HN user

apgwoz

7,297 karma

Personal: - http://sigusr2.net/ - My topcolor is #ccff66

Email: - web@apgwoz.com

Elsewhere: - https://github.com/apg

[ my public key: https://keybase.io/apg; my proof: https://keybase.io/apg/sigs/FVP39qxp7ptdAG2Nfeigd5-mN2nceMwWnPl2-EIhP4I ]

Posts265
Comments1,379
View on HN
sigusr2.net 9y ago

Show HN: Envjson: Config Checking for 12 Factor Apps

apgwoz
1pts0
hifibyapg.com 9y ago

Eagerly Evaluated Questions, with Joseph Jevnik

apgwoz
6pts0
github.com 12y ago

Show HN: Wipes – pipe stdin to your browser over websockets

apgwoz
31pts11
sigusr2.net 12y ago

When

apgwoz
4pts0
github.com 12y ago

Show HN: New unix utility "when"

apgwoz
20pts13
github.com 12y ago

Show HN: I made an OPML of the tech blogs you should read

apgwoz
1pts1
code.technically.us 12y ago

Recentralizing the Internet

apgwoz
2pts0
sigusr2.net 12y ago

Technical Interviews Make Me Smile

apgwoz
2pts0
sigusr2.net 13y ago

Applying the Web of Trust Model to Blog Reading

apgwoz
3pts0
www.matasano.com 13y ago

Javascript Cryptography Considered Harmful

apgwoz
3pts1
www.wired.com 13y ago

New Service Makes Tor Anonymized Content Available to All

apgwoz
1pts0
www.eff.org 13y ago

Why We Have an Open Wireless Movement

apgwoz
3pts0
code.technically.us 13y ago

Why I won't depend on your pre-release software

apgwoz
1pts0
sigusr2.net 13y ago

Fabric not Uniforms

apgwoz
3pts0
home.pipeline.com 13y ago

HAKMEM

apgwoz
2pts0
www.spacerogue.net 13y ago

Book Review: This Machine Kills Secrets

apgwoz
1pts0
www.computerworld.com 13y ago

Update: Google to pay $22.5M fine over privacy practices

apgwoz
1pts0
functional-orbitz.blogspot.com 14y ago

Phantom Type examples in OCaml

apgwoz
1pts0
blog.vmathew.in 14y ago

Motto Programming Language tutorial

apgwoz
2pts1
sigusr2.net 14y ago

Small, Life Problems? Just a Matter of Programming

apgwoz
1pts0
www.bobhancock.org 14y ago

Healthy Skepticism for the Impossible: Pycon 2012

apgwoz
2pts0
making.meetup.com 14y ago

Ending CSS bloat: Style guides, CSS frameworks, and Meetup

apgwoz
8pts0
patrickcollison.com 14y ago

Lisp Machines

apgwoz
141pts80
www.wingolog.org 14y ago

An in-depth look at the performance of guile's web server

apgwoz
52pts1
www.nomachetejuggling.com 14y ago

The Star Wars Saga: Suggested Viewing Order

apgwoz
5pts0
www.natsturner.com 14y ago

Ideation

apgwoz
3pts0
www.itworld.com 14y ago

GPL, copyleft use declining faster than ever

apgwoz
9pts0
smuglispweeny.blogspot.com 14y ago

AA, BB, CC, and DD

apgwoz
2pts0
www.youtube.com 14y ago

Bipedal Cycling Robot Can Balance, Steer and Correct Itself

apgwoz
1pts0
grantkot.com 14y ago

Grantophone: An instrument for your phone.

apgwoz
45pts18
OS9Map 27 days ago

16MB requirement! I wish all stuff was lightweight, like this! We’ve lost our way…

How many layoffs does a company have to do before realizing it’s in their best interest to start asking other companies to take the employees they don’t want to employ anymore?

Also, 75% placement seems wildly successful. Why isn’t Cisco also a head hunting firm?!

It’s absolute baseline, but yes, it relies entirely on the platform’s permissions model, the administrator who assigns permissions, and the application authors to not create vectors for env var dumps. :)

But honestly, if you’re in the container, and the application running in the container can get secrets, so can a shell user.

_Maybe_ there’s a model where the platform exposes a Unix domain socket and checks the PID, user, group of the connection, and delivers secrets that way? This has its problems, too, like it being non-standard, only possible in some scenarios and otherwise fallible… but better than nothing? If you reap the container when that process dies, you can’t race for the same PID, at least. I dunno

You’re thinking too much. When you run the app, the system decrypts the secrets and makes them available as env vars (or some other mechanism).

