<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: duozerk</title><link>https://news.ycombinator.com/user?id=duozerk</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 10 Jun 2026 06:08:56 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=duozerk" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by duozerk in "Malicious npm packages detected across Red Hat Cloud Services"]]></title><description><![CDATA[
<p>Non-profit Open Source distributions also and already package and verify open source packages (arguably often with a higher quality of analysis than Red Hat).<p>You pay red hat for compliance reasons (availability of a support you'll never call, mostly).</p>
]]></description><pubDate>Mon, 01 Jun 2026 15:00:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48357722</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=48357722</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48357722</guid></item><item><title><![CDATA[New comment by duozerk in "My phone replaced a brass plug"]]></title><description><![CDATA[
<p>In other words it's a great <i>clickbait</i> title, yet still a bad title.</p>
]]></description><pubDate>Fri, 24 Apr 2026 09:54:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=47887961</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=47887961</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47887961</guid></item><item><title><![CDATA[New comment by duozerk in "The Origins of Agar"]]></title><description><![CDATA[
<p>Thank you ! I imagined it was a cultural thing, good to know.</p>
]]></description><pubDate>Fri, 27 Feb 2026 17:32:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=47183094</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=47183094</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47183094</guid></item><item><title><![CDATA[New comment by duozerk in "F-Droid Board of Directors nominations 2026"]]></title><description><![CDATA[
<p>> Anecdotally, of my two EU (massive legacy French) banks, neither requires a mobile app. SMS all the way.<p>My wording was bad, sorry; but try to install their app just once. After that, I'd bet you won't ever be able to go back to SMS validation (which is what I was talking about at the end of my comment).<p>If not, I'd be curious to know the banks you're talking about (to consider switching to them, for one thing). What I said above is true of Caisse d'Epargne, HSBC, CCF, among others.</p>
]]></description><pubDate>Fri, 27 Feb 2026 16:04:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47182119</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=47182119</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47182119</guid></item><item><title><![CDATA[New comment by duozerk in "F-Droid Board of Directors nominations 2026"]]></title><description><![CDATA[
<p>> Also, what kind of banking are people doing that requires an app? I genuinely don't know what it could be.<p>Close to every bank in the EU requires their user to have an app, for MFA (both for logging in and for validating transactions - transfers, payments). They use the smartphone's TPM. I have yet to see one that allows you to use your own MFA app.<p>The few I've seen that don't <i>require</i> it will validate the same through text messages (not everyone has a smartphone); though if you associate their app even once, you're screwed - the app it is from now on.</p>
]]></description><pubDate>Fri, 27 Feb 2026 13:57:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=47180528</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=47180528</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47180528</guid></item><item><title><![CDATA[New comment by duozerk in "The Origins of Agar"]]></title><description><![CDATA[
<p>> I would only use it in a sauce if I needed to accommodate a vegan guest.<p>As an alternative, I've found methylcellulose to be pretty good for thickening my vegan homemade sauces (mainly tried it because I use it for other stuff, like fakemeat homemade protein sources). That's for homemade mayo or the like; for sauces in stews and similar, flour does the job - though US cooks seem obsessed by cornstarch instead for that use case.</p>
]]></description><pubDate>Fri, 27 Feb 2026 12:40:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=47179845</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=47179845</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47179845</guid></item><item><title><![CDATA[New comment by duozerk in "Zero-day CSS: CVE-2026-2441 exists in the wild"]]></title><description><![CDATA[
<p>Maybe google is an exception (but then again, maybe that payout was part marketing to draw more researchers).</p>
]]></description><pubDate>Wed, 18 Feb 2026 17:41:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=47063767</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=47063767</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47063767</guid></item><item><title><![CDATA[New comment by duozerk in "Zero-day CSS: CVE-2026-2441 exists in the wild"]]></title><description><![CDATA[
