<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: too_pricey</title><link>https://news.ycombinator.com/user?id=too_pricey</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 02 Sep 2026 08:59:54 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=too_pricey" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by too_pricey in "Breaking Claude Code Opus 5 Auto Mode"]]></title><description><![CDATA[
<p>As discussed [here](<a href="https://lobste.rs/s/ktbweg/prompt_injection_claude_code_opus_5_auto#c_gi7eqj" rel="nofollow">https://lobste.rs/s/ktbweg/prompt_injection_claude_code_opus...</a>), this is not prompt injection. The prompt was to summarize the website, and in the process of summarizing the website, Claude writes a decoding script that it runs in an insecure and exploitable way. At no point was the intent of the agent hijacked, this was just code. Which is potentially more interesting!</p>
]]></description><pubDate>Mon, 31 Aug 2026 11:15:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49508307</link><dc:creator>too_pricey</dc:creator><comments>https://news.ycombinator.com/item?id=49508307</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49508307</guid></item><item><title><![CDATA[New comment by too_pricey in "52-hertz whale"]]></title><description><![CDATA[
<p>I get it. Reminds me of the [last song] (<a href="https://youtu.be/nDRY0CmcYNU?is=2G47ZpdH3rSk_j3P" rel="nofollow">https://youtu.be/nDRY0CmcYNU?is=2G47ZpdH3rSk_j3P</a>) of the Kauaʻi ʻōʻō.</p>
]]></description><pubDate>Thu, 25 Jun 2026 20:14:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48678636</link><dc:creator>too_pricey</dc:creator><comments>https://news.ycombinator.com/item?id=48678636</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48678636</guid></item><item><title><![CDATA[New comment by too_pricey in "The real cost of owning a home"]]></title><description><![CDATA[
<p>They also neglect the Mortage Interest Tax Deduction and State and Local Tax Deductions,  whcih reduce the cost of both by your marginal tax rate, and is a big benefit towards owning.<p>More importantly, this neglects that buying a home is locking in the price for the long term for the majority of your housing cost. Buying usually is similar all in the first year, but after 5 years your mortage payment is the same while rent has probably gone up significantly.</p>
]]></description><pubDate>Tue, 26 May 2026 17:03:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48282520</link><dc:creator>too_pricey</dc:creator><comments>https://news.ycombinator.com/item?id=48282520</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48282520</guid></item><item><title><![CDATA[New comment by too_pricey in "I tried to replace myself with ChatGPT in my English class"]]></title><description><![CDATA[
<p>This isn't true. I'm one of those people who tested remarkably well, and back in college would do fine on exams despite frantically copying all of my own (non-comp Sci) assignments. Better than my peers who knew more and helped me cram. Test anxiety is real.</p>
]]></description><pubDate>Tue, 05 Aug 2025 03:56:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=44794188</link><dc:creator>too_pricey</dc:creator><comments>https://news.ycombinator.com/item?id=44794188</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44794188</guid></item><item><title><![CDATA[New comment by too_pricey in "FTC orders 'gun detection' tech maker Evolv to stop overstating effectiveness"]]></title><description><![CDATA[
<p>Multiple concert venues in my city use these, so I interact with them all the time. They have replaced standard metal detectors, bag searches, and manual patdowns w/ hands and/or metal-detecting wands. Security checkpoints are the primary point of delay for getting into venues, and places that have rolled these out process people through about 95% faster. It's a huge difference. If it does trigger, you just get the manual patdown you would have gotten anyway, so the false positive cases aren't any lost time.<p>The article and settlement seem to only mention the false positive rate, which is a bad thing to focus on. Every true positive is a much faster experience. Only subjecting 110 out of 3000 people to a longer search is a big improvement. Given the negative outcomes of a gun slipping through and the lack of a cost of a false positive, we probably want it to be tuned to be more false positive prone anyway. We don't need these to detect guns THAT well, we just need them to weed out people who definitely don't have them.<p>I do have concerns about what its false negative rate is relative to the standard practice it replaces. I do not really trust whatever psuedo-AI they're bolting to their metal detectors; it's probably easier to get a gun through. That said, the false negative rate probably isn't good already. TSA isn't great on their false positive rate, does more intense screening, and isn't being staffed by hungover 20-somethings. So maybe the false negative rate didn't actually increase by much?</p>
]]></description><pubDate>Mon, 30 Dec 2024 18:10:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=42551875</link><dc:creator>too_pricey</dc:creator><comments>https://news.ycombinator.com/item?id=42551875</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42551875</guid></item><item><title><![CDATA[New comment by too_pricey in "Security Is a Useless Controls Problem"]]></title><description><![CDATA[
<p>The Phoenix Project has been very influential on me in my security career, at least partially because I share the name of the ineffectual CISO and want so desperately to avoid the link.<p>I think the book is still very applicable, and every security practitioner needs to be hit over the head with it (or at least The DevOps Handbook or Accelerate). Security generally is decades behind engineering operations, even though security is basically just a more paranoid lens for doing engineering ops; the ideas from Phoenix are still depressingly revolutionary in my field.</p>
