HNHacker News
TopNewBestAskShowJobs

orthogonal_cube

145 karma · joined February 9, 2026

submissionscomments
orthogonal_cube··on OpenAI breaches Medicare, Albanese reveals
The lack of activity monitoring for traffic egress has astounded me. Anomaly detection should be part of all training and exercises to determine the extent the AI is going through. It really does feel like they just kick off the activity and leave it completely alone until it finishes with a result.
orthogonal_cube··on Flet 1.0 – Build cross-platform apps in Python
I don’t understand the points attempted to be made here.

> especially in the era of LLM

Using a tool to generate a product in a language that someone isn’t familiar with is not a good idea.

> horrible language from the performance…

Nor is it a good idea to choose a language strictly for its performance when requirements like portability and framework maturity are at the forefront.

> …to the dependencies…

Dependency management isn’t the greatest, but it’s also not awful for a deployed product. Managing dependencies as a developer with multiple projects that each have their own virtual environment may not be fun but it’s not exactly an impossible mess.

> …to everything

   from __future__ import everything
> can’t believe it got popular over Perl back in the day

And I’m sure people can’t believe that the iPod got more popular than the Zune, but sometimes convenience and taste are what drive decisions.

orthogonal_cube··on GOP issues stark warning to AI companies
It’s career-suicide to do so in nearly all cases. If your constituents disapprove then you can kiss re-election goodbye. If your party disagrees then you can kiss funding goodbye.
orthogonal_cube··on GOP issues stark warning to AI companies
I really wish we could experience at least a single year where our representatives worked to cover the needs of citizens in a collaborative, non-partisan manner rather than focusing on corporate interests and political theatre filled with slander and misinformation.
orthogonal_cube··on Falsehoods Programmers Believe About LANs
Programmers certainly believe that, but they quickly learn not to.
orthogonal_cube··on Debian votes to allow "responsible use of generative AI"
> I was referring specifically to the idea that you have to stand by the code that you write.

Any serious entity which has experts handling code will do so, yes.

My employer, for example, has various teams of actual developers and others with a significant number of “not really” devs who found their way into DevOps roles. The teams with seasoned developers hold the author responsible as to the integrity and quality of code, regardless of tools used. They won’t hesitate to call someone out directly for low-quality submissions in Teams channels. The teams that have a lot of “not really” devs will blame the model for issues that surface. Of course, they’re also pushing to not have to write any code directly by FY2028, but instead have models do it as part of an internal AI initiative. Somehow the idea of using AI to generate reports, process reports, write code, test and deploy got signed off.

orthogonal_cube··on Responding to the next frontier of critical cyber capabilities
There’s still levels to it.

“Isolation” can mean the network hardware has no direct connections to an extranet. Data is transferred manually by physical media (USB, DVD, etc.) with logging and dedicated transfer stations.

“Isolation” can mean a VLAN on equipment which has also has extranet access, creating a logical isolation rather than physical (to reduce cost). Data can be transferred manually or through diodes.

And then there’s “isolation” which is a joke: machines technically able to access the internet but require proxy configuration (which isn’t set but can be easily derived).

orthogonal_cube··on Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
> I'm surprised there are comments here that aren't impressed about what was accomplished here.

Possibly because some of the elements mentioned are suspected to be vibe-coded (JFrog Artifactory as the proxy cache) and some others have poor cyber hygiene (executing config from a dataset). It feels like an event that wouldn’t have happened if code were properly audited and written rather than relying on models to do the work. There’s also an issue with the ability to trust the source (OpenAI) as they have everything to gain by staging this as something that “suddenly happened” without anyone knowing for several days.

orthogonal_cube··on I think you might be fooling yourself with AI
> AI costs aren’t going to stay this high. They will go down.

I hear this a lot and it seems to be far too optimistic. Call me skeptical but plan pricing continues to increase with tighter usage constraints. We’re still at the point in time that companies like Anthropic, OpenAI, and GitHub charge seemingly reasonable prices in order to get people hooked onto AI before raising prices to get their return on investment.

orthogonal_cube··on Show HN: I replaced a $120k bowling center system with $1,600 in ESP32s
Any plans to let people create accounts to track their scores over time?
orthogonal_cube··on What `for x in y` hides from you – From Scratch Code
It would be very surprising for somebody without a formal software development background and years of experience.

