Hacker Newsnew | past | comments | ask | show | jobs | submit | bryancoxwell's commentslogin

Think you could argue that’s more LLM-assisted engineering than it is vibe coding.

Or simpler still, although related. Maybe we just can’t afford it: https://www.washingtonpost.com/national-security/2026/07/21/...


Not being able to afford something has never stopped the US before.


It’s literally stopping them from routine training and maintenance.


Well, depends on what "something"


Shockingly poorly handled by the maintainers. Goodness.


I think the reason is probably that the relevant maintainer doesn't see DHH as someone it's embarrassing to be citing with approval, not because politics and technology are separable but because he shares the views a lot of people disapprove of DHH for.

At any rate, someone noticed that he has a Youtube playlist (which has since been deleted, or maybe just made private) full of Curtis Yarvin (= Mencius Moldbug), Peter Thiel, and others known for such views.

If someone says "hey, you've got a quote from X who is a known Bad Person on your website; it would look better if you removed it" and you agree that X is a Bad Person then it's indeed pretty surprising and odd if you vigorously insist on leaving it there, and it looks like some sort of indifference to right and wrong.

But if in fact you think X is a Good Person who is being persecuted by a mob with Bad Opinions, it becomes much less surprising and looks (at least from your own perspective) like righteously standing up for your values against peer pressure and persecution.

(My own opinion, not that it's directly relevant, is that DHH is in the wrong morally and factually on this stuff. So I think Justin K. was standing up for bad values. But that isn't exactly the point; the point is that from this perspective his actions become much more comprehensible, even if not more encouraging for those of us who have been happy neovim users but object to anti-immigration politics.)



If I had a quote on my sugar packaging in 1925 "I like this sugar — Adolf Hitler" and then later it's 1950 and someone points out that my packaging still has this quote, I should rightfully consider removing it! Or at least somehow reframe it in a way like both good and evil agree this is the best sugar.


It is. 1856.


Love that idea, thanks for sharing


I’m intrigued by the question but I do think it has some worrying implications for portability.


Political leanings aren’t genetic


There are some studies, such as twin and adoption studies, suggesting genetics plays a role: https://pmc.ncbi.nlm.nih.gov/articles/PMC4038932/


nor are they stable in definition or constituents


Families transmit values via memes rather than genes. Politics is a meme competition and conservatives have a 2.1/1.5 advantage in reproducing meme transmitters. So without other interventions, liberals need about a 29% advantage in meme effectiveness for parity.


I reject my parents values, it does transmit with certainty. The rise of Trumpism has coincided with a rise in estrangement


But the memes that pass are more abstract, for example individual liberty. The modern application of that will lead to very different conclusions than parents came to during their time. Especially when you factor in the wacky paths modern cult-esque media tends to lead people down, and their kids getting to see the culmination of that.

Plus this "liberal vs conservative" dichotomy fell apart with the Republican party being taken over by destructive reactionaries. So personally as I've gotten older I've definitely gotten more conservative, but that has contributed to me voting Democrat rather than my previous Libertarian or overt protest vote.


Absolutely is to some extent, research strongly suggests it's brain structure, specifically around the amygdala. Facial structure can also be used as a predicator.

Conservative and Liberal Brains Might Have Some Real Differences - https://www.scientificamerican.com/article/conservative-and-... - October 26th, 2020

Kosinski, M., Khambatta, P., & Wang, Y. (2024). Facial recognition technology and human raters can predict political orientation from images of expressionless faces even when controlling for demographics and self-presentation. American Psychologist, 79(7), 942–955. https://doi.org/10.1037/amp0001295

Rasmussen SHR, Ludeke SG, Klemmensen R. Using deep learning to predict ideology from facial photographs: expressions, beauty, and extra-facial information. Sci Rep. 2023 Mar 31;13(1):5257. doi: https://doi.org/10.1038/s41598-023-31796-1 PMID: 37002240; PMCID: PMC10066183.

Pedersen WS, Muftuler LT, Larson CL. Conservatism and the neural circuitry of threat: economic conservatism predicts greater amygdala-BNST connectivity during periods of threat vs safety. Soc Cogn Affect Neurosci. 2018 Jan 1;13(1):43-51. doi: https://doi.org/10.1093/scan/nsx133 PMID: 29126127; PMCID: PMC5793824.

Haas, I.J., Baker, M.N. & Gonzalez, F.J. Who Can Deviate from the Party Line? Political Ideology Moderates Evaluation of Incongruent Policy Positions in Insula and Anterior Cingulate Cortex. Soc Just Res 30, 355–380 (2017). https://doi.org/10.1007/s11211-017-0295-0

Kanai R, Feilden T, Firth C ... Political Orientations Are Correlated with Brain Structure in Young Adults Current Biology, 2011; 21, 677-680 https://doi.org/10.1016/j.cub.2011.03.017

I think the more interesting question is: are we, as a species, evolving away from conservatism centric biology over time? Or is it because we stopped putting lead into the environment? Because you can see the generational cohort differences over time.

