<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: drewda</title><link>https://news.ycombinator.com/user?id=drewda</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 15 Jun 2026 06:55:29 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=drewda" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by drewda in "Show HN: Homebrew 6.0.0"]]></title><description><![CDATA[
<p>That doc is very useful and confidence inspiring in terms of being mainly about people and process, rather than about one single technical solution.<p>Relevant parts for those who have cool-downs at the top of mind:<p>> Across Homebrew’s history far more users have been protected by shipping zero-day fixes quickly than have been exposed to npm-style token-theft or crypto-mining attacks, so a global cooldown would be a net negative for most users’ security. The deeper reason Homebrew does not need a general cooldown is that, unlike language package managers, it already separates publishing from distribution: an upstream release does not reach users until it has passed human review, CI and checksum verification, which is the very review window that language-ecosystem cooldowns are trying to recreate.<p>[...]<p>> For ecosystems with a track record of fast-moving supply-side attacks, Homebrew applies a download cooldown: a freshly-published upstream version is not adopted immediately, giving the wider community time to detect and report a malicious release before Homebrew users are exposed. Cooldowns have been added for:<p><pre><code>    Bundler
    RubyGems livecheck
    npm and pip defaults
    PyPI resource resolution
    npm and PyPI in bump</code></pre></p>
]]></description><pubDate>Thu, 11 Jun 2026 18:02:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=48494074</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=48494074</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48494074</guid></item><item><title><![CDATA[New comment by drewda in "VoidZero Is Joining Cloudflare"]]></title><description><![CDATA[
<p>In many cases the acquiring company shares investors or board members with the acqui-hired entity.<p>To put it neutrally, VC partners are treating these are parts of their same portfolios, so if one team doesn't pan out on its own, it can be merged into another with somewhat similar overall goals or markets.<p>To put it more pointedly, it's perhaps all about who one knows and making sure that everyone gets to tell a story of successful exits.</p>
]]></description><pubDate>Thu, 04 Jun 2026 14:56:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=48399661</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=48399661</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48399661</guid></item><item><title><![CDATA[SF startup is testing robots in Airbnbs, and trashing them, lawsuit claims]]></title><description><![CDATA[
<p>Article URL: <a href="https://sfstandard.com/2026/05/28/sf-startup-secretly-testing-robots-airbnbs-trashing-lawsuit-claims/">https://sfstandard.com/2026/05/28/sf-startup-secretly-testing-robots-airbnbs-trashing-lawsuit-claims/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48317093">https://news.ycombinator.com/item?id=48317093</a></p>
<p>Points: 272</p>
<p># Comments: 150</p>
]]></description><pubDate>Thu, 28 May 2026 23:42:47 +0000</pubDate><link>https://sfstandard.com/2026/05/28/sf-startup-secretly-testing-robots-airbnbs-trashing-lawsuit-claims/</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=48317093</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48317093</guid></item><item><title><![CDATA[New comment by drewda in "GitHub confirms breach of 3,800 repos via malicious VSCode extension"]]></title><description><![CDATA[
<p>This will not reassure you, but the reason it isn't necessarily really bad is because it's only incrementally worse than the really bad news came out last month:<p>Security researchers identified a series of exploitable vulnerabilities in github.com by using LLMs to review the compiled GitHub Enterprise Server binaries: <a href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854" rel="nofollow">https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-38...</a></p>
]]></description><pubDate>Thu, 21 May 2026 05:50:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48218404</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=48218404</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48218404</guid></item><item><title><![CDATA[New comment by drewda in "Anthropic acquires Stainless"]]></title><description><![CDATA[
<p>> As we focus on Claude Platform capabilities and connecting agents to APIs, we’ll be winding down all hosted Stainless products, including our SDK generator. Starting today, new signups, projects, and SDKs will not be available.<p>For better or worse, it's an acquihire.</p>
]]></description><pubDate>Mon, 18 May 2026 17:29:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=48182630</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=48182630</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48182630</guid></item><item><title><![CDATA[New comment by drewda in "GeoJSON"]]></title><description><![CDATA[
