HNHacker News
TopNewBestAskShowJobs

popey

1,943 karma · joined April 3, 2012

Developer Relations at Tessl.io
submissionscomments
popey··on Show HN: HN.watch – Videos of all Hacker News posts
I can see vertical versions of these doing well on YT shorts or TikTok.
popey··on Tim Cook Sold Out Steve Jobs (2025)
Previously: https://news.ycombinator.com/item?id=45258743
popey··on How many of the 170k English words do you know?
That was a nice diversion. I got 76,750.
popey··on Show HN: Social Network for Corporate Cringe
It took a bit of clicking, but no login needed to see the "feed". https://cringeout.com/feed
popey··on Show HN: Cq – Stack Overflow for AI coding agents
My worry with the confidence scoring is that it conflates "an agent used this and didn't obviously break" with "this is correct". An agent can follow bad advice for several steps before anything fails. So a KU gaining confirmation weight doesn't tell you much about whether it's actually true, just that it propagated. You're crowd-sourcing correctness from sources that can't reliably detect their own mistakes.

It's why at Tessl we treat evals as a first-class part of the development process rather than an afterthought. Without some mechanism to verify quality beyond adoption, you end up with a very efficient way to spread confident nonsense at scale.

popey··on Agents.md file isn't the problem. Your lack of Evals is
The agents are smart enough to write the evals too.

It's agents all the way down!

Submit a GitHub repo containing skills to Tessl, and it will generate the evals, run them, and present the results. https://tessl.io/registry/skills/submit

The evals and results are all shown, no login necessary, so you can assess them yourself. e.g. https://tessl.io/registry/skills/github/coreyhaines31/market... (click details to see the eval texts).

popey··on Show HN: Open-Source Security Monitoring with AI and License Compliance
The vulnerability database search didn't find CVE-2024-9990 - a valid CVE according to NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-9990

I submitted a package-lock.json file to the playground and got a vulnerability report after processing. The sort order next to the pie chart is weird. Medium / High / Critical / Low. I'd expect Critical / High / Medium / Low?

The vuln report ended up in my email spam folder.

I had to hit 'resend' multiple times to receive the verification email. Once I did, I had to either create a new account or login. I don't yet have a password. When I tried to create an account, it said my email was already taken. This onboarding flow seems quite janky.

Is Vulert Open Source software? I couldn't find any links or repos. What does "Join the Open-Source Security Movement" mean in this context?

popey··on Spotify won't open-source Car Thing, but starts refund process
Probably because the Car Thing was never made available outside the US.
popey··on I created the largest curated directory of cybersecurity tools and resources
I submitted two open-source tools. The submission form has a field for 'License' in which the only two options are 'Free' and 'Commercial'. Those aren't licenses. Maybe adjust that field to either say 'cost' or 'terms', or actually have a license field which lets you paste an SPDX entry (or entries) or pick a license from a list.
popey··on Ubuntu 24.04 LTS is so buggy you can't install the OS [video]
There certainly used to be a strong push to have internal people use the product a lot more during the development cycle. There was also a real desire to make the devel version actually usable. That fell by the wayside, sadly.

Having your developer workstation break while you have a backlog full of stuff to do, would absolutely make you less motivated to run the developer release. Especially if you're not on the desktop team.

popey··on Ubuntu 24.04 LTS is so buggy you can't install the OS [video]
First comment on the video - from the maker of the video - is " FIX (worked for me): write Ubuntu ISO to USB flash with dd"

So, yeah. Okay.

(Speaking as ex-Canonical, and still Ubuntu user. I upgraded my ThinkPad 2 days before release, and it was a catastrophe I had to manually un-fudge with the help of the apt maintainer. It was a packaging problem).

My feeling on this particular release is that it was rushed out, and should probably have been kept back for a month or two. The xz and t64 (2038) issues occupied some unexpected time this cycle.

Also, there used to be a dedicated QA lab which did a whole slew of automated tests. I don't believe that still exists.

Also, also. The Ubuntu community has shrunk, which means fewer people doing QA.

Also, also, also. The guy running the desktop team left the day after the release. Read into that what you will.

popey··on Ubuntu 24.04 LTS is so buggy you can't install the OS [video]
RHEL even shipped upstart before systemd was a thing.
popey··on I've forked neofetch to keep it alive
Love that book. It enabled me to have one of my favourite flights of all time. Sat next to Chris Turner, chatting about his time at Acorn for about 9 hours.

I blogged about something related and included this anecdote part way through. https://popey.com/blog/2023/09/a-virus-for-the-bbc-micro/ - under "A short aside"

popey··on Rabbit R1 source code [part 1]
Looks like the repo was just removed from GH.
popey··on Ask HN: Go-to Linux distro for general use and development?
Been using and contributing to (and working for) Ubuntu on everything since 2005 or so.

I still use it for everything. I don't have time or inclination to switch. However I have been somewhat convinced to take a look at Nix (packaging) for some of the tools I use. But all my existing systems are fine. So likely when I next get a work machine (next week) I'll probably (if allowed) use Nix to install anything developer related over and above the stock image and supplied packages.

popey··on Telegram RCE
Possibly this one https://twitter.com/CertiKAlert/status/1777632812700713254
popey··on Vala Programming Language
No, the Ubuntu community is pushing Flutter, not upstream GNOME.

Like the desktop app store, the Ubuntu installer is now written in Flutter.

popey··on Feedle: A search engine for blogs and podcasts
Seems fixed now, I just submitted a podcast feed.
popey··on Generative AI Model Openness Framework Whitepaper
Abstract: Generative AI (GAI) offers unprecedented possibilities but its commercialization has raised concerns about transparency, reproducibility, bias, and safety. Many "open-source" GAI models lack the necessary components for full understanding and reproduction, and some use restrictive licenses, a practice known as "openwashing." We propose the Model Openness Framework (MOF), a ranked classification system that rates machine learning models based on their completeness and openness, following principles of open science, open source, open data, and open access. The MOF requires specific components of the model development lifecycle to be included and released under appropriate open licenses. This framework aims to prevent misrepresentation of models claiming to be open, guide researchers and developers in providing all model components under permissive licenses, and help companies, academia, and hobbyists identify models that can be safely adopted without restrictions. Wide adoption of the MOF will foster a more open AI ecosystem, accelerating research, innovation, and adoption.
popey··on Upside-Down-Ternet
This is coming up on 20 years old soon. Maybe add [2006] to the title :D

https://web.archive.org/web/20060315081659/http://www.ex-par...

popey··on DEF Con 31. Terminally Owned. 60 Years of Escaping [video]
I enjoyed this nostalgic talk from DefCon 31 by David Leadbeater, and you might, too.
popey··on Exodus Bitcoin Wallet: $490k swindle
I further thought about your feedback and the comments from the owner of exchangerate-API and have removed that section from the blog and mentioned it in a follow-up post.

I appreciate your comments, as they made me think more about that topic.

popey··on Exodus Bitcoin Wallet: $490k swindle
Hi Alex!
popey··on Exodus Bitcoin Wallet: $490k swindle
Yes, I understood your point.
popey··on Exodus Bitcoin Wallet: $490k swindle
Back in the day, we had long internal conversations about doing verification 'properly' with government-issued IDs, third-party verification agencies and the like. But that never amounted to anything, sadly.

They might consider it further if the store got to a decent scale (like the contemporaries like iOS, Play and Microsoft). But with "only" 6K applications published, and the money canon being pointed in other directions, I can't see it happening any time soon.

popey··on Exodus Bitcoin Wallet: $490k swindle
Indeed, the victim, in this case, did mention on the linked 4chan thread that they realised their mistake. While we only see a small part of their world through text communication on forums, I suspect they're kicking themselves in the real world.

Or perhaps not, and they have a ton of other wallets full to the brim with crypto-nonsense.

popey··on Exodus Bitcoin Wallet: $490k swindle
Sure, there was a bit of guesswork on my part. I could analyse the traffic in more detail, but when I wrote this all up, it was Sunday evening, and I wanted to do the minimum analysis to get a response to the unlucky rube.

I still have the snap, and could test further, but I suspect the endpoint linode boxes will disappear and popup somewhere else sometime.

popey··on Exodus Bitcoin Wallet: $490k swindle
Maybe I could have worded that sentence better. Thanks for the feedback. It wasn't intended the way you took it. But I appreciate you mentioning it anyway.
popey··on Digital Ocean killed my droplets and gives a vague reply
When I signed up and put in my credit card details, they immediately cancelled my order and completely deleted my account. I had to resort to moaning at them on twitter to get them to unblock me, which they did. Bit of a rubbish start to the journey though.
popey··on All the Major Tech Layoffs in 2024 So Far
I usually get this kind of data from https://layoffs.fyi/
Page 1 of 6Next →