<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: raesene9</title><link>https://news.ycombinator.com/user?id=raesene9</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 13 Jun 2026 08:53:16 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=raesene9" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by raesene9 in "Ask HN: What was your "oh shit" moment with GenAI?"]]></title><description><![CDATA[
<p>The one I remember most is, when experimenting with Opus 3.5 for the first time, I asked it to generate a Firecracker backed local VM creation and management tool, something I'd wanted for a while but not found.<p>My expectation was that it might get something barely functional but would probably fail, and instead it generated a working piece of software which achieved a lot of what I wanted.<p>That definitely made me realise that, for at least some classes of software task this was a major change in how things could be done.<p>More recently when I can give the model a Local Privilege Escalation PoC in Linux and ask it to test whether it can be used for container breakout and then generate a working container breakout, all in one prompt... that definitely changes things.</p>
]]></description><pubDate>Sat, 06 Jun 2026 14:39:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48425576</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=48425576</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48425576</guid></item><item><title><![CDATA[New comment by raesene9 in "Cooldown Support for Ruby Bundler"]]></title><description><![CDATA[
<p>not really, there are a number of security companies doing analysis of any new packages looking for supply chain attacks, so if you wait a couple of days, till their analysis is complete, you're reducing the risk of hitting a compromised package.</p>
]]></description><pubDate>Fri, 05 Jun 2026 15:24:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48413810</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=48413810</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48413810</guid></item><item><title><![CDATA[New comment by raesene9 in "Failing grades soar with AI usage, dwindling math skills in Berkeley CS classes"]]></title><description><![CDATA[
<p>I think perhaps the reason you are seeing quite a few commenters expressing skepticism to your comment "You go to a university because you are deeply interested in understanding the subject that you study." is that you appear to be extrapolating from one example (your own), without considering whether that's likely the wider experience of people going to university.<p>In the UK anyway, there's an acknowledged idea that many people go to university because there is a societal expectation that they should and also because many careers require a degree even for entry level positions.<p>There is also much less emphasis on other routes of tertiary education (e.g. vocational schools), when compared to places like Germany.</p>
]]></description><pubDate>Thu, 04 Jun 2026 13:21:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48398274</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=48398274</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48398274</guid></item><item><title><![CDATA[New comment by raesene9 in "I built a vulnerable app and spent $1,500 seeing if LLMs could hack it"]]></title><description><![CDATA[
<p>AFAIK pi's approach is to be quite minimal and allow extensions for customization, making it a more flexible solution, but you need to do work to make it fit your use case. OP mentions one extension, but perhaps it'd have benefited from more.<p>Another choice would be opencode which has more functionality and is a more heavyweight option out of the box.</p>
]]></description><pubDate>Thu, 04 Jun 2026 08:55:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=48395996</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=48395996</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48395996</guid></item><item><title><![CDATA[New comment by raesene9 in "UK sovereign LLM inference"]]></title><description><![CDATA[
<p>I'd expect for workflows where there is value in knowing that the data is processed in the UK. From a contractual/data protection standpoint, that could be very useful, depending on the use case.</p>
]]></description><pubDate>Fri, 15 May 2026 10:33:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48146888</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=48146888</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48146888</guid></item><item><title><![CDATA[New comment by raesene9 in "UK sovereign LLM inference"]]></title><description><![CDATA[
<p>Data Sovereignty as a term is now fairly well established term that doesn't have specific government connotations e.g. <a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/co-located-events/open-sovereign-cloud-day/" rel="nofollow">https://events.linuxfoundation.org/kubecon-cloudnativecon-eu...</a></p>
]]></description><pubDate>Fri, 15 May 2026 10:32:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48146881</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=48146881</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48146881</guid></item><item><title><![CDATA[New comment by raesene9 in "Incident Report: CVE-2024-YIKES"]]></title><description><![CDATA[
