HNHacker News
TopNewBestAskShowJobs

mirashii

2,652 karma · joined May 6, 2012

email: me at rdeaton dot space
submissionscomments
mirashii··on Fable 5 – Median thinking declined in August
And here's another great example of how a bunch of people who don't know what's going on throw noise into the system. That post is simply confused: the 1m opus calls are the auto-mode classifier, actual agent calls are still in Fable.
mirashii··on Hister: A private search engine for the pages you visit and the files you keep
It can also send to a self-hosted linkding, quite nice: https://linkding.link/archiving/#using-the-singlefile-browse...
mirashii··on Claude Cowork and chat are now one Claude
The mistake here is thinking or treating AI tools as special or different in any way. We’ve had tooling that does this for decades. Ansible, puppet, saltstack, NixOS/home-manager, and dozens of other solutions. Even better, writing the configuration is extra simple now, since you can just ask your agent to do it.
mirashii··on Iranian banks' SSL certificates are being revoked due to OFAC sanctions
DNS can be trivially MITM'd as well, it's certainly not a secure mechanism for distributing keys.
mirashii··on Compiler Can Undo Your Security Checks
But what are "all these things"? It does not define away all of the UB that C/LLVM has for sure, nor does it turn all UB into crashes, which I demonstrated above and is the inaccurate description of Fil-C that spawned this. But beyond that, it's my belief in all of this is that leaving some UB behavior while trying to state a global correctness property puts those guarantees at risk.

I spent a few minutes poking just to see if my gut is right here, and already, here's an example of UB being used in an optimization by the compiler that leaves a fil safety check at on -O0 but drops it at higher optimization levels. I find it difficult to believe that all of the complex interactions of every optimization pass in the presence of even this subset of UB are guaranteed not to violate these memory safety promises.

    #include <stdio.h>
    #include <stdlib.h>
    
    __attribute__((noinline)) static void poke(int *p, int k)
    {
        int n = 32 + (k & 15);          /* always >= 32: shifting an int by >= 32 is UB */
        p[(1 << n) * 20] = 0x41414141;  /* on x86 the CPU computes index 40, out of bounds */
    }

    int main(int argc, char **argv)
    {
        int *p = calloc(16, sizeof(int));
        poke(p, argc);
        puts("after poke");
        return 0;
    }
mirashii··on Compiler Can Undo Your Security Checks
I reference C's here because it gives the best idea of what clang/LLVM itself is going to consider UB and the bulk of the optimization semantics (where they haven't been changed by Fil-C), since Fil-C is really a fork with some additional passes and transforms built-in.
mirashii··on Compiler Can Undo Your Security Checks
You seem to be trying to apply some colloquial definition of undefined behavior. Undefined behavior is a very specific, defined term. The shift(1, 32) call is by definition undefined behavior (See 6.5.7 in the C standards from C99 up).

The behavior of the program itself when undefined behavior is invoked is allowed to be _anything_. I've simply demonstrated here that the compiler is using the fact that there is undefined behavior to perform optimizations that would not be allowed without undefined behavior. Those optimizations are allowed to result in the program doing anything at the compiler's whim.

mirashii··on Compiler Can Undo Your Security Checks
Neither. I'm claiming that UB allows a transform that violates or ignores the additional guards put in place by Fil-C, and by the definition of UB that is not a bug in the compiler, as any behavior is allowable.

To assert that something specific always happens under UB is counter to the definition of UB. Fil-C carefully defines away UB for some operations, but to make full guarantee of safety, even by their definition and modulo bugs, I believe it necessary to fully remove UB.

mirashii··on Compiler Can Undo Your Security Checks
I'm not so sure you can make such a strong statement about what happens when UB is invoked. The presence of UB allows the compiler to make all kinds of weird assumptions, and it seems very unlikely that there exists no series of allowable transforms that results in a pointer capabilities check being elided or similar.
mirashii··on Compiler Can Undo Your Security Checks

  #include <stdio.h>
  #include <stdlib.h>

  int shift(int x, int n) { return x << n; }

  int main(int argc, char **argv) {
      printf("%d\n", shift(1, 32));   /* n == width: UB */
      return 0;
  }
This program exhibits UB in Fil-C, and you can see that the optimizer does different things at -O0 (outputs 1) and -O1/-O2/-O3 (outputs 0). Since this creates poison, which Fil-C doesn't remove, you can use it to construct all kinds of weird things.

    static void loop(void) {
        int s = shift(1, 32);
        int n = 0;
        for (int i = 0; i < s + 3; i++)
            n++;
        printf("[loop] iterations=%d (s+3=%d)\n", n, s + 3);
    }
    
    static void sw(void) {
        switch (shift(1, 32)) {
        case 0:  puts("[switch] case 0"); break;
        case 1:  puts("[switch] case 1"); break;
        default: puts("[switch] default"); break;
        }
    }
    
    int main(int argc, char **argv) {
        loop();
        sw();
        return 0;
    }
In Fil-C -O0, this gives 4 iterations of the loop and executes sw(). At any higher optimization level, it turns loop() into an infinite loop and drops sw() from the binary entirely.
mirashii··on Compiler Can Undo Your Security Checks
> Fil-C or similar runtime handling so that any time its behaviour would become undefined the program exits instead

It’s worth being clear here that this is not what Fil-C does, it still has UB, and can still explode in many of the same ways as C and all (after all, it’s a clang fork). Fil-C takes one particular class of allocation related bugs and UB off the table, but leaves many of them behind.

mirashii··on OpenAI agents carried out an undisclosed attack on RubyGems
In either case, more of these coming out continues to make their announcement of a two week pause for hardening somewhat laughable. If they couldn’t either identify or communicate within 2 weeks about yet another incident, why should anyone believe 2 weeks is sufficient to harden all their infrastructure and add proper monitoring and everything?
mirashii··on We have a year to fix security everywhere
I would put both of those projects in the category of things I wouldn't call remarkably secure, yes.

