<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: outloudvi</title><link>https://news.ycombinator.com/user?id=outloudvi</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 27 Aug 2026 19:22:33 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=outloudvi" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by outloudvi in "NPM's release cooldown is security theater"]]></title><description><![CDATA[
<p>Went through the comment page and found this comment that explains well on most of the popular opinions. Thank you, hennell!</p>
]]></description><pubDate>Wed, 22 Jul 2026 01:44:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=49000804</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=49000804</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49000804</guid></item><item><title><![CDATA[New comment by outloudvi in "NPM's release cooldown is security theater"]]></title><description><![CDATA[
<p>I agree cooldown is not harmful in general. What I intended to say is that people (mostly) only know a security company is not trustable because they once failed to detect a malware package, and the reason people know a package is malware is that it has caused damaged to at least someone.</p>
]]></description><pubDate>Tue, 21 Jul 2026 17:45:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48995631</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48995631</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48995631</guid></item><item><title><![CDATA[New comment by outloudvi in "NPM's release cooldown is security theater"]]></title><description><![CDATA[
<p>I agree that LLM does not (and believe it never) fully <i>replace</i> researchers, but it produces artifacts (e.g. writeups, PoCs) at a cheaper price.<p>That makes me think LLM impacts human researchers' rewards, but now I realized the result might actually go in the opposite direction according to Jevons paradox. People still need experienced and professional human security researchers after all.</p>
]]></description><pubDate>Tue, 21 Jul 2026 17:37:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=48995529</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48995529</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48995529</guid></item><item><title><![CDATA[New comment by outloudvi in "NPM's release cooldown is security theater"]]></title><description><![CDATA[
<p>After reading the comments I now agree a short-length cooldown (maybe 1 or 3 days) is beneficial, given the following assumptions:<p>- Independent security companies are scanning the packages (be careful if the project is depending on some no-so-popular packages)<p>- Maintainers react promptly (it would be nonsense if people need to cooldown for 21 days because people may have 21-day vacations)</p>
]]></description><pubDate>Tue, 21 Jul 2026 17:26:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=48995389</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48995389</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48995389</guid></item><item><title><![CDATA[New comment by outloudvi in "NPM's release cooldown is security theater"]]></title><description><![CDATA[
<p>Sorry! That's 100% on me failing to make the analogy understood.<p>Shall have thought about that... but I'm playing too many Unity games recently.</p>
]]></description><pubDate>Tue, 21 Jul 2026 17:16:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48995252</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48995252</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48995252</guid></item><item><title><![CDATA[New comment by outloudvi in "NPM's release cooldown is security theater"]]></title><description><![CDATA[
<p>Thanks for your explanation on the definition of "security theater"!<p>> But if it turns out they can’t serve as the cooldown vanguard, then we have great evidence that they shouldn’t be trusted at all.<p>If they cannot serve as the cooldown vanguard, we are indeed going to realize they are not trustable, but by the time the damage has already been done. Therefore, if companies want to prevent the damage as much as possible, I believe they should do the scan by themselves.</p>
]]></description><pubDate>Tue, 21 Jul 2026 17:12:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48995191</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48995191</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48995191</guid></item><item><title><![CDATA[New comment by outloudvi in "NPM's release cooldown is security theater"]]></title><description><![CDATA[
<p>I applaud you if you do setup automated security scanners, without counting on external security groups or individuals (that doesn't have a security contract with your company).<p>This post is based on an assumption from what I see (I would be very happy if it's wrong) that most companies do not event bother to do these scans. They are merely waiting for the free kindness.</p>
]]></description><pubDate>Tue, 21 Jul 2026 16:57:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=48994991</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48994991</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48994991</guid></item><item><title><![CDATA[New comment by outloudvi in "NPM's release cooldown is security theater"]]></title><description><![CDATA[
<p>> The idea of not moving quickly to new software versions has been around for decades.<p>There are COBOL users and CentOS 6 users. They aren't affected by this issue.<p>They might need to face another set of issues like vulnerability backporting and so on. People not worrying about cooldowns might still need to patch their log4j libraries, but that's another thing. This post is not for them.<p>> There are always early adopters and researchers looking at new, publicly available software.<p>I agree with that. These hacks are very unlikely to go unnoticed, especially for popular packages (although they do happen; `chalk` has 3M downloads per week when it was hacked).<p>> The observation that "if everyone in production has a cooldown, the benefit is gone" is an absolutist opinion.<p>Yes. However, I think this is eventually becoming some type of pointless arms race, as cooldown does not act actively towards reducing ecosystem attacks.<p>To add a somehow random example, pnpm's default cooldown time is 1 day. Yarn's 7 days. I'm not sure whether one day pnpm would also change it to 7 days because of people asking.</p>
]]></description><pubDate>Tue, 21 Jul 2026 16:52:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=48994908</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48994908</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48994908</guid></item><item><title><![CDATA[New comment by outloudvi in "NPM's release cooldown is security theater"]]></title><description><![CDATA[
<p>I think it's great if people actually use LLM for the analysis. I did mention it in the solution part in the post:<p>> Run LLM-assisted audit on vendored code.</p>
]]></description><pubDate>Tue, 21 Jul 2026 16:27:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48994529</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48994529</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48994529</guid></item><item><title><![CDATA[New comment by outloudvi in "NPM's release cooldown is security theater"]]></title><description><![CDATA[
<p>I also believe sandboxing will get more and more important. There might be some trade-off on user experience or convenience, but given the security enhancement and (LLM agent's) freedom I think it will be well worth it.</p>
]]></description><pubDate>Tue, 21 Jul 2026 16:21:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48994431</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48994431</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48994431</guid></item><item><title><![CDATA[New comment by outloudvi in "NPM's release cooldown is security theater"]]></title><description><![CDATA[
<p>I do appreciate these security companies a lot (for example, Snyk), but I feel it hard to believe this is sustainable. Especially in the current world where LLM is devaluing security researchers' work.
If they cannot get enough fiat or credit, this will eventually turn to some incident like OpenSSL heartbleed or so.</p>
]]></description><pubDate>Tue, 21 Jul 2026 16:18:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48994387</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48994387</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48994387</guid></item><item><title><![CDATA[NPM's release cooldown is security theater]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.outv.im/2026/npm-cooldown-security-theater/">https://blog.outv.im/2026/npm-cooldown-security-theater/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48993885">https://news.ycombinator.com/item?id=48993885</a></p>
<p>Points: 44</p>
<p># Comments: 75</p>
]]></description><pubDate>Tue, 21 Jul 2026 15:46:18 +0000</pubDate><link>https://blog.outv.im/2026/npm-cooldown-security-theater/</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48993885</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48993885</guid></item><item><title><![CDATA[New comment by outloudvi in "What xAI's Grok build CLI sends to xAI: A wire-level analysis"]]></title><description><![CDATA[
<p>May I put some contents against GCP's AUP in my repo, wait for Grok Build to upload them, and report the bucket to Google?</p>
]]></description><pubDate>Sun, 12 Jul 2026 05:27:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48878545</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48878545</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48878545</guid></item><item><title><![CDATA[New comment by outloudvi in "Pintheft Linux LPE"]]></title><description><![CDATA[
<p>> Sadly, the RDS kernel module this requires is only default on Arch Linux among the common distributions we tested.<p>Sir, what do you mean by "Sadly"? I know your write-ups are mostly for marketing, but please don't expose your <i>malicious</i> intent so early.</p>
]]></description><pubDate>Wed, 20 May 2026 01:12:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48201834</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=48201834</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48201834</guid></item><item><title><![CDATA[New comment by outloudvi in "The West forgot how to make things, now it’s forgetting how to code"]]></title><description><![CDATA[
<p>The article speaks well but the situation for coding is more severe.<p>Shells are not needed once they are not in needed. Code does not: customer need is always there.<p>Before forgotting how to code, The West will first get round up by their own Monsanto, voluntarily.</p>
]]></description><pubDate>Sun, 26 Apr 2026 16:19:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47911457</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=47911457</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47911457</guid></item><item><title><![CDATA[New comment by outloudvi in "Tell HN: YC companies scrape GitHub activity, send spam emails to users"]]></title><description><![CDATA[
<p>These companys don't care about the reputation of their domains anymore at the moment they start to send spams. However, email senders (SendGrid, Mailgun etc.) care about the reputation of their IP addresses.</p>
]]></description><pubDate>Fri, 27 Feb 2026 02:44:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=47175744</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=47175744</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47175744</guid></item><item><title><![CDATA[New comment by outloudvi in "Tell HN: YC companies scrape GitHub activity, send spam emails to users"]]></title><description><![CDATA[
<p>I usually check the "Received" header and report to the email service provider. Once in a while I receive a response saying the case is properly handled.<p>These providers are the only ones that care about their reputation and thus may take some action. Investors? Nope.</p>
]]></description><pubDate>Thu, 26 Feb 2026 11:36:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47164658</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=47164658</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47164658</guid></item><item><title><![CDATA[New comment by outloudvi in "I cannot curl https://example.com (on some distros)"]]></title><description><![CDATA[
<p>> Is there good public discussion on root expiration?<p>Haven't seen a specific one but I guess the most relavant public discussion on root CA-led device bricking issues might have occurred around the time when DST Root CA X3 (naturally) expired - that's around September '24: <a href="https://letsencrypt.org/2023/07/10/cross-sign-expiration.html" rel="nofollow">https://letsencrypt.org/2023/07/10/cross-sign-expiration.htm...</a><p>I personally believe most issues blocking old device reuse can be solved by manufacturers returning the root permission back to users, so that users can install modded systems with up-to-date stuffs. However, it's a pity that manufacturers aren't willing to do it, as it hurts their interest on selling new devices. Will laws on "right to repair" work? Time will tell.</p>
]]></description><pubDate>Sun, 15 Feb 2026 16:34:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=47025012</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=47025012</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47025012</guid></item><item><title><![CDATA[I cannot curl https://example.com (on some distros)]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.outv.im/2026/i-cannot-curl-example-com/">https://blog.outv.im/2026/i-cannot-curl-example-com/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47024169">https://news.ycombinator.com/item?id=47024169</a></p>
<p>Points: 15</p>
<p># Comments: 2</p>
]]></description><pubDate>Sun, 15 Feb 2026 14:54:44 +0000</pubDate><link>https://blog.outv.im/2026/i-cannot-curl-example-com/</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=47024169</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47024169</guid></item><item><title><![CDATA[New comment by outloudvi in "Show HN: Gemini Pro 3 imagines the HN front page 10 years from now"]]></title><description><![CDATA[
<p>While the style and headline seems like Hacker News, the usernames seem increasingly alike Slashdot.</p>
]]></description><pubDate>Wed, 10 Dec 2025 01:53:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=46213141</link><dc:creator>outloudvi</dc:creator><comments>https://news.ycombinator.com/item?id=46213141</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46213141</guid></item></channel></rss>