HNHacker News
TopNewBestAskShowJobs

locknitpicker

936 karma · joined October 29, 2025

submissionscomments
locknitpicker··on Upgrade your desktop: Ubuntu 26.04.1 LTS is now available
I've installed Ubuntu 26.04 on a desktop I had lying around and things just work. It had 24.04 before, and the update barely registered as a concern. That desktop also ran Windows, and Ubuntu was incomparably snappy, to the point I felt that my typing speed was the bottleneck.

What I don't like about Ubuntu is the halfsnap, half apt nonsense.

locknitpicker··on Upgrade your desktop: Ubuntu 26.04.1 LTS is now available
> I'm curious what the audience is for Ubuntu nowadays? If you use it - why Ubuntu over another distro?

I would frame this the other way around. Why would anyone pick any other distro over Debian or Ubuntu?

locknitpicker··on Cf: The Agentic CLI for the Cloudflare API
> I just tested gcloud (...)

That's fine if all you want to do is put together a nonsensical apples to oranges comparison.

If you actually want to take a look at what kind of cli app Cloudflare can put together, you'd look at the likes of wrangler.

I mean, I'm sure it takes a couple of minutes to find a notable cli app written in your language of choice with is riddled with problems. Don't you agree? Would that serve as proof your language of choice is bad?

Having said that, you should take a look at what kinds of tests you are doing and what kind of values you're seeing. Any http request is expected to take ~200ms to execute, and any app that does any kind of auth verification will do a pair of those at app start. This is before the app does anything useful. Therefore this means you are trying to nitpick over milliseconds in domains where latency alone will be an order of magnitude or two greater than the values you are holding onto as meaningful.

Why do you think the likes of nodejs dominates backend development? It's surely not because of isomorphic JavaScript, it's something else.

locknitpicker··on America.gov
> america.gov = 25MB (before you start scrolling)

Yuge.

So notable, they are considering renaming JavaScript to AmericaScript.

locknitpicker··on DeepSeek Elastic Compute (DSec)
> If you're confused about who to contact to follow up on the ideas of a particular paper then write to the first author, or whichever author is listed as the contact person.

That just goes to show how much you understand the topic. The leading author is usually the institutional leader, and in paper mills it's frequently the guy who stands to benefit the most from the scam. Not the guy who actually did the work.

So now that you missed that one option, what's your plan? To walkt through the hundred names in the list?

locknitpicker··on Cf: The Agentic CLI for the Cloudflare API
> Well, anything less susceptible to supply-chain attacks, obviously

Supply chain attacks are a factor only as far as a programming language supports modularization and has a large ecosystem. I mean, wasn't rust in the news recently due to cargo being used to execute supply chain attacks?

locknitpicker··on Cf: The Agentic CLI for the Cloudflare API
> Choice of tech stack is not merely a question of performance, but also portability and packaging.

Yes, and clearly typescript is an established tech.

Just look at Cloudflare's wrangler cli.

Everything else is nonsense.

> This is an argument in favor of a language like Go (...)

Not really, in the sense that a myriad of alternatives would also meet the same bar,thus its stupid to frame it as "language X can do this, so language X should do it".

The bar is higher than that.

Typescript works well. Cloudflare already has a lot of experience using typescript to develop cli apps that hit their APIs.

Everyone just call down with the bike shedding. You're wasting everyone's time.

locknitpicker··on Cf: The Agentic CLI for the Cloudflare API
> Code should be written for the user.

Yes, and the user wants to use a command line app, regardless of what's running underneath.

locknitpicker··on Cf: The Agentic CLI for the Cloudflare API
> It's not just the complexity. You're also vulnerable to supply chain attacks via NPM.

Oh you mean like the attacks that occur in Rust's cargo?

https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on...

locknitpicker··on Cf: The Agentic CLI for the Cloudflare API
> Is this sarcasm? We’re talking about a CLI.

This is precisely why this blend of comments is insane.

All the CLI does is take command line arguments, put together requests based on them, send them to an API, get the responses, do mild transformation on the responses,and output it to stdout/stderr.

Pretty much any choice of tech stack will work well. This is not rocket science. It's pointless to talk about optimized solutions. It's a complete waste of time.

locknitpicker··on Cf: The Agentic CLI for the Cloudflare API
> 1. There's always a possibility they evaluated Rust / Go, concluded the agentic code in those languages is less maintainable / productive (for AI agents) than typescript, but didn't spell it out to avoid internet flame wars.