<p>Yup, technically speaking if the coordinates aren't in WGS84, it isn't GeoJSON</p>
]]></description><pubDate>Fri, 08 May 2026 17:43:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48066379</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=48066379</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48066379</guid></item><item><title><![CDATA[New comment by drewda in "Changes to GitHub Copilot individual plans"]]></title><description><![CDATA[
<p>This is pretty straightforward compared to the giant universe of companies that resell Microsoft services.<p>The number of intermediaries that some customers, especially governmental agencies, go through to get just an Azure bill can be wild...</p>
]]></description><pubDate>Wed, 22 Apr 2026 00:46:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=47857158</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47857158</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47857158</guid></item><item><title><![CDATA[New comment by drewda in "People inside Microsoft are fighting to drop mandatory Microsoft Account"]]></title><description><![CDATA[
<p>FWIW I've been on a OS X for many years now, but I still miss keyboard shortcuts in Windows. So much more consistent across the operating system and applications...</p>
]]></description><pubDate>Fri, 27 Mar 2026 16:01:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=47544466</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47544466</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47544466</guid></item><item><title><![CDATA[New comment by drewda in "US SEC preparing to scrap quarterly reporting requirement"]]></title><description><![CDATA[
<p>General Electric has a history of using that exact trick... just with jet engines and power generators and medical devices that can represent much larger amounts of revenue.</p>
]]></description><pubDate>Tue, 17 Mar 2026 03:12:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=47408146</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47408146</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47408146</guid></item><item><title><![CDATA[New comment by drewda in "Claude now creates interactive charts, diagrams and visualizations"]]></title><description><![CDATA[
<p>When using Claude Code, we often prompt it to draft diagrams in MermaidJS syntax.<p>Great for summarizing a multi-step process and quick to render with simple tools.</p>
]]></description><pubDate>Thu, 12 Mar 2026 17:10:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47354056</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47354056</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47354056</guid></item><item><title><![CDATA[Microsoft backs Anthropic to halt US DoD's 'supply-chain risk' designation]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.reuters.com/legal/litigation/microsoft-files-amicus-brief-support-anthropics-lawsuit-with-us-dod-2026-03-10/">https://www.reuters.com/legal/litigation/microsoft-files-amicus-brief-support-anthropics-lawsuit-with-us-dod-2026-03-10/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47331798">https://news.ycombinator.com/item?id=47331798</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 11 Mar 2026 04:41:30 +0000</pubDate><link>https://www.reuters.com/legal/litigation/microsoft-files-amicus-brief-support-anthropics-lawsuit-with-us-dod-2026-03-10/</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47331798</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47331798</guid></item><item><title><![CDATA[New comment by drewda in "Tinnitus Is Connected to Sleep"]]></title><description><![CDATA[
<p>Have you considered seeing an allergist to test if you have some environmental allergies? If so, they may be able to recommend or prescribe meds to moderate the effects of those allergies. (disclaimer: I'm not a doctor, just someone else with sinus issues)</p>
]]></description><pubDate>Sat, 07 Mar 2026 20:41:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=47291267</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47291267</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47291267</guid></item><item><title><![CDATA[New comment by drewda in "A GitHub Issue Title Compromised 4k Developer Machines"]]></title><description><![CDATA[
<p>No. A newspaper is in the business of selling you content (or advertising alongside content)<p>grith.ai appears to be in the business of guiding you click a "request early access" button so they can eventually sell you software (or so they can pitch seed investors on the length of their list of prospects)<p>Again, I'm not criticizing. Just pointing out a pattern that's becoming pretty common on HN, especially for stories about vulnerabilities written up by companies selling cybersecurity solutions or services.</p>
]]></description><pubDate>Fri, 06 Mar 2026 16:43:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=47277358</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47277358</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47277358</guid></item><item><title><![CDATA[New comment by drewda in "A GitHub Issue Title Compromised 4k Developer Machines"]]></title><description><![CDATA[
