HN user

guiambros

10,729 karma

Hacker, developer, entrepreneur.

@guiambros on twitter.

nospamHN at wrgms.com.

Comments are my own, and do not represent my employer or anyone else.

--

[ my public key: https://keybase.io/guiambros; my proof: https://keybase.io/guiambros/sigs/XWO9Wth2q7MSNMQLcZ83jqGh-kXYcfINRphBE6NxZ6s ]

Posts819
Comments1,126
View on HN
www.youtube.com 1mo ago

Under the Hood of "Sum Ergo Demonstro" Demo [video]

guiambros
3pts0
twitter.com 2mo ago

Analysis of X algorithm

guiambros
1pts0
twitter.com 2mo ago

The latest X algorithm has been published to GitHub

guiambros
52pts23
lkml.org 2mo ago

"Security problems are just bugs" (2017)

guiambros
3pts1
www.youtube.com 3mo ago

Database Turing Award Winner Mike Stonebraker [video]

guiambros
3pts0
www.youtube.com 3mo ago

Air Powered Segment Display [video]

guiambros
14pts0
www.youtube.com 3mo ago

AI's Next Frontier: Insights from Jeff Dean and Bill Dally In

guiambros
1pts0
www.youtube.com 3mo ago

ChatGPT vs. Electrical Engineering Graduate-Level Course Final Exam

guiambros
3pts0
www.youtube.com 3mo ago

Paul Graham, Founder Y Combinator [video]

guiambros
3pts0
feld.com 3mo ago

Nothing new to see here

guiambros
11pts13
www.youtube.com 3mo ago

The result of Joe Grand's $75M bulk hack [video]

guiambros
2pts0
twitter.com 4mo ago

Andrej Karpathy's lab has received the first DGX Station GB300

guiambros
1pts2
news.ycombinator.com 4mo ago

Ask HN: What is thick black row above top of header?

guiambros
4pts6
fabiensanglard.net 5mo ago

How Michael Abrash doubled Quake framerate

guiambros
2pts0
www.youtube.com 5mo ago

Biggest Computer Science Breakthroughs in 2025 [video]

guiambros
2pts0
www.cnbc.com 5mo ago

South Korean crypto firm accidentally sends $44B in Bitcoin to users

guiambros
3pts0
www.theverge.com 5mo ago

The Tragedy of Supernatural

guiambros
4pts1
www.uploadvr.com 6mo ago

Supernatural VR will no longer get new content or features

guiambros
1pts1
www.coindesk.com 6mo ago

Stablecoin giant Tether freezes $182M in USDT across five Tron wallets

guiambros
3pts0
www.youtube.com 6mo ago

I Built a 1 Petabyte Server from Scratch [video]

guiambros
2pts0
lists.gnu.org 6mo ago

GNU Ddrescue 1.30 Released

guiambros
5pts0
www.redblobgames.com 6mo ago

What I Did in 2025

guiambros
4pts0
www.redblobgames.com 6mo ago

RotMG Map Seeds

guiambros
1pts0
www.youtube.com 6mo ago

Collaboration That Built Modern AI: Conversation with Geoff Hinton and Jeff Dean

guiambros
1pts0
venturebeat.com 7mo ago

Quilter's AI designed a Linux computer that booted on the first try

guiambros
4pts1
cloud.google.com 7mo ago

CVE-2025-55182: RCE on React Server and Next.js

guiambros
1pts0
www.youtube.com 7mo ago

Jeff Dean on AI Trends at Stanford AI Club [video]

guiambros
2pts0
techcrunch.com 8mo ago

AI Fei-Fei Li's World Labs speeds up the world model race with Marble

guiambros
2pts1
www.pcmag.com 8mo ago

'The Truth Is Paywalled.' Internet Vets Lament the State of the 'Open' Web

guiambros
4pts1
twitter.com 8mo ago

FFmpeg Drama

guiambros
5pts0

Both things can be true. SO was universally hated because they let (or actively incentivized) bullying run rampant and destroy the culture.

And yes, it's possible AI would have killed it anyway, despite its best efforts. But in this version of parallel universes, AI was only a catalyst. Its fate was sealed well before 2020.

