HNHacker News
TopNewBestAskShowJobs

primitivesuave

4,642 karma · joined September 11, 2013

submissionscomments
primitivesuave··on Show HN: A working 3D model of an Enigma machine
Thank you!!
primitivesuave··on Show HN: A working 3D model of an Enigma machine
Thank you for the link! I love Observable notebooks.
primitivesuave··on Show HN: A working 3D model of an Enigma machine
Thank you! Very honored to be considered an educational gem :)
primitivesuave··on Show HN: A working 3D model of an Enigma machine
This is such a great idea. I didn't know about WebXR before reading your comment, and was delighted to see that this is a relatively easy thing to implement. I need to find some VR goggles to borrow so I can test this out, but I'll optimistically push out an update within the next day with the WebXR update.
primitivesuave··on Show HN: A working 3D model of an Enigma machine
Thank you!! I was also hitting performance issues, especially on mobile - I think the latest version has gotten it a bit closer to a smoother experience, but there is still a lot of low-hanging fruit on making this more fluid (especially the step transitions).
primitivesuave··on Show HN: A working 3D model of an Enigma machine
Yours is amazing work, and certainly a higher degree of fidelity than I was able to achieve with AI assistance. The initial motivation behind this was largely driven by curiosity around the rotor motion (the ratchet and pawl assembly), and then into how the wiring actually works. For my brain, I needed to press the keys a hundred times and watch the current flow before it started making sense.

I'm curious about how you worked out the inner dimensions and part placements so accurately. Thank you for providing this marvelous free resource!

primitivesuave··on Show HN: A working 3D model of an Enigma machine
I revamped the mobile experience last night, let me know what you think!
primitivesuave··on Show HN: A working 3D model of an Enigma machine
Thank you! My dream is to have a working Bombe [1] which can decrypt the Enigma traffic in your browser.

https://en.wikipedia.org/wiki/Bombe

primitivesuave··on Show HN: A working 3D model of an Enigma machine
Thank you for the kind words! As mentioned in the other comment below, I'll open-source it very soon and update the site with a GitHub link.
primitivesuave··on Show HN: A working 3D model of an Enigma machine
Thank you for the suggestion and the kind words! Completely agree that the navigation is a bit unintuitive, will work on fixing that tonight :)
primitivesuave··on Show HN: A working 3D model of an Enigma machine
I will open-source it very soon! I was a bit nervous about putting it out there before I'm sure that the machines are absolutely accurate, especially the more niche ones where I had to make some inferences about the wiring. Will add the GitHub link to the site when I've had a chance to review everything for accuracy, and will probably end up moving some of my "educated guesses" off the main branch.
primitivesuave··on Show HN: A working 3D model of an Enigma machine
Thank you for the tip about mobile performance, my apologies for neglecting it and I'm working on fixing it right now!
primitivesuave··on 'We hacked the FBI:' Hackers say they have data on all FBI employees
The recent Epic vs Health Gorilla lawsuit is an example of how your medical records have almost certainly made it to the hands of many people you will never know about.
primitivesuave··on It's time for Mark Zuckerberg to resign from Meta
Rather than investigate all the things where investigative journalism could potentially make a difference to real human beings' lives, the Guardian has chosen to pursue a plea for the majority owner of Meta's voting shares (61%) to step down from his position of power. Let us politely ask Sisyphus to stop pushing the boulder instead.
primitivesuave··on Building an (almost) fully self-hosted, sandboxed, agentic software factory
I've been meaning to write something about how I did it, and have been putting it off for a long time. I wrote all the tools myself - by that, I mean that everything was a web app running in my browser.

My advice would be to first set up an automation for yt-dlp to pull the media, then use Whisper to build a transcription pipeline. Chunk the transcript based on desired result granularity, then store embeddings in local Qdrant. It helps to use an orchestrator to handle all of this - my current recommendation is Dagster (dagster.io).

primitivesuave··on Building an (almost) fully self-hosted, sandboxed, agentic software factory
Excellent guess, and the documentary All The Queen's Horses does a much better job explaining that story than I ever could!

This one is about Dolton, IL - the series is called "Dolton Documentaries" on YouTube.

primitivesuave··on Building an (almost) fully self-hosted, sandboxed, agentic software factory
Honored by your interested :) It is called "Dolton Documentaries".
primitivesuave··on Building an (almost) fully self-hosted, sandboxed, agentic software factory
My favorite real-world example that I worked on: I created a YouTube documentary series about corruption in a small town in Illinois. This required downloading thousands of hours of government meeting videos from YouTube, transcribing + chunking + embedding, summarizing meeting segments, running a couple passes of validation, then searching for interesting storylines. I also scraped thousands of public documents which exposed campaign finance violations and some truly nefarious stuff going on behind the scenes.

I did 90-95% of the work on this with a local GPU. I still ran Claude and Codex, but they were just writing code to orchestrate API calls against local models, local Whisper, etc. Doing the same with the public cloud would have cost thousands of dollars, instead it cost a few hundred dollars for a frontier lab subscription and tens of dollars for electricity.

