<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: david_shaw</title><link>https://news.ycombinator.com/user?id=david_shaw</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 21 Jun 2026 02:17:09 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=david_shaw" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by david_shaw in "Agency stole bestselling author's book, used AI to relaunch as their own"]]></title><description><![CDATA[
<p>I'm playing through the couch co-op game <i>Split Fiction,</i> and this is basically the premise (with more fun gameplay).</p>
]]></description><pubDate>Sat, 20 Jun 2026 18:42:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=48611761</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=48611761</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48611761</guid></item><item><title><![CDATA[New comment by david_shaw in "Policy on the AI Exponential"]]></title><description><![CDATA[
<p><i>> A nation that possesses powerful AI facing one without it—or even facing one that is behind in AI by 3 years—could be the equivalent of an army of World War II Marines facing an army of medieval swordsmen.</i><p>This is a somewhat ironic take from someone who very publicly feuded with the US government about whether their AI could be used for waging war.</p>
]]></description><pubDate>Wed, 10 Jun 2026 20:32:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48482252</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=48482252</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48482252</guid></item><item><title><![CDATA[New comment by david_shaw in "Policy on the AI Exponential"]]></title><description><![CDATA[
<p><i>> we might have wished we prepared for more</i><p>Do you mean policy-wise (like Dario is talking about), or more broadly?<p>I wonder about broad preparedness, but unfortunately there's not a lot that we "normal" people can do to prepare. Hoard savings and food? Learn physical trades?</p>
]]></description><pubDate>Wed, 10 Jun 2026 20:24:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=48482141</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=48482141</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48482141</guid></item><item><title><![CDATA[New comment by david_shaw in "Policy on the AI Exponential"]]></title><description><![CDATA[
<p><i>> Members of the trusted coalition should freely share chips and semiconductor manufacturing equipment (SME) with each other, while working together to deny it to adversaries. US export controls on frontier chips and SME to China have been a major contributor to the US’s overall lead in AI, and these policies need to be expanded, tightened, and coordinated with other likeminded states.</i><p>I understand why Dario thinks this is crucial, but it's a very dystopian view of the medium-term future.<p>I'm not an optimist to the point that I believe that AI will lead to global Star Trek-style utopia (although it theoretically could), but ongoing disparity between "allied" and "enemy" powers relating to hardware technology and software models is both not <i>really</i> possible to enforce in the long term, and a pretty dismal state of global affairs even if successful.<p>I'd be interested in an expert geopolitical opinion on what the long tail of this would really look like in any sort of reasonable reality.</p>
]]></description><pubDate>Wed, 10 Jun 2026 20:22:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48482104</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=48482104</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48482104</guid></item><item><title><![CDATA[New comment by david_shaw in "CVE-Bench: testing LLM agents on real-world vulnerability patches"]]></title><description><![CDATA[
<p>The problem with Mythos and Glasswing related hype is that <i>finding</i> vulnerabilities isn't the problem for most organizations. It's great that Mythos and similar models can find vulnerabilities that remained undetected (and hopefully unexploited) for years. That's valuable, especially in open source projects, but it's never been the real challenge for software companies.<p>The <i>real</i> problem is balancing the need to fix vulnerabilities with the mandate of shipping new products and features. At every organization I've worked for or with, this has been the natural friction point. That's good: Product should make customers happy, and Security should keep the customers and their data safe.<p>Ultimately, the whole business should share these goals: everyone should strive for a resilient, useful product shipped quickly that delights customers. Easier said than done, but the friction should be tactical ("how do we spend engineering resources?") rather than strategic ("are security fixes important? do we care?").<p>Which is why I'm much more interested in automated (or semi-automated) PRs to actually <i>fix</i> discovered vulnerabilities rather than just identify them. But, as this project implies, it's not always that simple. It's easy to fix vulnerabilities if you don't care about breaking other functionality.<p>In my opinion, it's currently still necessary to have a human developer in the loop to make sure functionality in product is maintained, and potentially security in the loop to make sure the vulnerability is actually fixed and not just obfuscated.<p>Once this technology is sufficiently advanced -- and I think we're getting close -- my hope is that developer and security time will be spent thinking about resilient software design and architecture, not code-level vulnerabilities.<p>We'll see where it goes.</p>
]]></description><pubDate>Fri, 29 May 2026 19:43:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48328237</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=48328237</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48328237</guid></item><item><title><![CDATA[New comment by david_shaw in "The Melancholy of Slaying Monsters"]]></title><description><![CDATA[
<p>The Fallout games often exemplify this: nearly every decision you make is morally ambiguous, and often has far-reaching repercussions in the story and world.</p>
