I assume this is slow and that makes me curious - what are you using this for?
HN user
chr15m
comes with absolutely no warranty
https://mccormick.cx
https://github.com/chr15m
https://youtube.com/mccormix
Actions speak louder than words.
"didn’t you say that you check all the AI generated code for Redis?"... Yes, I do
For important code (Redis) he is still reading the diffs.
but: try it yourself, you will discover you can’t just say “implement XYZ” and see it working.
Yes, good software still requires engineering today.
I am working on a local first LLM frontend that saves all chats directly to your hard drive and ships in a single index.html file artifact that you can self host.
No code to show yet. I'm taking the time it requires.
The universal human language is not music, it is donut.
Extremely useful if you are, say, trialing a novel chemotherapy drug and want to end your trial ASAP to get everyone on the intervention arm if the drug actually works.
They are extremely useful for that, yes.
Yes, exactly. Absorption barrier.
The most important part of this for a living human being is touched on at the end. You only die once. Life expectancy is an ensemble mean over a population, and "you are not a population". You need to try to avoid risks that are going to kill you personally, not risks that affect aggregate life expectancy (there's overlap of course). Tinkering with HR-translated-to-life-years I think actually blurs that focus for individuals.
The worst case is a risk that has a low ensemble HR and low life years impact, but will kill you personally very soon if you take the wrong action. Eating peanuts has an HR of 1, unless you are prone to fatal anaphylaxis from peanuts. HRs are useful for (and biased towards) doctors protecting as many humans as possible, but as an individual you should try to discover your peanut allergies as early as possible and protect yourself against them.
Correct. The argument is not about the deployment or the technical quality of MLKEM. Pretending it is, is an appeal to authority, and is moving the goal posts from the actual argument.
I have edited my post to remove the rude acronym. Thank you for your feedback.
I do not think the response addresses the claims made, and uses logical fallacies in place of a well reasoned response.
a team of highly-regarded European academic cryptographers
This is absolutely an appeal to authority.
An important lesson.
Congratulations Citizen, you have complied with the mainthink.
the code which implements a client-side web application is distributed by the given website
Incorrect, and trivially falsifiable. Examples:
- Self hosting, where you control both client and server.
- Loading a web app from file:///
- Loading a web app from localhost.
The author's "no exceptions" is simply wrong.
The author also seems to assume the same server is required to both serve the code and store/transmit encrypted messages which obviously isn't the case. In addition the statements about service workers are ignorant.
The rest of the analysis is largely correct and the threat outlined (where somebody can replace your client) is a serious one that many underestimate. In particular the proprietary native mobile app model is vulnerable to this, as mentioned.
These problems come from giving LLMs too much agency. The fix is to ruthlessly manage context yourself, and use a harness that only allows one LLM response at a time. Don't leave context up to the LLM, and check everything it is doing. This gives you most of the speed increase while still giving you clean, concise, human-reviewed code.
I mean we need "a field guide to hand-written HTML for the modern front end developer."
We need the exact opposite of this.
The map is not the territory.
Here's the original paper if you want to skip the slop: https://keremcosar.uvacreate.virginia.edu/publications/BCCH-...
you’re criticizing a powerful politician, or talking about your experiences with abuse or addiction, or discussing embarrassing medical issues you’re facing
This is not the problem. Even if, like millions, you are not talking about these things online, these systems still place you in danger. Even if you are a perfect, clean, compliant citizen these privacy-destroying systems place you in danger.
Fundamentally these systems expose you to coercion, extortion, blackmail, ID theft, etc. by criminals and immoral people who want money or power over you. There are countless examples of bad actors inside and outside these systems obtaining access to innocent people's private data and misusing it to their detriment.
This is the strongest argument against these bad ideas. Arguments that paint innocent, privacy-seeking people as suspicious or immoral in any way, should not be used.
It is rational and moral to seek privacy for your own safety and the safety of those you care for. Don't let them argue otherwise.
Yep, it's sunlight.
Nobody will run that trial though because we've spent decades telling people the sun is dangerous and gives you cancer (both things can be true of course). Putting people in the sun every day would not pass ethics tests.
Also you cannot sell sunlight.
Yes and you could probably do it serially, trading off slower speed for higher intelligence.
I found this juxtaposition of facts telling:
Drug design: Using Mythos 5, our internal protein design experts accelerated... Nine of the 14 protein targets from this study (shown below) yielded strong candidates for *drug design that we’re currently investigating*.
(emphasis mine)
queries that are beneficial in the hands of cybersecurity professionals and biology researchers could be dangerous if available to malicious actors... When Fable’s classifiers detect a request related to cybersecurity, *biology and chemistry*, or distillation, the response is automatically handled by Claude Opus 4.8 instead.
All of the things they are nerfing are things that they also intend to profit from themselves.
- Cybersecurity - selling this to companies and US gov through "Glass Wing".
- Selling inference (distillation risk).
- And now, drug design.
I'm extrapolating "currently investigating" to "are going to monetize" but I don't think that's a big stretch. They appear to be using safety as a cover for anti-competitive behaviour.
It's smartphones (~2008).
Brevity is a more accurate indicator of effort than length.
"I would have written a shorter letter, but I did not have the time." -- Pascal, 1657
Marge, those people chased us with pitchforks and torches. TORCHES! At four in the afternoon!
I constantly find myself accidentally selling your product to people just because I find it so useful myself. It's great, please don't ruin it, and thanks for making it. Congratulations on the raise and best of luck!
The point is the Foundation is rich. Seventeen-plus months of operating runway in the bank.
I don't think "rich" is the correct way to describe this. It sounds like a lot of money but there are a lot of expenses and people to pay. Seventeen months sounds fragile - one long-ish recession and they're toast. I hope they survive.
the more barriers there are the better
No. Barriers have tradeoffs beyond simply safety. Safety is often possible without these barriers. False dichotomy.
Yes it's often a problem. I am a Joplin user. Many times I have thought "X would be so much easier if these were just Markdown files on disk." Joplin has an API you can use, but it's annoying. Files on disk would be better.
if you want always direct edit access and do it often why not then a simple plain text
I like the Joplin UI and features. I also have use-cases where I want plain text access outside Joplin. Obsidian shows its possible to have both (but I also want software libre).
This new version is not something you'll be able to run locally. It's a "cloud" model and likely too beefy if they do release the weights.
Side note: don't underestimate how much literal, physical time and energy "unfold" implies. Proofs occur on physical substrates.