frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Billing can be bypassed using a combo of subagents with an agent definition

https://github.com/microsoft/vscode/issues/292452
113•napolux•2h ago

Comments

AustinDev•1h ago
Is it just me or is Microsoft really phoning it in recently?
PlatoIsADisease•1h ago
Their software seems like it. Their sales team is brutal.
VerifiedReports•1h ago
Recently? They've been shipping absolute trash for 15 years, and still haven't reached the bottom apparently.
reppap•1h ago
Azure keeps randomly breaking our resources without any service health notifications or heads up, it's very fun living in microsofts world.
my_throwaway23•1h ago
To be fair, Windows 7 was quite good in my opinion.

Wait, what year is it?

ReptileMan•1h ago
windows 2000 server and windows 2003 server were their last great desktop OSs
orphea•1h ago
.NET is actually, unironically good. But yes, this is one of few exceptions, unfortunately.
mrweasel•35m ago
Thinking back, you're probably correct, but it seems like they where actively trying to create something good back then. That might just be me only seeing the good parts, with .Net and SQLServer. Azure was never good, and we've know why for over a decade, their working conditions suck and people don't stay long, resulting things being held together by duct tape.

I do think some things in Microsoft ecosystem are salvageable, they just aren't trendy. The Windows kernel can still work, .Net and their C++ runtime, Win32 / Winforms, ActiveDirectory, Exchange (on-prem) and Office are all still fixable and will last Microsoft a long time. It's just boring, and Microsoft apparently won't do it, because: No subscription.

dotancohen•50m ago
You must be new here.

Microsoft notoriously tolerated pirated Windows and Office installations for about a decade and a half, to solidify their usage as de facto standard and expected. Tolerating unofficial free usage of their latest products is standard procedure for MS.

falloutx•41m ago
By recently, you mean since 2007
Ygg2•26m ago
By recently I assume they mean since Windows 7. Alternatively since Windows 10. 2009-2015.

Last decade it was misstep after misstep.

pixelmelt•1h ago
Was good while it lasted, I hope Microsoft continues their new tradition of vibe coding their billing systems :p
scrubs•1h ago
Oh that was pithy, mean, and just the right amount of taking-it-personally. Well done!
VerifiedReports•1h ago
Billing for what?
rf15•1h ago
The access to premium models. This much should have been evident from reading the ticket.
numpad0•1h ago
> Copilot Chat Extension Version: 0.37.2026013101

> VS Code Version: 1.109.0-insider (Universal) - f3d99de

Presumably there is such thing as the freemium pay-able "Copilot Chat Extension" for VS Code product. Interesting, I guess.

ramon156•1h ago
The laat comment is a person pretending to be a maintainer of Microsoft. I have a gut feeling that these kind of people will only increase, and we'll have vibe engineers scouring popular repositories to ""contribute"" (note that the suggested fix is vague).

I completely understand why some projects are in whitelist-contributors-only mode. It's becoming a mess.

iib•1h ago
Some were already that and even more, because of other reasons. The Cathedral model, described in "The Cathedral and the Bazaar".
RobotToaster•1h ago
> I completely understand why some projects are in whitelist-contributors-only mode. It's becoming a mess.

That repo alone has 1.1k open pull requests, madness.

embedding-shape•1h ago
> That repo alone has 1.1k open pull requests, madness.

The UI can't even be bothered to show the number of open issues, 5K+ :)

Then they "fix it" by making issues auto-close after 1 week of inactivity, meanwhile PRs submitted 10 years ago remains open.

PKop•1h ago
> issues auto-close after 1 week of inactivity, meanwhile PRs submitted 10 years ago remains open.

It's definitely a mess, but based on the massive decline in signal vs noise of public comments and issues on open source recently, that's not a bad heuristic for filtering quality.

markstos•1h ago
No where in the comment do they assert they are work for Microsoft.

This is a peer-review.

PKop•1h ago
Let's just say they are pretending to be helpful, how about that?

