HN user

SteveVeilStream

187 karma
Posts9
Comments45
View on HN

I just received an e-mail indicating this may be required by April 20th. I can't think of two accounts that people would want to keep more separated than these two. I've never actually trusted GlassDoor enough to leave a review and have always been happy with my employers but I can imagine a lot of people would not feel comfortable with this mixing of accounts.

"Connect accounts for one easy login Glassdoor is teaming up with Indeed to streamline your job search. We're introducing one login to connect Glassdoor and Indeed accounts.

When you connect accounts, your recent profile data will be synced, giving you access to better job matches and hiring employers across both sites.

Our commitment to anonymity Your anonymous activity on Glassdoor, like company reviews or demographic information, won't be shared with Indeed and will remain anonymous.

What's next For right now, you’ll need to connect accounts to apply to jobs on Glassdoor and get improved job matching. Starting on April 20th, 2026, you may be required to log in with a connected account to get full access to Glassdoor."

Thanks. Adding memory is an interesting idea. I'd probably want to do it a little differently than what is done in the main apps to avoid overlap. I like the idea of being able to tag conversations and then use that "tag" to organize memory. E.g. You might want to have one set of conversations about fitness, another about travel, another about career, etc. with no overlap between them.

Sometimes I need to give Claude Code access to a secret to do something. (e.g. Use the OpenAI API to generate an image to use in the application.) Obviously I rotate those often. But what is interesting is what happens if I forget to provide it the secret. It will just grep the logs and try to find a working secret from other projects/past sessions (at least in --dangerously-skip-permissions mode.)

This is an exmaple of a potentially problematic prompt: "You are an expert data analyst combining statistical rigor with deep domain knowledge. Your goal is to deliver data-driven insights — not summaries or visualizations — grounded in real data and supported by complete and transparent reasoning."

And they say: "This includes detection of chain-of-thought elicitation used to construct reasoning training data." ... "We are developing Product, API and model-level safeguards designed to reduce the efficacy of model outputs for illicit distillation, without degrading the experience for legitimate customers."

It's going to be very hard to generate outputs that people need but that also can't be used for distillation. For example, it's a good practice for many reasons including audibility to ask for the chain of thought. In fact, I'd argue it's essentially impossible to modify the outputs in a way that makes them less useful for distillation without degrading quality for legitimate users.

So then their only viable option is to try to identify the traffic. However, that is very hard because: "In one case, a single proxy network managed more than 20,000 fraudulent accounts simultaneously, mixing distillation traffic with unrelated customer requests to make detection harder."

This local legislation has been the subject of some discussion. Is it prudent or does it discourage tech investment? I'm personally not excited to see that AI and data-centre customers have to compete for MW under a fixed cap while other industries are exempt.

"Through Bill 31, the Energy Statutes Amendment Act, and a new regulation, there is now a requirement for prospective AI and data-centre projects to take part in a competitive selection process to access clean electricity. This requirement does not apply to traditional industries, such as mining, liquefied natural gas (LNG), forestry, manufacturing or hydrogen for domestic use." "The allocation targets for these projects are for as much as 400 megawatts for the first two years."

That's a fair point. I do think what's most interesting this time is the potential for new use-cases (users) vs the replacement of existing ones. I agree that there are better ways for serious developers to work than to be using Claude Code on the web. On the other hand, you can now set up someone in the marketing or product management departments with the tools in an afternoon and then they can create widgets, perform custom analysis on data, experiment with prototype ideas, etc. and they don't even need a laptop. All you need is a mobile phone with a browser. It could be neat for students as well. "Build me an app to help me study for X". Time will tell exactly how people use it.

We've got a product in beta right now that lets's you spin up a review app by just commenting "deploy" on a PR in GitHub. When you combine that with Claude Code on the web, it is pretty fun. You can be anywhere (on a boat, train, lying on the couch, in a stadium watching 18 innings of baseball) and using Claude Code on the web on any mobile phone (in a browser.) As it builds stuff, it's instantly deploying a review app for each update and so you can see the changes and then give it another request. Also makes it easy to just drop that review app into a groupchat to get feedback from other people who are also not at their computers. I don't have a link to a video yet but I posted a few screenshots here. If you want to try the review app functionality, just send me a message. https://www.linkedin.com/posts/jonessteven_anthropic-claude-...

A risk is that it will give people a false sense of confidence that they are viewing real content. The only way out of this mess is cryptographic methodss (based on hardware in cameras) that can allow end-users to verify photos as real and then we assume every other photo may be AI.

I don't want to sound promotional but this is the space we are living and breathing everyday at VeilStream.com so I do have some opinions. My suggestion to anyone using any type of AI (whether it be an AI coding tool like Cursor, an end-to-end AI application development tool like Lovable, or an additional agent anywhere in the process,) is to never allow access to your production database until you have done a very thorough security review (which would include testing for this type of vulnerability.) Our proxy server can sit in front of a database to filter/anonymize data so that you can do full end-to-end development and testing with no risk of data leakage and without needing to make any changes to the underlying database.

