I've used Merlin for a while and I'm still impressed by Merlin's sound identification, it continues to inspire me.
I wrote about it last year: https://digitalseams.com/blog/what-birdsong-and-backends-can...
HN user
Writing about connections at digitalseams.com and personally at bobbiechen.com
<first two letters + last four>@twilio.com
I've used Merlin for a while and I'm still impressed by Merlin's sound identification, it continues to inspire me.
I wrote about it last year: https://digitalseams.com/blog/what-birdsong-and-backends-can...
AWS saw Anthropic billing a guy for $16 million on zero usage and thought, why stop at the millions?
https://www.techtimes.com/articles/320266/20260712/anthropic...
TK is a very standard term, see William Safire's usage in this 1996 NY Times article: https://www.nytimes.com/1996/10/06/magazine/of-hacks-and-tk....
Oh yeah, just like all cryptography is just a way for bad people to hide their criminal activity.
I'd read the confidential computing post! (used to work in this space myself)
He's right up there with Neal Agarwal (neal.fun) and Nolen Royalty (eieio.games) for me. I recently got to interview Nolen on keeping the internet fun and creative for my blog: https://digitalseams.com/blog/nolen-royalty-on-making-things
The wash sale rule (in the US) makes it a lot harder to pull this off.
That makes a lot of sense! I recently interviewed several great creators on this exact topic and they all echoed similar ideas - although it's easy to fear that someone else has done it better, oftentimes they really haven't, and they'll never have your own unique perspective.
One challenge is that it takes repetitions to get good enough that you can even bring your ideas to life, and many people don't push through this (Ira Glass "taste gap").
Full interviews here: https://digitalseams.com/blog/making-things-interview-series
Magnet app (for window splitting) is usually one of my first installs. I think I paid like $7 for it years ago and it's well worth it.
A good reminder that signup is a surprisingly rich target.
Every row has the same name: " Dene Hemen! 5K Lira Bonusunu Yakala" — Turkish for "Try it now! Grab the 5,000 Lira bonus." Casino spam.
Each registration fired a verification email. 55K signups = 55K attempted sends to fake addresses — the kind of bounce storm that gets a sending domain blacklisted.
I'd be surprised if the email addresses were entirely fake - it doesn't make sense to advertise to just the website developer. It seems more likely that this spammer is targeting real email addresses from some dump (QQ is especially prone to this, since you can target random QQ ID numbers and get a lot higher of a hit rate).
Nice share. Increasingly I am thinking about ways to improve verification ("interestingness tests"), ever since reading https://www.jasonwei.net/blog/asymmetry-of-verification-and-...
Hey Omar, do you have any plan to add support for Web Bot Auth? https://datatracker.ietf.org/wg/webbotauth/about/
While I understand that not every business wants automation on their site, I know some businesses are totally open to it. But from a technical perspective, it's very difficult to allow well-behaved browser automation while still blocking abusive bots. Web Bot Auth gives website owners / security vendors a lightweight way to allow providers like Intuned.
(I work on the Web Bot Auth implementation for Stytch, now a part of Twilio: https://stytch.com/blog/stytch-supports-web-bot-auth/ )
I help run a tech/AI meetup in San Francisco - during the initial post-Covid period we often hit capacity limits since there wasn't much else going on.
But since late 2024 into 2025, meetups are extremely back in fashion here. Every day of the calendar has multiple meetups and it's impossible to avoid conflicts, so attendance rate can vary wildly.
It's just like a parallel of tech venture capital, where missing the next big thing is far more costly than making a wrong bet. No wonder we see herding in tech investments as well.
YC also funded Sendblue which does something similar: https://www.ycombinator.com/companies/sendblue
It looks like a straightforward ToS violation to me as well. I guess it's another "ask forgiveness, not permission" move.
Sending emails that bounce is a really good way to increase the chance that your subsequent emails end up in spam.
I remember in 2021 or so there was a startup doing 20 minute grocery delivery in SF, $50 off on your first order.
I got some really nice steaks for free and the delivery actually arrived via motorbike in 10 minutes. They must have had delivery drivers waiting with their own inventory or something. Anyways, the VC funding dried up and the company was gone a few months later.
I too hate this word. It is usually used where hectomillionaire should be.
Yeah, I had the same question myself. I think that's what you would want to do to make it airtight (plus some amount of rate limiting or flagging for devices that are part of dedicated device farms).
But even if not, there's still value in raising the barrier to entry. For example, you can buy 1000 reCaptcha solves for $1-2 from various captcha-solver services. And yet that $0.001-per-request fee does discourage mass-scale bot attacks.
This is generally true of every application that handles sensitive data. Unless you explicitly clear that memory, it's likely to hang around forever.
For example, here is a 2019 writeup from KeePassXC with similar notes: https://keepassxc.org/blog/2019-02-21-memory-security/ - even though they explicitly clear sensitive data, there is still a window of opportunity.
During my time working on confidential computing, we had a variety of demos showing similar attacks against lots of different datastores, scripts, etc. That's just how computers work and your options are very limited if this is part of your threat model (imo just confidential computing and, if you can handle the performance hit, fully-homomorphic encryption).
Surely the prevalence of this saying contributes to the jailbreak's effectiveness.
I called this last year: https://digitalseams.com/blog/the-ai-lifestyle-subsidy-is-go... .
I see it as no different from the previous generation of consumer startups burning money - as Derek Thompson wrote,
...if you woke up on a Casper mattress, worked out with a Peloton, Ubered to a WeWork, ordered on DoorDash for lunch, took a Lyft home, and ordered dinner through Postmates only to realize your partner had already started on a Blue Apron meal, your household had, in one day, interacted with eight unprofitable companies that collectively lost about $15 billion in one year.
It's an interesting concept but unfortunately I think the comment is actually AI slop so there's no real story behind it. Check the account history.
If I understand correctly, threat model here seems to be to protect against accidental issues that would impact performance, but doesn't cover malicious actor.
For example, Sketchy Provider tells you they are running the latest and greatest, but actually is knowingly running some cheaper (and worse) model and pocketing the difference. These tests wouldn't help since Sketchy Provider could detect when they're being tested and do the right thing (like the Volkswagen emissions scandal). Right?
I love how many interviews Larry Tesler did (he passed away in 2020), he was so influential and it's interesting to see what that looks like from the inside.
Gypsy (that first modeless editor) recently turned 50 years old and I wrote about it here largely from those first-hand accounts: https://digitalseams.com/blog/the-gypsy-document-editor-cele...
And it's not mentioned in this ACM interview but rather this one with the Computer History Museum https://archive.computerhistory.org/resources/access/text/20... that implementing a modeless editor was easier too, since you could use a simple case-switch instead of having a bunch of explicit modules for each mode.
I was agreeing with you! Though I can see how I came on a little strong there.
It's interesting how many people I know who jump instantly from hobby to thinking about hustling, Etsy, Patreon, fame, etc. and the thought that they'll never be good enough to go pro is a real barrier. You don't need to monetize your joy.
Enterprise userscripts? Very neat, though I wonder if typical enterprise security policies would allow for this.
What LLM tool are you using to write this comment? It must have been really good to lift the stress of _10 years_ of never commenting?
This article is a great example of "strong + weak = weak".
I only made it to the interesting stuff because of Carreyou's name, otherwise I would have stopped.
The email timing and lack of email metadata were also strong, in my opinion. But all of this nonsense like "Wow, these guys both talk about PGP??" distracts from it.
I'm a big fan of Merlin and learning more about its development changed my perspective on software development! I wrote about that here: https://digitalseams.com/blog/what-birdsong-and-backends-can...