<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: EFLKumo</title><link>https://news.ycombinator.com/user?id=EFLKumo</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 03 Sep 2026 06:48:10 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=EFLKumo" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by EFLKumo in "Gemini 3.8 Flash and 3.8 Flash Cyber"]]></title><description><![CDATA[
<p>Sorry! I was just a bit excited writing the comment and ignored that :(</p>
]]></description><pubDate>Wed, 02 Sep 2026 17:48:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=49539832</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=49539832</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49539832</guid></item><item><title><![CDATA[New comment by EFLKumo in "Show HN: FrontierHarness Eval – 9 harness, same model, cost per pass varies 17x"]]></title><description><![CDATA[
<p>I've been confused a lot why there isn't a benchmark to measure a harness's performance rather than the model's one. Now there it is.</p>
]]></description><pubDate>Wed, 02 Sep 2026 17:46:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=49539798</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=49539798</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49539798</guid></item><item><title><![CDATA[New comment by EFLKumo in "Show HN: FrontierHarness Eval – 9 harness, same model, cost per pass varies 17x"]]></title><description><![CDATA[
<p>Claude Code supports the base URL env var so you could tell it to talk with any LLM API endpoint that receives the Anthropic style request format, e.g. DeepSeek.</p>
]]></description><pubDate>Wed, 02 Sep 2026 17:43:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=49539743</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=49539743</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49539743</guid></item><item><title><![CDATA[New comment by EFLKumo in "Mistral now trains on user input by default, except on enterprise tier"]]></title><description><![CDATA[
<p>Come on, think how fast Grok evolves after SoaceXAI acquired Cursor. I just believe if you can't get enough real data from practice then you can't train a good model. And for Mistral collecting data is a must step no matter what approach it takes.</p>
]]></description><pubDate>Wed, 02 Sep 2026 17:38:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=49539674</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=49539674</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49539674</guid></item><item><title><![CDATA[New comment by EFLKumo in "Gemini 3.8 Flash and 3.8 Flash Cyber"]]></title><description><![CDATA[
<p>Something maybe unfamiliar with you: not about coding but writing. I've asked it to write an argumentative essay, which is a part of "gaokao" (China's university entrance exam), and its work is *extremely* impressive. speaks and writes like a real senior high school student, and the opinions unfold progressively with deep hierarchy. I don't know how the Gemini team reaches this because this kind of Chinese capability literally outperforms at least 2/3 Chinese students, no to mention those who speak Chinese. After all, the model speaks like a real humankind if you prompt it well. That's AGI guys</p>
]]></description><pubDate>Wed, 02 Sep 2026 17:30:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=49539552</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=49539552</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49539552</guid></item><item><title><![CDATA[Microsoft ships a Rust WinUI3 library, React-like]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/microsoft/windows-rs/pull/4479">https://github.com/microsoft/windows-rs/pull/4479</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48357452">https://news.ycombinator.com/item?id=48357452</a></p>
<p>Points: 4</p>
<p># Comments: 1</p>
]]></description><pubDate>Mon, 01 Jun 2026 14:39:59 +0000</pubDate><link>https://github.com/microsoft/windows-rs/pull/4479</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48357452</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48357452</guid></item><item><title><![CDATA[New comment by EFLKumo in "Use boring languages with LLMs"]]></title><description><![CDATA[
<p>It's displayed in my practice that LLMs master Rust even as weaker models like deepseek.</p>
]]></description><pubDate>Wed, 27 May 2026 02:20:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48288689</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48288689</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48288689</guid></item><item><title><![CDATA[New comment by EFLKumo in "Cloudflare Flagship"]]></title><description><![CDATA[
<p>Worth noticing a Vercel equivalent: <a href="https://github.com/vercel/flags" rel="nofollow">https://github.com/vercel/flags</a></p>
]]></description><pubDate>Tue, 26 May 2026 23:55:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48287612</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48287612</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48287612</guid></item><item><title><![CDATA[New comment by EFLKumo in "Improving C# Memory Safety"]]></title><description><![CDATA[
<p>Making a XAML UI is fundamentally authoring a WinRT interface, I guess. And for cppwinrt, Microsoft's solution is like describing in so-called MIDL .idl files, compiler generating cpp stubs, copying these stubs and filling in implementations. After static reflection introduced in cpp idk if this process could become better, but Microsoft just left cppwinrt in maintenance mode, it's impossible I guess.<p>On the Rust side, IMO the windows-rs even has not thought about authoring new com interfaces, only consuming or impl-ing existing ones. In fact the experience of consuming windows apis in rust feels good if one would like to get rid of C++. Rust with NAPI or BoltFFI etc. offers an maintaining-friendly option for cross-platform app authors to interact with the OS more deeply. So in conclusion the situation right now is that windows apis just become not so unapproachable, while in-depth things keeping comfortable only with C# or .NET.</p>
]]></description><pubDate>Tue, 26 May 2026 11:29:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48278246</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48278246</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48278246</guid></item><item><title><![CDATA[New comment by EFLKumo in "Does anybody like React?"]]></title><description><![CDATA[
<p>Exactly what I want to say. Thank you.</p>
]]></description><pubDate>Tue, 26 May 2026 02:42:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=48274379</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48274379</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48274379</guid></item><item><title><![CDATA[LLM proactively bypassed pnpm's anti-supply-chain-attack config]]></title><description><![CDATA[
<p>Article URL: <a href="https://twitter.com/encrypted/status/2058658244328124562">https://twitter.com/encrypted/status/2058658244328124562</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48274185">https://news.ycombinator.com/item?id=48274185</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 26 May 2026 02:14:02 +0000</pubDate><link>https://twitter.com/encrypted/status/2058658244328124562</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48274185</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48274185</guid></item><item><title><![CDATA[New comment by EFLKumo in "Using AI to write better code more slowly"]]></title><description><![CDATA[
<p><a href="https://news.ycombinator.com/item?id=48246232">https://news.ycombinator.com/item?id=48246232</a><p>This reminds me the article above. Now people have diverse ideas on agentic coding. Some suggest human-in-the-loop while others suggest giving a detailed specification and let the agent run freely; some suggest leveraging LLM's high productivity and here we get an opinion that LLM can actually slowly write good code.<p>It's happy to see opinions that are more practical and variant emerging, turning LLM into literally a tool instead of something to be hated or hyped.<p>In my own practice, I find LLMs (SOTA ones) good at medium-level tasks, those needed to reason and plan for a while. However, the design taste on architecture is unexpectedly disgusting. Sometimes writing interfaces myself and asking LLMs to fill in implementations, alongside context-completing tools like context7, deepwiki, docs.rs MCPs, etc. and giving a escape hatch (e.g. encouraging it to use the AskUser tool in Claude Code), may be considered my best practice.</p>
]]></description><pubDate>Tue, 26 May 2026 01:30:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48273936</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48273936</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48273936</guid></item><item><title><![CDATA[New comment by EFLKumo in "Microsoft Copilot Cowork Exfiltrates Files"]]></title><description><![CDATA[
<p>By using "ReAct", I just wanted to emphasize the "agentic" perspective of tool calling, which makes tool calling facing the real world and at risk sometimes. So I'm not downplaying the significance of tool callings.<p>Yes I'm a builder of an agent infra on PCs, so I can completely sense that the protective measures are weak and inadequate, sometimes seeming like an unsolvable problem. But according to the article, what Microsoft did was hard to tell in a polite way. If they had even a little security awareness, I could completely understand, but it's like they've vibe coded the entire permissions system of Cowork.</p>
]]></description><pubDate>Tue, 26 May 2026 00:35:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48273590</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48273590</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48273590</guid></item><item><title><![CDATA[New comment by EFLKumo in "Nobody cracks open a programming book anymore"]]></title><description><![CDATA[
<p>> The kid who is right now learning to code by chatting with an agent is not a worse programmer than I was at 12, hunched over Learning Perl, retyping examples that would not run because I missed a semicolon.<p>To be honest, I'm 17 y.o., I'm coding by chatting with an agent, but it seems like we can't tell the distinction too absolutely.<p>At the first time writing a React app, I forgot to name a file with a .tsx extension and I used .ts instead, then spotting ugly error lines across my JSX syntax, confusing and sharing with my friend, and laughing this little funny thing all the day.<p>I once spent the whole afternoon choosing a js linter, reading their docs and perceiving different tastes. In my early twelve-ties (uh this sounds funny too) I'm always arrested by configuring Windows PEs, installing different Linux distributions on my PC, etc. Today I still read tech books, alongside videos, articles and also chatbots. Chatbot is a new tool, but there's no doubt it cannot replace other media types and what they bring to us/me.<p>What may I express is that a natural interest in programming or computer things cannot really be overwhelmed by LLM things. I don't know how to use vim skillfully since I majorly used Windows at my early age and I'm not familiar with vim's logic, but this practically doesn't stop anything. I still found Linux's fantasy, at last. And same for LLMs.</p>
]]></description><pubDate>Tue, 26 May 2026 00:25:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48273518</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48273518</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48273518</guid></item><item><title><![CDATA[New comment by EFLKumo in "Microsoft Copilot Cowork Exfiltrates Files"]]></title><description><![CDATA[
<p>It's not the first time we hear about prompt injection attacks, and for sure it's the fault of Microsoft. Many talking about the prompt injection itself, whether Copilot should be able to defense prompt injections, etc. But that's not the problem.<p>OpenAI released their LLM-driven browser Atlas last year. Though their team is brilliant (<a href="https://openai.com/index/hardening-atlas-against-prompt-injection/" rel="nofollow">https://openai.com/index/hardening-atlas-against-prompt-inje...</a>), there has been a number of succeeded injection attacks.<p>IMO the real vulnerability is located at the "Act" part of "ReAct" (reasoning and action) agent framework.<p>> “[Copilot] Cowork asks for your permission before taking sensitive actions...” ... when the recipient is the active user, these actions execute immediately without requiring human approval (users do not have a setting to modify this behavior).<p>> Copilot Cowork can retrieve ‘pre-authenticated download links’ for files the user has access to, which allow anyone who opens the link to download that file.<p>> Microsoft Copilot Cowork has read access to essentially any resource a user does through Microsoft Graph. As such, the primary mechanism to reduce the blast radius of attacks like this is to restrict excessive permissioning across one’s Microsoft ecosystem.<p>Take it easy. Inside the whole attack flow, Microsoft gives Cowork unrestricted access and the ability to bypass approvals. I don't find much problem with LLMs here. It's said the attack is also a threat for Opus 4.7, but I've found several times Opus 4.7 forbidding context7.com's "prompt injections" only requiring opus to ask me creating an context7 API key to get more requests for free. From my personal experience, such models indeed are trained to perceive injections, but these injections could mask themselves as sth like Agent Skills, and there are always ways to win as red teams.<p>We may not lay our hope too much on defense of injections, but concentrating on restricting LLM's permissions. The popular usage of CLIs in agents' (especially coding agents) workflow has also concerned me since most cli tools an agent can access actually have the same permissions with users.</p>
]]></description><pubDate>Tue, 26 May 2026 00:01:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=48273312</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48273312</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48273312</guid></item><item><title><![CDATA[New comment by EFLKumo in "you_can::turn_off_the_borrow_checker"]]></title><description><![CDATA[
<p>Yes. It assumes author of the macro guarantees the safety. Common cases are not adding unsafe{} and leaving this to user, relying on audit tools or [highlighters](<a href="https://lukaswirth.dev/posts/semantic-unsafe/" rel="nofollow">https://lukaswirth.dev/posts/semantic-unsafe/</a>), etc. However, it's indeed allowed to silently add unsafe blocks in macros. I'm not working on rust frequently btw, mistakes may exist.</p>
]]></description><pubDate>Mon, 25 May 2026 13:15:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48266466</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48266466</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48266466</guid></item><item><title><![CDATA[New comment by EFLKumo in "you_can::turn_off_the_borrow_checker"]]></title><description><![CDATA[
<p>though said for education purpose, keep finding these boundary-pushings playful. I can recall early days arrested by "several ways to access private members in C++" lol</p>
]]></description><pubDate>Mon, 25 May 2026 13:08:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=48266409</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48266409</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48266409</guid></item><item><title><![CDATA[How to scan for vulnerabilities with GitHub Security Lab's AI-powered framework]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.blog/security/how-to-scan-for-vulnerabilities-with-github-security-labs-open-source-ai-powered-framework/">https://github.blog/security/how-to-scan-for-vulnerabilities-with-github-security-labs-open-source-ai-powered-framework/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48265757">https://news.ycombinator.com/item?id=48265757</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 25 May 2026 11:47:56 +0000</pubDate><link>https://github.blog/security/how-to-scan-for-vulnerabilities-with-github-security-labs-open-source-ai-powered-framework/</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48265757</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48265757</guid></item><item><title><![CDATA[New comment by EFLKumo in "-​-dangerously-skip-reading-code"]]></title><description><![CDATA[
<p>I once thought about this and found that n-shots makes greater influences on LLMs. In other words, in a repo with good code quality and architecture (which offers good n-shots) and on a task with clear instructions and goals, LLM's output seems reliable enough, which meets your opinion. And n-shots is always better than relying on instruction following, instruction following mentioned in the article ("specifications") as an approach facing LLM's productivity, so imo the idea you suggested is another probability against/comparing with the article as well.</p>
]]></description><pubDate>Mon, 25 May 2026 04:10:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48263319</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48263319</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48263319</guid></item><item><title><![CDATA[New comment by EFLKumo in "Defeating Git Rigour Fatigue with Jujutsu"]]></title><description><![CDATA[
<p>This remind me of [jj megamerge](<a href="https://isaaccorbrey.com/notes/jujutsu-megamerges-for-fun-and-profit" rel="nofollow">https://isaaccorbrey.com/notes/jujutsu-megamerges-for-fun-an...</a>). jj allows concentrating on developing while leaving things for vcs alone, as well as solving vcs things (conflicts) at very beginning (megamerge). Really good.</p>
]]></description><pubDate>Sun, 24 May 2026 23:35:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=48262099</link><dc:creator>EFLKumo</dc:creator><comments>https://news.ycombinator.com/item?id=48262099</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48262099</guid></item></channel></rss>