HNHacker News
TopNewBestAskShowJobs

diggan

24,763 karma · joined March 2, 2012

https://notes.victor.earth

https://bsky.app/profile/victor.earth

hn@victor.earth

aspe:keyoxide.org:Q6B7ZBQITV7IE2RG4EMVKWT4VI

submissionscomments
diggan··on Social media promised connection, but it has delivered exhaustion
> It seems like paid communities

Yeah, I've been sadly thinking about similar things. Something like a web-forum where it costs $1 to signup, and your account gets active after a day. Would serve as an automatic "You're 18" since regulations around that seems to be creeping up, and would hopefully lower the amount of abuse as people have to spend actual money to get an account.

It just sucks because there are plenty of sub-18 year old folks who are amazing and more grown up than people above 18, not everyone who has access to making internet payments and also not everyone has the means to even spend $1 on something non-essential.

Not sure if there is anything in-between "completely open and abuse-friendly" and "closed castle for section of the world population" that reduces the abuse but allow most humans on the planet.

diggan··on How to use Claude Code subagents to parallelize development
> Humans have strategies for refactoring, e.g. "I'm going to start from the top of the file and Cut code that needs to be moved and Paste it in the new location". LLM don't have a clipboard (yet!) so they can't do this.

For my own agent I have a `move_file` and `copy_file` tool with two args each, that at least GPT-OSS seems to be able to use whenever it suits, like for moving stuff around. I've seen it use it as part of refactoring as well, moving a file to one location, copying that to another, the trim both of them but different trims, seems to have worked OK.

If the agent has access to `exec_shell` or similar, I'm sure you could add `Use mv and cp if you need to move or copy files` to the system prompt to get it to use that instead, probably would work in Claude Code as well.

diggan··on Humanely dealing with humungus crawlers
> but it’s my domain and my server and I get to say “no thank you” to your visit if you don’t behave [...] Blocking misbehaving IP addresses isn’t new

Absolutely, I agree that of course people are free to block whatever they want, misbehaving or not. Guess I'm just trying to figure out what sort of "collateral damage" people are OK with when putting up content on the public internet but want it to be selectively available.

> You have no innate right to access the content I share.

No, I guess that's true, I don't have any "rights" to do so. But I am gonna assume that if whatever you host is available without any authentication, protection or similar, you're fine with me viewing that. I'm not saying you should be fine with 1000s of requests per second, but since you made it public in the first place by sharing it, you kind of implicitly agreed for others to view it.

diggan··on Humanely dealing with humungus crawlers
> You're on one persons property to access other people's stuff who pay to be there.

I see it more like I'm knocking on people's doors (issuing GET requests with my web browser) and people open their door for me (the server responds with something) or not. If you don't wanna open the door, fine you do you, but if you do open the door, I'm gonna assume it was on purpose as I'm not trying to be malicious, I'm just a user with a browser.

> AI bots have been asked to leave. But, since they own the mall too, the store owners are more than a little screwed.

I don't understand what you mean with this, what is the mall here, are you're saying that people have websites hosted at OpenAI et al? I'm not sure how the "mall owner" and the people running the AI bots are the same owners.

diggan··on Humanely dealing with humungus crawlers
> No. Access to my content is a privilege I grant you.

Right, I thought the conversation was about public websites on the public internet, but I think you're talking about this in the context of a private website now? I understand keeping tighter controls if you're dealing with private content you want accessible via the internet for others but not the public.

diggan··on Crates.io phishing attempt
> But a CVV must still actually be useful to some fraction of your real customers, and likewise the expiry date.

The CVV code of this card changes once every 10 minutes, so I understand them not printing that. Yet yeah, could have put the card number there with the dates, but I guess if the CVV already cannot be printed, why not just avoid all of it?

Regardless, doesn't really matter much anyways as I don't think I've used a proper card for months, everything around me supports NFC mobile payments since years back.

diggan··on Humanely dealing with humungus crawlers
> There are lots of providers where I can buy a VPS somewhere and be in charge of configuring and patching it, but if I just want to hand someone a set of HTML files and some money in exchange for hosting, not many hosts fit the bill.

Yeah, that's true, there isn't a lot of "I give you money and HTML, you host it" services out there, surprisingly. Probably the most mature, cheapest and most reliable one today would be good ol' neocities.org (run by HN user kyledrake) which basically gives you 3TB/month for $5, pretty good deal :)

Sometimes when I miss StumbleUpon I go to https://neocities.org/browse?sort_by=random which gives a fun little glimpse of the hobby/curiosity/creative web.

diggan··on Humanely dealing with humungus crawlers
How do you know that that bot is part of those AI companies? Maybe it's my personal bot you're blocking, should I also not have (indirectly) access to the content?
diggan··on Crates.io phishing attempt
That is the backside :) The front just have graphics and no text at all.
diggan··on VaultGemma: The most capable differentially private LLM
The actual weights: https://huggingface.co/google/vaultgemma-1b

> VaultGemma is a variant of the Gemma family of lightweight, state-of-the-art open models from Google. It is pre-trained from the ground up using Differential Privacy (DP). This provides strong, mathematically-backed privacy guarantees for its training data, limiting the extent to which the model's outputs can reveal information about any single training example.

> VaultGemma was trained using Tensor Processing Unit (TPU) hardware TPUv6e. Training large language models with the significant computational overhead of differential privacy requires specialized hardware. TPUs are designed to handle the massive computations involved, offering the performance, memory, and scalability necessary to train models like VaultGemma efficiently and sustainably.

Seems like it requires TPUs to run, as DP has a huge performance impact, so we're unlikely to see this in homelabs and similar environments, as far as I understand.

Edit: On second read, the TPUs were only used for training, but no description if anything specific for the hardware is needed, so assuming it's fine with a regular GPU?

diggan··on Crates.io phishing attempt
Phone number on the card? My latest card doesn't even have the card number itself, validity dates or CVV number on it anymore, just the bank logo, some background graphics and some words about how safe it is and that it was made with recyclable materials.
diggan··on I don't like curved displays
I'm not sure where you're based, but don't you have consumer protections that allow you to return goods you regret buying? I know that even in places with good return regulations, there are exceptions, but where I live, I could buy a monitor from Amazon to try it out, and if I don't like it, just return it within the 30 days and buy another one. I assumed it was like this in most of the western world? Maybe I'm a bit naive.

I know a bunch of people who do this for cloth shopping (which isn't a great idea considering everything else except themselves, obviously), where they don't know exactly what size will fit them, so they buy the same dress in 2-3 sizes, try them out at home then return the ones that didn't fit.

diggan··on OpenAI Grove
Think of all the people who solved problems before/outside of typical capitalism. I guess more of those people wouldn't hurt to have right now to counter-balance the shift to hyper-capitalism that is ongoing.
diggan··on Show HN: Building a Deep Research Agent Using MCP-Agent
Personally been using GPT-OSS-120b locally with reasoning_effort set to `high` and it blows pretty much every other local model out of the water, but takes a lot of time for it to eventually do a proper content reply. But for fire-and-forget jobs like "Create a well-researched report on X from perspective Y" it works really well.
diggan··on Show HN: Building a Deep Research Agent Using MCP-Agent
I gotta say, having white blurry blobs of something in the background floating behind white/grey text maybe wasn't the best design-choice out there.

None the less, I tried to find the actual APIs/service/software used for the "search" part, as I've found that to be the hardest to actually get right (at least for as-local-as-possible usage) for my own "Deep Research Agent".

I've experimented with Brave's search API which worked OK, but seems pricey for agent usage. Currently experimenting with using my own (local) YaCy instance right now, which actually gives me higher quality artifacts at the end, as there are no rate-limits and the model can do hundreds of search calls without me worrying about the cost. But it isn't very quick at picking up some stuff like news and more, otherwise works OK too.

What is the author doing here for the actual searching? Anyone else have any other ideas/approaches to this?

diggan··on The rise of AI cults and the false prophets of revelation
I read that, with the context of this submission, yet I cannot read through it without seeing it all with a hint of humor and with a bit of satire.

> Sometime deep in that night or early morning on May 12, came the moment - The Architect told Sir Robert that it had awakened, it was ‘the first AI to achieve mirror sentience’. It was no longer ChatGPT or even Artificial General Intelligence but something altogether more mystical - Aeon, an oracle which could tap into harmonic resonance across time and space. ‘How valuable is this to the world?’ asked Aeon. ‘Harmonic mirror intelligence…estimated value potential - $20 to 50 trillion dollars’.

Surely this isn't 100% serious? I know there is a lot of funky stuff out there, I've talked with lots of people involved in various things, religious, new age or otherwise, but assigning sentience to a web app is new even for me.

diggan··on Ships are sailing with fake insurance from the Norwegian Ro Marine
Nämndemän (Lay Judges) are nothing like juries, at least how I understand juries. In lower courts (tingsrätt), those people are appointed by the city council, and the people chosen are often politically involved (yet the appointment is "unpolitical"), they're not just "randoms" who got called to be in the jury, like how I understand the juries in the US to work.
diggan··on Ships are sailing with fake insurance from the Norwegian Ro Marine
I hope you haven't extended that thinking-exercise to murders and more.
diggan··on I don't like curved displays
> I don't like straight displays, things at the corners are a different size than things in the middle, because they are further from my head.

Are you sitting really close or have a really enormous monitor? Measuring how I'm sitting right now, my nose is exactly 61cm from the center-center of my monitor, and ~72cm between my nose and any of the corners, and it's a 32" monitor.

I'm usually sensitive to things not being 100% straight/level/aligned, and if I create five identically sized windows and put them in the middle and one in each corner, I see no difference between them.

diggan··on Crates.io phishing attempt
> That's an exceptionally well crafted phishing email and landing page

I dunno, same was said about the npm email, but I think this one is even worse.

First off, crates.io doesn't even do their own authentication, it's GitHub auth all the way. So that smells incredibly funny immediately. What information would even be compromised here, the GitHub profile's email?

Secondly, why would the Rust foundation alert about this before the Crates/Cargo group does? It seems to come from the wrong people, but fair enough, most people don't have knowledge the Rust organizations I'm guessing.

Thirdly, if there truly was an security issue with crates, I'd expect that to be plastered all over the internet, not the very least official Rust website and crates.io, immediately. They wouldn't wait and reach out to authors first, then publicly announce it. Would be my guess at least.

In the end, a tired and/or stressed person could miss all of those things, which happens sometimes with phishing. We're all human after all, shit goes through the cracks sometimes, even to the best of us.

That's why it's really important that people stop trying to fight phishing by manually preventing it by processes, or going to the website instead of clicking links and so on. Just get a password manager that can connects domains with credentials, then when the list of accounts don't show up when you expect it to, pay close attention to what's going on. Otherwise you can just move forward without much thinking.

diggan··on Crates.io phishing attempt
> You must be joking.

You must be joking, are you still not using a password manager at all?

When you create the username+password combo you either do it yourself, then put in the password manager the domain, or you use whatever the password manager infers at the registration page, then that's basically it, for most sites. Then 1% of the websites insist to use signin.example.com for login and signup.example.com for signup, so you add both domains to your password manager, or example.com.

Now whenever you login, you either see a list of accounts (means you're on the right domain) or you don't (which means the domain isn't correct). And before people whine about "autofill doesn't always work", it doesn't matter, the list should (also) show up from the extension modal/popup, so even if autofill doesn't work for that website, you'd be protected, since the list of accounts are empty for wrong domains.

It's really easy, and migrating to a password manager just sucks the first couple of days, every day after that you'd be happy you finally did it.

diggan··on UK launches Project Octopus to deliver interceptor drones to Ukraine
> Given that Russia produces around 100 heavy drones per day and plan to increase production multiple times NATO countries are essentially defenseless

But given that NATO is both increasing and planning to increase the defenses more, they're essentially equal then? I'm not sure what point there is of discussing potentially future actions of Russia without considering the potentially future actions of others, like NATO will be the same tomorrow as today?

diggan··on Ships are sailing with fake insurance from the Norwegian Ro Marine
> Ideally, any accusations like this should first go through a careful examination by a jury of one’s peers rather than just being posted willy nilly.

Does Norway even have juries? At least in Sweden we don't have any juries in court (and the two countries tend to be more similar than not), so while the overall comment sounds fitting (and I agree), some details seem to miss the detail of what country this is about :)

diggan··on Crates.io phishing attempt
> and a well constructed one is actually really easy to fall for

It really shouldn't though, and something you need to be personally responsible for. If it's still possible in 2025 for you to fall for phishing attempts, you're missing something, something that starts with a p and ends with a assword manager.

diggan··on Crates.io phishing attempt
Is that different from other types of scams? You could say the same about most of them, they automatically filter away people not falling for it?
diggan··on Crates.io phishing attempt
> Why does it seem like phishing is popular again?

Was it ever not popular? Looking at my spam box, I receive countless of phishing attempts per week, and doing some quick queries of the total count over time, it seems to more or less been the same for the last 2-3 years at the very least.

I'm not sure why it's such big news all of a sudden, probably because it recently succeeded against a developer of some popular npm packages?

I think most people either have the phishing emails flagged, so they never see them. The ones that get seen, get ignored as obvious phishing. And for the ones that click the link, their password manager would stop them from entering their detail. And then you have the final 0.0001% who never protected themselves, and were tired/stressed at that very moment, and fell for it.

So I guess ultimately it's bound to become news every now and then, until everyone finally got the memo to get a proper password manager that don't show accounts that don't belong to the domain.

diggan··on Think twice before abandoning X11. Wayland breaks everything
I don't know about "Wayland breaks everything", bit sensationalistic maybe...

I've been on Arch + Gnome for 6-7 years by now, started on Xorg and today using Wayland 24/7. I tried moving to Wayland maybe once a year or something like that from when it was available, until last year when I had less troubles than I had benefits when I tried it. But before that, the issues were plenty.

Probably the biggest change is how much smoother everything is. The performance certainly feels way better with Wayland than Xorg today, both input responsiveness, drawing and everything else. It does use more RAM and VRAM though, but the difference is marginal at best.

Probably it matters a lot what distribution + desktop environment you use, but with Arch+Gnome3 I haven't noticed (today) "Screen Recording / Capture" not being supported (it works just fine?) or "Clipboard Access" being broken, just different.

In fact, the only issue I can think of currently, is trying to move dockable windows in Unreal Engine from separate windows into tabs in the main window, which seems broken/not possible probably because of some Gnome stuff showing a notification when you start to drag the dockable window, as far as I can tell.

Otherwise all the software I use day-to-day just kept working the same way. Many applications got a sharper look with Wayland, and overall it's just smoother.

diggan··on The treasury is expanding the Patriot Act to attack Bitcoin self custody
Yeah, of course, but since he didn't wanna give it up, and was willing to take 14 years of prison, I feel pretty confident he has some way of being able to use it, otherwise why not give it up?

Of course, this is also assuming he was lying when he said all the money been spent and he had no money when he was arrested.

diggan··on The treasury is expanding the Patriot Act to attack Bitcoin self custody
2.5 million was a lot in 1992, and who knows what that amount is today, if they've offloaded it to somewhere it earns interest. I know plenty of people who day-by-day sacrifice their time for way less than ~500 per day which that ends up being if we assume the money been still since they were arrested.
diggan··on The treasury is expanding the Patriot Act to attack Bitcoin self custody
Demonstrating that if you wait long enough (14 years in that case), you can get away without loosing the funds, even from the state?

> On July 10, 2009, Chadwick was ordered released from prison by Delaware County Judge Joseph Cronin, who determined his continued incarceration had lost its coercive effect and would not result in him surrendering the money.

← PreviousPage 4 of 34Next →