306 karma · joined February 10, 2012
How often do you listen to a song and think of these stories in your head? When you listen to the Beatles are you seeing Paul McCartney singing? I think for many people the answer is yes. These things (the story and the music itself) become connected and the story provides the context within which many people enjoy the music.
I'll admit this is a bit disappointing. I'd like to think that any piece could stand up on its on merits without some lore being required to appreciate it. But I have relented to the idea that this is just a very human thing. We do it with everything as it's just the way most of us are wired.
I'm happy to use and support Chinese model developers if it means less censorship and gatekeeping. I have absolutely no dog in this fight, and neither do most American developers. We will use whatever is cheaper and better. Game on.
{
"permissions": {
"allow": [
"Read(**/*.rs)",
"Edit(**/*.rs)",
"Write(**/*.rs)"
],
"deny": [
"Bash",
"PowerShell"
]
}
}In this case, it's difficult for me to see what exactly is gained by offloading all of those decisions to a mean regression algorithm. I agree it's a fun toy, but I can't imagine actually listening to or deeply enjoying any song made with these music models.
I could imagine it being used successfully in some targeted part of the process. For example, manipulating drums or changing the timbre of some previously recorded instrument. In that case it's not much different than traditional music creation tools like sampling.
While I understand the risks that Anthropic is dealing with here, I really question whether shutting down any and all security questions in such a paranoid fashion is the right solution. At the end of the day this was a detour for me. Maybe someone special enough to have Anthropic's permission will find and disclose the vuln responsibly. Security Research is not my full-time focus. But this left a nasty taste in my mouth. Not just as a customer who's been paying for Max since launch, but there's something very odd about a model telling me that I'm not allowed to be curious about something. Even if that something is a process running on my own computer.
This is why when cyberthreat actors steal millions in USD stablecoins by hacking a protocol or a large wallet, the very first thing they do is convert those stablecoins to something else.
I would recommend it only if this type of thing naturally interests you. I can't imagine powering through the initial learning curve if it felt like a frustrating chore.
That said, if having (most of) your machine defined declaratively in a git repository sounds exciting/useful/comfy, then I would encourage you to give it a try. You can start small by just configuring a few programs or options and see how you like it.
I wrote more about my experience here where I also link to my configs: https://bryce.is/writing/code/fully-nix-pilled
Put aside the bit rot that occurs constantly with digital project files in a way it never did with tape, just getting my DAW, plugins, samples, projects working has been a giant pain. I am a big fan of deterministic/reproducible computing environments in general. My primary machine is setup declaratively with Nix. It would be great if something like this existed for my music setup without having to compromise on creative choices.
Most of these plugins are of dubious software quality, but that is not mutually exclusive with their ability to accomplish great sounding results. One of the reasons I bought a dedicated machine for music is that I inherently don't really trust them to be running on the same device as my personal computing. Some of them (Universal Audio Apollo) even require kernel extensions on MacOS.
If anyone is attempting to solve this, I'd like to hear about it.
For all of the security suggestions in this article I was also surprised to see the author recommending ungoogle-chromium, which has a number of security issues. See: https://qua3k.github.io/ungoogled/
The primary issue I take with the article is the chosen tone. I think there are ways that these points could have been made without being overly cynical and negative. I think speaking authoritatively throughout the article has the effect of equating the importance of subjective preferences (like the choice of which terminal emulator to include), with legitimate security concerns (bash shortcomings, migrations, firewall misconfiguration, piping curl | sh to install software).
I wouldn't use Omarchy, but I am glad it exists. It's bringing more people into the desktop Linux ecosystem, which should be positive sum. Omarchy comes off to me as a little hacky and immature, but at this stage that seems.. mostly fine? Perhaps they should be more clear about that in their marketing, but I understand the goals and I admire the enthusiasm from DHH.
Part of me hopes that some amount of resources are being invested by someone in our government to analyze and assess this, but maybe that is overly optimistic.
I'm not sure if the reason may be as simple as the desire to pump their user numbers for earnings, or if it's something more egregious than that. It's not clear to me how a company owned by the public which relies on advertisers for revenue has been able to carry on for so long being a propaganda farm for foreign agents and marketing bots.
Also, while I love the convenience of Synology's software, I don't love that it's closed source. Their hardware is also fairly underwhelming for the price tag.
It may not be obvious to more casual observers, but there is a lot of trading volume happening on on-chain exchanges these days (as in easily 10B+ in trading volume per day with most of this coming from futures).
There are solutions on the desktop like Qubes (but it uses virtualization and is slow, also very complex for the average user). There are also user-space solutions like Firejail, bubblewrap, AppArmor, which all have their own quirks and varying levels of compatibility and support. You also have things like OpenSnitch which are helpful only for isolating networking capabilities of programs. One problem is that most users don't want to spend days configuring the capabilities for each program on their system. So any such solution needs profiles for common apps which are constantly maintained and updated.
I'm somewhat surprised that the current state of the world on the desktop is just _so_ bad, but I think the problem at its core is very hard and the financial incentives to solve it are not there.
That said, China is one of the most authoritarian countries in the world. It has some of the most effective controls in place around media, speech, technology, and capital of any country. I'm not sure whether that model could be easily copied, and whether it should be copied is maybe a different conversation altogether.