HNHacker News
TopNewBestAskShowJobs

tcbrah

38 karma · joined March 6, 2026

submissionscomments
tcbrah··on Show HN: Nightshift – Your code gets better while you sleep
that's the neat part, there is no prescribed system or code. your agent decides the implementation which you control, the repo is mostly natural language (save for the presentational tui)
tcbrah··on Show HN: Nightshift – Your code gets better while you sleep
great instinct. that's exactly what happens today! it learns from closed PRs and feedback on what changes are high value vs not
tcbrah··on Show HN: Nightshift – Your code gets better while you sleep
occassionally when you forget to git commit/stash before sleeping
tcbrah··on Show HN: Nightshift – Your code gets better while you sleep
great minds. we gotta collab, dm
tcbrah··on 2026: The year of the node based editor
tbf, node based editors have been "the year of" every year since blender. they all look like a murder board to me! comfyui especially has a terrible ui/ux IMO
tcbrah··on DeepSeek v4
giving meta a run for its money, esp when it was supposed to be the poster child for OSS models. deepseek is really overshadowing them rn
tcbrah··on Pipe to Bash
we've been complaining about curl | bash for like 15 years and yet here we are installing every new ai tool the exact same way lol. convenience always wins over security until it doesnt
tcbrah··on Fyn: An uv fork with new features, bug fixes, stripped telemetry
love that "we removed the telemetry" is now a headline feature worth forking an entire project over. says a lot about where dev tooling is headed tbh
tcbrah··on Microsoft rolls back some of its Copilot AI bloat on Windows
tbh the fact that they put copilot in the snipping tool tells you everything about how those decisions were being made lol
tcbrah··on Security analysts warn of 'expanded attack surface' as AI agents become default
tbh the real issue isnt even prompt injection its that people give these agents full wallet access and then act suprised when they get drained lol
tcbrah··on Adapting to AI: Reflections on Productivity
lol the 2025 "ai is just my pairing buddy" to 2026 "ai writes all my code" pipeline is speedrunning at this point
tcbrah··on MCP is dead; long live MCP
fair point, but there's a difference between maintaining a CLI you own vs depending on a third party to maintain a wrapper around an API you could call directly. not to mention the mcp protocol is fairly nascent whereas CLIs are much more battle-tested
tcbrah··on Cloudflare Workers AI now runs large models, starting with Kimi K2.5
the "77% cost reduction" number is doing a lot of heavy lifting here when the real play is getting your whole agent stack on cloudflare so switching costs go thru the roof lol
tcbrah··on Supply-chain attack using invisible code hits GitHub and other repositories
the fact that github still renders Private Use Area codepoints as whitespace instead of flagging them is wild tbh. like we've known about this vector since 2024 and npm/github just shrugged
tcbrah··on AI can 'same-ify' human expression – can some brains resist its pull?
tbh you can already tell whos using chatgpt to write their emails at work, everyone sounds like the same middle manager now. the homogenization isnt coming its already here
tcbrah··on MCP is dead; long live MCP
the maintenance burden is the real MCP killer nobody talks about. your agent needs github? now you depend on some npm package wrapping an API that already had good docs. i just shell out to gh cli and curl - when the API changes, the agent reads updated docs and adapts. with MCP you wait on a middleman to update a wrapper.

tptacek nailed it - once agents run bash, MCP is overhead. the security argument is weird too, it shipped without auth and now claims security as chief benefit. chroot jails and scoped tokens solved this decades ago.

only place MCP wins is oauth flows for non-technical users who will never open a terminal. for dev tooling? just write better CLIs.

