HN user

bornfreddy

2,237 karma
Posts3
Comments1,002
View on HN

For me, Fable is useless. It goes its own way and doesn't communicate much even if explicitly asked to. Sure it builds a lot of stuff, but it is more often than not useless because it misinterpreted the intention and didn't stop to ask - and because it doesn't communicate, it goes unnoticed for too long. Opus is much better for regular work, imho.

Using a Chinese LLM will not put a Marxist under your bed.

Interesting tangent - it might be taught to introduce stealthy backdoors in your company though. Maybe even across multiple PRs where each session puts a small chink in the armor, and together they allow unlimited access to the attacker who knows about them.

After all, LLMs are mostly black boxes. How comfortable would you be running a Chinese compiler?

...many pages simply do not work properly with it,...

Using Google's websites much, are we? FF works great everywhere except there. I think the official term for the bugs on these pages is "oops"...

I use FF everywhere except on G pages, where I use Brave.

GLM 5.2 vs. Opus 1 month ago

With openweights? Yes. It might halucinate a backdoor somewhere ( not that you can trust any model about that), but it will still work.

GLM 5.2 vs. Opus 1 month ago

I know that running this locally is prohibitively expensive (for now), but what kind of cost would I be looking at if I wanted to rent the hardware and run the model by myself?

5-10 minutes? I'm sold. Any link you can share?

I'm saying this as someone who has learned about CORS protections many times, implemented the solutions with care they deserved, but forgot most of it soon after - each time. So I'd be very happy to invest even 15 minutes to break this cycle.

Just had 10 rounds of busses, motorcycles and fire hydrants with Google before I decided I don't actually want to see that page so much. So Cloudflare is unfortunately not the only offender here.

I didn't try telling to be concise and stop pampering me yet (but good idea, tomorrow), however I found that instead of me writing agent instructions, it works much better if I tell claude to write instructions for itself. I do check if they make sense of course, but its wording works much better than mine.

This might not describe you, but I've met quite a few people who made similar claims. The problem usually wasn't that their counterparty didn't want to hear the truth. More commonly, the problem was that these persons assumed (and were convinced) that they knew the truth. Truth is rarely absolute and someone claiming to know it is a red flag in my book. Double so if multiple persons indicated their disagreement. Again, not knowing the exact question and answer it is impossible to say if you are an exception, but even if you are, you need to improve communication skills - what good is knowing "the truth" if others reject it?

That said, best of luck on the job hunt! Sometimes it just takes some time for the right opportunity to come along.

My pet peeve with the NY Times online is that there's no escaping the upsell screen after logging on.

I know this is not your point, and you should not be forced to do this, but uBlock Origin has a very nice filter which can hide DOM elements on the page if you set it up. Lifesaver with annoying webpages.

Sorry for late reply, just noticed your post.

We are talking about different threat models. I trust Google not to hack my phone, but I don't trust them not to spy on me. So yes, running a Google binary blob in privileged mode occasionally is preferred to running non-privileged Google binary blob all the time (otherwise push notifications do not work on GrapheneOS, IME).

I never used App Lounge but always F-Droid directly, or Aurora Store, so I can't comment on that.

But more importantly, you seem to confuse my rant against GrapheneOS not supporting MicroG as an endorsement of /e/OS. I know they have their set of problems, some of which you outlined. However if my goal is to limit communication of my device with Google as much as possible, then they (/LineageOS) still win. Which is a pity, I like GrapheneOS security focus otherwise, but my primary priority is degoogling my phone as much as possible (and no, it is not possible to do it completely without serious tradeoffs I am not willing to make).

There is no privacy advantage by using MicroG compared to Google play services. You still connect to there service all the same giving privileged access to your device.

...assuming you are connected all the time, or at least that the services are running all the time. In my case they are not. I only enable them every once in a while, when I need to be alerted of something. This might not be how most people use their phones, but I do it because there is no way to preserve any privacy at all if you are running Google services 24/7 (sandboxed or not).

I see Google services as malicious software - not security malicious (Google can't risk that) but privacy malicious. This is why I care more about ability to turn them on / off than about what kind of access they have. Even inside the sandbox, as regular apps, they have way too much info about me.

As I said: I would prefer sandoxed MicroG, but given the available options non-sandboxed MicroG is preferable to sandboxed always-on Google services.

You are missing the point. MicroG allows me to disable it when I want to, and push notifications still work when I (rarely) need to enable it.

It's not about security, it is about privacy. While MicroG in theory could bypass NetGuard, I very much doubt that anyone would bother. My privacy is not that precious.

But as I said, neither solution is great. How about sandboxing MicroG too?

Great experiment, hilarious! It would be interesting to see how 2 separate Claudes (or GPTs, or...) would behave - would they develop similar personalities?

No Google Maps or Android Auto on my phones, so I don't care much about privileged access - they have none anyway.

No, microG is definitely not talking to Google all the time, NetGuard would warn me if it did. I would assume it is not even running when I disable it (which is easily done, as opposed to stopping Google Services in GrapheneOS) - but to be fair I didn't actually validate that.

I kind of like GrapheneOS otherwise, this is by far my biggest gripe. I can even survive the icons. But avoiding Google (and other big tech) is the reason I am not on a cheaper and more convenient phone with regular Android, so if GrapheneOS refuses to support an alternative to Google Play Services, I'm not too happy about it. If there are real problems with microG then I'm sure the authors would be interested in a better solution too.