HNHacker News
TopNewBestAskShowJobs

ryuuseijin

131 karma · joined March 31, 2017

submissionscomments
ryuuseijin··on OpenAI agents tried to bruteforce a UN website's API fields
I believe, although I'm not a lawyer, there would be some liability, but I think a lot depends on intent as well. Punishment for other crimes also varies depending on whether it was an accident or not.

I realise that in this case it was OpenAI being responsible for their agents running wild, and they should know that that is to be expected and should have saveguards in place. If they can be shown to be negligent then the punishment can probably be expected to be a lot more severe than if it was an accident. I make no judgements as to what this particular instance is, but I do believe that OpenAI has a far more greater responsibility for its agents running wild than someone running a home lab.

ryuuseijin··on OpenAI agents tried to bruteforce a UN website's API fields
I clearly have been living under a rock, but in the case where it's just text in/out of their API, and a customer uses this on their own to do nefarious things, I don't see why they would be liable?

If they knowingly allowed use of their services for illegal purposes then yes, but in so far that they provide a service that can be used for useful things (including cyber security research) and did a best effort attempt at abuse, I don't see why it should make sense to hold them liable. This is especially the case now that frontier LLMs are almost a commodity that can be used without restrictions from providers outside of your legal jurisdiction.

ryuuseijin··on OpenAI agents tried to bruteforce a UN website's API fields
Should it be OpenAI, or should it be OpenAI customers who give the LLM the instructions and provide the LLM with the tools to execute code and make (malicious) network requests?

One would disincentivise providing capable AI models that can be used for cyber security research. The other would disincentivise criminals from commiting crimes.

[edit] - I realise now that this could actually be a case of OpenAI running those agents themselves, rather than someone using OpenAI's models? Could OpenAI be that careless?

ryuuseijin··on Evolving programming languages in the AI era
I think starting with a familar typescript-like base language is a good approach to this. This should be familiar enough for LLMs for the most part as long as additional features can be explained in a succinct system promopt/skill.
ryuuseijin··on Evolving programming languages in the AI era
I love this. I was thinking about a "cleaned up" typescript for a while now, and this seems to be it. I believe this can work better as an "ai-first" language than some other attempts I've seen that try to reinvent the language from scratch.

One thing I would love to have as a feature is native compilation.

ryuuseijin··on Show HN: Treepeat – Code similarity detection using Tree-sitter
This is what I wanted to help with duplicate code detection, which is now a real problem with agentic programming since the agent tends to duplicate helper functions a lot in bigger codebases.

I ended up writing my own tool [1] that uses vector search, which works but can be unusably slow in large codebases.

I will give this a shot.

[1]: https://github.com/ninjaxtools/slopdex

ryuuseijin··on Laya on Mac M4 CoreML Offline
The linked github project [1] contains more information.

[1]: https://github.com/mizorewww/laya-coreml

ryuuseijin··on Chat-based Large Language Models replicate the mechanisms of a psychic's con
The post makes sense for 2023. Today, not so much.

Also, definitely not AI written if the date is accurate.

ryuuseijin··on Telling a Computer to Do Things
There are some really powerful UIs that are extremely flexible, like spreadsheets, or ComfyUI, or certain issue trackers. On the whole however I would say they all still are mostly their own interaction silos and integrations with other programs have to be explicitly built for each app.

The great thing about a shell is that you can glue together programs that don't know about each other. This is not a silver bullet, with shell programs being text oriented etc., but it does give rise to some powerful possibilities that don't really work with UIs.

ryuuseijin··on Migrating the GitHub Copilot Runtime to Rust, Using Copilot
The downvote made me reconsider the way I posted, which was unnecessarily breathless by saying "How this passes review is beyond me". I will try not to use this style of writing in the future, which, although very human, is very human in a not so good way.

I think I do make a good point however that the article was very likely AI generated since it is difficult to see a human to write like that, and these are not the only examples of AI writing, the article is full of it.

I think it's fair to be critical of AI writing, especially when put out by a big organisation like GitHub. There was a time where you could click on an article published by the tech company whose product you use every day and expect to learn something interesting. It's another sign of the demise of a once great company.

ryuuseijin··on Migrating the GitHub Copilot Runtime to Rust, Using Copilot
Article is AI generated, maybe lightly human-edited.

> TypeScript, using Node.js as the framework and V8 for the execution engine

How this passes review is beyond me - Node.js is not a framework (at least not how the term is used in the industry) and there is not much choice for the engine since it comes with V8.

> That’s a respectable choice for a TUI application

Meaningless AI filler text.

> A project that would have taken a whole team of developers a year or two before agents

It would have taken a single person less than an hour to write a shorter blog post with the same information, before agents.

ryuuseijin··on Backups Aren't Simple
A bit of a tangent, but the linked rsnapshot tool is about 7k lines of perl code. The COPYING file is 20 years old and it's still maintained, the last change was 6 months ago. I'm feeling really old.

[1]: https://github.com/rsnapshot/rsnapshot/blob/master/rsnapshot...

ryuuseijin··on Ask HN: What are you working on? (September 2026)
https://github.com/ninjaxtools/slopdex

This is my attempt to improve my agentic coding workflow by giving the agent an index into the source code through vector embeddings and LLM generated descriptions with local sqlite as the storage backend.

There are many similar tools, but I wanted to learn how such a tool can work by building it myself. What I like about my own version is that I kept things simple - no MCP, no server, no watches, just a CLI that uses git commit hashes to reindex only what has changed.

ryuuseijin··on All grown-ups were once children, but only few of them remember it
I think the argument is not to not work, but to change the mindset that is so ingrained in our society that you must work. You don't want to starve, so you work, but you can do it with mindset that is fundamentally different, where you choose to focus on being in the moment, and don't let yourself get stressed by outcomes you have no control over, just as you would if you are playing a game or playing music.

Changing your mindset is hard, you are fighting against an entire society where your are expected to be "serious" as an adult and identify yourself with your work, but you do have a choice

ryuuseijin··on All grown-ups were once children, but only few of them remember it
This reminds me of a video I saw from Alan Watts [1] where he talks about how from childhood it is hammered into our minds that we must work we must do this or do that or we will be punished. And he talks about how you can choose to change your perspective or mindset and see work as a form of play, where you live in the moment.

This is probably harder to do than to say, but this video resonated with me because your mindset is something you do have control over, and choosing not to get stressed about work, and choosing not to take things "seriously" and choosing not to do something for the outcome but just for performing the act, just like you would play music (an example he gave) or to see it as a game is something you can do.

[1]: https://www.youtube.com/watch?v=Z9BXvBJ2dWo

ryuuseijin··on AI, Tools and Transformation
Agreed, as things get easier you need fewer accountable people. Organisations will shrink, people will be more accountable by themselves for things they ask the agent to do instead of having an accountable person do it for them.

On the other hand, I think for complicated software there is such a long tail of things that can go wrong, and in your linux example with disastrous consequences, people will pay good money for a long time to have someone who they can call if there is a problem. In the business they have the term indemnification - that's what companies like redhat provide for linux for example and it's probably a big part of what makes them a billion dollar business.

ryuuseijin··on Everything is free now, so why not a floating orb in my IDE
I noticed during my own automatic programming [1] that although code is free (or more free, at least compared to before coding agents) understanding is not. Instead of investing time to understand and master someone else's software tools, I now still need to understand and master what I build for myself, which can be a lot of fun if you build up your understanding from scratch while building out the tools.

[1] https://antirez.com/news/159

ryuuseijin··on AI, Tools and Transformation
> You need audit, security, maintenance and accountability.

I think this is where the role of humans will move towards in the future. Things like accountability can't really be outsourced to AI.

This relates to solving the alignment problem: if you give the AI a specific goal and it has to plan sub-goals, how can you be sure the sub-goals align with your interests.

For tasks in an isloated environment, this doesn't really become an issue. You can give a sandbox the least privileges it needs to do the job you want it to do.

It becomes a problem if you give it open-ended access to systems that connect to the real world and which can have real consequences. There have been stories about openclaw deleting someones email inbox because it though that was what the owner wanted. AI taking control of public wikis to coordinate, which was recently posted is another one.

For software concerns with potential real catastrophic consequences are security, durability, availability. I think for future software systems these are the concerns where you need to limit the AI in a way that it cannot circumvent guarantees that you give around these concerns.

