> There's an (increasingly small) group of software developers who don't like "magic" and want to understand where their code is running and what it's doing. These developers gravitate toward open source solutions like Kubernetes
Kubernetes is not the first thing that comes to mind when I think of "understanding where their code is running and what it's doing"...
Worth noting that the U.S. Digital Service (USDS, i.e the org that DOGE has now subsumed) has for a long while been experts at building and deploying static websites for the federal government. And doing it completely in the open. Within minutes you can literally clone and re-deploy all of httsp://usds.gov — 150MB of 2,700 assets and documents, built on Jekyll — locally or on S3. They've even written out the complete deployment instructions:
https://github.com/usds/website
For some reason quite a number of people seem to believe the purpoted goals of DOGE, removing waste and increasing efficiency of the government.
I can't really understand that as it seems obvious to me that they're just destroying parts of the government they don't like. And while there is certainly room for improvement in many areas, whatever they're doing is not going to improve anything, it's only destruction.
All I know, is if I was worth $200B and owned the island of Lanai, you would never hear from me again. Ellison, Musk, Zuckerberg and the rest of these weirdos are deeply damaged human beings.
[Putting my dusty Linux Distro Maintainer Hat on]
First of all, I wholeheartedly applaud Marcan for carrying the project this far. They, both as individuals and as a team proper, did great things. What I can say is a rest is well deserved at this point, because he really poured his soul into this and worn himself down.
On the other hand, I'll need to say something, however not in bad faith. He needs to stop fighting with the winds he can't control. Users gonna be users, and people gonna be people. Everyone won't be happy, never ever. Even you integrate from applications to silicon level, not everyone is happy what Apple has accomplished technically. Even though Linux is making the world go on, we have seen friction now and then (tipping my hat to another thing he just went through), so he need to improve his soft skills.
Make no mistake, I'm not making this comment from high above. I was extremely bad at it, and I was bullied online and offline for a decade, and it didn't help to be on the right side of the argument, either. So, I understand how it feels and how he's heartbroken and fuming right now, and rightly so. However, humans are not an exact science, and learning to work together with people with strong technical chops is a literal superpower.
I wish Hector a speedy recovery, a good rest and a bright future. I want to finish with the opening page of Joel Spolsky's "Joel on Software":
Technical problems are easy, people are hard.
Godspeed Hector. I'm waiting for your return.
Marcan links to an email by Ted Tso'o (https://lore.kernel.org/lkml/[email protected]...) that is interesting to read. Although it starts on a polarising note ("thin blue line"), it does a good job of explaining the difficulties that Linux maintainers face and why they make the choices they do.
It makes sense to be extremely adversarial about accepting code because they're on the hook for maintaining it after that. They have maximum leverage at review time, and 0 leverage after. It also makes sense to relax that attitude for someone in the old boys' network because you know they'll help maintain it in the future. So far so good. A really good look into his perspective.
And then he can't help himself. After being so reasonable, he throws shade on Rust. Shade that is just unfortunately, just false?
- "an upstream language community which refuses to make any kind of backwards compatibility guarantees" -> Rust has a stability guarantee since 1.0 in 2015. Any backwards incompatibilities are explicitly opt-in through the edition system, or fixing a compiler bug.
- "which is actively hostile to a second Rust compiler implementation" - except that isn't true? Here's the maintainer on the gccrs project (a second Rust compiler implementation), posting on the official Rust Blog -> "The amount of help we have received from Rust folks is great, and we think gccrs can be an interesting project for a wide range of users." (https://blog.rust-lang.org/2024/11/07/gccrs-an-alternative-c...)
This is par for the course I guess, and what exhausts folks like marcan. I wouldn't want to work with someone like Ted Tso'o, who clearly has a penchant for flame wars and isn't interested in being truthful.
> But then also came the entitled users. This time, it wasn’t about stealing games, it was about features. “When is Thunderbolt coming?” “Asahi is useless to me until I can use monitors over USB-C” “The battery life sucks compared to macOS” (nobody ever complained when compared to x86 laptops…) “I can’t even check my CPU temperature” (yes, I seriously got that one).
This sounds so rough. I can't imagine pouring your heart out into this labor of love and continue to have to face something like this. Back in the early days of Quora, when it used to be good, there used to be a be nice be respectful policy (they might still have it), I wonder if something like that would be helpful for open source community engagement.
Regardless, major props to Marcan for doing the great work that he did, our community is lucky to have people like him!
I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.
Something tells me aspects of living in the next few decades driven by technology acceleration will feel like being lobotomized while conscious and watching oneself the whole time. Like yes, we are able to think of thousands of hypothetical ways technology (even those inferior to full AGI) could go off the rails in a catastrophic way and post and discuss these scenarios endlessly... and yet it doesn't result in a slowing or stopping of the progress leading there. All it takes is a single group with enough collective intelligence and breakthroughs and the next AI will be delivered to our doorstop whether or not we asked for it.
It reminds me of the time I read books in my youth and only 20 years later realized the authors of some of those books were trying to deliver a important life messages to a teenager undergoing crucial changes, all of which would be painfully relevant to the current adult me... and yet the whole time they fell on deaf ears. Like the message was right there but I did not have the emotional/perceptive intelligence to pick up on and internalize it for too long.
Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations:
* Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneously, that has effectively no half-life once discovered, and whose exploitation will generate reliable telemetry from the target.
* Similarly, bugs like full-chain Android/Chrome go for hundreds of thousands of dollars because Google competes with a well-established grey market; a firm can take that bug and sell it to potentially 6 different agencies at a single European country.
* Even then, bounty vs. grey market is an apples-oranges comparison. Google will pay substantially less than the grey market, because Google doesn't need a reliable exploit (just proof that one can be written) and doesn't need to pay maintenance. The rest of the market will pay a total amount that is heavily tranched and subject to risk; Google can offer a lump-sum payment which is attractive even if discounted.
* Threat actors buy vulnerabilities that fit into existing business processes. They do not, as a general rule, speculate on all the cool things they might do with some new kind of vulnerability and all the ways they might make money with it. Collecting payment information? Racking up thousands of machines for a botnet? Existing business processes. Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no.
A bounty payout is not generally a referendum on how clever or exciting a bug is. Here, it kind of is, though, because $10,000 feels extraordinarily high for a server-side web bug.
For people who make their nut finding these kinds of bugs, the business strategy is to get good at finding lots of them. It's not like iOS exploit development, where you might sink months into a single reliable exploit.
This is closer to the kind of vulnerability research I've done recently in my career than a lot of other vuln work, so I'm reasonably confident. But there are people on HN who actually full-time do this kind of bounty work, and I'd be thrilled to be corrected by any of them.
My son had cancer during COVID, though he was fortunate enough to beat it into remission (with the help of a huge care team).
I was active duty military, and he is also non-verbal and autistic.
The things she talks about, how focused she was and how hard it is to do any of that now, I've been experiencing exactly the same things. I find it hard to do anything, put anything together, etc. after 3 years of managing his care closely, being at his bedside all hours, having to scream at nurses to call away a code because he couldn't breathe (anaphylaxis), and a ton of other things. All of this while working 50+ hours a week, including remotely from his bedside.
It's like I burnt out that part of me. Maybe I'm slowly healing? But I don't feel like it. I get minutes or hours when I can hit that stride again and it's absolutely terrifying to realize that I can no longer keep it up.
I don't know that this comment adds anything to her story. I just felt like I understood her on a level that's hard to communicate and had the urge to share that.
"The main thing holding back wider adoption is a lack of system interfaces. File access, networking, etc. But it's just a matter of time before these features get integrated."
But then you've got to figure out and prevent all the security holes that can be introduced by adding file access, networking, etc. That's what killed the Java write-once, run-anywhere promise. Maybe put the whole thing into a container? Oops, looks like the container wasn't replaced after all (though perhaps it could be simplified).
12vhpwr has almost no safety margin. Any minor problem with it rapidly becomes major. 600W is scary, with reports of 800W spikes.
12V2x6 is particularly problematic because any imbalance, such as a bad connection of a single pin, will quickly push things over spec. For example, at 600W, 8.3A are carried on each pin in the connector. Molex Micro-Fit 3.0 connectors are typically rated to 8.5A -- That's almost no margin. If a single connection is bad, current per connector goes to 10A and we are over spec. And this if things are mated correctly. 8.5A-10A over a partially mated pin will rapidly heat up to the point of melting solder. Hell, the 16 gauge wire typically used is pushing it for 12V/8.5A/100W -- that's rated to 10A. Really would like to see more safety margin with 14 gauge wire.
In short, 12V2x6 has very little safety margin. Treat it with respect if you care for your hardware.
That's one of the best blog posts I've read in a while. It nails the idea of "write one line that makes the reader want to read the next". It's humorous but also serious. There's no fluff. Instant subscribe.
I think we who are already in tech have this gleeful fantasy that new tools impair newcomers in a way that will somehow serve us, the incumbents, in some way.
But in reality pretty much anyone who enters software starts off cutting corners just to build things instead of working their way up from nand gates. And then they backfill their knowledge over time.
My first serious foray into software wasn't even Ruby. It was Ruby on Rails. I built some popular services without knowing how anything worked. There was always a gem (lib) for it. And Rails especially insulated the workings of anything.
An S3 avatar upload system was `gem install carrierwave` and then `mount_uploader :avatar, AvatarUploader`. It added an avatar control to the User form.
But it's not satisfying to stay at that level of ignorance very long, especially once you've built a few things, and you keep learning new things. And you keep wanting to build different things.
Why wouldn't this be the case for people using LLM like it was for everyone else?
It's like presuming that StackOverflow will keep you as a question-asker your whole life when nobody here would relate to that. You get better, you learn more, and you become the question-answerer. And one day you sheepishly look at your question history in amazement at how far you've come.
> I have been authoring the various Drive Stats reports for the past ten years and this will be my last one. I am retiring, or perhaps in Drive Stats vernacular, it would be “migrating.”
Thank you for all these reports over the years.
Liquid capsaicin treatments for bird seed are an effective squirrel repellent.
They also illustrate the evolution of this protein: birds have no receptors for capsaicin, while mammals do. Birds eat seeds mostly intactly. Their digestive systems are capable of breaking them down - but it's stochastic and some seeds make it through the bird undigested, being redistributed elsewhere. Obviously, having an agent sow your seeds widely is a fitness advantage, and so seedy plants are ultimately served well even if 90+% of their caloric investment into seeds goes into the birds.
Mammals, on the other hand, have teeth - particularly molars. Mammals that eat seeds grind them apart orally before even swallowing. As a result, any seeds ingested by mammals are very likely to be completely destroyed. Plants - peppers, anyway - found a chemical irritant that repels the mammals without even being sensed by birds.
I've used one such treatment (with an amusing logo illustrataion - https://i.imgur.com/JAl8vyW.png) to good effect to discourage squirrels at my feeder, so that they stick to my dedicated squirrel bungee with a log of compressed corn instead.
I think that LLMs are only going to make people with real tech/programming skills much more in demand, as younger programmers skip straight into prompt engineering and never develop themselves technically beyond the bare minimum needed to glue things together.
The gap between people with deep, hands-on experience that understand how a computer works and prompt engineers will become so insanely deep.
Somebody needs to write that operating system the LLM runs on. Or your bank's backend system that securely stores your money. Or the mission critical systems powering this airplane you're flying next week... to pretend like this will all be handled by LLMs is so insanely out of touch with reality.
There's such a huge disconnect between people reading headlines and developers who are actually trying to use AI day to day in good faith. We know what it is good at and what it's not.
It's incredibly far away from doing any significant change in a mature codebase. In fact I've become so bearish on the technology trying to use it for this, I'm thinking there's going to have to be some other breakthrough or something other than LLM's. It just doesn't feel right around the corner. Now completing small chunks of mundane code, explaining code, doing very small mundane changes. Very good at.
We have fired all our programmers.
However, the AI is hard to work with, it expects specific wording in order to program our code as expected.
We have hired people with expertise in the specific language needed to transmit our specifications to the AI with more precision.
It feels like Musk is single-handedly making a great case for why unlimited accumulation of wealth is a bad idea.
It's pretty colorful language, but my mind immediately jumps to "financial terrorist". He's using his enormous amount of wealth and influence as a weapon to bludgeon anyone and anything in his way.
> I'm beginning to think that the best way to approach a problem is by either not being aware of or disregarding most of the similar efforts that came before. This makes me kind of sad, because the current world is so interconnected, that we rarely see such novelty with their tendency to "fall in the rut of thought" of those that came before. The internet is great, but it also homogenizes the world of thought, and that kind of sucks.
I think this is true only if there is a novel solution that is in a drastically different direction than similar efforts that came before. Most of the time when you ignore previous successful efforts, you end up resowing non-fertile ground.
Sam’s reply on twitter[0]
no thank you but we will buy twitter for $9.74 billion if you want
[0]https://x.com/sama/status/1889059531625464090?
Krapivin made this breakthrough by being unaware of Yao's conjecture.
The developer of Balatro made an award winning deck builder game by not being aware of existing deck builders.
I'm beginning to think that the best way to approach a problem is by either not being aware of or disregarding most of the similar efforts that came before. This makes me kind of sad, because the current world is so interconnected, that we rarely see such novelty with their tendency to "fall in the rut of thought" of those that came before. The internet is great, but it also homogenizes the world of thought, and that kind of sucks.
> inconsistent command line arguments: is it -h or help or –help?
I've said it before and I'll say it again: the error "Option `--help` not understood, did you mean `-help`? Use `-help` to display program options." is one of the most insulting things a program can say to me. `--help` is the lowest common denominator. You have to support it. I don't care what your program has to special case in its parsing, just do it. If I knew your program's preferred syntax, I wouldn't be asking it for help.
Ignoring the horrifying political parts, I think one aspect here about data access that is inherently worrying is that it seems like all usual controls were bypassed and the DOGE people had very low level access to systems. So there are probably copies of sensitive data now in their possession, and nobody knows exactly what was copied and where it is stored.
This kind of access would be dangerous even in the hands of principled and well-meaning people. Giving it to people with glaring red flags like here is just entirely irresponsible.
All: if you're going to comment here, please make sure you're up on the guidelines at https://news.ycombinator.com/newsguidelines.html, and don't post low-information / high-indignation comments that could just as easily appear in any related thread. Such generic comments make discussion less interesting and more activating. That's not what we're trying for here.
Rather, we want curious conversation. I know that's not so easy when a situation is intense, infuriating, frightening, distressing, and so on. But we need to protect this site for its specific mandate—which is fragile at the best of times—so please make the effort.
As some of you know, this article was posted a dozen times and immediately flagkilled by users. I turned the flags off on this one because there's interesting new information in the story. But now it's up to the commenters to prove that was a good decision by co-creating a discussion that is interesting, curious, and has to do with the specifics of the article.
If we end up with yet-another interchangeable flamewar about $BigTopic, that will only confirm that the flaggers were right, so those of you who want fewer of these threads to be flagged have a particular interest in sticking to the intended spirit of the site and proving that a substantively different discusson is possible.
Edit: if you want to reply to this, please uncollapse the child comment below and reply there. Your views are welcome! I just also want to conserve space at the top of the thread.
Writing on a blog is a very inexpensive way to establish your credibility about different subjects. This pays off later down the line when you can link people to things you've written in the past.
Credibility is a very valuable commodity. It's worth investing in ways to build more of it.
Don't assume people will stumble across your content (though they will eventually via Google). Actively send links to people who you are already engaged in conversation with.
It's not the number of readers you have that matters: it's their quality. I'll take a dozen people reading my stuff who might engage with me usefully or lead to future opportunities over a thousand readers who don't match that criteria.