HNHacker News
TopNewBestAskShowJobs

hansvm

5,602 karma · joined December 22, 2019

submissionscomments
hansvm··on Adding Floating-Point Decimals for Fun and Profit
I like using rational types for that sort of thing.
hansvm··on What TLA+ can and can't check
Yeah, the last time I had to check anything regarding memory orderings, I wrote a custom analyzer for that problem. It's...not easy. The state space is enormous too, so even with compiled code I had to take some shortcuts and prove parts of the problem by hand.
hansvm··on There are no "rogue" AI agents
The people getting made richer are the people who already have connections and power. People quip about how capitalism is the worst economic system except for all the others, but its actual property is that it's inevitable without external pressures preventing it from happening -- people who have money (power) are able to use it to claim more money (power). If even a few people choose to exercise that privilege and that privilege isn't curtailed by other mechanisms, the current "wealth inequality" or whatever you want to call it is inevitable. Your girlfriend's crime was writing malware while poor, not writing malware.
hansvm··on Too AI; Didn't Read
How do you tactfully fix that, or can you?
hansvm··on I'm tired of being on the network
For an example from my own life (technically less relevant because if it comes down to it I'm fortunate and stubborn enough to win the lawsuit if that's what it comes down to, but swap me for any of their other million customers and the story still applies), my HSA has unilaterally made owning a sufficiently modern smartphone (<3yrs practically speaking, though it depends a bit on the manufacturer) with all the secure enclave bells and whistles mandatory to access my money I voluntarily placed into their system under a completely set of rules. Customer service has gone nowhere. If I couldn't afford the lawsuit, what options would I have? The employer offering the HSA a decade ago was just trying (and succeeding) to provide a nice benefit. I would've been insane to turn down a bunch of free money from my employer when the only stipulation was that it went through a third party taking a <<1% cut. The fuck-the-customer mentality happened later, and suddenly enough I couldn't do anything about it. If some family caves to their demands to access their own money, I'm not going to be the one to blame them for not being intentional about their decision making.
hansvm··on Mercury 2.5 LLM hits 770 tokens per second
If it could output 1k tokens per second but needed 4 seconds to produce the first batch of 4k, would that not be viable?
hansvm··on Samsung accidentally freezes its smart fridges with a software update
There's an old joke floating around if anyone remembers where it's from:

A tech enthusiast has the latest and greatest smartphones, voice assistants, and everything else cool and flashy. A programmer has a single inkjet printer from the 90s, and they keep a shotgun by their bedside in case it makes a noise.

hansvm··on ChatGPT now knows what you do on other websites via ad collector
Maybe 3 decades ago people had excuses, but the latest decade of cookie abuses have been designed by people who not only knew better but who took that better world into account as they buried it away from the general public. The fact that half a million developers think CORS is a server security measure isn't an accident.
hansvm··on Principles for Fast Tokio Applications
I'm not sure how other people are using LLMs for instrumentation, but IMO the layer you want running in prod is very different from what you want running for a one-off test. E.g., I have some code floating around which burns a pinned core on increasing a counter, with a little wrapper code around grabbing real timestamps at the beginning and end of a session and converting between the two units of time. It's helpful when microbenchmarking a very small unit of code as it actually behaves in a larger program (not perfect -- obviously tweaks the icache and pipeline behavior at a minimum -- but no measurement has zero tradeoffs, and you're always choosing which set of tradeoffs you prefer). An LLM can quickly instrument the call path I care about while I study this or that intervention. The ability to bang out a large amount of throwaway code is delightful.
hansvm··on Data collected by cars and sold to third parties
I know you're not the culprit, but it's annoying to see crap like this (highly invasive tracking, ostensibly for slightly more efficient tax collection), when far cheaper, better efforts (like Rhode Island's attempt to add tolls for just semis -- 98-99% of their freeway maintenance costs) are killed before they have a chance to prove themselves.
hansvm··on Bad code is kudzu
FWIW, I've seen the flip-side as well; solid coding patterns are easy for a person (or an LLM) to copy. To abuse the analogy a bit, your gardeners are happy copying whatever happens to be there, bad code will dominate that process unless actively removed, and the exponential nature of that arrangement favours removing trash code (weeds) early, much earlier than you might otherwise think.
hansvm··on Why is Google still serving dodgy ads?
- The big problem is that malicious ads are being displayed without appropriate attribution

