I have a kid with my partner and I'm still not sure it was the right decision for me. They do become a full-time job in their own right and there is a whole set of skills that you can kind of learn through books but is going to be unique to your little one.
The first couple of months were especially hard as they don't have much of a personality, don't really react much to the world around them, they're just feeding, sleeping, and growing. Starting at the beginning of the third month for me it started changing and every baby is kind of unique.
I now _detest_ most of the books/articles/child-rearing advice I've encountered. Most of all of their content is fluff to pad pages, a blog roll, and are frequently superseded by more modern research backed evidence. There is a lot of toxic advice in those books and systems as well, usually for parents that are prioritizing restoring their prior social lives over the well-being of their children.
It's time-consuming and exhausting, but I haven't found it to be _hard_ yet. Waking up in the middle of the night and giving your kid a hug and maybe reading to them a bit when they have a nightmare isn't a challenging task. The challenging tasks are exceptions (surprise medical issues, your daycare closing down with two days notice, etc). The baby and child industry put a cost premium on the clothes targeting them and they don't last very long due to the child's growth. I _saw_ this coming but not to the extreme it has actually manifested and you'll find it replicated in every child/baby sized item.
There are a lot of surprising upsides and my motivations have definitely changed since we had a kid. I will flip a mountain to see my kid smile and laugh, it hits deep. I enjoy spending time with her and I'm terrified of missing her achievements and milestones. When she comes to me and asks me to show her how something works, wants a book read to her, or just wants a hive five I get a double whammy of that serotonin once for being a Dad that she wants to engage with and once for getting to spend time with her.
I still, and unfortunately kind of frequently, miss what I have effectively sacrificed to have her. I am slower at staying on top of emerging trends, hobbies have been left by the wayside that I did for decades, I gave up running conferences and with it I drifted away from whole treasured social groups. None of this was really a surprise, but I didn't realize how much what I gave up was really part of who I was.
The social thing is interesting, you will inevitably drift away from friends who don't have kids. Even for the ones who do you will be so busy with your own life that you won't get to see them much. You will probably end up with more contact with parents from their schools although that will stop suddenly when they finish.
Not sure what the solution is other than putting in some deliberate effort to maintain those relationships (which I didn't do).
> It's time-consuming and exhausting, but I haven't found it to be _hard_ yet.
I think this is exactly what people mean when they say "hard": time-consuming and exhausting, not hard as in "I cannot figure this out". Usually you figure it out as you go.
This is excluding children with serious health problems, etc. I'm thankful I won the lottery in this regard, I know some situations can destroy families.
> I still, and unfortunately kind of frequently, miss what I have effectively sacrificed to have her. I am slower at staying on top of emerging trends, hobbies have been left by the wayside
Also rings true for me. Especially my hobbies, I barely have time for them now; and when she grows up who knows whether I'll be able to resume them. But in my case, this is balanced by this thought: would I be happier if I had more time for my hobbies, but she wasn't in my life. And the answer is very clearly that I prefer her to be in my life 1000000%, and if I cannot do my hobbies all that often that's an acceptable loss.
Ah yes let the FUD continue. This is a real problem but so far not nearly as severe as any of the marketing has made it out to be to the overall detriment of everyone including these companies announcing these scary capabilities. These announcements always included half hearted attempts at security layers which has now been demonstrated to benefit attackers more than defenders.
I wish I had a real solution to this beyond a dark age of the Internet where people have to finally come to terms with the general poor quality all modern software tends to normalize at.
The fact that HF had to resort to using GLM 5.2 to analyze the logs/payloads makes it look legitimate, at least for me. They would not say that they hit guardrails with the frontier US models when defending if this was an obvious PR stunt.
> When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead on zai-org/GLM-5.2, an open-weight model, on our own infrastructure. This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.
It depends on which side you're viewing this from. From oAI's it could be a publicity stunt or a request for regulation, and from HF's side they point out that they needed open models to get to the bottom of the issue, and that regulation will potentially lock us into a bad place.
You should go read the actual technical reports of the incidents and the follow on reports about the capabilities of smaller models in similar kinds of environments. This isn't new. The things exploited are still pretty basic in old and poorly maintained software or in gaps in architecture that were intentionally poked against security policies.
Are the findings valid? Yeah they're still doing security and they're still finding real zero-days. I think the internet is going to be bleak not because these models can ALL do basic security research but rather that the baseline quality of all deployed software is so low.
