<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: zar1048576</title><link>https://news.ycombinator.com/user?id=zar1048576</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 30 Jul 2026 05:12:28 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=zar1048576" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by zar1048576 in "Claude Mythos: The System Card"]]></title><description><![CDATA[
<p>I think we are in largely uncharted territory here, especially given the implications. Is Anthropic's approach optimal? Probably not. But given the stakes involved, gating access seems like a reasonable place to start.<p>I'm curious about how gated access actually holds over time, especially given that historically with dual-use capabilities containment tends to erode, whether through leaks, independent rediscovery, or gradual normalization of access.</p>
]]></description><pubDate>Mon, 13 Apr 2026 17:15:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=47755120</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47755120</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47755120</guid></item><item><title><![CDATA[New comment by zar1048576 in "Axios compromised on NPM – Malicious versions drop remote access trojan"]]></title><description><![CDATA[
<p>In case it helps, we open-sourced a tool to audit dependencies for this kind of supply-chain issue. The motivation was that there is a real gap between classic “known vulnerability” scanning and packages whose behavior has simply turned suspicious or malicious. We also use AI to analyze code and dependency changes for more novel or generic malicious behavior that traditional scanners often miss.<p>Project: <a href="https://point-wild.github.io/who-touched-my-packages/" rel="nofollow">https://point-wild.github.io/who-touched-my-packages/</a></p>
]]></description><pubDate>Tue, 31 Mar 2026 07:37:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47583943</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47583943</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47583943</guid></item><item><title><![CDATA[New comment by zar1048576 in "Universal Claude.md – cut Claude output tokens"]]></title><description><![CDATA[
<p>I think that concern is valid in general terms, but it’s not clear to me that it applies here.<p>The goal here seems to be removing low-value output; e.g., sycophancy, prompt restatement, formatting noise, etc., which is different than suppressing useful reasoning. In that case shorter outputs do not necessarily mean worse answers.<p>That said, if you try to get the model to provide an answer before providing any reasoning, then I suspect that may sometimes cause a model to commit to a direction prematurely.</p>
]]></description><pubDate>Tue, 31 Mar 2026 02:59:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=47582251</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47582251</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47582251</guid></item><item><title><![CDATA[New comment by zar1048576 in "Learn Claude Code by doing, not reading"]]></title><description><![CDATA[
<p>Have had similar issues with costs sometimes being all over the map. I suspect that the major providers will figure this out as it’s an important consideration in the enterprise setting</p>
]]></description><pubDate>Tue, 31 Mar 2026 02:39:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=47582135</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47582135</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47582135</guid></item><item><title><![CDATA[New comment by zar1048576 in "Vulnerability research is cooked"]]></title><description><![CDATA[
<p>My sense is that the asymmetry is non-trivial issue here. In particular, a threat actor needs one working path, defenders need to close all of them.  In practice, patching velocity is bounded by release cycles, QA issues / regression risk, and a potentially large number of codebases that need to be looked at.</p>
]]></description><pubDate>Mon, 30 Mar 2026 20:41:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=47579464</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47579464</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47579464</guid></item><item><title><![CDATA[New comment by zar1048576 in "The Cognitive Dark Forest"]]></title><description><![CDATA[
<p>I definitely agree w/ you that big organizations are generally better able to navigate the enterprise sales process, but mainy trying to say that customers might choose to work with a bigger company's products for reasons that typically go way beyond that (e.g., better integrations, support resources, etc.).</p>
]]></description><pubDate>Mon, 30 Mar 2026 17:07:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=47576941</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47576941</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47576941</guid></item><item><title><![CDATA[New comment by zar1048576 in "Quantum frontiers may be closer than they appear"]]></title><description><![CDATA[
<p>My sense is that if a threat actor were able to build a quantum computer to the scale of being able to compromise public-key primitives based on the difficulty of integer factorization and discrete logarithms under the key sizes used in practice today, one of the highest-valued targets will be Bitcoin.</p>
]]></description><pubDate>Mon, 30 Mar 2026 16:29:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=47576378</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47576378</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47576378</guid></item><item><title><![CDATA[New comment by zar1048576 in "Quantum frontiers may be closer than they appear"]]></title><description><![CDATA[
<p>Q-day estimates are sensitive to several factors; e.g., hardware qubit counts, error correction overhead, and algorithmic efficiency (e.g., better factoring approaches could compress the timeline meaningfully without any hardware breakthrough).<p>Migration complexity side is also not straightforward. Cryptographic primitives tend to be deeply embedded in ways that are not always easy to find. FWIW, we built a free scanning tool for developers to find and remediate cryptographic vulnerabilities in their repos (still in beta: <a href="https://app.threatpoint.com" rel="nofollow">https://app.threatpoint.com</a>).<p>2029 might be conservative or optimistic depending on which variable moves first.</p>
]]></description><pubDate>Mon, 30 Mar 2026 16:22:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=47576297</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47576297</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47576297</guid></item><item><title><![CDATA[New comment by zar1048576 in "Coding agents could make free software matter again"]]></title><description><![CDATA[
<p>I wonder if there will be a different phenomena — namely everyone just developing their own personal version of what they want rather than relying on what someone else built. Nowadays, if the core functionality is straightforward enough, I find that I just end up building it myself so I can tailor it to my exact needs. It takes less time than trying to understand and adapt someone else’s code base, especially if it’s (mostly) AI generated and contains a great deal of code slop.</p>
]]></description><pubDate>Mon, 30 Mar 2026 01:22:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=47569374</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47569374</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47569374</guid></item><item><title><![CDATA[New comment by zar1048576 in "There is no spoon – A software engineers primer for demystified ML"]]></title><description><![CDATA[
<p>Nice weekend project! Even though there are copious resources out there (textbooks, videos, etc.), those may not appeal to everyone. People have different preferred modalities for consuming information and there is always value in (correctly) reframing concepts in a way that can be better understood by people who don’t resonate with traditional textbooks and YouTube videos. I’m
glad you found a formulation that works for you, and judging by the number of upvotes, it resonated with others as well. At the very least, I’m sure that working on this improved your understanding as well!</p>
]]></description><pubDate>Mon, 30 Mar 2026 01:07:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=47569276</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47569276</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47569276</guid></item><item><title><![CDATA[New comment by zar1048576 in "ChatGPT won't let you type until Cloudflare reads your React state"]]></title><description><![CDATA[
<p>Definitely miss those!</p>
]]></description><pubDate>Mon, 30 Mar 2026 00:59:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=47569219</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47569219</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47569219</guid></item><item><title><![CDATA[New comment by zar1048576 in "The Cognitive Dark Forest"]]></title><description><![CDATA[
<p>I don’t know if that’s necessarily true. I do think that a big part of enterprise sales involves building a comprehensive solution that works well within the customer’s ecosystem. Start-ups usually tend to build point products, which have value, but are still missing functionality (even if that functionality is not scintillating) that customers really desire to easily deploy and maintain solutions. Also, customers do care about things like stability of their vendors and the level of available support.</p>
]]></description><pubDate>Mon, 30 Mar 2026 00:53:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=47569178</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47569178</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47569178</guid></item><item><title><![CDATA[New comment by zar1048576 in "Everything old is new again: memory optimization"]]></title><description><![CDATA[
<p>I agree with this. What you focus on depends on the circumstances. I believe PaulG likes to say that premature optimization is the root of all evil. Early on, you’re trying to ship and get a functioning product out the door — if spending a bit of money on extra RAM at that time helps you, it’s worth it. Over time, as you are trying to optimize, it makes sense to think more about memory management, etc.</p>
]]></description><pubDate>Sat, 28 Mar 2026 20:00:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=47557709</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47557709</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47557709</guid></item><item><title><![CDATA[New comment by zar1048576 in "AI bug reports went from junk to legit overnight, says Linux kernel czar"]]></title><description><![CDATA[
<p>I suspect the big jump came from the release of Claude Opus 4.5/4.6 and GPT-5.x-Codex between Nov ‘25 and Feb ‘26, which were trained with heavy reinforcement learning on long coding projects, rewarding only real success (like running code, using terminals, self-fixing bugs, and passing tests) while adding better memory for huge codebases and extra coding-specific training.</p>
]]></description><pubDate>Sat, 28 Mar 2026 13:20:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=47554346</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47554346</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47554346</guid></item><item><title><![CDATA[New comment by zar1048576 in "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised"]]></title><description><![CDATA[
<p>Definitely. But I think the nature of that impact is not entirely clear. In the legal context, LLMs are also hallucinating extensively, citing made up case law, etc. It’s not yet clear whether they are potentially solving one problem, while introducing many others.</p>
]]></description><pubDate>Sat, 28 Mar 2026 12:50:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=47554125</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47554125</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47554125</guid></item><item><title><![CDATA[New comment by zar1048576 in "We rewrote JSONata with AI in a day, saved $500k/year"]]></title><description><![CDATA[
<p>Fixing a bug is in the wheelhouse of AI to the extent that the fix can be verified — since there is a clear objective function. The real question is whether there are unintended side effects (e.g., new bugs that get introduced) or whether the test cases are comprehensive enough to determine whether the fix worked.</p>
]]></description><pubDate>Sat, 28 Mar 2026 12:33:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=47553999</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47553999</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47553999</guid></item><item><title><![CDATA[New comment by zar1048576 in "We rewrote JSONata with AI in a day, saved $500k/year"]]></title><description><![CDATA[
<p>+1 This is the core question to ask.</p>
]]></description><pubDate>Sat, 28 Mar 2026 12:28:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=47553958</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47553958</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47553958</guid></item><item><title><![CDATA[New comment by zar1048576 in "My minute-by-minute response to the LiteLLM malware attack"]]></title><description><![CDATA[
<p>I suspect that for a nation-state type threat actor, this wouldn’t be much of a deterrent. Any type of reputation system like this would work to a point until motivated threat actors find a way to game it.</p>
]]></description><pubDate>Sat, 28 Mar 2026 12:12:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=47553861</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47553861</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47553861</guid></item><item><title><![CDATA[New comment by zar1048576 in "Namespace: We've raised $23M to build the compute layer for code"]]></title><description><![CDATA[
<p>It does mean something to me, but perhaps not as profound as whoever coined the term was hoping!</p>
]]></description><pubDate>Sat, 28 Mar 2026 12:02:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=47553802</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47553802</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47553802</guid></item><item><title><![CDATA[New comment by zar1048576 in "MIT 15.393 – Nuts and Bolts of New Ventures (2026)"]]></title><description><![CDATA[
<p>Thanks for sharing. Can’t believe he’s still teaching that class after two and a half decades!</p>
]]></description><pubDate>Sat, 28 Mar 2026 11:50:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=47553727</link><dc:creator>zar1048576</dc:creator><comments>https://news.ycombinator.com/item?id=47553727</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47553727</guid></item></channel></rss>