- Add that attribution -- blame Google (or, supposing the ads are good, credit Google; a good header goes a long way toward swaying people's opinions)

- But it doesn't matter if a single website appropriately attributes Google's highest/lowest-quality ads. The last step (speculative and hand-wavy) is to incorporate that behaviour in some sort of software more people want to use. If you're fighting alone then you'll lose. If you can convince more people that appropriately crediting Google's advertising successes and blaming their malicious failures is advantageous, you'll (by definition) have more traction in the anti-megacorp-endorsed scams and other life-altering consequences.

hansvm··on Why is Google still serving dodgy ads?
That seems fixable. When people include this JS garbage, have a header/title/etc stating that this is Google's professional opinion. Bake it into a library offering enough other features that a large number of people are inclined to use it.
hansvm··on Don't be the out of touch Kung Fu master
The fatigue aspect matters too, but another important point I was trying to get across is that not all reviews are created equally. In a working, well tested, properly factored system, with a high quality PR, I can do a cursory, local analysis of the new code and be very confident that it works. AI code I've seen is ... not that. I wouldn't be comfortable in that review without manually checking preconditions and postconditions, defining invariants, examining lifetimes, and a host of other activities. Moreover, for a greenfield replacement of lots of SLOC, I'd expect that most of the code for the early PRs can't even meaningfully run or do anything important, making any sort of broader architectural analysis impossible.

I could see a world potentially where they came up with a magic prompt allowing each proposed PR to be cohesive, shippable, well factored, and everything else you need to be able to actually review it at a higher level and be comfortable with the results, but I'm skeptical. That's a major innovation if they managed to do so even as a one-off, and that wasn't the thing they highlighted when talking about the project.

hansvm··on Don't be the out of touch Kung Fu master
Assuming the LLM never got anything wrong or otherwise had to be re-prompted, that means your devs were reviewing 130 SLOC per hour, on what was described as moderately greenfield (examining new implementations rather than comparing to old historical accidents).

How?

I don't want to sound flippant, but if the point is to add human thought to the mix, that's a high review rate even when examining small tweaks to an existing, working product, even with substantial AI help to pre-filter major gotchas before you bother spending a lot of human effort on the review. That's only 20-30wpm, but a review isn't just scanning or reading code, especially if you're trying to figure out how a new system which doesn't run yet will fit together.

hansvm··on Why Emacs Consult async searches feel slow and how to speed them up
I've had good luck disabling the internet when I need my work computer to run faster. Those "security" checks are optional, and it'll let you work offline.

If just logging filesystem interactions and whatnot for future upload is also slow then you're hosed, but at one place I worked every application too an extra several seconds to start up for some sort of remote program inspection, which is fine till the application is git, grep, or cd.

hansvm··on Why Emacs Consult async searches feel slow and how to speed them up
> scrolled reddit

> no focus-wandering, no lollygagging

hansvm··on The Navier–Stokes Millennium Prize Problem
My doctor's privacy policy is a bit more abusive than OpenAI's. It exists mostly because of a $%^&&* legal framework rather than malice, and I've grown accustomed to "if I don't want to die then I sign away these rights." Despite my having theoretically signed my soul away, my doctor isn't selling personal information to my exes or to life insurance companies (though they could in the US; that extremely personal information is no longer mine). OpenAI is engaging in the "technically legal maybe we'll see but obviously unintended" side of this transaction, and maybe that works out for them, but I wouldn't personally choose to be a shill for "it's unreasonble to expect somebody with 'legal' permission to do something other than the maximum 'legally' permitted" if I were in your shoes.
hansvm··on On the Navier–Stokes Millennium Prize Problem
Those are two separate questions:

> How can I afford?

