HNHacker News
TopNewBestAskShowJobs

poorman

1,125 karma · joined June 29, 2013

submissionscomments
poorman··on OpenTrafficMap
I wonder if this could be used to track location of the vehicle
poorman··on HERMES.md in commit messages causes requests to route to extra usage billing
They acknowledged the bug. Screenshot and chargeback
poorman··on Darkbloom – Private inference on idle Macs
Yeah I think there's a dependency issue going on there. Something isn't installed that needs to be.
poorman··on Darkbloom – Private inference on idle Macs
If you are worried about a $300 solar panel you are not going to like the cost of a Mac Studio M3 Ultra 512 GB! haha
poorman··on Darkbloom – Private inference on idle Macs
As one of the only people running a Mac Studio M3 Ultra with 512 GB of RAM on the network, I can tell you at sustained 100% GPU utilization I am measuring 250 watts max (at the power outlet). My solar panels are easily producing this. The power calculation goes away once you connect a solar panel. You can get a 400 watt solar panel on Amazon for $300.
poorman··on Moving from GitHub to Codeberg, for lazy people
Same. I installed Forgejo two months ago when Github wouldn't let me create agent accounts. It's been awesome. Any time I want a new feature I open my agent on the server and tell it to add the feature to Forgejo. Took all of 15 minutes for it to add a working Show/Hide "Viewed" files on the PR reviews.
poorman··on The bridge to wealth is being pulled up with AI
I am going to say this for all the people thinking like this. This attitude will get you nowhere in life. It historically never has and in the future it never will.
poorman··on SETI@home: Data Acquisition and Front-End Processing (2025)
I was just thinking about this project the other day. Seems we have a whole lot of unused compute (and now GPU). I wish someone would create a meaningful project like this to distribute AI training or something. Imagine underfunded AI researchers being able to distribute work to idle machines like SETI@home did.
poorman··on We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
GitLab has some code in their repo if you want to see how to do it.
poorman··on We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
All SVGs should be properly sanitized going into a backend and out of it and when rendered on a page.

Do you allow SVGs to be uploaded anywhere on your site? This is a PSA that you're probably at risk unless you can find the few hundred lines of code doing the sanitization.

Note to Ruby on Rails developers, your active storage uploaded SVGs are not sanitized by default.

poorman··on Beginning January 2026, all ACM publications will be made open access
This is huge. A lot of these are the underpinnings of modern computer science optimizations. The ACM programming competitions in college are some of my fondest memories!
poorman··on Building an efficient hash table in Java
I think that's a great idea! I just checked one of my larger projects and it 55% ConcurrentHashMap and 45% HashMap so I'd personally benefit from this plan.
poorman··on Building an efficient hash table in Java
In a concurrent environment, I wonder if the overhead of wrapping every API call with a synchronized would make this significantly slower than using ConcurrentHashMap.
poorman··on CS234: Reinforcement Learning Winter 2025
RL is still widely used in the advertising industry. Don't let anyone tell you otherwise. When you have millions to billions of visits and you are trying to optimize an outcome RL is very good at that. Add in context with contextual multi-armed bandits and you have something very good at driving people towards purchasing.
poorman··on The privacy nightmare of browser fingerprinting
It's likely that yes, you will end up with an alias that links you because of a cookie somewhere, or a finger print of the elliptic curve when do do a SSL handshake, or any number of other ways.

The ironic thing is that because of GDPR and CCPA, ad tech companies got really good at "anonymizing" your data. So even if you were to somehow not have an alias linking your various anonymous profiles, you will still end up quickly bucketed into a persona (and multiple audiences) that resemble you quite well. And it's not multiple days of data we're talking about (although it could be), it's minutes and in the case of contextual multi-armed bandits, your persona is likely updates "within" a single page load and you are targeted in ~5ms within the request/response lifecycle of that page load.

The good news is that most data platforms don't keep data around for more than 90 days because then they are automatically compliant with "right to be forgotten" without having to service requests for removal of personal data.

poorman··on Cryptographic Issues in Cloudflare's Circl FourQ Implementation (CVE-2025-8556)
There is definitely a miss-alignment of incentives with the bug bounty platforms. You get a very large number of useless reports which tends to create a lot of noise. Then you have to sift through a ton of noise to once in a while get a serious report. So the platforms up-sell you on using their people to sift through the reports for you. Only these people do not have the domain knowledge expertise to understand your software and dig into the vulnerabilities.