<p>FWIW, the best way to get your website on Hacker News is to write a content-marketing blog post about someone else's work.<p>Don't get me wrong. This post is an interesting read. But the company publishing it appears to have nothing to do with the exploit or the people who discovered or patched it.<p>I tip my hat at their successfully marketing :)</p>
]]></description><pubDate>Fri, 06 Mar 2026 15:14:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=47275899</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47275899</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47275899</guid></item><item><title><![CDATA[New comment by drewda in "Google Workspace CLI"]]></title><description><![CDATA[
<p>While I prefer Google's productivity apps to the Microsoft world in this case Google is just catching up to the APIs and tooling that Microsoft has provided for a long time: <a href="https://learn.microsoft.com/en-us/powershell/microsoftgraph/overview?view=graph-powershell-1.0" rel="nofollow">https://learn.microsoft.com/en-us/powershell/microsoftgraph/...</a></p>
]]></description><pubDate>Thu, 05 Mar 2026 04:05:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=47257416</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47257416</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47257416</guid></item><item><title><![CDATA[New comment by drewda in "We Will Not Be Divided"]]></title><description><![CDATA[
<p>They put their names to their position publicly. That is meaningful action.</p>
]]></description><pubDate>Sat, 28 Feb 2026 17:14:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47197753</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47197753</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47197753</guid></item><item><title><![CDATA[New comment by drewda in "I am directing the Department of War to designate Anthropic a supply-chain risk"]]></title><description><![CDATA[
<p>Yes, it's officially still the Department of Defense.<p>If this were a news outline writing "Department of War" I would be concerned. But in the case of the Anthropic CEO's blog post, I can understand why they are picking their fights.</p>
]]></description><pubDate>Fri, 27 Feb 2026 23:44:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=47187679</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47187679</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47187679</guid></item><item><title><![CDATA[New comment by drewda in "Banned in California"]]></title><description><![CDATA[
<p>That's exactly why the Bay Area Air Quality Management District exists (established decades before the federal EPA):<p>> Charged with regulating stationary sources of air pollution emissions, the Air District drafted its first two regulations in the 1950s: Regulation 1, which banned open burning at dumps and wrecking yards, and Regulation 2, which established controls on dust, droplets, and combustion gases from certain industrial sources.<p>> Much research and discussion went into the shaping of Regulation 2, but there was no doubt about the need for it. During a fact-finding visit to one particular facility, Air District engineers discovered that filters were used over air in-take vents to protect the plant's machinery from its own corrosive emissions! This much-debated regulation was finally adopted in 1960.<p><a href="https://www.baaqmd.gov/en/about-the-air-district/history-of-air-district" rel="nofollow">https://www.baaqmd.gov/en/about-the-air-district/history-of-...</a></p>
]]></description><pubDate>Thu, 26 Feb 2026 14:47:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=47166841</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47166841</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47166841</guid></item><item><title><![CDATA[New comment by drewda in "Factory-built housing hasn't taken off in California"]]></title><description><![CDATA[
<p>The reason for most of those fees for parks and schools is because Prop 13 has prevented property taxes from raising with the market on older property owners (and the LLCs that own commercial properties), so cities and school districts have to instead turn to newcomers to get some amount of revenue to cover the costs of providing public services.</p>
]]></description><pubDate>Sun, 22 Feb 2026 22:00:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=47115191</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=47115191</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47115191</guid></item><item><title><![CDATA[New comment by drewda in "An AI agent published a hit piece on me"]]></title><description><![CDATA[
<p>FWIW, there's already a huge corpus of rants by men who get personally angry about the governance of open-source software projects and write overbearing emails or GH issues (rather than cool down and maybe ask the other person for a call to chat it out)</p>
]]></description><pubDate>Thu, 12 Feb 2026 19:40:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=46993969</link><dc:creator>drewda</dc:creator><comments>https://news.ycombinator.com/item?id=46993969</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46993969</guid></item></channel></rss>