontier coding with emergent cyber capabilities
OpenAI seems to understand that these guardrails hurt the good guys. This is why they released Daybreak Blue, which is a step in the right direction (but the model itself is weak as it's just Sol with fewer guardrails). Anthropic seems to believe that harming defenders is worth it if it means they can achieve regulatory capture. They do a lot of mental gymnastics to try to pretend that this is not actually what they are doing. As a result they have lost a lot of customer goodwill, which hasn't yet caught up with them yet, but absolutely will IMO.
bryceneal··on GPT-5.6
I find that 5.5 gives me far fewer refusals than Anthropic models for security and reverse engineering work. I hope the same is true for 5.6.
bryceneal··on Turning music into a chore is how I became a musician (2022)
The stories around how music is made is a very under-considered aspect of the listening experience. Oftentimes those stories are not strictly true, but contain a kernel of truth, and it's the most compelling version of the story that ends up sticking.

How often do you listen to a song and think of these stories in your head? When you listen to the Beatles are you seeing Paul McCartney singing? I think for many people the answer is yes. These things (the story and the music itself) become connected and the story provides the context within which many people enjoy the music.

I'll admit this is a bit disappointing. I'd like to think that any piece could stand up on its on merits without some lore being required to appreciate it. But I have relented to the idea that this is just a very human thing. We do it with everything as it's just the way most of us are wired.

bryceneal··on Anthropic says Alibaba illicitly extracted Claude AI model capabilities
Your take does not reflect the reality on the ground. The Chinese models are censored on a narrow range of political topics which have nothing to do with my work. The weights are open and they can be uncensored/abliterated with little effort.
bryceneal··on Anthropic says Alibaba illicitly extracted Claude AI model capabilities
I have 0 sympathy for Anthropic. Their latest models are extremely censored. The Fable rollout was horrible. Their Cyber Access program criteria denies doxxed Americans doing legitimate security work. Anthropic is hostile to their users and hostile to their own country. OpenAI is considerably better on all of these fronts, but still not perfect.

I'm happy to use and support Chinese model developers if it means less censorship and gatekeeping. I have absolutely no dog in this fight, and neither do most American developers. We will use whatever is cheaper and better. Game on.

bryceneal··on Ask HN: What are you working on? (June 2026)
I understand the problem you're trying to solve. Have you looked into configuring permissions for harnesses like Claude Code? I believe achieving what you want is possible with something like `.claude/settings.json` via something like:

  {
    "permissions": {
      "allow": [
        "Read(**/*.rs)",
        "Edit(**/*.rs)",
        "Write(**/*.rs)"
      ],
      "deny": [
        "Bash",
        "PowerShell"
      ]
    }
  }
bryceneal··on Ask HN: What are you working on? (June 2026)
Big fan here. I've tried lots of them and am currently fairly happily settled on https://github.com/nikitabobko/AeroSpace
bryceneal··on Ask HN: What are you working on? (June 2026)
This is really cool! What has been the biggest unexpected challenge of designing and building a keyboard from scratch?
bryceneal··on Ask HN: What are you working on? (June 2026)
This looks interesting. I thought I would leave this feedback incase it's helpful. There is not enough information about what the experience is like to convince me to sign up. You might consider letting players play around a bit without signing up first.
bryceneal··on Ask HN: What are you working on? (June 2026)
This looks really fun and is right up my alley. It could use some "stones"-style music. :)
bryceneal··on LLMs are eroding my software engineering career and I don't know what to do
One thing that occurs to me about music which makes it different from software or film is that it's a very impulsive art form. A human with semi-modern equipment can write, produce, mix, and master a song in less than a day. They can do this in a way that gives them full creative control over the thousands of tiny conscious and unconscious decisions that ultimately feed into what it is you like (but are probably unable to accurately articulate with words) about a song.

In this case, it's difficult for me to see what exactly is gained by offloading all of those decisions to a mean regression algorithm. I agree it's a fun toy, but I can't imagine actually listening to or deeply enjoying any song made with these music models.

I could imagine it being used successfully in some targeted part of the process. For example, manipulating drums or changing the timbre of some previously recorded instrument. In that case it's not much different than traditional music creation tools like sampling.

bryceneal··on Claude Opus 4.8
I guess Opus makes it impossible to do anything vaguely resembling security research. By chance I stumbled into an ACE for some software I had installed on my local machine after observing a strange crash. I figured I would take the time to investigate (so as to actually deeply understand what was happening myself and avoid throwing yet another hallucinated slop disclosure over the fence if it came to that), but I was completely locked out by Opus. I tried applying to their "Cyber Verification Program", but was effectively instantly denied in a way that was probably automated.

While I understand the risks that Anthropic is dealing with here, I really question whether shutting down any and all security questions in such a paranoid fashion is the right solution. At the end of the day this was a detour for me. Maybe someone special enough to have Anthropic's permission will find and disclose the vuln responsibly. Security Research is not my full-time focus. But this left a nasty taste in my mouth. Not just as a customer who's been paying for Max since launch, but there's something very odd about a model telling me that I'm not allowed to be curious about something. Even if that something is a process running on my own computer.

bryceneal··on Bitcoin miners are losing on every coin produced as difficulty drops
If you're being sincere, there are many easily accessible ways to short Bitcoin with leverage.
bryceneal··on Iran demands Bitcoin fees for ships passing Hormuz during ceasefire
To add more context to what I believe the parent commenter was referring to, the vast majority of USD stablecoins are custodial, meaning the funds can be frozen arbitrarily at any time by the custodian (i.e. Circle).

This is why when cyberthreat actors steal millions in USD stablecoins by hacking a protocol or a large wallet, the very first thing they do is convert those stablecoins to something else.

bryceneal··on Native Instruments enters into insolvency proceedings
I guess I can look forward to all of my plugins breaking in some way in the near future.
bryceneal··on Going immutable on macOS, using Nix-Darwin
I do this too. It's not for everyone. At this point it's easily been positive ROI for me, but that's after about two years now of maintaining my configs through multiple machines and MacOS upgrades.

I would recommend it only if this type of thing naturally interests you. I can't imagine powering through the initial learning curve if it felt like a frustrating chore.

That said, if having (most of) your machine defined declaratively in a git repository sounds exciting/useful/comfy, then I would encourage you to give it a try. You can start small by just configuring a few programs or options and see how you like it.

I wrote more about my experience here where I also link to my configs: https://bryce.is/writing/code/fully-nix-pilled

bryceneal··on Linux DAW: Help Linux musicians to quickly and easily find the tools they need
This is a great list. Even the first line item would be amazing. I'm really feeling this pain presently as I am moving my setup to a new dedicated machine.

Put aside the bit rot that occurs constantly with digital project files in a way it never did with tape, just getting my DAW, plugins, samples, projects working has been a giant pain. I am a big fan of deterministic/reproducible computing environments in general. My primary machine is setup declaratively with Nix. It would be great if something like this existed for my music setup without having to compromise on creative choices.

Most of these plugins are of dubious software quality, but that is not mutually exclusive with their ability to accomplish great sounding results. One of the reasons I bought a dedicated machine for music is that I inherently don't really trust them to be running on the same device as my personal computing. Some of them (Universal Audio Apollo) even require kernel extensions on MacOS.

If anyone is attempting to solve this, I'd like to hear about it.

bryceneal··on Alive internet theory
I agree that "the internet will always be filled with real people: looking for each other". The question is will they be able to successfully find each other, and how can they be sure they have?
bryceneal··on A Word on Omarchy
The author recommends using "Do Not Track", but this has been deprecated for some time. Safari and Firefox have both removed the option completely. Perhaps the author meant GPC?

For all of the security suggestions in this article I was also surprised to see the author recommending ungoogle-chromium, which has a number of security issues. See: https://qua3k.github.io/ungoogled/

The primary issue I take with the article is the chosen tone. I think there are ways that these points could have been made without being overly cynical and negative. I think speaking authoritatively throughout the article has the effect of equating the importance of subjective preferences (like the choice of which terminal emulator to include), with legitimate security concerns (bash shortcomings, migrations, firewall misconfiguration, piping curl | sh to install software).

