567 karma · joined December 7, 2024
After they killed that and then stopped handing out free model access to users of every Cline fork for weeks following model releases, vibe coder hype moved back to Chinese models for cost and the SOTA models for quality.
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
But at the same time.... I had been doing nearly everything the iPhone could do in terms of raw functionality (plus plenty of stuff that took 1+ years to land on iPhones) on multiple different Windows Mobile and Palm smartphones pre-iPhone.
Saying pre-iPhone smartphones don't count because "ugly nerdphone with gross keyboard" is just as ridiculous as a "iPhone was overhyped and no better than existing smartphones" claim.
Apple created a device category within smartphones that then consumed and became what we now think of as a "smartphone" after iPhone and Android together strangled the first movers.
Like, the famous Steve Jobs "an iPod, a phone, an internet communicator" line was just listing standard smartphone features by that point. More or less the definition of a smartphone in fact.
And, lest you think generating "600,000 lines of production code in 60 days" [2] is potentially problematic, has also fully solved the primary failure modes of AI coding identified by Andrej Karpathy, once and for all: "Karpathy's four failure modes? Already covered." [1]
As someone who has experienced mania, including with a programming bent specifically, it's hard not to raise an eyebrow at the idiosyncratic human-y bits of his thinking floating up from the sea of em-dashes and it's not X it's Y in his manifestos.
Plus volunteering this [3] in an interview:
“I sleep, like, four hours a night right now,” he told his interviewer, fellow VC Bill Gurley, during an onstage interview Saturday. “I have cyber psychosis, but I think a third of the CEOs that I know have it as well,” he joked about his current AI obsession. (Tan’s assistant confirmed to us that he was joking. ...)
It’s like I was able to re-create my startup that took $10 million in VC capital and 10 people, and I worked on that for two years, and I took anti-narcoleptics — I remember, you know, sort of being on modafinil...
[1] https://github.com/garrytan/gstack
[2] https://github.com/garrytan/gstack/blob/main/docs/ON_THE_LOC...
[3] https://techcrunch.com/2026/03/17/why-garry-tans-claude-code...
Like, thanks, really useful stuff (and definitely worth the creepy vibes to include that).
It sounds like Github Actions is the first choice, if it's unavailable (or if Github blocks GhostBox in the future), are each of the alternatives viable as a more or less drop-in replacement? Or would there be loss of functionality?
Those are the questions I had when reading through the site so I think some basic technical docs would go a long way to help people understand the project and decide to give it a try. I like the cute/whimsical branding but I'll admit to doing a little internal eye-roll when I clicked that link expecting technical specifics and instead read:
> GitHub Actions is only the first place ghosts come from. There are strange little pockets of temporary compute all over the internet. Ghostbox makes them feel like one small machine.
It's a neat idea though, and I've definitely had moments where I wished I could just spin up a free, temporary VM/container to do something but didn't feel like researching the current free-tier landscape and filling out a sign-up form and stuff. > They were always in harm's way. The war could have waited, and Iran could have doubled or tripled its missile stockpile and then they really would have been in harm's way.
I keep hearing this line defending US intervention but it doesn't really make sense. Iran was not threatening shipping traffic in the strait regardless of how many missiles they stocked up until they were forced to do so as an asymmetric warfare response to an attack by a superior military.The missing ingredient has never been how many missiles Iran has stockpiled, it was external military action from someone like the US that gave them the window to assert that control.
The US didn't do the world any favors by getting it out of the way sooner or something, that's just absurd apoligism for a poorly planned war of choice that has obviously been a net negative for basically the entire world.
It would be like if the US nuked China and then shrugged after they predictably retaliated saying it just proved the threat from their stockpile that had always existed.
Previously a quick scan of comment history would make it obvious you're looking at an LLM, now you're stuck arguing over a one off comment where they can get away with benefit of the doubt.
> Importantly, journalists in media, classically inept at any economic analysis, implied that 10% tariff = 10% RRP rise. They never corrected themselves, nor for the economists who falsely claimed the economy would collapse.
This is irrelevant to the discussion in the article, which is specifically about refunding a portion of whatever amount a company receives back from the government to customers.It's also pretty vague without any examples of what specifically deserves corrections.
https://openai.com/index/scaling-trusted-access-for-cyber-de...
> We are expanding access to accelerate cyber defense at every level. We are making our cyber-permissive models available through Trusted Access for Cyber , starting with Codex, which includes expanded access to the advanced cybersecurity capabilities of GPT‑5.5 with fewer restrictions for verified users meeting certain trust signals (opens in a new window) at launch.
