HNHacker News
TopNewBestAskShowJobs

throwaway7356

278 karma · joined June 6, 2023

submissionscomments
throwaway7356··on Red Hat being phased out of existence?
Untrustworthy blog reposts Twitter message from some person?
throwaway7356··on Show HN: LightCloud – A cloud console organised like file system
The site claims they have an editor "ICE" as open-source software. But that is a lie: it is not open source, but shareware or such.

They also accept contributions released only under the no-commercial-use-allowed license, so any dual licensing under a commercial-use-allowed license would be out of the window once a contribution gets merged.

Not sure what their business model is if they forbid commercial use. I guess selling commercial use licenses in violation of the no-commercial-use-allowed license?

throwaway7356··on Ask HN: Who's still keeping a DOS machine up because the business depends on it?
Let me assure you that Deutsche Bahn also still operates about 500 mechanical signal boxes, about 100 are from pre-WW1. Not these fancy, modern electromechanical relays (which Deutsche Bahn of course also has).
throwaway7356··on Excel now supports multiple values in a single cell
A PhD is not for teaching about specific software tools, and hopefully even less so about legacy software from the 80's.

If you want people to be able to use Excel or service a mechanical typewriter, you need to spend extra effort to teach them.

throwaway7356··on Italian parliament votes for return to nuclear energy
> Decomissionning is a made-up issue: no other industrial activity is expected to return clean nature after they stopped operating,

That is factually wrong. Coal mining has to re-naturalize the areas used for mining after the coal was removed.

And most industries are supposed to not just leave toxic waste and instead have a plan what to do with toxic waste products these days. And no, an empty building cannot be compared to radioactive waste.

throwaway7356··on Feds Target AI Critics as "Foreign Agents"
> And we may be heading to energy lockdowns.

Energy lockdowns have always been part of US culture, see https://en.wikipedia.org/wiki/Rolling_blackout#USA

It's un-American to invest in infrastructure and build a better power network. Both parties agree on this.

throwaway7356··on SAML: A fractal of bad design
The has been proven again and again to not work. See for example HTTPS certificate warnings for which now there is a standard to ask browsers to not show a popup just saying "The server might not be the correct one. Continue?"

It's an easy solution, but it doesn't work at all.

throwaway7356··on Why building a Rust LSP is hard
> Start with synchronous function calls instead of JSON.

LSP is a function call protocol. So that is already done?

throwaway7356··on Why building a Rust LSP is hard
If the old emacs approach is so much better, why is emacs switching to using LSP?
throwaway7356··on You can run Git on object storage if you re-make packfiles
It has been done. It is no longer done because it is not efficient.

Yes, it was not "object storage", but Git can be served from a dumb http server as static files. Now someone figured out that object storage can also serve static files via http. Wow!

throwaway7356··on Every invoice in Brazil's economy runs on SOAP 1.2
Many libraries still have unsafe defaults. They come from the XML-age where security concerns were minor (SQL injection was still new to most!)

Using XML in a safe way requires you to study what is wrong with XML first. That is not what many people do.

throwaway7356··on Every invoice in Brazil's economy runs on SOAP 1.2
> XML is mature and supported in all languages with code generation its more or less transparent to the dev.

No, XML is still not mature. They still need to fix the security issues everyone reimplements every time such as local file disclosure via DTDs, exploding documents due to entity expansion and so on. It basically doesn't handle untrusted input well, like SQL built from strings without parameter bindings.

I hope this is reasonable and doesn't use XML Security or similar extensions that add a whole stack of other security issues on top that everyone reimplements when adding SAML support.

throwaway7356··on Pion, an agent designed to run any company autonomously
I think you miss the most important bits:

- backdoor deals to discourage alternatives, such as moving headquarters to convince people not to use alternatives,

- monopoly abuse,

- active sabotage of alternative software by intentionally triggering false errors if used with competitors' software (DR DOS),

- unleashing Internet Explorer on humanity (which proves that AI can't be that bad if humanity survived that)

You know, the stuff that every philantrope like Gates does all the time.

throwaway7356··on US strikes $1.2B deal to pay German firm to halt offshore wind projects
Nuclear isn't as cheap as you present it. It needs heavy subsidies for insurance and waste disposal.

Most nuclear power proposals are just LARPing as "cheap" as they pretend subsidies don't exist.

In addition you have to shut nuclear power plants down in summers due to lack of sufficient cooling. That means you need to plan alternative replacement power generation.

throwaway7356··on US strikes $1.2B deal to pay German firm to halt offshore wind projects
Yes, because comparing it to larger countries with more economic power like China would make the US politics look even dumber.
throwaway7356··on An update on residential proxies and the scraper situation
It'll still connect to IPv6 addresses and bypass any firewalls.

