<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: brewmarche</title><link>https://news.ycombinator.com/user?id=brewmarche</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 29 Sep 2026 10:19:55 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=brewmarche" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by brewmarche in "Microsoft agentically ports Copilot runtime to Rust for $120K"]]></title><description><![CDATA[
<p>Just checked it and I underestimated. Just before the split it was at 54k LOC: <<a href="https://github.com/dotnet/runtime/blob/b96f3cc738f7fca9474fbe1116148b118eb6563e/src/coreclr/gc/gc.cpp" rel="nofollow">https://github.com/dotnet/runtime/blob/b96f3cc738f7fca9474fb...</a>><p>I’ve also read that a first version of the file came from a Common Lisp to C++ code generation step: <<a href="https://news.ycombinator.com/item?id=23295041">https://news.ycombinator.com/item?id=23295041</a>></p>
]]></description><pubDate>Mon, 21 Sep 2026 15:39:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49788700</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49788700</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49788700</guid></item><item><title><![CDATA[New comment by brewmarche in "Microsoft agentically ports Copilot runtime to Rust for $120K"]]></title><description><![CDATA[
<p>Until recently the .NET garbage collector used to be a single 30,000+ line C++ file. And it was maintained by one person if I remember correctly.</p>
]]></description><pubDate>Sun, 20 Sep 2026 12:11:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=49775022</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49775022</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49775022</guid></item><item><title><![CDATA[Joy's Law (Management)]]></title><description><![CDATA[
<p>Article URL: <a href="https://en.wikipedia.org/wiki/Joy%27s_law_(management)">https://en.wikipedia.org/wiki/Joy%27s_law_(management)</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49770730">https://news.ycombinator.com/item?id=49770730</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 19 Sep 2026 22:45:17 +0000</pubDate><link>https://en.wikipedia.org/wiki/Joy%27s_law_(management)</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49770730</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49770730</guid></item><item><title><![CDATA[New comment by brewmarche in "Small programming tricks"]]></title><description><![CDATA[
<p>Didn’t know about that one, and can’t find any references, but works in my fish<p>I’ve always used Ctrl+U, it’s an Emacs shortcut, so it works in many shells and other prompts (especially since readline supports it) by default.<p>(For example Ctrl+Opt+- doesn’t seem to work in the Python REPL whereas Ctrl+U does.)</p>
]]></description><pubDate>Wed, 16 Sep 2026 21:30:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=49733298</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49733298</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49733298</guid></item><item><title><![CDATA[New comment by brewmarche in "We got admin access to Baseten's production GitHub"]]></title><description><![CDATA[
<p>Yeah I have seen this issue a few times. If you use Docker build arguments that way add `--provenance=false` to get rid of all that build metadata. Build secrets are still better since they allow you to scope the secret inside of the Dockerfile. Also, the metadata can be useful to inspect images.</p>
]]></description><pubDate>Tue, 15 Sep 2026 18:43:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=49716931</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49716931</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49716931</guid></item><item><title><![CDATA[New comment by brewmarche in "Why is the x86 undefined instruction called ud2? Why 2?"]]></title><description><![CDATA[
<p>I thought MS-DOS had special handling for A: and B: since it allowed you to copy from A: to B: even with just one floppy drive.</p>
]]></description><pubDate>Sun, 13 Sep 2026 16:27:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=49685728</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49685728</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49685728</guid></item><item><title><![CDATA[New comment by brewmarche in "Asahi Linux on M3"]]></title><description><![CDATA[
<p>Apologies, I focused on LLVM as a whole. You are right about clang (and I didn’t know about the arm64 backend)</p>
]]></description><pubDate>Wed, 09 Sep 2026 19:06:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=49632331</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49632331</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49632331</guid></item><item><title><![CDATA[New comment by brewmarche in "Asahi Linux on M3"]]></title><description><![CDATA[
<p>They asked about ‘originated’ in particular.</p>
]]></description><pubDate>Tue, 08 Sep 2026 09:25:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=49607833</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49607833</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49607833</guid></item><item><title><![CDATA[New comment by brewmarche in "Asahi Linux on M3"]]></title><description><![CDATA[
<p>Swift comes to mind, and this website has more <a href="https://opensource.apple.com/projects/" rel="nofollow">https://opensource.apple.com/projects/</a> (it lists WebKit, but I guess they count WebKit after it split from KHTML, I’d agree with you there)<p>Also, Bonjour originated at Apple and it is cross-platform, although Avahi probably is more popular<p>CUPS is associated with Apple as well, but it seems that it also did not originate there</p>
]]></description><pubDate>Mon, 07 Sep 2026 13:42:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=49598368</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49598368</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49598368</guid></item><item><title><![CDATA[New comment by brewmarche in ".gitignore Everything by Default"]]></title><description><![CDATA[
<p><a href="https://github.com/github/gitignore/blob/main/Global/macOS.gitignore" rel="nofollow">https://github.com/github/gitignore/blob/main/Global/macOS.g...</a></p>
]]></description><pubDate>Sun, 06 Sep 2026 16:19:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=49588001</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49588001</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49588001</guid></item><item><title><![CDATA[New comment by brewmarche in ".gitignore Everything by Default"]]></title><description><![CDATA[
<p>But they do: <a href="https://github.com/github/gitignore/blob/main/Global/VisualStudioCode.gitignore" rel="nofollow">https://github.com/github/gitignore/blob/main/Global/VisualS...</a><p>You need to merge the relevant ignore files to create one specific for you, so if you use VSCode on macOS VisualStudioCode.gitignore (e.g., .vscode) + macOS.gitignore (e.g., .DS_Store). There are files for other OSs and editors as well. Technically their README says that the Global folder is intended for user-specific ignore files. But you can still use them for the repo .gitignore.<p>There is also this API which you can curl: <a href="https://gitignore.io/api/macos,vscode" rel="nofollow">https://gitignore.io/api/macos,vscode</a><p>Some of the templates seem to be identical, but I think they are not in sync.</p>
]]></description><pubDate>Sun, 06 Sep 2026 16:18:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=49587991</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49587991</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49587991</guid></item><item><title><![CDATA[New comment by brewmarche in "Ask HN: Who wants to be hired? (September 2026)"]]></title><description><![CDATA[
<p><p><pre><code>  Location: Germany (UTC +1/+2), EU citizen
  Remote: preferred
  Willing to relocate: no
  Technologies: C# and previously C++ and Java, prefer functional style and privately dabble with F# and Haskell. I know SQL, Azure, Docker, high performance computing (Monte Carlo simulations), see also CV
  CV: https://stash.ldr.name/wwtbh/rcv-202609-vfay7k0zano.pdf
  Email: see CV
</code></pre>
I work in mathematical finance so a lot of domain knowledge in that area (derivatives, pricing, probability theory).<p>I am looking for work in other domains as well.<p>Happy to provide you with a full CV personally.</p>
]]></description><pubDate>Tue, 01 Sep 2026 19:42:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=49527050</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49527050</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49527050</guid></item><item><title><![CDATA[New comment by brewmarche in "A CVE Dispute"]]></title><description><![CDATA[
<p>One could argue that this is not an issue with pip, the software, but of the index used. I mean, if you control both index and extra-index there is no problem (and one solution to this is to use your own mirror with a set resolution order). This could very well be addressed in PyPI, for example NuGet allows to reserve package prefixes.<p>We also do not create a CVE for curl because you can use it to download the wrong bash script. If this was an alert for suspicious usages of pip instead of pip itself, I’d be less critical of it.</p>
]]></description><pubDate>Tue, 01 Sep 2026 19:13:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=49526629</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49526629</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49526629</guid></item><item><title><![CDATA[New comment by brewmarche in "A CVE Dispute"]]></title><description><![CDATA[
<p>For the attack you mentioned (reusing internal packages in a public repository) prefix reservation is one possible solution. Unfortunately PyPI does not support it.</p>