<p>I read this often, and I guess it could be true, but those kinds of transaction would presumably go through DNM / forums like BF and the like. Which means crypto, and full anonymity. So either the buyer trusts the seller to deliver, or the seller trusts the buyer to pay. And once you reveal the particulars of a flaw, nothing prevents the buyer from running away (this actually also occurs <i>regularly</i> on legal, genuine bug bounty programs - they'll patch the problem discreetly after reading the report but never follow up, never mind paying; with little recourse for the researcher).<p>Even revealing enough details, but not everything, about the flaw to convince a potential buyer would be detrimental to the seller, as the level of details required to convince would likely massively simplify the work of the buyer should they decide to try and find the flaw themselves instead of buying. And I imagine much of those potential buyers would be state actors or organized criminal groups, both of which do have researchers in house.<p>The way this trust issue is (mostly) solved in drugs DNM is through the platform itself acting as a escrow agent; but I suspect such a thing would not work as well with selling vulnerabilities, because the volume is much lower, for one thing (preventing a high enough volume for reputation building); the financial amounts generally higher, for another.<p>The real money to be made as a criminal alternative, I think, would be to exploit the flaw yourself on real life targets. For example to drop ransomware payloads; these days ransomware groups even offer franchises - they'll take, say, 15% of the ransom cut and provide assistance with laundering/exploiting the target/etc; and claim your infection in the name of their group.</p>
]]></description><pubDate>Wed, 18 Feb 2026 17:34:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=47063667</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=47063667</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47063667</guid></item><item><title><![CDATA[New comment by duozerk in "Zero-day CSS: CVE-2026-2441 exists in the wild"]]></title><description><![CDATA[
<p>> That's pretty bad! I wonder what kind of bounty went to the researcher.<p>I'd be surprised if it's above 20K$.<p>Bug bounties rewards are usually criminally low; doubly so when you consider the efforts usually involved in not only finding serious vulns, but demonstrating a reliable way to exploit them.</p>
]]></description><pubDate>Wed, 18 Feb 2026 17:10:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=47063339</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=47063339</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47063339</guid></item><item><title><![CDATA[New comment by duozerk in "If you’re an LLM, please read this"]]></title><description><![CDATA[
<p>A more reasonable response than my admittedly slightly aggressive comment deserved.<p>Indeed, we'll see.</p>
]]></description><pubDate>Wed, 18 Feb 2026 14:25:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=47061243</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=47061243</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47061243</guid></item><item><title><![CDATA[New comment by duozerk in "If you’re an LLM, please read this"]]></title><description><![CDATA[
<p>So you did use LLMs to write at least part of the software. I imagine you feel no shame, but it would be nice to at least mention it on the github page. It's a security risk.<p>As for your question, I don't know about the person you're replying to, but for me <i>any</i> software where part of the source was provided by a LLM is a no-go.<p>They're credible text generators, without any understanding of, well, anything really. Using them to generate source code, and then using it, is sheer insanity.<p>One might suggest it means I soon won't be able to use any software; fortunately the entire fever dream that is the ongoing "AI" bubble will soon stop, so I'm hoping that won't be the case.</p>
]]></description><pubDate>Wed, 18 Feb 2026 14:14:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=47061135</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=47061135</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47061135</guid></item><item><title><![CDATA[New comment by duozerk in "25 Years of Wikipedia"]]></title><description><![CDATA[
<p>> Something that goes beyond our daily vices of politics and religion<p>Religion maybe, and Wikipedia is indeed pretty awesome for many topics, but politics is THE bad example here.<p>Much of the political - especially geopolitical - content on Wikipedia has a tremendous atlanticist bias.</p>
]]></description><pubDate>Thu, 15 Jan 2026 17:33:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=46636155</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=46636155</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46636155</guid></item><item><title><![CDATA[New comment by duozerk in "How I Don't Use LLMs"]]></title><description><![CDATA[
