<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: everforward</title><link>https://news.ycombinator.com/user?id=everforward</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 04 Oct 2026 00:47:14 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=everforward" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by everforward in "Show HN: Pi pod – Run your pi coding agent in sandboxes on your own server"]]></title><description><![CDATA[
<p>I have a similar project you might be interested in if you use ACP via Zed or something; I need to make a Show HN post at some point.<p>The gist is that it pretends to be an ACP agent to Zed, but it actually spins up a Docker container on your PC and proxies the ACP connection over websocket to the agent.  It supports bind-mounting your Pi config like you're doing (as well as copying files, so changes don't propagate to your host).  It also has early plugin support for your ACP connection.  It's basically an nginx proxy for ACP, I just made a plugin that will automatically kill a session if it detects OpenRouter secrets in agent output, tool calls, file access or shell commands.<p>It doesn't currently support remote targets like your server, but it's on the list.<p>Another notable difference is that it creates a new container every time you connect so you get an idempotent environment, though I am also working on a persistent style.  Everything supports it, I just need to make the host-side binary support finding a container to use before it tries starting a new one.<p><a href="https://abyss.scurry.io/" rel="nofollow">https://abyss.scurry.io/</a></p>
]]></description><pubDate>Sat, 03 Oct 2026 21:59:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=49948207</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49948207</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49948207</guid></item><item><title><![CDATA[New comment by everforward in "Pi Durable"]]></title><description><![CDATA[
<p>It’s neat but I don’t think fixes these issues because they have to integrate with live systems. You can lie about system time in tests by making everything else have the same time.<p>That doesn’t apply if I need to hit gmail.com and can’t login because my system time is a week behind and the JWT says it isn’t valid for another week.<p>Even if you make everything else accept the time, timestamps will be screwed. Like in a fake gmail service that accepts mocked times, what do you use for timestamps on emails?</p>
]]></description><pubDate>Fri, 02 Oct 2026 21:51:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=49939051</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49939051</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49939051</guid></item><item><title><![CDATA[New comment by everforward in "Pi Durable"]]></title><description><![CDATA[
<p>The good version of it is to only allow interacting with the environment declaratively (preferably idempotently as well), and then checkpointing those.<p>So rather than saying “open chrome, go to this page, click next page 5 times”, it would be something like “chrome is running; url is X; url is X/page/1; url is X/page/2” etc. Ansible, basically.<p>Other than that, you could just replay bash tool calls. That’s full of holes, though. Anything that relies on “date” will return different stuff, and if you try checkpointing the system time then TLS breaks due to timestamp differences.<p>If you wanted to go absolutely wild, some hypervisors can checkpoint the memory of a running VM and revert back to a prior version memory and all. I can’t imagine a way to make money off that (you’d be writing gigs of data per checkpoint), but I suppose it’s technically possible.</p>
]]></description><pubDate>Fri, 02 Oct 2026 14:33:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=49933983</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49933983</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49933983</guid></item><item><title><![CDATA[New comment by everforward in "Returning from vacation? The government can search your phone without a warrant"]]></title><description><![CDATA[
<p>Thats partially that we insist on interpreting it in this contorted lens of “how the founding fathers meant it”, when words like “reasonable” seem like they’re clearly meant to reflect the current opinion of the populace. If people find it unreasonable, it is, and vice versa.<p>I don’t think “interstate commerce” is unclear at all. That’s one where started with an end goal in mind and rationalized everything in between. There is no sane English reading of that passage that resembles the current interpretation at all. We just repeatedly mentally Google Translated it to Spanish and back until it was vague enough to allow what we wanted.</p>
]]></description><pubDate>Thu, 01 Oct 2026 14:59:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49922537</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49922537</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49922537</guid></item><item><title><![CDATA[New comment by everforward in "Returning from vacation? The government can search your phone without a warrant"]]></title><description><![CDATA[
<p>They don’t get tried in part because of Qualified Immunity (which has some rationality but I think we’ve taken it much too far), and in part because the structure of the system doesn’t incentivize it.<p>The people who would charge the officers are the same people who rely on the police to provide evidence. Both groups work closely together. Malfeasance by police typically provides the prosecution with evidence they want or people to charge. There’s no incentive other than morality to charge them, and a lot of reasons to find a way to rationalize it as untrue, or necessary, or whatever.</p>
]]></description><pubDate>Thu, 01 Oct 2026 14:51:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49922440</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49922440</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49922440</guid></item><item><title><![CDATA[New comment by everforward in "Systems that no one will test"]]></title><description><![CDATA[