]]></description><pubDate>Mon, 31 Aug 2026 17:14:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49512200</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49512200</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49512200</guid></item><item><title><![CDATA[New comment by brewmarche in "A CVE Dispute"]]></title><description><![CDATA[
<p>Maybe I was too harsh. It’s the CVE in conjunction with its high severity, the maintainers’ decision and the bundling of pip with CPython. In the end what can you do about it as a dev given that the pip maintainers have decided not to fix it? The only option is not to use pip at all (and sure, you can see the CVE as a critique of pip in a way), or discuss with your security team in hope for some exclusion. And since pip or at least ensurepip are part of Python you get a lot of these scan results<p>E: and if you decide not to use pip I don’t think there’s an official way to remove ensurepip, I typically rm -rf inside of site-packages, it works but doesn’t feel correct</p>
]]></description><pubDate>Mon, 31 Aug 2026 16:26:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=49511627</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49511627</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49511627</guid></item><item><title><![CDATA[New comment by brewmarche in "A CVE Dispute"]]></title><description><![CDATA[
<p>Yes, I’ve also experienced this kind of attitude. Some scanning tools can detect that certain CVEs do not apply because the specific functionality is not used.<p>I hope your team was OK with you uninstalling the VMware package manually (this is actually not a bad outcome if you don’t use that package)<p>There are also ridiculous CVEs like CVE-2018-20225 for pip, which will not get fixed as that behaviour is by design (but here as well it might be a good idea to strip pip if it’s not used)</p>
]]></description><pubDate>Mon, 31 Aug 2026 13:37:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=49509647</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49509647</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49509647</guid></item><item><title><![CDATA[New comment by brewmarche in "Casey Muratori – The Root of the Root of All Evil – BSC 2026 [video]"]]></title><description><![CDATA[
<p>In other videos Casey argues against the profile–fix–repeat workflow (I’m not saying that you necessarily meant this by measuring), instead arguing for estimating the theoretical maximum, then trying to get close enough to it. His argument is that the former might push you towards a local minimum without realising that you could do much better</p>
]]></description><pubDate>Sun, 30 Aug 2026 16:06:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49499921</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49499921</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49499921</guid></item><item><title><![CDATA[New comment by brewmarche in "Asahi Linux Progress Report: Linux 7.2"]]></title><description><![CDATA[
<p>Aren’t the shortcuts with the command key older than the PC ones (which started out as Shift+Insert etc. actually)? I wouldn’t call that desire to be different (also as mentioned below it has a lot of advantages in a terminal)</p>
]]></description><pubDate>Thu, 27 Aug 2026 09:44:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=49462140</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49462140</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49462140</guid></item><item><title><![CDATA[New comment by brewmarche in "A decades-old bug in Knuth's long division (TAOCP Vol II, Algorithm 4.3.1D)"]]></title><description><![CDATA[
<p>There’s a funny explanation at the bottom:<p>> It turns out that only 9 of the first 275 checks that I've sent out since the beginning of 2006 have actually been cashed. The others have apparently been cached. So this change in policy will probably not affect too many people. On the other hand, I don't like to renege on promises, so I shall do my best to find a suitable way to send money to anyone who really prefers legal tender.</p>
]]></description><pubDate>Sun, 23 Aug 2026 14:51:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=49409306</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49409306</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49409306</guid></item><item><title><![CDATA[New comment by brewmarche in "Splitting a Git Commit"]]></title><description><![CDATA[
<p>The Law Stack Exchange tags answers with the jurisdictions they apply to, but I think that’s the only StackExchange site that allows tags on answers.</p>
]]></description><pubDate>Thu, 20 Aug 2026 10:38:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49372799</link><dc:creator>brewmarche</dc:creator><comments>https://news.ycombinator.com/item?id=49372799</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49372799</guid></item></channel></rss>