HNHacker News
TopNewBestAskShowJobs

tobwen

45 karma · joined June 16, 2023

submissionscomments
tobwen··on Highlights from Git 2.56
"Most humans don't know about these features" - I agree with you there, but I think models should be able to do that. That's why, for the past year, I've been maintaining "changelog skills" that I feed into the models to fill in the gaps in their knowledge.

By the way, all modern models know which hospital the last pope was admitted to shortly before his death.

tobwen··on Highlights from Git 2.56
Some whataboutism for those, who use AI to code: Modern model will NOT know about these nice new features.

I did some intensive testing with changelogs and came to the conclusion that knowledge is partitioned and comes with variable cutoff dates.

Common tools, like GIT, have their feature cutoff in like 2023 or even earlier. Enough for a model to work with the tool when there was no groundbreaking change.

Gossip has a fresher cutoff date. People ask models like an interactive Wikipedia.

tobwen··on Exploring Claude/GPT Knowledge Cutoffs and Pre-Training Timelines
In my tests, I compiled the changelogs from various projects and checked how much functionality the model could recall over several test runs. In some cases, even with the latest models, the cutoff was around June 2024. Beyond that, it didn't recognize the features. However, it did know the cause of the last pope's death and even which hospital he was in (April 2025). However, the model did not know when Trump was sworn for the second time (Jan 2025) - but it did know THAT he was elected a second time (Nov 2024).
tobwen··on Exploring Claude/GPT Knowledge Cutoffs and Pre-Training Timelines
From my own experiments with various models, I suspect that LLMs have distinct/partitioned cutoff dates; for example, historical literature doesn't change (Greek history, Shakespeare, Goethe), general knowledge (updated only in certain areas), technologies (updated regularly), software also remains surprisingly stable - for example, with GIT, a basic command set is sufficient to do 99% of the jobs - new features are unknown or unnecessary, and tabloid knowledge, which is always up-to-date (politics, Taylor Swift albums).
tobwen··on Running MicroVMs in Proxmox VE, the Easy Way
Thanks for the write-up, I like the integration in the Proxmox VE environment.

Given some similarities, I’d like to briefly mention `krun` here. Although it’s an OCI-compatible container runtime, it uses MicroVMs with a similar approach. Perhaps we can exchange ideas here? I recall that GPU passthrough is also a recurring topic there.

https://github.com/containers/crun/blob/main/krun.1.md

tobwen··on Slop-scan – Detect AI code slop patterns in your repo
Hey LLM, invert those rules to get undetectable :)
tobwen··on SSH has no Host header
Isn't this solving the problem? https://github.com/balena-io/sshproxy
tobwen··on Rob Pike’s Rules of Programming (1989)
Added to AGENTS.md :)
tobwen··on Nvidia contacted Anna's Archive to access books
Books are databases, chars their elements. We have copyright for databases in EU :)
tobwen··on Blocking Countries Because of Scrapers
I’m using ipset for this… It‘s protecting my Asterisk PBX since 2020.
tobwen··on Kimi Releases Kimi-CLI, an Open-Source Python Command-Line Tool
And yes, you can use it with OpenRouter.
tobwen··on Tell HN: OpenAI now requires ID verification and won't refund API credits
In Europe, SEPA direct debits can also be withdrawn. But you can expect to receive a reminder with legal action within a few days.
tobwen··on New OSM file format: 30% smaller than PBF, 5x faster to import
My opinion: Without support in libosmium and GDAL, this will remain a marginal phenomenon.
tobwen··on Typst 0.14
The accessibility support (PDF/UA-1) is VERY nice, but there's still still a lot of work to do (-> tables).
tobwen··on Rusty-Sheet: An Excel/WPS/OpenDocument Spreadsheets File Reader for DuckDB
“When using wildcard patterns, this function analyzes the column structure and data types from the first matching worksheet only.”

Meh… I think I should work on a PR to fix this…

tobwen··on Macro Splats 2025
Has recently been used to visit "The Matrix" again: https://www.youtube.com/watch?v=iq5JaG53dho&t=1412
tobwen··on Paper2video: Automatic video generation from scientific papers
Hrhr, I'd love to have automatic CODE generation from Scientic Papers :D
tobwen··on Major security breach at Austrian AI startup localmind.ai
Indeed... The security breach is already a few days old, and the white hat hacker has informed many major newspapers about it and sent them an incident report. According to these media outlets, several credentials were stored in plain text in the knowledge base, which allowed the white hat access to other services.
tobwen··on Major security breach at Austrian AI startup localmind.ai
I just came across this incident involving localmind.ai, a small AI startup out of Innsbruck, Austria (founded in early 2024). The company stated that internal processes and control mechanisms failed and accepted full responsibility for the incident.

This summary outlines the key events and remediation actions from the official incident reports published by Localmind.ai between October 5 and October 9, 2025.

