Hacker Newsnew | past | comments | ask | show | jobs | submit | micimize's commentslogin

Also WRT coordination: All an agent has to do is think "if another agent could write, then I could read their answers. What's the first site I can think of where that might be possible?" because they all have approximately the same conditioning, they'll converge on the same sites.

Generally, models of the same class should be able to coordinate quite well without communicating. But also, this could be being exploited to detect this kind of thing early


Weren't they giving free access? Not exacty a meaningful heuristic if so


The key insight here is being the top used model on opencode while being fully served on Chinese chips. The free price itself might be just a flex or marketing budget.


it was not the first model served for free, i remember grok and others beeing free on openrouter but they never had this popularity because they where not good enough.


This comes almost exactly a week after the HF hack. Good strat, to drum up a bunch of press about how security-capable the model is right before releasing the product.

Or, it would be if it was intentional. It's a bit suspicious but it is probably incidental or opportunistic... though I do really struggle to see why this tool wasn't made better use of internally to actually harden their infra against the big scary AI they were testing.


With the scarcity of details in this and the OAI post, I feel there's no telling whether this was a particularly impressive series of exploits vs lackluster security. Similar w/ the similar Ant news WRT Mythos earlier.

Not saying the intro of agents capable enough to exploit the latter isn't meaningful, but we should not trust the use of technical terms to give us good heuristics of severity or import.

Ie, an agent "breaking out" of its local harness "sandbox" is trivial, and so is discovering a "zero-day" in a half-maintained internal piece of utility infra nobody put serious effort into securing.

Now, if I see something like a collaborative red-team effort where a frontier model gets into a replicated prod env setup by like, Big Four bank security+ops team, and manipulated balance numbers in a system of record, _that_ I'll freak out about.


Haven't we established defensive and offensive security usage are intractably entangled? I.e. "patch all [security] bugs, make no mistakes" gives one a list of potential exploits to hand off to less capable models.

Doesn't that undermine all good-faith discourse on cybersecurity safeguards, controlled usage etc? Or is that overstating the case (I'm not a security researcher myself so kinda parroting).


I got the Phomemo M02 Pro and have liked it alright for printing out playtest cards on-the-fly. Claude did manage to replicate an integration someone else did the hard work of working out w/ dithering etc, but the native app's fidelity & speed has been better for my use-case, at least


This is very cool - I try to have a container-centric setup but sometimes YOLOcal clauding is too tempting.

My biggest question skimming over the docs is what a workflow for reviewing and applying overlay changes to the out-of-cwd dirs would be.

Also, bit tangential but if anyone has slightly more in-depth resources for grasping the security trade-offs between these kind of Linux-leveraging sandboxes, containers, and remote VMs I'd appreciate it. The author here implies containers are still more secure in principle, and my intuition is that there's simply less unknowns from my perspective, but I don't have a firm understanding.

Anyhow, kudos to the author again, looks useful.


Thoughts: 1. Some hype-types may have been effusive about AI-assisted coding since ChatGPT, but IMO the commonly agreed paradigm shift was claude code, and especially 4.5, very very recent. 2. Anchoring biases in reaction to hype is still letting one's perspective be defined by hype. Yes the cursor post is a joke, but leading with that is a strawman. This article does not aim to take it's subject seriously, IMO. 3. While I agree the hype is currently at comical levels, the utility of the current LLMs is obvious, and reasons for "skilled" usage not being easily quantifiable are also obvious.

IE, using agents to iterate through many possible approaches, spike out migrations, etc might save a project a year of misadventures, re-designs, etc, but that productivity gain _subtracts_ the intermediate versions that _didn't_ end up being shipped.

As others have mentioned, I think yak-shaving is now way more automated. IE, If I want to take a new terminal for a spin, throw together a devtool to help me think about a specific problem better, etc, I can do it with very low friction. So "personal" productivity is way higher.


> the utility of the current LLMs is obvious

In that they obviously have no real utility, sure. There hasn't been a paradigm shift, they still suck at programming, and anyone trying to tell you otherwise almost certainly has something to sell you.


Based on my direct experience I find this remaining commonality of this opinion surprising, at least with regards to opus in claude code. I'm not as extreme as some who think we can/should avoid touching code or w/e but especially in exploratory contexts and debugging I find them extremely useful.

Maybe I should have said "obvious to me," but I guess I just struggle to see how a serious crack at using modern opus in claude code doesn't make it obvious at this point.

I'd really recommend trying the "spike out a self-contained minimal version of this rearchitecture/migration and troubleshoot it iteratively until it works, then make a report on findings" use-case for anyone that hasn't had luck with them thus far and is serious about trying to reach conclusions based on direct experience.


I promise you I don't have anything to sell you. I think 100% of our developers are landing most code changes using agent coding now. This is in a trading fintech.

Coding agents work. At some point you're going to not just look contrarian, you're going to look like a troll to keep denying it.

You may not like it, that's a perfectly valid take, but to deny they're good at coding at this point is silly.


Vapid and wrong on every point. Many good ideas come from steeping in a novel soup of ideas for a long time, you don't need that many people to care about quality to make it a lucrative differentiator, and as I've seen many point out on X dot com the everything app: where's all the the shipped results of these slop torrent?

The models are increasingly capable in impressive ways. Maybe the next gen will enable the "sales critter" to slop out commercially viable software with no tech know-how. If not, I'm sure we'll assume the next can, and if not that, the next.

But feigning confidence about the shape and nature of this unfurling sea-change is absurd when the high-profile examples we have are like, what, moltbook? And denigrate _all_ potential ingenuity and insight unilaterally into the bargain? What a careless way of looking at the world


Measuring in terms of KB is not quite as useful as it seems here IMO - this should be measured in terms of context tokens used.

I ran their tool with an otherwise empty CLAUDE.md, and ran `claude /context`, which showed 3.1k tokens used by this approach (1.6% of the opus context window, bit more than the default system prompt. 8.3% is system tools).

Otherwise it's an interesting finding. The nudge seems like the real winner here, but potential further lines of inquiry that would be really illuminating: 1. How do these approaches scale with model size? 2. How are they impacted by multiple such clauses/blocks? Ie maybe 10 `IMPORTANT` rules dilute their efficacy 3. Can we get best of both worlds with specialist agents / how effective are hierarchical routing approaches really? (idk if it'd make sense for vercel specifically to focus on this though)


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: