A foreign company can’t steal your IP to build out competing products?
Or use source code to find novel vulnerabilities and deeply compromise your company?
HN user
Security engineer. Strong opinions loosely held.
A foreign company can’t steal your IP to build out competing products?
Or use source code to find novel vulnerabilities and deeply compromise your company?
I think that’s the point
I don’t participate in bounties at all unless I believe there is a moral obligation or I’m set to make thousands of dollars. In each case, $0.05 is fine.
For a typical commercial entity? $0.05 is not a deterrent; the companies legal team is and has been for a decade.
Reminds me of someone (well known in their field) who charged $0.05 for using their “contact me” page. A trivial amount for someone who genuinely wanted to contact them, but just high enough to prevent any kind of scaled abuse
It was recently edited. I assume they saw this feedback
I love that the 5.9 lives on
ursa-ag.com For (a little bit) more info
Spinning it up is not the problem. You want to spend the time to throughly test it (or have your agent swarm test it) so you don’t waste the opportunity of having HN input?
I’d be wary of a founder with such bad NIH
Fixing is now the bottleneck.
Most patches are non-trivial and then each project/maintainer has a preferred coding style, and they’re being inundated with PRs already, and don’t take kindly to slop.
LLMs can find the CVE fully zero interaction, so it scales trivially.
You should probably add a huge disclaimer that this is an untested, experimental project.
Related, a direct comparison to other sandboxes and what you offer over those would be nice
Extensive discussion on this recently: https://news.ycombinator.com/item?id=47278426
(This looks like a BI rehash of that topic)
As a parent to two young kids and in more of a leadership position at work, Claude allows me to grind through my backlog of ideas in minutes between other tasks, and see which ones take flight.
I personally observe AI creation phenomenally good code, much better than I can write. At insane speed, with minimal oversight. And today’s AI is the worst we will ever have.
Progress in AI can easily be measured by the speed at which the goalposts move - from “it can’t count” to “yeah but the entire browser it wrote didnt compile in the CI pipeline”
Batshit crazy?
3 years ago LLMs couldn’t solve 7x8.
Now they’re building complex applications in one shot, solving previously unsolved math and science problems.
Heck, one company built a (prototype but functional) web browser
And you say it’s crazy that in the future it’ll be able to build a mail app or OS?
It is there to reduce our agency, to make it easier to fire us, to put us in even more precarious position
Could be. It could also end up freeing us from every commercial dependency we have. Write your own OS, your own mail app, design your own machinery to farm with.
It’s here, so I don’t know where you’re going with “I’m unhappy this is happening and someone should do something”
Don’t hold your breath
This has been done before; heat and having two crankshafts kinda kills it
I never said anything about 2FA magic links? We can do much, much better via things like FaceID integrated passkeys, and probably further steps from there.
Stop requiring computers/phones for everything.
Ah yes, that sounds straight forward. Let us know when you’ve deployed that to prod.
Hilarious example to use, because that literally is an effort that’s underway.
Thousands of people get scammed and have their lives ruined every year, so deprecating passwords is absolutely the right move
I was very surprised to find the opposite yesterday. I was asking ChatGPT about firearms and it hit a safeguard ~”I cannot give gun purchasing advice” so I switched to Gemini, and it happily answered the exact copy/paste question
Historically it was the opposite; OpenAI was yolo and Gemini overly cautious to the point of severely limiting utility
but demonstrating a reliable way to exploit them
Is this a requirement for most bug bounty programs? Particularly the “reliable” bit?
Driving even basic PTO attachments? That’s borderline
The relocation was the big question on my mind.
The other is: when will they charge? Does this ship not run at night?
Disclosure: I work @ goog, opinions my own
There’s absolutely been a lot of focus on LLMs, but they simply work very well at a lot of things.
That said, Carbon (C++ successor) is an active experimental (open source) project. Fuchsia (operating system, also open) is shipping to consumer products today. Non-LLM AI research capabilities were delivered at a level I’m not sure is matched by any other frontier lab? Hardware (TPUs, opentitan, etc). Beam is mind-blowing and IMO such a sleeper that I can’t wait for people to try.
So whilst LLMs certainly take the limelight, Google is still working on new languages, operating systems, ground-up silicon etc. few (if any?) companies are doing that.
Sorry, but AI still seems to be trash at anything moderately more complex than baby level tasks.
How familiar are you with the concept of the jagged frontier? That is, AI does indeed fail at things we might expect a third grader to be capable of. However, it is also absolutely exceptional at a lot of things. The trick is A) knowing which is which and B) being able to update yourself when new capabilities are unlocked
So yeah, it’s unsurprising you found a use case it couldn’t trivially do. But being able to one-shot quite complicated applications that may have taken a day to get right previously is an astonishingly useful thing, no?
Have a link to the source? And have they said they can’t break it, or haven’t yet? I’d imagine from a business perspective it would hardly be worth it
Care to elaborate on what it is like, then?
There are usually very comprehensive post mortems for these events, and none have suggested that at all
Anyone can switch from Claude to llama?
At some point (possibly already?), having no federal contracts will be a massive competitive advantage.