<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: adeon</title><link>https://news.ycombinator.com/user?id=adeon</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 17 Sep 2026 06:17:42 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=adeon" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by adeon in "NetHack 5.0.0"]]></title><description><![CDATA[
<p>I played this game a bit back in 3.4.3 times.<p>It's been great on long-haul flights to play on the laptop. Doesn't demand your battery.</p>
]]></description><pubDate>Sat, 02 May 2026 19:37:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=47989693</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=47989693</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47989693</guid></item><item><title><![CDATA[New comment by adeon in "Put the zip code first"]]></title><description><![CDATA[
<p>I get the vibe that it's more like there's unexpected complexity and it's difficult to be confident you know how zipcodes work with enough detail to make the feature work. And that is just one example of possible complexity.<p>Do zipcodes change for example? Can your drop-down quickly go out-of-date? You'd need a way to manually enter a city so people are able to tell the system an address. Do you want to bother making an auto-updating zipcode feature just for a form?<p>Is it going to confuse people because nobody else has bothered to make this superfancy selection feature thing?<p>Is this USA only? There are postal codes/zipcode-equivalents in other countries.<p>It starts to feel it's likely not worth the time and effort to try to be smart about this particular feature. At least not if I'm imagining this us some generic, universal address web form that is supposed to be usable for USA-sized areas.<p>To me it feels similar to that famous article about what you can and cannot assume about people's names; turns out they can be way more complicated and weird than one might assume.<p>Although maybe zipcodes don't really go that deep in complexity. But on the spot I would not dare to assume they are.</p>
]]></description><pubDate>Sun, 08 Mar 2026 00:36:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=47293069</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=47293069</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47293069</guid></item><item><title><![CDATA[New comment by adeon in "OpenAI API Logs: Unpatched data exfiltration"]]></title><description><![CDATA[
<p>Yeah I agree. I think even if you block CSP images, attacker could still hide information, or attempted exfiltration.<p>The post got me now instead wondering how to not make people shallowly dismiss perfectly fine articles for dumb reasons, like I <i>almost</i> did. It's not even that unclear what the attack is, in the article's its opening when I look at it now again, and I now went around their posts to see how PromptArmor generally does their writing because I got curious about the writing part...<p>I've seen in the past vulnerabilities that were way overblown but hyped up, so this made me notice how that armor has made me be skeptical whenever some article like this feels it combines marketing + vulnerability reporting.</p>
]]></description><pubDate>Wed, 21 Jan 2026 23:05:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=46712936</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=46712936</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46712936</guid></item><item><title><![CDATA[New comment by adeon in "OpenAI API Logs: Unpatched data exfiltration"]]></title><description><![CDATA[
<p>I found the tone in the article annoying, but my skim reading was that it is an actual vulnerability. The screenshot from OpenAI loads an image from a third-party site and the URL of the image might have all sorts of details etc.<p>I think the viewer should have some CSP policy in place to not do that.<p>That being said, if it was closed as "Not Applicable" it gives me a bit of reason to wonder if some crucial details about the whole chain was either not articulated or mentioned by PromptArmor. Maybe for other reasons it is not actually reasonable to put that on OpenAI site. I'm not sure on the spot. But on a skim read it looks like a legit vulnerability from OpenAI's part that they should fix.<p>I really wish PromptArmor just opened with "OpenAI's log viewer page lacks CSP policies, so it can load arbitrary URL images and here is an example how such things can easily end up on that page". This was really annoying to read but I kept going because I was curious was it a legit thing or not...<p>Edit: I don't know if the article was edited just now but there is a clarification paragraph that actually makes it a bit more clear. PromptArmor if you are reading this, I wonder if my gut reaction of being skeptical simply because of the tone and presentation is a common thing and there are ways to both be convincing right at the start of an article, but still allowing yourself to be marketing-like. I probably would have started with a paragraph that dryly describes exactly the vulnerability "OpenAI's Log viewer is not secure against maliciously crafted logs, which can result in data exfiltration. On this page, we show a realistic scenario by which a malicious third-party can sneak in an image URL to this page and exfiltrate data." and then go on with the rest of the article.</p>
]]></description><pubDate>Wed, 21 Jan 2026 22:40:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=46712657</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=46712657</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46712657</guid></item><item><title><![CDATA[New comment by adeon in "Landlock-Ing Linux"]]></title><description><![CDATA[
<p>I dumped it here just now: <a href="https://github.com/Noeda/landlock-network-sandboxer-tool" rel="nofollow">https://github.com/Noeda/landlock-network-sandboxer-tool</a><p>It hopefully will be obvious that nobody should expect quality :) it is like a simplified version of the sandboxer sample in my other comment. E.g. it maybe does not need to touch filesystem stuff at all.<p>I'd also look at some of the sibling comments for maybe more refined tooling than this thing. Maybe it's useful as a sample though.</p>
]]></description><pubDate>Sun, 30 Nov 2025 20:54:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=46100325</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=46100325</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46100325</guid></item><item><title><![CDATA[New comment by adeon in "Landlock-Ing Linux"]]></title><description><![CDATA[
<p>I've used Landlock to detect and stop unwanted telemetry. I wrote some C that stopped networking except to accept connections on a single port, no outgoing connections and no accepting connections on any other port.<p>`dmesg` shows the connections it blocks (I think this is maybe the audit feature). I used an example sandboxer.c as a base (<a href="https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/samples/landlock/sandboxer.c" rel="nofollow">https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux...</a>) except I just set mine up to not touch file restricting, just networking so that it has that one whitelisted incoming port.<p><pre><code>    ./network-sandboxer-tool 8000 some-program arg1 arg2 etc.
