<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: throwaway7356</title><link>https://news.ycombinator.com/user?id=throwaway7356</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 06 Sep 2026 20:32:29 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=throwaway7356" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by throwaway7356 in "US strikes $1.2B deal to pay German firm to halt offshore wind projects"]]></title><description><![CDATA[
<p>Nuclear isn't as cheap as you present it. It needs heavy subsidies for insurance and waste disposal.<p>Most nuclear power proposals are just LARPing as "cheap" as they pretend subsidies don't exist.<p>In addition you have to shut nuclear power plants down in summers due to lack of sufficient cooling. That means you need to plan alternative replacement power generation.</p>
]]></description><pubDate>Fri, 07 Aug 2026 12:32:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=49209417</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=49209417</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49209417</guid></item><item><title><![CDATA[New comment by throwaway7356 in "US strikes $1.2B deal to pay German firm to halt offshore wind projects"]]></title><description><![CDATA[
<p>Yes, because comparing it to larger countries with more economic power like China would make the US politics look even dumber.</p>
]]></description><pubDate>Fri, 07 Aug 2026 11:55:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49209041</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=49209041</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49209041</guid></item><item><title><![CDATA[New comment by throwaway7356 in "An update on residential proxies and the scraper situation"]]></title><description><![CDATA[
<p>It'll still connect to IPv6 addresses and bypass any firewalls.<p>Also users might become part (victim?) of a police investigation because of illegal actions that seem to originate from their local residential connection.<p>So still good to take down such backdoors. Would be nice to go after the botnet operators as well...</p>
]]></description><pubDate>Sat, 11 Jul 2026 11:20:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=48871009</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48871009</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48871009</guid></item><item><title><![CDATA[New comment by throwaway7356 in "An update on residential proxies and the scraper situation"]]></title><description><![CDATA[
<p>> Apps are not infected with NetNut. This is just Google abusing their monopoly position to hurt its competitors.<p>If apps ship with stealth backdoors to sell access to the user's internal residential network, that's malware. I doubt any users want app providers to sell access to their private file server and anything else on their local network.<p>It doesn't seem like monopoly abuse to exclude such malware from application stores, just like key loggers or apps intercepting other apps network traffic without the user being aware of it (say the banking app's network traffic and password entry).</p>
]]></description><pubDate>Sat, 11 Jul 2026 05:30:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48869054</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48869054</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48869054</guid></item><item><title><![CDATA[New comment by throwaway7356 in "GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos"]]></title><description><![CDATA[
<p>> The fix was prepared statements<p>You don't need prepared statements. The fix is parameter binding: submitting parameters separate from the SQL statement itself, separating code from (user) data.<p>> The analogous mitigation for agents is to have fixed behaviors they can perform, such as “read repo 1” “read repo 2”, etc., and the user input is used as data to select which of these fixed behaviors to execute.<p>No, that only deals with some special issues. It also doesn't separate code and (user) data, so it's not the same issue.<p>Having only limited actions is akin to using more restrictive database permissions. That also makes SQL injection no longer relevant: only SQL statements can be executed that the user is allowed to run either way.</p>
]]></description><pubDate>Wed, 08 Jul 2026 18:07:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48835198</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48835198</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48835198</guid></item><item><title><![CDATA[New comment by throwaway7356 in "What Emily Bender meant by "stochastic parrots""]]></title><description><![CDATA[
<p>> nor do they provide the brain an interpretation of what they perceive<p>> What it gets from the body is raw physical measurements<p>No, sensory organs like eyes do a lot of processing ("interpreation"). They certainly don't send "raw physical measurements" to the brain.</p>
]]></description><pubDate>Tue, 07 Jul 2026 17:38:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48821032</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48821032</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48821032</guid></item><item><title><![CDATA[New comment by throwaway7356 in "What Emily Bender meant by "stochastic parrots""]]></title><description><![CDATA[
<p>Then one can claim that humans are less intelligent than a goldfish as "none of us have ever seen a human swim as well as a goldfish".</p>
]]></description><pubDate>Mon, 06 Jul 2026 18:55:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48808929</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48808929</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48808929</guid></item><item><title><![CDATA[New comment by throwaway7356 in "What Emily Bender meant by "stochastic parrots""]]></title><description><![CDATA[
<p>> yet with enough developer elbow grease they can do all the same things an LLM can do, with much higher reliability<p>Where can I access such a Lisp expert system?<p>If I cannot because they don't exist: then they cannot do the same things an LLM can do. And of course one can assert anything and everything about what a non-existing thing could do.</p>
]]></description><pubDate>Mon, 06 Jul 2026 16:42:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48807122</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48807122</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48807122</guid></item><item><title><![CDATA[New comment by throwaway7356 in "Do you need separate systems when you already have Postgres?"]]></title><description><![CDATA[
<p>Yes, that condition makes it no longer open source software.<p>It also has the effect of making software adopting such licenses getting removed from open source distributions.</p>
]]></description><pubDate>Mon, 06 Jul 2026 16:23:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48806825</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48806825</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48806825</guid></item><item><title><![CDATA[New comment by throwaway7356 in "Claude Design System Prompt"]]></title><description><![CDATA[
<p>The terms of service are between Anthropic and one of their subscribers. So Anthropic can maybe cancel their contract.<p>This doesn't affect what copyright law allows or does not allow.<p>Also I think Anthropic very much suppports gathering data by whatever means possible. That should work both ways.</p>
]]></description><pubDate>Sun, 05 Jul 2026 13:55:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=48794342</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48794342</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48794342</guid></item><item><title><![CDATA[New comment by throwaway7356 in "It Still Can't Do My Job: Four Years of Moving Goalposts (2022–2026)"]]></title><description><![CDATA[
<p>> I think the notion that you could control something (legitimately) smarter than you is a pretty risky proposition.<p>Well, Trump seems to control a lot of people given how afraid they are.<p>Trump is also called not the smartest person out there.<p>So...</p>
]]></description><pubDate>Fri, 03 Jul 2026 15:56:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48776535</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48776535</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48776535</guid></item><item><title><![CDATA[New comment by throwaway7356 in "Enhancing X11 Application Security with LXC (2025)"]]></title><description><![CDATA[
<p>> In practice the only place it shows up is if you are using "ssh -X". That uses the security extension by default. Which is why there is also a "ssh -Y" that disables it for applications that it breaks.<p>Unless your distro changes the default to make "ssh -X" and "ssh -Y" behave the same which popular distributions do.</p>
]]></description><pubDate>Sun, 28 Jun 2026 07:23:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48705176</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48705176</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48705176</guid></item><item><title><![CDATA[New comment by throwaway7356 in "Enhancing x11 Application Security with LXC (2025)"]]></title><description><![CDATA[
<p>> But granting full rights to distro-provided programs like vim or xeyes is perfectly sane.<p>You mean run everything distro-provided as root?<p>There are reasons systems don't do that any more. Even distro-provided services are often setup in a way to no run with full rights. Can you imaging reasons why this is done?<p>What was neglected is doing the same on user level, which should be done for pretty much the same reasons.</p>
]]></description><pubDate>Sun, 28 Jun 2026 07:20:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48705169</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48705169</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48705169</guid></item><item><title><![CDATA[New comment by throwaway7356 in "U.S. government will decide who gets to use GPT-5.6"]]></title><description><![CDATA[
<p>Maybe include some election guides for poor, misguided Americans that would hurt themselves by not voting for God President Donald Trump I as well?<p>It's protecting people from themselves, so basically like the safeguards already included in the models.</p>
]]></description><pubDate>Fri, 26 Jun 2026 20:14:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48691431</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48691431</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48691431</guid></item><item><title><![CDATA[New comment by throwaway7356 in "U.S. government will decide who gets to use GPT-5.6"]]></title><description><![CDATA[
<p>Can't the AI companies spare a small investment in Trump coin to ease the process?</p>
]]></description><pubDate>Fri, 26 Jun 2026 20:03:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48691302</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48691302</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48691302</guid></item><item><title><![CDATA[New comment by throwaway7356 in "Anthropic says Alibaba illicitly extracted Claude AI model capabilities"]]></title><description><![CDATA[
<p>> Ok, but what about those shady sites that resell Windows education keys?<p>Yes, they are fine? They might no longer include full first party support by Microsoft for not being "new". Same as buying a used car (also comes with the "shady sites" for a far longer time).<p>Though this not making any difference by Microsoft not doing any support either way to make more money is a business decision by Microsoft.</p>
]]></description><pubDate>Thu, 25 Jun 2026 05:43:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48669423</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48669423</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48669423</guid></item><item><title><![CDATA[New comment by throwaway7356 in "Anthropic says Alibaba illicitly extracted Claude AI model capabilities"]]></title><description><![CDATA[
<p>> China aren't offering a cheaper solution. They are subsidizing an existing one<p>So basically like US companies subsidizing offerings with selling user data, ads for crypto scams, manipulation for elections, making people addicted to gambling and so on?<p>Seems fair and an improvement as you can choose between that and not. Unlike say offerings from Meta where the data selling and efforts to further gambling addiction is always included.</p>
]]></description><pubDate>Thu, 25 Jun 2026 05:39:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48669388</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48669388</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48669388</guid></item><item><title><![CDATA[New comment by throwaway7356 in "System call instrumentation on Linux/x86‑64 using memory‑indirect calls, part I"]]></title><description><![CDATA[
<p>> all system calls had to go through libc (or perhaps a big ntdll.dll-like<p>Which makes containers crap on Windows and *BSD as they have to run the currect libc or equivalent. Thus you need to build a different container per OS version which sucks compared to Linux.</p>
]]></description><pubDate>Sun, 21 Jun 2026 17:14:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48620647</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48620647</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48620647</guid></item><item><title><![CDATA[New comment by throwaway7356 in "Developers don't understand CORS (2019)"]]></title><description><![CDATA[
<p>Yes, many developers give nothing about even basic security.<p>That's why we still have every basic security issue like hardcoded passwords, SQL or other injections, XSRF and so on repeated on an endless loop. Even if they are trivial to avoid.</p>
]]></description><pubDate>Sun, 21 Jun 2026 07:30:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=48616509</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48616509</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48616509</guid></item><item><title><![CDATA[New comment by throwaway7356 in "Developers don't understand CORS (2019)"]]></title><description><![CDATA[
<p>> CORS is threat model used for when you can't trust your self.<p>No. But many lack basic understanding of web technologies or facts like that a browser can be used to access more than a single site. This leads to not understanding what problems cross-site requests can cause and thus the impossibility of understanding what CORS is for.</p>
]]></description><pubDate>Sun, 21 Jun 2026 07:08:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48616400</link><dc:creator>throwaway7356</dc:creator><comments>https://news.ycombinator.com/item?id=48616400</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48616400</guid></item></channel></rss>