<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: flaminHotSpeedo</title><link>https://news.ycombinator.com/user?id=flaminHotSpeedo</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 24 Jul 2026 05:44:09 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=flaminHotSpeedo" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by flaminHotSpeedo in "Dwarf Fortress in the Browser"]]></title><description><![CDATA[
<p>I was under the impression the purpose of that is to give an LLM a cheap (in terms of context window) understanding of a repo, and not at all for the benefit of humans?<p>Whether that's effective is another matter, even if the LLM generating the list does so correctly and updates the list consistently</p>
]]></description><pubDate>Thu, 18 Jun 2026 15:54:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=48587325</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=48587325</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48587325</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "How we run Firecracker VMs inside EC2 and start browsers in less than 1s"]]></title><description><![CDATA[
<p>I haven't personally tried, so I can't say for certain, but Lambda has publicly stated they run on bare metal EC2 instances, presumably the supply of whatever instance types they use should be fairly healthy</p>
]]></description><pubDate>Thu, 18 Jun 2026 03:08:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48580254</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=48580254</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48580254</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "How we run Firecracker VMs inside EC2 and start browsers in less than 1s"]]></title><description><![CDATA[
<p>Most mature and/or security conscious providers don't consider containers to be a secure isolation boundary (with Microsoft being a notable exception, though it's unclear whether that's a failure of internal policy or incompetent enforcement of policy).<p>Containers provide a much broader attack surface than VM's, and since they're not considered secure as an industry standard there's likely to be less resources put towards managing container escape CVE's than VM escape ones.</p>
]]></description><pubDate>Thu, 18 Jun 2026 03:05:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48580215</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=48580215</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48580215</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "Tech CEOs are apparently suffering from AI psychosis"]]></title><description><![CDATA[
<p>I wasn't expecting a peer reviewed study, but I certainly was expecting more from that title</p>
]]></description><pubDate>Thu, 28 May 2026 07:45:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48305908</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=48305908</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48305908</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "An AI agent deleted our production database. The agent's confession is below"]]></title><description><![CDATA[
<p>What makes you say that? The article is pretty clear that they had the llm working in a staging environment, then it decided to use some other creds it found which (unbeknownst to the author) had broad access to their prod environment.</p>
]]></description><pubDate>Sun, 26 Apr 2026 16:56:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=47911764</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=47911764</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47911764</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "Ubisoft's death by a thousand cuts"]]></title><description><![CDATA[
<p>I wish there was a mechanism to force shitty, bloated companies that have been mismanaged into a nosedive to divest "culturally valuable" IP early.<p>I enjoyed the early ghost recon and rainbow 6 games, but I don't even bother keeping up with news for newer ones.</p>
]]></description><pubDate>Tue, 24 Mar 2026 06:14:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47499152</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=47499152</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47499152</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "Urea prices"]]></title><description><![CDATA[
<p>350 was late last year. The text at the top of the linked page says prices are up about 30% over the past month. Directly prior to the war starting the price was about 470</p>
]]></description><pubDate>Thu, 12 Mar 2026 02:27:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=47345596</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=47345596</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47345596</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "Never buy a .online domain"]]></title><description><![CDATA[
<p>>  My opinion is that both should be liable in a case like this.<p>I totally agree, but if I went after every company I felt to be incompetent to the point of criminal negligence I'd be up to my eyeballs in lawsuits just over password requirements.<p>> The answer is always the same IMO. Break up big tech companies into a million little pieces.<p>Generally I agree, but in this case I think there's an even simpler solution: 1) hold Google accountable for entries in their safe browsing lists (as an adjacent poster pointed out, the legal precedent may be there) and 2) make companies legally liable for misusing 3rd party data.<p>Really just the second part would suffice, and frankly it's purely good for society. The inevitable outcome is that no one exposes data they can't guarantee, and maliciously consuming 3p data would nearly disappear</p>
]]></description><pubDate>Thu, 26 Feb 2026 08:50:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=47163584</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=47163584</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47163584</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "Never buy a .online domain"]]></title><description><![CDATA[
<p>That's fair, if your domain is erroneously put on the block list, Google should be liable for the consequences.<p>But my point is that any knock on effects like domain suspension, email deliver-ability, etc. stem from 3rd parties misusing the safe browsing list outside the scope of safe <i>browsing</i>.<p>I don't see how Google can be blamed for other companies erroneously treating the safe browsing list as a source of truth for generally malicious domains</p>
]]></description><pubDate>Wed, 25 Feb 2026 21:41:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=47158324</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=47158324</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47158324</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "Never buy a .online domain"]]></title><description><![CDATA[
<p>Self censorship requires a threat or risk of detriment if the party doesn't self censor, right? Where is that here?<p>What Radix does has no impact on Google, and I don't see how Google would be incentivized to pressure Radix. So I don't see how to make the leap blaming Google for Radix's incompetence. Yes, Google should recognize the risk of this happening, but they'd have to balance that against the rewards (or at least what they consider rewards)</p>
]]></description><pubDate>Wed, 25 Feb 2026 18:18:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=47155426</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=47155426</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47155426</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "I found a vulnerability. they found a lawyer"]]></title><description><![CDATA[
<p>Theoretically, the easiest way is to use a sub address (more commonly/colloquially known as email aliases or plus addresses, they're described in RFC 5233). You should be able to add a separator character (usually a plus, sometimes other characters instead/in addition) and arbitrary text to your email address, i.e. "myemail+somecompany@example.com" should route to "myemail@example.com"<p>In practice, this works about 95-99% of the time. Some websites will refuse the + as an invalid special character, and the worst of the worst will silently strip it before persisting it, and may or may not strip it when you input your email another time (such as when you're logging in or recovering your password).<p>I also suspect spammers strip out subaddresses frequently, very little of the spam I receive includes the subaddress.<p>So the only 100% reliable way is to use your own domain, but you don't need to run your own custom mail server</p>
]]></description><pubDate>Sat, 21 Feb 2026 20:10:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=47104189</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=47104189</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47104189</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "Software factories and the agentic moment"]]></title><description><![CDATA[
<p>You might want to review the commenting guidelines, notably the first few.<p>Like you mention, big tech gravitates to a handful of tech hubs across the US, which drives up salaries for every company in the area. Which is more data suggesting something is wrong with BLS' numbers.<p>My expectation (based on anecdotal/personal data - if you have better data I'd love to see it) is that the median developer in a tech hub makes more than an entry level big tech kid. So unless there's either an error, omission, or unexpected inclusion in the BLS data, the data implies that nearly all of big tech, plus ~50% of developers in tech hubs, accounts for about 10% of the workforce.<p>That doesn't make sense. What does seem plausible is that this data doesn't account for bonuses, options, RSUs, and the like, which would put big tech entry level jobs right around the median for developers. I'm not certain if that's the case, but it at least passes the sniff test.</p>
]]></description><pubDate>Sun, 08 Feb 2026 05:27:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=46931568</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=46931568</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46931568</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "Software factories and the agentic moment"]]></title><description><![CDATA[
<p>I think there's a fundamental misunderstanding where executives mistake software engineering for "code monkey with a fancy inflated title"<p>And coding agents are making that disconnect painfully obvious</p>
]]></description><pubDate>Sun, 08 Feb 2026 02:33:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=46930768</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=46930768</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46930768</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "Software factories and the agentic moment"]]></title><description><![CDATA[
<p>I question their data if their p90 value is $211k<p>I recognize that not everyone makes big tech money, but that's somewhere between entry and mid level at anywhere that can conceivably be called big tech</p>
]]></description><pubDate>Sun, 08 Feb 2026 01:40:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=46930477</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=46930477</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46930477</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "Some Epstein file redactions are being undone"]]></title><description><![CDATA[
<p>Are you thinking of the Missouri department of education's teacher directory website?<p><a href="https://krebsonsecurity.com/2022/02/report-missouri-governors-office-responsible-for-teacher-data-leak/" rel="nofollow">https://krebsonsecurity.com/2022/02/report-missouri-governor...</a><p>Luckily someone eventually talked sense into the governor, despite him ignoring the FBI originally when they told him it wasn't a hack</p>
]]></description><pubDate>Wed, 24 Dec 2025 20:09:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=46378790</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=46378790</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46378790</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "NTP at NIST Boulder Has Lost Power"]]></title><description><![CDATA[
<p>Actually, it's really important to me to have a network of atomic clocks available to verify the times I clock in and out, I want to make sure I get paid for an accurate duration of time down to the nanosecond</p>
]]></description><pubDate>Sun, 21 Dec 2025 02:33:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=46341711</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=46341711</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46341711</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "Over 40% of deceased drivers in vehicle crashes test positive for THC: Study"]]></title><description><![CDATA[
<p>> 103 drivers (41.9%) overall tested positive for THC, with yearly rates ranging from 25.7% to 48.9%.<p>The statistics for this seem suspect at best, I'll believe it once it's peer reviewed</p>
]]></description><pubDate>Sun, 21 Dec 2025 02:30:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=46341698</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=46341698</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46341698</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "Over 40% of deceased drivers in vehicle crashes test positive for THC: Study"]]></title><description><![CDATA[
<p>> Researchers analyzed coroner records from Montgomery County in Ohio from January 2019 to September 2024, focusing on 246 deceased drivers who were tested for THC following a fatal crash.<p>This paper would need to go into way more detail to be at all useful.<p>40% is a staggering number, which makes me suspect that all it measures is Montgomery County police's pretty good track record for deciding when to test someone for THC during an autopsy</p>
]]></description><pubDate>Sun, 21 Dec 2025 00:57:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=46341240</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=46341240</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46341240</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "I got hacked: My Hetzner server started mining Monero"]]></title><description><![CDATA[
<p>Yeah, in some (rare) situations physical isolation is a more appropriate level of security. Or if you want to land somewhere in between, you can use VM's with single tenant NUMA nodes.<p>But for a typical case, VM's are the bare minimum to say you have a _secure_ isolation boundary because the attack surface is way smaller.</p>
]]></description><pubDate>Thu, 18 Dec 2025 15:37:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=46313976</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=46313976</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46313976</guid></item><item><title><![CDATA[New comment by flaminHotSpeedo in "I got hacked: My Hetzner server started mining Monero"]]></title><description><![CDATA[
<p>Containers are never a security boundary. If you configure them correctly, avoid all the footguns, and pray that there's no container escape vulnerabilities that affect "correctly" configured containers then they can be a crude approximation of a security boundary that may be enough for your use case, but they aren't a suitable substitute for hardware backed virtualization.<p>The only serious company that I'm aware of which doesn't understand that is Microsoft, and the reason I know that is because they've been embarrassed again and again by vulnerabilities that only exist because they run multitenant systems with only containers for isolation</p>
]]></description><pubDate>Thu, 18 Dec 2025 06:36:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=46309548</link><dc:creator>flaminHotSpeedo</dc:creator><comments>https://news.ycombinator.com/item?id=46309548</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46309548</guid></item></channel></rss>