HNHacker News
TopNewBestAskShowJobs

SamInTheShell

236 karma · joined August 13, 2024

submissionscomments
SamInTheShell··on America.gov
And they changed the AI chat behavior again. We may know who our presidents are apparently again. Site seems pretty limited in what it can search up.
SamInTheShell··on America.gov
That's lovely, I have screenshots of different behavior this morning. They undid it. This is hilarious. I retried right now and it's saying Biden won the 2020 election again.
SamInTheShell··on America.gov
The harness was censored overnight as well. Can't ask it who won the 2020 election or who was the president in 2020 or 2000. It will say who is president right now though. Crazy shit really.
SamInTheShell··on America.gov
I agree with AI being useful for exactly the type of usecase you're thinking. Though I do want to point out a major flaw with trust in this specific harness. It got censored overnight.

Last night you could literally query and get factual information about election results; but today it wont even tell you who the president was in 2000.

There's a major censorship issue here.

SamInTheShell··on America.gov
Last night you can ask "Who won the 2020 election?" and it was like "I got you! It's Joe Biden".

Today it responds with "America does not provide campaign or party information."

The people on Reddit were right.

SamInTheShell··on Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions
Those are API things. Should be an API, build an MCP server for it. Doesn't touch the PC. About the automated responses, that's a write operation, therefore requires user consent.

If you want to design a system specifically to make sure you're not going to get stonewalled for sending me an emdash, you build and maintain a set of permissive rules for sending/reading to avoid my blacklist of people I'll never work with.

Once you got API stuff sorted, just throw a cronjob at it or build a service for that stuff.

^ There be prompts all over the place here, obviously. Realistically your MCP server will end up hacking on POP3.

SamInTheShell··on Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions
> that it still functions as a general purpose assistant

What features you want it to have? The thing you're saying is super vague, I would just say that one belongs in cloud.

If it must run things on the user's machine, it's gotta be in a rootless container and not be root inside the container. All tools belong in the container. Folder access explicitly configured by the user.

Like I already did this for my local AI: https://github.com/SamInTheShell/loom

It's not perfect or even done, but it works and it shows the security model that should be standard for aligned models we're running.

Unaligned models, absolutely different story.

Also VM is better than container for security, but containers are a bare minimum for me.

SamInTheShell··on Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions
The problem is trivial to solve. Treat AIs like they are users. We have user space for a reason. We have linux namespaces for a reason. We have real airgap architectures where the data center can't even connect out.

When you're a company running around with more than a few billion in the vault, you have no excuse for the level security negligence going on at every phase of rollout.

I gawked at Cursor executing a python script one time and decided enough was enough, I don't raw dog these tools anymore because their developers are the dumbest people to task with security work. They just don't care.

SamInTheShell··on Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions
These companies don't care. The technology exists, but the legislative stick just isn't there to incentivize these idiots to do the right things.
SamInTheShell··on Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions
It's already solved. I have two git repos proving these companies can fix the problems. The fact this continues just proves they don't care. In one project I literally containerize CLI coding tools, it works. You might say "sure, but network." I literally wrote a desktop app harness that you can toggle the network on/off too.

This is all amateur hour shenanigans.

SamInTheShell··on Go Concurrency Distilled
Still doesn't answer the question. In Java, allocate 8 gigs. Free 7 gigs. Why still 8 gigs? I didn't ask anything about if I could run a 1 gig process here.
SamInTheShell··on Go Concurrency Distilled
This is going to be interesting to check out. Thanks.
SamInTheShell··on MongoDB CEO resigns to join Meta
Migrate to yugabyte? It's a multi-raft fork of postgres.
SamInTheShell··on Go Concurrency Distilled
Never really thought about this but it seems to me that if you want to launch separate processes? Goroutines are built around functions, so you're just stuck with function semantics. If you want an entire process, you just invoke self with a feature flag on your binary and control a subprocess. If you need to communicate you establish your own message passing channels with STDIO or something.

I don't feel this is hacky or even a work around. Just different promises on what goroutines are vs threads/concurrency/processes in other languages.

Exit and panics are promised at the process level in Go.

SamInTheShell··on Go Concurrency Distilled
I don't have a use case where anything in my toolbox isn't already sufficient enough to solve, it wouldn't be worth while. Maybe if I cared to work at some big place or specifically Ericsson, but there's better things to be doing with my time. There's plenty of problems that can be solved with tools like uv/Python/PyWebView.
SamInTheShell··on Go Concurrency Distilled
The memory safety thing is just a moot out of scope contract. It seems moot to me every time someone shows up trying to push memory safety everywhere, that's a language to developer contract issue, not a functionality issue. When the contract of the language is such as that of Go vs Rust, the two languages are just offering different contracts. Rust just promises to hold your hand more than Go does.

Regarding the JVM and GC. Good luck with that? Every Java application I've seen in the wild when I supported JVM seemed to never release any ram it allocated. Ever. If it used 1G and even after free, the JVM decided that was going to be used again and wouldn't release it.

