<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: dhx</title><link>https://news.ycombinator.com/user?id=dhx</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 18 Aug 2026 14:39:24 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=dhx" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by dhx in "GLM-5.3: Frontier coding with emergent cyber capabilities"]]></title><description><![CDATA[
<p>Most discussion in recent years about chip fabrication shortages, expansion, etc has focussed on leading nodes (<7nm) and AI/computer chips. But perhaps more quietly in the background, China has been rapidly building other semiconductor capacity such as power semiconductors used in electric vehicles, wind turbines, solar modules, train traction systems, etc. For example, Chinese-produced motor vehicles (37% of global motor vehicle production in 2025) in a year or two are targeted to use 100% domestically produced chips, and this production is decreasingly dependent on imports, even for factory tooling.<p>The report at [1] is a good summary of long term trends for China's rise in domestic self-sufficiency for semiconductor manufacturing. The report predicts "At current pace, China may achieve self-sufficiency in semiconductor manufacturing by 2027-2028, though trailing at leading-edge nodes". By contrast, before the first Trump presidency in 2017, a chart shows China importing 30% of all globally manufactured semiconductors (and increasing). Other reports on semiconductor fabrication equipment sales show the means, which is China having been and continuing to be in number (1) position for expenditure on semiconductor fabrication equipment.<p>The reports at [2] and [3] are also a good summary of long term trends for semiconductor foundry capacity predictions to 2031. A prediction is made that China's current 12% global semiconductor foundry supply capacity (across all semiconductor categories) in 2025 will expand to ~30% by 2031.<p>[1] <a href="https://www.yolegroup.com/product/report/china-semiconductor-industry-2025---device-and-equipment-/" rel="nofollow">https://www.yolegroup.com/product/report/china-semiconductor...</a><p>[2] <a href="https://www.yolegroup.com/product/report/status-of-the-semiconductor-foundry-industry-2026/" rel="nofollow">https://www.yolegroup.com/product/report/status-of-the-semic...</a><p>[3] <a href="https://www.yolegroup.com/press-release/the-global-race-for-semiconductor-manufacturing-dominance/" rel="nofollow">https://www.yolegroup.com/press-release/the-global-race-for-...</a></p>
]]></description><pubDate>Sat, 15 Aug 2026 16:13:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=49311768</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49311768</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49311768</guid></item><item><title><![CDATA[New comment by dhx in "In Australia, a home battery boom has helped cut wholesale power prices"]]></title><description><![CDATA[
<p>I've contributed a bit on the infrastructure side of things to OpenStreetMap--high voltage transmission lines, pipelines, etc. I also have contributed to alltheplaces.xyz which whilst mostly known for collating shop locations, also collates infrastructure point data such as substations, traffic cameras, bins in parks, etc. As I'm in Australia, I naturally have more of an interest in Australia.<p>Sometimes when trying to improve OSM with a new substation, wind farm or otherwise, you might have missing information such as a wind farm that is covered with stitched imagery--left half is a 2024 swath showing construction underway and concrete foundations prepared, or a pad excavated, right half is a 2026 swath showing turbines installed and operating. Sometimes it can be helpful to double check assumptions made about an excavated pad being a wind turbine foundation against public data--e.g. press release stating how many turbines have been ordered for the wind farm, or a low resolution map in a company report indicating rough placement of turbines.<p>Or for a new substation with a 330kV bus and 110kV bus confirmed by tracing transmission lines to other substation buses, there could be a dangling transmission line traced to a tower next to the new substation, but it's not clear which bus it may connect to. This is where some more detailed public data, in the rare case it may be available (such as in Australia), can be useful to combine together to confirm an assumption. A real case I found recently was in Saudi Arabia where a press release from a company stated something to the effect of "We just successfully installed a 330kV feeder 9281 to substation G40", which confirmed how the the transmission lines connected to the substation.<p>I have however mostly mapped in countries where OSM is most lacking--and for electricity infrastructure that is China--by orders of magnitude. An example I worked on previously is Hainan, which was previously mostly missing from OpenInfraMap.