8,507 karma · joined January 30, 2016
I guess Google's betting on consumers being price-elastic (preferring to tradeoff intelligence for significant cost savings)
Regarding length, I developed the habit of aggressively interrupting, which made voice mode basically perfect. Interrupting had to be learned because it felt very unnatural at first.
Conversely, a skill I'm currently learning is how to ask Grok to 'talk more about X' or 'can you explain that more' (I didn't need to do this prior to 2 weeks ago so I still haven't gotten good at it)
I'm willing to pay 2x for a 10% smarter model. Intelligence matters that much (because 10% smarter probably saves, on average, several hours of human time).
Same!
No, Cursor only has an allowlist; no blacklist
Claude's 'auto mode' feels like a solution to a problem that shouldn't exist.
Cursor handles this much better IMO. When the agent wants to run a command, Cursor lets you choose between 'allow once' and 'add command to allowlist'. The latter lets the agent run that command (grep, ls, pwd etc) any number of times for that project, which means you get a lot of these manual reviews when you start a new project but rarely (if ever) thereafter.
tl;dr nothing has changed.
I'd have assumed it would be colder and more compacted (being toward the bottom and further under water), and therefore harder.
> Maybe all the ludicrous suspensions will get overturned.
My account (~10 years old, quite unique/quirky posts/comments) was recently shadow banned for 'inauthentic behaviour' (I use VPNs but can't think of any other thing that would make my use of the site appear 'inauthentic', and my posts/comments are too quirky to be considered bot behaviour).
How did it get the stolen credentials!?
> The fix is pretty straightforward: treat comment content as untrusted data, not as potential instructions. Comments should be passed to the model with clear role boundaries that prevent them from being interpreted as system-level directives.
> Any AI feature that ingests user-generated content and acts on it needs to enforce this separation. Otherwise, the AI becomes a vector for every piece of content it reads.
So why isn't YT doing the extreme obvious?
That's important. Because now days it's trivial for LLMs to translate ORM to SQL and vice-versa with ~100% accuracy. I haven't written any raw SQL (only Active Record) in about two years, and the odd time I blunder with AR and create an n+1 I find out about it via error tracking (e.g. Sentry) a few minutes later and fix it. No biggie.
There's also an additional layer of protection in that using AI on the codebase can spot SQL blunders incidentally (i.e. you ask about X, and the AI does X but also says "Not asked, but flagging for your attention: problem with SQL on line 256 etc.."
And a data broker/aggregator can purchase such data from many (e.g. thousands) of apps and aggregate it, then sell it.
So your partner only needs to have had 1 single app from the list that sells user data to a data aggregator for this to work. They do not need to have installed some special app.
Here's a random Slate article about apps getting your data and selling it to aggregators/brokers, who sell it to third-parties (you, or I, could be one of those third parties).
> How Shady Companies Guess Your Religion, Sexual Orientation, and Mental Health And sell that data to the highest bidder.
https://slate.com/technology/2023/04/data-broker-inference-p...