HN user

montroser

3,152 karma
Posts25
Comments566
View on HN
www.cole-k.com 10h ago

So Reddit has decided that plain HTML is unsafe

montroser
192pts193
tmctmt.com 3mo ago

HTTP desync in Discord's media proxy: Spying on a whole platform

montroser
4pts0
www.cnn.com 4mo ago

Justice Department seizes several websites it says spread terrorist propaganda

montroser
19pts4
www.theguardian.com 5mo ago

Fairphone 6: cheaper, repairable and longer-lasting

montroser
24pts9
mastransky.wordpress.com 5mo ago

Firefox and Linux in 2025

montroser
5pts0
spectrum.ieee.org 6mo ago

Fast GPU Interconnect over Radio

montroser
100pts12
apnews.com 7mo ago

Sewage can be used to heat and cool buildings

montroser
2pts0
pierce.dev 7mo ago

Go ahead, self-host Postgres

montroser
5pts0
orgpad.info 8mo ago

Goodbye Circles, Hello Squircles: Perfect Corners in CSS and Canvas

montroser
5pts0
boingboing.net 1y ago

Maine police caught lying about using AI to alter drug bust photo

montroser
35pts9
www.theverge.com 1y ago

Amazon is reportedly training humanoid robots to deliver packages

montroser
2pts1
www.x-cmd.com 1y ago

X-cmd: classic CLI tools on meth, in your POSIX shell

montroser
10pts1
social.treehouse.systems 1y ago

Details on Pixel 4a's forced "Update of Death"

montroser
3pts1
training.npr.org 1y ago

Why NPR conversations sound so fake: Reporter two-ways

montroser
4pts4
connect.mozilla.org 2y ago

Firefox Android to scrap URL from new address bar

montroser
13pts7
www.lexaloffle.com 2y ago

Pico-8 Fantasy Console

montroser
3pts0
news.ycombinator.com 4y ago

Ask HN: Why is there no enterprise grade open-source zoom alternative?

montroser
41pts34
journals.plos.org 4y ago

Pre-infection vitamin D3 levels association with severity of Covid-19 illness

montroser
41pts10
github.com 4y ago

Base1

montroser
2pts0
webreflection.medium.com 4y ago

LinkeDOM: A Jsdom Alternative (2021)

montroser
1pts0
www.nytimes.com 4y ago

If You Never Met Your Co-Workers in Person, Did You Even Work There?

montroser
2pts1
news.ycombinator.com 6y ago

Ask HN: What timezone do you use in conversation with a distributed team?

montroser
3pts4
github.com 6y ago

Abcdefghijklmnopqrstuvwxyz

montroser
2pts0
news.ycombinator.com 6y ago

Ask HN: How do you keep track of links/docs/assets relating to a project?

montroser
7pts5
www.plectica.com 7y ago

Interactive map of Cohen's testimony to congress

montroser
2pts1

Well, many EU countries like Italy and Germany officially freaked out about DeepSeek, ordering it to be banned from app stores etc.

This was always where this was heading, but we got here much faster than expected.

Once western governments declare it to be a "national security" risk for citizens to have access to open-weight frontier models, and once they classify using these models as acts of terrorism, what will that world be like?

Will using Kimi K3 come to be like how napster was in the olden days? Everybody knew it was technically illegal, but come on -- any track at your fingertips? But surveillance is quite more evolved now.

Or it will be like cannabis, where a guy in the neighborhood will low key rent you metered access to the 8x5090 rig in his basement he cobbled together from parts on ebay? Or everyone will flock to VPNs?

Or will the oppressors actually succeed? The same way that napster is long gone, and everyone accepts that they must pay spotify for a homogenized collection, where artists must take only a minuscule cut (more than napster though)... We'll be stuck with nerfed Cohere or Mistral models for open-weight options, as if they need more lobotomizing. Or else we can pay through the nose for Anthropic/OpenAI for "American Frontier" models which will fall increasingly far behind China.

Or else, like how Kindle Fire was subsidized by ads, we'll have "Kindle AI" where influence is sold to the highest bidder, where the LLM will tell us that smoking is actually healthy if big tobacco can engineer its renaissance by turning its lobbying dollars to pay-to-play, pumping its propaganda into the training pipeline for Amazon's extra commercialized line of ultra budget LLMs.

One time I hired two different random guys on craigslist to assemble three IKEA bureaus. They didn't know each other beforehand, and I hired them separately to work together.

They started by jockeying to see which one was going to be in charge, arguing about how to proceed, throwing shade, making claims of superiority. One guy wanted to follow the instructions, and the other guy just wanted to go on intuition. They couldn't agree and asked me which one should be in charge, and I said, I don't know just work together, follow the instructions, and get this stuff built.

The instructions guy assumed the lead, and then they settled into a rhythm. Three hours later, they couldn't stop gushing about each other, and a most beautiful bromance was born. They exchanged telephone numbers and made plans to hang out on the weekend.

Minikotlin 5 days ago

This is very cool! Slightly off-topic though, I miss technical people writing in their own voice about the awesome things they've built.

Well, it's not that hard: just give the LLM a user-scoped access token, same as if the user themselves were asking their own LLM to act on their behalf.

Basically, just like we don't show users information they shouldn't be able to see, and don't let them take actions they shouldn't be able to take -- we can use exactly those same explicit mechanisms (scopes, roles, permissions) to limit what the LLM can see and do.

