HNHacker News
TopNewBestAskShowJobs

lima

8,865 karma · joined May 17, 2016

submissionscomments
lima··on Hackers shoveled snow for company, were rewarded with network admin access
The company also should have restricted network access to the port in the conference room so that an unknown device like a Raspberry Pi could not make an Ethernet connection from that spot

Bad take - the actual problem is that there was a trusted network in the first place. This kind of network access control is trivial to bypass, and trusted devices can get compromised.

lima··on Postgres transactions are a distributed systems superpower
This. It's easy to forget that Postgres is fundamentally a single-node database without distributed transactions. It won't pass the Jepsen test suite with multiple nodes. DBOS, Temporal and friends inherit this limitation.

Something like Restate actually implements distributed transactions.

lima··on Google copybara: moving code between repositories
Gerrit's new UI comes pretty close, and it's also what Google uses for projects living outside of google3.

GitHub's PR review workflow is archaic in comparison, especially now that every page takes 2-3 seconds to load.

lima··on Google copybara: moving code between repositories
Don't worry, they accept PRs on that repo. They just merge them internally and then re-export them.

There are some variations, but this is generally the same with all open source projects which live in their internal monorepo, such as gVisor or Bazel.

lima··on AWS Bedrock to require sharing data with Anthropic for Mythos and future models
Yes it will, there's a clear purpose and the customer explicitly agrees.
lima··on AWS Bedrock to require sharing data with Anthropic for Mythos and future models
Fable on GCP requires accepting a 60-day retention policy: https://cloud.google.com/terms/advanced-ai-safety-addendum

I don't think it mentions sharing the data with third parties such as Anthropic?

lima··on Websites have a new way to spy on visitors: analyzing their SSD activity
Higher IO latencies in HDs might actually make this attack easier - more contention means more bits of data.
lima··on A more efficient implementation of Shor's algorithm
Shor published multiple quantum algorithms, including one for discrete logarithms. The term is sometimes used interchangeably.

They're closely related, ECC and RSA are both instances of the hidden subgroup problem.

lima··on Amateur armed with ChatGPT solves an Erdős problem
> How do you know the clanker respects the instruction not to search the internet?

You can't, but given that it's a previously unsolved problem, it doesn't seem relevant? (nor are the author's potential biases - the claims are easily verified independently)

lima··on Claude loses its >99% uptime in Q1 2026
We tried this, but the quota for Opus models defaults to 0 on VertexAI and quota increase requests are auto-rejected.

Any tips?

lima··on Claude loses its >99% uptime in Q1 2026
No, unless you count tricks which are explicitly against ToS
lima··on How BYD got EV chargers to work almost as fast as gas pumps
They use a buffer battery, it's quite feasible with that.
lima··on OpenCode – Open source AI coding agent
You can still use OpenCode with the Anthropic API.
lima··on Anthropic takes legal action against OpenCode
Fun fact: In Germany, the civil courts will usually take the case anyways if it has merit, but the winner ends up paying for the whole lawsuit if they failed to make an effort to resolve the case before suing.
lima··on German police probe student poster slur against Merz
And Hungary is pretty much a rogue EU state - their government did go full authoritarian and is aligned with Russia.
lima··on Stolen Gemini API key racks up $82,000 in 48 hours
It's true, neither AWS nor GCP support spending limits. Only alerting.
lima··on Hetzner Prices increase 30-40%
Everything gets more expensive?
lima··on We hid backdoors in ~40MB binaries and asked AI + Ghidra to find them
How does this approach compare to the various Ghidra MCP servers?
lima··on Gentoo on Codeberg
> But the implementation of Gerrit seems rather unloved

There are lots of people who are very fond of Gerrit, and if anything, upstream development has picked up recently. Google has an increasing amount of production code that lives outside of their monorepo, and all of those teams use Gerrit. They have a few internal plugins, but most improvements are released as part of the upstream project.

My company has been using it for years, it's a big and sustained productivity win once everyone is past the learning curve.

Gerritforge[0] offers commercial support and runs a very stable public instance, GerritHub. I'm not affiliated with them and not a customer, but I talk to them a lot on the Gerrit Discord server and they're awesome.

[0]: https://www.gerritforge.com/

lima··on HackMyClaw
Clearly, convincing it otherwise is part of the challenge.
lima··on Ghidra by NSA
This is changing, Ghidra is increasingly replacing IDA for commercial work.
lima··on I want to wash my car. The car wash is 50 meters away. Should I walk or drive?
LLMs don't really know why they got something wrong, so unless it had access to the original chain of thought, it's just guessing.
lima··on It's 2026, Just Use Postgres
It's really the same thing. Network partitions can (and do) occur within a single DC.

> If your network is down, your clients can't connect DB too, and nothing works

This sounds simple, but can only be achieved with high certainty using distributed consensus.

lima··on MinIO repository is no longer maintained
It's complex, but Ceph's storage and consensus layer is battle-tested and a much more solid foundation for serious use. Just make sure that your nodes don't run full!
lima··on Components will kill pages
> AI first websites will get so popular that browsing sites manually will look like trying to use a text only browser in the JavaScript world.

That might be great for accessibility, though.

lima··on It's 2026, Just Use Postgres
Reliable networks don't actually exist[1].

Clearly, it's possible to reduce the risk to the point where many companies are willing to accept it, but it's still a problem and comes with high operational costs. And for some use cases (like finance), even a small risk of undefined database behavior or lost writes is unacceptable.

The future are distributed databases with consensus, and unfortunately, Postgres isn't there yet.

[1]: https://aphyr.com/posts/288-the-network-is-reliable

lima··on It's 2026, Just Use Postgres
Postgres replication, even in synchronous mode, does not maintain its consistency guarantees during network partitions. It's not a CP system - I don't think it would actually pass a Jepsen test suite in a multi-node setup[1]. No amount of tooling can fix this without a consensus mechanism for transactions.

Same with MySQL and many other "traditional" databases. It tends to work out because these failures are rare and you can get pretty close with external leader election and fencing, but Postgres is NOT easy (likely impossible) to operate as a CP system according to the CAP theorem.

There are various attempts at fixing this (Yugabyte, Neon, Cockroach, TiDB, ...) which all come with various downsides.

[1]: Someone tried it with Patroni and failed miserably, https://www.binwang.me/2024-12-02-PostgreSQL-High-Availabili...

lima··on It's 2026, Just Use Postgres
Postgres is not a CP database, and even with synchronous replication, it can lose writes during network partitions. It would not pass the Jepsen test suite.

This is very hard to fix and requires significant architectural changes (like Yugabyte or Neon have done).

lima··on Lessons learned shipping 500 units of my first hardware product
500 was just their first batch.
lima··on Autonomous cars, drones cheerfully obey prompt injection by road sign
Waymo works just fine in poor weather and at night, and it does not rely on end-to-end VLMs that would be vulnerable to this attack.

They have coexisted with humans just fine over the past couple years.

← PreviousPage 2 of 34Next →