HNHacker News
TopNewBestAskShowJobs

folex

362 karma · joined October 27, 2016

submissionscomments
folex··on We hid backdoors in ~40MB binaries and asked AI + Ghidra to find them
> The executables in our benchmark often have hundreds or thousands of functions — while the backdoors are tiny, often just a dozen lines buried deep within. Finding them requires strategic thinking: identifying critical paths like network parsers or user input handlers and ignoring the noise.

Perhaps it would make sense to provide LLMs with some strategy guides written in .md files.

folex··on How I use Claude Code: Separation of planning and execution
this is exactly how I work with cursor

except that I put notes to plan document in a single message like:

   > plan quote
   my note
   > plan quote
   my note
otherwise, I'm not sure how to guarantee that ai won't confuse my notes with its own plan.

one new thing for me is to review the todo list, I was always relying on auto generated todo list

folex··on The Gleam Programming Language
> static types often reduce to a bunch of optionals, forcing you to null check every field

On one end, you write / generate / assume a deserialisator that checks whether incoming data satisfies all required invariants, eg all fields are present. On the other end, you specify a type that has all the required fields in required format.

If deserialisation fails to satisfy type requirements, it produces an error which you can handle by eg falling back to a different type, rejecting operation or re-requesting data.

If deserialisation doesn't fail – hooray, now you don't have to worry about uncertainty.

The important thing here is that uncertainty is contained in a very specific place. It's an uncertainty barrier, if you wish: before it there's raw data, after it it's either an error or valid data.

If you don't have a strict barrier like that – every place in the program has to deal with uncertainty.

So it's not necessarily about dynamic / static. It's about being able to set barriers that narrow down uncertainty, and growing number of assumptions. The good thing about ergonomic typing system is that it allows you to offload these assumptions from your mind by encoding them in the types and let compiler worry about it.

It's basically automatization of assumptions book keeping.

folex··on The Gleam Programming Language
> ends up being the same checks you would be doing with a dynamic language

Sure thing. Unless dev forgets to do (some of) these checks, or some code downstream changes and upstream checks become gibberish or insufficient.

folex··on A library of words: Discovering Roget's Thesaurus (2023)
Where does the stereotype 'thesaurus = synonyms + antonyms' come from?

I'm not a native english speaker, and I never heard that idea besides in, I'd guess, Friends TV show.

I've used thesauruses since my childhood for exactly the task of looking up meanings, explanations, perhaps some etymology baked in.

For English, I always use WordNet, it is quite good and works offline on Android.

For my basic level of Chinese, Outliers dictionaries are so far the best I have found, but that's mainly due to my heavy reliance on the etymology provided there.

Well, I guess I got carried away a bit. Back to my question, where thesaurus=synonyms+antonyms comes from?

folex··on Tailscale vs. Narrowlink
https://github.com/narrowlink/narrowlink/blob/main/agent/src...

mhm. single-handedly, though.

folex··on What gets to the front page of Hacker News?
I like that the URL is basically the answer to the question.
folex··on Replacing my best friends with an LLM trained on 500k group chat messages
I wouldn't describe it as a comedy as well.

However, I'd recommend Murderbot series, it is full of humour and shares atmosphere of Bobiverse and this personal approach to characters, as well. Highly recommend.

folex··on Ryuichi Sakamoto has died
/05
folex··on Ask HN: What is a specific use of GPT-4 that you think is remarkable?
I'm yet not doing this, unfortunately. API limits wouldn't allow me to load in some IRC chat there.
folex··on Ask HN: What is a specific use of GPT-4 that you think is remarkable?
I can't really wait for tooling to visualise complex technical concepts into nice animations and static images.

Imagine describing how some system works, what it consists of, and get architecture images + process animations.

folex··on Ask HN: What is a specific use of GPT-4 that you think is remarkable?
Retrieve information from public technical chats to provide Q&A on programming languages, technologies, engineering approaches and so on.
folex··on Show HN: Scribble Diffusion – Turn your sketch into a refined image using AI
I can't wait for a tool that would allow me to draw architecture diagrams, and maybe even process animations to explain how my software works.

https://scribblediffusion.com/scribbles/nca3ivborbebhipju6jg...

folex··on Ask HN: Why does every package+module system become a Rube Goldberg machine?
Being in the Rust full time for last 2 or 3 years: it is quite a pain to setup a release process for big Rust workspace.

