HNHacker News
TopNewBestAskShowJobs

hobofan

8,111 karma · joined March 21, 2014

Jack of all trades (- master of some?)

goisser94@gmail.com

https://hobofan.com

Mastodon: @hobofan@toot.berlin (Twitter: @hobofan)

---

Currently building https://github.com/EratoLab/erato

submissionscomments
hobofan··on Web Search API
I think Cloudflare is (for companies already using it) approaching the status of trusted main cloud supplier (which usually would be AWS, GCP, Azure) via which the majority of cloud costs are billed (so you don't have to go through a fresh procurement process).
hobofan··on What is going on with ceiling fans
Yes, and longer videos allow for Youtube to insert more ad breaks. For viewers that are Youtube Premium subscribers, the revshare portion that goes to the creator also grows linearly with watchtime.

Additionally, "the algorithm" rewards channels that have a lot of watchtime & retention (because againg, this leads to more ad placement opportunities for Youtube). So if you are able to produce long-form videos that keep the viewers engaged and watching, your videos are more likely to be recommended, which reinforces the popularity of long videos.

hobofan··on Why don't more developers “use the platform”?
When you tried to do that a few dozen times, and the outcome is always to build (and have to rebuild!) off platform, starting out off platform is the logical option.
hobofan··on Big Tech ruined the cloud, so we're renaming ours
I disagree that that leads to a huge amount of unavoidable complexity. I am (and have been) building systems that are deployed into exactly those security sensitive organizations, with exactly the stack I described above. The only main requirements that those systems usually have is audit logging, which is becomes easy with a centralized policy engine.

Most complexity that usually plagues authorization systems comes from complex authentication requirements, and can thus be largely isolated there. That's also where many (often legacy systems) lay a bad foundation, because they from the get-go tangle authentication & authorization into thing.

In a model as described above, that just turns into a slightly different `actor`. With that you can also handle things like context-aware authorization without littering your codebase.

hobofan··on Big Tech ruined the cloud, so we're renaming ours
> HA permissions are just to lock certain users or groups out of controlling certain things

Yes, but only very coarsly granular things.

- Permissions only work with entities. There are about ten different kinds of objects besides entities, that would also benefit a lot from being part of a uniform permission system.

- Permissions can only be defined for groups, not users, which is quite annoying if you want granular permissions

- With permissions only acting on groups, it also isn't possible to base permissions on user attributes. So you ultimately always have to model a permission set as a group, and then essentially have to have a synchronization mechanism that ensures that the right people are in the right groups

- This also makes scoped integration access impossible. You can't grant a third party app access to e.g. only your energy sensor data.

hobofan··on Big Tech ruined the cloud, so we're renaming ours
I think a lot of people have a wrong perception of how "complicated" authorization systems need to be, most likely because they've been confrontend with badly built ones their whole career.

These days if you build it with a central policy engine, e.g. on top of Open Policy Agent with Rego as a policy language, and stick to a (actor, object, action) triple system, you can build an extensible and powerful authorization system that usually also is less polluting to the codebase as many other approaches. For HA specifically, where you have a quite low numbers of actors and objects, most of the headaches that could come with such a system in terms of scaling also fall away.

hobofan··on Big Tech ruined the cloud, so we're renaming ours
That the default should be non-complicated isn't necessarily in conflict with features for power users, and I feel like in the HA forums it often is portrayed as an unresolvable conflict, when it isn't.

I do think the maintainers are getting better about it. The releases over the past year have reworked a lot of things to be more intuitive for casual users while also being more flexible for power users, but there is still a lot of ground left to cover.

I think with the growing popularity, and expansion of fields of use, this is something they'll ultimately have to reckon with. I've seen quite a few posts on the the HA subreddit, where it's being used for controls in e.g. hotels or other bigger buildings, because it has a great feature set and prevents vendor lock-in. There is no harm in also catering to those people & organizations.

hobofan··on Big Tech ruined the cloud, so we're renaming ours
I'm usually not one to jump quickly to that, but that's a joke of a permission system.
hobofan··on You said no MCP
So how do you explain it still being in the "OWASP Top 10" and the "CWE Top 25 Most Dangerous Software Weaknesses"?
hobofan··on Clef: Open-weight decision models, and new RL fine-tuning platform
Closely connected to decision models: A good library to do ranking based on pairwise ranking on multiple attributes. By using a decision model (especially one that can make decisions on multiple fields at the same time) this becomes a lot faster and more powerful. Could make for a pretty nice search reranker as well as prioritizer for many problems.

Of course you can also do ranking one-off with a decision model, but this likely less stable, and by doing pairwise ranking you can also relatively quickly do incremental inserts to the list.

hobofan··on You said no MCP
In practice, the problem with resources is that many resource collections are too large to list exhaustivley, and if that's the case you will need to need to implement a proper search tool anyways (as the Completions utility isn't a good fit), at which point there is little use in also implementing all of that as a resource, rather than `list_`,`search_`,`get_` for a resource.
hobofan··on Pi.dev: You Said No MCP
That has been one of the most common exploits for decades.
hobofan··on Pi.dev: You Said No MCP
> Normally if LLMs want to compose multiple operations, they have the perfect tool for this: bash, or whatever other OS shell is available.

I many scenarios, e.g. running the harness server-side, as is the case for chat interfaces, you don't really want to expose OS shell access as that opens up a huge security attack surface.

hobofan··on Pi.dev: You Said No MCP
There is a MCP SEP that outlines multiple ways, that I hope will sooner or later be accepted: https://github.com/modelcontextprotocol/modelcontextprotocol...

While we are waiting on that to become stabilized, we implemented a inspired/co-evolved way to do that in our tool[0], where you mark individual fields in the request/response schema as being file payloads, so that file exchange can be properly orchestrated by the harness and doesn't pollute the context. We just do inline base64 uploads of the required payloads, which in practice we've seen to work quite will until ~100MB files (which is otherwise also the size limit we usually recommend for file processed).

It's annoying that it's not stabilized yet, but for most bigger customers we've seen, they implement 80% of the MCP servers they connect in-house, so doing adjustments to the tool surface, and metadata has been less of a pain for them than we expected.

[0]: https://erato.chat/docs/features/mcp_servers#file-support

hobofan··on 500k facial scans at UK stations yield no arrests, 1 false positive
I would have said that they are mainly doing it to exploit the mechanism as it just serves their profit motif, and everything else is just a byproduct.

However, it appears that when I looked at the list of investors earlier, I've missed that Peter Thiel is among them. So yeah, there are clear political ties.

hobofan··on 500k facial scans at UK stations yield no arrests, 1 false positive
But why is there a need to measure it in the first place and then only react to it?

You already came to the proper conclusion by just thinking about it for a few minutes. Let's just skip building out a surveillance state, and put that money directly into mental health & housing initiatives instead.

hobofan··on 500k facial scans at UK stations yield no arrests, 1 false positive
It's not just politicized propaganda. A lot of unsafety feeling is almost self-inflicted.

In my opinion apps like the Citizen[0] app are some of the worst offenders. They constantly bombard you with scary notifications, creating a constant environment of fear. With that app people are constantly aware of things that are happening in your general area without any real benefit of informing you. It turns the mildly-annoying-but-ignoreable mentally ill person on the street corner from someone that "scares" the 10 people around them into someone that scares 10k people in the area.

Oh, and Citizen is also directly integrated into Axon's Flock-like surveillance product.

[0]: https://citizen.com/

hobofan··on Meta's Muse appears to use an OpenAI model labeled muse-special
Anthropic does the same thing with reasoning signatures. It has already become the standard pattern.
hobofan··on Factorio that you can touch
Not quite Factorio, but Satisfactory has a board game in the works: https://www.reddit.com/r/SatisfactoryGame/comments/1wj4gc6/i...
hobofan··on Tokens too cheap to meter
???

Yes, because it was a largely random undirected process.

hobofan··on Tokens too cheap to meter
> LLMs plateau in ability, in which they will start getting ASIC'd.

They don't need to plateu for that to happen. There are companies already building AI on ASIC, and IIRC they were approach 12 months lead time. A 12 months old frontier model (Sonnet 4.5, GPT-5, Kimi K2) for 1% of the price is still a rather good value proposition.

hobofan··on The current balance of power in open models
As long as you don't have "realtime" workloads, owning the GPUs quickly becomes the economical option. The main cost problems is in e.g. chat applications where the workload is spikey, and users expect an near-instant response, for which you need to scale the GPUs to the highest spikes of the workload.
hobofan··on Warez: The Infrastructure and Aesthetics of Piracy (2021)
NFO files (both image and text) for current releases and ones going way back can still be found on xrel.to
hobofan··on Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA
Pretty sure it's worded in a way that it applies only to the server, so it should be read as two distinct things:

- Japan-developed 2nm 3D-stacked CPU

- server integrated, developed, and manufactured in Japan

hobofan··on Nvidia announces native GPU programming in Rust
Why? The point of a shader language is to define a function that outputs some graphics. Why should that not be portable between GPUs/CPUs of different vendors?
hobofan··on Claude Cowork and chat are now one Claude
You are not the typical office worker.
hobofan··on A warning about 'model welfare'
I'm pretty sure the message board that was recently swarmed by OpenAI agents to collude on benchmarks would like to disagree.
hobofan··on EU chief opens door for Canada to become 'associate member'
> It's also the third largest economy in the world

If going by GDP (which this claim usually does), the EU as a whole beats out China for second place by ~10%. When going by individual countries Germany alone is the third place behind China, though with a large gap between the two.

hobofan··on The Google Play app review process now regularly takes longer than a week
From what I was able to see from the outside, App Store has had semi-automated reviews for updates in basically forever (+ some random spot checks), presumably based on some introspection that only triggers a human review if a new system API was used.
hobofan··on Introducing System One Models and Jev
That's still ultimately privacy by contract (where you have to trust the inference providers to uphold their end of the deal), rather than privacy by design.
Page 1 of 34Next →