HN user

sdrinf

1,634 karma

Hey there, fellow HNer! Happy to chat:

Contact: sdrinf at google's email service

Web: https://sdrinf.com/

Posts26
Comments293
View on HN
news.ycombinator.com 1y ago

Ask HN: Chatbox (GPT desktop front end) malware / supply chain attack risk?

sdrinf
1pts0
telegra.ph 3y ago

A deep dive into cognitive differences

sdrinf
1pts0
news.ycombinator.com 3y ago

Help: Google Chrome UX Downgrade

sdrinf
2pts0
imgur.com 3y ago

Comparing ChatGPT and Google results side-by-side

sdrinf
1pts2
www.cyberpunkforums.com 9y ago

Optimizing and Securing Windows 10

sdrinf
39pts38
www.pirateparty.org.uk 13y ago

UK Pirate party closes its piratebay proxy

sdrinf
4pts0
news.ycombinator.com 15y ago

Ask HN: Building channels for customer development?

sdrinf
6pts1
news.ycombinator.com 15y ago

Steal this idea: G+ public hangouts

sdrinf
3pts2
news.ycombinator.com 15y ago

Ask HN: Visiting San Francisco in September, recommend startup event?

sdrinf
7pts3
news.ycombinator.com 15y ago

Ask HN: accountant recommendation in (north) London?

sdrinf
1pts4
github.com 15y ago

Show HN: A/Bingo for PHP

sdrinf
33pts12
news.ycombinator.com 15y ago

Tell HN: Experience-based pivot for the musical industry

sdrinf
3pts1
news.ycombinator.com 15y ago

Ask HN: dealing with credit card fraud while selling physical products online?

sdrinf
16pts10
news.ycombinator.com 15y ago

Ask HN: Small side-project with clear user tunnel?

sdrinf
3pts0
spreadsheets.google.com 16y ago

HN help wanted board (Google Docs)

sdrinf
87pts16
news.ycombinator.com 16y ago

HN Yellow pages - followup

sdrinf
5pts1
spreadsheets.google.com 16y ago

HN yellow pages (Google docs)

sdrinf
118pts47
vimeo.com 16y ago

Reshma Sohoni of Seedcamp: Lessons learned from 21 startups - Leancamp

sdrinf
5pts1
news.ycombinator.com 16y ago

Ask HN: successful, transparent bootstrappers?

sdrinf
68pts50
news.ycombinator.com 16y ago

Ask HN: Interview questions for a better Product Hypothesis?

sdrinf
13pts8
news.ycombinator.com 16y ago

Ask HN: Maintaining useful business documentation

sdrinf
8pts2
spreadsheets.google.com 16y ago

Ask HN: Why is the Cofounder spreadsheet locked for writing?

sdrinf
17pts15
news.ycombinator.com 16y ago

Ask HN: common iteration patterns for business development?

sdrinf
4pts0
news.ycombinator.com 16y ago

Ask HN: Spam fighting with bogus lead gen nowdays?

sdrinf
4pts4
stackoverflow.com 16y ago

Ask HN: good business cases of AI?

sdrinf
2pts1
news.ycombinator.com 17y ago

Ask HN: list of companies, and business models?

sdrinf
4pts6

Just want to echo the recommendation for qwen3.5:9b. This is a smol, thinking, agentic tool-using, text-image multimodal creature, with very good internal chains of thought. CoT can be sometimes excessive, but it leads to very stable decision-making process, even across very large contexts -something we haven't seen models of this size before.

What's also new here, is VRAM-context size trade-off: for 25% of it's attention network, they use the regular KV cache for global coherency, but for 75% they use a new KV cache with linear(!!!!) memory-token-context size expansion! which means, eg ~100K token -> 1.5gb VRAM use -meaning for the first time you can do extremely long conversations / document processing with eg a 3060.

Strong, strong recommend.

