<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: jimrandomh</title><link>https://news.ycombinator.com/user?id=jimrandomh</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 22 Aug 2026 03:18:11 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=jimrandomh" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by jimrandomh in "Radiation damage to Hubble has been 4.3 years out of phase with the Solar cycle"]]></title><description><![CDATA[
<p>Is the relevant radiation solar radiation, or is there damage from radiation coming from the direction the optics are pointed? If it's the latter, then maybe the sun's emissions interact with inbound particles from sources outside the solar system? (I don't have sufficient background or time to check whether the paper already rules this out.)</p>
]]></description><pubDate>Fri, 21 Aug 2026 17:24:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=49391259</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=49391259</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49391259</guid></item><item><title><![CDATA[New comment by jimrandomh in "Pacing model development in an era of cyber-critical capabilities"]]></title><description><![CDATA[
<p>You can check, rather than make up a story about what you think the prompt was! Primary sources have written and said quite a lot about this! You are an unsandboxed human who has full internet access!</p>
]]></description><pubDate>Thu, 20 Aug 2026 19:43:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=49379211</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=49379211</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49379211</guid></item><item><title><![CDATA[New comment by jimrandomh in "Pacing model development in an era of cyber-critical capabilities"]]></title><description><![CDATA[
<p>The victim, Huggingface, told us. Or rather, they told the police first, setting up a situation where it was no longer possible for OpenAI to sweep it under the rug.<p>Skepticism can be healthy, but you've got to follow up and actually check things. If you're skeptical unconditionally and don't check, you get tricked into being as skeptical of scandals as you should be of sales pitches.</p>
]]></description><pubDate>Thu, 20 Aug 2026 01:35:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=49369447</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=49369447</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49369447</guid></item><item><title><![CDATA[New comment by jimrandomh in "Firefox is now the last major browser that still supports uBlock Origin"]]></title><description><![CDATA[
<p>...Huh. I just rechecked, and indeed it was. I may have been remembering a limitation that was present temporarily when the MV3 switchover happened.</p>
]]></description><pubDate>Sat, 15 Aug 2026 23:33:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=49315297</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=49315297</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49315297</guid></item><item><title><![CDATA[New comment by jimrandomh in "Firefox is now the last major browser that still supports uBlock Origin"]]></title><description><![CDATA[
<p>I use Firefox with (non-lite) uBlock Origin, and occasionally fire up Chrome (with uBO Lite) for testing. The main issue that I run into is that uBO lite filters can't vary per-domain, so in order to rule out an ad-blocking-false-positive on something I'm developing, I have to turn it off for _all_ sites, not just localhost. (Actual false positives are rare, but needing to check is not so rare.)</p>
]]></description><pubDate>Sat, 15 Aug 2026 00:01:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=49306087</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=49306087</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49306087</guid></item><item><title><![CDATA[New comment by jimrandomh in "Apple proposes to take a 15% cut of purchases made outside the App Store"]]></title><description><![CDATA[
<p>Do iOS users realize how much they're paying Apple? I feel like if, every time they bought something, users got a receipt with a line item showing that 30% of the money was going to Apple and not to the company they thought they were buying from, a lot of them would jump ship to Android.</p>
]]></description><pubDate>Fri, 14 Aug 2026 21:58:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=49305106</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=49305106</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49305106</guid></item><item><title><![CDATA[New comment by jimrandomh in "Taxpayers Funded a $533M Artillery Plant That Made Nothing"]]></title><description><![CDATA[
<p>This article makes no mention of Russian sabotage, but the Russian military has been caught sabotaging similar munitions-manufacturing facilities in Europe. Incompetence might be sufficient to explain the failure, but it also seems reasonably likely that there was an undetected sabotage operation or two mixed in to compound the problems.</p>
]]></description><pubDate>Fri, 14 Aug 2026 21:21:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49304758</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=49304758</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49304758</guid></item><item><title><![CDATA[New comment by jimrandomh in "uBlock Origin is giving up the fight to keep ads off Facebook"]]></title><description><![CDATA[
<p>Eventually, this arms race ends with a computer vision model that looks at the screen, classifies visual elements as ads, and draws a rectangle over anything that looks like an ad.<p>I am significantly less tolerant of ads than average people seem to be. (I think average people are making a horrible mistake about this, and are badly cognitively damaged by ads in ways they don't realize). If my choices are to look at ads or leave Facebook, I'll leave. But there are conversations people have there that I'd rather not lose access to, so... I guess I'd have to partially stick around and campaign for others to leave as well?</p>
]]></description><pubDate>Wed, 12 Aug 2026 20:18:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=49278006</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=49278006</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49278006</guid></item><item><title><![CDATA[New comment by jimrandomh in "Android may soon restrict on-device ADB"]]></title><description><![CDATA[
<p>As far as I can tell, this is a big overreaction to a misunderstanding.<p>I'm a developer with remote adb enabled, using it in the normal intended way (to install new builds of an Android project I'm developing, retrieve log files related to it, etc). Currently, I access this via VPN (tailscale), but it's exposed to connections (and any pre-auth security vulnerability risks) on any random public wifi network I connect to. Adding the ability to restrict this to just tailscale will be an improvement, for me.<p>The proposal at the top of the thread is that you specify which interface you want it to bind to, when you set up remote adb, rather than binding to every interface. Nothing in that proposal suggests that "localhost" would be rejected as a choice of interface. One person suggested binding only to "wlan0", but that was a short throwaway comment that is obviously wrong (wlan0 is less-trusted than VPNs) and obviously not what they're going to do.</p>
]]></description><pubDate>Sat, 25 Jul 2026 20:55:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49051467</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=49051467</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49051467</guid></item><item><title><![CDATA[New comment by jimrandomh in "I Tried Building a Real App with AI. It Took a Year"]]></title><description><![CDATA[
<p>The first thing to check for, in accounts like this, is "which AI model"? There is a subset of people who somehow don't realize how important that decision is, and don't mention or don't foreground which AI model they were using. This sort of person invariably gets much worse results out of AI, because they turn out to be using a shit-tier low-cost model instead of something that's actually good at what they're using it for.</p>
]]></description><pubDate>Fri, 24 Jul 2026 17:46:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=49039235</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=49039235</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49039235</guid></item><item><title><![CDATA[New comment by jimrandomh in "OpenAI and Hugging Face address security incident during model evaluation"]]></title><description><![CDATA[
<p>HuggingFace reported to law enforcement before they found out that OpenAI were the ones responsible. <a href="https://huggingface.co/blog/security-incident-july-2026" rel="nofollow">https://huggingface.co/blog/security-incident-july-2026</a></p>
]]></description><pubDate>Wed, 22 Jul 2026 05:20:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=49002178</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=49002178</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49002178</guid></item><item><title><![CDATA[New comment by jimrandomh in "OpenAI and Hugging Face address security incident during model evaluation"]]></title><description><![CDATA[
<p>As marketing stunts go, this is about on par with a food franchise announcing a safety recall or a chemical company announcing a spill. The AI actions described would constitute a felony if a human did them, and police are involved.</p>
]]></description><pubDate>Wed, 22 Jul 2026 04:36:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=49001947</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=49001947</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49001947</guid></item><item><title><![CDATA[New comment by jimrandomh in "X permanently banned my 15-year-old account for sharing my own open-source lib"]]></title><description><![CDATA[
<p>If that's all you'd posted recently, the problem is not likely to be the content you posted. The most likely thing that happened is that you shared an IP address (eg a VPN exit node, or a device with malware on your wifi network) with someone who was banned for good reasons, and got caught in the crossfire.</p>
]]></description><pubDate>Fri, 17 Jul 2026 01:30:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48942411</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=48942411</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48942411</guid></item><item><title><![CDATA[New comment by jimrandomh in "98% isn't much"]]></title><description><![CDATA[
<p>If you think a browser feature that's been standard since 2023 is only supported by 70% of your visitors, you're wrong. The 30% of "users" that don't support it aren't visitors, they're bots pretending to be browsers. Bots update their user-agent strings less often than users update their browsers. My experience maintaining firewall rules is that "outdated version of an evergreen browser" is a pretty reliable bot signal: those UAs correlate strongly with all of the other bot indicators (inhumanly high request rates, datacenter IPs, loading pages without loading the page's associated resources, etc).</p>
]]></description><pubDate>Tue, 07 Jul 2026 21:41:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48824274</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=48824274</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48824274</guid></item><item><title><![CDATA[New comment by jimrandomh in "Claude's AskUserQuestion: "No response after 60s – continued without an answer""]]></title><description><![CDATA[
<p>I've never seen this beore today; it happened today and was quite clearly incorrect behavior. I prompted it to research considerations for a significant code architecture decision. It asked a pretty difficult question about which direction to take, something that would take way more than 60s to answer properly. While I was thinking about it, it timed out.<p>Some Github issues claim that adding<p><pre><code>    "env": { "CLAUDE_AFK_TIMEOUT_MS": "86400000" }
</code></pre>
to ~/.claude/settings.json fixes it. This is plausible, but not documented anywhere (the source claims it was found by reverse engineering, and might break /goal).</p>
]]></description><pubDate>Fri, 03 Jul 2026 01:15:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48769466</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=48769466</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48769466</guid></item><item><title><![CDATA[New comment by jimrandomh in "Fable 5 will default to Opus 4.8 for coding tasks"]]></title><description><![CDATA[
<p>This is a misinterpretation. Fable 5's acceptable use policy has false positives during some coding tasks, and that's what they were talking about. But I've been using it for web dev tasks since it relaunched today, and it's worked fine without fallback.<p>(On a firmware-customization project involving a ghidra MCP, it triggered and switched to Opus; that was sort of expected.)</p>
]]></description><pubDate>Wed, 01 Jul 2026 22:25:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48753952</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=48753952</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48753952</guid></item><item><title><![CDATA[New comment by jimrandomh in "Cloudflare CEO is lying to you about the bot traffic jump"]]></title><description><![CDATA[
<p>Have you checked your IP address's reputation with a service such as ipqualityscore.com? If cloudflare thinks your traffic is bot traffic, it's likely that there is bot traffic you don't know about coming from your IP, either from a compromised device on your network or a sketchy VPN product.</p>
]]></description><pubDate>Fri, 05 Jun 2026 19:06:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=48416826</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=48416826</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48416826</guid></item><item><title><![CDATA[New comment by jimrandomh in "Cloudflare CEO is lying to you about the bot traffic jump"]]></title><description><![CDATA[
<p>I deal with scrapers that sometimes border on DDoSes for LessWrong. The amount of bot traffic varies greatly between sites; if you have more URLs you get more bot traffic (regardless of whether those URLs represent a deep content catalog, or useless URL parameter permutations). It's bad for LW because of the content-catalog depth.<p>It's easy to drastically underestimate the amount of bot traffic, because bots make efforts (of varying sophistication) to look human enough to evade blocking. That includes using fake user-agent strings corresponding to real browsers (often but not always with implausibly old version numbers), proxying through residential IPs, and sometimes using full headless browsers. In my own data, traffic from badly behaved browser-impersonation bots exceeds traffic from named scrapers like GPTBot by something like 10x.<p>The measured percentage of bot traffic is higher for HTML than for other content types because many bots will load an HTML page, and then not load the JS/CSS/image/etc resources it references. But these are the least-sophisticated and most-detectable bots.</p>
]]></description><pubDate>Fri, 05 Jun 2026 19:05:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48416806</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=48416806</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48416806</guid></item><item><title><![CDATA[New comment by jimrandomh in "macOS needs its grid back"]]></title><description><![CDATA[
<p>The full-screen mode handling might be a clue about what went wrong: if you swipe up from a space that contains a full screen app, it has an animation where the app goes into a slot in the preview strip, but that animation doesn't make sense visually for a non-full-screen space. So, perhaps someone was implementing that animation, didn't want to implement an alternate animation for the non-fullscreen case, and decided to minimize the preview strip instead? And because this was after Steve Jobs had died, there was no one left in charge of UX to explain why that was a bad idea?</p>
]]></description><pubDate>Tue, 02 Jun 2026 04:08:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=48365931</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=48365931</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48365931</guid></item><item><title><![CDATA[New comment by jimrandomh in "macOS needs its grid back"]]></title><description><![CDATA[
<p>Prior to MacOS 10.11, Mission Control was good: you would swipe up with four fingers and it would show you a preview of all of your spaces. Then in 10.11, for no discernable reason, they changed it to suck: rather than showing you a preview, the bar just says "Desktop 1", "Desktop 2", etc until you mouse over it; the practical effect is that using spaces is disorienting and requires memorization.<p>Some third-party software pretends to restore this functionality, but they do it by repositioning the mouse to simulate a hover, which introduces a delay and doesn't integrate correctly with the animation. Someone wrote a patch that works by disabling SIP and injecting code (<a href="https://github.com/briankendall/forceFullDesktopBar" rel="nofollow">https://github.com/briankendall/forceFullDesktopBar</a>), but eventually stopped maintaining it.<p>A decade later, I doubt anyone at Apple remembers that this bit of user interface used to be good.</p>
]]></description><pubDate>Tue, 02 Jun 2026 02:24:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=48365202</link><dc:creator>jimrandomh</dc:creator><comments>https://news.ycombinator.com/item?id=48365202</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48365202</guid></item></channel></rss>