170 karma · joined August 4, 2025
It's just a hobby for me (just $100/month in IAP revenue rn) but I really don't understand their system at all.
it's a real issue but I'm not sure it's the mass mobilization problem the article makes it out to be. pretty sure it's growing extremely fast, and it's a new field in general. the models will keep growing in capability because of human game theory (I need to make my model better because my competitors are). it's not practical to expect millions in headcount to move from frontier capability research to safety
I’m so tired of all this BS. Why did this become normal? and how do we not read this as cheap advertising?
They have been proven to: https://www.anthropic.com/research/small-samples-poison
The “bundle” or “context” is the value.
still, i use it every day and i don't see what replaces it. every "docker killer" solves one problem while ignoring the 50 things docker does well enough.
That said, their accuracy claims have been disputed before. Inside Higher Ed [1] reported that Turnitin's real-world false positive rate was higher than originally asserted, and the company declined to disclose the updated number. And, USD also noted that while Turnitin claimed <1% false positives, a Washington Post investigation found a 50% rate on a smaller sample, and that non-native English speakers / neurodivergent students get flagged at higher rates [2].
Now, those are from 2023 and the product (and AI in general) has been updated drastically since. But the broader incentive problem holds even if the detector itself is conservatively tuned. The product is a black box. And the downstream cost of errors falls entirely on students, not on Turnitin's renewal rate. You don't need aggressive tuning for the incentive structure to be broken.
[1] https://www.insidehighered.com/news/quick-takes/2023/06/01/t...
[2] https://lawlibguides.sandiego.edu/c.php?g=1443311&p=10721367
"useradd bob" is an "account setup". does that need age verification too? haha
Examples:
- ai.com launching with a super bowl ad and being taken down just from large sign up volume
- Taylor Swift drops an album on Spotify, everyone rushes to stream it, crashes Spotify
- random small websites get featured on reddit front page and get hit offline
> how large would the number of users need to be
depends on the target. small website on shared hosting could be hit offline by 1000 concurrent users. major platform might need millions of users concurrently hitting write paths, not just loading cached/static content. or all requiring open sustained connections
> what would they have to do
just all do the same thing at the same time.
> Have you noticed faster pace of development?
Yes, our org has had a 50% increase in PRs since Opus 4.5 released.
> Have you seen changes to code quality or code review?
Yes, significantly more bugs (no exact number), but consider it maybe 3-4x in volume. However, nothing catastrophic and everyone just uses AI for fast-follow fixes anyways. The company as a whole is embracing this style of development for better or worse.
> Do teammates that use these tools complete sprint tasks faster than those who don't?
Yes, but my entire team uses them. I’d say the ones who use it more effectively (crazy skill setups, better tooling/commands, better scaffolding) finish much faster. Probably 80% of my team still uses Cursor in the one-shot way with very vague requirements, and don’t have the AI connected to github, jira, slack, etc which can actually feed really important context into decision making.
If I do something more than once a day, I write a custom slash command for it. This has personally 2x’d my pace.
Is this product a ragebait/troll?
1) Account takeover of any user with just their email: POST /v1/account/recovery with any user's email, the API response gives you the plaintext recovery secret. Call PUT /v1/account/recovery with that secret + a new password. You now own their account. No email inbox access needed. Two curl commands.
2) Password hashes returned by the API: GET /v1/users with any API key returns every user's full argon2 hash, algorithm, and tuning parameters. tested and got $argon2id$v=19$m=65536,t=3,p=4$... for test@kraz.in.
3) CORS reflects any origin with credentials: Send Origin: https://evil.com to any endpoint — server responds with Access-Control-Allow-Origin: https://evil.com + Access-Control-Allow-Credentials: true. Any website on the internet can silently read authenticated API responses from logged-in users
There is literally like 50 more of these though. The author probably didn't spend more than 5 minutes on security hardening.