<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: throwaway2016a</title><link>https://news.ycombinator.com/user?id=throwaway2016a</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 14 Apr 2026 20:48:20 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=throwaway2016a" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by throwaway2016a in "Delve – Fake Compliance as a Service"]]></title><description><![CDATA[
<p>100%, accepting pre-generated board meeting notes is egregious. This whole thing is awful and I am in no way defending it. The opposite, I think other compliance as a service companies also need to be scrutinized as well.</p>
]]></description><pubDate>Fri, 20 Mar 2026 18:27:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=47458639</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=47458639</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47458639</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Delve – Fake Compliance as a Service"]]></title><description><![CDATA[
<p>There is a lot of serious allegations in here. But some of these complaints apply to most SOC 2 compliance services. For example: it points out that Delve provides pre-filled documents and encourages you to accept them as is. In my experience that is typical. I have seen companies just rubber stamp pre-created documents that describe IT processes that do not accurately reflect actual policy because the MBA[1] running the project didn't want to pull in IT and had no idea what any of it meant.<p>[1] No offense to MBA, just using it as a placeholder for: business stakeholder with no IT background.</p>
]]></description><pubDate>Fri, 20 Mar 2026 18:18:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=47458531</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=47458531</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47458531</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild"]]></title><description><![CDATA[
<p>I was literally just attending a course on "innovation" and the topic of Apple vs Android was covered. Interestingly enough, a majority of students commenting cited iOS "security" as a core value proposition. As an Android user, however, I know there are a lot of CVEs in volume but in terms of severity, when an iOS issue happens it appears to generally be much more severe.</p>
]]></description><pubDate>Wed, 18 Mar 2026 15:37:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=47427109</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=47427109</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47427109</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Skip the Tips: A game to select "No Tip" but dark patterns try to stop you"]]></title><description><![CDATA[
<p>First I will say, I am very much against dark patterns and I believe servers should be paid a fair wage and not have to rely on tips.<p>But until that I do tip for dine-in service. But I found the "buy me a coffee" link on the button of this to be much funnier / ironic than it probably should have been.<p>It's also missing what I think is the worst dark pattern:<p>Having no option not to tip at all. Instead requiring that the customer press "Custom" and manually entering "0.00"</p>
]]></description><pubDate>Fri, 13 Feb 2026 15:24:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=47003719</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=47003719</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47003719</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Using AI Generated Code Will Make You a Bad Programmer"]]></title><description><![CDATA[
<p>First, I'm using frontier models with Cursor agenic mode.<p>> Also, if you use an LLM haphazardly and it introduces a security flaw, you as the user are responsible. The LLM is a power tool, not a person.<p>I 100% agree. That was my point. A lot of people (not saying you, I don't know you) are not qualified to take on that level of responsibility yet they do it anyway and ship it to the user.<p>And on the human side, that is precisely why procedures like code review have been standard for a while.<p>But my main objection to the parent post was not that LLMs can't be powerful tools but that specifically the examples used of maintainability and security are (IMO) possibly the worst examples you can use. Since 70k line un-reviewable pull requests are not maintainable and probably also not secure (how would you know?).</p>
]]></description><pubDate>Fri, 19 Dec 2025 19:38:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=46329946</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=46329946</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46329946</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Using AI Generated Code Will Make You a Bad Programmer"]]></title><description><![CDATA[
<p>> If the programmers goal is to produce valuable software that works and is secure and easy to maintain then they will gravitate to LLM assisted programming.<p>Just this week alone I had the LLMs:<p>- Introduce a serious security flaw.<p>- Decided it was better to duplicate the same 5 lines of code 20 times instead of making a function and calling that.<p>And that is actually just this week. And to be clear, I am not making that up to prove a point, I use AI day in and day out and it happens consistently. Which is fine, humans can do that too, the issue is when there is a whole new generation of "programmers" that have absolutely zero clue how to spot those issues when (not if) they come up.<p>And as AI gets better (which it will) it actually makes it more dangerous because people start blindly trusting the code it produces.</p>
]]></description><pubDate>Fri, 19 Dec 2025 18:44:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=46329347</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=46329347</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46329347</guid></item><item><title><![CDATA[New comment by throwaway2016a in "TikTok 'directs child accounts to pornographic content within a few clicks'"]]></title><description><![CDATA[
<p>I'm not convinced that will fix the problem. Even in situations where identity is well known such as work or school, we commonly have bad actors.<p>It's also pretty unpopular for a good reason.<p>There is a chilling effect that would go along with it. Like it or not, a lot of people use these social platforms to be their true selves when they can't in their real life for safety reasons. Unfortunately for some people their "true self" is pretty trashy. But it's a slippery slope to put restrictions (like ID verification) on everyone just because of a few bad actors.<p>Granted I'm sure there's some way we could do that while maintaining moderate privacy but it's technologically challenging and I'm not alone in wanting tech companies to have less of my personal information not more.</p>
]]></description><pubDate>Fri, 03 Oct 2025 16:03:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=45464474</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=45464474</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45464474</guid></item><item><title><![CDATA[New comment by throwaway2016a in "TikTok 'directs child accounts to pornographic content within a few clicks'"]]></title><description><![CDATA[
<p>If you consider "skimpy outfits" pornographic that both Facebook and X are worse than TikTok for me. I've seen a few pieces of content I had to report before but not many.<p>X, on the other hand, has literal advertisements for adult products on my feed and I get followed by "adult" bot accounts several times a week that when I click through to block them often shows me literal porn. Same with spam facebook friend requests.<p>I think it boils down to a simple fact that trying to police user-generated content is always going to be an up-hill battle and it doesn't necessarily reflect on the company itself.<p>> Global Witness claimed TikTok was in breach of the OSA, which requires tech companies to prevent children from encountering harmful content...<p>Ok, that is noble goal but I feel that the gap between "reasonable measures" and "prevent" is vast.</p>
]]></description><pubDate>Fri, 03 Oct 2025 13:39:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=45462911</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=45462911</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45462911</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Why America still needs public schools"]]></title><description><![CDATA[
<p>Thank you on presenting the research. I appreciate that.<p>To address you points though:<p>> A handful of very bad students can easily derail the education of an entire class<p>Private school had plenty of bad apples too. In fact, some kids I went to school with were explicitly there because they were trouble makers and their parents though the nuns would break them (they didn't). In contrast, I've found my daughter's public school to be pretty zero tolerance when it comes to disruptors.<p>But even if you are right, that is also the strength of public schools. The same thing that makes them unable to turn down the bad apple is also what makes sure kids with special needs or low family means don't get left behind.<p>>  math is racist, or the contemporary 'reimaginings' of history that mix critical theory and contemporary values, and retrofit them into the past in an antagonistic fashion.<p>Except every time one of those stories come out and you dig deeper it is almost never actually what the media says. It's usually either extremely isolated or taken entirely out of context for sensationalism.<p>For example, there have been several documented cases of public school teachers teaching creationism, and also that the Civil war wasn't about slavery (despite slavery being specifically mentioned by multiple states when they joined the Confederacy), but I would never represent that as wide spread and try to tear down the whole system over it.</p>
]]></description><pubDate>Fri, 03 Oct 2025 01:22:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=45457689</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=45457689</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45457689</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Why America still needs public schools"]]></title><description><![CDATA[
<p>I didn't get a sense the article singled out charter schools specifically rather it just lists it as a alternative place that funds get funneled instead of to neighborhood public schools.<p>Which brings me to:<p>> The main reason "private" (in their sense of the word) schools are gaining in popularity is precisely because they are seen as delivering a better education by an ever wider chunk of society.<p>If you accept that the article is talking about charter schools, then yes, perhaps the narrow focus of the charter could allow for a stronger education in a specialized area could allow for better education in that area.<p>But, if you accept it as private schools as a whole, then I don't buy that argument fully. The administration has been very clear that the motivation is "anti-woke" and "traditional family values" and nothing to do with education quality. In fact, as someone who went to a religious school in a small town (granted 30+ years ago) I can vouch that my education (especially in science and math) was FAR worse than the public schools at the time and homeschooling quality varies wildly.<p>Edit: As far as<p>> More specifically the US currently spends more than the vast majority of the world per pupil<p>I also find this focus on spending per pupil very odd because it doesn't account for cost of living.<p>And if you dive into the fine print it says:<p>> Includes both government and private expenditures.<p>So what if (and this is a completely untested hypothesis) the reason we spend so much per pupil in that chart is being exasperated by the private school system.<p>Edit 2: after diving into it, that source provided is greatly inflated by private school spending including private colleges (which are insanely expensive). So that same data can also be used to argue the US is really spending too much on private schools not public ones.</p>
]]></description><pubDate>Thu, 02 Oct 2025 14:29:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=45450096</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=45450096</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45450096</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Vibe Coding Is the Worst Idea of 2025 [video]"]]></title><description><![CDATA[
<p>This whole thread is giving blockchain in 2015 vibes. People were using all sorts of quotes and anecdotes to tell skeptics why they were wrong and in 10 years the entire financial system will be running on blockchain. A certain amount of skepticism and cautious optimism is healthy.<p>Also, people seem to be missing that "AI Assisted" coding and "Vibe Coding" are not the same thing.<p>Personally I think the issue with vibe coding is two fold:<p>1. It is not good at solving problems that are uncommon.<p>2. It is not deterministic.<p>Yes, AI can do quality control and testing now. But anyone who has done TDD can tell you that just the mere presence of tests does not itself mean the code is effective or solving the right problem.<p>Is it getting better? Yes. Do I trust any vibe coded apps built by people who don't know actual code and are treating it like a black box? Absolutely not.<p>And I say that as someone who has tried pretty much every IDE out there and uses AI assisted coding (on "agent" mode) heavily every single day.</p>
]]></description><pubDate>Wed, 20 Aug 2025 13:46:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=44961917</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=44961917</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44961917</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Vibe Coding Is the Worst Idea of 2025 [video]"]]></title><description><![CDATA[
<p>Not OP, but there are many things that I know don't work without trying them. That's not a contradiction. It may or may not be true but it's not a contradiction by itself. You can know reasonable well that something doesn't work by looking at other people who have tried it (sometimes even better if those people are experts and you are not).</p>
]]></description><pubDate>Wed, 20 Aug 2025 13:41:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=44961873</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=44961873</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44961873</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Lab-grown salmon hits the menu"]]></title><description><![CDATA[
<p>When was the last time you actually priced them out?<p>When they first came up they were pricy but unless you're talking about fancy smart-bulbs with Wifi and color changing, they are not 10x the price. And they empirically last 5-20+ times longer.<p>So even before you consider that a huge portion of the energy put into incandescence is lost to heat (thereby making it cost MUCH more in electricity), they are still roughly the same price after accounting for lifespan.</p>
]]></description><pubDate>Tue, 19 Aug 2025 02:01:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=44947491</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=44947491</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44947491</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Link Out for In-App Purchases"]]></title><description><![CDATA[
<p>Stripe supports Apple Pay, though. You can easily enable both Apple Pay and Google Wallet.<p>But since it is just the regular version of Apple Pay and not an in-app purchase it has different (lower) fees.</p>
]]></description><pubDate>Fri, 02 May 2025 14:29:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=43870276</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=43870276</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43870276</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Minimal CSS-only blurry image placeholders"]]></title><description><![CDATA[
<p>I could tell and I really appreciate it. It's really helpful to see both the good and the bad.<p>Great work!</p>
]]></description><pubDate>Thu, 03 Apr 2025 11:59:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=43568371</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=43568371</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43568371</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Minimal CSS-only blurry image placeholders"]]></title><description><![CDATA[
<p>Very nice solution!<p>Definitely very low resolution, but compared to sites that use a solid color this seems much better. And only requiring one variable is really nice.<p>The article seems very well thought through. Though for both the algorithm and the benchmark algorithm the half blue / half green image with the lake shows the limitations of this technique. Still pretty good considering how light weight it is.</p>
]]></description><pubDate>Thu, 03 Apr 2025 01:17:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=43563663</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=43563663</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43563663</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Certificate will expire on 14 March – update Firefox to prevent add-on breakage"]]></title><description><![CDATA[
<p>It is a conversation that started with a simple post that was just pointing out that you had to download a new version the way Mozilla implemented the pinning.<p>I never said it was a good idea, I never made a political statement, I never said there wasn't a better way to do it with current PKI technology. I simply explained the way it had to be done the way Mozilla implemented it and I have to deal with rants talking about Hitler. And you call me unprofessional?<p>This conversation is over.</p>
]]></description><pubDate>Thu, 20 Mar 2025 22:40:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=43429873</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=43429873</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43429873</guid></item><item><title><![CDATA[New comment by throwaway2016a in "A powerful free and open source WAF – UUSEC WAF"]]></title><description><![CDATA[
<p>When I saw that link I thought maybe it was one of those: "add X to the recommended libraries list" PRs or something like that. But this is wild... it's literally an advertisement.</p>
]]></description><pubDate>Mon, 17 Mar 2025 14:58:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=43389260</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=43389260</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43389260</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Certificate will expire on 14 March – update Firefox to prevent add-on breakage"]]></title><description><![CDATA[
<p>You contradict your part here. I'm not sure if you meant to because the rest of your post sounds like it is saying Mozilla needs to pin if it's using a custom signing mechanism.<p>> Firefox uses (and ships with) the Mozilla Root Program<p>> can not not pin certificates<p>Shipping with a certificate store is by definition, pinning. So not only can it but your own post states it is when it says "and ships with".</p>
]]></description><pubDate>Mon, 17 Mar 2025 13:55:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=43388647</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=43388647</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43388647</guid></item><item><title><![CDATA[New comment by throwaway2016a in "Certificate will expire on 14 March – update Firefox to prevent add-on breakage"]]></title><description><![CDATA[
<p>1. Most of those articles refer to Public Key Pinning (HPKP), which is not the type Mozilla used. There is more than one type of pinning.<p>2. Once again... and I'm tired of repeating this... that's a straw man because never once in my original comment did I say pinning as a good idea or advocate for it.<p>3. With #2 in mind, seeing as my position was not for or against pinning, sending me articles about how bad it is just proves it is common enough use to warrant mainstream articles. Though again, moot, because I wasn't arguing it is common so another straw man.<p>From your source:<p>> Certificate pinning, the practice of restricting the certificates that are considered valid for your app to those you have previously authorized, is not recommended for Android apps.<p>At no point did I say this is not the case. I am aware of the limitations of pinning. Doesn't change the fact of my original post -- which is correct and has not been refuted in a single one of these replies -- Mozilla distributes the root public keys with their  app (as does Google as proven by my citation) and the way to upgrade it is to install the newest version.<p>That last sentence is ALL my original post said and one of your replies or the other persons once addressed that statement, you're all addressing these ridiculous straw men that I never actually said.</p>
]]></description><pubDate>Mon, 17 Mar 2025 13:21:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=43388316</link><dc:creator>throwaway2016a</dc:creator><comments>https://news.ycombinator.com/item?id=43388316</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43388316</guid></item></channel></rss>