<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: csande17</title><link>https://news.ycombinator.com/user?id=csande17</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 12 Aug 2026 12:12:09 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=csande17" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by csande17 in "Show HN: Gander, an Android file viewer that asks for no permissions"]]></title><description><![CDATA[
<p>Yeah, Android's sandbox deals with low-level file access and socket APIs and stuff. But Android also, intentionally, allows apps to expose their data and functionality to other apps via the higher-level "intent" system.<p>Apps get to choose what permissions are needed to access their intents, so under Android's security model, really it's <i>Chrome's</i> fault (or whatever browser the user has installed) for exposing an intent that allows apps that don't have the INTERNET permission to exfoltrate data.<p>Similarly, apps are also allowed to collude to share data with each other if they want; that's how stuff like Google Play Services works.</p>
]]></description><pubDate>Fri, 31 Jul 2026 09:57:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=49121136</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=49121136</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49121136</guid></item><item><title><![CDATA[New comment by csande17 in "VLC for Unity now supported on Linux"]]></title><description><![CDATA[
<p>Unity includes its own video player implementation ( <a href="https://docs.unity3d.com/Manual/Video.html" rel="nofollow">https://docs.unity3d.com/Manual/Video.html</a> ), so presumably you'd mainly want to use VLC for wider range of supported codecs?</p>
]]></description><pubDate>Mon, 27 Jul 2026 12:21:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49068621</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=49068621</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49068621</guid></item><item><title><![CDATA[New comment by csande17 in "Over 400 Linux CVEs published in the last 24 hours alone"]]></title><description><![CDATA[
<p><a href="https://docs.kernel.org/process/cve.html" rel="nofollow">https://docs.kernel.org/process/cve.html</a><p>> Note, due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel, but the possibility of exploitation is often not evident when the bug is fixed. Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify. This explains the seemingly large number of CVEs that are issued by the Linux kernel team.<p>(And because this happens during the stable release process, there are a lot of 24-hour periods where they issue a ton of CVEs for all the minor bugs fixed in the release.)</p>
]]></description><pubDate>Tue, 21 Jul 2026 14:32:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48992878</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48992878</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48992878</guid></item><item><title><![CDATA[New comment by csande17 in "The largest available Minecraft world, totalling 15 TB"]]></title><description><![CDATA[
<p>"Anarchy" in Minecraft means no rules, and "you can't say bad words (or build things containing bad words)" is a rule.</p>
]]></description><pubDate>Tue, 14 Jul 2026 23:30:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=48914315</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48914315</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48914315</guid></item><item><title><![CDATA[New comment by csande17 in "Are you telling me a readonly property is wrecking my performance?"]]></title><description><![CDATA[
<p>The scrollHeight property: <a href="https://developer.mozilla.org/en-US/docs/Web/API/Element/scrollHeight" rel="nofollow">https://developer.mozilla.org/en-US/docs/Web/API/Element/scr...</a></p>
]]></description><pubDate>Mon, 13 Jul 2026 12:15:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48891542</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48891542</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48891542</guid></item><item><title><![CDATA[New comment by csande17 in "What xAI's Grok build CLI sends to xAI: A wire-level analysis"]]></title><description><![CDATA[
<p>I think there's maybe a disconnect here that people are largely concerned with the contents of their private repos, while you're maybe more familiar with how AI interaction data is handled. (After all, the original topic of the thread was X.ai allegedly going above and beyond interaction data to exfiltrate entire repos.)<p>I personally did get the vibe that you were being evasive, just because the things you were saying didn't quite match what people were asking about, in a way that felt kind of like a corporate legally-not-a-denial denial. It's like, "Hey, has Contoso Apartments hidden a camera in my bathroom?" "Contoso Apartments is committed to your privacy and safety. We have strict controls in place to ensure that our maintenance staff cannot make a copy of your key without notifying you. To the best of my knowledge, we do not have any company initiative that involves opening envelopes addressed to you." Like it's theoretically reassuring for the company to commit to those things, but the fact that they can't directly answer the original question is disconcerting.<p>Ultimately there's probably not a whole lot you can do about this. Like realistically if Microsoft is doing this, they've probably constructed it in a way where not many people know and/or they can plausibly deny it. So it comes down to (a) Microsoft denies doing it, but isn't making the broadest legally binding commitment possible, (b) does the reader believe Microsoft and OpenAI are trustworthy with respect to privacy and intellectual property issues or not.<p>I've been in this kind of situation before, and it can be frustrating when people don't believe that you're in a good, isolated department of the company and you're committed to upholding ethical standards. I guess that's why big companies pay the big bucks :)</p>
]]></description><pubDate>Sun, 12 Jul 2026 10:50:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48880065</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48880065</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48880065</guid></item><item><title><![CDATA[New comment by csande17 in "What xAI's Grok build CLI sends to xAI: A wire-level analysis"]]></title><description><![CDATA[
