HN user

mtlynch

14,698 karma

I blog about software and entrepreneurship at https://mtlynch.io

I'm writing a book to help developers improve their writing at https://refactoringenglish.com

Posts163
Comments1,583
View on HN
refactoringenglish.com 2d ago

I Stopped “Creating Content”

mtlynch
303pts238
arbitrationinformation.org 7d ago

Arbitration Information

mtlynch
3pts0
refactoringenglish.com 10d ago

How to Write an Effective Software Design Document

mtlynch
2pts0
refactoringenglish.com 23d ago

How to Write an Effective Software Design Document

mtlynch
3pts1
refactoringenglish.com 26d ago

How to Write an Effective Software Design Document

mtlynch
3pts1
refactoringenglish.com 28d ago

How to Write an Effective Software Design Document

mtlynch
4pts8
terminalbytes.com 2mo ago

My Arduino spins faster when Claude burns more tokens

mtlynch
5pts1
eric.mann.blog 2mo ago

Job Search – Unreasonable Expectations

mtlynch
1pts0
expel.com 3mo ago

North Korea uses AI to industrialize attacks on developers

mtlynch
6pts0
mtlynch.io 3mo ago

Claude Code Found a Linux Vulnerability Hidden for 23 Years

mtlynch
10pts2
refactoringenglish.com 3mo ago

Which Design Doc Did AI Write?

mtlynch
2pts1
refactoringenglish.com 3mo ago

Which Design Doc Did a Human Write?

mtlynch
2pts0
refactoringenglish.com 3mo ago

Which Design Doc Did a Human Write

mtlynch
4pts0
mtlynch.io 5mo ago

My eighth year as a bootstrapped founder

mtlynch
318pts111
mtlynch.io 5mo ago

My Eighth Year as a Bootstrapped Founde

mtlynch
1pts1
mtlynch.io 5mo ago

My Eighth Year as a Bootstrapped Founder

mtlynch
2pts0
mtlynch.io 5mo ago

My Eighth Year as a Bootstrapped Founder

mtlynch
6pts2
www.maragu.dev 6mo ago

My AI got a GitHub account

mtlynch
1pts0
refactoringenglish.com 6mo ago

The Most Popular Blogs of Hacker News in 2025

mtlynch
692pts133
refactoringenglish.com 6mo ago

The Most Popular Blogs on HN in 2025

mtlynch
10pts3
mtlynch.io 7mo ago

My First Impressions of MeshCore Off-Grid Messaging

mtlynch
1pts0
mtlynch.io 7mo ago

My First Impressions of MeshCore Off-Grid Messaging

mtlynch
2pts0
mtlynch.io 7mo ago

My First Impressions of MeshCore Off-Grid Messaging

mtlynch
13pts4
blog.noforeignland.com 7mo ago

Off-Grid Boat Communications with Meshtastic

mtlynch
3pts1
refactoringenglish.com 8mo ago

What Makes the Intro to Crafting Interpreters So Good?

mtlynch
3pts0
refactoringenglish.com 8mo ago

What Makes the Intro to Crafting Interpreters So Good?

mtlynch
3pts0
mtlynch.io 8mo ago

Add a VLAN to OPNsense in Just 26 Clicks Across 6 Screens

mtlynch
4pts1
refactoringenglish.com 8mo ago

How to Get Feedback on Your Design Doc

mtlynch
1pts0
refactoringenglish.com 8mo ago

How to Get Meaningful Feedback on Your Design Document

mtlynch
3pts1
mtlynch.io 9mo ago

Hold Off on Litestream 0.5.0

mtlynch
96pts18

I think we disagree on the connotation of the word "lead."

To me, if someone describes me as a "lead," it implies that they are focused on making the sale rather than on anything else about the business relationship. I would also find it unsettling if a doctor told me that I was a "good lead" because I had a disease they treat.

OP here. Thanks for reading!

I'm having trouble understanding where we disagree. It seems like you're arguing that she's correct because it was helpful for the mutual acquaintance to refer me to this vendor, which I agree it is.

