HNHacker News
TopNewBestAskShowJobs

lima

8,863 karma · joined May 17, 2016

submissionscomments
lima··on Microsoft killed FoxPro in 2007. Anyway, here's FoxPro revived
What's wrong with the Sigstore ecosystem? Why reinvent this wheel in particular?
lima··on On the Navier–Stokes Millennium Prize Problem
They may still train on it if you submit feedback or flag a safeguard. The terms are a bit fuzzy on this.
lima··on Actively exploited sandbox RCE in all Chromium versions
Inside the JS sandbox, not the browser's outer containment sandbox.
lima··on Actively exploited sandbox RCE in all Chromium versions
That blocks all sorts of abuse, but a targeted exploit would be delivered on a clean domain.
lima··on Actively exploited sandbox RCE in all Chromium versions
It would be chained with a separate 0day sandbox escape.
lima··on Actively exploited sandbox RCE in all Chromium versions
uBlock Origin won't help with this kind of targeted exploit, and Firefox has a much worse security track record.
lima··on Actively exploited sandbox RCE in all Chromium versions
Which browser has a better security track record?
lima··on Hackers had a live feed of every ID verification company scanned for over a year
eID PKIs have very little in common with the web PKI. There's a national root of trust with strong attestation. It's a very simple trust relationship. You already trust the respective government to issue IDs.

Plenty of European countries have an eID CAs and it works fine. The PKI part is a solved problem.

Doesn't even need ZKP, the CA can just issue an attestation.

lima··on At-home test for infected ticks could improve Lyme Disease diagnosis
Yes, if you're unable to be polite about it, just don't comment and/or email the moderators. Your comment would have been informative and well-received without the snark.

You were right to call out the other person for trivializing the risks of tick bites, just assume good faith and be kind.

lima··on At-home test for infected ticks could improve Lyme Disease diagnosis
TIL about Ticktogs. Thanks!
lima··on At-home test for infected ticks could improve Lyme Disease diagnosis
Be careful with the dismantling, if it's a used test, you will likely end up with DNA amplicon contamination which is extremely hard to get rid of.
lima··on At-home test for infected ticks could improve Lyme Disease diagnosis
HN has very specific rules for this: https://news.ycombinator.com/newsguidelines.html

You don't respond to them at all, flag the comment, and/or email the moderators.

Being snarky does not contribute to the discussion and gets your comments flagged.

lima··on At-home test for infected ticks could improve Lyme Disease diagnosis
Lucira did that, but IMO it's quite wasteful. LAMP reactions don't need much, so it's best to make a cheap reader like Metrix or Pluslife so the tests can be less expensive.
lima··on At-home test for infected ticks could improve Lyme Disease diagnosis
Antibiotics aren't free of risks to the patient either, including doxycycline. There's always a risk tradeoff.
lima··on Tracking down the 16-year-old WAL-reset SQLite bug
There's also the more fundamental issue that Postgres - unlike something like Yugabyte - does not use a distributed consensus algorithm for writes and can lose committed writes during network partitions.

But of course, neither does Tailscale's weird DIY contraption.

lima··on At-home test for infected ticks could improve Lyme Disease diagnosis
And tick-borne encephalitis, in regions where that is endemic.

No need to be rude, though!

lima··on At-home test for infected ticks could improve Lyme Disease diagnosis
Ticks climb low vegetation (not just grass) and wait for a host to pass by ("questing").

If you're going to disagree with basic textbook biology knowledge, the burden of proof is on you.

lima··on At-home test for infected ticks could improve Lyme Disease diagnosis
CDC recommends prophylaxis only if the tick is engorged. In my country, guidelines do not recommend prophylaxis at all (for better or worse - personally, I would take a single doxycyclin dose for a >24h high-risk tick bite, Lyme is no joke).