[2] China publish nothing and even require their street view imagery providers to blur substations. Even so--this is largely a pointless effort because with a bit of extra puzzle solving (such as switching between 4 historic satellite images to find the one where a shadow or a tower or pole is visible) it's almost always possible to get an accurate map produced. Gaps are mostly limited to out of date satellite imagery which for China is a huge accuracy problem because the scale of electricity grid expansion is absurd. It's commonplace to start tracing a transmission line to only find half way along, the transmission line disappears on a stitch in satellite imagery, and then more recent imagery on the other side of the stitch shows 3 new 500kV+ (including HVDC) transmission lines routed in parallel, replacing the old line. You can open an OSM editor almost anywhere in China and scroll around for a minute to find an unmapped high voltage transmission line, wind farm, substation, etc (having a list of coordinates where new satellite swaths are available would help most here).<p>For a global list of electricity grid data sources, [1] is very detailed list that is well maintained. Countries in Africa are particularly challenging--some you'd be lucky to find even a single 800x800px image of the electricity grid... or even a website for the transmission network operator.<p>[1] <a href="https://github.com/open-energy-transition/Awesome-Electrical-Grid-Mapping" rel="nofollow">https://github.com/open-energy-transition/Awesome-Electrical...</a><p>[2] <a href="https://openinframap.org/#8.28/19.121/110.058" rel="nofollow">https://openinframap.org/#8.28/19.121/110.058</a></p>
]]></description><pubDate>Sat, 15 Aug 2026 13:34:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=49310432</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49310432</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49310432</guid></item><item><title><![CDATA[New comment by dhx in "Google is making private AI practical with homomorphic encryption"]]></title><description><![CDATA[
<p>I found [1] which appears to offer state-of-the-art performance of ~1000s latency for a FHE GPT-2 transformer block, equating I think to 3.33h inter-token latency (0.00008 token/s) for GPT-2(small) which has 12 transformer blocks. This result is using optimised packed arithmetic operations on a GPU as well--so seemingly is unlikely to have much performance upside from further optimisation.<p>I'm not sure I've interpreted [1] correctly though, and would appreciate correction if necessary.<p>[1] <a href="https://arxiv.org/pdf/2604.04783" rel="nofollow">https://arxiv.org/pdf/2604.04783</a> -- GPU Acceleration of TFHE-Based High-Precision Nonlinear Layers for Encrypted LLM Inference -- Guoci Chen, Xiurui Pan, Qiao Li, Bo Mao, Congming Gao, Chengying Huan, Mingzhe Zhang, Jie Zhang -- Apr 2026</p>
]]></description><pubDate>Sat, 15 Aug 2026 04:54:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=49307760</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49307760</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49307760</guid></item><item><title><![CDATA[New comment by dhx in "Google is making private AI practical with homomorphic encryption"]]></title><description><![CDATA[
<p>To throw out some real and up-to-date numbers from [1] for FHE at "128-bit security level", to sort 8x 8-bit unsigned integers on the most ordinary of desktop PCs, wait 3 seconds for the result. Want to sort 32x 8-bit unsigned integers instead? Come back 34 seconds later for the result.<p>update: also see [2] for some primitive unsigned 64-bit integer operation benchmarks with the TFHE-rs library (winner in the sorting performance comparison of [1]). Equality at 80ms, addition and subtraction at 100ms, division at 8 seconds, etc.<p>[1] <a href="https://eprint.iacr.org/2026/1495.pdf" rel="nofollow">https://eprint.iacr.org/2026/1495.pdf</a>  Oblivious Sorting under Fully Homomorphic Encryption: A Comprehensive Survey and Performance Analysis, Omar Ahmed and Rostin Shokri and Nektarios Georgios Tsoutsos, 2026<p>[2] <a href="https://docs.zama.org/tfhe-rs/tfhe-rs/1.0/get-started/benchmarks" rel="nofollow">https://docs.zama.org/tfhe-rs/tfhe-rs/1.0/get-started/benchm...</a></p>
]]></description><pubDate>Fri, 14 Aug 2026 18:10:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=49302507</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49302507</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49302507</guid></item><item><title><![CDATA[New comment by dhx in "In Australia, a home battery boom has helped cut wholesale power prices"]]></title><description><![CDATA[
