HNHacker News
TopNewBestAskShowJobs

woodruffw

42,213 karma · joined May 26, 2015

I'm a Software Engineer in New York City. Before that, I studied philosophy.

On the philosophy side, I'm chiefly interested in metaphysics (ontology and mathematics/formal systems & semantics) and deontological ethics (praise and blame, moral education, honesty & bad faith).

On the computational side, I'm chiefly interested in program analysis (compilers), security (compilers), and systems (compilers). I do a decent amount of professional open source work on projects that encompass some of those.

My opinions are my own and do not reflect those of any employer, institutions, affiliates, lovers or haters past, present, or future. They might not even be mine anymore!

Sites: https://yossarian.net / https://blog.yossarian.net / @yossarian@infosec.exchange

submissionscomments
woodruffw··on Rust's derive often implies inline
The codebase in question (uv) uses PGO already. I suspect there isn’t a general way to guarantee that PGO ensures that only the “right” things get inlined.
woodruffw··on Gods in the Classroom: Religion and Education in First Millennium BCE Babylonia
This isn't consistently true. The kind of animal sacrifice that happened during the First and Second Temple periods often involved burning the entire animal, except for its skin[1].

(To my understanding, giving the god(s) only the "undesirable" parts of the animal is popularly associated with the Greek gods, not Abrahamic faiths.)

[1]: https://en.wikipedia.org/wiki/Burnt_offering_(Judaism)

woodruffw··on Turn off Apple Intelligence on macOS 27 and get its disk space back
That doesn't seem to do much in the `curl | bash` setting, given that you're not verifying the attestation in that case. You still need to download it separately and run `gh attestation verify` first.

(Note that the attestation does not appear to cover the shell script either, it only covers the script's final payload. The shell script is also referenced via `main`, so it's mutable even if the underlying payload is properly attested. That's not good!)

woodruffw··on Getting the most out of Opus 5.5 in Claude and Claude Code
“Wall time” is a pretty common systems term (you see it when comparing total runtime to kernel time, for example). I wouldn’t have indexed on “wall clock time” or other variants as an LLMism.
woodruffw··on Several vulnerabilities have been discovered in the Linux kernel
From experience: many companies have a “risk management system” that involves nagging OSS projects to do free work for them, even when the advisory is manifestly nonsense or has no impact in context. Many teams have a “green dot” mindset, and CVE directly encourages that behavior by stapling CVSS scores to identifiers.
woodruffw··on Tell HN: Codex Is Down [fixed]
It's on the status page: https://status.openai.com
woodruffw··on Docker releases cloud sandboxes, enabling safe agentic workloads in the cloud
I have this nagging feeling with these kinds of agentic cloud products (and there seem to be so many these days): the promise is secure (as in isolated) workflows, but it’s unclear what that means when so many of the workflows themselves are privileged.

Or in other words: I often struggle to see the security value of a VM that I’m just going to load all of my sensitive credentials into anyways (since the agent needs them). The usability argument seems strong, but the security argument seems to hinge on me treating my local machine as a sort of bastion host, which I don’t think is generally true.

(This isn’t to denigrate the work itself: it seems very good. But it also seems like we’re still groping around a very weak definition of “security” for agentic workflows.)

woodruffw··on Nobody pays for FOSS, we can force them to
KYC is the polar opposite of “hippie BS.”
woodruffw··on US halts flights at busy East Coast airports, says fiber line cut
I completely agree. My comment is not to suggest there wasn't a problem or failure (clearly there was one!), but that we shouldn't assume incompetence versus conflicting priorities under limited resources.
woodruffw··on US halts flights at busy East Coast airports, says fiber line cut
They had two diverse paths, but apparently did not have a (reliable?) process for ensuring the backup path was functional during fail-over. I imagine there will be some soul-searching over that.

Nothing I've ever seen or experienced with FAA indicates a lack of care; the parsimonious explanation is almost always that people who care a great deal are working within complex systems that don't always have a consistent or externally legible set of priorities. Or more intuitively, the failures we see are the "acceptable" ones versus the unacceptable ones (like planes falling out of the sky).

woodruffw··on Nobody pays for FOSS, we can force them to
I think Alex Gaynor is essentially right here[1].

[1]: https://alexgaynor.net/2025/apr/08/putting-a-price-tag-on-op...

woodruffw··on Nobody pays for FOSS, we can force them to
(Speaking only for myself.)

Having open indices charge money is the “easy” part, relatively speaking. The author is correct that most companies will grumble a bit and then fork over the nominal amount of money needed to preserve their existing assumptions.

I think the rest of this don’t really work in practice though: it’s actually incredibly hard to distribute money to open source maintainers across hundreds of jurisdictions, and it’s not immediately obvious how a service like PyPI (which is barely funded to maintain and sustain itself) would shoulder such a burden without diverting a very large fraction of that money for things that would make people upset (read: lawyers and tax professionals).

(NPM would appear to be the exception to this since it has - at least on paper - the legal resources of Microsoft behind it. But I think it’s largely a quirk of history that the JavaScript packaging ecosystem ended up with a single corporate owner, and no ecosystem I’ve worked with seems eager to pursue a similar relationship.)

woodruffw··on Keys Not Included: recovering the signing keys for US driver's license barcodes
As far as compact encodings go, this kind of patch-and-fill technique isn't particularly egregious. The alternative mentioned (where the verifier has to be aware of a bitfield that defines the to-be-signed elements) is much easier to mess up!
woodruffw··on A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
I didn’t realize it was hasbara to describe Unit 8200’s proficiency as propaganda. One would reasonably expect the exact opposite.
woodruffw··on A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
“Space camp,” not “space.” As in, a place to park dorks.

