HN user

c7b

1,554 karma
Posts4
Comments508
View on HN

UX is not the problem with Passkeys. Passkeys were designed to align with the interests of BigTech, who are bent on stopping the abomination that is general computing devices in the hands of consumers and forcing them into their walled gardens. The language that is used for taking away freedoms is the same as always, safety. Where we ended up with Passkeys is an operating model that is suitable for corporate devices, i.e. the user can only do what the owners of the device allow them to. Suboptimal UX is downstream from that problem.

git as-is is completely unfit for purpose and a huge security risk for this use case, because it uses MD5, which is no longer collision-resistant.

If your proposal is 'something like git, with a few modifications to make it suitable for this use case', then that's exactly what I'm proposing. What you will need, once you've considered all requirements to the best extent feasible, will be a blockchain. Eg you do need the ability to make protocol updates, no matter the time scale of transactions.

Clearly, you would scope the features and choose implementation options so that it makes sense for the use case. Mining (ie PoW and/or Nakamoto consensus) is clearly inferior to any deterministic consensus here. A cryptocurrency isn't necessary and would be a distraction. But at least some limited programmability could make sense (eg for escrow).

That is what I'm saying. And you may be right, but the security guarantees are math and math is patient. If people decide to ignore it today, it'll still be true any time they decide to take another look.

Agreed that you don't need total ordering and hence consensus for pure asset transfers. But if you want to make any changes at all, like updating the list of nodes, you do. So in practice, you do need it. Every other proposal will fall short in a critical and avoidable way. Amending your git proposal with the necessary parts will turn it into a blockchain.

You can put an index on your blockchain DB, what are you talking? Every node can manage it as it pleases (within the limits of the consensus algorithm).

Yes, if you have a centralized model you don't need it. Just saying that this incident is the exact risk a blockchain is meant to mitigate through redundancy. You can say you don't care about this risk, but it doesn't change the truth of the statement.

Internally, you don't need it, agreed. But that is centralization risk exemplified in this incident. Which isn't necessary. Every notary could be a node. It would be a lot more resilient, and it would look a lot like a blockchain (not necessarily with a crypto currency though) if you do it properly.

A blockchain solves the problem of consensus under Byzantine faults. Payments are an incidental use case, and not even a good one because managing payments including avoiding double spending can be achieved with a weaker primitive than consensus.

A blockchain isn't stopping you from doing any of those things, if anything it's facilitating different backup models by different parties. A paper record is so much more susceptible to various kinds of risks, adversarial and otherwise. I recommend to look past the hype or hate at the technology. A blockchain is the logical extreme of where you end up when you think about how to sync backups, and you recognize that it comes with certain mathematical limitations on how much disruption you can handle.

Neural machines were always going to be an alternative computing paradigm to von Neumann machines. Had it not been for Minsky we would arguably have gotten to a point where they're useful sooner. But why do you say that as if it's a small thing?

Agreed, the Strix Halo doesn't feel good enough for $4k. It was supposed to be $2k (and was so until 6-12 months ago), which felt like a great deal. Not the best AI chip but you get what you pay for. A tinkerer's dream that could maybe even fit into a birthday gift budget for a lucky teenager. I hate to say it, but I hope they fail with their $4k box.

Bit of a tangent, but it's fun to think about how much it takes to become a -er, -ian or -ist in a given field. Philosophy is probably one of the hardest, you need to be seen as up there with the all-time greats. In history or physics you probably need to be faculty, in economics you need to have a PhD, in engineering you don't even need a degree but you need to be practicing,...

Hmm the list is a bit underwhelming. Basically, it's unnecessary requests, bloated JS, unoptimized images and generally poorly structured code. I would hate if that was where the average website is headed, but realistically, we were already headed there before LLMs. From the headline I was expecting CVEs, broken UX flows / business logic, leaked secrets.

Even more important in a local context is the difference between token generation and prompt processing speed. We tend to focus on the former, but for multi-turn/agentic workflows the latter can dominate.

You're the one making things up. An M3 Ultra with 128GB RAM doesn't exist, the M3 Max has 410GB/s bandwidth [0]. I was of course talking about the M4 Max with 546GB/s, which was closer to twice the price of a Strix Halo mini PC in a typical configuration when it was still available. And memory bandwidth isn't everything, NVidia's lead in software is substantial, look up any tests comparing them side-by-side.

[0] https://en.wikipedia.org/wiki/Apple_M3 [1] https://en.wikipedia.org/wiki/Apple_M4

The M4 Max with 128GB RAM has 546GB/s memory bandwidth [0], compared to Strix Halo's 250 (on the label, I've yet to see a benchmark that tops 220). It's not available at 128GB RAM anymore, at least in my shop, but when it was not so long ago it was about 4,7k, or a little over twice the price of a cheaper Strix Halo PC (around 2,2k a few months ago).

[0] https://en.wikipedia.org/wiki/Apple_M4

But ideally they would be competitive, right? If your goal is LLM or Diffusion inference or - god forbid - training, you're going to get way better performance on DGX Spark. The difference is more stark than 250 vs 273 GB/s bandwidth delta would suggest.

Now I think it's totally fine to have a less capable offering, and the Strix Halo is still a mighty capable machine for inference on mid-size MoEs. At 2k it was a tinkerer's dream. But the performance difference should be reflected in the price. This is roughly a doubling of the price compared to less than a year ago without adding any notable features, it's appalling.

This is just a little under the price of NVidia's DGX Spark with CUDA or a Mac with 128GB and twice the memory bandwidth. The point of Strix Halo used to be that it was half the price of those way more capable machines. You'd be crazy to buy the AMD chip at this price. But the hardware market is generally crazy right now, so I'm sure this will sell as well, unfortunately.

I'm sure there will be a fix for it, but it illustrates an important broader point I should probably have made above: if you opt for local AI today, expect to run into some issues. Expect to learn a bit about the tools you're using, the not-so-fun way. I'm not recommending it to non-technical friends (yet).

I'm not sure what you're trying to say. Is that a good or a bad thing? Model distillation is presumably part of the reason why Qwen is so good, yes. As a consumer, that's a good thing I would say. It's a natural counterbalance to the monopolistic tendencies of other tech segments.

If you have ethical concerns, model distillation feels like an arbitrary line to draw. Why is the first type of piracy ok, the second not? You should restrict yourself to ethical open source models. Which is btw where I genuinely hope the future of local models is going to lie. Open weights is not enough, we need fully open source models to be sustainable. Even for simple things like updating the knowledge cutoff. How we are going to distribute the training effort will be an interesting problem where I don't see an obvious solution yet. Maybe the blockchain/federated learning people can suggest something. Or university consortia, or some public sector solutions. Or something really boring - I for one would absolutely be willing to pay for DRM-free weights of an open source model (even if I could pirate them for free).

Web search, MTP (speeds up generation), uncensored models. Lots more things on my bucket list (eg various things related to image generation).

Not gonna lie, if you're coming from ChatGPT/Claude Code, you'll mostly be adding back features you've taken for granted, or solving problems you wouldn't have had. But sometimes you do get some extra utility, like uncensored models, which have become my go-to. Not because I'm doing anything saucy, but I hated how I'd become trained to pre-emptivly self-censor my prompts. The guardrails in open weights models are no less strong than in proprietary ones, subjectively even a bit stronger in Qwen. But luckily there's an entire sub-discipline of model ablation. Another advantage would be better control over image generation (although I can't attest to that, yet).