<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: apgwoz</title><link>https://news.ycombinator.com/user?id=apgwoz</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 16 Jun 2026 07:42:28 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=apgwoz" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by apgwoz in "Cisco workforce reductions"]]></title><description><![CDATA[
<p>How many layoffs does a company have to do before realizing it’s in their best interest to start asking other companies to take the employees they don’t want to employ anymore?<p>Also, 75% placement seems wildly successful. Why isn’t Cisco also a head hunting firm?!</p>
]]></description><pubDate>Thu, 14 May 2026 09:15:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48132892</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=48132892</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48132892</guid></item><item><title><![CDATA[New comment by apgwoz in "A Roblox cheat and one AI tool brought down Vercel's platform"]]></title><description><![CDATA[
<p>It’s absolute baseline, but yes, it relies entirely on the platform’s permissions model, the administrator who assigns permissions, and the application authors to not create vectors for env var dumps. :)<p>But honestly, if you’re in the container, and the application running in the container can get secrets, so can a shell user.<p>_Maybe_ there’s a model where the platform exposes a Unix domain socket and checks the PID, user, group of the connection, and delivers secrets that way? This has its problems, too, like it being non-standard, only possible in some scenarios and otherwise fallible… but better than nothing? If you reap the container when that process dies, you can’t race for the same PID, at least. I dunno</p>
]]></description><pubDate>Wed, 22 Apr 2026 04:22:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=47858969</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47858969</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47858969</guid></item><item><title><![CDATA[New comment by apgwoz in "Anthropic takes $5B from Amazon and pledges $100B in cloud spending in return"]]></title><description><![CDATA[
<p>The Ed Zitron rant will be phenomenal.</p>
]]></description><pubDate>Wed, 22 Apr 2026 02:27:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=47858061</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47858061</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47858061</guid></item><item><title><![CDATA[New comment by apgwoz in "A Roblox cheat and one AI tool brought down Vercel's platform"]]></title><description><![CDATA[
<p>Ah. The article has since been updated to point out that it’s not plaintext, but encrypted at rest (which would be expected). OK.</p>
]]></description><pubDate>Tue, 21 Apr 2026 16:48:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=47851305</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47851305</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47851305</guid></item><item><title><![CDATA[New comment by apgwoz in "A Roblox cheat and one AI tool brought down Vercel's platform"]]></title><description><![CDATA[
<p>You’re thinking too much. When you run the app, the system decrypts the secrets and makes them available as env vars (or some other mechanism).<p>In an admin ui, you list the names of secrets only, and provide a “reveal” or a “replace” on each one. They are never decrypted unless explicitly asked for.<p>Is this perfect? Absolutely not. The key is controlled by the company, but it can be derived in a manner that doesn’t allow for the dump of everything if it’s leaked.</p>
]]></description><pubDate>Tue, 21 Apr 2026 14:02:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=47848968</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47848968</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47848968</guid></item><item><title><![CDATA[New comment by apgwoz in "Quantum Computers Are Not a Threat to 128-Bit Symmetric Keys"]]></title><description><![CDATA[
<p>Not at all. I was simply making a joke on the parallel exploration of states.</p>
]]></description><pubDate>Tue, 21 Apr 2026 13:56:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=47848899</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47848899</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47848899</guid></item><item><title><![CDATA[New comment by apgwoz in "A Roblox cheat and one AI tool brought down Vercel's platform"]]></title><description><![CDATA[
<p>You pretty much have to assume someone is going to put sensitive data in an input like this. Encryption by default is the only sensible choice.</p>
]]></description><pubDate>Tue, 21 Apr 2026 05:09:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=47844758</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47844758</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47844758</guid></item><item><title><![CDATA[New comment by apgwoz in "Quantum Computers Are Not a Threat to 128-Bit Symmetric Keys"]]></title><description><![CDATA[
<p>Yeah, but… what if?</p>
]]></description><pubDate>Tue, 21 Apr 2026 04:40:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=47844589</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47844589</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47844589</guid></item><item><title><![CDATA[New comment by apgwoz in "John Ternus to become Apple CEO"]]></title><description><![CDATA[
<p>And his successor John Turnip.</p>
]]></description><pubDate>Tue, 21 Apr 2026 03:57:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=47844347</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47844347</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47844347</guid></item><item><title><![CDATA[New comment by apgwoz in "Pro Max 5x quota exhausted in 1.5 hours despite moderate usage"]]></title><description><![CDATA[
<p>Yes! I’ve been trying (and failing!) to get people to understand this. Build the high leverage tools while the tokens are cheap. Unfortunately, I haven’t figured out the right set of high leverage tools. :)</p>
]]></description><pubDate>Mon, 13 Apr 2026 07:34:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=47748913</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47748913</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47748913</guid></item><item><title><![CDATA[New comment by apgwoz in "Pro Max 5x quota exhausted in 1.5 hours despite moderate usage"]]></title><description><![CDATA[
