HNHacker News
TopNewBestAskShowJobs

iepathos

863 karma · joined March 8, 2021

submissionscomments
iepathos··on The Pentagon threatens Anthropic
The old path of 'military invents it, civilians eventually get it' (like the Space Race or early ARPANET) hasn't been true for decades. Today, almost all major technological leaps like the modern internet, search engines, smartphones, commercial drones, etc. start in the commercial consumer sector first. The global consumer market dwarfs the defense market, which means the private sector has vastly more capital for R&D. Government payscale caps out ~$190k-$200k/year for specialized roles without some congressional workaround. The top AI researchers at OpenAI, Anthropic, Google etc. make ~$1m-$5m+/year for total compensation. The government couldn't afford to hire the right talent and the right talent likely would refuse based on moral, ethical, and rational principles with the current government.
iepathos··on Minions: Stripe’s one-shot, end-to-end coding agents
"1000 PRs/week" with no breakdown of complexity or value is a vanity metric. If these are mostly migrations, boilerplate, and bug fixes on previous Minion PRs that were bug ridden, then you've just created 1000 code reviews/week to waste human time rubber-stamping. That's not productivity, that's busywork with extra steps.

It's like measuring productivity by how many people you pull into meetings each week. The CIA's Simple Sabotage Field Manual literally recommends holding as many meetings as possible with as many people as possible. The CIA should add "open as many PRs with AI as possible" to their list. Bonus sabotage points if the PRs are made from ambiguous "one-shot" attempts described in Slack with no follow up clarification.

iepathos··on Discord/Twitch/Snapchat age verification bypass
The hole is closed with per-site pseudonyms. Your wallet generates a unique cryptographic key pair for each site so same person + same site = same pseudonym, same person + different sites = different, unlinkable pseudonyms.

"The actual correct way" is an overstatement that misses jfaganel99's point. There are always tradeoffs. EUDI is no exception. It sacrifices full anonymity to prevent credential sharing so the site can't learn your identity, but it can recognize you across visits and build a behavioral profile under your pseudonym.

iepathos··on We mourn our craft
If AI is good enough that juniors wielding it outproduce seniors, then the juniors are just... overhead. The company would cut them out and let AI report to a handful of senior architects who actually understand what's being built. You don't pay humans to be a slow proxy for a better tool.

If the tools get good enough to not need senior oversight, they're good enough to not need junior intermediaries either. The "juniors with jetpacks outpacing seniors" future is unrealistic and unstable—it either collapses into "AI + a few senior architects" or "AI isn't actually that reliable yet."

iepathos··on TikTok's 'addictive design' found to be illegal in Europe
Apparent hypocrisy and injustice in government policy is an ugly thing in the world that should be pointed out and eliminated through public awareness and scrutiny.
iepathos··on TikTok's 'addictive design' found to be illegal in Europe
Get a life that's more interesting than dish washing 4-8 hours a day.
iepathos··on A sane but bull case on Clawdbot / OpenClaw
Thought the same thing. There is no legal recourse if the bot drains the account and donates to charity. The legal system's response to that is don't give non-deterministic bots access to your bank account and 2FA. There is no further recourse. No bank or insurance company will cover this and rightfully so. If he wanted to guard himself somewhat he'd only give the bot a credit card he could cancel or stop payments on, the exact minimum he gives the human assistant.
iepathos··on Ask HN: Do you have any evidence that agentic coding works?
The default output from AI is much like the default output from experienced devs prioritizing speed over architecture to meet business objectives. Just like experienced devs, LLMs accept technical debt as leverage for velocity. This isn't surprising - most code in the world carries technical debt, so that's what the models trained on and learned to optimize for.

Technical debt, like financial debt, is a tool. The problem isn't its existence, it's unmanaged accumulation.

A few observations from my experience:

1. One-shotting - if you're prompting once and shipping, you're getting the "fast and working" version, not the "well-architected" version. Same as asking an experienced dev for a quick prototype.

2. AI can output excellent code - but it takes iteration, explicit architectural constraints, and often specialized tooling. The models have seen clean code too; they just need steering toward it.

3. The solution isn't debt-free commits. The solution is measuring, prioritizing, and reducing only the highest risk tech debt - the equivalent of focusing on bottlenecks with performance profiling. Which code is high-risk? Where's the debt concentrated? Poorly-factored code with good test coverage is low-risk. Poorly-tested code in critical execution paths is high-risk. Your CI pipeline needs to check the debt automatically for you just like it needs to lint and check your tests pass.

