HN user

Zak

16,411 karma

zak.wilson@gmail.com

https://social.goodanser.com/@zak (Mastodon)

Posts21
Comments4,782
View on HN
github.com 3mo ago

Show HN: I resurrected Clojure-Android – native Clojure on your phone over nREPL

Zak
18pts0
docs.google.com 11mo ago

Google feedback form for Android developer verification requirements

Zak
76pts6
www.telegraph.co.uk 13y ago

Where are my flying... motorcycles?

Zak
2pts1
code.google.com 14y ago

Chrome still can't handle cancelled page loads three years after bug report

Zak
2pts0
io9.com 14y ago

Democracy needs ignorant, mostly apathetic people to function

Zak
1pts0
code.google.com 15y ago

Annoyed by about:blank when a page doesn't load? Vote for the Chrome bug report.

Zak
3pts1
www.unlambda.com 16y ago

MIT CADR (Lisp machine) emulator and software

Zak
54pts5
www.fastcompany.com 16y ago

What the iPad might have looked like 21 years ago

Zak
2pts2
www.bookshelf.jp 16y ago

Paul Graham's On Lisp in HTML

Zak
54pts15
www.pcmag.com 16y ago

China shuts down hacker training website

Zak
1pts0
news.ycombinator.com 16y ago

Author identification by machine learning - ethics?

Zak
1pts7
zakwilson.posterous.com 16y ago

IP geolocation is a bad way to select a UI language

Zak
139pts53
news.ycombinator.com 16y ago

If you were making an app store, what would the rules be?

Zak
3pts3
zakwilson.posterous.com 17y ago

The world needs better data manipulation tools than Excel and Access

Zak
32pts17
www.youtube.com 17y ago

Laptop repair using a propane torch

Zak
2pts1
news.ycombinator.com 17y ago

Idea: site to match hackers with short-term one-off gigs

Zak
4pts6
news.ycombinator.com 18y ago

Startup idea: high-volume email client

Zak
2pts0
news.ycombinator.com 18y ago

Scheme in the real world

Zak
29pts26
news.ycombinator.com 18y ago

I seem to be writing a web-app framework. Any advice?

Zak
11pts8
news.ycombinator.com 18y ago

Startup founders: what are the most difficult technical challenges you've faced?

Zak
7pts2
notabug.com 19y ago

underscore_consulting on building a successful Web 2.0 startup [video]

Zak
3pts0

Then I wouldn't use it, and I would probably stop using services that tried to push me in to it.

I use multiple devices and I want to log in to things using only my master password. I also want to be able to back up my credentials to local encrypted storage so I can restore them if my password manager service provider stops operating or becomes untenable.

I have a hard time imagining any significant number of people objecting based on the sender's privacy. An adult sending explicit images to a child is a crime in most jurisdictions. A child doing it with a recipient under 13 is a concerning behavior the parents need to address.

Notifying the parents even requires that the child acknowledge that's what's going to happen.

Pedophiles aren't stupid

I'm not entirely convinced that's true. Facebook is a leading reporter of CSAM, much of it sent through Messenger, which only recently got E2EE, and Instagram DM, which briefly had E2EE but no longer does. If I was going to transmit something that could get me in trouble, it certainly wouldn't be via Instagram DM.

Facebook's EU CSAM report is here: https://transparency.meta.com/reports/regulatory-transparenc...

You wrote this in the passive voice; it doesn't say who is doing the blocking.

Pornhub itself is doing the blocking; it uses geolocation and denies services to IP addresses from jurisdictions with age verification laws. The laws are usually not structured so as to require a third party such as an ISP to block noncompliant sites; instead, the governments of the states with those laws can sue the porn sites and their service providers (Verisign in the case of .com domains).

That's so opposite to my preferences that I'd be really interested in the results of someone studying that group of users.

I do like local native software, preferably using the native UI toolkit, filesystem and features of the device hardware not necessarily available to the browser. That doesn't describe most commercial mobile apps in 2026.

I once read that app users are seven times more profitable than web users. That easily answers the author's question about why a company would bother make an app when a web page is the natural fit for the use case.

I don't remember the source or methodology for that number, but I have no trouble believing it. An app gives the developer a foothold on the user's device. It can more easily send notifications, track the user's location, resist customization like ad blocking, and remain present on the user's device even when closed. It's easier to funnel users into profitable behavior with an app.

Companies wouldn't do this if a large fraction of users refused the app, but most users don't.

Remote Attestation 13 days ago

The auditor app itself does not result in any loss of freedom, but the widespread availability of remote attestation mechanisms on end-user devices incentivizes others to use it in a manner that does.

A purely local mechanism that lets the user check the integrity of their system is great. Making it easy for third parties to inspect it is a severe violation of user freedom and privacy.

What? Why would you feel bad about a negative review of something you didn't create?

Either the product is something I was curious about and hadn't decided to spend time and money on yet, in which case a negative review might save me the trouble, or it's something I've already done and formed my own opinion about, in which case I'm probably not reading reviews.

Remote Attestation 14 days ago

There's some value in that, but Signal's main security proposition is that you don't have to trust the infrastructure. E2EE means even compromised server software can't read message contents.

At the time the LLM generated the compiler, just syntax. The semantics it generated were the subset of C that the C version of the compiler already used.

