HNHacker News
TopNewBestAskShowJobs

sersi

2,025 karma · joined February 25, 2017

submissionscomments
sersi··on Claude for Small Business
To be fair with how powerful our computers are, it's a pity that electron apps like bitwarden, spotify are so slow and consume so much resources. I do miss the time when a lot of apps were snappy
sersi··on Write some software, give it away for free
That was my experience. When I first started consulting 20 years ago I stupidly charged $40/hour because I was young and dumb I stupidly discounted the time it took to find clients (and things like health insurance, etc...). I quickly adjusted and started charging $120/hour. I got much better clients and the projects I worked on became that much more interesting.

In my experience charging too little is one of the biggest mistake to do when starting.

sersi··on Do_not_track
While we wait for companies to very very slowly implement that proposal, is there a place that collects in one place all the opt out methods for most common tools in one place? Perhaps even a shell module that sets them and regularly updates its list?
sersi··on For Linux kernel vulnerabilities, there is no heads-up to distributions
Thanks for the reply (and thanks for the work you do)! Fair enough. And the issue is also that without some form of vetting you run the risk of disclosing the 0 day too early?

About that "That's the only policy by which all the legal/governmental agencies have agreed to allow us to operate in, so we are stuck with it.", you mean that if you disclose selectively, then you become liable for damages? or was it a more direct conversation with legal/governmental agencies?

And for a bug like this, what is the policy with backporting patches to lts branches? Since it was corrected in mainline on april 1st but only backported after the public disclosure. Do you delay backporting to minimise any attention on the security issue?

I guess that having a patch for that land on all the LTS branch would signal to any would be attacker that it's a significant security issue...

Sorry for all the questions but I'm genuinely interested.

EDIT: Just read your blog post at http://www.kroah.com/log/blog/2026/01/02/linux-kernel-securi... which does answer a lot of my questions...

sersi··on For Linux kernel vulnerabilities, there is no heads-up to distributions
To be fair, once Xint gave the heads up and the kernel team committed a patch, what was Xint supposed to do? Keep asking the kernel security team to backport patches for the LTS kernels?

As soon as a patch is committed, the clock starts ticking, the exploit will be discovered by reverse engineering recent commits. The commit was made on April 1st, Xint disclosed it on the 29th. If the Kernel Security team had wanted to, they had 28 days to backport patches in the LTS branches...

So, I wouldn't put any blame on Xint there.

sersi··on For Linux kernel vulnerabilities, there is no heads-up to distributions
Yes and that's why the current system where security researchers are expected to reach out to the distro mailing list is flawed and instead there should be a defined pipeline for the kernel security team to give a heads up.
sersi··on For Linux kernel vulnerabilities, there is no heads-up to distributions
Interesting comment by Greg Kroah-Hartman when asked why the kernel team doesn't notify distros directly

> Nope, sorry, we are NOT allowed to notify anyone about anything "ahead of time" otherwise we will have to tell everyone about everything. That's the only policy by which all the legal/governmental agencies have agreed to allow us to operate in, so we are stuck with it.

I'd be interested in knowing more about that policy... Seems that there should be exceptions for the major distros.

Of course, major distros who have contracts with SLA could also pay for someone to be on the kernel security team and get a heads up like that..

sersi··on CPanel and WHM Authentication Bypass – CVE-2026-41940
> You should read the other thread regarding copy fail and the gentoo maintainer Do you have a link?
sersi··on HERMES.md in commit messages causes requests to route to extra usage billing
What do you use now? How much ram do you have? I am increasingly thinking of doing that
sersi··on Ghostty is leaving GitHub
So much to list:

- They ditched their previous android app for a new one that doesn't get the grandfathered accessibility access so autofill is mostly useless...

- On mac, safari integration is consistently flaky. It regularly keeps getting blocked in a loop telling me to unlock 1password when 1password has already been unlocked.

- Passkeys are unreliable to the point of being unusable

- Autofill frequently doesn't work well where for some reason the site with the same url as saved in 1password is not offered during autofill. When 1password used to work, it helped catch phishing attempts because it wouldn't show autofill on pages that do not match. Nowadays because of the shitty autofill, people get trained to go to the app, copy the password and paste it in the website. This means that it will no longer protect from phishing attempts

- The previous behaviour of saving any newly generated password as a password object (not login) was much better. Now newly generated passwords are only available in the password history of the browser extension you specifically used.

- I can't tell 1password to ignore a specific website

At this point, the only reason I'm not using bitwarden is that search is very slow on it with 2k+ passwords.

sersi··on Networking changes coming in macOS 27
I just wish the new CEO decides to do a snow leopard release. Also change the macos release to when it's done instead of yearly
sersi··on Men who stare at walls
See the above comment by pfooty who explains it better than I did. I don't bump into people nor bump into walls. I use my peripheral vision to see what's happening while reading my kindle.

Honestly, it's never seemed hard to me and I don't remember a time when I was not able to walk while reading without bumping into things. Even as a student when studying for exams, I'd walk around in circle in my room reading my textbooks, for some reason walking helped to better remember...

sersi··on Men who stare at walls
Read while walking, I live in a walkable city. The pedestrian way is safe. I stop reading when I arrive at any intersection then start again once I cross. Even as a kid, I'd rush to open any magazine I bought before I got back home and would read them while walking.
sersi··on Men who stare at walls
And mostly reduced creativity.