<p>(FWIW, in my conspiracy theory, the data sharing would be buried in the part of the company responsible for making sure that people don't upload e.g. CSAM to private repositories, so the Copilot people wouldn't be directly aware of it. I might've edited that in after you already started writing your reply though.)</p>
]]></description><pubDate>Sun, 12 Jul 2026 07:01:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48879001</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48879001</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48879001</guid></item><item><title><![CDATA[New comment by csande17 in "What xAI's Grok build CLI sends to xAI: A wire-level analysis"]]></title><description><![CDATA[
<p>This is a nice answer to the question "how is GitHub preventing rogue employees at Microsoft from stealing my private repositories?". Like, it's good to know I'm covered if Microsoft accidentally hires a North Korean spy or something.<p>But if Microsoft really was selling private repo content to OpenAI, it probably wouldn't go through those access controls. It'd be an executive-level decision with enough force to plow through all the red tape, and it'd be implemented as a data pipeline or similar automated process that wouldn't trigger the same kind of notification as, like, a Trust and Safety employee taking manual action.<p>Probably the better evidence here is in GitHub's ToS where they say in pretty strong/binding terms that they aren't doing this: <a href="https://docs.github.com/en/site-policy/github-terms/github-terms-of-service#e-private-repositories" rel="nofollow">https://docs.github.com/en/site-policy/github-terms/github-t...</a> . If they are secretly selling your data to OpenAI they haven't left themselves a ton of wiggle room if people ever found out.<p>(Probably the biggest loophole they could use is to send private repo content to an OpenAI service for scanning/safety purposes. The ToS allows this and they're almost certainly doing it with other services like PhotoDNA. Then OpenAI can just violate whatever agreement they have not to store the data sent to that service.)</p>
]]></description><pubDate>Sun, 12 Jul 2026 06:23:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48878826</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48878826</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48878826</guid></item><item><title><![CDATA[New comment by csande17 in "Train sim created by just one person is being called the best ever made"]]></title><description><![CDATA[
<p>Unreal Engine's been free for just over 11 years now: <a href="https://www.unrealengine.com/blog/ue4-is-free" rel="nofollow">https://www.unrealengine.com/blog/ue4-is-free</a></p>
]]></description><pubDate>Fri, 10 Jul 2026 06:24:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48856432</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48856432</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48856432</guid></item><item><title><![CDATA[New comment by csande17 in "My thoughts on the Bun Rust rewrite"]]></title><description><![CDATA[
<p>> [T]he Bun project lead can do whatever the hell he wants with his own project. There is no objectively "right" path here, in a moral sense.<p>I think this is the exact point that the article was getting at in the last section. It is okay to not be very good at software engineering or people management! It is useful to know these things if you want to understand why the Bun project made specific technical decisions, but they don't make the people involved "bad people" in a more nebulous moral sense.<p>The lead developer of Zig is discussing these factors because the main technical decision was moving away from Zig.</p>
]]></description><pubDate>Thu, 09 Jul 2026 19:38:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=48851332</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48851332</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48851332</guid></item><item><title><![CDATA[New comment by csande17 in "My thoughts on the Bun Rust rewrite"]]></title><description><![CDATA[
<p>Bun's bundler claimed the bottom place in my recent analysis of how JavaScript tools handle generating inline script tags[1], because despite making lofty promises about being able to bundle applications into standalone HTML files, it produced a baffling combination of spurious syntax errors and miscompilations when presented with tricky code.<p>I'm pretty sure the version I tested was the Zig one (have they made a stable release of the Rust rewrite yet?). So I can definitely see how Bun's move-fast-and-break-things philosophy would have been a poor fit for the Zig community, even prior to the Rust rewrite.<p>[1] <a href="https://carter.sande.duodecima.technology/inline-script-pitfalls/#bun" rel="nofollow">https://carter.sande.duodecima.technology/inline-script-pitf...</a></p>
]]></description><pubDate>Thu, 09 Jul 2026 12:22:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48844740</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48844740</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48844740</guid></item><item><title><![CDATA[New comment by csande17 in "A bug which affected only left handed users"]]></title><description><![CDATA[
<p>Scissors are the other big one; most of them are designed so that when to try to use them with your left hand, you end up pushing the blades apart slightly so they don't cut as well (or at all).<p>With that being said, self-deprecating jokes about how left-handedness is an affront to God are definitely a prominent feature of lefty culture.<p>(Edit: I guess formal place-setting is another area of society that assumes right-handedness, as well as restaurants that pack people close enough together that everyone needs to use the same hands to avoid elbowing each other.)</p>
]]></description><pubDate>Thu, 09 Jul 2026 03:05:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=48840482</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48840482</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48840482</guid></item><item><title><![CDATA[New comment by csande17 in "98% Isn't Much"]]></title><description><![CDATA[
<p>It's really easy to serve fallback images to browsers that don't support AVIF, either client-side using the <picture> tag or server-side via the Accept header. Which mostly eliminates the concern from the article, since you don't have to drop support for any customers.<p>It kind of makes me wonder if anyone has made a build system / framework that serves nested CSS to modern browsers, and falls back to a preprocessed CSS file that removes all the nesting for older browsers.</p>
