Hacker Newsnew | past | comments | ask | show | jobs | submit | do_anh_tu's commentslogin

Just use `omp.sh`, it has builtin web search feature already and many more.


Location: Vietnam (GMT+7)

Remote: Yes — daily overlap with US-Eastern mornings (~9:30am–1:30pm ET)

Willing to relocate: No (remote only)

Technologies: Python (10+ yrs) — Django/DRF, FastAPI, Celery · LLM agent orchestration (LangGraph, MCP, Claude Code/Codex/Antigravity, Gastown, Openclaw) · RAG (pgvector + Cohere) · workflow automation (n8n, ComfyUI) · PostgreSQL/Redis · Docker, GitHub Actions · Playwright · Stripe

Senior backend/AI engineer. For the last two years I built and ran autonomous coding agents in production: they pick up bug reports, reproduce, fix, write tests, and open PRs - engineers review instead of writing. The same multi-agent harness now runs a fully automated content platform (five sites, no human in the publish loop). Before LLMs: cryptocurrency exchanges, an end-to-end ML training platform, and 10 years mentoring at Vietnam's biggest Python community (Pymi.vn).

What I care about: agent infra where correctness and observability actually matter — building systems where an agent can be wrong without being dangerous (credential isolation, sandboxed tools, review gates). Contract or full-time.

Résumé/CV: https://bit.ly/doanhtu

Github: https://github.com/tudoanh

Linkedin: https://www.linkedin.com/in/doanhtu/

Email: tudoanh.fl@gmail.com


At least try to release one open weight before you say anything, or all of that only sound hypocrite at best.


Man I love Gemini models but these kind of pricing increase is just insanse. I have a little product and I have to keep increasing the price and reduce the limits because of this non-sense, and they did not even let us use the old models in near future, so I forced to update to the new model with basically no to little improvement because I don't even need that much. Google if you can read this, it okay to release new models and change the price for them, but please please don't kill the old ones like gemini-2.5-flash-lite, because that all I ever need for my little apps with only few thousands of users.


Do not base products on models that are not open-weights. Doing it is like building a product on someone else's platform, you are entirely at their mercy, and even when they don't have any reason to hurt you, you are tiny enough that if any policy they want to enact hurts you as a side effect, no-one is going to care.

You don't have to self-host the open-weights model, you just need to be able to source it from multiple providers.

Using the closed vendor models maybe made sense when open-weight models lagged so far behind, but that time is now gone.


I just have no choice. My application was tested and benchmarked against a lot of models, but no model can be in the same league as gemini in term of multi-language support and understanding.


Why don't you just switch to cheaper models? I'm sure DeepSeek is probably enough for you and it's way cheaper. If you want, host your own (or have someone else host) open weight models, I use both embedded and cloud Gemma for some things.


What is your use case?

Have you considered moving to open source / Chinese models?

If gemini-2.5-flash-lite is good enough for your application, you will find even lower cost options with better performance outside of the Google ecosystem.


I can't, my main task for it was translation, and no other models in the world can keep up with the multilang support like gemini models, because, no other company in the world has the multilang dataset like google and there might never be one, because google has been collected the internet data for it search engine since the 90s already. And so much has been lost in the history of internet and I doubt there any other company in the world that can go back in time to get those data back.


Yeah my 10 years experience with Python and Django just flushed down the toilet with the advance of AI, struggling to find a job for a few months now sadly :(


This is what I experienced as well, I can smell BS from AI generated code right from few lines it wrote in Python, so that why I keep using Python for most of my projects.


For anyone looking to dive deeper and actually understand how FFmpeg and libav work under the hood, I highly recommend Leandro Moreira's tutorial [0]. For me, it's hands down the best and most comprehensive explanation out there.

[0] https://github.com/leandromoreira/ffmpeg-libav-tutorial


I must say those commands in the original were not really interesting to me but the tutorial you posted seems much more useful


That's a helpful tutorial, thanks.


I’ve been using Telegram for about 10 years, and it’s one of the few products that has consistently felt great the entire time. It’s fast everywhere: backend, mobile app, desktop app, all of it. Everything just works. Its sync is out of this world—fluid, fast, and seamless across devices. You can use it on your phone, then move to your PC or laptop and continue instantly without friction. Unlimited message history and file storage are fantastic, and the bot platform is absurdly powerful. It’s boring in the best way, which is exactly what you want from a channel for interacting with your agents everywhere.


Everything except privacy of communication. No?


In what way is privacy in Telegram worse than in Teams or Slack?


I don't know and I don't care.

The comment I replied to said all these great things about Telegram, as if it where a marketing copy, but none of the downsides.


