<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: tptacek</title><link>https://news.ycombinator.com/user?id=tptacek</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 12 Apr 2026 09:16:13 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=tptacek" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by tptacek in "Small models also found the vulnerabilities that Mythos found"]]></title><description><![CDATA[
<p>That's not what they did.</p>
]]></description><pubDate>Sun, 12 Apr 2026 03:29:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=47735897</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47735897</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47735897</guid></item><item><title><![CDATA[New comment by tptacek in "Small models also found the vulnerabilities that Mythos found"]]></title><description><![CDATA[
<p>That is <i>a</i> point. It might even be true. But showing a small model an example of vulnerable code and asking to confirm that it is vulnerable code isn't evidence for that point!</p>
]]></description><pubDate>Sun, 12 Apr 2026 02:23:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=47735650</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47735650</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47735650</guid></item><item><title><![CDATA[New comment by tptacek in "AI Job Loss Tracker"]]></title><description><![CDATA[
<p>This is a brochure site from "The Alliance for Secure AI", which I am unfamiliar with, but whose site gives "AGI weirdo". Am I misreading?<p><a href="https://secureainow.org/" rel="nofollow">https://secureainow.org/</a></p>
]]></description><pubDate>Sun, 12 Apr 2026 00:41:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=47735203</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47735203</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47735203</guid></item><item><title><![CDATA[New comment by tptacek in "Sam Altman's response to Molotov cocktail incident"]]></title><description><![CDATA[
<p>I disagree with almost all of this but I'm not here to single you out.</p>
]]></description><pubDate>Sun, 12 Apr 2026 00:28:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=47735139</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47735139</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47735139</guid></item><item><title><![CDATA[New comment by tptacek in "Sam Altman's response to Molotov cocktail incident"]]></title><description><![CDATA[
<p>By that I meant it didn't read like they were trying to push back on him.</p>
]]></description><pubDate>Sat, 11 Apr 2026 20:51:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=47733932</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47733932</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47733932</guid></item><item><title><![CDATA[New comment by tptacek in "Small models also found the vulnerabilities that Mythos found"]]></title><description><![CDATA[
<p>No, they didn't. They <i>distinguished</i> it, when presented with it. Wildly different problem.</p>
]]></description><pubDate>Sat, 11 Apr 2026 19:35:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47733343</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47733343</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47733343</guid></item><item><title><![CDATA[New comment by tptacek in "Small models also found the vulnerabilities that Mythos found"]]></title><description><![CDATA[
<p>Aisle and Anthropic are literally talking about two different problem spaces.</p>
]]></description><pubDate>Sat, 11 Apr 2026 19:28:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=47733298</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47733298</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47733298</guid></item><item><title><![CDATA[New comment by tptacek in "Sam Altman's response to Molotov cocktail incident"]]></title><description><![CDATA[
<p>There isn't one (much as I might think there should be). Threads about Mangione were also uncivil and activating.</p>
]]></description><pubDate>Sat, 11 Apr 2026 19:13:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=47733198</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47733198</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47733198</guid></item><item><title><![CDATA[New comment by tptacek in "Sam Altman's response to Molotov cocktail incident"]]></title><description><![CDATA[
<p>HN isn't a "science and technology" site.</p>
]]></description><pubDate>Sat, 11 Apr 2026 18:19:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=47732785</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47732785</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47732785</guid></item><item><title><![CDATA[New comment by tptacek in "Sam Altman's response to Molotov cocktail incident"]]></title><description><![CDATA[
<p>You're being nice about it but I think you're inadvertently expressing literally the sentiment Dan was referring to.</p>
]]></description><pubDate>Sat, 11 Apr 2026 18:18:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=47732780</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47732780</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47732780</guid></item><item><title><![CDATA[New comment by tptacek in "Small models also found the vulnerabilities that Mythos found"]]></title><description><![CDATA[
<p><i>Hold on, I misread your comment because I'm knee-jerk about code scanners, which were the bane of my existence for a while. Reworking... and: done. The original comment was just the first graf without the LLM qualification. Sorry about that.</i><p>The general approach without LLMs doesn't work. 50 companies have built products to do exactly what you propose here; they're called static application security testing (SAST) tools, or, colloquially, code scanners. In practice, getting every "suspicious" code pattern in a repository pointed out isn't highly valuable, because every codebase is awash in them, and few of them pan out as actual vulnerabilities (because attacker-controlled data never hits them, or because the missing security constraint is enforced somewhere else in the call chain).<p>Could it work with LLMs? Maybe? But there's a big open question right now about whether hyperspecific prompts make agents more effective at finding vulnerabilities (by sparing context and priming with likely problems) or less effective (by introducing path dependent attractors and also eliminating the likelihood of spotting vulnerabilities not directly in the SAST pattern book).</p>
]]></description><pubDate>Sat, 11 Apr 2026 18:07:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=47732696</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47732696</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47732696</guid></item><item><title><![CDATA[New comment by tptacek in "Small models also found the vulnerabilities that Mythos found"]]></title><description><![CDATA[
<p>If you cut out the vulnerable code from Heartbleed and just put it in front of a C programmer, they will immediately flag it. It's obvious. But it took Neel Mehta to   discover it. What's difficult about finding vulnerabilities isn't properly identifying whether code is mishandling buffers or holding references after freeing something; it's spotting that in the context of a large, complex program, and working out how attacker-controlled data hits that code.<p>It's weird that Aisle wrote this.</p>
]]></description><pubDate>Sat, 11 Apr 2026 17:28:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=47732350</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47732350</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47732350</guid></item><item><title><![CDATA[New comment by tptacek in "Molotov cocktail is hurled at home of Sam Altman"]]></title><description><![CDATA[
<p>They are nothing remotely like "tech bros", is my point.</p>
]]></description><pubDate>Fri, 10 Apr 2026 22:59:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=47724841</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47724841</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47724841</guid></item><item><title><![CDATA[New comment by tptacek in "Molotov cocktail is hurled at home of Sam Altman"]]></title><description><![CDATA[
<p>People in "local politics" are random neighbors, almost none of whom are "in politics" in the colloquial sense.</p>
]]></description><pubDate>Fri, 10 Apr 2026 22:41:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=47724632</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47724632</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47724632</guid></item><item><title><![CDATA[New comment by tptacek in "Molotov cocktail is hurled at home of Sam Altman"]]></title><description><![CDATA[
<p>Mostly just by not being emotionally destabilized by edgy comments, is all.</p>
]]></description><pubDate>Fri, 10 Apr 2026 22:40:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=47724609</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47724609</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47724609</guid></item><item><title><![CDATA[New comment by tptacek in "Molotov cocktail is hurled at home of Sam Altman"]]></title><description><![CDATA[
<p>These are message boards. The obvious sentiment, that firebombing attacks are awful (perhaps cut a little bit with "the perpetrator appears to be someone deeply in need of help) is boring. This is an availability bias issue: the only sentiments that actually spool out into threads are edgy. Once you learn to spot these effects, message boards make a lot more sense and are less jarring.</p>
]]></description><pubDate>Fri, 10 Apr 2026 22:12:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=47724302</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47724302</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47724302</guid></item><item><title><![CDATA[New comment by tptacek in "Molotov cocktail is hurled at home of Sam Altman"]]></title><description><![CDATA[
<p>I operate in at least one social circle that is heavily not-technical (local politics) and I do not see this at all.</p>
]]></description><pubDate>Fri, 10 Apr 2026 22:11:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=47724286</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47724286</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47724286</guid></item><item><title><![CDATA[New comment by tptacek in "Molotov cocktail is hurled at home of Sam Altman"]]></title><description><![CDATA[
<p>There's nothing "un-controversial" about trying to mitigate a firebombing attack with a broad critique of capitalism. It's an edgy take, just own it.</p>
]]></description><pubDate>Fri, 10 Apr 2026 22:10:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47724276</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47724276</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47724276</guid></item><item><title><![CDATA[New comment by tptacek in "Native Instant Space Switching on macOS"]]></title><description><![CDATA[
<p>God damnit I didn't know until 15 seconds ago that the Space-switching animation in macOS was annoying. Thanks a lot!</p>
]]></description><pubDate>Thu, 09 Apr 2026 20:59:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=47710002</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47710002</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47710002</guid></item><item><title><![CDATA[New comment by tptacek in "Netflix Prices Went Up Again – I Bought a DVD Player Instead"]]></title><description><![CDATA[
<p>I wouldn't watch ad-sponsored TV either, but you either want to watch the shows or you don't; your time is extremely valuable! I wouldn't assume the price of the show is that much a factor.</p>
]]></description><pubDate>Thu, 09 Apr 2026 20:50:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=47709837</link><dc:creator>tptacek</dc:creator><comments>https://news.ycombinator.com/item?id=47709837</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47709837</guid></item></channel></rss>