HN user

maldeh

518 karma
Posts0
Comments124
View on HN
No posts found.

I wish the order of presentation were different, because it starts with incorrect and misleading claims and then only later fixes its trajectory.

I wouldn't hold my breath, every inch of this article is evidently AI-generated - you can tell not only from the meandering narrative but also from the "Not because X, but Y", the short punchy sentences to reiterate the same point, the really strange cherry-picked examples for head-to-head comparisons, and the sincere concern over simplified generalisms.

Yeah, ok. This is what they should lead with. It's an important message.

Is it? Your optimism in hoping to find some point to all this restores some of my faith in humanity, but I think it's misplaced here. The entire premise of the article is bizarre - why should it be surprising or bad that historical figures from 1000s of years ago, regardless of their historical importance, don't have proportionate representation in contemporary discourse?

This seems like a pretty surprising process failure for a mature company like Grubhub, for such a marketing campaign to be greenlit without any guardrails. Wouldn't this be the kind of mishap you might expect from a startup or a 2-year old company?

Edit: I stand corrected. Per the Buzzfeed article, their spokesperson seems to be spinning this as an unexpected hit. So it wasn't a mistake, they were genuinely convinced it was a good idea?

https://www.buzzfeednews.com/article/kelseyweekman/grubhub-f...

It looks like it could be a binary intended to be snuck in with third party package dependencies and such that you might unintentionally execute within your lambda runtime. It's one thing doing mining at a slow trickle within the free tier of a single account, and another thing altogether when potentially millions of lambda functions in the wild are mining for you.

But agreed, it's not necessarily functionally different from any other crypto-mining malware hidden in public repos, save for the focus on runtime. Presumably Lambda provides a standardized enough runtime for reliable execution.

A more poignant elegy to the modern landscape of compliance theater I have never seen:

Security Standards. Okta's ISMP includes adherance to and regular testing of the key controls, systems and procedures of its ISMP to validate that they are properly implemented and effective in addressing the threats and risks identified. Such testing includes:

a) Internal risk assessments;

b) ISO 27001, 27002, 27017 and 27018 certifications;

c) NIST guidance; and

d) SOC2 Type II (or successor standard) audits annually performed by accredited third-party auditors ("Audit Report").

I don't think storing AWS keys within Slack would comply to any of these standards?

Likely some stressed out buyers paid for overpriced homes given the sharply rising prices across the market (although completely by their choice), and the sellers probably loved it - but that's already par for the course with the housing market at the moment. Zillow probably didn't help but isn't the sole contributor by any means.

One could argue that we are doing the followup even to this day (with the China CLEP programme, India’s Chandrayaan, USA’s ongoing Artemis campaign and others). The deed was done, the minimum bar was set and humanity has been as determined as ever to breach the peak it had achieved back in the sixties even as government funding waxes and wanes. Public interest has not changed in the least.

India's first forays into semiconductor fabrication in the 80s and 90s were likewise enthusiastically supported by the government (land, incentives, tax breaks and so on), but were ultimately hamstrung by more fundamental infrastructure issues that couldn't just be magicked away - water shortages and unstable power grids - each of which could grind manufacturing to a halt for months on end and delayed production cycles. (I think there was also a major fire in a leading SC plant that caused delays by years.) If anything these shortcomings could be exacerbated in 2021-22. The government would need a much more comprehensive infrastructural solution this time around.

Is this referring to Alexa, or some other product? Have there been any major notable reports about spying happening with Echos?

With regards to data collection for ads, personalized recommendations and such, are there any major concerns that don't also extend to ex:- visiting a website with a tracking cookie on?

(Don't get me wrong, I'm very wary of this product after Sidewalk [0] which I don't trust from a security perspective wherein as a bug could allow _third parties_ to snoop on me, but I'm just missing what people are talking about w.r.t. surveillance by Amazon itself)

[0] https://www.eff.org/deeplinks/2021/06/understanding-amazon-s...

This is a good principle in terms of reducing the overall blast radius of exploits. But to do this the implementations should genuinely be independent.

In practice we may find a monoculture within a hidden layer of the stack than we're optimizing for, such as an OS kernel method, TLS library or chipset which coincidentally has captured the entire market. When a clever enough exploit on a common resource is found, then the problem transforms to one of coordinating patching for the same, wherein a broad ecosystem of higher level components (like Android or PCs) becomes nearly impossible to thoroughly cover. As such malware authors may potentially still get away with writing a single version of their software so long as they target low-level enough. With sufficient fragmentation they don't even need to invent their own exploits, just use publicly known CVEs that they can brute-force against older devices.

(Not saying you're wrong, your recommendation may still be better in the long-run. We're after all weighing the risk level of black swan events, such as a zero-day on a low level of the stack, or a high level of the stack on a high-volume vendor)

The pricing appears to be static per model with a ceiling on the monthly request count, not charged per request.