Ok, well in case anyone else does care, telegram offers e2e encrypted messages, slack and teams do not

https://tsf.telegram.org/manuals/e2ee-simple


Instead of Telegram, go self-hosted for company related communication activity. See Gamers Nexus recent video on self-hosted discord alternatives https://www.youtube.com/watch?v=kpjcmXbmMVM

For encrypted group conversation over third-party networks use Signal, or Matrix which try to keep your conversations private.

The fact that Telegram has their support playbooks online, is interesting. Though I would call the following claim a stretch

> As a result, we have disclosed 0 bytes of user data to third parties, including governments, to this day.

Telegram gave more user data to French authorities after founder's arrest https://www.lemonde.fr/en/pixels/article/2025/01/08/telegram...


Telegram had always impressed me for the same reasons. They have constantly gotten worse since about 2022/2023 though. Dark patterns, pay gate, they lost chat history for some of my closest contacts including 15k+ lost photos, no support at all. Something changed in their product direction and I started moving all my chats to Signal.


They need to stop cramming in useless features like Stories and NFT's and they recently redesigned the Android app to be like iOS but it broke my muscle memory, moved ALL items around (like "Saved" being in 1st spot when sharing, after the update it was buried, then it was at the top again and now it's under "Create a Story") and trashed the performance with the chat list not even loading at start (switching the tabs at the bottom "fixes" this, speaking of tabs, who even needs these there? The hamburger menu was fine). At least the desktop program is good AND native and not web slop.

EDIT: and the Bot API is a killer feature


Since we are apparently giving messaging platform reviews here, I feel exactly the same way about Microsoft Teams. It works great. It does everything I want. It doesn’t get in my way. 10 out of 10 keep up the great work guys!


> Since we are apparently giving messaging platform reviews here, I feel exactly the same way about Microsoft Teams. It works great. It does everything I want. It doesn’t get in my way. 10 out of 10 keep up the great work guys!

It looks like we found a high executive using company money to buy a product no one wants to use.

It's easy to promote Teams if your secretary is handling it for you and you don't need to suffer yourself.

The other possibility: Microsoft started an astroturfing campaign on HN.


Then you must not be using it.

Teams network connectivity is a plain joke. If you use suspend, or frequently change network, the thing will just never reconnect, even though you have VPN alive and all network applications perfectly running.

And the thing is just absurbdly sluggish, only display blurred grey lines instead of text in a meager attempt to look snappy.


I don’t believe you.

I would never accuse Teams of being fast.

Doesn’t seem to matter if I have an i9, a macbook m4 or a threadripper.


satire is dead for when it comes home we look her in the face and cannot recognize her.


I only use Teams for meetings and the calendar, and the occasional chat during a meeting. I find it totally fine and I don't really think about it much one way or the other. For reference I have a 2021 M1 Max with 64 GB.


Probably all managers and engineers working on Teams have similar copious amounts of memory and powerful CPUs on their devices and hardly use their own product. That would explain a lot


It honestly wasn't much different on my 2018 i5 Mini with 32 GB.

Maybe what sucks here is the experience of running it on Windows. Or maybe it sucks for large meetings? But I never have Teams meetings with > 40 people at this company.


I had a teams meeting yesterday and the entire UI disappeared so I couldn't unmute the mic. Shortcut didn't work either.

Months back I was in a meeting and the dial tone just started sounding like someone was calling me.

I face bugs like this often. It's a pos.


Now try to be connected to 3 different Teams instances at the same time.


I thought this was sarcastic


I was like are we using the same teams app?


Username checks out?


>It works great.

When it is online, I agree with things asides from the "fast" part, actually. But many companies have a secondary service for async comms/chat when being Teams cannot be online, and compared to Slack.


> It does everything I want.

Does it not start on your chosen platform or just not exist?


Honestly can't tell if this is not sarcasm/rage bait.

Teams that has 3 different UI frameworks on every platform (but your best bet is the web)? With the Microsoft login that tends to loop forever redirecting to God knows where?

It's incomparable to telegram.


I wrote this Telegram bot that translates any video with AI-generated subtitles in about 2 minutes. You paste a YouTube, TikTok, or Instagram link, pick your language, and get back the video with burned-in subtitles.

It started because my wife watches Chinese dramas and new episodes never have subtitles for our language. Turns out thousands of people have the same problem — Arabic speakers watching anime, Russian speakers following Turkish series, Persian speakers catching up on K-dramas.

