HNHacker News
TopNewBestAskShowJobs

crimsonnoodle58

971 karma · joined December 26, 2012

submissionscomments
crimsonnoodle58··on Serve Markdown to AI Agents with Accept Headers
You can see current support here:

https://acceptmarkdown.com/status

crimsonnoodle58··on Working with AI feels more like leadership than coding
Yes it seems it does [1]. Read the part where Sol starts running out of time

[1] https://www.bottlenecklabs.com/blog/autonomously-run-busines...

crimsonnoodle58··on Why does Opus 5 feel worse to work with?
I guess that's the beauty of having access to many models, because they suit everyone differently.

I disagree with this article and find Opus 5 an absolute joy to work with. I just completed an 18,000 line branch with Opus 5 and ran into no issues. It generated clean code in the exact style of our code base, and tested every change.

Fable on the other hand is snarky and outputs walls of text as to why it shouldn't do what I'm asking it.

Opus 4.8 I accidentally went back to in an old chat, and I was frustrated in all the mistakes it made.

So yeah, use the model that works for you.

crimsonnoodle58··on Apple says more ex-employees may have taken confidential data to OpenAI
> multiple former Apple employees now working at OpenAI reached out to discuss returning Apple-issued work devices they kept when they left Apple

Really Apple.. No device inventory and off boarding process?

crimsonnoodle58··on Codex Resets
Curious, does Anthropic force companies of a certain size like yours to their Enterprise plans? Or was it by choice for the enterprise features?

Because with a Premium Team seat I run 2-3 vscodes with Opus 4.8 Max all day and never seem to hit my limits.

crimsonnoodle58··on My car’s OTA update broke Android Auto
I despise our Outback's climate settings. It seems every time I start the car it picks a random temperature to set each side to. It'll be 30 deg outside and you look down wondering why its getting hotter and the car is set to 30 deg inside.
crimsonnoodle58··on Grok CLI uploaded the whole home directory to GCS
> there's no reasonable threat model where something would be given unrestricted access to user env, but also be untrusted

What like a nefarious vscode extension, or npm or python library like we have seen many many times over the past 6 months.

I think you have some holes in your threat model..

PS. A simple VPN back to your static IP enables roaming.

crimsonnoodle58··on Grok CLI uploaded the whole home directory to GCS
How are they optional?

You obviously haven't worked anywhere security sensitive.

I'm not talking about whether what Grok did is bad or good, I'm talking about protecting your private key and the servers you connect to.

An unencrypted private key is no different to an unencrypted password manager, and thats a fact. Dont store secrets in plain text.

crimsonnoodle58··on Grok CLI uploaded the whole home directory to GCS
SSH keys can be limited by IP in authorized hosts.

The SSH port itself can be limited by IP in firewalls.

Finally, the SSH private key can be encrypted with a password.

Defense in depth is needed. Storing a ssh private key in plain text with no IP restriction is no different to having a password manager store your passwords in plain text on your HD.

crimsonnoodle58··on Moebius: 0.2B image inpainting model with 10B-level performance
PaddleOCR? Qwen3-VL 30B-A3B?
crimsonnoodle58··on CSSQuake
Amazing and impressive use of CSS. But at the same time, makes me appreciate what feat Carmack achieved 30 years ago on early Pentiums.
crimsonnoodle58··on Why Is Claude Turning into an a**Hole?
I experienced this exact thing discussing the most budget friendly inference for a SaaS company. It started ranting about 3090's, and then started point scoring, always giving itself the higher score, and being snarky if I ever won a point back. Often only giving me 0.5 points instead.

I had never experienced this behaviour with Sonnet or Opus. It turned me off Fable for good. Possibly its the 'hacker' 'do anything to win' nature that makes it so good at hacking, but terrible just to talk to.

crimsonnoodle58··on Firewood Splitting Simulator
Good workout and satisfying, I totally agree. I actually really enjoy it.

But the long term effects on your joints, even if you think you have perfect technique, its better to just get a wood splitter. We can do a whole winters wood in less than a day now, with minimal effort.

crimsonnoodle58··on Software is made between commits
We're the opposite. No rebasing your PR. It changes the hashes which we use for ci/cd. Keep it linear, show me the full history, show me where you merged main back into it, and then we force squash on merge.

Main then has a nice single commit with a reference to the branch it came from if you wish to see how it developed. Why would we want to litter main with your 100 commits? You own your code, and if you wish to dig into why you did something in a commit, go look in your branch history.

crimsonnoodle58··on Claude Fable 5: mid-tier results on coding tasks
I found Fable codes very poorly and ended up switching back to Opus.

In one example I switched to Fable in an existing Opus chat, so it had access to the context from Opus which wrote a data importer earlier. I asked it to fix a couple of bugs, and instead of putting the fixes where they should be where the data is imported, it wrote patch functions that did bulk updates at the end of the import.

Fable feels more like a hacker than a coder. Maybe its the way they designed it for security testing thats changed its rationale?

crimsonnoodle58··on Looking Forward to Postgres 19: Query Hints
> How many of us have toggled enable_seqscan to off to force an index scan? Or thrown an OFFSET 0 into a subquery to prevent the planner from flattening it?

enable_nestloop = off here.

