<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: password4321</title><link>https://news.ycombinator.com/user?id=password4321</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 12 Apr 2026 14:59:08 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=password4321" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[TruffleHog now finds all Deleted and Private Commits on GitHub (2024)]]></title><description><![CDATA[
<p>Article URL: <a href="https://trufflesecurity.com/blog/trufflehog-now-finds-all-deleted-and-private-commits-on-github">https://trufflesecurity.com/blog/trufflehog-now-finds-all-deleted-and-private-commits-on-github</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47724705">https://news.ycombinator.com/item?id=47724705</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 10 Apr 2026 22:48:01 +0000</pubDate><link>https://trufflesecurity.com/blog/trufflehog-now-finds-all-deleted-and-private-commits-on-github</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47724705</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47724705</guid></item><item><title><![CDATA[New comment by password4321 in "We've raised $17M to build what comes after Git"]]></title><description><![CDATA[
<p>related: <a href="https://news.ycombinator.com/item?id=41060102">https://news.ycombinator.com/item?id=41060102</a> <i>Anyone can access deleted and private repository data on GitHub</i></p>
]]></description><pubDate>Fri, 10 Apr 2026 22:28:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=47724473</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47724473</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47724473</guid></item><item><title><![CDATA[New comment by password4321 in "I still prefer MCP over skills"]]></title><description><![CDATA[
<p>Surprised to see no mention in the article or discussion yet about using MCPs in 'code mode', where an API is generated client-side relying on MCP primarily as an interface standard. I'm still learning but I've read this reduces the amount of context required to use the MCP.<p>It seems like a lot of the discussion is arguing in favor of API usage without realizing that MCP basically standardizes a universal API, thus enabling code mode.</p>
]]></description><pubDate>Fri, 10 Apr 2026 12:52:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=47717382</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47717382</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47717382</guid></item><item><title><![CDATA[New comment by password4321 in "We found an undocumented bug in the Apollo 11 guidance computer code"]]></title><description><![CDATA[
<p>The front page has moved on but this is pure gold, thanks for making the time to share all these details.</p>
]]></description><pubDate>Wed, 08 Apr 2026 00:03:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=47682932</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47682932</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47682932</guid></item><item><title><![CDATA[New comment by password4321 in "How to get better at guitar"]]></title><description><![CDATA[
<p>Practice make permanent.</p>
]]></description><pubDate>Tue, 07 Apr 2026 22:01:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=47681887</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47681887</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47681887</guid></item><item><title><![CDATA[New comment by password4321 in "Show HN: GovAuctions lets you browse government auctions at once"]]></title><description><![CDATA[
<p>Just keep in mind if you're providing value the scrapers will soon appear to claim it for themselves... look at what Craigslist does to protect their data though you want all traffic as you get off the ground.</p>
]]></description><pubDate>Mon, 06 Apr 2026 23:54:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=47668968</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47668968</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47668968</guid></item><item><title><![CDATA[New comment by password4321 in "Tell HN: Anthropic no longer allowing Claude Code subscriptions to use OpenClaw"]]></title><description><![CDATA[
<p>Continuous requests at a constant rate for days with interruptions?</p>
]]></description><pubDate>Sat, 04 Apr 2026 01:10:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=47634506</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47634506</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47634506</guid></item><item><title><![CDATA[New comment by password4321 in "Tell HN: Anthropic no longer allowing Claude Code subscriptions to use OpenClaw"]]></title><description><![CDATA[
<p>GitHub Copilot supports Anthropic models with any client but they have a monthly usage cap after which it is pay-per-prompt.<p><a href="https://news.ycombinator.com/item?id=46936105">https://news.ycombinator.com/item?id=46936105</a> Billing can be bypassed using a combo of subagents with an agent definition<p>> <i>"Even without hacks, Copilot is still a cheap way to use Claude models"</i><p>20260116 <a href="https://github.blog/changelog/2026-01-16-github-copilot-now-supports-opencode/" rel="nofollow">https://github.blog/changelog/2026-01-16-github-copilot-now-...</a><p><a href="https://github.com/features/copilot/plans" rel="nofollow">https://github.com/features/copilot/plans</a> $40/month for 1500 requests; $0.04/request after that<p><a href="https://docs.github.com/en/copilot/concepts/billing/copilot-requests#model-multipliers" rel="nofollow">https://docs.github.com/en/copilot/concepts/billing/copilot-...</a> Opus uses 3x requests</p>
]]></description><pubDate>Fri, 03 Apr 2026 23:57:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=47633952</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47633952</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47633952</guid></item><item><title><![CDATA[New comment by password4321 in "New patches allow building Linux IPv6-only"]]></title><description><![CDATA[
<p>> <i>ALL THE HEAVY LIFTING THERE</i><p>> <i>MUCH MORE IMPORTANT</i><p>I haven't done the exhaustive research but props in advance for being the only person shouting in caps on HN. Definitely one way to proclaim one's not AI-ness without forced spelling errors.</p>
]]></description><pubDate>Wed, 01 Apr 2026 21:02:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=47606530</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47606530</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47606530</guid></item><item><title><![CDATA[New comment by password4321 in "New patches allow building Linux IPv6-only"]]></title><description><![CDATA[
<p>I recently learned I can skip middle .0's in IPv4, no more 192.168's for me it's 10[.0.0]'s going forward.</p>
]]></description><pubDate>Wed, 01 Apr 2026 20:57:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=47606460</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47606460</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47606460</guid></item><item><title><![CDATA[Federated and Independent [Plugin] Repositories in WordPress (Linux Foundation)]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/fairpm/fair-plugin">https://github.com/fairpm/fair-plugin</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47604157">https://news.ycombinator.com/item?id=47604157</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 01 Apr 2026 17:50:09 +0000</pubDate><link>https://github.com/fairpm/fair-plugin</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47604157</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47604157</guid></item><item><title><![CDATA[New comment by password4321 in "EmDash – a spiritual successor to WordPress that solves plugin security"]]></title><description><![CDATA[
