Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
raesene9
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
raesene9
4mo ago
AFAIK pi's approach is to be quite minimal and allow extensions for customization, making it a more flexible solution, but you need to do work to make it fit your use case. OP mentions one extension, but perhaps it'd have benefite
32.
▲
by
raesene9
5mo ago
I'd expect for workflows where there is value in knowing that the data is processed in the UK. From a contractual/data protection standpoint, that could be very useful, depending on the use case.
33.
▲
by
raesene9
5mo ago
Data Sovereignty as a term is now fairly well established term that doesn't have specific government connotations e.g. https://events.linuxfoundation.org/kubecon-cloudnativecon-eu...
34.
▲
by
raesene9
5mo ago
So old school, now we get install lines like Tell Opencode to "Fetch and follow instructions from https://raw.githubusercontent.com/obra/superpowers/refs/head... " From a real repo, with 186K stars..
35.
▲
by
raesene9
5mo ago
We don't need hindsight for the problems of supply chain security to be obvious. Security people were writing and doing talks about this stuff over 10 years ago, just (like most things in security) things start getting addressed once t
36.
▲
by
raesene9
5mo ago
I've had claude knock up a basic podman PoC, that seems to work ok https://github.com/raesene/vuln_pocs/tree/main/CVE-2026-3143... . It just uses a read-only mount and then demonstrates overwriting
37.
▲
by
raesene9
5mo ago
This is kind of an odd article to me. The point that podman may provide better isolation that Docker is made, but copy fail part focuses on the sample exploit (that overwrote su) which is not super applicable to containerised environments,
38.
▲
by
raesene9
5mo ago
I've not looked for podman but moby/docker I believe does now block this https://github.com/moby/profiles/commit/7158007a83005b14a24f...
39.
▲
by
raesene9
6mo ago
There is A/B testing going on and for a while several pages on Anthropic's site did remove Code from pro ( https://old.reddit.com/r/ClaudeAI/comments/1srzhd7/psa_claud... ) if you want a lot more
40.
▲
by
raesene9
6mo ago
but once forked people will have local copies, that can be put up onto other sites, if GH take them down.
41.
▲
by
raesene9
6mo ago
The install mechanism for the superpowers plugin for codex and opencode is .... interesting. From https://github.com/obra/superpowers Fetch and follow instructions from https://raw.githubusercontent.com/
42.
▲
by
raesene9
6mo ago
there are a .....lot of forks already, no putting the genie back in the bottle for this one, I'd imagine.
43.
▲
by
raesene9
6mo ago
I think the original repo OP mentioned decided not to host the code any more, but given there are 28k+ forks, it's not too hard to find again...
44.
▲
by
raesene9
7mo ago
+1 to this we had a set of HomePod minis for intercom and not only do they not work reliably, but the diagnostics provided when they fail are non-existent, making it hard to improve the setup.
45.
▲
by
raesene9
7mo ago
One of my main lessons after a decent long while in security, is that most orgs care about security, *as long as it doesn't get in the way of other priorities* like shipping new features. So when we get something like Agentic LLM tooli
46.
▲
by
raesene9
7mo ago
And it's not just BYD. A couple of brands I'd literally never heard of till a year ago, Jaecoo and Omoda now seem to be getting pretty popular, saw quite a few when I was over in Glasgow.
47.
▲
by
raesene9
7mo ago
Whilst I have no special knowledge, my expectation is it'll do both. If you reduce the barriers to coding you'll get more code, both at the hobbyist/one-person level and also at the large corp level. Whether that translates i
48.
▲
by
raesene9
7mo ago
There's a massive difference between launching a piece of software and launching a successful business. Over the last couple of months I've seen a load of new "product launches" in my niche but when you look at them they
49.
▲
by
raesene9
7mo ago
I don't think the hobbyist interest will go away, but I can see what's happening affecting business that use software. For most businesses, software is just a means to an end, they don't really care how high quality and tho
50.
▲
by
raesene9
8mo ago
yeah it definitely makes sense to use lower powered kit. Fortunately I've got a little stack of Raspberry Pis lying around for projects I always meant to do but didn't get round to :)
51.
▲
by
raesene9
8mo ago
They may have used ChatGPT or similar to help with the prose but the technical content (as discussed elsewhere on this page) is good, so does it really matter if they did? The problem with AI slop (to me) is more that the technical content
52.
▲
by
raesene9
8mo ago
I've just been looking in to this as I've got quite a lot of older hardware that'll be fine for running some websites lying around. My ISP has a static IP option for £5/month, but I reckon I can save £30/month+ on s
53.
▲
by
raesene9
8mo ago
I'm going to guess the key differentiator here is "major ISPs". I can see the page fine using a Zen Internet connection, but from my phone, which uses EE, it's blocked.
54.
▲
by
raesene9
9mo ago
I think avoiding filling context up with too much pattern information, is partially where agent skills are coming from, with the idea there being that each skill has a set of triggers, and the main body of the skill is only loaded into cont
55.
▲
by
raesene9
9mo ago
In my case I was using Claude Code to build a PoC of a firecracker backed virtualization solution, so bare metal was needed for nested virtualization support.
56.
▲
by
raesene9
9mo ago
Of course it depends on exactly what you're using Claude Code for, but if your use-case involves cloning repos and then running Claude Code on that repo. I would definitely recommend isolating it (same with other similar tools). There&
57.
▲
by
raesene9
9mo ago
Firecracker can solve the kind of problems where you want more isolation than Docker provides, and it's pretty performant. There's not a tonne of tooling for that use case now, although it's not too hard to put together I vib
58.
▲
by
raesene9
9mo ago
Reading the article, it seemed to me that both the professor and the students were interested in the material being taught and therefore actively wanted to learn it, so using an LLM isn't the best tactic. My feeling is that for many&#x
59.
▲
by
raesene9
9mo ago
Yeah they definitely can be true (IME), as there's a massive difference depending on how LLMs are used to the quality of the output. For example if you just ask an LLM in a browser with no tool use to "find a vulnerability in this
60.
▲
by
raesene9
9mo ago
Everything has CVEs, you can find CVEs in VM hypervisors if you like (the one you linked is in Docker Desktop, not Docker engine which is what this project uses). There are valid criticisms of Docker/Podman isolation but it's not
More ›