This is a testament of how toxic the fanboys behind some of these language bandwagons became: people avoid mentioning their precious little tool wasn't the top choice to develop a project, because a mundane technical decision can gather so much vitriol from these types that a flame war is bound to happen.

locknitpicker··on Cf: The Agentic CLI for the Cloudflare API
> I don't understand why this is written in Typescript

I suppose you're not very familiar with typescript then.

Listen, all this CLI app does is serve as an interface to send requests to the Cloudflare API. This means it only does things like sending HTTP requests, and outputting JSON. The cli app also needs to run on multiple platforms. Performance is not an issue or a concern.

I'd frame this the opposite way: what better tool do you think there is for this purpose other than TypeScript?

On top of that, there's the fact that Cloudflare's core services run on V8. If there is anything this company has, it's people familiar with JavaScript and TypeScript.

locknitpicker··on DeepSeek Elastic Compute (DSec)
> It’s top comment because it’s anti-Chinese.

You need to tighten up your tinfoil hat. When HN features all the discussions on OpenAI's shenanigans on Navier-Stokes, you weren't seeing claims this was anti-US.

locknitpicker··on DeepSeek Elastic Compute (DSec)
> Why is this the top comment? Many of the comments, as well as this one, have no relation to content and only mention a triviality

This is hardly a triviality. If you are interested in a topic and you find a paper interesting, more often than not you are interested in reaching out to the author.

If a paper features a list of authors that outnumber the paper's pages 10-to-1, it's a major red flag, and it's quite plausible and expectable that 99%of the names in that list had zero input and might even have zero contribution to give to the topic. I'd even argue it's a kin to academic fraud.

By the way, the same goes for those researchers who work on paper mills, and manage to rake in production metrics that go well beyond an article per day.

locknitpicker··on C's Flexible Integer Sizes Were Not a Design Mistake
> The parent is completely right in the sense that for actually portable C code it was always better to use fixed-width integer types which were chosen for the problem to solve instead of target hardware capabilities.

You're confusing things. It's one thing to claim that either they never used a feature or they even have a personal preference to do things one way or another.

Another entirely different thing is to proclaim a programming language designed to target any conceivable CPU architecture somehow no longer needs to support basic cpu arch traits such as word size.

As I pointed out,there are still processors being sold today that do not support 32-bit ints. If you expect C to be able to target these architectures, obviously this feature is still a critical feature.

Also, people who maintain yesterday's systems that require non-32bit ints still need to work on them.

Chesterton's fence is still relevant. Why are we pretending that it's ok to mindlessly proclaim a feature is not requires because we don't understand why it was necessary to begin with?

locknitpicker··on C's Flexible Integer Sizes Were Not a Design Mistake
> At that time, 36 years ago, the C flexible integer sizes were already obsolete.

This is a highly ignorant comment. You're confusing the fact that you only had to work with a single target architecture with the whole concept of multiple processor architectures being somehow obsolete, as if there was a sudden law of nature that forced every single computer, being full blown HPC stuff or small microcontrollers used in embedded applications.

Take a look at arduino. They still have 16-bit models out there. Also noteworthy, it seems some DSPs also have ints larger than 32 bits.

locknitpicker··on Unsealed Briefs in Authors’ Case v. Microsoft/OpenAI
> Newly released court filings quote an OpenAI researcher saying: “I was just worried about optics (...)"

As a side-note, most orgs already cover the need to STFU in their training material for new hires, particularly how personal comments should not and cannot represent the company. I'm sure this lawsuit will be explicitly mentioned in upcoming versions of this sort training material in multiple orgs.

locknitpicker··on Ollaya – Ollama for open-source, Jev-style decision models
> I'm not sure what this means for AI startups if their innovations can be copied by OSS so quickly (what, like 2 weeks?).

My thoughts too. It sounds like a minor feature being framed as a whole new business.

Then again, Dropbox and Docker are too.

locknitpicker··on US lawmakers aim to keep China's tech out of sensitive government systems
That just goes to show the danger presented by using AI and chatbot services provided by US companies.
locknitpicker··on GitHub has not removed malicious imitation software after 3 weeks
> Prioritization and escalation exists in most companies.

Yes, indeed public awareness of a problem affects how an issue is reprioritized. Some companies even employ web scrapers to do sentiment analysis at each release, and visible issues do get bumped to high priority.