In an admin ui, you list the names of secrets only, and provide a “reveal” or a “replace” on each one. They are never decrypted unless explicitly asked for.

Is this perfect? Absolutely not. The key is controlled by the company, but it can be derived in a manner that doesn’t allow for the dump of everything if it’s leaked.

As another data point, I pay for Pro for a personal account, and use no skills, do nothing fancy, use the default settings, and am out of tokens, with one terminal, after an hour. This is typically working on a < 5,000 line code base, sometimes in C, sometimes in Go. Not doing incredibly complicated things.

I use the models to look for vulnerabilities all the time. I find stuff often. Have I tried to do build a new harness, or develop more sophisticated techniques? No. I suspect there are some spending lots of tokens developing more sophisticated strategies, in the same way software engineers are seeking magical one-shot harnesses.

Why? They claim this small model found a bug given some context. I assume the context wasn’t “hey! There’s a very specific type of bug sitting in this function when certain conditions are met.”

We keep assuming that the models need to get bigger and better, and the reality is we’ve not exhausted the ways in which to use the smaller models. It’s like the Playstation 2 games that came out 10 years later. Well now all the tricks were found, and everything improved.

The benefit here is reducing the time to find vulnerabilities; faster than humans, right? So if you can rig a harness for each function in the system, by first finding where it’s used, its expected input, etc, and doing that for all functions, does it discover vulnerabilities faster than humans?

Doesn’t matter that they isolated one thing. It matters that the context they provided was discoverable by the model.

There’s no doubt that stuff is print making. My point is that there are multiple ways of doing (within each of these): relief, Intaglio, lithography, screen printing, offset.

So if you say, “I’m a print maker,” it describes basically nothing. :)

This is just a general statement, not directed at you. Sorry it felt that way.

I like your stuff! I’ve been coveting a plotter for a while, but I’m pretty sure it won’t get used enough to justify the expense. :/

I do find the term “printmaking” hilarious because there’s just sooo many ways to make prints. I tried to get into linocut fairly recently, but the battleship grey linoleum I had wasn’t very good. It cracked and crumbled pretty easily. I did get some of pink Speedball “blocks,” but it gets expensive pretty quickly. I guess more to the point is the feeling that I lack much to say. But, that’s an excuse. :)

The point this article makes, that suddenly agents can do the work of customizing free software, completely makes sense. But, the reality is that the Free Software movement is opposed to the way Lemons are built today, and would not accept a world like this. (Rightfully!)

My belief is that Lemons effectively kill open source in the long run, and generally speaking, people forget that Free Software is even a thing. The reasoning for that is simple: it’s too easy to produce a “clean” derivative with just the parts you need. Lemons do much better with a fully Lemoned codebase than they do with a hybrid. Incentives to “rewrite” also free people from “licensing burdens” while the law is fuzzy.

The key to this argument is that we won’t need to rely on Anthropic/OpenAI soon — will they exist in the same way they do today in 12-18 months? The “open” models are getting better and better, and people are figuring out ways to make inference run on lesser hardware. It already might be viable for people that don’t expect “instantaneous” and are doing more hybrid development.

But you’re also never going to convince the people who still only run vi on the Linux console, without Xorg…

I honestly don’t remember what the frame rate was, but it definitely improved when I upgraded to a Pentium 100. I distinctly remember a buddy giving me some RAM (2x4MB) which allowed me to play on the 486. I was so happy!

The DX2s _were_ a significant improvement over the 486DX, but I’ll admit, I might be remembering the excitement of getting to play Quake at all! The framerate may have been 15-20 fps and I just dealt with it,

The minimum requirements, on the box, were apparently Pentium 75Mhz. 8MB (DOS), or 16 RAM (WIN95).

Anthropic claiming that its total revenue since January 2025 as $5 billion contradict that its expected run-rate revenue for the year 2026 is $19 billion?

Isn’t the “exceeding $5BN” comment a lifetime revenue? … on $30BN (edit: previously said spent) raised (or something ridiculous.)

A lot of the commentary on the frontier model companies is based on how much money they’ve spent to the relatively small amount they’ve made in return, and the skepticism, especially given almost continuous reporting, that deploying AI in a variety of situations doesn’t seem to yield favorable business outcomes. OpenAI shifting to enterprise / coding type stuff this week seems, also, potentially informative. Is Gen AI actually useful for anything but code? Signs keep pointing to no… and even then, we’re in the early stages of figuring out how to build without destroying everything… something Amazon just recognized as possible with their recent shopping outage.