HN user

thisisthenewme

209 karma
Posts0
Comments30
View on HN
No posts found.

i feel like ai would be very beneficial here. use ai to create massive amount of fake facebook accounts with fake picture and fake friends. meta wants all the data so we give them more than they would ever care about. make it impossible for them to really know real from fake.

As a developer, I kind of feel like this all smells like job security.

After using LLMs for a while, I have to admit it's pretty nice, and I like using it. I've been vibecoding a few apps, and it's a good dopamine hit to immediately see your ideas come to life. However, based on my experience, it will bite you if you trust it blindly. Even in my vibecoded projects, it keeps adding "features" without me asking for them. Since they're just pet projects, I don’t really care as long as the end result is what I'm expecting, but I don’t think companies will be as flexible. I also don't think customers would like it if features changed or got added with every new fix or update.

So this could go in a bunch of different directions from here, but to summarize the current situation:

    A lot of companies are heading in this direction.
    Without proper engineering, AI will easily write more code and potentially change the application unintentionally.
    We will have fewer junior engineers entering the market because of fear around AI and reduced hiring.
    AI usage will hit a critical point where it is making massive amounts of changes, and the people "prompting" it might start getting overwhelmed.
    We will end up with more features that people have to keep in their heads. I don’t think we can trust LLMs 100%, and because of that, developers will still need to know exactly what the application does.
    Eventually, there will be a lot of bugs, and developers will complain that we need additional human resources.
    Hiring starts again.
I think, right now, the toughest position is for new developers, and the best position is for people already in the market.

Migrated from archlinux to nixos. I don't think I can use anything else now...

I have a CI at home that builds my nixos config on a weekly basis with the latest flake. The artifacts are pushed to atticd. With this setup, when I actually need to update my machines, its almost instantaneous.

Agent Skills 6 months ago

My unproven theory is that agent skills are just a good way to 'acquire' unspoken domain rules. A lot of things that developers do are just in their heads, and using 'skills' forces them to write these down. Then you feed this back to the LLM company for them to train on.

I guess it's pretty much impossible to stop these companies from gathering data, there's too much money in it, it's too easy to implement, and there's no cohesive force to stop them. I'm wondering whether a crowdfunded effort to feed fake data into these systems would work so we overwhelm them and make their plans a bit more difficult.

I find the belief that government is the only limit to wealth creation very intriguing. I also find it interesting that the talking points usually contrast "free markets", which I assume represents the best case, with just "government". Markets can be limited or impacted by forces outside of government (price fixing, monopolies, manipulation). Is there an equivalent best-case scenario for "governments" that we can use as a reference when discussing how they impact free markets?

I feel like AI is already changing how we work and live - I've been using it myself for a lot of my development work. Though, what I'm really concerned about is what happens when it gets smart enough to do pretty much everything better (or even close) than humans can. We're talking about a huge shift where first knowledge workers get automated, then physical work too. The thing is, our whole society is built around people working to earn money, so what happens when AI can do most jobs? It's not just about losing jobs - it's about how people will pay for basic stuff like food and housing, and what they'll do with their lives when work isn't really a thing anymore. Or do people feel like there will be jobs safe from AI? (hopefully also fulfilling)

Some folks say we could fix this with universal basic income, where everyone gets enough money to live on, but I'm not optimistic that it'll be an easy transition. Plus, there's this possibility that whoever controls these 'AGI' systems basically controls everything. We definitely need to figure this stuff out before it hits us, because once these changes start happening, they're probably going to happen really fast. It's kind of like we're building this awesome but potentially dangerous new technology without really thinking through how it's going to affect regular people's lives. I feel like we need a parachute before we attempt a skydive. Some people feel pretty safe about their jobs and think they can't be replaced. I don't think that will be the case. Even if AI doesn't take your job, you now have a lot more unemployed people competing for the same job that is safe from AI.

I've started using worktrees recently and I have nothing but praise for it. It's especially useful to me because I work on multiple features and want to reduce friction from context switching. I basically have a structure like `/worktrees/<project>/<worktree>`. I use it alongside direnv and have my .envrc in the top-level project. That essentially allows me to set up project-specific environments for all of my worktrees. This works neatly with emacs projectile mode and lets me switch between different projects/features seamlessly. My head feels a lot lighter not having to worry about my git branch state, stashing changes, and all that jazz. I think it's a great tool to have in your repertoire and to use depending on your needs.

Ledger 2 years ago

I recently started using Ledger this year, and I've been really impressed with its utility for me. I think, for my personal needs, https://pypi.org/project/ledger-autosync/ is a must-have. I don't want create my own transactions, and with the autosync extension, I can simply export my bank transactions as QFX files and then import them into my ledger file. In the past, I struggled to accurately track my spending, and typical banking apps were either slow or lacked good querying capabilities. Now, I can easily budget, track purchases, calculate my worth across multiple accounts, and more.

I guess similar results might be possible with other accounting tool but Ledger perfectly meets my requirements. Also, it integrates pretty well with Emacs and I get to check my reports from there.

I find it even more interesting that people are defending either corporation. Neither of them is our friend, and they do what happens to be profitable. The core problem here is that Apple has a significant market share in the US, and for one reason or another, they are inconveniencing a portion of non-iPhone users and/or causing an unnecessary divide. Does it have to be this way? I think the answer would depend on whether or not this form of incompatibility brings them any competitive advantage.

So much missing context here, at least for me.

What is the rollback they are talking about? Is it in terms of something new in google chrome?

From what I can tell, they are looking for certain amount of ads 'injection' to come from chrome. What does that really mean? Does chrome really control the ads injected into the search results from google? I had assumed that was directly from google. Or maybe something happened in the recent chrome update that reduced the number of direct queries heading to google?

Also what's with the suggestion to increase the search box vertical space to increase in a search tab to make search prominent? That sounds pretty interesting to me.

Not depressed but just makes me question the value of our existence. If we are truly able to create machines with our intellectual potential, where does that leave us? Do we compete with the machines in a rat-race for a chance at happy existence? Or will we create a utopia where the machines do the difficult work and allow for an enjoyable existence for all. The people who are rooting for LLM's are hopefully working towards the latter but not sure if that is just wishful thinking.

FWIW, Firefox and uBlock on my Android phone will always keep me on that ecosystem. My desire to go into the Apple ecosystem (because of supposed privacy protections) faded as soon as I learned I can't really have a good ad blocking solution there.

Is the issue you have with the group of people doing the moderation, or with the idea of the moderation in the first place? Are you certain that its the 'SV engineers' that are doing the current moderation? If you think the problem is with the current group of moderators, who do you think should be moderating and what should be the criteria of their moderation? If you think we don't need any moderation, do you believe that people should have a fairly easy access to

  * Learn how to make bombs (as mentioned in the article)
  * Get away with committing crimes?
Are moderating these topics related to morality?

So on the side of wanting easy access to American data -

  - People in the gov who want to monitor the general populace for dissent
  - Power hungry individuals and governments
  - Governments wanting to learn about their foreign adversaries/allies
  - People in the gov who want to monitor other gov agents for whatever reason
  - Corporations wanting to learn about their adversaries
  - Corporations wanting to maximize their profits
  - Corporations wanting to learn about their users for whatever reasons
  - And so on and on.
On the side of limiting access to user data -
  - People wanting privacy
Don't want to sound too pessimistic but I can't help it.

The DoorDash and Grubhub lawsuit claims the New York City Department of Consumer and Worker Protection’s analysis of the regulation would add an average of $5.18 per order.

I'd rather have them charge the $5 than be guilted into paying the $5 dollars as a 'tip'. Just makes the costs of these purchases more apparent.

The dark net growing alongside the regular web is very interesting albeit worrisome. What helps one side helps the other, and the thing that hurts one also hurts the other. That's the main reason I really don't want Google or anyone else to cripple the ad-blockers because they really help with a lot of the attack vectors.

Anyway, kind of feels like the eventual outcome of Capitalism. You have a lack of supply to meet the growing demands of the cyber-criminals and fellow entrepreneurs rising up to close that void. Given the amount of money involved, not likely to ever stop. Not trying to give them any ideas but I'm wondering if there will be (or already is) venture capitalists investing in them. They most likely already have a 'Hacker News' to keep up with all the latest developments.

  According to the FBI, financial losses from cryptocurrency investment scams dwarfed losses for all other types of cybercrime in 2022, rising from $907 million in 2021 to $2.57 billion last year.

  https://arstechnica.com/information-technology/2023/06/fbi-warns-of-increasing-use-of-ai-generated-deepfakes-in-sextortion-schemes/

I think I'm less worried about AI taking over but rather some people taking over with the help of AI. I think at the current rate of AI research, Law doesn't seem to be able to keep up and that makes it vulnerable. I think I'm more worried about the (un)ethical ways people will be able to use the new technologies. Not sure if there is any data on whether the new technology helps the 'bad' guys more than the normal folks. On the more positive end, you get to have your personal all-knowing knowledge-base. On the other hand, I'm sure this will bring on an influx of additional crime (scams, forgery and so on).

https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_pr...

That graph places software engineers in the top-right quadrant, suggesting that they are predictable and "grammatical". However, I believe there should be a distinction between writing code and engineering. I would not classify software engineering as entirely predictable. For instance, while you could use a script to handle emojis with ChatGPT's help, it would be challenging to use the same strategy for a solution involving large systems that have multiple failure points and span multiple regions. Moreover, even if such a system were successful, multiple redundancies would need to be in place to prevent large-scale disruptions caused by downstream failures.

On the other hand, the chart places executives and investors on the 'safer' side. However, I think that with the real-time information available to AI, investing as a 'job' could be at a higher risk of being replaced. The same could be true for many executive positions (assuming that we are comparing merit-based positions to those based on nepotism).

Also a lot of problems in society seem to be linked to wealth disparity. Dystopian visions of the future are almost always dystopian due to wealth disparity. Who’s working on solving that?

> The communists. Didn't work out well.

Just wondering why you would think your comment adds any additional context to the original post? Is that a snide at communism just because you dislike it? Or are you saying that communism is the only way to solve the problems of wealth disparity and that it has failed in the past and we can never have any semblance of equality in the world?

This seems a bit scary because of its potential impact on me as a Software Developer. On the other hand, I'm also very excited to use this in personal projects and for learning. At least at its current state, however, it doesn't seem all that trustworthy. I was trying to see if it can give me good answers to queries that I've been unable to find with Google. For instance for query "How can I generate a kubernetes token that can be used to access a cluster?", it replied with answer for kubeadmin which is reasonable because I didn't give any context. I'm using k3s so I needed an approach that worked with it. I followed up with "Is there a specific command to do the above in k3s?". It responded to that with the following.

  Yes, k3s is a lightweight Kubernetes distribution that includes a utility called k3s-kubeconfig that can be used to generate Kubernetes tokens. k3s-kubeconfig is a command-line tool that is included with k3s, and it provides various subcommands for generating and managing Kubernetes tokens and configuration files.

  To generate a Kubernetes token with k3s-kubeconfig, you can use the token generate subcommand. This subcommand allows you to specify the token's expiration time, as well as the authentication groups and usernames that it should be associated with.

  Here is an example of how to use the k3s-kubeconfig command to generate a Kubernetes token:

  k3s-kubeconfig token generate \
  --ttl 24h \
  --groups system:bootstrappers:kubeadm:default-node-token \
  --username kubelet-bootstrap

  In this example, we use the k3s-kubeconfig token generate subcommand to generate a new Kubernetes token. We specify a time-to-live (TTL) of 24 hours using the --ttl flag, and we associate the token with the system:bootstrappers:kubeadm:default-node-token authentication group and the kubelet-bootstrap username.

  Please note that this is just an example, and you may need to adjust the k3s-kubeconfig command and its flags according to your specific k3s setup and configuration. For more information, you can refer to the k3s-kubeconfig documentation or consult a k3s expert.

I was initially impressed because after all my Google searches, I had never learned that there was a `k3s-kubeconfig` tool. That excitement quickly turned into amusement because turns out the tool doesn't exist.
Tailscale Funnel 4 years ago

I've been using tailscale in my home setup for a while and really appreciate the simplicity. It has just worked in my experience. Before taking the leap for tailscale I was semi-struggling with a vault + wireguard + consul-template approach which was pretty cool and fun to setup but a bit unnerving to be unsure if I got anything wrong and the chances of me being exposed.

This looks like yet another feature that fits my use case and reduces my security burden. Though learning a few things from this post the first being that I should have replaced my use of haproxy with rinetd ages ago. The other about Certificate Transparency logging. Still going through the wiki pages to understand how that works, but would it really log an event such as Tailscale terminating the request, dumping the data, and re-encrypting them before sending us the request? Or is it possible for a bad actor to hide the logging?