<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: philipwhiuk</title><link>https://news.ycombinator.com/user?id=philipwhiuk</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 14 Jun 2026 06:22:48 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=philipwhiuk" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by philipwhiuk in "WhatsApp Business API pricing 2026: what's free and where markup hides"]]></title><description><![CDATA[
<p>I mean surely this was always going to happen? A fixed fee just means less frequent users subsidising everyone else.</p>
]]></description><pubDate>Fri, 12 Jun 2026 16:11:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48505943</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48505943</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48505943</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Claude Fable is relentlessly proactive"]]></title><description><![CDATA[
<p>Isn't the whole point of a better model that it should be better at understanding you than the previous one? So the same prompt should return a better answer.<p>Prompting differently to the new model seems entirely backwards when trying to determine if the model has improved.</p>
]]></description><pubDate>Fri, 12 Jun 2026 11:18:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48502660</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48502660</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48502660</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Microsoft's open source tools were hacked to steal passwords of AI developers"]]></title><description><![CDATA[
<p>In a tool that's dumb enough to run code from untrusted folders.<p>`cd folder` does nothing.</p>
]]></description><pubDate>Wed, 10 Jun 2026 13:27:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48476009</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48476009</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48476009</guid></item><item><title><![CDATA[New comment by philipwhiuk in "What it feels like to work with Mythos"]]></title><description><![CDATA[
<p>> the author had to be referencing this moment in their challenge to Fable/Mythos.<p>Or it just swept it up in the training data given Anthropic license Reddit comments.</p>
]]></description><pubDate>Wed, 10 Jun 2026 08:53:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=48473439</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48473439</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48473439</guid></item><item><title><![CDATA[New comment by philipwhiuk in "What it feels like to work with Mythos"]]></title><description><![CDATA[
<p>Given that token counts are easily available not providing how much any of his examples cost is lunacy.</p>
]]></description><pubDate>Wed, 10 Jun 2026 08:52:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48473429</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48473429</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48473429</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Upcoming breaking changes for npm v12"]]></title><description><![CDATA[
<p>> On balance, it’s npm’s belief that the utility of having installation scripts is greater than the risk of worms. This is a tradeoff that we will continue to evaluate.<p>They chose...poorly</p>
]]></description><pubDate>Wed, 10 Jun 2026 08:45:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=48473363</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48473363</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48473363</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Upcoming breaking changes for npm v12"]]></title><description><![CDATA[
<p>grep?</p>
]]></description><pubDate>Wed, 10 Jun 2026 08:43:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48473356</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48473356</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48473356</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Upcoming breaking changes for npm v12"]]></title><description><![CDATA[
<p>The entire use-case of that package is a security nightmare.</p>
]]></description><pubDate>Wed, 10 Jun 2026 08:41:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48473335</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48473335</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48473335</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Job: Head of Stonehenge"]]></title><description><![CDATA[
<p>Urgency based on medical reasons rather than financial wealth.<p>Crazy huh?</p>
]]></description><pubDate>Tue, 09 Jun 2026 16:38:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48463424</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48463424</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48463424</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Job: Head of Stonehenge"]]></title><description><![CDATA[
<p>And this is third sector.</p>
]]></description><pubDate>Tue, 09 Jun 2026 16:37:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48463408</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48463408</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48463408</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Albania Is Not for Sale: Kushner's $4B Resort Triggers'Flamingo Revolution'"]]></title><description><![CDATA[
<p>Stop the financialisation of everything.<p>(Or if you prefer because you are unable to compute that, the price is upfront $70,000 trillion (2025 prices) - cash only)</p>
]]></description><pubDate>Tue, 09 Jun 2026 15:34:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=48462481</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48462481</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48462481</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Microsoft's open source tools were hacked to steal passwords of AI developers"]]></title><description><![CDATA[
<p>It only spreads if you run the code...</p>
]]></description><pubDate>Tue, 09 Jun 2026 13:05:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48460610</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48460610</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48460610</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Microsoft's open source tools were hacked to steal passwords of AI developers"]]></title><description><![CDATA[
<p>Some form of public communication from Microsoft Security indicating an actual threat to their ecosystem and published pipeline of work to reduce the ability of attacks to spread via GitHub actions.<p>They can publish self-congratulatory stuff like this: <a href="https://www.microsoft.com/en-us/security/blog/2026/06/05/securing-ci-cd-in-agentic-world-claude-code-github-action-case/" rel="nofollow">https://www.microsoft.com/en-us/security/blog/2026/06/05/sec...</a> but they can't publish a post-mortem on their own platform?<p>I'm told that when Affirmed got compromised Microsoft Security descended on the org and rewrote their entire backlog. Where is the plan from GitHub that they are now taking security seriously given GitHub Actions is now a primary threat vector even for projects written by their own company.</p>
]]></description><pubDate>Tue, 09 Jun 2026 13:01:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=48460562</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48460562</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48460562</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Microsoft's open source tools were hacked to steal passwords of AI developers"]]></title><description><![CDATA[
<p>* GitHub [which they own] failed to detect the account was compromised<p>* GitHub [which they own] allowed the contribution to ignore CI<p>* GitHub [which they own] failed to detect suspicious content on check-in<p>* GitHub [which they own] isn't sufficiently integrated into Microsoft security that the compromised token wasn't rolled.</p>
]]></description><pubDate>Tue, 09 Jun 2026 12:58:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=48460531</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48460531</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48460531</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Show HN: Gitdot – A better GitHub. Open-source, written in Rust"]]></title><description><![CDATA[
<p>Be honest and transparent about who you are what you have and what you did. If it took you a year of solid development, it'll probably look like it did. If it took you 15 minutes in Claude... well it probably looks like it did too.<p>If you are YC backed then say "YC Winter 2026" or whatever in your title frankly - people will work it out anyway.<p>They said it was a better GitHub, which is a very high bar (despite the regular complaints about GitHub). They also said it was anti-AI, despite it being vibe-coded.<p>Also, know your competitive space. Posting on HN is like pitching - not knowing about your competitors is not really going to work - you need an answer for, for example, why someone picks Gitdot over SourceHut.</p>
]]></description><pubDate>Tue, 09 Jun 2026 12:41:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=48460350</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48460350</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48460350</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Job: Head of Stonehenge"]]></title><description><![CDATA[
<p>The height of the stones goes to 13!</p>
]]></description><pubDate>Tue, 09 Jun 2026 09:43:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48458819</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48458819</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48458819</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Job: Head of Stonehenge"]]></title><description><![CDATA[
<p>Probably FANG or finance.</p>
]]></description><pubDate>Tue, 09 Jun 2026 09:42:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48458806</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48458806</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48458806</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Ask HN: Why hasn't there been a real competitor to Ticketmaster yet?"]]></title><description><![CDATA[
<p>DICE are owned by Fever as of 2025.</p>
]]></description><pubDate>Tue, 09 Jun 2026 09:28:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48458726</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48458726</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48458726</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Microsoft's open source tools were hacked to steal passwords of AI developers"]]></title><description><![CDATA[
<p>Azure are able to be targets of supply chain attack because of the supply chain ecosystem that <i>they still own</i>. It's not really a supply chain when it's still yours.</p>
]]></description><pubDate>Tue, 09 Jun 2026 09:24:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=48458702</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48458702</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48458702</guid></item><item><title><![CDATA[New comment by philipwhiuk in "Microsoft's open source tools were hacked to steal passwords of AI developers"]]></title><description><![CDATA[
<p>> > This is Microsoft’s second known breach over the past few weeks that has allowed hackers to compromise its open source projects, per Ars Technica.<p>> I, like many others love to knock on Microslop when I can, but in this case they did the right thing.<p>I've no idea what your problem with this sentence is. They have an organisational security problem, aided/demonstrated by lack of effort to effectively lockdown GitHub Actions and allowing MRs to circumvent CI/CD.<p>That this is a Microsoft problem that was present pre-AI is not up for debate. See <a href="https://www.cisa.gov/sites/default/files/2025-03/CSRBReviewOfTheSummer2023MEOIntrusion508.pdf" rel="nofollow">https://www.cisa.gov/sites/default/files/2025-03/CSRBReviewO...</a><p>In the age of AI, it's now endemic and being weaponised.</p>
]]></description><pubDate>Tue, 09 Jun 2026 09:23:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=48458686</link><dc:creator>philipwhiuk</dc:creator><comments>https://news.ycombinator.com/item?id=48458686</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48458686</guid></item></channel></rss>