HNHacker News
TopNewBestAskShowJobs

sparsesignal

144 karma · joined July 4, 2026

submissionscomments
sparsesignal··on Claude Session URL appended to commit messages and PR descriptions by default
I'm OK with the attribution, but I just didn't like a session URL appearing on a public repo all of a sudden. I was left wondering "did I just leak my private session?"

I don't understand why it isn't opt-in. Or at least a heads-up somewhere.

sparsesignal··on List of Google Easter Eggs
I searched for "times new roman" for some reason, and noticed the whole results page was rendered in that font. I knew there were easter eggs on the page, but I was surprised by the sheer number of them.
sparsesignal··on Tell HN: Cloudflare silently injects its analytics when you switch nameservers
I noticed the same thing with email-decode.min.js on my site. It turns out it's the "Email Address Obfuscation" feature, which I didn't expect to be on by default.
sparsesignal··on Docker Sandboxes – Disposable, isolated sandboxes for AI agents
What I run is one hardened QEMU/KVM VM per project holding the whole dev environment (editors, agents, containers), with nftables on the host allowing internet egress but dropping anything aimed at the host, the LAN, or any other private address, plus an allowlist for deliberate exceptions.

Basically, it's a plain QEMU/KVM VM on a stock Debian cloud image: device model stripped down to a virtio disk, a virtio NIC and a serial console, nested virt off, no passwordless sudo in the guest. It also ships a containment check that scans outward from inside the guest, so the network boundary is something you can verify.

Wrapping the whole environment rather than a single agent session puts supply chain attacks inside the boundary too. A poisoned npm or PyPI package, or a compromised editor extension, lands in the VM instead of on the host. That was the original reason I set this up; agents just made it more urgent.

There's no per-domain egress allowlist; the policy is "internet yes, private addresses no". Secret injection isn't built in either, though Infisical's agent-vault on the host as an egress proxy covers that part.

Wrote the whole setup up here, in case it's useful:

https://karamatli.com/posts/network-isolated-kvm-sandbox-ai-...

sparsesignal··on Responding to the next frontier of critical cyber capabilities
Thanks, glad it was useful
sparsesignal··on Responding to the next frontier of critical cyber capabilities
Thanks. Like you, I'd been running containers inside VMs for a while before the agents. Turns out it's right for them too. Making it IPv4-only simplified the firewall rules and network containment check, and made the boundary easier to reason about.
sparsesignal··on Responding to the next frontier of critical cyber capabilities
> I stress about my agent sandboxes all the time

Same here, so I ended up moving the whole dev environment (editors, agents, containers) inside a hardened QEMU/KVM VM that reaches the internet but has no route to the host, the LAN, or any other private address. I wrote a script to create such VMs and also verify network containment by scanning outward from inside the guest. Even then, I still don't feel great when running agents unattended.

Write-up in case anyone's curious:

https://karamatli.com/posts/network-isolated-kvm-sandbox-ai-...

sparsesignal··on The first transatlantic telegraph cable was a bold, beautiful failure (2019)
Posted this because I saw a piece of the cable at the Science Museum in London years ago. It looks like it's still on display in the Information Age gallery:

https://collection.sciencemuseumgroup.org.uk/objects/co33448...

sparsesignal··on The End of an Era
This assumes one-shot generation. I don't use it that way, and I don't think many people who find it useful do.

I use it as a colleague I'm drafting with. I'll ask how a sentence lands, tell it to make a paragraph more friendly or more dramatic, have it argue against a point I'm making. The piece comes together over many turns, and the information arriving in each turn is mine — it's not expanding one prompt, it's helping me converge on something.

The information-content framing also proves too much: a copy editor adds no information either. Neither does a translator, or a ghostwriter. What they add is form, and form is most of what makes writing good or bad.

sparsesignal··on Why do AI company logos look like buttholes? (2025)
It's still working for me, but only on the web (desktop) interface.
sparsesignal··on Why do AI company logos look like buttholes? (2025)
Have you tried clicking the Claude logo? https://x.com/ertug/status/2072339797708849398
sparsesignal··on Is Recursive Self-Improvement Here?
Frontier agents are already compressing the dev loop with humans in it, and as the article notes, compression alone can be exponential enough to matter. Walking vs. driving is a nice analogy.
sparsesignal··on Latent Programming Horizons in Coding Agents
Nice paper. They predict the outcome of edits up to ~25 steps before the agent makes them. Decodable doesn't mean causal, as the authors note, but a cheap probe that flags doomed trajectories early could save a lot of wasted agent compute. We clearly still have a lot to learn about what these models represent internally.