<p>Data diodes of some level are semi-common in my experience. An SSH bastion host is a sort of that thing.<p>I think it works better than you realize, though it is about as painful. Most of these just ban UDP leaving the subnet. TCP is stateful so you can set firewalls to allow inbound connections but not outbound, and you can terminate TCP connections based on bandwidth ratios (ie if you’re sending more than 10% of what you’re downloading then the connection gets killed).<p>Im largely with you on air gaps in the modern day, with the exception of storage. Backups should be airgapped, but that’s common practice basically anywhere that runs their own servers.</p>
]]></description><pubDate>Thu, 01 Oct 2026 14:46:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=49922374</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49922374</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49922374</guid></item><item><title><![CDATA[New comment by everforward in "You said no MCP"]]></title><description><![CDATA[
<p>I’m not sure; the integrated GUI seems like a major differentiator for them.<p>Pi’s agent is supposed to be simple, and a simple ACP agent is like a couple hundred lines of code. Making a system that allows UI plugins is way harder.<p>Also not sure if you’ve seen but you can get ACP from Pi with 
<a href="https://github.com/svkozak/pi-acp" rel="nofollow">https://github.com/svkozak/pi-acp</a> It bridges Pi’s RPC mode to ACP, works okay but not amazingly. My thinking level selector in Zed has never worked with it but everything else I use has worked (I’m sure other things don’t but I must not use them).</p>
]]></description><pubDate>Wed, 30 Sep 2026 14:37:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=49909636</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49909636</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49909636</guid></item><item><title><![CDATA[New comment by everforward in "You Said No MCP"]]></title><description><![CDATA[
<p>I’m still not entirely sold. I do hear you about team workflows, I’m just not sure MCP does that dramatically better (as of today).<p>I can see the snap appeal. One protocol, we can chuck an auth reverse proxy in front of all the MCPs, compliance has their integration point, etc.<p>I don’t think MCP is structured enough to give a huge edge over bash there. Looking at MCP messages, they aren’t immediately more legible than a bash command, output and exit code. You also don’t own a lot of the MCP servers you use, so backtracking for audits will require knowing what MCP commands did what back then.<p>I do suspect something more like MCP than bash will be the winner. MCP just feels very open source rather than enterprise. Eg I don’t think I’ve seen any sort of privilege escalation and logging scheme. The enterprise will want some sort of “request admin privileges” scheme. Likewise they’ll probably want more context on ACP requests; who is calling this MCP, using what agent, and for what project?</p>
]]></description><pubDate>Wed, 30 Sep 2026 14:29:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49909520</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49909520</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49909520</guid></item><item><title><![CDATA[New comment by everforward in "Dots: Always-on agents"]]></title><description><![CDATA[
<p>I'm working on a project that solves some of this [1].  It runs agents in Docker and proxies the ACP connection via websocket, with WASM-based plugins in that proxy so you can get in between your client and the agent if you want.<p>It currently tears down the container after the session, but it wouldn't take much to leave it running post-connection and make a mode that continually re-uses the same container.<p>It's also possible to intercept ACP read/write file and shell commands via one of the WASM-based plugins if you wanted to execute them in a separate VM/container.  I'd have to double check on FS permissions for the Docker socket; I think plugins have no file access currently because I haven't figured out a permission system for it yet.  The whole plugin system is new and I'm still working out some of the edges.<p>Feedback and feature requests welcome!<p>[1] <a href="https://github.com/SethCurry/abyss" rel="nofollow">https://github.com/SethCurry/abyss</a></p>
]]></description><pubDate>Wed, 30 Sep 2026 02:04:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=49903500</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49903500</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49903500</guid></item><item><title><![CDATA[New comment by everforward in "America.gov"]]></title><description><![CDATA[
<p>They can take it as authoritative, but that won't change the consequences if they're wrong.  This is already a thing between two people; "my cop friend told me it was okay" isn't a legal defense.  Changing the 2nd person to an AI doesn't change much, both are still agents of the government.<p>Doesn't really have any bearing on a similar system for HR.  The government is sort of unique in a bunch of ways, but not really being responsible for what their low level agents say is one of them.<p>I'm not sure how to fix that, to be honest.  I'm also not sure how much worse it is than trying to Google it?  Google is full of stuff that's either wrong, or won't apply for a reason that takes some reading comprehension to grasp (e.g. state-specific rules/programs/etc).</p>
]]></description><pubDate>Wed, 30 Sep 2026 01:15:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=49903163</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49903163</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49903163</guid></item><item><title><![CDATA[New comment by everforward in "500k facial scans at UK stations yield no arrests, 1 false positive"]]></title><description><![CDATA[
<p>That’s not hard to value, it just doesn’t make Flock look particularly good. If these actually work well, you would expect the average catch rate to be nearly 100%. We had decent rates just having humans look, Flock should be clearing those like crazy if it works.<p>It doesn’t. I had a car stolen, called it in as they pulled away. I live a block from a Flock camera, 2 others apparently captured it. Car wasn’t intercepted, car was never recovered, no arrests were ever made. They could have put up scarecrows and it would have done as much good for a lot cheaper.<p>> the system will come off pretty badly in terms of ROI.<p>It’s a bad evaluation function. A lot of the cost of crime isn’t directly the crime, it’s the economic deadweight of trying to deter the crime. Every car needs anti-theft parts, lots of people buy home security systems, armored cars to do bank drops, etc, all this stuff we pay for that exists solely to try to stop crime.<p>Flock would look great if it worked so well it made armored cars and car anti-theft obsolete. It won’t, but if it did the ROI would be crazy.</p>
]]></description><pubDate>Tue, 29 Sep 2026 13:37:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49893049</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49893049</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49893049</guid></item><item><title><![CDATA[New comment by everforward in "The problem is not AI code, but not knowing about system architecture or intent"]]></title><description><![CDATA[
<p>> But today you can do even better, with AI can do true waterfall by rewriting from scratch many times.<p>This does nothing other than ensure you end up in the "joy" of running a v0.0.1 product but for years on end instead of for a few months.<p>I hear this sort of thing a lot, and I can't help but internally translate it to "I've never had to take oncall for a product directly after a rewrite".  It will be broken; not even because the AI is "wrong", but because the rewrite has new edge cases.  No one rewrites a project to have the exact same edge cases.  Those edge cases will become outages.  No one will learn anything, because a month from now it will be rewritten and those edge cases will get swapped for something else; you can pick which edge of the CAP theorem you want to live on, but you can't pick "none of them".</p>
]]></description><pubDate>Mon, 28 Sep 2026 23:15:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49885782</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49885782</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49885782</guid></item><item><title><![CDATA[New comment by everforward in "The problem is not AI code, but not knowing about system architecture or intent"]]></title><description><![CDATA[
<p>I agree with you, but it's a moot point for software engineering.<p>> Your concerns have moved up the stack to managing requirements, context, and verification processes.<p>This has always been the concern.  "Add oauth to this app, there are no requirements beyond oauth working" has been an intern level task for ages.  What makes software engineering hard is when the requirements start adding "well it has to use this oauth backend that isn't technically spec compliant, and the user is going to send some kind of random token you need to translate to oauth, and...".  The problem isn't in writing code that will do the thing, it's figuring out exactly how that backend isn't oauth compliant and what chain of API calls I have to make to convert their random token into an oauth one, and etc.<p>Producing software that complies with a test suite isn't really novel.  You've been able to outsource that forever.  This falls apart in the same places outsourcing does; I'm sure India/Phillipines/etc/ is more than capable of iterating on code until it passes a test suite.</p>
]]></description><pubDate>Mon, 28 Sep 2026 23:06:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49885694</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49885694</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49885694</guid></item><item><title><![CDATA[New comment by everforward in "Flock Wants the Most Detailed Map of Its Surveillance Cameras Taken Offline"]]></title><description><![CDATA[
<p>I think you misunderstand the balance of power.  If you're talking about power over you specifically, your local clerk almost certainly has more than your senator.  If they both want to make your life suck, the clerk is the one with the relationship to the local PD, the ability to make your filings get lost in a pile for a couple days so they were technically filed late, etc.  Your senator or representative is likely in 0 of the processes you are likely to engage in unless you're notable enough that you specifically get targeted by the state legislature.<p>> Also, there are private individuals who knowingly exercise more power than that clerk.<p>This is partially a pet peeve of mine, but again, almost certainly not.  I struggle to think of someone with more ability to kill a project than a clerk that refuses to do their job.<p>Kim Davis was a clerk that refused a literal Supreme Court order.  As best I can tell, she did 5 days in jail and launched a million dollar speaking career out of it.  Bezos or Musk can be absolutely sidelined by a clerk who is pissed off enough to accept eventually getting fired as a result.</p>
]]></description><pubDate>Mon, 28 Sep 2026 22:53:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=49885583</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49885583</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49885583</guid></item><item><title><![CDATA[New comment by everforward in "Ember-1"]]></title><description><![CDATA[
<p>I vaguely recall a project from a while back that did something similar without LLMs.<p>I’m really pushing my recall, but I want to say it was written in Ruby and stored pre-configured commands that it just did traditional search over.<p>I vaguely recall it working okay because 99.99% of the questions people asked were the same (“tar command to gzip a directory and strip the prefix” is something I google like once a month).</p>
