HNHacker News
TopNewBestAskShowJobs

bjackman

4,994 karma · joined May 25, 2013

[ my public key: https://keybase.io/bjackman; my proof: https://keybase.io/bjackman/sigs/VqJOkkjZ3NpAA_GO1V1yRLqqvoDbwJu0bLFsLxgdj8c ]
submissionscomments
bjackman··on The bottleneck might be the air in the room
And I believe the accuracy is also not great on these cheap ones. The product in the OP's photo costs $200 where I live! And ISTR finding the sensor itself contributes a lot to this cost.

IIUC they also need fans. The one I have in my home has one that's actually integrated into the sensor unit.

bjackman··on Immich 3.0
Ah yeah I see. I guess the fallback there would be to split the service up into a remote encrypted storage layer that goes on the VPS and then host the actual service (with the decryption keys) locally?

But ISTR reading Immich kinda assumes the storage is on a plain local filesystem so you get perf issues if you do something clever under its feet. Could be out of date on that.

bjackman··on Immich 3.0
I really don't think you want E2EE for this. I host storage for family and friends, I haven't set Immich up yet (don't think I'd have space for everyone's photos) but the choice is between:

1. "Hey just so you know, I have access to everything you upload here".

2. "Do NOT lose your password or your data will be GONE FOREVER and I CANNOT get it back".

I definitely prefer 1 and I'm sure my users do too. They shouldn't upload it if they didn't trust me anyway.

In my case I follow it up with "and I might actually go digging around in your files if I need to debug something or you're wasting disk space". But I think you could also follow it up with "but I do promise not to look" and that would be valid too.

This whole thing only makes sense for people you're pretty close to.

(I do tell people not to back up their password managers on my system though).

I guess maybe for Immich specifically it would be nice to have a "vault" feature where people can upload nudes etc where they are willing to trade risk of loss for privacy on a per-photo basis.

bjackman··on Professor denounces mass AI fraud on an exam at Brown
No? Some subsets of the world has papyrus I guess but for most people during most of that time people were pressing text into clay and wax and stuff, it must have fucking sucked.

Then we got paper and pens and that was a pretty decent interim for a short period. Then about 100 years ago we got typing. Then about 20 years ago we reached a world where almost everyone is better at typing than they are at writing.

Obviously it's still important that people can write by hand, but expecting people to do it for more than a few hundred words at a time is idiotic. Would you like your clothes to be hand sewn too? That also worked for thousands of years (much longer than writing) but we stopped doing it for a very good reason.

bjackman··on Professor denounces mass AI fraud on an exam at Brown
Horse carts are literally designed to transport people but they aren't very good at it compared to cars
bjackman··on Professor denounces mass AI fraud on an exam at Brown
Well, how many times in that 9 years have you written on paper for 2 hours straight? Even as a kid who did it regularly, it sucked.

Doing it now I really don't think I could deliver my intellectual best while worrying about if anyone can read my handwriting and whether I'm gonna cramp up by the end of the exam.

Pen and paper is just not a very good way to produce text.

bjackman··on Professor denounces mass AI fraud on an exam at Brown
... Including a university. Literally everywhere you work as a student is serenaded by keyboard sounds.
bjackman··on PR spam today looks like email spam in the early 2000s
As a $BIGCORP member I don't think this would be a great solution. I suspect there are plenty of vibe coding PR spammers that work for my company. And the admins of the GitHub org would not really care, making it easy for staff to contribute to third party projects is nowhere near their top priority (and policing the behaviour of their org members outside of org-owned repos is not in their mandate even if they wanted to).
bjackman··on Polymarket has flooded social media with deceptive videos by paid creators
You are not evaluating those questions, you are evaluating the probability of that two things happening, and you need to evaluate it better than the other people to win.

There are no easy questions, the difficulty is set by the skill/investment level of your competition.

bjackman··on John Jumper to join Anthropic
Nothing major just a few little details:

- the /artifact thing is quite useful (don't think CC has it?)

- the /tasks is a bit better than CC's equivalent

- there are a few built-in skills that I haven't found CC equivalents for in the built in set (but the fact that I haven't sought out 3rd party versions shows you they aren't very important).

And more generally it does a better job of making the agent available. When Claude is debugging something complex and running a bunch of experiments it's often unavailable for like 20 minutes at a time, you only have /btw. Whereas AGY tends to more aggressively use timers and background jobs.

But now I wrote that out, I realised it's probably just as much of a system prompt thing as a harness design thing. Coz Claude _can_ operate that way too.