</code></pre>
I like it because it just works as an unprivileged usermode program without setting anything up. A tiny C program. It works inside containers without having to set up any firewalls. Aside from having to compile a small C program, there is little fuss. I found the whole Landlock thing trying to find out alternatives to bubblewrap because I couldn't figure out how to do the same thing in bwrap conveniently.<p>The "unprivileged" in "Landlock: unprivileged access control" for me was the selling point for this use case.<p>I don't consider this effective against actively adversarial programs though.</p>
]]></description><pubDate>Sun, 30 Nov 2025 11:20:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=46095737</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=46095737</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46095737</guid></item><item><title><![CDATA[New comment by adeon in "Accumulation of cognitive debt when using an AI assistant for essay writing task"]]></title><description><![CDATA[
<p>The task of riding a horse can be almost entirely offsourced to the professional horse riders. If they take your carriage from point A to point B, sure, you care about just getting somewhere.<p>Taking the article's task of essay writing: someone presumably is supposed to read them. It's not a carriage task from point A to point B anymore. If the LLM-assisted writers begin to not even understand their own work (quoting from abstract "LLM users also struggled to accurately quote their own work.") how do they know they are not putting out nonsense?</p>
]]></description><pubDate>Mon, 16 Jun 2025 05:06:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=44286764</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=44286764</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44286764</guid></item><item><title><![CDATA[New comment by adeon in "Claude 4 and GitHub MCP will leak your private GitHub repositories"]]></title><description><![CDATA[
<p>After I wrote the comment, I pondered that too (trying to think examples of what I called "security conscious design" that would be in the LLM itself). Right now and in near future, I think I would be highly skeptical even if an LLM was marketed as having such feature of being able to see "unsanitized" text and not be compromised, but I could see myself not 100% dismissing such thing.<p>If e.g. someone could train an LLM with a feature like that and also had some form of compelling evidence it is very resource consuming and difficult for such unsanitized text to get the LLM off-rails, that might be acceptable. I have no idea what kind of evidence would work though. Or how you would train one or how the "feature" would actually work mechanically.<p>Trying to use another LLM to monitor first LLM is another thought but I think the monitored LLM becomes an untrusted source if it sees untrusted source, so now the monitoring LLM cannot be trusted either. Seems that currently you just cannot trust LLMs if they are exposed at all to unsanitized text and then can autonomously do actions based on it. Your security has to depend on some non-LLM guardrails.<p>I'm wondering also as time goes on, agents mature and systems start saving text the LLMs have seen, if it's possible to design "dormant" attacks, some text in LLM context that no human ever reviews, that is designed to activate only at a certain time or in specific conditions, and so it won't trigger automatic checks. Basically thinking if the GitHub MCP here is the basic baby version of an LLM attack, what would the 100-million dollar targeted attack look like. Attacks only get better and all that.<p>No idea. The whole security thinking around AI agents seems immature at this point, heh.</p>
]]></description><pubDate>Mon, 26 May 2025 20:24:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=44101323</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=44101323</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44101323</guid></item><item><title><![CDATA[New comment by adeon in "GitHub MCP exploited: Accessing private repositories via MCP"]]></title><description><![CDATA[
<p>I think from security reasoning perspective: if your LLM sees text from an untrusted source, I think you should assume that untrusted source can steer the LLM to generate any text it wants. If that generated text can result in tool calls, well now that untrusted source can use said tools too.<p>I followed the tweet to invariant labs blog (seems to be also a marketing piece at the same time) and found <a href="https://explorer.invariantlabs.ai/docs/guardrails/" rel="nofollow">https://explorer.invariantlabs.ai/docs/guardrails/</a><p>I find it unsettling from a security perspective that securing these things is so difficult that companies pop up just to offer guardrail products. I feel that if AI companies themselves had security conscious designs in the first place, there would be less need for this stuff. Assuming that product for example is not nonsense in itself already.</p>
]]></description><pubDate>Mon, 26 May 2025 20:00:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=44101120</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=44101120</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44101120</guid></item><item><title><![CDATA[New comment by adeon in "Wavelet Trees: An Introduction (2011)"]]></title><description><![CDATA[
