HNHacker News
TopNewBestAskShowJobs

kay_o

328 karma · joined December 31, 2025

Disclosure: SDE at Riot. The views and opinions expressed here are my own and do not represent those of my employer, any statements made are in my personal capacity only.

I do not comment on any post that may be conflicts of interest.

submissionscomments
kay_o··on Fable 5.1 Solves the Cyphral Distich, a 370-year-old cipher
on older gemini models ide have to actively give them encouragement and/or easy bait problems that they can correctively solve without issue to avoid runaway spiraling into "i'm useless and i want to kms" behaviour with complex use case.

I have not seen this in other models.

kay_o··on Growing proof that autonomous cars save lives
I am not saying anything is ok, where did you read that?
kay_o··on Growing proof that autonomous cars save lives
> There's no reason for that person to be allowed to operate a vehicle

Doesn't much of america outside of cities also have the secondary problem of you physically cannot feed yourself, get to appointments, or do anything without operating a vehicle?

kay_o··on A Tesla ran a stop sign and killed a man, Full Self-Driving/Autopilot was on
Imho part of isuse here is that you cannot "partial AV" it.

You cannot have a car that will EVER need you to intervene or else it does not work because of awful human nature. The amount of tesla uber drivers ive had literally browsing tiktok, watching youtube UNTIL the car beeps that it is a green light detected, then they immediately hit the accelerator before looking up is ridiculous. You cannot have a half ass "autopilot" driving experience where you are expected to zone out and then be expected to take control within a millisecond during uncertainty. It does not help that FSD, AP, aAP, bAP, the model, whether the car is visual only all apply differently

kay_o··on Nitter and XCancel resume service after legal advice
Threat model a bit different, they can just request xcancel.com/unique-string and check what IP or account requested unique-string IMO
kay_o··on Ask HN: Do you route only certain websites through a VPN?
What about this can't be resolved by a PAC-file?
kay_o··on Wk. 6 of Vibecoding an MMO
Probely because that is the entirety of it. There is zero story or creativity or anything else that goes into an actual game, virtually nothing is named and any that has is a simply word or two jammed together into a name -- the player guide is written in claudish and has a literal table of the number of roads.

I don't think this is so much a game as a figure out how much can be vibecoded, such a tech demo rather of an engine

kay_o··on Asked Reddit support to give me API key so I can delete my data. They refused
If you are caught midway, you get banned for abuse/ToS, and you are not allowed to delete/edit your comments-account if you are unable to sign in. (I am guessing they are retaining data under some bullshit about gdpr legitimate interest in preventing abuse)

Rate limits are also quite low so it might take weeks to delete. Many subs will automatically ban you if you edit a comment to say something like 'redacted by' (ex: https://www.reddit.com/r/ModSupport/comments/1t1fekj/redact_...)

kay_o··on Claude Fable 5.1 and Claude Mythos 5.1
When doing basic CRUD apps I can count on fingers the amount of times guard rails haven't tripped and ended the session
kay_o··on [dead]
It's usually wrong.
kay_o··on Ask HN: Are Prompt Injections "Malware"?
In this specific case, they are already trespassing to be able to read the sign against the owner's wishes, are they not? The sign is only placed in a hidden corner visible by trespassers and not visible to any regular customer.
kay_o··on Ask HN: Is .org now Trump-controlled?
com net org org has always been owned and managed by the US
kay_o··on Ask HN: Are Prompt Injections "Malware"?
It's not malware. You chose to read their site.
kay_o··on Ask HN: How to break Claude Code addiction?
Is this work related or addiction related? You are repeatedly pulling a slot machine in hopes for a jackpot of working usable code, something which does not come up just often enough to require another pull of the conversation turn.

Claude does not have a sense of time. What is stopping you from not talking to it until the next day?

kay_o··on Amazon now hides all customer reviews on products
I can't tell if they're trying to fix it with slop now but clicking the number of reviews now jumps below the description. To nothing.

Things are going great

kay_o··on Amazon now hides all customer reviews on products
Presume this is an experiment or phased rollout.

