HN user

_lvbh

1 karma
Posts29
Comments790
View on HN
arti.torproject.org 3mo ago

Arti: a Rust Tor Implementation – no longer experimental and ready for use

_lvbh
3pts0
pganalyze.com 3mo ago

A Practical Introduction to Constraint Programming Using CP-SAT and Python

_lvbh
8pts2
duti.dev 4mo ago

HackEurope 2026: A short rant on AI and hackathons

_lvbh
15pts8
news.ycombinator.com 6mo ago

Tell HN: Deskflow is getting spammed with AI-slop PRs

_lvbh
4pts1
github.com 6mo ago

Show HN: App to spoof GPS location on iOS without jailbreaking

_lvbh
21pts4
conduit.rs 6mo ago

Conduit (Rust Matrix Server) v0.10.11 another critical vulnerability

_lvbh
10pts0
github.com 1y ago

Miru (anime player) is no longer open source

_lvbh
10pts5
news.ycombinator.com 1y ago

Ask HN: AI for maintenance of open source abandonware?

_lvbh
3pts1
duti.dev 1y ago

My uni is using AI for assessment feedback

_lvbh
3pts4
news.ycombinator.com 1y ago

Ask HN: What is the current SOTA transcription software accounting for accents?

_lvbh
3pts0
decrypt.co 2y ago

Jack Dorsey's Block to Shutter Cash App in UK

_lvbh
3pts0
news.ycombinator.com 2y ago

Ask HN: How much are you willing to use a "worse" product to promote competition

_lvbh
3pts9
news.ycombinator.com 2y ago

Ask HN: How do I make my niche knowledge discoverable for future rabbit holers?

_lvbh
5pts8
github.com 2y ago

Show HN: A deeper dive into Apple's WI-FI geolocation service

_lvbh
7pts1
tpo.pages.torproject.net 2y ago

Arti: A Tor Implementation in Rust

_lvbh
185pts30
news.ycombinator.com 2y ago

Tell HN: YouTube RSS feeds are gone (again)

_lvbh
27pts6
blog.duti.me 2y ago

Disorganized thoughts on xz backdoor and supply chain attacks

_lvbh
2pts0
news.ycombinator.com 2y ago

Ask HN: Those with memory loss, how do you respond when asked about your past?

_lvbh
1pts2
news.ycombinator.com 2y ago

Ask HN: Where can I find ideas on what to build (for fun)

_lvbh
6pts3
news.ycombinator.com 2y ago

Tell HN: Stop using email as the unique ID when using "Sign in with GitHub"

_lvbh
30pts18
news.ycombinator.com 2y ago

Ask HN: What do you use ChatGPT for and why doesn't it work for me?

_lvbh
12pts11
github.com 2y ago

Show HN: Copilot Chat for Neovim

_lvbh
2pts0
news.ycombinator.com 2y ago

Ask HN: The sky was orange and purple for a few minutes today in Cardiff

_lvbh
12pts15
www.lasso.security 2y ago

HuggingFace API Tokens were exposed, leaving users vulnerable

_lvbh
2pts1
news.ycombinator.com 2y ago

Ask HN: Why does OpenAI have such a ridiculous content policy?

_lvbh
3pts0
news.ycombinator.com 2y ago

Tell HN: Revolut suspended my account for no reason

_lvbh
27pts13
news.ycombinator.com 2y ago

Ask HN: ChatGPT-like hallucinations after excessive use of AI?

_lvbh
1pts1
news.ycombinator.com 2y ago

Ask HN: Learning iOS development without a Mac?

_lvbh
4pts0
blog.duti.me 2y ago

Wrecking OSTree on Fedorablue. An idiot’s journey

_lvbh
2pts2

This reminds me of when GPT-4 first released, the image capabilities were in preview and limited. A couple companies, including Perplexity, was leaking their API key on Replit & had early access by a couple weeks.

The dumb me at the time used it to do biology homework to do with diagrams instead of anything interesting...

I think the API endpoint was codenamed "rainbow" if I remember correctly. How time flies

1. The standard of living for the bottom 5% of society in terms of basic needs (food, water, shelter, and health) 2. Equality. The distance between the bottom and top in terms of economic and political power. Not just votes, but absolute power including if lobbying is allowed. 3. Hours of work per capita required to maintain current standard of living

Rare Wales mention! I'm currently in Cardiff (capital of Wales)

Most jobs here are C#, Java, and Python. Job market is decent. Lots of people have been moving here lately as developers. Expect very low pay relative to London or US though.

I also know some people living in Cardiff but working remote for companies in Reading or Warwick. Also a few people working fully remote for Bluesky.

I'm personally moving out (to San Francisco) to pursue a startup though

I get GitHub Copilot Pro for free for some reason. One day I checked and it was just there. So I use that until it runs out. When it does, https://synthetic.new with Kimi K2.5 works surprisingly well for small tasks where I still make all the decisions.