<p>If you need a reliable source for WordPress plugins, check out <a href="https://github.com/fairpm/fair-plugin?tab=readme-ov-file#fair-connect" rel="nofollow">https://github.com/fairpm/fair-plugin?tab=readme-ov-file#fai...</a><p><i>A system for using Federated and Independent Repositories in WordPress</i></p>
]]></description><pubDate>Wed, 01 Apr 2026 17:46:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=47604118</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47604118</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47604118</guid></item><item><title><![CDATA[New comment by password4321 in "Oracle slashes 30k jobs"]]></title><description><![CDATA[
<p>I can't really speak to 3rd party utilities, I think Management Studio was sufficient to keep most competition from ever starting.</p>
]]></description><pubDate>Tue, 31 Mar 2026 18:04:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=47591223</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47591223</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47591223</guid></item><item><title><![CDATA[New comment by password4321 in "Oracle slashes 30k jobs"]]></title><description><![CDATA[
<p>SQL Server's claim to fame was GUI admin tools making life easier for many who bore DBA responsibilities only in anger.<p>It remains one of the most reliable Microsoft products, but few would claim that is a high bar.</p>
]]></description><pubDate>Tue, 31 Mar 2026 17:30:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=47590753</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47590753</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47590753</guid></item><item><title><![CDATA[New comment by password4321 in "A Love Letter to 'Girl Games'"]]></title><description><![CDATA[
<p>> <i>all these super politically progressive AAA gaming companies somehow are worse</i><p>Corporate interest is primarily financial, anything beyond that is unfortunately all too often only (financially motivated) virtue signalling.</p>
]]></description><pubDate>Tue, 31 Mar 2026 17:24:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47590661</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47590661</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47590661</guid></item><item><title><![CDATA[New comment by password4321 in "Axios compromised on NPM – Malicious versions drop remote access trojan"]]></title><description><![CDATA[
<p>I think my vetting would settle for a repo diff against the previous version, confirming the only difference was the security fix (though that doesn't cover all the bases).</p>
]]></description><pubDate>Tue, 31 Mar 2026 16:44:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=47590082</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47590082</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47590082</guid></item><item><title><![CDATA[New comment by password4321 in "GitHub backs down, kills Copilot pull-request ads after backlash"]]></title><description><![CDATA[
<p>Azure DevOps <shudder/></p>
]]></description><pubDate>Tue, 31 Mar 2026 11:46:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=47585947</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47585947</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47585947</guid></item><item><title><![CDATA[New comment by password4321 in "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised"]]></title><description><![CDATA[
<p>Thanks for circling back.<p>I interpret your comment as emphasizing that the current norm relying on publicly accessible (GitHub) infrastructure building  releases in public and thus allowing public review of logs and artifacts provides tremendous value (and I admit that true 100% binary reproducibility is an often nearly unreachable goal still not yet typically expected as the norm).<p>> <i>Breaking that chain via a private repo is a step backwards</i><p>I was stating that performing a reproducible build elsewhere and distributing the output could in theory still be validated though it would require re-running said build for one's self and comparing the outputs. This might encourage the pursuit of 100% reproducibility! The chain need not be considered broken just because the final link is private.<p>> <i>the public has been deprived of this verifiability</i><p>This is not what I was trying to point out, though I agree the cost of verifying reproducibility would be higher. My point was that anyone could still perform the same steps themselves and verify the output. Yes this would be more work than reviewing logs on GitHub.<p>OP's primary concern with today's standard approach appears to be the automated connection from GitHub build action -> release. Even simply requiring manual maintainer intervention to copy the action output over to a release seems to satisfy both their and your concerns.<p>> <i>If the public had the ability to audit that the release tarball was correctly built from the version-controlled code</i><p>I am not intimately familiar with all the details of the XZ fiasco but agree that it offers an opportunity to learn and make changes to work toward making sure nothing similar can happen to any project again. If I am reading your link correctly, it serves as an example of members of the public (not a maintainer of XZ) doing exactly what you said: auditing the release tarball. IIRC this occurred only after an additional point release (apparently allowing the attacker to fix a bug in their backdoor) because of a performance regression.</p>
]]></description><pubDate>Mon, 30 Mar 2026 12:05:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47573187</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47573187</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47573187</guid></item><item><title><![CDATA[New comment by password4321 in "ChatGPT won't let you type until Cloudflare reads your React state"]]></title><description><![CDATA[
<p>Wow, if Seinfeld can have a soup nazi, I think it's within reason for you to be called the internet nazi.<p>"No s̶o̶u̶p̶ internet for you!"<p>Good luck!</p>
]]></description><pubDate>Sun, 29 Mar 2026 21:08:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=47567333</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47567333</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47567333</guid></item><item><title><![CDATA[New comment by password4321 in "Arm releases first in-house chip, with Meta as debut customer"]]></title><description><![CDATA[
<p>It's not my logic, it's the logic of the moderator(s) of HN. Here's more,  cut+paste from the link previously provided (<a href="https://news.ycombinator.com/item?id=43738815">https://news.ycombinator.com/item?id=43738815</a>):<p>> <i>I agree—they're not all the same story. On the other hand: stories in an ongoing sequence usually lead to repetitive discussion, which is bad for HN</i></p>
]]></description><pubDate>Sat, 28 Mar 2026 14:03:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=47554732</link><dc:creator>password4321</dc:creator><comments>https://news.ycombinator.com/item?id=47554732</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47554732</guid></item></channel></rss>