HN user

cube00

6,075 karma
Posts51
Comments1,256
View on HN
blog.documentfoundation.org 2d ago

How proprietary formats have become Microsoft’s main tool for lock-in

cube00
160pts123
ia.acs.org.au 8d ago

Telstra outage blamed on known bug in obsolete server

cube00
11pts1
unit42.paloaltonetworks.com 1y ago

Attack on Coinbase Expanded to the Widespread tj-actions/changed-files Incident

cube00
3pts2
www.youtube.com 2y ago

Should You Feel Guilty for Being a Maker? [video]

cube00
2pts0
batect.dev 2y ago

Batect is no longer maintained

cube00
1pts0
www.abc.net.au 2y ago

Australian government to overhaul privacy laws

cube00
5pts1
www.ralfj.de 3y ago

Cargo careful: run your Rust code with extra careful debug checking

cube00
4pts0
www.psypost.org 3y ago

Experts urge social media giants for transparency to protect mental health

cube00
2pts0
www.abc.net.au 3y ago

Google fined $60M for misleading Australian mobile users about location data

cube00
3pts0
www.space.com 3y ago

Possible SpaceX debris falls in Australia from Crew-1 Dragon spacecraft

cube00
5pts4
meta.stackexchange.com 4y ago

Duplicated votes are being cleaned up

cube00
1pts0
www.abc.net.au 4y ago

Google ordered to pay John Barilaro $715,000 over 'vulgar' YouTube videos

cube00
20pts21
www.abc.net.au 4y ago

Employee monitoring software became the new normal during Covid-19

cube00
2pts1
www.bloomberg.com 4y ago

Fidelity Investments Unveils a Crypto Option for 401(k) Plans

cube00
1pts1
www.linkedin.com 4y ago

When you get locked out of your Google account, what do you do? (2021)

cube00
194pts126
support.google.com 4y ago

Google Drive: Shortcuts replacing files and folders stored in multiple locations

cube00
138pts71
www.abc.net.au 4y ago

Pfizer offers $100m to buy company behind smartphone app that diagnoses Covid-19

cube00
9pts0
www.abc.net.au 4y ago

Facebook, Instagram parent company Meta sued over 'scam ads'

cube00
19pts0
transparencyreport.google.com 4y ago

Google's Certificate Search page is being discontinued on May 15th, 2022

cube00
3pts0
www.abc.net.au 4y ago

Couple sentenced in Australia over 'sophisticated' computer hacking scheme

cube00
2pts0
12ft.io 4y ago

On the Future of 12ft

cube00
2pts1
www.theguardian.com 4y ago

Eric Clapton wins legal case against woman selling bootleg live CD for £8.45

cube00
1pts0
sagrista.info 4y ago

Searx – Privacy-respecting metasearch engine

cube00
299pts147
holub.com 4y ago

Words that do not appear in the Agile Manifesto and Principles

cube00
4pts0
www.securecodewarrior.com 4y ago

Secure Code Warrior Devlympics 2021 running for next 12 hours

cube00
1pts0
www.equicon.de 4y ago

Legacy Train Control System Stabilization (Aspect 2012)

cube00
1pts0
www.npr.org 4y ago

Art or heist? A Danish artist took $84k and sent a museum 2 blank canvases

cube00
134pts191
www.abc.net.au 4y ago

Australian utility preparing to deploy robotic dog to inspect infrastructure

cube00
1pts0
www.imore.com 4y ago

Fail safe vs. fail secure: What everyone gets wrong about backups (2018)

cube00
2pts0
www.computerworld.com 5y ago

Microsoft, eBay Strike Web Services Deal (2001)

cube00
2pts0

A few stories in the news represents a beyond negligible fraction of billions of user accounts.

https://support.google.com/accounts/threads?thread_filter=(c...

How many times do you have to click "View more" to reach a post from last week? It's a problem.

The copy pasta advice from the "diamond product experts" says it all:

Account recovery is completely "self service". Google doesn't provide any form of live support for account recovery. If you can't recover your account using Google's automated recovery process, the account is lost. [1]

[1] https://support.google.com/accounts/thread/453660883/locked-...

