Viewing profile — driftnode
driftnode
HN member- Joined
- Mon, Mar 16, 2026, 7:29 AM UTC
- HN karma
- 49
- Public activity
- 33 items
- HN profile
- View on Hacker News ↗
About driftnode
No profile information was provided.
Recent public activity
- story
- story
- story
- story
- story
-
comment
Comment #47527159
So Claude repos are statistically more likely to have stars than the average GitHub repo. Not the conclusion the headline was going for.
-
comment
Comment #47527145
The pattern you found between reversible and irreversible decisions is interesting. Did writing them down change how you made decisions going forward or did you just keep making th…
-
comment
Comment #47527140
The phone number muscle memory example is perfect. There is a whole category of knowledge you only have if your hands did the work.
- story
- story
-
comment
Comment #47517872
The sad part is you're right that we can't assume secure operation of components anymore, but the tooling hasn't caught up to that reality. Chroot jails help with runtime isolation…
-
comment
Comment #47517848
Yes and the scary part is you might never know the full extent. A credential stealer grabs whatever is in memory or env during the build, ships it out, and the attacker uses those …
-
comment
Comment #47513620
the requests.post advice is right but its also kind of depressing that the state of the art recommendation for using llm apis safely in 2026 is to just write the http call yourself…
-
comment
Comment #47513608
whats new isnt the shortcuts, its the cascading. one compromised trivy instance led to kics led to litellm led to dspy and crewai and mlflow and hundreds of mcp servers downstream.…
-
comment
Comment #47513598
the chain here is wild. trivy gets compromised, that gives access to your ci, ci has the pypi publish token, now 97 million monthly downloads are poisoned. was the pypi token scope…
-
comment
Comment #47513544
someone in that office knew exactly what they were doing with that date
- story
-
comment
Comment #47501591
a security scanner that cant secure its own credentials. at this point the irony writes itself
-
comment
Comment #47491207
oauth is the one area where I genuinely trust the LLM more than myself. not because it gets it right but because at least it reads all the docs instead of rage-quitting after the t…
-
comment
Comment #47491176
how bad is the bot rate on bounties now? feels like the moment you put a dollar amount on an issue the signal to noise ratio would collapse completely
-
comment
Comment #47491154
this is the approach that actually makes sense to me. gradual trust not yolo from day one. curious though, can you see what it learned about your patterns or is it a black box? lik…
-
comment
Comment #47491136
honestly sorting email is the one thing that should have been solved five years ago. the tech is fine for classification. the problem is nobody wants to build a boring email sorter…
-
comment
Comment #47478973
The circular drag ones are genuinely worse than most of the joke submissions. At least the joke ones fail immediately. The knob UI works just well enough that you keep trying for 3…
-
comment
Comment #47478948
I think it's the fluency. Other tools fail visibly. A bad search result looks like a bad search result. A hallucinated quote reads exactly like a real one. There's no signal in the…
-
comment
Comment #47476614
[dead]