HNHacker News
TopNewBestAskShowJobs

samdoesnothing

77 karma · joined July 2, 2025

submissionscomments
samdoesnothing··on Go Proposal: Secret Mode
Does it? I'm not disputing you, I'm curious why you think so.
samdoesnothing··on How private equity is changing housing
You're absolutely right of course. Even a child could look at the present situation and determine that the solution is to simply build more housing, but for some reason many grown adults cannot accept such a simple solution and insist that what's actually needed is more government regulation or something.
samdoesnothing··on Kaiju – General purpose 3D/2D game engine in Go and Vulkan with built in editor
Making a game with Godot or Unity is much easier than making an engine.
samdoesnothing··on Horses: AI progress is steady. Human equivalence is sudden
It's inflation, simple as that. The US left the gold standard at the exact same time that productivity diverged from wages. Coincidence? No.

Pretty much everything gets more expensive, with the outliers being tech which has gotten much cheaper, mostly because the rate at which it progresses is faster than the rate at which governments can print money. But everything we need to survive, like food, housing, etc, keeps getting more expensive. And the asset class get richer as a result.

samdoesnothing··on Horses: AI progress is steady. Human equivalence is sudden
Barely affected? They benefit massively from it. That is why the rich get richer.
samdoesnothing··on Has the cost of building software dropped 90%?
Also blind leading the blind here but I see two paths.

1) Specialize in product engineering, which means taking on more business responsibility. Maybe it means building your own products, or maybe it means trying to get yourself in a more customer-facing or managerial role? Im not very sure. Probably do this if you think AI will be replacing most programmers.

2) Specialize in hard programming problems that AI can't do. Frontend is probably most at risk, low level systems programming least at risk. Learn Rust or C/C++, or maybe backend (C#\Java\Go) if you don't want to transition all the way to low level systems stuff.

That being said I don't think AI is really going to replace us anytime soon.

samdoesnothing··on Cancer is surging, bringing a debate about whether to look for it
Surely it has nothing to do with the proliferation of chemicals and microplastics into the ecosystem, water, food, etc. That would be absurd, after all, a Monsanto-sponsored study found that their pesticides are totally safe.
samdoesnothing··on AI should only run as fast as we can catch up
I do this but with copilot. Write a comment and then spam opt-tab and 50% of the time it ends up doing what I want and I can read it line-by-line before tabbing the next one.

Genuine productivity boost but I don't feel like it's AI slop, sometimes it feels like its actually reading my mind and just preventing me from having to type...

samdoesnothing··on Ask HN: Who else got pwned by the Next.js RCE?
I'm sure a lot of people and companies got pwned and they aren't going to disclose it. There are chrome extensions that passively polls sites for the vulnerability, and since the vulnerability is so simple to exploit and leaves virtually no trace...

My gut feeling is that we are going to be feeling the consequences of simultaneous enshittification of software, the mounting complexity of our systems, and AI enslopification combine to create far more vulnerabilities in the future. The only defence is to adopt simple systems and software.

samdoesnothing··on The programmers who live in Flatland
If something is marginally better, it's not guaranteed to win out because markets aren't perfectly rational. However if something is 10x better than its competitors it will almost always win.
samdoesnothing··on Germany votes to bring in voluntary military service programme for 18-year-olds
Everybody who talks like this is unwilling to fight themselves.
samdoesnothing··on Germany votes to bring in voluntary military service programme for 18-year-olds
Haha you think the youth own homes? It'll be young people dying so old people get richer just like every other war.
samdoesnothing··on Influential study on glyphosate safety retracted 25 years after publication
What is your point? That we should put more effort into protecting against asteroids? I'm sure you could make a convincing case for that.
samdoesnothing··on The past was not that cute
I wonder why it is that the past seems more real and the present dishonest and fake? Is it simply that it is?
samdoesnothing··on Influential study on glyphosate safety retracted 25 years after publication
How do you make that calculation when there is a small possibility of infinite risk? That is why the PP exists, otherwise you either ignore the possibility of total disaster events, or you cannot choose to act.
samdoesnothing··on Influential study on glyphosate safety retracted 25 years after publication
> I'm saying that the Precautionary Principle calls for exactly that position

Not necessarily. The PP is interpreted so many different ways, it was actually invoked by people like Nassim Talib to not only justify the vaccine rollout but to call for strict lockdowns among other measures.

There are many arguments made against the precautionary principle, just like there were many arguments made in favour of leaded gasoline. We all know who ended up on the right side of history on that one, and I expect it will be the same for roundup.

In the context of this article, we are discussing the PP as relevant to regulatory agencies. The EU employs the PP while the USA takes something called the Scientific Approach - in other words, the EU requires evidence that an intervention carries no risk, whereas the US requires proof that an intervention has significant risk in order to ban it. Idk about you, but I feel a lot better eating food grown in Europe.

