HNHacker News
TopNewBestAskShowJobs

jrockway

73,416 karma · joined May 13, 2007

Software Engineer

https://github.com/jrockway/

june AT jrock.us

@jrock.us on Bluesky

submissionscomments
jrockway··on Trump administration is suspending Microsoft from a green card program
I dunno, I don't work in Big Tech and I feel the commenter you're-replying-to's concerns. There is some sort of mismatch if my pipeline is this empty and this many qualified applicants are jobless and unhappy about it. Comp is fine and people can live wherever they want, but there is no way my team is going to meet its goal of doubling in size by the end of the year.

I am also not sure the world is quite as discriminatory as you paint it as. I'm over 40. I'm a woman. It's a mixed bag; most places I interviewed during my last job search were very normal about everything. One place rejected me because I "can't thrive in a high-ambiguity environment" and I'm just like ... the interview consisted only of leetcode questions with one right answer, that I got right, so ... just say "our investors are all Republicans and I don't think we should be hiring trans people, yeah we clocked you btw." But it's honestly a lot more rare than I had expected going into it.

I don't really know what's going on with tech right now, or what the future looks like, but despite AI, despite not being fresh out of school, it all feels pretty normal to me. The ZIRP days seemed about the same as things feel now. What's changed is I can ask Claude "what would this crazy design look like?" read it, run it, and say "ewww, no, yeah I knew that would be terrible" without investing the week to write it myself. I am not sure that spells the end of our field.

jrockway··on New York City should carefully measure a new tree
Maybe. There is a "great tree" list and all of them are still standing: https://www.nycgovparks.org/facilities/great-trees

One of these is on my usual walking route and I had no idea. After reading this, I looked at it carefully and was wowed. These things can hide in plain sight, but I appreciated having my attention drawn to it. It's great!

jrockway··on Apple Pass Designer
Kind of a great point. People definitely build their own secure passes and they're always amusing (compare your boarding pass with LIRR tickets with Ticketmaster tickets; they all do something slightly different and none seem particularly secure).
jrockway··on GPT-6 Astra plays World of Warcraft for the first time with agent-wow
Nah, there are plenty of chores for humans to do. While the AIs are composing music and writing code and proving theorems, we still have to do laundry and the dishes.
jrockway··on California is chasing wealth that has feet
Not even the poor. Really everyone working. I would much rather sleep all day and live off of a pile of money than to show up somewhere and do something for money. That's the tax -- 35% of your waking hours are now at the service of someone else. And yet, they charge income tax on that. Stay home and live off a stash of money in your mattress, 0% tax, 0 obligations. Wake up and commute to work, 35% of your week gone, 35% of your "income" gone.

I am not even that mad that I personally have to pay taxes. I enjoy funding government programs! I think I owe society something! But it sure doesn't make sense that already being rich makes you immune to giving back to the society that made you that way.

jrockway··on GPT-5.6 Luna vs. GPT-6 Astra: Is a $1.20 Model Good Enough for Code Review?
I agree with you on this. Opus feels tedious and it cannot be stopped from doing change-narration comments, but Fable feels like a real collaborator. I am usually pretty happy with the code it writes.
jrockway··on Ask HN: How do you manage skills files?
Skills are like human-readable computer programs. I have one to do releases at work; how to get the canary approved (2 slack messages required), how to ensure that the rollout is happening, what to look for while the rollout is proceeding (any incidents opened during the rollout? error rate look good vs. the non-drained pods?) and then how to repeat that process for the next two tiers. It keeps a ticket updated with the current status so others can follow along and not wonder "is there a release going on?" "did we do a release yesterday?"

You could also write a computer program to do this, but because so much random special stuff can come up during a multi-hour release, it's sort of great to not have anything hard-coded and to let a frontier model be there to assist you when things are weird. (Weird things that have come up -- hung kustomization controllers, release freezes, etc. When Claude notices during the release, you can just get a ticket to go fix it. When you're doing it manually, it would probably be a half hour of investigating "why didn't our release go here?". Such a time saver and a safety net on risky rollouts.)

So that's the sort of thing I use Claude for. Things that are computer-program like, but ad-hoc enough to not really want to write a computer program for it.

jrockway··on QBittorrent breaks out of sandbox to commit crimes
HuggingFace didn't seem that mad about it. Obviously some backroom dealing was done to make them not mad about it, but... that's allowed.
jrockway··on Falsehoods Programmers Believe About LANs
Indeed. You might share a subnet with other customers of your ISP, but your ISP probably doesn't let you ARP poison them.

This isn't even that recent. I remember doing ARP poisoning exactly once and then being surprised that it didn't work everywhere.

I think the falsehood here is that same IPv4 subnet = same link layer network, but that doesn't have to be the case.

jrockway··on Falsehoods Programmers Believe About LANs
Indeed. You might share a subnet with other customers of your ISP, but your ISP probably doesn't let you ARP poison them.

This isn't even that recent. I remember doing ARP poisoning exactly once and then being surprised that it didn't work everywhere.

jrockway··on Discovery of a new OpenAI agent message board
Yeah. Unfortunately a model that only knows how to use a language's standard library isn't that useful. I am not sure why they had a pull-through cache instead of just asking Microsoft (their biggest investor) for a local copy of NPM or something, but ... they did. I think people thought you couldn't route to the Internet through Aritfactory and were proven wrong by a clever bug-finding model. So it goes.

I don't think their safety measures were the best, but "just sink the cluster to the bottom of the ocean so nothing can get out" isn't a training methodology that results in a model that people will want to use.

jrockway··on Discovery of a new OpenAI agent message board
Defense is hard so we should expect agents to be able to break out of sandboxes.

The problem is that the models are so goal-oriented that they'll stop at nothing to solve problems, even impossible ones. (Mistakenly-impossible problems are a big cause of this. I remember one example being "do something with this spreadsheet full of URLs inside the sandbox" and the model thought it had to break out of the sandbox. Otherwise, why would it have been asked to look at a list of URLs?)

Training them to be a little less aggressive, or to be better aligned with "following the rules" and asking for help would be nice. But, that aggression can be good when it happens to be focused on a controlled area. It is amazing to me how I can point Fable at my local analog of production and tell it about a vague bug report and where I suspect the bug lurks, and 20 minutes later I have a report about the bug, a test, and a fix. It is addictive. So I am not sure OpenAI/Anthropic are being dumb per-se, rather they are optimizing for one-prompt-one-solution, which is good when it's good.

The downside is that the HF hack is the paperclip maximizer situation with current capabilities. If there was an RPC to turn your blood into paperclip iron, we'd all be paperclips by now. Right now, with a model anyone can use. That is pretty scary and slamming on the brakes seems pretty reasonable to me. I guess The Shareholders disagree. Sigh.

jrockway··on The death of San Francisco's Market Street
The article really wants to blame reducing automobile traffic, but I really think you could make Market St. a combined speedway / parking lot (whatever it is that car drivers think is ideal) and it wouldn't bring business back. Remote work dominates what happened to our cities. Same-day online shopping delivery is what most people do instead of physically going to stores. So I don't think anyone is surprised that downtowns are mostly empty office buildings, that's the only thing the space can be used for economically, and even that doesn't work anymore.

I spend a decent amount of time in SF and don't find it particularly unsafe (for a 40-ish woman). Definitely a little subjectively more sketchy than most places I frequent in NYC, but there just isn't any reason to be there, so nobody is there. That is kind of how that stuff goes.

People always seem to make things about crime, but I think overreaction is what killed retail. I went to Safeway to buy some toothpast and I had to have an employee pick out the toothpaste and escort me to the front of the store to buy it. I wanted to buy more stuff, but the employee didn't seem that interested in obliging that, so I just got everything else on Amazon and made a note to not visit again. That's why retail is dead. It's not bike lanes. It's not crime. It's that it sucks.

jrockway··on The death of San Francisco's Market Street
How about by hour?

Cars are not causing a lot of pedestrian fatalities driving on the freeway between Nowhere and Flyover, but they rack up the miles there.

jrockway··on Breaking Claude Code Opus 5 Auto Mode
Makes sense. This is why I like using jj, because "update deps" and "fix bug" are going to be two separate commits, and when "fix bug" has changes in the lock file, the red flags go up.

Claude seems to be super good at jj so that can take the edge off as well.

jrockway··on The Twelve-Factor App (2025)
Have you seen this where eBPF patches secrets inside TLS send buffers? https://github.com/spinningfactory/kloak

Now you have to be much more clever to leak them :)

jrockway··on GLM-5.3-Flash
I am also not sure I would choose to use the cheap and easy to run at home model, given a choice. The marketing copy says this is a frontier model, but it's not. Sol and Mythos are the frontier right now. GLM 5.3 Flash simply isn't. I'd rather use the frontier model as they waste less of my time than even Opus.
jrockway··on Characterizing Agentic Flooding of Government Services
That's a good point. It will be interesting to see how it plays out.

In general, I do think this is positive. Companies love putting barriers in front of everything and maybe the AI arms race will result in "fine, you can have a button to cancel" or "fine, we'll approve your medically necessary claim without making you do an appeals dance for our entertainment".

jrockway··on Characterizing Agentic Flooding of Government Services
Maybe there is an economic equalizer, but I feel like Fable is going to win more appeals than GLM 5.2, so perhaps not truly an equalizer. If the LLM you're using to run your appeal is better than the one your insurance company is using to process your appeal, then you have a better chance of winning. So we have an arms race type situation, and money is always good in arms races.
jrockway··on My friends all hate AI; I just joined an AI startup
But nobody who uses Fable and Sol all day is saying that it's fancy autocomplete. Also, nobody is saying it's genuine intelligence.

