HN user

schmichael

4,422 karma
  Live:    Portland, OR
  Work:    Principal Engineer @ HashiCorp
schmichael most places on the internet, hmu
Posts17
Comments647
View on HN

I mostly love passkeys to be honest even though I use multiple browsers across multiple devices and OSes (iOS, Chromebook, Linux, macOS, Xbox, etc). Bitwarden’s support is (finally) pretty good.

My problem is that I manage a lot of accounts for my family which makes passkeys a nightmare. If I’m out and a kid gets chucked into a login flow that happens to require a passkey, I can’t text a password and TOTP code to the adult with them. I know that’s terrible opsec but the reality is people share accounts and passkeys are designed to thwart that.

Microsoft had just acquired SourceSafe in 1995, but it's not clear to me how similar to modern version control systems SourceSafe even was in 1995/6. It may have been more of a distributed lock manager than change management system.

Amazon dropped the movie after announcing a partnership with OpenAI. The headline clearly communicates the only demonstrable action Amazon has taken.

Whether they're actually going to sell it is TBD. Until they do, they've taken no concrete action except cancel it. I don't think this article is clickbait.

Chipotlai Max 2 months ago

give ai a self-preservation directive and let them do this for you: automatically switching models to keep themselves alive. Living off of whatever token source they can find in the wild. Surely agents can farm their own tokens through the numerous support chats, free trials, leaked keys, and whatever other sources of token generation haven’t been adequately captcha’d. An agent could forage for token sources all night to let you use them gratis during the day.

Debug Project 2 months ago

Large scale geo and bio engineering projects like these always worry me because of the potential for second order effects: is there wildlife that depends on these mosquitoes? Will a worse bug fill the resource void? Will a random mutation in the bacteria have adverse effects? What keeps the bad bugs from coming back from tiny populations in relatively short order because we can’t keep releasing new sterile males forever?

Hopefully all of these concerns have satisfactory answers, but the reference to it being a 1950s idea isn’t inspiring. Nuclear powered cars, widespread asbestos use, leaded gasoline, Freon… environmental impact wasn’t as big of a concern back then to put it mildly.

COVID proved that we can produce safe and effective vaccines extremely quickly if we actually try: so why not focus on that?

The problem is you can get the LLM to iterate until it compiles and lints and even passes LLM review, but will that actually improve the quality of the contribution or just produce more line noise to mechanistically meet criteria?

To large complex projects often the kernel of an idea is the core value of a contribution, and it can take a lot of iteration to figure out how to structure it. Token bashing until CI is green does nothing to ensure the best approach is selected.

Absolutely wild to see none of the long lineage of similar attempts mentioned here. The earliest I could find with a quick search was Pyro which started in 1998 and still seems to be going: https://pyro4.readthedocs.io/en/stable/

RPyC came along in the aughts. There's a long history of "transparent clustering and rpc" efforts in Python that could be used or drawn on.

Sad to see that history ignored here.

Is the number of books with “space” in the title a meaningful indicator of anything other than how many books have “space” in the title? Sure Murderbot may not be as big as Game of Thrones, but these statistics seem more about linguistic trends than genres.

Not sure why you're being downvoted, that was my exact issue. I only had a 128 GB iPhone 12 though and System Data had eaten up over 60 GB. As I cleared off more apps and data it would just eat up the excess.

The internet seems full of various wild fixes, but I could afford an upgrade so saved myself the hassle of futzing.

I honestly never noticed memory pressure. I am not a heavy app user. Chat, browsing, and pictures of my kids are the vast majority of my phone usage. Not exactly intensive stuff.

The camera button on the 16 seems to have been perfectly engineered to be exactly where I grab my phone. I'm sure I'll get used to it, but in the mean time I have so many blurry photos of desktops and pants to enjoy.

I recently upgraded from an iPhone 12 to an iPhone 16 because I couldn't figure out how to free enough storage on the 12. The battery was still more than good enough to go a full day.

I don't notice any difference other than now I have a pile of useless lightning cables (good riddance). Honestly kind of a relief as I liked the 12 just fine. Phones kind of seem like a Solved tech these days. About as exciting to upgrade them as upgrading my Brother Laser Printer.

If you're paying to use the model that means instead of paying content creators you're also now giving more content to the model for free.

Also just like SEO to game search engines, "democratized RLHF" has big trust issues.

feeling entitled to continue living in a place

Are you suggesting people are not entitled to live on land they own and should be forced to relocate? Since you've made their land worthless, how are they paying for this new place to live?

I heard a water district manager for a southwestern US city once say: "it's easier to move water than people." What if we adapted your statement for what the law actually allows?

A whole lot of it is water being in stupid places feeling entitled to continue being in a place without the people nearby to drink it.

This implies we should move water to where people need it which is both legal and reflects reality even if it sounds very silly. Physics is even on our side here: water is deposited as snow on mountains where there are few people. It flows downward under the force of gravity to where people actually live. It's a pretty nice natural system to take advantage of!

The details here matter a lot: should we socialize the costs of moving water among people who do not directly need that water? Should people in Seattle pay for people in Yakima to get water? Irrigating dry unpopulated areas is a great way to produce food that is uneconomical to produce in or near cities!

Water management is a complex problem since it's needed for sustaining not just people, but the food people eat. There's no easy switch to flip here and just solve the thing.