(The problem with “alumni” is that it means very little in mandatory systems. Unit 8200 is where Israel parks its dorks, and it stands to reason that dorks are the ones who tend to start tech firms.)

woodruffw··on A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
> The idea that people bend over backwards to hire criminals as subject matter experts on security is largely a Judaic practice that television perpetuates in spite of reality.

What?

> If you're convicted of hacking in Israel, Unit 8200 will probably send a recruiter.

To the best of my understanding, Unit 8200 is filled with military conscripts, i.e. is primarily 18-somethings doing their mandatory service. You get assigned to it based on an aptitude test. The widely held idea that it’s a uniformly elite entity rather than the IDF’s space camp is a triumph of propaganda.

woodruffw··on Homebrew 7.0.0
I’m one of Homebrew’s security maintainers, and I don’t recall any contact with you. Who did you reach out to?

If you have concrete concerns, please bring them to us. Vague concerns and hand-waving about “people getting hurt” isn’t appropriate or productive.

woodruffw··on The death of San Francisco's Market Street
That’s fascinating; like others, I’d love to see the source data.
woodruffw··on The death of San Francisco's Market Street
That makes sense, given that the median car mile probably isn’t in a dense urban core. The more accurate comparison would require us to know pedestrian fatalities per mile in urban areas.
woodruffw··on The death of San Francisco's Market Street
The primary driver appears to be economics (vis a vis the pandemic and slow recovery afterwards), which has very little to do with the author’s primary target (cyclists and buses).

A more sensible null hypothesis would be that cyclist and bus traffic follow the same rough pattern as car and pedestrian traffic, i.e. economics is always the leader for whether people show up in a given public space. That would explain why NYC and most European cities haven’t seen any real negative consequences to aggressively pedestrianizing and re-allocating their streets away from single-occupant car traffic.

woodruffw··on How accurate have Ed Zitron's AI skeptic predictions been?
I mean, the point of Frankfurt’s bullshitter is that we know they’re bullshitting (or more expansively, Frankfurt gives us a set of criteria to test them against). We know they don’t care about the truth value of their statement, only that they are misrepresenting themselves because of a hidden “enterprise.” But there’s no such unknown enterprise in either’s case, and neither appears to be misrepresenting themselves (to my point about appearing earnest). Maybe that latter part is itself deception, but without the former they would fall into Frankfurt’s classification of a “liar” instead.

(I have to admit a bias when it comes to Frankfurt: I don’t think On Bullshit is that convincing. In particular, I think Frankfurt doesn’t do a good job of motivating the connection between bull sessions and bullshit in his strong sense, and many of his examples - like the Pascal/Wittgenstein one - don’t demonstrate misrepresentation either.)

woodruffw··on How accurate have Ed Zitron's AI skeptic predictions been?
I don’t think these mental states are in evidence for either of them. I think they’re both credibly earnest in their views.

(Frankfurt’s characterization of the bullshitter rests on not just the truth value being absent, but also on the bullshitter’s misrepresentation of what he’s “up to.” I don’t feel that either Zitron or Altman is misrepresenting what they’re getting up to.)

woodruffw··on How accurate have Ed Zitron's AI skeptic predictions been?
Without reference to either person, I think this is essentially a misunderstanding of Frankfurt’s analysis: On Bullshit is about expressing sentiments without caring about their truth value, i.e. the concept of a “bull session.”

Both Altman and Zitron are the opposite of Frankfurt’s bullshitter, because they both appear to evince genuine care for the truth value of their position.

(Frankfurt is very subtle about this, in that he distinguishes the kind of performative lying you’re suggesting as distinct in moral and rhetorical content from bullshitting. The liar wants you to believe a specific thing; the bullshitter wants to regale you.)

woodruffw··on uv: Deduplicate all files in the wheel cache
It depends on what you mean. The PEPs are essentially a behavioral core, and each tool (build backend, etc.) adds on top of that core. If you’re installing a package, any installer should work; if you’re developing a package, you may be subject to implementation details from your development tool of choice.
woodruffw··on uv: Deduplicate all files in the wheel cache
We do a lot more than that, e.g. how to cache distributions is not defined anywhere within PEPs (and should not be, since it’s a purely internal tool decision). But yes, it helps that uv implements the PEP for detached metadata, particularly during resolution.
woodruffw··on uv: Deduplicate all files in the wheel cache
I think this sockpuppet is referring to a different thread I commented in yesterday. But I think it would be an uncharitable stretch to read what I wrote in an official voice, much less “pro” in an unqualified sense.
woodruffw··on A CVE Dispute
This kind of hellish experience is a great example of the CVE system trying to have it both ways: when on the offense it’s a rich source of information for defenders, and when on the defense it’s just an opaque ID for coordination that implies nothing about the quality or correctness of the underlying report.
woodruffw··on CobaltC – The Successor to C?
Another one?
woodruffw··on Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
My understanding is that IME and PSP come more from the world of corporate compliance than anything else. In other words they exist for x86 because x86 gets deployed in corporate settings, and any ISA that attempts to occupy a similar niche will meet a similar fate.

(Compare ARM’s TrustZone, etc.)

woodruffw··on European Commission Revives Push for Encryption Backdoors in ProtectEU Strategy
I don’t think the average American voter “genuinely” thinks that they’re on a Blues Brothers-style mission from god to deliver liberalism and freedom to the world. I would be surprised if that’s even a minority view among voters.
Page 1 of 34Next →