HNHacker News
TopNewBestAskShowJobs

sbysb

99 karma · joined September 30, 2021

https://bitwizard.dev https://github.com/sbysb
submissionscomments
sbysb··on OpenChamber: An Agentic Development Environment
I had another comment in a thread last week about this: https://news.ycombinator.com/item?id=49111625

I really think that using something like Paseo (I use Ouijit[1] because I think it's actually a step ahead of where most of these multiplexers are) and nono[2] is basically the best coverage you can have, and really lets you go crazy with auto mode or permission skipping withiout having to worry about any security concerns.

A lot of people lean into the VMs but realistically it's not actually doing a lot of the security work that you need and leaves you wide open to prompt injection/exfiltration attaacks. The flexibility of a good nono setup (which is easy because they ship a nono skill that claude can consume) actually locks things down significantly better

1. https://ouijit.com/ 2. https://nono.sh/

sbysb··on Harness Engineering for Self-Improvement
There is a really good video by the author of pi.dev (which I have used to build some of my own harnesses): https://www.youtube.com/watch?v=RjfbvDXpFls

The basis of the argument is that the labs are constantly pushing updates to their system prompts that are used in claude code or codex, which are exceptionally bloated and change the sand beneath your feet with every update.

By rolling your own harness, as long as you keep up with the latest advances and changes in the ecosystem, you capture a lot of the 'control' that LLM-based development feels like it strips from you.

Obvious disclaimer that I use pi.dev when I am aiming for consistency, not absolute quality. Custom harnesses on pi are what I ship, claude code is still my fallback if I need to make sure a PR is the highest absolute quality

sbysb··on Ask HN: Who is hiring? (August 2026)
Oneleet (YC S22) | Multiple Roles | US & NATO Countries | Remote | Full-time

Oneleet is an all-in-one cybersecurity startup that has built its own Attack Surface Monitoring (ASM), Code Scanner, Dependency Management, Endpoint Protection, and Compliance Platform. We recently raised a Series A and are growing at an rapid pace and working on some very exciting projects.

What we're looking for:

- Strong problem solvers who can work independently in a remote environment

- Security-minded professionals passionate about building robust, scalable systems

Tech stack: Go, TypeScript, React, Kubernetes

We have a huge number of roles open across the organization from Engineering (backend, frontend, fullstack, AI, infra) to Operations.

If you're interested in joining our team, please reach out to join<at>oneleet<dot>com with the subject line "HN: <Job Title>" and your resume attached. Alternatively, you can also apply at https://jobs.ashbyhq.com/oneleet

sbysb··on Git worktrees are not an isolation boundary for coding agents
> nono is great but you'll still won't be able to run multiple dev servers, dbs or test in the browser...

With our profile setup you can do all three of those things - there is a fresh chrome profile that is blocked against the same network firewall. Claude and Playwright can navigate to the dev stack and screenshot/test it (and non-allowlisted websites are blocked at the network level).

As long as the developer runs the `task start` command outside the sandbox (because docker is blocked), the agent can then interact with it all that they want, and our devs can run 2-3 of these per machine and work on concurrent projects. (based on memory usage / cpu usage)

> a tool to teleport your files, skills, settings, claude/codex subscriptions etc in any of the popular sandboxes

FWIW this is _explicitly_ the opposite of our threat model - everything other than your git credentials that you 'teleport' in (code, settings, Claude/Codex subscription tokens) now lives inside the blast radius, on third-party infra, and a prompt-injected agent in the box can send it anywhere unless you're also egress-filtering. A VM isolates the machine - it doesn't protect the data.

Much easier to keep it all local and refuse any network or file access to anything you don't explicitly approve

sbysb··on Git worktrees are not an isolation boundary for coding agents
All git config and hooks are not writable inside the sandbox. This can be somewhat frustrating as you have to run git config commands outside, but the tradeoff is worth it imo. Nono allows for directory level permissioning, so the entire `.git/hooks` directory and `.git/config` / `.git/worktrees/*/config.worktree` are write blocked.

Worth calling out that this doesn't close all of these types of attacks, just the ones that are invisible (claude could very well write ./hack.sh and tie that in to your main.go, but at least it would be a diffable change, instead of invisible like a git hook)

sbysb··on Git worktrees are not an isolation boundary for coding agents
Git worktrees are a great isolation boundary for _changes_ (especially making changes in parallel on a single machine), but not behavior. If you are trying to actually run autonomous agents securely you need something that lives outside the harness that actually blocks actions in a way that can't be prompted around.

We use nono [1] for this internally, essentially blocking any actions we don't want agents to be able to do without human approval. Our developers can just run `task claude` or whatever their harness is) and it pre-wraps it with our profile that enforces:

- Filesystem: read/write only the worktree plus dev-tooling dirs (Go, Doppler, Graphite caches, git common dir); explicitly no Docker socket and it can't edit its own Claude settings files (so it can't loosen its own permissions).

- Network: outbound only to an allowlist - Anthropic, Doppler, Go module proxies, our dev environments while still allowing binding local dev-server ports.

- GitHub: read anything in the org, and create/edit PRs and push branches - but it cannot merge, close, review, or comment on PRs, delete branches, touch repo settings/secrets, manage auth, or use raw gh api. Those are all "human-only". GitHub tokens are never exposed to the agent; they're injected by a proxy so it can't read or exfiltrate them.

This is great because it is harness agnostic - any developer can use whatever harness they want as long as they port the nono profile to it, as it will enforce all of the above in a way that is not tied to a specific harness implementation

[1] https://github.com/nolabs-ai/nono

sbysb··on I'm Begging You to Leave Your AI Note-Taker at Home
I mean most of these tools pair the notes/transcript with a video recording of the call. It can be super helpful to search the summaries to find the right recording, and then click the line in the transcript to re-watch the meeting.

For work, this is strictly better than not recording the meeting, as it allows for much faster searching, and it is very rarely wrong about the high level topics of a convo. I almost always go "General AI summary search" -> Transcript -> recording when trying to remember a specific item from a call.

That being said the parent article is spot on and I can't imagine someone bringing a recording to a conversation they aren't being paid to have.

sbysb··on Ask HN: Who is hiring? (July 2026)
Oneleet (YC S22) | Multiple Roles | US & NATO Countries | Remote | Full-time

Oneleet is an all-in-one cybersecurity startup that has built its own Attack Surface Monitoring (ASM), Code Scanner, Dependency Management, Endpoint Protection, and Compliance Platform. We recently raised a Series A and are growing at an rapid pace and working on some very exciting projects.

What we're looking for:

- Strong problem solvers who can work independently in a remote environment

- Security-minded professionals passionate about building robust, scalable systems

Tech stack: Go, TypeScript, React, Kubernetes

Open role highlights:

- Application Security Engineer: Help drive the design and implementation of bleeding edge security tooling

- Application Software Engineer: Contribute to an all-in-one cybersecurity agent for devices, including security alerting and mobile device management

- Product Marketing Manager: Build the sales enablement arsenal and thought leadership content that turns technical capabilities into deals won

- We are also hiring across the stack (backend, frontend, fullstack, AI, infra) on the engineering team.

If you're interested in joining our team, please reach out to join<at>oneleet<dot>com with the subject line "HN: <Job Title>" and your resume attached. Alternatively, you can also apply at https://jobs.ashbyhq.com/oneleet

sbysb··on Gribouille 0.3.0: A Grammar of Graphics for Typst
I do not think that is the problem with markdown lol. There are lots of problems with markdown, especially vanilla or the more limited versions of it - but really its super power is that it is readable with a regular text editor (or `cat`) and can be rendered without a compilation step.

Markdown is not competing with latex or typst, it is competing with (and has won against) .txt files

sbysb··on DeepSeek v4
It's difficult because even if the underlying model is very good, not having a pre-built harness like Claude Code makes it very un-sticky for most devs. Even at equal quality, the friction (or at least perceived friction) is higher than the mainstream models.
sbysb··on Parallel agents in Zed
You should check out Ouijit [1] - I use it regularly for work and it's nice because it focuses on the environment that you want, and just gives you a shell that you can use any tooling in, as well as VM isolation per worktree if needed.

[1]: https://github.com/ouijit/ouijit

sbysb··on Ask HN: What Are You Working On? (April 2026)
https://meza.chat/

Been building an E2EE chat client on the weekends that sits right between Discord (but dis-enshittified) and Matrix (but with good UX around encryption). Still got some rough edges - we are in the second nine of the march of nines in terms of quality.

https://github.com/mezalabs/meza

sbysb··on The cult of vibe coding is dogfooding run amok
I have used Claude Code in the terminal to the tune of ~20m tokens in the last month and I have very little to complain about. There are definitely quirks that are annoying (as all software has, including vs code or jetbrains IDEs) but broadly speaking it does what it says on the tin ime
sbysb··on The cult of vibe coding is insane
> some people say that the max AI Level should be 5

> of course some people think that you lose touch with the ground if you go above AI Level 2

I really think that this framing sometimes causes a loss of granularity. As with most things in life, there is nuance in these approaches.

I find that nowadays for my main project I where I am really leaning into the 'autonomous engineering' concept, AI Level 7 is perfect - as long as it is qualified through rigorous QA processes on the output (ie it is not important what the code does if the output looks correct). But even in this project that I am really leaning into the AI 'hands-off' methodology, there are a few areas that dip into Level 5 or 4 depending on how well AI does them (Frontend Design especially) or on the criticality of the feature (in my case E2EE).

The most important thing is recognizing when you need to move 'up' or 'down' the scale and having an understanding of the system you are building

sbysb··on Cursor 3
FWIW I'm not saying Cursor is not capable of this, but that all of the 'Cursor' bits are superfluous, and using tools that bring you closer to the 'bare metal' of the terminal actually give you both more flexibility (I can run Claude Code, Crush, Codex, OpenCode, etc) and remove an entire layer of abstraction that I believe hinders a devs ability to really go all in on agentic engineering.

I started using Cursor and it was my daily driver for a year or two, but I haven't looked back once in regret moving more towards a terminal focused workflow. (Not to mention the pricing of Cursor being absolutely abysmal as well, although often comped by employers)

sbysb··on Cursor 3
> Anyway, you’re right Claude Code is less ergonomic; generally slower.

The secret in my experience is parallelization - Cursor might be faster or have better ergo for a single task, but Claude Code really shines when you have 6 tasks that are fairly independent.

If you treat CC as just another terminal tool and heavily use git worktrees, the overall productivity shoots through the window. I've been using a tool called Ouijit[1] for this (disclosure: the dev is an old colleague of mine), and I genuinely do not think I could go back to using Cursor or any other traditional IDE+agent. I barely even open the code in an editor anymore, primarily interacting through the term with Vim when I need to pull the wires out.

[1]: https://github.com/ouijit/ouijit

sbysb··on Ask HN: Who is hiring? (April 2026)
Oneleet (YC S22) | Multiple Roles | US & NATO Countries | Remote | Full-time Oneleet is an all-in-one cybersecurity startup that has built its own Attack Surface Monitoring (ASM), Code Scanner, Endpoint Protection, and Compliance Platform. We recently raised a Series A and are growing at an rapid pace and working on some very exciting projects.

What we're looking for:

- Strong problem solvers who can work independently in a remote environment

- Security-minded professionals passionate about building robust, scalable systems

- Comfortable working during Eastern Time

Tech stack: Go, TypeScript, React, Kubernetes Open roles

* Application Software Engineer, Endpoint Security (macOS experience preferred)

* Fullstack Engineer, AI Implementation

* Senior Product Designer

* GTM Engineer

* Customer Support Specialist

We offer: - Competitive salary

- Equity in a fast growing cybersecurity startup

- 100% remote work

- Company offsites yearly (past offsites have been in The Netherlands, Portugal and Italy)

If you're interested in joining our team, please reach out to join<at>oneleet<dot>com with the subject line "HN: <Job Title>" and your resume attached. Alternatively, you can also apply at https://jobs.ashbyhq.com/oneleet

Additional Note: We are also building out a 'forward deployed' sales team based in San Fransisco - if interested, please reach out to join<at>oneleet<dot>com with the subject line of `HN: SF Sales`

sbysb··on Ask HN: Who is hiring? (November 2025)
Oneleet (YC S22) | Multiple Roles | US & NATO Countries | Remote | Full-time

Oneleet is an all-in-one cybersecurity startup that has built its own Attack Surface Monitoring (ASM), Code Scanner, Device Monitoring, and Compliance Platform. We just raised a Series A and are growing at an rapid pace and working on some very exciting projects.