Counterpoint to peeps on this thread:

* This approach is the _most consistent_ with retaining anonymity on the internet, while actually helping parents with their issues. If any age-relevant gatekeeping needs to be made on the internet at all, this is the one I find acceptable.

* this is because the act very specifically does NOT require age _verification_ ie using third-parties to verify whether the claimed age is correct. Rather, it is piggybacking on the baked-in assumption, that parents will set up the device for their kids, indicating on first install what the age/DoB is, then handing over the device -a setting which can, presumably, only be modified with parental consent

* yes, there are edge cases, esp in OSS, and yes, it would be nice to iron those out -but the risk = probability x impact calculus on this is very very low.

* If retaining anonymity on the internet is of value to you, don't let the perfect be the enemy of good enough.

Taking the opposite side of that bet, here is why:

* even if an openweight model appears on huggingface today, exceeding SOTA, given my extensive experience with a wide variety of model sizes, I would find it highly surprising the "99% of use cases" could be expressed in <100B model.

* Meanwhile: I pulled claude to look into consumer GPU VRAM growth rates, median consumer VRAM went 1-2GB @ 2015 to ~8GB @ 2026, rougly doubles every 5 years; top-end isn't much better, just ahead 2 cycles.

* Putting aside current ram sourcing issues, it seems very unlikely even high-end prosumers will routinely have >100GB VRAM (=ability to run quantized SOTA 100b model) before ~2035-2040.

I'm working on something like this. Specifically, I'm doing recursive self-improvement via autocatalysis -but predominantly in writing/research / search tasks. It's very early, but shows some very interesting signs.

The purely code part you described is a bit of an "extra steps" -you can just... vscode open target repo, "claude what does this do, how does it do it, spec it out for me" then paste into claude code for your repo "okay claude implement this". This sidesteps the security issue, the deadly trifecta, and the accumulation of unused cruft.

can someone please try running the experiment of "but what if just forking&spinning up an OSS clone, scaling up to take in the migrants, acquire network effects, collect roughly same subscription revenue, but run on just, like, 10 people?"

Discord has a financially and politically vulnerable posture that is downstream of having to operate a very large team, raise funding, be exposed to investor market pressure. However, it is also one of the rare instances of successful consumer freemium subscription monetization. A clone does not have to pay the tuition of "what makes this specific space compelling, and want-to-pay-for"; it just have to _exists_, passively soaking up migrants from each platform shift.

ITT WTB 3rd place for my frens.

Besides the editorial control -which openai openly flagged to want to remain unbiased- there is a deeper issue with ads-based revenue models in AI: that of margins. If you want ads to cover compute & make margins -looking at roughly $50 ARPU at mature FB/GOOG level- you have two levers: sell more advertisement, or offer dumber models.

This is exactly what chatgpt 5 was about. By tweaking both the model selector (thinking/non-thinking), and using a significantly sparser thinking model (capping max spend per conversation turn), they massively controlled costs, but did so at the expense of intelligence, responsiveness, curiosity, skills, and all the things I've valued in O3. This was the point I dumped openai, and went with claude.

This business model issue is a subtle one, but a key reason why advertisement revenue model is not compatible (or competitive!) with "getting the best mental tools" -margin-maximization selects against businesses optimizing for intelligence.

GLM-4.7-Flash 6 months ago

Note: I strongly recommend against using Novita -their main gig is serving quantized versions of the model to offer it for cheaper / at better latency; but if you ran an eval against other providers vs novita, you can spot the quality degradation. This is nowhere marked, or displayed in their offering.

Tolerating this is very bad form from openrouter, as they default-select lowest price -meaning people who just jump into using openrouter and do not know about this fuckery get facepalm'd by perceived model quality.

You have two options:

* Use it as a "source": chatgpt -> settings -> apps & connectors -> add it as your connector. This supports only 2 functions: search, and fetch; details: https://help.openai.com/en/articles/11487775-connectors-in-c... ; in business / edu version there is support for "full MCP mode": https://help.openai.com/en/articles/12584461-developer-mode-...