Anyway, like I said none of these come anywhere near balancing out the model quality gap.

bjackman··on VPN ban update for UK households as government looks at 'age-gate'
I'm a Brit living abroad, when I visit the UK I use a Tailscale network with an exit node at my home, and yeah this always seems to work for me.

Going the other way around to try and watch British TV I used to find with a normal hosted VPN services could still figure out I wasn't in the country, but now I have a Tailscale exit node at my mum's place in the UK it always works fine.

So I suspect it all comes down to the IP source, probably a residential IP is the best possible case and with commercial VPNs it depends on how hard they work on isolating their IP blocks from known datacentres.

bjackman··on Ask HN: Will programmers write more efficient code during the memory shortage?
You don't save memory with code, you save it with architecture, platform decisions, and feedback loops.

Feedback loops are the important bit. If you want to reduce your service's memory footprint, don't at the code look at the memory profile and monitoring. You will find something like "oh shit 30% of our RAM is used by these buffers that we could basically eliminate if we tweak the flush frequency".

If you automate/regularise those investigations you will get an efficient service.

Same is true of every other performance metric, and reliability. It comes from your engineering processes (alerts, qualification, prod experimentation) not "write better code".

bjackman··on Hyundai buys Boston Dynamics
For my personal use, I really fucking want a humanoid robot, coz my home and all the bullshit in it was built for humanoids, I want a robot to do the bullshit for me. I don't want to move into a new, robot-oriented home.

I've never been to a factory but I bet there's a lot of the same bullshit. Ditto in a mine.

On the other hand, I've been in a datacentre. I don't see much need for a humanoid form in there, everything is flat and predictable. Why don't we have robot DC techs? This is probably an interesting clue re the next 10 years of robotics and maybe the reason Boston Dynamics is only valued at $1.1B.

Seems we might still be pretty limited on usecases. Maybe a dexterity bottleneck.

bjackman··on John Jumper to join Anthropic
This is weird coz as a user of both Gemini and Claude I have the opposite feeling.

Antigravity CLI is quite decent, it's a huge step up from Gemini CLI (like, for example, it actually fucking works) and has some genuine advantages over Claude Code. Does Codex have something over both of them? I haven't tried it.

But the model just fucking sucks. Before I switched to Claude for personal stuff a few weeks ago, I was like "damn model capabilities are really slowing down" but no, it's just Gemini that's slowing down.

Will have to see if 3.5 Pro is any good when that comes out. But it feels like they would be attempting to catch up to Opus, not to Fable.

FWIW issue is never really about the code it writes it's about general intelligence. Gemini hallucinates like it's 2024, fails to follow instructions, and goes down wildly wrong debugging paths. Opus just gets the job done, first time, every time. With Gemini it feels like "I _am_ glad this intern is working for me but I'm tired of babysitting him" and with Claude it's like "this new PhD guy can replace me soon".

bjackman··on Volkswagen started blocking GrapheneOS users
The "driving" tech I want in my car is:

- Cruise control.

- Camera for parking. I guess sensors too. These are just unbelievaly useful IMO, it makes parking trivial in cases that used to require quite intense focus. I see the appeal of fully automated parking, but with cameras and a car that you have lots of experience parking I think I am fine Austin-Powers-ing into any space that the car physically fits into.

- I guess, maybe, I kinda like the thing where it automatically watches your blindspot and has a little orange light to remind you that there's a car there.

I dunno, when did cars get all that stuff? (Cruise control was basically universal in the US before I was even born I think, but not sure when the others showed up).

But then there's some non-driving tech that I do want:

- Completely frictionless navigation and media control. Android Auto just seems to be fucking nonfunctional so I think maybe what I want here is actually just a Qi mount and a reliable bluetooth controller?

- I've never had it but I bet remote climate control is really nice (warm up the wheel 5 mins before you set off on a frozen morning / turn on the AC 2 mins before you get into a car that you couldn't park in the shade).

bjackman··on Volkswagen started blocking GrapheneOS users
I have no plans to buy a car but I'm curious: what is the sensible choice for technical people with a reasonable amount of money?

I rent cars whenever I travel to the US and I've never not been pissed off by a car's software.

If you live in a country that makes it practica/affordable and you don't need too much range, I wonder if buying an old car with a broken engine and paying someone to do an electric conversion is a good choice?

Or maybe generally just buy a ~10 year old car, find a mechanic and say "I want this car to last a really long time, if we can build a trust relationship I will spend a lot of money in your business" and just budget for extensive proactive maintenance? Maybe with this approach you can still save money relative to a new car?

