HNHacker News
TopNewBestAskShowJobs

confusedbucket

22 karma · joined July 28, 2026

submissionscomments
confusedbucket··on I Built AI Agents That Ask Companies to Delete Their Data. Most Never Answered
I still vividly remember when GDPR was being implemented. LinkedIn was suddenly filled with GDPR gurus and insightful posts about how impactful the laws are, lawyers were constantly producing new contract templates and forms, companies were sending bulletins informing their users about their updated policies. I had to sign 6 documents related to GDPR when buying a car (we counted it with the dealer).

Developers had it easy, because all they had to do was putting a new page on the website, maybe add a cookie banner when they were at it (it didn't have to do anything besides being an annoyance to the user; lawyers didn't care about the technical aspect since they wouldn't know what a cookie was to begin with).

No client I was contracting for has ever asked about what would it take to actually satisfy the erasure request or whether we only store the data we actually need. Suggesting removal of the data or not collecting them at all and respecting prior consent to marketing campaigns (which the law here actually mandates) were often frowned upon or just ignored.

Outside of the big companies where the fines are likely, GDPR was mostly just a legal excercise from the start. I sent probably like 20 requests over the years (usually as a retaliation to spam), I remember maybe 3 companies acting on them and few more at least unsubscribbing me from their newsletters. One of those companies was a real-estate agency that I contracted for few years later; found my full record in the CRM database with a note saying I'm a dick.

confusedbucket··on I built the fastest PHP webserver in the world
And get rid of all the hardcoded paths, domains, things that only make it work on the specific OS the previous person was using even though there's nothing in the app that would justify it. And then one day, someone introduces Docker, that will make it work everywhere, only now you have to start the containers in some specific order and comprehend some complicated volume setup and it runs 10x slower.
confusedbucket··on I built the fastest PHP webserver in the world
Outside of the prefork mode (which cannot compete even with just FPM/Apache mod), this has a bunch of isolation issues that I don't see mentioned anywhere; namely statics in functions (often seen as a request-lifetime cache in PHP), typed statics without defaults, define(), $_ENV, setlocale(), ignore_user_abort() or mb_internal_encoding() just to name a few. It also assumes all function/class declarations are guarded, so this isn't a drop-in replacement for a webserver that "just works"; for most code, it probably doesn't, so the "unmodified PHP" claim seems like a stretch.

EDIT: After reading through the fairly long README, this is mentioned. So you either use the provided server API to make it fast, or use the CGI mode - even for WP, Laravel or Symfony ("legacy", really?)). It'd be better advertised as a framework, using which is the only way to actually achieve the promised results.

I'm also a bit confused by the webserver code itself; it's PHP 5 code (with all the @class and @private annotations, even) that targets 8.1 (EOL) and yields deprecation notices on PHP 8.2.

The taken approach is interesting, but I'd not put this in front of anything that matters.

If you're this uncomfortable with having to run a webserver, but comfortable with a vibecoded webserver, consider switching to Go, .NET or any other stack where you don't have to fight the PHP's inherent shared-nothing model.

confusedbucket··on Claude Cowork and chat are now one Claude
In the web interface, are there any plans to support attaching local directories through File System Access API and accessing internal (as in, not reachable over Internet) MCPs, assuming correct CORS setup, of course?
confusedbucket··on The Netherlands, Spain push for EU-wide minimum age on social media
> It's not like they can't pass this locally if they want it

It wouldn't be the first time an unpopular or downright malicious law got pushed upstream:

- Data Retention Directive (UK)

- Press publishers' right (Germany, Spain)

- PNR Directive (UK, France)

- Chat control (Spain + few others)

- Mandatory fingerprints on national ID cards (Germany)

Personally, I really struggle to act on this as a voter, because at least in my country, EU works as a retirement home for washed politicans who then go to work with their hand already raised, usually against my interests. Given how widely unpopular some of these laws are, I suspect this might be a widespread issue.

confusedbucket··on “It works better in the app”
If only Google had a UI framework that would let them build apps and target all platforms.
confusedbucket··on Show HN: The load-bearing vocabulary of Claude
I think you are subtly dissing me :)

I was half-joking, of course I could've just asked Claude, but the linked site shows there has been actual recent spikes in the use of the word 'spike'. The term does match what I was recently doing, but hacking around legacy ERP software, blackboxes and other enterprise abominations isn't that out of the ordinary for me.

confusedbucket··on Show HN: The load-bearing vocabulary of Claude
That confirms the recent spike of Claude calling everything I was recently working on a 'spike'. I still don't know what that term is supposed to represent (apparently).
confusedbucket··on Quake Shareware, a CD-ROM just a little too full
COD:BO7's single-player uses dedicated servers. Terrible, yes, but that's as foolproof as it gets when it comes to piracy. They also probably did this to combat all the 'services' offering to unlock camos/cosmetics that you'd normally have to grind for; players would give someone their credentials (probably stolen later and sold to cheaters) and the person on the other side would then use a hacked client to trick the backend into thinking they completed all the challenges. With a server-side campaign, that probably got much more time consuming, I reckon.
confusedbucket··on Firefox for iOS now has a native adblocker
Fair enough and good for you. My point was that currently your only options are either giving up a freedom to run the software you want, or losing utility. In neither case I feel like being in control. The war is over and the users lost.
confusedbucket··on Firefox for iOS now has a native adblocker
Where do I buy this device that does let me run any software I want?

Most Android phones don't even let users unlock the bootloader anymore. And if you do unlock the bootloader, now Google Pay doesn't work, among other things. I don't really feel like being in control of what software I use when the software I actually want refuses to run. F-Droid homepage is also concerning.

Linux phones barely handle the basic functions.

confusedbucket··on Ask HN: Crooked Timber showed showed me a virus captcha, What now?
> Has this happened to you before ?

Almost, recently. I bought a new Mac, needed something reliable to carry around. I never had a Mac or anything from Apple before, so I wasn't familiar with how exactly does it work. I knew homebrew existed, I understood it's similar to Linux/Windows in that not all applications are in the store, but wasn't familiar at all with how those are commonly installed.

Here's what I did:

1. Open Safari, the only browser there was.

2. Typed "claude mac download" in the search bar (needed Cowork).

3. Clicked the first link.

4. Copied the command it told me to, instructing me to run it in terminal.

Only now I realize that there's something fishy about the command; it had base64 payload in it. Didn't run it and took closer look on the page - it was a Claude share (which I quickly scrolled over).

I can admit mistakes, but Google, Apple and Anthropic deserve some blame here, too.

- Google: pushed malware link up top, didn't (distinctly, at least) mark it as a paid result and I'd swear it didn't show me the URL (which I usually always check before clicking, but maybe I just missed it as the search results are rendered differently from Kagi's)

- Safari: hides path by default, so all you see is "claude.ai". Someone probably thought this looked nice, I think it's just borderline idiotic.

- Anthropic: hosts what's essentially a user-content on their main domain.

Also recently saw a few legit projects using base64 in their install one-liners. Please, stop it.

> How do you protect yourself ?

Installed not Safari and made Google not my default search engine, as I always do. That way I at least always know where I am.