You could set the goalposts such that it wasn't novel enough to count, but for a short time I had code running in a language that nobody had ever known. Getting it from that point to a language that's ergonomic to use, teaches something about computing, or both is a longer journey, and certainly not one an LLM could take on its own.

An LLM won't come up with an interesting CRUD app on its own either. Parts of that process are pretty mechanical, but we had skeletons and templates before we had LLMs.

it’s hard to imagine they’ll ever independently develop a compiler for a truly novel programming language

I did exactly that using an LLM. It may not count as independent depending on how strict you are about that, but then LLMs don't do anything independently.

I wrote a small sample program and expected output, then told the LLM to write a compiler for it in C using LLVM. I subsequently told it to extend the language until it could be used for its own compiler, and rewrite the compiler in the new language. It did.

I don't think that contradicts your point about creativity. A compiler is probably a more mechanical task than a CRUD app is. There's a non-negotiable definition of done and correct.

Designing a language is a creative task of course, and I wouldn't expect an LLM to come up with a novel or ergonomic design on its own. In fact subsequent experiments have shown me that LLMs will consistently ignore terrible ergonomics in a language, never seeking opportunities to add abstraction or beauty.

The phones part is a red herring here. Phones work fine for reading text.

Video outcompeting text as a mainstream medium for both information and entertainment is as old as television. Youtube would be a more reliable way to make money than a blog in 2026 even if it was primarily consumed on TVs or PCs.

She delivered a shocking stat: 79% of U.S. buyers would only buy a car if it supported CarPlay.

I would be shocked by the number being that high because while iOS has a slim majority of the market share, it's nowhere near 79%.

There's already a restriction that requires going into the settings and flipping a toggle, with a warning. I think that's enough.

To be clear, enough does not mean that will stop every trojan/scam. People send Starbucks gift cards to callers claiming to be from the IRS calling to collect overdue taxes despite the obvious absurdity. Enough means that someone who doesn't know anything about computers but who reads and believes the warning label has sufficient information to know that it's a potentially dangerous decision. Some people will make the dangerous decision anyway, but it's on them at that point.

People keep talking about it that way inside our circles, and if we do that here, we will surely fail to do better with a broader audience.

Last year's example of ICEBlock makes the freedom/tinkering distinction clear to most people. ICEBlock was an iOS-only app for tracking immigration raids in the USA and alerting users when they're nearby. Apple caved to government pressure and banned it. Because iOS users don't have the freedom to install apps from other sources, that's the last word; the app is effectively dead.

I've found most people understand pretty well why that sort of thing is a problem even if it did not affect them.

The only time I've actually seen Android malware in the wild, it was because my mother installed a homescreen flashlight toggle widget from the Play Store that also displayed ads on the lockscreen. That was forbidden under Play Store rules, but there it was. I replaced it with something from F-Droid.

The Play Store still has a problem with shady apps years later. If Google wants to be more like Apple, they should start with better curation in their own store.

Knoppix 22 days ago

When I would fix Windows machines for pocket change, Knoppix was one of the first tools I'd reach for. It made separating janky hardware and janky software much easier.

Dark Sky Lighting 23 days ago

The site links a couple studies coming to a different conclusion about crime. Feeling safer doesn't necessarily mean you are safer.

As for pedestrian safety, button-activated lights over crosswalks are one potential alternative to always-on outdoor lighting. It might lead to a considerable safety improvement once people got used to the light being an indication that pedestrians are likely present.

Dark Sky Lighting 23 days ago

It does link a couple studies to back up that claim. Critiques of those studies or evidence for the opposite would contribute to the conversation; this does not.

I'm seeing a big red flag here for what purports to be a systems programming language: it isn't used for its own compiler. The compiler is written in Rust.

A systems programming language should be able to self-host its compiler. Writing compilers is one of the canonical systems programming tasks. Making that happen may not even be hard in the LLM and LLVM era as it's a fairly mechanical task for an LLM to execute, and you can output textual LLVM IR to bootstrap on any architecture LLVM supports.

One issue I keep seeing with cost comparisons is that they compare API rates while a substantial fraction of users are on subscription plans.

It's more expensive to use GLM 5.2 paying z.ai or Opencode Zen API rates than it is to use Opus on a subscription plan. Both of those providers offer subscriptions priced favorably relative to their API rates, but only in what are effectively trial sizes.

The ability to build reliable software has existed for a long time. Commercial airlines make heavy use of it, and serious failures are vanishingly rare.

The problem is building software to those standards of reliability is expensive and slow. Consumer software never justifies it. Business software rarely does. If you want me to accept liability for the consequences of bugs in code I write, I'm giving you a schedule five times as long and a price twenty times as high.

The name wasn't invented until 2003, but yes.

Guestbooks, contact forms, signup pages, and the like started receiving automated abuse approximately five minutes after they were invented. It didn't take long after that for people to start including a question they expected to be easy for a person and hard to automate with a script.

What's relatively new is CAPTCHAs merely to browse a site. There are few faster ways to get me to close your site, and maybe send you an unfriendly email.

I have the impression the situations where that actually happens are at least arguably serious misconduct, and usually targeted at someone with significant assets.

A construction company that pockets ten million dollars and doesn't build anything probably can't shield its owner this way, but a single-developer software consultancy that pockets ten thousand dollars and delivers buggy code can.