Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there evidence of any state-sponsored bots at all? It seems like this has become an accepted fact but I don’t see any data indicating it’s actually real.

No one mentioning Gore Vidal (or Truman Capote)... so sad


No, they’re talking about LLMs - they’re a different technology from search engines.

ShinyHunters has been "in business" since 2019 and it is their reputation that resulted in eg. Canvas paying their ransom this year. Without that reputation, it is unlikely a large-scale ransom would have been paid, because the reputation is what gives them credibility that paying the ransom will actually result in the promise being upheld.

“…who had worked on well-being and safety issues for Meta” Never saw that one coming.

Super cool! This direction of things felt obvious the moment ChatGPT w/ Vision came out.

If gas was free for EU, we'd still pay more than US for it, by the sheer amount of taxes. 25-30% of current price is gas cost itself, raw cost, the rest is taxes.

So if EU somehow magically got the same amount of gas for 100% free, we'd at most pay some 25% less than we do now, and it would still be more expensive than US.


You really put a lot of trust in countries that are rules by oligarchs and where a far-right is rising to power...

Conversely, most of the high impact bugs are also written in C and C++, because they rely on "coding style and engineering practice" to be correct. Rust raises the floor on this by a lot.

I use nono.sh for sandboxing -- I think a lot of power users are using sandbox + YOLO mode because approval prompts slow them down

yes it's bad if the permission system is broken, but serious users have not trusted this stuff for a while, find the built-in permissions layer burdensome, and are already using a safety layer somewhere else


The problem with super smart people is that they often succeed without having to or bothering to understand even the most basic common sense techinques.

I had a friend who told me a story, that when he was a kid, he found a copy of the Borland Pascal DOS compiler on his dad's machine. It came with a demo demonstrating the graphics library, but that was the extent of his introduction to Pascal, most of the syntax he figured out by trial and error.

He went ahead and build a quite elaborate tank game, with things like enemy AI, multiple weapons and destructible terrain.

The code was a fever dream, but the game was pretty impressive, and enjoyable.

One of the things he didn't intuit, was that you could not only use built in functions, but define your own. So when he needed a code block a second time, he just copied it, so you can imagine how pleasant that code looked.


This is a good summary of the dangers of using agentic clis, but the title & general focus on opencode is odd for two reasons:

1. Most obviously & importantly this is a complaint without a straightforward suggested alternative. A sibling commenter mentions suggesting fixes to Opencode would be more productive: I don't necessarily agree since many of these issues are fundamental & would likely require an almost ground up rethink & rewrite, but the issue is that the article contains no constructive proposal at all: it may as well be titled "Stop Using LLMs"

2. None of the major issues listed are unique to OpenCode. At least the full list within the "Alarming Things" seems in my mind to apply to Claude CLI, & I would guess most other agents from frontier model providers.

Granted it's worthwhile documenting these issues as a plea for someone to build better tooling from the ground up, so the article is far from worthless - on the contrary I've bookmarked it & will be sharing & referencing it widely & often. But the title & focus is just very odd & seems misguided, especially when the contents of the piece is otherwise so good.


super useful!

Sheol got turned into Hades, then Christianity mashed it together with Gehenna to create "Hell".

You mean except the bugs in the zig version and any future CVEs?

For very small companies (startups) AWS makes a lot of sense because you have very few employees and you don’t want that limited employee time being spent managing servers

My parents got $7000 when the state wanted to shave their hill for better visibility around a road curve. They lost a pretty cherry tree.

I made this because I wish it were a built‑in feature.

Flight Control HD was one of the first iPad games I had. I under-appreciated how much easier this game was with a finger than a trackball.

You don't seem to understand what I'm talking about.

bad axiom -> worthless theorem.

bad unsafe section -> verified safe section is actually not safe.


why was this, some event?

perhaps if the boot were Rust it would crumble in the face of Bare Metal

Sovereignty has gone from being a theoretical concern that a lot of cloud (esp. AWS) advocates poo-poohed to something that is a very real concern in the minds of many. It's not just US foreign policy either. It's even within Europe--to say nothing of things related to China.

You missed a fourth option: renounce your European citizenship

There are a number of points I completely agree with in this blog post. Security implications, handing out all your data to anthropic/openai/google, allowing a slop machine to execute arbitrary code on your machine and having full access to your network is something that would have made anyone working in security commit a ritual suicide just thinking about it as recent as 2022-2023. And I am baffled by the fact that we all sign tons of NDA's as part of our employment contracts, just to throw all out the window by giving it all away to anthropic/openai/google etc, at what is effectively a symbolic fee. We all know it costs a lot more than 100 bucks a month or whatever it is they charge.

That said, I firmly believe that if AI is to survive, the future HAS TO BE local or near-local. Having said that, statements such as

> Docker causes security holes:

> It creates a god-service that runs as root.

> It deliberately punches a hole in ufw firewalls.

Sorry, none of those are correct IF you know what you are doing. Though I will admit, seeing people that know what they are doing is increasingly uncommon.

Also there is nothing wrong with developing inside containers. If anything, that is arguably one of the biggest selling points for containers - environment(s) you can crash infinitely at no cost.

I still dislike opencode for a bunch of reasons - the assumption that llms are immune to screw ups, being one. As for the default behavior - using cloud by default - I didn't know that(I do not use any AI for direct coding tasks) and if that is the case, yeah, this is bad. Undeniably a horrible decision.


I want to agree with this. My fear is that governments and corporations love using technology to launder evil shit. Once security is automated, entire groups of people can be quickly and effortlessly disenfranchised by flipping a bool on a server somewhere. No appeal, no recourse, no human faces. You get to find out from some LLM that you aren't allowed in the country anymore because the "algorithm" identitifed you as a risk. uwu so sawd

It only works if the "intellence-driven security" is being developed in good faith.


This is one of the reasons I only use Codex Cloud. Although it seems they've been nerfing it this week with strict "execution windows" on each task that weren't there before.

Related discussion about the DELETE Act in January:

https://news.ycombinator.com/item?id=46449694


Not a US citizen. But yeah, Germany does quit a lot of shit these days as well and will be doing even more, once we get our far right government after the next election. Will be the day I set my bug out plan in motion.

Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: