<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: zrm</title><link>https://news.ycombinator.com/user?id=zrm</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 27 Aug 2026 09:42:24 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=zrm" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by zrm in "When str.lower() is a security vulnerability in Python"]]></title><description><![CDATA[
<p>How does the customer service rep tell that a name with some Unicode gubbins is an attack rather than a customer from Juárez or 서울? Having a busy hand copy and paste the attacker-provided string into the system doesn't get you out of it.</p>
]]></description><pubDate>Wed, 26 Aug 2026 07:42:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=49445324</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=49445324</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49445324</guid></item><item><title><![CDATA[New comment by zrm in "Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing"]]></title><description><![CDATA[
<p>> Any stenographic system that you have the code for can be trivially defeated.<p>They're giving you an oracle regardless, which is almost as good. Take LLM output, make some modification, ask the detector if it's LLM output, repeat until you learn what kind of changes you have to make to defeat it.<p>Or don't even bother learning what to do, just make arbitrary changes until it says it's not, so when the person they're submitting to does the same check it says the same thing.</p>
]]></description><pubDate>Mon, 17 Aug 2026 10:15:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=49328692</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=49328692</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49328692</guid></item><item><title><![CDATA[New comment by zrm in "Concurrency, interactivity, mutability, choose two"]]></title><description><![CDATA[
<p>> we're approaching a time where a single processor has hundreds of threads<p>Approaching? EPYC 9996 has 512 threads. EPYC 9754 had 256 threads three years ago.</p>
]]></description><pubDate>Thu, 30 Jul 2026 11:30:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=49108552</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=49108552</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49108552</guid></item><item><title><![CDATA[New comment by zrm in "Hetzner Price Adjustment"]]></title><description><![CDATA[
<p>It seems like what's missing here is lower cost plans, because the <i>existing</i> plans had been fairly affordable, but now they're basically triple.<p>The least expensive one seems to be CPX11, old price $6.99, new price $20.49. That's 2GB RAM, 40GB SSD. RAM and SSD are now much more expensive, fair enough, but maybe I don't need all that for my mostly-idle VM, so then where's the plan with ~0.67GB RAM and ~13GB SSD for the old price?</p>
]]></description><pubDate>Mon, 15 Jun 2026 19:26:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48545882</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48545882</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48545882</guid></item><item><title><![CDATA[New comment by zrm in "Motorola effectively bricked its entire line of WiFi routers without explanation"]]></title><description><![CDATA[
<p>> I did not.<p>This is the exact quote:<p>> And at least for connected devices at home, a dedicated app can have lower friction for initial setup for the "I'm not a computer person" crowd than other alternatives do.<p>What good does it do you to dispute that you implied it as a justification for the status quo when your error is contained in the part you're not disputing?</p>
]]></description><pubDate>Wed, 10 Jun 2026 07:04:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=48472525</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48472525</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48472525</guid></item><item><title><![CDATA[New comment by zrm in "Motorola effectively bricked its entire line of WiFi routers without explanation"]]></title><description><![CDATA[
<p>You made the claim that companies require apps because it has lower friction for ordinary users. That claim is in error.<p>The implication that there is nothing anyone can do to improve the existing state of affairs is also incorrect.</p>
]]></description><pubDate>Sun, 07 Jun 2026 07:13:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48432619</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48432619</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48432619</guid></item><item><title><![CDATA[New comment by zrm in "Motorola effectively bricked its entire line of WiFi routers without explanation"]]></title><description><![CDATA[
<p>> And at least for connected devices at home, a dedicated app can have lower friction for initial setup for the "I'm not a computer person" crowd than other alternatives do.<p>For a <i>router</i>? This is the device that you will often not have internet access with which to download an app until after it's configured. Many people have wired internet specifically because they live somewhere with poor cellular reception. Meanwhile the device can give out DHCP and use the standard captive portal mechanisms to automatically direct any client device to its configuration page.</p>
]]></description><pubDate>Sun, 07 Jun 2026 01:45:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=48430955</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48430955</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48430955</guid></item><item><title><![CDATA[New comment by zrm in "I tried to make Claude make me money on open-source bounties"]]></title><description><![CDATA[
<p>You only need things like that for non-iterated games. A company that gets a reputation for keeping the money when it's a real bug would stop getting real bug reports.</p>
]]></description><pubDate>Sun, 17 May 2026 03:46:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48165891</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48165891</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48165891</guid></item><item><title><![CDATA[New comment by zrm in "I tried to make Claude make me money on open-source bounties"]]></title><description><![CDATA[
<p>You don't have to determine if it's an AI or not. If AI finds a real bug then it can get the bounty. If a human pays to make you read artisanal hand-crafted word salad then they don't get a refund. Real bugs get the bounty, imaginary bugs pay the fee.</p>
]]></description><pubDate>Sun, 17 May 2026 03:28:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48165810</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48165810</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48165810</guid></item><item><title><![CDATA[New comment by zrm in "I tried to make Claude make me money on open-source bounties"]]></title><description><![CDATA[
<p>Bounties already have that whenever you reject one for being nothing.</p>
]]></description><pubDate>Sat, 16 May 2026 23:47:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48164825</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48164825</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48164825</guid></item><item><title><![CDATA[New comment by zrm in "I tried to make Claude make me money on open-source bounties"]]></title><description><![CDATA[
<p>Just require people submitting a bounty to post an evaluation fee. If it's a real bug they get a refund and the bounty. If it's AI slop, you keep the evaluation fee.</p>
]]></description><pubDate>Sat, 16 May 2026 23:39:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48164768</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48164768</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48164768</guid></item><item><title><![CDATA[New comment by zrm in "Linux gaming is faster because Windows APIs are becoming Linux kernel features"]]></title><description><![CDATA[
<p>It seems like what this needs is the return of video arcades.<p>Fill a room at the mall with Linux boxen with midrange GPUs and fiber internet and the sort of keyboards you can clean with pressurized water. Charge an entry fee and then sell pizza, cheetos, coffee, soda and beer. Open at 11AM and close at sunrise.<p>Then publish the public IPs used by the arcade-owned machines at each location in the chain and use different public IPs for the customer WiFi. No DRM nonsense, just a way to know you're playing with someone at the arcade where the management doesn't allow cheats on their machines.</p>
]]></description><pubDate>Thu, 14 May 2026 04:20:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=48131062</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48131062</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48131062</guid></item><item><title><![CDATA[New comment by zrm in "CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq"]]></title><description><![CDATA[
<p>There are two different kinds of updates.<p>One is security updates and bug fixes. These need to fix the problem with the smallest change to minimize the amount of possible breakage, because the code is <i>already</i> vulnerable/broken in production and needs to be updated <i>right now</i>. These are the updates stable gets.<p>The other is changes and additions. They're both more likely to break things and less important to move into production the same day they become public.<p>You don't have to wait until testing is released as stable to run it in your test environment. You can find out about the changes the next release will have immediately, in the test environment, and thereby have plenty of time to address any issues <i>before</i> those changes move into production.</p>
]]></description><pubDate>Tue, 12 May 2026 20:35:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48114168</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48114168</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48114168</guid></item><item><title><![CDATA[New comment by zrm in "CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq"]]></title><description><![CDATA[
<p>> That whole model dates to before automated testing was even really a thing, and no one knew how to do QA; your QA was all the people willing to run your code and report bugs, and that took time.<p>That's not what it's about.<p>What it's about is, newer versions change things. A newer version of OpenSSH disables GSSAPI by default when an older version had it enabled. You don't want that as an automatic update because it will break in production for anyone who is actually using it. So instead the change goes into the testing release and the user discovers that in their test environment before rolling out the new release into production.<p>> On top of that, the backport model heavily discourages the kinds of refactorings and architectural cleanups that would address bugs systemically and encourage a whack-a-mole approach - because in the backport model, people want fixes they can backport.<p>They're not alternatives to each other. The stable release gets the backported patch, the next release gets the refactor.<p>But that's also why you <i>want</i> the stable release. The refactor is a larger change, so if it breaks something you want to find it in test rather than production.</p>
]]></description><pubDate>Tue, 12 May 2026 20:09:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48113771</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48113771</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48113771</guid></item><item><title><![CDATA[New comment by zrm in "CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq"]]></title><description><![CDATA[
<p>They can block traffic to update servers so the computers behind the router <i>aren't</i> all patched up, then exploit them. They also get access to all the IoT devices on the internal network. They can also use your router as a proxy so their scraping/attack traffic comes from your IP address instead of theirs.<p>It's definitely bad.</p>
]]></description><pubDate>Tue, 12 May 2026 19:44:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=48113422</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48113422</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48113422</guid></item><item><title><![CDATA[New comment by zrm in "CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq"]]></title><description><![CDATA[
<p>They're not going to put a newer version in stable. The way stable gets newer versions of things is that you get the newer version into testing and then every two years testing becomes stable and stable becomes oldstable, at which point the newer version from testing becomes the version in stable.<p>The thing to complain about is if the version in <i>testing</i> is ancient.</p>
]]></description><pubDate>Tue, 12 May 2026 19:31:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=48113263</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48113263</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48113263</guid></item><item><title><![CDATA[New comment by zrm in "Postmortem: TanStack NPM supply-chain compromise"]]></title><description><![CDATA[
<p>For that you really only need CAP_NET_BIND_SERVICE.<p>The bigger issue is that if you want to install or update system-wide packages, many of those will be <i>used by</i> privileged processes. Suppose you want to update /bin/sh. Even if the only permission you had is to write binaries, that'll get you root.</p>
]]></description><pubDate>Tue, 12 May 2026 10:08:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48106210</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48106210</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48106210</guid></item><item><title><![CDATA[New comment by zrm in "If AI writes your code, why use Python?"]]></title><description><![CDATA[
<p>> But if you want to participate in the writing, debugging, and maintenance, it has to be in a language that a human can read.<p>I think the idea is that languages like Python and JavaScript make it easier for humans to write the initial implementation, whereas the "hard" languages from the perspective of creating the minimum viable product are the ones that make it easier for humans to maintain the code, and this has historically been a major trade off.<p>Whereas if you have the AI write the initial implementation...</p>
]]></description><pubDate>Tue, 12 May 2026 05:37:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=48104584</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48104584</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48104584</guid></item><item><title><![CDATA[New comment by zrm in "Motherboard sales 'collapse' amid unprecedented shortages fueled by AI"]]></title><description><![CDATA[
<p>"When you thrash them" is kind of the issue. There are ten year old business desktops with a <10W idle power consumption. If your use for it is to have something to rsync files to and host your personal website and the like, even old hardware is going to average 99% idle. There is no meaningful power savings from newer hardware unless you're consistently putting it under significant load.<p>Some of the newer hardware is actually worse because the idle power consumption of PCs since around 2010 is determined in significant part by the low-load efficiency of the power supply. Brand new machines with the wrong power supply can use several times as much power at idle as ten year old machines with the right power supply. Annoyingly, power supply efficiency <i>at idle</i> is rarely documented so the only thing to do is measure it.</p>
]]></description><pubDate>Fri, 08 May 2026 10:08:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=48061020</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48061020</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48061020</guid></item><item><title><![CDATA[New comment by zrm in "Motherboard sales 'collapse' amid unprecedented shortages fueled by AI"]]></title><description><![CDATA[
<p>> You cannot utilize that type of speed with a Mac Mini.<p>Mostly because the base Mini has Thunderbolt 4 which maxes out at 40Gbps. Anything with a PCIe 4.0 x16 slot will take a 100Gbps NIC. 100Gbps is around 10GBps (8 bits per byte plus encapsulation overhead). Desktop CPUs can do AES-GCM at 2.5GBps+ per core and have up to 16 cores and around 50GBps of memory bandwidth (dual channel DDR4-3200), so the NIC still seems like the bottleneck.</p>
]]></description><pubDate>Thu, 07 May 2026 21:57:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48055670</link><dc:creator>zrm</dc:creator><comments>https://news.ycombinator.com/item?id=48055670</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48055670</guid></item></channel></rss>