HNHacker News
TopNewBestAskShowJobs

ollien

1,228 karma · joined March 29, 2015

submissionscomments
ollien··on My last six months at Evernote
Hug of death? Archives don't have it either
ollien··on Tile's security is so bad it's a feature for stalkers
Very cool! I only skimmed Section 4 a bit, but that's really cool!

I was going to ask how the web UIs possibly work if the location is indistinguishable, but I went to the Google Find Hub, and it appears you can't view the location for tags unless you enter your phone's pin code / pattern lock. This must either communicate with the phone or the keys are stored on Google's end.

EDIT: I turned my phone off, and I can still get the location of my keys... surely this doesn't mean the key is stored on their end? Wouldn't be very good E2EE in that case :)

ollien··on Tile's security is so bad it's a feature for stalkers
It's interesting to me that other trackers have end-to-end encryption. I wouldn't have expected it but makes sense for the threat model.

> Providerslike Apple and Google achieve location indistinguishability by end-to-end encrypting location information using a public key embedded in BLE advertisements emitted by a tag

Though it makes me wonder... What's the private key? If the public key is attached to the tag, how is the device getting it? I'm guessing it gets shared during pairing.

ollien··on An interview with an Apple emoji designer
If the author is reading this, the hyperlink to the book in the first paragraph is broken. Looks like it's attempting to direct you to an absolute url that was meant to be relative.

    <a href="https://books/face-with-tears-of-joy">
ollien··on PS3 Emulator Devs Politely Ask That People Stop Flooding It with AI PRs
I've struggled with this "responsibility" take. What does it mean in the context of an open source project? As far as I understand it, the original contributors of bugs are often not the ones fixing them (though they can be). Is it that if you write enough buggy code you get banned as a contributor? Is it that you're not allowed to say Claude ate my homework?
ollien··on I’ve banned query strings
When the goal is "the funniest way", I think that's a hit :)
ollien··on I’ve banned query strings
I don't think it's an abuse, RFC9110 defines 414 as a response for "refusing to service the request because the target URI is longer than the server is willing to interpret". Since adding a query string involves only adding characters, this seems fine; there's no stipulation as far as I can tell that all pages a server hosts must adhere to the same length. I'd be curious if any well-known clients interpret it that way though, and make caching decisions based on it. As far as I know, they shouldn't.

Obviously it's against the spirit of the thing, but I don't think it's wrong per-se.

ollien··on Tell HN: Fiverr left customer files public and searchable
I've never been in the position that I've had to deal with this. Is the best you can do in this situation to pull the files and optionally republish them to a robots.txt'd path (with authn/z, too)? I can't imagine you can get it pulled from search engines very quickly...
ollien··on Show HN: I made a "programming language" looking for feedback
I've been waiting for something like this to come along. I keep hearing people say LLMs are a new abstraction layer, and I fundamentally disagree. We don't commit our compiled machine code, we commit our C. Yet, with LLMs, we commit our generated source code, completely throwing away the English language abstraction.

This seems to scratch that itch. The non determinism makes it probably not suitable for most uses, though.

ollien··on OpenTelemetry profiles enters public alpha
As far as I'm aware, Pyroscope itself is not a profiler, but a place you can send/query profiles. OpenTelemtry is releasing a profiler, so they don't compare. One can be used with the other.
ollien··on OpenTelemetry profiles enters public alpha
Very excited for this. We've used the Elixir version of this at $WORK a handful of times and have found it exceptionally useful.
ollien··on AI Usage Policy
Not sure how I feel about transcripts. Ultimately I do my best to make any contributions I make high quality, and that means taking time to polish things. Exposing the tangled mess of my thought process leading up to that either means I have to "polish" that too (whatever that ends up looking like), or put myself in a vulnerable position of showing my tangled process to get to the end result.
ollien··on Install.md: A standard for LLM-executable installation
I don't love the concept, but I do wonder if it could be improved by using a skill that packages and install script, and context for troubleshooting. That way you have the benefits of using an install script, and at least a way to provide pointers for those unfamiliar with the underlying tooling.
ollien··on Unauthenticated remote code execution in OpenCode
Yep yep, makes sense. I was thinking about it running in headless mode (i.e. with --listen)
ollien··on Unauthenticated remote code execution in OpenCode
> Neovim’s server defaults to named pipes or domain sockets, which do not have this issue. The documentation states that the TCP option is insecure.

Good note on pipes / domain sockets, but it doesn't appear there's a "default", and the example in the docs even uses TCP, despite the warning below it.

https://neovim.io/doc/user/api.html#rpc-connecting

(EDIT: I guess outside of headless mode it uses a named pipe?)

> VS Code’s ssh daemon is authenticated.

How is it authenticated? I went looking briefly but didn't turn up much; obviously there's the ssh auth itself but if you have access to the remote, is there an additional layer of auth stopping anyone from executing code via the daemon?

ollien··on Unauthenticated remote code execution in OpenCode
A coworker raised an interesting point to me. The CORS fix removes exploitation by arbitrary websites (but obviously allows full access from the opencode domain), but let's take that piece out for a second...

What's the difference here between this and, for example, the Neovim headless server or the VSCode remote SSH daemon? All three listen on 127.0.0.1 and would grant execution access to another process who could speak to them.

Is there a difference here? Is the choice of HTTP simply a bad one because of the potential browser exploitation, which can't exist for the others?

ollien··on RTX 5090 and Raspberry Pi: Can it game?
I'm not very familiar with this layer of things; what does it mean for a GPU to drive a boot sequence? Is there something massively parallel that is well suited for the GPU?
ollien··on Minecraft removing obfuscation in Java Edition
It's even recognized by the Library of Congress!

https://www.loc.gov/static/programs/national-recording-prese...

ollien··on Pop OS 24.04 LTS Beta
This might be what finally gets me to ditch my i3+xfce setup. Anyone done a similar transition?
ollien··on GMP damaging Zen 5 CPUs?
It is important to remember that CPUs scale their turbo with thermals. It's not a matter of needing to turn turbo on and off
ollien··on GMP damaging Zen 5 CPUs?
> The small coolers used by them are not recommended by Noctua for 9950X

Noctua's CPU compatibility page lists the NH-U9s as "medium turbo/overclocking headroom" for the 9950X [0]. I don't think it's fair to suggest their cooler choice is the problem here.

[0] https://ncc.noctua.at/cpus/model/AMD-Ryzen-9-9950X-1831

ollien··on 2025 Stack Overflow Developer Survey Results
As in, Gemini users are interested in Tailwind? Is this suggesting that Gemini is suggesting tailwind, and people are using it? It's very weird
ollien··on 2025 Stack Overflow Developer Survey Results
Can anyone make sense of the sankey chart under "Developers at all levels are exploring the evolving AI landscape through Stack Overflow"? How does "Large Language Model" flow into "Tailwind CSS 4"?
ollien··on Cloudflare 1.1.1.1 Incident on July 14, 2025
I'm a bit uneducated here - why was the other 1.1.1.0/24 announcement previously suppressed? Did it just express a high enough cost that no one took it on compared to the CF announcement?
ollien··on Supabase MCP can leak your entire SQL database
We're agreeing. I'm saying that in a pre-LLM world, no one would do that, so we shouldn't do it here.
ollien··on Supabase MCP can leak your entire SQL database
Yes, sorry :)

Yeah, that makes sense if you have full control over the agent implementation. Hopefully tools like Cursor will enable such "sandboxing" (so to speak) going forward

ollien··on Supabase MCP can leak your entire SQL database
Where would you insert the second LLM to mitigate the problem in OP? I don't see where you would.
ollien··on Supabase MCP can leak your entire SQL database
I'll be honest -- I'm not sure. I don't fully understand LLMs enough to give a decisive answer. My cop-out answer would be "non-determinism", but I would love a more complete one.
ollien··on Supabase MCP can leak your entire SQL database
Heh - I hope I didn't suggest that you _should_ use eval in production. It's a catastrophically bad idea due to the unchecked power.

You do raise a good point that this is effectively eval, but I would also imagine that no developer is running `SELECT username FROM users LIMIT 1 |xargs "bash -c"`, either, even on their local machine.

ollien··on Supabase MCP can leak your entire SQL database
We're agreeing, here. I'm in fact suggesting you _shouldn't_ use the output from your database as input.
Page 1 of 11Next →