<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: c2h5oh</title><link>https://news.ycombinator.com/user?id=c2h5oh</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 24 Apr 2026 20:28:20 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=c2h5oh" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by c2h5oh in "Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign"]]></title><description><![CDATA[
<p>They are not, but npm is uniquely bad in that regard. Refusal to implement security features that would have made attacks like this harder really doesn't help <a href="https://github.com/node-forward/discussions/issues/29" rel="nofollow">https://github.com/node-forward/discussions/issues/29</a></p>
]]></description><pubDate>Thu, 23 Apr 2026 21:06:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=47881992</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=47881992</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47881992</guid></item><item><title><![CDATA[New comment by c2h5oh in "Pink noise reduces REM sleep and may harm sleep quality"]]></title><description><![CDATA[
<p>7 nights is not nearly enough to get used to new environmental factor introduced in the study, possibly exacerbating disruption from sleeping in a new place (sleep clinic).<p>n=25? Seriously?<p>This is barely passable as an early hypothesis test before you perform an actual study.</p>
]]></description><pubDate>Mon, 16 Feb 2026 01:52:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=47029978</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=47029978</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47029978</guid></item><item><title><![CDATA[New comment by c2h5oh in "Capital One to acquire Brex for $5.15B"]]></title><description><![CDATA[
<p>Majority of EU population. Even in US debit is more popular than credit in 18-25 age bracket.</p>
]]></description><pubDate>Fri, 23 Jan 2026 01:22:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=46727241</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=46727241</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46727241</guid></item><item><title><![CDATA[New comment by c2h5oh in "AMD GPU Debugger"]]></title><description><![CDATA[
<p>GDB supports it <a href="https://sourceware.org/gdb/current/onlinedocs/gdb.html/AMD-GPU.html" rel="nofollow">https://sourceware.org/gdb/current/onlinedocs/gdb.html/AMD-G...</a><p>You also get UMR from AMD <a href="https://gitlab.freedesktop.org/tomstdenis/umr" rel="nofollow">https://gitlab.freedesktop.org/tomstdenis/umr</a><p>There is also a bunch of other tools provided: 
<a href="https://gpuopen.com/radeon-gpu-detective/" rel="nofollow">https://gpuopen.com/radeon-gpu-detective/</a> <a href="https://gpuopen.com/news/introducing-radeon-developer-tool-suite/" rel="nofollow">https://gpuopen.com/news/introducing-radeon-developer-tool-s...</a></p>
]]></description><pubDate>Mon, 08 Dec 2025 17:37:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=46195175</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=46195175</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46195175</guid></item><item><title><![CDATA[New comment by c2h5oh in "Discontinuation of ARM Notebook with Snapdragon X Elite SoC"]]></title><description><![CDATA[
<p>Qualcomm doesn't bother to upstream most of their SoCs. They maintain a fork of a specific Linux kernel version for a while and when they stop updating it or new version of Android requires newer kernel then updates for all devices based on that SoC end.<p>They have little experience producing code that is high enough quality it would be accepted into Linux kernel. They have even less experience maintaining it for an extended period of time.</p>
]]></description><pubDate>Sat, 22 Nov 2025 17:14:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=46016320</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=46016320</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46016320</guid></item><item><title><![CDATA[New comment by c2h5oh in "A new chapter begins for EV batteries with the expiry of key LFP patents"]]></title><description><![CDATA[
<p>I'd agree if you could stick them in the containers discharged, but you can't. This means that even safer chemistry like sodium battery is still hazardous cargo.</p>
]]></description><pubDate>Mon, 17 Nov 2025 11:42:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=45952767</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=45952767</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45952767</guid></item><item><title><![CDATA[New comment by c2h5oh in "A new chapter begins for EV batteries with the expiry of key LFP patents"]]></title><description><![CDATA[
<p>The small handful of sodium batteries that are currently available retail all seem to have rather bad roundtrip efficiency compared to LFP and voltage drop starting at a high state of charge.<p>Also LFP prices dropped enough that shipping cost from China became a significant part of the price. This will be even more of a factor should the less energy dense sodium batteries ever reach the promised $30/kWh.</p>