> "Peer review"

no unless your "peers" are bots who regurgitate LLM slop.

markstos•1h ago
You think they lied about reproducing the issue? It’s useful to know if a bug can be reproduced.
cmeacham98•1h ago
We cannot know for sure but I think it's reasonably likely (say 50/50). Regurgitating an LLM for 90% of your comment does not inspire trust.
cmeacham98•1h ago
It's not a peer review it's just AI slop. I do agree they don't seem to be intentionally posing as an MS employee.
usefulposter•1h ago
It's performative garbage: authority roleplay edition.

Let me slop an affirmative comment on this HIGH TRAFFIC issue so I get ENGAGEMENT on it and EYEBALLS on my vibed GitHub PROFILE and get STARS on my repos.

albert_e•1h ago
On the other hand ... I recently had to deal with official Microsoft Support for an Azure service degradation / silent failure.

Their email responses were broadly all like this -- fully drafted by GPT. The only thing i liked about that whole exchange was that GPT was readily willing to concede that all the details and observations I included point to a service degradation and failure on Microsoft side. A purely human mind would not have so readily conceded the point without some hedging or dilly-dallying or keeping some options open to avoid accepting blame.

datsci_est_2015•9m ago
> The only thing i liked about that whole exchange was that GPT was readily willing to concede that all the details and observations I included point to a service degradation and failure on Microsoft side.

Reminds me of an interaction I was forced to have with a chatbot over the phone for “customer service”. It kept apologizing, saying “I’m sorry to hear that.” in response to my issues.

The thing is, it wasn’t sorry to hear that. AI is incapable of feeling “sorry” about anything. It’s anthropomorphisizing itself and aping politeness. I might as well have a “Sorry” button on my desk that I smash every time a corporation worth $TRILL wrongs me. Insert South Park “We’re sorry” meme.

Are you sure “readily willing to concede” is worth absolutely anything as a user or consumer?

Cyphus•49m ago
I wholly agree, the response screams “copied from ChatGPT” to me. “Contributions” like these comments and drive by PRs are a curse on open source and software development in general.

As someone who takes pride in being thorough and detail oriented, I cannot stand when people provide the bare minimum of effort in response. Earlier this week I created a bug report for an internal software project on another team. It was a bizarre behavior, so out of curiosity and a desire to be truly helpful, I spent a couple hours whittling the issue down to a small, reproducible test case. I even had someone on my team run through the reproduction steps to confirm it was reproducible on at least one other environment.

The next day, the PM of the other team responded with a _screenshot of an AI conversation_ saying the issue was on my end for misusing a standard CLI tool. I was offended on so many levels. For one, I wasn’t using the CLI tool in the way it describes, and even if I was it wouldn’t affect the bug. But the bigger problem is that this person thinks a screenshot of an AI conversation is an acceptable response. Is this what talking to semi technical roles is going to be like from now on? I get to argue with an LLM by proxy of another human? Fuck that.

belter•21m ago
>> The next day, the PM of the other team responded with a _screenshot of an AI conversation_ saying the issue was on my end for misusing a standard CLI tool.

You are still on time, to coach a model to create a reply saying the are completely wrong, and send back a print screen of that reply :-)) Bonus points for having the model include disparaging comments...

falloutx•42m ago
Exactly I have seen these know it all comments on my own repos and also tldraw's issues when adding issues. They add nothing to the conversation, they just paste the conversation into some coding tool and spit out the info.
blibble•1h ago
the "AI" bot closing the issue here is particularly funny
anonymars•1h ago
Vibes all the way down. "Please check out this other slop issue with 5-600 other tickets pointed to it" -- I was going to ask, how is anyone supposed to make sense of such a mess, but I guess the answer is "no human is supposed to"
peacebeard•1h ago
My guess is either someone raised this internally and was told it was fine, or knew but didn't bother raising it since they knew they’d be blown off.
zkmon•1h ago
Nothing compared to pirated CDs with Office and Windows, 20 yrs back.
stanac•1h ago
They don't care, they would rather let you use pirated MS software than move to Linux. There is a repo on GH with powershell scripts for activating windows/office and they let it sit there. Just checked, repo has 165K stars.

This could be the same, they know devs mostly prefer to use cursor and/or claude than copilot.

anonymars•1h ago
What's the direct cost to Microsoft of someone pirating an OS vs. making requests to a hosted LLM?
light_hue_1•1h ago
Why would you report this?!

A second time. When they already closed your first issue. Just enjoy the free ride.

anonymars•1h ago
Some part of me says, let their vibing have a cost, since clearly "overall product quality going to shit" hasn't had a visible effect on their trajectory
brushfoot•1h ago
Even without hacks, Copilot is still a cheap way to use Claude models:

- $10/month

- Copilot CLI for Claude Code type CLI, VS Code for GUI

- 300 requests (prompts) on Sonnet 4.5, 100 on Opus 4.6 (3x)

- One prompt only ever consumes one request, regardless of tokens used

- Agents auto plan tasks and create PRs

- "New Agent" in VS Code runs agent locally

- "New Cloud Agent" runs agent in the cloud (https://github.com/copilot/agents)

- Additional requests cost $0.04 each

piker•56m ago
+1. I see all these posts about tokens, and I'm like "who's paying by the token?"
Hrun0•52m ago
> +1. I see all these posts about tokens, and I'm like "who's paying by the token?"

When you use the API

indigodaddy•3m ago
So 100 Opus requests a month? That's not a lot.
thenewwazoo•1h ago
Every time I see something about trying to control an LLM by sending instructions to the LLM, I wonder: have we really learned nothing of the pitfalls of in-band signaling since the days of phreaking?
Mountain_Skies•1h ago
It'll be a sad day for Little Bobby Tables if in-band signaling ever goes out of fashion.
quadrature•1h ago
Sure but the exploit here isn’t prompt injection, it is an edge case in their billing that isn’t attributing agent calls correctly.
thenewwazoo•1h ago
That's fair - I suppose the agent is making a call with a model parameter that isn't being attributed, as you say.
cpa•1h ago
It reminds me of when I used to write lisp, where code is data. You can abuse reflection (and macros) to great effect, but you never feel safe.

See also: string interpolation and SQL injection, (unhygienic) C macros

g947o•1h ago
> Note: Initially submitted this to MSRC (VULN-172488), MSRC insisted bypassing billing is outside of MSRC scope and instructed me multiple times to file as a public bug report.

Good job, Microsoft.

syl5x•1h ago
I did that weeks ago: https://news.ycombinator.com/item?id=46757318
sciencejerk•59m ago
Have confirmed that many of these AI agents and Agentic IDEs implement business logic and guardrails LOCALLY on the device.

(Source: submitted similar issue to different Agentic LLM provider)

direwolf20•8m ago
Who would report this? Are they hoping for a bug bounty or they know their competitors are using the technique?

Tech Independence

https://sive.rs/ti
1•ryangibb•1m ago•0 comments

The New Fabio Is Claude

https://www.nytimes.com/2026/02/08/business/ai-claude-romance-books.html
1•mold_aid•1m ago•1 comments

Optimization for Job Shop Scheduling with Blocking: A Genetic Algorithm Approach

https://www.mdpi.com/1999-4893/19/2/115
2•PaulHoule•1m ago•0 comments

The AI Bubble I Live in (and You Probably Don't)

https://thoughts.jock.pl/p/ai-bubble-living-inside
1•joozio•2m ago•0 comments

Show HN: Asterbot – AI agent built from sandboxed WASM components

https://github.com/asterai-io/asterbot
1•rellfy•4m ago•0 comments

Show HN: LM Council Let LLMs argue with each other so you don't have to

https://www.lm-council.com/
1•mvfolino68•4m ago•0 comments

Show HN: SendRec – Self-hosted async video for EU data sovereignty

https://github.com/sendrec/sendrec
1•alexneamtu•5m ago•1 comments

The disappearing art gallery in your post office

https://www.washingtonpost.com/business/2026/02/08/missing-post-office-art-murals/
2•_tk_•9m ago•0 comments