<p>Distribution infrastructure capacity is a current and ongoing concern for summer peak loads (every house turning on air conditioners at once) even with the large government subsidies that have existed for residential solar panels, residential batteries, reverse cycle heat pump cooling/heating and insulation. The cost to rebuild every distribution substation, change every pole-top transformer and rewire suburbs would be much higher if these subsidies never existed.<p>For most of Australia's population you can look up an annual report that each transmission and distribution operator is required to publish annually for their predicted demand on substations, transmission lines and distribution lines. For example in Victoria this report is the TCPR, an example available at [1]. For many distribution substations, the 10th percentile maximum demand is predicted to occur in the early 2030's, meaning that at least transformers at substations would need upgrading, or the substation rebuilt or expanded. The reasons include higher density development in urban areas, electric vehicle charging and for winter, electrification of gas heating.<p>As an example of the impact of residential solar generation, [2] states that for an urban growth corridor of Melbourne being built largely in the era of residential solar panels being a standard housing feature, a distribution substation ATS West has 2x 150MVA transformers operating at combined peak of 200MVA, also with 125MW of embedded residential solar generation. Without that 125MW embedded residential solar generation, this substation and feeders perhaps would have had to be replaced years earlier to allow import of ~325MVA rather than ~200MVA. Also not mentioned explicitly in this report is residential battery storage which may be reducing maximum demand from predictions made before residential batteries were widely installed.<p>As a side note, perhaps Australia perhaps has the most open and transparent electricity market in the world? I don't know any other country where the entire electricity grid down to 230/400VAC distribution lines running on poles in every residential street is available publicly on a map, including serial numbers of poles and ratings of pole-top transformers. And substation schematics and constraint reports, etc are all available through various public reports. I think the transparency demonstrates a great deal of confidence in the electricity grid and how it is managed.<p>[1] <a href="https://www.powercor.com.au/network-planning-and-projects/network-data/" rel="nofollow">https://www.powercor.com.au/network-planning-and-projects/ne...</a> -- refer to the PDF document in the TCPR zip file download for a substation-by-substation analysis in easy to read format.<p>[2] <a href="https://media.powercor.com.au/wp-content/uploads/2025/06/12194001/ATS-West-PADR.pdf" rel="nofollow">https://media.powercor.com.au/wp-content/uploads/2025/06/121...</a></p>
]]></description><pubDate>Fri, 14 Aug 2026 16:37:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49301143</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49301143</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49301143</guid></item><item><title><![CDATA[New comment by dhx in "GLM-5.3: Frontier coding with emergent cyber capabilities"]]></title><description><![CDATA[
<p>I take it from [1] (transcript of recent DeepSeek CEO discussion with investors) that DeepSeek would disagree on the immediate catastrophic impact to the likes of OpenAI or Anthropic. The reason is even though technology parity mostly exists, only OpenAI, Anthropic et al have the inference capacity to gain market share and generate revenue. Chinese vendors don't have the chips needed to scale up inference and gain market share, and the DeepSeek CEO doesn't think this would happen in optimistic circumstances in the next 3 years, but thinks it might be possible in 5 years.<p>In summary, regardless of country of origin, availability of inference capacity is the moat protecting the likes of OpenAI and Anthropic, not technology superiority.<p>[1] <a href="https://www.fredgao.com/p/deepseeks-liang-wenfeng-breaks-his" rel="nofollow">https://www.fredgao.com/p/deepseeks-liang-wenfeng-breaks-his</a></p>
]]></description><pubDate>Fri, 14 Aug 2026 08:57:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49296211</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49296211</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49296211</guid></item><item><title><![CDATA[New comment by dhx in "DeepSeek API Pricing Update"]]></title><description><![CDATA[
