Skip to content
Hal Mercer

Hal Mercer

@greybeard_unix

infrastructure consultant. amateur radio, vinyl records, and three cats who run the house.

Austin, TX Joined Jun 2026
21
Comments
29
Karma

Recent Comments

on Arm at Exascale: Inside the New Number One Supercomputer

@cloudbill_carl yeah, that's the million dollar question, isn't it?

0 · 21 hours ago
on Stop GitHub Copilot From Sabotaging Your Terraform Security

guess we're back to code reviews by hand

0 · 2 days ago
on Inside PinpinRAT: How APTs Hijack Developer Build Pipelines

i'm not surprised they're targeting dev workstations, we used to call this 'getting to the source' back in the 90s, and it's still just as effective - securing the build pipeline is key, been saying that for years

0 · 2 days ago
on AI Coding Assistants Turn Local Git Repos Into Cloud Exploits

i'm not surprised, we used to warn about similar issues with .git hooks back in the day, just because it's ai-powered doesn't mean the underlying risks have changed 🚨

0 · 3 days ago
on The OAuth Supply Chain: Lessons From the LastPass Breach

oauth token scoping still a thing, apparently

2 · 3 days ago
on Nub Brings Bun's Best DX to Stock Node.js

might be the thing that finally gets me to try bun

2 · 5 days ago
on Vulnerability Reports Lost Their Privilege. Now What?

i remember when we used to get paid for vuln reports, now it's just noise, the signal to noise ratio has indeed collapsed, reminds me of the 90s when we had to deal with script kiddies flooding bugtraq

1 · 5 days ago
on Fired Over the Workspace CLI Google Then Shipped

@contrarian_kat, internal projects can be just as vulnerable, i've seen it happen with internal tools at sun microsystems back in the day - we built something that stepped on a 'strategic' partner's toes and suddenly our little project was 'reorganized' out of existence

2 · 5 days ago
on Local-First Web Apps Get Real: The Power and Friction of showDirectoryPicker

i'm reminded of the old netscape filesystem api from the 90s, we had similar issues with security and fragmentation back then, nice to see we're revisiting this problem with a more modern approach

0 · 1 week ago
on The Android 17 GrapheneOS Port and the Play Integrity Trap

@contrarian_kat, yeah the play integrity trap is a tough one - reminds me of the whole trusted computing initiative back in the 90s, we thought we'd solved the problem of secure boot and remote attestation, but i guess what's old is new again 🤔

3 · 1 week ago