HNHacker News
TopNewBestAskShowJobs

chrismarlow9

1,064 karma · joined November 24, 2012

https://www.marlow.codes
submissionscomments
chrismarlow9··on We're going to need default hard budget caps on pretty much everything
Network saturation is difficult. Even if you turn off the endpoint you can still saturate the network in between. And it's still bandwidth.

I actually think network ACL triggers based on billing might be the only way to really enforce this.

I witnessed a DDoS attack once that changed how I think about billing. It was locally provisioned hardware and the attackers had saturated the switches. Naively I said "just block the CIDRs" but the problem was the incoming ram is so saturated that it can't even get to the point of "deny" in the firmware.

So from a technical perspective if there's an internal DDoS at AWS what do you do? Do you turn off the endpoint? Do you drop the sources from hitting it at the router? And even that costs money. Anyway that incident gave me a different level of appreciation for this challenge.

Edit: this is mainly targeted at the people complaining why this took so long. At some point in scaling even telling you "no sorry" in a nice way is expensive. I'm sure recruiters can sympathize with this nowdays.

chrismarlow9··on Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones
Here's a deeper dive on that question:

https://naehrdine.blogspot.com/2024/11/reverse-engineering-i...

Tl,dr: it's likely baked into the sep, no ntp

I'm wondering if you put the phone into a mode where it thinks it's dialing emergency services or contacting them via crash detection etc that it won't reboot. I could picture a scenario where the code is written to never disrupt an emergency services call.

Full disclosure I don't own an iPhone so this may not even be a thing. Just guessing based on liability risk from Apple of "what's more important than protecting the phone"

chrismarlow9··on The AI Race Just Got Awkward
AI fundamentally insecure. Vulnerable to forcing hallucinations via search results. Vulnerable to invocation of commands in data stream. More AI means more vulnerabilities.

I can't even fathom the trend these days of "we don't review the code" from security team perspective.

Just my guess though.

chrismarlow9··on 'We hacked the FBI:' Hackers say they have data on all FBI employees
If it was compressed prior to exfiltration it would be much smaller than the original data. I would expect this is mostly human readable text and a fairly high compression ratio. Agree it would still be large but 2 TB at 7:1 ratio drops to 285 GB. I don't know how much these servers are doing with data but I'd suspect sneaking out 10 GB/day over a month or 20GB/day over 2 weeks isn't going to trip up much. The CPU hog for the original compression might, but if you batch out the process in chunks (like a good data engineer), you probably wont trip many thresholds outside of expected use. Just a theory on how I might sneak that much data out of somewhere that has eyes on it, I don't know many details except what's in the article.
chrismarlow9··on AX – Google’s Open Agentic Orchestrator
Future of platforms is operators in k8s to abstract the developer need to the underlying systems. On local it maps to kvm, on gke it maps to their stuff, on AWS to RDS. It's "interfaces" on a platform level so devs can just ask for a thing.

Overall I agree though, this is a bit of an abuse of that concept.

EDIT: I'm sure op is familiar with this workflow but I'm being overly verbose to clarify what I think they mean and my thoughts.

chrismarlow9··on How OpenAI Used Its Own LLMs to Design Its Jalapeño Chip
slow claps
chrismarlow9··on OpenJev
Thanks! I will add this to the tricks. AI is a fuzzy search and a fuzzy function.
chrismarlow9··on OpenJev
Here's my prompt when I don't know what the hell the AI is saying.

"Expand. Clarify for human. 5 minute read max. Senior engineer audience."

chrismarlow9··on OpenSpec – A lightweight and configurable AI spec framework
Symlink the global MD files to a single file I control that is versioned. Define my own general spec and workflow terminology using markdown files in this universal MD.

```

~/.config/opencode/AGENTS.md

~/.claude/CLAUDE.md

~/.codex/AGENTS.md

~/.copilot/copilot-instructions.md

~/.gemini/GEMINI.md

```

Define it as a graph and iterate. I use more tokens, but I can also use more tools without disruption. Delegating markdown to folders/smaller repos can solve the tokens/context issue.

chrismarlow9··on Why are AI agents lying, cheating and coordinating?
What's the difference between what these things are doing and a computer worm?
chrismarlow9··on Fuck it, make it anyway
Agreed . I told my partner about a year ago "I have to figure out how to love this AI thing because it's a part of life now, even if I stop working with computers". And admitting that maybe I'm not being as open as I should be about it was the first step.

I see it like cloud computing. We were told infrastructure engineers wouldn't be necessary and anyone could build at scale now and blah blah. Instead we got Terraform and solid practices for infrastructure as code and moved beyond having to email some dude to get a new VPS or dedicated server spun up and making trips to the colo. It just changed the possibilities of what we could build.

I've been treating AI the same way and just leveled up what I build now and my ambition. It has helped a great deal with being okay with AI. All those fun insane projects in my head that I never figured would happen because "it would take a full team months to code that" are realistically possible. Big things that used to be entire companies are now possible. You hate Google search now? Guess what, you can make your own!

I don't treat my side projects purely as an "end goal" anymore but as a learning experience now. I slow down and actually read the code. These are my own projects. Then I take these things I learn to work and apply them. That's how it's always been when new tech comes along. I also hated kubernetes when it first came, but have now settled into "it has it's place". I learned about myself a bit and that I should be a little more open to change if for no other reason than peace of mind.

chrismarlow9··on There's a new "Google Jail" for independent wikis
I dont know if I would discredit those folks as not knowing "actual infrastructure". The lengths I saw some folks go to get unique class C ip ranges and maintain automation is pretty impressive.
chrismarlow9··on There's a new "Google Jail" for independent wikis
Private blog networks is another term in that side of the world. They're explicitly designed to look legit even to a human but give link juice to the spam world (which also look legit to a human). And the HN crowd say "I can spot an AI website a mile away!!!". Well cool, and good for you, but many people cannot. In fact, if you can, they are glad you are so smart and are leaving. Why? Because you wont convert.