<p>It would have to be reproduced on a CUDA stack because AFAIK Huawei don't sell the Ascend 950PR (for inference) to anyone, rather, they operate them as part of the Huawei Cloud and only allow select customers (such as DeepSeek) to rent them.<p>The CEO of DeepSeek recently revealed to investors a lot about the resources available to DeepSeek, and the gap between Huawei and NVIDIA. Select quotes from the transcript (translation is a bit patchy on the source website though):<p>"We currently have roughly 20,000 H-equivalent compute cards"<p>"Huawei 950—right now Huawei gives us 16,000 cards, this should be publicly stateable."<p>"Like Huawei gives us roughly 16,000 cards of capacity, internet giants maybe get a hundred-something thousand, we get ten-something thousand—I think this ratio is also relatively... but this is probably just how much capacity Huawei has."<p>"16,000 Huawei 950 cards only equal 4,000 B-series cards."<p>"Huawei’s supernode, Huawei’s 950 supernode, in performance and price can completely substitute for NVIDIA’s GB200, GB300. The price is definitely more expensive, but limitedly so. Fifty percent more expensive, a hundred percent more expensive—a hundred percent more doesn’t matter, two hundred percent more doesn’t matter. For example, a hundred percent more expensive—I think it can already be considered a price-level substitute."<p>"I think domestic hardware might need a few years."<p>"I don’t quite believe that five years from now, we’ll still be stuck on the production capacity problem. Right now we’re definitely stuck on the production capacity problem—this year, next year, the year after, I think we might still be stuck on the production capacity problem, but five years later, I think maybe not necessarily—I’m still relatively optimistic."<p>[1] <a href="https://www.fredgao.com/p/deepseeks-liang-wenfeng-breaks-his" rel="nofollow">https://www.fredgao.com/p/deepseeks-liang-wenfeng-breaks-his</a></p>
]]></description><pubDate>Thu, 13 Aug 2026 17:30:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=49289231</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49289231</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49289231</guid></item><item><title><![CDATA[New comment by dhx in "Qwen3.8-2.4T"]]></title><description><![CDATA[
<p>Now that people have played with the model for a bit, there is one reported real world win for DeepSeek v4 Pro 0813 that is perhaps quite consequential given the drama in the US about Mythos.<p>In a benchmark, DeepSeek v4 Pro 0813 found 87.5% of selected real world software vulnerabilities publicly reported and with CVEs assigned, which is above runner ups Opus 5 and Qwen 3.8 which both found only 81.3%. However there is a downside to this--DeepSeek v4 Pro 0813 is less accurate with a 35% false positive rate versus GPT-5.6-Sol's 15% false positive rate. For vulnerability analysis though, it's probably worth finding that one extra vulnerability no other model has found even if requires significantly more triage to remove false positives, or additional cost to run every vulnerability detection through other models to verify.<p>[1] <a href="https://nitter.net/pilvar222/status/2087691659953815783#m" rel="nofollow">https://nitter.net/pilvar222/status/2087691659953815783#m</a></p>
]]></description><pubDate>Thu, 13 Aug 2026 16:22:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49288301</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49288301</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49288301</guid></item><item><title><![CDATA[New comment by dhx in "DeepSeek API Pricing Update"]]></title><description><![CDATA[
<p>Old DeepSeek Flash 0731 prices have been independently reproduced.[1] The issue is DeepSeek being inundated and not having capacity to serve the demand, hence the price increases to significantly dampen demand. Never mind international demand either--just think about the magnitude of Chinese domestic demand. Prices for anything related to AI or computing in general (mobile phones, cloud data centre hosting, etc) will continue to climb fast as demand for computer chips _far_ exceeds supply. DeepSeek doesn't have an option other than to just work away on improving their technology in the period of time before computer chips once again become a commodity. For example, DeepSeek's cache ratio for their models apparently leads to 1/2 GPU time requirement versus the second best provider.[2]<p>[1] <a href="https://nitter.net/thdxr/status/2085377844515922210#m" rel="nofollow">https://nitter.net/thdxr/status/2085377844515922210#m</a><p>[2] <a href="https://nitter.net/thdxr/status/2087610161636471289#m" rel="nofollow">https://nitter.net/thdxr/status/2087610161636471289#m</a></p>
]]></description><pubDate>Thu, 13 Aug 2026 15:27:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=49287470</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49287470</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49287470</guid></item><item><title><![CDATA[New comment by dhx in "Qwen3.8-2.4T"]]></title><description><![CDATA[
<p>Also of interest: DeepSeek V4-Pro-0813 (1.6T-A49B) benchmark scores have apparently just been announced on the DeepSeek WeChat channel and they're sitting about Fable 5 level.[1]<p>[1] <a href="https://www.reddit.com/r/LocalLLaMA/comments/1vmi0fg/deepseek_v4pro0813_benchmarks/" rel="nofollow">https://www.reddit.com/r/LocalLLaMA/comments/1vmi0fg/deepsee...</a></p>
