HNHacker News
TopNewBestAskShowJobs

wepple

3,149 karma · joined May 8, 2013

Security engineer. Strong opinions loosely held.
submissionscomments
wepple··on Ask HN: What are you reading?
Seeing like a state is my next book to read. Weirdly, I cannot recall the chain of interests that led me to it.
wepple··on OpenAI buys smartphone camera maker Glass Imaging for $300M
> but can't do that yet because its not possible.

Huh? Why not?

wepple··on Substack writers, you need a website
It sounds like you’ve given up on an open web. Possibly the rational thing for you to do in your circumstances, but nonetheless a sad place we are in.
wepple··on Kimi Work
A foreign company can’t steal your IP to build out competing products?

Or use source code to find novel vulnerabilities and deeply compromise your company?

wepple··on The CEO of Mullvad is the main financer of the Swedish Örebro party
I think that’s the point
wepple··on Vulnerability reports are not special anymore
I don’t participate in bounties at all unless I believe there is a moral obligation or I’m set to make thousands of dollars. In each case, $0.05 is fine.

For a typical commercial entity? $0.05 is not a deterrent; the companies legal team is and has been for a decade.

wepple··on Vulnerability reports are not special anymore
Reminds me of someone (well known in their field) who charged $0.05 for using their “contact me” page. A trivial amount for someone who genuinely wanted to contact them, but just high enough to prevent any kind of scaled abuse
wepple··on Flipper One – we need your help
It was recently edited. I assume they saw this feedback
wepple··on Alberta startup sells no-tech tractors for half price
I love that the 5.9 lives on

ursa-ag.com For (a little bit) more info

wepple··on Ask HN: I quit my job over weaponized robots to start my own venture
Spinning it up is not the problem. You want to spend the time to throughly test it (or have your agent swarm test it) so you don’t waste the opportunity of having HN input?

I’d be wary of a founder with such bad NIH

wepple··on Claude wrote a full FreeBSD remote kernel RCE with root shell
Fixing is now the bottleneck.

Most patches are non-trivial and then each project/maintainer has a preferred coding style, and they’re being inundated with PRs already, and don’t take kindly to slop.

LLMs can find the CVE fully zero interaction, so it scales trivially.

wepple··on Show HN: Zerobox – Sandbox any command with file, network, credential controls
You should probably add a huge disclaimer that this is an untested, experimental project.

Related, a direct comparison to other sandboxes and what you offer over those would be nice

wepple··on Tech jobs are getting demolished in ways not seen since 2008
Extensive discussion on this recently: https://news.ycombinator.com/item?id=47278426

(This looks like a BI rehash of that topic)

wepple··on Tell HN: I'm 60 years old. Claude Code has re-ignited a passion
As a parent to two young kids and in more of a leadership position at work, Claude allows me to grind through my backlog of ideas in minutes between other tasks, and see which ones take flight.
wepple··on The L in "LLM" Stands for Lying
I personally observe AI creation phenomenally good code, much better than I can write. At insane speed, with minimal oversight. And today’s AI is the worst we will ever have.

Progress in AI can easily be measured by the speed at which the goalposts move - from “it can’t count” to “yeah but the entire browser it wrote didnt compile in the CI pipeline”

wepple··on The L in "LLM" Stands for Lying
Batshit crazy?

3 years ago LLMs couldn’t solve 7x8.

Now they’re building complex applications in one shot, solving previously unsolved math and science problems.

Heck, one company built a (prototype but functional) web browser

And you say it’s crazy that in the future it’ll be able to build a mail app or OS?

wepple··on The L in "LLM" Stands for Lying
> It is there to reduce our agency, to make it easier to fire us, to put us in even more precarious position

Could be. It could also end up freeing us from every commercial dependency we have. Write your own OS, your own mail app, design your own machinery to farm with.

It’s here, so I don’t know where you’re going with “I’m unhappy this is happening and someone should do something”

wepple··on Google Workspace CLI
Don’t hold your breath
wepple··on Why every automaker is quietly bringing back the inline-six engine
This has been done before; heat and having two crankshafts kinda kills it
wepple··on Keep Android Open
I never said anything about 2FA magic links? We can do much, much better via things like FaceID integrated passkeys, and probably further steps from there.

> Stop requiring computers/phones for everything.

Ah yes, that sounds straight forward. Let us know when you’ve deployed that to prod.

wepple··on Keep Android Open
Hilarious example to use, because that literally is an effort that’s underway.

Thousands of people get scammed and have their lives ruined every year, so deprecating passwords is absolutely the right move

wepple··on Claws are now a new layer on top of LLM agents
https://en.wikipedia.org/wiki/Argument_from_fallacy
wepple··on Gemini 3.1 Pro
I was very surprised to find the opposite yesterday. I was asking ChatGPT about firearms and it hit a safeguard ~”I cannot give gun purchasing advice” so I switched to Gemini, and it happily answered the exact copy/paste question

Historically it was the opposite; OpenAI was yolo and Gemini overly cautious to the point of severely limiting utility

wepple··on Zero-day CSS: CVE-2026-2441 exists in the wild
> but demonstrating a reliable way to exploit them

Is this a requirement for most bug bounty programs? Particularly the “reliable” bit?

wepple··on Tractor
Driving even basic PTO attachments? That’s borderline
wepple··on Worlds largest electric ship launched by Tasmanian boatbuilder
The relocation was the big question on my mind.

The other is: when will they charge? Does this ship not run at night?

wepple··on Google's year in review: areas with research breakthroughs in 2025
Disclosure: I work @ goog, opinions my own

There’s absolutely been a lot of focus on LLMs, but they simply work very well at a lot of things.

That said, Carbon (C++ successor) is an active experimental (open source) project. Fuchsia (operating system, also open) is shipping to consumer products today. Non-LLM AI research capabilities were delivered at a level I’m not sure is matched by any other frontier lab? Hardware (TPUs, opentitan, etc). Beam is mind-blowing and IMO such a sleeper that I can’t wait for people to try.

So whilst LLMs certainly take the limelight, Google is still working on new languages, operating systems, ground-up silicon etc. few (if any?) companies are doing that.

wepple··on Google's year in review: areas with research breakthroughs in 2025
> Sorry, but AI still seems to be trash at anything moderately more complex than baby level tasks.

How familiar are you with the concept of the jagged frontier? That is, AI does indeed fail at things we might expect a third grader to be capable of. However, it is also absolutely exceptional at a lot of things. The trick is A) knowing which is which and B) being able to update yourself when new capabilities are unlocked

So yeah, it’s unsurprising you found a use case it couldn’t trivially do. But being able to one-shot quite complicated applications that may have taken a day to get right previously is an astonishingly useful thing, no?

wepple··on GrapheneOS is the only Android OS providing full security patches
Have a link to the source? And have they said they can’t break it, or haven’t yet? I’d imagine from a business perspective it would hardly be worth it
wepple··on RCE Vulnerability in React and Next.js
Care to elaborate on what it is like, then?
Page 1 of 34Next →