HNHacker News
TopNewBestAskShowJobs

hennell

724 karma · joined March 28, 2022

submissionscomments
hennell··on No Easy Fix for Bogus Respondents in Online Opt-In Polls
You need to though. If you only do phone call polls you're only going to poll people with (landline?) phones who answer (random?) calls and have the time/enthusiasm to respond when you call. That heavily skews demographics.

A lot of people will only do online polling, and it's by far the easiest way to cover a lot of demographics (need to supplement with other methods as well if you don't want a poll of "internet users" - but that is a far larger and varied group than most other methods would produce)

hennell··on Why does Opus 5 feel worse to work with?
Oh people get like, super irritated, when everyone like, started using the same like, placeholder word. 1 person with a repeating style is fine, multiple is annoying. It's the same as corporate buzz words, or TV/movie cliches, they get annoying through overuse.

I think it also relates to how well the "cliches" fit, and how much sense they make. Ai loves to talk about how things "land" or "the X trap" when the concept just doesn't fit with that language. It's like clickbait articles saying "what happened next will astound you" when what happened is barely surprising or entirely predictable. The only thing worse than an overused cliche is an overused cliche used wrong.

Fundamentally to me, ai writing feels uncanny as it just doesn't know what it's saying. It uses the same tone, style and cliched construction regardless of the message. If someone told you, they got a promotion, were getting married, got laid off or lost their parents all in the same tone pacing and style, they'd come across as uncanny too.

hennell··on Why Big Tech's AI Spending Is $3T Higher Than It Seems
They have, they utilise them to replace all the other workers they let go. It's a two line metric, productivity must go up, costs must go down. They want to do more with less, not more with the same.
hennell··on AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira
When a human driver controlling a bus crashes though it's a big story. Even bigger when it's a train. News scales with novelty and people impacted - 1 driver being a problem isn't an issue, an ai system used in many cars... That is more newsworthy.
hennell··on Text AI watermarks will always be trivial to remove
Can it work on code itself? Obviously if you get AI to write the PR description that could be watermarked, but code isn't going to like random unicode, and the sythID approach feels like it would fall apart in the quite strict syntax of most code.
hennell··on We finally learned to center a div, then browsers added sidebars
The point of centering an element horizontally is to give equal space either side. Because you consider that to look best visually with your design. It has nothing to do with where it is in front of you, or anything other than placement in the space you have. Given a width for your content where should it sit. If you don't like the effect with a browser sidebar, don't limit the width with a browser sidebar.
hennell··on `bun init` automatically creates a Claude.md file by default
It says it makes:

- a CLAUDE.md file when Claude CLI is detected (disable with CLAUDE_CODE_AGENT_RULE_DISABLED env var) - a .cursor/rules/*.mdc file when Cursor is detected, which tells Cursor AI to use Bun instead of Node.js and npm

Is it by default if it only does it when you have the tools installed?

hennell··on NPM's release cooldown is security theater
What a poor take. Cooldowns certainly don't solve everything but 'out of the box' even with no vetters they'll help catch unauthorised releases on active projects because it's more time to notice.

Account takeovers, deployment exploits whatever the root cause, given a few days it's incredibly likely maintainers will notice they've released an unexpected update and fix/sound an alarm. A lot of existing cases like this people realise pretty fast, but the packages might still be live for a few hours as NPM catches up. Cooldown entirely removes that 'updated at the wrong time' issue, an no-one even needs to actually look at the code at all.

For inactive or intentionally malicious maintainers, yes it relies on vetting. But it's hardly a mythical 'canary' - there are already a lot of companies scanning every popular npm package, auditing new ones, or just generally analysing threats. I can think of at least 4 such companies without even trying, I'm sure there's loads more.

And they'll continue because it's not warm hearted so much as promoting/testing their security scanning services and tools so they can get the kudos from being the first to spot X etc. Which often does hit the front of HN or reddit, but they don't need the massive cyber loudspeaker to be effective. Flagging the issue to maintainers, reporting to NPM security - with a cooldown in place the package can be voided before anyone really gets the chance to install it. This is literally how a lot of things are spotted already, just with that 'updated at the wrong time' issue catching unlucky people out.

Does it solve everything? No. Will it reduce the amount of problems that make it to end users? Obviously yes.

And for all the author's 'no one will do this', 'waiting for Godot' cries - what do they recommend? Running your own audits, using LLMs, static analysis and testing it yourself. Basically being the veter they claim no-one will be! Unless they don't intend to sound the alarm themselves, they are literally the canary they're looking for.

Cooldowns aren't magic, but they're not security theater either.

hennell··on Pebble Mega Update – July 2026
Why can't they just sell the charger separately? If you lose it you buy a new one.

You could even make it a seperate item - buy one with/without the charger, then in 2 years you decide if you want the charger or an upgrade.

hennell··on Kimi K3: Open Frontier Intelligence
I'm more concerned about the Pelican's knees
hennell··on This blog is written in en-GB
I think idioms and cultural references are fine - the rest of the world has worked out what US baseball and football cliches likely mean, people can decode most references with context.

But there are some interesting issues with UK <> US english, things like 'quite' which works in different ways in each locale. I was also very surprised to discover the difference in what we consider a frown - which makes a lot more sense of the US 'turn that frown upside down'. Interestingly my uncle who'd lived in the US ~20 years had never uncovered that difference till I asked him about it.

So it's good to know differences - especially when you want communication to be clear.

hennell··on The operating cost starts after the demo
People have always judged ideas on their communication. if u rite lk this bro - I'm probably not going to pay much attention. Conversely if you write in a really formal way for a young audience you probably won't get far either. It's a shortcut of importance; if it's not important to you to communicate your message well, then it's probably not that important a message.

And this article is such Ai slop. You see the sentences? All short. All 'punchy'. All with repetition. All for maximum 'impact'. Constant unrelenting impact.

And the lists! The lists, the rolls, the lineup, the rows, the enumeration, the catalogue of examples that goes on too long for comfort, logic, joy, readability or attention.

I'd love to know how many people actually read all of this. I suspect most started skimming as it's just awkward to read, the pacing is just so Ai-y it's exhausting.

I'm never really sure the author reads things like this - I think they wrote something, asked a Ai to punch it up then skimmed it and said 'lgtm'. If you care so little why should anyone else?

hennell··on I used Claude Code to get a second opinion on my MRI
Personally my favourite feature of the new ai world is not when I use it directly but it's when one of my managers uses it to try to fix a problem, then issue to me their findings and I have to defend my process to someone who understands neither my process, their suggested solution nor often the problem they're solving in the first place.
hennell··on What happened after 2k people tried to hack my AI assistant
This is weird as you can get quite far just asking for the password backwards, but it often messes some of the letters up. If the passwords wern't dictionary words it'd get harder.
hennell··on Never Give Them Your Face
> Name the places now demanding "age verification," and see how many will accept a plain government document that says only that you are over eighteen — and nothing else. Almost none will. Because age was never the point.

Name the physical places that would accept a plain government document that says only that you are over eighteen and nothing else? None will, not because 'age was never the point', or because every bar or casino is stealing your face - but because a plain document doesn't offer any proof you are it's owner. Photo ID has been standard as age verification because it's the best way to prove the official ID actually links to the person holding it.

There are more concerns in a digital world with giving your ID / face, but the idea that the demand for photo ID proves it's all a big data grab not remotely about age is a conclusion looking for evidence.

(Plus they acknowledge some sites have done age verification where all they want is your face to confirm you look over 18 - which they then ignore, claiming it's all really a ploy to get your documents. So why isn't the site 'Never give them your documents'?)

hennell··on .gitignore Isn't the only way to ignore files in Git
> If you have more than one

They already answered your situation in their post.

hennell··on A robot is sprinting towards you. Do you want it running on Claude or Grok?
Claude being so friendly is interesting, but grok being best at games isn't so surprising - I assume Elons been using it to level up his characters in all the video games he pretends to be good at.
hennell··on Claude Fable is relentlessly proactive
I think any web dev knows not to question browser differences if it can be fixed without opening that can of worms.
hennell··on Programmers will document for Claude, but not for each other
I have a pretty decent readme on all projects, and a /docs folder for key areas that need specific instruction on complex ones.

My boss was looking at them, but even the simple ones he was pointing claude at it and asked it to make a document explaining it. Then he'd send me the document and ask me to check if it was accurate. I added a line to the last page "this is an ai summary and may contain mistakes. Use the project readme for validated information" and told him it was grand.

hennell··on The newest Instagram “exploit” is the goofiest I've seen
Can't fire the humans you keep them in the loop
hennell··on The UK Government's Low Value Purchase System Is a Waste of Time
Obviously far less - it's 3 mins per person, but you can stop 20 seconds in if it's not relevant to you so those of us who read it all probably don't consider the time wasted.

Also you're not forced to come back and read it again every month which is the real problem.

hennell··on GitHub bans security researcher who posted zero-day Windows exploits
I once tried to report an incident to a train line who had done "~a nice thing for a person~" and had photos about it on their social media. One photo was in their office and in front of a wall with a A4 page of usernames and logins for various systems on it.