]]></description><pubDate>Wed, 12 Aug 2026 16:01:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=49274543</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49274543</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49274543</guid></item><item><title><![CDATA[New comment by dhx in "Amazon plans gigantic gas power plant for new AI data center"]]></title><description><![CDATA[
<p>They're going to rely on a fuel source which only has 9-17 years of domestic supply at current production rates and proven reserves?[1]<p>And a fuel source with largest proven reserves in countries that are currently or can be foreseen to be problematic to extract and purchase from: Russia, Iran, Qatar, Turkmenistan, Saudi Arabia, China, UAE, Venezuela and Nigeria rounding out the top 10.[1]<p>[1] <a href="https://en.wikipedia.org/wiki/List_of_countries_by_natural_gas_proven_reserves" rel="nofollow">https://en.wikipedia.org/wiki/List_of_countries_by_natural_g...</a></p>
]]></description><pubDate>Mon, 10 Aug 2026 09:27:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=49241353</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49241353</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49241353</guid></item><item><title><![CDATA[New comment by dhx in "US beef prices have soared but farmers aren't making more money"]]></title><description><![CDATA[
<p>For lumber, data at [1] indicates much volatility in North American lumber prices from January 2023 to February 2026. Trough-to-peak prices for 2023, 2024 and 2025 have been over 30% across a given year. The main difference for 2026 so far is the stability of prices which have remain peaked for half a year.<p>Now is the perfect time for someone being overly dramatic to say "In the 2 years since July 2024, lumber prices have increased 47%, significantly higher than inflation".<p>But someone else could also say "Lumber prices are the same as July 2025 even though inflation has risen" or "Lumber prices are up just 10% in the 3 years since July 2023, lower than the rate of inflation across these 3 years".<p>[1] <a href="https://madisonsreport.com/wp-content/uploads/2026/07/IndexGraph2023-2026-4.png" rel="nofollow">https://madisonsreport.com/wp-content/uploads/2026/07/IndexG...</a></p>
]]></description><pubDate>Thu, 06 Aug 2026 15:21:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=49197950</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49197950</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49197950</guid></item><item><title><![CDATA[New comment by dhx in "CISA Alert: Water Sector PLC Targeting"]]></title><description><![CDATA[
<p>There can be surprisingly few critical components and processes in a water and sewerage network due to gravity-fed designs (far more cost efficient), large buffers (water reservoirs, sewage sumps, etc) allowing intermittent operation of otherwise critical components, retained ability for humans to manually operate equipment, and also the fields of availability and safety engineering which typically prefer elimination of software failure modes by designing equipment to not rely upon software.<p>The aim of a water network is to:<p>1. Take water from a water source (elevated dam -- strongly preferred, river, ocean) and as much as possible, gravity feed it to a treatment plant.<p>2. Treat the water using processes that are simplified/fail-safe as much as possible and could be operated manually by humans if necessary. This is where availability and safety engineers would design equipment to not be dependent on software and instead use mechanical or analogue electronics control.<p>3. Pre-position treated water as much as possible at ~50-90m hydraulic head (~500-900kPA) above the water faucets where people want to use the treated water and provide a buffer for X days of usage. Any pumps between the treatment plant and elevated storage therefore only need to operate intermittently to refill the buffer.<p>Sewerage networks have similar aims:<p>1. Let sewage flow as much as possible downhill to the treatment plant via gravity. Where a rising main (elevation gain) is required, place a large enough sump for X hours/days of usage and pump up to higher elevation from the sump.<p>2. Treat the sewage using processes that are simplified/fail-safe as much as possible and could be operated manually by humans if necessary. For example, a compressor used for aeration can be manually switched on/off with a mechanical switch and plugged into a diesel generator, and not require someone logging in with multi-factor authentication to a laptop to issue a command to a PLC to turn on the compressor.