Their stated reason? Child safety.
Their actual reason? You can figure that out.
1,260 karma · joined December 29, 2018
Their stated reason? Child safety.
Their actual reason? You can figure that out.
One of the best patterns I’ve see is having an /ai-notes folder with files like ‘adding-integration-tests.md’ that contain specialized knowledge suitable for specific tasks. These “skills” can then be inserted/linked into prompts where I think they are relevant.
But these skills can’t be static. For best results, I observe what knowledge would make the AI better at the skill the next time. Sometimes I ask the AI to propose new learnings to add to the relevant skill files, and I adopt the sensical ones while managing length carefully.
Skills are a great concept for specialized knowledge, but they really aren’t a groundbreaking idea. It’s just context engineering.
> According to Bloomberg and CNN, citing sources, SitusAMC sent data breach notifications to several financial giants, including JPMorgan Chase, Citigroup, and Morgan Stanley. SitusAMC also counts pension funds and state governments as customers, according to its website.
It would be silly to provide every employee access to GitHub, regardless of whether they need it. It’s just distracting and unnecessary risk. Yet people are over-provisioning MCPs like you would install apps on a phone.
Principle of least access applies here just as it does anywhere else.
Just saw the Audi etron gt has amazing deals on used cars. Then I saw a new model coming out with better battery, more power, better range, and more features. Suddenly last year’s model is way less compelling.
But hey, that just means better used EV prices for the rest of us. You can get some high end gently used ones for a great price.
—
“ For Tesla owners in the U.S., their 2023 Model Ys are worth 42% less than what they paid two years ago, while a Ford F-150 truck bought the same year depreciated just 20%. Older EV models depreciate even faster than newer ones. ”
On a plane this is so useful. Flights go by much faster.
When traveling it’s so much less of a productivity drag to be able to pop this on and work with more real estate and focus.
The spatial videos and photos, whether taken with a real spatial device or upgraded later, are… so immersive. Seeing very old memories in 3d is emotional.
But I would pay so much to have a great gaming experience. Like a racing sim or something else realistic. The hardware is so impressive.
Frankly, I think this shines most as a consumption device for 3d content. There’s just not nearly enough yet.
Have you written about MCP gateways for helping companies route all MCP traffic through one plane for observability, security, and compliance? Happy to chat through that. I just recorded an end to end demo of what we are working on: https://vimeo.com/1127330739/ee1fe5245b
I've had this issue on my M1 and now my M4 mac for about a year now, and I can't figure it out. Uninstalling and reinstalling hasn't helped.
Literally, someone can reliably send me a slack notification in a meeting (even when DND is on) and cause my Zoom outbound video to get gummed up.
Edit: I ask because I wonder if it has to do with this.
Executives are blaming the model quality, but that’s not the problem. It’s how well the AI understands what it is supposed to do and how connected it is to the information it needs.
If that organization understands their business processes well and has a team capable of adapting to new things, they will likely get AI to work for them and pull ahead.
But if that organization barely has their stuff together and isn’t all that good at adapting, then AI will fail to deliver meaningful results.
It’s basically just like amplified prompt engineering. Provide a vague prompt and you’ll get a low quality answer. But if you can properly communicate what you need, the AI generally will perform.
So TLDR it’s typically not the AI failing, it is the organizations failing to use AI.
Tried launching something in 2022. Night of the launch, my whole team pulls an all nighter.
Some launches suddenly pull ahead with 20 upvotes right out of the gate. We have a handful. I see the same LinkedIn messages this author cites, but I ignore them. Why cheat?
Once someone secure a top spot, all the traffic goes to those apps, and they stay ahead to matter what. Accumulative advantage.
1 hour later, we get hit with a cyberattack. We don’t have rate limiters on sending invites from validated users, and someone overwhelms that system. All the queues are flooded and grind to a halt.
We work furiously to resolve it. It takes hours to get everything flushed and healthy again.
We ended in 9th place or something.
Never again. I realized it’s just pay to play.
But the idea itself is compelling: documentation + invocation in a bi-directional protocol. And enough real players have thrown their weight behind making this thing work that it probably some day will.
I don't understand fully the "it's immature so it's worthy or ridicule" rationale so much. Don't most good things start out really rough around the edges? Why does MCP get so much disdain?
MCP is a novel technology that will probably transform our world, provides numerous advantages, comes with some risks, and requires skill to operate effectively.
Sure, none of the underlying technologies (JSON-RPC, etc.) are particularly novel. But the capability negotiation handshake built into the protocol is pretty darn powerful. It's a novel use of existing stuff.
I spent years in & around the domain of middleware and integrations. There's something really special about the promise of universal interoperability MCP offers.
Just like early-aviation, there are going to be tons of risks. But the upside is pretty compelling and worth the risks. You could sit around waiting for the kinks to get worked out or dive in and help figure out those kinks.
In fact, it seems I'm the first person to seriously draw attention to the protocol's lack of timeout coordination, which is a serious problem[0]. I'm just a random person in the ecosystem who got fed up with timeout issues and realized it's up to all of us to fix the problems as we see them. So there's still plenty of opportunity out there to jump in and contribute.
Kudos to this team for responsibly contributing what they found. These risks are inherent in any new technology.
[0]: https://github.com/modelcontextprotocol/modelcontextprotocol...
Sure, teams could build their own connectors via function calling if they're running agents, but that only gets you so far. MCPs promise universal interoperability.
Some teams, like Block, are using MCP as a protocol but generally building their own servers.
But the vast majority are just sifting through the varying quality of published servers out there.
Those who are getting MCP to work are in the minority right now. Most just aren't doing it or aren't doing it well.
But there are plenty of companies racing into this space to make this work for enterprises / solve the problems you rightfully bring up.
As others have said here, the cat is out of the bag, and it is not going back in. MCP has enough buy-in from the community that it's likely to just get better vs. go away.
Source/Bias disclaimer: I pivoted my company to work on an MCP platform to smooth out those rough edges. We had been building integration technology for years. When a technology came along that promised "documentation + invocation" in-band over the protocol, I quickly saw that this could solve the pain of integration we had suffered for years. No more reading documentation and building integrations. The capability negotiation is built into the protocol.
Edit: a comma.
I’ve ended up building similar things over and over again. For example, simplifying the worker-page connection in a browser or between chrome extension “background” scripts and content scripts.
There’s a reason many prefer “npm install” on some simple sdk that just wraps an API.
This also reminds me a lot of MCP, especially the bi-directional nature and capability focus.
It is not hard to imagine getting a black mark in some invisible proprietary profile that determines if you can access Uber Eats, LinkedIn, etc. and have no recourse to fix it or get another chance.
But then I thought about the implications of that choice to delete it. And here I am posting this instead, probably to the same end. But it’s a different message about self censorship.
I had the same experience recently with: - Ticketmaster - Docusign - Vercel
Probably a handful more I forgot.
I believe the main reason is because it prevents fraud.
But I see a deeper motive that phone numbers are more friction to change and therefore our “real” numbers become hard-to-change identity codes that can easily be used to pull tons of info about you.
You give them that number and they immediately can look up your name, addresses, age, and tons of other mined info that was connected to you. Probably credit score, household income, etc.
Phone numbers have tons of “metadata” you provide without really knowing it. Like how the Exif data in a photo may reveal a lot about your location and device.
Wrapping business processes around these LLMs is the same kind of hard organizational problem plaguing most internal IT projects. People are still the bottleneck.
You also run into the issue of accuracy compounding. Running multi step flows with AI compounds the success rate and dramatically increases the chances of a full-job failure. E.g. even at 99% success rate for any single step, a 30-step process is only likely to succeed 75% of the time without errors. If you go down to 95% success for each, you only have a 75% likelihood of flawless execution at about 6 steps.
So it’s also about getting those per step success rates way up.
I also think this is a sign of late stage capitalism where the opportunities to profit “ethically” are becoming much harder to find and exploit. That leads to more pressure to find gray areas that others’ ethical or moral convictions prevented them from exploiting.
I just installed graphene os on a brand new cash-bought pixel for the express purpose of not being left out of some important WhatsApp groups or missing out on some other experiences that require installing apps that I know won’t respect my privacy. I assume anything from Meta is hazardous at this point.
Edit: "experts" > "workers"
At checkout they looked at me like I was up to no good when I said I didn’t want to give them my name, address, and phone number just to purchase the device. I didn’t set up a plan. They said it was for “restocking” or something.
Fortunately they accepted obviously fake info. These front line sales people just don’t care as long as they can say they followed the policy.
The user containers are very helpful. I have to have TikTok for work and I put it in a container all by itself with a vpn on kill switch. And for one app that needs google play services, I have it a container with that.
The duress passcode is super clever, too. You enter a different device passcode and it just wipes the device.
I was super hesitant at first but thought that this might be the most accepting place of any. For the most part, my comments were getting tons of upvotes and replies and so I thought “wow this is furthering the conversation. I should keep going!”
I wasn’t outsourcing the entire process after all. I moved from asking it to rephrase things I wrote (I’m sure plenty of people use grammarly and the like) to asking it to give me some drafts with a specific opinion and viewpoint, and then I would edit to my liking.
Anyway, this totally blew up and now I regret it. But it was an interesting ride because it really opened some interesting questions about the fact that these were some of the comments I made that the community upvoted the most, which to me is a sign of contributing value.
I’m running an experiment.
A few days ago I flagged a piece someone else had written with ai. It has a specific cadence and some typical patterns. But many people seemed to buy it before I commented. I was surprised.
Today I pushed the boundary further and it clearly was that boundary.
Check my comment history.
I started out just saying “rephrase this so it sounds tighter” and moved recently towards just jotting rough notes and saying “make an HN comment out of this” and then editing.
I’ve been using gpt-5. I was going to see how Claude sonnet 4 performs at coming across as human-written / flagging some spidey senses.
(This was all by hand.)