<p>I tried to find some use cases, this paper has listed some, although I think it's not obvious to me what makes the trees uniquely useful compared to other schemes (<a href="https://users.dcc.uchile.cl/~gnavarro/ps/cpm12.pdf" rel="nofollow">https://users.dcc.uchile.cl/~gnavarro/ps/cpm12.pdf</a> seems to be the same Navarro as referenced in the article).<p>The use cases listed in that pdf are revolving around compression, e.g. graph adjacency list is listed as one. I myself found the last use case listed as smelling interesting (colored range queries), but I would need to dig into the references on that one to see what's actually going on with that one and is it truly anything interesting.<p>I would be interested in things like what's the unique advantage wavelets trees have compared to e.g. stuffing roaring bitmaps or other kinds of bitmaps into a tree. The RRR has rank-and-select queries which I think roaring bitmap won't do, so that might tie into something. Maybe a problem where the wavelet tree is the only known efficient way to solve it, or maybe it is uniquely really easy to throw at some types of problems or something else.<p>Anyone know real-world examples of wavelet trees used somewhere? I got interested enough to dig a bit deeper but on the spot as I'm writing this comment, I'm not smart enough to immediately see do these things have killer applications in any niches.</p>
]]></description><pubDate>Sat, 17 May 2025 01:27:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=44011335</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=44011335</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44011335</guid></item><item><title><![CDATA[New comment by adeon in "NSA spied through Angry Birds, other apps: report (2014)"]]></title><description><![CDATA[
<p>Thanks for the resources. Got back to procrastinate on HN and checked the resources (briefly looked at transcript on the video, but found this article more interesting).<p>I've always assumed that some amount of unencrypted HTTP traffic is going to be slurped into archives, but I've been too lazy to really check an example and how does that look like in the real world. That BADASS system is an example, focusing on phones. I've also run mitmproxy in my home to learn and then I've wondered if the big agencies have something like that but much more scaled and sophisticated.<p>I've recently got into studying security, deobfuscated code, or decompiling, tried to find vulnerabilities or bad security, in websites and programs. I've found some, although not anything worth writing home about. I found a replay attack in one VSCode extension that implemented its own encrypted protocol, but it is difficult to use it to do real damage. Found a bad integrity check library (hopelessly naive against canonicalization attack) used by another VSCode extension. I've found something weird in Anthropic's Claude website after you log in, but because their "responsible security policy" is so draconian, I don't want to bother trying to poke it to research it further in case I earn their wrath.<p>Biggest bummer I found that a video game (Don't Starve Together) I had played for a long time with friends does not have any encryption whatsoever for chat messages to this day. (People gonna say private things in video game chats). The other video game I play in multiplayer a lot, Minecraft, has encryption (a bit unusual encryption but it is encryption).<p>That article gave me a bit of validation that I'm not a nut for giving shits about encryption and security, and being annoyed at ungodly amount of analytics I see in mitmproxy my laptop is blabbering about.</p>
]]></description><pubDate>Thu, 08 May 2025 21:53:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=43931744</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=43931744</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43931744</guid></item><item><title><![CDATA[New comment by adeon in "NSA spied through Angry Birds, other apps: report (2014)"]]></title><description><![CDATA[
<p>Lol, yeah, I also learned yesterday that there is apparently, NSA, National Security Authority. No, not the NSA this article is talking about and everyone knows about.<p>I mean: National Security Authority, "Kansallinen turvallisuusviranomainen", which appears to be some office/people under Finnish foreign affairs: <a href="https://um.fi/national-security-authority-nsa-contact-information" rel="nofollow">https://um.fi/national-security-authority-nsa-contact-inform...</a><p>I will say I got confused a moment yesterday when googling on the topic here because when you put NSA and Finland in the same search, it would get topics about this <i>other</i> NSA that just happens to exist which I had never heard of before, and just happens to be Finland-associated.</p>
]]></description><pubDate>Thu, 08 May 2025 21:20:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=43931483</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=43931483</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43931483</guid></item><item><title><![CDATA[New comment by adeon in "NSA spied through Angry Birds, other apps: report (2014)"]]></title><description><![CDATA[
