<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: tmsbrg</title><link>https://news.ycombinator.com/user?id=tmsbrg</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 29 Apr 2026 18:58:48 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=tmsbrg" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by tmsbrg in "Waymo says can't avoid bike lanes because riders want to be dropped off in them"]]></title><description><![CDATA[
<p>Kind of weird article. If you want cars to stay out of bike lanes, make them protected like in here in the Netherlands. But also why do people expect to be taken to a bike lane rather than a parking space?<p>Also seeing a lot of ignorance about cycling here in the comments. Would recommend some people to watch some Not Just Bikes videos. Building better cycle infrastructure is better for everyone, cars and cyclists included. Less people die, and cars don't have to deal with cyclists on the road. Ex <a href="https://www.youtube.com/watch?v=d8RRE2rDw4k" rel="nofollow">https://www.youtube.com/watch?v=d8RRE2rDw4k</a></p>
]]></description><pubDate>Sun, 26 Apr 2026 21:27:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47914736</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=47914736</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47914736</guid></item><item><title><![CDATA[New comment by tmsbrg in "Oh My Zsh adds bloat"]]></title><description><![CDATA[
<p>I never noticed any issues, actually. I guess the zsh base is solid and stable.</p>
]]></description><pubDate>Sat, 10 Jan 2026 20:14:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=46569487</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46569487</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46569487</guid></item><item><title><![CDATA[New comment by tmsbrg in "How will the miracle happen today?"]]></title><description><![CDATA[
<p>He calls it the "miracle", I want to shout "It's not a miracle! It's other people!"<p>I feel he's depending on others' kindness and not even really acknowledging them. It's like he feels it's a miraculous power that's helping him (God?) rather than the actual individuals choosing to help him. Maybe that explains why he doesn't seem to feel the need to give back to them.<p>It reminds me of an episode of The Wire where a mediocre detective tries to use magic to solve a case. After he wakes up the next day he goes to the office and finds the case is solved. He says the magic worked! And the police chief tells him it wasn't magic, it's his colleagues who worked all night solving cases.</p>
]]></description><pubDate>Sat, 10 Jan 2026 14:33:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=46566010</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46566010</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46566010</guid></item><item><title><![CDATA[New comment by tmsbrg in "Oh My Zsh adds bloat"]]></title><description><![CDATA[
<p>I tried fish for a while but as someone who heavily used bash before I couldn't get used to the new language. I also didn't feel they the language was much better than bash, at least for my usage. But I loved the default automatic coloring of arguments, underlining of files, etc.<p>Later I found fizsh, which I love and still use as default shell now. It's basically a configuration around zsh adding the colors, completions, and other good stuff inspired by fish to zsh. Can really recommend it for those who are used to zsh or bash but want their CLI to be more readable. Colors especially help with big command line arguments to show where they start and end, and keeping track of complex stuff like loops and conditional logic in your commands.</p>
]]></description><pubDate>Sat, 10 Jan 2026 12:12:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=46565065</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46565065</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46565065</guid></item><item><title><![CDATA[New comment by tmsbrg in "IBM AI ('Bob') Downloads and Executes Malware"]]></title><description><![CDATA[
<p>I'm surprised there's no mention about disclosing the bug to IBM?. Usually these kinds of disclosures have a timeline showing when they told the vendor about the bug and when it was fixed. Now it looks like they just randomly released the vulnerability info on their blog.<p>Also a bit annoyed there's no date on the article, but looking at the HTML source it seems it was released today (isn't it annoying when blog software doesn't show the publish date?).</p>
]]></description><pubDate>Thu, 08 Jan 2026 19:27:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=46545318</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46545318</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46545318</guid></item><item><title><![CDATA[New comment by tmsbrg in "Total monthly number of StackOverflow questions over time"]]></title><description><![CDATA[
<p>Maybe there's a key idea for something to replace StackOverflow as a human tech Q&A forum: Having a system which somehow incentivizes asking and answering these sorts of challenging and novel questions. These are the questions which will not easily be answered using LLMs, as they require more thought and research.</p>
]]></description><pubDate>Sun, 04 Jan 2026 13:54:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=46487968</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46487968</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46487968</guid></item><item><title><![CDATA[New comment by tmsbrg in "39th Chaos Communication Congress Videos"]]></title><description><![CDATA[
<p>Thanks for the answers! Will look into this some more. I'm not based in the US I'm afraid but thanks for mentioning it.</p>