> Broad access is made possible through our investments in model safety, authenticated usage, and monitoring for impermissible use. We have been working with external experts for months to develop, test and iterate on the robustness of these safeguards. With GPT‑5.5, we are ensuring developers can secure their code with ease, while putting stronger controls around the cyber workflows most likely to cause harm by malicious actors.
> Organizations who are responsible for defending critical infrastructure can apply to access cyber-permissive models like GPT‑5.4‑Cyber, while meeting strict security requirements to use these models for securing their internal systems.
"GPT‑5.4‑Cyber" is something else and apparently needs some kind of special access, but that CyberGym benchmark result seems to apply to the more or less open GPT-5.5 model that was just released.https://lundi.am/The-Black-Masses-of-Michel-Foucault-the-Bul...
Plus as others noted, even if true your original statement would still be a lie since a Panopticon is a concept not a person.
... and would then forget to use it 1/5 times and break auth/sessions in new code handling by using plain fetch.
Plus given time constraints, they generally wouldn't try to cram huge amounts of tiny text into every visible inch of the page without some intentional reason to do so (using that somewhat hard to read console-ish font Claude seems to love as a default).
Maybe the dark mode/terminal font/high text density look presents as "cool looking" at first glance for one-shotting evals so they've all converged on it. But to OP's point, this seems like a solvable (or at least mitigable) issue if models or harnesses were concerned about it.
But I picked it up again about a month ago and I have been quite impressed. Haven’t hit any of those frustrating QoL issues yet it was famous for and I’ve been using it a few hours a day.
Maybe it will let me down sooner or later but so far it has been working really well for me and is pretty snappy with the auto model selection.
After cancelling my Claude Pro plan months ago due to Anthropic enshittification I’ve been nervous relying solely on Codex in case they do the same, so I’ve been glad to have it available on my Google One plan.
Since you'd still end up having to build a gigantic heat exchange setup with steam turbines, pipes/ducts/pumps, generators, valves, gauges, vents, maybe even a cooling tower, etc. Plus a labyrinth of catwalks, ladders, access tunnels for workers in hard hats servicing/inspecting/replacing stuff who are on-site 24/7 and exposed to non-trivial occupational hazards dealing with superheated liquids at high pressure every day.
The entire concept of a steam turbine is just fundamentally a big hassle compared to an inexpensive solid state slab + batteries that are modular and basically plug-and-play by comparison.
A confused user will likely hit the only available button to "Cancel" which ends the process without granting any permissions.
By design it's a more conservatively designed approval prompt compared to e.g. accessing a camera or microphone where users get presented with a equally weighted "yes/no" decision.
Also, the website can't enumerate connected devices until access is granted individually. The API call to request a device allows filtering by pre-defined vendor IDs, but with no visibility into what's connected. Meaning an attacker has to choose between:
1. showing a list of a half dozen options, which will confuse the user and likely make them cancel, or 2. narrowly target it hoping for a single result to improve odds they blindly choose it, which increases odds no devices will appear at all.
And since they can't enumerate devices until granted access, that prevents a targeted attack with e.g. a red flashing "WARNING: Your computer is infected! Pick 'USB 10/100/1000 LAN' and click 'Connect' to erase viruses immediately!"
> you request webUSB access maliciously to some random device
> an unsavvy user is likely to click ok
That's not how WebUSB works, the user always has to pick the device themselves from a list. The list cannot have a device pre-selected, and the "Connect" button is greyed out until the user makes a choice themselves.The default "wtf? get this out of my face" path for a confused user is "Cancel".
The list can be filtered with vendorId filters defined ahead of time, but even if only a single device qualifies the user still has to chose to click it to enable the "Connect" button.
Once a device has been selected, it is considered "paired" to that specific site and the site can see its presence if available on future page loads. The user can revoke access/"unpair" from the site permissions button.
See example below of the pairing process:
Actual artists who need years to create a few hours of handcrafted content don't have a chance in an environment where hundreds of hours of slop can be generated in less than a day for a few hundred bucks. Platforms like Deezer recognize they need to address that imbalance somehow or they'll eventually lose their high quality contributors in a vicious cycle if it becomes impossible to compete.
Of course, it wasn't nearly as effective back then compared to current SOTA models, but none of those are hard to imagine someone recommending Cursor for anytime in 2024 or later.
If OP instead said something like one shotting an entire line of business app with 10k LoC I would agree with your reminder about perspective. But it feels somewhat hype-y to say that goal posts are being moved "monthly" when most of their list has been possible for years.
But I can't quite decide whether this post being so conspicuously incongruous with the rest implies it's an exception and more likely real... or if the overall trend of posting low-effort SEO spam makes it probable that this, too, is simply marketing slop, just prompted for attention grabbing clickbait instead of inbound filler.