<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: gnfargbl</title><link>https://news.ycombinator.com/user?id=gnfargbl</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 25 Jul 2026 23:08:15 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=gnfargbl" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by gnfargbl in "Show HN: Bribes.fyi – Know before you go. New feature added"]]></title><description><![CDATA[
<p>Public servants should neither ask for nor expect either?</p>
]]></description><pubDate>Sat, 25 Jul 2026 19:38:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=49050790</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=49050790</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49050790</guid></item><item><title><![CDATA[New comment by gnfargbl in "UK AISI / Caisi Preliminary Assessment of Kimi K3's Cyber Capabilities"]]></title><description><![CDATA[
<p>Assuming the providers are compromised (and I agree that some of them probably are) then I doubt the angle taken will be to poison the product. That kind of thing usually gets noticed eventually.<p>A more likely scenario is to focus on the model users as potential victims, e.g. by logging internal infrastructure descriptions, capturing private access tokens from chats, etc. That is very deniable, because it's hard to <i>prove</i> where the compromised data originated.</p>
]]></description><pubDate>Sat, 25 Jul 2026 16:47:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=49049154</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=49049154</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49049154</guid></item><item><title><![CDATA[New comment by gnfargbl in "Android May Soon Restrict On-Device ADB"]]></title><description><![CDATA[
<p>That link is mentioned in the article. To quote it:<p><i>> Connection to localhost has also been the source of exploit where app are using that socket to adbd to escalate their privileges. What about we restrict to always only binding to wifi interface wlan0 ?</i><p>Nowhere in that text do I see a proposal to assign an additional CVE for this behaviour. Personally I think it would be unusual to assign a CVE for intended-but-potentially-harmful functionality, although I expect people have done that in the past. But, I think overall we're agreeing here.</p>
]]></description><pubDate>Sat, 25 Jul 2026 10:50:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=49046459</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=49046459</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49046459</guid></item><item><title><![CDATA[New comment by gnfargbl in "UK AISI / Caisi Preliminary Assessment of Kimi K3's Cyber Capabilities"]]></title><description><![CDATA[
<p>The most important pieces of information in this report are (a) the confirmation that the PRC models have no guardrails and will participate in offensive activity, and (b) the confirmation that they <i>sometimes</i> meet their objectives.<p>For the purposes of model selection, it's irrelevant to an attacker if a model achieves an offensive objective 70% of the time, when that model refuses to participate 100% of the time. However, a model that <i>always</i> participates but "only" succeeds 10% of the time is golden -- just run it more often, or give it more tokens. Attackers are patient, and many of them are well-resourced.</p>
]]></description><pubDate>Sat, 25 Jul 2026 10:11:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=49046248</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=49046248</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49046248</guid></item><item><title><![CDATA[New comment by gnfargbl in "Android May Soon Restrict On-Device ADB"]]></title><description><![CDATA[
<p>You, and may of the people in the thread here are at cross purposes, I think.<p>The CVE mentioned in the article is <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0073" rel="nofollow">https://nvd.nist.gov/vuln/detail/CVE-2026-0073</a>. That's a real CVE: logic error leading to auth bypass. Fix can be seen at <a href="https://android.googlesource.com/platform/packages/modules/adb/+/842d331f9e5fb10770a09379e19240daea057dba%5E%21/#F0" rel="nofollow">https://android.googlesource.com/platform/packages/modules/a...</a>.<p>Separately, a number of people here are attempting to argue that the availability of On-Device ADB should be regarded as a "CVE" in and of itself. Google does not appear to share that view.</p>
]]></description><pubDate>Sat, 25 Jul 2026 09:33:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=49046052</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=49046052</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49046052</guid></item><item><title><![CDATA[New comment by gnfargbl in "Nobody knows what a used GPU cluster is worth"]]></title><description><![CDATA[
<p><i>> The job of an operations team is to keep all of this in steady state. They know which racks run hot in summer, which cooling loops have been flaky since the last firmware update, which jobs to re-route when a node degrades but has not failed yet. None of that knowledge is written down. It lives in the team.</i><p>Hmmn. All of this information <i>should</i> live in the monitoring system, in which case any frontier model <i>will</i> be able to get to grips with it in short order. It feels like the author doesn't really fully understand the changes brought about by the systems they are writing about.</p>