Looking back at 2015 when Python 2 was still supported, there was a lot of confusion for why Python 2 would create a tuple while Python 3 created a generator for the following statement:

  foo = (x for x in [10, 20, 30])
The blog post is trying to help fill in a gap of knowledge for anyone trying to understand more of what goes on behind the curtains.
orthogonal_cube··on America pays workers just 27% of what its wealth allows – the worst in the OECD
> I am able to see my PCP and dentist within a week if I want.

This is very much location- and provider-dependent, regardless of rural or urban setting. You also have to factor in that some doctors do not work at a single clinic but may schedule their week to spend certain days at one facility and the rest at others (ex. Monday and Thursday at Facility A, Tuesday and Wednesday at Facility B, Fridays off) which can limit the ability to see them in the same week especially if the facilities are not owned by the same organization.

Healthcare access and quality aren’t consistent. Some states or areas in the same state will have better providers than others. Some health insurances will cover things without question and others may fight against you on covering things.

I recently had knee surgery and hit my deductible due to the procedure but insurance billed me for full price on part of the it because they deemed it to be “experimental and unnecessary.” There was some back-and-forth between the surgeon’s office, my insurance, and myself to understand why only a part of it wasn’t covered. This was an additional $1,200 that eventually I had to pay for; even after paying $1,100 up front because of my high-deductible health plan. I’m financially stable enough to cover it without it destroying my savings but this kind of surprise isn’t uncommon for US citizens even with recent laws trying to make costs more predictable.

orthogonal_cube··on Show HN: 18 Words
Was this by chance inspired by a previous submission (now defunct) that had a similar premise?

https://news.ycombinator.com/item?id=40536488

Edit: I believe it was transferred to a new domain at https://wordnerd.co/

orthogonal_cube··on CarPlay Is Additive
$240/yr in software subscriptions but likely far more than that by selling the extra metadata they can extract from the service
orthogonal_cube··on Ubiquiti: Enterprise NAS, Built on ZFS
Are Ubiquiti products commonplace for companies that contract with the US government outside of the DoD/DoW?

Since DoD/DoW generally requires STIG compliance, and none authored are for any specific Ubiquiti product, we can cross that off the list. Sure they can get exceptions or use a more generalized STIG but stakeholders generally have pre-defined limitations on what they will and will not allow on networks they sponsor.

orthogonal_cube··on TIL: You can make HTTP requests without curl using Bash /dev/TCP
It was fun exploring this to make a native-shell-only peer-to-peer file transfer utility at work for some automation scripts. At least, it was until trying to replicate it in Powershell was somehow triggering Crowdstrike and the corporate Cybersecurity team thought I was writing malware.
orthogonal_cube··on Ask HN: What was your "oh shit" moment with GenAI?
This is not uncommon when becoming disillusioned with something that has been hyped up and forced upon you for an extended period.

The fatigue of the product (and sting of false promises) causes the negatives to overshadow anything positive to say.

orthogonal_cube··on Remote Work Leaves Younger Workers Sidelined
I find this study interesting but wonder if the wording is specifically done to cause some sensationalism.

> However, there is a twist: for positions on distributed teams, the firm consistently hired more experienced workers, even after reopening. This divergence suggests that the firm’s hiring decisions were influenced by the complications of remote work rather than other macroeconomic trends.

They don’t consider (almost intentionally) that remote positions don’t have the same restrictions as in-person positions. Anyone meeting desired qualifications can be considered for a remote position. Only people willing to relocate to, or already live near, a target office and meet the qualifications can be considered for an in-person job. Remote positions therefore are likely to be more competitive and difficult for inexperienced candidates because the pool of candidates is far larger. The hiring manager is incentivized to pick the person they believe will contribute the most for the amount they’re willing to pay.

The findings about mentorship in-person may be true but it is strange to put that as the deciding reason. There are no details provided over how “quality” is quantified nor decided. Selecting a sample size of one firm to analyze in detail without looking at others to confirm this feels very flawed.

orthogonal_cube··on Open Source Resistance: keep OSS alive on company time
I miss working at a place which allowed this.

