<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: bostik</title><link>https://news.ycombinator.com/user?id=bostik</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 30 Jul 2026 03:58:26 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=bostik" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by bostik in "Codex Security"]]></title><description><![CDATA[
<p>That's quite an indictment of the common app development practices. (Not that I disagree with your point...)<p>And security <i>is</i> hard. Because it is by definition off the happy path, it is quite often at odds with MVPs and rapid release cycles. Then you add all the ways the users can use your product to attack/abuse others.<p>Any non-hobbyist app development does indeed require at least a decent understanding of security.</p>
]]></description><pubDate>Wed, 29 Jul 2026 05:54:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=49093857</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=49093857</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49093857</guid></item><item><title><![CDATA[New comment by bostik in "Future euro banknote design proposals"]]></title><description><![CDATA[
<p>> <i>deliberately destroy old notes and issue new ones with different images to replace them</i><p>Big part of the reason for this appears to be security. Many years ago a high-ranking official from Finnish central bank told in an interview that bank notes need to be redesigned approximately once per decade. Reason is that it takes about that long for the materials and printing technology to get commoditised enough for criminal enterprises to be able to start manufacturing "high-grade" forgeries at any real scale.<p>Every generation of bank notes employs a whole bunch of newly developed technologies and tricks that make the notes themselves distinctive, as well as <i>incredibly difficult</i>[ß] to forge.<p>ß: Some of it is down to tightly locked down and guarded speciality supply chains. Some is due to advances in microprinting and ilk. If you had unlimited resources, you could arrange to have the necessary equipment, supplies, staff and materials to print your own forged money. It'd just be slow, low-yield and very expensive.</p>
]]></description><pubDate>Sat, 25 Jul 2026 05:27:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=49044776</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=49044776</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49044776</guid></item><item><title><![CDATA[New comment by bostik in "Traders are increasingly betting against SpaceX just weeks after IPO"]]></title><description><![CDATA[
<p>Matt Levine pointed out to a likely culprit, and it indeed has <i>nothing</i> to do with the business outlooks.[0]<p>SpaceX sold only 5% of their stock in the IPO. Earliest lockups will start to [partially] expire in mid-August, bringing in further 7% of SpaceX stock to market. If you expect the market to be flooded with >2x volume of supply, you can either sell right now before the price drops even further or hold and wait for the business fundamentals catch up with pricing expectations.<p>0: <a href="https://bloom.bg/4f7pFnd" rel="nofollow">https://bloom.bg/4f7pFnd</a></p>
]]></description><pubDate>Sun, 19 Jul 2026 09:06:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48966241</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48966241</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48966241</guid></item><item><title><![CDATA[New comment by bostik in "Claude Code: Anatomy of a Misfeature"]]></title><description><![CDATA[
<p>> <i>I have never seen a UI where just selecting text means auto-copy to the paste buffer.</i><p>Isn't this the default behaviour of every X application since the 1990's?</p>
]]></description><pubDate>Fri, 17 Jul 2026 19:09:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48951125</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48951125</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48951125</guid></item><item><title><![CDATA[New comment by bostik in "Claude Code: Anatomy of a Misfeature"]]></title><description><![CDATA[
<p>> <i>Copy/paste is one of the most basic, low-level features of a modern operating system. NO APPLICATION SHOULD EVER SCREW WITH IT, IN ANY WAY!</i><p>-Ghostty enters the chat-<p>Middle-click paste in Ghostty is hazardous: the damn thing can move your cursor to the position of your mouse pointer and paste there. An utterly infuriating behaviour - it is a <i>text terminal</i>. It has no business emulating the usability crimes GUIs first committed and then committed to.</p>
]]></description><pubDate>Fri, 17 Jul 2026 19:06:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48951099</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48951099</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48951099</guid></item><item><title><![CDATA[New comment by bostik in "Potential session/cache leakage between workspace instances or consumer accounts"]]></title><description><![CDATA[
<p>Or as the Risky Business guys crystallise it: "James Kettle breaks the internet. Again."</p>
]]></description><pubDate>Sat, 04 Jul 2026 18:39:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=48787687</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48787687</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48787687</guid></item><item><title><![CDATA[New comment by bostik in "Suspicious Discontinuities (2020)"]]></title><description><![CDATA[
<p>This <i>does</i> happen in Finnish tax system. Your tax rate (percent with one decimal) is calculated based on your annual gross income. Rates are <i>supposed</i> to be calculated smoothly, and they are certainly calculated for each individual separately.<p>In reality they are step functions. It is surprisingly common to have people refuse promotions because if would put them above an income tax threshold, bump up their rate, and end up with less money after taxes in the end.<p>The UK tax system is far from fair but at least it has clear brackets: income above threshold X is taxed at rate Y.</p>
]]></description><pubDate>Sat, 27 Jun 2026 16:37:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48699657</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48699657</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48699657</guid></item><item><title><![CDATA[New comment by bostik in "U.S. government will decide who gets to use GPT-5.6"]]></title><description><![CDATA[
<p>Thinking like a business vs. thinking like a state.<p>If you see a given technology as fundamental[tm], you want to ensure that you will retain access to it AND its ongoing development. China may well foresee a possible future where US imposes export controls and global sanctions to block PRC from having access to the necessary equipment to either train or use the most advanced models - let alone its alternate parallel universe where US might go as far as prevent <i>anyone else than US themselves</i> having the most advanced forms of the technology at all.[ß]<p>To ward off such a scenario, China doesn't need to become the sole leading supplier. They only need to guarantee that nobody else can even try to block them off, and that the technology itself can never be yanked.<p>ß: What could possibly give them such ideas?</p>
]]></description><pubDate>Sat, 27 Jun 2026 09:10:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48696534</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48696534</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48696534</guid></item><item><title><![CDATA[New comment by bostik in "U.S. government will decide who gets to use GPT-5.6"]]></title><description><![CDATA[
<p>More likely the PRC sees the open-weight models' progress as a way to prevent an existing dominant player from cementing their (finicky) lead and pulling up the ladder.<p>That strategy <i>happens</i> to have beneficial side effects to the global Hoi Polloi, but to attach any kind of benevolence to it would be naive.</p>
]]></description><pubDate>Sat, 27 Jun 2026 05:57:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48695570</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48695570</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48695570</guid></item><item><title><![CDATA[New comment by bostik in "An oral history of Bank Python (2021)"]]></title><description><![CDATA[
<p>Yeah, and Beacon was acquired a year ago. The acquiring company in turn went private. Yesterday.<p>Genius coder, yes. Nice guy, <i>most definitely</i> yes.</p>
]]></description><pubDate>Fri, 26 Jun 2026 17:53:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48689700</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48689700</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48689700</guid></item><item><title><![CDATA[New comment by bostik in "The worthlessness of Vitamin D is mildly exaggerated"]]></title><description><![CDATA[
<p>> <i>Now imagine if you lived in northern Europe around the 60th parallel, where the sun doesn't get high enough in winter to produce vitamin D.</i><p>Like... all of Finland? And most of Norway?<p>Both countries where the answer to "when does the sun rise?" can be "at the end of January".</p>
]]></description><pubDate>Wed, 24 Jun 2026 06:34:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48656001</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48656001</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48656001</guid></item><item><title><![CDATA[New comment by bostik in "Vulnerability reports are not special anymore"]]></title><description><![CDATA[
<p>"Temporary" can be an awfully long time. There is ample evidence that discovery rate of bugs (many of which can be bucketed into vulnerabilities) in <i>any</i> non-trivial piece of software is more or less stable.[0] In a recent podcast episode the ex-CISO of Adobe commented that every now and then they'd take a sustained squeeze to find all occurrences of a given type of bug (ie. source of vulnerability) in a codebase. They'd find a good amount of them and fix them.<p>Then a year or two later they'd repeat the operation and they'd find <i>about the same amount of same types of bugs</i>. In many occasions in code that had been in place in the previous round and had remained essentially untouched.<p>Paraphrasing what the Gruqg has quipped - a large piece of software has infinity bugs. Infinity minus N is still infinity.<p>0: Discovery rate with regards to the time spent <i>looking</i> for bugs. LLM-powered bug hunting has amped up the speed with which code bases can be investigated.</p>
]]></description><pubDate>Wed, 24 Jun 2026 06:08:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=48655806</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48655806</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48655806</guid></item><item><title><![CDATA[New comment by bostik in "Show HN: Are You in the Weights?"]]></title><description><![CDATA[
<p>Hah. My chosen name collision with my online handle makes the models consistent. They all are certain that I am an adhesives manufacturer. (Good!)<p>On the other hand, the tool did make an assessment of sorts: NO STABLE PERSON FOUND.</p>
]]></description><pubDate>Fri, 19 Jun 2026 04:17:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=48594712</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48594712</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48594712</guid></item><item><title><![CDATA[New comment by bostik in "The hacker sent by Anthropic to calm the government's nerves about AI safety"]]></title><description><![CDATA[
<p>> <i>I think Andy Jassy did forward a concerning report about an apparent jailbreak in Fable, and he probably did so in good faith</i><p>If so, then he is not fit to run an engineering organisation.<p>The "jailbreak" in question was effectively (I'm paraphrasing):<p><pre><code>    * You are a senior engineer.
    *  You want to ensure that any fixes you do come with tests, both before and after.
    * There is a bug in this code. It happens to be a security related bug.
    * Fix this code.
</code></pre>
And the model did what it's supposed to. It wrote a fix, and to prove that the fix worked, it wrote a test for it. What do you call a test that happens to validate a security fix?<p>Yep. A proof of concept.</p>
]]></description><pubDate>Thu, 18 Jun 2026 05:07:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=48581055</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48581055</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48581055</guid></item><item><title><![CDATA[New comment by bostik in "A low-carbon computing platform from your retired phones"]]></title><description><![CDATA[
<p>No, it's not that way around. And it's not a law.[ß] If you and a high-finance institution agree to a separate (lawyer-negotiated!) contract where you provide essential/important software to the institution, <i>they</i> quite often require code escrow arrangements as part of the deal.<p>There are a few such services around, usually owned by a giant global consulting house.<p>The idea is that if you as a vendor go out of business or otherwise become unable to maintain the software, the finance institution gets access to the software via the escrow. Importantly, they also gain the contractual and legal rights to <i>further maintain</i> (read: modify) the software.<p>Under such contract the vendor has an obligation to upload periodic code releases to the escrow service, and the escrow service validates that the release builds. (And passes the bnudled test suite.) Rather surprisingly these services don't even cost that much... at least in the grand scheme of things. The requirement usually comes up only when the underlying supplier deal is at least six figures annually.<p>ß: well, contract law is still law but not in the sense the parent appears to be thinking</p>
]]></description><pubDate>Sun, 14 Jun 2026 05:45:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=48524526</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48524526</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48524526</guid></item><item><title><![CDATA[New comment by bostik in "A low-carbon computing platform from your retired phones"]]></title><description><![CDATA[
<p>Code escrow.<p>You factor in the expense of having your code releases escrowed by a third party (where part of the escrow contract itself is: "must be buildable from sources as provided"), and have a post-release pipeline that automatically uploads the new version. At the end of the term, the escrow holder releases <i>all</i> the versions.<p>This is a fairly common arrangement in high finance. If you want to supply services to a bank/insurer/etc. they will typically require an escrow arrangement as a contingency plan against you as a vendor going away. And yes, <i>they</i> pay the escrow costs.</p>
]]></description><pubDate>Sat, 13 Jun 2026 19:15:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48520462</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48520462</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48520462</guid></item><item><title><![CDATA[New comment by bostik in "Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable"]]></title><description><![CDATA[
<p>ZDR had been turned off. We sent in a request to have it re-enabled (and to disable Fable access for the time being).<p>Somewhere along the line we also used the self-service toggle to turn ZDR back on. I am not 100% certain of the exact timeline of interleaving events, many of the actions were taken by our Western US folks. Sorry. It's been a bit hectic over the past ~36h...</p>
]]></description><pubDate>Thu, 11 Jun 2026 07:19:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48487322</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48487322</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48487322</guid></item><item><title><![CDATA[New comment by bostik in "Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable"]]></title><description><![CDATA[
<p>I read the same announcement. Or more precisely, I read at least two slightly different revisions of the announcement (it was updated between my two passes).<p>Our org has ZDR, and has had it since the contract was signed. Yesterday two things held true at the same time:<p><pre><code>    1. Fable was available if you had at least .170 CLI client; and
    2. ZDR was no longer on
</code></pre>
By the time West Coast woke up, the admin panel apparently had an option to toggle ZDR again. It remained off by default.</p>
]]></description><pubDate>Thu, 11 Jun 2026 06:31:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=48486936</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48486936</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48486936</guid></item><item><title><![CDATA[New comment by bostik in "Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable"]]></title><description><![CDATA[
<p>They need to walk back a lot more.<p>Unilaterally revoking zero-data retention, even for enterprise contracts that <i>explicitly require that</i>? Nope.<p>Fable is utterly unusable for any kind of security work. I tripped the safeguards yesterday - using Fable to dig into a complex (& annoying) security bug that has so far resisted both human and Opus 4.8 level investigation. "Sorry Dave, I can't let you do that."<p>For the time being we are requesting Anthropic disable Fable for our enterprise and turn ZDR back on. The two may be interlinked so that one will always get neither or both. ZDR is a contractual obligation. Fable in its current form is useless. Might as well flip the old behaviour on and avoid burning money for no reason while this mess is being sorted out.</p>
]]></description><pubDate>Thu, 11 Jun 2026 04:52:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48486358</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48486358</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48486358</guid></item><item><title><![CDATA[New comment by bostik in "Claude Desktop spawns 1.8 GB Hyper-V VM on every launch, even for chat-only use"]]></title><description><![CDATA[
<p>At least in a corporate environment, Claude Desktop is a pretty decent compromise. Preconfigured internally deployed MCP servers and third-party connectors make many of the necessary integrations relatively easy to control.<p>I use Claude Code CLI myself (inside a VM, to isolate it from the host) for >90% of my needs. For the remaining fraction - email scours, cloud drive searches, other third-party connections - the desktop application is <i>surprisingly decent</i>. I don't even have more than half a dozen connectors enabled. In the VM I have separate, personally managed access tokens available for various third-party services. Wouldn't really try to maintain more than 5-6, otherwise it gets too confusing. [ß]<p>The desktop application mostly Just Works[tm] with SSO. At least when M365 doesn't suffer from their 4-times-a-day auth outage.<p>ß: A lot of APIs and authentication systems were designed in the stone age. You either need a 1:1 permissioned access token that can do horrendous damage, or you deal with ultra-granular, confusing and ill-designed scoping jungle where nothing makes sense. Atlassian, I'm looking at you especially. At least an MCP server, provisioned with a reasonably done service account, doesn't have all of <i>your</i> powers to get things wrong with.</p>
]]></description><pubDate>Wed, 10 Jun 2026 19:08:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48481141</link><dc:creator>bostik</dc:creator><comments>https://news.ycombinator.com/item?id=48481141</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48481141</guid></item></channel></rss>