You have to consider that the user base of Google accounts is in the billions.

Basing your security decisions on "it'll never happen to me" because there are billions of other users who will get burnt first is not a wise strategy either.

Why take the chance when there are so many other alternatives that let you own your vault or at least companies that still have some semblance of a support team.

Losing a decade of my Google Maps Timeline data even with backups enabled made me realise I may not be lucky enough to win the lottery but I am lucky enough for Google to pick little old me, hidden in the billions, to lose my data.

While this all sounds like a warm and fuzzy nostalgic trip, big music didn't like us doing this when we made mix tapes off the radio.

Spotify certainly doesn't like it and it's second only their prohibition on reverse engineering their own software in their User Guidelines.

  The following is not permitted for any reason whatsoever in relation to the Services and the material or content made available through the Services, or any part thereof:
  2. copying, reproducing, redistributing, "ripping," recording, transferring [1]
It's surprising that a Spotify developer would not only write this up but also self post it to HN. Is there some performance review metric tied to how influential you are for the company or something?

[1] https://www.spotify.com/us/legal/user-guidelines/#:~:text=co...

According to the ads manager UI, unless I'm willing to allow up to $3 a click I'm warned "my bid may be too low to deliver reliably".

Considering I'm paying 20 cents per click elsewhere, this could get real expensive, real fast.

I simply could no longer provide the effort (mental or time-wise) that the role demanded, and thus I was not performing my duties to an acceptable degree, facing severe burnout, and risks to my mental health.

[...]

We've proven that FLOSS works, and is in demand.

If "FLOSS works" maintainers shouldn't be "facing severe burnout", I've come across two more in the past week alone:

* Filebrowser (Mar 2026): https://hacdias.com/2026/03/11/filebrowser/

* axum-login / tower-sessions (last week): https://github.com/maxcountryman/axum-login/discussions/330

Oh well that changes things.

It's the same for any case where someone sends you something and wants it sent back with changes.

If you screw up their files it's never going to go well for you (family, friends, volunteer groups).

Nobody will ever thank you for messing up their work because it's now saved in an open format.

If they end up using a feature that triggers the format nag screen they'll likely end up saving it back into the native Microsoft format anyway.

Smaller annual opex is far easier to get approved then large multiyear capex with deprecation.

AWS was also cheaper in the beginning but has been slowly ratcheting up the pricing making colocation or on-premise viable again for some workloads which have steady compute demands.

send them back an ODT

The formatting goes wonky or the macros stop working and you get the blame for doing something "weird" to the document everyone else managed to pass around just fine.

As much as you're doing the right thing by using open formats, you still end up looking like the incompetent employee. No good deed goes unpunished.

A breath of fresh air to pause new subscriptions rather than the Google approach of quietly nerfing the limits and hoping you don't notice you're getting less value for your monthly/annual subscription.

Limits may change without notice, including due to capacity constraints. When there’s a large increase in activity in Gemini Apps, we may change limits to maintain a high standard of quality. [1]

[1] https://support.google.com/gemini/answer/16275805

Seems to be working just fine though?

As with all transpile ports, the true test will be how well it can be extended and maintained over time. Historically working with the output of a transpile is not pleasant and requires heavy rework to get it to the point where you can be comfortable enough to extend it.

The existing community is now either going to need to learn Rust or new Rust developers are going to have to join the project and they may not invested enough to refactor the transpiled output when they could work on something else like Boa.

There has to be a second PR approver. There's no way a company as large this can allow an individual the ability to push to production without a secondary person involved.

When there's at least two people involved you can then start to look at more systematic factors that go beyond any single human mistake.

When both the submitter and approver miss that there's no changelog entry for a PR does that mean a checklist is needed? Should the changelog be automated with the commit message which can be improved for external consumption?

I'd find it very hard to believe that this high profile change just happened to be the only change missing from the changelog.