]]></description><pubDate>Mon, 17 Nov 2025 05:48:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=45951128</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=45951128</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45951128</guid></item><item><title><![CDATA[New comment by c2h5oh in "Novo Nordisk's Canadian Mistake"]]></title><description><![CDATA[
<p>With de minimis for US-bound packages suspended I suspect way more packages are inspected than used to be.</p>
]]></description><pubDate>Sun, 19 Oct 2025 22:29:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=45638619</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=45638619</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45638619</guid></item><item><title><![CDATA[New comment by c2h5oh in "The graduate 'jobpocalypse': Where have all the entry-level jobs gone? [video]"]]></title><description><![CDATA[
<p>Similar three stages are also at every job you have:<p>- you underperform while onboarding and rapidly learning to cover whatever skill gaps you discover<p>- you slowly go from doing OK to being overqualified, but it doesn't get reflected in compensation or title enough and your employer has little incentive to help you reach the next stage, because you are currently overperforming compared to your pay<p>- you are so much past your paygrade you quit and go to a company that will pay you what you will be worth after onboarding and learning to cover skill gaps<p>With everything that companies provided to earn long term employee loyalty being sacrificed to stock price employee growth through multiple roles in the same company has become more of an exception.</p>
]]></description><pubDate>Mon, 29 Sep 2025 12:35:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=45412950</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=45412950</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45412950</guid></item><item><title><![CDATA[New comment by c2h5oh in "Time Spent on Hardening"]]></title><description><![CDATA[
<p>Unless you equate web development and SaaS then no. It's the same in education, finance and SaaS targeting Fortune 500 companies.<p>Source: most of the companies I worked or consulted for in the past 20 years.</p>
]]></description><pubDate>Fri, 19 Sep 2025 23:11:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=45307890</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=45307890</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45307890</guid></item><item><title><![CDATA[New comment by c2h5oh in "Time Spent on Hardening"]]></title><description><![CDATA[
<p>This is not a "companies don't spend enough time with static and dynamic analysis of their software" problem, it's "less than a third of companies I worked or consulted for in the past 20 years mandated having input validation of any kind" problem.</p>
]]></description><pubDate>Fri, 19 Sep 2025 21:30:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=45306879</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=45306879</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45306879</guid></item><item><title><![CDATA[New comment by c2h5oh in "Time Spent on Hardening"]]></title><description><![CDATA[
<p>I was once told to stop wasting time submitting PRs adding null checks on data submitted via a public API. You know, the kind of checks that prevented said API from crashing if a part of payload was missing. I was told to stop again with my concerns dismissed when I pointed similar things out during code review. I left that company not long after, but it's still around with over a quarter of a billion in funding.<p>I would love to say that this was an exception during almost 20 years of my professional career, but it wasn't. It was certainly the worst, but also much closer to average experience than it should have been.</p>
]]></description><pubDate>Fri, 19 Sep 2025 21:21:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=45306782</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=45306782</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45306782</guid></item><item><title><![CDATA[New comment by c2h5oh in "Time Spent on Hardening"]]></title><description><![CDATA[
<p>The time spend on hardening software is always zero or very close to that unless the company makes that hardening a selling point of the product they make.<p>In the world of VC powered growth race to bigger and bigger chunk of market seems to be the only thing that matters. You don't optimize your software, you throw money at the problem and get more VMs from your cloud provider. You don't work on fault tolerance, you add a retry on FE. You don't carefully plan and implement security, you create a bug bounty.<p>It sucks and I hate it.</p>
]]></description><pubDate>Fri, 19 Sep 2025 20:58:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=45306498</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=45306498</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45306498</guid></item><item><title><![CDATA[New comment by c2h5oh in "%CPU utilization is a lie"]]></title><description><![CDATA[
<p>To complicate things more HT performance varies wildly between CPU architectures and workloads. e.g. AMD implementation, especially in later Zen cores, is closer to a performance of a full thread than you'd see in Intel CPUs. Provided you are not memory bandwidth starved.</p>
]]></description><pubDate>Wed, 03 Sep 2025 02:41:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=45111744</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=45111744</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45111744</guid></item><item><title><![CDATA[New comment by c2h5oh in "What Are Traces and Spans in OpenTelemetry?"]]></title><description><![CDATA[
<p>That's why you sample just enough instead of storing everything</p>
]]></description><pubDate>Sun, 31 Aug 2025 14:42:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=45083511</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=45083511</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45083511</guid></item><item><title><![CDATA[New comment by c2h5oh in "Libxml2's "no security embargoes" policy"]]></title><description><![CDATA[
<p>With SAAS swallowing big chunk of software business GPL is much less effective.<p>There isn't much difference between MIT and GPL unless you are selling a product that runs locally or on premisses and with the latter some companies try to work around GPL by renting servers with software on it - either as physical boxes or something provided on cloud provider marketplace.<p>Look at what you actually have installed on your computer - odds are that unless your job requires something like CAD, photo/video editing or other highly specialized software you have nothing made by large enterprise with exception of OS and Slack/Teams/Zoom.</p>
]]></description><pubDate>Thu, 26 Jun 2025 09:08:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=44385565</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=44385565</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44385565</guid></item><item><title><![CDATA[New comment by c2h5oh in "AMD's Strix Halo under the hood"]]></title><description><![CDATA[
<p>APUs are going to replace low end video cards, because they no longer make economical or technical sense.<p>Historically those cards had narrow memory bus and about a quarter or less video memory of high end (not even halo) cards from the same generation.<p>That narrow memory bus puts their max memory bandwidth at a comparable level to desktop DDR5 with 2 DIMMs. At the same time quarter of high end is just 4GB VRAM which is not enough for low details for many games and prevents upscaling/frame gen from working.<p>From manufacturing standpoint low end GPUs aren't great either - memory controllers, video output and a bunch of other non-compute components don't scale with process node.<p>At the same time unified memory and bypassing PCIE benefits igpus greatly. You don't have to build an entire card, power delivery, cooler - you just slightly beef up existing ones.<p>tl;dr; sub-200 dollas GPUs are dead and will be replaced by APUs. I won't be surprised if they will start nibbling at lower mid-range market too in the near future.</p>
]]></description><pubDate>Fri, 14 Mar 2025 11:34:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=43361615</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=43361615</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43361615</guid></item><item><title><![CDATA[New comment by c2h5oh in "Huawei targeted in new European Parliament corruption probe"]]></title><description><![CDATA[
<p>They have a significant DSLAM markeshare too</p>
]]></description><pubDate>Thu, 13 Mar 2025 11:05:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=43352105</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=43352105</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43352105</guid></item><item><title><![CDATA[New comment by c2h5oh in "Nvidia's RTX 5090 power connectors are melting"]]></title><description><![CDATA[
<p>- Most 12VHPWR connectors are rated to 9.5-10A per pin. 600W / 12V / 6 pin pairs = 8.33A. Spec requires 10% safety factor - 9.17A.<p>- 12VHPWR connectors are compatible with 18ga or at best 16ga cables. For 90C rated single core copper wires I've seen max allowed amperages of at most 14A for 18ga and 18A for 16ga. Less in most sources.. Near the connectors those wires are so close they can't be considered single core for purpose of heat dissipation..</p>
]]></description><pubDate>Tue, 11 Feb 2025 16:56:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=43015109</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=43015109</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43015109</guid></item><item><title><![CDATA[New comment by c2h5oh in "Beekeepers halt honey awards over fraud in global supply chain"]]></title><description><![CDATA[
<p>Better yet befriend a beekeeper. You gain a friend and honey.</p>
]]></description><pubDate>Sat, 07 Dec 2024 19:02:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=42351962</link><dc:creator>c2h5oh</dc:creator><comments>https://news.ycombinator.com/item?id=42351962</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42351962</guid></item></channel></rss>