tcbrah··on I found 39 Algolia admin keys exposed across open source documentation sites
ill take that as a compliment, my writing finally passed the turing test
tcbrah··on I found 39 Algolia admin keys exposed across open source documentation sites
the wildest part is algolia just not responding. you email them saying "hey 39 of your customers have admin keys in their frontend" and they ghost you? thats way worse than the keys themselves imo. like the whole point of docsearch is they manage the crawling FOR you, but then the "run your own crawler" docs basically hand you a footgun with zero guardrails. they could just... not issue admin-scoped keys through that flow
tcbrah··on Can I run AI locally?
genuine question - what are you working on that needs that level of privacy? outside of NSFW stuff most API providers arent doing anything with your prompts
tcbrah··on Can I run AI locally?
tbh i stopped caring about "can i run X locally" a while ago. for anything where quality matters (scripting, code, complex reasoning) the local models are just not there yet compared to API. where local shines is specific narrow tasks - TTS, embeddings, whisper for STT, stuff like that. trying to run a 70b model at 3 tok/s on your gaming GPU when you could just hit an API for like $0.002/req feels like a weird flex IMO
tcbrah··on Show HN: fftool – A Terminal UI for FFmpeg – Shows Command Before It Runs
the confirm screen showing the actual command is lowkey the best part. i use ffmpeg daily for video assembly (concat demuxer + xfade + zoompan for ken burns) and honestly the only reason i got decent at it was reading the commands that other wrappers were generating under the hood. most ffmpeg GUIs hide that from you which defeats the purpose IMO - you end up dependent on the tool forever instead of actually learning the flags
tcbrah··on How we hacked McKinsey's AI platform
the data leak is bad but the write access to system prompts is what keeps me up at night. they could silently rewrite how Lilli responds to 43k consultants with a single UPDATE statement - no deploy, no code review, no logs. imagine poisoning the strategic advice that gets copy pasted into client deliverables. tbh most companies i see doing AI stuff store prompts the exact same way, just rows in postgres right next to everything else
tcbrah··on After outages, Amazon to make senior engineers sign off on AI-assisted changes
because the incentive structure is broken. if my performance review rewards me for using AI more, im going to use AI more even when i shouldn't. engineers will rubber stamp AI suggestions to hit their metrics instead of actually reviewing the code. you cant optimize for quantity of AI usage and quality of output at the same time IMO
tcbrah··on Launch HN: Prism (YC X25) – Workspace and API to generate and edit videos
nice, fal is solid. whats the pricing like compared to calling the model APIs directly?

lots of people are asking for my script so i'm open sourcing it fairly soon (openslop.ai if you want to get notified). currently integrating with runware, elevenlabs, cartesia, kling, runwayML but will look into integrating with fal too. would you be open to connecting to helping with integration with fal?

tcbrah··on Launch HN: Prism (YC X25) – Workspace and API to generate and edit videos
ive tried like 5 of these all-in-one AI video platforms and always end up back at my own script. the problem isnt the "glue work" between tools honestly - thats like 20 lines of python. the problem is when the platform abstracts over the model APIs so much that you cant access new params when kling or whoever ships an update. how quickly do yall expose new model features when providers update? thats the make or break thing IMO
tcbrah··on TADA: Fast, Reliable Speech Generation Through Text-Acoustic Synchronization
the 0.09 RTF is wild but i wonder how much of that speed advantage disappears once you need voice cloning or fine grained prosody control. i use cartesia sonic for TTS in a video pipeline and the thing that actually matters for content creation isnt raw speed - its whether you can get consistent emotional delivery across like 50+ scenes without it drifting. the 1:1 text-acoustic alignment should help with hallucinations for sure but does it handle things like mid-sentence pauses or emphasis on specific words? thats where most open source TTS falls apart IMO
tcbrah··on FFmpeg-over-IP – Connect to remote FFmpeg servers
yep same here, i do the same thing for my video pipeline. spawn ffmpeg as a child process from node, pipe stdin/stdout directly and skip disk entirely for intermediate steps. concat demuxer + xfade filters for stitching scenes together. the only time i touch disk is the final output and even thats optional if youre uploading straight to s3 or whatever
tcbrah··on After outages, Amazon to make senior engineers sign off on AI-assisted changes
the funniest part is amazon literally started tying AI usage to performance reviews like 6 months ago and now theyre doing damage control. you cant simultaneously pressure every engineer to use more AI AND be shocked when AI-assisted code breaks prod. pick one lol
tcbrah··on No, it doesn't cost Anthropic $5k per Claude Code user
yeah the json token counts are super misleading. i run a bunch of claude agents for automation and like 85% of input tokens end up being cached reads -which cost 1/10th of the sticker price. so your $200k number is probably closer to $25-30k in real cost, and thats before you factor in that anthropics own infra is way cheaper than retail API pricing. the $5k forbes number was always nonsense but even the "corrected" estimates in TFA are probably still too high IMO
tcbrah··on Learnings from paying artists royalties for AI-generated art
the spotify comparison is telling because spotify succeeded by being better than piracy, not by being more ethical. tess was trying to compete on ethics against tools that were just flat out better at the actual job.

i generate hundreds of images weekly for video content and the honest truth is i never think "i want this specific artist's style." i think "i need a documentary still that looks like 1970s film grain" or "i need a character that matches my last 50 frames." consistency and speed matter way more than provenance. the few times i tried artist-specific fine tunes the quality was noticeably worse than just prompting a good base model well.

the 6.5% artist signup rate buried in there is actually the real story. they cold emailed 325 high end editorial artists and got 21. those artists didn't want passive income from AI - they wanted AI to not exist in their market at all. paying someone royalties to automate away their livelihood is a weird value prop no matter how you frame it.

Page 1 of 2Next →