Your position isn't unique, there are many very intelligent people who nonetheless overestimate their capacity for understanding the world and predicting the future.

samdoesnothing··on Influential study on glyphosate safety retracted 25 years after publication
No because it wasn't mandatory in most places, so there was no systemic risk. People were free to take it, in the same way people are free to drink alcohol, and the precautionary principle doesn't apply to individual risk.

I still think we are talking about two different things here.

samdoesnothing··on Cloudflare outage on December 5, 2025
I agree, I was just commenting that your single server being simpler is less affected by entropy :)
samdoesnothing··on Influential study on glyphosate safety retracted 25 years after publication
> It's that you can't mechanically shift the burden of proof to anything "new" and assign a lower risk to the status quo by default

Not quite - it is true that you cannot assign a lower risk to the status quo by default, but the burden of proof is on the new intervention to prove that it's safe, not on detractors to prove that it isn't.

In other words, if the world is functioning today, you need to prove that your intervention won't cause ruin, no matter how small the chance or how big the upside.

samdoesnothing··on Influential study on glyphosate safety retracted 25 years after publication
Are we even talking about the same thing? The precautionary principle, at least as far as I understand it, is to emphasize caution, pausing and review before leaping into new innovations with potential for causing extreme harm when extensive scientific knowledge on the matter is lacking. As risk increases, the threshold for certainty rises as well.

Is that something you consider to be deeply problematic and false?

Of course you can dispute both the risk and amount of certainty present, but claiming that the principle is fallacious seems absurd to me.

> "The precautionary principle (PP) states that if an actionor policy has a suspected risk of causing severe harm to the public domain (affecting general health or the environment globally), the action should not be taken in the absence of scientific near-certainty about its safety. Under these conditions, the burden of proof about absence of harm falls on those proposing an action, not those opposing it. PP is intended to deal with uncertainty and risk in cases where the absence of evidence and the incompleteness of scientific knowledge carries profound implications and in the presence of risks of "black swans",unforeseen and unforeseable events of extreme consequence"

samdoesnothing··on Influential study on glyphosate safety retracted 25 years after publication
The precautionary principle clearly states that if you have a chemical that kills living things and you have a company who stands to make a lot of money off of this chemical as long as it's safe for humans, that you should be very very careful about it. Probably should be avoided until there is not just proof from a lab or from paid off scientists.

Kind of crazy that this isn't just obvious to everybody.

samdoesnothing··on Cloudflare outage on December 5, 2025
With all due respect, your dedicated server is not quite as complex as Cloudflare...
samdoesnothing··on Thoughts on Go vs. Rust vs. Zig
"research", it's a bunch of rust fans at google who are claiming it, without any real serious methodology.
samdoesnothing··on RCE Vulnerability in React and Next.js
Not really, I didn't keep receipts. This stuff was discussed heavily on X a couple years ago when they were first launched and a lot of people questioned the wisdom of implicit RPC and blurring the lines between client/server, and the increasing complexity of React. I'm sure there were some articles written as well.

I believe one of the React email services got pwned because they leaked sensitive info via RSC, and there was a whole fiasco around Next.js encrypting server secrets and sending them to the client.

Lo and behold just a couple years later, a lvl 10 RCE because of the complexity of their RPC approach coupled with the blurring of the lines between client/server...it's not like it's surprising to us. A repro of the vulnerability is on X & Github if you want to search for it, it's a classic deserialization bug that only exists because their format is so complex (and powerful).

Remember a lot of us use React as a UI library and to see it causing our servers to get pwned is what people were uneasy about when they announced RSC.

Unfortunately much of this discussion is on X which makes it hard to find, especially because I think Dan Abromov deleted his X account.

samdoesnothing··on RCE Vulnerability in React and Next.js
Just because something is made possible and you can do it doesn't mean you should!

The criticism is that by allowing you to do something you shouldn't, there isn't any benefit to be had, even if that system allows you to do something you couldn't before.

samdoesnothing··on RCE Vulnerability in React and Next.js
Especially cuz the vast majority of sites can either just be client rendered SPA's or server rendered multipage apps. There is no need for the complexity for most sites and yet this is the default for pretty much all js frameworks...
samdoesnothing··on Everyone in Seattle hates AI
Most people don't have a problem with using genai for stuff like throwaway UI's. That's not even remotely relevant to the criticisms. People reject having it forced down their throats by companies who are desperate to make us totally reliant on it to justify their insane investments. And people reject the evangelicals who claim that it's going to replace developers because it can spit out mostly working boilerplate.
samdoesnothing··on RCE Vulnerability in React and Next.js
This is genuinely embarrassing for the Next.js and React teams. They were warned for years that their approach to server-client communication had risks, derided and ignored everyone who didn't provide unconditional praise, and now this.

I think their time as Javascript thought leaders is past due.

samdoesnothing··on Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
It's probably a list of bullet points or disjointed sentences fed to the LLM to clean up. Might be a non-English speaker using it to become fluent. I won't criticize it, but it's clearly LLM generated content.
samdoesnothing··on Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
Ya ur right, it's either LLM generated, LLM enhanced, or the author has been reading so much LLM output that its writing style has rubbed off.
← PreviousPage 3 of 10Next →