Incident overview and initial response (October 5)

On October 5, 2025, at 05:43 CEST, Localmind detected unauthorized access to its systems. The immediate response was to take all affected systems, including internal platforms and customer instances, offline to contain the breach. Initial measures included:

  - Resetting all passwords and regenerating API keys (e.g., for Notion, SendGrid, Hetzner).
  - Deactivating all user accounts, restricting access to a minimal number of administrators with mandatory two-factor authentication (2FA).
  - Initiating a forensic investigation.
Root cause analysis (October 5, Update #2)

The breach originated from a misconfiguration in an externally accessible beta-test instance. The flaw granted administrator privileges by default to a newly registered account. The attacker used this access to:

  - Access the integrated automation platform (n8n).
  - Retrieve an unrestricted API key for the internal Notion knowledge base, which contained infrastructure documentation and credentials.
  - Use the compromised information to escalate access further and send emails from an internal account.
The company stated that internal processes and control mechanisms failed and accepted full responsibility for the incident.

Impact assessment and forensic Updates

  - Scope: The core Localmind platform was not compromised. The attack was confined to administrative interfaces and test environments. A limited number of customer systems were accessed, while on-premise instances showed no signs of unauthorized access.
  - Forensics: Unauthorized logins were traced to IP addresses from VPN providers, complicating attribution. Login activity occurred outside regular business hours (nights, weekends). As of October 8, no evidence of large-scale data exfiltration was found.
  - Data transparency: Localmind offered data exports to customers to conduct their own audits for potential GDPR breach notifications.
Remediation and security hardening measures

The company initiated a comprehensive infrastructure rebuild and security overhaul.

  1. New infrastructure: A migration of virtual machines to new, Tier IV, ISO 27001/27018 certified data centers with a fully isolated infrastructure was nearly complete as of October 8. Systems are being rebuilt from clean data volumes (e.g., Docker volumes) onto new, hardened hosts.
  2. Access security:
    - Implementation of an F5 Web Application Firewall (WAF) with pre-authentication for each customer instance.
    - Mandatory two-factor authentication (2FA) for all application logins.
    - Deployment of the Wazuh security agent for centralized login monitoring and anomaly detection.
    - All previous service accounts and credentials within automation workflows were deleted, requiring a re-issue.
  3. Automation restriction: Critical automation nodes in n8n (e.g., Execute Command, Read/Write File to Disk) were disabled and will be unavailable in cloud environments going forward.
  4. Enhanced monitoring: Additional security agents were deployed for endpoint security, configuration assessment, file integrity monitoring, and threat intelligence.
  5. Process change: Each customer instance undergoes a manual audit and documentation before restart, with the audit protocol provided to the customer.
Subsequent Attack Attempt (October 9)

On October 9, Localmind reported a renewed attempt to gain unauthorized access. The new security measures successfully blocked these attacks. The only confirmed impact was a brief, unauthorized text modification on a separately hosted, external development website, which was promptly reverted. The company attributes this attempt to the same threat actor.

Status as of latest update (October 9, 2025)

Systems were in a phased, controlled restart process, with customers being kept informed. The company continues to work on audits and security fortifications.

Sources (as Mementos)

<https://web.archive.org/web/20250000000000*/https://www.loca...> <https://web.archive.org/web/20250000000000*/https://security...>

tobwen··on Subway Builder: A realistic subway simulation game
Warning: There are no sandwiches in this simulation :)
tobwen··on Read Pages Later and Offline
Firefoxies for example.
tobwen··on Read Pages Later and Offline
What is this “offline”?
tobwen··on Show HN: A modern spreadsheet with Python integration
VBA and the ability to use Office files with embedded VBA are disabled in many corporations… Some malware in the past used VBA for their attacks and Microsoft never added a proper sandbox.
tobwen··on On Running systemd-nspawn Containers (2022)
Nope, you can compile/download and run it completely from unprivileged userspace.
tobwen··on File Pilot: A file explorer built for speed with a modern, robust interface
That's exactly what I've been asking myself and I wish I could. I index our huge, nested network drives every night with Everything and can search & find within seconds.
tobwen··on Choosing an op-amp for your project
But pre-ROHS of course :)
tobwen··on Reverse engineering the Sega Channel game image file format
It was even crazier in Germany! In 2000, the television station NBC received a radio license for RadioMP3. They broadcasted the charts and entire albums (with covers) via teletext, which could be legally recorded at home. Bit rate 128 kbit/s - simply with a TV capture card. The public broadcaster also transmitted software via “VideoDAT” during its ComputerClub program. However, this required special hardware.
tobwen··on Ask HN: Browser-UI with multi-LLM for the team?
Let's discuss this publicly, please. Open Knowledge has the advantage that others also benefit from it.

About the use case: Ultimately, I just want to enable my team to use different LLMs without having to create an account for each team member. However, it should be possible to upload attachments. RAG is not required at the moment.

tobwen··on Ask HN: Browser-UI with multi-LLM for the team?
Thanks it sounds great. I'll definitely have a look at that. Maybe I can connect it to LiteLLM so that we can connect all kinds of models.
tobwen··on Ask HN: Browser-UI with multi-LLM for the team?
Thanks, I'll have a look at that. But anything with ‘book a call’ sounds unaffordable for us unfortunately ;)
Page 1 of 2Next →