]]></description><pubDate>Wed, 27 May 2026 08:02:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48291132</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=48291132</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48291132</guid></item><item><title><![CDATA[New comment by david_shaw in "OpenBSD 7.9"]]></title><description><![CDATA[
<p><i>> <a href="https://www.openbsd.org/images/PinkPuffy.png" rel="nofollow">https://www.openbsd.org/images/PinkPuffy.png</a><p>> Apparel (t-shirts, so far): <a href="https://openbsdstore.com/" rel="nofollow">https://openbsdstore.com/</a></i><p>Interesting.<p>In the image you linked (PinkPuffy.png), the cat's hat says "security." In the OpenBSD store, the cat's hat reads "POLICE" on several of the shirts.</p>
]]></description><pubDate>Tue, 19 May 2026 18:37:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48197414</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=48197414</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48197414</guid></item><item><title><![CDATA[New comment by david_shaw in "Incident Report: CVE-2024-YIKES"]]></title><description><![CDATA[
<p>He certainly popularized it (maybe coined it), but I've seen a <i>lot</i> of organizations and developers repeat that mantra.<p>Even without the specific words, look to product teams debating tradeoffs of going to market vs. waiting for better security controls. They're pushing for faster product release every time, at pretty much every org.</p>
]]></description><pubDate>Sun, 10 May 2026 19:09:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48086840</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=48086840</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48086840</guid></item><item><title><![CDATA[New comment by david_shaw in "Incident Report: CVE-2024-YIKES"]]></title><description><![CDATA[
<p>It's easy to be cynical because, yes, both the problems and solutions seem dead obvious in hindsight. But for a long time (and maybe even still), a hacker creed was "move fast and break things."<p>It's great that there's so much momentum in fixing the glaring problems with supply chain systems like npm, but I'm concerned that we're entering a new era of security-related problems caused in large part by agentic development.<p>I'm not just talking about Mythos/Glasswing surfacing vulnerabilities in pretty much everything it touches; I think the way we're developing software, pulling in dependencies, and potentially losing human thought modeling of complex systems is going to lead to a <i>lot</i> of hacked together software and infrastructure that humans won't fully understand.<p>I hope in a few years we don't look back at today and wonder how we could have been so naive -- how we failed to actually <i>plan</i> for the long-tail of AI development in a way that doesn't solve problems by attempting to just use AI to rebuild complex systems.<p>But the article was funny.</p>
]]></description><pubDate>Sun, 10 May 2026 18:49:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48086645</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=48086645</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48086645</guid></item><item><title><![CDATA[New comment by david_shaw in "AISLE Discovers 38 CVEs in OpenEMR Healthcare Software"]]></title><description><![CDATA[
<p>We'll see more of this, but this <i>particular</i> review is driven by marketing narrative. I'll explain what I mean:<p>Back in 2010, as a security engineer, I also looked at OpenEMR. It was an absolute disaster, and was (and is) somewhat well-known as such. I found and published vulnerabilities very similar to these <i>sixteen years ago.</i> This is not exactly the Fort Knox of software.<p>It makes sense for AISLE to demonstrate that they're able to find vulnerabilities here, but I'd love to see a side-by-side comparison of modern SAST and DAST reviews. I bet we'd find similar vulnerabilities.</p>
]]></description><pubDate>Tue, 28 Apr 2026 18:05:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=47938143</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=47938143</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47938143</guid></item><item><title><![CDATA[New comment by david_shaw in "GTFOBins"]]></title><description><![CDATA[
<p>I think the idea is that if you're given an improperly configured restricted shell/command access, you can use any of the listed tools to gain access to some subset of what that user would normally have access to in an unrestricted environment.<p>A very simple version of this would be if you set a user's default shell to "rbash" but the user can just run "bash" to get a real shell.</p>
]]></description><pubDate>Tue, 28 Apr 2026 07:20:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=47931363</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=47931363</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47931363</guid></item><item><title><![CDATA[New comment by david_shaw in "Anduril, Palantir and SpaceX are changing how America wages war"]]></title><description><![CDATA[
<p>I don't have a subscription to The Economist, but I was interested in the concept of these organizations as "neo-primes."<p>I found an article on The Cipher Brief describing them: <a href="https://www.thecipherbrief.com/defense-neoprime-innovation" rel="nofollow">https://www.thecipherbrief.com/defense-neoprime-innovation</a><p>Specifically, the idea here is that companies like Anduril, Palantir, and SpaceX are rapidly delivering cutting-edge technology (including software) as opposed to the traditional defense contractor process of long, drawn out, super expensive projects mostly focused on hardware (such as building a new type of jet).<p>It makes sense: this is basically what happened in civilian tech, too. Delivering high-tech solutions quickly -- dare I say with agility -- is usually the superior approach.</p>
]]></description><pubDate>Mon, 20 Apr 2026 19:19:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=47839233</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=47839233</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47839233</guid></item><item><title><![CDATA[New comment by david_shaw in "FBI used iPhone notification data to retrieve deleted Signal messages"]]></title><description><![CDATA[
<p><i>> If it were secure, it would only notify that there is a message, with no details included.</i><p>You're right. This is configurable via settings, but is not the default state.<p>That said: if I can get friends and family to use Signal instead of iMessage, that gives <i>me</i> the opportunity to disable those notifications and experience more security benefits.<p>But I agree with your point: most people think that Signal is bulletproof out of the box, and it's clearly not.</p>
]]></description><pubDate>Fri, 10 Apr 2026 19:43:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=47722745</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=47722745</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47722745</guid></item><item><title><![CDATA[New comment by david_shaw in "Launch HN: RunAnywhere (YC W26) – Faster AI Inference on Apple Silicon"]]></title><description><![CDATA[
<p>I think the title should read "RunAnywhere," not "RunAnwhere."</p>
]]></description><pubDate>Tue, 10 Mar 2026 18:41:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47327194</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=47327194</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47327194</guid></item><item><title><![CDATA[New comment by david_shaw in "An interactive map of Flock Cams"]]></title><description><![CDATA[
<p>It would be an interesting and potentially useful project to combine these camera locations with Maps routing -- similar to "avoid toll roads," we could "avoid surveillance cameras."</p>
]]></description><pubDate>Wed, 04 Mar 2026 21:31:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=47254186</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=47254186</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47254186</guid></item><item><title><![CDATA[New comment by david_shaw in "Zed will require age identification for its services"]]></title><description><![CDATA[
<p>It's wild that all other comments in this thread (so far) seem to completely miss this nuance. There are lots of services that, in their terms, require users to be adults.<p>This type of age "identification" is a lot different than age <i>verification</i>, submission of ID, etc.</p>
]]></description><pubDate>Tue, 03 Mar 2026 23:00:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47240335</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=47240335</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47240335</guid></item><item><title><![CDATA[New comment by david_shaw in "We Will Not Be Divided"]]></title><description><![CDATA[
<p>I'd prefer to see board (or executive) level signatories over lay employees -- the people who can enforce enterprise policy rather than just voice their opinions -- but this is encouraging to see nonetheless.<p>I can't help but notice that Grok/X is not part of this initiative, though. I realize that frontier models are really coming from Anthropic, OpenAI, and Google, but it feels like <i>someone</i> is going to give in to these demands.<p>It's incredible how quickly we've devolved into full-blown sci-fi dystopia.</p>
]]></description><pubDate>Sat, 28 Feb 2026 02:32:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=47189418</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=47189418</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47189418</guid></item><item><title><![CDATA[New comment by david_shaw in "Claude Code Remote Control"]]></title><description><![CDATA[
<p><i>> What does "solving" coding mean?</i><p>Maybe this was sarcasm, but it's a good point:<p>"Coding" is solved in the same way that "writing English language" is solved by LLMs. Given ideas, AI can generate acceptable output. It's not writing the next "Ulysses," though, and it's definitely not coming up with authentically creative ideas.<p>But the days of needing to learn esoteric syntax in order to write code are probably numbered.</p>
]]></description><pubDate>Wed, 25 Feb 2026 17:47:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=47154957</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=47154957</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47154957</guid></item><item><title><![CDATA[New comment by david_shaw in "I built Timeframe, our family e-paper dashboard"]]></title><description><![CDATA[
<p>This is for sure an inspirational project, but I wish the barrier to entry was lower.<p>I've noticed e-ink/paper displays having somewhat of a moment right now (especially very small "phone-like" form factors as portable ereaders), and I hope this trend continues.<p>I'm very far from a meaningful reduction in "screen time," but looking at e-ink displays instead of OLEDs feels like a nice step in that direction.</p>
]]></description><pubDate>Sun, 22 Feb 2026 21:30:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47114909</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=47114909</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47114909</guid></item><item><title><![CDATA[New comment by david_shaw in "Making frontier cybersecurity capabilities available to defenders"]]></title><description><![CDATA[
<p><i>> I am seeing something closer to the opposite of skepticism among vulnerability researchers.</i><p>My initial claim was overly broad, but the feeling of <i>discomfort</i> feels widespread to me.<p>In my experience, some of that is technical skepticism, some of it is job-related anxiety, and some might just be fear of the unknown.<p>I still think that security engineering skill sets, once pivoted to "design of resilient systems," will be a differentiator between quickly-built projects and enterprise-ready software. But we'll see!</p>
]]></description><pubDate>Sat, 21 Feb 2026 19:54:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=47104038</link><dc:creator>david_shaw</dc:creator><comments>https://news.ycombinator.com/item?id=47104038</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47104038</guid></item></channel></rss>