My point is that the term "lead" implies that she's thinking about making the sale rather than serving me as her client. Do we disagree about the connotation of the word "lead?"

As a more extreme example, if you went to a doctor for an illness and they said, "Wow, I'm going to make so much money treating you," I imagine you'd find it off-putting even if the doctor would only earn the money because they're doing a useful thing by treating your illness.

I appreciate the critique!

Sometimes when I'm thinking about a blog post, I fall in love with a joke I want to use, but then it constrains how I think about the topic. I still like the David example, but I'm too close to the post to have a balanced perspective, just having finished it today.

OP here. Thanks for reading!

I'm not trying to argue that art is sacred and we have to hold it up over everything else, but I am joking that there is still an implicit boundary where we don't use "content" to refer to things that we respect highly.

I think a lot of people that talk about "art" vs. "content" are talking about art vs. business, but I'm more arguing about big vs. small and aggregation vs. individuality.

It makes sense for YouTube and Twitter and Facebook to refer to everything on the Internet as "content" because there's so much variety and those platforms are trying to capture all of it. But I just realized it's silly for me, an individual author to refer to my work as "content" when I could just as easily say "book" or "blog posts."

OP here. Thanks for reading!

I feel that all the terms mentioned are useful in specific contexts. Web traffic brings visitors to your resource. If they read your blog, they become readers. If they use your products, they become users. When someone buys something from you, they become a customer.

I'll respectfully disagree. I think those terms make sense if you're talking in general terms, but if you're an individual person talking about your work, they're generic catchall terms with better alternatives.

Like, in concrete terms, let's say I publish funny cartoons on my website and sell prints of those cartoons. It doesn't make sense for me to say "web traffic brings visitors to my resource." What traffic? What resource? It would be more meaningful to say, "Visitors find my website through Google search."

OP here. Thanks for reading!

I don't really have anything against the existence of the catchall term "content." Like, I don't expect the CEO of YouTube to say, "music, short film, art, comedy, journalism, ..., creators" every time he talks about YouTube users. It makes sense from their perspective to bucket everything into "content."

The thing I found interesting was just that the language had crossed over to people where it doesn't make sense to bucket everything. If I'm a blogger, I can just say "blogger" and it's more meaningful than "content creator" but I think the people running small businesses or doing creative work have needlessly adopted the big bucket terminology of "content."

Are you talking about this line?

What Kelley can't do is say, "It's an outright fabrication that Sumner does X today," based on an observation from nine months ago.

I think it's clear that I presented it as a hypothetical dialog, not something you literally said. But I agree that the fairer way to present it would be to say, "Kelley can't say 'It appears to be an outright fabrication'," to match the original language in your blog post.

I think you are earnestly trying to untangle the facts from two parties for whom you have no bias one way or the other, which is commendable.

Honestly, my bias is to support Zig. I personally like the Zig project and you as a person (this blog post notwithstanding) enough that I've contributed a small monthly financial amount for the last 2.5 years. You've never sucked up all my code and then tried to sell it back to me.

So, despite the fact that I have many reasons to favor you and Zig over Sumner and Anthropic, when I read both blog posts, the impression I walk away with is that your blog post is needlessly critical of Sumner as a person and that you made unsubstantiated accusations against him.

To do this, they need to make this rewrite appear successful, so they need to retcon this idea that they were doing good engineering practices in their zig codebase the whole time, including fuzzing, even though that is not the case.

I don't get that from their blog post.

Both you and Loris seem to be saying that Sumner's "We've been fuzzing Bun" claim implies to everyone that they've been fuzzing it for a long time as much as they possibly can, but I think it just means what it says. They've been fuzzing it some, and some bugs fell out of it, not that they fuzzed it perfectly or followed every software engineering practice perfectly.

Right, that part is not in dispute.

If Sumner says today, "We do X," then Kelley can say, "Nine months ago, Sumner did not do X," and both can be correct. What Kelley can't do is say, "It's an outright fabrication that Sumner does X today," based on an observation from nine months ago.

One of the things I find so disappointing about Kelley's behavior here is that he falsely accused Jarred Sumner of lying about fuzzing Bun, and then when Sumner showed evidence[0] that they've been fuzzing Bun for months, Kelley just silently edited his post[1] to walk back the accusation and never apologized or admitted he was wrong.

I commented on Mastodon[2] to point out to Kelley that it's dishonest to silently remove the accusation, as so many people were already talking about it, and it confuses the conversation if Kelley retroactively edits it, and he replied[3]:

the false claim is in the bun blog post not mine. I only changed the text because it's easy to lazily argue against it. Please read more carefully. They are the ones being deceitful not me.

Loris Cro, Zig's VP of Community, gave a slightly clearer response[4]:

Jarred's post has a section about what they "were already doing" to maintain their Zig codebase, which includes "24/7 fuzzing", which will make the average reader assume that the codebase has been fuzzed thoroughly, while in reality it has been for, what, 2 months before the rewrite?

Even then, I find it so bizarre that Loris thinks that if someone says, "We've been fuzzing Bun," and shows evidence of months of fuzzing, then that person is lying because "We've been fuzzing Bun" somehow implies something longer than two months.

The duration is irrelevant. If you say you've been fuzzing it and you've fixed bugs that your fuzzer found, then clearly you're fuzzing. The Zig team doesn't get to arbitrarily move the goalposts of what "fuzzing" means.

[0] https://news.ycombinator.com/item?id=48845652

[1] https://news.ycombinator.com/item?id=48854921

[2] https://m.mtlynch.io/@michael/116896188093796421

[3] https://mastodon.social/@andrewrk/116897155344411469

[4] https://hachyderm.io/@kristoff/116898483283387067

I'm having trouble understanding what you mean.

If I say, "I run 5 miles every day" and my old neighbor says, "I lived next door to him until 9 months ago, and he definitely doesn't run 5 miles a day," and then I show my GPS logs proving I've been running 5 miles a day for the last 9 months, I am correct and my ex-neighbor is incorrect.

If Sumner had said, "We've been fuzzing our code for years," then Kelley could justifiably say that's incorrect. But Sumner is saying that currently Bun fuzzes their code, which is true, so Kelley appears to be incorrect to claim it is a "fabrication."

For me, using Fuzzilli for testing a Zig code is not fuzzing, it's integration testing. If you're running code externally (e.g. wrapping binary) you cannot guarantee that side effect isn't caused by IO. I consider fuzzing a low level activity with many external variables removed.

I've never heard anyone restrict the definition of "fuzzing" in this way. If I repeatedly generate inputs to a program and then run the program with those inputs, that's fuzzing. It doesn't matter if there's IO or not.

Depending on where you are and how you communicate semantics matter more or less. It's very similar to compiler/transpiler. E.g. TypeScript "Compiler" is called compiler but in fact it's transpiler (it emits other high-level language as a result).

It's still a compiler. It translates code from one language to another. You can argue whether we need the term "transpiler," but a source-to-source compiler is a compiler.

Yes, "their" refers to Bun's code, not the Zig compiler's code. Fuzzili is a fuzzing engine for JavaScript, so integrating it into Bun means that Fuzzili is fuzzing Bun.[0]

From the Bun post[1]

We fuzz Bun's runtime APIs 24/7 using Fuzzilli, the JavaScript engine fuzzer used by V8 & JavaScriptCore

From Andrew Kelley's post today[2]:

The post claims they were fuzzing their Zig code, while during our calls the whole Bun team told us that they were not fuzzing anything. This appears to be an outright fabrication.

Sumner says that the Bun team has been fuzzing Bun's Zig code. Kelley says that this is a fabrication. Sumner showed proof that the Bun team has been fuzzing Bun's Zig code.

It looks like Kelley is incorrect and made an unfounded claim. The generous interpretation is that at the time Kelley and Sumner had a more collaborative relationship, Sumner was not fuzzing Bun's Zig code, but I'd expect Kelley to check if anything had changed since then before publicly accusing Sumner of lying in this week's Bun blog post.

[0] https://github.com/googleprojectzero/fuzzilli

[1] https://bun.com/blog/bun-in-rust

[2] https://andrewkelley.me/post/my-thoughts-bun-rust-rewrite.ht...