What you're describing is a harness implementation detail not something specific to the MCP protocol or even how skills behave. Both of those are effectively providing the same level of information to the harness. Harnesses have traditionally (and still generally do) exposed enabled MCP servers and their actions ahead-of-time in the system prompt directly instead of doing progressive disclosure.
Really not trying to be cheeky... but why? Who is the audience here? I can see maybe academics with small grants and want to do the absolute minimum spend on compute... But that is an audience you will have to fight for every cent.
This doesn't solve or provide guidance for the subtle problems in these otherwise opensource solvers... The first example requires the client to manually disambiguate equivalent variables to get a stable solution... Sure that's a pretty common problem everyone working with optimizers should be familiar with but they're also one of the hardest things to track down in a complex derived model.
Hei i'd argue the opposite ; the target you named are actually able to formalize this and spend more time on this because they have the mathematical background - it is not the case for many amateur programmer who would now be exposed to such problematic with a tool that can give them somewhat of an insight - being exposed to the tool it-self alone is huge because it allows an operator to experience and learn - this is all of course almost hyperbolic, reality is that most people won't be doing that - but it allows it, and it's cool !
There is an audience for such platforms - Timefold Platform optimizes 1,000,000 visits and 2,000,000 shifts per week - but only if it's more than just orchestration.
If it handles explainabily, what-if scenarios and insights to fulfill business needs.
And that's where supporting many solvers becomes the blocker.
A lowest common denominator design.
Those solvers are a black box. They don't expose what they're running, why they made certain decisions or how they can scale to large datasets or complex business requirements.
We've picked our poison: one solver, which we've built in the open, in the last 20 years, versatile enough to handle any scheduling problem. That delivers.
None of these solvers genuinely focuses on the quality of the features that matter in real-world operations.
Many of them, including Timefold, lack a realistic, financially grounded model of the world. They do not adequately account for traffic, driver preferences, or other factors that require a continuous feedback loop between what actually happened in practice and what the optimizer expected to happen.
A vehicle-routing problem without real-world feedback is little more than a gimmick. Even assuming the world could be modelled perfectly, what happens when an unpredictable event disrupts the plan? Is the supposedly “globally optimal” solution robust enough to adapt, or will it create a backlog that forces the business to hire additional workers because the system failed to build in sufficient redundancy?
That being said:
I fully agree that the solver industry as a whole has focused for far too long on global optima for academic requirements, instead of real-world use for the actual business requirements, and how to deal with business objective changes each quarter.
The problem frequently crops up in order-deterministic systems that use time and haven't accounted for the edge case of all the vagaries related to time-keeping of this being only one.
I've worked on some extremely sensitive systems that had thousands of lines of C dedicated to handling skewing a time gap across an hour-per-second when necessary. I know that code assumed only "missing" time (jump-forwards)... Even knowing what I know as a developer now, if I was re-implementing that system from scratch and didn't have this top-of-mind, I'd bet I would miss "overlapping" or "duplicate" time entirely.
Maybe that is more of a me problem than others, but I'd bet there are some safety critical systems out there where the responsible engineers, QA, and specs all missed this as well.
"Move fast and break things" applies even more in business than in software. If you get the revenue and don't suffer a legal penalty, you win. I've worked at companies that didn't outright fake their certifications, but definitely didn't care about following them and just did whatever was needed for the customer to pay up. In fact I'd say that's most companies. This is not a compiler you have to pass, it's a game you play with your customers.
The article itself covers the specific reasons that has led to that exact problem and the potential solutions available in the ecosystem with their various trade-offs.
A big chunk of the problem with this kind of legislation for me is that it inherently indicates a failure to govern to me. I disagree with the premise of the solution, but even more so this is trying to legislate a specific engineering solution for our current systems rather than any form of financial, objective guidance, or have reasonably actionable and enforceable consequences.
While laws that target engineering decisions are sometimes reasonable, they are always accompanied with specific guidance from a credible academic based institution (e.g. mechanical and civil engineering use private licensing bodies and develop specific curriculum and best practices).
The only time this law will ever be enforced is punitively for other crimes against major actors who are extremely limited in number. It is unenforceable for Linux, trivial for Apple, Microsoft, and Google to add to their OS. Presumably easy to spoof, the law describes it as minimal but once again, there isn't a specification so who knows. Websites won't be liable, they're getting a sweetheart deal here.
