<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: erikerikson</title><link>https://news.ycombinator.com/user?id=erikerikson</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 13 Apr 2026 21:03:26 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=erikerikson" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by erikerikson in "AI Will Be Met with Violence, and Nothing Good Will Come of It"]]></title><description><![CDATA[
<p>There is?<p><a href="https://www.pewresearch.org/politics/2026/03/25/americans-broadly-disapprove-of-u-s-military-action-in-iran/" rel="nofollow">https://www.pewresearch.org/politics/2026/03/25/americans-br...</a></p>
]]></description><pubDate>Sun, 12 Apr 2026 15:45:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=47741080</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47741080</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47741080</guid></item><item><title><![CDATA[New comment by erikerikson in "France's government is ditching Windows for Linux, says US tech a strategic risk"]]></title><description><![CDATA[
<p>I didn't make the claim that Europe is specifically problematic.  I was noting that between extremes the GP was talking about<p>> Europe's treatment of perceived outsiders<p>Who'd've thunk it, people be tribal?</p>
]]></description><pubDate>Sat, 11 Apr 2026 17:46:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=47732517</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47732517</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47732517</guid></item><item><title><![CDATA[New comment by erikerikson in "France's government is ditching Windows for Linux, says US tech a strategic risk"]]></title><description><![CDATA[
<p>That's fair.  To continue being fair, there's a lot of rough behavior happening throughout the world these days.  We've forgotten how bad we can make things.<p>I'd suggest that in Europe also there's more than just bad thoughts for outsiders but bad words, bad treatment, and exclusion from thriving.  Extreme cases include bodily harm and I'm fairly certain death but these extreme occur at a lower scale.</p>
]]></description><pubDate>Sat, 11 Apr 2026 15:43:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=47731532</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47731532</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47731532</guid></item><item><title><![CDATA[New comment by erikerikson in "France's government is ditching Windows for Linux, says US tech a strategic risk"]]></title><description><![CDATA[
<p>I agree things have improved but the GP to my first post set context to:<p>> Europe's treatment of perceived outsiders<p>You seemed to be picking a rather narrow slice of the scope.</p>
]]></description><pubDate>Sat, 11 Apr 2026 14:11:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=47730789</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47730789</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47730789</guid></item><item><title><![CDATA[New comment by erikerikson in "France's government is ditching Windows for Linux, says US tech a strategic risk"]]></title><description><![CDATA[
<p>In the UK two decades ago (admittedly not the shortest time) I heard plenty of terrible words and treatment of Pakistanis (which seemed to be used as a good enough bucket for all brown skinned people) and people with red hair.  A general disdain for Continentals was a little more subdued.  When I was younger France was famous for it's poor treatment of foreigners and non-francophiles.  Consider all the politics and anger towards those that continue to try to cross the Mediterranean on makeshift boats or the constant complaints about "benefit thieves" who emigrate from the Eastern bloc. There are many examples and some of them are not without basis but while things have gotten less stabby-stabby there's some fairly brutal attitudes and behaviors.</p>
]]></description><pubDate>Sat, 11 Apr 2026 13:55:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=47730645</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47730645</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47730645</guid></item><item><title><![CDATA[New comment by erikerikson in "France pulls last gold held in US"]]></title><description><![CDATA[
<p>No but I read the article and that was the way it described the gain.</p>
]]></description><pubDate>Mon, 06 Apr 2026 15:46:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47662431</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47662431</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47662431</guid></item><item><title><![CDATA[New comment by erikerikson in "France pulls last gold held in US for $15B gain"]]></title><description><![CDATA[
<p>Imagine they bought the gold in the US for 1b and sold for 16b.  Yes they turned around and purchased 16b of order gold immediately but there's was still a transaction where they sold an asset for more than they bought it.</p>
]]></description><pubDate>Mon, 06 Apr 2026 13:55:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=47660987</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47660987</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47660987</guid></item><item><title><![CDATA[New comment by erikerikson in "How to make a sliding, self-locking, and predator-proof chicken coop door (2020)"]]></title><description><![CDATA[
<p>Thanks so much, good to know.  We want chickens in a place with eagle problems.</p>
]]></description><pubDate>Sat, 04 Apr 2026 18:08:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=47641635</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47641635</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47641635</guid></item><item><title><![CDATA[New comment by erikerikson in "How to make a sliding, self-locking, and predator-proof chicken coop door (2020)"]]></title><description><![CDATA[
<p>The price is ridiculous but I've been happy with the design of <a href="https://www.ladiesfirstchickendoor.com/products/" rel="nofollow">https://www.ladiesfirstchickendoor.com/products/</a><p>In the city the door doesn't always shut but I think I could adjust that, I just haven't needed to.</p>
]]></description><pubDate>Sat, 04 Apr 2026 15:18:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47639776</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47639776</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47639776</guid></item><item><title><![CDATA[New comment by erikerikson in "How to make a sliding, self-locking, and predator-proof chicken coop door (2020)"]]></title><description><![CDATA[
<p>How is a bantam helpful with eagles?</p>
]]></description><pubDate>Sat, 04 Apr 2026 15:13:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=47639715</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47639715</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47639715</guid></item><item><title><![CDATA[New comment by erikerikson in "Marc Andreessen is wrong about introspection"]]></title><description><![CDATA[