However, guidelines universally recommend against testing ticks. For instance, IDSA says this:

> Knowing tick characteristics (ie, species, life stage, and an assessment of the degree of blood engorgement) is helpful for anticipatory guidance and in determining if antibiotic prophylaxis to prevent Lyme disease is appropriate [127]. Tick identification is available in most commercial laboratories and at some local health departments. Studies from the United States and Europe have shown that detecting B. burgdorferi sensu lato in Ixodes spp. ticks, however, poorly predicts either subsequent disease (0–12.4%) [126, 128–133] or asymptomatic seroconversion (0–4.7%) [126, 129, 130, 132, 134]. This is likely due to a variety of factors that influence the likelihood of transmission and the observation that most Ixodes spp. ticks discovered by patients have been attached for <48 hours [61, 62, 135].

(https://www.idsociety.org/practice-guideline/lyme-disease/)

The point is that the test is likely not useful to reliably inform any sort of prophylactic treatment, especially if the risk of transmission is high enough to warrant prophylactic treatment in the first place, in which case the PEP is indicated regardless of the tick test.

Sure, it modifies the prior probabilities, but what's the clinical significance of that?

lima··on At-home test for infected ticks could improve Lyme Disease diagnosis
Ticks do not drop from trees.
lima··on The First At-Home Test for Infected Ticks Could Improve Lyme Disease Diagnosis
> But you would know whether you needed to even book an appointment.

Only if the test is sufficiently accurate to rule out transmission. Even molecular tests can't reliably predict that.

lima··on The First At-Home Test for Infected Ticks Could Improve Lyme Disease Diagnosis
Yes, but this test cannot diagnose Lyme in humans.
lima··on At-home test for infected ticks could improve Lyme Disease diagnosis
Unfortunately, there are major issues with this approach.

The vendor claims "lab-level accuracy" (conveniently omitting the actual accuracy numbers), but the test is a lateral flow test, which means its Limit of Detection is going to be orders of magnitude worse than molecular tests. Tick tests do not require FDA clearance, so their claims are most likely unreviewed.

Existing lab tests for ticks are almost universally based on PCR.

Ticks are small (especially nymphs) and extracting enough material can be tricky even for molecular testing, so I can't imagine an LFT test working terribly well, especially for nymphs, which are responsible for a lot of Lyme infections due to being easy to miss.

The other, bigger problem is that the test result is mostly useless.

The risk of Lyme transmission from an infected tick ranges rougly from <1% for a fresh bite (<24h) to ~10-25% once the tick is engorged (72h+). A positive tick test result would be insufficiently predictive of Lyme disease transmission on its own to justify taking antibiotics in most cases in the absence of other symptoms.

And you can't trust negative results either due to limited sensitivity, so you can't rule out transmission either.

In my opinion, tests like this can lead to worse overall health outcomes due to unnecessary treatment or withholding prophylaxis from someone who otherwise qualifies.

lima··on DeepSeek V4 Flash 0731 Intelligence, Performance and Price Analysis
Bandwidth is really cheap when you run your own infra
lima··on Codex Resets
It's a competitive market. Kimi K3 has almost reached parity with Opus.
lima··on What AI did to stackoverflow in a graph
It always worked like that
lima··on Hackers shoveled snow for company, were rewarded with network admin access
Even if you can't authenticate at the application level, it's still much better to encrypt/authenticate traffic on the wire (using a VPN or something like Tailscale) instead of 802.1x auth.
lima··on OpenPrinter
Non commercial licenses are not generally considered open source
lima··on Hackers shoveled snow for company, were rewarded with network admin access
Google solved credential phishing a long time ago using hardware tokens (gnubby - the predecessor to FIDO/U2F/Passkeys...).

There's other types of social engineering, but phishing is mostly an engineering issue.

lima··on Hackers shoveled snow for company, were rewarded with network admin access
Probably 802.1x, but it's easy to bypass if you have access to an authorized device. This kind of authentication has to be done at the application level, treating the network as a perimeter doesn't work.
lima··on Hackers shoveled snow for company, were rewarded with network admin access
The company also should have restricted network access to the port in the conference room so that an unknown device like a Raspberry Pi could not make an Ethernet connection from that spot

Bad take - the actual problem is that there was a trusted network in the first place. This kind of network access control is trivial to bypass, and trusted devices can get compromised.

Page 1 of 34Next →