]]></description><pubDate>Tue, 07 Jul 2026 13:35:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48817629</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48817629</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48817629</guid></item><item><title><![CDATA[New comment by csande17 in "NSA and IETF: Fairness"]]></title><description><![CDATA[
<p>He makes the legal argument in more detail in <a href="https://blog.cr.yp.to/20251004-weakened.html#standards" rel="nofollow">https://blog.cr.yp.to/20251004-weakened.html#standards</a><p>The gist of it is that standards organizations like the IETF depend on a specific carve-out in US antitrust law (in order for it to be legal for American companies like Cisco and Google to participate in them), and that carve-out includes a specific definition of what "standards organizations" and "consensus" are. So even if the IETF uses different words to describe its processes, those processes still have to comply with the legal definition that separates a "standards organization" from, like, an illegal cartel.</p>
]]></description><pubDate>Tue, 07 Jul 2026 06:18:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48814250</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48814250</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48814250</guid></item><item><title><![CDATA[Every JavaScript bundler handles inline script tags wrong]]></title><description><![CDATA[
<p>Article URL: <a href="https://carter.sande.duodecima.technology/inline-script-pitfalls/">https://carter.sande.duodecima.technology/inline-script-pitfalls/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48795633">https://news.ycombinator.com/item?id=48795633</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 05 Jul 2026 16:44:15 +0000</pubDate><link>https://carter.sande.duodecima.technology/inline-script-pitfalls/</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48795633</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48795633</guid></item><item><title><![CDATA[New comment by csande17 in "If you're a button, you have one job"]]></title><description><![CDATA[
<p>Maybe I misread the article, but I think the Nothing photos app is literally ignoring the second tap, not just failing to provide feedback</p>
]]></description><pubDate>Sun, 05 Jul 2026 08:08:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=48792240</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48792240</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48792240</guid></item><item><title><![CDATA[New comment by csande17 in "If you're a button, you have one job"]]></title><description><![CDATA[
<p>> Why? How, even, have they implemented this?<p>This is really common because of two design features that most UI frameworks share:<p>- The code that changes the color of the button is an internal part of the "button" component, so that people don't have to individually implement it on every button. But this means that it's kind of disconnected from the code that actually performs the action. If the "on click" handler has some last-ditch check that aborts the action, like the "don't rotate the image if it's in the middle of the rotate animation" check from the article, often there's no way for it to tell the button to cancel the color change. (And conversely sometimes the "on click" handler can fire even if the color change animation doesn't play correctly.)<p>- Buttons usually change color when you press down the mouse button, but only perform the action when you release the mouse button. Sometimes this is used to intentionally give you a chance to cancel the action at the very last minute by dragging your mouse off the button while it's still held down (or, on mobile, to e.g. reinterpret your interaction as scrolling instead of clicking), other times it just creates more opportunities for something to happen that prevents the action from working after the color change has already happened.</p>
]]></description><pubDate>Sun, 05 Jul 2026 07:50:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=48792136</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48792136</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48792136</guid></item><item><title><![CDATA[New comment by csande17 in "It's not me, it's the compiler"]]></title><description><![CDATA[
<p>Rust has a feature called "tuple structs" where the properties of the struct are accessed by numeric indices instead of names: <a href="https://doc.rust-lang.org/book/ch05-01-defining-structs.html#creating-different-types-with-tuple-structs" rel="nofollow">https://doc.rust-lang.org/book/ch05-01-defining-structs.html...</a> / <a href="https://doc.rust-lang.org/book/ch05-02-example-structs.html#refactoring-with-tuples" rel="nofollow">https://doc.rust-lang.org/book/ch05-02-example-structs.html#...</a><p>In most other languages this would be written as "this.current_index" or some other property name.</p>
]]></description><pubDate>Sun, 05 Jul 2026 07:16:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=48791967</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48791967</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48791967</guid></item><item><title><![CDATA[New comment by csande17 in "If you're a button, you have one job"]]></title><description><![CDATA[
<p>iOS has an accessibility option called "Ignore Repeats", which seems like a better approach because it's system-wide. So people who need that kind of accommodation can have it in places like the on-screen keyboard too, without needing everyone else to slow down their typing.</p>
]]></description><pubDate>Sun, 05 Jul 2026 07:09:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48791939</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48791939</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48791939</guid></item><item><title><![CDATA[New comment by csande17 in "If you're a button, you have one job"]]></title><description><![CDATA[
<p>It's not really a question of <i>how many</i> taps they support, but <i>how fast</i>.<p>This same issue also seems like it would prevent you from quickly double-tapping the button to turn an image upside-down, a much more common use case.</p>
]]></description><pubDate>Sun, 05 Jul 2026 07:05:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48791917</link><dc:creator>csande17</dc:creator><comments>https://news.ycombinator.com/item?id=48791917</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48791917</guid></item></channel></rss>