<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: lq9AJ8yrfs</title><link>https://news.ycombinator.com/user?id=lq9AJ8yrfs</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 15 Jun 2026 00:03:08 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=lq9AJ8yrfs" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by lq9AJ8yrfs in "Jira Is Turing-Complete"]]></title><description><![CDATA[
<p>that's nearly a requirement for anti-bot things.  turnstile etc.</p>
]]></description><pubDate>Mon, 25 May 2026 13:55:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48266888</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=48266888</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48266888</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "Serving a website on a Raspberry Pi Zero running in RAM"]]></title><description><![CDATA[
<p>LLMs, including open ones, are really good at this it turns out. It stands to reason, there is tons of training material out there no doubt they have consumed and are ready to regurgitate.<p>Yesterday I one-shotted several interactive pages, that Qwen built out of straight HTML and Javascript.  I handed it my API (source code, not even a swagger, via an MCP that Qwen wrote for me), asked for a frontend, and it delivered.  One page at a time to keep context down, and mightve gotten lucky on the first draw but after the first one I told it to make the next ones like the first.<p>Can't say I've had that experience with backend languages & frameworks, incl writing that same API, but perhaps I'm off the beaten path with those, or perhaps there's greater breadth of things to do vs a narrower set of acceptance criteria?  IDK.<p>Here I was sweating that I'd have to research and learn a current-day frontend framework.  It felt like a magic wand using consumer-grade AI.  HTML and plain old Javascript was plenty.<p>Tangent but apropos of other contemporary threads on HN, it puts a spin on supply chain threats.  There's no NPM or anything, except perhaps whatever mysteries are baked into the model.</p>
]]></description><pubDate>Fri, 08 May 2026 17:41:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=48066363</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=48066363</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48066363</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "Scores decline again for 13-year-old students in reading and mathematics (2023)"]]></title><description><![CDATA[
<p>It happens in the private sector too.  I was involved in procurement at a megacorp for several years.<p>At one point one of my colleagues asked for assistance in getting an order of 500 iphones approved.  As "spares".<p>Fortunately the corp had a policy that phone purchases needed to have a named individual declared.<p>I declined politely to assist.<p>It was common to see certain mid level execs churning through 2x - 5x the equipment of IC's (who would never get out-of-lifecycle approvals anyeay) and some quid pro quo stuff.  As a fraction of their total comp it was modest ultimately, and for this reason my boss advised me to keep my mouth shut.</p>
]]></description><pubDate>Thu, 23 Apr 2026 13:56:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=47875813</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=47875813</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47875813</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "The dangers of California's legislation to censor 3D printing"]]></title><description><![CDATA[
<p>CNC milling is typically included in the bans being considered in various states.<p>While poetically consistent, it enlarges the crater around these bad laws if they are passed and enforced.  Basically all new manufacturing setups will need to stop and reprogram to stop and start according to fluctuating rules designed by committee, and will need to be made brittle to prevent circumvention.<p>It is a debacle.</p>
]]></description><pubDate>Tue, 14 Apr 2026 21:53:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=47771986</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=47771986</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47771986</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "My minute-by-minute response to the LiteLLM malware attack"]]></title><description><![CDATA[
<p>I don't think I've met an llm that is adversary resistant, and here are counterparties that are actively playing the field, to put it mildly.<p>The bug bounty service providers did an adequate job of filtering out junk reports.  There was a survivorship bias, some of the bogus ones that got through had an uncanny ability to twist words.</p>
]]></description><pubDate>Fri, 27 Mar 2026 12:48:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=47542077</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=47542077</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47542077</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "My minute-by-minute response to the LiteLLM malware attack"]]></title><description><![CDATA[
<p>As a sometimes peripheral and sometimes primary program manager for vulnerability disclosure, for companies you nearly can't avoid, $0.02 follows.<p>It's a signal vs noise thing.  Most of the grief is caused by bottom feeders shoveling anything they can squint at and call a vulnerability and asking for money.  Maybe once a month someone would run a free tool and blindly send snippets of the output promising the rest in exchange for payment.  Or emailing the CFO and the General Counsel after being politely reminded to come back with high quality information, and then ignored until they do.<p>Your report on the other hand was high quality. I read all the reports that came my way, and good ones were fast tracked for fixes.  I'd fix or mitigate them immediately if I had a way to do so without stopping business, and I'd go to the CISO, CTO, and the corresponding engineering manager if it mattered enough for immediate response.</p>
]]></description><pubDate>Thu, 26 Mar 2026 17:33:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47533321</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=47533321</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47533321</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "Trivy under attack again: Widespread GitHub Actions tag compromise secrets"]]></title><description><![CDATA[
<p>It doesn't help that a lot of security software is pretty niche.  It's unreasonable to expect most candidates to know it or have experience.<p>In one case I was one of exactly two people out of 500 that had used the product as a paying customer.  Neither of us was in management.<p>After a year or two the CISO drifted over and asked me to show him how to use the product, but he was more interested in soundbytes than actually using the system.<p>It became a powerpoint exercise and I collected my attaboy.</p>
]]></description><pubDate>Tue, 24 Mar 2026 12:24:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=47501623</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=47501623</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47501623</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "Trivy under attack again: Widespread GitHub Actions tag compromise secrets"]]></title><description><![CDATA[
<p>From having worked at and consulted with security software producing companies as well as security software consuming ones, I would say the security companies are worse than average at security.<p>And their security teams more cynical.<p>Sometimes they deliberately hire lower aptitude candidates to run internal security to prevent them from getting distracted by the product.<p>In other cases they are getting high on their own supply, more or less.<p>Jack Welch style management seems to take a deeper toll in this sector.</p>
]]></description><pubDate>Tue, 24 Mar 2026 12:19:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47501563</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=47501563</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47501563</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "Chicken Nuget"]]></title><description><![CDATA[
<p>It seems hard to donate a trademark application to someone.<p>Trademarks seem like a sore spot for successful OSS but probably useful for solving this problem.<p>Or perhaps a license change?  Might be tricky to do what the author means and still meet the definition of /open/.  Maybe that's ok?</p>
]]></description><pubDate>Fri, 13 Mar 2026 12:09:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=47363352</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=47363352</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47363352</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "Google closes deal to acquire Wiz"]]></title><description><![CDATA[
<p>Getting your cloud 'wiz wit' in Philadelphia would mean having melted cheese on it.</p>
]]></description><pubDate>Wed, 11 Mar 2026 23:31:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=47343990</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=47343990</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47343990</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "FreeCAD"]]></title><description><![CDATA[
<p>there are a lot of "do what I mean" type papercuts in openscad.  BOSL2 is a library that, for me at least, takes away enough of them to make a rewarding experience.  still find myself brute forcing which axis to translate or rotate things the way i want.<p>concur otherwise that openscad is parameter friendly.  the lightbulb moment for me was when i finally grasped its functional grammar and leaned into it, esp recursion instead of algebraic solutions.  that should probably be the subject of a tutorial or several.</p>
]]></description><pubDate>Sat, 21 Feb 2026 01:33:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=47096514</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=47096514</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47096514</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "FreeCAD"]]></title><description><![CDATA[
<p>i like the way prusaslicer has a conspicuous setting to enable intermediate and advanced settings so that users can start with a less intimidating setup and opt in to the bells and whistles if and when they are ready.<p>this pattern could probably benefit a lot of apps</p>
]]></description><pubDate>Sat, 21 Feb 2026 01:20:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=47096414</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=47096414</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47096414</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "IPv6 is not insecure because it lacks a NAT"]]></title><description><![CDATA[
<p>Real world CSRF attacks into hxxp://192.168.0.1 home routers and polluting DNS and DHCP settings you could argue is caused or at least facilitated by NAT, or NAT misconceptions especially.<p>Though IPv6 has a similar situation with well defined unicast and multicast addresses.<p>True story, popular browsers won't let you load a webpage via various IPv6 local address literals for this reason.  Hxxp://[ff02::] addresses won't work.<p>/ You can have your cake by "tying a knot" with yourself and port forwarding from 127.0.0.1 to the IPv6 literal. An ssh port forward will do this with aplomb.  Then load hxxp://localhost:port and it works again.<p>// Browser logic</p>
]]></description><pubDate>Wed, 21 Jan 2026 14:41:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=46706351</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=46706351</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46706351</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "IPv6 is not insecure because it lacks a NAT"]]></title><description><![CDATA[
<p>NAT causes security issues too.  Reflection attacks are much harder to stop if the endpoint and its network address are decoupled.<p>You can provoke loops and tangles of many sorts, some at the same protocol level and others going up and down.<p>My memory is fading but I vaguely recall a time when all of AOL shared something like a dozen egress addresses for certain traffic -- might have been proxies as opposed to NAT/"PAT" as we know it today.  Iow, you couldn't block one without blocking 1/12 of AOL users.<p>Stronger memories of a time when your IP address (some were nat, some were not, varied by ISP) depended on which modem bank you dialed into, which was strongly influenced by what phone number you dialed.  Which diluted the identity value of a given IP for a computer or user.</p>
]]></description><pubDate>Wed, 21 Jan 2026 04:28:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=46701133</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=46701133</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46701133</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "Ask HN: Are there any antifeature-free power tools you can still buy new?"]]></title><description><![CDATA[
<p>As an outsider to this industry, is there any real moat against what an enthusiast or several could pull off with a few iterations?<p>Feels like a well placed post to a model sharing site could affect the landscape.<p>If we can do ghost guns shouldn't hand tools follow?</p>
]]></description><pubDate>Mon, 05 Jan 2026 03:44:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=46495149</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=46495149</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46495149</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "Bison return to Illinois' Kane County after 200 years"]]></title><description><![CDATA[
<p>If your schedule allows, try to time your visit around any of the science fairs that they sponsor and/or host.  Top notch all around.</p>
]]></description><pubDate>Mon, 05 Jan 2026 03:35:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=46495083</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=46495083</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46495083</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "Ask HN: Have You Automated Cooking?"]]></title><description><![CDATA[
<p>My espresso machine is semi-automated and lots of folks seem to go for fully automatic coffee experiences.  Mr Coffee all the way to K-cups etc.<p>There are some crazy things [1] going on in the oven world, though Miele seems to have blown the marketing.  My wife and kids all furrowed their brows when I told them about the fish in the ice block.  They don't understand or care about physics, they just like tasty food they know how to prepare.  "Why would you cook a fish in an ice block in the first place?"<p>[1] <a href="https://www.mieleusa.com/m/in-dialog-with-food-miele-to-unveil-a-revolutionary-new-cooking-method-at-ifa-1040.htm" rel="nofollow">https://www.mieleusa.com/m/in-dialog-with-food-miele-to-unve...</a></p>
]]></description><pubDate>Tue, 02 Dec 2025 15:29:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=46122176</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=46122176</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46122176</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "Okta's NextJS-0auth troubles"]]></title><description><![CDATA[
<p>I rather disagree on the difficulty of pulling it off.  The problem space is well-defined and there aren't that many degrees of freedom in functional design.<p>I'll concede there is some complexity in integrating with everything and putting up with the associated confusion.  And granted the stakes are a little raised due to the nature of identity and access, and like you point out what could go wrong.  Implementation is annoying, both writing the identity solution and then deploying and operating it. But the deployment & operation part is still there if you go with Okta or 1Login or Cognito or whomever.<p>The implementation is a capital type thing that is substantially solved already with the various F/OSS solutions people are mentioning - it's just a docker pull and some config work to get it going into a POC.<p>There are much harder problems in tech IMO, anything ill-defined for starters.<p>The C-level folks seem to think they are buying some kind of indemnity with these "enterprise" grade solutions, but there is no such thing.  They'll even turn it around and take Okta's limitations as existential--"if even Okta doesn't get it right, there is no way we could pull it off".  Out of touch, or less politely, delusional.</p>
]]></description><pubDate>Fri, 21 Nov 2025 16:01:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=46005707</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=46005707</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46005707</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "Okta's NextJS-0auth troubles"]]></title><description><![CDATA[
<p>Among the reasons to leave my last job was a CISO and his minion who insisted spending $50k+ on Okta for their b2b customer and employee authentication was a bulletproof move.<p>When I brought it up, they said they didn't have anyone smart enough to host an identity solution.<p>They didn't have anyone smart enough to use Okta either.  I had caught multiple dealbreakers-for-me such dubious / conflicting config settings resulting in exposures, actual outages caused by forced upgrades, not to mention their lackluster responses to bona fide incidents over the years.<p>I use Authentik for SSO in my homelab, fwiw.</p>
]]></description><pubDate>Thu, 20 Nov 2025 22:57:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=45999029</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=45999029</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45999029</guid></item><item><title><![CDATA[New comment by lq9AJ8yrfs in "Show HN: Autism Simulator"]]></title><description><![CDATA[
<p>Those all seem like easy problems to solve.<p>Draw straws and one person dials in from their desk or a phone closet. Take advantage of multiple locations, which are frequently if not always part of the landscape. I had a similar experience, there was a lady on the same floor who was sensitive to light, versus I had a plant that was dying, so I bought a timer and a desk lamp and set it directly under  the lamp to run after hours, and we kept the lights dim during the day.<p>At some point the rigidity is just another type of enshittification, there to subtract. Ingrained in their culture and part of their prerogative. Denying them the privilege is an insult that earns greater retribution. Pour encourager les autres.<p>It would literally cost them nothing to be flexible. Solzhenitsyn level material.<p>Suggests a new unit of measure, the Solz, which characterizes how occult and byzantine the rules are and how vindictive and arbitrary the application. Bonus points for tail-eating and Lysenkoist aspects.  Stalin era normalized to 1.<p>I had "exceeds" ratings the whole time at this job, btw.  I am told my contributions live on 10 years later, I can't say that about most of my work experience.</p>
]]></description><pubDate>Thu, 02 Oct 2025 14:26:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=45450048</link><dc:creator>lq9AJ8yrfs</dc:creator><comments>https://news.ycombinator.com/item?id=45450048</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45450048</guid></item></channel></rss>