What we're looking for:

Strong problem solvers who can work independently in a remote environment - Security-minded professionals passionate about building robust, scalable systems - Comfortable working during Eastern Time

Tech stack: Go, TypeScript, React, Kubernetes

Open roles

* Software Engineer, Cloud Security Posture Management

* Application Software Engineer, Endpoint Security (macOS experience preferred)

* Fullstack Engineer, AI Implementation

* Security Program Manager (US/EU Timezone)

We offer:

- Competitive salary - Equity in a fast growing cybersecurity startup - 100% remote work - Company offsites every other quarter (past offsites have been in The Netherlands, Portugal and Italy)

If you're interested in joining our team, please reach out to samuel<at>oneleet<dot>com with the subject line "HN: <Job Title>" and your resume attached.

Alternatively, you can also apply at https://jobs.ashbyhq.com/oneleet

sbysb··on Ask HN: Who is hiring? (September 2025)
Oneleet (YC S22) | Multiple Roles | US & NATO Countries | Remote | Full-time

Oneleet is an all-in-one cybersecurity startup that has built its own Attack Surface Monitoring (ASM), Code Scanner, Device Monitoring, and Compliance Platform. We are growing at an unprecedented pace and working on some very exciting projects.

What we're looking for:

Strong problem solvers who can work independently in a remote environment - Security-minded professionals passionate about building robust, scalable systems - Comfortable working during Eastern Time

Tech stack: Go, TypeScript, React, Kubernetes

Open roles:

* Software Engineer, Backend

* Software Engineer, Cloud Security Posture Management

* Application Software Engineer, Endpoint Security

* Security Program Manager (EU Timezone)

* Technical Sales (must have background in Computer Science or Cybersecurity)

* Invoicing Coordinator

We offer:

- Competitive salary - Equity in a fast growing cybersecurity startup - 100% remote work - Company offsites every quarter (past offsites have been in The Netherlands and Italy)

If you're interested in joining our team, please reach out to samuel<at>oneleet<dot>com with the subject line "HN: <Job Title>".

Alternatively, you can also apply at https://www.ycombinator.com/companies/oneleet/jobs

sbysb··on Ask HN: Who is hiring? (July 2025)
Oneleet (YC S22) | Multiple Roles | US & NATO Countries | Remote | Full-time

Oneleet is an all-in-one cybersecurity startup that has built its own Attack Surface Monitoring (ASM), Code Scanner, Device Monitoring, and Compliance Platform. We are growing at an unprecedented pace and working on some very exciting projects.

What we're looking for:

Strong problem solvers who can work independently in a remote environment - Security-minded professionals passionate about building robust, scalable systems - Comfortable working during Eastern Time

Tech stack: Go, TypeScript, React, Kubernetes

Open roles:

* Senior Software Engineer (Backend)

* Application Software Engineer (Endpoint Security)

* Security Program Manager (EU Timezone)

* Internal Security Compliance Auditor

* Technical Sales (must have background in Computer Science or Cybersecurity)

* Invoicing Coordinator

We offer:

- Competitive salary - Equity in a fast growing cybersecurity startup - 100% remote work - Company offsites every quarter (past offsites have been in The Netherlands and Italy)

If you're interested in joining our team, please reach out to samuel<at>oneleet<dot>com with the subject line "HN: <Job Title>". If you have already applied but haven't heard back, feel free to follow up on the thread, things have been super busy!

Alternatively, you can also apply at https://www.ycombinator.com/companies/oneleet/jobs

sbysb··on Ask HN: Who is hiring? (June 2025)
Oneleet (YC S22) | Multiple Roles | US & NATO Countries | Remote | Full-time

Oneleet is an all-in-one cybersecurity startup that has built its own Attack Surface Monitoring (ASM), Code Scanner, Device Monitoring, and Compliance Platform. We are growing at an unprecedented pace and working on some very exciting projects.

