Is there some legitimate thing people are doing on LinkedIn that the crap is getting in the way of? One can make a profile and (thought it’s terrible for this) search for jobs without ever scrolling the feed. If you don’t like it just don’t use it.
It feels like complaining that the strip bar has alcohol and nudity everywhere, why are you there?
I deleted my Facebook account a couple of years ago and my Twitter one yesterday.
It's not just LLMs, it's how the algorithms promote engagement. i.e. rage bait, videos with obvious inaccuracies etc. Who gets rewarded, the content creators and the platform. Engaging with it just seems to accentuate the problem.
There needs to be algorithms that promote cohorts and individuals preferences.
Just because I said to someone 'Brexit was dumb', I don't expect to get fed 1000 accounts talking about it 24/7. It's tedious and unproductive.
Google's real moat isn't the TPU silicon itself—it's not about cooling, individual performance, or hyper-specialization—but rather the massive parallel scale enabled by their OCS interconnects.
To quote The Next Platform: "An Ironwood cluster linked with Google’s absolutely unique optical circuit switch interconnect can bring to bear 9,216 Ironwood TPUs with a combined 1.77 PB of HBM memory... This makes a rackscale Nvidia system based on 144 “Blackwell” GPU chiplets with an aggregate of 20.7 TB of HBM memory look like a joke."
Nvidia may have the superior architecture at the single-chip level, but for large-scale distributed training (and inference) they currently have nothing that rivals Google's optical switching scalability.
I _hate_ how this is written. At no point does it disclose explicitly:
* What systems were accessed
* What information was potentially exposed
* Just how "proactively" they've been about this (no timeline)
* Numbers... The scale of any of it
---
Some comments from quoted portions of article
> Mixpanel detected a smishing campaign ...
Doesn't give any details on who the companion targeted, or how, or how widespread.
> We took comprehensive steps to contain and eradicate unauthorized access and secure impacted user accounts.
So there was definitely _some_ sort of unauthorized access, but doesn't say to which accounts or in what systems
> Performed global password resets for all Mixpanel employees
So... definitely sounds like they expected compromise of Mixpanel employee credentials
Sixteen years here, and the half-life decay of this community has been slower than anywhere else. That takes real, consistent work, and we have been lucky to have it. Through good times and rough ones, including the loss of Aaron Swartz (who I only knew of through HN), this has stayed a place for real conversation.
The grit, curiosity, and people building things have always been inspiring.
Thanks for all the discussions over the years.
Happy Thanksgiving!
Codes of conduct are perfunctory virtue signalling. Do we really need a unique set of "rules" posted on every project? They all sound like they were written by the same AI bot. That said, it's telling that the Zig leader can't even follow them. The rules should just be taken down.
Amusingly, this post violates Zig's own code of conduct: https://ziglang.org/code-of-conduct
> Examples of behavior that contribute to creating a positive environment include:
> - Using welcoming and inclusive language.
> - Being respectful of differing viewpoints and experiences.
> - Showing empathy towards others.
> - Showing appreciation for others’ work.
> created by monkeys
I don't particularly care for either Zig or Github, but...
they do precisely cite the technical issues. That snippet links to a Github discussion comment https://github.com/actions/runner/issues/3792#issuecomment-3...
(reproduced below)
"The bug in this "safe sleep" script is obvious from looking at it: if the process is not scheduled for the one-second interval in which the loop would return (due to $SECONDS having the correct value), then it simply spins forever. That can easily happen on a CI machine under extreme load. When this happens, it's pretty bad: it completely breaks a runner until manual intervention. On Zig's CI runner machines, we observed multiple of these processes which had been running for hundreds of hours, silently taking down two runner services for weeks."
"I don't understand how we got here. Even ignoring the pretty clear bug, what makes this Bash script "safer" than calling into the POSIX standard sleep utility? It doesn't seem to solve any problem; meanwhile, it's less portable and needlessly eats CPU time by busy-waiting."
"The sloppy coding which is evident here, as well as the inaction on core Actions bugs (in line with the decay in quality of almost every part of GitHub's product), is forcing the Zig project to strongly consider moving away from GitHub Actions entirely. With this bug, and many others (severe workflow scheduling issues resulting in dozens of timeouts; logs randomly becoming inaccessible; random job cancellations without details; perpetually "pending" jobs), we can no longer trust that Actions can be used to implement reliable CI infrastructure. I personally would seriously encourage other projects, particularly any using self-hosted runners, to look carefully at the stability of Actions and ask themselves whether it is a solution worth sticking with long-term when compared with alternatives."
----
I agree that the writing in the blog post is more colorful than precise, but sanitizing every bit of expression dulls the internet. Humans invented language for a reason.
> it’s abundantly clear that the talented folks who used to work on the product have moved on to bigger and better things, with the remaining losers eager to inflict some kind of bloated, buggy JavaScript framework on us in the name of progress.
> More importantly, Actions is created by monkeys
This writing really does not reflect well on Zig. If you have technical issues with Github, fine: cite them. But leave ad hominems like "losers" and "monkeys" out of it.
A note that it's easy to "overstay" a visa when waiting for a green card interview - the wait times are often in the 6-16 month range, and if you leave the country you'll be considered to have abandoned your "petition to adjust status". It's a catch-22, and it looks like the only recourse is for an immigration lawyer to file a habeas corpus petition in federal court.
> As a bonus, we look forward to fewer violations (exhibit A, B, C) of our strict no LLM / no AI policy,
Hilarious how the offender on "exhibit A" [1] is the same one from the other post that made the frontpage a couple of days ago [2].
[1] https://github.com/ziglang/zig/issues/25974
[2] https://news.ycombinator.com/item?id=46039274
I once stayed at a very boutiquey, avant-garde hotel with a platonic friend. We had booked a twin room with separate beds, but what I did not expect was that the shower cubicle, with clear glass on all three sides, would be placed between the beds.
Calling the people who work on GitHub “losers” is not cool.
> As a bonus, we look forward to fewer violations (exhibit A, B, C) of our strict no LLM / no AI policy, which I believe are at least in part due to GitHub aggressively pushing the “file an issue with Copilot” feature in everyone’s face.
Also, the big part of that issue is people are incentivized to make their GitHub profile look good to have a higher chance of getting hired. Any non-mainstream platform is not as compelling to get social credits.
I don't think that adds up.
"Staying in a hotel with a romantic partner and/or family" is at least as primary a use case for hotels as "staying in a hotel with a platonic friend" and is still a scenario where you want a door but is NOT a scenario where "just get separate rooms" is a logical conclusion. "Get the hell out of that hotel and complain about it to everyone you know," on the other hand, is.
The much more specific way to target platonic buddies/coworkers from sharing a room would be eliminating rooms with two beds since the "couple" scenario would generally be perfectly happy with that still.
I am not doing any of this.
It becomes obsolete in literally weeks, and it also doesn't work 80% of the time. Like why write a mcp server for custom tasks when I don't know if the llm is going to reliably call it.
My rule for AI has been steadfast for months (years?) now. I write (myself, not AI because then I spend more time guiding the AI instead of thinking about the problem) documentation for myself (templates, checklist, etc.). I give ai a chance to one-shot it in seconds, if it can't, I am either review my documentation or I just do it manually.
Huh.. I've stayed in over 1,000 hotels and Airbnbs over the last 15 years and not once saw a bathroom with no door. Lots of bathroom windows, but always some kind of door.
It's not about saving a few bucks on a door. It's about discouraging you and your friends from sharing a single room. Hotel sees the money they're leaving on the table and will trade you for it for the low price of watching your buddies do their business.
"Here, install my new 1-day old NPM package that doesn't let you install packages younger than 90 days."
Pardon me, I couldn’t help myself :D
Apple also helped develop USB C more than a decade ago, they still had to be forced to actually use it in their phones. There is no contradiction here
For those unfamiliar, the studio behind S&box is Facepunch, creators of Garry's Mod and Rust. Facepunch as a company doesn't get much attention but they're wildly successful. Started as just some guy in a bedroom, now ~$100m/year in revenue (all via Steam), $100m in the bank, ~100 employees and almost entirely a company of game developers (maybe 20% of employees are administrative staff). Still owned and ran by the founder, Garry. S&box (and Garry's Mod and Rust) is pure game developers making things they want to make.
Unfortunately for OpenAI, they are not positioned to capture value from any of the "big margin" use cases that they highlight as key to their future. I think all of these are pretty unrealistic for them:
- Revenue sharing from drug discovery (called out by OpenAI CFO): Why would a pharma company give away the upside to a commoditized intelligence layer? Why would OpenAI have a more compelling story than Google Deep Mind, which has serious accolades in this space?
- Media generation for ads and other content: For ads, OpenAI is facing off against Google, Meta and Amazon, all of which have existing relationships with advertisers. For the foreseeable future, AI content will be a major discount product compared to humans. OpenAI will not get to charge $1M for an ad like a production company does. So the TAM of ad production (~$50B) shrinks below $1B because AI deflates prices so much.
- Other agent use cases: OpenAI doesnt have a surface to build these on. Google has chrome, Microsoft has office, Apple has OS's. The other use cases like coding will be a low-margin competition between model providers until some of them throw in the towel. The players with the best cash position win - and thats not OAI.
I think the place that they could win is retail (also called out by OAI CFO). They made deals with Etsy and other small retailers. I was fixing my guitar the other day and would have instantly bought the tools it had suggested that I would need. The problem is that they have to win against Amazon here, and there is zero chance of a partnership for obvious reasons.
It’s wild how Voyager forces two truths to sit together:
Technically, what we’ve done is almost boringly modest.
~17 km/s
~1 light-day in ~50 years
No realistic way to steer it anywhere meaningful now On cosmic scales it’s… basically still on our doorstep.
Psychologically, it’s still one of the most ambitious things we’ve ever done.
We built something meant to work for decades, knowing the people who launched it would never see the end of the story.
We pointed a metal box into the dark with the assumption that the future would exist and might care.
I keep coming back to this: Voyager isn’t proof that interstellar travel is around the corner. It’s proof that humans will build absurdly long-horizon projects anyway, even when the ROI is almost entirely knowledge and perspective.
Whether we ever leave the solar system in a serious way probably depends less on physics and more on whether we ever build a civilization stable enough to think in centuries without collapsing every few decades.
Voyager is the test run for that mindset more than for the tech.
"If they had a perfectly normalized database, no NULLing and formally verified code, this bug would not have happened."
That may be. What's not specified there is the immense, immense cost of driving a dev org on those terms. It limits, radically, the percent of engineers you can hire (to those who understand this and are willing to work this way), and it slows deployment radically.
Cloudflare may well need to transition to this sort of engineering culture, but there is no doubt that they would not be in the position they are in if they started with this culture -- they would have been too slow to capture the market.
I think critiques that have actionable plans for real dev teams are likely to be more useful than what, to me, reads as a sort of complaint from an ivory tower. Culture matters, shipping speed matters, quality matters, team DNA matters. That's what makes this stuff hard (and interesting!)
This sort of Monday morning quarterbacking is pointless and only serves as a way for random bloggers to try to grab credit without actually doing or creating any value.
Not that we would literally do this with Voyager, but it makes me wonder at the potential utility of a string of probes, one sent every couple of [insert correct time interval, decades, centuries?], to effectively create a communication relay stretching out into deep space somewhere.
My understanding with the Voyagers 1 and 2 is (a) they will run out of power before they would ever get far enough to benefit from a relay and (b) they benefited from gravity slingshots due to planetary alignments that happen only once every 175 years.
So building on the Voyager probes is a no-go. But probes sent toward Alpha Centauri that relay signals? Toward the center of the Milky Way? Toward Andromeda? Yes it would take time scales far beyond human lifetimes to build out anything useful, and even at the "closest" scales it's a multi year round trip for information but I think Voyager, among other things, was meant to test our imaginations, our sense of possible and one thing they seem to naturally imply is the possibility of long distance probe relays.
Edit: As others rightly note, the probes would have to communicate with lasers, not with the 1970s radio engineering that powered Voyagers 1 and 2.
> This is the culture that replaced hacker culture.
Somewhere along the lines of "everybody can code," we threw out the values and aesthetics that attracted people in the first place. What began as a rejection of externally imposed values devolved into a mouthpiece of the current powers and principalities.
This is evidenced by the new set of hacker values being almost purely performative when compared against the old set. The tension between money and what you make has been boiled away completely. We lean much more heavily on where someone has worked ("ex-Google") vs their tech chops, which (like management), have given up on trying to actually evaluate. We routinely devalue craftsmanship because it doesn't bow down to almighty Business Impact.
We sold out the culture, which paved the way for it to be hollowed out by LLMs.
There is a way out: we need to create a culture that values craftmanship and dignifies work done by developers. We need to talk seriously and plainly about the spiritual and existential damage done by LLMs. We need to stop being complicit in propagating that noxious cloud of inevitability and nihilism that is choking our culture. We need to call out the bullshit and extended psyops ("all software jobs are going away!") that have gone on for the past 2-3 years, and mock it ruthlessly: despite hundreds of billions of dollars, it hasn't fully delivered on its promises, and investors are starting to be a bit skeptical.
In short, it's time to wake up.
> I find it particularly disillusioning to realize how deep the LLM brainworm is able to eat itself even into progressive hacker circles.
That's the thing, hacker circles didn't always have this 'progressive' luddite mentality. This is the culture that replaced hacker culture.
I don't like AI, generally. I am skeptical of corporate influence, I doubt AI 2027 and so-called 'AGI'. I'm certain we'll be "five years away" from superintelligence for the forseeable future. All that said, the actual workday is absolutely filled with busy work that no one really wants to do, and the refusal of a loud minority to engage with that fact is what's leading to this. It's why people can't post a meme, quote, article, whatever could be interpreted (very often, falsely) as AI-generated in a public channel, or ask a chatbot to explain a hand-drawn image without the off chance that they get an earful from one of these 'progressive' people. These people bring way more toxicity to daily life than who they wage their campaigns against.
> And yeah, I get it. We programmers are currently living through the devaluation of our craft, in a way and rate we never anticipated possible.
I'm a programmer, been coding professionally for 10 something years, and coding for myself longer than that.
What are they talking about? What is this "devaluation"? I'm getting paid more than ever for a job I feel like I almost shouldn't get paid for (I'm just having fun), and programmers should be some of the most worry-free individuals on this planet, the job is easy, well-paid, not a lot of health drawbacks if you have a proper setup and relatively easy to find a new job when you need it (granted, the US seems to struggle with that specific point as of late, yet it remains true in the rest of the world).
And now, we're having a huge explosion of tools for developers, to build software that has to be maintained by developers, made by developers for developers.
If anything, it seems like Balmers plea of "Developers, developers, developers" has came true, and if there will be one profession left in 100 year when AI does everything for us (if the vibers are to be believed), then that'd probably be software developers and machine learning experts.
What exactly is being de-valuated for a profession that seems to be continuously growing and been doing so for at least 20 years?
If "Era of Scaling" means "era of rapid and predictable performance improvements that easily attract investors", it sounds a lot like "AI summer". So... is "Era of Research" a euphemism for "AI winter"?
It’s crazy you can pay for premium, which is not cheap, and you can’t disable shorts.
The number of times I clicked “show less” and it has zero effect on the number of shorts.
I noticed this morning there was a new version of the YouTube app on my Apple TV. I can’t wait to find out how they screwed this one up.
My personal long-term complaint is the length of video titles.
Lots of people like to make really long video titles. So right now there is one on my screen titled “The Best Decisions Every Video Game Console Developer Made”.
Now if you didn’t know, that is not the whole title. But there’s absolutely no indication of that. The only way you actually know that is either by checking or if the stuff on the screen is clearly not the end of a sentence.
So what is the full title? Well if you click and hold on the video, you get a pop-up letting you choose a couple of things such as play or safe to watch later or indicate you’re not interested. And at the top of the pop-up you see more words in the title. In this case you also see “(Part”.
Yep. You get ONE extra word. Sometimes not even that.
The ONLY way to see the full title is to start watching the video.
Obnoxious.
I used to pay for YouTube premium. I stopped doing that, uninstalled the apps, and now use it through the browser with adblockers. (Yes, on my phone and iPad.)
It works so well I’ve gotten at least half a dozen neighbours to do the same. If you haven’t tried it, it’s a definitive step up in UX.
Whoever made automatic AI dubs a default and impossible to disable also needs to be fired
> Examples include converting boxplots into violins or vice versa, turning a line plot into a heatmap, plotting a density estimate instead of a histogram, performing a computation on ranked data values instead of raw data values, and so on.
Most of this is not about Python, it’s about matplotlib. If you want the admittedly very thoughtful design of ggplot in Python, use plotnine
> I would consider the R code to be slightly easier to read (notice how many quotes and brackets the Python code needs)
This isn’t about Python, it’s about the tidyverse. The reason you can use this simpler syntax in R is because it’s non-standard-evaluation allows packages to extend the syntax in a way Python does not expose: http://adv-r.had.co.nz/Computing-on-the-language.html
> If you need to make a national payroll, you have to use it for a small town with a payroll of 50 people first, get the bugs worked out, then try it with a larger town, then a small city, then a large city, then a province, and then and only then are you ready to try it at a national level.
At a large box retail chain (15 states, ~300 stores) I worked on a project to replace the POS system.
The original plan had us getting everything working (Ha!) and then deploying it out to stores and then ending up with the two oddball "stores". The company cafeteria and surplus store were technically stores in that they had all the same setup and processes but were odd.
When the team that I was on was brought into this project, we flipped that around and first deployed to those two several months ahead of the schedule to deploy to the regular stores.
In particular, the surplus store had a few dozen transactions a day. If anything broke, you could do reconciliation by hand. The cafeteria had single register transaction volume that surpassed a surplus store on most any other day. Furthermore, all of its transactions were payroll deductions (swipe your badge rather than credit card or cash). This meant that if anything went wrong there we weren't in trouble with PCI and could debit and credit accounts.
Ultimately, we made our deadline to get things out to stores. We did have one nasty bug that showed up in late October (or was it early November?) with repackaging counts (if a box of 6 was $24 and if purchased as a single item it was $4.50 ... but if you bought 6 single items it was "repackaged" to cost $24 rather than $27) which interacted with a BOGO sale. That bug resulted in absurd receipts with sales and discounts (the receipt showed you spent $10,000 but were discounted $9,976 ... and then the GMs got alerts that the store was not able to make payroll because of a $9,976 discount ... one of the devs pulled an all nighter to fix that one and it got pushed to the stores ).
I shudder to think about what would have happened if we had tried to push the POS system out to customer facing stores where the performance issues in the cafeteria where worked out first or if we had to reconcile transactions to hunt down incorrect tax calculations.
It's a great article, until the end where they say what the solution would be. I'm afraid that the solution is: build something small, and use it in production before you add more features. If you need to make a national payroll, you have to use it for a small town with a payroll of 50 people first, get the bugs worked out, then try it with a larger town, then a small city, then a large city, then a province, and then and only then are you ready to try it at a national level. There is no software development process which reliably produces software that works at scale without doing it small, and medium sized, first, and fixing what goes wrong before you go big.
I really liked Simon's Willison's [1] and Meta's [2] approach using the "Rule of Two". You can have no more than 2 of the following:
- A) Process untrustworthy input - B) Have access to private data - C) Be able to change external state or communicate externally.
It's not bullet-proof, but it has helped communicate to my management that these tools have inherent risk when they hit all three categories above (and any combo of them, imho).
[EDIT] added "or communicate externally" to option C.
[1] https://simonwillison.net/2025/Nov/2/new-prompt-injection-pa... [2] https://ai.meta.com/blog/practical-ai-agent-security/
I used to spend a lot of time in Jakarta for work, and it's an underrated city. Yes, it's hot, congested, polluted and largely poor, but so is Bangkok.
Public transport remains not great, but it's improved a lot with the airport link, the metro, LRT, Transjakarta BRT. SE Asia's only legit high speed train now connects to Bandung in minutes. Grab/Gojek (Uber equivalents) make getting around cheap and bypass the language barrier. Hotels are incredible value, you can get top tier branded five stars for $100. Shopping for locally produced clothes etc is stupidly cheap. Indonesian food is amazing, there's so much more to it than nasi goreng, and you can find great Japanese, Italian, etc too; these are comparatively expensive but lunch at the Italian place in the Ritz-Carlton was under $10. The nightlife scene is wild, although you need to make local friends to really get into it. And it's reasonably safe, violent crime is basically unknown and I never had problems with pickpockets (although they do exist) or scammers.
I think Jakarta's biggest problems are lack of marketing and top tier obvious attractions. Bangkok has royal palaces and temples galore plus a wild reputation for go-go bars etc, Jakarta does not, so nobody even considers it as a vacation destination.
Who would have thought that having access to the whole system can be used to bypass some artificial check.
There are tools for that, sandboxing, chroots, etc... but that requires engineering and it slows GTM, so it's a no-go.
No, local models won't help you here, unless you block them from the internet or setup a firewall for outbound traffic. EDIT: they did, but left a site that enables arbitrary redirects in the default config.
Fundamentally, with LLMs you can't separate instructions from data, which is the root cause for 99% of vulnerabilities.
Security is hard man, excellent article, thoroughly enjoyed.
For those who are wondering, like me, what is this? Is this a new alternative to Stripe? The answer is: no. This is an added layer of abstraction on top of Stripe.
I work at $FANG, every one of our org's big projects go off the rails at the end of the project and there's always a mad rush at the end to push developers to solve all the failures of project management in their off hours before the arbitrary deadline arrives.
After every single project, the org comes together to do a retrospective and ask "What can devs do differently next time to keep this from happening again". People leading the project take no action items, management doesn't hold themselves accountable at all, nor product for late changing requirements. And so, the cycle repeats next time.
I led and effort one time, after a big bug made it to production after one of those crunches that painted the picture of the root cause being a huge complicated project being handed off to offshore junior devs with no supervision, and then the junior devs managing it being completely switched twice in the 8 month project with no handover, nor introspection by leadership. My manager's manager killed the document and wouldn't allow publication until I removed any action items that would constrain management.
And thus, the cycle continues to repeat, balanced on the backs of developers.
> Most people switch browsers for one reason: speed.
Is that true? Maybe it is and I'm out of the loop but I can't remember the last time someone complained about browser speed. The bottleneck seems to be website bloat more than anything else. Would love to see this argument quantified.
I study and write quite a bit of tech history. IMHO from what I've learned over the last few years of this hobby, the primary issue is quite simple. While hardware folks study and learn from the successes and failures of past hardware, software folks do not. People do not regularly pull apart old systems for learning. Typically, software folks build new and every generation of software developers must relearn the same problems.
It took me until my mid-30s to feel like I had crossed a threshold in processing grief and trauma from my late teen years. I was capable of adult behavior long before then, but my concept of the world and how I fit into it (or don't) was still childlike in many ways on a fundamental level.
Like most such things, I'd expect this to be a spectrum, and I may be somewhat of a late bloomer. Regardless, I have a theory that there is somewhat of a protective effect operating here. Believing in a simpler reality which involved future wish fulfillment for me - however unrealistic it was - may have helped me survive. Coming to acceptance of what I see as a more accurate but far bleaker perspective required me to grow strong enough to sustain my will to live despite that perspective.
Biggest lesson learned: I could not do it without at least one other person (or more) who I trust almost 100% with all of myself. Realizing that going it alone is futile is definitely part of what I consider becoming an adult, and it can take a long time to fully accept that.
I remembered reading about this news back when that first message was posted on the mailing list, and didn't think much of it then (rust has been worming its way into a lot of places over the past few years, just one more thing I tack on for some automation)...
But seeing the maintainer works for Canonical, it seems like the tail (Ubuntu) keeps trying to wag the dog (Debian ecosystem) without much regard for the wider non-Ubuntu community.
I think the whole message would be more palatable if it weren't written as a decree including the dig on "retro computers", but instead positioned only on the merits of the change.
As an end user, it doesn't concern me too much, but someone choosing to add a new dependency chain to critical software plumbing does, at least slightly, if not done for very good reason.
Did these Ocaml maintainers undergo some special course for dealing with difficult people? They show enormous amounts of maturity and patience. I'd just give the offender Torvalds' treatment and block them from the repo, case closed.
As someone dealing with open-source compliance in distributed systems, the purity tests in these comments are exhausting.
Hardware is messy. IP licensing for sensors and radios is a nightmare. Getting a functional OS out with "only" a few binary blobs is a massive engineering and legal victory.
I'd rather have a working, 95% open ecosystem that I can actually hack on, than a 100% pure theoretical one that never ships. Kudos to Eric for navigating the legal minefield to make this happen.
There are LLMs with more self-awareness than this guy.
Repeatedly using AI to answer questions about the legitimacy of commits from an AI, to people who are clearly skeptical is breathtakingly dense. At least they're open about it.
I did love the ~"I'll help maintain this trash mountain, but I'll need paying". Classy.
We should just build more CLI tools, that way the agentic AI can just run `yourtool --help` to learn how to use it. Instead of needing an MCP-server to access ex. Jira it should just call a cli tool `jira`. Better CLI tools for everything would help both AI and humans alike.
No one tech-savvy wants this. We are already sick of Google's Android lockdowns on mobile phones, and now coming after laptops and desktops?
What's that going to be like? Will developers have to beg to have control over devices they own? Will we be locked down on the store and have to manually install "unverified" software? Will I be able to take screenshots at will on MY computer, or get a black screen because Google decides so?
The list can go on and on ad nauseam. Given what Google has done on the mobile space I have zero interest in having the same autocratic experience to be replicated on the last type of devices (PCs and laptops) where we can really have true open choices and alternatives. Screw them.
Some animals are ready to go as soon as they are born. These are called precocial animals. They are born knowing how to walk.
It's interesting seeing what comes built-in. You can see this if you watch a horse being born. Within the first hour, the foal will stand, and despite long legs, this usually works the first time. Lying down, however, is not preprogrammed. I've watched a foal circle trying to figure out how to get down from standing, and finally collapsing to the ground in a heap. Standing up quickly is essential to survival, but smoothly lying down is not. Within a day, a newborn foal can run with the herd.
Of the mammals, most of the equines and some of the rodents (beavers) are precocial. Pigs are, monkeys are not. It's not closely tied to evolutionary ancestry.
>>> Here's my question: why did the files that you submitted name Mark Shinwell as the author?
>>> Beats me. AI decided to do so and I didn't question it.
Really sums the whole thing up...
One key point about retention which is not often mentioned, and indeed neither does this article, is that retention is inversely proportional to program/erase cycles and decreases exponentially with increasing temperature. Hence why retention specs are usually X amount of time after Y cycles at Z temperature. Even a QLC SSD that has only been written to once, and kept in a freezer at -40, may hold data for several decades.
Manufacturers have been playing this game with DWPD/TBW numbers too --- by reducing the retention spec, they can advertise a drive as having a higher endurance with the exact same flash. But if you compare the numbers over the years, it's clear that NAND flash has gotten significantly worse; the only thing that has gone up, multiplicatively, is capacity, while endurance and rentention have both gone down by a few orders of magnitude.
For a long time, 10 years after 100K cycles was the gold standard of SLC flash.
Now we are down to several months after less than 1K cycles for QLC.
SSD firmware engineer here. I work on enterprise stuff, so ymmv on consumer grade internals.
Generally, the data refresh will all happen in the background when the system is powered (depending on the power state). Performance is probably throttled during those operations, so you just see a slightly slower copy while this is happening behind the scenes.
The unused space decaying is probably not an issue, since the internal filesystem data is typically stored on a more robust area of media (an SLC location) which is less susceptible to data loss over time.
As far as how a user is supposed to manage it, maybe do an fsck every month or something? Using an SSD like that is probably ok most of the time, but might not be super great as a cold storage backup.
So, like, we were already pretty much priced out of higher-end graphic cards, and now it's happening to RAM. All this while jobs are disappearing, layoffs are ongoing and CEOs are touting AI's 'capabilities' left and right.
Next is probably CPUs, even if AIs don't use them that much, manufactures will shift production to something more profitable, then gouge prices so that only enterprises will pay for them.
What's next? Electricity?
Where the f*k is all the abundance that AI was supposed to bring into the world? /rant
Every time I see an article like this, it's always missing --- but is it any good, is it correct? They always show you the part that is impressive - "it walked the tricky tightrope of figuring out what might be an interesting topic and how to execute it with the data it had - one of the hardest things to teach."
Then it goes on, "After a couple of vague commands (“build it out more, make it better”) I got a 14 page paper." I hear..."I got 14 pages of words". But is it a good paper, that another PhD would think is good? Is it even coherent?
When I see the code these systems generate within a complex system, I think okay, well that's kinda close, but this is wrong and this is a security problem, etc etc. But because I'm not a PhD in these subjects, am I supposed to think, "Well of course the 14 pages on a topic I'm not an expert in are good"?
It just doesn't add up... Things I understand, it looks good at first, but isn't shippable. Things I don't understand must be great?
One of the more disturbing things I read this year was the my boyfriend is AI subreddit.
I genuinely can't fathom what is going on there. Seems so wrong, yet no one there seems to care.
I worry about the damage caused by these things on distressed people. What can be done?
This is also super relevant for everyone who had ditched Claude Code due to limits:
> For Claude and Claude Code users with access to Opus 4.5, we’ve removed Opus-specific caps. For Max and Team Premium users, we’ve increased overall usage limits, meaning you’ll have roughly the same number of Opus tokens as you previously had with Sonnet. We’re updating usage limits to make sure you’re able to use Opus 4.5 for daily work.
This is gonna be game-changing for the next 2-4 weeks before they nerf the model.
Then for the next 2-3 months people complaining about the degradation will be labeled “skill issue”.
Then a sacrificial Anthropic engineer will “discover” a couple obscure bugs that “in some cases” might have lead to less than optimal performance. Still largely a user skill issue though.
Then a couple months later they’ll release Opus 4.7 and go through the cycle again.
My allegiance to these companies is now measured in nerf cycles.
I’m a nerf cycle customer.
The burying of the lede here is insane. $5/$25 per MTok is a 3x price drop from Opus 4. At that price point, Opus stops being "the model you use for important things" and becomes actually viable for production workloads.
Also notable: they're claiming SOTA prompt injection resistance. The industry has largely given up on solving this problem through training alone, so if the numbers in the system card hold up under adversarial testing, that's legitimately significant for anyone deploying agents with tool access.
The "most aligned model" framing is doing a lot of heavy lifting though. Would love to see third-party red team results.
One of my students recently came to me with an interesting dilemma. His sister had written (without AI tools) an essay for another class, and her teacher told her that an "AI detection tool" had classified it as having been written by AI with "100% confidence". He was going to give her a zero on the assignment.
Putting aside the ludicrous confidence score, the student's question was: how could his sister convince the teacher she had actually written the essay herself? My only suggestion was for her to ask the teacher to sit down with her and have a 30-60 minute oral discussion on the essay so she could demonstrate she in fact knew the material. It's a dilemma that an increasing number of honest students will face, unfortunately.
so, they are basically confirming Android and Apple have their backdoors as no arrests or seizures on that matter have taken place
I think your devices should have government-mandated backdoors if and only if you are a public servant. I don't understand why private citizens are held to higher standards of conduct than politicians and cops.
ProTip: use PNPM, not NPM. PNPM 10.x shutdown a lot of these attack vectors.
1. Does not default to running post-install scripts (must manually approve each)
2. Let's you set a min age for new releases before `pnpm install` will pull them in - e.g. 4 days - so publishers have time to cleanup.
NPM is too insecure for production CLI usage.
And of course make a very limited scope publisher key, bind it to specific packages (e.g. workflow A can only publish pkg A), and IP bound it to your self hosted CI/CD runners. No one should have publish keys on their local, and even if they got the publish keys, they couldn't publish from local. (Granted, GHA fans can use OIDC Trusted Publishers as well, but tokens done well are just as secure)
For context, djb has been doing and saying these things since he was a college student:
While a graduate student at the University of California at Berkeley, Bernstein completed the development of an encryption equation (an "algorithm") he calls "Snuffle." Bernstein wishes to publish a) the algorithm (b) a mathematical paper describing and explaining the algorithm and (c) the "source code" for a computer program that incorporates the algorithm. Bernstein also wishes to discuss these items at mathematical conferences, college classrooms and other open public meetings. The Arms Export Control Act and the International Traffic in Arms Regulations (the ITAR regulatory scheme) required Bernstein to submit his ideas about cryptography to the government for review, to register as an arms dealer, and to apply for and obtain from the government a license to publish his ideas. Failure to do so would result in severe civil and criminal penalties. Bernstein believes this is a violation of his First Amendment rights and has sued the government.
After four years and one regulatory change, the Ninth Circuit Court of Appeals ruled that software source code was speech protected by the First Amendment and that the government's regulations preventing its publication were unconstitutional. - Source https://www.eff.org/cases/bernstein-v-us-dept-justiceWhy are all the comments here so weird? It's like people saw (but didn't read) an article entitled "Man Opens a Taqueria in his Hometown" and the only responses are
1) Why didn't he open it in my hometown? This location isn't convenient for me.
2) Wouldn't it be better for someone else to open a taqueria instead? My cousin is looking for work. Shouldn't we be putting resources into helping him open a restaurant instead?
It's like people hear "X in Asian country" and all they can think about is their own geopolitical narrative fed to them by the US state department. Obviously Japan is going to want to develop lucrative manufacturing... within Japan.
The "use cooldown" [0] blog post looks particularly relevant today.
I'd argue automated dependency updates pose a greater risk than one-day exploits, though I don't have data to back that up. That's harder to undo a compromised package already in thousands of lock files, than to manually patch a already exploited vulnerability in your dependencies.
[0] https://blog.yossarian.net/2025/11/21/We-should-all-be-using...
It's not "node" or "Javascript" the problem, it's this convenient packaging model.
This is gonna ruffle some feathers, but it's only a matter of time until it'll happen on the Rust ecosystem which loves to depend on a billion subpackages, and it won't be fault of the language itself.
The more I think about it, the more I believe that C, C++ or Odin's decision not to have a convenient package manager that fosters a cambrian explosion of dependencies to be a very good idea security-wise. Ambivalent about Go: they have a semblance of packaging system, but nothing so reckless like allowing third-party tarballs uploaded in the cloud to effectively run code on the dev's machine.
co-founder of PostHog here. We were a victim of this attack. We had a bunch of packages published a couple of hours ago. The main packages/versions affected were:
- posthog-node 4.18.1, 5.13.3 and 5.11.3
- posthog-js 1.297.3
- posthog-react-native 4.11.1
- posthog-docusaurus 2.0.6
We've rotated keys and passwords, unpublished all affected packages and have pushed new versions, so make sure you're on the latest version of our SDKs.
We're still figuring out how this key got compromised, and we'll follow up with a post-mortem. We'll update status.posthog.com with more updates as well.
Ex-Meta employee here. I worked at reality labs, perhaps in other orgs the situation is different.
At Meta we did "fix-it weeks", more or less every quarter. At the beginning I was thrilled: leadership that actually cares about fixing bugs!
Then reality hit: it's the worst possible decision for code and software quality. Basically this turned into: you are allowed to land all the possible crap you want. Then you have one week to "fix all the bugs". Guess what: most of the time we couldn't even fix a single bug because we were drown in tech debt.