I was just on Amazon and only the first page of reviews are visible if logged in and no reviews are visible if logged out.

edit: It seems badly done too as the (140) count next to the stars still links to the review section below the description's anchor but simply does nothing onclick due to the fact that the whole destination div is gone.

kay_o··on I keep getting flagged for AI, but I suck at writing. How can I solve this?
> I'm not asking it to rewrite. I'm asking it to fix my spelling,

No matter what you demand, LLM will rewritten, no matter how you tell it not to, it will be rewritten. Your only option is to use traditional corrections such as in Word. LLM will not translate as is.

kay_o··on Fable and the end of the free lunch
I don't even need to tiptoe ! Not being there and not prompting anything is enough to trigger safeguards.

Having not asked a single security question it will write wildly vulnerable code, go back and fix it, and guardrail itself out of existence after charging me a large sum with no refunds for no output and having not fixed it because that might be secuirty adjacents.

And if it doesn't do this you end up with code that has such holes, store xss , no authz ... if it does not go back and notice it has written bad code.

Since they hide thinking and reasoning from the user (who is also paying for those tokens) it is a black box what is triggering it, has the LLM this time thought of "Oh, this has XSS" and used a bad dangerous word such as XSS, while the previous conversation did not ?

kay_o··on Ask HN: OpenCode no longer including DeepSeek?
> They seemed to suggest they were running it on their own hardware?

Where did you see this? I was to manually opt in to "allow models hosted in China" and there is writing about how their no data retention agreement with DeepSeek is only temporary -- both things such that have an implication that they are not running it inhouse.

kay_o··on Ask HN: OpenCode no longer including DeepSeek?
What plan do you use at Fireworks? I've been rugpulled multiple times on their Fire Pass subscription
kay_o··on Degraded performance for multiple models
It definitely isn't but Claude for some very unique reason enjoys to overthinking and go on side quests in the stupid ways I've not seen Codex, DS, Kimi, Mistral do at equivalent effort and thinking setting.
kay_o··on An update on leaving Gmail for Fastmail
I use mailboxorg its acceptable.

The webmail has io.ox in the URL so I assume it is hosted ox (www.ox.io of softwares) which is SIGNIFICANTLY worse performance and usability wise compared to the Fastmail webmail -- I don`t use SMTP/IMAP so I do not know what that is like. Routinely on restricted networks that only allow HTTP/HTTPS so it is a webmail only experience opinionated in mine.

kay_o··on The AI Credit Resale Economy
This is what every chinese "credit reseller" is doing, selling all the prompts and responses to labs in addition to selling quanted kimi/ds/etc as opus/fable
kay_o··on Ask HN: Why was my Show HN flagged?
AI slop and you do not contribute other than self promotion.

Yes it is promotion.

kay_o··on What Happened to HackerOne?
My largest problem with H1 is how braindead scripted/AI their triage is.

- Starting scenario: no way to contact a company outside of H1 (or some other managed programme)

- The company is compromised, their customer support has no idea what this means, they have no security.txt or any other security contact

- I have explicitly told H1 to just forward it with no bounty, I don't want a bounty, only remediation, I do not care about a bounty or any reward

- H1 closes as "not eligible" and tells me to not submit stuff I can't prove it's my compromise by putting my username on it

- Corporate server is still compromised and being used as a proxy to brute force my services

kay_o··on Is Cloudflare classifying opencode.ai as malware?
It is here: https://radar.cloudflare.com/scan/08d947f4-488e-486a-abfc-42...

It is also flagged on urlhaus.abuse.ch and a few others

kay_o··on SFR (French Internet provider) is blocking opencode.ai
Multiple (major) services are detecting opencode's domain as malicious. Presumably SFR uses those feeds. Check virustotal it the URL
kay_o··on Is Cloudflare classifying opencode.ai as malware?
Multiple services are detecting opencode's domain as malicious. Cloudflare uses those feeds. Check virustotal it the URL
kay_o··on Ask HN: Is Reddit trying to kill old Reddit?
You are a bad user to them. You are not a high value user that is valuable, registering with your real, non throwaway email that consumes meme slop and stolen content without ad blockers.
kay_o··on Tell HN: Our paid Claude AI subscription unavailable >1 week and no support
It is nothing. There are many individuals that run 10 seats, not even business, and unless you are paying API per token rates you are a loss already without answering a support ticket ! Unfortunately ...
Page 1 of 6Next →