<p>As another data point, I pay for Pro for a personal account, and use no skills, do nothing fancy, use the default settings, and am out of tokens, with one terminal, after an hour. This is typically working on a < 5,000 line code base, sometimes in C, sometimes in Go. Not doing incredibly complicated things.</p>
]]></description><pubDate>Sun, 12 Apr 2026 18:17:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=47742671</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47742671</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47742671</guid></item><item><title><![CDATA[New comment by apgwoz in "Small models also found the vulnerabilities that Mythos found"]]></title><description><![CDATA[
<p>It takes longer, but a spade is better than bare hands. The goal is to speed up finding valid vulnerabilities, and be faster than humans can do it.</p>
]]></description><pubDate>Sun, 12 Apr 2026 04:04:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47736060</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47736060</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47736060</guid></item><item><title><![CDATA[New comment by apgwoz in "Small models also found the vulnerabilities that Mythos found"]]></title><description><![CDATA[
<p>I use the models to look for vulnerabilities all the time. I find stuff often. Have I tried to do build a new harness, or develop more sophisticated techniques? No. I suspect there are some spending lots of tokens developing more sophisticated strategies, in the same way software engineers are seeking magical one-shot harnesses.</p>
]]></description><pubDate>Sun, 12 Apr 2026 03:00:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=47735798</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47735798</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47735798</guid></item><item><title><![CDATA[New comment by apgwoz in "Small models also found the vulnerabilities that Mythos found"]]></title><description><![CDATA[
<p>Why? They claim this small model found a bug given some context. I assume the context wasn’t “hey! There’s a very specific type of bug sitting in this function when certain conditions are met.”<p>We keep assuming that the models need to get bigger and better, and the reality is we’ve not exhausted the ways in which to use the smaller models. It’s like the Playstation 2 games that came out 10 years later. Well now all the tricks were found, and everything improved.</p>
]]></description><pubDate>Sun, 12 Apr 2026 01:32:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=47735437</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47735437</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47735437</guid></item><item><title><![CDATA[New comment by apgwoz in "Small models also found the vulnerabilities that Mythos found"]]></title><description><![CDATA[
<p>The benefit here is reducing the time to find vulnerabilities; faster than humans, right? So if you can rig a harness for each function in the system, by first finding where it’s used, its expected input, etc, and doing that for all functions, does it discover vulnerabilities faster than humans?<p>Doesn’t matter that they isolated one thing. It matters that the context they provided was discoverable by the model.</p>
]]></description><pubDate>Sat, 11 Apr 2026 20:58:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=47733968</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47733968</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47733968</guid></item><item><title><![CDATA[New comment by apgwoz in "Ask HN: Any interesting niche hobbies?"]]></title><description><![CDATA[
<p>There’s no doubt that stuff is print making. My point is that there are multiple ways of doing (within each of these): relief, Intaglio, lithography, screen printing, offset.<p>So if you say, “I’m a print maker,” it describes basically nothing. :)<p>This is just a general statement, not directed at you. Sorry it felt that way.</p>
]]></description><pubDate>Thu, 09 Apr 2026 15:01:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=47704670</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47704670</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47704670</guid></item><item><title><![CDATA[New comment by apgwoz in "Ask HN: Any interesting niche hobbies?"]]></title><description><![CDATA[
<p>I like your stuff! I’ve been coveting a plotter for a while, but I’m pretty sure it won’t get used enough to justify the expense. :/<p>I do find the term “printmaking” hilarious because there’s just sooo many ways to make prints. I tried to get into linocut fairly recently, but the battleship grey linoleum I had wasn’t very good. It cracked and crumbled pretty easily. I did get some of pink Speedball “blocks,” but it gets expensive pretty quickly. I guess more to the point is the feeling that I lack much to say. But, that’s an excuse. :)</p>
]]></description><pubDate>Thu, 09 Apr 2026 00:47:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=47698017</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47698017</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47698017</guid></item><item><title><![CDATA[New comment by apgwoz in "Sky – an Elm-inspired language that compiles to Go"]]></title><description><![CDATA[
<p>You _can_ do trampolines, but that is kind of infectious, or needs to be very explicit with extra code, etc.</p>
]]></description><pubDate>Tue, 07 Apr 2026 01:51:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=47669794</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47669794</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47669794</guid></item><item><title><![CDATA[New comment by apgwoz in "Claude Code's source code has been leaked via a map file in their NPM registry"]]></title><description><![CDATA[
<p>It’s also deterministic, unlike llms…</p>
]]></description><pubDate>Tue, 31 Mar 2026 15:02:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47588386</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47588386</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47588386</guid></item><item><title><![CDATA[New comment by apgwoz in "Claude Code's source code has been leaked via a map file in their NPM registry"]]></title><description><![CDATA[
<p>> That's like a truck company using horses to transport parts. Weird choice.<p>Easy way to claim more “horse power.”</p>
]]></description><pubDate>Tue, 31 Mar 2026 15:01:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=47588351</link><dc:creator>apgwoz</dc:creator><comments>https://news.ycombinator.com/item?id=47588351</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47588351</guid></item></channel></rss>