Their CISO literally acknowledged it and then they all continued ignoring it again. This isn't just bad process, this is a broken security organization.
HN user
tedivm
Blog: https://www.tedivm.com
Book: https://www.manning.com/books/terraform-in-depth
Portfolio: https://projects.tedivm.com/
Github: https://github.com/tedivm
BlueSky: https://bsky.app/profile/tedivm.com
Fediverse: https://hachyderm.io/@tedivm
LinkedIn: http://www.linkedin.com/in/roberthafner
Comments are my own and not those of my employer.
Most automated analysis isn't dependent on just behavior, but rather suspicious things in the code itself. You have a popular open source package with files that exist on pypi but not github then that's a big flag, or if a similar package suddenly has some base64encoded garbage that runs through an obfuscated exec call. In other words the simple fact that the project has obfuscated code is enough to flag for further attention.
That said if the only issue is time, researchers will just run their automated analysis through machines with dates in the future alongside their normal tests.
China is releasing open weight models you can simply run yourself.
Yup, this is one of the many reasons why I prefer OpenCode as my agentic harness of choice. If I'm confused about something I can just read the source code.
The courts have never said piracy, which is how the training sets were originally built, is legal. There are several court cases still ongoing over this.
More memory means less aggressive quantization, more concurrent requests, and larger context windows. I also get a boost in tokens per second (not double, about 1.5x compared to a single GPU).
The 35B model is an MoE (mixture of experts), which uses only a subset of parameters at a time. The 27b one is slower but has way better performance.
No, I use Qwen3.6 27b for everything.
I have a Linux box with two 3090s and it's been great for running Qwen3.6 27b. I lowered the power on each card down to 250w, and then built a small ducting/fan system to vent the waste heat outside. The machine is pretty much silent, and I'm still getting 110 tokens per second out of it for coding tasks.
This is just not true. There have been leaks due to micrometers in just about every section of the ship at one point or another. A quick search pulls up examples of US modules having issues, especially around interfaces and seals. NASA had a whole investigation between 2018 and 2021 about the recurring issue.
So you both used Anthropic models (Opus 4.7 being from Anthropic)? I'm struggling to understand what your comparison really was here.
Frankly the non-profit has failed. OpenAI is one of the least open of the AI companies (Anthropic is a bit worse). If it wasn't for the labs in China the dream of an actual open ai system would be dead.
They literally threw out every line of code that existed before and rewrote it in a completely different language, seemingly on a whim. That's how it was trashed, in the very literal sense that all of the existing project was tossed in the trash in favor of a completely brand new code base. That's a big deal even if you ignore the coding agent aspects.
Yeah that was a typo, I meant 4.6.
I've had the opposite experience, and have built multiple fantastic applications with Qwen3.6 27b. What quantization have you tested with?
I've completely replaced GitHub Copilot using Sonnet 3.6 with OpenCode using Qwen3.6 27b, and it's been a great experience.
AWS literally did that. They paid for full time developers to contribute back to the redis code base, including core redis developers. If you actually look at the redis code base the majority of it was written by people who never worked for redis.
AWS literally paid for developers for the redis project, including the salary of core members. It's not like they didn't contribute back to the community.
AWS stomped on open source projects - despite the clear desire of projects like Elasticsearch, Redis, and MongoDB not to be cloned and monetized, AWS pushed ahead with OpenSearch, Valkey, and DocumentDB anyway, capturing the hosted-service money after those communities and companies had built the markets; the result was a wave of defensive licenses like SSPL, Elastic License, RSAL, and other source-available models designed less to stop ordinary users than to stop AWS from stripping open-source infrastructure for parts, owning the customer relationship.
This is completely backwards, at least with OpenSearch and Valkey. AWS didn't create the forks until after the upstream projects changed their license, so it's really weird to say that the forks "resulted" in the license changes when those forks where a response to the license changes. With Valkey in particular it was members of the former redis core development team that created Valkey.
When it comes to understanding large organizations I think a simple principle should apply:
The Purpose of a System is What it Does[1].
Whether malicious or not, the system does what it does. If people wanted it to do something else they would change the system. The reality is that when corporations make mistakes that benefit them those mistakes rarely get fixed without some sort of public outcry, turning the "mistake" into a "feature".
1. https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_wha...
Even if you go service by service you're talking about critical things like `git` operations (literally what they're named for) at a single nine, and stuff that's pretty basic like static web hosting as only two nines. They literally can't even keep static webpages up.
It really has been remarkable watching GitHub just crumble as an organization. There's a lot of discussion about why: the switch from being independent to being part of Microsoft, having resources pushed to Copilot instead of core service, the organization structure itself, a reliance on vibe coding, etc etc.
Regardless of the reason, it's undeniable that GitHub is facing some serious issues. The unofficial status page[1] tells a horrifying story.
I would absolutely love to get some insider perspective on this (if only to learn how to prevent it from happening anywhere I work), but I think it's clear to anyone who has been paying any attention that GitHub is a sinking ship and the only reason people haven't abandoned it already is inertia. Considering how much else is changing in software right now I don't think inertia is enough to sustain a company.
Storing on GPU would be the absolute dumbest thing they could do. Locking up the GPU memory for a full hour while waiting for someone else to make a request would result in essentially no GPU memory being available pretty rapidly. This type of caching is available from the cloud providers as well, and it isn't tied to a single session or GPU.
That cost that you're talking about doesn't change based on how long the session is idle. No matter what happens they're storing that state and bring it back at some point, the only difference is how long it's stored out of GPU between requests.
You can send books to your kindle over USB, and I do that all the time for larger books that are above the size limit on the email system.
The big problem is that Amazon no longer allows you to download books from their site to your desktop, so you have no way to actually get a purchased book and send it to the kindle even over USB. However, if you buy non-DRM books from other book sellers you won't have this problem.
Google does not have unlimited. I had to pay to increase my storage.
Why treat them as the enemy, when a dialog might cause them to reach common ground about what is the right thing.
People like Elon literally are the enemy. He used his wealth to literally change our government in his favor. The idea that we need to go and have polite discussions to maybe change his mind, while he gets to stomp all over us (his DOGE efforts literally resulted in people dying). If a dialog with them was going to work it would have happened a long time ago, but the more we learn about these people the more obvious it is that they believe themselves to be smarter and better than the rest of us. They aren't going to listen to others, and pretending that they will seems like deflecting and giving up in advance. Our best hope is that people can get enough power to regulate billionaires out of existence before a revolution does it instead.
I'm well aware of this: I bought a pretty beefy (consumer grade beefy) GPU machine and run all sorts of open weight models. I do think there is potential.
But are you expecting 360m Americans to start their own businesses? That is a solution that doesn't scale. Consumer grade GPUs aren't going to scale all that much either, and the cost of the models are going up rather than down as vendors start seeking profits. We already see the memory and storage markets exploding in cost due to the rise in demand as well.
A request is any interaction where you ask Copilot to do something for you—whether it's generating code, answering a question, or helping you through an extension. Each time you send a prompt in a chat window or trigger a response from Copilot, you're making a request. For agentic features, only the prompts you send count as premium requests; actions Copilot takes autonomously to complete your task, such as tool calls, do not. For example, using /plan in Copilot CLI counts as one premium request, and any follow-up prompt you send counts as another.
This clearly isn't true for agentic mode though. This document is extremely misleading. VSCode has the `chat.agent.maxRequests` option which lets you define how many requests an agent can use before it asks if you want to continue iterating, and the default is not one. A long running session (say, implementing an openspec proposal) can easily eat through dozens of requests. I have a prompt that I use for security scanning and with a single input/request (`/prompt`) it will use anywhere between 17 and 25 premium requests without any user input.
Seriously. They can say they want to share their gains all they want, but I don't see them spending any lobbying money on things like universal income (and if Altman can afford to lobby for age verification laws he can certainly afford to lobby for things that actually benefit society). The reality is they don't lobby for anything that would take wealth away from them, and any redistribution of wealth (such as a s 75% tax rate) would by definition take wealth away from them.
This is only true if productivity gains tied to general well being, but instead it's being concentrated in the hands of a few.