HNHacker News
TopNewBestAskShowJobs

csande17

4,518 karma · joined March 23, 2015

Opinions expressed here do not reflect the views of my employer or its customers, partners, or minions. I'm not a lawyer.
submissionscomments
csande17··on We're going to need default hard budget caps on pretty much everything
Simple: when data is added to S3, immediately bill the full cost of storing that data until the end of the month (or fail the upload request if there's not enough quota left). If the data is deleted before the end of the month, refund the remaining storage time.

To prevent cases where users can upload an excessive amount of data on March 31 that they then can't afford the April bill for, AWS should also maintain a "next month's balance" limit that gets handled in the same way.

It would take a bit more work to correctly handle things like ephemeral data and tiered storage classes, but it's not insurmountable.

You could apply the same kind of billing to most other long-lived resources, including VMs that run business-critical services.

csande17··on Gemini ending free use of Flash and Pro models
In the old versions of Alexa and Google Assistant (before LLMs), you could memorize a couple of voice commands that they'd reliably recognize to do a really basic task. If you need an oven timer but you've got meat juice on your hands, you yell, "Alexa, set a 30-minute timer!" If you want to turn your bedroom lights on without fumbling in the dark, you yell, "Hey Google, turn on my lights!". That was, like, the main thing they were sold for.

But then Google changed the default voice assistant on Android to use Gemini. So instead of relying on hard-coded "if the user says this exact phrase, do the thing we said would happen" conditions, people now have to hope the model's smart enough to figure what "turn on my lights" means from first principles every single time.

csande17··on Updates to Full Disk Access in macOS
I think GP was talking about backup apps that run on the iPhone/iPad itself.

It's still possible to back up an iPhone to a jailbroken computer, using roughly the same iTunes sync system that was available on iPods. For now.

csande17··on Zig v0.17.0
He sees the value of using LLMs... only after performing NASA-level verification and fully comprehensive fuzzing using traditional tools. Since Zig has not done those things, LLM-generated bugs are still banned.
csande17··on San Francisco Onion Futures Company
You're not really trading a future, you're just pre-ordering onions.
csande17··on Why I'm still bearish on LLMs after Navier-Stokes
Even if you take that website at face value, the ELO scores shown are relative to the other AI models tested, and not comparable to the ELO scores of humans who play against other humans.
csande17··on Homebrew 7.0.0
FWIW, I also got a bit of an LLM vibe skimming the changelog. In particular, the section about Linux sandboxing jumped out at me:

> Status in 7.0.0: kernels without Landlock continue working without Linux sandboxing in the less secure pre-6.0.0 configuration; brew doctor reports missing protection as an advisory.

> No replacement opt-out; unavailable Landlock remains advisory.

With that being said, I can kind of see why "eliminate all traces of AI writing styles" wouldn't be a goal of the review/editing process. I've been out of the Apple ecosystem for a while, but I imagine Homebrew has enthusiastically adopted LLMs for a lot of tasks. If the public communications reflect that, then people who don't like LLMs can bounce immediately, rather than getting invested in the project and feeling betrayed later.

csande17··on Homebrew 7.0.0
If you say "AI tools", some vibe-coders try to equivocate between tools that generate the whole program for you and, like, an editor that uses an scoring algorithm to decide which method to show at the top of an autocomplete list. But if you say "vibe coding", some vibe-coders try to claim that what they're doing technically isn't vibe coding because they applied some non-zero amount of testing or review during the process.

If you ask "did you build this using Codex or Claude", it removes most of the wiggle room. And it's worded pretty neutrally, so it will often get vibe-coders who aren't technically using either of those tools to say something like, "Actually, I've built a custom harness for DeepSeek..." instead of an outright denial.

csande17··on How Trail of Bits helps verify the integrity of Signal chats
You're absolutely right! Let's delve deeper...
csande17··on Uber is laying off 10% of staff
There were too many meetings, so they got rid of the people whose jobs were to create lots of meetings.
csande17··on Zig: Pointer Stability for ArrayLists
The devlog is the very first place changes get written about when they land in Zig's master branch (and sometimes even before!), so presumably zig.guide will mention this change once it actually makes it into a release.
csande17··on Show HN: Gander, an Android file viewer that asks for no permissions
Yeah, Android's sandbox deals with low-level file access and socket APIs and stuff. But Android also, intentionally, allows apps to expose their data and functionality to other apps via the higher-level "intent" system.