Maybe they resisted because it was completely ridiculous waste of engineering resources all over the country and for absolutely no tangible reason other than white people trying to feel better about themselves.
I work in the field of film mastering (with countless product names with the word “master” in it) and luckily no one got the ridiculous idea in their head that we need to change this lingo.
Show me a single person who has a valid reason for me not calling my branch “master” or my bedroom “the master”. I honestly think this sort of ridiculing word policing is why we lost this last damned election. And if you’re somehow proud that you’ve renamed your git branches, you’re very likely a contributor to that lost election.
Sorta related since Disney held a share in it previously but Dick Tracy exclusive rights are still held by Warren Beatty who produced and starred in the role back in 1990. He had to fight off a challenge from Tribune Media in court decades ago but stipulation was he had to produce new Dick Tracy stuff every few years. It’s lead to a series of increasingly surreal late night specials on TCM where he appears in character and talks about random stuff and the 1990 movie, last time was in 2023: https://m.youtube.com/watch?v=MwKncYwtec4
It would be a good thing, if it would cause anything to change. It obviously won't. As if a single person reading this post wasn't aware that the Internet is centralized, and couldn't name specifically a few sources of centralization (Cloudflare, AWS, Gmail, Github). As if it's the first time this happens. As if after the last time AWS failed (or the one before that, or one before…) anybody stopped using AWS. As if anybody could viably stop using them.
I love the idea, but this line:
> 1) no bug should take over 2 days
Is odd. It’s virtually impossible for me to estimate how long it will take to fix a bug, until the job is done.
That said, unless fixing a bug requires a significant refactor/rewrite, I can’t imagine spending more than a day on one.
Also, I tend to attack bugs by priority/severity, as opposed to difficulty.
Some of the most serious bugs are often quite easy to find.
Once I find the cause of a bug, the fix is usually just around the corner.
> Big-city transit has an equilibrium point, and it is incredibly stable. Every serious transit city in the world ends up in the same place
You're cherry-picking your own examples. It worked in Iowa City.
Y Combinator and much of SV would be out of business if innovators followed that thinking. One reason is that people do come up with new ideas; that's how the world changes. The other is that the world changes, and what didn't work before now works - costs change and value changes, and now it's worthwhile. For example, with congestion pricing and other rapidly increasong costs of NYC car ownership, there's more value in free transit.
Oddly, it's the thinking advocated by many HN posts, denigrating the innovation under discussion as impossible, useless, etc.
> without sustainability, a political shift will kill it
That can be said of many things. A political shift could kill military funding in the US.
I knew some people that were initially very optimistic, and I tried to keep an open mind when DOGE got started despite the outlandish claims that they would be able to cut $2 trillion dollars from the budget, but it's apparent at this point that the project has been an extreme failure. It'll probably take a few years to really sort out their damage and overall impact though.
It's also imperative to mention in every DOGE-related discussion and conversation that the funding freeze to USAID is directly responsible for killing thousands of people [0]. Most of the damage done by DOGE can probably be reversed, but the thousands of death as a direct result of actions taken by the richest man in the world should not be forgotten. (Although I'm told there is a bit of uncertainty with any specific figures because the funding disruption also impacted the mechanisms for tracking and reporting deaths.)
[0] https://www.newyorker.com/culture/the-new-yorker-documentary...
Reminds me of when Reddit posted their year end roundup https://web.archive.org/web/20140409152507/http://www.reddit... and revealed their “most addicted city” to be the home of Eglin Air Force Base, host of a lot of military cyber operations. They edited the article shortly afterward to remove this inconvenient statistic
Walk willingly into platos cave, pay for platos cave verification, sit down, enjoy all the discourse on the wall. Spit your drink out when you figure out that the shadows on the wall are all fake.
Rust has its issues and there are plenty of things to not like about Rust, but this article is giving me the impression that this person has not written much Rust. Unfortunately, many such cases with Rust criticism.
> Memory safety is not that sacred. In fact, for many applications malfunctioning is better than crashing — particulary in the embedded world where Rust wants to be present. You cannot get 99.999% reliability with Rust — it crashes all the time.
Yeah until that memory safety issue causes memory corruption in a completely different area of code and suddenly you're wasting time debugging difficult-to-diagnose crashes once they do start to surface.
> We actually had a recent Cloudflare outage caused by a crash on unwrap() function: https://blog.cloudflare.com/18-november-2025-outage/
There were multiple failures before that `unwrap()` and the argument can easily be made that this is no different than an unchecked exception or a release assertion.
> Sync/Send, Mutex and reference counting (Arc)? Unfortuantely, those lock or simply mess with CPU caches badly, so they are inefficient for multithreaded communication, at least an intensive one. They are safe, but inefficient. Which kinda destroys the first uncompromising thing in Rust — performance.
Doing this the "correct" way in other languages has similar impact? So I'm not sure why Rust forcing you to do the correct thing which causes perf issues is uniquely a Rust issue. Doing this the "just get it done" way in other languages will likely come back to bite you eventually even if it does unblock you temporarily.
There are plenty of times I did a `static mut` global in Rust just to get some shit done and oops, accidentally hit some UB as the project grew.
I've been a Windows user since 3.1; and I've even defended Microsoft in the past (particularly when they made unpopular choices, but for technically correct reasons, like UAC or forcing vendors to rewrite their drivers into userland or using a safer driver model).
BUT, I won't defend Windows 11 and Microsoft's general direction. I feel like there has been a slow cultural shift within Microsoft, from a core of fantastic engineers surrounding by marketing/sales, to the org's direction being set by marketing/sales UX be damned.
Plus it feels like a lot of the technical expertise retired out, and left a bunch of engineers scared to touch core systems instead preferring to build on top using Web tech. It means that Windows/Office stopped improving, and have actually both regressed significantly.
I've actually found myself recommending MacOS, particularly the prior generation of Macbook Airs which are absurdly powerful with absurd battery life for a fair price. Combine that with the lack of user hostility, and UX, that MacOS brings relative to Windows 11, and it is hard to ignore.
Hey, I made this font. I really ummed and ahhed over the name for this exact same reason. But in the end it was just too clever to pass up. Thanks for moving past it, haha.
Typography nerds are some of my favourite nerds.
Font specimen pages are so often screaming with design language and intention, they push and prod to evoke and present.
Maybe the secret has something to do with the lack of priority to the actual content; just present the font gosh-darn!
Looks nicely executed within the confines of the inspiration. very cool
The web/webapps/mobile helped lead to this era of "desktop PCs" (to include laptops) where the browser mattered more than the OS. It allowed Apple to become resurgent in the desktop market because OS compatibility mattered less than ever.
It's not weird that it led to Apple regaining _some_ market share because clearly there was demand for the Apple/MacOS/OS X experience that may have been tempered by incompatibility in the pre-webapp days.
What _is_ weird, and nonintuitive, is that the (by all accounts) higher-cost vendor would be seen as ascendent in this market. All the more weird for two reasons:
1. The Apple experience, at least on the OS side, matters less and less in the webapp world.
2. Apple isn't trying, either! They're seemingly doing their best to abandon and alienate their desktop OS users. A decade or more of stagnation or regression in features and usability, capped off by Tahoe this year.
It feels like Apple and Microsoft are just waiting for the desktop OS to die, waiting for mobile to take it over; so we can all just shut up and stop asking for filesystems and terminals so they can sell us iPads and Surfaces, and they can finally be free of this ancient burden of selling desktop computer OSes.
And the consumers keep buying the stupid things, demanding product in a market that the vendors don't want any part of.
Yep, I knew this was Comcast/Xfinity just seeing the title. I had the exact same problem, for years. Intermittent disconnects for a few minutes at a time, multiple times a day. I must have had upwards of 50 technicians come to my house, all insisting there was some problem with the wiring in my house (there wasn’t) or the router or whatever (hardware all replaced multiple times including the wiring). Eventually after years of complaining that the issue isn’t in my house, they finally sent a bucket truck a half a mile up the road and the problem was fixed in about 30 minutes. It worked well for about a year and then started happening again. They started giving me the run around again. I had appointments scheduled for technicians to come, three times in a row they just never showed up. To “apologize” to me they said they would provide a credit on my account. The amount? 1 penny. I took a screenshot and saved it in case anyone thinks I am making this up. Luckily, by this time starlink was available in my area. I switched to that, turns out it’s much cheaper anyway and since then have not had any issues. The sooner Comcast goes out of business, the better.
Tip to anyone reading this: After I cancelled and closed my account, they billed me one last time for double my monthly bill ($200). No idea why, probably they thought they'd try to get away with it. I had little to no interest in participating in their customer support circus again, so I just went online to my bank and submitted a dispute of the charge. The bank instantly ruled in my favor and closed the case, issuing a permanent credit. I have never seen that before. They must be getting tons of Comcast chargebacks to do that.
I also submitted a complaint to the AG office and my local commission but I'm not expecting anything to happen.
> a Meta spokesperson said in a statement to TIME. "The full record will show that for over a decade, we have listened to parents, researched issues that matter most, and made real changes to protect teens
Omegalol. Cigarette maker introduces filter, cares about your health.
I don't agree, and this feels like something written by someone who has never managed actual systems running actual business operations.
Operating systems in particular need to manage the hardware, manage memory, manage security, and otherwise absolutely need to shut up and stay out of the fucking way. Established software changes SLOWLY. It doesn't need to reinvent itself with a brand new dichotomy every 3 years.
Nobody builds a server because they want to run the latest version of Python. They built it to run the software they bought 10 years ago for $5m and for which they're paying annual support contracts of $50k. They run what the support contracts require them to run, and they don't want to waste time with an OS upgrade because the cost of the downtime is too high and none of the software they use is going to utilize any of the newly available features. All it does is introduce a new way for the system to fail in ways you're not yet familiar with. It adds ZERO value because all we actually want and need is the same shit but with security patches.
Genuinely I want HN to understand that not everyone is running a 25 person startup running a microservice they hope to scale to Twitter proportions. Very few people in IT are working in the tech industry. Most IT departments are understaffed and underfunded. If we can save three weeks of time over 10 years by not having to rebuild an entire system every 3 years, it's very much worth it.
Ouch. This hits incredibly hard.
I’ve been this dad who sits frozen at the TV every evening. I had the affairs with the emotionally unavailable men, and became one myself.
Before you judge the man in this story too harshly — and there’s certainly much to judge, especially given the follow-up post — consider the environment he and I grew up in. Being gay as a young teenager in the early 1990s could feel literally like a death sentence. AIDS panic was everywhere. Gay men in movies were comedy sidekicks or dying wrecks (“Philadelphia”). There was a real threat of violence from other kids. If you could pass as straight, why wouldn’t you give it your best shot? The alternative was to be a laughing stock and die alone in a hospital where nurses don’t dare touch you. (This is literally how I imagined gay life at age 13.)
I still feel like I’m barely getting started on the therapy journey to recover from those decades. Seems like the man in the story never had the chance for professional help (or didn’t seek it). The compartmentalization can be extremely taxing. He disappointed many people, but that doesn’t mean he was a bad person.
I'm a dad too, and I'm in a somewhat similar situation. My son is under five, and it feels like I'm still at the very beginning of his story. I've known I was gay since high school, probably even earlier, but I kept choosing whatever seemed like the easiest path. It felt easier to stay closeted. Easier to date a woman. Easier to move in together, propose, get married, and even have a child than to face my truth.
I love my wife and my son, and I feel loved by them in return, but I'm also painfully aware that the version of me they love is someone I constructed. I lie constantly: about why I don't want sex, about my affairs, about my feelings, about my motivations. No one really knows me, and I don't get to be myself, not even in the relationships where I should feel safest.
I've read The Courage to Be Disliked by Ichiro Kishimi and other similar books, and I'm trying to build the courage to finally do something about all of this. It's incredibly difficult. But I refuse to use my son as an excuse to keep postponing coming out. This blog has pushed me even further in that direction.
They'll be angry (well at least my wife). Their lives will be upended. But at least they'll have the chance to ask questions, to understand. They'll see me taking responsibility for the consequences of my choices, and maybe just maybe, in some way, that clarity will be a relief for all of us.
From reading both posts, there's a few things that come to my mind:
- It seems this is how the author is processing her father's passing, and it's not really up to us to make moral calls on the content of the posts. They are thoughts with gaps of missing context against a real life of highs and lows which is not readily condensed into a blog post.
- I'm peering into the life of a private person, that feels like a violation. Even though they have passed, the people around them are very much alive.
- We can't makes guesses at what a person truly values, neither positively nor negatively. What can be seen as promiscuity can also be seen as seeking validation, human motives and emotions exist in the grey area.
- This is a person who was deprived of the sort of genuine sexual and emotional attention that we take for granted from puberty age. They lived as a type of outsider in school, work, and their daily norms. The integrity of their actions shouldn't be evaluated against our own values which were likely built from a different life experience.
- It's ok not knowing or judging. One has to practice a type of "radical acceptance" when reviewing these sorts of life matters.
There's a follow-up posted already too.
https://www.jenn.site/my-dead-deadbeat-gay-dad/
I’ve recently had to deal with my father cognitive decline & falling for scams left & right using Meta’s apps. This has been so hard on our family. I did a search the other day on marketplace and 100% of all sellers were scams, 20-30 of them.
Meta is a cancer on our society, I’m shutting down all my accounts. Back when TV/Radio/News paper were how you consumed news, you couldn’t get scams this bad at this scale. Our parents dealt with their parents so much easier as they cognitively declined. We need legal protections for elders and youth online more than ever. Companies need to be liable for their ads and scam accounts. Then you’d see a better internet.
At this point, I think all of the big tech companies have had some accusations of them acting unethically, but usually, the accusations are around them acting anticompetitively or issues around privacy.
Meta (and social media more broadly) are the only case where we have (in my opinion) substantiated allegations of a company being aware of a large, negative impact on society (mental wellness, of teens no less), and still prioritizing growth and profit. The mix is usually: grow at all costs mindset, being "data-driven", optimizing for engagement/addiction, and monetizing via ads. The center of gravity of this has all been Meta (and social media), but that thinking has permeated lots of other tech as well.
The comment at the bottom of the article I believe is correct. I believe this because our neighborhood had the same problem. One day my neighbor, frustrated beyond his capacity, and seemingly very high on something, went outside and started ripping infrastructure out by hand and damaging everything else he could find with a hammer.
They came out and replaced a lot of the damaged equipment and did a few upgrades. After that the intermittent 2 minute drop problems disappeared.
There's a fascinating and redacted interview with an "anonymous" subject about the disaster. To say the least it's an unsuccessful attempt to hide the identity of the individual:
"Q. So how did you get yourself started into submersible operations?
A. Well, I'm sure you're familiar with my film Titanic. When I set down the path to make that film, the first thing that I did was arrange to be introduced to the head of the submersible program at the P.P. Shirshov Institute in Moscow, a guy named..."
https://media.defense.gov/2025/Sep/17/2003800984/-1/-1/0/CG-...
I had a similar problem with a different ISP, Optimum, in Northern NJ. It wasn't as regular as the author's problem -- my cable modem would desync intermittently throughout the day despite the signal strength numbers being in spec.
I replaced everything downstream of the drop from the street, all new wiring inside, a new modem/router/etc. All signs pointed to the problem being outside the house. I went so far as to connect an oscilloscope to the coax line to look for patterns. I discovered that if I physically manipulated a particular section of the line from the pole, a huge interference pattern appeared and the modem's connection dropped. Eventually I could reproduce the connection loss fairly easily.
Convincing the ISP to actually do anything about it was much harder. Despite first-hand evidence that the coax from the pole needed to be replaced, their tech support insisted that someone had to come into the house to inspect the interior wiring. No amount of insistence on my part would convince them that it was not necessary. The building was a vacation home, and this was during peak COVID time, so there was basically no chance of that happening. The appointment came with threats of service charges if they sent a tech and could not enter the building or reproduce the problem, so I cancelled it.
Coincidentally, I happened to discover that the mayor of the town had started a hotline specifically for reporting home Internet problems in the town. So I sent in a message to that service, not really expecting anything to come of it. But shortly after I get a phone call from some higher-up department of the ISP. They had a truck out within a few days to replace the drop -- with no one home -- and the connection was rock solid ever since.
This experience taught me that ISPs often have distinct support channels that governmental departments use to contact them. I think they called it the "executive support team" or something along those lines. Basically, if you can get a message in that way, it's possible to circumvent the useless consumer-level support. Long story short, I think escalating this through the local or state level government may be the author's best shot at getting this resolved.
I sympathize with the author. I remain on Charter’s shitlist to this day because I had a very similar issue about twenty years ago, except our connection cut out entirely after ~10MB of data had downloaded in a continuous stream, and the cable modem had to wait for the line to become available again. No amount of technical documentation, logs, traceroutes, equipment swaps, or anything on my end would convince them it was a problem with their infrastructure.
So, exasperated, I filed a complaint with the FCC. A week later, it got fixed along with an apology, no truck roll needed.
I miss when the government had teeth and used it against companies, man.
99% of my use of `satisfies` is to type-check exhaustivity in `switch` statements:
type Foo = 'foo' | 'bar';
const myFoo: Foo = 'foo';
switch (myFoo) {
case 'foo':
// do stuff
break;
default:
myFoo satisfies never; // Error here because 'bar' not handled
}Finally some progress towards smellovision.
I thought this was a really good piece of writing. It’s rare to do something like this because the job discourages it by putting PR filters on everything you say.
My uncle was a pretty big pop star in the 1960s. His group at one point had a big fanzine, they were household names across the country, over time they had stalkers and weird fans and all that, made movies and albums, had big parties and knew other famous people, pretty much all those things that the OP writes about (circa 50 years later, some of it has changed but not that much).
He could be charismatic and surprisingly eloquent and I could picture him writing a piece like this, if the mood had struck.