]]></description><pubDate>Wed, 22 Jul 2026 20:16:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=49012785</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=49012785</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49012785</guid></item><item><title><![CDATA[New comment by gnfargbl in "That post never existed. Stop listening to that thing"]]></title><description><![CDATA[
<p>Because it's correct but irrelevant. It tells you about as much about the utility of LLMs as the statement "humans are just overpowered tree shrews" tells you about us.</p>
]]></description><pubDate>Mon, 20 Jul 2026 19:00:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48983340</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48983340</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48983340</guid></item><item><title><![CDATA[New comment by gnfargbl in "I tricked Claude into leaking your deepest, darkest secrets"]]></title><description><![CDATA[
<p><i>> After 15 minutes of confusion, it turned out Cloudflare had put a crazy robots.txt on my site without my consent (Cloudflare, love you guys, but this needs to stop).</i><p>That's a hard one for Cloudflare, no? They got to where they are by being (if you want to be cynical, playing the role of) the benevolent, neutral guardians of the internet, a one-stop shop that makes most of the bad nonsense go away without much effort on the part of the developer. Continuing that stance probably does mean some basic AI crawler blocking by default, unfortunately. At least they document it [1].<p>[1] <a href="https://developers.cloudflare.com/bots/additional-configurations/managed-robots-txt/" rel="nofollow">https://developers.cloudflare.com/bots/additional-configurat...</a></p>
]]></description><pubDate>Wed, 15 Jul 2026 08:22:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=48917781</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48917781</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48917781</guid></item><item><title><![CDATA[New comment by gnfargbl in "Show HN: Beautiful QR Codes"]]></title><description><![CDATA[
<p>I don't disagree, but remember the lesson of <a href="https://news.ycombinator.com/item?id=9224">https://news.ycombinator.com/item?id=9224</a> -- historically, people have been willing to pay for convenience.</p>
]]></description><pubDate>Tue, 14 Jul 2026 11:39:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48905170</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48905170</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48905170</guid></item><item><title><![CDATA[New comment by gnfargbl in "When AI Costs More Than the Engineer"]]></title><description><![CDATA[
<p>To me it seems like a first-year physics scaling laws problem. To get linear improvements in capability, you appear to need need exponential (or at least superlinear) increases in model size. We have no technical nor business solution for that kind of scaling, so the long-term outcome is obvious.</p>
]]></description><pubDate>Mon, 06 Jul 2026 12:15:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=48803575</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48803575</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48803575</guid></item><item><title><![CDATA[New comment by gnfargbl in "When AI Costs More Than the Engineer"]]></title><description><![CDATA[
<p>You're not using them wrong at all. Part of the reason LLMs are good at writing code is that they're good at understanding code. You're just not using the full menu of capabilities -- which is totally fine.</p>
]]></description><pubDate>Mon, 06 Jul 2026 12:09:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48803541</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48803541</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48803541</guid></item><item><title><![CDATA[New comment by gnfargbl in "When AI Costs More Than the Engineer"]]></title><description><![CDATA[
<p>You're looking at the status quo and ignoring the trajectory. The best current open models are about as good as closed models from ~1.5 generations ago. The rate of improvement of all models is converging to zero. It follows that in a few generations, open models inferencing will be about as good as closed model inferencing.<p>The problem is going to become that there's no incentive for anyone to run the stupidly-expensive training phase. May God have mercy on the stock market.</p>
]]></description><pubDate>Mon, 06 Jul 2026 09:01:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=48802277</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48802277</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48802277</guid></item><item><title><![CDATA[New comment by gnfargbl in "When AI Costs More Than the Engineer"]]></title><description><![CDATA[
<p>Working regularly with AI is like managing a small team of unbelievably knowledgeable, very smart, and occasionally crashingly naïve junior developers. Because they're so knowledgeable and smart, they can get a lot done very quickly. Because they make a proportion of howling errors, you have to keep a close eye on them -- or carefully train another agent to do it for you, in which case you now have to keep a close eye on that agent as well.<p>So, overall, you get more done that without AI, at the cost of spending almost all of your time writing specs and doing code review and almost none of it writing code.<p>Do you get 3.3x the work done? Probably not. Do you get 2x the work done? I think maybe, if you can hack the dynamics of the new job as a manager of eager robots. For me the jury's still out on the second point.</p>
]]></description><pubDate>Mon, 06 Jul 2026 08:26:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48802058</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48802058</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48802058</guid></item><item><title><![CDATA[New comment by gnfargbl in "EV Batteries Are Defying Expectations After Miles"]]></title><description><![CDATA[
<p>That article says calendar ageing was the dominant ageing mechanism for batteries in their test vehicle, because said vehicle spent 96% of its life stationary. Unless I'm missing it, the article doesn't put a number figure on the rate of calendar ageing.<p>Real-world observations suggest batteries are likely to be serviceable for around 20 years, which is around the same lifetime of an average ICE car. Users who can tolerate a much reduced range (which is most of us) can likely extend this even further.</p>
]]></description><pubDate>Sun, 05 Jul 2026 09:12:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48792561</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48792561</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48792561</guid></item><item><title><![CDATA[New comment by gnfargbl in "Cooling in Space"]]></title><description><![CDATA[
<p>I think we can't rule out the explanation that all the ideas of space data centers could have been connected solely to a desire to pump SpaceX's IPO.</p>
]]></description><pubDate>Sun, 14 Jun 2026 11:14:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48526150</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48526150</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48526150</guid></item><item><title><![CDATA[New comment by gnfargbl in "Cooling in Space"]]></title><description><![CDATA[
<p><a href="https://en.wikipedia.org/wiki/A_Modest_Proposal" rel="nofollow">https://en.wikipedia.org/wiki/A_Modest_Proposal</a></p>
]]></description><pubDate>Sun, 14 Jun 2026 11:08:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48526118</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48526118</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48526118</guid></item><item><title><![CDATA[New comment by gnfargbl in "Meta enables ADB on deprecated Portal devices [video]"]]></title><description><![CDATA[
<p>If the leadership of a company aren't the right people to make decisions about what that company does, who is?<p>Are you advocating for legislation? How would that work?</p>
]]></description><pubDate>Fri, 05 Jun 2026 07:06:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48409031</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48409031</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48409031</guid></item><item><title><![CDATA[New comment by gnfargbl in "Goodbye Visa and Mastercard: 130M Europeans switching to sovereign payment"]]></title><description><![CDATA[
<p>Ah yes, Pierre will surely have no issues paying for his <i>baguette et croissant</i> by filling in the boulangerie's IBAN on his mobile phone and waiting 15 minutes for them to check receipt.</p>
]]></description><pubDate>Wed, 20 May 2026 13:42:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48207642</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48207642</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48207642</guid></item><item><title><![CDATA[New comment by gnfargbl in "BYD overtakes Tesla and Kia as the best-selling EV brand in key overseas markets"]]></title><description><![CDATA[
<p>Is BYD beating Kia here in the UK? It's hard to tell from the SMMT figures [1] but it looks to me as if Kia sold just under twice as many vehicles as BYD. Given that so much of Kia's lineup is now BEV, I'm not sure who is winning.<p>Tesla <i>is</i> doing poorly here. That's almost entirely down to Musk's public image, not because BYD make better cars.<p>[1] <a href="https://www.smmt.co.uk/vehicle-data/car-registrations/" rel="nofollow">https://www.smmt.co.uk/vehicle-data/car-registrations/</a></p>
]]></description><pubDate>Wed, 06 May 2026 19:16:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48040411</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=48040411</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48040411</guid></item><item><title><![CDATA[New comment by gnfargbl in "Spain's parliament will act against massive IP blockages by LaLiga"]]></title><description><![CDATA[
<p>That statement from La Liga is nothing short of embarrassing. Raving about child pornography, in a simple copyright infringement case? And the repeated focus on "IPs" is incredibly disingenuous; Cloudflare's multiplexing of half the internet onto a small number of IP addresses is not exactly a secret in the tech community.<p>Why are Spain's courts allowing this injunction to stand? It's clearly being used to bring the court system itself into disrepute at this point.</p>
]]></description><pubDate>Thu, 30 Apr 2026 17:43:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=47965857</link><dc:creator>gnfargbl</dc:creator><comments>https://news.ycombinator.com/item?id=47965857</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47965857</guid></item></channel></rss>