<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: mook</title><link>https://news.ycombinator.com/user?id=mook</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 01 Aug 2026 00:26:13 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=mook" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by mook in "Anti-fraud tools can't keep pace with robocall scammers"]]></title><description><![CDATA[
<p>I was under the impression that SHAKEN / STIR was supposed to do that by authenticating the phone numbers displayed against the telco that made the call. But as the other comment says, your telco earns money from scam calls and they don't want that to stop.</p>
]]></description><pubDate>Fri, 31 Jul 2026 16:24:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=49125192</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=49125192</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49125192</guid></item><item><title><![CDATA[New comment by mook in "Tell HN: Namecheap gave my account to an unverified third party"]]></title><description><![CDATA[
<p>Isn't prompt injection basically social engineering for LLMs already anyway?</p>
]]></description><pubDate>Thu, 23 Jul 2026 22:46:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=49029094</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=49029094</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49029094</guid></item><item><title><![CDATA[New comment by mook in "Tell HN: Namecheap gave my account to an unverified third party"]]></title><description><![CDATA[
<p>Hmm, I don't know the area well; why would 2FA have been relevant here? From the (unverified) story, the account was administratively handed over via support; there was no indication from any party that the account was hacked. So 2FA prompts would never be part of the picture.</p>
]]></description><pubDate>Thu, 23 Jul 2026 22:44:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=49029065</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=49029065</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49029065</guid></item><item><title><![CDATA[New comment by mook in "OverpAId – Fire your CEO. Hire the future"]]></title><description><![CDATA[
<p>Interesting. At a smaller company I worked at, the CEO was a sales role, as far as I could tell.</p>
]]></description><pubDate>Wed, 22 Jul 2026 15:22:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=49008269</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=49008269</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49008269</guid></item><item><title><![CDATA[New comment by mook in "My car’s OTA update broke Android Auto"]]></title><description><![CDATA[
<p>At scale, testing software is appreciably more expensive than using hardware. That's why at most people test a tiny slice of it, and ships out broken software in the hopes of fixing it later. Testing hardware is expensive because nobody thinks it can be fixed cheaply afterwards.<p>See also: the article linked to this thread.</p>
]]></description><pubDate>Fri, 17 Jul 2026 01:58:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48942587</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48942587</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48942587</guid></item><item><title><![CDATA[New comment by mook in "My car’s OTA update broke Android Auto"]]></title><description><![CDATA[
<p>That's why we have Android Auto: move the updates to a thing that already has frequent Internet connection, and if the update goes wrong it's clearly the fault of this other company, plus the car itself still works fine.<p>Jeep already had an OTA the broke the ability for the car to be driven.</p>
]]></description><pubDate>Fri, 17 Jul 2026 01:52:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48942544</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48942544</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48942544</guid></item><item><title><![CDATA[New comment by mook in "Grok Build is open source"]]></title><description><![CDATA[
<p>Nice, [3] reminded me of OpenGrok † the old Sun project that was basically LXR on steroids.<p>† <a href="https://oracle.github.io/opengrok/" rel="nofollow">https://oracle.github.io/opengrok/</a></p>
]]></description><pubDate>Thu, 16 Jul 2026 02:43:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48929796</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48929796</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48929796</guid></item><item><title><![CDATA[New comment by mook in "Dependabot version updates introduce default package cooldown"]]></title><description><![CDATA[
<p>I keep getting things like "denial of service when the SCSS or whatever parse is given malicious input”. Great, that's part of the build chain, all of its inputs are stuff we control. Why do we care.</p>
]]></description><pubDate>Wed, 15 Jul 2026 06:58:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48917194</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48917194</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48917194</guid></item><item><title><![CDATA[New comment by mook in "Dependabot version updates introduce default package cooldown"]]></title><description><![CDATA[
<p>But updates to broken packages are still allowed: if a new version is pushed within the three days, it does not reset the cool-down. You just get a pull request to update to a known-bad version instead.</p>
]]></description><pubDate>Tue, 14 Jul 2026 23:13:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48914160</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48914160</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48914160</guid></item><item><title><![CDATA[New comment by mook in "How to stop Claude from saying load-bearing"]]></title><description><![CDATA[
<p>I don't see how you can tell it's AI, instead of just your co-workers having no respect for language. See: management-speak using "double-click".</p>
]]></description><pubDate>Tue, 14 Jul 2026 17:43:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48910448</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48910448</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48910448</guid></item><item><title><![CDATA[New comment by mook in "Dependencies should be fetched directly from VCS"]]></title><description><![CDATA[
<p>I think it's implied to be refusing to unpublish at the request of the author; unpublishing due to outside forces is probably inevitable. If some unsupportable content got introduced in a new version (e.g. xz), at least the historical versions would be kept.<p>That of course brings in questions of cost, trust, and governance, so there's definitely a trade-off…</p>
