<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: kevincox</title><link>https://news.ycombinator.com/user?id=kevincox</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 01 Oct 2026 23:59:42 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=kevincox" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by kevincox in "Gitea 28.0"]]></title><description><![CDATA[
<p>Of course I wouldn't recommend taking the conclusion. But it is a valuable view of some differences that the Forgejo developers perceive as valuable.</p>
]]></description><pubDate>Wed, 30 Sep 2026 23:14:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=49915701</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49915701</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49915701</guid></item><item><title><![CDATA[New comment by kevincox in "The new Firefox design is here"]]></title><description><![CDATA[
<p>Seriously, are you proud of the new look? SHOW IT TO ME. Even the video was mostly themed mock-ups that didn't show what the actual design looks like. Just post a screenshot of the whole browser.</p>
]]></description><pubDate>Tue, 29 Sep 2026 14:00:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=49893422</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49893422</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49893422</guid></item><item><title><![CDATA[New comment by kevincox in "Dutch governments builds alternative for Microsoft based on NixOS"]]></title><description><![CDATA[
<p>llama.cpp has a flake in-repo that I often use for trying out different branches and patches. I also have yet to have an issue just replacing the src and build number attribute in the nixpkgs build (in one cases I wanted to add an additional CMake flag but that was also easy).<p>IMHO this is way easier than without Nix in many cases as figuring out the upstream build process and getting it running can often be quite the chore. With Nix it is all set up for you.</p>
]]></description><pubDate>Fri, 25 Sep 2026 12:49:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=49843919</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49843919</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49843919</guid></item><item><title><![CDATA[New comment by kevincox in "We just shipped support for the ugliest part of HTTP: Vary"]]></title><description><![CDATA[
<p>One major issue with Vary is that it makes cache coalescing very complicated. This is because you can't know whether two requests will share a response until you get that response. So for subsequent requests you need to decide if you should block it hoping that the response will satisfy it or if you should send it through pessimistically, possibly triggering a thundering herd effect on every cache rotation.<p>I'm not sure if it is possible to solve this nicely in a generic way, but it does make it a bit ugly.</p>
]]></description><pubDate>Thu, 24 Sep 2026 13:57:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=49830677</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49830677</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49830677</guid></item><item><title><![CDATA[New comment by kevincox in "Linux support is coming to Snapdragon X2 Series"]]></title><description><![CDATA[
<p>Thanks. This link has more detail about Linux support. I submitted it separately for discussion.<p><a href="https://news.ycombinator.com/item?id=49824189">https://news.ycombinator.com/item?id=49824189</a></p>
]]></description><pubDate>Wed, 23 Sep 2026 23:38:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=49824201</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49824201</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49824201</guid></item><item><title><![CDATA[Linux on Snapdragon X2 Series Early Developer Preview]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.qualcomm.com/developer/blog/2026/09/announcing-linux-on-snapdragon-x2-series-early-developer-preview">https://www.qualcomm.com/developer/blog/2026/09/announcing-linux-on-snapdragon-x2-series-early-developer-preview</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49824189">https://news.ycombinator.com/item?id=49824189</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 23 Sep 2026 23:37:30 +0000</pubDate><link>https://www.qualcomm.com/developer/blog/2026/09/announcing-linux-on-snapdragon-x2-series-early-developer-preview</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49824189</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49824189</guid></item><item><title><![CDATA[New comment by kevincox in "OpenAI bots knew about the RubyGems caching vulnerability"]]></title><description><![CDATA[
<p>I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.</p>
]]></description><pubDate>Mon, 14 Sep 2026 13:20:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=49696400</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49696400</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49696400</guid></item><item><title><![CDATA[New comment by kevincox in "Make your first edit to OpenStreetMap"]]></title><description><![CDATA[
<p>Documenting public water sources is an incredible public good. I thank you for your efforts.</p>
]]></description><pubDate>Sun, 13 Sep 2026 14:50:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=49684630</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49684630</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49684630</guid></item><item><title><![CDATA[New comment by kevincox in "Rust is tier-1 language at Microsoft"]]></title><description><![CDATA[
<p>How does Rust help with 2 at all? IIUC the main requirements were not memory or performance related but TPM and instruction set minimums.</p>
]]></description><pubDate>Thu, 10 Sep 2026 21:01:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=49650125</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49650125</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49650125</guid></item><item><title><![CDATA[New comment by kevincox in "What do Visa and Mastercard do? An intro to card networks"]]></title><description><![CDATA[
<p>No, but my credit card has no battery, requires no cell service, is waterprrof and quite durable.<p>I see the advantages of the Chinese system but I really found myself missing my card.<p>- While payer-offline payments were possible most merchants didn't want to (and some seemed unable to) so payments in places with bad cell service were painful.<p>- It was a lot more steps to open the app and enter scanning mode or display your code than to just tap a card or phone.<p>- It was always unclear if you were scanning or being scanned, leading to friction for every payment (generally larger brands scan you and you scan for smaller merchants).<p>Honestly for in-person card payments are just nicer.<p>For online WeChat was better, but no different than Apple Pay or Google Pay except for course that it is standardized by the government.</p>
]]></description><pubDate>Thu, 10 Sep 2026 11:09:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=49641691</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49641691</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49641691</guid></item><item><title><![CDATA[New comment by kevincox in "Jellyfin 12.0"]]></title><description><![CDATA[
<p>This is almost certainly a you problem. Tons of people play remuxes with Jellyfin.<p>I would check that your client supports the requisite codecs, and has a sufficient network connection. Or alternatively check that your server has enough horsepower (GPU or CPU) to transcode.</p>
]]></description><pubDate>Tue, 08 Sep 2026 17:11:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49613235</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49613235</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49613235</guid></item><item><title><![CDATA[New comment by kevincox in "Delidded Intel I9-14900KS CT Scan"]]></title><description><![CDATA[
<p>Probably because the account has only ever submitted its own content.<p><a href="https://news.ycombinator.com/submitted?id=LabsLucas">https://news.ycombinator.com/submitted?id=LabsLucas</a><p>>  Please don't use HN primarily for promotion. It's ok to post your own stuff part of the time, but the primary use of the site should be for curiosity.<p>> <a href="https://news.ycombinator.com/newsguidelines.html">https://news.ycombinator.com/newsguidelines.html</a></p>
]]></description><pubDate>Sun, 06 Sep 2026 19:10:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49589755</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49589755</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49589755</guid></item><item><title><![CDATA[New comment by kevincox in "Can I opt out of my input or output data being used for training?"]]></title><description><![CDATA[
<p>Yes, I found this comment very hard to understand until I realised they were talking about it being opt-out with no setting to change it. (At first I thought it was opt-in by default, and the "by default" implies that there is a setting to change the opt-in/opt-out setting)</p>
]]></description><pubDate>Thu, 03 Sep 2026 13:45:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49549853</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49549853</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49549853</guid></item><item><title><![CDATA[New comment by kevincox in "Play Store blocks AuroraStore, hurting GrapheneOS users"]]></title><description><![CDATA[
<p>This also has nothing to do with GrapheneOS except for some user overlap.</p>
]]></description><pubDate>Tue, 01 Sep 2026 18:20:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=49525816</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49525816</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49525816</guid></item><item><title><![CDATA[New comment by kevincox in "Saving 100 terabytes of memory by optimizing 1.1.1.1's DNS cache"]]></title><description><![CDATA[
<p>It sounds like you are just writing your own allocator? That sounds great, but why is it going to be better than jemalloc?<p>There are many reasons a specialized allocator can be better, but just saying "write your own" doesn't really add much value to the discussion.</p>
]]></description><pubDate>Fri, 28 Aug 2026 18:12:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49482372</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49482372</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49482372</guid></item><item><title><![CDATA[New comment by kevincox in "Three ways to smuggle SQLite into Nix"]]></title><description><![CDATA[
<p>It seems that you could just compile the data into the WASM blob. Then use a more optimized query engine than sqlite. This should be very fast to compile (most of the WASM is just a byte buffer, the code is just a few binary searches and some result encoding). The downside is that you need to recompile to update the repo, but I don't think that should be particularly expensive.</p>
]]></description><pubDate>Fri, 21 Aug 2026 18:50:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=49392359</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49392359</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49392359</guid></item><item><title><![CDATA[New comment by kevincox in "The August 17 outage"]]></title><description><![CDATA[
<p>Thundering herd is different. Thundering herd is when a lot of clients trigger requests at the same time. Common situations being a specific time, some other event just occurred or synchronize on other parts of your infrastructure (such as readers queuing behind a R/W lock that then get unblocked at the same time to continue to make a bunch of requests at the same time.<p>Request amplification via retries is a different problem that causes large amounts of traffic (but it is generally more steady than spiky)</p>
]]></description><pubDate>Fri, 21 Aug 2026 11:23:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=49386489</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49386489</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49386489</guid></item><item><title><![CDATA[New comment by kevincox in "Malicious Rust crate Arrayref runs a build-time payload"]]></title><description><![CDATA[
<p>Sandboxing the process only works well when the malware requires more capabilities than the software itself.<p>So if your software needs to make HTTP requests and read the filesystem then the malware will be able to make HTTP requests and read the filesystem, which is enough for a ton of malware. Sure, maybe you can limit the directories it can access a bit and possibly some sort of network filtering, but it isn't a silver bullet.<p>Capability security in-language would make a huge difference, because the more granular you "sandbox" the less likely it is that the compromised component has the access it wants. For example if the HTTP client library is compromised maybe it can't access the filesystem so can't steal your cookies. Or maybe like in this case no permissions were needed at all and despite the process having enough capabilities for malware this malware can at worst return bad values and try to chain this to an exploit which is far more difficult than just running it itself.</p>
]]></description><pubDate>Thu, 20 Aug 2026 15:35:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=49376128</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49376128</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49376128</guid></item><item><title><![CDATA[New comment by kevincox in "Win-V combo from Windows on Ubuntu"]]></title><description><![CDATA[
<p>It is if you use full-disk-encryption which is highly recommended.</p>
]]></description><pubDate>Wed, 19 Aug 2026 16:00:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=49363324</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49363324</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49363324</guid></item><item><title><![CDATA[New comment by kevincox in "Show HN: Declarative-forms – await an object the way prompt() awaits a string"]]></title><description><![CDATA[
<p>I really like this approach. It is very natural for modal dialogs to be things that you await. I have used it in various projects in the past.<p>The main downside is if you need to affect the dialog from "outside". For example data that refreshes and needs to update the form (although in most cases a changing form is an anti-pattern anyways). But also any form of dynamically updating data (a clock) or lazy loading (maybe for a dropdown that depends on others) you are going to want a full UI library rather than a one-shot declarative form.<p>When I used this I had a separate call to create the dialog and await the result. This way there is a handle you can use to update the data if you need to. But even then if you are using React it probably doesn't integrate as cleanly as a "regular" component would.<p>But still, I think in most cases this is what you need and the easiest way to get it. I wouldn't take a more complicated approach until you need to.</p>
]]></description><pubDate>Tue, 18 Aug 2026 14:20:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=49346023</link><dc:creator>kevincox</dc:creator><comments>https://news.ycombinator.com/item?id=49346023</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49346023</guid></item></channel></rss>