I'm addicted to reading, I take my kindle and phone everywhere, so will grab them when I'm walking, taking a shower, waiting in line, going to the restroom... Between my kindle and my phone, I read a lot more books than I ever did but I don't digest the information as much as I used to. I also don't make as much associations between what I read and things going on in my own life. So, in a way, despite reading a lot more, I don't think I benefit as much from it.

Now, I'm purposefully forcing myself not to reach to my kindle when taking a walk so that my mind can wander as much as I do.

sersi··on AI should elevate your thinking, not replace it
That does seem to depend on countries and universities.

I do have to say I was appalled by some of the tests I had as an exchange student in the US (will not name the Uni in question but ranked around 60 in us rank). I remember a computer graphics test where a lot of questions were of the type "Which companies created the consortium maintaining the opengl specification?"... it was fully possible to obtain a passing grade just by rote memorization of facts. So I have no trouble believing that in the US it's possible in some unis to get a software engineering degree without understanding or critical thining

sersi··on Tim Cook's Impeccable Timing
Yeah, I hated the keyboard but really did like the touchbar. Apple really dropped the ball there though. We shouldn't have needed Better Touch Tool to make it useful.
sersi··on OpenAI ad partner now selling ChatGPT ad placements based on “prompt relevance”
I've had much more luck with perplexity. Still not perfect but at least works better.
sersi··on Stop trying to engineer your way out of listening to people
> It might be that with precision, readability is lost

The poster you replied to just wrote a comment on HN that is meant to be read by an audience, is clear, well written and well structured. Given that, why ever would you assume that the documentation that same poster produced would be too terse to serve the job?

sersi··on Changes in the system prompt between Claude Opus 4.6 and 4.7
I really hate that change, it's now regularly picking bad interpretation instead of asking.
sersi··on Everything we like is a psyop?
So TikTok is for b2c. What's the equivalent for b2b product targeting developers or opensource software? Stars on github?

Or are there a lot of adtroturfing hn accounts to influence the narrative?

It reminds me of pg's article on submarine and the pr industry

sersi··on Claude Opus 4.7
From a quick tests, it seems to hallucinate a lot more than opus 4.6. I like to ask random knowledge questions like "What are the best chinese rpgs with a decent translations for someone who is not familiar with them? The classics one should not miss?" and 4.6 gave accurate answers, 4.7 hallucinated the name of games, gave wrong information on how to run them etc...

Seems common for any type of slightly obscure knowledge.

sersi··on My AI-Assisted Workflow
So far my flow with llm is spec, get the llm to develop it, it kinda works as a proof of concept. Then I look at the code, the structure and architecture makes me want to vomit. So I initiate a refactoring round where I tell it exactly what I want to refactor it to. It kind of follows but I still need to make manual changes

At the end of that process I get something that's not too terrible.

So for producing production ready code I'm not sure it's ready yet since the handholding is a significant investment.

For producing quick prototypes/proof of concept. It's great

And to be completely fair, working as a consultant I've seen my fair share of production code that was even more of a mess than what claude generates by default

sersi··on My AI-Assisted Workflow
Thinking before you start implementing the entire project is doomed to fail. Thinking before you implement each features/user story is usually rather important.

A waterfall model with short feedback loops iterating on small tasks is not the worst thing in the world

sersi··on An AI Vibe Coding Horror Story
I'd argue that back in the visual basic/Delphi day, there was a minimum level of competence needed AND, more importantly, apps didn't have as much surface area because they weren't exposed to internet
sersi··on Am I German or Autistic?
I mean I've regularly seen trains in germany arriving AFTER the next train. Statistically they are worse than pretty much any european country.

And outside of trains, my german friends run the gamut of being always on time to systematically being 30 minutes late. Don't really see much of a correlation between being German and punctual.

Japan on the other hand I do associate with punctuality, when I worked there I was made to sit in the seiza postion for the m9rniny meeting if I was late by even 3 minutes. My friends there were overwhelmingly ontime except (and proving my point) for a German coworker I had there :)

sersi··on Am I German or Autistic?
Having lived in Germany and experienced the wonderful Deutche Bahn, I wouldn't really associate punctuality with being German.
sersi··on Open Source Security at Astral
Main reason I now use uv is being able to specify a cool down period. pip allows it but it's with a timestamp so pretty much useless..

And that doesn't prevent me from running it into a sandbox or vm for an additional layer of security.

sersi··on LittleSnitch for Linux
> For keeping tabs on what your software is up to and blocking legitimate software from phoning home, Little Snitch for Linux works well. For hardening a system against a determined adversary, it's not the right tool.

What would be the right tool to harden in a similar way to little snitch on mac? Meaning intercepting any connection and whitelisting them reliably.

sersi··on Finnish sauna heat exposure induces stronger immune cell than cytokine responses
My problem with turkish style hammam is that unless it's extremely well maintained it often smells of mold. When I went to some nice hammams in turkey, I didn't have that problem but outside of turkey, it's often unbearable.
sersi··on Finnish sauna heat exposure induces stronger immune cell than cytokine responses
I've never read as much on my kindle as when my son was born. I didn't want to use my phone so any micro break was spent reading. Much harder to do now that my son is 4 years old, I'm less sleep deprived but there's less opportunities for micro breaks when I'm with him.
← PreviousPage 3 of 18Next →