Apps get to choose what permissions are needed to access their intents, so under Android's security model, really it's Chrome's fault (or whatever browser the user has installed) for exposing an intent that allows apps that don't have the INTERNET permission to exfoltrate data.

Similarly, apps are also allowed to collude to share data with each other if they want; that's how stuff like Google Play Services works.

csande17··on VLC for Unity now supported on Linux
Unity includes its own video player implementation ( https://docs.unity3d.com/Manual/Video.html ), so presumably you'd mainly want to use VLC for wider range of supported codecs?
csande17··on Over 400 Linux CVEs published in the last 24 hours alone
https://docs.kernel.org/process/cve.html

> Note, due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel, but the possibility of exploitation is often not evident when the bug is fixed. Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify. This explains the seemingly large number of CVEs that are issued by the Linux kernel team.

(And because this happens during the stable release process, there are a lot of 24-hour periods where they issue a ton of CVEs for all the minor bugs fixed in the release.)

csande17··on The largest available Minecraft world, totalling 15 TB
"Anarchy" in Minecraft means no rules, and "you can't say bad words (or build things containing bad words)" is a rule.
csande17··on Are you telling me a readonly property is wrecking my performance?
The scrollHeight property: https://developer.mozilla.org/en-US/docs/Web/API/Element/scr...
csande17··on What xAI's Grok build CLI sends to xAI: A wire-level analysis
I think there's maybe a disconnect here that people are largely concerned with the contents of their private repos, while you're maybe more familiar with how AI interaction data is handled. (After all, the original topic of the thread was X.ai allegedly going above and beyond interaction data to exfiltrate entire repos.)

I personally did get the vibe that you were being evasive, just because the things you were saying didn't quite match what people were asking about, in a way that felt kind of like a corporate legally-not-a-denial denial. It's like, "Hey, has Contoso Apartments hidden a camera in my bathroom?" "Contoso Apartments is committed to your privacy and safety. We have strict controls in place to ensure that our maintenance staff cannot make a copy of your key without notifying you. To the best of my knowledge, we do not have any company initiative that involves opening envelopes addressed to you." Like it's theoretically reassuring for the company to commit to those things, but the fact that they can't directly answer the original question is disconcerting.

Ultimately there's probably not a whole lot you can do about this. Like realistically if Microsoft is doing this, they've probably constructed it in a way where not many people know and/or they can plausibly deny it. So it comes down to (a) Microsoft denies doing it, but isn't making the broadest legally binding commitment possible, (b) does the reader believe Microsoft and OpenAI are trustworthy with respect to privacy and intellectual property issues or not.

I've been in this kind of situation before, and it can be frustrating when people don't believe that you're in a good, isolated department of the company and you're committed to upholding ethical standards. I guess that's why big companies pay the big bucks :)

csande17··on What xAI's Grok build CLI sends to xAI: A wire-level analysis
(FWIW, in my conspiracy theory, the data sharing would be buried in the part of the company responsible for making sure that people don't upload e.g. CSAM to private repositories, so the Copilot people wouldn't be directly aware of it. I might've edited that in after you already started writing your reply though.)
csande17··on What xAI's Grok build CLI sends to xAI: A wire-level analysis
This is a nice answer to the question "how is GitHub preventing rogue employees at Microsoft from stealing my private repositories?". Like, it's good to know I'm covered if Microsoft accidentally hires a North Korean spy or something.

But if Microsoft really was selling private repo content to OpenAI, it probably wouldn't go through those access controls. It'd be an executive-level decision with enough force to plow through all the red tape, and it'd be implemented as a data pipeline or similar automated process that wouldn't trigger the same kind of notification as, like, a Trust and Safety employee taking manual action.

Probably the better evidence here is in GitHub's ToS where they say in pretty strong/binding terms that they aren't doing this: https://docs.github.com/en/site-policy/github-terms/github-t... . If they are secretly selling your data to OpenAI they haven't left themselves a ton of wiggle room if people ever found out.

(Probably the biggest loophole they could use is to send private repo content to an OpenAI service for scanning/safety purposes. The ToS allows this and they're almost certainly doing it with other services like PhotoDNA. Then OpenAI can just violate whatever agreement they have not to store the data sent to that service.)

csande17··on Train sim created by just one person is being called the best ever made
Unreal Engine's been free for just over 11 years now: https://www.unrealengine.com/blog/ue4-is-free
csande17··on My thoughts on the Bun Rust rewrite
> [T]he Bun project lead can do whatever the hell he wants with his own project. There is no objectively "right" path here, in a moral sense.