The LLM could try to do more than what's allowed, but they get shot down with an access denied message just like anyone else.

The anti pattern is to think that you can reimplement access control with prompt engineering and give the LLM root access. That is doomed to fail every time.

Vite+ Beta 20 days ago

Vite had five major version in the four years 2022-2026. Version 3 => 4 => 5 => 6 => 7 => 8. Each one of those had breaking changes and required devs to go through a migration. It's too much. And for what? It's not as if it is dramatically better now than it was in version 3.

I can't say I would really look forward to bringing this level of needless churn and constant disruption to the rest of my development toolchain. Anyway, Vite+ is really just wrapping existing tools into an abstracted command-line interface? And so I have more layers of indirection to wade through in order to get the thing to do what I want? So far I am not optimistic about this prospect...

I've been driving glm-5.2 for a day or two now. It feels like a mature, seasoned colleague.

It could be luck, but I don't know -- it keeps one-shotting relatively hard stuff. And taking initiative to think about what potential regressions it should look out for, and choosing to do strategic refactoring when it should do. It is not confidently incorrect hardly at all, doesn't tell me that it's fresh risky pile of changes is ready for production without having exercised all the code paths and writing a bunch of tests, etc.

We might be reaching the next level here...

Reading the paper, by "Fertility" the author really means "rate of pregnancy" which seems kinda like a different thing.

Basically, access to the Internet is correlated with less teenage pregnancy. Idiocracy in motion...

Makes sense to split the foundation, as the communities have split (and withered).

From its inception Perl 6 was an incredible journey that resulted in a genuinely weird and interesting new programming language, and squandered a broad wealth of momentum and good will and enthusiasm from the Perl community at large. It was a dramatic slow death over the course of a decade, where people who had built their careers, and small and large companies who had built their economic engines on Perl got to come to the realization that the whole thing was over, killed somewhat inadvertently by its own creator...

Well, this is certainly not benchmaxxed, I'll give it that. And props for being honest about how far behind Qwen 3.6 MoE is this model.

But yeah, it's not the best look to have to stretch and say it's "competitive" with other models in it's weight class, when it offers not much else that's useful or novel.

Well, this is the exact opposite of his point. Of course it should make sense when not animating! That is given. The entire crux of his point is that it should also make during an animation.

In an ideal world, it is hard to argue with. Yes, sure it should make sense. But also, please don't spend precious cycles on this unless all the other bugs are fixed, and this animation consistency is truly the most important remaining issue to address.

In Cellpond, I handpicked hexadecimal values for each channel so that the resultant colours would better fit my app's theme and needs.

Well, this is an admission that trying to balance "wiggle room" without too much "fussing" with 1000 colors didn't really work.

Evenly sampled in rgb space, a 1000 color palette yields neither enough flexibility (especially in the blacks, greys, whites), nor enough constraint to really make it dead simple.

For app development at least -- choose 20 gradations of blackish to whiteish; 8 gradations of an accent color and so too for a couple of secondary colors...and you're good. That's like 48 colors instead of 1000.

Result is ~12 tokens per second, as reported by OP down in these comments here.

An impressive effort, and better than I would have thought possible on this hardware -- but still pretty far short of what one needs for an satisfactory interactive session.

Chuwi Minibook X 2 months ago

This is my daily driver laptop. It's pretty good for what it is. Runs Linux perfectly, not trying to be especially too fast, very nice pixel density, all metal case, sturdy build. Battery life is not the best. Beautifully compact.

In practice, my experience is that it's mostly a lose-lose proposition. You have to invest in learning a bunch of same-but-difterent framework apis to do what the language already does natively. And in return, the code is more complex, and harder to debug, and so it has more bugs.

We once hired a very smart fellow to build out a media processing pipeline. He did with rxjs, but it wasn't scaling well. We tried to get with the paradigm for a bit and help scale it up, but flame graphs in profiler output were all crazy, and it was a pain to wire in timing traces, etc. We built a POC imperative version just to prove that we could indeed achieve the throughput we thought we could, and then we just said, well hey, this is faster and simpler, so... let's just go with this instead. And so we did.

Come on, now. The human writes the plan up front, which includes guidance on testing strategy, classes of tests, particular test cases to cover, etc. And just like normal, of course you don't just ship the code without doing manual verification, code review, auditing the test cases, and all the rest.

It matters for at least a few reasons:

- Depending on the nature of your application, it may be very important to be able to audit the business logic and intended behavior. For compliance reasons, for operational reasons, for moral/ethical reasons -- you very well might want to affirm what the code is actually trying to do.

- A coding agent may get very creative in order to write code that passes a tightly-defined unit test. It may come up with approaches that technically pass, but work against the overall intention of the app in the first place. This becomes an arms race rather than a productive collaboration, where the agent's increasing creativity has to be matched by a sprawling test suite.

- Eventually, inevitably, business requirements will change, and the blob will need to evolve. It will be much easier for an agent or a human alike to understand how to safely make the change, if the existing implementation is transparent and understandable.

Well, my team does what we call vibe engineering.

You do ask hard questions up front, define boundaries, give lots of high level architectural guidance, declare interfaces, and bounds of abstraction... And then you ask the LLM to make it so, and it does. You give it the structure, and it fills in the implementation.

This is engineering, more or less.