HNHacker News
TopNewBestAskShowJobs

lordofmoria

941 karma · joined December 11, 2012

submissionscomments
lordofmoria··on The bread paradox: why convenience always wins, and why SaaS isn't doomed
I completely agree that people are vastly undervaluing convenience, reliability and SaaS being essentially a great way to make something “someone else’s problem”.

The count argument would be that building with AI will potentially give you infinite customizability, which is especially attractive if you’ve ever hit a brick wall using a line-of-business SaaS product. It works great until you hit that wall.

But again, I think this counter argument oversells the value of customization. Most users-would-be-builders would happily build a monstrosity that doesn’t even serve themselves well, if you let them. Building good workflows (and therefore good SaaS products) is not nearly as easy or straightforward as it seems.

lordofmoria··on Opus 4.7 knows the real Kelsey
I wonder if there’s a simpler and less interesting answer? That it’s just picking up on voice and style, not anything that would apply to the average non-writer?

This person is a skilled writer. Part of that skill is developing a unique voice and style. The AI can identify that - and while that’s certainly impressive because it can identify even relatively niche authors, it has nothing to do with a wider capability to deanonymize people based on arbitrary written text (ex Facebook or text messages).

If you are a professional musician, it’s not difficult to identify a well known musician / recording after listening to only a few seconds - whether they’re playing Bach or Rachmaninov, the style is just “them” - this is the same thing. But you couldn’t take some anonymous high school musician and guess who they were, even if they were your student - the median quickly regresses towards a homogenous, non-distinct style / voice.

lordofmoria··on Show HN: Eve – Managed OpenClaw for work
https://sprites.dev as well (it’s a fly.io product). They look suspiciously identical…
lordofmoria··on Litestream v0.5.0
A small warning for folks.

I once was responsible for migrating a legacy business app to Azure, and the app had a local MSSQL server co-running with the app (the same pattern that Litestream is using).

As have been mentioned below, the app had been developed assuming the local access (and thus <1ms latency), so it had a ton of N+1 everywhere.

This made it almost impossible to migrate/transition to another configuration.

So, if this style of app hosting doesn't take off and you're at all worried about this being a dead end storage once you reach a certain scale, I'd recommend not doing this, otherwise your options will be very limited.

Then again - I bet you could get very very far on a single box, so maybe it'd be a non factor! :)

lordofmoria··on OpenAI to buy AI startup from Jony Ive
I don't understand all the pessimism and incredulity about the valuation. This is an acquisition to take on and disrupt Apple.

Ives + Altman is perceived as a viable successor to the Ives + Jobs partnership that made Apple successful.

Apple is weak and doesn't seem capable of innovating anymore, nor do they seem to understand how to build AI into products.

There's an opportunity to build an Apple-sized hardware wearables company with AI at its core, just as Altman built ChatGPT and disrupted the Google-sized search.

"Apple-sized" more than justifies a 5B valuation.

lordofmoria··on I stopped using AI code editors
Sorry, I probably phrased that poorly - when you’re coding with AI, you should get in the habit of spending more time checking for security mistakes. Not sanitizing, not scoping properly. Same mistakes a junior or mid would make, but unlike them, the AI will not doubt itself and highlight particular code it wrote asking “is this right?”. So you need to develop the habit of being careful.
lordofmoria··on I stopped using AI code editors
What? Note for any juniors reading this: DO NOT TRY THIS AT HOME.

Does the author enjoy writing code primarily because they enjoy typing?

Are they not able to have the mental discipline to think and problem solve whilst using the living heck out of an AI auto complete?

What's the fun in manually typing out code that has literally been written, copied, copied again, and then re-copied so many times before that the LLM can predict it?

Isn't it more dangerous to not learn the new patterns / habits / research loops / safety checks that come with AI coding? Surely their future career success will depend on it, unless they are currently working in a very, very niche area that is guaranteed to last the rest of their career.

I'm sorry, this is a truly unnatural and absurd reaction to a very natural feeling of being out of our comfort zone because technology has advanced, which we are currently all feeling.

lordofmoria··on Are LLMs able to notice the “gorilla in the data”?
The fundamental problem here is lack of context - a human at your company reading that text would immediately know that Gorilla was not an insider term, and it’d stick out like a sore thumb.

But imagine a new employee eager to please - you could easily imagine them OK’ing the document and making the same assumption the LLM did - “why would you randomly throw in that word if it wasn’t relevant”. Maybe they would ask about it though…

Google search has the same problem as LLMs - some meanings of a search text cannot be de-ambiguified with just the context in the search itself, but the algo has to best-guess anyway.

The cheaper input context for LLMs get, and the larger the context window, the more context you can throw in the prompt, and the more often these ambiguities can be resolved.

Imagine in your gorilla in the step example, if the LLM was given the steps, but you also included the full text of slack/notion and confluence as a reference in the prompt. It might succeed. I do think this is a weak point in LLMs though - they seem to really, really not like correcting you unless you display a high degree of skepticism, and then they go to the opposite end of the extreme and they will make up problems just to please you. I’m not sure how the labs are planning to solve this…

lordofmoria··on Apple Passwords’ generated strong password format
I think the assumption is that this is going into a somewhat modern hashing algorithm like argon, bcrypt (created 1999 - that's a quarter-century ago), or scrypt with salt. With those assumptions, the calculations aren't reusable, and definitely not 1B passwords / second.

If that's not true and the password is being stored using MD5 (something that's been NIST-banned at this point for over a decade), then honestly all bets are off, and even 128 bits of entropy might not be enough.

lordofmoria··on What's New in Ruby on Rails 8
Yes, edited!
lordofmoria··on What's New in Ruby on Rails 8
Rails went through a down period 2014-2020 due to several reasons:

1. React burst on the scene in 2014

2. the hyperscale FANG companies were dominating the architecture meta with microservices, tooling etc, which worked for them at 500+ engineers, but made no sense for smaller companies.

3. there was a growing perception that "Rails doesn't scale" as selection bias kicked in - companies that successfully used rails to grow their companies, then were big enough to justify migrating off to microservices, or whatever.

4. Basecamp got caught up in the DEI battles and got a ton of bad press at the height of it.

5. Ruby was legitimately seen as slow.

The big companies that stuck with Rails (GH, Shopify, Gitlab, etc, etc) did a ton of work to fix Ruby perf, and it shows. Shopify in particular deserves an enormous amount of credit for keeping Ruby and Rails going. Their continued existence proves that Rails does, in fact, scale.

Also the meta - tech-architecture and otherwise - seems to be turning back to DHH's favor, make of that what you will.

lordofmoria··on What's New in Ruby on Rails 8
I had a bad experience with Action Cable + Redis (extremely high memory overhead, tons of dead redis connections), so it's a bit "fool me once" with regard to action cables.

The main argument for caching in the DB (the slight increase in latency going from in-memory->DB-in-memroy is more than countered by the DB's cheapness of cache space allowing you to have tons more cache) is one of those brilliant ideas that I would like to try at some point.

Solid job - i just am 100% happy with Sidekiq at this point, I don't understand why I'd switch and introduce potential instability/issues.

lordofmoria··on Jensen's Inequality as an Intuition Tool (2021)
This was interesting, especially with the DCF example at the end - it’s pertinent to business sell decisions (assuming your ownership structure allows you to make a decision) should I sell at an 8x multiple of revenue, or hold at an X% growth rate and Y% cash flow? What’s my net after 10 years?

The point of Jensen’s inequality if I understand correctly is that you’d underestimate the value of holding using a basic estimate approach, because you’ll underestimate the compounding cash flow from growth?

lordofmoria··on Human drivers are to blame for most serious Waymo collisions
Thanks for doing the math and making this concrete!

I think it’s interesting because:

1) it gives Waymo a higher target to shoot for - it hasn’t “solved” self-driving because its safer than the average driver. I am so impressed by Waymo, but I feel like some of this article smacked of premature “mission accomplished” vibes. The fact that it just accepted the comparison to average without caveat is an example of that. 2) As a matter of policy, everyone can agree that a Waymo ride home for the tipsy is good, but where policy will have issues is convincing good drivers such as my dad to take Waymos everywhere. Not to mention most drivers irrationally think they’re way better than average - that will affect policy in a real way.

lordofmoria··on Human drivers are to blame for most serious Waymo collisions
I think it’s Waymo 6 accidents, not .6 if Waymo has ~1.2 accidents per 100k miles.
lordofmoria··on Human drivers are to blame for most serious Waymo collisions
Because if Waymo is clearly a better driver than average, but not better than me, it might affect my decision to use one.
lordofmoria··on Human drivers are to blame for most serious Waymo collisions
I’d like to see a comparison of Waymo to the top 10% of drivers, rather than average.

I’d consider my dad a good driver - he’s driven many hundreds of thousands of miles without a crash in probably 30 years. Does such data exist?

lordofmoria··on Founder Mode
Brilliant explanation - it puts into words and makes sense of some experiences I’ve had that are hard to articulate.
lordofmoria··on Show HN: Launch React components in your app with no-code
I actually disagree with this - HTML5/jsx is not a bad UI-building abstraction even for non-technical people. The things that make react complicated are syncing state with the backend, routing, etc.

