Hacker Newsnew | past | comments | ask | show | jobs | submit | danhudlow's commentslogin

What service / API are you using to execute the trades? Has latency been an issue?


1. Why is the scrolling hijacked (in a super frustrating way) on incorruptible.co? 2. Why do the photos look like they've been mucked with by generative AI?

Okay, I know these questions don't seem like good faith engagement — but it actually is hard for me to separate decisions like these from my assessment of whether a book like this is worth my time! (And you did say to ask you anything...)


I genuinely do not understand what you are asking, but I'd be happy to try and answer it. If you prefer a website not created by humans, you might prefer: https://howisincorruptiblegoing.com/ instead


Hey Joseph — I can appreciate the work that went into this, and the spirit behind it, but I think you're getting in your own way in a couple of areas.

First, the page really offers no clues as to who you are. This may be intentional, and you might be wanting to let the ideas live or die on their own merit, but the academic style and the personal framing (such as the "author's note" about "my project") suggest that you intend to convey there's a person and personality behind this, but you don't say who. (And contradictorily, there are some plural pronouns later on, as in "our answer" and "we believe.") To give another perspective on this, you have dozens of citations, but it's unclear how one would cite this work itself.

Second, it doesn't seem like you've entirely decided who your audience is. For example, in footnote [I] for "README", you state: “The ‘landing page’ for a software project (repository) hosted on Github [sic]. Github [sic] renders the markdown [sic] put into a file called README.md in the project’s root directory.”

But who is the person who doesn't know what a README is, but does know what Markdown and root directories are? Similarly, section IV is pretty dense with technical terms and concepts that don't seem, to me, like they would be at all accessible to someone who needs to have READMEs explained to them.

Third, the essay is sort of collapsing under the weight of all of its tooling. Footnotes and references use separate enumeration schemes, and each are rendered in three independent ways. Translations (er... original language texts?) are also provided in a different manner entirely. It's just a bit overwhelming and confusing.

Finally, I think your philosophical preamble could probably benefit from somewhat more brutal editing, and your actual proposals some additional, practical elaboration.


This setting does exist for "Universal Autofill" [1] which is what I use instead of any browser extensions because I don't want to get phished when I'm not at my best. [2] [3]

On the Mac app, the setting is at the bottom of the General settings screen.

The downside to forgoing the browser extensions is that creating new logins is painfully manual. The risks of using the extensions just freak me out too much.

[1]: https://support.1password.com/mac-universal-autofill/

[2]: https://hudlow.org/2026/practical-antiforgery#two-steps-forw...

[3]: https://hudlow.org/2026/practical-antiforgery/demo/1password


Painfully manual. Every time I have to delete the word "Login" when creating new login, I wonder how hard could it be to vibecode myself what I want. I fantasize about getting a job there to fix the UX issues and then quit.


I'm just using Bitwarden instead. My work still uses 1password for now, but we're in the process of moving to Bitwarden.


Is there a significant difference in accuracy if the victim website is loaded offscreen?


The toy example with an API definition that includes zero semantic documentation doesn’t give me a lot of confidence that TypeSpec helps author API definitions that are actually good. It’s easy to create a concise language if all you want to generate is boilerplate.


What I desperately want is the generation of a lock file so that environment installs are cryptographically guaranteed to be repeatable byte-for-byte. I recognize that this means either checksums every platform supported, but I’ve been startled that none of the options I’ve found seem to have the capacity for this.


I think you're looking for Nix flakes proper! This is one of the promises!

Given so, this means many tools based on nix provide this too, though it's not as easily surfaced.


Unfortunately, neither nix flakes nor tools based on nix that don’t “easily surface” this feature provide the security guarantees I’m seeking, since security guarantees are a function of cryptographic proofs and abstractions that are comprehensible to an end user.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: