HNHacker News
TopNewBestAskShowJobs

mtlynch

14,908 karma · joined June 16, 2017

I blog about software and entrepreneurship at https://mtlynch.io

I'm writing a book to help developers improve their writing at https://refactoringenglish.com

submissionscomments
mtlynch··on Building a backyard office, the build and cost breakdown
I jumped to the end and saw $2.3k for the mini split and couldn't believe it. I've installed mini splits on two homes and the quotes were always in the $15-25k range for 3-5 head units, so $2.3k for a head + outdoor condenser unit sounded implausible, but then I saw he found a surprisingly good deal:

> I got a ton of quotes for installing a mini split. They ranged from $4-$7k, which was higher than I expected after researching the cost of a quality small unit and knowing this would be a tiny job for an HVAC contractor, especially because I had my electrician prewire the electrical. I was considering installing a DIY system (Mr. Cool DIY system with pre-charged AC lines), But found an HVAC contractor who would install a system for a much lower price than the other quotes I received (and he had great reviews on Thumbtack). In the end, I got a Daikin Mini-split, a common system with many replacement parts. The installation took about 5 hours, and my tech did a great job. I am glad I researched and got a lot of quotes for this one.

mtlynch··on Codefloe Is a Professionally Hosted Public Git Forge
I've ported a couple of repos to CodeFloe in the last few days, and so far, so good. Performance is similar to when I self-host Forgejo on a dedicated VPS where I'm the only user, which is super fast. And their built-in CI is pretty nice.

It's a huge contrast to Codeberg, which struggles with basic navigation of the web UI and every git push or pull takes 2-10s.

mtlynch··on Codefloe Is a Professionally Hosted Public Git Forge
I think you're holding CodeFloe to an unreasonably high standard here. What SaaS vendors agree to financial guarantees if they lose user data or have an outage?

Here's GitHub's policy:

> We will not be liable for damages or losses arising from your use or inability to use the service or otherwise arising under this agreement.

https://docs.github.com/en/site-policy/github-terms/github-t...

Here's Atlassian's policy for BitBucket:

> 14. Limitations of Liability

> 14.1. Damages Waiver. Except for Excluded Claims or Special Claims, to the maximum extent permitted by Law, neither party will have any liability arising out of or related to this Agreement for any loss of use, lost data, lost profits, interruption of business or any indirect, special, incidental, reliance or consequential damages of any kind, even if informed of their possibility in advance.

https://www.atlassian.com/legal/atlassian-customer-agreement...

mtlynch··on Buy Your Friends Batteries
I read the book Poor Economics[0] around when it came out, and it described something similar.

For people who don't have access to banks, they form "savings clubs" where there will be, say, 12 people who put in $100 per month, and one person takes the pot every month. The idea is that if you keep the money yourself, then you're socially pressured to spend it when there are holidays or guests, but if it's locked up in the savings club, you can't spend it, and then you get a big lump sum to spend on a large purchase that would be otherwise hard to save for.

[0] https://en.wikipedia.org/wiki/Poor_Economics

mtlynch··on OpenAI’s head of ethics leaves less than a year after joining
Strangely, a few years ago, Facebook hired a rabbi and appointed him "Director of Responsible Innovation."[0]

He did an interview on Search Engine that I thought was interesting,[1] but it definitely seemed like there was more to the story than just, "Facebook needed to be ethical, and this guy was so good at ethics that he decided to help out."

[0] https://chochmat.org/rabbi-zvika-krieger/

[1] https://www.searchengine.show/what-does-it-feel-like-to-beli...

mtlynch··on Mea Culpa – Dark Hours
How is this Gruber's fault? What level of verification do you expect of a tech blog discussing the experience of another tech blogger?
mtlynch··on Super Mario Derivations
This is such a cool and funny use of derivations. He defines a Nix attribute path that emulates game state in Super Mario 3 so that you can say

    nix build '.#level1.rightb.rightb.rightab.rightb'
And it outputs the screenshot that results in that sequence of button presses. And shared prefixes cache to the same hash, so Nix caches every step so that you can try different button sequences and only have to calculate from the point that you've reached a unique sequence.
mtlynch··on In Memory of My Wife, Elise Cawley, with Thanks for 36 Wonderful Years
I tried using it, but it didn't work well in my experience.

There was be a huge textarea for notes, so I'd write detailed notes after a good conversation, but it didn't auto-save, so if your browser crashed or you accidentally closed the tab, you lose everything. There would also be weird CSRF token errors, which also could cause you to lose everything you just typed.