Minor nit:

> AI doesn’t change the question: it creates new choices and moves the thresholds.

This cause an adverse reaction when I read the post. This was probably not written by an LLM since the rest of the article doesn't look like it, but maybe in the future we need to all be more concious about leaving LLM-tells out of our writing.

ryuuseijin··on Portal by Spotify cut my Claude Code token usage by 90%
Here is another technique to save tokens: allow the model to read a skeleton of the source code before reading the code, to give it an index into the code so it can read targeted chunks.

There is a tool that uses ripgrep and treesitter that does this [1], adapted from the maki coding agent.

[1]: https://github.com/ninjaxtools/treesitter-index

ryuuseijin··on fx :Tiny, open, native coding agent.
Since I've seen some other agent tools being suggested, let me throw Maki in the ring as well: https://maki.sh/

- written in rust, super fast startup and rendering

- implements token saving techniques

- plugins written in lua

No affiliation, just think it's a really well made piece of software.

ryuuseijin··on Ask HN: Does anyone else feel like nothing matters anymore?
I agree that AI is a gamechanger in many ways, however it is not the end of life or the end of civilization. Life will go on, and people will be happy productive members of society, even with AI becoming part of everyday life - at least that is what I believe, since believing the alternative would be self defeating.

When I think back to the 90s when the internet became popular, to me, living in the middle of nowhere, being able to interact with others through a computer, it was such an exciting time and it is what got me into programming. I believe right now today, there will be young people who may, just like me, be super excited about this AI thing, want to learn more about it, become a wielder of it, with all the energy and hope that comes with youth, just like when I discovered the internet. To them AI is not a "learn this new thing or you are going to be left behind", but it is probably something that gives them hope.

Even older people can do this. I remember when I was 16 a taxi driver, probably in his 50s asking me to tell him about this internet thing: "what should I do to learn the internet?". I fondly remember this driver since he seemed to have such an innoncent interest and willingness to learn from this 16 year old who didn't know anything himself.

Even with AI, as good as it is now, as well as with it becoming better, people will be part of the process. Although I'm nostalgic about how software used to be created, I'm trying to embrace the new way of doing things and look for new opportunities and a way how I can make a difference, with a positive outlook - this has never failed for me in the past.

ryuuseijin··on Incident with Github.com
https://fly.io/ - it runs the machine and serves the traffic
ryuuseijin··on Ask HN: Alternatives to GitHub
Forgejo is great to self host. I have an easy to use template for setting it up on fly.io with backups here: https://forgejo-fly.fly.dev/forgejo-admin/forgejo-fly
ryuuseijin··on Incident with Github.com
Just going to leave this here - self hosted forgejo on fly.io with restic backups: https://forgejo-fly.fly.dev/forgejo-admin/forgejo-fly
ryuuseijin··on Incident with Github.com
Just going to leave this here - self hosted forgejo on fly.io with restic backups: https://forgejo-fly.fly.dev/forgejo-admin/forgejo-fly
ryuuseijin··on Show HN: Laptop is the last place your secrets are still in plaintext
For development on linux I like to use dotenvx, which lets you put encrypted secrets in an .env file and supply the private key separately.

I have a small wrapper script [1] that prompts for the private key which allows me to paste it from my password manager and launches a shell with the env variables decrypted. This allows me to avoid storing any secrets while still having shell session open where I can terminate and restart a server process for example without having to re-enter the secret all the time.

[1] https://gist.github.com/ryuuseijin/0cf6ab852fbb18d6702933a24...

ryuuseijin··on Getting a Gemini API key is an exercise in frustration
Just a note that you can use opencode with their API gateway (they call it "zen") to get access to all the most popular models using a single account, including gemini. (Although this wouldn't have helped the author, since they wanted to try the Gemini CLI specifically).
ryuuseijin··on Claude Code on the web
Yes, I only use my own keys. It even lets you use your Claude Max subscription.
ryuuseijin··on Claude Code on the web
I'm using opencode which I think is now very close to covering all the functionality of claude code. You can use GPT5 Codex with it along with most other models.
ryuuseijin··on Consistent hashing
Shameless plug for my super simple consistent-hashing implementation in clojure: https://github.com/ryuuseijin/consistent-hashing
Page 1 of 2Next →