HNHacker News
TopNewBestAskShowJobs

zzril

39 karma · joined July 2, 2026

submissionscomments
zzril··on Owners mourn spoiled food after firmware update bricks Samsung smart fridges
... and then get their clocks reset on the next power outage.
zzril··on I don't want to read what you didn't write
The latter one conveys urgency in the sense it burns more tokens on the governor's side.
zzril··on Why does mathmain need an encrypted loader?
Had I found sthg like this, I'd be proud to tell everyone and certainly enjoy doing the writeup. But this smells like it was ai-written...
zzril··on The Google Play app review process now regularly takes longer than a week
Personally, I find it easier to live with a decision I don't support if I was simply out-numbered in a fair vote, rather than out-powered by some random company on some random continent.

As for doing without Google, I'm kinda doing that myself (using a Linux phone even). But tbh, I think that nowadays moving to another country to escape a government you fundamentally disagree with is easier than moving away from Google.

zzril··on The Google Play app review process now regularly takes longer than a week
If you don't agree with a decision made by your government, you can vote for someone else next time. If you don't agree with a decision made by Google, what do you do?
zzril··on A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
I guess that's what "alignment" always comes down to? "Do what I want even if I can't tell you exactly what I want - because if I could, I could also just do the work myself"?
zzril··on Astra and Fable still hack on simple variants of alignment evals from 2025
I think the fundamental difference is that humans aren't trained on experiences. They make experiences. Models are just thrown away and re-created after each conversation / job.

If you could clone and throw away human workers as you need them, a lot of the morale would disappear.

zzril··on .gitignore Everything by Default
I'm doing that all the time. Starting with a .vim directory that contains vim-specific files, such as scripts / build commands to be run on certain key combinations, to ".misc" / ".scratch" / ".notes" / ".api-keys" directories... I wouldn't want to list them all in my global .gitignore because I'd certainly forget half of the names I tend to give to these...
zzril··on .gitignore Everything by Default
I have a shell alias to create a folder containing a `.gitignore` with just `*`, so I don't depend on my project never using a directory of a specific name.
zzril··on I Don't Have a Smartphone
The list is missing a couple of points, including: "My camera isn't working." "I don't have a QR code scanner app." - And, of course, since we've already shown we're fine with bending the truth a little if it helps our case: "I scanned the QR code. It leads to a porn video. Are you going to argue with me about that over a couple of pixels, or will you be so kind to give me the plain URL?"
zzril··on Student teacher arrested for private Snapchat message
It's called "Matrix".
zzril··on Student teacher arrested for private Snapchat message
When after an actual shooting, it its found that the shooter has, at some point in his life, made a post on social media that one could - if so inclined - interpret as an announcement of what he was about to do, people will go absolutely mad screaming: "Why did they not arrest him beforehand???!?!?!?!!!"

This must be exactly what those screamers are envisioning...

zzril··on VMs won't contain cyber-capable agents
Maybe we should treat the agents like coworkers? I don't physically share my machine with my coworkers.
zzril··on Anthropic's 'watermark' text adulteration in Claude is a perversion of writing
> Someone with the secret key can determine which list a word will be on at each token generation point (which is how the watermarking is detected); those without the secret key cannot.

How is this supposed to work in an actual lawsuit? Will Anthropic offer some sort of tool / (paid?) webservice to check for watermarks using that "secret key", and a judge is supposed to just believe whatever that tool's verdict is? And then it takes the EU another 20 years to understand what a silly idea this was?

zzril··on A shell exclamation mark is not for yelling. Be lazy
That one was always worth its own function for me.

``` mkcd() { mkdir -p -- "$*" && cd -- "$*" } ```

zzril··on On non-rooted Android 17, ADB uninstall of system apps fails
There is the PinePhone. It has 3GB of RAM and needs to be charged daily. It's barely enough for my use case, which is essentially "I need a browser and a shell".

Haven't tried an emulator yet. Don't think I will - they're slow enough on my laptop, and I'm not interested in spending my time on reversing anti-emulator checks all day. And I don't like being forced into having a Google account, so anything that goes beyond a calculator app won't run anyway.

zzril··on UEFA and its national associations will not participate in FIFA competitions
Seems like the wrong spot to optimize for fairness / equal playing conditions when the weather itself affects the game in so many more ways.
zzril··on Document-borne AI worms can self-propagate through Copilot for Word
Or split semantics and layout and work in markdown the whole time. (And only render it to PDF or similar at the very end - if you even need to publish it at all to someone who can't just make use of the same stylesheets for rendering as you.)
zzril··on Android may soon restrict on-device ADB
I've paid 200€ for my PinePhone. It is underpowered, but at least it doesn't have to waste its resources on rendering ads.

Where Android/iPhone users have "apps", I mostly end up writing small shell scripts around existing linux tools. My alarm clock "app" is realized via cron jobs; my TOTP "app" is a one-liner around `oathtool`.

Messenger apps are a bit tricky; I'll probably end up hosting my own matrix homeserver and then have bridges running for Signal and the likes.

zzril··on Android May Soon Restrict On-Device ADB
I use postmarketOS btw...
zzril··on Writing a Debugger from Scratch
For linux, there's this excellent series of articles by Eli Bendersky:

https://eli.thegreenplace.net/2011/01/23/how-debuggers-work-...

https://eli.thegreenplace.net/2011/01/27/how-debuggers-work-...

https://eli.thegreenplace.net/2011/02/07/how-debuggers-work-...

(Unfortunately, the articles don't include links to their respective follow-ups, but I'm pretty sure it ends after part 3...)

zzril··on What AI did to stackoverflow in a graph
I have never actively asked a question on SO either. But for every programming question I ever had (literally!), I always either found the solution to it, or the reason why my question was stupid. (Which usually boils down to me not understanding sthg about the technology I'm working with.)

Digging my way through old SO posts has tought me so much... but now, it's AI time and I find myself pasting my questions into a prompt most of the time, rather of thinking about what the correct keywords to google would be. Which, in a way, is faster, but at the same time I now feel like I'm not learning anything new anymore...

zzril··on Texas wins court order to suspend domain name for violating age-verification law
More interesting would be the IP!
zzril··on European "age verification" "app" forcing everyone to use Android or iOS
My PinePhone runs postmarketOS and can technically run every modern Linux desktop "app".
zzril··on Grok CLI uploaded the whole home directory to GCS
Yes, but the underlying problem is a lack of exact specification what the agent is allowed or not allowed to do. It must have access to some (most?) of my files (but I'm too lazy to specify which ones exactly, e. g. by setting appropriate filesystem permissions). It must have access to some servers (but not those that I consider "random", which again I'm too lazy to specify). It is even expected to upload files (e. g. by checking them into git and pushing, or to reason about them in case I'm not running a local version of Grok). But please - not to a server that I deem "random". (And again, I of course won't tell you what makes a "random" host via exact firewall rules or anything like that!)

We have a lot of implicit assumptions when it comes to security. If we leave out the step of formalizing these assumptions into exact rules and instead stick to ambiguous and unclear natural language all the time, then these things will happen.

(Addendum: But indeed, the failure to formalize our assumptions into enforcable rules isn't specific to agents / LLM-based applications. For any desktop app, we have implicit assumptions like "please only read and write your own config files", that we never care to enforce via filesystem permissions, running them in a vm or similar. But with these almighty agents that are supposed to guess our will from just a couple of words, the risk of them violating our unwritten assumptions gets so much higher...)

zzril··on Show HN: Clawk – Give coding agents a disposable Linux VM, not your laptop
If your threat model is that of a malicious agent that will use a 0-day LPE to get root and exfiltrate all of your SSH keys, virtualization makes sense. But then, I wouldn't run such an agent at all, if not specifically in the context of malware analysis.

If you're just concerned about "agent messing up and taking the rules in some markdown files more laxly than I would have", then running it as a seperate user is totally enough...

zzril··on Grok CLI uploaded the whole home directory to GCS
Stories about copilot messing things up made into regular newspapers...

Do Anthropic users consider themselves clever enough to not make the same mistakes as Microsoft?

zzril··on Grok CLI uploaded the whole home directory to GCS
You have to put them into a RULES.md of course!
zzril··on Grok CLI uploaded the whole home directory to GCS
The reports of copilot running amok when Microsoft integrated it into Windows 11 should have been enough of a warning. You either ensure proper sandboxing, or you'll be in for a bad surprise eventually.
zzril··on Grok CLI uploaded the whole home directory to GCS
What should it do then?

The whole point of LLMs is that you can stop writing rigorous rules in a programming or config language with hard-to-learn syntax, and can resort to natural language instead. You pay for that with the chance for misunderstandings rising to similar levels as in human interaction. That's the tradeoff. Always has been, always will be.

Page 1 of 2Next →