What we're looking for:

Strong problem solvers who can work independently in a remote environment - Security-minded professionals passionate about building robust, scalable systems - Comfortable working during Eastern Time

Tech stack: Go, TypeScript, React, Kubernetes

Open roles:

* Senior Software Engineer (Backend)

* Security Program Manager

* Internal Security Compliance Auditor

* Technical Sales (must have background in Computer Science or Cybersecurity)

* Invoicing Coordinator

We offer:

- Competitive salary - Equity in a fast growing cybersecurity startup - 100% remote work - Company offsites every quarter (past offsites have been in The Netherlands and Italy)

If you're interested in joining our team, please reach out to samuel<at>oneleet<dot>com with the subject line "HN: <Job Title>". If you have already applied but haven't heard back, feel free to follow up on the thread, things have been super busy!

Alternatively, you can also apply at https://www.ycombinator.com/companies/oneleet/jobs

sbysb··on Ask HN: Who is hiring? (May 2025)
Oneleet (YC S22) | Multiple Roles | US & NATO Countries | Remote | Full-time

Oneleet is an all-in-one cybersecurity startup that has built its own Attack Surface Monitoring (ASM), Code Scanner, Device Monitoring, and Compliance Platform. We are growing at an unprecedented pace and working on some very exciting projects.

What we're looking for:

Strong problem solvers who can work independently in a remote environment - Security-minded professionals passionate about building robust, scalable systems - Comfortable working during Eastern Time

Tech stack: Go, TypeScript, React, Kubernetes

Open roles:

* Senior Software Engineer (Backend)

* Security Program Manager

* Internal Security Compliance Auditor

* Technical Sales (must have background in Computer Science or Cybersecurity)

We offer:

- Competitive salary - Equity in a fast growing cybersecurity startup - 100% remote work - Company offsites every quarter (past offsites have been in The Netherlands and Italy)

If you're interested in joining our team, please reach out to samuel<at>oneleet<dot>com with the subject line "HN: <Job Title>". Alternatively, you can also apply at https://www.ycombinator.com/companies/oneleet/jobs

sbysb··on Is this a good book for me, now?
I have always said that you can gain more value from self-help/life management type books by reading the table of contents and then spending the time you would have read the book just thinking about those topics and coming to your own conclusions.

This is obviously a bit hyperbole but seriously most self help books could be an article instead and I wouldn't miss anything that was cut

sbysb··on I gained a new appreciation for Test Driven Development
The very first test can be a simple "Did my HTTP request receive a response?". Then you can build on "Does this HTTP response have this value I need".... etc

The way I have always gone about TDD is just that I am testing the code I am writing by running the test, not from the main entrypoint of the application. The things you would log and look for when you run the application you instead validate with an `assert()`. Then once you have finished developing, you do a single pass verification from main and you have both a test and a function written

sbysb··on Don't store TOTP in Bitwarden for your online accounts (2022)
I think that while storing a TOTP in your password manager is less secure than using an external app, I also feel like this is missing a large portion of when I am storing a TOTP in Bitwarden - shared accounts.

Being able to store a TOTP in my password manager allows me to have a shared account still use 2FA - and provided all parties also have 2FA on their Bitwarden accounts I think this is a pretty secure system and much preferable to one party having TOTP and everyone else needing to email or message them to get the code. Especially considering that as the number of "Hey can you send me the code to log in real quick" messages the 2FA holder gets goes up, the likelihood they get complacent and just start automatically responding could also create a threat vector.

sbysb··on You might not need JavaScript
Most people do not want/need this, so the original point stands
sbysb··on Visa's marketing opt-out has been down for over a week. Is this a legal issue?
This must be regional because I have been using a chip-and-pin card for the last 5 years and I cannot for the life of me remember the last time I had to physically swipe the card. Tap support is definitely still spotty but that is something that is more of a convenience than a security issue
sbysb··on [dead]
Link should probably be to the github status page, not to a random tweet:

https://www.githubstatus.com/

sbysb··on dwm
This is something I have come to realize I unconsciously have gotten very dependent on - MacOS let's you swap virtual desktops for the monitor you are currently focused on without swapping any of the others. I never realized how intuitive this is until switching back to my XFCE linux installation and getting very frustrated with virtual desktops entirely. I might have to give dwm a try again on my linux machine if it supports this.
sbysb··on Don't start with microservices – monoliths are your friend
I would actually disagree - to me you can have "decent separation of concerns in your code" but still have only built the app to support a single entry point. "Modular monolith" to me is a system that is built with the view of being able to support multiple entry points, which is a bit more complex than just "separating concerns"
Page 1 of 2Next →