HNHacker News
TopNewBestAskShowJobs

thewebguyd

6,804 karma · joined March 22, 2024

submissionscomments
thewebguyd··on Apple Retires iPhone Upgrade Program for Klarna-Backed Leases
Carrier financing is so popular in the US too, it only makes sense for Apple to take a piece of that pie and let users go directly to Apple instead of through the carriers.

What worries me is that this spells further price increases across the lineup, and the leasing option is serving as a way for consumers to be able to stomach the ever increasing price of RAM. There's going to be a limit to how expensive these products can be before sales start really suffering and moving to hardware-as-a-service extends that runway even further.

thewebguyd··on Google's Beyond Zero: Enterprise Security for the AI Era
I don't think Google are advocating for removing the deterministic controls, are they?

Sounds like adding the LLM in would be on top of the existing deterministic controls.

Existing controls handle the "Should you be able to access this resource right now?" the LLM handles "Is this user behaving as we expect them to while accessing this resource?"

thewebguyd··on Google's Beyond Zero: Enterprise Security for the AI Era
Correct. In existing zero trust identity, we already have deterministic risk signals.

In Entra where I work we already check things like "Is this person on a managed device? Is it compliant? Where are they? What MFA methods do they have registered/did they use?" on top of existing RBAC, etc. and its continuously evaluated. Entra watches for leaked passwords, assigns risk scores, etc. and you can make access decisions based on user risk or sign in risk, force password changes, require different MFA methods depending on the resource and the risk level, etc.

"Should this API call on this resource be allowed right now?" is mostly already determined by the above.

Where I see adding AI into the evaluation is to watch for unusual behavior that's not picked up by the deterministic signals. "Alice is trying to download gigs worth of data from the company file share, however she has never done that in the past, and there hasn't been any recent role/job changes" and so the LLM flags it or denies the request, or pushes it for a human approver, etc.

thewebguyd··on Google's Beyond Zero: Enterprise Security for the AI Era
The weird IP would already be handled by existing zero-trust controls. Users in Entra ID (for example) can be assigned a risk score already based on deterministic factors. On a managed device or not, which MFA methods they have registered, eligible for any privileged roles, where they are, impossible travel detection, etc. You can even require human approvers.

This reads to me to be more for continuous behavioral monitoring once the access is gained via the deterministic controls. You wouldn't leave "Can person X access resource Y" up to the AI model, that's already decided based on the existing rules. Where the model comes in is "Is person X behaving in an expected way while using resource Y." Like, downloading a bunch of data when they've never done that before, might get flagged for either a session revocation, or a human review, or prompt for additional authentication, etc.

thewebguyd··on Nvidia's $750B in Deals Reignite Circular AI Fears
> How do you lose in this market if you do gpu?

You don't. Nvidia gets paid either way. They were never the ones in danger (outside of the buildout going bust and having a massive surplus of cheap, used GPUs flood the market).

> You can debate that llm producers will go bankrupt, some of them at least for sure.

And that's the risk that will cascade down and kill off a bunch of companies and cause a debt crisis. If (for example), OpenAI goes to Oracle and says "I promise I'll pay you, at some point in the future, $1T to build my datacenters" and then Oracle funds that build out with debt, and then OpenAI goes bust, or just doesn't make enough money or can't raise enough cash to start making payments on their IOU, Oracle now also can't pay their debt and will eventually go bust, and now the private credit market takes a huge haircut, potentially bankrupting entire funds (like what happened in '08).

thewebguyd··on Nvidia's $750B in Deals Reignite Circular AI Fears
> all you need to do is take those profits and give them to your customers to buy more things

Those customers aren't buying Nvidia chips with Nvidia's money. They're using Nvidia's equity check to finance debt, and then using debt to buy the GPUs. Nvidia invests $1B in someone like CoreWeave, CoreWeave then takes that check, goes to PE a borrows $10B w/ the GPUs as collateral. Nvidia basically paid $1B to get $10B in sales, and now CoreWeave is saddled with debt based on an IOU from the AI labs.

Nvidia is insulated from the debt exposure, but the companies doing the datacenter build outs are the ones in real trouble if the house of cards comes falling down.

thewebguyd··on Nvidia's $750B in Deals Reignite Circular AI Fears
No, Nvidia is getting paid. Nvidia puts down a fraction of equity cash, and the recipients are taking that to PE to finance debt, using the GPUs as collateral. So Nvidia pays $1B, receiving company uses it to secure $10B in debt and buys $10B worth of GPUs.