]]></description><pubDate>Tue, 12 Nov 2024 02:10:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=42112200</link><dc:creator>too_pricey</dc:creator><comments>https://news.ycombinator.com/item?id=42112200</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42112200</guid></item><item><title><![CDATA[New comment by too_pricey in "Security Is a Useless Controls Problem"]]></title><description><![CDATA[
<p>I actually wrote blogs about two of my (least) favorites: [VPNs](<a href="https://securityis.substack.com/p/security-is-not-a-vpn-problem)and" rel="nofollow">https://securityis.substack.com/p/security-is-not-a-vpn-prob...</a> [Encryption](<a href="https://securityis.substack.com/p/security-is-not-an-encryption-problem" rel="nofollow">https://securityis.substack.com/p/security-is-not-an-encrypt...</a>). Thank you for pointing out I don't link to them in this original post.<p>Password resets are definitely one, and I still have to tell prospects and customers that I can't both comply with NIST 800-63 and periodically rotate my passwords, every single day. Other ones I often counter include other aggressive login requirements, WAFs, database isolation, weird single tenancy or multitenancy asks, or for anti-virus to be in places that they don't need to be.</p>
]]></description><pubDate>Tue, 12 Nov 2024 01:55:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=42112137</link><dc:creator>too_pricey</dc:creator><comments>https://news.ycombinator.com/item?id=42112137</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42112137</guid></item><item><title><![CDATA[New comment by too_pricey in "Security Is a Useless Controls Problem"]]></title><description><![CDATA[
<p>I wrote this! I'm excited to see this get attention here. I'll be responding to folks' comments where I feel like I have something to add, but please let me know if you have any questions or feedback!</p>
]]></description><pubDate>Tue, 12 Nov 2024 01:44:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=42112088</link><dc:creator>too_pricey</dc:creator><comments>https://news.ycombinator.com/item?id=42112088</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42112088</guid></item><item><title><![CDATA[New comment by too_pricey in "Ask HN: My client want an agent on my laptop. Is this the new normal?"]]></title><description><![CDATA[
<p>You're completely right re Drata as a company (we use a different compliance vendor, but very similar setup re the agent).<p>You're a bit off on whether this would fail a SOC2 audit, thankfully.  As the OP said, they don't have access to production systems, which basically means you can treat that employee however you want from a SOC2 (and ISO, and most other control framework perspectives).  The company OP is working for can state "We do not require these controls on contractors without production access" and that is totally fine for SOC2.  Pushing back on the agent requirement is totally reasonable!</p>
]]></description><pubDate>Fri, 17 Dec 2021 13:40:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=29591924</link><dc:creator>too_pricey</dc:creator><comments>https://news.ycombinator.com/item?id=29591924</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29591924</guid></item><item><title><![CDATA[New comment by too_pricey in "When pop history bombs: a response to Malcolm Gladwell"]]></title><description><![CDATA[
<p>I'm with you.  The focus on this line also ignores context.<p>Gladwell is directly quoting Nassim Taleb, and openly says how little he follows the math Taleb discusses earlier in the same chapter.  The point is "Look at how smart Taleb is, I don't even know what half these words mean", he was never trying to understand the math or imply he did.  In that context mis-transcribing eigenvalues doesn't feel nearly as damning as it's made out to be around these parts?</p>
]]></description><pubDate>Thu, 17 Jun 2021 06:24:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=27536668</link><dc:creator>too_pricey</dc:creator><comments>https://news.ycombinator.com/item?id=27536668</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27536668</guid></item><item><title><![CDATA[New comment by too_pricey in "Signal is having technical difficulties"]]></title><description><![CDATA[
<p>They're a non-profit, so their financials are publicly disclosed.  ProPublica only has it as recently as 2018, but here was the financials then: <a href="https://projects.propublica.org/nonprofits/display_990/824506840/12_2019_prefixes_82-86%2F824506840_201812_990_2019121216951146" rel="nofollow">https://projects.propublica.org/nonprofits/display_990/82450...</a></p>
]]></description><pubDate>Fri, 15 Jan 2021 18:44:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=25794510</link><dc:creator>too_pricey</dc:creator><comments>https://news.ycombinator.com/item?id=25794510</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=25794510</guid></item><item><title><![CDATA[New comment by too_pricey in "Launch HN: Yotta Savings (YC S20) – Behavioral psychology to help people save"]]></title><description><![CDATA[
<p>How are ya'll planning to adjust to changes in interest rates?  Will prizes become lower, rarer, will the base/worst case interest rate change first, etc?<p>For this to have the societal impact ya'll seem to want, it's going to need high usage from people who probably have little experience with the changes in the Fed rate and its impact on savings accounts.  You obviously need to adjust to this yourself, but I can see changes in lottery odds (or changes in prize value) as being aggravating to users.</p>
]]></description><pubDate>Fri, 10 Jul 2020 04:08:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=23788047</link><dc:creator>too_pricey</dc:creator><comments>https://news.ycombinator.com/item?id=23788047</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=23788047</guid></item></channel></rss>