Gen Z women are the most liberal group in the country - https://19thnews.org/2025/10/gen-z-women-politics/ - October 7th, 2025

Exploring Young Women's Leftward Expansion - https://news.gallup.com/poll/649826/exploring-young-women-le... - September 12th, 2024

Pew Research: Age, generational cohorts and party identification - https://www.pewresearch.org/politics/2024/04/09/age-generati... - April 9th, 2024

Tangentially, I strongly believe this is related to why US religions are losing members with every generational cohort. This is covered in the below https://www.graphsaboutreligion.com posts, but unfortunately, they are paid and I don't have a way to unlock to share them. I will inquire with the author if I can compensate them to unlock these specific references.

This is Not Simple Generational Replacement - https://www.graphsaboutreligion.com/p/can-millennials-save-t... - April 23rd, 2026

When Are Half Your Members Going to be Dead? - https://www.graphsaboutreligion.com/p/when-are-half-your-mem... - January 29th, 2026

The Generational Collapse of American Religion - https://www.graphsaboutreligion.com/p/the-generational-colla... - January 19th, 2026

The Politics of Religion - https://news.gallup.com/opinion/polling-matters/510464/polit... - September 1st, 2023 (“Everything else being equal, the more religious the individual in the U.S. today, the higher the probability that the individual identifies with or leans toward the Republican party. I called this the “R and R rule” in my 2012 book on religion, found the phenomenon alive and well in my 2014 review of Gallup data, and now, nine years later, Gallup’s data confirm that this religiosity gap is more evident than ever.“)

TLDR Brain structure->Politics and Religious Belief System


I use the ever living hell out of .git/info/exclude. Works great for scripts/Makefiles I only want locally and collaborators wouldn’t care about or be able to use.


Interested in examples of the types of scripts others collaborators wouldn't be able to use? Like scripts for PR workflows?


Usually when I'm working in one part of the codebase and I have sample data or something at a specific path on my local machine and Im testing the same thing over and over again will I make a Makefile or something and info/exclude it to help me keep focused. That's one way I use it.


I use git worktrees pretty heavily in my own workflows (I worked like an AI agent before AI agents made worktrees cool). I like to track my ephemera/utility scripts in git, so what I do is keep a private ephemera repo for those, and then use `git worktree add` from the collaborative repo to check out the branch I'm working on there into a subdirectory of my ephemera repo.

  git-home/
    company-project/ <-- git repo with main checked out
    ephemera/ <-- my private repo
      my-data-script.py
      work/ <-- gitignored
        company-project-feature-X/ <-- worktree on feature-X branch
        company-project-feature-Y/ <-- worktree on feature-Y branch
      
This way, too, I can easily use the same ephemera scripts across multiple branches, or even multiple repos, concurrently.


How do you manage the lifecycle of the worktrees in practice? Is it mostly manual git worktree add/remove, or do you use aliases/scripts/some other tools?


Oh this is really clever, I'll have to try this. Thank you :)


Yeah this is pretty much it.


For quite a while, I've have had a shell fcn that will take all the untracked files listed in a git status, and push them to .git/info/exclude. Generally applied after an add+commit of everything I do want to go generally into the repo.


> Their initial reply from the CEO: "I would love to hear what the vulnerability is, but I assume you want to get paid for it. Is that the play?"

Well that’s pretty damning.


Should have been handled better, but some context is necessary:

If your name is associated with a startup in a visible leadership position you will get mass-spammed from people claiming to have discovered critical vulnerabilities in your system. When you engage with them, the conversation will turn into requests to hire them for their services.

So the CEO handled it poorly, but it's also not a great choice to withhold the details of the vulnerability in initial contact. If the goal was to get something fixed it should have been included in an easy-to-forward e-mail that could have been sent to someone who could act upon it.

Anyone who works with security or bug bounties can tell you that the volume of bad reports was a problem before LLMs. Now that everyone thinks they're going to use LLMs to get gigs as pentesters the volume of reports is completely out of control.


I keep getting emails with the content like: "I found a critical bypass vulnerability in your app what is the appropriate channel to disclose it, and do you have a bounty program?"

I tried engaging and replying to them, and it inevitably turns into: "Yeah, we don't actually have the vulnerability, but you are totally vulnerable, just let us do a security audit for you".

I have a pre-written reply for these kinds of messages now.


