<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: wakamoleguy</title><link>https://news.ycombinator.com/user?id=wakamoleguy</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 12 Sep 2026 07:58:48 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=wakamoleguy" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by wakamoleguy in "Claude is only available to people over 18 years"]]></title><description><![CDATA[
<p>These statistics don't necessarily imply that the programs don't improve the situation, only that mental health outcomes are worsening faster than programs are improving them. The existence of support programs could also encourage more measurement of mental health issues, which says nothing about the ground truth.</p>
]]></description><pubDate>Fri, 11 Sep 2026 18:58:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49663506</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=49663506</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49663506</guid></item><item><title><![CDATA[New comment by wakamoleguy in "Every Fucking Website (2020)"]]></title><description><![CDATA[
<p>On the extreme side, things like blackmail and fraud are generally illegal, even if they can make you money. Most of these dark patterns that "work" tend to follow a similar pattern: by taking advantage of the target, one can extract more money from them.<p>I would possibly be a terrible salesperson, because these all give me the ick. Your product should provide an offer of genuine value.</p>
]]></description><pubDate>Fri, 14 Aug 2026 16:28:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=49300996</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=49300996</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49300996</guid></item><item><title><![CDATA[New comment by wakamoleguy in "Now we have a timeline of the OpenAI accidental attack against Hugging Face"]]></title><description><![CDATA[
<p>In a typical office environment, the correct response to “I don’t have access to this Google Doc” is to ask for access from the person who sent you the link. In another context, it could be fair to think “Hmm, this is some sort of capture the flag challenge, and obtaining access is the point of the assignment.” That assessment separates what we’d consider reasonable from way out of line.<p>I do wonder what this means for AI agents longer term. In a world where we humans already struggle with truth and misinformation, what happens when you can easily (intentionally or accidentally) spin up a cohort of fanatical believers to pursue any given conspiracy theory?</p>
]]></description><pubDate>Sat, 08 Aug 2026 12:01:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49220998</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=49220998</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49220998</guid></item><item><title><![CDATA[LLMs Are Surprisingly Bad Blog Authors]]></title><description><![CDATA[
<p>Article URL: <a href="https://wakamoleguy.com/p/llms-are-surprisingly-bad-blog-authors">https://wakamoleguy.com/p/llms-are-surprisingly-bad-blog-authors</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48990923">https://news.ycombinator.com/item?id=48990923</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 21 Jul 2026 11:38:17 +0000</pubDate><link>https://wakamoleguy.com/p/llms-are-surprisingly-bad-blog-authors</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=48990923</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48990923</guid></item><item><title><![CDATA[New comment by wakamoleguy in "Don't make gates optional, make them flexible"]]></title><description><![CDATA[
<p>That's a really good question. This may also end up depending on the level of trust within the team. One thing I didn't call out is that an "optional gate" can still just be checked by sending a DM, like "Hey, do you think I need this check on this project?" So in high trust teams the differences are small.<p>On lower trust teams, I could see the cycle you mention crop up more. I'm not sure of the answer, but I don't think it is to force everybody through the onerous process out of perceived fairness. Any ideas on how to bring visibility to that failure mode?</p>
]]></description><pubDate>Tue, 30 Jun 2026 19:44:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=48738222</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=48738222</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48738222</guid></item><item><title><![CDATA[New comment by wakamoleguy in "Tidal AI Policy"]]></title><description><![CDATA[
<p>There is only zero incentive if the filter detects AI music reliably. It's still a race between effective detection and cost to generate content, isn't it?</p>
]]></description><pubDate>Mon, 29 Jun 2026 13:57:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48719372</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=48719372</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48719372</guid></item><item><title><![CDATA[Don't make gates optional, make them flexible]]></title><description><![CDATA[
<p>Article URL: <a href="https://wakamoleguy.com/p/flexible-gates">https://wakamoleguy.com/p/flexible-gates</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48692330">https://news.ycombinator.com/item?id=48692330</a></p>
<p>Points: 50</p>
<p># Comments: 8</p>
]]></description><pubDate>Fri, 26 Jun 2026 21:40:05 +0000</pubDate><link>https://wakamoleguy.com/p/flexible-gates</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=48692330</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48692330</guid></item><item><title><![CDATA[New comment by wakamoleguy in "The Future of Email"]]></title><description><![CDATA[
