HNHacker News
TopNewBestAskShowJobs

zbentley

6,028 karma · joined June 30, 2017

Zac Bentley

he/him

github.com/zbentley

blog.zacbentley.com

submissionscomments
zbentley··on Does Reddit have an astroturfing problem? What the data suggests
What do you mean when you say "men who pretend to be women"?

I understand this is a fraught question, and I'm not trying to be snide or score points. Given the specifics of the post you're replying to, I think that's a germane thing to clarify here.

zbentley··on PS5 Relapse Exploit
Pushback like there was to making Office 365 or Adobe subscription-only? Or pushback like there was to Google mostly killing AOSP? Or pushback like there was to ads in Netflix & friends? Or pushback like there was to <pick a subscription service> price hikes?

You'll note that all those things are still there, and their competitors are either not there or not significantly bolstered by people disgruntled by those changes.

zbentley··on The last time my family was replaced by technology
> "Make this. LGTM. Now make this".

I think well north of 90% of people in software engineering have job expectations that, when assisted/automated with AI, boil down to exactly that.

It's a pain in the ass to work at such a job and find challenges or things to master--your superiors don't want you to do that, there's not enough time in the day, and you're tired from LGTM-now-make-this work.

That's most software jobs, because that's what most software companies want.

zbentley··on Tells of a Slop UI
> To be fair, your blog has the opposite issue, with the sidenotes forcing me to zoom in to read the text on mobile.

Very true, I’ve procrastinated on fixing that for too long.

zbentley··on Does Georgism work? Five years later
I don’t think dialogue has ever been the principal motivator for social change.

> I don’t want to live in such a society.

You kind of already do, but kind of don’t. Coercive politics still rule, but countries with strong civil liberties protections allow less harmful forms of coercion. Under strongman rule, coercion looks like the threat of murder. Under a liberal democracy, coercion looks like blocking traffic. That’s a big improvement.

Positive incentives (bribery and upside) also play a role opposite coercion. But “dialogue” absent self interested or dominance-oriented goals is a much less significant influence—unless you loosen the definition of dialogue to include things like “I convince you that it’s in your interests to vote for X so that protestors stop blocking traffic”, at which point there’s no distinction between the concepts.

zbentley··on Tells of a Slop UI
Really not a fan. Like, fairly significantly bad. Text sizing is poorly chosen, the only affordance for navigation or understanding what content is contained within what sections is at the bottom, sections are concentrated together in an overwhelming way (god help me if I’m a frequent visitor primarily interested in “external writings and presentations”), headings and font sizing is variously too close together and too far apart, code blocks are always in a huge font compared to prose, and code blocks blow out the horizontal scroll, meaning that vertical scrolling on mobile is a massive pain in the ass.

There are good examples out there for minimal, straightforward blog design. This ain’t it.

zbentley··on Tells of a Slop UI
UI design (not implementation) is an area where “describe it with a programming language” has historically not worked. So much of what makes a UI good or bad is determined reactively after seeing the initial prototype. Those refinements are rarely based on an encoded set of principles that found their way into a training set, and the code used to implement such refinements was varied enough that models and humans both struggle to infer its intentions after the fact.
zbentley··on Allegations of sexual harassment and rape at Bay Area AI party houses
Los Alamos?
zbentley··on How I changed teaching after AI managed to do all my homework assignments
> But will we finally have a path away from standardized testing, middle-of-the-road education? I am hopefully optimistic. We'll rediscover the need for human growth and development in our schools.

I worry that the availability of this path will be extremely unevenly distributed, amplifying existing educational gaps along class, race, and language-proficiency lines.

That might be better than a forced average denominator, but the social effects of further amplifying those gaps are pretty severe and don’t take that long to happen. Combine that with the fact that education isn’t like new miracle drugs, where improvements inevitably tend to become more and more widely available to different groups, and I’m not as optimistic about the future.

zbentley··on On caring for user data: NeoVim caused Vim undo files to be deleted
“Here, take this car, it’s free!”

“Ow, the gas pedal is actually a bear trap.”

