HNHacker News
TopNewBestAskShowJobs

quinnjh

258 karma · joined September 20, 2021

personal site Https://Quinnjh.net view as a graph here https://qjarvisholland.github.io
submissionscomments
quinnjh··on Building a certificate authority for the whole Internet
Who do you like to go with for certs?
quinnjh··on Guitar amp and effects pedal built on the Waveshare ESP32-S3-Touch-AMOLED-2.06
I was wondering how they got any usable latency with esp32. External adc/dac card- okay

Has one been built ? Not clear from the docs

quinnjh··on Exit the Cave
What did you build? Can’t find on your profile/submissions
quinnjh··on What's the best programming language for coding agents?
Strongly agree- this is how I “evaluated” languages pre-agents. though I suspect this would bias results in favor of whatever has best signal to noise for boilerplate from stackoverflow/reddit , rather than what LLM’s “””reason””” best with. (Presuming those aren’t quite one-and-the-same)
quinnjh··on Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
Can't tell if you're joking or not - krebs on security may have some notes here.
quinnjh··on OpenAI and Hugging Face address security incident during model evaluation
To quote the release:

> This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities. We estimate maximal cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity.

> In this case I don't think the intent of the user is to have the model break the evaluator

If i understand the quote, the intent of the user was to prompt the model to break out/find exploits, with safeguards switched off.

Seems while not capable of solving the goal in a traditional route, it was capable of finding exploits and using them.

Perhaps the model should instead look like it's trying to solve it and then pretend it is unable to? or would that be aligned _against_ the user prompt?

Is being aligned with the user prompt always a good thing?

I'm not one to glaze OAI here for a marketing move, but to give them benefit of the doubt, isn't it more responsible of them to evaluate the models actual capabilities than to cloak it in a veneer of harmlessness?

Chatbots are tricky as they play in the domain of language and thought - and certainly raise ethical issues- but the entire field of cybersecurity has decades of red team engagements breaking things and finding exploits, neutral cells monitoring the engagement and letting the system operators know the results, and blue teams patching against what is found. It's kinda how the whole space evolves. OAI's play here seems to be "buy our pro plan plus cyber or you're toast"

quinnjh··on OpenAI and Hugging Face address security incident during model evaluation
They mention that it cost a significant amount of inference , meaning they paid a significant amount of api usage on returning results to a prompt that specifically stated the long running goal is to find and use an exploit, with safety guardrails off.

the model is aligned with the org - openAI, and presumably the orgs interests. hugging face gets a red-team engagement (possibly for free?) and can work on patching it while openAI gets a Mythos style PR moment.

It completed its assignment and furthered interests of the two parties involved. Could you explain the misalignment?

quinnjh··on Show HN: Word in Web – Near MS Word Parity Docx Editor in Web
Rad. Thanks for sharing! Will give it a spin and check out the repo.
quinnjh··on Global review confirms mRNA vaccines are safe, effective and full of promise 
Certainly not _all_ of it, but a few billion at least.

for the curious:

https://www.usaspending.gov/search?hash=5ec35bf87ec1fd63d28d...

quinnjh··on I am retiring from tech to live offline
This makes me think of how boxed cake recipes decided to leave out the eggs because people liked to still feel like they were "cooking" for people.
quinnjh··on ProgramBench: Can language models rebuild programs from scratch?
Well there goes my hunch!

Thanks for the input

quinnjh··on Agents need control flow, not more prompts
For the non haskell folks like myself, what would that look like/ why is parsing better? Perl i get
quinnjh··on ProgramBench: Can language models rebuild programs from scratch?
My hunch is that it would take years of hundreds of thousands of developers working with machine code, posting stackoverflow questions with machine code, and publishing github repos written on it with documentation. Thats all the free labor LLMs leveraged to use high level langs.

>We won't be developers, we won't be devops, we'll be modelops! /s

I can still see this happening with higher level langs. the thing is the compiler is not replaced in the training data, more likely LLMs will give rise to semideterministic layers on the compilers

I could see nvidia achieving this first with how nice the devex is with CUDA

quinnjh··on Quantum Computers Are Not a Threat to 128-Bit Symmetric Keys
> for RSA and ECC, is there anything preventing us from using keys 10x bigger?

you can run benchmarks yourself: openssl speed rsa1024 rsa2048

also this (slightly dated) java ex writeup covers this well: https://www.javamex.com/tutorials/cryptography/rsa_key_lengt...

tldr trade off is found between better performance and how many years the data needs to be assumed confidential

quinnjh··on Qwen3.6-35B-A3B: Agentic coding power, now open to all
is it possible to have greater success with the specificity? I don't think i ever drew a bike frame properly as a kid despite riding them and understanding the concept of spokes and wheels...
quinnjh··on Music for Programming
This site is a gem that has accompanied me on many spikes in the last year :) datasette's original music is top tier too. cognitively stimulating but not attention stealing.
quinnjh··on Running Gemma 4 locally with LM Studio's new headless CLI and Claude Code
so no subscription is needed?
quinnjh··on Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
https://www.csoonline.com/article/3844047/cisa-cybersecurity...
quinnjh··on Returning to Rails in 2026
>If we are all supposed to be talking to agents now, what's the difference[...]?

it's a little cringe, but arguably the benefit of having agents use rails would be tht when you review and audit the agent produced code, you review something that is, as you put it: "beautiful and simple code" and "making it easy to reason about..."

I loved rails back in 2017. I may be an outlier but the line tempts me to try it again despite having adopted the who cares attitude to langs. Would be nice to hear from someone first hand if they felt it helped.

quinnjh··on MyFirst Kids Watch Hacked. Access to Camera and Microphone
Article was a bit of a nothingburger for the technically inclined.

Digging into the paper, the significant finding (RCE) is achieved via:

A payload was written which installs a reverse shell backdoor for root persistence. The payload was sent from a computer hosting a Wi-Fi to which the watch was connected, to ensure the watch had a reachable IPv4 address. The program ncat was used both to send the payload to the watch's network service, and to catch reverse shell connections.

So if i understand this- it requires the watch being connected to a compromised AP. Anyone get a different read?

quinnjh··on Diode – Build, program, and simulate hardware
I haven't managed to design a pcb without finding an issue in the first run.

Shoutout to OSHpark's prototype service. Something like 5 bucks an inch and you only have to toss out 3 if you find a fault.

quinnjh··on Binance fired employees who found $1.7B in crypto was sent to Iran
What was the benefit to you over using USD? (actually wondering)
quinnjh··on Web 4.0
Very curious project! Enjoyed the storytelling buildup on the site.

Digging into the repo i can see over 50 open issues from the past few days with a lot of requests for refunds.

Are there any "success stories" ? Could go a long way to building trust in the tool.

quinnjh··on 60 Year old vibe coder create revenue SaaS with vibe agent and vibe testing tool
earlier show hn thread: https://news.ycombinator.com/item?id=4548251
quinnjh··on Minions: Stripe’s one-shot, end-to-end coding agents
Definitely seemed like a ballmer joke to me, with how it changes size
quinnjh··on So you want to build a tunnel
google ai estimates that 4.7 billion hours have been spent in minecraft. At least these are real :)
quinnjh··on So you want to build a tunnel
We love engineer Kala. She decided to do a thing, while marking progress on her "technology tree" of skills gained by (very arguable) necessity. Dealing with permits and city beuaracracy seems like one of the hardest parts!
quinnjh··on Claude Opus 4.6
the field is advancing so fast it's hard to do real science as their will be a new SOTA by the time you're ready to publish results. i think this is a combination of that and people having a laugh.

Would you mind sharing which benchmarks you think are useful measures for multimodal reasoning?

quinnjh··on A few random notes from Claude coding quite a bit last few weeks
> Definitely, like drug dealers, you know they're cutting the good stuff with low cost cached gibberish.

Can confirm. My partner's chatGPT wouldnt return anything useful for her given a specific query involving web use, while i got the desired result sitting side by side. She contacted support and they said nothing they can do about it, her account is in an A/B test group without some features removed. I imagine this saves them considerable resources despite still billing customers for them.

how much this is occurring is anyones guess

quinnjh··on After two years of vibecoding, I'm back to writing by hand
This analogy works pretty well. Too much time doing everything in it and your muscles will atrophy. Some edge cases will be better if you jump out and use your hands.
Page 1 of 7Next →