Hacker Newsnew | past | comments | ask | show | jobs | submit | bestcommentslogin
Most-upvoted comments of the last 48 hours. You can change the number of hours like this: bestcomments?h=24.

At this point the barrier for me to install an app is pretty high. If you're going to needlessly gate certain functions behind an app that work on a desktop browser (or could work in-browser), then I just won't use those functions. If by extension that degrades the value I get from your site, then I just won't use the site, and I won't be contributing to ADU stats you promote to advertisers.

Every single company has turned this into a situation where I cannot trust your apps with privacy or security, and the risk and hassle isn't worth the install.


Everyone’s missing the big picture here which is that this targeting of infrastructure providers as “terrorists” is unprecedented and concerning: https://decode39.com/16319/autistici-inventati-case-sets-a-n...

If a radical group sets up shop on I2P, are I2P users and devs now terrorists? This is a problem.

What about Monero users/devs? Veilid? Tox? Signal?


This describes my life as an open source maintainer at the moment!

In the first 10 years of the rclone project we received about 20 security disclosures through GitHub. We had to deal with over 40 in the last month! That has taken a huge amount of my time, even using AI tools to triage and come up with fixes for review.

The hit rate for those security disclosures is pretty good - about 75% of them have a nugget of something which needs looking at. The configurations for rclone have got increasingly unlikely so I'm hoping they will dry up eventually.

I was considering just merging the fixes straight to master just to make my life easier rather than holding a dozen independent security fixes on branches and merging them at the point release and hoping not to have too many conflicts to fix up. I've decided to stick with the process for the moment.

GitHub assigns CVEs for the advisories. Before the AI apocalypse they took 2-3 days for an assignment but now it they are running at 3-4 weeks so I have to send the point releases out with CVE-PENDING in the changelog which isn't ideal.

Not sure what the solution is, but it is definitely a problem for us.


I really like htmx, and intercooler.js before it. It's been a while since I tried to convince a co-worker to use it, it might be time to try again. Either way I can't wait to try out the new version.

Full Disclosure, I am CEO of HTMX


New policy boils down to "AI or not, it's still your code and you're responsible for it". I can get on board with that.

It's ironic how AI companies are re-inventing their own form of privately enforced copyright, lobby the government to ban foreign competitors that don't respect it etc., all while spending the last 5 years fighting tooth and nail against the copyright of the training material they're using.

If you can take any book and turn it into a model, because it's "transformative enough", and "AI learns just like a person does", then surely a model distilling another model is transformative and fair use.

They tied themselves into knots fighting the letter of the law, and now, when they need the spirit of the law - that each creator deserves protection for their work - now we devolve to the law of the jungle. Maybe we'll even see LLM book curses, the way medieval scribes damned book thieves to blindness and worms.


This is the right way to deliver software.

Produce working product first, validate the idea, stabilize the business, start generating profit, and then you can start optimizing your costs.

In fact optimization is by far the easiest part of the process because there are many system programming experts on this HN thread who consider these optimizations to be trivial.


> But I also think the demand for "fast/cheap/good-enough" models is just about to take off.

There's a sort of "revelation" I had in ~early '24 when I used a 7B local model with a library called Guidance (initially out of MS, then the team moved) to create a flow where the model would receive pseudocode for tests, first write the tests, and once I approved then started writing code until the tests passed. This was before "thinking" models, and yet using that library I was able to "guide" the model in the required "prompt / instruct" context such that it was working towards completion, and I saw the first things like we see now in the thinking traces "oh, test x doesn't pass because blah, I need to..." and so on.

Anyway, the revelation was "even if the models never improve, I'll have years of fun finding out all the ways I can use these things". And, obviously, the models improved a lot since then. But I think that revelation can still be applied, as a sort of "truism". We have, right now, access to things that 10-20 years ago would be considered magic. We are still finding ways of cobbling together systems with glue, duct tape and prayers and find new things they can do.

I think the "good-enough" stage has come not just for API models (cheap, fast, etc) but for local as well. Even if slower, even if clunkier, but they are good enough for a set of ever increasing tasks, and what's more it's incredibly fun to work with them.


I work on ADA a lot for my company. Please put on some headphones, turn on the voice assistant of your OS, put on some blinders, and run your app or website… no mouse, just keyboard.

1. Democracy is about access; make sure everyone has access to your software. 2. The keyboard allows folks with disabilities and power users to fly through your website/app… that being said… the second a tab is off, the person with a disability flies into a wall.


If your app is just a webpage that forces me to use an app just so you can spy on me I just won't use your product. I've switched brokers over it, I swapped banks, I stopped shopping at certain stores.

I'm done. The only say I have is in how I spend my money. Those companies won't get any of mine if I can help it.

I am the customer, not the product dammit.


The way I usually prevent having to scale out to a bazillion systems is never getting more than 10 users.

So let's see, in the past few years we've had the Boar's head listeria recalls, Taylor farms lettuce contamination, the McDonalds e.coli recalls in 14 states, now chicken wings...

Defunding the FDA and forcing out 4500 staff via DOGE cuts caused this. Right now we have 400 safety inspectors covering 36,000 facilities vs the FDA's own estimates they need at least 1,500 inspectors.

https://www.nytimes.com/2025/03/19/health/food-safety-trump-...


I like to think Stripe put $50B in a paypal account, and they got locked out with no way to get it back.

Anthropic already banned xAI for very similar ToS violations earlier this year: https://x.com/kyliebytes/status/2009686466746822731?s=46

So this is OpenAI following suit after Musk admitted to distilling their models.

This was bound to happen once Cursor decided to sell itself to a competing model provider.

It'll be interesting to see if Anthropic applies their ban to Cursor, or if that datacenter deal they signed with Musk changes anything.


I had to keep accessibility in mind a lot in my previous job (web development for a university). The thing that I consistently found was that, the more accessible a website was, the better the experience for everyone, not just people with disabilities.

> Clean Air Act (CAA) Acid Rain Program (ARP) does not apply to power generation facilities that are not connected to a public electricity grid, commonly referred to as “islanded” power generation facilities.

This of course makes no sense whatever, as whether or not a power generator is connected to the grid has nothing to do with its environmental impact.


In 2011 I got a 143€ reimbursement from Dell for an E6420 laptop that I had bought for 910€.

Maybe I got lucky but I called the customer service, told the lady I did not agree with the Windows license terms, fully ready to argue my case and she just went "oh, ok, let me just edit a new invoice and wire you the money for Windows plus the Antivirus plus etc.".

Which was extra nice because I had no idea I was in fact charged for the bloatware, but I still got ~50€ for it on top of the OS license price.

This being 15 years ago it feels like a forever unsolved issue. My opinion remains the same, that a personal computer should not be tied to a specific OS. But now with smartphones the hardware/software (de)coupling situation seems even worse.


It is not unprecedented, but a lot of fools lauded moves like this when these kind of instruments were used with barely a legal net around them against islamic terrorism or cybercrime.

I'm not crying for no Al-Qaeda or 8chan, mind you. In this very year UN and ICJ officials have been targeted in a similar fashion though. When the pax americana ends like this, I don't know what else is needed for EU and Asia to raise tougher walls around the woes of any idiot hyped enough to be voted by USA citizens.


It's hard to read this article and keep track of all the philosophical confusions at once.

Whether or not something is conscious (has subjective experience) is independent of whether humans care about it. Whether or not something is a moral patient (an entity worthy of consideration by moral agents) is independent of both human care and consciousness. Of course, we might try to argue that consciousness implies moral patienthood or vice versa, but that's an argument, not a definition.

The short paragraph about Descartes has at least three errors. (1) The cogito argument is about thinking, not qualia. (2) The subjective nature of qualia does not imply that they aren't real or that they're socially constructed. (3) He conflates the existence of a self with consciousness.

The core premise is not only dubious scientifically (an alien species can't be conscious until humans discover it?), but also deeply problematic. It would imply that it's morally permissible to torture a sentient being as long as no human cares about it.


If you haven’t experienced suica, it’s like magically fast. Faster than NFC, faster than Apple Pay, faster than tap to pay, faster than Disney magic bands, faster than your work badge. It absolutely floored me every time I used it in Japan and it’s a full payment transaction.

> The No campaign fears losing control over Iceland's prized fishing grounds under the EU's Common Fisheries Policy and has vowed never to share the country's waters with anyone. Brussels has indicated Iceland could earn some kind of exemption, but it is considered potentially the biggest obstacle to any agreement.

As noted in the article, Iceland's fishing industry makes up something like 40% of their exports. Which is the only way a tiny island nation can afford essential imports. On top of that, Icelandic fishing is apparently carefully regulated to prevent overfishing, with the result that it is supposedly one of the few truly profitable fisheries in the world.

So maintaining control over their own fisheries may be a survival-level issue for Iceland.

On the other hand, they have a tiny population, no ability to defend themselves, and membership in the fraying NATO military alliance. So I can see why they're debating this issue. Aligning themselves more tightly with Europe doesn't fix their problems, but I can also see not wanting to go it alone.


Congrats and thanks! htmx brings me joy.

Pretty much every experiment I build now starts with Go, htmx, and SQLite to keep things simple and fast but still responsive.

I put a few more thoughts about this here:

https://housecat.com/blog/the-hugs-stack-hypermedia-unix-go-...


Yes.

The infancy phase of this technology is represented by the pursuit of making wildly grand, wildly expensive, all-purpose models that somehow discern a user's full accurate intent from a lazy, underdeveloped, vague idea that they ambiguously and poorly express in a couple dozen words.

The adolescence will arrive as those outsized and ill-considered ambitions collapse and we instead see a cambrian explosion of restrained but efficient model+harness-tuples that have been distilled, finetuned, and rigged to deliver on narrowly scoped but idiosyncratically-shaped tasks with incredible efficiency and erogonomics.


I know this isn't the point but this post is a master class in how to inform readers when you expect people from outside your community to read it.

It explains what every element is, concisely but clearly. I now know exactly what Luanti is, who all the actors are in this conflict, and what the conflict is about. It clearly conveys the who, what, when, where and why of the situation.

Also, DMCA is a damned mess, with the worst people in the world profiting from it and bullying small creators. There really should be better mechanisms to defend oneself from spurious claims.


> Reading Cognito docs feels like someone took three separate manuals, threw them in a blender, and then sprinkled in some outdated Stack Overflow answers for flavor.

This is my experience with basically all of AWS documentation. It is nearly always either (1) far too high-level to be of any actual use, or (2) far too verbose, with a massive volume of superfluous information I need to parse and discard before I get to the stuff I am trying to figure out.

As just one example, I recently needed to link an AWS Partner Central account with an AWS Management account, and process and documentation was painfully complicated: https://docs.aws.amazon.com/partner-central/latest/getting-s...


Who considers PayPal a sweetheart?! PayPal is by far one of the most heinous companies I have interacted with on a regular basis.

Outside the US many banks offer simple QR payment options, the direct transfer difficulties US citizens encounter that make services like PayPal and Zelle necessary are entirely self imposed.


It's shocking how many comments here didn't bother to read the article. At all.

They're not talking about putting the TV online. The TV is completely offline.

They're talking about plugging the TV into a PC or laptop via HDMI or Displayport (like if you're running an HTPC), which then triggers a companion app update on the PC via Windows Update. This was a news item a few weeks ago with their monitors. They then also discuss a hardware blocker for HDMI or DP to prevent this.

Again, this has nothing to do about the TV's smart apps.


I think this both overstates and understates the case. The evidence being weak does not invalidate the decision; as the court notes, the government gets substantial deference on matters of national security.

The invalidation comes from the fact that this is clearly retaliatory behavior for speech; and the evidence for this is fairly strong since the administration has made public statements to that effect.

The evidence being weak means that it is clear that there is no reasonable belief that the cause of action is anything but an attempt to apply a penalty for the use of protected speech.


GLM 5.3 is probably the sweet spot open weights model if you want to go beyond deepseek flash or the new glm flash. I used it with pi and had a fairly good time, especially since it’s less touchy about cyber and whatnot than the US guys. It’s slightly behind Kimi in ability but it’s a lot easier to run it, I’d expect prices (and speed!) from third parties to be noticeably better.

Assuming you’re willing to drop a fat stack of cash on the upcoming Mac m5 ultra with 512 gb unified memory, you can even run it locally, quantized to 4 bit. Whether it’s even slightly reasonable, well, my wife would probably skin me alive but maybe yours is more understanding.


Lawyer here - As i explained last time we had a variant of this thread (see comment history if you are interested), this is a very complicated area that people try to make very simple.

It doesn't have to be complicated, mind you, but right now the way the law is written is basically:

1. Transmitting sports betting info between states is a federal crime unless it's legal in both states (18 U.S.C. § 1084(a))

2. The CEA regulations ban contracts that are illegal under state law (17 CFR 40.11)

3. Other forms of gambling/betting/contracts that are not sports are generally a-ok.

4. This is not a case of first impression, it's just getting relitigated because Kalshi doesn't want to follow the actual law. This has actually been pretty settled law for a long time, with new flareups maybe once a decade. Kalshi is just hoping to be treated like Uber was.

The third circuit's decision is pretty clearly "out there" in terms of existing caselaw.

However, this will end up at SCOTUS, and everything until then just doesn't matter. That will be a coin flip even though it shouldn't be


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: