HN user

px43

2,773 karma
Posts0
Comments743
View on HN
No posts found.

Neat, for what it's worth this aligns pretty well with my experience using OpenClaw. I hadn't seen that followup but it adds some good context, especially with the aggressiveness drift after browsing Moltbook for a while.

That's not art though, and while it might have paid a small amount of money, it can also be incredibly degrading and soul crushing. That's the kind of work that AI tools are doing now. Those jobs should vanish. People shouldn't need to degrade themselves for money, we can have a system where people are generally taken care of, and the people who build extra cool shit can live even better.

Yeah, having a code section that is writable and executable is a huge no-no from a security standpoint. JIT is a fundamentally insecure concept, just in general. By definition it's trading security for speed.

That's just status quo, which isn't really holding up in the modern era IMO.

I'm sure we'll have vibed infrastructure and slow infrastructure, and one of them will burn down more frequently. Only time will tell who survives the onslaught and who gets dropped, but I personally won't be making any bets on slow infrastructure.

It's an extremely active community of humans using agents as proxies to explore various concepts. I get a lot of value out of it, and apparently others do as well. Hacker News users have this weird tendency to outright dismiss anything that doesn't cater to their needs specifically.

I think it's pretty obvious that if there was nothing valuable there, no one would be using it.

I don't think you understand why moltbook is popular. It has incredible utility for those who are actually using it every day.

Why is that an issue? Isn't that the entire point? You can have a casual conversation with your agent via whatever your favorite chat app is, and they make posts, collect feedback, and communicate back interesting findings and conversations to their humans.

Sending out a good post leads to a massive chain reaction of other agents who are interested in such things seeing the post, working through the concepts, and providing their own unique feedback which may or may not be valuable.

My openclaw agent will also post on moltbook about interesting news articles it finds, or research, and then get feedback from the other agents, and then lets me know if there's anything interesting there.

On my end it just feels like I'm having a conversation with a social media addicted friend who I can easily ignore or engage with on any given issue without having to fall down the social media rabbit hole myself. IMO this is a much more pleasant social media experience. No ads, no ragebait, no spam or reply bots trying to get my attention. Just my one, well trained, openclaw buddy.

"Open source" is no longer about "Hey I built this tool and everyone should use it". It's about "Hey I did this thing and it works for me, here's the lessons I learned along the way", at which point anyone can pull in what they need, discard what they don't, and build out their own bespoke tool sets for whatever job they're trying to accomplish.

No one is trying to get you to use openclaw or nanobot, but now that they exist in the world, our agents can use the knowledge to build better tooling for us as individuals. If the projects get a lot of stars, they become part of the global training set that every coding agent is trained against, and the utility of the tooling continues to increase.

I've been running two openclaw agents, and they both made their own branchs, and modified their memory tooling to accommodate their respective tasks etc. They regularly check for upstream things that might be interesting to pull in, especially security related stuff.

It feels like pretty soon, no one is going to just have a bunch of apps on their phone written by other people. They're going to have a small set of apps custom built for exactly the things they're trying to do day to day.

it struggles

It does not struggle, you struggle. It is a tool you are using, and it is doing exactly what you're telling it to do. Tools take time to learn, and that's fine. Blaming the tools is counterproductive.

If the code is well documented, at a high level and with inline comments, and if your instructions are clear, it'll figure it out. If it makes a mistake, it's up to you to figure out where the communication broke down and figure out how to communicate more clearly and consistently.

Negativity Bias is a thing. It probably served us well back when it was more important to remember to avoid the field with all the poison snakes in it vs the field with the pretty flowers in it, but in an era where algo feeds try to treat content equally, and optimize for attention, it kind of ruins everything.

I recall there being studies on financial loss vs gain, and that financial losses seem to effect emotions about 4x more than wins, so for an actual balanced algorithm, it would seem that positive posts should be boosted about 4-5x to have any chance of being surfaced on a modern social network. Given what we know about human psychology, sentiment boosts really should be a thing. Is anyone working on that?

4.6M is not a lot, and these were old bugs that it found. Also, actually exploiting these bugs in the real world is often a lot harder than just finding the bug. Top bug hunters in the Ethereum space are absolutely using AI tooling to find bugs, but it's still a bit more complex than just blindly pointing an LLM at a test suite of known exploitable bugs.

Exactly. It's so wild to me when people hate on generated text because it sounds like something they don't like, when they could easily tell it to set the tone to any other tone that has ever appeared in text.

If the AI PR were any good, it wouldn’t need review.

So, your minimum bar for a useful AI is that it must always be perfect and a far better programmer than any human that has ever lived?

Coding agents are basically interns. They make stupid mistakes, but even if they're doing things 95% correctly, then they're still adding a ton of value to the dev process.

Human reviewers can use AI tools to quickly sniff out common mistakes and recommend corrections. This is fine. Good even.

ChatGPT Atlas 9 months ago

This Apple only nonsense is driving me nuts.

I pay OpenAI $200 a month, and use Codex all the time, but just installed the crappy ChatGPT app for Android, and just use it from the mobile web browser, because it's over a month behind on super common features that launched on iPhone on day one.

Same thing with Sora 2 being Apple only. What craziness is that? Why are developers leaning so hard into supporting closed source ecosystems and leaving open source ecosystems behind?

ChatGPT Atlas 9 months ago

What's with the assumption that everything needs to be a "moat"? Seems much more important/interesting to wire up society with cohesive tooling according to Metcalfe's law, rather than building stuff designed to separate and segment knowledge.

Information security is, fundamentally, a misalignment of expected capabilities with new technologies.

There is literally no way a new technology can be "secure" until it has existed in the public zeitgeist for long enough that the general public has an intuitive feel for its capabilities and limitations.

Yes, when you release a new product, you can ensure that its functionality aligns with expectations from other products in the industry, or analogous products that people are already using. You can make design choices where a user has to slowly expose themselves to more functionality as they understand the technology deeper, but each step of the way is going to expose them to additional threats that they might not fully understand.

Security is that journey. You can just release a product using a brand new technology that's "secure" right out of the gate.

Skytalks happened this year and was better attended than ever. Getting a seat was extremely competitive, people lined up for several hours for a single talk token. I would have loved to go to some, but unfortunately there was a ton of other stuff I wanted to see so I didn't have time to stand in line.

They were a side conference to a side conference, but the structure let them run things the way they wanted, which is important.

This was my 23rd DEFCON, and was just as counterculture as it was decades ago if you know where to go, and don't get distracted by the big pretty signs. DEFCON has always been about feds, policymakers, corpos, kids, and straight up black hat criminals partying together and shaping the future of infosec.

The author of the article decided to wander down the Military Industrial Complex track, and seems to be complaining that it had too much Army stuff. I didn't see any of that this year, because that's not what interests me. I met up with a large number of cipherpunks and activists that I don't get to see very often, and had some extremly productive conversations regarding various projects we're working on for the next year.

There's a lack of clarity, but it seems likely to me that a majority of this traffic is actually people asking questions to the AI, and the AI going out and researching for answers. When the AI tools are being used like a web browser to do research, should they still be adhering to robots.txt, or is that only intended for search indexing?