Bugs are always going to happen but housekeeping like writing something to a changelog when a commit is merged can be quality assured.

Not every feature will necessarily appear in the changelog

This was such a frustrating part of this incident, along with Anthropic's refusal to explain why the changelog is no longer a complete record, what else is going out? [1]

Boris Cherny's only participation in the thread was to delete "extreme danger" from the GH issue title [2]

I guess we should be thankful they added an option and disabled it by default. OpenAI is standing firm on their decision to not allow their 60s timeout to be disabled, [3] however more of the Codex harness is open source so customers have been able to fork it to add the option themselves.

[1] https://github.com/anthropics/claude-code/issues/73125

[2] https://github.com/anthropics/claude-code/issues/73125#event...

[3] https://github.com/openai/codex/issues/28969

I didn't have time to recreate the entire comic before publish date.

It's depressing that even a blog post about open sourcing a two decade old piece of software has such a hard deadline the author feels pressured to publish before they're ready.

  v1.0-pre and v1.0 share the same internal version number (rup 206, "Beta 2") but differ in ~99 of 111 shared source files [1]
While I shouldn't complain because they just won't do these releases in the future and I accept it was a different time; I still find it surprising Microsoft didn't have better version control considering they took it seriously enough to build their own internal version control system (SLM). [2]

[1] https://github.com/microsoft/comic-chat#:~:text=v1.0%2Dpre%2...

[2] https://devblogs.microsoft.com/oldnewthing/20251028-00/?p=11...

I used to think I had to use a component library, but for some cases it seems all I really needed was CSS to give my webapp that material feeling everyone seems to feel more comfortable with.

I now have a more critical eye and look into potential UI components code to decide if it really does need the custom code or if styling alone can get the job done.

Shoelace upending everything to Web Awesome has given me an incentive to revisit this rather then blindly find/replacing all the sl- prefixes to wa- given how much larger it makes my bundle.

  You can request deletion of your Google user data by emailing the official support channel. [1]
It always worries me when you need to email support just to delete your own data.

I'm logged in with my Google account over a secure connection and yet I can only delete over insecure email.

Not that it really matters when there's no support email address anyway.

  For privacy-related questions, please contact the application operator through the official support channels listed by your team. [1]
[1]: https://html-drive.com/privacy.html

There is a privacy popup setting for:

  Marketing - These cookies are used to deliver relevant advertisements and track their effectiveness.
Where do advertisements fit into the website and product?
  Ello has specific instructions to talk to the child about the learning activities.
Giving large language models "specific instructions" is not a robust way to ensure safety.

There really needs to be more published technical detail on what safety systems you have in this because if trillion dollar companies can't stop AI going off the rails, I feel you're overselling the safety systems you've built.

Reading further it then goes beyond "learning activities" into LLM generated content.

  Some (not all) of Ello’s stories and illustrations have been created with AI technology, and AI allows children to create their own stories and experiences through guided and safe scaffolding.
How are your safety systems checking the illustrations generated?

He's been teasing this blog post everywhere (in commit messages, multiple times on X, here on NH [1]) so I wonder how much of it was building hype compared with it legitimately taking two months to write.

I wonder if the delay of Fable has also been a factor and maybe they didn't want to release this blog post while they couldn't allow customers to use Fable and waste the advertising opportunity.

[1] https://news.ycombinator.com/item?id=48133519

the assumption that the rewrite was happening with an Opus-like model, and not with Fable

I thought the same thing. Looking back, I was probably mislead in May when Jarred was explaining the pattern to "Rewrite every .zig file to .rs" as if it was something I could have done in May following his pattern. What he wasn't telling us was he was using pre-release Fable. [1]

A possible signal for next time is when we see an Anthropic owned company disabling the Claude Co-Authored-By trailer. [2] In an IPO year they have to take every chance to promote Claude unless it was something (Fable) that we weren't supposed to know about back in May.

[1] https://xcancel.com/jarredsumner/status/2060050586024743376#...

[2] https://github.com/oven-sh/bun/commit/23427dbc12fdcff30c23a9...