In practice what this law does is absolve abusive platforms an from any responsibility. It adds extra meaningless work and overhead for legitimate adult platforms while opening themselves up to new potential legal challenges, and ultimately doesn't replace the responsibility its removing.
This doesn't make children safer. This doesn't make the internet safer. This kind of legislation makes it easier to abuse children online by removing responsibility from platforms that are known to be dangerous to them yet profit from their presence the most.
I think this is solving a real operational pain point, definitely one that I've experienced. My biggest hesitation here is the direct exposure of the managing account identity not that I need to protect the accounts key material, I already need to do that.
While "usernames" are not generally protected to the same degree as credentials, they do matter and act as an important gate to even know about before a real attack can commence. This also provides the ability to associate random found credentials back to the sites you can now issue certificates for if they're using the same account. This is free scope expansion for any breach that occurs.
I guarantee sites like Shodan will start indexing these IDs on all domains they look at to provide those reverse lookup services.
CAA records including an accounturi already expose the account identity in the same manner, so I feel like that ship has already sailed somewhat (and I would prefer that the CAA and persist record formats match).
The accounturi is an optional extension. Email, and phone are also optional. This is the first challenge that publicly requires you to specify your account ID publicly. There may be implementations that require it but neither Let's Encrypt or the protocols require them.
I think the difference is that using the existing DNS method listing the account is entirely optional. I have left it out on domains that I don't want correlated for that very reason.
Exactly. They should provide the user with a list of UUIDs(or any other randomish ID tied to the actual account) that can be used in the accounturi URL for these operations.
I think the previous post is talking about a search that will find the sibling domain names that have obtained certificates with the same account ID. That is a strong indication that those domains are in the same certificate renewal pipeline, most likely on the same physical/virtual server.
Run ACME inside a Docker container, one instance (and credentials) for each domain name. Doesn't consume much resources. The real problem is IP addresses anyway, CT logs "thankfully" feed information to every bad actor in real time, which makes data mining trivially easy.
This is publicly publishing the account ID. There is an optional extension in RFC8659 that extends it but it isn't required by any implementer. This puts that ID into a public well known location that is easy to scrape and will be (this is exactly the kind of opsec info project like Maltego love to go lookup and pull in).
I'm not sure the distinction matters, and attribution is inherently hard and easy to get wrong. I frequently read Country X is doing Y, less as a indicator of government action and more of a single that we can't be more specific of who within the country is performing an action but we know the behavior is occurring there.
In the case of IP address purchases, these are publicly tied to specific public and private entities and can be easily queried through the regional registries. These private entities are frequently the same kind of shell company you'll get with hiding shady financial details.
The first couple of months were especially hard as they don't have much of a personality, don't really react much to the world around them, they're just feeding, sleeping, and growing. Starting at the beginning of the third month for me it started changing and every baby is kind of unique.
I now _detest_ most of the books/articles/child-rearing advice I've encountered. Most of all of their content is fluff to pad pages, a blog roll, and are frequently superseded by more modern research backed evidence. There is a lot of toxic advice in those books and systems as well, usually for parents that are prioritizing restoring their prior social lives over the well-being of their children.
It's time-consuming and exhausting, but I haven't found it to be _hard_ yet. Waking up in the middle of the night and giving your kid a hug and maybe reading to them a bit when they have a nightmare isn't a challenging task. The challenging tasks are exceptions (surprise medical issues, your daycare closing down with two days notice, etc). The baby and child industry put a cost premium on the clothes targeting them and they don't last very long due to the child's growth. I _saw_ this coming but not to the extreme it has actually manifested and you'll find it replicated in every child/baby sized item.
There are a lot of surprising upsides and my motivations have definitely changed since we had a kid. I will flip a mountain to see my kid smile and laugh, it hits deep. I enjoy spending time with her and I'm terrified of missing her achievements and milestones. When she comes to me and asks me to show her how something works, wants a book read to her, or just wants a hive five I get a double whammy of that serotonin once for being a Dad that she wants to engage with and once for getting to spend time with her.
I still, and unfortunately kind of frequently, miss what I have effectively sacrificed to have her. I am slower at staying on top of emerging trends, hobbies have been left by the wayside that I did for decades, I gave up running conferences and with it I drifted away from whole treasured social groups. None of this was really a surprise, but I didn't realize how much what I gave up was really part of who I was.