If you want the top-teir "hackers" on the platforms to see your bug bounty program then you have to pay the up-charge for that too, so again miss-alignment of incentives.

The best thing you can do is have an extremely clear bug-bounty program detailing what is in scope and out of scope.

Lastly, I know it's difficult to manage but open source projects should also have a private vulnerability reporting mechanism set up. If you are using Github you can set up your repo with: https://docs.github.com/en/code-security/security-advisories...

poorman··on Claude Code on the web
Totally agree. I was just thinking that I wouldn't want this feature for Claude Code but for Codex right now it would be great! I can simply let tasks run in Codex and I know it's going to eventually do what I want. Where as with Claude Code I feel like I have to watch it like a hawk and interrupt it when it goes off the rails.
poorman··on Doing Rails Wrong
Stimulus and Hotwire are the "rails way" now. I've read the docs and they still confuse the hell out me. Seems like you're reinveting your own javascript components over and over again.

In my opinion Rails 8 + Intertia.js + React so much less "reinventing the wheel" (especially if you use shadcn components).

poorman··on Gem.coop
Here's the thing. They could have put up link to a git repository where others can follow along with the maintenance of this project, but here isn't one. There is a list of maintainers explicitly mentioned on this page but no link to the git repository. This leads me to think this project is not about the code but about the people.
poorman··on Shopify, pulling strings at Ruby Central, forces Bundler and RubyGems takeover
I hope this all works out. I remember the day Oracle bought Sun Microsystems and the impact it had on the community and maintainers.
poorman··on Find SF parking cops
Someone should plot this on a heat map so we can see what areas the parking cops don't write tickets for!
poorman··on Show HN: Run Qwen3-Next-80B on 8GB GPU at 1tok/2s throughput
If you have 64 GB of RAM you should be able to run the 4-bit quantized mlx models, which are specifically for the Apple silicon M chips. https://huggingface.co/collections/mlx-community/qwen3-next-...
poorman··on GPT-OSS vs. Qwen3 and a detailed look how things evolved since GPT-2
This article really goes into a lot of detail which is nice. gpt-oss is just not good for agentic use in my observation.

tldr; I'll save you a lot of time trying things out for yourself. If you are on a >=32 GB Mac download LMStudio and then the `qwen3-coder-30b-a3b-instruct-mlx@5bit` model. It uses ~20 GB of RAM so a 32GB machine is plenty. Set it up with opencode [1] and you're off to the races! It has great tool calling ability. The tool calling ability of gpt-oss doesn't even come close in my observations.

[1] https://opencode.ai/

poorman··on GPT-OSS vs. Qwen3 and a detailed look how things evolved since GPT-2
As we saw with GPT-5 the RL technique of training doesn't scale forever
poorman··on Jemalloc Postmortem
How cool would it be to see Doug Lea pick up the torch and create a modern day multi-threaded dlmalloc2!?
poorman··on Jemalloc Postmortem
Jemalloc is used as an easy performance boost probably by every major Ruby on Rails server.
poorman··on Cloudflare was down
Can’t wait to read this post-mortem. Seems odd that a Google Cloud outage would bring down Cloudflare services.
poorman··on Magistral — the first reasoning model by Mistral AI
Is there a popular benchmark site people use? Becaues I had to test all these by hand and `Qwen3-30B-A3B` still seems like the best model I can run in that relative parameter space (/memory requirements).
poorman··on Ruby 3.5 Feature: Namespace on read
Try using the Pay gem and others that assume a global singleton for a multi-tenant app (as in multiple different websites under different domains with different Stripe API keys). Lots of gems assume this and their configuration is global.

I personally would love to have this feature!

poorman··on Evolving GitHub Issues
In GitHub, if you want to put an issue from a repository on a Project board it creates a project item to reference it, thus using an issue. If you have a large project (which I have where we hit the capacity of project items) then you are forced to start deleting issues from the project. Which in my opinion isn't great, because that limit includes project issues that have been marked "done". Then you lose the history of maybe why things were done a certain way.
Page 1 of 8Next →