don't undervote me....it's a joke
HN user
kseniamorph
It's worrying because it feels like a loss of control. But there must be control. And this what responsibility is. You should worry only about people who don't understand responsibility, not AI-inspired ones
Co-author here. We collected 90 public signals from employee reviews and social media describing the organizational impact of post-acquisition cost extraction at CDK in the year before the attack. The question we’re interested in is the following: does the PR ownership model inherently increase cyber risk? This is what we see based on the data, but we found little to no research on this topic. Has anyone seen credible academic or industry research on PE or LBO-style ownership as a cyber risk factor specifically? We could only find adjacent work (PE portfolio cyber surveys, PE healthcare studies) and would value pointers to anything we missed.
nothing but thieves! cool band btw
there is a real one though — https://www.anthropic.com/engineering/claude-code-sandboxing. needs to be enabled with /sandbox, not on by default.
i feel like moves like this make it even harder for new open-source tools to break through. there's already evidence that LLMs are biased toward established tools in their training data (you can check it here https://amplifying.ai/research/claude-code-picks). when a dominant player acquires the most popular toolchain in an ecosystem, that bias only deepens. not because of any skewing, but because the acquired tools get more usage, more documentation, more community content. getting a new project into model weights at meaningful scale is already really hard. acquisitions like this make it even harder.
wow, not bad result on the computer use benchmark for the mini model. for example, Claude Sonnet 4.6 shows 72.5%, almost on par with GPT-5.4 mini (72.1%). but sonnet costs 4x more on input and 3x more on output
given specification approach: personally i found it useful in some cases to write preceding block-comments for functions. you can describe the desired behaviour there, input/output types, etc. you can even make a skeleton from comment blocks and run one-shot generation. but this approach is especially useful in iterative development and maintenance.
i like how this research (and others related) kind of supports the idea that free will might be lacking. I still keep a pinch of skepticism about this idea, understanding that it's just a concept. But personally i like it, because it even fells a bit relieving... not to say that it helps you abandon responsibility, but it makes your stance on life easier, and pushes you not to blame yourself too much for your weaknesses.
I remember reading a CF blog post about crawler separation and responsible AI bot principles where they argue every bot should have one distinct purpose. Now they're building crawling infrastructure themselves, and their own /crawl endpoint lists "training AI systems" as a use case alongside regular crawling. So not only are they in the crawling business now, they're not following the separation principle. To be fair, there's a business logic here. But it's hard not to notice the irony. https://blog.cloudflare.com/uk-google-ai-crawler-policy/
they are seeking talent, not buying the product. this is a valid strategy for devs - just to attract attention no matter what.
Curious whether people here see value in this kind of research: using alternative public data to assess vendor risk before a breach, rather than after. We're aware that "we found signals before a known breach" is a weaker claim than "these signals predicted a breach we didn't know about yet." Is retrospective analysis like this useful to practitioners, or does it only matter if it can be made prospective?
This matches what I've seen too. Though I'd add another dimension: soft skills. In my experience, job searching has always been easier for people who communicate well regardless of their technical level. And soft skills might be what's making some people more resilient to this market shift specifically
Saw the edit: I think that clarification was important. The core point resonates with me personally. The shift isn't about writing less code, it's about where the real judgment lives. Knowing what to build, how to decompose a problem, which patterns to reach for - and critically, when the model is confidently wrong. Without that foundation you're not moving faster, you're just making bad decisions faster. The scope point resonates too. Small, well-defined tasks with verifiable output is where agents actually shine.
makes sense, but i'd separate two things: models converging in ability vs hitting a fundamental ceiling. what we're probably seeing is the current training recipe plateauing — bigger model, more tokens, same optimizer. that would explain the convergence. but that's not necessarily the architecture being maxed out. would be interesting to see what happens when genuinely new approaches get to frontier scale.
Curious about the baseline choice. modded-nanogpt was optimized for wall-clock speed, not data efficiency, so it seems like an unusual reference point for this kind of benchmark. Why not vanilla NanoGPT?
oh it reminds me of all these claims regarding "bad" TV shows, "bad" songs, "bad" movies, etc. i understand that AI gives you a deeper feeling of interaction, but let's be honest - if you have a mental illness anything can be a trigger. that's sad, but it looks like personal responsibility rather than a corporate one
We heard feedback that GPT‑5.2 Instant would sometimes refuse questions it should be able to answer safely, or respond in ways that feel overly cautious or preachy, particularly around sensitive topics.
Lol it won't solve the issue when ChatGPT treats me like a teenager and tells me to ask my parents about everything (I just don't want to provide my ID to OpenAI to verify my age). Btw that's why I stopped using ChatGPT in my everyday life
Is there anyone who really understands what’s different about the OpenAI agreement? Or maybe these are just Sam Altman’s public statements that don’t actually reflect the real terms of the deal. I honestly can’t figure it out.
Wtf is going on
The self-reinforcing effect here was somewhat predictable given how LLMs are trained. The more repositories and AI blogs recommend the same tools, the more those patterns get locked in through training data. This makes market entry increasingly difficult for new tools. I know that the "optimize for bots, not humans" strategy already exists, but I'm skeptical it works at meaningful scale. The training data collection is opaque, proprietary, and the volume a new project can generate is incomparable to what established tools produce organically. So I have a bad feeling about the future...
disagree. at least i can see the quality of research coming out of Anthropic, which tells me these people are interested in what they're doing. i don't see this level of scientific rigor in OpenAI
The comparison feels off to me. The Maker Movement was an actual movement with a shared ideology of self-transformation through building. People identified with it. Vibe coding is just a description of a practice. The term covers a broad range of people: developers building components in languages they don't know, people trying to ship something fast and cash out, enthusiasts, and plenty of developers who are just too lazy to do their job. Any generalizations about what this "means for society" are going to be strained by definition. The author partially senses this. He writes that vibe coding "skipped the scenius phase" but misses why. I think there was no scenius phase because there was no movement in the first place. The tool just became available to everyone at once.
The policy change is separate and unrelated to Anthropic’s discussions with the Pentagon, according to a source familiar with the matter.
ok lol what a coincidence.
but setting aside the conspiracy. the article actually spells out the real reason pretty directly: Anthropic hoped their original safety policy would spark a "race to the top" across the industry. it didn't. everyone else just ignored it and kept moving. at some point holding the line unilaterally just means you're losing ground for nothing.
I'm not sure the practical implications are as dramatic as the paper suggests. Most adversaries who would want to deanonymize people at scale (governments, corporations) already have access to far more direct methods. The people most at risk from this are probably activists and whistleblowers in jurisdictions where those direct methods aren't available, not average users.
meanwhile cats: https://socradar.io/blog/dark-web-profile-blackcat-alphv/
Visited Kansai recently and a few things stood out. Passport control was fully automated: just scanned and walked through. Security flagged something in my bag and resolved it really fast without slowing down the line. It's a small thing, but it's the kind of operational detail that makes a real difference. My travel experience has never been smoother. Makes me wonder why more airports don't get this right.
I feel like the authors make a logical inconsistency. They present the drop in "identify missing context" behavior in artifact conversations as potentially concerning, like people are thinking less critically. But their own data suggests a simpler explanation: artifact conversations show higher rates of upfront specification (clarifying goals +14.7pp, specifying format +14.5pp, providing examples +13.4pp). It's obvious that when you provide more context upfront, you end up with less missing context later. I'd be more sceptical about such research.
"Social media is going the way of alcohol, gambling, and other social sins: societies are deciding it’s no longer kids’ stuff."
Oh, remember those good old times when alcohol was kids' stuff.......