Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dwheeler
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
dwheeler
6mo ago
I suggest this vocal performance: https://youtube.com/watch?v=GggK9SjJpuQ
32.
▲
by
dwheeler
8mo ago
I prefer the term "assistant". It can do some tasks, but today's AI often needs human guidance for good results.
33.
▲
by
dwheeler
8mo ago
I also made a list of tips on writing code with AI, with a special focus on security. Others may find the tips useful. Here they are: https://openssf.org/blog/2026/01/05/ai-software-development-...
34.
▲
by
dwheeler
9mo ago
This has many similarities to the Heartbleed vulnerability: it involves trusting lengths from an attacker, leading to unauthorized revelation of data.
35.
▲
by
dwheeler
10mo ago
Many people use Octave https://octave.org/ which is compatible (generally) with Matlab, supports this simple syntax, and is open source software. Indeed, I've taken at least one class where the instructor asked people
36.
▲
by
dwheeler
11mo ago
That's only true if future improvements are easy to create as past ones, that customers care as much about those improvements, and there are no other differentiators. For example, many companies do well by selling a less capable but mo
37.
▲
by
dwheeler
11mo ago
I love having built-in local natural language translation implemented by AI, which Firefox provides. Local models have different properties than remote properties, and natural language translation is a useful thing. AI should be added
38.
▲
Secure AI/ML-Driven Software Development (LFEL1012) – Free Online Course
(training.linuxfoundation.org)
1 points
by
dwheeler
1y ago
|
1 comments
39.
▲
by
dwheeler
1y ago
The Linux Foundation's Open Source Security Foundation (OpenSSF) has released a free online course "Secure AI/ML-Driven Software Development (LFEL1012)". It discusses protecting your software development environment, cre
40.
▲
by
dwheeler
1y ago
Yes, you need training if you want something good instead of slop. For example, when asked to write functions that can be secure or insecure, 45% of the time they'll do it the insecure way, and this has been stable for years. We in the
41.
▲
Celebrating Five Years of OpenSSF: A Journey Through Open Source Security
(openssf.org)
1 points
by
dwheeler
1y ago
|
1 comments
42.
▲
by
dwheeler
1y ago
Summarizes what's happened in the Open Source Security Foundation (OpenSSF) since its founding five years ago.
43.
▲
by
dwheeler
1y ago
Using AI assistants != Vibe Coding. AI can be a helpful assistant but they are nowhere near ready for letting loose when the results matter.
44.
▲
by
dwheeler
1y ago
Citation needed. I'm not sure what you mean by "Unix specification". But if you mean the international standard POSIX, yes, people care. Red Hat routinely participates in POSIX spec revision. There are a very few deviations w
45.
▲
by
dwheeler
1y ago
Action! is a cool language. However, by design it did not support recursion, directly or indirectly: https://atariwiki.org/wiki/Wiki.jsp?page=Action Variables were assigned constant locations, which made things easier
46.
▲
by
dwheeler
1y ago
Phones should include an AM/FM tuner. Then you can hear local stations, and if you're out of cell range or things go badly, receive broadcasts.
47.
▲
by
dwheeler
1y ago
I don't like the phrase "real coder". It's not clear what it means. I really like the word "assistant" for what we have today. The AI code assistant tools available today, like Claude Code and GitHub Copilot, c
48.
▲
by
dwheeler
1y ago
> Learning how to use LLMs in a coding workflow is trivial. There is no learning curve. You can safely ignore them if they don’t fit your workflows at the moment. I'm sprry, but I disagree with this claim. That is not my experience,
49.
▲
by
dwheeler
1y ago
> The thing that I find amazing about this sub, is that the final hull survived all those trips, and then before the final one let everyone know it was toast, and Stockton ignored it. He was careless with peoples lives, but his sub actua
50.
▲
by
dwheeler
1y ago
The report has many gems about the tragedy. Basically, there were clear physical causes, which in turn were caused by hubris: PHYSICAL CAUSES "4.2.4.4. American Bureau of Shipping (ABS) Classification Society Background" ... "
51.
▲
by
dwheeler
1y ago
James Cameron gave an interview that did a great job explaining the problems. In particular, carbon fiber is great for planes, but a terrible idea for compressive forces like going deep underwater. See: "James Cameron on the OceanGate
52.
▲
by
dwheeler
1y ago
I'm not sure how much this matters. They should measure impact, not reader count. Many reports are written for a narrow audience. That's fine if it provides key information necessary to make a good decision with wide impact.
53.
▲
by
dwheeler
1y ago
Not to the same degree, though, and the arguments for status quo are especially weak. There are reasonable arguments pro and con case-insensitive filenames. Character encoding issues are dwindling, since most systems just use utf-8 for file
54.
▲
by
dwheeler
1y ago
Ah yes, yet ANOTHER vulnerability caused because Linux and most Unixes allow control characters in filenames. This ability's primary purpose appears to be to enable attacks and to make it significantly more difficult to write correct c
55.
▲
by
dwheeler
1y ago
It may not seem like it, but this is impressive progress. Getting a compiler to bootstrap at all is an accomplishment, especially for Rust since that depends on so many things working. Once it can reliably bootstrap, a lot of performance-
56.
▲
by
dwheeler
1y ago
Yes. GNOME and KDE at least coordinate via freedesktop.org. At least they did!
57.
▲
by
dwheeler
1y ago
Yes, the Veritasium episode is great. In short: there's plenty of evidence Amelia Earhart was reckless. I'm sad that she paid with her life, but that is sometimes what happens when you're reckless while using dangerous mach
58.
▲
by
dwheeler
1y ago
One of those alternative specifications is in the W3C Extensible Markup Language (XML) 1.0 (Fifth Edition). As I note, "The W3C specification is much more similar to typical regex syntax making it much easier for today's software
59.
▲
by
dwheeler
1y ago
More or less. It's a perfectly workable approach, but it's the reverse of what practically everyone else does, as well as the reverse of regex notation. Common notations should be common.
60.
▲
by
dwheeler
1y ago
I like lots of programming languages, I don't really have 1 favorite. I like the relative simplicity of C, and I have long familiarity with it, but its lack of memory safety and endless undefined behavior make it more difficult to safe
More ›