HNHacker News
TopNewBestAskShowJobs

collinmanderson

2,528 karma · joined September 26, 2014

submissionscomments
collinmanderson··on Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
uv also has --exclude-newer-package which I think can be used for overriding just a certain package.

https://docs.astral.sh/uv/reference/cli/#uv-run--exclude-new... https://docs.astral.sh/uv/reference/settings/#exclude-newer-...

collinmanderson··on So where are all the AI apps?
There are more apps, fewer libraries.

You don't need as many libraries when functionality can be vibe-coded.

You don't need help from the open source community when you have an AI agent.

The apps are probably mostly websites and native apps, not necessarily published to PyPI.

"Show HN" has banned vibe-coded apps because there's been so many.

collinmanderson··on Shall I implement it? No
> "Red/green TDD" is apparently the nomenclature

From your link:

> what "red/green" means: the red phase watches the tests fail, then the green phase confirms that they now pass.

> Every good model understands "red/green TDD" as a shorthand for the much longer "use test driven development, write the tests first, confirm that the tests fail before you implement the change that gets them to pass".

collinmanderson··on Put the zip code first
I agree using the preferred city name works just fine for USPS, though maybe not for UPS/Fedex.

What I want to know is: Why isn't this preferred city+state mapping dataset for zip codes publicly available from USPS? It would be like 40kb of data for the entire thing. Why is this not public domain from the US Government?

Edit: or is this what I'm looking for (the "Physical City", "Physical State" columns? https://postalpro.usps.com/ZIP_Locale_Detail

It's missing 00501 at least (which zippopotam has), and military zip codes (which zippopotam doesn't have). Military zip codes are included in this file: https://postalpro.usps.com/areadist_ZIP5

Also fun fact 88888 is for "Operation Santa" uspsoperationsanta.com, which zippopotam is missing, but appears in the areadist_ZIP5 file.

collinmanderson··on Claude Opus 4.6
I suspect they have generic SVG drawing that they focus on.
collinmanderson··on Microsoft 365 Outage
Yes, this is super annoying.

I keep getting SMTP errors like: 334 VXNlcm5hbWU6 UGFzc3dvcmQ6 Authentication unsuccessful [BL1PR13CA0304.namprd13.prod.outlook.com 2026-01-22T20:59:23.476Z 08DE59C2EA6C3D25]

and: '550 (x.x) [x.x.x.x]:xxxx is currently not permitted to relay through this server. Perhaps you have not logged into the pop/imap server in the last 30 minutes or do not have SMTP Authentication turned on in your email client.'

See also:

https://news.ycombinator.com/edit?id=46725075

https://news.ycombinator.com/item?id=46724812

https://www.reddit.com/r/msp/comments/1qk45c0/microsoft_serv...

https://www.reddit.com/r/sysadmin/comments/1qk3tg7/microsoft...

https://www.reddit.com/r/sysadmin/comments/1qk518l/email_ser...

collinmanderson··on Ask HN: I'm sure more than just Microsoft is down rn
Yes, this is super annoying.

I keep getting SMTP errors like: 334 VXNlcm5hbWU6 UGFzc3dvcmQ6 Authentication unsuccessful [BL1PR13CA0304.namprd13.prod.outlook.com 2026-01-22T20:59:23.476Z 08DE59C2EA6C3D25]

and: '550 (x.x) [x.x.x.x]:xxxx is currently not permitted to relay through this server. Perhaps you have not logged into the pop/imap server in the last 30 minutes or do not have SMTP Authentication turned on in your email client.'

See also:

https://news.ycombinator.com/item?id=46724962

https://news.ycombinator.com/item?id=46724544

https://www.reddit.com/r/msp/comments/1qk45c0/microsoft_serv...

https://www.reddit.com/r/sysadmin/comments/1qk3tg7/microsoft...

https://www.reddit.com/r/sysadmin/comments/1qk518l/email_ser...

collinmanderson··on Service degradation on Microsoft 365 (Business or Enterprise)
Yes. This is super annoying.

I keep getting SMTP errors like: 334 VXNlcm5hbWU6 UGFzc3dvcmQ6 Authentication unsuccessful [BL1PR13CA0304.namprd13.prod.outlook.com 2026-01-22T20:59:23.476Z 08DE59C2EA6C3D25]

and: '550 (x.x) [x.x.x.x]:xxxx is currently not permitted to relay through this server. Perhaps you have not logged into the pop/imap server in the last 30 minutes or do not have SMTP Authentication turned on in your email client.'

See also:

https://news.ycombinator.com/item?id=46724812

https://news.ycombinator.com/item?id=46724544

https://www.reddit.com/r/msp/comments/1qk45c0/microsoft_serv...

https://www.reddit.com/r/sysadmin/comments/1qk3tg7/microsoft...

https://www.reddit.com/r/sysadmin/comments/1qk518l/email_ser...

collinmanderson··on Eat Real Food
> it could not be more unpopular right now to tell people to stop eating meat

If we phrased it from a carbon perspective that would probably help it be more popular, at least for beef which is a huge methane emitter.

https://ourworldindata.org/food-choice-vs-eating-local

https://ourworldindata.org/less-meat-or-sustainable-meat

collinmanderson··on Eat Real Food
Yeah that seems phrased wrong, but here's xkcd visual: https://xkcd.com/1338/
collinmanderson··on Package managers keep using Git as a database, it never works out
Can you rsync a repo from GitHub?
collinmanderson··on Package managers keep using Git as a database, it never works out
I consider apt kinds slow. I wish it were much faster.
collinmanderson··on How uv got so fast
Some issues I noticed were:

> PEP 658 went live on PyPI in May 2023. uv launched in February 2024. uv could be fast because the ecosystem finally had the infrastructure to support it. A tool like uv couldn’t have shipped in 2020. The standards weren’t there yet.

In 2020 you could still have a whole bunch of performance wins before the PEP 658 optimization. There's also the "HTTP range requests" optimization which is the next best thing. (and the uv tool itself is really good with "uv run" and "uv python".)

> What uv drops: Virtual environments required. pip lets you install into system Python by default. uv inverts this, refusing to touch system Python without explicit flags. This removes a whole category of permission checks and safety code.

pip also refuses to touch system Python without explicit flags?

For uv, there are flags that allow it, so it doesn't really "removes a whole category of permission checks and safety code"? uv has "permission checks and safety code" to check if it's system python? I don't think uv has "dropped" anything here.

> Optimizations that don’t need Rust: Python-free resolution. pip needs Python running to do anything.

This seems to me to be implying that python is inherently slow, so yes, this optimization requires a faster language? Or maybe I don't get the full point.

> Where Rust actually matters: No interpreter startup. ... uv is a single static binary with no runtime to initialize.

This one's pretty petty/pedantic, but "Rust technically has a very lightweight runtime." https://users.rust-lang.org/t/does-rust-have-a-runtime/11406...

collinmanderson··on How uv got so fast
Using the -S (“isolated”) flag can maybe cut startup in half.
collinmanderson··on How uv got so fast
> I agree the email module is atrocious in general

Hah. Yes sounds like we are very much on the same page here. Python stdlib could really use a simple generic email/http header parser.

> It's unusual that you actually need to install Python again after initially having "python+dependencies installed".

I’m thinking about 3rd party installers like poetry, pip-tools, pdm, etc, where your installer needs python+dependencies installed before it can start installing.

> “write a pretty fast implementation using python” This is my current main project btw. (No, I don't really care that uv already exists. I'll have to blog about why.)

Do you have anything public yet? I’m totally curious. I started doing this for flake8 and pip back in 2021/2022, but when ruff+uv came along I figured it wasn’t worth my time any more.

collinmanderson··on How uv got so fast
> the conversation here keeps collapsing back to "Rust rewrite good/bad." That feels like cargo-culting the toolchain instead of asking the uncomfortable question: why did it take a greenfield project to give Python the package manager behavior people clearly wanted for the last decade?

I think there's a few things going on here:

- If you're going have a project that's obsessed with speed, you might as well use rust/c/c++/zig/etc to develop the project, otherwise you're always going to have python and the python ecosystem as a speed bottleneck. rust/c/c++/zig ecosystems generally care a lot about speed, so you can use a library and know that it's probably going to be fast.

- For example, the entire python ecosystem generally does not put much emphasis on startup time. I know there's been some recent work here on the interpreter itself, but even modules in the standard library will pre-compile regular expressions at import time, even if they're never used, like the "email" module.

