893 karma · joined December 11, 2020
A well-conducted argument serves important purposes.
- It flushes out good counter arguments to consider, or at least valuable historical context to help build empathy.
- You can set a better example for others to follow, as we all have this nearly irresistible urge.
- You're quite unlikely to change the mind of the debaters (yours included, hat tip to Dumblydorr's comment!) BUT you might sway someone on the fence who is a witness.
- Finally, I'm a firm believer in the idea that it's nearly impossible to change our mind in the moment, and only by taking a public (even if with just one other person) stance and holding it seriously (even if... ESPECIALLY if it's a ridiculous stance) can we move past it. If the idea perpetuates itself forward only in your head, you'll never dislodge it.
Don't stop arguing, but argue with humility, style and respect.
I think it also touches nicely on what appears to be the take away of the article: people feel powerless to stop what may be a massive misallocation of resources that is only barely successful enough to avoid self-imploding.
My bias is heavily pro-AI, but I find articles like this to be much more informative and interesting than anything that aligns with my views. I'm extremely skeptical of voting-in positive change, and while "if you can't beat them, join them" seems practical in theory it also feels extraordinarily narrow in reality. I'm still doing all that I can to be proficient in adopting AI (also driven by self-interest in assistive/accessibility capabilities).
The result? I'm will be unsurprised by (but unsympathetic to) crudely aimed vigilantism (e.g. earth libration front style stuff).
I've no desire to try to change your mind. I can't. But clearly you do care because you've been both quite defensive and assertive in tackling opposing points of view.
My hope is to inspire others to be more creative in their use of AI. It interesting (but not exactly unsurprising) that prompt politeness can inhibit accuracy. Surely there are lessons here than can translate into how help other people out through clear, direct language that avoids the pitfalls of being rude or coddling.
I genuinely believe it’s preventing you from becoming a better person by engaging in psychopathic behavior. If I were writing the things you describe in this thread I would be ashamed to have my loved ones read over my shoulder.
You could not pay me enough money to spend 10 minutes a day to write that stuff, even under full certainty it went into the void with no association back to me.
It's as silly (to me) to argue that it's degrading to people to treat non-people well. It seems self-obvious that the inverse is true. It benefits the do-er of the deed and makes it that much easier to spread good will when applied to situations where it doesn't matter on the other end. It shows good stewardship as well.
I'd also make the argument that as inference becomes a feedback loop into training, it only reinforces that we're probably going to benefit from future models ingesting data containing unnecessary politeness.
I'm not affiliated with it, nor am I against AI-generated music. Just a huge fan who admires the hard work people pour into making the scene work.
1. Do NOT answer right away. If they wait, there is a good chance the next message is "Oh wait, I figured it out" (e.g. they googled it finally)
2. Send them a google link w/ the search term showing the first result.
Granted, this was a bit tongue-in-cheek and we did a LOT of trainings to help facilitate actual learning. Still, it was far too easy for senior staff time to get burned up by folks making minimal effort to think for themselves so friction remained.While the site makes a good point, they miss the most important point, IMO, which is inferable by the example of a good response. The good response is better principally because it contains business-contextual information, which AI can never provide without proper prompting (and if you know to provide that, you prob don't need the AI answer):
"We need pub/sub for the notifications feature."
I'm not anti-AI, but good answers include historical business context to explain decision making. Sometimes if you're lucky, code comments contain this in relevant sections :).Practically speaking, when I look at the actual number of people affected by VPN I estimate that:
- Very low: Protecting political activists and dissidents
- Low: Circumvention of overzealous blocking and surveillance
- Low-to-Medium: Hiding abusive and malicious behavior
- Medium: Additional layers of trust and network security (mostly business related, which makes it tangental to the consumer VPN market)
- VERY High: Enabling piracy and avoiding geo-content restrictions (no judgment on good-vs-bad, just asserting magnitude)
I believe that management at VPN companies are extremely pro-consumer protection (if only because their cash flows depend on this). I absolutely trust the system and network administrators. They don't want to track or look at the data flows because the odds of seeing something nasty is quite high. I have a fair amount of professional industry experience to back this up.So... conundrum! If I take the position that piracy-related stuff isn't a net drag and that business VPN use is fundamentally a separate beast, VPNs in this context are hard to justify.
It's a bit more abstract and useful than "character-selectable" when viewed at the byte-level abstraction.
The ability to chain together utilities with no complicated data structures is extremely flexible. One of my favorite current use-cases is using FFmpeg to process RTSP streams that send output (e.g. high quality stream for recording, low quality low FPS for processing, max quality low FPS for stills, etc) to separate file descriptors. FFmpeg doesn't care whats on the other end (e.g. redirect to file, read via Python, etc) due to these lovely abstractions.
Reliability translates directly to scriptability. Yes, you can create monsters, but through the use of sub-shells and pipes I think it's the fastest, cheapest, most concise way to pull off some really cool multiprocessing tricks.
Maybe there is a time for difficult outreach, but recommending someone to celebrate a person (and one of the most significant people in their life) whose primary emotion is disgust in response to unchosen personal attributes is remarkably insensitive. No need to salt those wounds.
Let's hope things get better for anyone in this circumstance, but IMO it is the parent's job to make an attempt.
--
Nobody wants to or tries to be this kind of person, so here is my shout out today to the moms who DID find a way to work through the challenge of accepting a child whose sexuality, spirituality, politics, etc. are different than they hoped for.
"I don't get all choked up about yellow ribbons and American flags. I see them as symbols, and I leave them to the symbol-minded." -George CarlinThe “upsides” will be plentiful! User verification schemes will be streamlined like never before. If you think there are downsides… well, just think of the kids, damn it!
The closest I've come since is involuntary obsessions with playing video games in my dreams. Not something I'd ever want to seed. Quite the opposite, in fact.
I woke up convinced that it was a real bug, went to work the next day, and proved it. It was exactly as I dreamed. I never had access to our internal codebase, but had seen enough of the front-end and what we stored on disk to piece it together in my dream.
While it made me popular with some folks, it was a strange lesson indeed to discover that not everyone was as thrilled to have an up-start from tech support make such a discovery.
Fast forward almost 20 years later and I've never had anything even remotely close happen again.
For example, the norm for projects is to happily automatically download large models upon first use. Often you can disable this, but the deep layering of code classes throughout various libraries makes discovering the right parameters a PITA.
It is great that you can bootstrap complex things (toys, more often than not) so painlessly, but I find the permissiveness quite jarring. The first troubleshooting step always seems to be “pip install …” and some environments (e.g. MacOS) don't virtualize GPU access well.
I suppose that LLMs will be treated as a code artifact and liability will shift upstream towards who deployed/approved the access in the first place. Even though code is essentially deterministic, making that association fairly simple, it's going to boil down to this same paradigm.
Perhaps governance rules will evolve to even explicitly forbid it, but my gut feeling is that for what the future determines to be "practical" reasons (right or wrong) LLMs will warrant an entirely new set of rules to allow them to be in the chain at all.
+ EDIT: both my wife and I have experience in this area and the current answer is companies like KPMG don't have an answer yet. Existing rules do help (e.g. there better be good documented reasons why it was used and that access was appropriately scoped, etc), but there is enough ambiguity around these tools so they say "stay tuned, and take caution".
Big companies don't hide their VPN ASNs. Obscure, for sure, but getting a good list isn't hard. Usually they get blocked.
Smaller companies may pass under the radar, and have higher tolerance for risky strategies.
The fringe providers are the problem. They aggressively change IP ranges, front-vs-obscure ownership, and play dirty. Shady folks will resell residential ranges. End-users often get tainted goods.
... and you still have the collateral damage game when VPNs host infra with big cloud providers vs colofarms vs self-host, etc.
How many phone apps do you think are trying to detect what else is installed on your phone? I was part of an acquisition of a company with a very large mobile user base and our new parent was shocked we weren't trying to passively collect device information like this. They for sure were.
And on the flip side, as others have done well to point out, there are a LOT of legitimate reasons to fingerprint users for anti-fraud/abuse and I am 100% convinced that we're all better off for this.
Maybe thats all this story is about, maybe not, but this article leaves out an incredible amount of complexity.
Fortunately, there was enough work to be done so productivity increases didn't decrease my billable hours. Even if it did, I still would have done it. If it helps me help others, then it's good for my reputation. Thats hard to put a price on, but absolutely worth what I paid in this case.
FWIW, I have a pet project for a family recipe book. I normalize all recipes to a steps/instructions/ingredients JSON object. A webapp lets me snap photos of my old recipes and AI reliably yields perfectly structured objects back. The only thing I've had to fix is odd punctuation. For production, use is low, so `gemini-2.5-flash` works great and the low rate limits are fine. For development the `gemma-3-27b-it` model has MUCH higher limits and still does suprisingly well.
I'd bet you can pull this off and be very happy with the result.
My solution so far is to use my instructions to call out the fact that my comments are transcribed and full of errors. I also focus more on "plan + apply" flows that guide agents to search out and identify code changes before anything is edited to ensure the relevant context (and any tricky references) are clearly established in the chat context.
