“ Worst case: Claude does something unexpected on a disposable VM.”
.. with a valid SSH key unless I’m reading it wrong?
HN user
“ Worst case: Claude does something unexpected on a disposable VM.”
.. with a valid SSH key unless I’m reading it wrong?
The fact this study even exists is a sign of something having gone very wrong IMHO.
The notion of tracking if time spent on anything helps “prevent burnout” speaks volumes to how we view ourselves as consumables.
The whole culture we have emphasises trading working the best years of your life just so you can (maybe) rest for a little while at the end of your life when your health is failing, which has always been really sad to me.
It's 1AM in San Francisco right now. I don't envy the person having to call Matthew Prince and wake him up for this one. And I feel really bad for the person that forgot a closing brace in whatever config file did this.
"In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Dec 05, 2025 - 07:00 UTC"
No need. Yikes.
Claude offline too. 500 errors on the web and the mobile app has been knocked out.
Seems like it. Claude just went offline and is throwing Cloudflare 500 errors on the web interface.
I was under the impression (admittedly from an article I read a couple of years ago) that the consensus within the company was pretty much always that robo-taxis were one man’s pipe dream.
Weren’t there also disclosure documents a couple of years ago when they were trying to license autopilot that said they believed internally they were at level 2 as opposed to 4/5? (I might be remembering this part wrong)
Right but when do I get my cheap Tesla?
All of which would be better than what the post is advocating and I totally agree with this.
I don’t think we need to be calling people incompetent over a disagreement.
Are you suggesting that not opening the ports to any other services means they’re no longer a vulnerability concern?
That would be.. concerning.
Literally no-one said that.
(Some of) the reasons why you would do this are explained (I thought clearly) above. None of this is security through obscurity.
I agree in principal but not in practice here.
If you’re using a typical docker host, say CoreOS, following a standard production setup, then running your app as a container on top of that (using an already hardened container that’s been audited), that whole stack has gone through a lot more review than your own custom-configured VPS. It also has several layers between the application and the host that would confine the application.
Docker would increase the attack surface, but a self-configured VPS would likely open a whole lot more windows and backdoors just by not being audited/reviewed.
I absolutely am! Doh!
because FC runs on any hardware evenwithout dedicated GPUs
Twenty years of memes disagrees wholeheartedly
It’s great that this isn’t hurting them but it leaves out a lot that makes me a bit nervous about this being taken as advice.
They’re advocating deploying a binary as preferable to using docker, fair enough, but what about the host running the binary? One of the reasons for using containers is to wrap your security hardening into your deployment so that anytime you do need to scale out you have confidence your security settings are identical across nodes.
On that, the monolith talked about here can be hosted on a single VPS, again that’s great (and cheap!), but if it crashes or the hardware fails for any reason that’s potentially substantial downtime.
The other worry I’d have is that tying everything into the monolith means losing any defence in depth in the application stack - if someone does breach your app through the frontend then they’ll be able to get right through to the backend data-store. This is one of the main reasons people put their data store behind an internal web service (so that you can security group it off in a private network away from the front-end to limit the attack surface to actions they would only have been able to perform through a web browser anyway).
That’s a rather generous assumption.
Do Apple definitely not retain a key? If they don’t is the encryption quantum secure?
That seems like the worst option. Everything up to the free tier would stay there forever with no way for you to ever request it to be deleted.
Were Linux and git made with Scandinavian longing?
He’ll never tell you. He’ll just stare sullenly at you on a crisp November evening through the frost-coated glass of your remote log cabin until slowly he’ll raise one hand bearing his middle finger, without breaking eye contact or changing his expression.
“Pass that along to Jensen Huang” he’ll whisper. Then with a surge of the creeping blizzard outside your window, he’ll be gone forever.
I do think you can build products and services that people will capital-L Love, even forgiving some warts too, but the bar for that is very high. I’m very skeptical of tech businesses not led by engineers for exactly this reason (the incentives don’t align with a level of quality people will care deeply about).
I mean, Op started right off the bat with the idea that op would love to live in a communist society.
By all means Op can say that they agree with some Marxist ideas, but when the real human costs of that model are very well proven out by now it should be a red flag if someone doesn’t acknowledge those costs from the jump. I’m not surprised this quickly went to suggesting Stalin wasn’t so bad.
I like the approach taken here. Nextcloud is becoming the defacto open-personal-cloud standard so it makes sense to integrate photos into that. If Nextcloud were getting up to shenanigans in the future I'm confident the project would be forked, and in the meantime I don't expect it would be hard to plug in an alternative backend.
I think for an open-source and/or self-hosted solution to come close to an approximation of google cloud/iCloud/whatever we need projects like this to be able to pick their niche and hyper-focus on it, which leaning on Nextcloud does in this case I feel.
I’d love to hear more about this switch as a family member is considering something similar as a 42 y/o.
If you don’t mind, was it long ago that you made this switch? Was there anything that you’d do differently in retrospect?
The big one I guess: do you feel that not having gone the “traditional” route made it more difficult to find roles in the early days?
Feel free not to answer if too invasive but I’d find any info really helpful.
To be honest I’ve come to suspect I may be guilty of this myself. I’m trying to do better at being open-minded to unpopular opinions (not always successfully).
That’s the more bizarre decision to me.
I get that some suits have decided PC isn’t a threat to Playstation’s business model, but they’re just wrong.
A gaming PC will play PC/Xbox/Playstation/Switch exclusives now. That really is compelling for someone in the market.
Exactly.
.. and they’re spending up the wazoo to do it!
Ok. Slave wages too.
My point is that all technology is built on prior discoveries and all matter of other factors that produce the civilisation, that produces doohickies, to look up cat memes.
They're spending up the wazoo on Xbox
2002 - Rare - $375 million
2005 - Lionhead - ???
2014 - Mojang - $4 billion
2014 - Gears of War - ???
2018 - Compulsion - ???
2018 - inXile - ???
2018 - Obsidian - ???
2018 - Ninja Theory - ???
2018 - Playground - ???
2018 - Undead Labs - ???
Sept 2020 - Zenimax / Bethesda - $7.5 billion
January 2022 - Activision Blizzard - $69 billion
This is just acquisitions, so it isn't exhaustive as it doesn't include first party costs and development expenditure, or Halo expenses / 343, as it assumes they essentially paid nothing to Bungie (or their costs were negative) after that split happened.
Microsoft don't publish extensive separate numbers for the Xbox division, but their Q1 2022 filing nonetheless states $3.6 billion - which is up 8%. They've also been open that they still, 21 years later, make at most break-even on their hardware sales.
That's a lot of expenditure relative to income. To state the utterly obvious: they're not getting nothing for that money, so it's not like they are sunk costs, but I'm not sure what standard would meet "spending up the wazoo" if not 20 times revenue (at minimum, as it only includes spending on acquisitions for which the amount paid is made public).
I think what's more likely in this case is that MS under Satya really does want to be a good corporate citizen, but are finding themselves in a bind that threatens the whole organisation.
They're spending up the wazoo on Xbox, still, to battle PlayStation. They were supposed to have conquered that market over 15 years ago and are still throwing money at it.
Windows is hurting as a retail business. License costs have been driven down by Chromebooks and resurgent Macs, and with all the free upgrades they get very little revenue from gaming PCs anymore (which is one of their biggest markets) while also battling Proton and Vulkan to keep users on the platform.
That leaves Azure and Office as the big cash cows. Azure is struggling to compete with AWS, and the big draw of Azure is the deep integration between it and Visual Studio (which, to be fair, is unrivalled anywhere else).
That's the bind. Microsoft needs the open-source community to embrace Visual Studio Code, and they have, but they also need to protect Azure's hegemony with .NET developers.
Can you build and deploy .NET on other clouds currently? Of course. Do you lose a lot of features by doing that? yes. Ones you may miss, or (if you've never been on Azure to become familiar with them), ones that may draw you to migrate later.
I appreciate that, sorry if I got.. er.. pitchforky.
Coming back to (2) - what I mean is that it's unclear to me if there's ever been a bear or bull cycle in that market in reality. It's such a short span of time that you could still, even now, be in the tulipmania phase of a speculative frenzy that hasn't yet run it's course (and I'd argue that is the case for a bunch of reasons).
I see these posts, and my gut feeling is that Mullvad is probably fairly trustworthy at this moment in time, but the more word of their service spreads the more likely I would assume it is that they get approached by the type of government representatives you don’t say no to.
(I.e. I assume success to be a death knell for a service like this.)
I’m not a customer, but I’ve considered it from a privacy perspective (in that I could just route general browsing through it to block a layer of data harvesting). The problem is that I don’t know what authority they have to push back if pushed by the right actor (who inevitably will knock on the door at some point).