Show HN: How I use Claude to ship 150 PRs per day

https://github.com/wiggum-cc/chief-wiggum
1•0kenx•9m ago•0 comments

Metafile-codecov-bundle: track bun/esbuild artifact bundles with codecov

https://github.com/jbergstroem/metafile-codecov-bundle
1•jbergstroem•13m ago•0 comments

Skills I use with Claude for shaping

https://github.com/rjs/shaping-skills
1•tosh•14m ago•0 comments

Show HN: A small Agent framework built around Handoff

https://github.com/PsiACE/republic
1•recrush•14m ago•0 comments

Show HN: AI Cost Board – Track LLM Cost, Requests, and Errors Across Providers

https://aicostboard.com
1•tkrenn06•15m ago•0 comments

The Rise of Local ASR Models

https://oatmealapp.com/blog/the-rise-of-local-speech-recognition/
2•frostdiscord39•17m ago•0 comments

Evaluating TCP BBRv2 on the Dropbox edge network

https://arxiv.org/abs/2008.07699
1•fanf2•17m ago•0 comments

Prankster launches Super Bowl party for AI agents

https://entertainment.slashdot.org/story/26/02/08/1827216/prankster-launches-super-bowl-party-for...
2•MilnerRoute•21m ago•0 comments

Show HN: A local-first documentation tool for AI agents (MCP)

https://github.com/neuledge/context
2•moshest•23m ago•1 comments

Federal statement on Jeffrey Epstein's death dated day before he was found dead

https://www.standard.co.uk/news/world/statement-jeffrey-epstein-death-day-before-b1270109.html
10•saubeidl•24m ago•4 comments

Preserving the Open Web: Inside the New Wayback Machine Plugin for WordPress

https://blog.archive.org/2026/02/04/inside-the-new-wayback-machine-plugin-for-wordpress/
2•Tomte•26m ago•0 comments

Updates and Bot Wars

https://marisabel.nl/public/blog/Updates_and_Bot_Wars
3•todsacerdoti•31m ago•0 comments

Seven Pages of a Sealed Watergate File Sat Undiscovered. Until Now.

https://www.nytimes.com/2026/02/08/opinion/trump-nixon-watergate-radford.html
3•themgt•32m ago•0 comments

Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/
21•nullcathedral•35m ago•1 comments

Latest Epstein files reveal disgraced financier's Silicon Valley connections

https://www.france24.com/en/latest-epstein-files-reveal-disgraced-financier-s-silicon-valley-conn...
7•mgh2•35m ago•1 comments

Hackers arrested after being hired by Iowa to pentest courthouse win case [video

https://www.youtube.com/watch?v=x1txcEPPhrw
5•hajile•40m ago•0 comments

Google is killing authentic websites and I made it worse [video]

https://www.youtube.com/watch?v=II2QF9JwtLc
5•basilikum•41m ago•1 comments

Specification Driven Development

https://www.joshuapurtell.com/posts/spec_eng/
2•JoshPurtell•41m ago•0 comments

A header-only C allocator library

https://github.com/abdimoallim/alloc
2•abdimoalim•43m ago•1 comments

Experts Have World Models. LLMs Have Word Models

https://www.latent.space/p/adversarial-reasoning
5•aaronng91•46m ago•1 comments

Prepare your OSS repo for AI coding assistants

https://angiejones.tech/stop-closing-the-door-fix-the-house/
2•hashim-warren•46m ago•0 comments

Hud: Runtime Code Sensor for Production-Safe AI Code

https://marketplace.visualstudio.com/items?itemName=Hud.hud
2•aanthonymax•52m ago•0 comments