HN user

horsawlarway

11,083 karma
Posts0
Comments2,154
View on HN
No posts found.

They specifically call out credentials used during the attack.

But they should be rotating those regardless. You don't get to say "Maybe the attacker didn't get this credential". You just rotate.

The most generous interpretation is that they have not yet have completed that rotation, and they didn't want to risk putting those credentials into the wild during that process.

---

But all of that aside, I feel like the undercurrent of this comment is that the "safety" rules that providers are pushing are genuinely harmful.

Another point where "if you don't own the model, you can't properly operate the tool" becomes true. Open isn't about profits, it's about capabilities.

I find this thought process somewhat faulty given that the vast majority of software ends up in that spot regardless.

Hard to take this as that big a deal when Google literally launched a product along similar social themes named "Google Buzz" which lasted all of like 16 months in 2010, well before agents and llms.

Either the project will find a fit, or it won't - and code quality doesn't have all that much to do with it existing in 2 years (some - but not as much as engineers want to believe).

in what context, and at what ROI?

Because... I have use-cases where this is true, and use-cases where this falls flat on its face.

I don't actually think it's obvious (at all, really) without defining what "superior" means.

In the same way that I don't think it's obvious that a plane is superior to a car, or a boat, or a bike.

They each do things the others don't, and excel in different spaces.

ping is going to dominate over 3ms in pretty much every situation.

And the non-xwayland numbers are all within a single ms of each other.

---

Not to undermine the measurements of the author (agree with you, it's a cool effort), but my read is that this was basically proof that it doesn't matter.

while I understand this argument - I think it consistently falls down when compared to the types of content that are generally purchased and consumed.

I'd argue that most folks get plenty of value from the content itself, entirely separate from the intent, context, or even existence of the author.

I don't care about the motivations of the director to enjoy an action movie. I don't care about the life history of the author to enjoy a good fiction.

I think there is (and should be) space for content where people care, but I'd suggest it's the fringes (ex - majority of music is production grade pop, not meaningful songs, majority of books sales are erotic fiction, etc).

Generally speaking - I agree with you. Source bias is a real logical fallacy, and failing to evaluate the content itself, regardless of the source, is a problematic view of the world.

In the same way that I don't need the lumber in my house "hand sawed" for it to achieve my goal of creating a habitable space.

---

But more broadly, I do think there's space to at least question the use and role of AI.

Because while content can (and should) be addressed directly, there's a valid meta-conversation about the intent of producing content, and the results producing that content might have.

What goal does producing this content achieve?

What is the role of this content in society?

Is this content, on this scale, an appropriate thing to be making?

These are MUCH harder questions - often because we've shifted from concrete (content) to abstract (value judgements).

To go back to my housing analogy: We're no longer evaluating the benefits of hand-sawed vs power sawed timber. We're discussing whether our housing is built in the right spots, if we're building enough of it, and are we allocating it in the right ways.

It somewhat boggles my mind that there are an incredible number of persistent, useless, and annoying comments on here every day accusing any and every article of being AI slop.

AI is a machine that generates content that is supposed to be statistically identical to the content that it was trained on, and it's trained on the content posted here.

The content here will look like AI generated content, and the AI generated content will look like the content here. By fucking definition.

---

Instead we get a bunch of pseudo-intellectual, hokey about how "my AI radar is perfect!" and "I can always spot it because of [insert bullshit about detecting style that's semantically the same as the pre-existing stuff]".

It's just... exhausting.

Yes - there is a lot of AI content on here. Just like there were a bunch of (and still are) under whelming marketing articles on here. Just like there's STILL a bunch of interesting and engaging articles (some of them even written by AI!).

Just vote based on the content and move on with your lives.

People out here wasting time and energy on trying to burn witches. If you want a "sure-fire" AI free experience... Go talk to a real person, in person. Otherwise...

TypeScript 7 14 days ago

but still it was obviously the right way to go compared to JS or, god forbid, shell.

I just don't think this is true.

Frankly - it's hard to argue this at all (even today) given that JS is the dominate language on the planet, and it lacks types... as does python, which had a reputation for decades as THE language to use to teach new folks to code. Or take PHP which dominated server development for a LOOONG time: also lacks types. Ruby on Rails has a wonderful reputation as the "get shit done" framework: no types.

Types are good for modern software companies, where code size has ballooned up very high (common to work on a codebase with hundreds of thousands of lines) or teams are large (50+ developers) and terrible if you just want to hammer out something that works as a solo dev.

Do I like types today? Sure - the tooling is solid, and I work on large codebases with large teams.

Did I like types as a solo dev at 3 person startup? no.

TypeScript 7 14 days ago

Look at some of the typing present in MS COM back in the IE5/6 days and we can discuss more. I can honestly tell you - I'll take untyped languages any day of the week over that clusterfuck.

Personally - I also think people really underestimate just how much the tooling around types has improved over the last 20 years.

If I'm having to try to look up the difference between iBrowserInterface6 and iBrowserInterface5 and iBrowserInterface4... (and yes - shit like this really did exist: https://learn.microsoft.com/en-us/windows/win32/api/shdeprec...)

And I have no tooling for autocomplete, and the docs are shoddy, and google is just coming on the scene...

People understandable want to throw their computer out the window.

Types are great. Some forms of them were not.

I'm going to poke at a downstream consequence here.

Lets say this catches on (in some form or another, whether in this precise implementation or not).

So assume we have a world where resources can be gated by a payment wall that agents can interact with.

I'm also assuming that world continues to have agents that are majority hosted and run by 3rd parties (ex - google/anthropic/openai/xai/etc).

---

At what point can I sue these companies for obviously failing to act in my interests?

Because that's the clear next step here.

Basically - where is the fiduciary duty that I would require for a real working relationship?

Because otherwise these agents can and will prefer to access payment gated resources that have financial relationships with their operators or developers.

Tidal AI Policy 22 days ago

Real question, have you actually used any of the llm based media generation tooling?

Because "load samples, arrange them, and instruct it to do a thing" are basically the required steps.

Arguably, if you don't care much about the result, you can skip loading samples.

You still have to... write the music.

When? When you load up other folk's samples? When you press a play button? When you arrange other folk's samples?

It's a recording device that plays samples. It doesn't give a flying flip about who wrote them.

You might choose to write samples, lots of people using them don't.

Tidal AI Policy 23 days ago

Frankly, this is also how I mostly listen to music - I set a song or two I like, then I let auto-discovery keep adding to the list.

If I happen to like it, I hit thumbs up/like. Otherwise I ignore it.

I sometimes go through and browse musicians, mainly to see if they have other songs I might like, but generally speaking... it's not high on my list of priorities. Then again, I don't give a shit about the "pop" aspect of music at all. It's mainly background noise I put on while doing something else.

---

As an aside:

I also think it’s an entirely false equivalence to say using electronic instruments are like AI music tools. Very different things – an electric guitar doesn’t play music by itself. It’s still a tool at the end of the day.

I think this is where it gets weird, and I think you're pretty solidly incorrect here. Samplers and grooveboxes absolutely play music by themselves. I think there's also a weird world where things like "Girl Talk" are somewhat spiritual successors to AI music...

Ex - I definitely love girl talk, and I'm not in any way implying that those albums don't take skill and taste, but he's literally just playing samples of other artists. If that's real music (and I'd argue strongly that it IS real music) then I think I struggle to rule out AI generated songs that are edited by someone (and if you've used this tooling, it still requires lots of editing).

My increasing frustration with these plans is the harness lock in.

Anthropic won't even let you run "claude -p [prompt]" any more... They bill it at api rates.

So if you're trying to automate the ai (and seriously, that's the point) the subsidized plans are crippled.

I really liked this in the day (and i just played with the version you linked and can still remember all the key patterns - I'm typing this comment with it now).

But it just can't touch swiping for speed. Frankly, the keyboard I miss most is the T9 predictive text from my old school pre smart phone era.

Nothing has come close to the same expressiveness and speed while being usable completely blind, only by feel.

I do feel like mobile keyboards have stagnated in a bad spot, though.

My experience has been that absolutely no one cares, as long as they could be construed to be "somewhat similar".

Ex - People change hair color, lose a boat load of weight, wear eye-color changing contacts, drastically change hair styles (facial and normal) etc...

No one bats an eye at an ID that "only sorta vaguely resembles you" outside of a very limited subset of places (the only one I can actually think of is Customs while traveling).

---

So my take is that as long as the gender appears similar and the ethnicity seems "close enough"... the store is still going to sell you alcohol, the bar is going to let you in, and the movie theater is going to sell you tickets.

In practice this means no rooted/jailbroken phones.

Personally - this is less acceptable to me than just having the site collect my image/id.