I'd share this with my CEO / CS team - especially with GPT in place and live previews, there's no reason why someone can't build simple react components into these "slots".

lordofmoria··on The golden age of scammers: AI-powered phishing
no, it’s not…
lordofmoria··on The golden age of scammers: AI-powered phishing
The section “Recognizing AI phishing attempts” is mournfully short, but there’s some companies out there like Jericho Security (https://www.jerichosecurity.com) that are working on countermeasures, at least for enterprises.
lordofmoria··on Shapeshift: Semantically map JSON objects using key-level vector embeddings
Since LLMs are bad at the null hypothesis (in this case, when a key does not exist in the source JSON), how does this prevent hallucinating transformations for missing keys?
lordofmoria··on Please don't mention AI again
Even if it’s meant as tongue-in-cheek, it comes off as dismissive and carries a certain smugness that I find particularly irritating.

And the smugness feels especially unfounded because the author clearly has decided to double down on their views even though it’s not at all evident that they’ve taken the time to interact with the tech as an end user (which millions upon millions have, last time I checked). They’ve just not gotten it, or: yes, it is you, not me.

This is just another form of rote, unthinking (anti) hype. It reminds me of the smugness that Balmer had towards the iPhone.

lordofmoria··on Safe Superintelligence Inc.
And now we have our answer. sama said that Ilya was going "to start something that was personally important to him." Since that thing is apparently AI safety, we can assume that that is not important to OpenAI.

This only makes sense if OpenAI just doesn't believe AGI is a near-term-enough possibility to merit their laser focus right now, when compared to investing in R&D that will make money from GPT in a shorter time horizon (2-3 years).

I suppose you could say OpenAI is being irresponsible in adopting that position, but...come on guys, that's pretty cynical to think that a company AND THE MAJORITY OF ITS EMPLOYEES would all ignore world-ending potential just to make some cash.

So in the end, this is not necessarily a bad thing. This has just revealed that the boring truth was the real situation all along: that OpenAI is walking the fine line between making rational business decisions in light of the far-off time horizon of AGI, and continuing to claim AGI is soon as part of their marketing efforts.

Companies in the end are predictable!

lordofmoria··on OpenAI Dissolves High-Profile Safety Team After Chief Scientist Sutskever's Exit
the most obvious explanation for this, that requires the least competence https://simple.wikipedia.org/wiki/Hanlon%27s_razor is that sama concluded that AGI cannot be achieved soon, so it's no longer a concern.
lordofmoria··on Launch HN: Nango (YC W23) – Source-available unified API
Congrats! We’ve been using Nango for about a year, mostly to handle oauth flows for us to about 7-8 integrations (Dropbox, google drive, etc) that our users can self-service connect in our app.

Very stable, the team is respnsibe to handling the weird corner cases (which their value prop is all about), and they seem to be able to build new integrations and functionality quickly.

I’ll be taking a closer look at their sync functionality, since our users want email in app (CRM style).

lordofmoria··on Google delays third-party cookie demise yet again
The Storage Access API is an unmitigated pile of garbage. Google's page on it admits as much (https://developers.google.com/privacy-sandbox/3pcd/storage-a...).

From Google's own page: "Work is continuing to resolve all remaining blocking issues, before standardizing the API."

lordofmoria··on Google delays phase-out of third-party cookies on Chrome yet again
This completely breaks iframes that use session cookies for authentication. The Storage Access API (https://developers.google.com/privacy-sandbox/3pcd/storage-a...), which is the supposed way around this is very much still a work in progress ("Work is continuing to resolve all remaining blocking issues, before standardizing the API.") - and it seems ridiculous that they'd sunset 3rd party cookies before this is fully baked / supported (not to mention that the UX of the flow is very rough).

I'm really hoping this gets knocked down by regulators. It's really all to do with anti-competitive behavior from google ads, and nothing to do with privacy - all the big players have already long-since moved on, because of ad-revenue has shifted to mobile.

lordofmoria··on Lessons after a Half-billion GPT Tokens
OP here - I had never thought of the analogy to DevOps before, that made something click for me, and I wrote a post just now riffing off this notion: https://kenkantzer.com/gpt-is-the-heroku-of-ai

Basically, I think we’re using GPT as the PaaS/heroku/render equivalent of AI ops.

Thank you for the insight!!

lordofmoria··on Lessons after a Half-billion GPT Tokens
Hey, OP here!

The answer is a bit boring: the expenditure definitely has helped customers - in that, they're using AI generated responses in all their work flows all the time in the app, and barely notice it.

See what I did there? :) I'm mostly serious though - one weird thing about our app is that you might not even know we're using AI, unless we literally tell you in the app.

And I think that's where we're at with AI and LLMs these days, at least for our use case.

You might find this other post I just put up to have more details too, related to how/where I see the primary value: https://kenkantzer.com/gpt-is-the-heroku-of-ai/

Page 1 of 3Next →