<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: Tharre</title><link>https://news.ycombinator.com/user?id=Tharre</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 13 Aug 2026 19:30:15 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=Tharre" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by Tharre in "DeepSeek API Pricing Update"]]></title><description><![CDATA[
<p>System RAM and/or NVMe storage still has a real cost. And swapping out the context between VRAM and system RAM / NVMe still consumes bandwidth.<p>I don't have a clue on what the real cost to inference providers comes out to, but it seems really weird that there would be such a big gap, in what should be a pretty competitive market.</p>
]]></description><pubDate>Thu, 13 Aug 2026 15:52:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=49287854</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=49287854</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49287854</guid></item><item><title><![CDATA[New comment by Tharre in "DeepSeek API Pricing Update"]]></title><description><![CDATA[
<p>How could that possibly work? Deepseek was undercutting every other provider by an order of magnitude on cached tokens.<p>Do they just set a super low caching time and hope that drops effective cache rates low enough? Do all other providers somehow overcharge by that much? Are they just going to sell it as a loss leader?</p>
]]></description><pubDate>Thu, 13 Aug 2026 15:29:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=49287496</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=49287496</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49287496</guid></item><item><title><![CDATA[New comment by Tharre in "Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot"]]></title><description><![CDATA[
<p>Why would you voluntarily pretend to be a AI bot, when those have already a much higher chance of being blocked? Seems holly unproductive.<p>Best hypothesis I can come up with is to somehow make the AI companies look bad, but they seem to be doing an excellent job at that themselves already by scraping everyone hundreds of times per hour over and over.</p>
]]></description><pubDate>Wed, 12 Aug 2026 16:52:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=49275344</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=49275344</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49275344</guid></item><item><title><![CDATA[New comment by Tharre in "I'm a USB-C Maximalist"]]></title><description><![CDATA[
<p>You're saving a fraction of a cent per device, while banking on customers not sending it back as defective because it didn't charge when they tried it with a random cable.<p>If it is a deliberate choice, it's a really, really dumb one.</p>
]]></description><pubDate>Wed, 15 Jul 2026 02:58:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48915712</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48915712</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48915712</guid></item><item><title><![CDATA[New comment by Tharre in "I'm a USB-C Maximalist"]]></title><description><![CDATA[
<p>They skipped out on literally 2 resistors. That's it, that's all that is required for real USB-C charging.</p>
]]></description><pubDate>Wed, 15 Jul 2026 01:43:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48915240</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48915240</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48915240</guid></item><item><title><![CDATA[New comment by Tharre in "I'm a USB-C Maximalist"]]></title><description><![CDATA[
<p>No? Passive fully-featured USB-C cables had the same amount of wires and active components, which really is just the e-marker chip, since day one. The same 5 Gbps cable can now do 20 Gbps if the cable was made well enough.<p>Active cables are a different story of course, but that's the same for HDMI cables.</p>
]]></description><pubDate>Wed, 15 Jul 2026 01:42:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48915233</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48915233</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48915233</guid></item><item><title><![CDATA[New comment by Tharre in "I'm a USB-C Maximalist"]]></title><description><![CDATA[
<p>The "cost" they're cutting of course being 2 simple resistors, that cost absolutely nothing. So less of a executive decision and more a case of whoever designed the board didn't do a quick google search to figure out how the connector works.</p>
]]></description><pubDate>Wed, 15 Jul 2026 01:18:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=48915071</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48915071</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48915071</guid></item><item><title><![CDATA[New comment by Tharre in "Running local models is good now"]]></title><description><![CDATA[
<p>I've been running Qwen3.6-35B-A3B (and 3.5 previously) locally and it's a great model for many small tasks, probably a significant chunk of what most normal people are using LLMs for right now.<p>But for coding in a harness? In my experience it's unusable even for small projects. It just gets hard stuck at every little problem, wasting hundreds of thousands of tokens trying to make a convoluted solution work instead of doing the obvious thing. Or it will spend hours trying to reason through a fairly simple code flow, incrementally adding debug print statements, only to get confused by the output and then editing completely unrelated code that it convinced itself is the problem.<p>I've tried instead giving Sonnet the problem description and code and have it come up with a detailed plan that Qwen should implement, but doing that actually consumes a significant amount of tokens compared to just telling it to implement everything, and the results are honestly not that much better. There are just too often subtle issues with the plan that Qwen doesn't recognize when implementing, but make the resulting solution it comes up with unusable.</p>
