HN user

nomilk

8,142 karma
Posts386
Comments1,513
View on HN
cdn.openai.com 2d ago

Exact Prompt Used by OpenAI for "A Proof of the Cycle Double Cover Conjecture" [pdf]

nomilk
1pts0
www.youtube.com 5d ago

Storm [video]

nomilk
1pts0
www.youtube.com 9d ago

Comparing the Burn Ability of 4 Materials Used for Wall Insulation [video]

nomilk
1pts0
old.reddit.com 16d ago

Rules for Building SaaS in 2026

nomilk
3pts0
www.youtube.com 27d ago

What Jess Livingston and Paul Graham learned about resilience from Y Combinator [video]

nomilk
2pts0
en.wikipedia.org 28d ago

Distribution of Lightning

nomilk
3pts0
www.youtube.com 1mo ago

Seirawan Chess [video]

nomilk
2pts0
playday.one 1mo ago

Bobby Prince's Doom (1993) Soundtrack Inducted into Library of Congress

nomilk
3pts0
en.wikipedia.org 1mo ago

Water Fluoridation in Australia

nomilk
2pts0
www.youtube.com 1mo ago

Ruby on Rails' DHH on Basecamp 5, Vibe Coding, and the Future of Rails [video]

nomilk
2pts0
www.the-sun.com 1mo ago

Facebook down: Meta users being hit with 'query error' message

nomilk
2pts2
meta.stackoverflow.com 1mo ago

Terms of Service Ban AI Agents from Using Stack Overflow for Agents

nomilk
4pts1
www.msn.com 1mo ago

GitLab to cut workforce by 14% and exit 22 countries in restructure around AI

nomilk
14pts1
www.youtube.com 1mo ago

Fast Food's Digital Revolution: Why Fast Food Got So Expensive [video]

nomilk
3pts0
twitter.com 1mo ago

Codex generated code that bypasses security constraints

nomilk
6pts0
www.youtube.com 1mo ago

The Highest Break in Professional Snooker – Ronnie O'Sullivan – 153 [video]

nomilk
2pts1
en.wikipedia.org 2mo ago

Rule of Thirds

nomilk
2pts0
www.youtube.com 2mo ago

Should you move to Silicon Valley? [video]

nomilk
3pts1
news.ycombinator.com 2mo ago

Ask HN: Are SaaS businesses going to zero?

nomilk
2pts11
en.wikipedia.org 2mo ago

Catatumbo Lightning

nomilk
5pts0
www.youtube.com 2mo ago

Red Alert 2 UI in real life [video]

nomilk
2pts0
en.wikipedia.org 2mo ago

Ashby's Law of Requisite Variety (Cybernetics)

nomilk
2pts0
twitter.com 2mo ago

Claude Opus 4.6 was nerfed prior to release of Opus 4.7

nomilk
1pts0
meta.stackexchange.com 3mo ago

What Is an XY Problem?

nomilk
1pts0
twitter.com 3mo ago

What Features Did X and xAI Add in 2025?

nomilk
2pts0
en.wikipedia.org 3mo ago

Entasis

nomilk
3pts0
www.youtube.com 3mo ago

The Untold Story of R [video]

nomilk
2pts1
en.wikipedia.org 3mo ago

Thucydides Trap

nomilk
1pts1
www.youtube.com 3mo ago

Exploring Psychic Powers Live TV Special (1989) [video]

nomilk
2pts0
www.youtube.com 3mo ago

Vermin Supreme: When I'm President Everyone Gets a Free Pony [video]

nomilk
11pts4

The article suggests a seemingly easy fix:

The fix is pretty straightforward: treat comment content as untrusted data, not as potential instructions. Comments should be passed to the model with clear role boundaries that prevent them from being interpreted as system-level directives.

Any AI feature that ingests user-generated content and acts on it needs to enforce this separation. Otherwise, the AI becomes a vector for every piece of content it reads.

So why isn't YT doing the extreme obvious?

August 3, 2014

That's important. Because now days it's trivial for LLMs to translate ORM to SQL and vice-versa with ~100% accuracy. I haven't written any raw SQL (only Active Record) in about two years, and the odd time I blunder with AR and create an n+1 I find out about it via error tracking (e.g. Sentry) a few minutes later and fix it. No biggie.

There's also an additional layer of protection in that using AI on the codebase can spot SQL blunders incidentally (i.e. you ask about X, and the AI does X but also says "Not asked, but flagging for your attention: problem with SQL on line 256 etc.."

Loupe itself can see if you have tinder/bumble/hinge installed (verify for yourself: install tinder, then install loupe, don't give it any permissions, and it can tell if you have tinder installed or not). So the answer is: buy the data from any app your partner has installed! Or more easily, a data aggregator which will have already combined data from hundreds/thousands of apps.

So your partner only needs to have had 1 single app from the list that sells user data to a data aggregator for this to work. They do not need to have installed some special app.

Here's a random Slate article about apps getting your data and selling it to aggregators/brokers, who sell it to third-parties (you, or I, could be one of those third parties).

How Shady Companies Guess Your Religion, Sexual Orientation, and Mental Health And sell that data to the highest bidder.

https://slate.com/technology/2023/04/data-broker-inference-p...

They don't, utilise the fact that every single iPhone app has access to what other apps are installed! - purchase that info from literally any iPhone app or aggregator that has it for that user. Curious how much this would cost to purhcase - a working credit card goes for $5-10 on the black market so 'apps installed on X's iphone' might be, like, 10c?

Why does a random app (with no special permissions given to it) get access to so much info, and why doesn't Apple tell users this (important) info? Why can't Apple make a long list of check boxes so users can dis/allow on a per-category and per-app basis?

E.g. I had no idea a random app you install (and give no permissions to) instantly has a list of every app installed on the device (e.g. can infer whether you're dating [or cheating!] from presence of tinder/bumble/hinge). That alone seems instantly monetizable by unscrupulous actors via 'is-my-partner-cheating' as a service: charge $10 to give a probable answer.

Could be useful for mass production of espresso-based drinks (like the ones sold at convenience stores), and possibly various foods like Tiramisu.

An average coffee shop's espresso machine might use $200/month of electricity, so even though the percent saving (75%) is high, it's off a base that's small relative to other costs; possibly too small to be enticing.

Similar providers (heroku, aws) haven't increased their compute/ram/ec2/dyno prices recently; why is Hetzner's increase so massive (> 3-4x) - wouldn't increased hardware costs affect everyone else too?

Siri AI 1 month ago

They do (one hand), but it doesn't require anything precise (like finding the app and clicking on it, which you can't really do while driving). If Siri could open an AI voice chat, that would awesome. But I'm not counting on that within this decade.

Siri AI 1 month ago

I placed eggs into boiling water and because my hands were wet I used voice and said "hey Siri, start a timer". It replied "you'll have to unlock your iPhone first", so I hovered my face over the bench the phone was sitting on, then the screen rattled and prompted for the numeric passcode. Ugh..

Using Siri essentially required me to use my hands anyway, so what's the point of voice?

I'd very seriously consider moving away from iPhone to a device that treats voice AI as a first class citizen (presently I mapped the 'double back tap' to open grok voice chat, and triple back tap to end it, which is a wonderful improvement over not having these, as you can do that pretty easily, even while driving etc).

Very cool. Small (almost so small as to be silly) suggestion. But my first instinct as a non-classical music listener was to copy the names of songs into youtube so I could see if I recognised them. But for whatever reason I can't select the text (on desktop, not sure if different elsewhere). Could be cool to allow the text to be selectable, or even better link directly to it if it's on yt or other platforms/places.

Re: Rocket Man Bad

Humans evolved to crave schadenfreude because curiosity and desire for justice are both helpful to reproductive success in group settings (e.g. tribes).

Media 'hacks' this evolved instinct for schadenfreude by manufacturing bad people so readers satiate their craving for 'justice' by gorging on the missteps of others.

This is harmless entertainment in works of fiction, but destructive and counter-productive in reality.

I see your point, that donors could influence political appointees to nix certain research topics for their own benefit.

How often does that actually happen, and wouldn't other institutions pick up the slack in most cases? (i.e. high value research doesn't cease to be high value just because one type of grant or institution refuses to fund it; it would therefore be attractive to other institutions/researchers)

Some benefits of having political appointees in the loop are that the pubic perceives (not necessarily 'gets') greater value from public research funding, and the people responsible for the funding (political appointees) are closer to the actual spending and are more involved in the allocative process, which should mean fewer expensive, hard-to-justify topics.

Being curious definitely leads to discoveries. But important discoveries can also be made by saying "Topic X, if better understood, might lead to a cure for cancer - let's look into (and fund) that".

We could think of this problem as a slider from 0-100 where we allocate from 'none' up to 'all' our research budget to curiosity-driven research.

Political appointees having a say will likely move the slider toward the 0 (not necessarily to zero). I'm just not sure it's a bad thing.

A "just say yes" attitude leads to certain disaster

Disaster's a possibility. But if an idea has a 1% chance of success, "just say no" usually assures failure, whereas "just say yes" is a shot at that 1% chance.

think of this as the just-say-no engineer, as opposed to the just-say-yes engineer. The just-say-yes engineer is obsessed with moving fast, approves code changes by default, values MTTR over MTBF, and tends to ship a lot of code. The just-say-no engineer is obsessed with quality, is happy to move slowly, and blocks code changes by default.

Love the concept of the 'just-say-yes' engineer vs 'just-say-no' engineer (and corresponding prioritisation of MTTR over MTBF).

I'm definitely a 'just-say-yes' with the caveat that bad architectural choices can be super painful to fix later, and features become a lot harder to fix when they have users as opposed to before launch (so I'm a little bit 'just-say-no', or at least 'just-think-for-a-bit-first').

I also think the balance between 'just-say-yes' and 'just-say-no' really depends a lot on the project. If it's finance or healthcare, perhaps 'no' by default is best. But if it's a silly startup idea, YOLO.

I see the benefit (it avoids the “works on my machine” problem), but my rails app isn’t too fancy and works on heroku ~100% of the time when it works on the dev machine. Making an intermediate build redundant (technically not entirely but it’s just not worth the effort).

For small teams it could be as simple as everyone agreeing to ensure tests pass on main before pushing to prod.