Edit: Actually, I didn't spot the free tier of 1000 requests. I wonder how you avoid the problem of a lot of users leaving defunct/disused models running while still keeping them hot - presumably some kind of limit to the model count?

Yeah, given that the article started off establishing how an Estimator was basically an interface with simple rules about supporting "fit" and "predict" and how it could contain anything or do anything, I thought the argument laid out here would be about how these derivative implementations broke these rules.

The rest of the article instead seems to have lost the plot though, somehow finding fault with various derivative or concrete implementations of this interface, for A) being inextensible implementations and not transitive interfaces themselves, as though "be anything do anything" no longer applied; or B) not being perfectly aligned with sklearn estimator details that the author didn't really identify as essential, like not following some sklearn-specific parameter naming rule or not being serializable via pickle (like seriously, pickle support is often not appropriate for production, why should this be a required pattern! It's not even a requirement of the interface unless you read between the lines like the author implies is essential to be at parity.) As other commenters outlined here, it assumes that sklearn's contract is absolute, as though other libraries couldn't reinterpret the core principles.

The arguments against Tensorflow or Sagemaker's interfaces especially stretch quite a bit - what exactly is so offensive about these implementations given the very rules that the author establishes in this article? All "fit" is supposed to do is update internal state as the author asserts, but what precludes implementations of this interface from using cloud-based compute resources to achieve this end? And what about the fact that a docker container is deployed to the cloud by this command makes "fit" a lie? And honestly, what does the author have in mind for an estimator implementation that uses cloud resources like GCP TPUs or AWS EC2 that is also somehow more correct or pure than these implementations?

More than anything, the author's dismissal of the value that GCP and AWS's implementations bring in eliminating infrastructure management via their Estimator implementations (equating it to "simply" writing Dockerfiles or running Docker containers on the cloud like there's no setup involved) implies that they're thoroughly disconnected from the realities of ML devops on the cloud. They're free to run their purist single-core sklearn estimators on their laptops as much as they'd like though (unless Dask somehow gets a pass from these arbitrary rules around how estimators can and cannot be used).

I'm frankly astonished that the species lasted for two and a half million years all while being highly endangered the whole time.

Like, nevermind a comet, a poorly timed burp from a volcano could have sufficiently reduced diaspora enough to make them disappear.

What does a yearly installment plan even mean in the context of a cloud subscription-based service, as opposed to one for which one has already received goods?

And first of all, as the OP noted in the twitter thread, they believed they were doing a monthly subscription as advertised; the "yearly plan" interpretation is Adobe getting creative in the terms of service.

That'd be fantastic in a week or a month. ICUs in Washington and New York are running low on supply as we speak, any help now could buy a medical professional in these areas precious days.

Whoa, before we start pulling out the pitchforks, I think this may be terribly distorting OP's words and intent.

- My reading of it was that OP was in awe at the immense scale of engineering that went into Autopilot to make it production-ready in contrast to his own project which gives a perspective into what it takes for a HelloWorld in this space (he comments on its limitations: "That is just lane keeping so far but it does quite a good job at doing it. It is still a bit weak when wanting to predict the angle when there is an intersection and it doesn’t see the next road and say there is an highway exit.")

- The github project looks to be using an existing recording of a car driving from the comma2k19 dataset and predicting the expected vehicular response. No pedestrians endangered.

- Not that this should matter in an ideal world, but it appears the author is a talented young programmer who's still in school. It feels a bit much to admonish a newcomer to the space for perceived arrogance and irresponsibility; and even if there were at all real critiques to be made here, I'm sure there's a less rude way to make that argument that wouldn't discourage students from their learning journey.

Your musings here are legitimate, so long as you recognize your feelings as a single datapoint and don't mistake them for a general trend, or extrapolate them to the wider population.

As a counterpoint, I don't know of any friends or close acquaintances who would consider feminism or femininity a dirty word. To me, it's a fairly straightforward proposition:

Q: Are you pro- women having equal rights to men w.r.t. social structures, family responsibilities, economic opportunities, etc.?

A: Yes?

Q: And are you willing to take a second look at your social and professional conduct to make sure it doesn't put your female peers in difficult, awkward or uncomfortable positions?

A: Sure, why wouldn't I.

Hooray! you might be a feminist, it's not that hard.

Also, personally don't see what's wrong with unisex products, and I think it may be possible companies might possibly occasionally find the odd not-shitty cause they can back because their employees collectively believe in the positive message and that also aligns well with their goals, and not solely because of a small group of cynical PR managers running focus groups.

Benchmark is a major investor, actually. But it sounds like they might be getting the short end of the stick on this deal, like almost everybody else.

This case could be quite different from Uber per the thesis of this article by Stratechery: https://stratechery.com/2019/neither-and-new-lessons-from-ub...

While Benchmark was looking to preserve its assets from being squandered on possibly the startup-catch of a lifetime, Softbank on the other hand relishes being the Big Stack Bully, leaning hard on their portfolio companies to aim for home runs everytime, and their excessive leverage allows them concessions from companies most VCs can only dream of.