I recently got into the DGX Spark and just a month ago, got an AMD Ryzen developer platform. Both are incredibly useful tools for some upcoming projects I'm working on (also related to government corruption), but in my limited experience of trying to run opencode on them, the "good models" are still completely unusable because the system prompt alone requires a minute of thinking.

primitivesuave··on Manus will return to operating as an independent company
My non-technical teammates use Claude Cowork extensively. We set up MCP servers to give them audited access to certain internal services, while they just have to think of MCP as a "connector" which they can configure in the GUI.
primitivesuave··on Show HN: Ex-Deloitte auditor open-sourced the whole SOC 2 method for your AI
It's great to see SOC2 going in this direction. I've had to set up all kinds of compliance automation over the past decade (mainly Drata, Vanta, Oneleet), but at the end of the day it's a huge pain grabbing screenshots for what feels like a very performative process.

I asked a SOC2 auditor a while back about why they don't just make their own compliance automation dashboard, so we can pre-fill all their specific requests. They mentioned that certain rules are in place to separate evidence preparation from the actual auditing firms. However, after doing some armchair ChatGPT research, it seems like an audit firm could potentially be permitted to provide evidence management software, as long as you're not guaranteeing an audit result or preventing people from taking the evidence elsewhere. Perhaps you could shed light on the legal aspects and AICPA guidance here for providing evidence collection as AI skills to the companies you audit?

primitivesuave··on Teach yourself programming in ten years (1998)
FWIW, Peter Norvig also gave an updated take on what programming will look like with LLMs around 2 years ago. It did give me some hope back then, but with the development of Fables and Kimis and Sols I think it's truly anyone's guess where the art of programming will go.

https://www.youtube.com/watch?v=ia6aJIplmtc

primitivesuave··on Hannah Fry Wins the Leelavati Prize in 2026 for Mathematics Outreach
Most well deserved. For the uninitiated, highly recommend her 2019 Christmas lectures which are excellent.

https://www.youtube.com/watch?v=_q4DrUHKC0Q

primitivesuave··on What happened to TheNumbers.com
I'm curious how this compares to just using DuckDB in the browser?

https://duckdb.org/2021/10/29/duckdb-wasm

primitivesuave··on What happened to TheNumbers.com
I deployed a Lambda function behind CloudFront which rendered a simple HTML page with the query results from executing some SQL over the dataset. I served millions of page views for next to nothing because most pages were already in the cache.

I don't know where you get this expectation that people should anticipate that a crawler might try every possible combination of query parameters, thereby missing the cache on each one. Most people consider it a bitter and arrogant perspective, which is why this got downvoted.

primitivesuave··on What happened to TheNumbers.com
Yes, if I wanted to put a nice HTML interface over the query results then I would still end up with the same problem where some combinatoric explosion of query parameters to the `/search` endpoint, most of which are cache misses, leads to many many TBs of network egress.
primitivesuave··on What happened to TheNumbers.com
Thanks for that tip, this is exactly how I would do this if I had to do it from scratch. Just in case it's useful for anyone else: https://docs.cloud.google.com/bigquery/public-data
primitivesuave··on What happened to TheNumbers.com
Completely agree, I've worked at several companies where I saw the AWS bill balloon from five to six figures, usually because of pointless over-provisioning. However, it all became worth it when I saw Jeff Bezos go to space. [1]

1. https://www.youtube.com/watch?v=IOmX793-5t4

primitivesuave··on What happened to TheNumbers.com
They were both more exhaustive and more frequent. I don't remember the exact numbers, but it was definitely over 100x the traffic from search engines. By the way, search engines were allowed under robots.txt - I did want all 11.5 million loans to be individually indexed so they would pop up in Google search results, and I actually did receive/forward multiple tips about fraudulent loans because someone searched a business name on Google. All of this traffic was barely a blip, and my AWS bill for my hobby data science account was only ~$50-$100/month.

When I looked at the logs after getting the billing alert, 99.99% of the requests were to the "/search" endpoint with virtually every permutation of ~10-12 facets in the query parameters. There was only one scraper, but it triggered an enormous amount of network egress since it ended up missing the cache on the majority of queries.

primitivesuave··on What happened to TheNumbers.com
A couple years ago, I was running a website which allowed the public to view all the US government handouts to small businesses during the COVID-19 pandemic. It also tracked all the fraudulent loans being prosecuted by the DOJ, and allowed anyone to run structured queries over the public dataset. There was a "donate" button which took in ~$2k in donations over the lifetime of the site, and you could download the entire underlying dataset (around 10 GB uncompressed) for free directly on the site.

Despite the "download all data" link being prominently placed on the front page, the AI scrapers decided it would be more efficient to download terabytes upon terabytes of raw HTML by paginating through every possible facet on the search endpoint. Even with CloudFront caching results and a fairly efficient backend setup, the monthly bill ended up with around $1k just going toward network ingress/egress, so I shut down the site the following month.

primitivesuave··on Canvas is down as ShinyHunters threatens to leak schools’ data
If Boeing claimed a plane was airworthy, but it crashed because basic engineering controls were skipped, we have collectively put our faith in the NTSB to preserve evidence, run an independent technical investigation, etc. There is no such authority for software - most security auditors (SOC2, HITRUST, etc) are just looking at self-reported data.

Just take a look at the recent Epic vs. Health Gorilla lawsuit to see how nonexistent the protection is around exchanging your medical records, one of the most sensitive types of PII.

Page 1 of 32Next →