]]></description><pubDate>Sat, 03 Jan 2026 21:36:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=46481875</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46481875</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46481875</guid></item><item><title><![CDATA[New comment by tmsbrg in "39th Chaos Communication Congress Videos"]]></title><description><![CDATA[
<p>Hey, I just saw your talk and for someone who's not really up to date with the latest AI developments it's eye opening what you got going in SoC investigations.<p>I personally work as pentester and we're still doing a lot of manual work with AI simply as a better version of Google, but seeing the BOTS presentation I feel we can do better. Do you have any idea if anyone's working on something similar to Louie in pentesting space, or if Louie could work with pentesting workflows?</p>
]]></description><pubDate>Sat, 03 Jan 2026 16:36:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=46478596</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46478596</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46478596</guid></item><item><title><![CDATA[New comment by tmsbrg in "Exe.dev"]]></title><description><![CDATA[
<p>Seems it's overloaded now. I like the UX though. My usual question with any hosting is how do you avoid this being abused by hackers, scammers, etc.? Right now it's easy to just create any VMs for free based on a mail account, that seems ripe for exploitation (maybe it's down now cause someone's exploiting it?)</p>
]]></description><pubDate>Sat, 27 Dec 2025 14:28:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=46402078</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46402078</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46402078</guid></item><item><title><![CDATA[New comment by tmsbrg in "Fahrplan – 39C3"]]></title><description><![CDATA[
<p>Some talks which sound really brilliant. I love [0] exploiting a memory leak for years before it's fixed. Also [1] I'm really curious about the custom crypto used in Chinese apps. Oh and curious about the found [2] GPG vulnerabilities. I think some of the politics ones are actually also very interesting. Looking forward to the streams.<p>[0] <a href="https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/a-tale-of-two-leaks-how-hackers-breached-the-great" rel="nofollow">https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/...</a>
[1] <a href="https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/protecting-the-network-data-of-one-billion-people-breaking-network-crypto-in-popular-chinese-mobile-apps" rel="nofollow">https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/...</a>
[2] <a href="https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/to-sign-or-not-to-sign-practical-vulnerabilities-i" rel="nofollow">https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/...</a></p>
]]></description><pubDate>Fri, 26 Dec 2025 14:06:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=46392094</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46392094</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46392094</guid></item><item><title><![CDATA[New comment by tmsbrg in "CSRF protection without tokens or hidden form fields"]]></title><description><![CDATA[
<p>Oh, thanks. I learned something new. Never knew that different subdomains are considered the same "site", but MDN confirms this[0]. This shows just how complex these matters are imo, it's not surprising people make mistakes in configuring CSRF protection.<p>It's a pretty cool attack chain, if there's an XSS on marketing.example.com it can be used to execute a CSRF on app.example.com! It could also be used with dangling subdomain takeover or if there's open subdomain registration.<p>[0] <a href="https://developer.mozilla.org/en-US/docs/Glossary/Site" rel="nofollow">https://developer.mozilla.org/en-US/docs/Glossary/Site</a></p>
]]></description><pubDate>Thu, 25 Dec 2025 15:05:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=46384809</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46384809</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46384809</guid></item><item><title><![CDATA[New comment by tmsbrg in "CSRF protection without tokens or hidden form fields"]]></title><description><![CDATA[
<p>What do you mean with clientside Javascript CSRF?</p>
]]></description><pubDate>Thu, 25 Dec 2025 13:40:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=46384330</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46384330</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46384330</guid></item><item><title><![CDATA[New comment by tmsbrg in "CSRF protection without tokens or hidden form fields"]]></title><description><![CDATA[
<p>What do you mean with same-site cross-origin requests?</p>
]]></description><pubDate>Thu, 25 Dec 2025 13:38:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=46384319</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46384319</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46384319</guid></item><item><title><![CDATA[New comment by tmsbrg in "CSRF protection without tokens or hidden form fields"]]></title><description><![CDATA[
<p>I'm surprised there's no mention of the SameSite cookie attribute, I'd consider that to be the modern CSRF protection and it's easy, just a cookie flag:<p><a href="https://scotthelme.co.uk/csrf-is-dead/" rel="nofollow">https://scotthelme.co.uk/csrf-is-dead/</a><p>But I didn't know about the Sec-Fetch-Site header, good to know.</p>
