<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: Xelynega</title><link>https://news.ycombinator.com/user?id=Xelynega</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 05 Apr 2026 13:08:21 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=Xelynega" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by Xelynega in "Guid Smash"]]></title><description><![CDATA[
<p>That's not how namespacing works though, is it?<p>Getting UUID 'A' from app 'X' is easily distinguishable from UUID 'A' from app 'Y'.</p>
]]></description><pubDate>Sun, 17 Aug 2025 17:45:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=44933396</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=44933396</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44933396</guid></item><item><title><![CDATA[New comment by Xelynega in "Guid Smash"]]></title><description><![CDATA[
<p>You're glossing over the fact that they assumed youtube would want to assign a UUID to each pixel in a 4k@60fps video as the use case that this would fail for...</p>
]]></description><pubDate>Sun, 17 Aug 2025 17:44:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=44933389</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=44933389</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44933389</guid></item><item><title><![CDATA[New comment by Xelynega in "If you're remote, ramble"]]></title><description><![CDATA[
<p>I don't think they're discounting that distrust can be legitimate, they're questioning whether it's useful to distrust somebody when it's not your job to micromanage them or they're providing adequate output.</p>
]]></description><pubDate>Mon, 04 Aug 2025 03:38:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=44781939</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=44781939</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44781939</guid></item><item><title><![CDATA[New comment by Xelynega in "Supabase MCP can leak your entire SQL database"]]></title><description><![CDATA[
<p>Going a step further, I live in a reality where you can train most people against phishing attacks like that.<p>How accurate is the comparison if LLMs can't recover from phishing attacks like that and become more resilient?</p>
]]></description><pubDate>Wed, 09 Jul 2025 02:02:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=44505695</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=44505695</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44505695</guid></item><item><title><![CDATA[New comment by Xelynega in "Supabase MCP can leak your entire SQL database"]]></title><description><![CDATA[
<p>Are you not worried that anthropomorphizing them will lead to misinterpreting the failure modes by attributing them to human characteristics, when the failures might not be caused in the same way at all?<p>Why anthropomorphize if not to dismiss the actual reasons? If the reasons have explanations that can be tied to reality why do we need the fiction?</p>
]]></description><pubDate>Wed, 09 Jul 2025 02:01:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=44505689</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=44505689</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44505689</guid></item><item><title><![CDATA[New comment by Xelynega in "OpenAI slams court order to save all ChatGPT logs, including deleted chats"]]></title><description><![CDATA[
<p>> But I would be pretty irritated if the government stepped in and mandated they make my searches public and linkable to me.<p>Who is calling for this? Are you perhaps taking an absolutist view where "not destroying evidence" is the same as "mandated they make my searches public and linkable to me"? That's quite ridiculous.</p>
]]></description><pubDate>Thu, 05 Jun 2025 18:33:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=44194412</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=44194412</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44194412</guid></item><item><title><![CDATA[New comment by Xelynega in "GitHub MCP exploited: Accessing private repositories via MCP"]]></title><description><![CDATA[
<p>I don't understand your logic. Should security reports never be published that say "hash the password before storing it in the DB". Boring research is boring most of the time, that doesn't make it unimportant, no?</p>
]]></description><pubDate>Tue, 27 May 2025 07:47:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=44104778</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=44104778</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44104778</guid></item><item><title><![CDATA[New comment by Xelynega in "The Xenon Death Flash: How a Camera Nearly Killed the Raspberry Pi 2"]]></title><description><![CDATA[
<p>One of the things I'm not looking forward to with people "just throwing it through an LLM for a final pass" is the loss of individual voice.<p>Everything is starting to sound the same, and it's becoming monotonous</p>
]]></description><pubDate>Sun, 25 May 2025 06:36:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=44086021</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=44086021</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44086021</guid></item><item><title><![CDATA[New comment by Xelynega in "Microsoft Teams will soon block screen capture during meetings"]]></title><description><![CDATA[
<p>Yea, this sounds like "Microsoft teams no longer supporting video on Linux and old versions of mac/windows" more than anything</p>
]]></description><pubDate>Sat, 10 May 2025 20:00:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=43948464</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=43948464</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43948464</guid></item><item><title><![CDATA[New comment by Xelynega in "Getting forked by Microsoft"]]></title><description><![CDATA[
<p>How is compliance as written impossible?</p>
]]></description><pubDate>Mon, 21 Apr 2025 16:57:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=43754017</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=43754017</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43754017</guid></item><item><title><![CDATA[New comment by Xelynega in "Getting forked by Microsoft"]]></title><description><![CDATA[
<p>Why?</p>
