HN user

gbear605

3,554 karma
Posts64
Comments1,103
View on HN
www.effectivealtruism.org 7mo ago

500M, but Not a Single One More

gbear605
2pts0
neal.fun 11mo ago

Space Elevator

gbear605
1pts0
ntietz.com 1y ago

Covers as a way of learning music and code

gbear605
3pts0
mail.openjdk.org 1y ago

Towards a JSON API for the JDK

gbear605
1pts0
andreabergia.com 1y ago

Writing C++ in 2025

gbear605
25pts7
sheep.horse 1y ago

Yo Google, Thanks for the AI Overview but Your Search Sucks Now

gbear605
13pts1
www.wsj.com 1y ago

Disney to Cut Nearly 6% of Staff Across ABC News, Disney Entertainment Networks

gbear605
2pts1
jdk.java.net 1y ago

Java 23 General-Availability Release

gbear605
9pts1
philosophybear.substack.com 2y ago

The rich and dynamic tapestry of AI plagiarism or: You're not an AI detector

gbear605
1pts0
gomakethings.com 2y ago

Front end devs don't understand accessibility

gbear605
1pts0
stuartmarks.wordpress.com 2y ago

My Favorite JDK 21 Feature: Javadoc Search URL

gbear605
2pts0
www.jefftk.com 3y ago

Preparing for Less Privacy

gbear605
3pts0
www.aiweirdness.com 3y ago

Apparently I am a robot

gbear605
72pts48
www.lesswrong.com 4y ago

To Make Better Software, Do What Artists Do

gbear605
7pts1
www.lesswrong.com 4y ago

Reflections on Connect Developers

gbear605
1pts0
www.gwern.net 5y ago

Do scholars follow Betteridge's Law? Questions in journal article titles (2016) [pdf]

gbear605
2pts0
www.cnn.com 5y ago

New report finds clear and convincing evidence that China is committing genocide

gbear605
2pts0
drewdevault.com 5y ago

Web analytics should at least meet the standards of informed consent

gbear605
63pts24
www.lesswrong.com 5y ago

Pain is not the unit of effort

gbear605
2pts1
drewdevault.com 5y ago

I want to contribute to your project, how do I start?

gbear605
17pts1
notebook.drmaciver.com 6y ago

Being Friends with Your Coworkers

gbear605
3pts0
www.lesswrong.com 6y ago

How long can people usefully work?

gbear605
3pts0
www.cnbc.com 6y ago

Selling to restaurants made Toast a $5b startup – a month later, Covid-19 struck

gbear605
2pts0
drewdevault.com 6y ago

The Abiopause

gbear605
6pts0
venam.nixers.net 6y ago

Professional Software Engineering Topics and Practices

gbear605
2pts0
www.lesswrong.com 6y ago

The YouTube Revolution in Knowledge Transfer

gbear605
12pts1
slatestarcodex.com 6y ago

Too Much Dark Money in Almonds

gbear605
238pts157
www.bbc.com 6y ago

Young Swedes are burning out: Burnout is rising in the land of work-life balance

gbear605
3pts0
slatestarcodex.com 6y ago

Against Against Billionaire Philanthropy

gbear605
6pts0
slatestarcodex.com 7y ago

5-HTTLPR: A Pointed Review

gbear605
119pts7

That's true, but then the people you're selling to have to want to buy the shares. And if you're buying YES at 97%, you're not going to be able to sell the YES shares to anyone at much higher - because eventually someone has to hold it to the end.

It's true that this isn't as true for NO, because a small change can give a huge return, but that's asymmetrical. So there's incentive for traders to buy NO, hoping that it moves down, but not an incentive for traders to buy YES, since it doesn't have any room to go up.

It's worth noting that Polymarket (and all other prediction markets using money) has some fundamental problems that cause inaccuracy. Most notably here, the elections are still several months out, so you're asking people to put up 97 cents to get a dollar back in three months. But for that time frame I could also put 97 cents in treasuries and get 98 cents back, so the market won't be accurate within 1% of reality, and treasuries are considered a good deal safer than Polymarket.

In addition, there can be issues related to fees, Kelly betting (if the correct bet is 98%, don't want to bet all the way to 98% or you have no returns and you definitely don't want to put all of your wallet in on it in case it goes against you), and so on.

So this isn't a "3% chance of the elections happening" it's "3%, plus or minus the rate of return over three months, plus or minus all the other related issues". I don't know if that gets you down to zero percent, but it definitely gets you closer.

(Yes Polymarket has tried to do some things to resolve these issue, no they don't work very well.)

The difference between weight and volume measurements could easily be a 20% or 30% gap. I’ve measured two of my cups of flour before and they were off by roughly that amount.

Maybe I’m just bad at measuring, but it’s a lot more than 5%.

Soccer is extremely widespread and played by both boys and girls at a young age (up until puberty or so), but there definitely is a gender gap after that. I'd guess that there are a lot of other sports that are almost solely played by boys, so boys tend to drift away from soccer, while there are fewer options for girls. (Though there are some - lacrosse and softball for a couple examples.)

It certainly can matter for proper baking (which this recipe seems to be?), though for traditional pancakes I would never bother. But there's a reason that bakeries weigh their ingredients. It's more consistent and allows for different people to get more similar results.

As discussed elsewhere in this forum, these exploits are being found by security companies in the first few days after they're published, that's just already too late. For example, the auditor who made the very post that we're discussing! For another, many security-focused AI companies have automated checks on NPM packages. Many people are implementing it on their end by having their client wait seven days before pulling new packages, but that's O(N) rather than O(1), and it's not evenly spread.

If no one reviews it and it still gets out, then we can address it then, but that seems much less likely.

Ideally, the solution is that all of these language package managers need to get serious and have maintainers, but lacking that, at least having the waiting period be built into the server instead of the client is a clear win.

One easy change would be that before any package can be published, it has to wait a minimum of two weeks in a state where it can be reviewed but it can't be installed without jumping through several hoops with big warning signs, things like "INSTALL_INTENTIONALLY_DANGEROUS_PACKAGES_THAT_WILL_BREAK_MY_COMPUTER=1", selecting yes in a dialogue that asks if they want to install software that likely has viruses, and pointing to a different package repository URL.

If there's some change that must get out sooner, then there can be some fee to pay to npm to have their security team do their own review.

Critically, there must be time for someone to review before it's the default to be selected.

I'm sure there are issues with this, this was off my head, but it seems like a really easy step to at least stem the problem for now. And there are a bunch of ideas like this that would help, but NPM doesn't seem willing to take it seriously as an existential threat to the ecosystem, rather than taking trivial steps.

Pyramid schemes are defined by the price and structure. A business that sells knives is a fine business. A business that sells overpriced knives by promising that you can then find someone else to sell more knives for you at an even higher price is a pyramid scheme.

Selling tulips is a fine business. Selling tulips at an insanely high price by promising that the market for tulips will keep on expanding and increasing the price of tulips is a pyramid scheme. (Well, maybe not quite a pyramid scheme, the structure isn't right. But it certainly wasn't a sustainable business model.)

At least for my software job in the US, and other salaried jobs I’ve seen, there are explicitly no hours listed, and it’s supposedly based only on your output. In practice though, if your butt isn’t in the seat 40 hours a week or so, and usually more, the boss will be mad.

Two thirds of Europeans want this - https://www.techpolicy.press/almost-two-thirds-of-europeans-...

The figures were almost universal across all categories: 62 percent of those surveyed across the five European countries said they favored or had considered replacing US data storage and payment services, while 59 percent of respondents said they would back a change from American video-conferencing companies like Zoom.

(Technically only five countries in the EU in this survey, but the five most populous countries, and presumably other countries generally agree)

If you want to do it occasionally, sure, whatever. I have a coworker who solely communicates in the form of screenshots of him asking Cursor my question, even when they’re questions that are interested in his motivation or plans, not the code base, and that Cursor does a bad job answering. I’ll ask a Slack channel “does anyone have experience with tools A and B, so they can suggest which matches our use case better”, and he’ll respond with a screenshot.

I don’t need him to pass on LLM answers. I can and do ask them myself. I’m asking questions because I’m interested in the experience my coworkers have beyond what AIs have trained on.

This is Java, but recently I had a case where one library depended on a version of an Apache Commons library, and another library depended on a different version of the same Apache Commons library, and neither version worked with both libraries. In my case, I was able to upgrade one of them to a newer version so that I could use just one Apache Commons version, but I got lucky there.

Speaking as someone who is a bit more familiar with your site, the variety of content you post is really valuable. I know multiple people, myself included, who have either gone from EA to Contra or Contra to EA thanks to both being on your blog.

More broadly, I love it when an author I trust in one area writes about other topics.

Everywhere on Amazon.com has bad UI/UX. For one example, the flow on checking out as a non-Prime member (not sure about Prime members) is janky and feels straight out of 2005. Like it reloads the page, taking ten+ seconds, every time you enter new data (address, credit card, personal info, etc.). I would be laughed out of the room if I tried to deliver this at work, but Amazon delivers it for millions of people.

So no, they care zero about their customers, except maybe for getting as much money as possible out of it.

If your volume is low enough, it should be pretty fine. It can just piggy back onto your personal browser cookies for Cloudflare.