I started writing in a markdown file and then copying over, and then I realized it's simpler to just write in markdown files and skip the app entirely, so I now just use different markdown files for each person and I add a date heading when I want to add a new entry.

The design of Monica also never quite matched my thinking. There were all these features designed to capture the relationship graph of how you knew everyone and what all their friends and pets' names are and how they met and what their birthdays are, but for me, the thing I want to remember is like, "Oh, when I saw Joe last year, he was getting into woodworking. When I see him next week, I want to ask how that's going." I never feel like, "I bet Joe will be so impressed that I remembered how he met his friend Ned!"

mtlynch··on Ask HN: What are the viable alternatives to DuckDuckGo?
Also a happy Kagi user since 2023, and full disclosure: I participated in their crowdfund, so I have some financial stake in the company that I don't really understand.

I'm always surprised when I see people say, "I can't imagine paying for a search engine."

Imagine if you lived in a city with horrible air pollution, and you were coughing all the time and coming down with mysterious respiratory illnesses. And then you go to a friend's house in the same city who's happy and healthy, and it turns out they have an air filter they pay $10/mo for. And your reaction is, "I can't imagine paying $10/mo just to breathe air."

Pay for search! Get out of the ad-optimized Google black hole. This is a tool you use hundreds of times per month and it fundamentally influences the way you experience the web. It's something that should be a no-brainer to pay for even if it was only marginally better than Google, but I've found it significantly better than Google in most dimensions.

mtlynch··on Show HN: Bribes.fyi – Know before you go. New feature added
Reposting is officially allowed:

> Are reposts ok?

> If a story has not had significant attention in the last year or so, a small number of reposts is ok. Otherwise we bury reposts as duplicates.

https://news.ycombinator.com/newsfaq.html

While we're on the subject of following site guidelines:

> Please don't post shallow dismissals, especially of other people's work. A good critical comment teaches us something.

https://news.ycombinator.com/newsguidelines.html

mtlynch··on I Inspected My Take-Home Interview Project. It Was a Whole Operation
Yeah, exactly. If there's a C2 server, there's some protocol for communication between the C2 server and each victim node.

You can intentionally infect a machine with the malware but then watch the traffic between the victim node and the C2 server. If you get lucky, the C2 server assumes that the victim node is trusted and doesn't sanity check victim->server communication.

Note that this cranks up the danger quite a few notches, though it sounds like you know what you're doing.

mtlynch··on I Inspected My Take-Home Interview Project. It Was a Whole Operation
> Naturally, the next move was pivoting from defense to offense. I wanted to see if the attackers left any vulnerable services exposed on their IP.

Why not attack them through the C2 interface? That's where I'd expect them to slip up.

mtlynch··on I Stopped “Creating Content”
I think we disagree on the connotation of the word "lead."

To me, if someone describes me as a "lead," it implies that they are focused on making the sale rather than on anything else about the business relationship. I would also find it unsettling if a doctor told me that I was a "good lead" because I had a disease they treat.

mtlynch··on I Stopped “Creating Content”
OP here. I wrote the post myself with no AI (modulo grammar checks).

What makes you think it's AI-generated?

mtlynch··on I Stopped “Creating Content”
OP here. Thanks for reading!

I'm having trouble understanding where we disagree. It seems like you're arguing that she's correct because it was helpful for the mutual acquaintance to refer me to this vendor, which I agree it is.

My point is that the term "lead" implies that she's thinking about making the sale rather than serving me as her client. Do we disagree about the connotation of the word "lead?"

As a more extreme example, if you went to a doctor for an illness and they said, "Wow, I'm going to make so much money treating you," I imagine you'd find it off-putting even if the doctor would only earn the money because they're doing a useful thing by treating your illness.

mtlynch··on I Stopped “Creating Content”
I appreciate the critique!

Sometimes when I'm thinking about a blog post, I fall in love with a joke I want to use, but then it constrains how I think about the topic. I still like the David example, but I'm too close to the post to have a balanced perspective, just having finished it today.

mtlynch··on I Stopped “Creating Content”
OP here. Thanks for reading!

I'm not trying to argue that art is sacred and we have to hold it up over everything else, but I am joking that there is still an implicit boundary where we don't use "content" to refer to things that we respect highly.

I think a lot of people that talk about "art" vs. "content" are talking about art vs. business, but I'm more arguing about big vs. small and aggregation vs. individuality.

It makes sense for YouTube and Twitter and Facebook to refer to everything on the Internet as "content" because there's so much variety and those platforms are trying to capture all of it. But I just realized it's silly for me, an individual author to refer to my work as "content" when I could just as easily say "book" or "blog posts."

mtlynch··on I Stopped “Creating Content”
OP here. Thanks for reading!