]]></description><pubDate>Mon, 21 Apr 2025 16:57:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=43754015</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=43754015</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43754015</guid></item><item><title><![CDATA[New comment by Xelynega in "Getting forked by Microsoft"]]></title><description><![CDATA[
<p>> I won't use GPL libraries in my code.<p>Why? Do you also avoid libraries with an even number of consonants in the name?</p>
]]></description><pubDate>Mon, 21 Apr 2025 16:52:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=43753975</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=43753975</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43753975</guid></item><item><title><![CDATA[New comment by Xelynega in "Getting forked by Microsoft"]]></title><description><![CDATA[
<p>> I create open source software for the benefit of everyone, for profit or not for profit.<p>I have the same reasoning as to why I pick the AGPLv3 license as the default for my new projects. I want any benefits from my code to continue to benefit everyone, even if someone is profiting off of it.</p>
]]></description><pubDate>Mon, 21 Apr 2025 16:48:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=43753940</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=43753940</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43753940</guid></item><item><title><![CDATA[New comment by Xelynega in "Top OpenAI Catastrophic Risk Official Steps Down Abruptly"]]></title><description><![CDATA[
<p>So the name being wrong means the department should be gutted?<p>Overly-serious naming is hardly a reason to throw the baby out with the bathwater.</p>
]]></description><pubDate>Thu, 17 Apr 2025 17:39:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=43719977</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=43719977</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43719977</guid></item><item><title><![CDATA[New comment by Xelynega in "Canadian math prodigy allegedly stole $65M in crypto"]]></title><description><![CDATA[
<p>What "intended uses" are there for it other than being an unregulated options market with constant scams and a "code is law" tool?<p>I would imagine any other legitimate use would be served better by traditional database/finance systems.</p>
]]></description><pubDate>Thu, 17 Apr 2025 17:30:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=43719851</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=43719851</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43719851</guid></item><item><title><![CDATA[New comment by Xelynega in "Damn Vulnerable MCP Server"]]></title><description><![CDATA[
<p>If you're authenticating the exact same way you would to an HTTP api(put an API key in the config), why does MCP need to exist instead of just plugging in the API key + link to openapi specs in an "Agent API Config"?<p>I was responding to you saying that the security model is different because servers can be treated as client applications for the security model, but that doesn't make sense for third party servers that you aren't hosting and just sending/receiving data from.<p>From the client PoV, booking.com could return malicious information to my prompt telling it to do unauthorized things with my computer(e.x. upload banking cookies to a remote endpoint). This doesn't sound secure, and just saying "it's part of the client" doesn't change that.</p>
]]></description><pubDate>Thu, 17 Apr 2025 17:23:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=43719788</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=43719788</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43719788</guid></item><item><title><![CDATA[New comment by Xelynega in "Damn Vulnerable MCP Server"]]></title><description><![CDATA[
<p>How will this work when people are talking about third party MCP servers(e.x. booking.com, GitHub, etc.)</p>
]]></description><pubDate>Wed, 16 Apr 2025 20:26:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=43709990</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=43709990</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43709990</guid></item><item><title><![CDATA[New comment by Xelynega in "CVE program faces swift end after DHS fails to renew contract"]]></title><description><![CDATA[
<p>Don't open source developers and users of their software also benefit from the CVE database?<p>If it were privately funded, what incentive would these private companies have to track bugs for these open source projects that don't make money?</p>
]]></description><pubDate>Wed, 16 Apr 2025 08:00:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=43702718</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=43702718</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43702718</guid></item><item><title><![CDATA[New comment by Xelynega in "CVE program faces swift end after DHS fails to renew contract"]]></title><description><![CDATA[
<p>Yes, as it would  be a public good to everyone to be able to know where the potholes(that aren't profitable to fix for these private companies apparently) are  so they can avoid them.<p>They might take a step back and realize that it would be more cost-effective to just own the roads, in which case your thought experiment ends where we are, because where we are was a place reasoned to(to an extent).</p>
]]></description><pubDate>Wed, 16 Apr 2025 07:58:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=43702706</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=43702706</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43702706</guid></item><item><title><![CDATA[New comment by Xelynega in "Everything wrong with MCP"]]></title><description><![CDATA[
<p>> So what? You’re basically claiming that it’ll fail because some companies won’t want to provide too much value for free.<p>> If GitHub has an MCP server, you’re still paying them to host your code (potentially)<p>So are you saying that all uses of MCP that rely on data you don't own or pay someone to store are not likely to exist?<p>I would agree with that point of view, but I'm not sure you do even though you are the one sharing it.</p>
]]></description><pubDate>Wed, 16 Apr 2025 07:25:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=43702494</link><dc:creator>Xelynega</dc:creator><comments>https://news.ycombinator.com/item?id=43702494</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43702494</guid></item></channel></rss>