I wouldn't use Omarchy, but I am glad it exists. It's bringing more people into the desktop Linux ecosystem, which should be positive sum. Omarchy comes off to me as a little hacky and immature, but at this stage that seems.. mostly fine? Perhaps they should be more clear about that in their marketing, but I understand the goals and I admire the enthusiasm from DHH.

bryceneal··on A competitor crippled a $23.5M bootcamp by becoming a Reddit moderator
I suspect the scope and scale of these operations are at least 1-2 orders of magnitude larger than most people think. I also strongly suspect such operations are not limited only to the governments you listed here. If the public was able to quantify the scope then maybe they would be more outraged.

Part of me hopes that some amount of resources are being invested by someone in our government to analyze and assess this, but maybe that is overly optimistic.

bryceneal··on A competitor crippled a $23.5M bootcamp by becoming a Reddit moderator
I'm equally confused at just how bad Reddit is at identifying and removing bad actors to the point that I'm convinced it must be an intentional.

I'm not sure if the reason may be as simple as the desire to pump their user numbers for earnings, or if it's something more egregious than that. It's not clear to me how a company owned by the public which relies on advertisers for revenue has been able to carry on for so long being a propaganda farm for foreign agents and marketing bots.

bryceneal··on User ban controversy reveals Bluesky’s decentralized aspiration isn’t reality
I would disagree with that characterization. There are dozens of NFT marketplaces which all have access to the same underlying data. An NFT is denoted by its address on chain, which is trivial to find. Similarly anyone can create a website that looks like Google, but the "real" google is the DNS entry at "google.com".
bryceneal··on Synology reverses policy banning third-party HDDs
I am in the same boat. I'd prefer something that just works, but I am at the point now that setting something up with TrueNAS seems like it may be worth the effort in the long term.

Also, while I love the convenience of Synology's software, I don't love that it's closed source. Their hardware is also fairly underwhelming for the price tag.

bryceneal··on User ban controversy reveals Bluesky’s decentralized aspiration isn’t reality
OpenSea is very nearly "entirely on-chain" if I'm understanding your point correctly. It's powered by smart contracts. It's not custodial like Coinbase or Robinhood. Users custody their assets in their own wallets. They trade by submitting transactions directly from their wallet to a smart contract address on-chain which facilitates fulfillment of the trade. The code for these smart contracts is open source and verifiable.

It may not be obvious to more casual observers, but there is a lot of trading volume happening on on-chain exchanges these days (as in easily 10B+ in trading volume per day with most of this coming from futures).

bryceneal··on The "Wage Level" Mirage: H-1B proposal could help outsourcers and hurt US talent
In my experience H1-Bs know that the consequence of losing their job could mean being forced to leave the country. Management knows that too. Obviously this affects the incentives and behavior of both the manager and the employee.
bryceneal··on Malicious versions of Nx and some supporting plugins were published
This is also my impression. Containers aren't full-proof. There are ways to escape from them I guess? But surely it's more secure practically than not using them? Your project looks interesting I will take a look.
bryceneal··on Malicious versions of Nx and some supporting plugins were published
This is a huge issue and it's the result of many legacy decisions on the desktop that were made 30+ years ago. Newer operating systems for mobile like iOS really get this right by sandboxing each app and requiring explicit permission from the user for various privileges.

There are solutions on the desktop like Qubes (but it uses virtualization and is slow, also very complex for the average user). There are also user-space solutions like Firejail, bubblewrap, AppArmor, which all have their own quirks and varying levels of compatibility and support. You also have things like OpenSnitch which are helpful only for isolating networking capabilities of programs. One problem is that most users don't want to spend days configuring the capabilities for each program on their system. So any such solution needs profiles for common apps which are constantly maintained and updated.

I'm somewhat surprised that the current state of the world on the desktop is just _so_ bad, but I think the problem at its core is very hard and the financial incentives to solve it are not there.

bryceneal··on U.S. sanctions cloud provider 'Funnull' as top source of 'pig butchering' scams
I believe China's cryptocurrency ban is more about fighting capital flight than scammers. There are restrictions in China on everything from foreign exchange, overseas investments, domestic property, and cross-border payments. They have two separate currencies in part to prevent money from leaving the country.

That said, China is one of the most authoritarian countries in the world. It has some of the most effective controls in place around media, speech, technology, and capital of any country. I'm not sure whether that model could be easily copied, and whether it should be copied is maybe a different conversation altogether.

Page 1 of 3Next →