Also users might become part (victim?) of a police investigation because of illegal actions that seem to originate from their local residential connection.

So still good to take down such backdoors. Would be nice to go after the botnet operators as well...

throwaway7356··on An update on residential proxies and the scraper situation
> Apps are not infected with NetNut. This is just Google abusing their monopoly position to hurt its competitors.

If apps ship with stealth backdoors to sell access to the user's internal residential network, that's malware. I doubt any users want app providers to sell access to their private file server and anything else on their local network.

It doesn't seem like monopoly abuse to exclude such malware from application stores, just like key loggers or apps intercepting other apps network traffic without the user being aware of it (say the banking app's network traffic and password entry).

throwaway7356··on GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos
> The fix was prepared statements

You don't need prepared statements. The fix is parameter binding: submitting parameters separate from the SQL statement itself, separating code from (user) data.

> The analogous mitigation for agents is to have fixed behaviors they can perform, such as “read repo 1” “read repo 2”, etc., and the user input is used as data to select which of these fixed behaviors to execute.

No, that only deals with some special issues. It also doesn't separate code and (user) data, so it's not the same issue.

Having only limited actions is akin to using more restrictive database permissions. That also makes SQL injection no longer relevant: only SQL statements can be executed that the user is allowed to run either way.

throwaway7356··on What Emily Bender meant by "stochastic parrots"
> nor do they provide the brain an interpretation of what they perceive

> What it gets from the body is raw physical measurements

No, sensory organs like eyes do a lot of processing ("interpreation"). They certainly don't send "raw physical measurements" to the brain.

throwaway7356··on What Emily Bender meant by "stochastic parrots"
Then one can claim that humans are less intelligent than a goldfish as "none of us have ever seen a human swim as well as a goldfish".
throwaway7356··on What Emily Bender meant by "stochastic parrots"
> yet with enough developer elbow grease they can do all the same things an LLM can do, with much higher reliability

Where can I access such a Lisp expert system?

If I cannot because they don't exist: then they cannot do the same things an LLM can do. And of course one can assert anything and everything about what a non-existing thing could do.

throwaway7356··on Do you need separate systems when you already have Postgres?
Yes, that condition makes it no longer open source software.

It also has the effect of making software adopting such licenses getting removed from open source distributions.

throwaway7356··on Claude Design System Prompt
The terms of service are between Anthropic and one of their subscribers. So Anthropic can maybe cancel their contract.

This doesn't affect what copyright law allows or does not allow.

Also I think Anthropic very much suppports gathering data by whatever means possible. That should work both ways.

throwaway7356··on It Still Can't Do My Job: Four Years of Moving Goalposts (2022–2026)
> I think the notion that you could control something (legitimately) smarter than you is a pretty risky proposition.

Well, Trump seems to control a lot of people given how afraid they are.

Trump is also called not the smartest person out there.

So...

throwaway7356··on Enhancing X11 Application Security with LXC (2025)
> In practice the only place it shows up is if you are using "ssh -X". That uses the security extension by default. Which is why there is also a "ssh -Y" that disables it for applications that it breaks.

Unless your distro changes the default to make "ssh -X" and "ssh -Y" behave the same which popular distributions do.

throwaway7356··on Enhancing x11 Application Security with LXC (2025)
> But granting full rights to distro-provided programs like vim or xeyes is perfectly sane.

You mean run everything distro-provided as root?

There are reasons systems don't do that any more. Even distro-provided services are often setup in a way to no run with full rights. Can you imaging reasons why this is done?

What was neglected is doing the same on user level, which should be done for pretty much the same reasons.

throwaway7356··on U.S. government will decide who gets to use GPT-5.6
Maybe include some election guides for poor, misguided Americans that would hurt themselves by not voting for God President Donald Trump I as well?

It's protecting people from themselves, so basically like the safeguards already included in the models.

throwaway7356··on U.S. government will decide who gets to use GPT-5.6
Can't the AI companies spare a small investment in Trump coin to ease the process?
throwaway7356··on Anthropic says Alibaba illicitly extracted Claude AI model capabilities
> Ok, but what about those shady sites that resell Windows education keys?

Yes, they are fine? They might no longer include full first party support by Microsoft for not being "new". Same as buying a used car (also comes with the "shady sites" for a far longer time).

Though this not making any difference by Microsoft not doing any support either way to make more money is a business decision by Microsoft.

throwaway7356··on Anthropic says Alibaba illicitly extracted Claude AI model capabilities
> China aren't offering a cheaper solution. They are subsidizing an existing one

So basically like US companies subsidizing offerings with selling user data, ads for crypto scams, manipulation for elections, making people addicted to gambling and so on?

Seems fair and an improvement as you can choose between that and not. Unlike say offerings from Meta where the data selling and efforts to further gambling addiction is always included.

Page 1 of 4Next →