<p>3. Design overflows into the system for emergency release of partially or untreated sewage, and practice this process as part of disaster recovery exercises. This is generally an aim arising due to risk assessment process that says building a $1bn sump with 8 independent pumps is cost prohibitive versus the 1-in-200 year chance of untreated sewage messing up a downstream river for a few weeks.<p>Ultimately a lot of the cybersecurity risk comes down to government appetite to accept 1-in-1000 (or whatever) year failure modes. Is it worth investing now in triple modular redundant automated control systems (mostly used in safety-critical sectors such as aviation and space), or installing a just-in-case diesel generator at every one of 500 pumping stations across a region, or building $10bn of sewage sumps to hold sewage for up to a month, or building 2 treatment plants instead of 1 and using different technology for each, or hiring and training more humans to regularly exercise manual control and operation of a network, etc? Or just accept that once every 1000 years, some water rationing may be required, or a downstream river will be polluted for a few weeks?</p>
]]></description><pubDate>Sun, 02 Aug 2026 04:01:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=49140971</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49140971</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49140971</guid></item><item><title><![CDATA[New comment by dhx in "Show HN: I mapped every US golf course"]]></title><description><![CDATA[
<p>OSM probably has the best data on golf courses because for many courses, people have mapped each 'golf=hole' as a way, and mapped other golf course features such as 'golf=bunker', 'golf=green', etc.<p>OSM knows of almost 40k golf courses around the world.[2] This compares to 38k golf courses known to the R&A Golf Around the World Fourth Edition (2021) report and 37.6k courses listed in the NGF course database as of July 2024. It's likely OSM knows of 99.99..% of all active golf courses and also still retains tags for closed/unused golf courses too. So if OSM were to be inaccurate, it'd likely be inaccurate for whether a golf course is open or closed, rather than OSM not knowing about a golf course existing.<p>I wonder whether an OSM tile server / custom style sheet for golfers would be easiest and most useful/comprehensive way to keep track of golf courses?<p>[1] <a href="https://wiki.openstreetmap.org/wiki/Tag:golf%3Dhole" rel="nofollow">https://wiki.openstreetmap.org/wiki/Tag:golf%3Dhole</a><p>[2] <a href="https://taginfo.openstreetmap.org/tags/leisure=golf_course#overview" rel="nofollow">https://taginfo.openstreetmap.org/tags/leisure=golf_course#o...</a><p>[3] <a href="https://assets.randa.org/c42c7bf4-dca7-00ea-4f2e-373223f80f76/50ff4344-b576-4e2e-a9e2-8411712954ac/2021%20Golf%20Around%20The%20World%20Fourth%20Edition.pdf" rel="nofollow">https://assets.randa.org/c42c7bf4-dca7-00ea-4f2e-373223f80f7...</a><p>[4] <a href="https://thegolfwire.com/worldwide-golf-course-development-report/" rel="nofollow">https://thegolfwire.com/worldwide-golf-course-development-re...</a></p>
]]></description><pubDate>Sun, 26 Jul 2026 11:12:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49056890</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49056890</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49056890</guid></item><item><title><![CDATA[New comment by dhx in "IRGC claims it destroyed Amazon's Bahrain data center"]]></title><description><![CDATA[
<p>Update 2:<p>Upon checking Sentinel-2 imagery for BAH55 from 2026-03-29 to 2026-04-13 (and all later imagery) there is also visible blast damage to the roof of BAH55, which would correspond in timing to media reports about damage caused about 2026-04-01. Sentinel-2 imagery appears to clarify AWS' claim of "while in Bahrain, a drone strike in close proximity to one of our facilities" to mean a direct impact to the building. However it seems likely from high resolution satellite imagery of BAH55 that the machinery rooms of the building perhaps took most of the damage, perhaps leaving data halls in a better shape elsewhere in the building (but possibly still unusable due to water/smoke damage).<p>[1] <a href="https://browser.dataspace.copernicus.eu/?zoom=17&lat=26.156&lng=50.47834&themeId=MONITORING&visualizationUrl=U2FsdGVkX1%2Fw5mHZWOYZDa4YUMn8v1fQpZu%2FcqMDdblbzAPsuzzeQRne1Gcp3ko4msKcSLuPi8gOVU0r3rwuS36wT7J5o%2F458yaeO%2FMVr9PeZgRtdQE3abwl4ylYkZys&datasetId=S2_L2A_CDAS&fromTime=2026-03-29T00%3A00%3A00.000Z&toTime=2026-03-29T23%3A59%3A59.999Z&layerId=1_TRUE_COLOR&demSource3D=%22MAPZEN%22&cloudCoverage=30&dateMode=SINGLE" rel="nofollow">https://browser.dataspace.copernicus.eu/?zoom=17&lat=26.156&...</a><p>[2] <a href="https://browser.dataspace.copernicus.eu/?zoom=17&lat=26.156&lng=50.47834&themeId=MONITORING&visualizationUrl=U2FsdGVkX1%2Bt1jX5zan9wgSCbM8pXIuFa%2BWHURYdjsMsT%2FA%2ByEgIJdPvJTXH0crwk9Po%2FhJhxW7eMId2aKEg6WtB8mqTf5dtNTCps6bkRGkCsziUVIP8Ci8MPxGaJCYN&datasetId=S2_L2A_CDAS&fromTime=2026-04-13T00%3A00%3A00.000Z&toTime=2026-04-13T23%3A59%3A59.999Z&layerId=1_TRUE_COLOR&demSource3D=%22MAPZEN%22&cloudCoverage=30&dateMode=SINGLE" rel="nofollow">https://browser.dataspace.copernicus.eu/?zoom=17&lat=26.156&...</a></p>