> I feel that all the terms mentioned are useful in specific contexts. Web traffic brings visitors to your resource. If they read your blog, they become readers. If they use your products, they become users. When someone buys something from you, they become a customer.

I'll respectfully disagree. I think those terms make sense if you're talking in general terms, but if you're an individual person talking about your work, they're generic catchall terms with better alternatives.

Like, in concrete terms, let's say I publish funny cartoons on my website and sell prints of those cartoons. It doesn't make sense for me to say "web traffic brings visitors to my resource." What traffic? What resource? It would be more meaningful to say, "Visitors find my website through Google search."

mtlynch··on I Stopped “Creating Content”
OP here. Thanks for reading!

I don't really have anything against the existence of the catchall term "content." Like, I don't expect the CEO of YouTube to say, "music, short film, art, comedy, journalism, ..., creators" every time he talks about YouTube users. It makes sense from their perspective to bucket everything into "content."

The thing I found interesting was just that the language had crossed over to people where it doesn't make sense to bucket everything. If I'm a blogger, I can just say "blogger" and it's more meaningful than "content creator" but I think the people running small businesses or doing creative work have needlessly adopted the big bucket terminology of "content."

mtlynch··on Zig Creator Calls Spade a Spade, Anthropic Blows Smoke
Are you talking about this line?

> What Kelley can't do is say, "It's an outright fabrication that Sumner does X today," based on an observation from nine months ago.

I think it's clear that I presented it as a hypothetical dialog, not something you literally said. But I agree that the fairer way to present it would be to say, "Kelley can't say 'It appears to be an outright fabrication'," to match the original language in your blog post.

> I think you are earnestly trying to untangle the facts from two parties for whom you have no bias one way or the other, which is commendable.

Honestly, my bias is to support Zig. I personally like the Zig project and you as a person (this blog post notwithstanding) enough that I've contributed a small monthly financial amount for the last 2.5 years. You've never sucked up all my code and then tried to sell it back to me.

So, despite the fact that I have many reasons to favor you and Zig over Sumner and Anthropic, when I read both blog posts, the impression I walk away with is that your blog post is needlessly critical of Sumner as a person and that you made unsubstantiated accusations against him.

> To do this, they need to make this rewrite appear successful, so they need to retcon this idea that they were doing good engineering practices in their zig codebase the whole time, including fuzzing, even though that is not the case.

I don't get that from their blog post.

Both you and Loris seem to be saying that Sumner's "We've been fuzzing Bun" claim implies to everyone that they've been fuzzing it for a long time as much as they possibly can, but I think it just means what it says. They've been fuzzing it some, and some bugs fell out of it, not that they fuzzed it perfectly or followed every software engineering practice perfectly.

mtlynch··on Zig Creator Calls Spade a Spade, Anthropic Blows Smoke
Right, that part is not in dispute.

If Sumner says today, "We do X," then Kelley can say, "Nine months ago, Sumner did not do X," and both can be correct. What Kelley can't do is say, "It's an outright fabrication that Sumner does X today," based on an observation from nine months ago.

mtlynch··on Zig Creator Calls Spade a Spade, Anthropic Blows Smoke
One of the things I find so disappointing about Kelley's behavior here is that he falsely accused Jarred Sumner of lying about fuzzing Bun, and then when Sumner showed evidence[0] that they've been fuzzing Bun for months, Kelley just silently edited his post[1] to walk back the accusation and never apologized or admitted he was wrong.

I commented on Mastodon[2] to point out to Kelley that it's dishonest to silently remove the accusation, as so many people were already talking about it, and it confuses the conversation if Kelley retroactively edits it, and he replied[3]:

> the false claim is in the bun blog post not mine. I only changed the text because it's easy to lazily argue against it. Please read more carefully. They are the ones being deceitful not me.

Loris Cro, Zig's VP of Community, gave a slightly clearer response[4]:

> Jarred's post has a section about what they "were already doing" to maintain their Zig codebase, which includes "24/7 fuzzing", which will make the average reader assume that the codebase has been fuzzed thoroughly, while in reality it has been for, what, 2 months before the rewrite?

Even then, I find it so bizarre that Loris thinks that if someone says, "We've been fuzzing Bun," and shows evidence of months of fuzzing, then that person is lying because "We've been fuzzing Bun" somehow implies something longer than two months.