- Because the python ecosystem doesn't generally optimize for speed (especially startup), the slowdowns end up being contagious. If you import a library that doesn't care about startup time, why should your library care about startup time? The same could maybe be said for memory usage.

- The bootstrapping problem is also mostly solved by using a complied language like c/rust/go. If the package manager is written in python (or even node/javascript), you first have to have python+dependencies installed before you can install python and your dependencies. With uv, you copy/install a single binary file which can then install python + dependencies and automatically do the right thing.

- I think it's possible to write a pretty fast implementation using python, but you'd need to "greenfield" it by rewriting all of the dependencies yourself so you can optimize startup time and bootstrapping.

- Also, as the article mentions there are _some_ improvements that have happened in the standards/PEPs that should eventually make they're way into pip, though it probably won't be quite the gamechanger that uv is.

collinmanderson··on We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
If it’s running code outside of a normal browser sandbox then, yes it’s a RCE. Because it can now access to nearly everything on the user’s computer, including their browser, email, etc.

XSS is limited to accessing just that one website.

collinmanderson··on We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
Yes, it's generally a "full account takeover" for a given discord user.

But RCE usually means ability to run any code on the web server, and would generally get you access to _everything_ including full direct access to the database. All accounts and all data, not just a few accounts.

collinmanderson··on We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
with http-only they can't _steal_ the cookie, but they can still _use_ the cookie. It reduces the impact but doesn't fully solve it.
collinmanderson··on We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
with http-only they can't _steal_ the cookie, but they can still _use_ the cookie. It reduces the impact but doesn't fully solve it.
collinmanderson··on We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
Generally code execution within browser/client-side javascript sandbox is just "XSS".

RCE usually implies server-side code execution (or breaking out of browser sandbox).

collinmanderson··on We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
> But you can use an `img` tag (`<img src="evil.svg">`) and that'll basically Just Work

That doesn't help too much if evil.svg is hosted on the same domain (with default "Content-Type: image/svg+xml" header), because attacker can send a direct link to the file.

collinmanderson··on Tell HN: HN was down
Yes. It's hard to explain the experience of hosting a website since 2023.

A crazy amount of really dumb bots loading every url on the website in a full headless browser, with default Chrome user-agent string. All different ip addresses, various countries and ASNs.

These crawlers are completely automated and simply crawl _everything_ and don't care at all if there's value in what they're crawling or if there's duplicate content, etc.

There's no attempt at efficiency, just blindly crawl the entire internet 24/7. Every page load (1 per second or more?) is from a different ip address.

collinmanderson··on Announcing the Beta release of ty
I've always assumed it was something like:

ruff - "RUst Formatter".

ty - "TYpe checker"

uv - "Unified python packaging Versioner"? or "UniVersal python packaging"

collinmanderson··on Announcing the Beta release of ty
Thanks.

I really need better generics support before ty becomes useful. Currently decorators just make all return types unknown. I need something this to work:

    _F = TypeVar("_F", bound=Callable[..., Any])
    def my_decorator(*args: str) -> Callable[[_F], _F]: ...
Also, I use a lot of TypedDicts and there's not much support yet.
collinmanderson··on Microsoft has a problem: lack of demand for its AI products
> worst thing they've shipped since Internet Explorer

IE6 was a really good browser when it shipped in 2001, especially compared to Netscape 6.

The problem was it didn't improve for the next 5 years.

collinmanderson··on It’s time to free JavaScript (2024)
I like it. JSON’s father.
collinmanderson··on Django 6
Yes. I'm still maintaining a Django site that I helped get live in 2007. I started learning Django in 2006.
collinmanderson··on I want to build a chip fab in Canada
> I want to build a chip fab in Canada. Here's the plan:

> We need to raise ~$350 million to purchase a world-class extreme ultraviolet (EUV) lithography machine from ASML. Then, we get the machine installed and can start producing chips for cell phones, laptops, TVs, etc. If you want to join the party, check out the HN thread.

Based on this thread: https://news.ycombinator.com/item?id=46151810

collinmanderson··on The RAM shortage comes for us all
I'll happily invest $100 into this project in exchange for stock. let me know.
← PreviousPage 2 of 32Next →