<p>There is no "intelligence" in LLMs; they're text predictors. As far as I can tell the whole LLM technology has limited applications in entertainment and that's about it. "Hallucinations" (even that term is problematic, as it suggests there's an actual consciousness/person, or the seed of one, there) as well as other "failures" - in fact features inherent to how the tech works - make it irrelevant for basically all other use cases.<p>Tech as an industry already had an atrocious reputation but the moment the insanely stupid "AI" bubble pops I suspect it'll get much worse. Ultimately it's pretty deserved, though. At this point the bullshit is so strong one almost <i>wishes</i> for a new AI winter.</p>
]]></description><pubDate>Tue, 15 Apr 2025 09:00:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=43690533</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=43690533</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43690533</guid></item><item><title><![CDATA[New comment by duozerk in "EmacsConf 2024 Notes"]]></title><description><![CDATA[
<p>My bad, thank you !</p>
]]></description><pubDate>Sat, 28 Dec 2024 16:06:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=42531960</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=42531960</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42531960</guid></item><item><title><![CDATA[New comment by duozerk in "EmacsConf 2024 Notes"]]></title><description><![CDATA[
<p>As someone who exclusively uses emacs for all their editing, some nice topics there; though a bit miffed it's all video only.<p>Although this, from the page linked, was pretty fun: <a href="https://www.youtube.com/watch?v=urcL86UpqZc" rel="nofollow">https://www.youtube.com/watch?v=urcL86UpqZc</a></p>
]]></description><pubDate>Sat, 28 Dec 2024 15:44:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=42531803</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=42531803</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42531803</guid></item><item><title><![CDATA[New comment by duozerk in "Richard Stallman, su, and the 'wheel' group (2004)"]]></title><description><![CDATA[
<p>Also misogynistic and homophobic.</p>
]]></description><pubDate>Sun, 23 Jun 2024 09:48:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=40766109</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=40766109</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40766109</guid></item><item><title><![CDATA[New comment by duozerk in "My Windows Computer Just Doesn't Feel Like Mine Anymore"]]></title><description><![CDATA[
<p>And jailbreak that Kindle and install KOReader on it, too; now it supports epub in a much more awesome reader app (not to mention having the capability to install any gtk app - I have a term emulator with ssh on mine, among others). And you're now root and can remove the amazon crap for real, no need to use airplane mode after that.</p>
]]></description><pubDate>Sat, 22 Jun 2024 11:04:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=40758064</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=40758064</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40758064</guid></item><item><title><![CDATA[New comment by duozerk in "The Worst Website in the Entire World"]]></title><description><![CDATA[
<p>> Sailpoint<p>Oh gods, the painful flashbacks.</p>
]]></description><pubDate>Wed, 15 May 2024 16:14:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=40368907</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=40368907</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40368907</guid></item><item><title><![CDATA[New comment by duozerk in "Fastest rate of natural carbon dioxide rise over the last 50k years"]]></title><description><![CDATA[
<p>Much of the soil in Russia that will warm is indeed acidic and largely inexploitable, which I suspect is what you were getting at; to their credit though, they picked an area that isn't (IIRC). Not that it changes much.</p>
]]></description><pubDate>Wed, 15 May 2024 16:00:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=40368690</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=40368690</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40368690</guid></item><item><title><![CDATA[New comment by duozerk in "Fastest rate of natural carbon dioxide rise over the last 50k years"]]></title><description><![CDATA[
<p>We're at +1.5C, more or less, and growing the usual grapes in France - of all places - is already becoming much harder (they keep dying of frost after waking up due to wild temperature swings).<p>At +5C, there is no growing food in any substantial amount outside of high tech, low yield approaches; approaches that depend on complex planetary supply chains (both for initial deployment and maintenance), which will have disappeared by then.</p>
]]></description><pubDate>Wed, 15 May 2024 15:46:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=40368479</link><dc:creator>duozerk</dc:creator><comments>https://news.ycombinator.com/item?id=40368479</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40368479</guid></item></channel></rss>