It's amusing how some people in this thread try to pretend this doesn't happen, and make these bold assertions with a straight face in replies to people who were in actual meetings where issues were escalated because of this.

locknitpicker··on GitHub has not removed malicious imitation software after 3 weeks
Yes,evidently bandwidth from HN unblocks takedown requests of malicious content.
locknitpicker··on ArXiv receives multiyear commitments to support it as an independent nonprofit
> The preprint papers on arXiv are like 99% the same as the published versions, except they're free instead of locked behind a multi-thousand dollar/year paywall.

I don't think you fully understand the problem. It doesn't matter if you can find in arxiv a preprint of an article published on a reputable journal. What matters is that right besides that paper you will find a dozen other papers that can be utter nonsense generated by a poorly calibrated slop factory. You don't find those in papers published in respectable journals which enforce double blind peer review and were filtered for relevance and quality.

It's that peer review process that creates value and relevance. Otherwise all you have is a glorified file server.

locknitpicker··on ArXiv receives multiyear commitments to support it as an independent nonprofit
> Without arXiv we'd have had a blog post and nothing citable.

Arxiv is a blog. Your paper is a blog post which is just as citable and as peer reviewed as blogspot.

locknitpicker··on ArXiv receives multiyear commitments to support it as an independent nonprofit
> How is science to evolve if good research requires $49 a pop to view?

This kind of criticism is misplaced. The answer to reputable journals being held hostage by the likes of Elsevier is not dropping peer review and dump articles in a blog-like site such as Arxiv.

I'm confident the bulk of academia would love to move away from Elsevier et al and have free open journals as their discourse venue. However, the publish or perish situation created pressure to count only the papers published in reference publications in their productivity metrics, and those were hijacked by for-profit editorial companies which unscrupulously abuse their dominant entrenched position.

And publishing on Arxiv does not change that.

locknitpicker··on Starlink ground station in Poland hit by fire in suspected arson attack
> Try telling this to the far-left.

Russia has indeed been funding and supporting fringe/extremist organizations throughout Europe.

https://www.euronews.com/2025/10/29/from-moscow-with-chaos-h...

However, even those parties that toe Moscow regime's line don't want to be caught supporting it directly due to the expected backlash.

That goes to show how much "the west" cares about what Moscow says.

locknitpicker··on Starlink ground station in Poland hit by fire in suspected arson attack
> And the west (...)

Frankly, "the West" doesn't care about Russia. They were a gas station masquerading as a country, but now they aren't even a gas station. Let's just fund Ukraine to the gills and in no time they won't even be good for petty vandalism.

locknitpicker··on Starlink ground station in Poland hit by fire in suspected arson attack
> The Nord Stream incident being a fine example.

If you know something the world doesn't know, you'd better get cracking at updating the Wikipedia article documenting the issue.

https://en.wikipedia.org/wiki/Nord_Stream_pipelines_sabotage

locknitpicker··on Starlink ground station in Poland hit by fire in suspected arson attack
> My understanding is that increasingly “adversaries” who may or may not be Russia simply pay local gangs/thugs/idiots to do it.

Yes, and the playbook extends to some anti-war orgs throughout Europe who play the role of useful idiots by advocating things such as a) pressure your government to stop supporting Ukraine, b) force Ukraine to capitulate and agree to Russia's demands. They do so under the guise of "no to war, yes to peaceful negotiation" but the way they neglect Ukraine's best interests and push Russia's maximalist agenda is pretty telling.

locknitpicker··on 28% of job postings on company career sites have been open over 90 days
> People used to spend their entire careers at a single company. Something changed, and it wasn't worker attitude.

The US-style neoliberal attitude towards decimating the workforce at a drop of a hat for PR purposes does have a chilling effect on any employee's trust.

But don't fool yourself: one of the most important tools anyone has to improve their life and wellbeing is the ability to switch jobs. It can create career opportunities you would otherwise not have, and even unblock career progression by sidestepping your current job's corporate constraints.

locknitpicker··on 28% of job postings on company career sites have been open over 90 days
> Perhaps the armed forces are doing something right, and the tech industry is not.

This shows some ignorance on the history of work relations. The bad old days of industrial guilds and company towns are not renowned for quality of life and independence. Your life was tied to the company, and all you could aspire to do in your life would be to toil in the same low paying job while mixing up your corporate structure with your life's social structure. If god forbid you lost your job, you and your family would lose your whole life.

Tell me how this is doing things right.

For those in the US to understand, see how your access to healthcare is tied to your employer, and the impact this have on your life of you are forced out of your job. Now extrapolate this to every single aspect of your life.

Page 1 of 31Next →