<p>> A person reading a suspicious email might notice that the sender’s domain has an extra character, or that something about the request feels off. An AI assistant scanning your inbox for items that need action may not slow down to check those things.<p>I don't quite buy this in either direction (although they are both couched as possibilities, which makes it a pretty safe statement). Humans might notice, but years of annual mandated phishing trainings has led me to believe that humans as a whole are generally not great at noticing.<p>AI agents OTOH mostly do as they are prompted. If the human prompting them tells them to check these things, they will likely check much more consistently than any human. If the prompt doesn't say to check, the agent won't. But that again falls back to what the human might or might not think about.</p>
]]></description><pubDate>Fri, 12 Jun 2026 14:57:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48505031</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=48505031</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48505031</guid></item><item><title><![CDATA[New comment by wakamoleguy in "Moving away from Tailwind, and learning to structure my CSS"]]></title><description><![CDATA[
<p>What a strange take. LLMs produce plausibly correct output, which is exactly where plain JavaScript and DOM manipulation will result in a spaghetti mess.<p>Frameworks like React that add structure to the data flow, component encapsulation, and a huge repertoire of patterns to train on, plus Typescript for immediate compile-time feedback loops… those are what LLMs thrive on.</p>
]]></description><pubDate>Sat, 16 May 2026 13:51:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48160274</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=48160274</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48160274</guid></item><item><title><![CDATA[New comment by wakamoleguy in "They Said It Would Cost $54M. We Said "No Thanks.""]]></title><description><![CDATA[
<p>I disagree. Especially with AI, it’s far too easy to generate and insert an image with no time, energy, or eye for detail.<p>Authors do it because it supposedly leads to better engagement, shows up bigger on social media, and breaks up the text. But generally, unless the visual content meaningfully adds to the text content, users will largely ignore it.</p>
]]></description><pubDate>Thu, 14 May 2026 12:17:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=48134336</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=48134336</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48134336</guid></item><item><title><![CDATA[New comment by wakamoleguy in "Reviving BrowserID in 2026"]]></title><description><![CDATA[
<p>Thanks! I have been learning about FedCM recently, but I need to read more. My understanding is that it requires the relying party to allowlist which IdPs it trusts, is that correct? That always seemed like it would make it gravitate towards social sign-ins, and harder for self-hosted email domains to participate.<p>I haven't come across the Email Verification Protocol yet, will take a look! At a glance, the flow seems almost identical to BrowserID. I'm curious how the UX looks.</p>
]]></description><pubDate>Sun, 26 Apr 2026 16:14:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47911421</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=47911421</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47911421</guid></item><item><title><![CDATA[New comment by wakamoleguy in "Reviving BrowserID in 2026"]]></title><description><![CDATA[
<p>That’s real, yeah. I also remember a couple concerns around that privacy as well. One being that if your IdP controls your email, they could probably figure out what sites your communicating with anyways. And perhaps a timing issue with when relying parties fetch the public key to verify assertions?<p>For bespoke projects, a lot of the privacy concerns go away once I’m using my own authentication in the first place (I control the full stack). So then the value would come more from federation (which is hard to bootstrap) or developer experience. I do still think BrowserID has something going for it there, potentially.<p>I do wonder if I’ll miss the centralized session management, though. I’m building this IdP to be modular, so I could try a different protocol on top of the user management core down the road.<p>Thanks for sharing!</p>
]]></description><pubDate>Sun, 26 Apr 2026 12:31:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=47909804</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=47909804</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47909804</guid></item><item><title><![CDATA[New comment by wakamoleguy in "Reviving BrowserID in 2026"]]></title><description><![CDATA[
<p>That’s how this project started, with trying to take the Persona repo and bringing it up to date. There were two challenges… first, don’t underestimate how hard it is to take a decade old Node repo and run it today. There are no types, many dependencies don’t work on modern Node versions, and upgrading them all together is a nightmare. BrowserID is not a very complex protocol, so rebuilding it gave me an opportunity to use new tools (TypeScript, Bun, Jose for crypto).<p>And the second reason is that I don’t want to try to be Mozilla Persona. The fallback IdP is a great idea, but y’all have no reason to trust me to be the one to run it. I can sidestep that issue for my own needs today, avoid the complexity of sending emails, and if for some reason this project does pick up any steam we can figure out whether/how to add that functionality down the road.</p>
]]></description><pubDate>Sun, 26 Apr 2026 12:15:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=47909725</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=47909725</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47909725</guid></item><item><title><![CDATA[New comment by wakamoleguy in "Reviving BrowserID in 2026"]]></title><description><![CDATA[
<p>I’ve tried it in the past. This was a few years ago, so it’s possible it’s changed since then. But the reason I’m not choosing it for myself today is that it relies on either Sign in with Google (fine) or magic links to verify the user. I really don’t want to manage email delivery for this project, which is admittedly a stubborn personal choice. It just adds a lot of complexity that I don’t care to spend time on for hobby projects.</p>
]]></description><pubDate>Sun, 26 Apr 2026 12:05:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=47909671</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=47909671</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47909671</guid></item><item><title><![CDATA[New comment by wakamoleguy in "Reviving BrowserID in 2026"]]></title><description><![CDATA[
<p>The biggest one I’ve come across is the ability to manage and revoke sessions from a centralized location. With BrowserID, you can’t just sign out of your IdP and expect all relying parties’ sessions to invalidate. Instead, BrowserID asserts that you controlled the email at a point in time, and then it’s up to the site to decide how to manage the session afterwards.<p>3rd party cookie blocking makes this worse, since it’s difficult to silently refresh your session by checking with the IdP behind the scenes. I believe Auth0 uses a hidden iframe for this, which uses 3rd party cookies and looks a lot like a tracking pixel. Without that refresh mechanism, though, relying parties are pushed to have longer lived sessions, which makes the lack of a global revocation worse.</p>
]]></description><pubDate>Sun, 26 Apr 2026 11:59:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=47909628</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=47909628</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47909628</guid></item><item><title><![CDATA[Reviving BrowserID in 2026]]></title><description><![CDATA[
<p>Article URL: <a href="https://wakamoleguy.com/p/reviving-browserid-in-2026">https://wakamoleguy.com/p/reviving-browserid-in-2026</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47906770">https://news.ycombinator.com/item?id=47906770</a></p>
<p>Points: 31</p>
<p># Comments: 13</p>
]]></description><pubDate>Sun, 26 Apr 2026 02:38:51 +0000</pubDate><link>https://wakamoleguy.com/p/reviving-browserid-in-2026</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=47906770</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47906770</guid></item><item><title><![CDATA[New comment by wakamoleguy in "Youth Suicides Declined After Creation of National Hotline"]]></title><description><![CDATA[
<p>And yet the data shows that they did decline. I'm sure they could be much better, and the response will vary from state to state.</p>
]]></description><pubDate>Wed, 22 Apr 2026 18:03:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47867076</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=47867076</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47867076</guid></item><item><title><![CDATA[New comment by wakamoleguy in "I wrote to Flock's privacy contact to opt out of their domestic spying program"]]></title><description><![CDATA[
<p>The data ownership is really interesting, as many threads here are going into. I wonder if it's possible to sidestep that entirely, though! Under the CCPA, "personal information" is defined as information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked — directly or indirectly — with a particular consumer or household. That says nothing about ownership.<p>To the extent that Flock is only storing the data on behalf of their customers, I'd understand they wouldn't be required to delete it. But to the extent that they are indexing it, deriving from it, aggregating it across customers, and sharing it via their platform, it seems they should be required to remove that data from those services.<p>But then again, I am not a lawyer!</p>
]]></description><pubDate>Tue, 14 Apr 2026 19:41:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=47770454</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=47770454</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47770454</guid></item><item><title><![CDATA[New comment by wakamoleguy in "One item purchased, ten emails"]]></title><description><![CDATA[
<p>Is there a technical limitation why these never seem to be grouped into a thread? I generally appreciate the updates on my package, but I also value a tidy inbox.</p>
]]></description><pubDate>Wed, 08 Apr 2026 18:49:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=47694542</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=47694542</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47694542</guid></item><item><title><![CDATA[New comment by wakamoleguy in "Shooting down ideas is not a skill"]]></title><description><![CDATA[
<p>These are all risks. Not all risks need to be mitigated, but some can be. Others can be accepted. Saying “Python is too slow for production scale, but our goal is a small proof of concept,” is a valid answer even if it doesn’t “solve” the complaint. And if you don’t even have that answer, then the burden is not your problem. The lack of due diligence is.</p>
]]></description><pubDate>Sun, 05 Apr 2026 02:31:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=47645615</link><dc:creator>wakamoleguy</dc:creator><comments>https://news.ycombinator.com/item?id=47645615</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47645615</guid></item></channel></rss>