But I find no matter what I use, it still makes more sense to code by hand for anything that actually matters.

The things I've vibe coded are throwaway scripts to generate a gif, user scripts to tweak annoying websites, and various utilities that just need to work.

There are so many scanners these days these things get caught pretty quick. I think we need either npm or someone else to have a registry that only lets through packages that pass these scanners. Can even do the virustotal thing of aggregating reports by multiple scanners. NPM publishes attestation for trusted build environments. Google has oss-rebuild.

All it takes is an `npm config set` to switch registries anyways. The hard part is having a central party that is able to convince all the various security companies to collaborate rather than having dozens of different registries each from each company.

Rather than just a hard-coded delay, I think having policies on what checks must pass first makes sense with overrides for when CVEs show up.

(WIP)

Did it? Just checked and my feed is still completely untranslated. I have my settings set as English. I hope they don't do the weird YouTube thing of translating things from languages you know into the language you set. Multilingual people exist

Utaite. Will find barely any anywhere else. Thankfully if you're in one of those sub-communities, you don't ever get recommended anything political or American.

I've personally found the repairability to be worth the price for me. I got the baseline $999 back when it launched & have done stupid things like spilling a whole gallon of milk on it. Had to take it apart & clean as well as replace the keyboard but now it's still chugging along. Used to own a MacBook & the keyboard started dying after a year with a failed A key. Very expensive to replace so I just remapped caps lock to A. Then the screen started getting weird color issues and dead pixels. A MacBook Neo does look attractive though. Probably better performance.

Stars occasionally correlate with quality but more often it's timing and naming. I have a total of 40k stars on GitHub, and I know the code is shit in most of those repos (many written back when I was 16-18 as I was just learning to code). Jumping on hype trains before they start is how you get stars.

A couple questions:

- The default seems to make the payment without confirmation. What stops an endpoint from changing payment amount between an inspect request and the actual request?

- Will adoption of this payment protocol ever grow large enough for anyone to implement this on either the client or server?

- Bots have more of a financial incentive to crawl sites than a human. I doubt this will actually stop anything

- I see a AGENTS.md. How much of this is vibe coded? It's near impossible to get a sense of the care taken to review LLM output. Hard to trust with money.

What does production ready even mean? The problem with AI is that there isn't an obvious way to prove how much human attention\care was actually put in & thus no signal on quality. Nobody is gonna review 1M lines. Also, the 1M line number shouldn't really be a boast. More lines != higher quality or more features

I've been working on a project lately as my bachelor's dissertation which I later plan on working on long term on this issue.

The basic premise is a secure package registry as an alternative to NPM/PyPi/etc where we use a bunch of different methods to try to minimize risk. So e.g. reproducible builds, tracing execution and finding behavioral differences between release and source, historical behavioral anomalies, behavioral differences with baseline safe package, etc. And then rather than having to install any client side software, just do a `npm config set registry https://reg.example.com/api/packages/secure/npm/`

eBPF traces of high level behavior like network requests & file accesses should catch the most basic mass supply chain attacks like Shai Hulud. The more difficult one is xz-utils style attacks where it's a subtle backdoor. That requires tests that we can run reproducibly across versions & tracing exact behavior.

Hopefully by automating as much as possible, we can make this generally accessible rather than expensive enterprise-only like most security products (really annoys me). Still definitely need a layer of human reviews for anything it flags though since a false positive might as well be defamation.

Won't know if this is the right direction until things are done & we can benchmark against actual case studies, but at least one startup accelerator is interested in funding.

Not quite sure which channels I should reach out via but I've put my email on the page so they can contact me.

Based on timings, it seems that Wikipedia wasn't really at risk from the domain being bought as everything was resolved before NS records could propagate. I got 1 hit from the URL which would've loaded up the script and nothing since.

they are using Apple's Wi-Fi positioning service, but proxying it through their own servers

My concern with this system is that their proxy is (afaik) compatible with Google's format, which by default is less privacy respecting as it does the location calculation server side and doesn't allow the client to cache.

I'd much prefer if they called out to Apple's servers directly (or through a direct proxy) & cached the AP data locally so over time it will work offline.

100% agree even as someone who grew up around people speaking mandarin. I still cannot write despite having taken the language in both GCSEs and IB, while also living in the country for 3+ years.

i can speak the language just enough to get by but once you get into technical terms, i'm once again completely lost. Unless they do a Singapore or Dubai and make business in English, i dont see any chance of them attracting talent

Psychosis.hn 5 months ago

First try I got 0/5 with 3 false positives, by the third i got 4/5 with 1 false positive.

it's getting scary, i don't know how much longer we can tell humans apart from AI