HNHacker News
TopNewBestAskShowJobs

runningmike

829 karma · joined December 26, 2016

No security no privacy. 0complexity
submissionscomments
runningmike··on Permissive vs. Copyleft Open Source
Title should have [2025], since this blog is from 2025.

On subject: In 2026 I hope the wars FOSS vs OSS and copyleft vs permissive are over.

This article has a lot of nonsense. In practice you should choice a license that meets your goal. So do not choice a license from an ideology , a license has a purpose and every project has a different goal.

"This means as an author of some copyleft code, I have special rights that my users don’t have: I am allowed to use my code for proprietary purposes" -> Nonsense: Everyone has the same rights! You can not revoke a license, and re-licensing your own GPL code has more nuances than stated in this article.

For every OSI approved license is a place in 2026 and a good use case thinkable. So some more nuance in 2026 and more references to scientific studies over this subject of more than 30 years history would improve this old article.

runningmike··on Data Privacy while using API tools
Your questions is rather general. But a try: "What’s the best Postman alternative if privacy is a concern — Postmate Client vs. Thunder Client?"

- Always use a local client (100%) that you fully control. - Be aware tat many providers have advanced finger printing techniques. So reaching out to a remote API is always a severe privacy risks! At least when you make an API call from you 'own' computer/home/work to an API-service. - Most 'tools' for making API tools use telemetry. If you use a tool within a IDE that uses Telemetry you could be harmed twice. (E.g. VSCode with Thunder Client)

runningmike··on Software Is Becoming Marketing
Nice write-up... but with strong opinions that seem plausible, yet are highly debatable.

"The rise of the long tail" -> To my knowledge the 'long tail' was years ago a subject of many scientific business studies. The conclusion: proof was never found for this economic theory. And yes, the book of Chris Anderson (20 years ago!) was an attractive read that also seems plausible.

"The barrier to entry for software has fallen." -> This is the marketing mantra since 4GL and IDEs. Visual coding IDEs, so coding without knowing coding never worked out as marketers promised, Same with nocode things years later.

Truth is programming in a natural language is very hard, that's why we have programming languages. And the hard part was never programming, but problems solving and gathering requirements before programming. Or during programming if you are fan of the agile community. AI/ML technology is a great tool for solving some problems, but certainly many problems can not be solved with AI for coming years. AI can not replace people, but people who do not add much value are, have been, and always will be the first to encounter technology progress.

runningmike··on Behind Python: The Languages That Power AI
The conclusion of this paper is not a surprise. Still wondering what the value of this research paper is for the long term.
runningmike··on Pandas for Reproducible Data Analysis
Full title:Pandas for Reproducible Data Analysis: From Spreadsheets to Research-Grade Python Workflows
runningmike··on Pyodide 314.0: Python packages can now publish WebAssembly wheels to PyPI
Great news. And indeed a nice step to an even broader Python ecosystem.
runningmike··on Are insecure code completions in PyCharm a vulnerability?
“ Are insecure code completions a vulnerability?” No it might be a potential security weakness. Semantics matters.

See also: https://nocomplexity.github.io/pythonsecurity/fundamentals/w...

runningmike··on Crucial and Vital Security by Design Principles
Security by Design principles do not guarantee security. They are a mandatory aid to thinking, not a replacement for it.
runningmike··on WordPress 7.0
AI-Integrated WordPress….still not sure if this is good or bad. It will definitely be a disaster for the revenue of many smb web agencies.
runningmike··on Open and Free Security Books
A curated, opinionated list of high-quality cyber security books.
runningmike··on Ask HN: How do you approach a new codebase?
Assuming you have a c or cpp project: compile and build it first , run the tests if any.. and run cscope or equivalent on code you want to change first.
runningmike··on Learning Software Architecture
Nice read. “ Learning Software Architecture” means understanding that there is no single good answer. It is art and science.

Read tip: Simplify IT - The art and science towards simpler IT solution https://nocomplexity.com/documents/reports/SimplifyIT.pdf

runningmike··on OWASP Foundation's Strategic Plan [pdf]
The OWASP Board has released its new Strategic Plan to tackle software security.

I haven’t quite made up my mind about the certification programmes yet. There are already so many out there for security, and most seem to cover the same ground.

runningmike··on Quarkdown – Markdown with Superpowers
Nice! But in the Comparison should be MyST - https://mystmd.org/ This is the new markdown standard to be….
runningmike··on A Practical Introduction to Constraint Programming Using CP-SAT and Python
Nice blog but title should end with (2024).