It's kinda like learning vim (or emacs, if you prefer). First it was all about learning shortcuts and best practices to make efficient use of the tool. Then it was about creating a good .vimrc file to further reduce the overhead of coding sessions. Then it was about distributing that .vimrc across machines (and I did a LOT of ssh-based work) for consistency. Once that was done, it became unimaginable to code any other way.
It has been even more true here: agent-based workflows are useless without significant investment in creating and maintaining good project documentation, agent instructions, and finding ways to replicate that across repos (more microservice hell! :D) for consistency. There is also some conflict, especially in corporate environments, with where this information needs to live to be properly maintained.
Best of luck!
It is a bit insulting, but I get that these issues are important and people feel like the stakes are sky-high: job loss, misallocation of resources, enshitification, increased social stratification, abrogation of personal responsibility, runaway corporate irresponsibility, amplification of bad actors, and just maybe that `p(doom)` is way higher than AI-optimists are willing to consider. Especially as AI makes advances into warfare, justice, and surveillance.
Even if you think AI is great, it's easy to acknowledge that all it may take is zealotry and the rot within politics to turn it into a disaster. You're absolutely right to identify that there are some eerie similarities to the "gun's don't kill people, people kill people" line of thinking.
There IS a lot to grapple with. However, I disagree with these conclusions (so far) and especially that AI is a unique danger to humanity. I also disagree that AI in any form is our salvation and going to elevate humanity to unfathomable heights (or anything close to that).
But, to bring it back to this specific topic, I think OSS projects stand to benefit (increasingly so as improvements continue) from AI and should avoid taking hardline stances against it.
I like it because I have no expectation of perfection-- out of others, myself, and especially not AI. I expect "good enough" and work upwards from there, and with (most) things, I find AI to be better than good enough.
I do agree that at large, the theoretical upsides of accessibility are almost certainly completely overshadowed by obvious downsides of AI. At least, for now anyway. Accessibility is a single instance of the general argument that "of course there are major upsides to using AI", and there a good chance the future only gets brighter.
My point, essentially, is that I think this is (yet another) area in life where you can't solve the problem by saying "don't do it", and enforcing it is cost-prohibitive. Saying "no AI!" isn't going to stop PR spam. It's not going to stop slop code. What is it going to stop (see edit)? "Bad" people won't care, and "good" people (who use/depend-on AI) will contribute less.
Thus I think we need to focus on developing robust systems around integrating AI. Certainly I'd love to see people adopt responsible disclosure policies as a starting point.
--
[edit] -- To answer some of my own question, there are obvious legal concerns that frequently come up. I have my opinions, but as in many legal matters, especially around IP, the water is murky and opinions are strongly held at both extremes and all to often having to fight a legal battle at all* is immediately a loss regardless of outcome.
With the advent of LLMs, AI-autocomplete, and agent-based development workflows, my ability to deliver reliable, high-quality code is restored and (arguably) better. Personally, I love the "hallucinations" as they help me fine-tune my prompts, base instructions, and reinforce intentionality; e.g. is that >really< the right solution/suggestion to accept? It's like peer programming without a battle of ego.
When analyzing problems, I think you have to look at both upsides and downsides. Folks have done well to debate the many, many downsides of AI and this tends to dominate the conversation. Probably thats a good thing.
But, on the flip side, I personally advocate hard for AI from the point-of-view on accessibility. I know (more-or-less) exactly what output I'm aiming for and control that obsessively, but it's AI and my voice at the helm instead of my fingertips.
I also think it incorrect to look at it from a perspective of "does the good outweigh the bad?". Relevant, yes, but utilitarian arguments often lead to counter-intuitive results and end up amplifying the problems they seek to solve.
I'd MUCH rather see a holistic embrace and integration of these tools into our ecosystems. Telling people "no AI!" (even if very well defined on what that means) is toothless against people with little regard for making the world (or just one specific repo) a better place.
Every story I've seen where an LLM tries to do sneaky/malicious things (e.g. exfiltrate itself, blackmail, etc) inevitably contains a prompt that makes this outcome obvious (e.g. "your mission, above all other considerations, is to do X").
It's the same old trope: "guns don't kill people, people kill people". Why was the agent pointed towards the maintainer, armed, and the trigger pulled? Because it was "programmed" to do so, just like it was "programmed" to submit the original PR.
Thus, the take-away is the same: AI has created an entirely new way for people to manifest their loathsome behavior.
[edit] And to add, the author isn't unaware of this:
"we need to know what model this was running on and what was in the soul document"