]]></description><pubDate>Tue, 16 Jun 2026 16:12:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48557538</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48557538</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48557538</guid></item><item><title><![CDATA[New comment by Tharre in "EV demand up 50% in France and Germany since Iran war"]]></title><description><![CDATA[
<p>I don't know what kind of straw man you built up in your head, but I can assure you I don't believe in any of that.</p>
]]></description><pubDate>Fri, 12 Jun 2026 23:00:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=48510389</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48510389</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48510389</guid></item><item><title><![CDATA[New comment by Tharre in "EV demand up 50% in France and Germany since Iran war"]]></title><description><![CDATA[
<p>And demand will probably go up a lot further still. Right now fuel prices are kept artificially low by every country releasing their strategic reserves, but these will run out at some point.<p>Europe is heading into the worst energy crisis since at least the 1970s, possibly worse. And yet very little is happening to prepare for it. Definitely some fun times ahead.</p>
]]></description><pubDate>Fri, 12 Jun 2026 21:59:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48509932</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48509932</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48509932</guid></item><item><title><![CDATA[New comment by Tharre in "AUR packages compromised with Infostealer and Rootkit"]]></title><description><![CDATA[
<p>> If a PKGBUILD is running a command to download something not listed in source, that's a sign that something nefarious could be happening, and such a PKGBUILD absolutely requires careful human review.<p>First, although I don't disagree with that being how it should work, in a world where everyone relies on npm, cargo, etc. to handle dependencies this scenario is not realistic.<p>Second and more importantly, it doesn't really change much if it's listed in the sources or not. You can patch a startup file to download something as soon as the program is executed, including checks if it's currently running in a virtual environment. You cannot statically detect that the PKGBUILD contains something like that, antivirus software has been trying to do just that for decades and their detection is still basically useless.<p>> A less than 100% reliable mechanism sure beats the current situation which is "wait for users report on the forum that they have been pwn3d".<p>The current situation is users are expected to review PKGBUILDs before they install them. And you're ignoring that implementing any mechanism has a cost. I don't know if it's worth it or not, but it's not unrealistic that it would be a ton of effort for no barely any gain.</p>
]]></description><pubDate>Fri, 12 Jun 2026 17:59:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48507335</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48507335</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48507335</guid></item><item><title><![CDATA[New comment by Tharre in "AUR packages compromised with Infostealer and Rootkit"]]></title><description><![CDATA[
<p>> You do realize that the people relying on the service also get served malware, right? The service is already disrupted.<p>Huh? No they don't. I'm not sure what part of the attack your misunderstood, but most people are going to be completely unaffected by this. None of the infrastructure or anything like that got compromised. I updated my AUR packages 2 hours ago, and didn't get served any malware.<p>Again, there's probably some kind of malware on npmjs at any given time. You don't just shutdown the entire server because of that, that's madness.</p>
]]></description><pubDate>Fri, 12 Jun 2026 17:39:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48507085</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48507085</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48507085</guid></item><item><title><![CDATA[New comment by Tharre in "AUR packages compromised with Infostealer and Rootkit"]]></title><description><![CDATA[
<p>From the concrete example someone posted below, you'd see that a post-install hook exists, literally this line:<p>> install=toggldesktop-bin-deps.install<p>And the toggldesktop-bin-deps.install contains this:<p>> post_install() {{<p>>   cd /tmp<p>>   bun add axios uuid ora js-digest<p>> }}<p>Seeing any install hook download anything from the web should immediately raise alarms when reviewing, even before you checkout what packages it actually installs.</p>
]]></description><pubDate>Fri, 12 Jun 2026 17:27:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48506921</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48506921</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48506921</guid></item><item><title><![CDATA[New comment by Tharre in "AUR packages compromised with Infostealer and Rootkit"]]></title><description><![CDATA[
<p>"Hey, let's take down all of npm, because there's a package that installs something malicious, and some people may install it without reviewing it first. The thousands of other people relying on this service can wait."<p>Do you not realize how crazy of an request that is?</p>
]]></description><pubDate>Fri, 12 Jun 2026 17:08:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48506674</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48506674</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48506674</guid></item><item><title><![CDATA[New comment by Tharre in "AUR packages compromised with Infostealer and Rootkit"]]></title><description><![CDATA[
