HNHacker News
TopNewBestAskShowJobs

iepathos

863 karma · joined March 8, 2021

submissionscomments
iepathos··on Coding expertise is going to collapse from AI reliance
I see a lot of parallels with how people were worried for decades that kids who learned with calculators wouldn't be able to do math. Instead, studies show the opposite that kids who learned with calculators do better in math even when the calculators are later removed. The reason is our learning bandwidth is limited and if you're learning multiplication and division tables you aren't learning the far more important higher level concepts.

There is something similar happening with AI and most people don't understand it and we don't have enough long term studies for data to make conclusions on this yet. Engineers sounding an alarm here but they also don't have the data to support their worry. Certainly some of the lower level understanding of coding languages aren't being acquired and maintained as much as before. Whether that underlying knowledge actually needs to take up the learning bandwidth that it was taking is the real question. My hunch is that it doesn't and that dropping it makes room for higher level concepts and understanding that are actually more important given modern tooling, the same way we don't actually need to know binary and assembly to be effective engineers, but time will tell.

iepathos··on What Happened to HackerOne?
An LLM finds a dubious bug, an LLM turns it into a convincing report, and now the proposed solution is to have an LLM triage it? There are a lot of turtles holding up this approach and the circular logic seems hard to miss.

Automated triage can filter obvious spam, which was already fast and easy for humans to do. The hard part is independently reproducing a plausible finding and assessing its actual impact. If LLMs could already do that reliably, then the slop report problem wouldn't exist in the first place.

iepathos··on All of Winona Police Department's Flock cameras cut down and stolen
For additional context, for first I've ever seen their rfs specifically asked for startups focused on military applications and warfare "The Future of American Defense" https://www.ycombinator.com/rfs

Disappointing to see this is the future they are trying to invest in.

iepathos··on Google fixed more Chrome bugs in June than over the past two years, thanks to AI
Nice marketing Google, now tell us how many of the bugs that were fixed were actually introduced by AI usage to begin with?
iepathos··on US citizen charged after GrapheneOS phone wipes during airport search
> The motion also states that Tunick asked four times to speak with a lawyer and was denied each time.

This is the kind of thing that loses cases, even if they were legitimate at first. Seems like the prosecutor is desperate charging for the phone wipe cause they didn't have any evidence of terrorism, child-pornography, etc. The problem they have now is given he was in custody and agents pressured him to provide the passcode that they then incompetently put into the phone, the fact that they denied him a lawyer multiple times means there is a very strong argument that his rights were violated. Typically, courts suppress any evidence when there is a violation like this with someone in custody. So the compelled passcode, the phone's reaction when that passcode was entered, and the agents' testimony describing the supposed wipe would be thrown out by most judges. What's left for the prosecution after this is jack and shit, but jack left town.

iepathos··on It's not empowering to hand off the details
If I commission a part specified as 10.00 ± 0.01 mm, I can verify it with a calibrated micrometer without understanding the CNC machine, its software, or how to manufacture the part. Likewise, a function with a finite input space can be exhaustively tested against its specification without understanding its implementation. In these cases, I need to understand the requirement and the test, not the production details, which can actually be a black box.

Your examples show that verification is sometimes inadequate, not that it requires full productive competence. The conclusion doesn't generalize.

iepathos··on It's not empowering to hand off the details
This post ignores that verifying something works doesn't require you to fully understand it. This is easily observable in products we use everyday. We don't need to understand them to be able to verify they work correctly. The cost of verification is often cheaper than the cost of production.

It present delegation as absence of power/agency. While I think there is some kernel of truth in here, the claim "it's not empowering to hand off the details" quickly falls apart when we consider real examples. If it were true, it would mean any leader who coordinates an organization isn't empowered through delegation. We know that's false. The general claim doesn't hold at all. Somewhere in there is an argument for engineers losing something in the hand off, but it isn't clearly articulated.

iepathos··on DeepSeek pause fundraise after comments on compute gap to US leaked (transcript) [pdf]
There is no war in Ba Sing Se
iepathos··on Codeberg Bans Cryptocurrency Projects
Perhaps, but it's important to keep in mind not even a majority of Codeberg users voted for this. A majority of their privileged voters did, which is a small minority of the actual users, and it wasn't unanimous amongst the voters. Over 30% of their voters did not agree with this choice. I'm not building crypto or vibecoded projects and this still makes me seriously question if I could trust Codeberg's current majority voters to not simply target other minority software categories without real justification just because they didn't personally approve of it.
iepathos··on Codeberg Bans Cryptocurrency Projects
Prohibiting fraud or infrastructure abuse is one thing, but declaring entire categories of lawful software harmful to Codeberg’s reputation is another. They've ironically tanked Codeberg's reputation far more from these policy changes than any projects in that category could have possibly. After these changes, it is difficult for any business, or any project seeking stable infrastructure, to trust that its codebase won’t become unacceptable after the next member vote.
iepathos··on Can a MUD evaluate LLMs? A $99 proof of concept
Haha, ty for this. That's just a personal habit. I tend to call Discord disco for short amongst my friends.
iepathos··on Codeberg bans vibe coded projects
Your two points seem logically at odds. If simply asking people not to upload prohibited material worked without enforcement, then Codeberg's existing copyright policy (and international laws) would already be sufficient. If people don't reliably follow that policy, then adding a vague AI-specific policy with the same enforcement problem changes nothing. What logical connection between AI involvement and copyright infringement does this new rule address that the existing copyright policy does not?
iepathos··on Can a MUD evaluate LLMs? A $99 proof of concept
MUDs never disappeared. People stopped finding them engaging enough to use. Blaming Discord reverses the causality. MUDs lost engagement long before disco was created. People congregate on disco because it offers a more compelling social interface, even if it lacks the depth of a persistent game world. The opportunity I'd draw from this isn’t to convince people to return to older and less engaging interfaces. It’s to build persistent roleplaying systems around the interaction modes that have proven to be more engaging already. Potentially combine voice, speech recognition, text, tts, and synthesized characters with a proper world simulation underneath. If roleplaying communities already gather in disco, then deliver the experience where they already are. The interface was always irrelevant to what made MUDs fun anyway. Imagination and connecting with other people was always the thing.
iepathos··on Codeberg bans vibe coded projects
This seems like a wild basis for a hosting policy. It doesn't ban code shown to be infringing, malicious, insecure, or unmaintained. It bans code based on how Codeberg believes it was produced or some individuals at Codeberg believe it was produced.

How would they establish that a project "mostly" consists of AI-written code? Lines, commits, tokens, or architectural importance? There is no reliable detector, and metadata only catches people who honestly disclose their tool use. In practice, this only creates an incentive to conceal AI usage.

Authorship is also a poor proxy for quality. Human-written codebases routinely contain copied patterns, unnecessary abstractions, stale comments, superficial tests, security vulnerabilities, and large subsystems nobody seems to understand. Many mature projects exhibit the exact same problems attributed to LLM-generated code with the technical debt they've built up over time. Slop isn't new or unique to generated code. It is extremely common, especially in beginner, hobby, and abandoned projects which have historically served as a critical part of the open source software community.

The copyright justification is particularly weak. Lack of copyright protection does not make code non-free. Public domain source is still free software. A particular output might reproduce protected third-party code, but that requires evidence about that output. It isn't established merely by showing that an LLM was involved. If provenance were the true concern, then allowing some undefined minority of AI-generated code doesn't solve it. A single copied component can create a real licensing problem. So, the argument immediately falls apart when they qualify it with "mostly".

I don't use Codeberg, so I have no personal stake in this, but I'm surprised its community adopted such a vague and practically unenforceable policy. The argument that Codeberg has limited resources and cannot host endless disposable projects sounds legitimate until you consider how this policy could be enforced. Either someone must investigate repositories and infer their production history from circumstantial evidence, which is expensive and unreliable, or enforcement will be selective and complaint-driven.

If resource consumption, abandonment, or low-effort projects are the actual problems, Codeberg should regulate those observable problems directly though I'd argue targeting "low-effort" projects is as problematic as this policy suffering from many of the same issues. As written, the policy seems more likely to punish honest disclosure than to actually prevent harmful or infringing code.

iepathos··on Hacker wipes Romania's land registry database
Do the people who sign sworn affidavits already have to have proven identities? If so, then they're unable to recover from a situation where they lost everyone's identity.
iepathos··on Suspecting AI cheating, Ivy League prof ordered in-person final; scores fell 50%
The article, the teacher, and the general academic community skips the hard question when it comes to AI and that's whether these exams are testing knowledge that is still worth internalizing in the same way?

Academia has a long history of lagging behind acceptance of new cognitive tools where they claim to want to defend the students, but instead defend the assignments of the past at the expense of the students. Calculators were treated as threats to learning, even though they ultimately freed students to focus on higher-level math and provably improved their abilities across many different studies. Internet sources were dismissed as less legitimate than books, as if “published in an outdated book from the 70s” magically made it more trustworthy than the most scrutinized reference sources online.

It is not clear from the article exactly how much of this course falls into that category, but if the answers can be produced trivially with a prompt and chatgpt, then maybe memorizing that material is no longer the right educational target. Academia desperately needs to redesign itself around AI as a cognitive tool students should be trained to leverage. If a question is trivially answered by a prompt with it, then you need harder questions that actually require students to push beyond that. Simply removing AI from the equation, calling it cheating, and pretending that it isn't an ever-present asset people are expected to leverage in real life is naive and just repeats the mistakes of the past.

iepathos··on Microsoft fire idTech team at Id software
Sure, the tweet was about their releases since 2016 when I assume this particular dev was involved, not the original release. To be clear, I'm not saying their games aren't good or even that they didn't have some success. 20 million in sales for their entire franchise isn't bad, it isn't the 500 million in sales we see from CoD or Battlefield, but it isn't bad. I actually liked the games, but claiming they are the "BEST GAMES EVER!" and having the gall to mention Google where no Google results ever show them as the best is where I have an issue. We don't need to spread misinformation like that and if the dev actually believes this I can only assume they live in a bubble.
iepathos··on Microsoft fire idTech team at Id software
Wow, that tweet claiming the Doom series is the best first person action game in the entire industry is crazy. That dev has to be completely disconnected from the rest of the game industry or delusional. No stats support that claim at all. Not player count, not sales, not reviews, nothing. The first Doom was certainly industry defining, but it and its sequels have never been considered the best by anyone except apparently this dev. If they were the best, they probably wouldn't be getting laid off right now.
iepathos··on Zuckerberg says AI agent development going slower than expected
It's not all that surprising that people were worried and believed this. The AI companies and infrastructure companies partnering with them have spent a lot of money and time trying to convince people this is the case year after year. The critical clue people miss is that everyone claiming that has very clear financial incentives to convince people that's the case even when they know it isn't. Anyone who was actually building with LLMs and judging for themselves based on its performance knew fully well that wasn't the case year after year.
iepathos··on Vulnerability reports are not special anymore
"LLMs are as good as almost any security researcher"

Oh really? If LLMs were as good as almost any security researcher then you wouldn't be getting flooded by bullshit reports from them. You'd be receiving legitimate reports instead.

iepathos··on Air France and Airbus found guilty of manslaughter over 2009 plane crash
Ahh good to know, thanks for clarifying.
iepathos··on Air France and Airbus found guilty of manslaughter over 2009 plane crash
That's right, Airbus is responsible for the faulty equipment onboard, not pilot training. Air France is responsible for its pilots' operational training and recurrent training.
iepathos··on Dutch suicide prevention website shares data with tech companies without consent
Gun rights are generally not gone forever. Federal law bars people adjudicated mentally defective or formally committed to a mental institution, neither of which include a temporary mental hold for suicide watch. State laws vary, but none of them have a law where a single temporary hold means "gun rights gone forever." Some states let people go buy a gun the day they are released from suicide watch, despite how irresponsible that sounds.
iepathos··on Darkbloom – Private inference on idle Macs
You can see in their stats view they have a lot of providers/nodes connected but practically no actual demand/consumers. They just launched and I'm sure get providers was top of their agenda, but it's essentially unusable as a provider unless they perform some serious lift to get actual paying customers.
iepathos··on Farmer arrested for speaking too long at datacenter town hall vows to fight
Not quite the same. Here it wasn't just the overreaction from some weak authority figure. The arresting cop had to knowingly violate established laws. The officers who pursued the charge had to have done the same. That's systematic corruption and failure in the local law enforcement who imo all need to be investigated and fired asap. It's less some weak authority overreacting and more like a whole lot of incompetent people who are supposed to uphold the law actively violating it.
iepathos··on Ask HN: Who wants to be hired? (April 2026)
Location: Mountain View, CA

Remote: Yes

Willing to relocate: No

Technologies: Python, Rust, Typescript, Go, Infrastructure, DevSecOps

Résumé/CV: https://www.linkedin.com/in/glenbbaker

Email: iepathos@gmail.com

Hi, I'm a Staff engineer with 14+ years of experience. Spent the last 8.5 years building an early stage startup and following it through acquisition. I supported the post-acquisition transition by training and mentoring offshore engineers and helping maintain continuity as the company shifted from startup execution to standardized enterprise delivery.

My background spans backend engineering, infrastructure, and security, with hands-on work in Python, Rust, and TypeScript. I maintain open source projects and contribute when I can to core Rust projects such as Clap and Cargo. I’m a good fit for teams that need pragmatic execution and someone comfortable owning hard problems across systems, platform, and DevSecOps.

iepathos··on Malus – Clean Room as a Service
This is essentially 'License Laundering as a Service.' The 'Firewall' they describe is an illusion because the contamination happens at the training phase, not the inference phase. You can't claim independent creation when your 'independent developer' (the commercial LLM) already has the original implementation's patterns and edge cases baked into its weights.

In order to really do this, they would need to train LLMs from scratch that had no exposure whatsoever to open source code which they may be asked to reproduce. Those models in turn would be terrible at coding given how much of the training corpus is open source code.

iepathos··on Ars Technica fires reporter after AI controversy involving fabricated quotes
If the Ars Technica editorial process requires assuming reporters don't fabricate quotes, then their process is inadequate. That's like a software company letting junior engineers release directly to production with just a spellcheck and no real process to catch errors. Major publications like The New Yorker, The Atlantic, etc. have a dedicated fact-checking department that is part of the process and needs to give the ok before any article is published. Why is their process so deficient by comparison? Why wasn't there any fact checking?
iepathos··on The United States and Israel have launched a major attack on Iran
The idea that China hasn't 'attacked anyone' in 40 years is factually incorrect. In 1988, they engaged in a deadly naval skirmish with Vietnam over the Johnson South Reef. More recently, the PLA engaged in fatal border clashes with India in the Galwan Valley (2020). On top of direct skirmishes, they have engaged in constant gray-zone aggression: violently ramming Philippine and Vietnamese vessels in the South China Sea, firing water cannons at supply ships, and surrounding Taiwan with live-fire military blockades. That doesn't even touch on the internal human rights abuses against the Uyghurs in Xinjiang. Multiple international bodies and governments have recognized what they are doing to Uyghurs since 2014 as genocide. Finally, it's hard to ignore their devastating handling of COVID-19. The active suppression of information, punishment of early whistleblowers, and refusal to cooperate with international investigations resulted in unprecedented worldwide damage, amounting to an act of gross global endangerment.
iepathos··on Addressing Antigravity Bans and Reinstating Access
Refreshing response from Google especially given the incompetence with which Anthropic has handled bans.
Page 1 of 8Next →