Another thing that bit me is that automatic updates reserve disk space even if no update is available. It makes sense when you have plenty of disk space but on my MacBook Air with 256gb of storage it was about 10% that I got back after turning off automatic updates. I’ll get a Mac with more storage next time so I don’t have to do that.
Apologies, I didn’t mean to imply it’s a benchmark, I just wanted to provide a reproducible example of where I see models make decisions that seem to be fine initially but might paint the software architecture into a challenging corner. I don’t expect models to read my mind, but I do see them produce a lot of verbose output, none of which is used to say “here’s a simple response to your ask, but have you also considered...”
I disagree with the assertion that the model gets it. Here’s a practical example I just tried with Fable 5.1. I gave it this prompt: “Write a Go function that can be used to establish secure communication to a remote system using a certificate. Keep it short, single function, and explain how to use it.” The output forced the use of a private key stored in a file even though that wasn’t specified anywhere as a requirement. The function Claude wrote takes a private key file argument and calls a Golang function that requires a private key file (tls.LoadX509KeyPair) even though Go has crypto.Signer which could support private keys in various other manifestations like HSM or KMS. I argue that a person who “gets it” (or who is reasonably experienced in security) would have opted for not requiring private key material for this to work.
For the record, this isn’t unique to Claude. ChatGPT and Gemini do the same, each with its own quirks. ChatGPT got extra credit for being the only one who allowed the function to also take a CA file for server authentication.
Don’t get me wrong: LLMs are the future (maybe even the present) of software development but I think there’s some way to go before they can be entirely hands-off in some areas. I still find myself having to course correct designs and plan mode helps me with that.
And of course, thank you for your work on Claude. :)
Thank you for working on this, I love the idea. What surprised me was the way user identities is managed, I assumed you’d use whatever git uses. Would you mind elaborating on that?
To me, there’s a difference between ads that help me learn about brands or products, or make me laugh or have some positive emotion (Super Bowl ads, billboard signs, and movie previews come to mind) and ads that take over search results, interfere with the content I want to consume on an already-small screen, or are just distasteful to me. I can’t say I like ads but I recognize that I specifically dislike some ads more than others.
That’s the important question. Someone else on the thread suggested it was to divert attention from one failure (AI) and now they have two. I wonder how Steve Jobs would react to this mess. Maybe he’d say he would not have been in such a mess in the first place. :)
I thought the same thing. Some of the commenters said this move might be related to stock price or appeasing shareholders, so I wonder if that, too, was directed at them, as in “we’re big and we plan on getting even bigger”
My hypothesis is that this is government response (own stake in Intel) to another government’s action (hint take over of Taiwan) and as such is outside the free market. But I have no evidence to support it, it’s just an opinion and it could be that they view Intel as “too big to fail” or something like that as you suggest.
I agree, and I think the government’s incentive might also be a having strategic production capability in the US. Maybe they’re concerned about TSMC’s future with the tension between China and Taiwan?
Encryption at Rest makes it easy to reason about data hygiene, since access to the data is gated through access to the keys.
You want to delete data? Toss the keys. You want to confidentially process data? Make the keys available to a TEE or such. You want to prevent yourself from having constant access to the data? Let the client provide the keys. And of course, you want to protect the keys? Use an HSM.
Interviews are more thorough because firing became harder.
It used to be that if you hired an employee and found out they aren’t good at their job you could fire them. Today it is complicated and can backfire if the employee believes they were fired because of any reason other than their skills, or were not provided with ample opportunity and support to succeed.
The solution is a lengthier process based on the assumption that once hired, the company is stuck with the employee unless they decide to leave.
Google is known to be against new and safe technologies. Google Finance still uses Flash, and Android has the worst IPv6 support despite it being based on Linux. What's your point?
It's simple. There is no way Firefox can guarantee anywhere near the level of stability and security Chrome offers without a process per tab. OS primitives operate in terms of processes (scheduling, memory, sandboxing, and so on) and Firefox will not be able to use any of them. I really want to use Firefox, but I'm almost certain not doing a process-per-tab will be the last nail in its coffin. The code will be more complex to maintain, and no advantages in security or performance will be gained, leading to less users and thus less maintainers.
If there was one thing that caught my attention with Chrome back when it was released (2008?) it was its reliance on OS primitives (processes) as the building blocks for a stable and secure browser. This is essentially the same argument the Varnish folks did when comparing to other proxy solutions like Squid back in the day. I don't understand why Firefox is taking this route.
Please DO process-per-tab. I have a lot of memory. I want you to use it. If it's not enough, I will buy more memory or a stronger device. But please, whatever you do, don't make security or stability trade offs for me. The M:N threading model has never worked out. We know 1:1 works. Please do that. Please, please, please use a process-per-tab.
Some of the times they're harmed, some of the times they're not. There's no correlation, ruling out the slightest possibility of causation. Is it risk management, then? No, because a product with a well known and trusted brand has much higher chances of success. Is Google internationally reducing the success chance of their billion dollar bets? No. The only reasonable conclusion to make is that Google doesn't want to taint their new offerings with the existing brand.
The premise that visible business failure harms brands is false. It's your opinion and it sounds like it makes sense, but it's not supported by any data.
That has already happened. One of the reasons Goole renamed itself "Alphabet" and started using different brand names (e.g. "Waymo") for other products is to confuse consumers about their source. The "Google" brand has become synonymous with advertising and invasion of privacy, and the reversal of strategy (used to stick the brand on everything vs. isolating it to search and ads) is a hedge against the growing consumer distrust.
People must remember that Google is first and foremost an advertising company. 90% of its revenue comes directly from advertising. Anyone who thinks they will prioritize anything over ad revenue is either very naive or very stupid.
Google's CEO declared it's "AI first" and they developed TensorFlow. If they wanted to, they could have easily prevented those ads from entering their network.
I see pfSense playing two possible roles the SD-WAN. The first is customer-centric, and will allow pfSense edge devices to connect to a third-party SD-WAN service or one provided by Netgate itself. The other is vendor-centric, and will allow SD-WAN vendors to use pfSense for their Point-of-Presence software when building the geographically distributed network for SD-WAN traffic optimization.
Both are smart strategies and well within your core competency. As long as you're not building your own SD-WAN service you're golden.
If I had to guess, I'd say Netgate is working on an SD-WAN service of sorts. Many players in this market are displacing the edge firewall, and offering a built-in service of their own or in partnership with a third-party might be a smart move.
People working at Facebook and Google lie to themselves that they're doing something important while working for a "cool" tech company. They're ignorant to the fact that these companies make their entire revenue from advertisements.
It sends your code to the cloud. You have not addressed people's concerns who asked about keys embedded in source code, not entire files to ignore. The uninstall process looks and feels a lot like stopping a rogue process that keeps respawning. You've silently integrated with an unrelated project (autocomplete-python) to collect data.
I applaud the idea and UX in the video. I'd love to use a tool that does all that. That said, I completely condemn everything else about you. I strongly recommend anyone who has installed Kite to remove it from their computers immediately as it seems that the people behind it don't have the community's best interests in mind.