<p>Ah yeah, I saw the propublica as well, it was one of the first articles I found when looking on the topic. I don't doubt at all that Angry Birds data was used by NSA, doesn't seem controversial.<p>The specific question I am interested in is: Did Rovio <i>knowingly</i> and <i>willingly</i> accept $$$ from NSA (directly or indirectly) to weaken their security? I.e. were they acting as a willing accomplice.<p>Because that part would be unusual for Finland (well, at least as far as I know). For US companies I wouldn't bat an eye at news like this.</p>
]]></description><pubDate>Thu, 08 May 2025 06:46:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=43923695</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=43923695</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43923695</guid></item><item><title><![CDATA[New comment by adeon in "NSA spied through Angry Birds, other apps: report (2014)"]]></title><description><![CDATA[
<p>Is there any reliable source for NSA paying Rovio other than this random bar discussion? Not that I don't believe you or that I'm naive about NSA and the power of money, but I looked around news in 2014 and the accusations against Rovio specifically are a bit different flavor. It seems that Rovio was oversharing data to ad networks (Millennial Media comes up a lot), and NSA likely slurped data from the advertising companies. This bar banter is suggesting that NSA had some kind of arrangement with Rovio directly instead, and Rovio willingly went along.<p>Or alternatively, do you feel the Rovio employee's blabbering was talking about an actual, real NSA deal with Rovio, or was it more like a bar joke and direct NSA co-operation was not really implied? (e.g. "we know our security is bad, but these ad companies pay us $XX million to not use encryption so it's sorta like NSA pays us to keep it that way <i>sips beer</i>").<p>I'm interested, because if that is an actual thing that happened, then that's an example of NSA paying a Finnish company $$$ to weaken their security, and the Finnish company willingly agreeing to that. Is it in NSA's Modus Operandi to approach and then pay foreign companies to do this sort of thing?<p>Your comment is describing it in few words, but to me it sounds like it maybe wasn't implying an actual NSA direct co-operation, more like someone doing bar banter and being entirely serious. But that's just me trying to guess tone.<p>(I'm Finnish. I want to know if Rovio has skeletons in their closet. So I can roast them.)</p>
]]></description><pubDate>Thu, 08 May 2025 06:23:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=43923577</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=43923577</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43923577</guid></item><item><title><![CDATA[New comment by adeon in "Why 'Margin Call' remains Wall Street's favorite movie"]]></title><description><![CDATA[
<p>Okay, now that makes sense. I actually put your example of gun violence in google with kabuki theater and that found me some (depressing) articles that use the phrase. Thanks for educating me on a new expression :)</p>
]]></description><pubDate>Wed, 30 Apr 2025 09:23:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=43842884</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=43842884</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43842884</guid></item><item><title><![CDATA[New comment by adeon in "Why 'Margin Call' remains Wall Street's favorite movie"]]></title><description><![CDATA[
<p>I feel a little stupid for asking... but what does "kabuki theater" mean in this context? Do you mean the CEO in the scene sort of "acted a rehearsed show" in a meeting to make sure everyone in the room followed through some thought process? Or maybe in other words (guessing meaning): making people get up and talk to force them to think through something (CEO's real goal), but the CEO framed it as him simply asking questions? (I have not seen the movie or the scene, apologies if the meaning is more obvious to infer if one has seen it).<p>I tried googling it but I get some movie theater in San Francisco and a Wikipedia page describing it as a Japanese theatre with dancing and elaborate costumes and flair. I've not seen it used in an expression before.</p>
]]></description><pubDate>Wed, 30 Apr 2025 07:51:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=43842338</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=43842338</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43842338</guid></item><item><title><![CDATA[New comment by adeon in "The Story Behind “100 Go Mistakes and How to Avoid Them”"]]></title><description><![CDATA[
<p>So not only do you write a full book, but you keep the content online, up to date by making sure readers are informed of new developments that might make advice irrelevant? And you are able on the spot to say "one of three mistakes that are not relevant anymore"? You impress me, random book-writing Internet person.<p>You give me a feeling you really care about the craft and just making a good useful resource, which what I respect. I looked around the site and bookmarked it as a technical writing example I might go to read around now and then.<p>I sometimes teach coding or general computing things (but hands-on, less about writing) and I've come to appreciate that sometimes it is extraordinarily difficult to educate on or communicate complicated ideas.<p>Quoting you: To give you a sense of what I mean by improving the book “over and over“, keep in mind that between feedback from my DE, external reviewers, and others, there are parts of the book that I rewrote more than ten times.<p>I also do rewriting especially with content I intend to be a resource or education piece. Obsessively rewrite. Make it shorter. Clearer. Oops that reads like crap let's start over. IMO having an urge to do this and address all feedback or your own itches means you care about your work. Just have to remind myself that that perfect is the enemy of good enough (or something like that I forgot if the expression went exactly like that).</p>
