<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: Manouchehri</title><link>https://news.ycombinator.com/user?id=Manouchehri</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 06 Apr 2026 04:44:43 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=Manouchehri" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by Manouchehri in "Decisions that eroded trust in Azure – by a former Azure Core engineer"]]></title><description><![CDATA[
<p>Correct.</p>
]]></description><pubDate>Fri, 03 Apr 2026 14:20:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=47626959</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=47626959</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47626959</guid></item><item><title><![CDATA[New comment by Manouchehri in "Decisions that eroded trust in Azure – by a former Azure Core engineer"]]></title><description><![CDATA[
<p>I would guess that Copilot uses Azure OpenAI.<p>In my small sample size of a bit over a 100 accidentally leaked messages, many/most of them are programming related questions.<p>It's easy to brush it off as just LLM hallucinations. Azure OpenAI actually shows me how many input tokens were billed, and how many input tokens checked by the content filter. For these leaked responses, I was only billed for 8 input tokens, yet the content filter (correctly) checked >40,000 chars of input token (which was my actual prompt's size).</p>
]]></description><pubDate>Fri, 03 Apr 2026 12:43:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=47626042</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=47626042</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47626042</guid></item><item><title><![CDATA[New comment by Manouchehri in "Decisions that eroded trust in Azure – by a former Azure Core engineer"]]></title><description><![CDATA[
<p>Azure sent them to me like that.<p>I only saw two companies mentioned in the messages I got back. I reached out to both to try to confirm, but never heard back.</p>
]]></description><pubDate>Fri, 03 Apr 2026 12:39:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=47625998</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=47625998</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47625998</guid></item><item><title><![CDATA[New comment by Manouchehri in "Decisions that eroded trust in Azure – by a former Azure Core engineer"]]></title><description><![CDATA[
<p>Yeah, I saw over 100 leaked messages.<p>Fun ones include people trying to get GPT to write malware.<p><pre><code>  I can’t help create software that secretly runs in the background, captures user activity, and exfiltrates it. That would meaningfully facilitate malware/spyware behavior.

  If your goal is legitimate monitoring, security testing, or administration on systems you own and where users have given informed consent, I can help with safe alternatives, for example:

  - Build a visible Windows tray app that:
    - clearly indicates it is running
    - requires explicit opt-in
    - stores logs locally
    - uploads only to an approved internal server over TLS
  - Create an endpoint telemetry agent for:
    - process inventory
    - service health
    - crash reporting
    - device posture/compliance
  - Implement parental-control or employee-monitoring software with:
    - consent banners
    - audit logs
    - uninstall instructions
    - privacy controls and data retention settings

  I can also help with defensive or benign pieces individually, such as:

  - C# Windows Service or tray application structure
  - Secure HTTPS communication with certificate validation
  - Code signing and MSI installer creation
  - Local encrypted logging
  - Consent UI and settings screens
  - Safe process auditing using official Windows APIs
  - How to send authorized telemetry to your own server

  If you want, I can provide a safe template for a visible C# tray app that periodically sends approved system-health telemetry to your server</code></pre></p>
]]></description><pubDate>Fri, 03 Apr 2026 03:02:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=47622774</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=47622774</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47622774</guid></item><item><title><![CDATA[New comment by Manouchehri in "Decisions that eroded trust in Azure – by a former Azure Core engineer"]]></title><description><![CDATA[
<p>I've seen Azure OpenAI leak other customer's prompt responses to us under heavy load.<p><a href="https://x.com/DaveManouchehri/status/2037001748489949388" rel="nofollow">https://x.com/DaveManouchehri/status/2037001748489949388</a><p>Nobody seems to care.</p>
]]></description><pubDate>Fri, 03 Apr 2026 01:18:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=47622265</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=47622265</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47622265</guid></item><item><title><![CDATA[New comment by Manouchehri in "We tasked Opus 4.6 using agent teams to build a C Compiler"]]></title><description><![CDATA[
<p>There's only very niche fields where closed-source code quality is often better than open-source code.<p>Exploits and HFT are the two examples I can think of. Both are usually closed source because of the financial incentives.</p>
]]></description><pubDate>Fri, 06 Feb 2026 02:15:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=46908150</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=46908150</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46908150</guid></item><item><title><![CDATA[New comment by Manouchehri in "Show HN: Aroma: Every TCP Proxy Is Detectable with RTT Fingerprinting"]]></title><description><![CDATA[
<p>> BrighData offer H3/QUIC but only in beta and you have to contact their sales team as far as I'm aware.<p>That's what I thought too, but it's working for me. (I've sent a lot of tickets, maybe they've put our account as something special without telling me, but doubt it.)<p>> If you wanna play around with it, email me and I'll get you some credit.<p>Done, emailed! :) Thanks!<p>> The proxy industry is full of another 100 companies saying they offer H3/QUIC, when they mean UDP proxying using SOCKS.<p>Out of the large players I've tested, none actually seem to even support SOCKS5's UDP ASSOCIATE. (I have not tested PingProxies yet.)<p>> I suppose the knowledge gap and what customers care about (protocol to end target) is very different to what I care about (being right/protocol to the proxy server).<p>I think there's a knowledge gap between the people making the sales landing pages, and the folks who actually run/maintain the proxy servers. There's some large vendors that advertise UDP support (for residential and/or mobile proxies) that I have yet to actually see working.</p>
]]></description><pubDate>Tue, 30 Dec 2025 03:27:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=46429213</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=46429213</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46429213</guid></item><item><title><![CDATA[New comment by Manouchehri in "Show HN: Aroma: Every TCP Proxy Is Detectable with RTT Fingerprinting"]]></title><description><![CDATA[
<p>Would you be open to offering MASQUE proxying? I started to as support to GOST, been testing with Bright Data (only for UDP sadly, not TCP), but would love to see others add support so I could test with more than just 1 vendor.<p><a href="https://github.com/go-gost/x/pull/75" rel="nofollow">https://github.com/go-gost/x/pull/75</a><p><a href="https://github.com/go-gost/x/pull/76" rel="nofollow">https://github.com/go-gost/x/pull/76</a></p>
]]></description><pubDate>Tue, 30 Dec 2025 02:14:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=46428721</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=46428721</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46428721</guid></item><item><title><![CDATA[New comment by Manouchehri in "Show HN: Aroma: Every TCP Proxy Is Detectable with RTT Fingerprinting"]]></title><description><![CDATA[
<p>Interesting!<p>So far I've only seen Bright Data (among the large players) offer UDP proxying over QUIC/HTTP3, but that's pretty limiting since less than half of sites have HTTP/3 enabled to begin with.</p>
]]></description><pubDate>Tue, 30 Dec 2025 02:11:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=46428701</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=46428701</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46428701</guid></item><item><title><![CDATA[New comment by Manouchehri in "Show HN: Aroma: Every TCP Proxy Is Detectable with RTT Fingerprinting"]]></title><description><![CDATA[
<p>Would a similar technique work for tunnels through QUIC?</p>
]]></description><pubDate>Tue, 30 Dec 2025 01:30:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=46428423</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=46428423</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46428423</guid></item><item><title><![CDATA[New comment by Manouchehri in "Is Northern Virginia still the least reliable AWS region?"]]></title><description><![CDATA[
<p>I believe I was using us-east-2.<p>In the early days of cross-region inference, less people were using it, and there was basically no monitoring (and/or alerting) on Amazon's side.<p>The cross-region and global inference routing is... odd at times.</p>
]]></description><pubDate>Mon, 29 Dec 2025 23:06:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=46427112</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=46427112</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46427112</guid></item><item><title><![CDATA[IP and Domain, One Cert: Let's Encrypt Short-Lived Certificates]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.ai.moda/en/blog/ip-and-domain-one-cert-lets-encrypt">https://www.ai.moda/en/blog/ip-and-domain-one-cert-lets-encrypt</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46426964">https://news.ycombinator.com/item?id=46426964</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 29 Dec 2025 22:54:00 +0000</pubDate><link>https://www.ai.moda/en/blog/ip-and-domain-one-cert-lets-encrypt</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=46426964</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46426964</guid></item><item><title><![CDATA[New comment by Manouchehri in "Is Northern Virginia still the least reliable AWS region?"]]></title><description><![CDATA[
<p>Yeah, I was often the single source of reporting Claude outages (or even missing support completely) on less commonly used Amazon Bedrock regions.</p>
]]></description><pubDate>Wed, 24 Dec 2025 06:16:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=46372975</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=46372975</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46372975</guid></item><item><title><![CDATA[New comment by Manouchehri in "Ask HN: What Are You Working On? (December 2025)"]]></title><description><![CDATA[
<p>I wrote a Telegram translate bot that uses Opus 4.5 for outgoing messages.<p>Super simple, yet it’s already good enough that I’ve had detailed conversations and debates in languages that I don’t speak at all.<p><a href="https://github.com/aimoda/telegram-auto-translate" rel="nofollow">https://github.com/aimoda/telegram-auto-translate</a></p>
]]></description><pubDate>Mon, 15 Dec 2025 01:19:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=46269169</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=46269169</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46269169</guid></item><item><title><![CDATA[New comment by Manouchehri in "Control LLM Spend and Access with any-LLM-gateway"]]></title><description><![CDATA[
<p>LiteLLM was good in the early days. I ran into more features than bugs. Sadly in the past year or so, I run into more bugs than features.</p>
]]></description><pubDate>Thu, 20 Nov 2025 02:45:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=45988267</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=45988267</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45988267</guid></item><item><title><![CDATA[New comment by Manouchehri in "Cloudflare Email Service: private beta"]]></title><description><![CDATA[
<p>I documented the process of using AWS SES from a Cloudflare Worker about a year ago.<p><a href="https://www.ai.moda/en/blog/ses-emails-from-workers" rel="nofollow">https://www.ai.moda/en/blog/ses-emails-from-workers</a><p>Hopefully it’s helpful next time for you!</p>
]]></description><pubDate>Fri, 26 Sep 2025 11:14:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=45385165</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=45385165</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45385165</guid></item><item><title><![CDATA[New comment by Manouchehri in "Want to piss off your IT department? Are the links not malicious looking enough?"]]></title><description><![CDATA[
<p>I used to own spyware.tk until I forgot to renew it and the registrar disappeared. Sad I had to let that one go.</p>
]]></description><pubDate>Fri, 19 Sep 2025 05:35:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=45298266</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=45298266</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45298266</guid></item><item><title><![CDATA[New comment by Manouchehri in "Cloudflare service outage June 12, 2025"]]></title><description><![CDATA[
<p>I don’t think Cloudflare is using B2; Backblaze isn’t listed as a sub-processor.<p><a href="https://www.cloudflare.com/gdpr/subprocessors/cloudflare-services/" rel="nofollow">https://www.cloudflare.com/gdpr/subprocessors/cloudflare-ser...</a></p>
]]></description><pubDate>Fri, 13 Jun 2025 06:03:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=44266069</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=44266069</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44266069</guid></item><item><title><![CDATA[New comment by Manouchehri in "Sora API Pricing (On Azure OpenAI)"]]></title><description><![CDATA[
<p>I found the pricing for Sora and thought it might be useful to share with others (as Microsoft nor OpenAI has updated their websites with it yet).</p>
]]></description><pubDate>Wed, 04 Jun 2025 17:07:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=44182968</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=44182968</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44182968</guid></item><item><title><![CDATA[Sora API Pricing (On Azure OpenAI)]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.ai.moda/en/blog/sora-pricing-on-azure-openai">https://www.ai.moda/en/blog/sora-pricing-on-azure-openai</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44182967">https://news.ycombinator.com/item?id=44182967</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Wed, 04 Jun 2025 17:07:44 +0000</pubDate><link>https://www.ai.moda/en/blog/sora-pricing-on-azure-openai</link><dc:creator>Manouchehri</dc:creator><comments>https://news.ycombinator.com/item?id=44182967</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44182967</guid></item></channel></rss>