“Why are you complaining? It’s free!”

zbentley··on ASML says it sold 'absolutely nothing' in Europe in 2026
Not GP, but: Belgium and Louisiana. And I’d pick Belgium again in a heartbeat, even if you removed all of the non-political (e.g. climate) differences.
zbentley··on Fifteen years later, the Apple Cards origin story
> only possible in a ZIRP environment.

Why did interest rates matter to Apple, a company famously averse to extended or significant borrowing?

zbentley··on Fifteen years later, the Apple Cards origin story
MagSafe chargers have lights though?
zbentley··on HomelabFest will be in St. Louis in September 2027
“Personal” is an arbitrary line that anyone can decide to draw anywhere. Supporting someone professionally/publicly gives them resources which they can use on other “personal” pursuits.

Also, as we’ve seen in the case of DHH and others (https://drewdevault.com/weird-guys should not be taken as gospel, but it’s certainly a reasonable place to start), public figures have a tendency to move their “personal” business more towards their professional/public platform.

zbentley··on California is chasing wealth that has feet
> They don't have any useful mechanism to stop the sale of a share of stock

The SEC exists. As do many other mechanisms by which the government regulates direct and brokered securities trades and sales. You can make the case that some of those controls are poorly/ineffectively implemented, but you can’t claim that it’s not something the government routinely regulates, intervenes in, and sometimes prohibits outright.

zbentley··on Unknown number of Texas voter registrations went unprocessed due to DPS error
Yeah! And that's bad!

But "racist state officials did voter suppression" is a different failure mode of the system than "data system corrupted registrations and now they're scrambling to fix the damage".

The malicious-officials problem has fixes like "vote people out" and "decommission harmful programs" and "restore cut funding".

The busted-data-system problem has fixes like "national ID card system" or "remove regulations preventing effective data sharing" or "hold system implementors responsible for failures".

If you see the disenfranchisement/conspiracy of the former in the bureaucratic/tech debt of the latter, you'll fix the wrong problems in the wrong ways, and make things worse.

zbentley··on Unknown number of Texas voter registrations went unprocessed due to DPS error
> Broken implementations were the desired outcome, because the constant doubt allows for things like disenfranchising people via voter roll purging.

I have trouble believing that, given that the "design", such as it is, took place over many decades of inter-agency regulatory/technical wrangling and organic growth.

At different times and points, the people that built what we think of as "the voting system" had totally different goals. Sometimes those goals were "make sure everyone eligible can vote as easily as possible"--and that's laudable! But more often the goals were "build $niche_system_component to comply with $specific_regulation". The number of times, during the design phase, where the people planning actually wanted to suppress votes and were empowered to make a part of the system actually do that was probably a rounding error compared to times when people fully accidentally moved the system in that direction due to bureaucratic myopia and shitty implementation.

I'm all for blaming political actors for things they intentionally do that are bad! Defunding the EPA? Bad! Getting into stupid wars? Bad! Banning mail-in voting? Bad! People with power and pre-meditated goals did those things, and many more, and should be opposed for it.

But "voting system is broken due to bureaucratic inter-operation failures, and state government staff have to do a postmortem and data recovery (ballot reprocessing)" isn't one of those times.

zbentley··on Unknown number of Texas voter registrations went unprocessed due to DPS error
I know this was mostly glib, but it really doesn't work that way. There aren't centralized data repositories that even can be joined, in many cases. Even when they could be (by batch/paper-form request/extremely slow system integration) joined conceptually, many decades of inertia, law, regulation, and political opposition often prevent those interconnections from existing. Even when they are permitted to exist, they're usually implemented in extremely broken ways.

And plenty of that headwind is not coming from the "party of small government"! The refrain of "the government should not have centralized data it can use to infringe on my rights" often transcends party, depending on what issue is at hand. That's sometimes a reasonable position to hold, but it definitely has a cost, especially when taken to extremes, or when make-citizen-services-work-better initiatives are framed as spying or whatnot.

zbentley··on Unknown number of Texas voter registrations went unprocessed due to DPS error
> Surely the government already knows who is a citizen

No. There's a lot more nuance there than you'd think, in the "broken regulatory and technical processes" domain, not political issues.

Example questions with unsatisfactory (not "impossible to do well", just "broken due to decades of technical and regulatory debt") answers: what government agencies, plural, are the authority of who is a citizen? Do they all agree? Do they provide ways for different agencies to check identities against their registries? If so, how do they match information in a citizenship-check request against their internal systems? By name? If so, how do they handle different name spellings (marriages, name changes, present/omitted middle names, non-ASCII)? By some other identifier? If so, how do they validate uniqueness of that identifier (SSNs are not secure/are widely leaked for tens of millions of people, addresses change and can have multiple residents, not everyone has a passport number, state-issued IDs/drivers licenses aren't stored centrally by the federal government)? If a check-requested identifier is invalid, can they tell whoever requested the check why it's invalid? Do these validation requests happen in real time/one at a time, or periodically in batches? Do the people sending the validation requests have any contact at all with the people providing information about why unsuccessful requests failed?

I've worked on these systems--human and technical. It's hard even for a functioning, outcome-focused, centralized government. In this problem domain, the US federal government is none of those things, and has not been for many decades (or ever, in some areas).

Sure, some of the issues are politically-caused (one party has an incentive to not fix problems that privilege their agenda), but most of them are accumulated failures with no malicious agenda as the cause.

zbentley··on Unknown number of Texas voter registrations went unprocessed due to DPS error
> The whole process feels like it’s designed to discourage people from voting.

Possible, but I doubt it. I've worked on the systems that do things like ID correlation/verification on the backend. They're ... imagine the most broken possible implementation you've ever worked on, then imagine it worse, then imagine that it's maintained by entirely different contractors than the ones that built it, with minimal incentive for improvement.

That's most of government IT implementations, and has been for decades.

Even when specific systems in this area are implemented well, the regulatory/bureaucratic complexity of the government prevents them from being more than marginally useful at best. I expanded more on some of the concerns/issues in this area in an adjacent comment here: https://news.ycombinator.com/item?id=49832393

zbentley··on Making Tailscale Faster
No idea if this is what they meant, but it’s plausible that client battery usage goes up when connected to Tailscale using an exit node. Suddenly, a lot more traffic has to be processed in userland, on the CPU. Ordinary internet transit might be offloaded to the kernel or hardware such that it’s more battery-efficient.

Then again, that begs the question of what you’re heavily using exit-node-routed internet links for that Tailscale’s battery draw is noticeable. Most network-intensive internet tasks draw way more power to drive whatever the application is, such that VPN overhead is a rounding error.

zbentley··on C++26: Trivial infinite loops are no longer undefined behaviour
Yes. Loops that manipulate data are extremely common. Combining memory accesses and increasing cache locality are extremely beneficial to performance. Transformations that rewrite loops to increase the chances of locality/combining are therefore likely to be worthwhile.
zbentley··on UTF-8000: Unlimited UTF-8
I think the DoS has pretty common amplification vectors in the form of APIs that split or otherwise copy (e.g. materializing code points for Unicode regex searching).

Additionally, OOM inside a low level routine can be a troublesome attack, since OOM handling in many applications does questionable (nee vulnerable) things when crashes occur in not-known-to-be-memory-intensive code. Sure, that’s sloppy engineering, but it’s common.

zbentley··on The scourge of x86 emulation
“Emulator” is a term of art in this area which refers to emulation of a hardware (and usually machine instruction) environment. Ironically, “translation” (as in instruction translation), as proposed by a sibling comment, is an even more connoted-with-hardware-emulation term.

WINE is … well, most directly it’s just an implementation of an API (the Windows APIs). In webdev parlance it might be called a “polyfill”. Perhaps a “compatibility shim”?

zbentley··on PyPy v8.0.0 Release
I do think Go and Java are strong examples of this. Those languages have native code support, but it’s clunky to use and, more importantly, very rare.

If you removed JNA/JNI/CGo, plenty of people would complain…but the vast majority of uses of those languages would still work, unaltered, because most common tasks on the JVM and Go runtime don’t require external native deps.

zbentley··on What Zig felt like, coming from Rust
> Arenas make lots of sense for video games, but their applicability for these other applications is much more dubious.

It's a fairly common pattern in non-video contexts to preallocate arenas of different sizes for different workload pools (e.g. different routes for a server).

It's also fairly common to allocate per-work-item (e.g. request/session/batch job) arenas for "general-purpose" scratch allocations that are small (your header parsing, auth context retrieval, etc.) and then default to a global manual/refcounting allocator for one-off large data actions like your holiday change. Since most business applications are returning summary/small aggregates over the large data action (in this example, something like "holiday updated successfully", not the entire history of the PTO table or the database connection's internal state), the copy cost of moving data between the global dynamic allocator and the arena for result transmission tends to be small.

That's not a terrible approach in some situations. If the large majority of code only needs the scratch arena and/or some per-handle allocators stored on e.g. the database connection pool, it can work well. But if, over time, the amount of bookkeeping required to maintain data tagging/movement between arenas/allocators becomes severe, it's worth stopping, stepping back, and considering that you've kind of walked backwards into inventing a shitty generational GC.

zbentley··on Warez: The Infrastructure and Aesthetics of Piracy (2021)
Does that extend to medical systems? If someone hacks my pacemaker and destabilizes my heart, or my pharmacy/hospital and prevents me from receiving medical care, is that something that should be legally permitted on the basis that "medical device makers/pharmacies/hospitals should try harder, and should somehow compensate their patients if a hack occurs"?

How do you compensate someone who's dead?

This isn't hypothetical: https://www.politico.com/news/2022/12/28/cyberattacks-u-s-ho...

zbentley··on I don't like passkeys
All true, but there's a wrinkle with delegating auth in computer systems--the same wrinkle that comes up when thinking about digital data as property/copyrightable etc.: when you delegate auth, you copy the access; you don't loan it. So every digital delegated-auth scenario is like your "make a copy of your house keys" example, not your "loan out your debit card" example.

If we extend the metaphor, this would be like making a copy of your keys and handing those out every time someone other than you needed access to your house. Dinner guest? Key copy. Neighbor dropping off a borrowed tool? Key copy. Relative from out of town visiting? Key copy.

In the same way that I think most homeowners would look askance at passing out so many copies of their keys, delegated digital auth is troublesome. Nontechnical users are unlikely to pay attention to "what clients are using delegated credentials for which actions" dashboards. Revocation, while technically easy, isn't something that I think most casual users will be mindful of, resulting in endless growth in the list of principals with access to a resource (just like the "sharing passwords" scenario we have now). Time-based auto-revocation will be an annoyance for delegates who only need to access a resource rarely, resulting in exasperated administrators rubber-stamping new-delegate-credentials requests.

I don't know if there's a good solve here. Shared passwords might be the local maximum of convenience and security, but that feels pretty bad.

zbentley··on Bend 2 and the Vibe-Coding Trap
> That's why all your LLM requests to build something substantial should start with "run prior work research first".

Yes, but I think there are incentives to not do this for many LLM providers. Doing prior-work research is slow (web searches aren't fast, LLMs are rate-limited or blocked from plenty of pages, etc.), and sometimes contradictory which annoys LLM users, many of whom like faster gratification cycles from the agent slot machine handle.

Also, writing a bunch of bespoke code instead of leveraging prior art makes a lot of users feel like they own something novel/big/important, and also poses a larger maintenance surface for the LLM to make future changes (which costs tokens).

I don't think there's, like, a conspiracy at LLM providers to set up system prompts/RAG/etc. to discourage research-and-use-prior-art-by-default approaches. Rather, OpenAI/Anthropic/Google/etc. are optimizing for real but sometimes misleading success metrics which often lead away from a research-first approach.

zbentley··on You can run Git on object storage if you re-make packfiles
I posted this because it seemed timely given that 'CGamesPlay and I were discussing this exact kind of system two weeks ago on the thread about why kernel.org's cgit (git web UI) hosting system was becoming expensive to operate due to LLM scraper load: https://news.ycombinator.com/item?id=49504674
Page 1 of 34Next →