He also lost pretty much all the money through mismanagement (several times over), eventually moved out of LA, had a tumultuous family life with numerous spouses and wasn’t around much for his kids, and after his 40s was trapped in a sad cycle of reunion tours because the band still needed the money. The tours still had some level of excitement and crowd enthusiasm, even pretty late in life and I guess he always loved the stage, the performing, all that. But in the end, I kinda felt it seemed like a lonely existence. Hard to form really deep connections when you’re always traveling and often away in your head.
You can include arbitrary HTML tags in Markdown at any place you need them.[0] I am not aware of any Markdown tooling that does not support this.
So, no, Markdown is not holding me back. It is perfectly capable of what the author claims it isn't.
[0]: https://daringfireball.net/projects/markdown/syntax#html
It’s a fun demo but they never go into buildings, the buildings all have similar size, the towns have similar layouts, there’s numerous visual inconsistencies, and the towns don’t really make sense. It generates stylistically similar boxes, puts them on a grid, and lets you wander the spaces between?
I know progress happens in incremental steps, but this seems like quite the baby step from other world gen demos unless I’m missing something.
Before anybody gets too excited, it's better to understand what exactly happened.
China ran an experimental reactor that achieved some conversion of thorium into uranium. More precisely, the conversion ratio was 0.1 [1]. This means that for each new fissile atom generated from thorium (i.e. uranium-233) 10 atoms have been burned from the original fissile inventory.
Now, conversion happens in every nuclear reactor. Some new fissile material (generally Pu-239) is generated out of "fertile material" (generally U-238). And, surprisingly, that conversion ratio is quite high: 0.6 for pressurized light water reactors and 0.8 for pressurized heavy water reactors [2].
What China has achieved therefore is well below what is business as usual in regular reactors. The only novelty is that the breeding used thorium, rather than uranium.
Is this useless? No, it is not. In principle increasing the conversion ratio from 0.1 to something higher than 1.0 should be doable. But then, going from 0.8 in heavy water reactors to more than 1.0 should be even easier. Why don't people do it already? Because the investment needed to do all the research is quite significant, and the profits that can be derived from that are quite uncertain and overall the risk adjusted return on investment is not justified. If you are a state, you can ignore that. If China continues the research in thorium breeding, and eventually an economically profitable thorium breeder reactor comes out of that, the entire world will benefit. But the best case scenario is that this would be three decades in the future.
[1] https://www.world-nuclear-news.org/articles/chinese-msr-achi...
[2] https://en.wikipedia.org/wiki/Breeder_reactor#Conversion_rat...
Some time ago I noticed that in Chrome, every time you click "Never translate $language", $language quietly gets added to the Accept-Language header that Chrome sends to every website!
My header ended up looking like a permuted version of this:
en-US,en;q=0.9,zh-CN;q=0.8,de;q=0.7,ja;q=0.6
I never manually configured any of those extra languages in the browser settings. All I had done was tell Chrome not to translate a few pages on some foreign news sites. Chrome then turned those one-off choices into persistent signals attached to every request.I'd be surprised if anyone in my vicinity share my exact combination of languages in that exact order, so this seems like a pretty strong fingerprinting vector.
There was even a proposal to reduce this surface area, but it wasn't adopted:
https://github.com/explainers-by-googlers/reduce-accept-lang...
I wish there was an actual thriving business model like this -- just fixing most annoying bugs, for a price, of commonly used desktop software. Why proprietary software companies cannot or do not want to provide this service is over me. Perhaps I'm too much used to consulting.
As the article said Duralex was the brand use by a large number of school cantinas in France. Inside of each glass there’s a small number used by the brand to identify the mold used for the creation of the glass. For kids that was a way to decide who is going to fetch the water for the table (smaller number or higher number of the table). That’s why the CE is holding his glass like that in the guardian article. Beside the nostalgia i think a lot of people support them because it’s a SCOP (the majority of the capital of the company is owned by the employees) [1] and it’s nice to see that another kind of company is possible.
[1] https://fr.wikipedia.org/wiki/Soci%C3%A9t%C3%A9_coop%C3%A9ra...
US actually provided child care to mothers employed during WWII. [0]
Richard Nixon vetoed the bill that would have expanded it out to all families. [1]
Funny how we keep forgetting the past and reject what benefited us as a whole with a moved to pure individualism built around selfishness. AKA The rich keep getting richer.
[0] https://www.wwiimemorialfriends.org/blog/the-lanham-act-and-...
[1] https://en.wikipedia.org/wiki/Comprehensive_Child_Developmen...
I've started a company in this space about 2 years ago. We are doing fine. What we've learned so far is that a lot of these techniques are simply optimisations to tackle some deficiency in LLMs that is a problem "today". These are not going to be problems tomorrow because the technology will shift. As it happened many time in the span of the last 2 years.
So yah, cool, caching all of that... but give it a couple of months and a better technique will come out - or more capable models.
Many years ago when disc encryption on AWS was not an option, my team and I had to spend 3 months to come up with a way to encrypt the discs and do so well because at the time there was no standard way. It was very difficult as that required pushing encrypted images (as far as I remember). Soon after we started, AWS introduced standard disc encryption that you can turn on by clicking a button. We wasted 3 months for nothing. We should have waited!
What I've learned from this is that often times it is better to do absolutely nothing.
When I studied chemistry at university, only a handful of select students were introduced to the nuclear science lab in the basement. It had a lot of spicy isotopes, neutron sources, etc. Even as a chemistry student with free run of the place for years I had no idea it was in the building until the department head pulled a few of us aside.
The reason for the informal secrecy, as it was explained to me, is that every so often someone would find out there was plutonium etc in the basement and have a public freak out, including on occasion other (non-STEM) professors at the same university. These people would try to organize crusades to get it shut down because evil. Intentionally obscuring its existence greatly mitigated this drama. They appreciated us continuing the tradition of keeping it out of sight and out of mind from the general public.
The publicity around this Kodak case was an example of why no one talks about nuclear labs. The public cannot be trusted to engage in a discussion about anything “nuclear” in good faith. There are quite a few areas of science like this.
I was diagnosed with ADD as a kid (before it was ADHD). People always describe the disorder as "lack of focus" but that's a really poor description for what I have.
I would say I have "hyper focus", to the point where if I'm working on something interesting, I will lose track of time and am unable to redirect my attention to anything else.
This makes me incredibly "spacey" as often my mind is still fixated on the task even long after I've stopped working on it. It also makes it very hard for me to accomplish any task I don't think are interesting...
And often a new idea will strike me like an epiphany that immediately takes the top spot of my attention.
The result is I have hundreds of half finished projects in flight across countless areas of interest.
He added: “This isn’t simply a blurb of words and phrases. This is not just a stock statement from an LLM.
This is a testament to outsourcing, laziness and the unexpected ways technology finds ways to change every press release.”
"He added: "This isn't simply a story about old paper and ink. This was never just about a collectible.
"This is a testament to memory, family and the unexpected ways the past finds its way back to us." """ Men going extreme in sentimental when they just sold a $9M collectible :).
Here are some reasons to start a personal blog:
1. It's a great way to learn. Teaching something to someone else has always been the best learning tool, and writing about something with an audience in mind is an effective way to capture some of that value.
2. It can be a big boost in job hunting. As a hiring manager two of the most important questions I have about a potential candidate are: Can they code? Can they communicate well? If a candidate has a blog with just two articles on it that hasn't been updated in five years that's still a big boost over candidates with nothing like that at all. In a competitive market that could be the boost you need to make it from the resume review to the first round.
3. If you blog more frequently than that it can be a really valuable resource for your future self. I love being able to look back on what I was thinking and writing about ten years ago. Having a good tagging system helps with this too - I can review my tag of "scaling" or "postgresql" and see a timeline of how my understanding developed.
4. It's a great way to help establish credibility. If someone asks you about X and you have a blog entry about X from five years ago you can point them to that.
5. Building a blog is really fun! It used to be one of the classic starter projects for new web developers, I think that needs to come back. It's a fun project and one that's great to keep on hacking on long into the future.
Notably none of the above reasons require your blog to attract readers! There's a ton of value to be had even if nobody actually reads the thing.
As a general rule, assume nobody will read your blog unless you actively encourage them to. That's fine. What matters isn't the quantity of readers, it's their quality. I'd rather have a piece read by just a single person that leads to a new opportunity for me than 1,000 people who read it and never interact with me ever again.
If you DO start to get readers things get even more valuable. I've been blogging since 2002 and most of the opportunities in my career came from people I met via blogging. Today I get invited to all sorts of interesting events because I have a prominent blog covering stuff relating to AI and LLMs.
But I do honestly think that a blog is a powerful professional tool even if nobody else is reading it at all.
If you want to give it a go I've written a few things that might be useful:
- What to blog about: https://simonwillison.net/2022/Nov/6/what-to-blog-about/ - Today I learned and write about your projects
- My approach to running a link blog - https://simonwillison.net/2024/Dec/22/link-blog/ - aka write about stuff you've found
"We are Arduino. We are open. We’re not going anywhere."
