2,359 karma · joined March 31, 2020
But that's just me. Vote with your dollars; I've voted with mine.
The US has used one-way "drones" since the 80s or earlier. The entire Gulf War in the early 90s featured a ton of tomahawk cruise missiles. The only real change is that the new shaheeds are way cheaper, slower, and smaller, but can be spammed in larger numbers.
I love the confidence with which you give your answer though! Europeans famously underestimate the American West, which is why they often get into serious trouble (or die[1]) at alarming rates out here.
Not here to change your mind, but I'm "defending" SF because I've never experienced such a difference between the lived experience in a city and the online vitriol you see constantly about it. It's a true "don't believe your lying eyes" situation and it's honestly a bit disorienting.
I honestly disagree with this article - it seems to be conflating "economic activity" with extremely high-end real estate sales data in certain neighborhoods. The city feels much more alive in the past 12 months than it was previously, and there is a lot more energy and public events. If there's anything specific to complain about, it's that the AI boom has led to the 996+ crowd staying inside and not contributing much to the local scene, but honestly that's probably fine with everyone involved.
In the future, I could see this solved by the same "nuclear launch key" style delegation of keys. Aka in order to run certain API or database commands, the service requires both the standard dev key (presumably used by the LLM) and a separate "human admin key" that gets requested whenever a specific operation is requested. It could be tied to a biometric request or something as well to avoid the LLM hacking its way around it. Honestly this is pretty out of my technical depth but just thinking out-loud.
My broader point is that LLMs are going to need access to these keys whether we like it or not, and until we get extremely scoped API permissions (which would make a ton of sense, but most services aren't there), you have to live a bit on the edge to move quickly.
I think the better route is to be honest and say that database integrity is a primary foundation of the company, there's no task worth pursuing that would require touching the database, specifically ask it to think hard before doing anything that gets close to the production data, etc.
I run a much lower-stakes version where an LLM has a key that can delete a valuable product database if it were so inclined. I've built a strong framework around how and when destructive edits can be made (they cannot), but specifically I say that any of these destructive commands (DROP, -rm, etc) need to be handed to the user to implement. Between that framework and claude code via CLI, it's very cautious about running anything that writes to the database, and the new claude plan permissions system is pretty aggressive about reviewing any proposed action, even if I've given it blanket permission otherwise.
I've tested it a few times by telling it to go ahead, "I give you permission", but it still gets stopped by the global claude safety/permissions layer in opus 4.7. IMO it's pretty robust.
Food for thought.
The US had the atom bomb for a few years before anyone else had it. Anthropic has mythos now before anyone else - they are probably using it to churn out as many software clones as possible before someone else catches up.
You'd have to pay me to ride in a Tesla robotaxi. That tech isn't anywhere near the same as Waymo.