I built https://github.com/iepathos/debtmap to solve this systematically for my projects. It measures technical debt density to prioritize risk, but more importantly for this discussion: it identifies the right context for an LLM to understand a problem without looking through the whole codebase. The output is designed to be used with an LLM for automated technical debt reduction. And because we're measuring debt before and after, we have a feedback loop - enabling the LLM to iterate effectively and see whether its refactoring had a positive impact or made things worse. That's the missing piece in most agentic workflows: measurement that closes the loop.

To your specific concern about shipping unreviewed code: I agree it's risky, but the review focus should shift from "is every line perfect" to "where are the structural risks, and are those paths well-tested?" If your code has low complexity everywhere, is well tested (always review tests), and passing everything, then ask yourself what you actually gain at that point from further investing your time over-engineering the lesser tech debt away? You can't eliminate all tech debt, but you can keep it from compounding in the places that matter.

iepathos··on The Code-Only Agent
The "code witness" concept falls apart under scrutiny. In practice, the agent isn't replacing ripgrep with pure Python, it's generating a Python wrapper that calls ripgrep via subprocess. So you get:

- Extra tokens to generate the wrapper

- New failure modes (encoding issues, exit code handling, stderr bugs)

- The same underlying tool call anyway

- No stronger guarantees - actually weaker ones, since you're now trusting both the tool AND the generated wrapper

The theoretical framing about "proofs as programs" and "semantic guarantees" sounds impressive, but the generated wrapper doesn't provide stronger semantics than rg alone, it actually provides strictly weaker ones. This is true for pretty much any CLI tool you're having the AI wrap python code around to do instead of calling battle tested tools directly.

For actual development work, the artifact that matters is the code you're building, which we're already tracking in source control. Nobody needs a "witness" of how the agent found the right file to edit and if they do agents have parseable logs. Direct tool calls are faster, more reliable, and the intermediate exploration steps are ephemeral scaffolding anyway.

iepathos··on You Need to Ditch VS Code
Research on calculator use in early math education (notably the Hembree & Dessart meta-analysis of 79 studies) found that students given calculators performed better at math - including on paper-and-pencil tests without calculators. The hypothesis is that calculators handle computation, freeing cognitive bandwidth and time for problem-solving and conceptual understanding. Problem solving and higher level concepts matter far more than memorizing multiplication and division tables.

I think about this often when discussing AI adoption with people. It's also relevant to this VS Code discussion which is tangential to the broader AI assisted development discussion. This post conflates tool proficiency with understanding. You can deeply understand Git's DAG model while never typing git reflog. Conversely, you can memorize every terminal command and still design terrible systems.

The scarce resource for most developers isn't "knows terminal commands" - it's "can reason about complex systems under uncertainty." If a tool frees up bandwidth for that, that's a net win. Not to throw shade at hyper efficient terminal users, I live in the terminal and recommend it, but it isn't going to make you a better programmer just by using it instead of an IDE for writing code. It isn't reasoning and understanding about complex systems that you gain from living in a terminal. You gain efficiency, flexibility, and nerd cred - all valuable, but none of them are systems thinking.

The auto-complete point in the post is particularly ironic given how critical it is for terminal users and that most vim users also rely heavily on auto-complete. Auto-complete does not limit your effectiveness, it's provably the opposite.

iepathos··on Rob Pike goes nuclear over GenAI
Thanks for the thoughtful reply.

The objections to non-profits, OSFs, education, healthcare, and small companies all boil down to: they don't pay enough or they're inconvenient. Those are valid personal reasons, but not moral justifications. You decided you wanted the money big tech delivers and are willing to exchange ethics for that. That's fine, but own it. It's not some inevitable prostitution everyone must do. Plenty of people make the other choice.

The Google/AI distinction still doesn't hold. Anthropic and OpenAI also created products with clear utility. If Google gets "mixed bag" status because of Docs and Maps (products that exist largely just to feed their ad machine), why is AI "unquestionable cancer"? You're claiming Google's useful products excuse their harms, but AI companies' useful products don't. That's not a principled line, it's just where you've personally decided to draw it.

iepathos··on Rob Pike goes nuclear over GenAI
> As IT workers, we all have to prostitute ourselves to some extent.

No, we really don't. There are plenty of places to work that aren't morally compromised - non-profits, open source foundations, education, healthcare tech, small companies solving real problems. The "we all have to" framing is a convenient way to avoid examining your own choices.

And it's telling that this framing always seems to appear when someone is defending their own employer. You've drawn a clear moral line between Google ("mixed bag") and AI companies ("unquestionably cancer") - so you clearly believe these distinctions matter even though Google itself is an AI company.

iepathos··on Europeans' health data sold to US firm run by ex-Israeli spies
What specific legal recourse beyond what exists? You can already sue for breach of contract if a company violates their privacy policy. The real problems are: (1) detecting violations in the first place, and (2) proving/quantifying damages. A 'guarantee' doesn't solve either.
iepathos··on Why are 38 percent of Stanford students saying they're disabled?
I agree with you that cheating is a loaded word, but the question at the end here that the rules or standards enable users to work around it therefore it's not cheating is a bad semantic argument. We can use the exact same argument to excuse every kind of rule breaking that people do. If a hacker drains a billion dollars out of a smart contract, then they literally were only able to do so because the coded rules of the smart contract itself enabled it through whatever flaw the hacker identified. That doesn't make it less illegal or not cheating for the hacker. It feels like victim blaming to point the finger at the institution being exploited or people who get hacked and say its their problem not the individuals intentionally exploiting them.
iepathos··on I don't care how well your "AI" works
These hyper paranoid statements like "I personally don’t touch LLMs with a stick. I don’t let them near my brain", are fairly worrisome for a technical person who claims to have any understanding of AI and undermines the credibility of the critique. There is some truth in here but it's beneath a lot of paranoia that's hard to sift through.
iepathos··on Launch HN: Hypercubic (YC F25) – AI for COBOL and Mainframes
I can tell they're using MkDocs for the HyperDocs static site gen based on the screenshot. I'm working on an open source solution to generating docs with AI for codebases and maintaining them for documentation drift. I wrote a bit about it initially here https://entropicdrift.com/blog/prodigy-docs-automation/ for anyone who is interested. I'm currently using mdbook instead of mkdocs, may add support for a mkdocs workflow to produce similar doc sites for just the cost of the LLM tokens. I didn't realize COBOL had such a large market for documentation with code as the source of truth. I'll have to try generating docs on an open source COBOL codebase to see how it fairs. Would be nice if hypercubic had actual live doc examples for what hyperdocs generates instead of just a screenshot, hard to judge how good or bad it is with just a single screenshot.
iepathos··on Ask HN: What Are You Working On? (Nov 2025)
Improving the open source automated documentation maintenance workflow I setup https://entropicdrift.com/blog/prodigy-docs-automation/ Any feedback is very welcome.
iepathos··on Singapore to cane scammers as billions lost in financial crimes
The erosion of freedom is everyone's problem. Normalizing government control over personal bank accounts is a dangerous precedent. Today it's scam prevention, tomorrow it's freezing accounts of political opponents.
iepathos··on Amazon strategised about keeping water use secret
Kind of surprised I have to point this out. Power companies do not generate the same amount of power regardless of whether that power would be consumed on their grid or not. They increase generation based on demand. Whether that power comes from high water consumption generation is based on location which determines which power sources are available in the local grid. A major part of why indirect water consumption from power generation is included in the standard WUEsource - water usage effectiveness metric - is because it makes it clear what the impact will be when assessing data center location and size. In other words, it's important to choose locations near power generation that doesn't consume water heavily. Yes, the amount of water used in generating electricity and the efficiency there is controlled power companies choices for power generation at their locations. Data centers control the location they are built in and without an estimate of indirect water usage they cannot strategize locations with lower environmental impact.