To be remarkably secure, these projects would need to not have these kinds of defects, despite the combination of being written in languages have that have a long track record of footguns and lack of initiatives to fix them (proposal-symbol-proto, and PHP's list is too long to even start) and being themselves ecosystems with questionable track records on security in the related areas (Look at $wpdb in 2026, or overall code quality and willingness to modernize, or the entirety of the model of RSC for things that are just going to nearly guarantee you punch all kinds of holes on accident).

mirashii··on We have a year to fix security everywhere
The "surprisingly secure" WordPress just had a unauthenticated RCE earlier this year. Just simplifying isn't going to be enough.

https://nvd.nist.gov/vuln/detail/cve-2026-63030

mirashii··on GrapheneOS says Pixel 11 has MTE support after all
They’re the second largest manufacturer of Android smartphones in the US, and 10% of the global market. Seems a bit unreasonable to dismiss them out of hand on that basis.
mirashii··on Zig: Pointer Stability for ArrayLists
To make matters worse, there’s also a weaker documentation problem. Where should one learn that they need to do this? zig.guide’s page on ArrayList doesn’t mention it. https://ziglang.org/documentation/master/std/#std.ArrayList doesn’t mention it, https://ziglang.org/documentation/master/std/#std.ArrayList doesn’t mention it at the top level, just a method in the midst of dozens of other methods. I honestly don’t know how one is meant to discover this outside of random blog posts.
mirashii··on Claude Session URL appended to commit messages and PR descriptions by default
Just in case, you can check your config. https://code.claude.com/docs/en/settings-reference#remotecon...
mirashii··on Claude Session URL appended to commit messages and PR descriptions by default
This isn’t quite true. There’s a daemon you can launch with `claude rc` that will let you get at all sessions, but if you just `/rc` in one session only that session becomes available.
mirashii··on California lawmakers unanimously pass Linux exemption from age-verification law
> under license terms that permit a recipient to copy, redistribute, and modify the software

The “under license terms…” is a pretty important clause you omitted here.

mirashii··on California lawmakers unanimously pass Linux exemption from age-verification law
By requiring hardware attestation, like Private Access Tokens in iOS/MacOS (see https://blog.cloudflare.com/eliminating-captchas-on-iphones-... for example) and Web Environment Integrity and its successors ( https://github.com/explainers-by-googlers/Web-Environment-In... ).
mirashii··on GitHub Outage Tracker: Is GitHub Cooked?
You're the only mention of Apple in this thread, and I don't see what they have to do with it.
mirashii··on Queryable Executables
PoC || GTFO has an issue that is a PDF that is also a valid NES rom which will render the md5sum of the PDF itself, and other crazy tricks of that type over the years.

https://dl.packetstormsecurity.net/mag/pocgtfo/pocorgtfo14.p...

mirashii··on Malicious Rust crate Arrayref runs a build-time payload
It’s absolutely mad and extremely entitled to expect that a volunteer group of developers do an order of magnitude or more additional work for no additional pay or benefits to themselves.
mirashii··on Go 1.27
This is only a small piece of the story for what people say when they want tagged unions. Without all of the ancillary support in the language, like exhaustive pattern matching, it really doesn't count.
mirashii··on The Amazon Tax
> People's urge to rid the world of ads is similar to our urge to rid the world of "middlemen".

This is a lazy strawman and not what the author of the post argued for.

> It's natural, and I get it (ads are annoying), but this is a forum where I expect people to think a little more deeply about the economics and second order effects of things.

Then maybe contribute to the dialog on that front. The article did so more than your comment setting up a strawman.

mirashii··on I want extern "fil-C"
Probably the shortest statement of Filip's definition is at https://fil-c.org/invisicaps . There's a few other statements around HN and twitter, like this https://news.ycombinator.com/item?id=43195623 , and the recent GISMO talk

But you can see in a number of his public comments statements that Rust is not memory safe by his definition because it has unsafe as an escape hatch. https://x.com/filpizlo/status/2079244258062766177 and https://news.ycombinator.com/item?id=49053608 as some examples.

mirashii··on I want extern "fil-C"
> Rust isn’t memory safe (because unsafe) isn't an argument anyone makes

This is an argument that Fil-C makes, by choosing a very specific definition of memory safety. It’s even stated explicitly in that tweet linked.

mirashii··on Text AI watermarks will always be trivial to remove
> AI companies already store all prompts and responses for future training.

They store some prompts and responses, not all, that's what you're missing.

mirashii··on Exploiting System Management Mode with a very long interrupt
If I’ve understood correctly, what your missing here is that the first core in SMM tells the second to join it in SMM, times out on the wait, does its thing and exits, but then the second core joins SMM after the first has exited, so now the first core is running outside SMM, second core in SMM, so first core can attack the second.
mirashii··on OpenChamber: An Agentic Development Environment
Just FYI, it’s “piqued my interest”
Page 1 of 19Next →