I'd support just putting the id in a dedicated device (ex - gov issues smart key) or just accepting that sometimes people will share id info (just like... physical ids).

It doesn't even close all the doors to transferring ids - since I can still just hand someone a phone (just like... physical ids).

Yeah, totally reasonable comment given the utter security that must come from anthropic with their installer, amiright?

oh wait...

"curl -fsSL https://claude.ai/install.sh | bash"

(right from https://claude.com/product/claude-code)

Further - what the flicking fuck do you think an installer is going to do on your system? Not run any commands? Because I've written installers for every platform... they ALL can run commands.

So what exactly is the complaint in this comment? If you want to go read the install script - knock yourself out (or hell, point your agent at it...).

It's true we hit limits, but I feel like a lot of it was "limits" in the sense that the tradeoff stopped being worth the cost, so we optimized in other areas.

So we hit limits on clock speed in the early 2000s (ex - the 4ghz wall) but it also turned out that mobile as the driver for sales meant no one really cared much about clock speed compared to performance/watt.

Clock speed mattered, but only relative to how many watts it took to get it (and above 4ghz... too many watts).

But we've seen a 15x improvement over the last 20 years. Performance/Watt is WAY up.

My guess is that LLMs are going to drive another "improvement cycle" in areas that we didn't care much about before.

I've built about 10 personal desktop machines (1 every ~4 years) and I can honestly say that I didn't care much about memory bandwidth prior to 2021.

In the same way that I didn't care much about how many watts my pentium 4 was using in 2005.

But now... now I care a lot about memory bandwidth. I care about memory speeds and total system ram in a manner I really, really didn't before.

So I think we're going to see a big shift to machines built on unified ram with a crazy focus on squeezing memory bandwidth and total ram capacity as far as we can.

My bet is that we'll get a similar 10-15x improvement by 2040 in unified system ram designs.

I fully expect to see 2tb unified ram desktops and 200gb unified ram phones be relatively common on a 20 year timeline, assuming we see similar levels of geopolitical stability (ex - world war 3 throws a wrench into things).

GLM 5.2 vs. Opus 1 month ago

I'm also very impressed at the output given the lack of image support.

They picked a task that heavily favors a model that can do multi-modal with images, and GLM still came within striking distance.

What I'm hearing from this article is that the next generation of open models that includes better multi-modal support are basically no-brainers for adoption.

Seems like a HUGE win for Z.ai and open models in general here.

I just want to say, as someone who lost literally every single grandparent I had to covid... this dude can go fuck himself.

Like - right up his own asshole.

---

I understand this comment is inappropriate. I think the comment in the article is WAY more fucking out of line than this.

I don't generally switch to implementing myself on the model, although there are definitely times where I stop it and correct it mid-task.

It's prone to thinking longer and more repetitively, again - it's definitely not opus 4.7/4.8.

I've been using pi.dev as my harness for it, and been pleasantly surprised by how nice it feels (I have used aider, but only very briefly and quite a while back - so I can't realistically compare).

I would say it's roughly where I felt claude was a year back - Most of the sessions need to be more "pair programming" and less "I let it run for hours".

I'm a big fan of frequent "human in the loop" style workflows even when I'm on something like opus at work, though. I have opinions about lots of things, and re-inforcing that the model should stop and ask frequently seems to get me considerably better output, without having to "re-roll" if you will.

I've done a good bit of management, and I think it's roughly producing what a junior dev might produce in a day every 5 minutes. And just like a junior dev, you need to be steering it back on track fairly often.

Opus feels more like a mid-level at this point. I can hand it a chunk of work and "leave" but I still get better output if I'm checked-in and watching/steering.

No real change in inference speed. It basically just allows me to slot in more context or a bigger model.

A single RTX-3090 will do approximately the same tok/s, but it won't fit the entire 300k context in VRAM.

Sometimes that matters, a lot of times it doesn't.

On the speed front - MOE models are great. Biggest perf difference in modern models is the move to MOE architectures.

I get very similar quality from the both the Gemma-4 31B dense model, and the Gemma-4 26B MOE model (both at Q4 quant) but the MOE version runs at ~3 times the speed (150tok/s vs 46tok/s).

Yes, today is not a great time to purchase hardware.

When I bought, I paid $850 a piece. And I needed one anyways for the gaming I was going to do.

My guess is the next good time to buy is going to be 24-36 months from now, depending on how the AI bubble goes.

