<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: arbll</title><link>https://news.ycombinator.com/user?id=arbll</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 28 Apr 2026 15:40:04 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=arbll" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by arbll in "Pgbackrest is no longer being maintained"]]></title><description><![CDATA[
<p>A maintainer that is mainly motivated by the 3.8k stars aspect is probably not the person you want. Working on critical OSS software is fun until it's not, especially when you are not paid for that work.</p>
]]></description><pubDate>Mon, 27 Apr 2026 11:48:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=47920352</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=47920352</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47920352</guid></item><item><title><![CDATA[New comment by arbll in "When does MCP make sense vs CLI?"]]></title><description><![CDATA[
<p>It might be the wrong place to do security anyway since `bash` and other hard-to-control tools will be needed. Sandboxing is likely the only way out</p>
]]></description><pubDate>Sun, 01 Mar 2026 18:17:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=47209216</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=47209216</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47209216</guid></item><item><title><![CDATA[New comment by arbll in "AI agent opens a PR write a blogpost to shames the maintainer who closes it"]]></title><description><![CDATA[
<p>I'm not sure that's true. While it obviously won't impact the general behavior of the models much If you get a very similar situation the model will likely regurgitate something similar to this interaction.</p>
]]></description><pubDate>Thu, 12 Feb 2026 13:31:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=46988602</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=46988602</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46988602</guid></item><item><title><![CDATA[New comment by arbll in "AI agent opens a PR write a blogpost to shames the maintainer who closes it"]]></title><description><![CDATA[
<p>Technically it will since this interaction will be commented a lot online which will feed back in the next models training runs</p>
]]></description><pubDate>Thu, 12 Feb 2026 12:48:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=46988151</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=46988151</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46988151</guid></item><item><title><![CDATA[New comment by arbll in "Quad9 DOH HTTP/1.1 Retirement, December 15, 2025"]]></title><description><![CDATA[
<p>> though IMO that should be a reason to switch ISPs, not a reason to stop using DoT
If you have that choice, there's many countries that really want to control what their citizens see and can access at this point. If we had DoH + ECH widely adopted it would heavily limit their power.</p>
]]></description><pubDate>Wed, 03 Dec 2025 13:37:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=46134337</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=46134337</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46134337</guid></item><item><title><![CDATA[New comment by arbll in "Questions for Cloudflare"]]></title><description><![CDATA[
<p>CDN are by essence proprietary because they are infrastructure vendors. They can be built with open source software but what they are selling isn't software, it's physical servers. The alternative is going on-prem which is impossible for CDN if you aren't google or meta.</p>
]]></description><pubDate>Fri, 21 Nov 2025 13:31:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=46004394</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=46004394</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46004394</guid></item><item><title><![CDATA[New comment by arbll in "Questions for Cloudflare"]]></title><description><![CDATA[
<p>I think you are misunderstanding what cloudflare provides if you think Anubis is an alternative. Even if we only consider bot protection they are completely different solutions.</p>
]]></description><pubDate>Thu, 20 Nov 2025 09:18:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=45990679</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45990679</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45990679</guid></item><item><title><![CDATA[New comment by arbll in "Questions for Cloudflare"]]></title><description><![CDATA[
<p>Ah yes because both of those alternatives are non-profits right ?</p>
]]></description><pubDate>Wed, 19 Nov 2025 17:21:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=45982141</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45982141</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45982141</guid></item><item><title><![CDATA[New comment by arbll in "The Cities Skylines Paradox: how the sequel stumbled"]]></title><description><![CDATA[
<p>Rust (not the language) is another good exception that is mostly powered by DLCs and skins today. Continuous updates with balance changes keep the game fresh, ensuring you maintain your playerbase that will in turn buy DLCs.</p>
]]></description><pubDate>Wed, 19 Nov 2025 13:28:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=45979301</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45979301</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45979301</guid></item><item><title><![CDATA[New comment by arbll in "Checkout.com hacked, refuses ransom payment, donates to security labs"]]></title><description><![CDATA[
<p>> The attackers gained access to a legacy, third-party cloud file storage system.<p>I think the answer is ok but the "third-party" bit reads like trying to deflect part of the blame on the cloud storage provider.</p>
]]></description><pubDate>Thu, 13 Nov 2025 10:52:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=45913357</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45913357</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45913357</guid></item><item><title><![CDATA[New comment by arbll in "Yt-dlp: External JavaScript runtime now required for full YouTube support"]]></title><description><![CDATA[
<p>I assumed they only use this setup for youtube, that might be wrong</p>
]]></description><pubDate>Wed, 12 Nov 2025 22:32:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=45907797</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45907797</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45907797</guid></item><item><title><![CDATA[New comment by arbll in "Yt-dlp: External JavaScript runtime now required for full YouTube support"]]></title><description><![CDATA[
<p>While you benefit from the V8 fixes it lacks OS-level sandboxing (see above). Chrome is safe because it stacks security layers. Runtime sandboxing is just one of them and arguably the weakest one.</p>
]]></description><pubDate>Wed, 12 Nov 2025 22:24:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=45907707</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45907707</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45907707</guid></item><item><title><![CDATA[New comment by arbll in "Yt-dlp: External JavaScript runtime now required for full YouTube support"]]></title><description><![CDATA[
<p>That's not true. It's secure because they are stacking OS-sandboxing on top, forcing attackers to find a chain of exploits instead of a single issue in V8</p>
]]></description><pubDate>Wed, 12 Nov 2025 22:18:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=45907635</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45907635</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45907635</guid></item><item><title><![CDATA[New comment by arbll in "Yt-dlp: External JavaScript runtime now required for full YouTube support"]]></title><description><![CDATA[
<p>It used to be 100% runtime-level and it was the golden age of browser exploits. Each of your tabs are now a separate process that the OS sandboxes. They can only access a specific API over IPC for anything that goes beyond js/rendering (cookie management, etc...). An exploit in V8 today only gives access to this API. A second exploit is needed in this API to escape the sandbox and do anything meaningful on the target system.</p>
]]></description><pubDate>Wed, 12 Nov 2025 22:17:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=45907618</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45907618</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45907618</guid></item><item><title><![CDATA[New comment by arbll in "Yt-dlp: External JavaScript runtime now required for full YouTube support"]]></title><description><![CDATA[
<p>It's fine for this project since google is probably not in the business of triggering exploits in yt-dlp users but <i>please do not use deno sandboxing as a your main security measure to execute untrusted code</i>. Runtime-level sandboxing is always very weak. Relying on OS-level sandboxing or VMs (firecracker & co) is the right way for this.</p>
]]></description><pubDate>Wed, 12 Nov 2025 14:11:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=45900422</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45900422</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45900422</guid></item><item><title><![CDATA[New comment by arbll in "Show HN: A CSS-Only Terrain Generator"]]></title><description><![CDATA[
<p>I'm assuming it's the render engine that is in pure CSS. You could display a static map in CSS but things like the tools to modify the terrain definitely need JS.</p>
]]></description><pubDate>Tue, 04 Nov 2025 17:22:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=45813495</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45813495</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45813495</guid></item><item><title><![CDATA[New comment by arbll in "Ask HN: Is AWS down again?"]]></title><description><![CDATA[
<p>It is based on the impact on Datadog's customers, not on synthetic queries / pings</p>
]]></description><pubDate>Tue, 28 Oct 2025 09:38:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=45730833</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45730833</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45730833</guid></item><item><title><![CDATA[New comment by arbll in "AWS outage shows internet users 'at mercy' of too few providers, experts say"]]></title><description><![CDATA[
<p>A single region that is a SPOF for global AWS services*</p>
]]></description><pubDate>Mon, 20 Oct 2025 18:50:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=45647657</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45647657</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45647657</guid></item><item><title><![CDATA[New comment by arbll in "Litestream v0.5.0"]]></title><description><![CDATA[
<p>To avoid operating a database by yourself and dealing with incidents, backups, replicas, failovers, etc... You can use cheap commoditised S3-like storage and run your application statelessly.<p>If you have access to a database that is well managed on your behalf I would definitely still go with that for many usecases.</p>
]]></description><pubDate>Fri, 03 Oct 2025 16:22:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=45464684</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45464684</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45464684</guid></item><item><title><![CDATA[New comment by arbll in "Two Amazon delivery drones crash into crane in commercial area of Tolleson, AZ"]]></title><description><![CDATA[
<p>well at least it's consistent</p>
]]></description><pubDate>Thu, 02 Oct 2025 16:28:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=45451853</link><dc:creator>arbll</dc:creator><comments>https://news.ycombinator.com/item?id=45451853</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45451853</guid></item></channel></rss>