The problems for services such as GitHub with scaling are reducing cost per customer. That's even more pertinent when discussing inference at scale.

I don't think that's true. When I look at GitHub's incident history,[0] it doesn't read to me like a company that's struggling to cut costs. It looks like a company that's trying to do a million things to serve a million use cases, and the growing interconnections between all those distinct services and workflows cause unexpected failures.

[0] https://www.githubstatus.com/history

Not GP, but just being smaller makes it easier to achieve reliability. Like if you're a git forge with 100 similar customers, you can likely achieve an order of magnitude better reliability than GitHub, who is trying to serve millions of customers with wildly different needs.

The target audience of the app is me and my wife. This is a "home-cooked meal" app.[0] If it's useful to other people, I'm glad, but I'm primarily building it for myself for the pleasure of building and the satisfaction of a tool that works exactly how I want it to work.

You could approximate it with email, but I want things that you can't do with email like letting recipients control the frequency of emails, making high-res images available without bloating everyone's inboxes.

[0] https://www.robinsloan.com/notes/home-cooked-app/

Thanks for reading!

But I spent five years on a solo app and never wrote anything close to this. Not on principle event, just the design just kept moving.

Yeah, I agree that for solo projects, it makes sense to greatly scale down the design phase. In a lot of cases, you'd scale design down to zero if you need user feedback to figure out what to build.

But even for solo projects, if I keep at it for months or years, I eventually get to the point where some problem is hard enough that I need to do some upfront design, even if it's not as formal as a whole design doc.

Most are not serious, and we’ve quietly fixed them, thanked the researcher, and went our merry way... These come from a wide variety of locations and people, and sometimes, but not always, are looking for bug bounties.

I take it that Metabase is both not paying bug bounties and not using these tools internally?

If that's the case, Metabase is not going to get meaningful investment from researchers who want to fix issues, but they'll get increased attention from malicious attackers who have no qualms exploiting the vulnerabilities for profit.

LLMs have made it a lot easier for people to find vulnerabilities in software. Open-source makes it easier, but we already have non-AI tooling (IDA Pro, Ghidra) that's good at binary reverse engineering, and LLMs can use that output to find vulnerabilities as well.

This year, as I select products to use for sensitive data, I've been paying a lot more attention to whether they offer bug bounties and for how much. For example, I like Kagi for search and thought about trying Orion, their web browser. Then, I saw that Kagi's been paying $100 for UXSS vulnerabilities.[0] For comparison, Firefox pays $8-10k,[1] and Chrome pays up to $10k for the same class of bug.[2]

[0] https://help.kagi.com/kagi/privacy/bug-bounty-program.html

[1] https://www.mozilla.org/en-US/security/client-bug-bounty/

[2] https://bughunters.google.com/about/rules/chrome-friends/chr...

That would be even worse than our already bad system.

The system is already pretty bad because vendors underinvest in security, and then to fix it, researchers have to volunteer their time to investigate with no guarantee of payment. If the vendor could force researchers to hand over findings for free, nobody would want to do security research except hobbyists having fun. They're basically signing up for hours of tedious forced labor to explain vulnerabilities to the vendor.

I wish there was legislation that allowed the government to fine vendors for security vulnerabilities like this where the amount scales based on how much user data they leaked. And it could function like other whistleblower systems where a researcher who spots a leak can report it to the government and collect 50%. That way, if the vendor says, "We're not paying you," the researcher can turn around and collect the money from fines.

Oh, I'm glad!

Yeah, I don't think you'll find it a red-pill kind of book at all. I know what you mean about books like The 48 Laws of Power feeling like the world is 100% zero sum, so everything is about dominating or outplaying people.

How to Win Friends and Influence People is very much focused on win-win. There is an agenda to make friends and influence people, as you'd guess from the title, but the strategies are about taking a genuine interest in people and making them feel good.

It's almost 100 years old, so the style is kind of hokey, and only about half the advice resonated with me, but there are 3-4 lessons that had a major impact on me.