Live data from Hacker News

Viewing profile — driftnode

driftnode

HN member
Joined
Mon, Mar 16, 2026, 7:29 AM UTC
HN karma
49
Public activity
33 items

About driftnode

No profile information was provided.

Recent public activity

  1. story
  2. story
  3. story
  4. story
  5. story
  6. comment
    Comment #47527159

    So Claude repos are statistically more likely to have stars than the average GitHub repo. Not the conclusion the headline was going for.

  7. comment
    Comment #47527145

    The pattern you found between reversible and irreversible decisions is interesting. Did writing them down change how you made decisions going forward or did you just keep making th…

  8. comment
    Comment #47527140

    The phone number muscle memory example is perfect. There is a whole category of knowledge you only have if your hands did the work.

  9. story
  10. story
  11. comment
    Comment #47517872

    The sad part is you're right that we can't assume secure operation of components anymore, but the tooling hasn't caught up to that reality. Chroot jails help with runtime isolation…

  12. comment
    Comment #47517848

    Yes and the scary part is you might never know the full extent. A credential stealer grabs whatever is in memory or env during the build, ships it out, and the attacker uses those …

  13. comment
    Comment #47513620

    the requests.post advice is right but its also kind of depressing that the state of the art recommendation for using llm apis safely in 2026 is to just write the http call yourself…

  14. comment
    Comment #47513608

    whats new isnt the shortcuts, its the cascading. one compromised trivy instance led to kics led to litellm led to dspy and crewai and mlflow and hundreds of mcp servers downstream.…

  15. comment
    Comment #47513598

    the chain here is wild. trivy gets compromised, that gives access to your ci, ci has the pypi publish token, now 97 million monthly downloads are poisoned. was the pypi token scope…

  16. comment
    Comment #47513544

    someone in that office knew exactly what they were doing with that date

  17. story
  18. comment
    Comment #47501591

    a security scanner that cant secure its own credentials. at this point the irony writes itself

  19. comment
    Comment #47491207

    oauth is the one area where I genuinely trust the LLM more than myself. not because it gets it right but because at least it reads all the docs instead of rage-quitting after the t…

  20. comment
    Comment #47491176

    how bad is the bot rate on bounties now? feels like the moment you put a dollar amount on an issue the signal to noise ratio would collapse completely

  21. comment
    Comment #47491154

    this is the approach that actually makes sense to me. gradual trust not yolo from day one. curious though, can you see what it learned about your patterns or is it a black box? lik…

  22. comment
    Comment #47491136

    honestly sorting email is the one thing that should have been solved five years ago. the tech is fine for classification. the problem is nobody wants to build a boring email sorter…

  23. comment
    Comment #47478973

    The circular drag ones are genuinely worse than most of the joke submissions. At least the joke ones fail immediately. The knob UI works just well enough that you keep trying for 3…

  24. comment
    Comment #47478948

    I think it's the fluency. Other tools fail visibly. A bad search result looks like a bad search result. A hallucinated quote reads exactly like a real one. There's no signal in the…

  25. comment