HN user

semenko

1,034 karma

nick.semenkovich.com / semenko@alum.mit.edu / @semenko

Physician Scientist (MD/PhD) & Infosec Enthusiast

Via MIT (Course 6/7) / WashU / Brigham and Women's

meet.hn/city/43.0386475,-87.9090751/Milwaukee

Posts14
Comments105
View on HN

GitHub's COO shared this under-reported X post last month [1] on their exponential growth. I'd love to see more proactive messaging on their growth rate / vision for agentic interactions.

… platform activity is surging. There were 1 billion commits in 2025. Now, it's 275 million per week, on pace for 14 billion this year if growth remains linear (spoiler: it won't.)

GitHub Actions has grown from 500M minutes/week in 2023 to 1B minutes/week in 2025, and now 2.1B minutes so far this week.

[1] https://x.com/kdaigle/status/2040164759836778878

I have "Advanced Protection" turned on, so I just can't use this at all, because my newly created Google Cloud GCP app isn't trusted (even though I own it and I'm requesting read-only scopes). What a mess.

  Access blocked: [app name] is not approved by Advanced Protection. Error 400: policy_enforced

I found the most interesting part of the NIST outage post [1] is NIST's special Time Over Fiber (TOF) program [2] that "provides high-precision time transfer by other service arrangements; some direct fiber-optic links were affected and users will be contacted separately."

I've never heard of this! Very cool service, presumably for … quant / HFT / finance firms (maybe for compliance with FINRA Rule 4590 [3])? Telecom providers synchronizing 5G clocks for time-division duplexing [4]? Google/hyperscalers as input to Spanner or other global databases?

Seriously fascinating to me -- who would be a commercial consumer of NIST TOF?

[1] https://groups.google.com/a/list.nist.gov/g/internet-time-se...

[2] https://www.nist.gov/pml/time-and-frequency-division/time-se...

[3] https://www.finra.org/rules-guidance/rulebooks/finra-rules/4...

[4] https://www.ericsson.com/en/blog/2019/8/what-you-need-to-kno...

I was optimistically hoping some of the MV3 changes would result in Chrome webstore policy enforcement being standardized, but that hasn't happened.

Sensor Tower (https://sensortower.com/) makes a lot of popular extensions, like StayFocusd https://www.stayfocusd.com/. They seem to resell ad data (in violation of [1]?) and ship likely obfuscated code [2] (in violation of [3]?), but there's no enforcement or even clear reporting mechanism.

[1] https://developer.chrome.com/docs/webstore/program-policies/...

[2] https://robwu.nl/crxviewer/?crx=https%3A%2F%2Fclients2.googl...

[3] https://developer.chrome.com/docs/webstore/program-policies/...

This title has little to do with the article (and keeps changing).

This piece compares non-surgeon MDs with non-MDs (medical assistants) performing minor surgeries in resource-limited settings.

Its a bit of an odd comparison, as the non-MDs have specifically trained in a 3-year program to perform minor surgeries (CapaCare).

Carbon costs per-vehicle can be calculated based on your local grid power source, duration of ownership, and more: https://www.carboncounter.com/ -- be sure to click the "Customize" tab

If your annual driving distance is low (<5,000 miles) and your grid is relatively dirty (e.g. the midwest [SRMW] grid), a range of EVs have more CO2 emissions/mile than conventional internal combustion vehicles.

(This is a project from the MIT Tranick lab / http://trancik.mit.edu/)

Physician scientist here: this study is a bit dated. Many of these issues have been "solved" (depending on your threat model) within the last ~7 years. Most healthcare systems have adopted Imprivata [1] for SSO, where physicians tap a badge and are connected to (usually) a VDI session of Epic.

What this study misses is the real driver of EMRs: billing. EMRs exist to facilitate billing documentation to charge for patient care. Yes, they have other benefits (like viewing lab results), but if you ever see true critical care (at the bedside, in an ER, or in an ICU) little depends on the EMR (or even labs for that matter).

A few comments here talk about patient notes: in most clinical environments, inpatient notes are useless, and a tedium required to bill. They're filled with copy-pasted jargon to meet insurance company requirements. True patient care happens in less than ~1 paragraph of text called a handoff. [2]

[1] https://www.imprivata.com/

[2] https://bmjopenquality.bmj.com/content/bmjqir/7/3/e000188/F2...

The lack of a stockpile is due to limited shelf stability and long-term bacterial growth.

It's unfortunate Reason doesn't expand on the other side of this issue: the formula industry lobbied the FDA to reduce bacterial testing frequency (and inspections overall), with an emphasis on Cronobacter risks, arguing that the FDA "overestimat[ed] the expected annual incidence of Cronobacter infection". [1]

[1] https://theintercept.com/2022/05/13/baby-formula-shortage-ab...

Hey Graham -- great post! The Medtronic / Guardian sensor combo is generally disliked by patients, though (in the US) the Medtronic 770G is FDA approved for ages 2+.

Most prefer the t:slim X2 with "Control-IQ" (their hybrid closed-loop: https://www.tandemdiabetes.com/products/t-slim-x2-insulin-pu...), which is FDA approved for ages 6+, and works great.

The bleeding edge is the Beta Bionics (https://www.betabionics.com/) bi-hormonal system (insulin + glucagon), currently in clinical trials for ages 6+.

Apparently this is real — fascinating! ( The relevant text of the bill is here: https://www.congress.gov/bill/117th-congress/house-bill/3684... )

This builds on an NHTSA-funded pilot program called Driver Alcohol Detection System for Safety (DADDS; https://www.dadss.org/).

DADDS advanced two technologies for passive impaired driving detection: non-contact breath sensors (exhaled EtOH near the driver), and touch sensors (embedded into the steering wheel).

The bill adds this as a requirement on top of existing distracted driving prevention systems, which have been expanding but don't always get much press (e.g. Subaru's driver-facing cameras).

Physician scientist here -- this is a unique and somewhat odd case where Martha prefers to use the iron lung over modern alternatives.

She would likely do fine with a modern non-invasive positive pressure ventilation (NIPPV) approach.

There are many patients with other illnesses (COPD, ALS, etc.) that depend on nocturnal ventilation -- most commonly nocturnal BiPAP (two pressure levels that support respiratory muscles).

Physician here; this isn't true for the ventilation of COVID patients, or ICU patients in general.

There's a difference between simple ventilator [1], and an anesthesia machine [2] that adds gas mixing, scavenging, etc.

ICU patients are anesthetized using IV sedation (a common regimen in the US is fentanyl/propofol), not inhalational anesthetics. Most vents only have simple inline filters to reduce contamination.

[1] A classic vent in the US is the Puritan Bennett 840. Here's its manual showing filters: https://www.medtronic.com/content/dam/covidien/library/us/en...

[2] https://en.wikipedia.org/wiki/Anaesthetic_machine

The isolation seems mostly defined by this SELinux policy: https://github.com/android/platform_system_core/blob/lollipo...

   service media /system/bin/mediaserver
       class main
       user media
       group audio camera inet net_bt net_bt_admin net_bw_acct drmrpc mediadrm
       ioprio rt 4
You'd need another exploit to elevate from SELinux (and I think send MSSes for a self-propagating worm). Though given Android's abysmal patching, most Android kernels are also terribly outdated...

Oh hey, any chance you could explain this bit of the /usr/bin/google-chrome script I've always wondered about? (Sadly, the bug is RVG.)

   # Sanitize std{in,out,err} because they'll be shared with untrusted child
   # processes (http://crbug.com/376567).
   exec < /dev/null
   exec > >(exec cat)
   exec 2> >(exec cat >&2)
Somehow child processes can abuse stdin/stderr/stdout in ... creative ways?