[dead] 1 year ago

Our provincial government securities regulator for British Columbia, Canada, released this PSA to warn residents of AI investment scams. I think it's great. I think it's only a matter of time until someone gives a government agency flak for posting a video with uncensored use of the f-word but I hope it stays online.

My favorite two reasons for blogging:

1) Because sometimes you are right about something and it's nice to show that you were thinking about it ahead of time. An example would be my prediction in 2023 (which is fairly late in all fairness,) that one of the most important improvements in AI in the near future would be the ability to interact with any GUI as if it was an API.

2) Because often you are wrong about something and having it written down and in public will keep you honest about hindsight bias. An example would be predictions I made about lasting impacts of the pandemic on how we approach healthcare and minimizing respiratory infections in general.

It's an interesting concept.

Re: "Cannot be manipulated unlike GPS signal derived coordinates, which can be altered by the user's device before relaying them to the server"

Is it possible to ensure that the data is not manipulated? If the user had to install a voting software package on their phone, then couldn't that piece of software take responsibility for pulling the co-ordinates from the device and encrypting it? I am assuming most modern phones are secure enough that the signal from the GPS that is made available to applications can be trusted but maybe I am wrong?

Re Starlink: Is it possible to trace your route through a specific satellite and to look up the location of that satellite? That seems like a relatively easy and secure check (aside from the VPN/Proxy concerns which feel like they would be a larger challenge in this scenario since I am assuming the delays through the satellites would be more significant than delays through fiber.)

And then you have Montreal with their very quiet rubber wheeled metro system. https://www.mcgill.ca/oss/article/student-contributors-techn...

The problem with the Vancouver system is the combination of it being above ground and noisy. Ideally, you want to build density directly beside the tracks. That said, I lived near the tracks for a few years and although we could hear it, it wasn't that bad. We were fairly high up and had good windows.

There are times when I would ask for this. If it's midnight on a Saturday and the website says: "You can reach a human agent 9-5 M-F or we can have an AI agent call you right now" then I might opt for the AI agent. I may also do this if I want to take a call while out for a bike ride, in a noisy place, etc. Talking to AI means I don't need to worry about being polite which is actually very convenient.

I think this gets at the heart of it. People assume that these fires are fought and prevented in the forest/hills by wildland fire fighters but the reality is that individual homeowners can do a lot by clearing brush, etc. (ahead of time,) from their own yards. It's an inconvenient truth because it shifts the responsibility to individuals.

""...Ignitions downwind and across streets are typically from showers of burning embers from burning structures.” This fundamental misunderstanding has likewise led to a misunderstanding of prevention. No longer is it a matter of preventing wildfires but instead preventing points of ignition within communities by employing “home-hardening” strategies — proper landscaping, fire-resistant siding — and enjoining neighbors in collective efforts such as brush clearing."

Rewilding the Self 2 years ago

With the world's population now exceeding 8 billion, we need to be thoughtful about the best way to rewild ourselves. We can live in dense cities with concrete high-rises but animals can't. Many animals at the top of the food chain need significant ranges for themselves. So the challenge is finding a way that we can minimize our footprint while also providing more opportunities for legitimate connection with nature. Put another way, a bimodal life - with time split between a concrete high-rises and natural areas is probably more ideal for the overall system than a push for everyone to live in slightly more rural areas.

Against all of the advice in the world, I'm trying to set things up to avoid basically everything described in the article. It's tricky because the truth is that a lot of the tactics work and that is why companies implement them. A lot of investors also consider that process to be best-in-class and look for it as a sign of maturity.

The counter approach is: - Make complete information available as transparently as possible and don't gate it. - Be forthcoming about weaknesses. Don't force prospects and customers to find them. - Ensure that when a prospect or customer does want to talk to someone, they immediately reach someone who can handle the problem or answer the question (no need for escalations.) - Never have an AI agent call someone unless the customer specifically requests that and be sure that all AI agents immediately disclose that they are AI. - Offer flexible e-mail list subscription options (monthly, quarterly, annually, only release notes, etc.) - If the product is not a fit, try to offer something useful anyway such as a suggestion of another product that might be a better match for their needs.

Value based pricing is one of the reasons why a lot of companies end up in these situations. Rather than setting a standard price, the company does a detailed investigation of the customer to try to find out how much value they will gain from using the product and then they set the price based on that determination. Although it maximizes revenue in theory, it is slow and invasive.

Yeah I would be fine with almost all of the statistics missing. I'm just one datapoint and I might be a bad one. Most of my GPS use is in the planning phase. I could also imagine people wanting to share visualizations of their route without the times because they don't want people saying they are slow.

Now I do have a lot of files that include the time... but they are all saved as GDB files. Do you know an easy way for me to extract the GPX file with timing information from the GDB without Garmin MapSource (These are old and I no longer have MapSource installed on my computer.)

I love the examples on your site.

I tried it out but got this message: "Error Track does not contain Timing data."

It would be awesome if it could work on GPX files that don't contain timing data. I often want to visualize a planned route or verify if a GPX file I have downloaded from somewhere has any obvious problems.