HNHacker News
TopNewBestAskShowJobs

marcusb

3,342 karma · joined August 12, 2016

I mainly do backend development in Rust.

You can find me online at a few other places:

* Email: marcusb@marcusb.org

* Blog: https://marcusb.org

* Mastodon: https://mastodon.sdf.org/@marcusb

Certified “AI hater” — Ars Technica

---

[ my public key: https://keybase.io/marcusb; my proof: https://keybase.io/marcusb/sigs/M6JD8qft2hLYGUHk57yfm5NG9pN-BrilfjCak7rFOl4 ]

submissionscomments
marcusb··on As A.I. makes law firms more efficient, clients ask: 'Where's my discount?'
*outlaw AI-generated legal documents by non-lawyers.
marcusb··on New Jersey fines data center $1.1M after drone pics expose 62 gas generators
It is in the Memphis area - not Nashville - but yes, they use gas turbine generators.
marcusb··on Self hosted email continues to steeply decline
Interestingly, DNS does have such a record (MB,) just never widely used - https://datatracker.ietf.org/doc/html/rfc1035/#section-3.3.3
marcusb··on Anthropic says Alibaba illicitly extracted Claude AI model capabilities
They implemented it. They just couldn't get out of their own way to successfully sell it (See "Dealer's of Lightning"[0])

0 - https://www.amazon.com/Dealers-Lightning-Xerox-PARC-Computer...

marcusb··on Zenzizenzizenzic
Or tried that vocabulary estimator that is currently on the front page (it gave me zenzizenizenic in the last section.)
marcusb··on Efficient method to capture carbon dioxide from the atmosphere
It is used as a shielding gas in some welding processes (notably, MIG welding.)
marcusb··on Children with cancer scammed out of millions fundraised for their treatment
False equivalence. In your straw man, the elephant isn't misled into believing that by posing for a photo it could be "helped," nor is it possible to communicate such an idea to an elephant. In the story, money was raised for the boy's cancer treatment, and that money was improperly withheld, denying him the treatment those funds could have provided. He was harmed by that, and by being misled into thinking he could get treatment by appearing in the video, he was scammed. Lying to the family and stating the funds weren't raised is also scamming them.

But, of course, you know that, but you would rather dig and (try to) play semantic games than admit you are wrong. Do better.

marcusb··on Mozilla's new CEO is doubling down on an AI future for Firefox
Yeah. “We’re not incentivized to push one model or the other,” may be a statement of current fact, not of values.
marcusb··on Children with cancer scammed out of millions fundraised for their treatment
I think the kid in the article who got $27k raised in his name for cancer treatment, received $0 in cancer treatment from those funds, and subsequently died of cancer definitely got scammed.
marcusb··on Async DNS
I'm one of the Hickory maintainers, although I mainly work on the server-side code.

https://github.com/hickory-dns/hickory-dns is our Git repo

Documentation for the resolver including an example: https://docs.rs/hickory-resolver/latest/hickory_resolver/ind...

marcusb··on Rust in the kernel is no longer experimental
https://www.redox-os.org/
marcusb··on After the Bubble
A lot? Also irrelevant. All it takes is one for the statement "nobody can see the bubble" to be false. Take the housing bubble for instance. Do you think the people who called that one were successful purely by chance, or does the fact that a few investors observed that mortgage lenders were underwriting loans to people with extremely poor credit and approving loan applications the lenders knew to be materially fraudulent at a massive scale indicate that the call was more of an educated wager? Did they know to a certainty it was a bubble? No, of course not. Was it a very reasonable guess? Absolutely.
marcusb··on After the Bubble
That's the conventional wisdom, undercut by the fact that people have guessed (and bet their fortunes) that previous bubbles were bubbles well before they popped.

Its more accurate to say that bubbles rely on most people being blind to the bubble's nature.

marcusb··on After the Bubble
> The GenAI bubble is going to pop. Everyone knows that.

I think the first part of this is probably true, but I don’t think everyone knows it. A lot of people are acting like they don’t know it.

It feels like a bubble to me, but I don’t think anyone can say to a certainty that it is, or that it will pop.

marcusb··on Netflix to Acquire Warner Bros
More choice as in “more revenue streams from which to create shareholder value.”
marcusb··on Rsync.net Technical Notes – Q4 2025
Another happy rsync.net customer.

I published my scripts[0] and notes[1] about doing append-only backups with Borg on rsync.net since at the time rclone studio wasn't supported. My strategy is to do Restic backups to a backup server at my house and Borg backups to rsync.net as my offsite backup, so the scripts handle both.

The post I linked above also outlines how I handle expiring old backups (requires either manual action with your privileged key, or a suitably isolated host that has the ability to purge the backups automatically.). You really don't want to fill up your disk (or hit your hard quota) with Borg. Recovering -- even deleting existing backups -- requires a bit of extra space unless you want to rm -rf.

0 - https://marcusb.org/hacks/backuptools.html

1 - https://marcusb.org/posts/2024/07/ransomware-resistant-backu...

marcusb··on Cloudflare outage on November 18, 2025 post mortem
Rust has debug asserts for that. Using expect with a comment about why the condition should not/can't ever happen is idiomatic for cases where you never expect an Err.

This reads to me more like the error type returned by append with names is not (ErrorFlags, i32) and wasn't trivially convertible into that type so someone left an unwrap in place on an "I'll fix it later" basis, but who knows.

marcusb··on Anthropic’s paper smells like bullshit
The security world overemphasizes (fetishizes, even,) the "advanced" part because zero days and security tools to compensate against zero days are cool and fun, and underemphasizes the "persistent" part because that's boring and hard work and no fun.

And, unless you are Rob Joyce, talking about the persistent part doesn't get you on the main stage at a security conference (e.g., https://m.youtube.com/watch?v=bDJb8WOJYdA)

marcusb··on Laptops with Stickers
I used to work for medium/big tech companies (8,000 - 70,000 employees.)

I always had a sticker on my laptop - everybody had the same laptop (or maybe one of two models.) It was a reliable way to quickly identify mine in a big group at a meeting or conference.

marcusb··on Collaboration sucks
I once worked at a place where one of the partners consistently claimed the engineering team over-built and over-thought everything (reality: almost everything was under-engineered and hanging on by a thread.)

His catch phrase was "all you gotta do is [insert dumb idea here.]"

It was anxiety inducing for a while, then it turned into a big joke amongst the engineering staff, where we would compete to come up with the most ridiculous "all you gotta do is ..." idea.

marcusb··on I Am Mark Zuckerberg
Interesting. I've used my personal domain name for email for almost 30 years and I've never had that problem.
marcusb··on Vodafone Germany is changing the open internet, one peering connection at a time
? My comment had nothing to do with Starlink.

Your first example I was referring to - which you've now edited out of the article[0] to be more generic - stated:

> When Deutsche Telekom customers want to watch YouTube, that traffic flows directly from Google's network to Deutsche Telekom's network at a Frankfurt exchange point—maybe four or five router hops, minimal latency, no intermediaries. It's elegant. It's efficient. And it's exactly what Vodafone is abandoning.

Later:

> Deutsche Telekom pioneered this model in Germany, and the results have been catastrophic for customers. Not "slightly annoying" or "a bit slower"—genuinely, documentably terrible.

0 - original here: https://web.archive.org/web/20251107180616/https://coffee.li...

marcusb··on Vodafone Germany is changing the open internet, one peering connection at a time
After using Deutsche Telekom as an example of how great direct peering is, a few paragraphs later the article uses Deutsche Telekom as an example of the dangers of using peering provider intermediaries.
marcusb··on Amazon confirms 14,000 job losses in corporate division
Once a company moves on to recurring, large-scale layoffs justified by vague corporate Mumbo-Jumbo, I think it is safe to assume it is a "day 2" company.
marcusb··on F5 says hackers stole undisclosed BIG-IP flaws, source code
Sure, every little bit helps. But, keep in mind formal verification isn’t going to prevent configuration errors, and it remains to be seen if, for example, automated verifiers can do anything like the sel4 proof at scale. sel4 is tiny compared to most other software systems. There will still be technical avenues to attack, and if those get closed off nation state actors will just go back to spying the old fashioned way.
marcusb··on F5 says hackers stole undisclosed BIG-IP flaws, source code
Mostly I mean they research vulns and buy exploits on the open market, but yes they are also getting backdoors placed in commercial products.
marcusb··on F5 says hackers stole undisclosed BIG-IP flaws, source code
> I agree. I think what we are split on is purpose/intent.

I… don’t think so? Your original comment was that companies claim nation state attack as a way to get government funding. That has nothing to do with assessing blame for an attack.

> Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who?

If you think you as a private entity can defend against a tier 1 nation state group like the NSA or Unit 8200, you are gravely mistaken. For one thing, these groups have zero day procurement budgets bigger than most company market caps.

That’s why companies reflexively blame nation state actors. It isn’t to get government funding. It is to avoid blame for an attack by framing it as something they could not have prevented.

> So we agree?

No, I don’t believe we do.

marcusb··on F5 says hackers stole undisclosed BIG-IP flaws, source code
> I keep seeing it pop up again and again and it only makes sense in that context.

Not saying that these companies would turn down corporate welfare given the chance, but I’ll offer an alternative explanation: it shifts accountability away from the company by positing a highly resourced attacker the company could not reasonably be expected to protect against.

If you have a physical security program that you’ve spent millions of dollars on, and a random drug addict breaks in and steals your deepest corporate secrets people are going to ask questions.

If a foreign spy does the same, you have a bit more room to claim there’s nothing you could have done to prevent the theft.

I’ve seen a bunch of incident response reports over the years. It is extremely common for IR vendors to claim that an attack has some hallmark or another of a nation-state actor. While these reports get used to fund the security program, I always read those statements as a “get out of jail free” card for the CISOs who got popped.

marcusb··on American solar farms
Really? I had no idea! Thanks for clearing that up.
marcusb··on American solar farms
This is a very frivolous argument against solar farms given the amount of noise and other pollution emanating from regular farms.

Farm-scale irrigation is not silent.

Crop Dusters are not silent.

Combines and other tractors are not silent.

Burning fields are both not silent and release a tremendous amount of sooty smoke that spreads far beyond the boundaries of a farm.

Farms make a lot of noise.

Page 1 of 9Next →