]]></description><pubDate>Wed, 24 Dec 2025 23:02:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=46380228</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46380228</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46380228</guid></item><item><title><![CDATA[New comment by tmsbrg in "We Need to Die"]]></title><description><![CDATA[
<p>> Leaders generally don't rule for life in functioning countries, and the mortality of individual Kims has not helped the people of North Korea.<p>I guess you'd say most people in the world don't live in functioning countries then? China, Russia, much of the middle east and Africa are not democratic and sometimes the death of a dictator is the only way to move them forward. USA and many democracies in the west are also backsliding so maybe soon few people will live in a "functioning country".<p>Counterpoint on Kim: The death of Stalin or Mao Zedong released a death grip on their respective countries. You can't ignore that getting rid of natural death would make individual centralization of power a worse problem.<p>>How are these people currently oppressing you, and how would the existence of longevity treatments make that worse?<p>Just one example: Trump using sanctions to block the ICC from doing it's job (and thus letting people in Gaza die and blocking steps of justice against Israel). The fact is that the centralization of power in modern times into individual hands is already unprecedented. Old people are already ruling the world and they'd do everything to rule it forever.</p>
]]></description><pubDate>Tue, 09 Dec 2025 22:09:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=46211423</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46211423</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46211423</guid></item><item><title><![CDATA[New comment by tmsbrg in "We Need to Die"]]></title><description><![CDATA[
<p>As I said in another comment, I'm against immortality because old people need to make way for new generations. But this comment is cute. I like the idea that we'd be there and we're able to see how people are doing, but we're not influencing the world anymore. Though I could also imagine at some point it could become depressing in bad times when there's nothing you can do, or boring after tens of thousands of years of repetition. I can also imagine some bad spirits trying to break out and influence worldly affairs.</p>
]]></description><pubDate>Tue, 09 Dec 2025 21:03:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=46210606</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46210606</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46210606</guid></item><item><title><![CDATA[New comment by tmsbrg in "We Need to Die"]]></title><description><![CDATA[
<p>Not the argument I expected. I'm also against people living forever, but more because it's a way for society to go forward and get rid of old ways of thinking. There's a saying that science advances one death at a time. And can you imagine a world where current leaders are still in power 1000 years later? Or where the leaders of 1000 years ago were still in charge? Whenever I hear people talk about living forever I think of how it'd be something tech billionaires and autocrats would use to oppress us forever. No thanks.</p>
]]></description><pubDate>Tue, 09 Dec 2025 21:00:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=46210579</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46210579</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46210579</guid></item><item><title><![CDATA[New comment by tmsbrg in "If you're going to vibe code, why not do it in C?"]]></title><description><![CDATA[
<p>Even experts create C/C++ code that is routinely exploited in the wild (see: pegasus malware, Zerodium, Windows zero days, Chrome zero days, etc.). No, please don't vibe code anything security critical, and please don't create unnecessary security risk by writing it in unsafe languages such as C/C++. The only advantage I can see is it creates some fun easy targets for beginning exploit developers. But that's not an advantage for you.</p>
]]></description><pubDate>Tue, 09 Dec 2025 20:44:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=46210380</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=46210380</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46210380</guid></item><item><title><![CDATA[New comment by tmsbrg in "Show HN: Why write code if the LLM can just do the thing? (web app experiment)"]]></title><description><![CDATA[
<p>So the AI basically hallucinates a webapp?<p>I guess any user can just run something /api/getdatabase/dumppasswords and it will give any user the passwords?<p>or /webapp?html=<script>alert()</script> and run arbitrary JS?<p>I'm surprised nobody mentioned that security is a big reason not to do anything like this.</p>
]]></description><pubDate>Sun, 02 Nov 2025 10:42:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=45789334</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=45789334</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45789334</guid></item><item><title><![CDATA[Voyage of Magellan – Epilogue: Sailor of Eternal Fame]]></title><description><![CDATA[
<p>Article URL: <a href="https://analog-antiquarian.net/2025/06/27/epilogue-sailor-of-eternal-fame/">https://analog-antiquarian.net/2025/06/27/epilogue-sailor-of-eternal-fame/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44413895">https://news.ycombinator.com/item?id=44413895</a></p>
<p>Points: 17</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 29 Jun 2025 15:29:43 +0000</pubDate><link>https://analog-antiquarian.net/2025/06/27/epilogue-sailor-of-eternal-fame/</link><dc:creator>tmsbrg</dc:creator><comments>https://news.ycombinator.com/item?id=44413895</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44413895</guid></item></channel></rss>