<p>So old school, now we get install lines like Tell Opencode to "Fetch and follow instructions from <a href="https://raw.githubusercontent.com/obra/superpowers/refs/heads/main/.opencode/INSTALL.md" rel="nofollow">https://raw.githubusercontent.com/obra/superpowers/refs/head...</a>"<p>From a real repo, with 186K stars... <a href="https://github.com/obra/superpowers" rel="nofollow">https://github.com/obra/superpowers</a></p>
]]></description><pubDate>Mon, 11 May 2026 07:09:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48091929</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=48091929</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48091929</guid></item><item><title><![CDATA[New comment by raesene9 in "Incident Report: CVE-2024-YIKES"]]></title><description><![CDATA[
<p>We don't need hindsight for the problems of supply chain security to be obvious. Security people were writing and doing talks about this stuff over 10 years ago, just (like most things in security) things start getting addressed once the pressure of incidents gets high enough :)</p>
]]></description><pubDate>Mon, 11 May 2026 07:03:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48091886</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=48091886</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48091886</guid></item><item><title><![CDATA[New comment by raesene9 in "Podman rootless containers and the Copy Fail exploit"]]></title><description><![CDATA[
<p>I've had claude knock up a basic podman PoC, that seems to work ok <a href="https://github.com/raesene/vuln_pocs/tree/main/CVE-2026-31431/podman" rel="nofollow">https://github.com/raesene/vuln_pocs/tree/main/CVE-2026-3143...</a> . It just uses a read-only mount and then demonstrates overwriting that read-only file.<p>Key point for testing exploitability is kernel version, package versions (in case they ship a patch) and loaded kernel modules. Some stripped down environments don't have the relevant modules available.</p>
]]></description><pubDate>Fri, 08 May 2026 14:59:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48064180</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=48064180</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48064180</guid></item><item><title><![CDATA[New comment by raesene9 in "Podman rootless containers and the Copy Fail exploit"]]></title><description><![CDATA[
<p>This is kind of an odd article to me. The point that podman may provide better isolation that Docker is made, but copy fail part focuses on the sample exploit (that overwrote su) which is not super applicable to containerised environments, and not the general effect of exploiting the vulnerability, which is to allow the user to overwrite a file that they should only have read-only access to.<p><a href="https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC" rel="nofollow">https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kuber...</a> - This PoC has a good example of how Copy Fail might have an impact in a container based environment, it's exploiting the shared layers in a pair of container images, to overwrite a file in one image based on the running of an exploit in another.<p>Whilst I've not directly tested podman for that kind of attack, I'd be a bit surprised if it stopped it, given how this vuln works.</p>
]]></description><pubDate>Fri, 08 May 2026 14:12:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48063484</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=48063484</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48063484</guid></item><item><title><![CDATA[New comment by raesene9 in "CVE-2026-31431: Copy Fail vs. rootless containers"]]></title><description><![CDATA[
<p>I've not looked for podman but moby/docker I believe does now block this <a href="https://github.com/moby/profiles/commit/7158007a83005b14a24fb7a833e80123bf406e9d" rel="nofollow">https://github.com/moby/profiles/commit/7158007a83005b14a24f...</a></p>
]]></description><pubDate>Tue, 05 May 2026 06:14:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48018708</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=48018708</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48018708</guid></item><item><title><![CDATA[New comment by raesene9 in "Changes to GitHub Copilot individual plans"]]></title><description><![CDATA[
<p>There is A/B testing going on and for a while several pages on Anthropic's site did remove Code from pro (<a href="https://old.reddit.com/r/ClaudeAI/comments/1srzhd7/psa_claude_pro_no_longer_lists_claude_code_as_an/" rel="nofollow">https://old.reddit.com/r/ClaudeAI/comments/1srzhd7/psa_claud...</a>) if you want a lot more details.</p>
]]></description><pubDate>Wed, 22 Apr 2026 08:46:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47860849</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=47860849</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47860849</guid></item><item><title><![CDATA[New comment by raesene9 in "Claude Code's source code has been leaked via a map file in their NPM registry"]]></title><description><![CDATA[
<p>but once forked people will have local copies, that can be put up onto other sites, if GH take them down.</p>
]]></description><pubDate>Fri, 03 Apr 2026 10:24:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=47624997</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=47624997</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47624997</guid></item><item><title><![CDATA[New comment by raesene9 in "A Rave Review of Superpowers (For Claude Code)"]]></title><description><![CDATA[
<p>The install mechanism for the superpowers plugin for codex and opencode is .... interesting. From <a href="https://github.com/obra/superpowers" rel="nofollow">https://github.com/obra/superpowers</a><p>Fetch and follow instructions from <a href="https://raw.githubusercontent.com/obra/superpowers/refs/heads/main/.codex/INSTALL.md" rel="nofollow">https://raw.githubusercontent.com/obra/superpowers/refs/head...</a><p>it's like curl|bash but with added LLM agents...</p>
]]></description><pubDate>Fri, 03 Apr 2026 09:59:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47624864</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=47624864</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47624864</guid></item><item><title><![CDATA[New comment by raesene9 in "Claude Code's source code has been leaked via a map file in their NPM registry"]]></title><description><![CDATA[
<p>there are a .....lot of forks already, no putting the genie back in the bottle for this one, I'd imagine.</p>
]]></description><pubDate>Tue, 31 Mar 2026 13:16:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=47586929</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=47586929</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47586929</guid></item><item><title><![CDATA[New comment by raesene9 in "Claude Code's source code has been leaked via a map file in their NPM registry"]]></title><description><![CDATA[
<p>I think the original repo OP mentioned decided not to host the code any more, but given there are 28k+ forks, it's not too hard to find again...</p>
]]></description><pubDate>Tue, 31 Mar 2026 13:14:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=47586893</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=47586893</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47586893</guid></item><item><title><![CDATA[New comment by raesene9 in "Box of Secrets: Discreetly modding an apartment intercom to work with Apple Home"]]></title><description><![CDATA[
<p>+1 to this we had a set of HomePod minis for intercom and not only do they not work reliably, but the diagnostics provided when they fail are non-existent, making it hard to improve the setup.</p>
]]></description><pubDate>Tue, 24 Mar 2026 08:51:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47500043</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=47500043</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47500043</guid></item><item><title><![CDATA[New comment by raesene9 in "OpenCode – Open source AI coding agent"]]></title><description><![CDATA[
<p>One of my main lessons after a decent long while in security, is that most orgs care about security, *as long as it doesn't get in the way of other priorities* like shipping new features. So when we get something like Agentic LLM tooling where everything moves super fast, security is inevitably going to suffer.</p>
]]></description><pubDate>Sat, 21 Mar 2026 16:21:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=47468415</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=47468415</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47468415</guid></item><item><title><![CDATA[New comment by raesene9 in "BYD is seeing a flood of new EV buyers"]]></title><description><![CDATA[
<p>And it's not just BYD. A couple of brands I'd literally never heard of till a year ago, Jaecoo and Omoda now seem to be getting pretty popular, saw quite a few when I was over in Glasgow.</p>
]]></description><pubDate>Fri, 20 Mar 2026 18:54:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=47458979</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=47458979</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47458979</guid></item><item><title><![CDATA[New comment by raesene9 in "We automated everything except knowing what's going on"]]></title><description><![CDATA[
<p>Whilst I have no special knowledge, my expectation is it'll do both. If you reduce the barriers to coding you'll get more code, both at the hobbyist/one-person level and also at the large corp level.<p>Whether that translates into more value for those larger corps is the trillion dollar question :) Writing code is a small part of the process of finding and shipping features that customers want, so it remains to be seen how much LLM tools translate it.<p>I think it's fairly widely accepted that from a financial standpoint we're in an AI/LLM bubble. There has been more investment than we're likely to see financial benefits, but it's impossible to predict to what degree (if you can predict that and the timing you can make a lot of money!!)</p>
]]></description><pubDate>Tue, 03 Mar 2026 15:25:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=47233807</link><dc:creator>raesene9</dc:creator><comments>https://news.ycombinator.com/item?id=47233807</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47233807</guid></item></channel></rss>