HN user

hennell

709 karma
Posts0
Comments205
View on HN
No posts found.

What a poor take. Cooldowns certainly don't solve everything but 'out of the box' even with no vetters they'll help catch unauthorised releases on active projects because it's more time to notice.

Account takeovers, deployment exploits whatever the root cause, given a few days it's incredibly likely maintainers will notice they've released an unexpected update and fix/sound an alarm. A lot of existing cases like this people realise pretty fast, but the packages might still be live for a few hours as NPM catches up. Cooldown entirely removes that 'updated at the wrong time' issue, an no-one even needs to actually look at the code at all.

For inactive or intentionally malicious maintainers, yes it relies on vetting. But it's hardly a mythical 'canary' - there are already a lot of companies scanning every popular npm package, auditing new ones, or just generally analysing threats. I can think of at least 4 such companies without even trying, I'm sure there's loads more.

And they'll continue because it's not warm hearted so much as promoting/testing their security scanning services and tools so they can get the kudos from being the first to spot X etc. Which often does hit the front of HN or reddit, but they don't need the massive cyber loudspeaker to be effective. Flagging the issue to maintainers, reporting to NPM security - with a cooldown in place the package can be voided before anyone really gets the chance to install it. This is literally how a lot of things are spotted already, just with that 'updated at the wrong time' issue catching unlucky people out.

Does it solve everything? No. Will it reduce the amount of problems that make it to end users? Obviously yes.

And for all the author's 'no one will do this', 'waiting for Godot' cries - what do they recommend? Running your own audits, using LLMs, static analysis and testing it yourself. Basically being the veter they claim no-one will be! Unless they don't intend to sound the alarm themselves, they are literally the canary they're looking for.

Cooldowns aren't magic, but they're not security theater either.

Why can't they just sell the charger separately? If you lose it you buy a new one.

You could even make it a seperate item - buy one with/without the charger, then in 2 years you decide if you want the charger or an upgrade.

I think idioms and cultural references are fine - the rest of the world has worked out what US baseball and football cliches likely mean, people can decode most references with context.

But there are some interesting issues with UK <> US english, things like 'quite' which works in different ways in each locale. I was also very surprised to discover the difference in what we consider a frown - which makes a lot more sense of the US 'turn that frown upside down'. Interestingly my uncle who'd lived in the US ~20 years had never uncovered that difference till I asked him about it.

So it's good to know differences - especially when you want communication to be clear.

People have always judged ideas on their communication. if u rite lk this bro - I'm probably not going to pay much attention. Conversely if you write in a really formal way for a young audience you probably won't get far either. It's a shortcut of importance; if it's not important to you to communicate your message well, then it's probably not that important a message.

And this article is such Ai slop. You see the sentences? All short. All 'punchy'. All with repetition. All for maximum 'impact'. Constant unrelenting impact.

And the lists! The lists, the rolls, the lineup, the rows, the enumeration, the catalogue of examples that goes on too long for comfort, logic, joy, readability or attention.

I'd love to know how many people actually read all of this. I suspect most started skimming as it's just awkward to read, the pacing is just so Ai-y it's exhausting.

I'm never really sure the author reads things like this - I think they wrote something, asked a Ai to punch it up then skimmed it and said 'lgtm'. If you care so little why should anyone else?

Personally my favourite feature of the new ai world is not when I use it directly but it's when one of my managers uses it to try to fix a problem, then issue to me their findings and I have to defend my process to someone who understands neither my process, their suggested solution nor often the problem they're solving in the first place.

Name the places now demanding "age verification," and see how many will accept a plain government document that says only that you are over eighteen — and nothing else. Almost none will. Because age was never the point.

Name the physical places that would accept a plain government document that says only that you are over eighteen and nothing else? None will, not because 'age was never the point', or because every bar or casino is stealing your face - but because a plain document doesn't offer any proof you are it's owner. Photo ID has been standard as age verification because it's the best way to prove the official ID actually links to the person holding it.

