There is a growing misconception that the GDPR and similar laws give complete control over any user-contributed inputs to a website, but that’s not true.
It has been widely misinterpreted as a tool to force website operators to remove anything you've contributed to the website or any information about you, but that is neither consistent with the language of the law nor consistent with what the courts have found.
You are free to remove your own e-mail address from an account (visit your account page) or to never provide any identifying information at all to the website. I've also seen the moderators change account names away from identifying information for those who request it.
However, there is no GDPR requirement that websites must universally delete any and all contributions you provide to a public website if you retroactively decide you don't want you public posts to be public.
Like I said, I doubt casual HN commenters have a better grasp on the law than Y Combinator's legal team.
I accept that if someone data-mined every comment by said user, they might be able to build a picture of said user clear enough to identify them (e.g. posting times might indicate likey country of origin). Possibly, depending on the content they posted.
(I'm just thinking around the problem. I'm not a security/privacy researcher designing systems I'd like others to use, just an interested user curious where the lines in the law lie, and also what the threat models might be to me as a user.)