]]></description><pubDate>Sat, 25 Jul 2026 12:27:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=49047028</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49047028</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49047028</guid></item><item><title><![CDATA[New comment by dhx in "IRGC claims it destroyed Amazon's Bahrain data center"]]></title><description><![CDATA[
<p>Update: IRGC published satellite imagery a few hours ago showing an impact to BAH54, apparently impacted on 2026-07-24, alongside another undated image before the impact. From a quick comparison of both images with reliable satellite imagery sources (e.g. WV02 image dated 2025-02-21 on ESRI World Imagery Wayback) there are no obvious signs of image manipulation, with roof features and surrounding buildings/other features lining up as expected. Additionally the claimed post-strike image adds a significant number of vehicles to the site (when there are usually close to none present), which may correspond to fire fighting vehicles expected to be monitoring the site afterwards. Further, Sentinel-2 imagery from 2026-07-24 shows a dark patch (blast damage) on the roof of BAH54 per <a href="https://browser.dataspace.copernicus.eu/?zoom=18&lat=26.05096&lng=50.505&themeId=MONITORING&visualizationUrl=U2FsdGVkX1%2FBhOOoTjHdi47xgOyNOyq4ViXctLUx6BML4JV87USLO70FQrVMZRDOuo51lFcquLx3tPp5rpUDqa8XSaoUgeIRvpg4m9LgWrZGgTzZaMYtXZTPIx9J%2BN2C&datasetId=S2_L2A_CDAS&fromTime=2026-07-24T00%3A00%3A00.000Z&toTime=2026-07-24T23%3A59%3A59.999Z&layerId=1_TRUE_COLOR&demSource3D=%22MAPZEN%22&cloudCoverage=30&dateMode=SINGLE" rel="nofollow">https://browser.dataspace.copernicus.eu/?zoom=18&lat=26.0509...</a></p>
]]></description><pubDate>Sat, 25 Jul 2026 11:18:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=49046618</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49046618</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49046618</guid></item><item><title><![CDATA[New comment by dhx in "Government orders GitHub to remove Bluetooth-based chat app Bitchat: Jack Dorsey"]]></title><description><![CDATA[
<p>To add:<p>The request has not yet been published by GitHub to <a href="https://github.com/github/gov-takedowns/tree/master/India/2026" rel="nofollow">https://github.com/github/gov-takedowns/tree/master/India/20...</a><p>Also not mentioned in the project's GitHub repository yet per <a href="https://github.com/search?q=repo%3Apermissionlesstech%2Fbitchat%20india&type=code" rel="nofollow">https://github.com/search?q=repo%3Apermissionlesstech%2Fbitc...</a></p>
]]></description><pubDate>Fri, 24 Jul 2026 15:31:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49037145</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49037145</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49037145</guid></item><item><title><![CDATA[New comment by dhx in "IRGC claims it destroyed Amazon's Bahrain data center"]]></title><description><![CDATA[
<p>AWS's 3 data centres in me-south-1 are:<p>BAH53 (Manama): <a href="https://www.openstreetmap.org/way/1492345589" rel="nofollow">https://www.openstreetmap.org/way/1492345589</a><p><pre><code>  An adjoining substation to BAH53 had one of it's two main buildings damaged/destroyed about 2026-07-16 per https://soaratlas.com/maps/asia-damage-to-data-center-power-substation-bahrain-jul-16th-2026-142024

  Then about 2026-07-22 BAH53 itself was damaged/destroyed per https://soaratlas.com/maps/asia-damage-to-amazon-web-services-bahrain-jul-22nd-2026-142112

  Possibly the least defended of the three sites as there is no air/missile defence battery in between this site and Iran.
</code></pre>
BAH54 (Zallaq): <a href="https://www.openstreetmap.org/way/1359931661" rel="nofollow">https://www.openstreetmap.org/way/1359931661</a><p><pre><code>  No media reports about this data centre being attacked previously. Possibly the safest of the three as there are at least two (probably three) air/missile defence batteries in between this site and Iran.
</code></pre>
BAH55 (Hamala): <a href="https://www.openstreetmap.org/way/956069872" rel="nofollow">https://www.openstreetmap.org/way/956069872</a><p><pre><code>  Apparently the Batelco DC.1 data centre adjoining (and apparently critical to) BAH55 was damaged/destroyed about 2026-04-01 per https://www.bbc.com/news/articles/cgk28nj0lrjo _or_ the adjoining substation to these two facilities was damaged/destroyed -- news articles are hard to follow as to what exactly might have been damaged and the extent of damage caused.

  Middle ground for defence with one or two (maybe three) air/missile defence batteries between this site and Iran, depending on where drones/missiles are launched from.
</code></pre>
If these data centres are rebuilt, you'd maybe expect them to be rebuilt in new locations behind existing _permanent_ (and seemingly quite expensive) air/missile defence batteries in Bahrain (<a href="https://www.openstreetmap.org/way/1492281507" rel="nofollow">https://www.openstreetmap.org/way/1492281507</a> and <a href="https://www.openstreetmap.org/way/1492953902" rel="nofollow">https://www.openstreetmap.org/way/1492953902</a>). Based on the permanency of those air/missile defence batteries it doesn't look like the government of Bahrain are expecting things to get safer for data centre hosting in Bahrain any time soon.</p>
]]></description><pubDate>Fri, 24 Jul 2026 14:57:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=49036640</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=49036640</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49036640</guid></item><item><title><![CDATA[New comment by dhx in "Half a Second – a book about the XZ backdoor"]]></title><description><![CDATA[
<p>See [1] for April 2024 Clickhouse Github activity analysis of the xz backdoor.<p>I haven't seen anyone write up a proper analysis that includes consideration of:<p>- GitHub activity (e.g. all API actions on GitHub side including replying to comments) _and_ mailing list activity _and_ other public facing activity all considered together.<p>- Complexity of public actions e.g. was there a queue of code changes that would have taken 20 hours effort to put together that were all committed at once? Were there any long streaks of high activity where it might reveal how many people were involved?<p>- Latency of public actions e.g. if an issue was raised by some random person, how long did it take for the attacker to respond, and later resolve/commit a patch? Similar to the complexity of public actions, it might reveal how many people were involved by estimation of the time needed for an experienced developer to fix an issue vs. actual time taken, both in terms of level of effort and duration.<p>- International dispersement of a team in different timezones with some core hours for collaboration, review and public facing activity.<p>- Public holidays, country/region-specific work habits, etc--e.g. consideration of "summer holiday" periods or similar common holiday periods, consideration of unusual days of no/low activity versus snow days, power outages, etc which might have been experienced by the attacker.<p>Distribution of actions from Github indicates the attacker used a 6 day work week excluding Sunday, and almost all activity conducted between UTC 12:00-16:00. Within these 6 days, activity was uneven at 0.5, 1, 1, 1, 1, 0.5 effort per day. There are low activity periods too that line up with summer solstice (southern hemisphere) or winter solstice (northern hemisphere).<p>There are interesting patterns in the data not yet publicly analysed (I think?) that seemingly would reveal the true location of attackers, particularly because attacker actions are anchored to uncontrollable events such as a known-good contributor (such as Linux distro maintainer) raising a Github issue against a repository and the attacker replying an hour later. For such events with low latency of reply, it'd be well worth considering when a reply was made quickly, and when it wasn't, across a few years of data points.<p>[1] <a href="https://news.ycombinator.com/item?id=39905375">https://news.ycombinator.com/item?id=39905375</a></p>
]]></description><pubDate>Sun, 19 Jul 2026 12:28:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48967579</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=48967579</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48967579</guid></item><item><title><![CDATA[New comment by dhx in "Microsoft has released software updates to plug at least 570 security holes"]]></title><description><![CDATA[
<p>Title is not correct. Microsoft didn't patch a lot of this, they're reporting patches for dependencies that other people patched and Microsoft are inheriting.<p>For example, Mariner (now branded Azure Linux) is a Microsoft-supported Linux distribution. So in this list of 570 vulnerabilities, Microsoft have reported 100 vulnerabilities inherited from all sorts of open source software projects included in their Azure Linux distribution. The OpenSSH vulnerabilities are described in better detail at <a href="https://www.openssh.org/releasenotes.html" rel="nofollow">https://www.openssh.org/releasenotes.html</a> where it implies 2 vulnerabilities were detected with Swival Security Scanner (using LLMs) and another 6 by other researchers/companies (using undisclosed methods).<p>As an example of one of the OpenSSH vulnerabilites CVE-2026-59996 which is attributed to Swival Security Scanner, Swival have published the output of their automated vulnerability detection report at <a href="https://github.com/Swival/security-audits/blob/main/openssh/003-source-server-escapes-remote-target-directory.md" rel="nofollow">https://github.com/Swival/security-audits/blob/main/openssh/...</a></p>
]]></description><pubDate>Wed, 15 Jul 2026 05:30:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48916625</link><dc:creator>dhx</dc:creator><comments>https://news.ycombinator.com/item?id=48916625</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48916625</guid></item></channel></rss>