<p>Non-introspection is a fantastic source of strategic vulnerability.  It can facilitate a bias to action which has it's clear value.  However, if you are creating a highly valuable asset then it puts you in a position where you are extremely easy to manipulate and harvest.  Perhaps this serves VCs quite well.</p>
]]></description><pubDate>Fri, 03 Apr 2026 17:13:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47629332</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47629332</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47629332</guid></item><item><title><![CDATA[New comment by erikerikson in "Axios compromised on NPM – Malicious versions drop remote access trojan"]]></title><description><![CDATA[
<p>I've believe I've already written that but it is that my password manager gets compromised.  It is not perfectly secure and has failure points.  Given that it is separate from the second factor a successful attack against the password manager still leaves an attacker unable to login without a separate compromise of my TOTP code.  Of course that can also be compromised but two compromises is strictly more difficult than one.</p>
]]></description><pubDate>Thu, 02 Apr 2026 01:10:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47608818</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47608818</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47608818</guid></item><item><title><![CDATA[New comment by erikerikson in "Axios compromised on NPM – Malicious versions drop remote access trojan"]]></title><description><![CDATA[
<p>My password manager, as is standard for most of them, will not fill or show a password if the URL bring visited doesn't match the credential.  Thus, a credential not showing is a huge red flag.  The workflow is pretty standardized so any deviation is a big red flag.<p>Maybe you can be more specific about the attack flow you are imagining and how it will work technically to bypass my controls.<p>To answer your question, no and I provided details.  It literally provides a second, non portable factor with a different vulnerability surface.</p>
]]></description><pubDate>Wed, 01 Apr 2026 16:11:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=47602789</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47602789</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47602789</guid></item><item><title><![CDATA[New comment by erikerikson in "Axios compromised on NPM – Malicious versions drop remote access trojan"]]></title><description><![CDATA[
<p>I disagree.<p>I use a password manager and systemically use long random passwords.  An attacker would need to compromise my password manager, phish me, wrench me, or compromise the site the credential is associated with to get that.<p>Using local only TOTP (no cloud storage or portability for me, by choice) they would have to additionally phish me, wrench me, compromise my phone, or compromise my physical security to get the code.<p>None of these are easy except the wrench which is high risk.  My password manager had standard features which make me more phishing resistant, and together they are more challenging than either apart.  For example the fact that my password manager will not fill in the password on a non associated site means I am much less likely to fill in a TOTP code on an inappropriate site.  Though there are vulnerable scenarios they aren't statistically relevant in the wild and the bar is higher regardless.<p>Now I happen to have a FIDO key which I use for my higher security contexts but I'm a fairly low value target and npm isn't one of my high security contexts.  TOTP improves my security stance generally and removing it from npmjs.org weakened my security stance there.</p>
]]></description><pubDate>Wed, 01 Apr 2026 13:40:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=47600728</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47600728</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47600728</guid></item><item><title><![CDATA[New comment by erikerikson in "Axios compromised on NPM – Malicious versions drop remote access trojan"]]></title><description><![CDATA[
<p>TOTP although venerable was better than no second factor at all.</p>
]]></description><pubDate>Tue, 31 Mar 2026 17:11:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=47590452</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47590452</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47590452</guid></item><item><title><![CDATA[New comment by erikerikson in "Axios compromised on NPM – Malicious versions drop remote access trojan"]]></title><description><![CDATA[
<p>No it's not but it's better than nothing.  Don't let the perfect be the enemy of the good.</p>
]]></description><pubDate>Tue, 31 Mar 2026 17:09:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=47590430</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47590430</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47590430</guid></item><item><title><![CDATA[New comment by erikerikson in "Axios compromised on NPM – Malicious versions drop remote access trojan"]]></title><description><![CDATA[
<p>How does this stance work with your CICD?</p>
]]></description><pubDate>Tue, 31 Mar 2026 14:25:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=47587869</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47587869</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47587869</guid></item><item><title><![CDATA[New comment by erikerikson in "Axios compromised on NPM – Malicious versions drop remote access trojan"]]></title><description><![CDATA[
<p>Instead they took away TOTP as a factor.<p>Scaling security with the popularity of a repo does seem like a good idea.</p>
]]></description><pubDate>Tue, 31 Mar 2026 14:12:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=47587683</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47587683</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47587683</guid></item><item><title><![CDATA[New comment by erikerikson in "Police used AI facial recognition to wrongly arrest TN woman for crimes in ND"]]></title><description><![CDATA[
<p>Yes, finding out how badly wrong you were is never fun.  Of course the lack of ubiquitous Oxford comma use is itself and separately displeasing.</p>
]]></description><pubDate>Sun, 29 Mar 2026 18:03:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47565521</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47565521</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47565521</guid></item><item><title><![CDATA[New comment by erikerikson in "AI overly affirms users asking for personal advice"]]></title><description><![CDATA[
<p>Doesn't sound like a close friend to me.  If I tell them what I really think they may not be a friend?  Close may not mean what you think it means.<p>The challenge is that these social choices have a strong stratification effect and those of us who can transit the cultures are statistically rare.</p>
]]></description><pubDate>Sat, 28 Mar 2026 23:00:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=47558830</link><dc:creator>erikerikson</dc:creator><comments>https://news.ycombinator.com/item?id=47558830</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47558830</guid></item></channel></rss>