<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: illithid0</title><link>https://news.ycombinator.com/user?id=illithid0</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 13 Jun 2026 15:47:56 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=illithid0" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by illithid0 in "Uber’s COO says it’s getting harder to justify money spent on tokenmaxxing"]]></title><description><![CDATA[
<p>>"He said that, based on talks with Uber's senior engineering leaders, he realized higher token usage did not translate into a proportional increase in useful consumer features."<p>Goodhart's law strikes again at someone with enough power to be both ignorant of it and make others suffer their ignorance. You cannot simply measure productivity by tokens spent just like you can't measure it by hours spent in a chair at a desk.</p>
]]></description><pubDate>Mon, 25 May 2026 17:01:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48269053</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=48269053</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48269053</guid></item><item><title><![CDATA[New comment by illithid0 in "Leave Me Behind"]]></title><description><![CDATA[
<p>I would like to think they'll be the only ones punished, should punishment come. And as a disclaimer for what I'm about to say, I'm neither a Wall Street banker nor an AI company executive, so I don't want to accidentally make a specious connection between the two, but...<p>The 2008 housing crisis affected everyone. Bubbles that get too big pop across the population, whether they're complicit or not. As a little guy in a big world, with no expertise to truly know if there's a meaningful difference, I have a bit of anxiety about it all. I just don't want to catch collateral.</p>
]]></description><pubDate>Mon, 25 May 2026 14:15:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48267127</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=48267127</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48267127</guid></item><item><title><![CDATA[New comment by illithid0 in "Leave Me Behind"]]></title><description><![CDATA[
<p>I'm in a position right now where I'm trying to decide if staying in my own field of information security is worth it to me. I have an entire project plan built out for using local models to do some crazy augmentation of my own skill set, e.g. malware development pipelines and vulnerability research.<p>My biggest problem as an independent contractor is marketing and notoriety. Security has been a race to the bottom for over a decade now, but it's gotten exponentially worse. LLMs can't just do my job, but there are enough people with checkbooks who believe that it can and enough companies out there with an incentive to confirm that belief that it's getting harder for me to find work organically.</p>
]]></description><pubDate>Mon, 25 May 2026 13:58:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48266928</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=48266928</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48266928</guid></item><item><title><![CDATA[New comment by illithid0 in "Ask HN: What has HN given you?"]]></title><description><![CDATA[
<p>A place to see content that is actually relevant to my field with as little algorithmic intervention as possible. There is still a presence within the readership here that verges on philosophical despite being grounded in the technological, and that is why I keep coming back.</p>
]]></description><pubDate>Mon, 25 May 2026 13:52:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48266855</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=48266855</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48266855</guid></item><item><title><![CDATA[New comment by illithid0 in "Ask HN: How will you manage your digital assets when you die?"]]></title><description><![CDATA[
<p>It starts with relying less and less (as is possible) on outsourced digital assets such as photo storage, social media accounts, etc. while I'm still alive.<p>After that, I have strict requirements (and instructions) in my estate for accessing and deleting the few accounts I still need at that time. I'm fortunate enough to have started using a password manager as early as 15 years ago, and used it diligently, so redundant access is as easy as possible.</p>
]]></description><pubDate>Mon, 25 May 2026 13:50:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=48266828</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=48266828</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48266828</guid></item><item><title><![CDATA[New comment by illithid0 in "Leave Me Behind"]]></title><description><![CDATA[
<p>This is some anecdata, but I'll share it nonetheless as I have a pretty wide network of software and security engineer friends from which I've heard the following.<p>Almost no one I know wants agent usage to be a zero-sum activity. There are a few oddballs who obviously only got into software for the money, so any means to that end is acceptable. That does not stop those with say-so over things like employment (and, if you're in the USA, the associated healthcare), from treating it as a zero-sum activity.<p>When engineers are being told to maximize token usage, are constantly being brought into meetings where they're expected to reveal their latest and greatest use of LLMs, and not using enough tokens in your role is seen as a negative, then the pressure starts to creep in. Yes, I know this is silly to most people who read this site, and I agree. It's bonkers. But there is certainly something to the idea of "AI psychosis" in upper management that is making agent use zero-sum company-wide.</p>
]]></description><pubDate>Mon, 25 May 2026 13:40:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48266708</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=48266708</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48266708</guid></item><item><title><![CDATA[New comment by illithid0 in "The world just lived through the 11 hottest years on record"]]></title><description><![CDATA[
<p>I often wonder if whatever it is we currently experience as consciousness or self-awareness was a major contributor to species-wide problems such as climate change.<p>Having come across Zapffe's "existential elk" theory in the last year, it's hard to not see consciousness as a design flaw rather than an upgrade that sits at the root of the things driving climate change, e.g. hyperconsumerism, rampant use of non-renewable materials, and all the other things we choose into for personal satisfaction despite the negative impacts to the whole.<p>Might we have been better off without consciousness, or at least not as detrimental to the planet? I don't know.</p>
]]></description><pubDate>Mon, 23 Mar 2026 19:45:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=47494219</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=47494219</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47494219</guid></item><item><title><![CDATA[New comment by illithid0 in "Blacksky AppView"]]></title><description><![CDATA[
<p>Ah, okay, thank you. I was expecting it to work more like Mastodon in the sense that I can go to a different instance and interact with accounts seamlessly without having to bring them up in my own instance, but this is fine, too.</p>
]]></description><pubDate>Mon, 09 Mar 2026 15:53:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=47310701</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=47310701</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47310701</guid></item><item><title><![CDATA[New comment by illithid0 in "Blacksky AppView"]]></title><description><![CDATA[
<p>I was trying to interact with the account mentioned in the grekpak blog post here: <a href="https://blacksky.community/profile/did:plc:w4xbfzo7kqfes5zb7r6qv3rw" rel="nofollow">https://blacksky.community/profile/did:plc:w4xbfzo7kqfes5zb7...</a><p>I can't comment, follow, like, or anything like that without getting the "Sign in or create your account to join the cookout!" popup. I wasn't trying to cause problems or get downvoted, this is just the the first non-BlueSky PDS I've ever come across and was curious to see the federation work.</p>
]]></description><pubDate>Mon, 09 Mar 2026 13:58:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=47309144</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=47309144</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47309144</guid></item><item><title><![CDATA[New comment by illithid0 in "Blacksky AppView"]]></title><description><![CDATA[
<p>I might be missing something about the protocol, but when logged into BlueSky, I can't interact with BlackSky accounts at all. I specifically have to have an account there to even follow a BlackSky account.<p>I'm not as familiar with ATProto as ActivityPub, but following someone from another Mastodon instance, for example, is seamless as long as I'm logged in to the account I have on my home instance.</p>
]]></description><pubDate>Mon, 09 Mar 2026 01:08:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=47303593</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=47303593</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47303593</guid></item><item><title><![CDATA[New comment by illithid0 in "Blacksky AppView"]]></title><description><![CDATA[
<p>That post isn't very clear about what specifically happened on BlueSky that made the author move, and I can't see the full thread he links without having a BlackSky account.<p>What moderation decisions were made regarding this "Link" user that were suspect, using the post author's word?</p>
]]></description><pubDate>Sun, 08 Mar 2026 23:50:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=47302963</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=47302963</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47302963</guid></item><item><title><![CDATA[New comment by illithid0 in "Let's Get Physical"]]></title><description><![CDATA[
<p>My first assessment was honestly as anticlimactic as OP's.<p>We had to break into a particular unit of a multi-tenant office building. The client wanted us to focus on social engineering, but if we were able to do that, to move on to testing if anyone would see it as suspicious if someone was messing with doors and stuff.<p>So my partner walked up to the reception desk with a toolbox and a clipboard, claiming to be there for an off-schedule inspection of the elevator fire suppression system. Signed the guestbook with no formal verification, walked into the office area, and sat down to plug his laptop into an ethernet drop.<p>Meanwhile, after he texted me to let me know he was in, I took the stairs up to a door that led into the back of the target unit and just had to use a traveler's hook to pull door latch open. No guard plates or anything in the way.<p>Then I walked around in my business casual outfit until I found what looked like  an IT closet, waited for a time when no one was in the hall with me, and used an under-the-door tool to pop it open. All their network equipment was in there along with spare laptops and an unlocked IT admin machine on a desk.<p>:)</p>
]]></description><pubDate>Thu, 05 Mar 2026 20:31:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=47266883</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=47266883</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47266883</guid></item><item><title><![CDATA[New comment by illithid0 in "Let's Get Physical"]]></title><description><![CDATA[
<p>From one red teamer to red teamer to another, glad your first assessment went so well and you had a great time. My first physical pentest made me want to never sit in front of a terminal again.<p>People, as we like to say, are not paid enough to care. At-will employment, company-sponsored healthcare, etc. have employees so focused on their own wellbeing that protecting "the company" is the last thing on their minds, and I can't really blame them. That lady who you barged in on may very well have just been used to micromanaging jerks doing it to her all the time, so she has to seem busy.<p>Physical security, in my experience, comes down to giving people something to protect which actually benefits them to protect. All the technical controls in the building can fail and one person with enough skin in the game can kill an intrusion attempt in seconds.</p>
]]></description><pubDate>Thu, 05 Mar 2026 19:56:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=47266463</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=47266463</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47266463</guid></item><item><title><![CDATA[New comment by illithid0 in "I verified my LinkedIn identity. Here's what I handed over"]]></title><description><![CDATA[
<p>Thank you so much for sharing this. Not only is it a great post, but the site invokes such warm feelings of an internet long lost.</p>
]]></description><pubDate>Sat, 21 Feb 2026 15:27:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=47101654</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=47101654</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47101654</guid></item><item><title><![CDATA[New comment by illithid0 in "Trump's global tariffs struck down by US Supreme Court"]]></title><description><![CDATA[
<p>I'm not sure what this has to do with the Constitutionality of his tariffs or their ability to accomplish the stated goals.</p>
]]></description><pubDate>Fri, 20 Feb 2026 22:25:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=47094854</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=47094854</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47094854</guid></item><item><title><![CDATA[New comment by illithid0 in "Trump's global tariffs struck down by US Supreme Court"]]></title><description><![CDATA[
<p>The power to impose tariffs is given to Congress in the Constitution. Exceptions are allowed but in rare and specific situations. The fact that SCOTUS struck it down means the tariffs as imposed were unconstitutional.<p>You can be for tariffs all you want, I'm not here to argue their efficacy. But you absolutely cannot with any intellectual honesty still be on the fence about whether he abused his power given this ruling.<p>It is not "flip flopping policy" to break the bounds of your Constitutional power and be shut down by one of the branches meant to check you.</p>
]]></description><pubDate>Fri, 20 Feb 2026 15:38:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=47089357</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=47089357</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47089357</guid></item><item><title><![CDATA[New comment by illithid0 in "Carl Sagan's Baloney Detection Kit: Tools for Thinking Critically (2025)"]]></title><description><![CDATA[
<p>Normally I'm pretty good at extending intellectual generosity. But for them, it's at the level of voting for a candidate who supports cuts to Medicaid and then wondering why it's suddenly infinitely harder for me to get through to anyone about assistance (not even for myself, for them) following staffing cuts.<p>"This isn't what I voted for" is a common utterance. They can't help themselves, so I do my best to help, while they undercut my options to help them.</p>
]]></description><pubDate>Fri, 13 Feb 2026 18:48:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=47006220</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=47006220</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47006220</guid></item><item><title><![CDATA[New comment by illithid0 in "Carl Sagan's Baloney Detection Kit: Tools for Thinking Critically (2025)"]]></title><description><![CDATA[
<p>I don't know, man. I'm at a point where not even the tangible effects on me that the policies and decisions some members of my family endorse are enough to get them to think twice.<p>I can sit right in front of them and describe the problems I'm now dealing with and point out the exact legislative changes that caused them and it's like their brains turn off until the subject changes. More than happy to pray for me, though.</p>
]]></description><pubDate>Thu, 12 Feb 2026 19:05:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=46993449</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=46993449</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46993449</guid></item><item><title><![CDATA[New comment by illithid0 in "AT&T, Verizon blocking release of Salt Typhoon security assessment reports"]]></title><description><![CDATA[
<p>I've worked as a security consultant with one or two companies (who shall remain nameless) whose sole product was a hardware device with a black-box software stack meant to be a plug-and-play lawful intercept compliance solution. Telecoms should be able to buy it, install it, and access a web panel to do their government-mandated business.<p>In the three or four year I worked with them, they would only let me do penetration testing of their user network, and never the segments where the developers were, and never the product itself. In speaking with their security team (one guy - shocker) during compliance initiatives, it was very clear to me that the product itself was not to be touched per the <i>explicit</i> direction of senior leadership.<p>All I can say is that if the parts of their environment they <i>did</i> let us touch are any indication of the state of the rest of their assets, that device was compromised a long time ago.</p>
]]></description><pubDate>Mon, 09 Feb 2026 16:50:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=46947523</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=46947523</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46947523</guid></item><item><title><![CDATA[Kubernetes Remote Code Execution via Nodes/Proxy Get Permission]]></title><description><![CDATA[
<p>Article URL: <a href="https://grahamhelton.com/blog/nodes-proxy-rce">https://grahamhelton.com/blog/nodes-proxy-rce</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46766140">https://news.ycombinator.com/item?id=46766140</a></p>
<p>Points: 55</p>
<p># Comments: 4</p>
]]></description><pubDate>Mon, 26 Jan 2026 14:36:12 +0000</pubDate><link>https://grahamhelton.com/blog/nodes-proxy-rce</link><dc:creator>illithid0</dc:creator><comments>https://news.ycombinator.com/item?id=46766140</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46766140</guid></item></channel></rss>