-- statement from Qualcomm without a single human being's name on it
Dram alternates between feast and famine; it's the nature of a business when the granularity of investment is so huge (you have a fab or you don't, and they cost billions -maybe trillions by now). So, it will swing back. Unfortunately it looks like maybe 3-5 years on average, from some analysis here: https://storagesearch.com/memory-boom-bust-cycles.html
(That's just me eyeballing it, feel free to do the math)
No, one study doesn’t upend the last few decades of understanding of emotional attachment.
The study simply says that ability to connect w friends is more predictive than observations they made of apparent attachment of parents.
This happens much later so of course it’s more predictive of the actual end effects - that’s when attachment styles actually show up for the first time. Kids grow up to be very adaptive toward their parents but when they get to the rest of society that’s when the failures of connection and the failed bids for attention show up.
A very resilient kid will do fine with friends even with a very bad attachment environment. A very sensitive kid or one with developmental problems will struggle in social environments.
I didn’t think I’d be so pro Waymo but anecdotally I had a fantastic experience with one recently.
I was at a music show very late ~1-2am in SF and walked out to grab an uber to the airbnb I was staying at. I kept getting assigned an uber, then I’d wait 10 minutes, then they’d cancel. Rinse and repeat for 30 minutes, mind you I even resorted to calling Lyfts at the same time and nothing bit. Then I say screw it and download Waymo. 1 minute and it’s accepted my ride, and I know it’s not going to cancel because it’s a robot. 3 minutes and it picks me up. The car is clean, quiet, I can play my own music in it via Spotify, and it’s driving honestly more safely than some uber drivers I’ve had in SF. It’s one of the few things where the end result actually lives up to the promise from a tech company.
This is what I say a lot. Valve isn't even remotely close to having clean hands here. They invented loot crates. Hats. Etc.
It's just that the bar is so INSANELY low - it's probably somewhere deep in the earth's core at this point - that valve looks like a fucking angel by being only VAGUELY greedy on occasion.
When your competition is EA... it's not hard.
I find it interesting that the question is "why don't they use drones". My question is: why so much air surveillance? I live in Germany. The only times I hear a helicopter is if someone is being rescued or if someones missing. I rarely see them at all.
> Much credit to Valve for pushing that out as FOSS.
Cynical: Valve doesn't sell hardware or operating systems, they sell games. These devices are merely another storefront.
Optimistic: Valve has also figured out how to turn good will into a commodity. Blowing cash on Steam sales is a bit of a cultural centerpiece of the PC gaming community.
Gabe has proven that you can make stupid amounts of money by [mostly] doing right by the consumer. I'm not sure if there's more to the secret source, her sauce, because we've yet to see another CEO pull their head out of their arse far enough to see how lucrative this approach can be: consumerism is fickle, fanaticism is loyal.
It is a weird form of centralized planning. Except there's no election to get on to the central committee, it's like in the Soviet era where you had to run in the right circles and have sway in them.
There's too much group-think in the executive class. Too much forced adoption of AI, too much bandwagon hopping.
The return-to-office fad is similar, a bunch of executives following the mandates of their board, all because there's a few CEOs who were REALLY worked up about it and there was a decision that workers had it too easy. Watching the executive class sacrifice profits for power is pretty fascinating.
Edit: A good way to decentralize the power and have better decision making would be to have less centralized rewards in the capital markets. Right now are living through a new gilded age with a few barons running things, because we have made the rewards too extreme and too narrowly distributed. Most market economics assumes that there's somewhat equal decision making power amongst the econs. We are quickly trending away from that.
I'm so mad about this, I need DDR5 for a new mini-PC I bought and prices have literally gone up by 2.5x..
128GB used to be 400$ in June, and now it's over $1,000 for the same 2x64GB set..
I have no idea if/when prices will come back down but it sucks.
All I can say is,
- the insane frothing hype behind AI is showing me a new kind of market failure - where resources can be massively misallocated just because some small class of individuals THINK or HOPE it will result in massive returns. Even if it squeezes out every single other sector that happens to want to use SDRAM to do things OTHER than buffer memory before it's fed into a PCIE lane for a GPU.
- I'm really REALLY glad i decided to buy brand new gaming laptops for my wife and I just a couple months ago, after not having upgraded our gaming laptops for 7 and 9 years respectively. It seems like gamers are going to have this the worst - GPUs have been f'd for a long time due to crypto and AI, and now even DRAM isn't safe. Plus SSD prices are going up too. And unlike many other DRAM users where it's a business thing and they can to some degree just hike prices to cover - gamers are obviously not running businesses. It's just making the hobby more expensive.
It's incredibly obvious that they're trying to make Steam Deck 2 ARM-based. That's the generational change Valve is waiting for.
This is gonna be fantastic.
I used to work at a YMCA, and the local homeschool group asked us to do a PE class, which I taught.
I had the kids doing swimming, rock climbing, and all kinds of traditional PE games.
I worked with "normal" kids most of the time, and I will say the homeschool kids stuck out. They're more awkward around kids their age, but far less awkward around adults. They know how to speak and act, in large part. And they were disproportionately ahead of their peers academically--though I think that's probably a selection bias for the parents seeking out homeschool PE classes.
This was in the early 2000s, before Facebook. I'm sure the avenues to connect have only grown with social media.
All of the pizza examples are about reducing cost. The argument about dating apps is about increasing retention. The dynamics are qualitatively different.
The argument with pizza is more like "people like salty, fatty food, so pizza places are incentivized to make their pizza less healthy so that people come back more often"... which is exactly what happens!
So why doesn't a legitimately healthy restaurant come along and take the whole market? It's partly because restaurants aren't just in the business of selling (healthy) food: it's also about convenience and satisfaction and experience. More importantly, that just doesn't fit with how people largely make day-to-day decisions.
The same thing happens with dating apps. People get drawn in for all sorts of reasons that don't necessarily map to getting married, even if finding a long-term relationship is explicitly their goal. Tinder competes with Tiktok more than it competes with other dating apps.
The other problem is that making a really effective dating app is just hard. It's fundamentally difficult to help people find compatible partners, especially without in-person contact. That's compounded by cultural and demographic issues. It doesn't matter how well your app is designed when there's a massive imbalance in genders!
I can't say my public school experience was great, I was bullied and didn't really click with the popular kids, but being around a cross section of actual American kids in my age group (my school district mixed middle class with lower class neighborhoods) helped me shape my worldview and learn to deal with people who didn't look or talk like me. I frequently saw fights, so I learned that you just stay away and watch your mouth around specific people. I learned that the BS American value of "popularity" doesn't translate into successful futures.
I worry this move to homeschooling and micromanaging children's social lives just creates bubbles and makes children incapable of interacting with those outside of them.
> This is a very difficult combination to achieve, and yet that’s exactly what we’ve done for Valve with Mesa3D Turnip, a FOSS Vulkan driver for Qualcomm Adreno GPUs.
Look at that. Something Qualcomm should have been doing.
Much credit to Valve for pushing that out as FOSS.
At my last job, we only updated dependencies when there was a compelling reason. It was awful.
What would happen from time to time was that an important reason did come up, but the team was now many releases behind. Whoever was unlucky enough to sign up for the project that needed the updated dependency now had to do all those updates of the dependency, including figuring out how they affected a bunch of software that they weren't otherwise going to work on. (e.g., for one code path, I need a bugfix that was shipped three years ago, but pulling that into my component affects many other code paths.) They now had to go figure out what would break, figure out how to test it, etc. Besides being awful for them, it creates bad incentives (don't sign up for those projects; put in hacks to avoid having to do the update), and it's also just plain bad for the business because it means almost any project, however simple it seems, might wind up running into this pit.
I now think of it this way: either you're on the dependency's release train or you jump off. If you're on the train, you may as well stay pretty up to date. It doesn't need to be every release the minute it comes out, but nor should it be "I'll skip months of work and several major releases until something important comes out". So if you decline to update to a particular release, you've got to ask: am I jumping off forever, or am I just deferring work? If you think you're just deferring the decision until you know if there's a release worth updating to, you're really rolling the dice.
(edit: The above experience was in Node.js. Every change in a dynamically typed language introduces a lot of risk. I'm now on a team that uses Rust, where knowing that the program compiles and passes all tests gives us a lot of confidence in the update. So although there's a lot of noise with regular dependency updates, it's not actually that much work.)
People in this thread are worried that they are significantly vulnerable if they don't update right away. However, this is mostly not an issue in practice. A lot of software doesn't have continuous deployment, but instead has customer-side deployment of new releases, which follow a slower rhythm of several weeks or months, barring emergencies. They are fine. Most vulnerabilities that aren't supply-chain attacks are only exploitable under special circumstances anyway. The thing to do is to monitor your dependencies and their published vulnerabilities, and for critical vulnerabilities to assess whether your product is affect by it. Only then do you need to update that specific dependency right away.
XBMC on the original Xbox was so unbelievably far ahead of it's time, it's crazy and that's not just nostalgia talking.