Nvidia gets real cash, pays TSMC, etc.

The people in real trouble are companies like CoreWeave, Oracle, etc. that took an IOU from OpenAI (for example) to start a buildout, entirely debt financed. It works out so long as demand keeps going up, but the moment the music stops and that debt comes due and there's no revenue to pay it, game over.

Nvidia's concern isn't not actually getting paid, it's being faced with a glut of cheap, depreciated GPUs flooding the market impacting their future revenue. They'll live.

But OpenAI, not being able to pay CoreWeave, for example, that IOU, and then private credit coming for the debt payments from CoreWeave, is what would start the chain reaction. We may actually get to live to see Oracle fall.

thewebguyd··on Nvidia's $750B in Deals Reignite Circular AI Fears
Right. The risk isn't accounting fraud, its the equity-to-debt loop that relies on all these companies making "enough money to pay it back someday."

Nvidia invests, that equity check gets used to secure 10x it in debt with the GPUs as collateral, and then they buy the chips.

Nvidia gets paid, so they don't hold the debt liability. But, if AI revenue doesn't cover those debt payments before the GPUs depreciate, the loop starts to unravel, and fast. CoreWeave, Oracle, all the "neoclouds" etc. will blow up, and there could potentially be a ton of PE debt that is now under-collateralized due to depreciation, causing a pretty big haircut to basically all of private credit.

thewebguyd··on Apple Will 'Watch Everything Burn' When the AI Bubble Bursts
> is AI like that where most users will get bored?

User's getting bored will also spell trouble for the subscription model. I don't think we'll see a world where the average normie is going to be running agents in a loop overnight to make software. They'll get bored use it to cheat on their homework and as a Google replacement, generate silly images for a week then get bored of that, and then realize the have no actual reason to be spending $100/month and drop down to a lower tier or just cancel all together and live within the free-tier limits.

So if that happens, the labs are now left only with power users that can actually generate asymmetric cost. The market will bifurcate into free-tier users and "get their money's worth" users. So the risk isn't that the top 5% of users use more tokens than the subscription has any right to give you, it's that everyone else cancels their plans and only those top 5% of users remain.

The labs will have to put stricter rate limiting and token limits on the subscription plans to avoid MoviePass style burn.

Gyms get away with it because most don't let you cancel easily. You pay monthly, but are locked in for 6 months or a 1 year at a time (Adobe subscription style). Maybe the labs will start to do the same? Let you pay $20/month, but you are forced into an annual commitment?

thewebguyd··on Apple Will 'Watch Everything Burn' When the AI Bubble Bursts
> It very well could crash the consumer hardware market as a result

Tbh, I hope it does. Prices are outrageous, and I'm a firm believer in personal computing/having access to powerful hardware, privately and locally, is hugely important.

On a more selfish note, I miss the days of being able to build an outrageously powerful desktop for myself for relatively cheap. For now I'm still holding onto my AM4 motherboard w/ 64GB DDR4 and an aging GPU, praying my 7 y/o GPU holds up long enough for prices to drop again.

thewebguyd··on US citizen charged after GrapheneOS phone wipes during airport search
Right, these goons are hand searching through phones specifically to find something, anything, they can use to make your life suck and detain you further.

A pin that boots into a dummy account, full of benign messages, photos, innocent web browsing, etc. is going to get you a pass. They'll flip through everything and get bored after a minute of not finding anything.

Far less likely to aggravate them than wiping your phone

thewebguyd··on AI companies spend record sums on Washington lobbying
Right. That's what actually buys you the politician. Being able to promise "Pass this regulation for us and we'll make sure you are set up for life, since we know it's politically unfavorable"

the ~$2M just gets your foot in the door, that's it.

thewebguyd··on Apple Will 'Watch Everything Burn' When the AI Bubble Bursts
Interestingly, that METR study has updated data for 2026 that shows a speed up, although they admit that the data may not be reliable because of changed pay rate for participation, but this quote is telling:

> The primary reason is that we have observed a significant increase in developers choosing not to participate in the study because they do not wish to work without AI, which likely biases downwards our estimate of AI-assisted speedup.

So compared to just last year, they had a hard time finding participants because too many didn't want to work without AI.

thewebguyd··on Apple Will 'Watch Everything Burn' When the AI Bubble Bursts
Unpredictable AWS bills are a supply-side problem. He's talking about consumer behavior, and consumers of software do not expect a metered service.

But most consumer's aren't paying per token for access to models, so unless that changes and the labs start charging API pricing to everyone, it's kind of a moot point.

thewebguyd··on Open-weight AI is having its Kubernetes moment
Everywhere, huh? Still plenty just running on VMs or serverless that don't need full blown container orchestration.

I'll agree that (nearly) everyone should know when Kubernetes is useful, but let's not pretend its the default method for everything. Even then, choosing to deploy on K8s falls on the sysadmins/DevOps I wouldn't expect the devs know or do much more than provide the Dockerfile.

thewebguyd··on Open-weight AI is having its Kubernetes moment
> if you really want Kimi K2 instead of K3 you can still use it.

I think this is a very important aspect, especially after the huge GPT-4o backlash when GTP-5 came out. Each model has certain quirks, and areas where the previous model might be better for some use cases than the latest and greatest, and the labs so far seem to have no desire to offer some kind of "LTS" release.

thewebguyd··on Android may soon restrict on-device ADB
> why not allow developers to restrict access localhost?

Ads and tracking, obviously (https://localmess.github.io/)

All these changes Google is doing to Android aren't for you as the user, they are to protect their business interests from the user.

thewebguyd··on If coding has been solved, why does software keep getting worse?
> replace management with leading engineers

Wasn't this the whole point of agile and self organizing teams?

Then managers with 10 different PM* acronyms in their email signature got hired in, with no engineering experience, to lead product and software teams?

thewebguyd··on If coding has been solved, why does software keep getting worse?
Windows 8.1 was pretty solid, if short lived. New task manager, overhauled file copy, better SSD support & HiDPI scaling/multi-monitor support was hugely improved over 7, 8.1 also improved the window snapping and fixed the horrible table UI for it from 8.0

8.1 also ran faster than 7 on a lot of machines, they did a lot of work to optimize it for the crappy tablets which translated well to desktop.

Also the last version of Windows that you could opt-out of telemetry with (until Microsoft backported 10's telemetry engine to 7 and 8.1 via optional update)

thewebguyd··on If coding has been solved, why does software keep getting worse?
> defaults of hiding all windows for an application behind it's icon in the dock never made sense to me

Not that it's a better workflow, but macOS does make a distinction between hidden and minimized. You can "hide" an app, and all windows will be hidden, only the dock icon showing. Minimize will move that specific window into a separate area onto the dock since macOS treats apps & windows as separate entities.

What I absolutely hate though is you can cmd+tab and bring out a hidden app (but it restores all of its windows which drives me nuts), but you can't for a minimized app without holding option before releasing the keys.

thewebguyd··on If coding has been solved, why does software keep getting worse?
KDE is great, but

> The computer also just obeys me. It does exactly what I tell it to, and nothing more.

Is the biggest benefit and point. You can toss whatever UI/workflow style you want on top of pretty much any distro. I absolutely cannot stand the loss of user agency on modern software/operating systems. I have to use both macOS and Windows at work and I hate them almost equally (I hate windows a little more than I hate macOS, but because of Microsoft's behavior, not because of the UI).

I feel like every piece of commercial software and OS now is like Blizzard "You think you do, but you don't"

thewebguyd··on If coding has been solved, why does software keep getting worse?
> was to bundle all changes in "required security updates."

Kind of...Cumulative Security Updates on Patch Tuesday still do not contain new OS features, and on pro editions of windows you can at least, last time I used Windows (maybe this changed?), still skip quality updates & feature updates.

What Windows does do is tie all the "connected experiences" crap to out of band updates via the store/AppX packages which background update automatically, so when you reboot after a patch windows will run its post update OOBE and push all those features agian/turn them on. So technically not bundled with security updates, but a dark pattern that disrespects users nonetheless.

thewebguyd··on Nvidia, Microsoft, Meta warn against overregulating open-weight models
And yet ~64+% of the US makes less than $74k/year. The median, once you filter out part-time and seasonal workers is ~$65k/year.

You're right, they are not good salaries but they are the reality of wages in the US outside of the SF/NYC bubble.

thewebguyd··on Nvidia, Microsoft, Meta warn against overregulating open-weight models
> you are saying these companies are significantly overvalued at present.

I do lean toward them being significantly overvalued at present. OpenAI & Anthropic's valuations assume high margin product pricing on raw intelligence itself. Even if assume the labs will start charging value-based pricing, enterprise buyers will pay that pricing to whoever saves them engineering hours to make any cheap model work inside their compliance boundary, no guarantee that's going to be OpenAI or Anthropic.

Microsoft wins either way, proprietary, expensive models or cheap commoditized inference, because they monetize the workflow on top, not the raw intelligence. I also happen to think it's everything "on top" where a lot of value lives. Plenty of non-tech enterprises and companies out there itching for a ClickOps style AI product, especially if they don't have an engineering team, that they can buy off the shelf, meets all the compliance checkboxes, and does what they need without having to build the agents and harnesses themselves with the APIs.

thewebguyd··on Nvidia, Microsoft, Meta warn against overregulating open-weight models
> but I suppose that they might promote self-hosting on some kind of instances rented from Azure.

Yeah, Microsoft wants to sell Azure compute. They also want to sell their upcoming surface ultra hardware with the Nvidia chip in it. They preached hard on "unmetered intelligence" at this year's BUILD conference, went hard on local AI, and Azure Foundry, Windows Foundry Local, etc.

Copilot, both GH and M365, are also made to be model agnostic. Microsoft sells enterprise services and software, they'd prefer (I'm assuming) to not be locked in and dependent on any 1 or 2 model providers and would prefer plenty of options and competition in that space because they can just easily offer a model agnostic harness, integrated with the rest of their stack.

thewebguyd··on Nvidia, Microsoft, Meta warn against overregulating open-weight models
Not entirely, if models become commodity, then Microsoft's play as an infrastructure & enterprise apps company is the better bet. They don't need to make profitable mass-market AI models, they just need the best tooling on top of any model their customers pick, remaining fully model agnostic.

"AI Product" doesn't necessarily mean "We sell API access to a our models." Ton of companies out there itching to buy a commercial off the shelf product to deliver whatever AI capabilities they need packaged in a nice GUI, with enterprise governance controls, without needing a dev team/team of engineers to integrate it or develop harnesses, etc.

Buy it->have IT click a few buttons in an admin console->Deploy and have it be immediately useful is the play.

thewebguyd··on Nvidia, Microsoft, Meta warn against overregulating open-weight models
It's also a completely normal salary for non-dev, non-IT roles in most of the US that aren't major HCoL cities, which are the roles I was referring too mostly where the cost tradeoff of AI vs. Hiring humans isn't as clear cut as the labs marketing departments want everyone to believe.

Even in the US, only about 23% of workers earn $100k/year or more.

According to the US BLS, the median income for "knowledge workers" is ~$65k-$72k/year.

People in SF, NYC, etc. live completely different lives from the rest of the country.

thewebguyd··on Nvidia, Microsoft, Meta warn against overregulating open-weight models
Yeah, correct, I wasn't thinking of devs specifically, more other office/administrative roles threatened by automation. Even where I live in a relatively HCOL area, any non-dev office role you can still expect to see a$65-$80k salary range, and $80k is pushing toward the top end for non tech roles.
thewebguyd··on Nvidia, Microsoft, Meta warn against overregulating open-weight models
55k is low for a dev, but not for a ton of other office/administrative roles that are threatened by AI automation.
thewebguyd··on Nvidia, Microsoft, Meta warn against overregulating open-weight models
Maybe for startups or simple orgs, but in any regulated industry/high compliance requirements they are still useful or outright required.

Claude Team w/ Cowork still only lets you set R/W permissions globally for each MCP connector for the whole team, they still don't offer config on a per-user basis. The enterprise controls are sorely lacking first party. Maybe fine for most startups or flat orgs, but any established enterprise with strong identity & access governance is going to have an issue with that. You can make it work, but you need to make your own agent/harness and give it an identity in Entra or whatever else you use, so for a non-tech company without a dev team, right back to square one of preferring to just buy a COTS solution vs trying to hand out direct model access with minimal governance.

(M365) Copilot sucks but Microsoft is putting a ton of work into agent governance & identity that sorely lacking elsewhere.

← PreviousPage 4 of 34Next →