]]></description><pubDate>Mon, 28 Sep 2026 14:27:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=49878547</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49878547</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49878547</guid></item><item><title><![CDATA[New comment by everforward in "On caring for user data: NeoVim caused Vim undo files to be deleted"]]></title><description><![CDATA[
<p>At one point vim lacked asynchronous plugins. If a plugin was running a builder or linter it locked the editor up (from what I recall).<p>That fell apart when people wanted vim to do some more modern IDE kind of things like all the “… on save” stuff (build on save, test, lint, etc). I think LSP support is native in neovim as well.<p>I believe vim merged asynchronous plugin support a while back though, so I’m not sure how different they really are anymore.</p>
]]></description><pubDate>Sun, 27 Sep 2026 16:18:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=49868065</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49868065</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49868065</guid></item><item><title><![CDATA[New comment by everforward in "Turning GLM-5.3-Flash into a Jev-like decision model"]]></title><description><![CDATA[
<p>I think the truth is sort of halfway between yall.<p>Hallucinations in tool call results _do still exist_, but basically everyone asks for a JSON schema for the tool call and uses that to validate and re-prompt the LLM until it emits something with a valid schema.<p>That all goes out the window when a string field has a “hidden” schema in that only particular strings are valid, but that restriction isn’t in the JSON schema. I have had failures when I want a field to be specifically formatted Markdown or something.<p>We’ll probably see something that handles this better in the future like jsonnet or Cue or dhall that has some execution capabilities so you can write a custom validator beyond what JSON schema supports.</p>
]]></description><pubDate>Sun, 27 Sep 2026 14:19:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=49866867</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49866867</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49866867</guid></item><item><title><![CDATA[New comment by everforward in "U.S. appeals court upholds designation of Anthropic as supply chain risk"]]></title><description><![CDATA[
<p>Bombing civilian infrastructure is a war crime because the end state is the same as bombing civilians. Killing power shuts down hospitals and emergency responders (generators run out eventually) and desalination plants. The military is largely unphased, they’re the first ones to get gas for generators.<p>Also, this is carpet bombing. Carpet bombing is the targeting of civilian infrastructure with effectively willful ignorance of the collateral damage.<p>We started a war knowing the only way to win was either boots on the ground or war-criming our adversary into submission. We don’t get to pretend our hands are tied and we have to send out the bombers. We don’t have to do this because Iraq forces us to, we have to do this because we elected a man who can barely read Post It notes and ignored half a century of military intelligence. We are at fault for every dollar of damage caused to infrastructure and every life lost.</p>
]]></description><pubDate>Sat, 26 Sep 2026 22:00:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=49860928</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49860928</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49860928</guid></item><item><title><![CDATA[New comment by everforward in "Plan mode is dead"]]></title><description><![CDATA[
<p>I haven’t tested with Claude specifically in a while, but I see this a lot on larger features.<p>It tends to be small decisions way down the stack that bubble up, or an incoherent data model that can’t handle what you’re asking for cleanly.<p>Eg I was messing with a state tracker the other day. The state tracker assumes a container is either currently running, or fully removed from disk.<p>The LLM chose to remove the state file when the container is stopped and then to remove it after, which leaks container storage.<p>The LLM is kind of stuck though, because every option other than “rewrite the data model” has negative outcomes and it probably violates user expectations to launch a massive rewrite there.</p>
]]></description><pubDate>Sat, 26 Sep 2026 14:01:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=49856641</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49856641</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49856641</guid></item><item><title><![CDATA[New comment by everforward in "U.S. appeals court upholds designation of Anthropic as supply chain risk"]]></title><description><![CDATA[
<p>Militaries have a lot of experience, and an exceptionally poor track record.<p>I don’t remember the last war that didn’t have credible evidence of war crimes occurring. Were bombing civilian infrastructure in Iran, Iraq had Abu Ghraib among all the Collateral Damage stuff, the Highway of Death in the Gulf was probably a war crime, Vietnam had My Lai, WWII was the advent of carpet bombing civilian infrastructure. I can’t think of any for Korea, but I also know very little so that doesn’t say much.<p>We still haven’t charged anyone for the second strike on that fishing boat in South America, and I haven’t heard a single rationale for why that’s not a war crime other than “fog of war”.<p>The US doesn’t even really have a meaningful system for finding and prosecuting these, because we aren’t signatories for the ICC and have a bill saying we’ll invade if they charge one of our service members with a war crime. We aren’t basically the furthest thing from having any experience prosecuting war crimes. I can probably count on my fingers the number of cases we’ve tried. We rarely charge our own service members, and we usually kill foreign combatants rather than capture and charge them.</p>
]]></description><pubDate>Fri, 25 Sep 2026 18:14:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=49848061</link><dc:creator>everforward</dc:creator><comments>https://news.ycombinator.com/item?id=49848061</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49848061</guid></item></channel></rss>