Contrary to your belief that it is about clickbait, it's actually just about how to accurately evaluate environmental impact of data centers backed by science and basic logic.

iepathos··on Ask HN: What are you working on? (October 2025)
I'm working on Debtmap - An open source Rust-based code complexity analyzer that tells you exactly which code to refactor and which code to test for maximum impact. Combines complexity metrics with test coverage data to identify the riskiest code in your codebase. Uses entropy analysis to reduce false positives by distinguishing genuinely complex code from repetitive patterns.

https://github.com/iepathos/debtmap

iepathos··on PYX: The next step in Python packaging
Human naming has nothing to do with software naming which seems obvious but apparently not. Python package creators should check the pypi registry for names and generally avoid name collisions where reasonable. Common sense applies for reduced confusion for users globally and also for potential legal issues if any party trademarks their software name. What makes one pyx more real than the other is one was first and took the spot on pypi. Simple as that. https://pypi.org/project/PyX/
iepathos··on Buffett to step down following six-decade run atop Berkshire
Immigrants are a critical part of the working class in America. Always have been.
iepathos··on Buffett to step down following six-decade run atop Berkshire
I don’t think it’s accurate to say that the working class is “resorting to populism to reverse the trend.” If anything, the fact that so many working-class voters support a wealthy oligarchy—one that consistently advances policies benefiting the super-rich at the expense of ordinary people—suggests that a significant portion of the population is being swayed by misinformation and manipulation, not that they’re successfully advocating for their own interests.

Ironically, it’s often the opposite party that actually pushes for policies that would materially benefit the working class. The real fallacy is equating the current wave of so-called “populism” with a genuine effort to improve conditions for workers. In practice, what’s being called “populism” is frequently just another vehicle for entrenched elites to consolidate power, not a movement to empower ordinary people.

iepathos··on Former tech CEO suing to get the record of his arrest removed from the internet
Right... but we all know this guy beat his girlfriend from the report. She didn't want to press charges, that doesn't mean this guy is innocent and it doesn't mean he shouldn't suffer reputational harm. For the good of any future women who might consider dating him it's actually in the interest of society that people like this have arrest reports published about them. Many abuse victims are too scared to press charges and just suffer silently. In doing so it enables abusers to move on to new victims who have no way of knowing until it's too late.
iepathos··on Deepseek: The quiet giant leading China’s AI race
I find the open source argument pretty weak. Linux is open source but is more used in production than windows, macos, or any other operating system by far and very arguably out-performs them. The very nature of being open source does not mean proprietary alternatives pick up all the benefits and being open source it is free and easily moddable which appeals to many of the best engineers who can drive the innovation further than proprietary alternatives. Proprietary alternatives don't necessarily have the resources or desire to adapt innovations from open source tech for their own solutions.
iepathos··on Ask HN: SWEs how do you future-proof your career in light of LLMs?
Better tools that accelerate how fast engineers can produce software? That's not a threat, just a boon. I suspect the actual transition will just be people learning/focusing on somewhat different higher level skills rather than lower level coding. Like going from assembly to c, we're hoping we can transition more towards natural language.

> junior to mid level software engineering will disappear mostly People don't magically go to senior. Can't get seniors without junior and mid to level up. We'll always need to take in and train new blood.

iepathos··on Coder wrote a bug so bad security guards wanted a word when he arrived at work
Office Space just keeps replaying in my head. All he needed was a timely fire to get away with it.
iepathos··on Mysterious New Jersey drone sightings prompt call for 'state of emergency'
For real, with everyone having a smartphone with high quality cameras on them there really is zero excuse for there to not be highly detailed accurate videos of this if they are legit especially with people describing them as "low and slow".
iepathos··on U.S. math scores drop on major international test
> The education system is the same for all the kids

This is incorrect, certainly an ideal we'd all like but far from reality. The educational experiences and outcomes of 1st and 2nd generation immigrants can and often does differ significantly from native-born students. Seeing the difference in the data/scores should clue you into this and helps us understand the socioeconomic impact on student achievement that immigration has. Language is often a large factor where 1st and 2nd generation students may be speaking a different language at home than they are in school. The US has significantly more immigrants than other countries in the world which is why not controlling for it skews the data disproportionately.

iepathos··on Why America's economy is soaring ahead of its rivals
The Federal Reserve study classifies non-ordinary expenses with households by comparing against median data for a region. For example, having a massive house means the square footage is significantly above median for the region and classifies it as a non-ordinary expense. As far as I know, it doesn't look at interest rates on individual mortgages because I don't believe they have that data accessible. It is a pretty sophisticated multi-dimensional approach they look at household income levels, regional economic conditions, household composition, rural vs urban, local cost of living, etc. It accounts for whatever the team of economic phds who designed it could think of with the data they have available.
← PreviousPage 2 of 8Next →