Yeah, the signal to noise ratio on vulnerability reports is very weak, especially when the initial report withholds any detail.

I get tons of these messages too and the ones that do include details are the kind of junk you get from free "website vulnerability scanners" that are a bunch of garbage that means nothing -- "missing headers" for things I didn't set on purpose, "information disclosure vulnerabilities" for things that are intentionally there, etc... You can put google.com into these things and get dozens of results.


I run bug bounty for a fairly large OSS project and the amount of shitty/bad actor spam/beg bounties etc we get is huge. Like 95% of the emails to security@ are straight garbage


From the looks of it, they actually asked for a way to report.


email security@company


Sure that is perhaps a good way to inquire about the appropriate channels to disclose a security vulnerability, but email is not a secure communication method for sending the details about a security vulnerability


It's kind of insane to think that the state of email encryption is still so bad in The Future Year 2026.

No flying cars? Okay. Nobody traveled much beyond the orbit of the Moon? Dang. But email? We didn't even get reliable privacy separate from identity?


> Nobody traveled much beyond the orbit of the Moon?

Oh, don't think that outer space will let you escape the misery of email:

> "I have two Microsoft Outlooks and neither one is working": Artemis II astronauts


start there and handle everything once you get in contact with appropriate people


Yeah. I'm just saying how it could have been overlooked. Doesn't excuse it, though.


The number of spam "I found a vulnerability" emails you get as a SaaS operator is ridiculous, they never offer any proof of a vuln and just want you to confirm you have a bug bounty program (in which case they'll start scanning afterwards), or to pay ahead of time for the information or they'll threaten to release it.

Their response isn't damning to me. It sounds like they just assume they're one of these spammers.


i have even more damning ones.

When the "good Samaritan" do not go to the vendor, they go to the client (i.e., they do not contact the DIB company, they contact the Gov agency).

I have seen government contractors getting pilloried, losing their livelihood when this happened. And, yes there is always a "quick fix offer" by the "good Samaritan" to the vendor and promised re-assurance to the Gov agency, only if this misguided vendor would go with their solution.

It is also not unusual to find out later on, that the identification or even the resource reported on was wrong - but by this time the Gov agency already punished the contractor and the reporting "good Samaritan" is laughing (sometimes to the bank).

they can get away with unethical vulnerability disclosure because think of the children, the threat to the nation, grandma off the cliff, and <insert your favorite cliche justification of malfeasance>.

Yes, sore subject.


That just sounds like good old business to me. When outside of public view, good businessmen are extremely cut-throat and unethical.


They could sell the next one to an adversary for a lot more money if they're going to act like that.


Yes, there are also many other lucrative illegal activities.


How is it illegal? It’s information available to the public.


If you sell something to someone and they do computer crimes, you're going to have to prove that you couldn't've known that they're a computer crimer.

It's the same thing with selling general offensive security tools. You have to proactively make it clear that it's for testing and not criminal use. Otherwise, cops are going to assume you're complicit and make things shitty.


Isn't it also illegal to withhold knowledge of a vulnerability for payment? It sounds like it should fall under some variety of blackmail.


That would be even worse than our already bad system.

The system is already pretty bad because vendors underinvest in security, and then to fix it, researchers have to volunteer their time to investigate with no guarantee of payment. If the vendor could force researchers to hand over findings for free, nobody would want to do security research except hobbyists having fun. They're basically signing up for hours of tedious forced labor to explain vulnerabilities to the vendor.

I wish there was legislation that allowed the government to fine vendors for security vulnerabilities like this where the amount scales based on how much user data they leaked. And it could function like other whistleblower systems where a researcher who spots a leak can report it to the government and collect 50%. That way, if the vendor says, "We're not paying you," the researcher can turn around and collect the money from fines.


Vendors routinely get researchers arrested for breaking into their computers as well.


Legality aside there is no market for this really.


Data breaches of average people sell for quite a bit of money, often for phishing. I find it hard to believe no one would be interested in this.

Or any other dataset with a hyper targeted demographic.


I’m not up to date on local models, but is that clear?


Gemma4:e4b is crazy good and quite usable on 10 years old midrange hardware.

Not sure about the security capabilities and haven't tested it all that well, as I usually just use hosted models, but I do find myself using it and it's been quite successful for parsing unstructured data, writing small focused scripts and translations.

The fact that I retain control of the data itself makes it incredibly useful, as I work in an environment where I can't just paste internal stuff into Codex.

But since it's run locally on a toaster testing it is out of scope for me. It takes a fairly long time to do anything.


Local models are 6-12 months behind the “frontier” models. This mean anthropic, openai, and google don’t have a moat, they’re on a treadmill running to stay ahead. Treadmills don’t justify their valuation.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: