HNHacker News
TopNewBestAskShowJobs

rectang

16,678 karma · joined October 5, 2014

submissionscomments
rectang··on Noise infusion banned from statistical products published by Census Bureau
Ranked Choice Voting makes it easier to vote for “less bad” candidates.

RCV also tends to work against polarization, since it rewards candidates who are at least acceptable to a broad swath of the electorate.

It may not be the “answer” for all that ails the American political system, but it would help.

ETA: Unlike many other reforms it's also doable within the constraints of the current constitutional order and is hard for SCOTUS to torpedo (though I suppose I shouldn't underestimate SCOTUS).

rectang··on How to setup a local coding agent on macOS
Does anybody run a local agent on a Mac using an outboard GPU?
rectang··on LLMs are eroding my software engineering career and I don't know what to do
Yes, and that demonstrates that developers are not immune. And so, developers who suspect they're being asked to do something illegal (but aren't sure) are going to act as sticklers who irritate enterprise architects until you take concrete action to reassure them.

Complain about them, denigrate them, upbraid them for performing analysis outside their primary expertise, fire and replace them.... none of that changes the incentive structure that shunts people in the implementation role towards conservatism out of a perceived need for self-preservation.

rectang··on LLMs are eroding my software engineering career and I don't know what to do
But here we're talking about developers being asked to implement decisions which they don't understand to be compliant.

Engineers are not shielded by their implementer role if they participate in illegal activity. James Robert Liang was a rank-and-file engineer for Volkswagen and he got jailed for his role the VW emissions scandal[1].

No matter how much an enterprise architect or compliance officer promises "it'll be fine" to the developer, the developer needs documented CYA. An enlightened organization would perhaps find ways to expedite that CYA documentation rather than demonizing programmers as a class.

[1] https://apnews.com/general-news-988ea2ae45694b37b320e68cefe3...

rectang··on LLMs are eroding my software engineering career and I don't know what to do
I am skeptical that developers who implement a non-compliant solution that gets a company in trouble get off scot-free.

If the company you work for actually had such a no-fault culture, I doubt you'd be criticizing programmers so aggressively for being sticklers, but would instead be trying to understand and account for the systemic factors (including human factors) behind their behavior.

rectang··on LLMs are eroding my software engineering career and I don't know what to do
In your world, do subordinates ever get scapegoated for bending the rules at a boss's behest?
rectang··on Public Domain Image Archive
Eventually there will be successful copyright lawsuits for derivative images produced by LLMs. Copyright laundering is an illusion.
rectang··on Public Domain Image Archive
There are lots of sites that provide images that somebody has claimed are public domain. But for significant use, you what you really need is provenance documentation.

These folks seem to be more up-front about the issue than many sites I’ve seen:

https://pdimagearchive.org/reusing-images/

> On each image page we communicate to the best of our knowledge the rights status of both the underlying work and the digital copy of this work. We provide this information based on a basic knowledge of copyright law and what is communicated by the source institution — it is strictly meant as a guideline and it should not be taken as legal advice. We admit no responsibility for any untoward consequences that may arise through reuse of material featured on our site. If you are requiring certainty as to usage allowed for an image, then you are encouraged to check with the source institution and make your own investigations.

rectang··on Squillions: How money laundering won
A great opportunity for selective enforcement!
rectang··on Malicious npm packages detected across Red Hat Cloud Services
I'm using VSCode dev containers, powered by Podman on a Mac. Most people would probably choose Docker over Podman but I'm weary of Docker and wanted to try something else. I would not consider myself an expert on containers but with the help of Claude I've been able to fight my way through various challenges:

* Persist a volume for Claude so that conversations don't get blown away with every container rebuild. An attacker may still be able to get a Claude token from me, which is something I'd like to tighten up in the future.

* Fix file permissions issues by running rootful inside the container. (The container process still runs on the host as an ordinary user. Since my threat model is "compromised dependency scanning for credentials in project dir and home dir" rather than "attacker escaping the container", I figured that was good enough to get started.)

* Work around architectural availability issues with precompiled PyPI libraries. This I punted on by choosing a different approach and eliminating the problematic dependency (by writing my hobbyist CAD 3d printing stuff using Blender extensions instead of CadQuery). I've gotten the impression that dependency compatibility with a container workflow is an ongoing challenge.

* Run a database in a docker-compose sidecar for integration testing.

For all the projects I'm containerizing I'm the solo dev with full control over the Git repo so I can make the call to add a `.devcontainer/devcontainer.json` config file. I haven't yet explored how to isolate projects I don't control.

rectang··on Malicious npm packages detected across Red Hat Cloud Services
About a week ago, I uninstalled Node from my laptop, which felt great. :)

I'm trying to do all work in dev containers (or other sandboxes), limiting the blast radius if I'm unlucky enough to be hit by an exploit. The attackers may get a Claude token, but they won't easily be able to escape the container and scan my home dir.

Cooldowns and allow-listing of installer scripts are good additions to layered security, especially for CI. However, I think the fundamental thing that needs to change is the OS permissions model. The default of trusting third-party software with everything your user has access is no longer workable.

rectang··on Roughly a quarter of American professionals hit a wall in their careers
From the perspective that a company is an amoral profit-seeking automaton, it's not a "terrible system", it's a successful initiative to reduce compensation.
rectang··on NPM packages from Red Hat have been compromised
Opponents of gun control surely feel the same way about the Onion’s story.
rectang··on The dead economy theory
> people need jobs to be happy

The happiness of the aristocracy depends on the spectacle of miserable workers performing humiliating tasks.

rectang··on Legislation Killed Would Have Effectively Blocked Police LPR, Including Flock
> Just yesterday, flock helped police catch a dude

"Those who would give up essential liberty to purchase a little temporary safety deserve neither liberty nor safety."

— Benjamin Franklin

rectang··on Dutch block US takeover of Solvinity as against public interest
> The proposed deal drew opposition from lawmakers and activists because Solvinity provides infrastructure for DigiD, the digital ID system Dutch citizens use to access sensitive medical, pension and tax information.

Understandable that the Netherlands wouldn't trust the USA with its citizans' data.

rectang··on Training our own AI models
I think the lesson from the airline industry is that while consumers will get angry about surcharges, pricing transparency is what really gets punished in the marketplace. There are enough consumers who will always buy the deceptively priced item that it's suicidal to tell the truth (absent government regulation forcing the issue for all purveyors).

There are a fair number of well-meaning restaurateurs who have tried no-tip policies for ethical reasons. But the mass marketplace has not changed.

rectang··on Training our own AI models
I used to wait tables once upon a time and it was standard practice to add a fixed service charge for any large party in lieu of a tip. Have you really never encountered that?
rectang··on Training our own AI models
Do you leave a negative review if they add the service charge but don't ask for a tip?
rectang··on Don't Subscribe So Casually
Companies who wish for more casual subscribers should support services (such as Apple App Store subscriptions) and anti-dark-pattern laws which reassure the public that unsubscribing will be easy.

Then the complacency and other psychological effects that this article seeks to inoculate users against will be maximized.

rectang··on Magnifica Humanitas
I prefer the term "software developer" and that's what I use when I don't need the prestige of the term "software engineer". It's disadvantageous for organizations to do that with actual job titles, though.

Absent US government intervention to codify the term "engineer", probably the only way out of the "engineer" trap is through further title inflation, where the developers all become "vice presidents". :)

rectang··on Jira Is Turing-Complete
Even more nauseating than https://brainfuck.org
rectang··on Toxic chemical leak at a manufacturing facility in Orange County
From what I hear[1], we should be relying on the fact that environmental disasters are bad for business in a true Scotsman "free market".

[1] https://news.ycombinator.com/item?id=48238025#48240301

rectang··on U.S. researchers face new restrictions on publishing with foreign collaborators
The idea that being "bad for business" is a sufficient disincentive to dissuade commercial entities in a free market from harming and killing people is risible.

Even if you eliminated the immunity shield for corporate leadership so they couldn't skate after their company goes bankrupt, there would still be innumerable risk-takers willing to gamble with human lives to make more money.

I expect the argument you want to make is that having people harmed and killed is an acceptable sacrifice for greater economic efficiency, but you're aware that it doesn't play well — especially when the benefits of economic efficiency tend to flow to the people doing the killing rather than the people being killed.

rectang··on Fender escalates legal campaign against S-style guitars
> It's Fender abusing the courts

I think "BigCo abusing the courts" — or alternately, "courts are designed to facilitate abuse by the wealthy" — is the essence of this story.

The case is dicey at best on the legal merits. It also offends community sentiments because it's a rugpull against businesses who wouldn't be copying if the design had been defended from the start.

But none of that matters because Fender can exhaust the resources of the companies it's targeting. All that matters is who can pay their lawyers the longest in a war of attrition.

Rock 'n' Roll has died many deaths. I suppose this is just one more, but it still hurts.

rectang··on Everything in C is undefined behavior
> the upshot is you never need to deal with the Rust community

In the end, everything comes down to culture war.

rectang··on Dumb ways for an open source project to die
This is basically a problem with Open Source hosted at Github, right? Because Github doesn't allow you to turn off PRs for people outside your organization.

Since Github has been asked to change this policy since time immemorial and has not responded, another possible response is to host your project somewhere else that doesn't have the same policy and/or doesn't have the same volume of spammers. Of course that means that you don't get the benefits of hosting at Github, but the cost/benefit ratio of hosting there has changed over time.

rectang··on Fender escalates legal campaign against S-style guitars
If a guitar company were attempting to enforce IP rights on a new design instead of one from 75 years ago with a decades-old cottage industry of copycats large and small, this would be a different story.

Small builders like LsL have the community’s sympathy. They don’t have the resources to fight a legal battle against the world’s largest guitar company.

rectang··on Shutterstock to pay $35M over hard-to-cancel subscriptions
Did Shutterstock come out money ahead?

Is 35 million and the potential for future punishment a sufficient deterrent?

rectang··on The Third Hard Problem
At least the title “The Third Hard Problem” is still appropriate regardless of whether you get the joke right.
← PreviousPage 3 of 34Next →