<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: Twirrim</title><link>https://news.ycombinator.com/user?id=Twirrim</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 17 Aug 2026 07:09:36 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=Twirrim" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by Twirrim in "Stop sending me huge PRs; a rant"]]></title><description><![CDATA[
<p>I've had _some_ success by asking Codex write a full plan, broken up in to logical phases, complete with git commit points along the way.<p>It's probably not quite how I would approach doing git commits, but they're at least logical boundaries, and make narrative sense for a reviewer.</p>
]]></description><pubDate>Sat, 15 Aug 2026 01:33:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=49306733</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=49306733</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49306733</guid></item><item><title><![CDATA[New comment by Twirrim in "RISC-V: They Should Have Known Better"]]></title><description><![CDATA[
<p>> So you write software for a platform you know nothing about?<p>That's how a sizeable chunk of software is written and shipped.<p>Runtime detection of CPU features is very much a thing, and is in fact used extensively in software you use or interact with every single day.<p>Just as a quick example, OpenSSL's approach for x86_64 is OPENSSL_ia32cap<p><a href="https://docs.openssl.org/master/man3/OPENSSL_ia32cap/" rel="nofollow">https://docs.openssl.org/master/man3/OPENSSL_ia32cap/</a><p>This ensures (in theory, at least) that even if you're using your linux distribution's openssl library which is more generically targeted, you will get optimal/native runtime performance for your actual CPU.</p>
]]></description><pubDate>Sat, 15 Aug 2026 01:30:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=49306704</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=49306704</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49306704</guid></item><item><title><![CDATA[New comment by Twirrim in "Tl;Dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open"]]></title><description><![CDATA[
<p>Unsecured Firebase... yet again.<p>Plus the added bonus of unresponsive CTOs and employees that don't seem motivated or capable of taking ownership and at least driving things forward.</p>
]]></description><pubDate>Tue, 04 Aug 2026 16:29:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=49171179</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=49171179</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49171179</guid></item><item><title><![CDATA[New comment by Twirrim in "Increasing the lifespan of a bulb makes it worse in every other way"]]></title><description><![CDATA[
<p>I bought a whole bunch of GE LED bulbs figuring big name, probably more reliable.  Nope.  Diabolically bad.  Never again.</p>
]]></description><pubDate>Fri, 31 Jul 2026 22:44:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=49129386</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=49129386</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49129386</guid></item><item><title><![CDATA[New comment by Twirrim in "Neutrino-1 8B"]]></title><description><![CDATA[
<p>Independent testing of prismml suggest quite a capability drop off outside of their cherry picked benchmarks. I'll be curious to see what this model achieves though.</p>
]]></description><pubDate>Tue, 28 Jul 2026 06:02:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=49079975</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=49079975</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49079975</guid></item><item><title><![CDATA[New comment by Twirrim in "Scriptc by Vercel: TypeScript-to-Native compiler, no JavaScript engine in binary"]]></title><description><![CDATA[
<p>This is one of the things that is tiring me out the most. Previously people could have these "ohh shiny"  ideas and would lose steam before they could be implemented, especially in areas they're clueless about.<p>Now people can have these ideas, slop together an awful solution that works at a surface level, maybe, but will never really go places because the foundation is slopped with no party involved actually capable of thinking thing through. But hey we launched something so let's make lots of noise!  Oh look, a banana ... Sorry, what were we talking about?<p>There's an engineer on a team at work that I routinely engage with who slops together stuff so fast his team is basically exhausted all the time. They're stuck picking up a whole stream of pieces of crap because the engineer is incapable of actually doing the hard work of getting things to production because there's more "ohh, shiny" stuff they can spend tokens on, and their leadership aren't stepping in because it all looks terribly productive (it really isn't)</p>
