I just finished reading this book while taking a train for a weekend vacation. To your point, he mentions that if spending money doesn't make you happy, it's because you're spending it on the wrong things. You shouldn't spend money to get the respect of others, because it's fleeting, causes envy, and is the fast food of getting respect. You need to spend money in ways that give you new experiences until you discover what kind of spending DOES make you happy.
HN user
MattSayar
mattsayar.com
Security Product Manager
Feel free to reach me at matt[dot]sayar[a]gmail[.]com
I got a shirt I liked from a conference, and I didn't know who made it. It was soft, fit comfortably... I took a picture of some random numbers on a tag and Gemini parsed out the numbers and found the manufacturer. Pretty neat
It smells like an architecture-related issue to me. They wanted to release the model asap, but they're still implementing the fine-grained controls to constrain the model to non-subscription users.
The loudest reaction to Mythos Preview from other security leaders has been about speed - scan faster, patch faster, compress the response cycle. More than one team we have spoken with is now operating under a two-hour SLA from CVE release to patch in production [...] If regression testing takes a day, you cannot get to a two-hour SLA without skipping it, and the bugs you ship when you skip regression testing tend to be worse than the bugs you were trying to patch.
Over time, I wonder if these models will be able to generate more secure code by default by doing this kind of exploitability testing before ever merging their code.
I like simonw's take that open source should be more valuable [0]
An interesting result of this is that open source libraries become more valuable, since the tokens spent securing them can be shared across all of their users. This directly counters the idea that the low cost of vibe-coding up a replacement for an open source library makes those open source projects less attractive.
I can understand why the reflexive move to fork the code and move it in-house, but how sustainable will that be when eng teams have MORE code to manage and mitigate vulnerabilities for?
[0] https://simonwillison.net/2026/Apr/14/cybersecurity-proof-of...
You can borrow ebooks via Libby to your Kindle.
I taped an Airtag-equivalent to one of my bikes as well
I recognize the sarcasm. The data I can find says it's performing at baseline however?
Yeah I left out a lot of details! But it did more than just my writing style.
It was able to piece together some other details that I've dropped related to where I live, in addition to my casual tone etc
It wasn't the username MattSayar, it's an alt account.
Took me a minute to realize Sid isn't associated with 0xide.computer. Clever domain name!
Getting Google to index my personal site has been a pain. Every other search engine works fine, but ever since I switched the images on my site to .webp (a format created by Google!), my site's content just doesn't get indexed anymore. I've given up since web search traffic matters less and less these days with LLMs, and it only really bothers me when I'm trying to search for my own articles.
The link is a 404. Is the repo still Private?
Small world, Matt! It's been fun seeing you pop up from time to time after writing for the same PSP magazine together
You just realistically can't know everything. I have a tankless water heater. It's almost a magical black box to me, but I know a little bit more about it now that I've taken pictures of it and asked LLMs to explain it to me. I'm still not a water heater technician, but I feel more knowledgeable.
And on the topic of motorcycles, I recently got a crappy bike that barely starts, and I partially got it because I feel capable of fixing it. And now it runs pretty well because I used lots of "video chats" with Gemini (and the owner's manual as context) to fix it!
Just be sure to run it with --accept-dns=false otherwise you won't have any outbound Internet on your server if you ever get logged out. That was annoying to find out (but easy to debug with Claude!)
This is exactly the way I see it. You can always get better performance at lower levels of abstraction, but there are trade-offs. Sometimes the trade-offs are worth it (like building bigger things), and sometimes they aren't (it's a buggy mess).
This is exactly the case. Businesses in the past wouldn't automate some process because they couldn't afford to develop it. Now they can! Which frees up resources to tackle something else on the backlog. It's pretty exciting.
Location: Colorado
Remote: Yes
Willing to relocate: No
Technologies: Product Management, Cybersecurity, Artificial Intelligence | CISSP, CCSP certified
Résumé/CV: https://mattsayar.com | https://www.linkedin.com/in/mattsayar/
Email: matt@mattsayar.com
I'm a PM with a proven track record shipping AI products that make money. At Anomali, I launched their Copilot generative AI suite from zero to millions in ARR. I handled everything from product-market fit to pricing and packaging. Before that, I built Splunk's first cloud-native SaaS app called Mission Control, coordinating 40+ engineers across 30+ teams to unify SIEM, SOAR, and investigation workflows into one platform. We gained over 1000 DAUs and 350+ customers in six months.I'm technical enough to be dangerous with a CS degree, partial MS in Cybersecurity from Georgia Tech, and I build things for fun (my side projects have hit the HN front page). But my real value is bridging deep technical understanding with business strategy in fast-moving security/AI markets.
Looking for companies at an inflection point where I can build or significantly scale a product function. Ideally somewhere at the intersection of AI and cybersecurity.
My small personal blog with tens of readers a month gets thousands of hits a day from bots. The ROI there must be worthwhile for those bots but not for me to self-host
I like the idea of having my own rack in a data center somewhere (or sharing the rack, whatever) but even a tiny cost is still more than free. And even then, that data center will also have outages, with none of the benefits of a Cloudflare Pages, GitHub Pages, etc.
Say more! Are you just squirting lemon juice into the bottle? How much? How often are you refilling the rinse aid reservoir?
Agree those tools are unreliable. Unless you have a massive amount of ML models trained on individuals' writing[0], the best you can do is vibe-checking[1].
[0] https://mattsayar.com/can-ai-tell-if-im-writing-ai-slop-a-ma...
[1] https://en.wikipedia.org/wiki/Wikipedia:Signs_of_AI_writing
It's like we forget rocks can easily go through windows.
Yeah, in the cybersecurity space it's a lot more prevalent. TLP:CLEAR, if you will.
In practice, "organization" usually means your company or business. "The community" usually means an Information Sharing and Analysis Center (ISAC) aka a group of similar orgs that share information with each other; think financial services companies in the US, or energy companies in Japan.
Good luck following the Enterprise Edition https://github.com/EnterpriseQualityCoding/FizzBuzzEnterpris...
Like many changes, you originally hate it, then you get used to it, then you hate when it changes again.