<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: NoahZuniga</title><link>https://news.ycombinator.com/user?id=NoahZuniga</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 15 Jun 2026 08:27:10 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=NoahZuniga" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by NoahZuniga in "Statement on US government directive to suspend access to Fable 5 and Mythos 5"]]></title><description><![CDATA[
<p>I didn't say if LLMs are allowed do that, I said that humans are allowed to do that.</p>
]]></description><pubDate>Sat, 13 Jun 2026 10:37:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48515768</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48515768</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48515768</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Statement on US government directive to suspend access to Fable 5 and Mythos 5"]]></title><description><![CDATA[
<p>Yes!<p>Creating personal copies of copyrighted works are allowed. (Also, libraries really don't mind if you take pictures of the content of works they have.)</p>
]]></description><pubDate>Sat, 13 Jun 2026 08:22:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48514851</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48514851</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48514851</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Ask HN: Favorite text heavy blogs that are a joy to read?"]]></title><description><![CDATA[
<p>I really like <a href="https://dynomight.net/" rel="nofollow">https://dynomight.net/</a></p>
]]></description><pubDate>Fri, 12 Jun 2026 20:51:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48509301</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48509301</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48509301</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Ask HN: Is anyone shorting the overspend in AI yet?"]]></title><description><![CDATA[
<p>The market can stay irrational longer than you can stay solvent.</p>
]]></description><pubDate>Thu, 11 Jun 2026 08:41:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=48487853</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48487853</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48487853</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Claude Fable 5"]]></title><description><![CDATA[
<p>Well they're not fully charging you. You get opus 4.8 pricing when it falls back to opus 4.8. Also you can disable it (and it seems like it's off by default in the api)</p>
]]></description><pubDate>Wed, 10 Jun 2026 09:22:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48473683</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48473683</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48473683</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Ask HN: Why are so many Show HNs being flagged?"]]></title><description><![CDATA[
<p>that wasn't a show HN?<p>> There was a thread yesterday<p>said thread was: CT scans of BYD car parts (<a href="https://news.ycombinator.com/item?id=48375824">https://news.ycombinator.com/item?id=48375824</a>)</p>
]]></description><pubDate>Wed, 03 Jun 2026 23:17:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48391426</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48391426</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48391426</guid></item><item><title><![CDATA[New comment by NoahZuniga in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>> The only way to allow this behavior is to have the two web pages in the different origins cooperate with each other using the Window.postMessage() API<p>Small nitpick, but it's also possible to communicate by changing the location.anchor property (by either the iframe or its parent window.)</p>
]]></description><pubDate>Wed, 03 Jun 2026 09:38:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=48381866</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48381866</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48381866</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Danish Pension Blacklists SpaceX over 'Catastrophic Governance'"]]></title><description><![CDATA[
<p>well I agree, my point is that ie 2007-2021 is better than 2009-2021, and with my example I meant to illustrate that the best performers will perform less well and the poor performers perform better if you include 2008, showing that this does in fact matter.</p>
]]></description><pubDate>Sat, 30 May 2026 18:02:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=48339013</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48339013</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48339013</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Danish Pension Blacklists SpaceX over 'Catastrophic Governance'"]]></title><description><![CDATA[
<p>Judging a pension fund by how it performs in a bull market seems wrong. Like their main job is to limit your downside from market crashes (if they're not doing that then they offer nothing compared to an index fund), so its strange to not include 2008 crisis (or .com bubble popping).<p>Checking this shows that the top 2 performers in this graph lost more money (~8%) in 2008 than the bottom 2 (~2%)</p>
]]></description><pubDate>Sat, 30 May 2026 13:32:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48335988</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48335988</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48335988</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Google Chrome adds session cookie theft protection for all users"]]></title><description><![CDATA[
<p>* only on sites that implement a new api</p>
]]></description><pubDate>Sat, 30 May 2026 02:33:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48331864</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48331864</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48331864</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Are we self-sovereign PKI yet?"]]></title><description><![CDATA[
<p>The entire premise of this article is wrong!<p>> Signal ships safety numbers because the platform might one day be compelled or compromised, and the architecture is meant to let you catch that. But almost nobody verifies<p>We have a solution to this! Wa and Signal both have key transparency. This uses cryptography to make it possible to verify that everyone is getting the same data[1]. Now your phone can check the keys listed under your username are all keys you made (and your contacts can check this too!)<p>Edit 2 (quick note): if you don't trust the app on your phone to verify your keys, then you also can't trust it to show you a valid security code, or do what the author proposed in their product spaces.<p>Edit:<p>It's also striking how similar (in essence) the current solution is to the solution the author is working on/proposing:<p>> Spaces takes this shape. (Disclosure: I work on it.) Issued names live in a binary Merkle trie. The root of that trie is committed to Bitcoin’s chain, used here as a widely-replicated, hard-to-rewrite timestamp service<p>Fundamentally the same: the name is your phone number (or alternatively in signal your username), key transparency also uses a merkle tree based structure. Instead of using the bitcoin chain as a consensus mechanism, key transparency implementations generally use trusted witnesses: simple servers that promise to only sign consistent versions of the merkle tree. This is better! Because essentially no clients (phones) have a local copy of the bitcoin chain, so you still have to trust a server to tell you what was posted in the bitcoin block.<p>For the rest current key transparency systems also have verifiers, which verify that the append only merkle tree is transformed into a dictionary legitimately (this is pretty compute intensive, and needs to be done by a trusted server too. WA currently contracts cloudflare as their only verifier). Spaces would also have to do this to be secure if they reach any scale, but this isn't mentioned in TFA.<p>Also a message for the author: Key transparency is cool tech, but you shouldn't reinvent the wheel! I hope you research current solutions more! You can ask questions in the transparency.dev slack (<a href="https://transparency.dev/slack/" rel="nofollow">https://transparency.dev/slack/</a>)<p>[1]: There are a bunch of details here. You need to check that everyone _is_ actually getting the same data. There are multiple ways to do this. The transparency ecosystem has generally stabilized on a system where you have trusted verifiers. But anyone (yes you!) can setup a server that can help monitor the chat app and trusted verifiers.</p>
]]></description><pubDate>Tue, 26 May 2026 16:46:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=48282256</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48282256</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48282256</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Netherlands blocks US takeover of vital digital supplier"]]></title><description><![CDATA[
<p>No I checked this. They aren't.</p>
]]></description><pubDate>Tue, 26 May 2026 16:31:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48282011</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48282011</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48282011</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Netherlands blocks US takeover of vital digital supplier"]]></title><description><![CDATA[
<p>Logius is actually not a company but a part of the dutch (national) goverment.</p>
]]></description><pubDate>Tue, 26 May 2026 13:53:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48279917</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48279917</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48279917</guid></item><item><title><![CDATA[New comment by NoahZuniga in "What Is Date:Italy?"]]></title><description><![CDATA[
<p>Even with CAA records, any CA can still create a cert for any website. So if you're worried about an untrustworthy CA, then this won't help you.<p>It could make it less likely for a CA with buggy code to accidentally issue a cert for your domain.</p>
]]></description><pubDate>Mon, 18 May 2026 21:06:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=48185622</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48185622</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48185622</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Kickstarter is forced to ban adult content by payment processors"]]></title><description><![CDATA[
<p>pornhub doesn't even accept payment via credit card. A while back they were kicked off due to there being too much CSAM.</p>
]]></description><pubDate>Wed, 13 May 2026 18:42:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48125750</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=48125750</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48125750</guid></item><item><title><![CDATA[New comment by NoahZuniga in "LinkedIn scans for 6,278 extensions and encrypts the results into every request"]]></title><description><![CDATA[
<p>Even better! Moving to firefox fixes this.<p>Chrome for some reason (still!) gives extensions static ids. Firefox has the id change per firefox instance.</p>
]]></description><pubDate>Thu, 30 Apr 2026 20:54:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=47968102</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=47968102</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47968102</guid></item><item><title><![CDATA[New comment by NoahZuniga in "We found a stable Firefox identifier linking all your private Tor identities"]]></title><description><![CDATA[
<p>The real reason is that fingerprint.com's selling point is tracking over longer periods (months, their website claims), and this doesn't help them with that.</p>
]]></description><pubDate>Wed, 22 Apr 2026 20:22:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=47868797</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=47868797</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47868797</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Changes to GitHub Copilot individual plans"]]></title><description><![CDATA[
<p>If you cancel you get a prorated refund</p>
]]></description><pubDate>Wed, 22 Apr 2026 11:56:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=47862305</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=47862305</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47862305</guid></item><item><title><![CDATA[New comment by NoahZuniga in "Ask HN: Does magic link authentication use HTML canvassing?"]]></title><description><![CDATA[
<p>Well, password practically always has reset my password emails. So you have the "off-loading" problem either way.</p>
]]></description><pubDate>Tue, 21 Apr 2026 16:37:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=47851158</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=47851158</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47851158</guid></item><item><title><![CDATA[New comment by NoahZuniga in "A Roblox cheat and one AI tool brought down Vercel's platform"]]></title><description><![CDATA[
<p>I'd instead blame the IT department that let users install arbitrary software.</p>
]]></description><pubDate>Tue, 21 Apr 2026 10:56:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=47847106</link><dc:creator>NoahZuniga</dc:creator><comments>https://news.ycombinator.com/item?id=47847106</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47847106</guid></item></channel></rss>