No, of course not coincidence. It's just that people didn't have an alternative until 2021-ish. Users hated SO for many years prior, but had nowhere to go other than small niche communities. When LLMs came into play, it was just the obvious choice.

In an alternate universe, where LLMs didn't exist, I bet you SO would be equally dead by this decade. Someone better, with healthier values and a more welcoming community, would come up and steal their lunch.

You missed the point (and I should have clarified better). It's not that 1 Gbps is bad; it's pretty good, actually. And I do think Verizon is one of the least bad options.

The problem is that there's zero competition. And while many other countries have 2, 5, 8Gbps available, there's zero reason for Verizon to offer it, despite being a densely populated area.

And 1 Gbps has been the max available for 10 years. It's very likely in 2036 we'll be in the exact same situation.

I wish we had a model like Switzerland, where the fiber is centrally managed, and providers compete just to connect you to the network.

I live in NYC, one of the most densely populated cities in the world, and yet Verizon Fios 1 Gbps is my only option. I tried to upgrade to Fios 2 Gbps, but it's not available. Spectrum only goes to 200Mbps; no other providers in my area.

I have no idea if Switzerland is any better, but the US situation in 2026 is appalling. If we're this bad in NYC, imagine what someone in rural America goes through.

It doesn't seem the case; the study was made purely on behavioral conditioning. And mosquitoes don't live very long, so it's unlikely they'd learn this in practice, outside of a very controlled environment.

But there's a natural selective pressure, and it's plausible that mosquitoes would eventually evolve their sensors to become attracted to DEET, over multiple generations. And with each generation lasting only 20-30 days and a single female mosquito laying 300-500 eggs in total, they can evolve orders of magnitude faster than us.

It's really unfortunate that FPGA development is still stuck in the 90s. The incentives between IP owners and hobbyists are so misaligned that I don't see the possibility of this ever improving.

The market is full of dark patterns, and vendors like AMD/Xilinx can pull shitty moves like what OP highlighted, knowing there is no decent alternative (Altera is another disaster). Lattice had the opportunity to fully embrace opensource toolchain and try to disrupt from the bottom, but they seem stuck in the middle, not wanting to commit one way or another.

I'm grateful to SymbiFlow, and IceStorm and others, even though they obviously lack support for proprietary hardware features.

This is awesome news. Thank you for the great work, and being so open to suggestions from the community. That's what makes Obsidian a world apart from all its competitors and predecessors.

This is fantastic news. Just a few days ago I mentioned [1] the Obsidian Community Plugins model was broken and needed an overhaul. This is a step in the right direction.

If I may, two suggestions:

1) Allow the user to filter for plugins based on the desired level of strictness (manually reviewed, safety rating, etc).

2) The Disclosures seems a bit too lenient. For example, the popular Templater plugin [2] gets a 92 rating, with Excellent Health and Satisfactory review. But the disclosures are pretty concerning: dynamic code execution, network calls, wasm blobs, malware scan not available, etc.

I know it's tricky to boil this down to a single numerical score that works for everyone, but I think the bar needs to be higher than this. And Plugin developers should be held to a higher standard (e.g. don't use eval()) or at least thoroughly document why you need it.

[1] https://news.ycombinator.com/item?id=48089793

[2] https://community.obsidian.md/plugins/templater-obsidian

Also:

- Think Python

- Think Data Structures

- Think Java

- Think Perl6 (!)

- Modeling and Simulation in Python

- Probably Overthinking It

And more [1]. He's a prolific writer, and very generous for offering many of them for free. I read several of them online or through O'Reilly, and bought printed copies just to appreciate his work. Really enjoyed Think DSP, Think Complexity, Think Bayes, etc.

[1] https://www.amazon.com/stores/Allen-Downey/author/B001O8NBPS

Yes, in this specific case.

Obsidian Plugins are still incredibly vulnerable. A compromised plugin will essentially take over your machine. There's no sandboxing of any kind. It's even more insecure than browser extensions (that could steal your auth tokens, but at least don't have unfettered access to your filesystem).

This is really unfortunate. I love Obsidian and am a paid subscriber for many years, but the community plugins needs a security overhaul asap, before someone gets hurt.

Not sure why you were downvoted. From the last paragraph:

"I spent a total of 35 days here. The first arrest was 3 days of processing, the initial 10 days followed by the 10 days extension for a total of 23 days before my case was dropped. But the same time my case was dropped my accusers found a another reason to issue a second arrest keeping me there for an additional 12 days!

Both cases were ultimately dropped and the second arrest was essentially tied to the first and shouldn’t have even been possible."

The answer is in your question:

"...through a vulnerable WordPress plugin, a web shell, weak SSH credentials, or a compromised container"

DirtyFrag alone doesn't help an attacker; they need to get in first. But the blast radius is much wider now. A wordpress flaw, or a prompt injection in your OpenClaw skills, or a supply chain compromise in npm librarires means they now have full root access to your system.

Also hilarious to see Drew Houston responding a bit later on the same thread:

we're in a similar space -- http://www.getdropbox.com (and part of the yc summer 07 program) basically, sync and backup done right (but for windows and os x). i had the same frustrations as you with existing solutions.

let me know if it's something you're interested in, or if you want to chat about it sometime.

drew (at getdropbox.com)

Posting this to remind folks of Linus' and the kernel team's longstanding stance on security vulnerabilities, given the recent CopyFail discussion [1].

The researchers followed the standard disclosure process of 90+30, but distros were not notified. The kernel had a bug, but kernel developers did not (and will not) notify downstream distros.

The real discussion we should be having is: what should be the responsible disclosure process, and who should be accountable for contacting the downstream projects?

And should the Linux kernel be treated differently than other opensource projects? And if yes, where do we draw the line? If, for example, I find a bug in OpenSSL, is it reasonable to expect that I contact every single operating system, device maker, or library developer that packages openssl in their gizmos?

[1] https://news.ycombinator.com/item?id=47965108

I still use it daily, mostly for managing information consumption. It reads my twitter feed and scans HN twice per day, and sends me a digest of the discussions on Discord.

The best part is that it reads the comments too, and sends me a quick blurb. For example, this is what it sent me earlier, commenting on [1]:

  TL;DR: A classic essay arguing that compiler construction isn't as hard as thick textbooks suggest, pointing to Jack Crenshaw's accessible "Let's Build a Compiler" series as the real starting point.

  The Vibe: HN agrees most CS textbooks are overcomplicated — developers sharing their own minimal compiler projects and alternative learning resources.
I also have a few custom skills to read transcripts from YT videos and summarize the content, and store summaries in a personal wiki-style folder.

It runs in an isolated vm and doesn't have access to anything other than my X account, so I'm not too worried about prompt injection. I also don't have any skills installed other the ones I developed or carefully vetted.

[1] https://news.ycombinator.com/item?id=47776796

I like the combined suggestions of three other commenters:

1) Allow transfers during a very short window (e.g. 24h before the event)

2) Allow full refunds up to x days before the event

3) Release a small batch of tickets 24h before the event, as a way of reducing the chance for scalpers to make money, and giving real fans a last chance without paying exorbitant prices

All three together offer a reasonable tradeoff. The tickets will go (mostly) to real fans, yet still giving you flexibility in case your plans change (work, sick, etc). And if you know well in advance, you can get a full refund, without having to worry with reselling, paying commission, etc.

Also prohibit secondary markets entirely. Similar to airlines, there's no reselling of tickets.

Of course, this is just wishful thinking. Too many intermediaries benefit from screwing showgoers, so this will never be implemented.

Yes, cat and mouse, except that each user who gets caught will have their account and credit card banned for life. Good luck dealing with the hassle of losing your account history.

Look, I would love to pay a fixed amount per month ($20, $200, whatever) and have an all-you-can-eat token buffet. But that is (today) a commercial impossibility.

Maybe one day inference will become so cheap that we'll all have a single subscription, and assisted by powerful local models. But today the token consumption is outpacing the reduction in inference cost, so we're nowhere near this becoming a reality.

I understand you want really hard to believe in what you're saying. But you should believe them when they say "no third party applications using OAuth".

It's irrelevant if you're paying them. They say clearly 1P apps are ok; 3P apps are not. Yours is 3P, so you're breaking the ToS.

Will they care? Probably not. At least not until you become popular enough to show up in their dashboards. So you should be fine for a whole, until you cross some threshold and they decide it's time to close the loophole.