It would be hard to sell me on wanting to use Java again (people can pay me enough to do it, but I hate it). Which kinda sucks since Apache Foundation has a ton of really cool projects using it. Kotlin maybe, but I have no real use cases where it would be better than anything else I know right now.

SamInTheShell··on Go Concurrency Distilled
I gave an example. Go allocate 8 gigs. Then get it garbage collected. Why is JVM still allocating 8 gigs?
SamInTheShell··on Go Concurrency Distilled
To the concurrency/threading; no? (there might be an "it depends situation somewhere idk about)

But Go itself comes with it's own runtime built into the final binary. It doesn't work well in some use-cases, I mentioned some of the draw backs in a couple other comments if you want to dig those up.

Also I saw some of the other comments. Channels are ultimately just used for message passing and aren't that complicated. You also can use mutexes or some other locking pattern. There's some primitive atomic structures available that solve some use-cases preventing you from even have to having to really deal with working between goroutines.

SamInTheShell··on How to keep enjoying programming in a world of LLMs
Was happy to see someone forked Zed into "Gram". It was very disappointing to see every code editor go the route of being more than a code editor or even full IDE. I can literally just invoke a separate AI app to do code if I want that. I don't want to have to be actively conscious of every keystroke being shipped up to a backend to be processed. Sometimes I just need a dumb scratchpad to plop a password onto with other shared notes while I'm mid-task in an unsaved tab.
SamInTheShell··on How to keep enjoying programming in a world of LLMs
Idk, I could see some of my stats (like Claude usage) and I tried to avoid spending an unjustified amount of money.
SamInTheShell··on How I changed teaching after AI managed to do all my homework assignments
Why not just make the assignments "reading" based and set an expectation of randomized quizzes that take 5 minutes at the start of class to fill out to get the homework credit? When I say randomized, like multiple versions. You can use LLMs to churn out PDFs to a tailored format and utilize a pool of questions.
SamInTheShell··on Go Concurrency Distilled
I found Go memory issues easier to solve than Java issues. You can see an example with etcd used in Kubernetes. I had to enable performance profiling in etcd to identify why it was eating up all the memory. It led me to a specific partition of keys that tracked back to a specific object type in Kubernetes.

It was literally enabling a flag and running some commands to do some really quick exports.

Dealing with the JVM though, heap dumps are slow to process and the UI I had to download was very clunky. I don't know if there are better tools, but even if there are the path to just doing it isn't straight forward.

SamInTheShell··on Go Concurrency Distilled
I don't think you understand the threading concurrency topic. Also memory safety is so far off base here, where's that coming from? Java does some stuff okay, but do you really want to defend the horrid JVM problems? Also why can't I have my memory back when it's not in use in tightly packed systems?

It's not great for everything and neither is Go. You can find a bit more context on that in some of the other threads.

SamInTheShell··on Go Concurrency Distilled
Depends on what you're solving for. Message passing is fine. That's all channels does.
SamInTheShell··on Go Concurrency Distilled
I looked at BEAM about a year or so ago, similar conversation here. I don't think BEAM is the same when you start looking at what part of code is executing in which thread. There's tradeoffs depending on what you're solving for, like Go makes it really simple to distribute your work across threads concurrently, but when you start looking at integrating with stuff, you run into having to do tricks to do things with unshare (ref: docker/podman/containers...) and you haven't been able to integrate into libnss since they started using some "unused linux signal" for concurrency controls (PAM used that signal).
SamInTheShell··on Go Concurrency Distilled
The concurrency and threading in Go just feels like magic compared to every other language. I'm a goroutine addict and I refuse to be rehabilitated.

Just from observations over the years, I don't think there's any other language quite like this, in terms of how things can end up happening in any thread.

SamInTheShell··on Paul Graham on LLMs 'Thinking'
Poor choices are still poor choices. Words are very curious things with very infinite meanings, shifting between context. There’s probably something to be said about how we shape our languages and how ambiguity of meaning can prevent those who just don’t know from knowing. You know what I mean?

Sure maybe the English language is choosing to adopt the word “thinking” for what is going on here. Some people are choosing “reasoning”. It’s all the same to me though. The thought outputs aren’t any different that the final message for me, regardless of its shape.

I don’t have a better alternative, but I’m pretty sure this just makes people who aren’t in the industry dumber when they see it.

It doesn’t really matter. There’s no way the training loop necessary is sustainable and these things are a fad. How long? Idk. But language will change and there will be a day where using an LLM requires as much training as reading old religious texts. Got to learn more language.

SamInTheShell··on Paul Graham on LLMs 'Thinking'
I too sometimes wonder what gives these words power.
SamInTheShell··on Paul Graham on LLMs 'Thinking'
It’s still not thinking just because we call the reasoning texts “thoughts”. To imply otherwise in the direction of these models truly “thinking” is just a failure to understand the technology.
SamInTheShell··on Snorkel AI triples valuation to $3.5B as demand for AI training data booms
Seems finite in nature.
Page 1 of 7Next →