HN user

rakel_rakel

525 karma

ed(1) is the standard editor.

Posts12
Comments40
View on HN

Interesting, thanks. I don't know where "around here" is, but the signals I've seen in a lot of articles is that the demand for junior software people has taken a dive since a year or two back, with student programs etc getting cancelled. One googler said they were getting a junior to their team and that was kind of a big deal because it hadn't happened in that whole department for a long time.

In relation to that, I guess my question becomes: if the same thing will happen in math research, who will write the ten page math proof prompts in the future?

I don't think researchers in math/TCS will be made obsolete, but I think it will instead no longer make sense to work on any low-hanging, or even medium-hanging (you know what I mean) fruit. We'll be needed for problems where actual novel approaches are needed.

I wonder how this compares to what we see happening with "juniors" in software development? In math research, do you also get the training for the profession from working on the low hanging fruits for a while, to then move to the medium-hanging, and later go on to work on previously unsolved stuff?

What a great post! I would love to read more of these for other films.

Everything in the set was real. We couldn't fake any of it, because audiences are so sophisticated now in their knowledge of computers. ... - Cory Faucher (Special Effects Coordinator)

This sentiment seems to run throughout the movie, and I believe it's why it's held up so well in terms of visuals, I don't think it would have aged nearly as well as it has if more CGI (or other ways of "faking" things) had been been used.

As for the question (in <references[9]>):

Some code associated with Nedryland is visible on screen. It looks like actual source code[9] with Classic Mac OS API functions calls.

That looks like old Pascal, and since the window has MPW (Macintosh Programmers Workshop) in the title, that's probably it?

People creating things that didn't exist before is so refreshing, and Prahou is such an amazing artist. Making it look easy (or for the untrained eye like silly scribbles on old thinkpads) he created a whole world around his characters, and the talent and rigor is super impressing.

I would recommend anyone to dive into it!

I read every piece like this one as: Money is moving in the vulnerability space now, when as before the LLM hype incentivized that, your best bet was that someone skilled enough would accept living with the financial insecurity of being a gig worker to hopefully stumble upon your projects bug bounty program. Is the bet here is that the hype lasts, and that people willingly will keeping on paying Dario to be able to contribute?

But give it 1-3 months and the open models will catch up.

I wish that this would stopped being thrown around, what is this timeline based on? How good is your open model from between March and May?

Also, having read "Gödel, Escher, Bach" I know that the hare never catches up with the turtle.

That's awesome, I'm happy for you finding such great value in it!

Not sure if it's important or not, but for the sake of OP's discussion I note that your value is not necessarily tied to "speed of execution".

Which things, specifically?

Low level systems programming mostly. Embedded systems, *nix userland programs, API and library design, sometimes including writing assembly although in very small fractions.

I’ll probably make a lot of enemies by saying this, do people realize that code is just a means to an end?

You will need a lot more to make yourself my enemy, but this is the divisor between us... not that you like to use Claude and I don't.

I think it depends a lot on where your interest in (self) development lies.

My main motivator has always been to understand how things work, and myself being able to create as elegant solutions as my technical role models (in the range from colleagues and mentors to the elders of our field), hopefully even pushing it further. Having the LLM just create the product robs me of that, or at least of the most rewarding parts of that. And that's why I don't like to use it.

Different people are driven by different things, I don't think either trumps the other in the objective sense, we're just wired differently.

I agree, it's very off-putting, and I totally understand that the amount of reports are overwhelming for maintainers of popular libraries.

More reports means more fixes means more code changes means more bugs.

Sounds like we'll be riding a downward spiral for the foreseeable future? It will be very interesting to see how stats like the ones you shared develop in the coming year(s).

From the article I find this a bit concerning:

So: the Claude releases changed way more lines of code than historical ones, but didn't have more bugs. More code, same bugs. That's not what you'd expect if Claude were making things worse.

More code, same bugs, is a net negative, no? I mean unless it's strictly needed for the inherent complexity of the program. But I've seen a tokenizer written by Rob Pike and I've seen a tokenizer written by Claude.... they are not the same :D

I agree about letting AI loose on rsync is baffling, and also that how the issue was filed was incredible obnoxious. A thought crossed my mind though, with the risk of going slightly off topic. Disregarding the fact that mature software like Rsync does not need this kind of movement in changed LOC. Also assuming the maintainers best intentions with how they manage the project:

Since this is happening in open source, what do you think about the state of the quality of closed source software? AI usage (input as a success metric) is part of what you're being evaluated on as an employee, and people are panicking at the threat of mass layoffs due to AI.

Yikes!

The bottom performers won’t have that self check. They are the ones producing 10x output with the agents. What do you think is happening to the average output of that organization?

Nailed it!

At my last place this was encouraged (by non-technical leadership driving the AI adoption policies, as well as setting salaries) and seen as a huge win.

The "step change in number of created PR's" was celebrated (cult-style), and by one of the (co) CEO's praised as a paradigm shift of the same magnitude as the personal computer. Meanwhile, I was stuck finding insta-reject level bugs in pull requests from people one-shotting 6000 line PR's "finally solving" long-standing issues from the backlog. Needless to say I left.

That's helpful, thanks!

Once past IPO, I suspect the 70% -> R&D must shrink, right? I mean, to keep the stock afloat long term P/E must come down right?

Public investors strike me as less willing to pour money into R&D, which is why I'm wondering about the timing of IPO in my initial question.

The hyperbolic nature of the articles in both AI camps is very exhausting to me.

I'd like to get in front of a whiteboard with someone who knows economics and the token providers businesses well enough to answer my "explain to me like I'm five" questions. But I'll start with these in here:

Is my observation correct that for the token providers this is a margins game, while for the consumers this is a quality of service/product game? If the quality:margin lines will cross at some point on the x-axis, is the race is to reach this point before running out of money? If yes: What historical examples are there where the delta between these two is huge?

I'm guessing LLM's are unique in a sense, since there's really no limit to how good a consumer of the product expects it to get? (Compared to for example email which is much easier to scale in regards to compute.)

Also extreme noob at life question: Why would you want to IPO before having a sustainable business model? What's the upside?

If I understand you correctly, you're asking me if I would class this as a 20k USD (plus environmental and societal impact) bug? nope, I don't.

I've not said anything else than that I think this specific bug isn't worth the attention it's getting, and that 20k USD would benefit the OpenBSD project (much) more through the foundation.

When it’s a security researcher, HN says that’s a squalid amount. But when its a model, it’s exorbitant.

Not sure why you're projecting this onto me, for the project in question $20k is _a_lot_. The target fundraising goal for 2025 was $400k, 5% of that goes a very long way (and yes, this includes OpenSSH).

Spending $20000 (and whatever other resources this thing consumes) on a denial of service vulnerability in OpenBSD seems very off balance to me.

Given the tone with which the project communicates discussing other operating systems approaches to security, I understand that it can be seen as some kind of trophy for Mythos. But really, searching the number of erratas on the releases page that include "could crash the kernel" makes me think that investing in the OpenBSD project by donating to the foundation would be better than using your closed source model for peacocking around people who might think it's harder than it is to find such a bug.

On the global stage, state-sponsored attacks from actors like China, Iran, North Korea, and Russia have threatened to compromise the infrastructure that underpins both civilian life and military readiness.

AITA for thinking that PRISM was probably the state sponsored program affecting civilian life the most? And that one state is missing from the list here?

I'm not sure that analysis (and perhaps especially security analysis) is the biggest issue with LLMs.

I was replying to the statement that "maybe code quality is really not that important for trivial things", not whether LLM's are good at analysis nor not.

Thanks for the link though, looks like an interesting talk!

maybe code quality is really not that important for trivial things

I hear this narrative being pushed quite a bit, and it makes my spidey senses tingle every time. Secure programs are a subset of correct programs, and to write and maintain correct programs you need to have a quality mindset.

A 0-day doesn't care if it's in a part of your computer you consider trivial or not.

Two Worlds 4 months ago

I usually enjoy this guys rants more than me most hn users, so I might be biased already, but this one hits the nail on the head:

Anything a person without skill can build with AI is worth very little, because anyone else can build that same thing.

And it's going to be interesting seeing what happens to big tech when there's no real difference in what an engineer and a (technical) PM can produce daily. Tweak some configs, find and fix a bug, push.