HNHacker News
TopNewBestAskShowJobs

runningmike

829 karma · joined December 26, 2016

No security no privacy. 0complexity
submissionscomments
runningmike··on Ask HN: React Native or Flutter when the back end is Node?
It depends do you want to maintain ii? Do you use AI? Performance issues can always be solved. Do you want to use browser’s capabilities or keep control in your own backend ? Less frameworks is better, use e.g the same for everything.
runningmike··on Coding Is Not Solved
Parts of this nice read are AI generated it seems…
runningmike··on Dutch Police Arrest 'Reformed' Hacker in Shiny Hunters Investigation
Interesting part “ Those sources said Rey had an ongoing beef with the Dutch hacker over control of the ShinyHunters brand and data, and that the inclusion of the oversized Umbreon Pokemon image in the FBI jobs site defacement was likely an attempt by Rey to pin the hack on the Dutchman.”
runningmike··on Jupyter Ipywidget for Editable Tables
Nice! Do you have a repository where the MIT code is hosted?
runningmike··on Science Is Open Software
100% disagree! Do not mix and cherry pick terms and definitions to make your point. That's not scientific -) Take e.g. a look in https://opensciencemooc.eu/ and check a nice accepted handbook like "The Turing Way" [1]

[1] https://book.the-turing-way.org/

runningmike··on Cyclomatic Complexity in C#
Nice question! Plenty (open) research papers and thesis available the last 40 years -)

Some nice papers: https://arxiv.org/pdf/2002.07135 , https://arxiv.org/abs/2411.17343, https://doi.org/10.25300/MISQ/2025/49.1.075 or see https://arxiv.org/abs/2411.17343

There are many studies about this subject, but mind that complexity in code something different than 'complex' systems. You will need to dive into complexity science , but hard and 'soft' aspects should be taken into account when it comes to cyber security!

runningmike··on Cyclomatic Complexity in C#
From a security perspective cc is highly relevant. I use it to get a solid rating of the security aspects of Python code. I use [1] which is solid and proven.

[1] https://nocomplexity.com/documents/codeaudit/complexitycheck...

runningmike··on The PSF Strategic Plan 2026
"Today we are sharing the outcome: at its July 8 meeting, the PSF Board adopted the PSF Strategic Plan 2026, covering 2026 to 2031."

As someone who loves Python, but lives in the EU I see too much emphasis on PyCON_US and US Python users and US firms. The Python world is far larger than US...

runningmike··on Small Tech: The Need for Principle-Driven Software
The thing is how to deal with principles in practice? Good principles[1] are never trivial. A principle must have implications, some which you can never predict upfront. You will and must have continuous discussing when you use principles to steer your business / software or life.

[1] See e.g. https://nocomplexity.com/documents/0complexity/principles.ht...

runningmike··on I need a clear Python roadmap?
Read one or more of the absolute best (free) Python books[1] and do some hands-on.

If you can not choose, just start with "Python Programming for Data Science". No barrier for starting, its cc-by and requires no account to read.

[1] Check: https://nocomplexity.com/documents/pythonbook/bookreferences...

runningmike··on Not in My Git Yard: Catching Backdoors at Commit and Release Time
Too bad that the focus is open source. This is a common ailment seen in many security research papers!

A real concern should be Code-Level Backdoors in COTS software. Backdoors that even many resellers and paying customers are not aware off..

runningmike··on Teaching NumPy's ufuncs new tricks
Nice deep insight. I love the personal story at the start!
runningmike··on The Story of VS Code | Official Documentary
Is this worth watching?
runningmike··on Type Hints in Python Libraries and Frameworks: An Empirical Analysis of Adoption
Full title: "Type Hints in Python Libraries and Frameworks: An Empirical Analysis of Adoption and Maintenance"

Conclusion: Type hints in Python libraries and frameworks primarily serve as API contracts rather than comprehensive descriptions of implementation details.

I come from C/C++, so for me using Python without type hints is the way forwards. But for some libraries it make sense. As long as type hints "do nothing"...but only for some tools.

runningmike··on A Comprehensive Study of Native Code Bugs in Python Applications
" In this paper, we set out to fill this critical gap, focusing on real-world native code bugs in native Python applications (i.e., software written in Python and C as primary languages, a.k.a Python-C software). We start by collecting and labeling the first set of 1,039 automatically mined and then manually confirmed native-bug-fixing commits from 200 Python-C projects on GitHub. "

I have serious doubt about this study. It's does not meet crucial reproducible research criteria. And most real-world Python-C Application are not FOSS and available on a public repository. But doing research on public repository is easy.

This paper focuses solely on public repositories. This is harmful and fuels the inaccurate perception that open-source software is inherently buggy, a view still promoted by commercial vendors and adopted by many managers worldwide.

runningmike··on Metadata requests no longer tracked in PyPI download counts
Nice improvement! Good reliable statistics for Python package use is a real challenge! So best is to use multiple indicators to get a rough indication!

"This change removes one source of potential confusion and misinterpretation, but does not mean download counts are an accurate measure of how many people use a package."

runningmike··on Firefox's password "security" is mind-numbingly stupid
Some context and nuance: https://support.mozilla.org/en-US/kb/use-primary-password-pr...
runningmike··on Open Source is a cost-allocation system
Nice insight in cost involved with a huge free to use systems, Drupal!

I think it is always better to make a clear distinguish between FOSS and OSS. Just to avoid these kind of issues in discussions again and again!

runningmike··on Show HN: ZMQ Arena – a benchmark harness for ZeroMQ/ZMTP implementations
Great to see this! Nice work.
runningmike··on The Python documentation is now available in Russian
I'll still see many languages still not supported. Translating the Python Docs in another language and maintaining it , is a hell of a job. Nice too see this!
runningmike··on Thinking in Python
Nice to see this! Personally, I prefer CC BY-SA to CC BY-NC-ND, but it is certainly much better than 100% protected. Over the years, I've built and maintain a list[1] of CC BY-SA Python books that have no access barriers, such as mandatory account creation or intrusive web trackers.

[1] https://nocomplexity.com/documents/pythonbook/bookreferences...

runningmike··on Tailscale didn't stop the Hugging Face intrusion
“ the agent ran Tailscale with --no-logs-no-support, which suppresses reporting from that client.

That's an option designed for users who are concerned about sending telemetry metadata to Tailscale.”

And imho a serious security architect should never ever allow telemetry on security products. Far too many risks.

runningmike··on Hugging Face warns an autonomous AI agent hacked its network
"Our anomaly-detection pipeline uses LLM-based triage over security telemetry to separate real signals from the daily noise, and it was the correlation of those signals that flagged the compromise."

After reading https://huggingface.co/blog/security-incident-july-2026:

I still have no clue what was detected or how bad this really is. There are a lot of words, but little to no concrete information. What is the current security architecture like? What is detected, and where? What goes undetected because logs aren't available? How many user datasets are at risk?

runningmike··on JupyDash – turn any Jupyter notebook into a dashboard
Looks nice and interesting. Do you have a repository to the code?
runningmike··on Ask HN: Why isn't Google indexing information about the AT Protocol?
Yes.
runningmike··on The Dogfood Advantage
Dogfooding is for many companies not possible.. Sometimes using another product gives a good perspective too. Never become blind with your own product.
runningmike··on Ask HN: Why isn't Google indexing information about the AT Protocol?
I got 2300 results. DuckDuckGo Uses google. Google is very personalised. They use many dirty tricks to give personalised results. Use another box and check the results again.
runningmike··on Staying in the Game
Is this good or bad news for Bluesky?
runningmike··on Cross-Ecosystem Vulnerabilities in Python Applications
Some notes after reading the paper “Cross-Ecosystem Vulnerability Analysis for Python Applications” (19 Mar 2026, https://arxiv.org/abs/2603.18693v1)
runningmike··on Demystifying Security Risks of AI-Powered Applications on Pre-Trained Model Hubs
Original title: Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model Hubs

Remarking conclusion: "Alarmingly, we find thousands of apps leaking credentials, hundreds containing input injection vulnerabilities that allow arbitrary code execution, and tens harboring embedded backdoors—indicating active exploitation." AI use for creating applications seems insecurity by default...

Page 1 of 8Next →