Or, is it possible to buy a newish car and then just rip out and completely replace the infotainment/climate control/etc while still keeping stuff like the parking cameras working?

bjackman··on US holds off blacklisting DeepSeek, more than 100 firms deemed security risks
Hosting DeepSeek Pro yourself is gonna be wildly expensive though?

You have a wide choice of providers available, so if you can find one you trust you can get inference without data harvesting and it's still very cheap. But dedicated HW is insanely inefficient.

Opus estimates you can do it for $13k/month if you get committed pricing on the HW.

bjackman··on Running local models is good now
Re being away from the HW: with Tailscale and llama-server it's now super easy to just run an inference server at home and use it from wherever you are.
bjackman··on The EU Open Source Strategy
It's a good technical artifact yeah but it would need to be forked and degoogled, today it is only really useful with Google services as a backend.

Also it's coupled to the device ecosystem which is organised by Google. This coupling with the HW is one of its major technical strengths though, including for the security things I'm yapping about.

So yeah I think the two options for a EuroOS are:

- Fork and degoogle ChromiumOS/AOSP

- Invest in a Silverblue/bootc/Flatpak style system and just keep filling the gaps there

Hard to say which would be the better option. Both require at least tens of millions in investment over 5+ years.

bjackman··on The EU Open Source Strategy
SELinux is a framework not a solution. Main places that gap is closed are Android and ChromeOS, not normal distros.

MacOS has:

- Serious integrity story

- Actual kernel hardening

- No reams and reams of garbage in their kernel (wouldn't have equivalents to the recent AF_ALG vulns coz they don't have dumb stuff like AF_ALG).

- Filesystem security boundaries retrofitted onto the Unix model (interesting user data, browser creds etc are gated by special permissions that are tied to the application build, backed by the integrity story - a `curl | bash` command cannot dump your ~/Documents)

When people escalate privileges on MacOS it's news, when they do it on Linux it's Tuesday (you might think the recent spate of privesc vulns on Linux was unusual but that is totally normal).

I say this as someone who works on Linux security every day (I am a kernel developer) and uses Linux on every computer I have, both at work and at home, BTW. I am not a Linux hater or Apple fanboy by any means.

These are all solvable problems at EU scale too. Just, I think they should solve other problems first in the priority list of delivering sovereign IT.

bjackman··on The EU Open Source Strategy
I worked at Google on post-Aurora endpoints security. Windows laptops are alive and well at Google. Linux laptops have had one foot in the grave for a while now (it's a bummer). Google historically made gLinux work only with enormous investments in customised distros and D&R.

> But maybe you could elaborate a bit more concretely about what kind of intra-host security boundaries are missing

- no boundaries between applications, everything runs as $USER which can read your browser creds

- no boundary between user and root, everything can trivially escalate privs (maybe we will fix this post Glasswing, let's see)

- no boundary between boots, root can trivially persist a compromise (probably non-root too)

The tech exists to solve all these problems on Linux, but there isn't a distro that strings it all together. (Unless you count ChromeOS/Android which are not really OSS).

bjackman··on The EU Open Source Strategy
> Genuinely interested: does it bring something to say "everything is crap anyway, but given that we must choose between one of them, we may as well choose the least bad" instead of "the best solution we currently have is X"

Well I dunno if that's true, that's why I didn't say it. Linux _may_ be the best solution overall I am not sure. It is definitely not the best solution from a security perspective.

> Secondly, are you sure that it is impossible to secure a system for a whole department? I have seen relatively big companies having an IT team managing their own Linux flavour. That is, whitelisting the packages that can be installed by the users.

Just whitelisting packages isn't enough. ChromeOS effectively does this and their whitelist is extremely small, yet they are still only ok with that because they backed it up with the rest of the pieces needed to make a secure Linux desktop, including a fully vertically integrated stack.

bjackman··on The EU Open Source Strategy
Sovereignty yes it's obviously better.

I am just talking about the pure tech fact that GNU/Linux desktops do not have any meaningful intra-host security boundaries.

Is this a worthwhile tradeoff against being tied to US tech? Yeah maybe, like I said there are no good options here, and Linux might be the least bad.

bjackman··on The EU Open Source Strategy
It's not alien tech but it's a basic fact that only the US has it right now.

Yes we could build a serious distro with a massive investment to get Flatpak, systemd, bootc, up to scratch, set up OSS endpoint management software, set up a safe package supply chain, etc. And yes I would love to see it. But I think in the short term the money would be better spent replacing crap like Outlook and OneDrive than Windows. Note this doesn't require building much software it's about figuring out how to run infrastructure in a way that's friendly to the bizarre world of public sector organisations.

Maybe Dunning-Kruger but the latter just seem like much easier problems to solve.

Also totally pointless until we have an OSS web browser that the whole sector can adopt (maybe we already do, but any funding gaps for Firefox should still be addressed before we build our own EuroOS). No point in having a wonderful sovereign OS that just serves as a bootloader for Chrome.

bjackman··on The EU Open Source Strategy
I do not think I want my public sector running GNU/Linux desktops. There is no distro that meets the security requirements.

I don't know if Windows is better, I have heard rumours that it's pretty bad.

I know MacOS is MUCH better from a security PoV but I definitely don't want my public sector shelling out to Apple and I don't think it meets the boring IT management requirements anyway (I think big tech has a lot of crazy workarounds to make their MacBook fleets workable).

So yeah overall no good options here. I would love to see the EU fund development of a better distro for this usecase, but doubt it's the highest ROI thing you can do in this space.

bjackman··on Ask HN: What was your "oh shit" moment with GenAI?
My "I saw this very early" claim deserves some skepticism, but...

Don't y'all remember GPT2? When they published that AI-generated unicorns-in-the-Andes article, my jaw was on the floor. I remember very clearly thinking "oh, history is now divided into the time before this moment and the time after it".

There's been a long series of "oh holy shit this is USEFUL NOW" moments in the last 2 years but none of them compare to that first moment. The day before, I didn't know if real AI was possible. Then one day it was suddenly clear that it was. And if you'd been thinking about AI at all it was obvious that if the technology was at all possible, it was gonna be a really fucking big deal sooner or later.

bjackman··on Pre-Modern Armies for Worldbuilders, Part I: Why They Fight
I think Conway's law is more interesting. It seems natural that networks of human relationships would mirror each other when the same groups of humans translate themselves into a new context.

Whereas the structure of technological products is a "different thing" than the human relationships that created it, it's less obvious that it would translate across that boundary.

bjackman··on Uber's $1,500/month AI limit is a useful signal for AI tool pricing
As well as rational vs irrational they are also just different types of spending.

Hiring someone vs paying a vendor for a service:

- different level of commitment

- might tie your org to a physical location

- different legal risks

- shows investors a different picture (probably this would even influence a bank loan)

- manager has to fight a different bureaucracy

Not to mention that comparing the cost of a hire by looking at their salary is pretty dumb. ISTR hearing at Google that the overall estimated cost of employing a SWE is like 4X their compensation? Can't remember the exact figures though.

bjackman··on Claude Opus 4.8
Ultimately I think the only way you can trust benchmarks is if you build them yourself and keep them secret from the AI labs.

There are different levels of "cheating" on benchmarks. The worst would be just literally putting them in the loss function during RL, I assume the major labs are not cheating at that level. And I am sure they are making a genuine effort to keep the benchmark content out of the training data.

But, ultimately it seems implausible that they completely abstain from benchmarking their model until they are about to release it. Even if they did do that, the benchmark is still ultimately a part of the outermost feedback loop. So these models are all, to _some_ degree, benchmark-solving machines.

I think all we can really do is live with the model for a while and develop a subjective feeling about its quality. This shouldn't be surprising, nobody believes that coding interviews work, we all know that you just have to work with someone to figure out if they're a good programmer. As AIs become more human like it's natural they should get harder to evaluate.

This is a bit awkward, it puts us in quite a weak position as consumers.

Maybe to some extent you can get a meaningful signal from sentiments on HN etc, but:

- There must be some amount of manipulation going on of this

- Even if it was fully organic, it's highly likely that your experience will differ materially from the median online nerd, because AIs are bizarre things that respond in unpredictable ways to intangible things.

bjackman··on Show HN: Write your BPF programs in Go, not C
Yeah I actually advocate for dropping to assembly quite a lot in BPF:

- portability isn't a concern

- BPF ASM syntax is quite readable

- it can often let you write simpler code by directly doing what the verifier needs instead of dancing around trying to make Clang do it for you.

I think the most exciting alternative BPF language would be one where the compiler interacts with the verifier. E.g. if the program included a logical proof of correctness that the verifier could check more efficiently than its limited builtin analysis.

← PreviousPage 3 of 32Next →