Version incrementing, packaging wasms, dancing around code generation – all doable, but not standardized.

There's a release-please to automate all that, but it's not an easy task to set it up in all of your repos.

Besides, if in addition to Rust projects, you have projects in other languages like JavaScript, then you have to do it twice and struggle with understanding all of the package management systems provided by all languages you have.

A single swiss-army-knife package manager would be amazing.

folex··on Ask HN: Why does every package+module system become a Rube Goldberg machine?
Yes!

I'm in a team that works on a pet prog lang for distributed systems, and we did some research of using an existing package managing systems. We've settled on NPM for now, but god I wish there would be a better generic package manager out there.

folex··on Ruby on Jets: Like Rails but serverless
we're building open serverless-centered cloud-like p2p network to aolve exactly this issue. to eliminate vendor lock and make it open so anyone can both provide and consume compute resources and develop backends on top of that.

https://fluence.network

folex··on A command line tool that draw plots on the terminal
awesome!
folex··on Human gene linked to bigger brains was born from seemingly useless DNA
pile of tickets is a very nice metaphor
folex··on Kitchen Renovation ideas animation using Stable Diffusion [video]
Do you think it's gonna be a tool used by these "average teams" or like a standalone self-serve product without any service human involved? I'd bet on a former, but why do you think?
folex··on Make-A-Video: AI system that generates videos from text
I wish to have such a tool to generate tutorials for different technologies. Like distributed systems, consensuses, replication, this kind if stuff.

Something like: there are 10 peers, A sends to B, B waits for C, yadayada.

folex··on Ask HN: Who is hiring? (August 2022)
Fluence | Full Remote | Worldwide

Distributed VM over a p2p network.

https://fluence.one/join.html

https://github.com/fluencelabs

One of the target audience are distributed systems researchers: we provide a high-level strong-statically typed prog language for distributed systems.

Looking for:

    - Scala / Haskell people who are into writing compilers and designing prog langs are most wanted;
    - Distributed systems engineers and researchers;
    - People proficient in scaling p2p networks (if you exist!);
    - Engineering Manager;
and more :)
folex··on Show HN: Wachy – A UI for eBPF-based performance debugging
Awesome! Can it be used for Rust?
folex··on WebAssembly: The New Kubernetes?
It depends on specific WASM runtime implementation, but usually you have to be explicit about allowing each syscall.
folex··on WebAssembly: The New Kubernetes?
> This post describes something like Erlang actors, but if each can be a pure function encoded in WASM...

Not just a dream. https://github.com/fluencelabs/fluence

folex··on WebAssembly: The New Kubernetes?
I'd say that article compares WebAssembly to Docker/moby/other container runtimes, not k8s.
folex··on WebAssembly: The New Kubernetes?
Multiplexing between several WASM modules is exactly how services are organized on https://fluence.network

Each peer in a p2p network can host multiple services and expose their API to the network. Each service, then, is a collection of WASM modules that interact with each other in FFI manner.

folex··on XMPP: The secure communication protocol that respects privacy
How about XMPP performance on low-performance networks like mobile ones?

I believe poor networking performance was one of the reasons XMPP had to be customised in WhatsApp and overall didn't become as widely used as I'd like it to be :)

Is it still the case? Or was that problem addressed at standard level somehow?

folex··on A not so gentle intro to web3
take plain old database, then add requirements 1) to be public, 2) not controlled by a single entity, 3) stored data is objectively consistent, and you basically get a blockchain
folex··on How Telegram Messenger circumvents Google Translate's API
such APIs could be running on https://fluence.network with an interoperability and composition across different services
folex··on Nassim Taleb: Bitcoin, Currencies, and Fragility [pdf]
There was an interesting debate on this topic, with one of the speakers being Saifedean Ammous, author of The Bitcoin Standard.

https://www.youtube.com/watch?v=MN4klUUx8fM

P.S. I find the name of the book 'The Bitcoin Standard' fairly misleading, given that the first 2/3 it is about Gold Standard and barely mentions Bitcoin. I have not found the latter 1/3 of the book interesting to read, so I dropped it there.

Page 1 of 4Next →