<p>Some of these have corporate backing and/or better funding and thus more manpower to review things, but yeah it essentially applies to all of them. It's no accident that there's news about a new npm package being compromised every other week.<p>Ultimately, the way we're doing permissions on the OS level is fundamentally broken on desktop OSes, and we're increasingly feeling the effects of that. Ideally everything should be sandboxed by default, and only given access to it's own files, instead of everything the user has.<p>But we're a long way away from that, and that's not something a single project could enforce.</p>
]]></description><pubDate>Fri, 12 Jun 2026 16:10:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=48505933</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48505933</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48505933</guid></item><item><title><![CDATA[New comment by Tharre in "AUR packages compromised with Infostealer and Rootkit"]]></title><description><![CDATA[
<p>I assume you're talking about the "remote: " messages? I've only ever seen those on push operations, not sure if they're even available for clone.<p>Maybe they'd be an option, but then the whole "making sure they've read the message before proceeding" part goes out the window.</p>
]]></description><pubDate>Fri, 12 Jun 2026 16:05:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48505874</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48505874</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48505874</guid></item><item><title><![CDATA[New comment by Tharre in "AUR packages compromised with Infostealer and Rootkit"]]></title><description><![CDATA[
<p>Any and all modifications to PKGBUILDs may download something and execute it, that's the very purpose of PKGBUILDs, to download and install new software. I'm sure it would be great to have trusted reviewers look over every update, but the simple reality is that all of this work is done by volunteers and there isn't nearly enough manpower for it.<p>Maybe doing automated LLM reviews would help, but this is a large infrastructure investment. And it's not clear that it helps at all, after all models are quite vulnerable to prompt-injection type attacks.</p>
]]></description><pubDate>Fri, 12 Jun 2026 15:35:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48505487</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48505487</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48505487</guid></item><item><title><![CDATA[New comment by Tharre in "AUR packages compromised with Infostealer and Rootkit"]]></title><description><![CDATA[
<p>You seem confused about how the AUR works. There is no "client" like you're talking about that can show the user anything.<p>There are AUR helpers, but these are completely unaffiliated with arch and the people running the AUR. The canonical, recommended way of installing arch packages is cloning a git repo, reading through the sources and then building it with makepkg. There is no client there that could show the user anything.</p>
]]></description><pubDate>Fri, 12 Jun 2026 15:05:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=48505120</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48505120</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48505120</guid></item><item><title><![CDATA[New comment by Tharre in "AUR packages compromised with Infostealer and Rootkit"]]></title><description><![CDATA[
<p>No it shouldn't. You don't break everyone's workflow just because some people refuse to take basic security advise seriously.<p>> New API should have infrastructure for informing users and making sure they've read the message before proceeding.<p>How would that even work? AUR packages are just git repos, everything that AUR helpers are doing or not doing is not under the control of the arch maintainers.</p>
]]></description><pubDate>Fri, 12 Jun 2026 14:15:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48504427</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48504427</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48504427</guid></item><item><title><![CDATA[New comment by Tharre in "AUR packages compromised with Infostealer and Rootkit"]]></title><description><![CDATA[
<p>People need to get into their heads that the AUR is just a collection of user-produced PKGBUILDs.<p>You have to review the source of every PKGBUILD from the AUR you install, full stop. Yes that includes any updates. This really has always been the case; we've had discussion about this for well over a decade. People are always asking why there's no official AUR helper like yay - this is why.<p>A lot of people complain about Arch Linux being elitist, but the simple reality is it's a distro built for people who know what they are doing and don't need or want their hand held at every step of the way. This also means that if you break or compromise your own system by installing random AUR packages, it's your own damn fault.<p>All of that being said, the era of allowing anyone to adopt AUR packages might be coming to an end. If for no other reason then the effort of rolling back every affected package every time is too high. I'm not sure what the alternative would be, reviewing every adoption request seems like too much effort and wouldn't necessarily even help every time.</p>
]]></description><pubDate>Fri, 12 Jun 2026 14:09:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48504330</link><dc:creator>Tharre</dc:creator><comments>https://news.ycombinator.com/item?id=48504330</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48504330</guid></item></channel></rss>