HN user

mukmuk

356 karma
Posts6
Comments26
View on HN

I’m not sure how to reconcile anthropic’s update / some of the exuberant comments here with recent feedback like the following from curl maintainer Daniel Steinberg:

“I see no evidence that this setup [Mythos] finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing.”

https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v...

ChatGPT for Excel 3 months ago

From my experience, LLM performance in these areas is being massively oversold. I have repeatedly tried using Claude to modify a range of models typical of investment banking / private equity / sellside research contexts, and the results have been generally disastrous. On multiple occasions, the xlsx would no longer open.

Somewhat relatedly, there is a pretty plausible theory that some “find the Yeti” expeditions were in fact cover for operations by my country’s intelligence services to sabotage China. See e.g., https://topsecretumbra.substack.com/p/the-secret-history-of-...

(Btw the general idea that there are animals that we don’t know about is not remotely far-fetched. A new possum genus was discovered like a month ago.)

That is no longer true. What we have historically referred to as “health insurance” companies responded to ACA margin limits by becoming sprawling behemoths whose rampant self-dealing makes such profit margin calculations meaningless.

Walmart Pay 11 years ago

I think this is a common misperception regarding Apple Pay - it actually does not use disposable credit card numbers. Apple Pay generates a Device Account Number (DAN) once when you add a card to your phone's wallet. Thereafter, the same DAN is reused on that device for all transactions with that card.

So it actually does not do much to defeat merchant tracking, assuming you consistently use Apple Pay where it is available.

@prottmann alluded to it, but it might be useful to add Marty as well (http://martyjs.org) (no affiliation).

It's just behind Reflux on the superficial metrics (stars, contributors, npm downloads) so is likely to be on most short-lists.

I've had a good experience with Marty so far but remain curious about the others. Reflux worries me a bit because of its minor divergences from the Flux design decisions.

Does the reference to similar incidents this year suggest this was a watering hole attack targeting a Java vulnerability? It would be nice to know, just generally, what vectors were used here to the extent it was anything novel.