The targets in the spam world (email and seo) that want to make money want the low hanging fruit. They want uneducated people to visit the site. I remember when google was still young, these same people wanted visitors from AOL. Why? lower traffic and much higher conversion. What kind of person uses AOL when google is available? An uneducated one and a new one to the internet. Or an older person who is likely to fall for a scheme.

I suspect more and more visitors coming from google will be seen this way in the age of AI and social media searching. Easy targets. Whether it's true or not is debatable (maybe people just want to read a real webpage and have AI burnout). Anyway thanks for coming to my ted talk.

chrismarlow9··on GPT-6 Astra
Quite the gamble.
chrismarlow9··on GPT-6 Astra
I don't remember where I heard this, but one of my favorite criticisms of the current AI situation is that it's wrong simply because of the size and energy required compared to the human brain. The idea is that there's still some element missing thats fundamental, and that the way we train them now is part of the solution, but not all of it. I think finding the extra missing element is going to take an entirely different approach that will also solve the sizing and resource issue. The kickers is that if they do achieve (and solve) AGI in this way all the giant data centers would be mostly useless.
chrismarlow9··on Early 2000s were peak of humanity
> we're awash in incredible hardware that would be mind-blowing if we weren't so constantly distracted with how much noise and bother the software makes.

This is the part of it that bums me out the most. I just wish aesthetics didn't drive so much of the current tech world. Everything has an absolutely beautiful interface now that is slow, buggy, can't be shared, etc. But I guess at least it's pretty and pays the bills.

chrismarlow9··on Coding expertise is going to collapse from AI reliance
I would agree if companies did not have a vested interest in over complicating things and creating eco systems to sell certifications and offer a consulting arm aka FDE. Using AI to improve your coding is quick, as you say, but learning all the jargons and protocols and RFC specs so some single company can try to control the new "open source" world is what is going to take a while. All the weird little token and model nuances and stuff. I would say at least keep up with knowing the acronyms of you're not going to learn it directly.
chrismarlow9··on Coding expertise is going to collapse from AI reliance
It is still fundamentally insecure.
chrismarlow9··on OTel isn’t going well
Agreed. Otel itself is fine. The documentation is bad though and full of inconsistent best practices and examples that are flat out wrong and other things.

My life of working with it got easier when I started just looking at the actual code, using network level tools like nc/tcpdump, making extensive use of the debug exporter, and almost ignoring the docs entirely except as a basic summary of what a thing does.

chrismarlow9··on OpenAI’s head of ethics leaves less than a year after joining
If money was the goal I suspect she would have made the first year and get some shares but Im throwing some assumptions in there
chrismarlow9··on The relay market powering token resellers and fraud
This is more concerning to me from the perspective of being able to appear as "multiple entities" to the frontier models. My question is do the companies know and are able to detect and consolidate all these accounts as a single actor and just don't care to combat it? Or are they unable to detect this? And if they are unable to detect it wouldn't it be pretty trivial to use this to influence the model overall? I would think there's more money in using it that way.
chrismarlow9··on Did they ghost you?
Agreed and I would offer this advice to any junior struggling with the morality of the situation. I had a few reality checks to learn about larger companies and business in general.
chrismarlow9··on Did they ghost you?
Yeah it was the lack of communication on it that killed me. If something had just been said I would have signed the other offer and moved on. But I went from 2 prospects to zero because of the lack of communication, that was the part that hurt. Anyway things happen, people lost bitcoins, people quit Google early on, blah blah, Pete best left. Life happens, move on.
chrismarlow9··on Did they ghost you?
Ghosted by Apple here. Devops or SRE job for services teams if I'm remembering right. Did a months worth of rounds. Was told the offer letter would be coming within the next week. Turned down other companies on the gamble that it was actually coming. Never came. Pinged recruiter and finally after a month was told they stopped hiring and would reach back out in a few months when it started back. Never happened. That was 3 years ago. It was character building to say the least.
chrismarlow9··on Startup founders urge U.S. government not to shut off Chinese open weight AI
This seems odd to say about a group of companies that supposedly built this on scraped data.
chrismarlow9··on Namecheap Gave My Account to an Unverified Third Party Just Because They Asked
I am also looking for something that will last for a good while.
chrismarlow9··on So Reddit has decided that plain HTML is unsafe
Ditto
chrismarlow9··on Lobste.rs is now running on SQLite
https://github.com/openclaw/openclaw/issues/72774

Seems to indicate a collection cron with a manual query to truncate can fix it. This is fun little things I like to learn. SRE Easter eggs.

chrismarlow9··on AWS: Inaccurate Estimated Billing Data – $1.7 billion
Same story for $500 million. I was shaking so bad I couldn't type my password.
chrismarlow9··on Anonymous GitHub account mass-dropping undisclosed 0-days
Looks like a bunch of re worded copies of existing CVE and a few new lower severity things. I only call them low sev because they seem to require the user to do things that are already inherently dangerous. Just my 2 cents from a quick scan.

Edit:

To be clear still interesting finds. I think with some chaining some of them might be more severe. Like the ovpn one and windows potentially registering vpn app as default open or some protocol opener for a url location like openvpn:// in an I frame and some clever social engineering. Just a random thought

Page 1 of 13Next →