]]></description><pubDate>Mon, 27 Jul 2026 05:31:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=49065499</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=49065499</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49065499</guid></item><item><title><![CDATA[New comment by Twirrim in "Startup founders urge U.S. government not to shut off Chinese open weight AI"]]></title><description><![CDATA[
<p>I poison their requests with crap, particularly because they were the worst offenders for sheer request rate.  The site has maybe a hundred pages, and I'd see them hit at a sustained 20 rps for weeks on end, same content being pulled over and over and over again.  Easily handled by my small server as it's static content, but the sheer arrogance (inadvertent or otherwise) pissed me off.<p>I'm not sure if they caught on, or just finally started behaving better, but after months of being served crap in my never ending labyrinth of auto-generated junk, they have stopped.</p>
]]></description><pubDate>Thu, 23 Jul 2026 16:42:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=49024512</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=49024512</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49024512</guid></item><item><title><![CDATA[New comment by Twirrim in "That post never existed. Stop listening to that thing"]]></title><description><![CDATA[
<p>It is depressing listening to engineers I respected, who now just parrot incorrect information at me from their LLM.<p>One smart engineer seems to have entirely offloaded all thinking and conversations to one, with just occasional editing. It's utterly bizarre to hold any conversation with him. It's one kind of rude thing if he was doing that to respond to me reaching out to him if he felt I'm not worth his time. It's a other when he's the one actively reaching out and asking my help with something.</p>
]]></description><pubDate>Tue, 21 Jul 2026 01:11:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48986952</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48986952</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48986952</guid></item><item><title><![CDATA[New comment by Twirrim in "Google Is Censoring Reviews of ICE Detention Centers"]]></title><description><![CDATA[
<p><a href="https://xkcd.com/1357/" rel="nofollow">https://xkcd.com/1357/</a></p>
]]></description><pubDate>Mon, 20 Jul 2026 16:08:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=48980806</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48980806</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48980806</guid></item><item><title><![CDATA[New comment by Twirrim in "AWS: Inaccurate Estimated Billing Data – $1.7 billion"]]></title><description><![CDATA[
<p>It's one of those "I hate it, but I get it" situations. Migrating metering over to a whole new format on AWS's scale is a scarily large undertaking.</p>
]]></description><pubDate>Mon, 20 Jul 2026 02:21:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48973724</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48973724</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48973724</guid></item><item><title><![CDATA[New comment by Twirrim in "AWS: Inaccurate Estimated Billing Data – $1.7 billion"]]></title><description><![CDATA[
<p>I got known as a "Chaos Monkey" at AWS, and have sort of carried on that title.  It's not exactly accurate, but tech stuff just breaks around me, and it's very, very rarely my fault.  I'm pretty cautious and resist any urge to "I wonder what happens..." with anything that could possibly have an effect beyond me.<p>The "Chaos Monkey" effect at AWS was so pronounced you could literally see on our sev2 count graph when it was my on-call week, because I'd get dramatically more sev2s than any other engineer.<p>The service I worked for at AWS was amazingly stable and reliable.  A large majority of the alarms that ever fired, fired because of problems with another service we depended on in some way.  This billing thing is a good example.  I was on-call when there was a major SQS outage in a region, through a DynamoDB outage, S3 outages, all sorts of stuff.  We used to joke that it would probably be a net benefit for AWS if I wasn't on-call, just so my spooky-at-a-distance wouldn't happen.<p>I eventually lost my "most sev2s in a week" record toward the end of my time there when someone else was on-call and DynamoDB had a major outage.  DynamoDB held all of our metadata so everything broke and every alarm we had fired over the space of a few hours.</p>
]]></description><pubDate>Sat, 18 Jul 2026 20:11:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48961842</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48961842</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48961842</guid></item><item><title><![CDATA[New comment by Twirrim in "AWS: Inaccurate Estimated Billing Data – $1.7 billion"]]></title><description><![CDATA[
<p>Sure, and I would expect the COE called out the operational aspects.  No one should have been in a position to be able to trigger that bug trivially (I don't remember if it came from a service, or if they injected the metering record themselves somehow, or quite what.  Way too long ago for that)<p>Most engineers with more than a few years of experience know better than to directly try a stunt like that in production, but they do often get there through painful personal experience.  I just wish I hadn't been one of the many that got to suffer from that engineer choosing to learn at that particular moment!</p>
]]></description><pubDate>Sat, 18 Jul 2026 00:21:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48953824</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48953824</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48953824</guid></item><item><title><![CDATA[New comment by Twirrim in "AWS: Inaccurate Estimated Billing Data – $1.7 billion"]]></title><description><![CDATA[
<p>I wonder if AWS billing still uses CSV files for passing data around.<p>IIRC it was one of my first on-calls at AWS over a decade ago now, and I got a page early evening because some stuff we did with billing records broke because some "smart" engineer thought it'd be a great idea to put an experimental record in with a description something like "I wonder what happens if I put, a comma in this field", into the production record.  I watched region after region fail the same way as the record spread.   That one engineer made a mess of lots of people's evenings.  They could have used the test endpoint, but no.  Much better to test in production!</p>
]]></description><pubDate>Fri, 17 Jul 2026 19:54:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=48951607</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48951607</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48951607</guid></item><item><title><![CDATA[New comment by Twirrim in "OnePlus halts operations in USA and Europe"]]></title><description><![CDATA[
<p>I got badly burned by the Pixel 5a, but especially with Google's support.  My wife and I both had 5a, and both died spectacularly right around the end of warranty period.  Mine ultimately got replaced under warranty and <i>that</i> replacement died the same way when I was on vacation less than a year later... which they refused to repair under warranty.<p>They put up such a shit show and had us run through so many hoops with my wife's phone that it ended up being out of warranty by the time they agreed it was broken and needed repaired.  The support experience was so painful I reluctantly let them get away with their bullshit, bought a new phone (oneplus) for my wife, and swore not to buy another Pixel phone despite having a <i>strong</i> preference for them and the pure Android experience.</p>
]]></description><pubDate>Thu, 16 Jul 2026 19:24:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48939074</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48939074</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48939074</guid></item><item><title><![CDATA[New comment by Twirrim in "Grok CLI uploaded the whole home directory to GCS"]]></title><description><![CDATA[
<p>I can secure myself first, so I'm never at fault.  I <i>never</i> want to be the one to accidentally break production.<p>Beyond that, I just keep advocating for more safe and secure approaches any opportunity I get.</p>
]]></description><pubDate>Tue, 14 Jul 2026 18:18:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48910975</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48910975</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48910975</guid></item><item><title><![CDATA[New comment by Twirrim in "Grok CLI uploaded the whole home directory to GCS"]]></title><description><![CDATA[
<p>I've been biasing towards VMs myself just out of caution, but maybe that's just extreme paranoia.<p>The way I look at it is similar to how I'd look at any hypothetical employee.  How do I ensure the agent only has access to the minimum possible they need to get their job done?<p>That means no access to git repositories (no pushes on my behalf means it can't accidentally nuke git history, something there is anecdotal evidence of agents doing).  It can make local changes in git only and I will take responsibility for pushing them.  No access to the wider internet beyond what I deem acceptable.  No permissions to access any internal APIs except what I provide (and not using my credentials).<p>In one case, I have a tool that has a set of dangerous commands alongside a large number of safe ones.  I don't even have it installed in the agent's VM.  I run an MCP that is a simple python wrapper around the tool on the host side, and expose it to the agent in the VM, so that it can only possibly run a strict safe subset that I can trust it with access.</p>
]]></description><pubDate>Mon, 13 Jul 2026 19:13:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=48897359</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48897359</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48897359</guid></item><item><title><![CDATA[New comment by Twirrim in "Grok CLI uploaded the whole home directory to GCS"]]></title><description><![CDATA[