* Enable "developer mode" chatgpt -> settings -> apps & connectors -> advanced settings -> developer mode. Available on paid&pro levels only. This can do full MCP access, but can't (currently) use your memory settings.

The option that works under all conditions is to use the API, and add it as a function directly (no MCP) -this works regardless what plan you have on openai.

The specific "anomaly" is that claude 4 / opus model _does not know_ because it is _not in its' training data_ what its own model version is; AND because it's training data amalgamates "claude" of previous versions, the non-system-prompted model _thinks_ that it's knowledge cut-off date is April 2024. However, this is NOT a smoking gun in different model serving. The web version DOES know because it's in its prompt (see full system prompts here: https://docs.claude.com/en/release-notes/system-prompts )

Specific repro steps: set system prompt to: "Current date: 2025-09-28 Knowledge cut-off date: end of January 2025"

Then re-run all your tests through the API, eg "What happened at the 2024 Paris Olympics opening ceremony that caused controversy? Also, who won the 2024 US presidential election?" -> correct answers on opus / 4.0, incorrect answers on 3.7. This fingerprints consistently correctly, at least for me.

I actually _like_ this, and so does the comfyweb & weebs who are a very significant portion of the driving force behind calm, decade-long projects.

This absolutely works... until, and when network effects kick in.

Payment processors have major network effects in that infra setup is expensive, banks need to be onboarded one-by-one, and whichever network has the most consumers, businesses will gravitate towards it. Iterate this over 20 years, and this always results in natural monopolies / duopolies. This creates a natural chokepoint/linchpin over which millions of people's mutually exclusive needs are getting banged at; including consumers at large, govs at large, and special-interest groups at large.

Absent crystal clear legislation -and porn is anything, but- this will always be arbitrary, and leave one side in the dust.

Early-40s here who still does all-nighters. How long is recovery time for you? What does it entails -ie what doesn't work as much as it should / takes longer while you recover?

Mozilla is sooo fucked here. On one hand, it would take them approx ~1 sentence of blog to say "We won't sell your input info to anyone" and this drama goes away.

OTOH: if the currently pending court case on anti-monopoly bars google from making payments to mozilla (which is about ~90%++ of their revenue), mozilla truly, and well is fucked. Meaning -they need to diversify, and they know it; they can't sell browsers, related services are heavily competed for, so ads & selling user data is broadly the only viable strat that can underwrite their existence.

Of course, the community won't have it. And therein lies the rub: by going with google's bribe, on this long term, they wrote themselves into a corner they can't exit.

O1 for collabing on design docs, o1 for overall structure, break it into tasks per preference / sort; sonnet/o1 for executing each small tasks.

O1 is higher quality, more nuanced, and has deeper understanding; the biggest downside rn is the significantly higher latency (both due to thinking, and also, continue.dev doesn't support o1 streaming currently, so you're waiting until it's all done), and higher cost.

In terms of tools: either vscode with continue.dev / cline, or cursor

Languages: node.js / javascript, and lately c# / .net / unity

Cease and desist letters.

There are many, many people, and companies who operate under the false belief that the CAN-SPAM act does not apply to them; and eg create new mailing lists to blast many people with their spam. Some of these unfortunately includes corps I have business relationship with (looking at you, Google), so "mark as spam" doesn't work well. Cease and desisting their legal department does. I have changed marketing strat of multiple largecorps by being a dangerous professional.

* IA's most important function (at least for me) is holding copies of the World Wide Web as it was.

* Given an annually compounding 30% linkrot, 99.92% of all the content ever published on the Internet is no longer available.

* This has been litigated, see Field v. Google Inc., 412 F (2006), and held to be "fair use" due to safe harbor of Section 512(b) of the DMCA

* This exemption does not apply to books, music, videos, or any of the other pirated material.

