Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
snowmobile
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
snowmobile
9mo ago
You seem upset. I'm simply saying that if I didn't trust a human developer to run shell commands on the webserver (or the much lower bar of my own laptop), I woudn't trust them to push code that's supposed to run on that
32.
▲
by
snowmobile
9mo ago
Wait, so you don't trust the AI to execute code (shell commands) on your own computer, so therefore need a safety guardrail, in order to facilitate it writing code that you'll execute on your customers' computers (the financi
33.
▲
by
snowmobile
9mo ago
It's interesting to try. I picked six random reports from the hackerone page. Claude managed to accurately detect three "Resolved" reports as valid, two "Spam" as invalid, but failed on this one https://h
34.
▲
by
snowmobile
9mo ago
There are many incentives not to sell exploits, the major one being that it's not logistically feasible. First of all the people submitting these false reports don't have any real exploits. But imagine you were sitting on an actua
35.
▲
by
snowmobile
9mo ago
That's a story that people like to tell to justify bug bounty programs, but it strikes me as very unlikely that some random pentester / white-hat hacker would have access to communication with malware producers. Black-hat hackers
36.
▲
by
snowmobile
9mo ago
How exactly would that work? Curl isn't exactly software that can be "hosted" somewhere, and I'm not sure where you'd hide the flag in the software? Either very few actual vulns would end up being able to retrieve t
37.
▲
by
snowmobile
9mo ago
"In other words" means paraphrasing, not simply changing the words to something completely different.
38.
▲
by
snowmobile
9mo ago
> It's not uncommon to get invites from people you've never met offline and were just in a game you played together. What? Why does this imply that they're "abusive" or that they'd want to spend effort tryin
39.
▲
by
snowmobile
9mo ago
No, that is obviously not logical. A feature can be nice-to-have for most people, while still not needing to be perfectly secure against all sorts of far-fetched scenarios. If you want to guess how most of the userbase would react, just ima
40.
▲
by
snowmobile
9mo ago
It's different in the sense that LLMs are unpredictable and if you let them take arbitrary actions you don't know what's gonna happen, unlike any other program. A random generator doesn't "want" anything but pu
41.
▲
by
snowmobile
9mo ago
How can you trust the AI to write (working) code if you can't even trust it to run commands on your dev machine?
42.
▲
by
snowmobile
9mo ago
I think it's a quite small demographic that have abusive friends on Steam that they can't simply unfriend for whatever reason, and it's not a reasonable expectation on Steam to design for that case. It'd be like a pencil
43.
▲
by
snowmobile
9mo ago
I consider myself a fairly good developer, and I think that's in large part due to knowing, "doing this should be possible, and the reason it's not working right now is just due to stupidity (my own or the developer of whatev
44.
▲
by
snowmobile
9mo ago
I suppose that returns some guardrail text about how it's not allowed to talk about it? Meanwhile we see examples of it accidentally deleting files, writing insecure code and whatnot. I'm more worried about a supposedly "well
45.
▲
by
snowmobile
9mo ago
Sure, it's certainly closer to a browser than a virus. But it's pretty far from a human and comparing it to one is dangerous in my opinion. Maybe it's similar to a dog. Not in the sense of moral value, but rather an entity (o
46.
▲
by
snowmobile
9mo ago
Sure, and right now they aren't very capable, so it's fine. But I'm interested in the mindset going forward. I've read a few stories about people handling radioactive materials at home, they usually explain the precautio
47.
▲
by
snowmobile
9mo ago
Sure, current agents are harmless, but that's due to their low capability, not due to their alignment with human goals. Can you explain why you'd view them as more similar to humans than to computer viruses?
48.
▲
by
snowmobile
9mo ago
An AI has no concept of human life nor any morals. Sure, it may "act" like it, but trying to reason about its "motivations" is like reasoning about the motivations of smallpox. Humans want to make money, but most people
49.
▲
by
snowmobile
9mo ago
Bit of a wider discussion, but how do you all feel about the fact that you're letting a program use your computer to do whatever it wants without you knowing? I know right now LLMs aren't overly capable, but if you'd apply th
50.
▲
by
snowmobile
9mo ago
How's using a custom library any way close to "standard"? How about the actual HTML standards? The whole reason you'd use "shadcn" is that customizing the actual HTML radio button isn't enough for you. Oth
51.
▲
by
snowmobile
9mo ago
> it's clear from research that users prefer custom buttons if they provide more "features" than the defaults. Hate to be asking for a "source", but what research? And what "features" can a radio button
52.
▲
by
snowmobile
9mo ago
There's literally an example of that in the post. > where you don’t hide the native appearance What do you mean by this? Seems like an arbitrary requirement to set. Could you show an actual example of how this overengineered style i
53.
▲
by
snowmobile
9mo ago
"There are reasons" is a pretty bland defense of why something was done in a bad way. You'd have to show that the reasons are valid, which I highly doubt. Also, somebody spending thousands of hours on making a worse version o
54.
▲
by
snowmobile
9mo ago
Not really, for the same reason entrapment isn't usually seen as an accurate way to gather information for law enforcement. See also Goodhart's law and overfitting.
55.
▲
by
snowmobile
9mo ago
Perhaps you're right but I won't believe you until you whip up a live-rendering proof of concept. It's a bit rude to dismiss somebody's cool work as "painful", with some hypothetical "improvements" th
56.
▲
by
snowmobile
9mo ago
I mean, a lot of code is written using the NPM ecosystem, that doesn't make it good though. There are tons of objectively bad things that are popular. "Tracking personal data on webpages is already becoming the primary way of adve
57.
▲
by
snowmobile
9mo ago
> We’ve all collectively figured out what sustainable AI-assisted development looks like, and it turns out to be more structured than those early vibes. Is this satire of AI hype? Genuinely can't tell if he's being serious.
58.
▲
by
snowmobile
9mo ago
Seems like you're using your computer wrong by posting here then. In fact, 99% of people are using their computing devices wrong all the time. The computer must be the most misused tool in the world.
59.
▲
by
snowmobile
9mo ago
That's exactly what I mean though. If you miss the target with your rifle, would you call that "bullet not working"?
60.
▲
by
snowmobile
9mo ago
I suppose Cursor forgot to tell their AI that, before claiming that it built everything "from-scratch"
More ›