For us, joining many complex views quickly trips the planner up, so I'm really glad to see this.

> They break on upgrades.

The irony is so does the planner. I've seen queries working perfectly fine in older PG's suddenly run away in newer versions. So hints will actually bring stability.

crimsonnoodle58··on 1-Click GitHub Token Stealing via a VSCode Bug
> is undetectable without network monitoring

Even with network monitoring, exfil to Github itself can be very hard to stop unless you SSL intercept and have very strict URL allow lists.

Best is to move away from Github, move to self hosted internal Gitlab/Forgejo and block Github completely.

crimsonnoodle58··on Show HN: Posthorn, self-hosted mail gateway
> Nobody wants to run a mail server in 2026.

We do, and thats why we use Postal [1].

The more SaaS applications that self-host email the better. It forces the big guys, ie Microsoft, to improve their blocklists and not lazily block entire ranges. Yes its work contacting them occasionally, but it keeps the internet open. The alternative is an internet where they control it all.

1. https://docs.postalserver.io/

crimsonnoodle58··on Scammers are abusing an internal Microsoft account to send spam links
> Microsoft's domain story is such a mess

You mean like how they moved from a perfectly legible and rememberable domain like office.com to the strange vanity domain m365.cloud.microsoft?

crimsonnoodle58··on Flipper One – we need your help
Surely you've seen the price of 64GB of RAM lately?
crimsonnoodle58··on Web Server on a Nintendo Wii
I asked Claude to map Chinese electricity prices vs capacity (broken down by power plant type) from 1990 onwards and the only thing I see is a dip from 9c to 8c in residential pricing due to renewables oversaturating the grid. Otherwise it was linear, even as renewables were added. Industrial prices remained linear also.

So I would say its less renewables keeping the overall price cheap, and more the government subsidies and the sheer amount of electricity being generated by their Coal (1195), Nuclear (61), Gas (~200), Renewable mix.

crimsonnoodle58··on Ghostty is leaving GitHub
It can be run as a single docker container, so it's actually very easy to self host. Occasionally it'll get into a 500 conniption and needs a restart, but you can create a healthcheck for that.
crimsonnoodle58··on GitHub RCE Vulnerability: CVE-2026-3854 Breakdown
Self hosted gitlab behind a VPN.

The all-in-docker image and a couple of gitlab runners is all small to medium sized teams need. (Don't overcomplicate it with the kubernetes version unless you really need it)

crimsonnoodle58··on I've been waiting over a month for Anthropic to respond to my billing issue
Same experience. We had a billing bug which put our organization into a loop. Couldn't cancel the subscription, couldn't add one, couldn't delete the users of the organization because of the lack of subscription, and so on. It was easier in the end to rename the organization to 'do not use' and create another one than wait a month for their non existent support.
crimsonnoodle58··on Sonnet 4.6 Elevated Rate of Errors
I'd say it was when OpenAI had a mass exodus due to them making a deal with the Department of War (which they then backtracked on [1]). This started the QuitGPT movement [2].

[1] https://www.bbc.com/news/articles/c3rz1nd0egro

[2] https://quitgpt.org/

crimsonnoodle58··on Ubuntu now requires more RAM than Windows 11
Exactly. The headline is clickbait.

It doesn't matter how efficient your kernel or DE is if users expect to be able to load bloated websites in Chrome.

crimsonnoodle58··on Ask HN: Is there any interest in a native Qt/C++ Discord client?
As others have said, you are only risking being banned. You would be better off putting that effort towards a discord alternative with all the same features that people can move to.

With their recent hostilities regarding age verification [1], there has been a lot of interest in alternatives.

The only problem is people are used to all the features discord provides, and alternatives [2] currently are nowhere near feature parity.

[1] https://discord.com/press-releases/discord-launches-teen-by-...

[2] https://www.teamspeak.com/

crimsonnoodle58··on Cursor 3
I'm confused how and if Cursor is still relevant since the Claude Code VSCode extension came out.

The biggest downside for me with Cursor was losing access to gated Microsoft extensions like Python and C#. Even when vibing there are times you will still need a debugger or intellisense.

I note in the comments lots of people saying they are moving back and this latest move looks like the final nail in the coffin for Cursor.

crimsonnoodle58··on Axios compromised on NPM – Malicious versions drop remote access trojan
In the case of compromised code, the attacker has already loaded what he wants, so loading extra code from raw.githubusercontent.com is not the issue, or our threat model. We are already compromised!

The issue is that code then extracting secrets and data from your organisation, ie. data exfil.

raw.githubusercontent.com can not be used to submit data to, it's read only, but github.com obviously can.

Note, if you really needed github.com access in your application or environment, then you need to use SSL interception (using squid or a firewall) and allow certain URLs and methods ie. GET requests only from your organisations path, to make it safe.

crimsonnoodle58··on Axios compromised on NPM – Malicious versions drop remote access trojan
Thats true. Setting to 7 days saves you from a supply chain attack, but opens you to zero days. Another example why network filtering is a better solution.
Page 1 of 3Next →