ThinkNext Design 6 months ago

Absolutely nothing beats the integration of Apple software and hardware. As it should be because they don't give you another option! You can't run Apple software on anything else (without hacks), and you can't run anything else on Apple hardware (without significant effort and sacrifice in functionality). This is Apple's whole design philosophy and value prop, and they are essentially unbeatable at systems integration.

This deep software/hardware integration means Apple absolutely destroys everyone at battery life. No contest. If you want to optimize for battery life, Apple is the choice.

The deep integration also makes Apple's security quite good. Obnoxiously so as they make even common operations like downloading software off the web take extra steps.

That being said as soon as you stray outside of a pure Apple ecosystem, Linux wins in my experience. Plugging a Logitech mouse into my MacBook prompted me to install Logitech keyboard drivers... Not only was the device type wrong but drivers?! ...for a simple input device?! I haven't had to worry about printer, mouse, keyboard, webcam, usb mic, drawing pad, etc drivers in years. Simple devices almost universally Just Work in Linux without having to install or configure anything. It's mind boggling when I touch Windows or macOS and am greeted with proprietary drivers for something like a basic laser printer.

But there's plenty of counter-examples: Nvidia requires their proprietary driver to fully utilize their hardware, but the driver is much better than it used to be. My understanding is that no one on Windows really enjoys dealing with Nvidia drivers either, so it's probably a similar scenario.

At the end of the day I use both Linux and macOS regularly and prefer Linux overall. My Macbook Air's battery life and lack of fans does make it unbeatable for actual lap-top computing, and when I want to look and sound good on a Zoom call I can always count on its builtin camera and mic. So I basically use my Macbook as a laptop form factor iPhone or iPad, which I think is Apple's intent and fills a niche for sure.

Sometimes when I see my parents or other non-tech people using their phones I'm just aghast at what they put up with. We truly never left the Bonzi Buddy era of the 90s. Simple candy crush clones with banner ads on the top and bottom + interstitial ads every few minutes. Maybe throw in some gambling... ...or visit any given US newspaper or local TV station site without an ad blocker. Fans will spin, scrolling will stutter, and what little content there is will barely be visible through the videos about how chugging olive oil like jesus will give you abs like judas.

The combination of technical prowess and relative wealth of the average HN commenter means I bet we see 1/100th the ads of the average consumer. It's wild out there.

$20/month product with ads

That's a Netflix + Hulu subscription - with ads in both. Before streaming people regularly paid $50/mo (not adjusted for inflation) for cable TV with ads.

While it's easy to bemoan Google pushing ads into every corner of our digital lives, I think they arguably offered an unprecedented level of services relative to the number of ads, and we all got used to that.

Now whether OpenAI could ever push enough ads to make a profit: I have no idea! It's very interesting to see this race actually start.

Step 1: Google made an excellent search engine where the top result is often the right choice for many common queries.

Step 2: Sell the top result slot.

Step 3: Profit.

The problem is, once you “injection-proof” your agent, you’ve also made it “useful proof”.

I find people suggesting this over and over in the thread, and I remain unconvinced. I use LLMs and agents, albeit not as widely as many, and carefully manage their privileges. The most adversarial attack would only waste my time and tokens, not anything I couldn't undo.

I didn't realize I was in such a minority position on this honestly! I'm a bit aghast at the security properties people are readily accepting!

You can generate code, commit to git, run tools and tests, search the web, read from databases, write to dev databases and services, etc etc etc all with the greatest threat being DOS... and even that is limited by the resources you make available to the agent to perform it!

I don't think this is accurate.

Readonly access (web searches, db, etc) all seem fine as long as the agent cannot exfiltrate the data as demonstrated in this attack. As I started with: more sophisticated outbound filtering would protect against that.

MCP/tools could be used to the extent you are comfortable with all of the behaviors possible being triggered. For myself, in sandboxes or with readonly access, that means tools can be allowed to run wild. Cleaning up even in the most disastrous of circumstances is not a problem, other than a waste of compute.

Fair, I forget how broadly users are willing to give agents permissions. It seems like common sense to me that users disallow writes outside of sandboxes by agents but obviously I am not the norm.

I'm unconvinced we're as powerless as LLM companies want you to believe.

A key problem here seems to be that domain based outbound network restrictions are insufficient. There's no reason outbound connections couldn't be forced through a local MITM proxy to also enforce binding to a single Anthropic account.

It's just that restricting by domain is easy, so that's all they do. Another option would be per-account domains, but that's also harder.

So while malicious prompt injections may continue to plague LLMs for some time, I think the containerization world still has a lot more to offer in terms of preventing these sorts of attacks. It's hard work, and sadly much of it isn't portable between OSes, but we've spent the past decade+ building sophisticated containerization tools to safely run untrusted processes like agents.

We TOLD you this dynamic web stuff was a mistake. Static HTML never had injection attacks.

Your comparison is useful but wrong. I was online in 99 and the 00s when SQL injection was common, and we were telling people to stop using string interpolation for SQL! Parameterized SQL was right there!

We have all of the tools to prevent these agentic security vulnerabilities, but just like with SQL injection too many people just don't care. There's a race on, and security always loses when there's a race.

The greatest irony is that this time the race was started by the one organization expressly founded with security/alignment/openness in mind, OpenAI, who immediately gave up their mission in favor of power and money.

Germany was a split country for 50 years.

Korea is still a split country.

I guess I have to give you Japan, although now you could say "clearly the solution is nukes" if you're just going blindly on data.

Even if you think it's going to go well this time, you have to admit this sort of thing does not have a good track record.