Mostly not my money, tech makes one fabulously wealthy, I care more about math than fast cars or whatever (even as a pizza driver you can afford a fancy car if that's your primary motive), etc.

> Already solved

That's a very interesting insight into mathematics. It's absolutely just as interesting to prove that certain proof techniques are or aren't possible as it is to actually prove the main result, sometimes moreso, especially if they have any chance of improving attacks at other problems.

hansvm··on On the Navier–Stokes Millennium Prize Problem
> not a counterpoint

>> isn't a counterpoint

Where do we disagree?

hansvm··on The Helicopter with Radioactive Blades
It's a medieval measurement, still in popular use. Nowadays it means approximately 2.54 centimeters. Historically, it's the height of the ash pile a "witch" would leave behind, and the word has morphed only slightly from "witches" into "inches."
hansvm··on On the Navier–Stokes Millennium Prize Problem
Not a counterpoint per se, but I burned $50k recently on a much more modest math problem (result already known, just thought I had a sketch of a more interesting proof), and the LLM thought it had proved it within those bounds but had instead subtly fucked up the Lean definition. Take from that what you will.

Not to mention, it's still very much up in the air whether the model derived the answer of its own accord or sniped the important details from the researchers it was spying on.

hansvm··on Getting your hands dirty is good for you
The streets are power washed often enough that it's usually fine, at least if you're careful where you step.
hansvm··on Trusting-Trust Attack against an Entire Linux Distribution
What happens when "security" includes a time component? A shocking number of modern systems depend on time, either in enough time having elapsed to prove something about the attacker, or in little enough time elapsing as a critical component of the system in question. That feels like it escapes the bounds of your definitions and is also somewhat unavoidable. Is that rectifiable somewhere?
hansvm··on Splash-free urinals (2025)
Yep. The next step is getting people to bother aiming for the urinal and hanging their member above it while shaking off any last drops. Till then, I don't think this design survives a collision with the real world.
hansvm··on The revolt of the reader
Quietly
hansvm··on Discovery of a new OpenAI agent message board
Directly charge for your services, let the AI find a way.
hansvm··on Discovery of a new OpenAI agent message board
Good thing we're not trying to deploy them into fully autonomous weapons or anything....
hansvm··on .gitignore Everything by Default
I normally go with `.*/` -- I find that hidden files are much more likely than hidden directories to be useful.
hansvm··on .gitignore Everything by Default
IME people are usually shoving their personal preferences in CLAUDE.md, sometimes automatically as the agent updates the file with that developer's pet peeves.

- Right now at $WORK, CLAUDE.md has a line saying to put one-off scripts in some gitignored place. That's fine if they're not worth checking in (IMO, you should build the tooling which would have made the script easy and check that in, but whatever), but that AI rule doesn't really keep them from being checked in -- developers manually review every line of code and decide what to check in -- that's just somebody deciding they'd rather not have to think so hard when running git add. Which is fine, but it directly conflicts with my preference for all AI-generated files to be plainly visible as a diff or with git status or something. They have a different diffing strategy, which is also fine, but that's just a dev's personal preference encoded in a whole-team doc.

- Or, I have a prompt I use to encourage higher quality code before I have to manually inspect it. It basically says "delete $200 and 1hr." For somewhat obvious reasons, I don't run it on every piece of code the AI shits out. I make it available in the project for people who want to use it, but I don't even want it in my CLAUDE.md, much less the team's.

- Similarly with whether to use git for checkpointing. I prefer to check the AIs output at each step. A colleague prefers to have it save its progress using git in 30+ commits on a side branch and then check them all at once. One of those workflows was in CLAUDE.md and absolutely is not anymore -- it's quite appropriate for a single developer's AI settings, but not for the team as a whole.

Those settings files are a lot closer to .vscode directories or other dev-specific editor configuration. Project-specific information should be exposed differently.

Page 1 of 34Next →