I think this is the exact point that the article was getting at in the last section. It is okay to not be very good at software engineering or people management! It is useful to know these things if you want to understand why the Bun project made specific technical decisions, but they don't make the people involved "bad people" in a more nebulous moral sense.

The lead developer of Zig is discussing these factors because the main technical decision was moving away from Zig.

csande17··on My thoughts on the Bun Rust rewrite
Bun's bundler claimed the bottom place in my recent analysis of how JavaScript tools handle generating inline script tags[1], because despite making lofty promises about being able to bundle applications into standalone HTML files, it produced a baffling combination of spurious syntax errors and miscompilations when presented with tricky code.

I'm pretty sure the version I tested was the Zig one (have they made a stable release of the Rust rewrite yet?). So I can definitely see how Bun's move-fast-and-break-things philosophy would have been a poor fit for the Zig community, even prior to the Rust rewrite.

[1] https://carter.sande.duodecima.technology/inline-script-pitf...

csande17··on A bug which affected only left handed users
Scissors are the other big one; most of them are designed so that when to try to use them with your left hand, you end up pushing the blades apart slightly so they don't cut as well (or at all).

With that being said, self-deprecating jokes about how left-handedness is an affront to God are definitely a prominent feature of lefty culture.

(Edit: I guess formal place-setting is another area of society that assumes right-handedness, as well as restaurants that pack people close enough together that everyone needs to use the same hands to avoid elbowing each other.)

csande17··on 98% Isn't Much
It's really easy to serve fallback images to browsers that don't support AVIF, either client-side using the <picture> tag or server-side via the Accept header. Which mostly eliminates the concern from the article, since you don't have to drop support for any customers.

It kind of makes me wonder if anyone has made a build system / framework that serves nested CSS to modern browsers, and falls back to a preprocessed CSS file that removes all the nesting for older browsers.

csande17··on NSA and IETF: Fairness
He makes the legal argument in more detail in https://blog.cr.yp.to/20251004-weakened.html#standards

The gist of it is that standards organizations like the IETF depend on a specific carve-out in US antitrust law (in order for it to be legal for American companies like Cisco and Google to participate in them), and that carve-out includes a specific definition of what "standards organizations" and "consensus" are. So even if the IETF uses different words to describe its processes, those processes still have to comply with the legal definition that separates a "standards organization" from, like, an illegal cartel.

csande17··on If you're a button, you have one job
Maybe I misread the article, but I think the Nothing photos app is literally ignoring the second tap, not just failing to provide feedback
csande17··on If you're a button, you have one job
> Why? How, even, have they implemented this?

This is really common because of two design features that most UI frameworks share:

- The code that changes the color of the button is an internal part of the "button" component, so that people don't have to individually implement it on every button. But this means that it's kind of disconnected from the code that actually performs the action. If the "on click" handler has some last-ditch check that aborts the action, like the "don't rotate the image if it's in the middle of the rotate animation" check from the article, often there's no way for it to tell the button to cancel the color change. (And conversely sometimes the "on click" handler can fire even if the color change animation doesn't play correctly.)

- Buttons usually change color when you press down the mouse button, but only perform the action when you release the mouse button. Sometimes this is used to intentionally give you a chance to cancel the action at the very last minute by dragging your mouse off the button while it's still held down (or, on mobile, to e.g. reinterpret your interaction as scrolling instead of clicking), other times it just creates more opportunities for something to happen that prevents the action from working after the color change has already happened.

csande17··on It's not me, it's the compiler
Rust has a feature called "tuple structs" where the properties of the struct are accessed by numeric indices instead of names: https://doc.rust-lang.org/book/ch05-01-defining-structs.html... / https://doc.rust-lang.org/book/ch05-02-example-structs.html#...

In most other languages this would be written as "this.current_index" or some other property name.

csande17··on If you're a button, you have one job
iOS has an accessibility option called "Ignore Repeats", which seems like a better approach because it's system-wide. So people who need that kind of accommodation can have it in places like the on-screen keyboard too, without needing everyone else to slow down their typing.
csande17··on If you're a button, you have one job
It's not really a question of how many taps they support, but how fast.

This same issue also seems like it would prevent you from quickly double-tapping the button to turn an image upside-down, a much more common use case.

Page 1 of 29Next →