For the moment, the best possible solution seems to me simply disabling auto-updates. On long-term, if supermium can port over the critical fixes from chromium, ubo v2 may still survive with chrome-ish packaging.

For larger context, the ecosystem is fragmenting, and I have ~10 browser extensions that are critical to me. I don't think I will prioritize chrome's software cadence over my own preferences, thank you.

For the moment, the best possible solution seems to me simply disabling auto-updates. On long-term, if supermium can port over the critical fixes from chromium, ubo v2 may still survive with chrome-ish packaging.

For larger context, the ecosystem is fragmenting, and I have ~10 browser extensions that are critical to me. I don't think I will prioritize chrome's software cadence over my own preferences, thank you.

This article omits specificity of which GPT model. Re-running the experiment on the EU regulation paper using gpt-4-1106 (the current-best "intelligent" one):

https://chatgpt.com/share/d5709aeb-d24c-488b-985c-c13eba0c01...

"4. IORP Directive: The IORP (Institutions for Occupational Retirement Provision) Directive is analyzed, highlighting its scope and its impact on pension funds across the EU. The paper suggests that the directive's complex regulations create inconsistencies and may need clarification or adjustment to better align with national policies." "5. Regulatory Framework and Proposals: A significant portion of the paper is devoted to discussing potential reforms to the regulatory framework governing pensions in the EU. It proposes a dual approach: a "soft law" code for non-economic pension services and a "hard law" legislative framework for economic activities. This proposal aims to clarify and streamline EU and national regulations on pensions."

^^ these corresponds to the author's self-selected two main points.

Alternative hypothesis on "job to be done": individuals attempting to de-google themselves, at least on the productivity suite. This does involve the rest of the suite as well, as individual users do, actually, have docs on google drive.

Question: why is clicking on the (test) phishing email's link "fail"? Isn't the whole contract between browsers and society that one can safely open any website they want (ie loading a webpage is safe), and what you do on the actual site is the actually unsafe op?

Asking because in the vast majority of cases, the phishing landing page has way more signals to recognize than the email headers.

They're heuristics, but failure on them is extremely predictive, and for the n>25 ventures I had personal experience with, have a fitness of ~99% predictive power.

What inspired that question?

I am the person described in the requirement list. I brought 2 startups from seed to series A, built a cashflow business of my own, led teams, have 5+ years of runway (yes, in San Francisco), and actively looking for a potential idea + business person. I have worked my ass off for the past 10 years to put myself into this position. I'm doing startups to fulfill the intersection of broad positive externalities + financial reward space, which is possible, and I did it 3 times already. I'm looking for a cofounder+idea because what I can do alone is limited. Over the past 2 years, I have reviewed >1500 pitches, talked with 150+ founders, had in-depth conversation with 10, executed (and failed) with 2.

My counterparties are not real.

In descending order of frequency:

* Tirekickers / wannabes: these people have fantasies about doing a startup... someday, but definitely not just now.

* Super excited about <thing/area>... has no related experience, fails at basic business ontology ("target market", "valueproposition") <- 95% mark

* Has no hypothesis about marketing channels, nor any insight on why this particular combination might work

* fails on all of market scoping, TAM, customer development, financial model <- 99% mark

Rest: limited operational experience, OR self-defeating / low psychological resilience, going nowhere.

There is a laundry list on sibling comment (https://news.ycombinator.com/item?id=39904704) for ticking boxes. My current hypo, is that peeps who check these boxes AND don't have a tech cofounder on their rolodex typically go to angels/VCs, and get a recommendation from them; and therefore will never appear on any markets for cofounders. Curious if this matches your experience.

Logging in means random videos I check from various corners of the internet starts shaping the recommendation algo. Many of these are extremely deep and vicious traps (eg my most recent one was misery porn).

Youtube premium does not works for incognito mode. This requires careful, and manual curation of my "history" page.

No thank you.