There are more concerns in a digital world with giving your ID / face, but the idea that the demand for photo ID proves it's all a big data grab not remotely about age is a conclusion looking for evidence.

(Plus they acknowledge some sites have done age verification where all they want is your face to confirm you look over 18 - which they then ignore, claiming it's all really a ploy to get your documents. So why isn't the site 'Never give them your documents'?)

I have a pretty decent readme on all projects, and a /docs folder for key areas that need specific instruction on complex ones.

My boss was looking at them, but even the simple ones he was pointing claude at it and asked it to make a document explaining it. Then he'd send me the document and ask me to check if it was accurate. I added a line to the last page "this is an ai summary and may contain mistakes. Use the project readme for validated information" and told him it was grand.

I once tried to report an incident to a train line who had done "~a nice thing for a person~" and had photos about it on their social media. One photo was in their office and in front of a wall with a A4 page of usernames and logins for various systems on it.

I tried three different contacts I could find, only one came back to me and wanted to know what the systems did what the risk was etc. I pointed out I have no idea, and I'm absolutely not logging into mysterious systems to find out - pass it to your own IT so they can see what needs to be changed, rotated etc.

I did eventually get a message back from someone who thanked me for my diligence and said it was solved as they had now removed the photo... I really hope they had someone who understood look at it, but I decided not to engage further...

What we need to do is to stop comparing every hobby performance, whether it's music or dancing, with the top 10 artists in their field.

I feel like one of the less discussed issues of the hyper-connected world is there are no small ponds to be the big fish in anymore. Used to be you could be the best in your school, church, town even city etc - even if you weren't that good. I remember being astounded as a kid by a woman who juggled 5 tennis balls in a local talent show. Now I can hop on youtube and watch people do way more impressive feats it doesn't seem so unique. I suspect that 5 ball routine might still be the greatest juggling I've seen in person, but it still doesn't compare to random acts I've seen online.

But especially with the para-social relationships of social media people feel connected even to big names now. You might not compare the local young singer to Taylor Swift, but people will to the tiktok singer they 'know' who liked their reply once.

It's gratifying and inspiring to be top of your class in something, but in a world where it's always a class of millions, you know you'll never reach the top.

IMO they should be doing way more to control push notifications, there's so much more control they could give the user, and many clear violations of their policies.

One of the best apps I've bought for android is buzz kill which lets you set rules around notifications. I have cool downs on family chats and social media so it doesn't keep buzzing when things kick off, filter Amazon alerts to only "we're two stops away" and "We've delivered" messages and dismiss the rest.

I have custom buzz patterns and sounds for urgent alerts and rules that batch notifications depending what WiFi I'm on, time outs on things that don't matter after a few hours etc.

My notifications list is now way smaller and far more relevant.

Also quickest way to sort out notifications is to take your phone off silent. Hearing everything coming in, you see more when it you can then decide if the notification should make noise, or exist at all on a per app basis.

I always found walking around throwing a stress ball as I think out a new feature far more effective then heading straight to the computer. Much easier to think out the abstraction then getting stuck in the details of my first solution, and only realising a the flaws/a better way hours later.

Convincing people it's an important part of working though, that was the tough one. And now if you spend any time thinking people want you to use Ai for the thinking bit...

Didn't the first 365 copilot lauch have a whole rollback as they belateded realised the rag setup would often ignore file access and permissions, so queries like "List the highest paid members of x team sorted by salary" would just work etc?

The combo of rushing with a technology that isn't very easy to control, understand or securely limit is just mad to me.

I can't currently see how they can release without it causing way more chaos than help. Scanning your own code is a useful security tool, but being able to scan others is basically an exploit finder, which against open source is impossible to police.

Not that you really want to stop open source contributors from getting help from contributor forks anyway, although like the article says you then end up with overloaded maintainer(s) who can't keep up or triage legit issues easily.

It all seems like a hard product to monitize, easy on corporate code maybe, but in open source maintainers have to pay for scans that will give them more to do, or risk exploitors getting some big zero days very cheap. Starts to feel a bit mafia protection racket somehow.

Maybe they'll just decide not to care about the impact as someone else will do it anyway? Maybe they continue their surprisingly slow role or to responsibly bring it up. Maybe there's a clever project to tell if code is a fork even if you obscure it, or they'll make something that will only give you the patches not the problem... I'd love to be a fly on the wall for their risk analysis of the whole situation.

I'm not sure I'd say a company that makes ceramic toilets also making a tool for memory chips... which is also ceramic is really 'different things'. They're clearly a ceramic company. Different tolerances, but similar expertise.

Now the paper company got into the hotel business seems a far better example. No idea how that happens.

? That appears to be arbitrary eras then arbitrary companies from that era. Do you think Amazon and Google disappeared after 2001? Do you think databricks is now bigger than IBM?

Change might be inevitable, but I'm not sure your list shows or proves that.

Back in the day I had 4 twitter accounts for different interests, I would see tech talk on one, art or photography on others, it was great, each felt like a connected but different corner of the same world.

I left over a year ago when all of them just became dominated by the same nft and crypto posts everywhere. Couldn't scroll my timeline without seeing fake BBC news articles promising "David Attenboroughs best crypto investment " whatever account I was in. I'm not sure cleaning up a mess they made themselves is really "actively innovating", but I'd agree the country thing would have been interesting back when I used it

It's perfectly possible. Two tables, one stores answer responses only, the other just marks off who has responded. No link between them and you have anonymous data but can tell who hasn't responded.

Of course if you record created/updated timestamps on both, insert both records in the same order, accidently record the user code in the response data, take backups in between responses, have identifying questions or just don't have that many people responding it's easy/not hard to reverse engineer.

But it's quite possible to do right, I did it quite effectively almost by mistake years ago. Sent a customer survey out with generated codes as identifiers recorded with answers. Before sending reminder emails a script grabbed the codes, marked the customer as responded and wiped the code (so I could just get future responses where code was not null to mark next people off). Although I had timestamps the script meant customers were updated in blocks, there really wasn't any data to link them.

I know because the Boss was not happy he couldn't find out which customer had said what, and I had to point out all the communication (with customers and me) called it an anonymous survey, so why would I have saved them?

So it is possible, just not easy even if you intend it, and it's often not intentional...

I don't trust anonymous surveys either now...

Nobody has to drink it, just test it. The analogy is stupid, but it's more like if there was no FDA, you'd wait a week for food safe labs to test it, or you'd invest in your own testing.

The early release channel is sensible, but if you're a bad actor who's compromised a package you're not going to early release are you, you get it straight out there.

I always found it weird when helping people with excel formulas how few people even try to check maths they don't understand, let alone try to understand it.

I struggle to remember even relatively simple maths like working out "what percentage of X is Y" so if I write a formula like that I'll put in some simple values like 12 and 6 or 10,000 and 2,456 just to confirm I haven't got the values backwards or something. I've been shown sheets where someone put a formula in that they don't understand, checked it with numbers they can't easily eyeball and just assumed it was right as it's roughly in their ball park / they had no idea what the end result should be.

Then again I've also seen sheets where a 10% discount column always had a larger number than the standard price so even obviously wrong things aren't always checked.

Curious how it would track more ide things like a refactor to method command rather than cut and paste. I can understand not tracking paste as you don't really know where it came from, but rtm is using the same code just moving it for you.

This does make more sense to some of the big claims "95% of our code is ai generated" though. By the logic here a lot of my code would be considered generated for years. ide auto complete on variables, functions, closing brackets, class names etc. Lines changes by linters and formatters to add so much as a comma are not mine anymore. Add in refactoring and my use of ide templates and framework generators to make common files and increasingly small amounts would be considered my written code.