12,427 karma · joined March 27, 2019
> While amusingly as of June 8 Blacksmith’s terms implied that their right to bill you is contingent on you providing payment information, a SaaS app certainly could have terms that obligate users to pay for unexpected overage when on a free trial.
> And let’s be clear: our agents run a lot of CI jobs, so we did expect to hit the limits of the free plan. We used the service and got value for it. So it’s not inherently dishonest, just surprising. My read is that they can do this.
So I read this that the terms say "blacksmith will only bill you if you provide payment information" but then they say that blacksmith can bill you if you don't provide payment information. That seems to contradict the terms, which I would assume underlie the "contract" that you agree to when agreeing to the terms.
Once you take away this way of working, I might as well not work in a notebook at all (which admittedly is my default way of working anyway).
As a side note, how do you make up that billion user number? Claude has 10 million users.
Note I didn't ask the researchers either and am only deducing this from the text.
I think you're completely ignoring the premise of the articles argument (as I understand it). The failure of the declaration was a feature not a flaw. In otherw words it was never about the freedom of the individual but the freedom of large corporations.
In the end governments (even totalitarian ones in a limited sense), are vehicles of the people. Unregulated spaces will favor the person with the most resources and thus lead to more concentration of power. It's essentially a information centric continuation of Reaganomics. The article argues that this could have been (and was, e.g. by Winner) anticipated in the 90s, and that in fact this was the intention of Barlow and co.
An interesting anecdote, in France Pipi Longstockings was heavily censored until the 90s because it was viewed as promoting disobedience. Naturally that made it so dull that nobody wanted to read it, so French people (at least those who were children then) generally don't know pipi. I only found out about all this when we moved to Sweden and my French partner had never heard of pipi, which I couldn't believe.
With niri I just open another window and it's where I need it and all other windows are still to the left and right so I just "scroll" there. Now I'd say my workflow is messier now, but I think that's actually a good thing. Tiling window managers require (but also make it reasonably easy) to be organised. With niri I don't have to be organised. Sometimes it you can't find a window immediately, but you can just use overview (and I also have a window search rofi). Initially I still had some named workspaces similar to my sway tags, mainly because I found I was still switching to them out of habit. Nowadays I don't use them any longer.
I think a much better metric is suppression of dissent, human rights records etc., not (the illusion of) choice at the poll booth once every 4 years.
They have been doing it (and likely others as well), but they are not anthropic which a million dollar marketing budget and a trillion dollar hype behind it, so you just didn't hear about it.
You don't think that security companies (and likely these guys as well) develop systems for doing this stuff?
I'm not a security researcher and I can imagine a harness that first scans the codebase and describes the API, then another agent determines which functions should be looked at more closely based on that description, before handing those functions to another small llm with the appropriate context. Then you can even use another agent to evaluate the result to see if there are false positives.
I would wager that such a system would yield better results for a much lower price.
Instead we are talking about this marketing exercise "oohh our model is so dangerous it can't be released, and btw the results can't be independently verified either"
>At AISLE, we've been running a discovery and remediation system against live targets since mid-2025: 15 CVEs in OpenSSL (including 12 out of 12 in a single security release, with bugs dating back 25+ years and a CVSS 9.8 Critical), 5 CVEs in curl, over 180 externally validated CVEs across 30+ projects spanning deep infrastructure, cryptography, middleware, and the application layer.
So there is pretty good evidence that yes you can use this approach. In fact I would wager that running a more systematic approach will yield better results than just bruteforcing, by running the biggest model across everything. It definitely will be cheaper.