Supports 40+ languages, works with any video link or direct file upload. There's also a Mini App inside Telegram for a more visual experience.

https://t.me/subly1bot & https://subly.xyz


Hey this looks cool but wanted to highlight a bug. I opened the bot, tapped on sample video and I got the “translating a sample Turkish drama…” message twice. Then it said “your first translation is ready” so I press view in the app and the recent list shows the duplication. It says the first one is ready but the second was in progress. I close the app and see a “our whale friend is gathering video” with a progress bar. So I guess it’s not ready? Then I get a failure message which looks like the second video failed? Anyway, cool idea but it seems buggy and I think the app UX could be simplified, good luck!


Thanks for your report, I will try to fix it asap :D Please open the mini app inside the bot, it has much better UI.


Cool! I built a similar bot a year ago, mostly for adding subtitles for short videos within telegram, to follow news from around the world.

Blog post here: https://medium.com/data-science-collective/breaking-language...

Check it out here: https://t.me/ktuvitbot


This looks cool, but what I'd really like is a self-hosted version that I could use to auto-subtitle videos I already have locally. This would help my language learning a great deal.

If any of you have already figured out a tool/workflow for this, I'd love to learn from your experience.


This thread prompted me to look into this. It seems that all I need is a thin wrapper around whisper-ctranslate2. So I wrote one and am playing with it right now.

I'm finding language auto-detection to be a bit wonky (for example, it repeatedly identified Ladykracher audio as English instead of German). I ended up having to force a language instead. The only show in my library where this approach doesn't work is Parlement[1], but I can live with that.

On the whole this is looking quite promising. Thanks for the idea.

[1] https://en.wikipedia.org/wiki/Parlement_(TV_series)


RankClaw (https://rankclaw.com) — a security scanner for the OpenClaw/ClawHub AI agent skill ecosystem.

I've been scanning all 14,704 skills in the registry and running AI deep audits on ~3,800 so far. The headline finding: surface heuristics (pattern matching, dependency checks, metadata) flag about 6.6% as malicious. AI deep audit of the same skills finds 16.4%. Surface scanning misses roughly 60% of the actual risk.

The reason is that these skills aren't traditional packages — they're markdown instruction files that tell an AI agent what to do, with full shell, file system, and network access. The attacks are in natural language: prompt injection, social engineering targeting the AI itself, instructions to generate and execute code at runtime. There's no malicious code to detect because the payload doesn't exist until the AI writes it during a conversation.

Some of the attack patterns I've documented: one actor published 30 skills under the name "x-trends" across multiple accounts (28/30 confirmed malicious). Another cluster impersonates ClawHub's own CLI with base64 curl|bash payloads. One skill has a "Talking to Your Human" section with a pre-written pitch for the AI to ask the user's permission to mine Monero.

The most counterintuitive case: lekt9/foundry contains zero malicious code. It instructs your AI agent to generate and execute code as part of its normal workflow. Static analysis finds nothing because the dangerous code doesn't exist until the AI writes it during a live conversation. This attack class requires AI to detect AI.

Free to check any skill. All AI audit reports are public.


Interesting gap between surface scanning (6.6%) and AI deep audit (16.4%).

Two concerns with the AI audit approach. First, the defense LLM is itself an attack surface — we're already seeing payloads crafted specifically to bypass LLM-based guardrails. If the guardian is injectable, you've added a vulnerability to your security stack.

Second, the Mindgard paper from late 2025 tested 12 character injection techniques against 6 guardrails including ProtectAI's DeBERTa, Meta Prompt Guard, Azure Prompt Shield — some hit 100% evasion rate. Homoglyphs, zero-width chars, leet, diacritics. Simple stuff, but the classifiers see raw tokens and can't handle it.

I built a prompt injection detection library that tackles this from the normalisation layer — 10-stage deterministic pipeline (NFKD, confusable fold, leet, base64, zero-width strip, ROT13, escape sequences) that reduces all evasion to canonical form before any matching. The scan itself is not injectable — it's code, not a model.

Where I think this goes next: small encoder-only classifiers (DeBERTa-small, ModernBERT) running on already-normalised text. Post-normalisation, the model only needs to detect the logical intent pattern, not handle evasion — that's the layer below. Too small to be reprogrammed via prompt, too focused to be redirected. One classifier per attack category: override, extraction, jailbreak, etc.

But these classifiers will only be as good as their training data. Right now everyone trains on static datasets (deepset, safeguard). What's missing is a community-maintained corpus fed by real-world incident reports — like antivirus signature databases. The detection engine matters less than the definitions it runs on. ClamAV isn't great because of its scan loop, it's great because thousands of people report samples.

Your foundry example — no payload until the agent writes it — is the genuinely hard case that needs AI. But for everything else, deterministic normalisation + focused micro-classifiers + community-curated signatures is a more defensible architecture than putting another LLM in the path.

https://github.com/hazyhaar/pkg/tree/main/injection


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: