8,111 karma · joined March 21, 2014
goisser94@gmail.com
https://hobofan.com
Mastodon: @hobofan@toot.berlin (Twitter: @hobofan)
---
Currently building https://github.com/EratoLab/erato
Additionally, "the algorithm" rewards channels that have a lot of watchtime & retention (because againg, this leads to more ad placement opportunities for Youtube). So if you are able to produce long-form videos that keep the viewers engaged and watching, your videos are more likely to be recommended, which reinforces the popularity of long videos.
Most complexity that usually plagues authorization systems comes from complex authentication requirements, and can thus be largely isolated there. That's also where many (often legacy systems) lay a bad foundation, because they from the get-go tangle authentication & authorization into thing.
In a model as described above, that just turns into a slightly different `actor`. With that you can also handle things like context-aware authorization without littering your codebase.
Yes, but only very coarsly granular things.
- Permissions only work with entities. There are about ten different kinds of objects besides entities, that would also benefit a lot from being part of a uniform permission system.
- Permissions can only be defined for groups, not users, which is quite annoying if you want granular permissions
- With permissions only acting on groups, it also isn't possible to base permissions on user attributes. So you ultimately always have to model a permission set as a group, and then essentially have to have a synchronization mechanism that ensures that the right people are in the right groups
- This also makes scoped integration access impossible. You can't grant a third party app access to e.g. only your energy sensor data.
These days if you build it with a central policy engine, e.g. on top of Open Policy Agent with Rego as a policy language, and stick to a (actor, object, action) triple system, you can build an extensible and powerful authorization system that usually also is less polluting to the codebase as many other approaches. For HA specifically, where you have a quite low numbers of actors and objects, most of the headaches that could come with such a system in terms of scaling also fall away.
I do think the maintainers are getting better about it. The releases over the past year have reworked a lot of things to be more intuitive for casual users while also being more flexible for power users, but there is still a lot of ground left to cover.
I think with the growing popularity, and expansion of fields of use, this is something they'll ultimately have to reckon with. I've seen quite a few posts on the the HA subreddit, where it's being used for controls in e.g. hotels or other bigger buildings, because it has a great feature set and prevents vendor lock-in. There is no harm in also catering to those people & organizations.
Of course you can also do ranking one-off with a decision model, but this likely less stable, and by doing pairwise ranking you can also relatively quickly do incremental inserts to the list.
I many scenarios, e.g. running the harness server-side, as is the case for chat interfaces, you don't really want to expose OS shell access as that opens up a huge security attack surface.
While we are waiting on that to become stabilized, we implemented a inspired/co-evolved way to do that in our tool[0], where you mark individual fields in the request/response schema as being file payloads, so that file exchange can be properly orchestrated by the harness and doesn't pollute the context. We just do inline base64 uploads of the required payloads, which in practice we've seen to work quite will until ~100MB files (which is otherwise also the size limit we usually recommend for file processed).
It's annoying that it's not stabilized yet, but for most bigger customers we've seen, they implement 80% of the MCP servers they connect in-house, so doing adjustments to the tool surface, and metadata has been less of a pain for them than we expected.
[0]: https://erato.chat/docs/features/mcp_servers#file-support
However, it appears that when I looked at the list of investors earlier, I've missed that Peter Thiel is among them. So yeah, there are clear political ties.
You already came to the proper conclusion by just thinking about it for a few minutes. Let's just skip building out a surveillance state, and put that money directly into mental health & housing initiatives instead.
In my opinion apps like the Citizen[0] app are some of the worst offenders. They constantly bombard you with scary notifications, creating a constant environment of fear. With that app people are constantly aware of things that are happening in your general area without any real benefit of informing you. It turns the mildly-annoying-but-ignoreable mentally ill person on the street corner from someone that "scares" the 10 people around them into someone that scares 10k people in the area.
Oh, and Citizen is also directly integrated into Axon's Flock-like surveillance product.
[0]: https://citizen.com/
Yes, because it was a largely random undirected process.
They don't need to plateu for that to happen. There are companies already building AI on ASIC, and IIRC they were approach 12 months lead time. A 12 months old frontier model (Sonnet 4.5, GPT-5, Kimi K2) for 1% of the price is still a rather good value proposition.
- Japan-developed 2nm 3D-stacked CPU
- server integrated, developed, and manufactured in Japan
If going by GDP (which this claim usually does), the EU as a whole beats out China for second place by ~10%. When going by individual countries Germany alone is the third place behind China, though with a large gap between the two.