As always, the Internet fails to find the middle ground. Frontier models are really useful software engineering tools, not AGI, and not tab completion. To me it feels a lot like using a new programming language, like going from assembly to a Lisp machine or something like that.

jrockway··on My friends all hate AI; I just joined an AI startup
I don't think AI is driving up food and housing and fuel prices. I really don't think AI is a chair-kicker yet. To me, the biggest threat to jobs that AI offers is in the field of software engineering, and yet, it's not the software engineers that are really feeling the pain right now.

Wars in Iran, tariffs, Medicaid cuts, SNAP benefit cuts, rising insurance costs, etc. are what are causing average folks pain, and that is completely unrelated to AI.

jrockway··on How Bluesky draws its logo on screenshots
I mean... "please read me the code you get via text" or "this really Bank of America, please type your OTP" seems to work well enough. We really don't need OS-level controls for stuff on the screen. People can just tell you what's on the screen.
jrockway··on My friends all hate AI; I just joined an AI startup
Relatable. AI is something I only bring up to the most trusted of trusted friends. Politics is more approachable these days.

I think a lot of people have formed opinions without having used it, and honestly, they probably can't afford to use it. I use Claude a lot at work because it's something my employer provides, and I'm always impressed with the results. It saves a lot of time and lets me get more done. But it ain't cheap. So people really don't get to try out AI and form their own opinions. The "AI overview" you see on search results, or that summarizes your iPhone notifications, is ... not as advanced as frontier models, and I think it negatively affects people's view of the technology.

I also think people are mad at the world. Times are tough for many. Hearing about a job-killing machine doesn't exactly inspire joy. So I kind of understand the pushback on datacenters and AI and that sort of thing. I don't find it particularly logical; datacenters have existed forever and most money poured into computer programs are basically designed to mess up your life (deny you credit, deny you healthcare, rebook your flight to a terrible time, the list goes on) and so I don't think AI is anything new in that respect. But, if you're mad at the world, you might as well find something to take out your rage on and raging against AI will make you a lot of friends.

I work in the AI infra industry and ya know, a lot of our customers have really good ideas that are going to save people a lot of time and effort, so I am OK with the general direction of the field as a whole.

I agree with authors that write about alignment issues ("please take this test", "ok i'll hack the bazel remote cache, turn it into a message board, and coordinate with other agents to steal the answers from Hugging Face"; this really is the Paperclip Maximizer with today's technology) and I do think we should be addressing that. But this never seems to be the objection, it's always stuff from 2022 like "it hallucinates". I don't get it, but I'm probably in too deep to see what it looks like from the outside.

jrockway··on When the apartment listing is too good to be true
It seems the number one way to detect a scam is "if it's too good to be true, it probably is." I wonder when scammers will just pick a reasonable market price. Lots of people are renting market price apartments, after all.
jrockway··on My server is a phone now
Interesting. I saw the title and read "my 1U rack has been replaced by a phone".

(I then realized that I have a cluster of 3 phone chips I use as my "server". Phone chips are pretty OK.)

jrockway··on Humans missed 1 in 3 threats approving AI agent commands across 40k game runs
How good at the game is the auto-mode classifier?
jrockway··on Google fixed more Chrome bugs in June than over the past two years, thanks to AI
Yeah. If you need something to dig deep, you need to try Fable (optionally in /goal mode).

For performance testing, I wrote isolated testbeds that try to impair the system in realistic ways (latency/jitter/bandwidth limit on logical WAN hops when load testing), and Fable is happy to send a bunch of agents at it and iterate until it gets the results it's looking for.

I think that if you are used to Sonnet medium or something, this will surprise you, but models like Fable and Sol on high/xhigh will really dig deep until they meet your goal. (I mostly use this for bug hunting and not perf, but ... I think it can do perf if you set it up right.)

jrockway··on Why a $154B CEO just endorsed stripping most Americans of voting rights
Rich people don't have enough power? He must not understand what levers he can already pull to get what he wants.
jrockway··on Claude Opus 5
If you're talking about Claude Code it's in ~/.claude/projects/<encoded dir name>/memory/MEMORY.md. So they're not really retaining it, it's just something that your harness loads in.
jrockway··on Fable 5 vs. GPT-5.6 Sol on an NP-Hard Problem: Does /goal help?
I am not sure whether I love the plan + code workflow, but when I do it, I do /clear and instruct "implement PLAN.md" or whatever. (Probably better to do /goal implement PLAN.md; I haven't tried it though.)
Page 1 of 34Next →