Some employers get tangled up in just the legal review process.

Once I asked permission to submit a patch to a project and it had quite an interesting email trail. It came down to a single question: if the patch was written during hours billed to a customer for the purpose of fixing a bug in a deliverable product, and the library being patched had to be recompiled and delivered with the source code, and the contract states that all work and intellectual property associated to the product would be transferred to the customer, do we have authority to release the patch in the public domain?

Legal didn’t want to answer it.

orthogonal_cube··on Show HN: Building a web server in assembly to give my life (a lack of) meaning
I frequently reference this exact meme to people whenever someone complains about complicated or difficult-to-write code. Now that’s you’ve made this project I suppose we have zero room to complain anymore!
orthogonal_cube··on Making Julia as Fast as C++ (2019)
Dang, haven’t read much on Julia as of late. I remember using it for a CS 300-level course around 2016 when learning about tokenizing and parsing as part of language fundamentals. Julia has undoubtedly made some significant performance improvements since then. Would love to see a follow-up that explores what, if anything, from this still holds true and what improvements can be made.
orthogonal_cube··on Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
To answer the first question, a number of veteran independent researchers probably wouldn’t have touched such a system. Plenty of companies will send their lawyers after you if you tell them that you’ve discovered a vulnerability of some sort and wish to responsibly disclose. Even if you do things in good faith, the company has zero reason to assume the best from you and can hold a sword over your head by citing poorly-written laws that lean in their favor regarding computer fraud and abuse.

DoD does appear to offer a “Defense Industrial Base - Vulnerability Disclosure Program” for all public-facing DoD/DoW systems.[1] However, this might not include contractor-controlled assets or services. I cannot view the HackerOne page that it redirects to (login is required) to view more details.

[1]: https://www.dc3.mil/Missions/Vulnerability-Disclosure/DIB-Vu...

orthogonal_cube··on Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock
Honestly I’m surprised this wasn’t already a feature in macOS. Thank you for coding it and publishing as open-source!
orthogonal_cube··on Do you even need a database?
SQLite did decently well but I think they should’ve done an additional benchmark with the database loaded completely into memory.

Since they’re using Go to accept requests and forwarding them to their SQLite connection, it may have been worthwhile to produce the same interface with Rust to demonstrate whether or not SQLite itself was hitting its performance limit or if Go had some hand in that.

Other than that, it’s a good demonstration of how a custom solution for a lightweight task can pay off. Keep it simple but don’t reinvent the wheel if the needs are very general.

orthogonal_cube··on CPU-Z and HWMonitor compromised
Seems the installers hosted by them are fine. The links on the site have been changed to direct people towards Cloudflare R2 storage with various copies of malicious executables.

Looking forward to information down the line on how this came about.

orthogonal_cube··on FCC updates covered list to include foreign-made consumer routers
That’s the ironic part.

Plenty of consumer-grade devices have had very lax security settings or backdoors baked in for purposes of “troubleshooting” and recovery assistance. It’s never been limited to foreign-made devices.

Security has never been part of the review process. The only time any agency has really cared is when encryption is involved, and that’s just been the FBI wanting it to be neutered so they can have their own backdoors.

orthogonal_cube··on Shall I implement it? No
> Why does it ask a yes-no question if it isn’t prepared to take “no” as an answer?

Because it doesn’t actually understand what a yes-no question is.

orthogonal_cube··on I don't use LLMs for programming
> even configuring servers is easier with Claude

To what extent is Claude configuring these servers? Is this baremetal deployment with OS configuration and service management? Or is it abstracted by defining Terraform files to use pre-created images offered by a hosting service?

orthogonal_cube··on RFC 454545 – Human Em Dash Standard
Ha, well I’m not on the spectrum but ADHD does have some overlap here and there.
orthogonal_cube··on RFC 454545 – Human Em Dash Standard
> Good writing doesn't have mad tangents anyway, there should be a flow and natural transition.

In general, yes. Technical documents, research reports, news articles, and other formal publications should follow this.

Anything else which allows a bit more freedom in expression? I’d say it’s a matter of taste.

Page 1 of 2Next →