HN user

MrDarcy

656 karma
Posts0
Comments283
View on HN
No posts found.

But how do you find a respectable one, in a gold rush?

Look for those who are trying to serve established respectable professions, ideally have already done so for many years or decades. Accounting, Legal, Healthcare, Journalism (in the ideal sense).

Then look at their own mission. Then look at their own work. Do they show their work? Are they open? Do they willingly allow their customers to audit their work product? Does how they talk about their work match the work product itself? Does the thing do what it says on the tin? Are they hypocrites with respect to those they serve or those they manage?

These are my strategies and I’ve found they lead to working almost exclusively with people who have high Integrity.

The article is incorrect and misleading. Railway did have an account manager and they did call them and they did pick up the phone and work with them to restore service.

Google I/O 2 months ago

Nobody has taken away the freedom to program like we used to. Punch cards may be more expensive now, but vim and emacs are still as free as they ever were.

Google I/O 2 months ago

Clearly a matter of opinion and circumstances. Plenty of people with effectively zero cost access to agents who see value in implementing an operating system from scratch. The team who made the demo for example, and those of us who see the possibilities the demo inspires for another example.

There’s no way this was automated or silent.

The only reasonable explanation is Railway lost control of their estate and something was happening that warranted a group of humans to decide flipping the kill switch was the best of a set of bad alternatives.

Google I/O 2 months ago

Which is good. Why reinvent this particular wheel? Even I, a grey beard 30 year vim user appreciate VScode as my daily driver.

The error and omission of not enforcing mandatory security training covering posting plaintext passwords to public sites for CISA contractors is itself an act of gross negligence.

So much so the contracting company’s insurer would cite it as the reason why the claim is not covered by their policy.

Halt and Catch Fire 2 months ago

A reasonable proposal from a single person outside the IETF seems most likely to succeed.

It’s not like the IETF have any obvious success managing or deploying solutions to IP problems known for over 30 years.

Recently went with a vendor of an agentic observability and evaluation product built on Supabase and Clerk. The number of vulnerabilities and CVE’s and outright… I don’t even know the words, coming from this stack is staggering.

Be very very wary of any vendor selling something built on this Supabase + Clerk stack. That alone is a very strong indicator they do not understand basic security or data protection.

The purpose of a sandbox is to control the interface between inside and outside of the sandbox. If you put the harness on the outside and connect it to a model and to an API then there’s no point in the sandbox. You don’t have any control over the interface.

A lot of what an agent does doesn't need a sandbox at all: thinking, calling APIs, summarizing, waiting for CI.

I don’t get it. Calling an API requires a sandbox in most cases. The others could be abused in service of an un-sandboxed agent with API access.

If the harness is outside the sandbox then it’s just an ambiguous and confusing security model and boundary.

This usage pattern is a few months behind the curve. It’s effective at full on feature development now. Keep it fed with plans and it’ll keep implementing, leaving the codebase better than it found it each cycle.

Not sure why this would catch heat rationally speaking. It is quite clear in a professional setting effective use of coding agents is the most important skill to develop as an individual developer.

It’s also the most important capability engineering orgs can be working on developing right now.

Software Engineering itself is being disrupted.