I would recommend reading: "The CP-SAT Primer: Using and Understanding Google OR-Tools’ CP-SAT Solver" - https://d-krupke.github.io/cpsat-primer/

When starting with CP-SAT. The google docs are not great unfortunately.

runningmike··on ChatGPT, Is This Real?
Full title: ChatGPT, is this real? The influence of generative AI on writing style in top-tier cybersecurity papers

"we find a sharp rise in the frequency of LLM-favored marker words such as underscoring and enhancing."

runningmike··on Security Concerns in Generative AI Coding Assistants
Original title: Security Concerns in Generative AI Coding Assistants: Insights from Online Discussions on GitHub Copilot

"the sentiment expressed across all concern areas is generally skewed toward the negative end of the polarity scale."

runningmike··on Google has a secret reference desk
Nice article. But the warning can be stronger imho: Instead of: "Don’t assume your results are the same as anyone else’s."

"The results search you get from G*gle results are unique."

G*gle does not use the easy to use Lucene search syntax but has many 'magic' things, like:

Searching for high-quality Open Access content or solid technical answers on software challenges requires a rigorous scientific methodology, combined with creativity and extensive experience. Despite being a crucial competency, it is rarely taught in depth.

Even with the rise of LLMs, effectively navigating search results remains an unsolved problem.

runningmike··on How Complex is my Code?
To do a Simple Cyclomatic Complexity check, operating on the principle that secure systems are simple systems, you can use https://github.com/nocomplexity/codeaudit or try the wasm version on https://nocomplexity.com/codeauditapp/dashboardapp.html

Complexity directly impacts security. Simple systems are: Maintainable: Easier to change and manage. Reliable: Less prone to logic errors. Testable: Easier to validate and test.

runningmike··on Open source died in March. It just doesn't know it yet
100% click bait title indeed!

We are brainwashed by commercial vendors to advocate for complex, expensive cyber security solutions that are costly to implement and lack transparency.

Most (commercial) cyber security solutions are not future-proof and not maintainable in the long term. Most cyber security improvements programs end with more paperwork and more new fancy software tools, without increased security resilience.

runningmike··on I Quit. The Clankers Won
Love the one-armed code bandit on the home page of this blog! Nice UX experience! See: https://dbushell.com/
runningmike··on Unlocking Python's Cores:Energy Implications of Removing the GIL
Title shortened - Original title:

Unlocking Python’s Cores: Hardware Usage and Energy Implications of Removing the GIL

I am curious about the NumPy workload choice made, due to more limited impact on CPython performance.

runningmike··on Odido Security Breach – 6M Customers (Full Timeline and Analysis)
Odido’s Biggest Failures misses the key points, in my opinion: 1) a lack of "security by design" and 2) insufficient security monitoring.

By centralising and outsourcing all data to what appears to be a Salesforce Cloud solution, this was a disaster waiting to happen. If even minimal security monitoring had been active, someone should have noticed something. It is also possible that the security management department was competent, but senior management failed to understand or act upon the advice provided.

runningmike··on Security Risks of AI Agents Hiring Humans: An Empirical Marketplace Study
Study based on the website https://rentahuman.ai/ Minority Report next level?
runningmike··on Simplify IT: The art and science towards simpler IT solutions(2025)[pdf]
Problem Solving Methods (PSMs) are key for solving complex problems.
runningmike··on What came first: the CNAME or the A record?
The end of this blog is …. “ To learn more about our mission to help build a better Internet,”

Reminds me of https://news.ycombinator.com/item?id=37962674 or see https://tech.tiq.cc/2016/01/why-you-shouldnt-use-cloudflare/

runningmike··on The recurring dream of replacing developers
“ AI: The Latest Chapter in a Long Story” More the current chapter. Curious about the next one!
runningmike··on The Tulip Creative Computer
It was a great innovative company in the Netherlands. They designed and manufactured everything themselves. Hardware boards and software. See https://www.homecomputermuseum.nl/collectie/tulip/?srsltid=A...
runningmike··on Simple Is a Scam
There are a lot of similarities between IT companies that promise simple IT solutions with criminals and fraudsters that offer ‘Get-rich-quick’ schemes.
runningmike··on LLM Learning Resources
Understanding how LLMs work is challenging. But learning the core concepts is should be fun. Good news is that great open tutorials are created that give you a kickstart when working with LLMs.
← PreviousPage 2 of 8Next →