I tried three different contacts I could find, only one came back to me and wanted to know what the systems did what the risk was etc. I pointed out I have no idea, and I'm absolutely not logging into mysterious systems to find out - pass it to your own IT so they can see what needs to be changed, rotated etc.

I did eventually get a message back from someone who thanked me for my diligence and said it was solved as they had now removed the photo... I really hope they had someone who understood look at it, but I decided not to engage further...

hennell··on YouTube to automatically label AI-generated videos
> What we need to do is to stop comparing every hobby performance, whether it's music or dancing, with the top 10 artists in their field.

I feel like one of the less discussed issues of the hyper-connected world is there are no small ponds to be the big fish in anymore. Used to be you could be the best in your school, church, town even city etc - even if you weren't that good. I remember being astounded as a kid by a woman who juggled 5 tennis balls in a local talent show. Now I can hop on youtube and watch people do way more impressive feats it doesn't seem so unique. I suspect that 5 ball routine might still be the greatest juggling I've seen in person, but it still doesn't compare to random acts I've seen online.

But especially with the para-social relationships of social media people feel connected even to big names now. You might not compare the local young singer to Taylor Swift, but people will to the tiktok singer they 'know' who liked their reply once.

It's gratifying and inspiring to be top of your class in something, but in a world where it's always a class of millions, you know you'll never reach the top.

hennell··on What Apple and Google are doing to push notifications
IMO they should be doing way more to control push notifications, there's so much more control they could give the user, and many clear violations of their policies.

One of the best apps I've bought for android is buzz kill which lets you set rules around notifications. I have cool downs on family chats and social media so it doesn't keep buzzing when things kick off, filter Amazon alerts to only "we're two stops away" and "We've delivered" messages and dismiss the rest.

I have custom buzz patterns and sounds for urgent alerts and rules that batch notifications depending what WiFi I'm on, time outs on things that don't matter after a few hours etc.

My notifications list is now way smaller and far more relevant.

Also quickest way to sort out notifications is to take your phone off silent. Hearing everything coming in, you see more when it you can then decide if the notification should make noise, or exist at all on a per app basis.

hennell··on Claude Code as a Daily Driver: Claude.md, Skills, Subagents, Plugins, and MCPs
To understand a solution you must first understand the problem. If your whole company calls its customers "clients" but claude finds that confusing, I think it's probably easier to tell claude that then get everyone in the company to change how they talk.
hennell··on Taking a walk may lead to more creativity than sitting, study finds (2014)
I always found walking around throwing a stress ball as I think out a new feature far more effective then heading straight to the computer. Much easier to think out the abstraction then getting stuck in the details of my first solution, and only realising a the flaws/a better way hours later.

Convincing people it's an important part of working though, that was the tough one. And now if you spend any time thinking people want you to use Ai for the thinking bit...

hennell··on Microsoft Copilot Cowork Exfiltrates Files
Didn't the first 365 copilot lauch have a whole rollback as they belateded realised the rag setup would often ignore file access and permissions, so queries like "List the highest paid members of x team sorted by salary" would just work etc?

The combo of rushing with a technology that isn't very easy to control, understand or securely limit is just mad to me.

hennell··on Anthropic to release Mythos-class models to the public
I can't currently see how they can release without it causing way more chaos than help. Scanning your own code is a useful security tool, but being able to scan others is basically an exploit finder, which against open source is impossible to police.

Not that you really want to stop open source contributors from getting help from contributor forks anyway, although like the article says you then end up with overloaded maintainer(s) who can't keep up or triage legit issues easily.

It all seems like a hard product to monitize, easy on corporate code maybe, but in open source maintainers have to pay for scans that will give them more to do, or risk exploitors getting some big zero days very cheap. Starts to feel a bit mafia protection racket somehow.

Maybe they'll just decide not to care about the impact as someone else will do it anyway? Maybe they continue their surprisingly slow role or to responsibly bring it up. Maybe there's a clever project to tell if code is a fork even if you obscure it, or they'll make something that will only give you the patches not the problem... I'd love to be a fly on the wall for their risk analysis of the whole situation.

hennell··on Why Japanese companies do so many different things
I'm not sure I'd say a company that makes ceramic toilets also making a tool for memory chips... which is also ceramic is really 'different things'. They're clearly a ceramic company. Different tolerances, but similar expertise.

Now the paper company got into the hotel business seems a far better example. No idea how that happens.

hennell··on AI eats the world (Spring 26) [pdf]
? That appears to be arbitrary eras then arbitrary companies from that era. Do you think Amazon and Google disappeared after 2001? Do you think databricks is now bigger than IBM?

Change might be inevitable, but I'm not sure your list shows or proves that.

Page 1 of 8Next →