Live data from Hacker News

Viewing profile — winstonwinston

winstonwinston

HN member
Joined
Thu, Nov 20, 2025, 1:03 AM UTC
HN karma
172
Public activity
96 items

About winstonwinston

No profile information was provided.

Recent public activity

  1. comment
    Comment #49180467

    You can’t be upset because they want to know the truth, seriously. When a project has concerns about generated code, it is for a reason.

  2. comment
    Comment #49145830

    > I think we all know the answer to this: bad incentives. Better technology, worse food quality, more profit.

  3. comment
    Comment #49118216

    The blog post is painfully vague. What usually happens when you publish a package on PyPI is that it will be downloaded tens of times shortly after uploading files by some 3rd-part…

  4. comment
    Comment #49098928

    It’s the OneDrive installing new OneDrive Photos app. It happens on any Windows version, such as Server 2025 that has OneDrive installed. It isn’t limited to Windows 11.

  5. comment
    Comment #49084176

    Realistically spoofed address (unauthenticated email) will be treated as spam and it’ll be implicitly quarantined or rejected as such by many well-known mail receivers. You can mak…

  6. comment
    Comment #49077385

    To be fair, it’s used by only those who choose to use horrendous “mta-sts” instead of DNS-based Authentication of Named Entities (DANE). I might add that if you want to enforce SMT…

  7. comment
    Comment #49047544

    Hash pinning (already) works, and this change is all about when you as a PyPI user do not use hash pinning for installing releases, when you pin just release version for example. T…

  8. comment
    Comment #49029509

    > "Our model is powerful enough to commit multiple felonies (and we can't stop it)" is "marketing," I suppose. Well this bad publicity (if that’s how you want to frame it) certainl…

  9. comment
    Comment #49015127

    Using strong password as you suggested is a solved problem for your use case, but that is not universal. Passkeys provide universal security for all. Also PIN or biometrics verific…

  10. comment
    Comment #49013803

    > How can I do that, if Passkeys are the only option to log in? It is not feasible to remove password login or some other recovery login method. > If I can just use a password to l…

  11. comment
    Comment #49004086

    For starters they (those who submit) should not hide the fact. If they do, it is quite obvious to spot LLM generated code for anyone competent.

  12. comment
    Comment #48977621

    Quick search shows this in Wordpress: > WordPress database access abstraction class. class wpdb {} So this is some sort of ORM provided. $results = $wpdb->get_results( "SELECT * FR…

  13. comment
    Comment #48973527

    In Europe too, for Sd via DVB-C/T2. It is however non-existent for OTT.

  14. comment
    Comment #48958676

    Microsoft can remove device driver crapware from being distributed via windows update if you can get their attention on this.

  15. comment
    Comment #48869149

    Apple earned some trust unlike openai.

  16. comment
    Comment #48840662

    They want to allow forwarders (such as mailing lists) to modify signed messages all while keeping the original signed author email address. It is meant to replace ARC which is now …

  17. comment
    Comment #48798025

    > Finally, one aspect to consider is that many mail servers reject mail when the Envelope From domain has no MX or A/AAAA records. When the Envelope From domain and From domain are…

  18. comment
    Comment #48770748

    I did but where is fun in that. When I got involved in infosec community decades ago, veterans told me then, I should always investigate for myself, not just reading someones repor…

  19. comment
    Comment #48770697

    Yes, and I have 250GB Evo Samsung with similar stats, of same age and power on time.

  20. comment
    Comment #48770327

    > Is this a theory or did you test this yourself? This is just a pointer for exercise you could do if you are interested. I can’t tell what is the actual HME vulnerability they cla…

  21. comment
    Comment #48769339

    > Sure, that's possible, but I doubt it and I was also unable to trigger such behavior. An oversized message is bounced directly by the receiving SMTP server. > So the theory now h…

  22. comment
    Comment #48767121

    Even when it rewrites message envelope and headers, the actual message body of an NDR (nondelivery report) can disclose original address information. Because the NDR is generated b…

  23. comment
    Comment #48752029

    I was using FDK AAC encoder, I didn’t know Apple encoder was available for systems other than Apple. Though I have once compared AAC FDK to Apple AAC at 192kbps, and couldn’t tell …

  24. comment
    Comment #48744560

    This model looks pretty good on paper based on what it claims: up to 6.1 COP and is able to reach water temp of 59C. If it is able to deliver that would be news. So far models popu…

  25. comment
    Comment #48722113

    When it is about paying money for a commercial service I think it is valid point to vote with your wallet. Otherwise if it was a free service, it would not really matter as the who…