]]></description><pubDate>Thu, 10 Apr 2025 23:09:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=43648812</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=43648812</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43648812</guid></item><item><title><![CDATA[New comment by adeon in "The Story Behind “100 Go Mistakes and How to Avoid Them”"]]></title><description><![CDATA[
<p>Yes, that was the crux of my question (and was answered by that link when I checked teivah-given link, which linked <a href="https://go.dev/blog/loopvar-preview" rel="nofollow">https://go.dev/blog/loopvar-preview</a> right there as well). Basically I wondered if the example given was really about:<p>1) In Go, the 'i' variable in the for loop is the same 'i' for each round of the iteration, meaning closures created inside the loop all refer to that same 'i' variable, instead of getting their own copy of it. Very easy to accidentally think the all closures have their own copy of 'i'. Goroutines are only mentioned because in Golang this mistake tends to come up with Goroutines because of a common code pattern.<p>OR<p>2) Goroutines themselves either behave or have some weird lexical scope rules in a way I don't know and it doesn't really have to do with closures but an entirely Golang-foreign-alien concept to me I cannot see, and this is why the book example had Goroutines mentioned with the mistake.<p>I rarely write Go myself so I was curious :) It looks like it was 1) unless I am bad at reading, and I think the Go 1.22 change is good. I could easily imagine myself and others making that mistake even with the knowledge to be careful around this sort of code (the link shows a more complicated example when scrolling down that IMO is a good motivating example).</p>
]]></description><pubDate>Thu, 10 Apr 2025 22:47:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=43648708</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=43648708</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43648708</guid></item><item><title><![CDATA[New comment by adeon in "The Story Behind “100 Go Mistakes and How to Avoid Them”"]]></title><description><![CDATA[
<p>I got a question about the example shown, the goroutine one marked as #63, I'd copypaste but it's an image.<p>Is there a reason the common mistake is about goroutines specifically? If I instead just made function closures without launching off goroutines, would they all refer to the same 'i' variable? (I assume it's maybe just that the mistake tends to go hand in hand with goroutine-launching code in a pattern like that).<p>I'd presume the book would say right after the example :)<p>But otherwise: the author gets serious respect from me for going through that process, taking feedback and learning how to communicate, i.e. taking "how do I make a good book?" very seriously and trying their best. And also things like for putting their foot down when the problematic copyeditor. I'm almost interested in the book, not for learning about Go but learning about what it looks like when I know the writing has some serious intent behind it to communicate clearly.</p>
]]></description><pubDate>Thu, 10 Apr 2025 22:06:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=43648483</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=43648483</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43648483</guid></item><item><title><![CDATA[New comment by adeon in "Meta’s brave new horizons"]]></title><description><![CDATA[
<p>I was at an event where people were making these avatars, many first time users. One person who gave feedback at the end said he was frustrated he could not get the avatar to look like him.<p>I think whatever the hell Meta is doing with their weird alien humanoids is far from "normie" appeal as well. The furries and anime girls seem more normie in comparison.<p>I don't know if there is some middle ground that would actually be appealing to some definition of a "billion normie"s. Maybe actually photorealistic looking humans? Making the graphics not look like it's from 2003? Or going the other way: make them look like the Mii characters with Nintendo? Something totally different? Maybe appealing to the furries and anime girls would be actually a good idea at first, to build up some "power users" or whatever, and then attract more casual users.<p>I share the sentiment of the Instagram users in the article and the grandparent; it is baffling to me why the product looks so terrible, with so many resources poured into the Metaverse.</p>
]]></description><pubDate>Sun, 23 Feb 2025 09:12:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=43147963</link><dc:creator>adeon</dc:creator><comments>https://news.ycombinator.com/item?id=43147963</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43147963</guid></item></channel></rss>