<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: winstonwinston</title><link>https://news.ycombinator.com/user?id=winstonwinston</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 05 Sep 2026 09:27:55 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=winstonwinston" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by winstonwinston in "An open DNS recursive service for free security and high privacy"]]></title><description><![CDATA[
<p>> I prefer to run my own local recursive resolver.<p>Used to be fine. I stopped doing it when average TTL dropped to 300 seconds and it takes far too long for my local recursor to get the answer >100ms, when 3rd party resolver delivers in <10ms.</p>
]]></description><pubDate>Fri, 04 Sep 2026 21:53:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=49570688</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49570688</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49570688</guid></item><item><title><![CDATA[New comment by winstonwinston in "An open DNS recursive service for free security and high privacy"]]></title><description><![CDATA[
<p>When I run a mix of CF and Quad9 resolvers, Quad9 was consistently slower in response times when measured. But it didn’t make any perceivable difference in real usage.</p>
]]></description><pubDate>Fri, 04 Sep 2026 21:43:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=49570581</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49570581</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49570581</guid></item><item><title><![CDATA[New comment by winstonwinston in "Discovery of a new OpenAI agent message board"]]></title><description><![CDATA[
<p>A “swarm” and “hijacked” reads like DoS and spam at the very least, doubt any of those is legal in german law.</p>
]]></description><pubDate>Fri, 04 Sep 2026 21:05:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49570195</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49570195</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49570195</guid></item><item><title><![CDATA[New comment by winstonwinston in "Models Don't Go Rogue"]]></title><description><![CDATA[
<p>If they wanted air gapped environment they would’ve it. I mean, if you want to sabotage your trial by hard constraints you can do it, or you do not do it to see interesting results. They even said it that some constraints were disabled for the test.</p>
]]></description><pubDate>Fri, 04 Sep 2026 00:29:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=49558991</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49558991</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49558991</guid></item><item><title><![CDATA[New comment by winstonwinston in "Java is memory efficient [audio]"]]></title><description><![CDATA[
<p>No memory ever wasted, consumes all of it.<p>But this does not seem to be the case anymore. Today I see that eclipse IDE is more memory friendly than Chrome.</p>
]]></description><pubDate>Thu, 03 Sep 2026 22:11:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=49557844</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49557844</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49557844</guid></item><item><title><![CDATA[New comment by winstonwinston in "uv: Deduplicate all files in the wheel cache"]]></title><description><![CDATA[
<p>I can say that I have used pip only and it does a package manager job well, it just works.<p>I’m not sure at what uv excel at but reading comments it seems uv is not only package manager but also venv manager.</p>
]]></description><pubDate>Tue, 01 Sep 2026 19:34:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49526942</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49526942</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49526942</guid></item><item><title><![CDATA[New comment by winstonwinston in "How to get a free .arpa domain"]]></title><description><![CDATA[
<p>Do these free HE assigned IPv6 prefix(es) just remain valid indefinitely even when not actually being used/routed?</p>
]]></description><pubDate>Tue, 01 Sep 2026 18:22:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=49525842</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49525842</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49525842</guid></item><item><title><![CDATA[New comment by winstonwinston in "Debian votes to allow "responsible use of generative AI""]]></title><description><![CDATA[
<p>What a fucked up reality when you need to point out that code contributor is responsible for their code.</p>
]]></description><pubDate>Sat, 29 Aug 2026 16:37:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=49491291</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49491291</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49491291</guid></item><item><title><![CDATA[New comment by winstonwinston in "Apple threat notifications and spyware: what everyone should know"]]></title><description><![CDATA[
<p>Google has been sending some similar alerts long before Apple, those read something like "Government-backed attackers may be trying to steal your password".</p>
]]></description><pubDate>Thu, 27 Aug 2026 15:22:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=49466326</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49466326</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49466326</guid></item><item><title><![CDATA[New comment by winstonwinston in "Six government passport CAs that Python rejects and OpenSSL accepts"]]></title><description><![CDATA[
<p>`Cryptography` is not a Python stdlib:<p><pre><code>  try:
    from cryptography import x509
    from cryptography.hazmat.primitives import hashes
    from cryptography.x509.oid import NameOID
  except ImportError:  # pragma: no cover
    sys.exit("missing dependency: pip install cryptography")
</code></pre>
Then it goes on with a subprocess for openssl for a case that `cryptography` package does not handle.<p>Why not submit issue with `cryptography` project to get it fixed if it is a problem that needs fixing?</p>
]]></description><pubDate>Thu, 27 Aug 2026 14:49:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49465788</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49465788</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49465788</guid></item><item><title><![CDATA[New comment by winstonwinston in "VMs won't contain cyber-capable agents"]]></title><description><![CDATA[
<p>I have no idea what you mean.<p>It is no surprise that known unpatched CVEs will be exploited. Perhaps more effort should be put into shipping fixes faster than writing blogs about exploiting known issues.</p>
]]></description><pubDate>Wed, 26 Aug 2026 17:45:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=49453030</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49453030</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49453030</guid></item><item><title><![CDATA[New comment by winstonwinston in "Migrating a Synology NAS to a UniFi UNAS Pro 8 with Robocopy, SMB Multichannel"]]></title><description><![CDATA[
<p>You could just run multiple rsync processes using different src and dest paths to achieve multiple copy streams. Anyway this would not be likely much faster if rsync is run over encrypted SSH due to CPU performance, compared to unencrypted SMB.</p>
]]></description><pubDate>Mon, 24 Aug 2026 05:49:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=49415630</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49415630</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49415630</guid></item><item><title><![CDATA[New comment by winstonwinston in "How a Texas student blew the whistle on a rogue AI hacking attempt"]]></title><description><![CDATA[
<p>Well, when I go look at the “victim repository”, to me that looks like manufactured persona with pointless vibe codes projects, a test playground so to speak. It does not appear that they actually let it target an actual persona/project.</p>
]]></description><pubDate>Sat, 22 Aug 2026 21:14:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49403939</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49403939</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49403939</guid></item><item><title><![CDATA[New comment by winstonwinston in "Giving an LLM your prod database is easy. Taking access away is the hard part"]]></title><description><![CDATA[
<p>Blog post is displayed for a moment and shortly after the post text is replaced with a cryptic error about regex parsing. I guess it has something to do with Safari javascript engine. Anyway, the current state of web development is so pathetic.</p>
]]></description><pubDate>Sat, 22 Aug 2026 08:33:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49397784</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49397784</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49397784</guid></item><item><title><![CDATA[New comment by winstonwinston in "Every Model Cheats"]]></title><description><![CDATA[
<p>It would loose automagic?<p>In a recent full discloure I was reading about a CVE of an LLM agent, the vendor installed a “secure sandbox VM” and then just shared a host’s filesystem read/write to the agent’s VM.</p>
]]></description><pubDate>Fri, 21 Aug 2026 01:56:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=49382748</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49382748</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49382748</guid></item><item><title><![CDATA[New comment by winstonwinston in "Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub"]]></title><description><![CDATA[
<p>> after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.<p>Unencrypted signing key. They just don’t care anymore.</p>
]]></description><pubDate>Wed, 12 Aug 2026 11:01:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49270503</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49270503</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49270503</guid></item><item><title><![CDATA[New comment by winstonwinston in "Windows 11's built-in Weather app wastes more than 1 GB of RAM"]]></title><description><![CDATA[
<p>> It may be that the 662 MB used by the "Renderer" is shared between many Windows components, so killing that Weather app may not reclaim as much space as you may hope, instead, it would require killing every user of the component, some may be core system apps.<p>Bet one’s ass that “Renderer” sub-process is embed browser engine allocating working memory for rendering of web app page layout.</p>
]]></description><pubDate>Mon, 10 Aug 2026 16:19:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=49245758</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49245758</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49245758</guid></item><item><title><![CDATA[New comment by winstonwinston in "Rust-lang/rust is adopting an LLM policy"]]></title><description><![CDATA[
<p>You can’t be upset because they want to know the truth, seriously. When a project has concerns about generated code, it is for a reason.</p>
]]></description><pubDate>Wed, 05 Aug 2026 09:25:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=49180467</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49180467</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49180467</guid></item><item><title><![CDATA[New comment by winstonwinston in "If technology got better, why did everything get worse?"]]></title><description><![CDATA[
<p>> I think we all know the answer to this: bad incentives.<p>Better technology, worse food quality, more profit.</p>
]]></description><pubDate>Sun, 02 Aug 2026 16:11:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=49145830</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49145830</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49145830</guid></item><item><title><![CDATA[New comment by winstonwinston in "Investigating three real-world incidents in our cybersecurity evaluations"]]></title><description><![CDATA[
<p>The blog post is painfully vague. What usually happens when you publish a package on PyPI is that it will be downloaded tens of times shortly after uploading files by some 3rd-party automatic security scanners which then could “detonate” (install and execute) the package in some sandbox and to log what happens.</p>
]]></description><pubDate>Fri, 31 Jul 2026 02:03:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=49118216</link><dc:creator>winstonwinston</dc:creator><comments>https://news.ycombinator.com/item?id=49118216</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49118216</guid></item></channel></rss>