---

I'll add to this, I personally don't like Apple hardware (not so much related to the hardware as their company philosophy) but their machines with unified memory (or AMDs latest unified memory offerings) get pretty equivalent speeds to my 3090s, and are probably a much better modern entrypoint to local llms.

There's a reason the joke is that Silicon Valley software devs bought up all the Mac minis for OpenClaw.

You can get a 48gb unified RAM M4 pro mac mini for ~2k. If you're not going to do much else with the machine, it's what I'd pick as my budget inference device right now. Spend a year of claude now, get ~150tok/s for the next decade (plus) for ~free.

If you want more capable and are willing to spend a little more, go with the newer Ryzen AI Max+ 395 machines.

You'll spend less on power too.

My last suggestion would be to go buy an RTX3090 at this point. You can do a lot better for a lot cheaper.

I mean - the base experience is just fine, with perfectly reasonable built in tools for file access and editing, plus bash.

But yes - it expands a lot if you're willing to play with it.

I'd actually say the vscode comparison is wrong, because vscode is very much "bring your own extension" in the same way that Pi is. While Claude is much more "visual studio" vibes. It's thick, it's opinionated, and it's absolutely not something you can really customize, but it can feel slick for supported workflows.

Pi is decent.

I've used the cli agents for claude, cursor, and pi, plus several custom harnesses I've written myself from time to time as experiments (and I guess technically gastown, if we're calling that a harness).

Pi is... just fine.

It does what I need it to, has a decent selection of tooling out of the box, integrates nicely with other tools, and generally gets out of my way enough that I don't think about it much anymore.

If you can run ~30b models at decent speeds, I think most folks would be pleasantly surprised at how capable they are with pi.

Tack on some of the extensions (ex https://pi.dev/packages/pi-mcp-adapter?name=mcp and https://pi.dev/packages/pi-web-access?name=search) and I get web tooling (ex - perplexity search), access to mcps to do things like drive chrome (https://browsermcp.io/) or firefox (https://github.com/mozilla/firefox-devtools-mcp)

It's fine. Is it as good as a subsidized top tier model? Nope. Is it free and still very capable? Yup.

And personally, I've been having a LOT of fun with the pi sdk (https://pi.dev/docs/latest/sdk)

Which is something that all the other providers charge you api access rates for (ex - thousands a month).

For personal use, yes.

I replaced a $100/m subscription to claude in favor of running pi harness pointed at unsloth studio, using both qwen (unsloth/Qwen3.6-35B-A3B-MTP-GGUF) and gemma (unsloth/gemma-4-26B-A4B-it-GGUF) models, depending on my mood.

I have a machine I built about 5 years ago with dual RTX3090s in it (I was going to build a new gaming machine anyways, and the llama release had just dropped so I tacked another used 3090 onto the build), and I get ~150tok/s on either of those models (at UD-Q4_K_XL quant) and can use the entire 300k context length without having to exit VRAM.

To be very clear - it's not as good as claude. But it's free and not so much worse that it matters significantly.

For my personal needs, free beats $100/m.

I also have an openclaw instance pointed at the same inference server, and it's great for that (genuinely solid use-case for local models).

Some example projects

- Replacement launcher for android tvs (with usage monitoring and tracking for kids)

- Custom admin portals for my k8s cluster services

- Custom home assistant integrations/automations (recently some shelly devices for power monitoring and switching)

- Grocery list management and meal planning (mostly via openclaw)

- some custom workflows for 3d asset generation in comfyui.

---

Long story short, if you're trying to make money via software... I'd probably still recommend using a paid provider. But the local models are very capable of cool stuff.

Fox to buy Roku 1 month ago

Assuming the nvidia shield.

I'll also echo my general disappointment with the direction of these devices. A decade ago, they were one of the best streaming devices you could buy.

then a couple years back it was "there's a new discover tab, filled with ads! Don't you love it?"

then it was "not enough people are viewing the discover tab, so we're merging the discover tab with the home tab! Don't you love it?"

---

They're still decent hardware for a streaming device (although somewhat dated at this point), but now you have to go out of your way to make the software not shitty.

Removing the stock launcher helps a lot, but requires ADB access. (easy enough, and [insert llm of choice] can both generate a minimal replacement launcher and install it for you for about $10 worth of tokens, so technical users are fine, but I can't really recommend them to non-technical family anymore.)