HNHacker News
TopNewBestAskShowJobs

runningmike

829 karma · joined December 26, 2016

No security no privacy. 0complexity
submissionscomments
runningmike··on Lotusbail npm package found to be harvesting WhatsApp messages and contacts
Popularity is never a metric for security or quality….Always verify.
runningmike··on The FOSS community acts like a cult and it's not helping the cause
There is no such a thing as 'FOSS community' and FOSS people.

This blogs says a lot about the author...

But flagging this is submission is overkill imho.

runningmike··on Show HN: Merview – OSS Mermaid and Markdown Editor and Viewer
Great to see another FOSS alternative for the defacto marmaid format!

I added this nice tool directly to my collection of great architecture tools. (https://nocomplexity.com/documents/arplaybook/software-archi...)

runningmike··on GIJN's Top Investigative Tools of 2025
The guide on how to quickly identify AI-generated material is great. Link in the article.
runningmike··on How did IRC ping timeouts end up in a lawsuit?
See also https://techrights.org/i/2025/12/case-judgment-summary.html
runningmike··on Put SSH keys in .git to make repos USB-portable
The bad thing is: these kind of blogs are used for LLM trainings. Never trust AI for security advice without thinking and understanding what you do.
runningmike··on Put SSH keys in .git to make repos USB-portable
Is this a joke? It is called “private key” with a reason…
runningmike··on Python Data Science Handbook
https://learningds.org/intro.html Cc-by-nc-nd
runningmike··on Launch-Day Diffusion: Tracking Hacker News Impact on GitHub Stars for AI Tools
Repository on: https://github.com/obadaKraishan/Launch-Day-Diffusion

Statement made in the paper:"GitHub stars are a useful metric" imho not so true...and a dangerous claim!

runningmike··on PyOpenSci Python Package Guide
Python packaging made simple. Recommendations & guidance curated by the pyOpenSci community. Well maintained and licensed under the Creative Commons Attribution-ShareAlike license.
runningmike··on Ask HN: Why aren't more startups using .NET?
Technology choice is by far the least important choice. A business is seldom about technology, but the value for customers. Other factors count more, but your question leaves all important factors out. So the consultant answer is: it depends….
runningmike··on Show HN: Secure private diffchecker with merge support
Do you release the code as FOSS?
runningmike··on Trillions spent and big software projects are still failing
There is no such thing as ‘simplicity science’ that can be directly applied when dealing with IT problems. However, many insights of complexity science are applicable to solving real world IT problems. People love simple solutions. However Simple is a scam, https://nocomplexity.com/simple-is-a-scam/

There are no generic, simple solutions for complex IT challenges. But there are ground rules for finding and implementing simple solutions. I have created a playbook to prevent IT diasasters, The art and science towards simpler IT solutions see https://nocomplexity.com/documents/reports/SimplifyIT.pdf

runningmike··on Personal blogs are back, should niche blogs be next?
“Free” is not free. The dependency on MS should be evaluated for you as user and for your visitors ..
runningmike··on Pre-PEP: Rust for CPython
Interesting proposal, but with severe risks: becoming dependent on a single specific compiler and rustc could include malicious code that isn’t obvious to an outside auditor. See https://aeb.win.tue.nl/linux/hh/thompson/trust.html Ken Thompson demonstrated this.

But what will the future of RustPython be? https://github.com/RustPython/RustPython/

Major shifts like this are complex, not so only from a technical perspective but even more because a lot of humans with different opinions are involved. But radical changes are sometimes needed to be innovative again.

runningmike··on Enisa threat landscape 2025 [pdf]
ENISA analysts collected and analysed 4 875 incidents. Phishing (including vishing, malspam, and malvertising) is still accounting for about 60% of observed cases.
runningmike··on Zensical – A modern static site generator built by the Material for MkDocs team
The new modern static site generator and best for now seems to be Jupyter Book 2 - https://jupyterbook.org/stable/

Launched last week and build upon MyST engine. Makes Shphinx obsolete. Like to see a real comparison with Zensical.

runningmike··on New Glenn Mission NG-2
Entering a hold to allow more time for the weather to clear. New T-0 forthcoming.…
runningmike··on New Glenn Mission NG-2
New Glenn launch Live
runningmike··on Python in Excel: The Future or Merely a Gimmick?
Python with open office calc is doing a great job for years.
runningmike··on Ask HN: What is a passkey and why is everybody asking for one lately?
https://www.eff.org/deeplinks/2023/10/what-passkey Or see

https://news.ycombinator.com/item?id=45736872

runningmike··on Uv is the best thing to happen to the Python ecosystem in a decade
Seems like a commercial blog. And imho hatch is better from a Foss perspective.

UV means getting more strings attached with VC funded companies and leaning on their infrastructure. This is a high risk for any FOSS community and history tells us how this ends….

runningmike··on Passkeys: They're not perfect but they're getting better
“Passkeys are the future of authentication” …this is not the future I hope….When Google, Microsoft and a lot of other B*G-Tech companies promote Passkeys, you know it is not done to protect your security and privacy.

Nice read https://techrights.org/n/2025/05/02/Passkeys_Are_Vendor_Lock...

runningmike··on Tech Trends Report 2026
The full report has 189 pages and can be downloaded at https://surfdrive.surf.nl/index.php/s/DX4kegErJxLwHaM

Report is created by SURF, the IT cooperative of Dutch education and research institutions.

runningmike··on Show HN: I Spent $300 Learning That Replit Has SSH Support
Nice work! Are you planning to open source the code?
runningmike··on Gecko Security (YC Company) Allegedly Steals CVE Reporting Credit
Reaction: "Disappointed to see public accusations without reaching out first, especially after launching a competitive product.

We work directly with maintainers via GitHub, not bounty platforms. Neither we nor the maintainers knew about your Huntr reports at the time, otherwise they would have been marked as duplicates.

We've publicly credited FuzzingLabs for the 2 CVEs where your findings came first, and we're always happy to credit whoever finds them before we do.

The claim about stolen CVEs doesn't hold up when many links you provided were already marked as "duplicate" or "invalid" on Huntr."

source: https://x.com/gecko_sec/status/1977805927320551672

This is become a flame-war.

runningmike··on Netherlands cracks down on China-owned chip firm over security risk
A real dangerous actions and precedent from this government in what was once a normal democratic country…
runningmike··on State of AI Report 2025
I love these kinds of open-access reports. No registration needed for reading, and just simple cc-by. I miss some predictions, so here some more:

AI investments will lead to far more disappointments

More reality that AI/ML solutions do not fit every problem.

More and heavier Security and Privacy breaches

runningmike··on CamoLeak: Critical GitHub Copilot Vulnerability Leaks Private Source Code
Somehow this article feels like a promotional for Legit. But all AI vibe solutions face the same weaknesses. Limited transparency and trust Issues: Using non FOSS solutions for cybersecurity is a large risk.

If you do use AI cyber solutions, you can be more vulnerable for security breaches instead of less.

runningmike··on Python 3.14.0 is now available
Python 3.14 has great new features like: - Free-threaded Python is now officially supported

- Template string literals (t-strings) for custom string processing

- Syntax highlighting in PyREPL and more!

Great work , congratulations with this release!

← PreviousPage 3 of 8Next →