The duration is irrelevant. If you say you've been fuzzing it and you've fixed bugs that your fuzzer found, then clearly you're fuzzing. The Zig team doesn't get to arbitrarily move the goalposts of what "fuzzing" means.

[0] https://news.ycombinator.com/item?id=48845652

[1] https://news.ycombinator.com/item?id=48854921

[2] https://m.mtlynch.io/@michael/116896188093796421

[3] https://mastodon.social/@andrewrk/116897155344411469

[4] https://hachyderm.io/@kristoff/116898483283387067

mtlynch··on My thoughts on the Bun Rust rewrite
I'm having trouble understanding what you mean.

If I say, "I run 5 miles every day" and my old neighbor says, "I lived next door to him until 9 months ago, and he definitely doesn't run 5 miles a day," and then I show my GPS logs proving I've been running 5 miles a day for the last 9 months, I am correct and my ex-neighbor is incorrect.

If Sumner had said, "We've been fuzzing our code for years," then Kelley could justifiably say that's incorrect. But Sumner is saying that currently Bun fuzzes their code, which is true, so Kelley appears to be incorrect to claim it is a "fabrication."

mtlynch··on My thoughts on the Bun Rust rewrite
Andrew was wrong. He stealth edited his post to hide it. https://news.ycombinator.com/item?id=48854921
mtlynch··on My thoughts on the Bun Rust rewrite
> For me, using Fuzzilli for testing a Zig code is not fuzzing, it's integration testing. If you're running code externally (e.g. wrapping binary) you cannot guarantee that side effect isn't caused by IO. I consider fuzzing a low level activity with many external variables removed.

I've never heard anyone restrict the definition of "fuzzing" in this way. If I repeatedly generate inputs to a program and then run the program with those inputs, that's fuzzing. It doesn't matter if there's IO or not.

> Depending on where you are and how you communicate semantics matter more or less. It's very similar to compiler/transpiler. E.g. TypeScript "Compiler" is called compiler but in fact it's transpiler (it emits other high-level language as a result).

It's still a compiler. It translates code from one language to another. You can argue whether we need the term "transpiler," but a source-to-source compiler is a compiler.

mtlynch··on My thoughts on the Bun Rust rewrite
Yes, "their" refers to Bun's code, not the Zig compiler's code. Fuzzili is a fuzzing engine for JavaScript, so integrating it into Bun means that Fuzzili is fuzzing Bun.[0]

From the Bun post[1]

> We fuzz Bun's runtime APIs 24/7 using Fuzzilli, the JavaScript engine fuzzer used by V8 & JavaScriptCore

From Andrew Kelley's post today[2]:

> The post claims they were fuzzing their Zig code, while during our calls the whole Bun team told us that they were not fuzzing anything. This appears to be an outright fabrication.

Sumner says that the Bun team has been fuzzing Bun's Zig code. Kelley says that this is a fabrication. Sumner showed proof that the Bun team has been fuzzing Bun's Zig code.

It looks like Kelley is incorrect and made an unfounded claim. The generous interpretation is that at the time Kelley and Sumner had a more collaborative relationship, Sumner was not fuzzing Bun's Zig code, but I'd expect Kelley to check if anything had changed since then before publicly accusing Sumner of lying in this week's Bun blog post.

[0] https://github.com/googleprojectzero/fuzzilli

[1] https://bun.com/blog/bun-in-rust

[2] https://andrewkelley.me/post/my-thoughts-bun-rust-rewrite.ht...

mtlynch··on How to ask for help from people who don't know you
This is what Jason Cohen did when he was getting WPEngine off the ground. He messaged 40 WordPress consultants on LinkedIn and offered to pay them higher than their hourly rate since it was a one-off task.[0]

Out of 40 messages, 38 replied and agreed to a phone call, and none of them actually asked for the money.

[0] https://mtlynch.io/notes/designing-the-ideal-bootstrapped-bu...

mtlynch··on How to Write an Effective Software Design Document
OP here. Happy to take any feedback or questions about this post.
mtlynch··on How to Write an Effective Software Design Document
Author here.

Happy to answer any questions or take feedback about this post.

mtlynch··on GLM-5.2 is a step change for open agents
> The problems for services such as GitHub with scaling are reducing cost per customer. That's even more pertinent when discussing inference at scale.

I don't think that's true. When I look at GitHub's incident history,[0] it doesn't read to me like a company that's struggling to cut costs. It looks like a company that's trying to do a million things to serve a million use cases, and the growing interconnections between all those distinct services and workflows cause unexpected failures.

[0] https://www.githubstatus.com/history

← PreviousPage 2 of 34Next →