<p>The easiest, most guaranteed way to isolate it is to run it in a VM or container where it literally can't do the wrong thing without some kind of full container or VM exit exploit.<p>It's not hard, it's trivial.  Most folks here are constantly working with containers.  You know how to run a container with a local directory mounted in it.<p>For myself, I've been using Lima (<a href="https://lima-vm.io/" rel="nofollow">https://lima-vm.io/</a>) to reduce even that little bit of extra work.  Lima works cross-platform leveraging native virtualisation or containerisation, and has some useful capabilities for using agents.</p>
]]></description><pubDate>Mon, 13 Jul 2026 16:15:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=48894867</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48894867</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48894867</guid></item><item><title><![CDATA[New comment by Twirrim in "Apache Shiro security framework releases 3.0.0"]]></title><description><![CDATA[
<p>Agreed. In my current job, across several large java code bases that have been developed over the last 12 years, the <i>only</i> place I've seen xml come into play is for maven. We've hundreds or more similar scale code bases and I don't think I've ever seen it in use beyond that, though I only occasionally look at those code bases.<p>No one is ever reaching for xml or even thinking about it.</p>
]]></description><pubDate>Thu, 09 Jul 2026 13:33:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=48845579</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48845579</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48845579</guid></item><item><title><![CDATA[New comment by Twirrim in "EVE Online's Carbon engine is now open source: Fenris Creations explains why"]]></title><description><![CDATA[
<p>>  I still consider it some of the best multiplayer experiences I've ever had though.<p>I played Eve for a few years as part of a corporation in Xetic and then Ascendant Frontier.<p>So many painful large battles (time dilation got added after I stopped playing), and some wild solo fights.  My favourite was the time I got caught solo in a T2 Interceptor, when out scouting.  We knew an attack was coming but didn't know where.<p>I screwed up, and found myself surrounded by 5 enemy player ships, with no possibility of escaping.  The only thing going for me was that I was in an inty, and they were in larger ships, so I could outmanouver them.  I knew I was done for.  If I flew away they'd be able to hit me as the only thing keeping me safe was my radial velocity (I was orbiting the ship faster than their weapons can rotate, but that only really works 1 on 1, to the other ships you're not moving quite as fast)<p>It was really just about how long I could hold out and making sure I was ready to warp the moment I got podded.  I constantly switched orbit between ships, trying to keep them close together so I could maintain high radial velocity, while taking pot shots at them and starting to chip away at armour, and taking glancing shots from them myself.  It felt like that fight went on for hours, but it was probably only 5 or so minutes before they finally managed to pod me, and I managed to warp away to freedom.  That was probably nearly 20 years ago (I stopped playing maybe late 2007 / early 2008?) and I still remember it vividly.  Once I'd got myself to safety I remember just sitting in my seat staring at the screen, as the adrenaline faded.</p>
]]></description><pubDate>Wed, 08 Jul 2026 16:11:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48833759</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48833759</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48833759</guid></item><item><title><![CDATA[New comment by Twirrim in "Amazon will stop accepting new customers for Mechanical Turk"]]></title><description><![CDATA[
<p>Back around 10 years ago, I gained a new manager who had previously managed mechanical turk.  It was already recognised as a dead end back then.<p>I remember him talking about getting a mandate from Amazon Security to upgrade from the long EOL MySQL 4.0 to MySQL 5.something, and that it was almost impossible to get any resources committed from leadership to even do it <i>despite</i> the fact it was security requiring it (which usually resulted in everyone jumping before stopping to ask how high to jump).  I want to say he ended up doing it himself?  Something like that..<p>All existing extremely minimal headcount was tied up in a massive technical debt of KTLO work, and proposals to resolve those issues similarly met resourcing road-blocks.</p>
]]></description><pubDate>Mon, 06 Jul 2026 23:27:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48811836</link><dc:creator>Twirrim</dc:creator><comments>https://news.ycombinator.com/item?id=48811836</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48811836</guid></item></channel></rss>