]]></description><pubDate>Mon, 06 Jul 2026 03:44:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48800422</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48800422</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48800422</guid></item><item><title><![CDATA[New comment by mook in "MSI Center – How to gain SYSTEM privileges in seconds"]]></title><description><![CDATA[
<p>For some reason, that holds an appxbundle per the article. I'd suspect they needed to run some pre- or post-install code (maybe to check for their hardware?).</p>
]]></description><pubDate>Sat, 04 Jul 2026 06:49:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48783195</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48783195</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48783195</guid></item><item><title><![CDATA[New comment by mook in "LastPass notifies users of yet another data breach"]]></title><description><![CDATA[
<p>I use KeepassXC, but I have no need to share passwords with other people. In a corporate situation that would probably not work as well.</p>
]]></description><pubDate>Thu, 25 Jun 2026 15:44:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48675140</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48675140</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48675140</guid></item><item><title><![CDATA[New comment by mook in "Epidurals are a miracle technology"]]></title><description><![CDATA[
<p>Don't forget the insurance, plus the hospital has costs that must be paid for too. A surgery with _just_ the surgeon and no support staff isn't one I'd want to be in.<p>(Not in the medical field at all)</p>
]]></description><pubDate>Tue, 23 Jun 2026 15:36:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48646742</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48646742</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48646742</guid></item><item><title><![CDATA[New comment by mook in "Dwarf Fortress in the Browser"]]></title><description><![CDATA[
<p>This is the sort of trademark violation where I can get behind proper enforcement. It's using the name of an unrelated project for advertisement (attention).</p>
]]></description><pubDate>Thu, 18 Jun 2026 16:30:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48587882</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48587882</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48587882</guid></item><item><title><![CDATA[New comment by mook in "Humiliating IIS servers for fun and jail time"]]></title><description><![CDATA[
<p>That page eventually leads to the CVE page: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204" rel="nofollow">https://msrc.microsoft.com/update-guide/vulnerability/CVE-20...</a><p>While that's still pretty vague, it sounds like the issue was that something running as SYSTEM (the page seems to indicate some part of Windows Update) was not correctly checking if inetpub was a symlink or something along those lines. It also links to a script to set ACLs on that directory; presumably that's not possible to do if the directory doesn't exist.<p>It would probably be better to fix whatever component to not have the link traversal bug, but maybe there's some reason that makes the proper fix infeasible…</p>
]]></description><pubDate>Wed, 17 Jun 2026 07:58:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48567224</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48567224</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48567224</guid></item><item><title><![CDATA[New comment by mook in "CJEU: Social networks are the 'publishers' of algorithmically-altered feeds"]]></title><description><![CDATA[
<p>It sounds like it's the editorial decision (of what to promote) is the accountable thing; that seems reasonable to me. Looking at the comments on that thread, it sounds like non-editorial sorting ("simple categorization and indexation") would still be fine.</p>
]]></description><pubDate>Tue, 16 Jun 2026 19:49:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=48560952</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48560952</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48560952</guid></item><item><title><![CDATA[New comment by mook in "Caddy compatibility for zeroserve: 3x throughput and 70% lower latency"]]></title><description><![CDATA[
<p>That's because the client certificate interface in browsers is supremely dumb. It always just lists all certificates you have, with very little context in the UI, and hopes that's good enough. I believe that's part of the reason client certificates are not poplar; having actual users deal with that is terrible, and the browsers (in practice, Chrome because of its overwhelming market share) isn't incentivized to fix it.</p>
]]></description><pubDate>Sun, 14 Jun 2026 16:48:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48529476</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48529476</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48529476</guid></item><item><title><![CDATA[New comment by mook in "The experience of rendering Arabic typography and its technical debt"]]></title><description><![CDATA[
<p>There's the <a href="https://en.wikipedia.org/wiki/Ideographic_Description_Characters" rel="nofollow">https://en.wikipedia.org/wiki/Ideographic_Description_Charac...</a> that kind of does that. The problem is that there's character divergence (see all the brouhaha about Unicode Han unification), so there needs to be something else to select variants too.<p>As a reference, I don't believe any of the pre-Unicode CJK&c encodings attempted that.</p>
]]></description><pubDate>Sat, 13 Jun 2026 20:15:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48520974</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48520974</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48520974</guid></item><item><title><![CDATA[New comment by mook in "The Future of Email"]]></title><description><![CDATA[
<p>Isn't the post office heroics normally when it's not deliverable? If the sender wrote down 744 Evergreen Terrace but they meant 742, that mail will be delivered to your neighbor and hopefully they'll redirect it to you.</p>
]]></description><pubDate>Fri, 12 Jun 2026 20:04:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48508839</link><dc:creator>mook</dc:creator><comments>https://news.ycombinator.com/item?id=48508839</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48508839</guid></item></channel></rss>