Hacker Newsnew | past | comments | ask | show | jobs | submit | jjordan's commentslogin

FYI I've been building an app, Android first, and discovered the magic of Kotlin Multiplatform. The LLM modularized everything so that it's substantively the same code base, but with Swift only where it's needed. Still working through it, but it seems like a great and underrated platform to build on.

You're not emitting the code yourself anymore. The platform ease of use for humans no longer matters as much (if at all).

Preference for a native feel, solid software, bugfree code, compile/develop velocity, LLM friendliness.

We're in a brand new world.


There should be laws put in place to ensure drivers will always be able to drive their cars, if they choose, and also prevent insurance companies from skyrocketing your rates for doing so. This is IMO past due.

Why? Insurance companies use detailed risk data. If they discover that letting you drive your own car is a much higher risk than an auto-drive, why should they not be allowed to account for that?

Insurance companies aren't political -- they charge for whatever costs more.


Yes, I definitely trust insurance companies to do the right thing here.

Car insurance companies have their problems, but pricing risk is not one of them.

We saw this before -- they used to charge people who lived in high crime areas more money. They had to stop because it turned out that those high crime areas also had a lot of poor people, so the government stepped in and stopped allowing pricing by zip code.

But the insurance companies weren't wrong about the risk -- those customers cost them more. So instead they had to raise everyone's rates to account for the fact that they (rightly) could not discriminate.

I suspect the same would happen here. That poorer people could not afford self driving, and they same anti-discrimination rules would apply.


> Car insurance companies have their problems, but pricing risk is not one of them.

If pricing risk was an exact science, you'd get the same quote from all providers (given similar coverage). Yet if you try that, you'll find that the quotes could vary as much as 2-3x. Therefore no, we shouldn't blindly trust "the algorithm".


>Insurance companies aren't political -- they charge for whatever costs more.

Insurance companies you are required to interact with by law are absolutely political.


I meant they aren't political in their pricing. They don't charge less or more for something because it is considered liberal or conservative.

I agree with your first statement but certainly not with the second. Rates for human drivers should and will skyrocket. Individual states may try to push back with regulation but it won't succeed in the long-term

Rates for human drivers are currently at the correct level for insurance companies to pay for damage and make some profit.

If autonomous cars result in less damage than humans, their insurance price will be cheaper than human drivers, but there's no reason to raise the human rate at the same time, their accident rate should stay the same.


> If autonomous cars result in less damage than humans, their insurance price will be cheaper than human drivers, but there's no reason to raise the human rate at the same time, their accident rate should stay the same.

Wouldn't the accident rate for humans go down as well as the percentage of SDV increase? After all, the humans won't be exclusively having accidents with each other.


I don't think you're seeing the future trajectory. Autonomous cars and trucks will be able to do their thing with a much smaller margin for error - because they don't make errors. So for example instead of two seconds distance to the car in front of you it will be 0.1 second. The vast majority of humans would have an accident as soon as they got on the road.

We need that increase volume and reduced accident count in order to grow without having to build more roads.


Great, so when a deer jumps into the middle of the highway the size of the ensuing pileup is twenty times larger. I don't particularly think we should use technology to push efficiency to the point where a mechanical failure, a material failure, or an unexpected object cause much larger scale catastrophes than exist today.

Why not aim for the same distance between cars and twenty times more safety instead?


Because traffic volume.

Autonomous cars won't panic and cause pileups.


The way to prevent pileups is not to assume that everything will work correctly, including every system on every car.

It's to assume that every single thing that could break, will break, and design enough resiliency in that you have to stack up as many failures as possible before things truly go off the rails.

So to do this without killing people, you add the new systems with the same safety thresholds, then gather quite a few years of statistics, then, slowly let things become more efficient if that's both warranted by data and also warranted by simulation of events that you do not yet have data for.

Skipping steps in this because you want to put more cars on the road immediately is foolish and dangerous.


I agree with all that. Robot cars will take time and we shouldn't skip steps. Tort lawyers will continue to keep companies inline.

They have a reason: profit.

This is testable. The profits of car insurance companies should rise (let’s say substantially) in real dollars as accident payouts decrease as a result of the inevitable dominance of autonomous vehicles.

Why should they skyrocket? As more autonomous vehicles appear on the roads, incidents with non-autonomous vehicles will go down. Driving will become inherently safer.

In the long-long-term, self-driving will get good enough and people will be relying on it so thoroughly that allowing people to drive on their own, with barely any practice, will probably be more risky than it's worth. In say, idk, 100 years (probably sooner), I doubt people will be able to drive their own cars in the way they do today.

The overwhelming majority of bad driving is caused by alcohol and other drugs, drowsiness, and inattentive driving.

Sober, well-rested human beings who pay full attention to the road are surprisingly good drivers, to the point where I'm not actually sure that robotaxis can reliably beat them yet.

Yeah, a hundred years from now fewer people will drive themselves, but considering how many people DESPISE driving and only do it because it's required of them, that isn't bad.


> The overwhelming majority of bad driving is caused by alcohol and other drugs, drowsiness, and inattentive driving.

> Sober, well-rested human beings who pay full attention to the road are surprisingly good drivers, to the point where I'm not actually sure that robotaxis can reliably beat them yet.

Including "inattentive" and "pay full attention to the road" feels a little tautological? Like, what's your definition of "inattentive"? More or less by definition, if there's an accident, someone was "inattentive" and didn't do the correct thing. Unless they were actively malicious and trying to hurt someone, which I agree would be a tiny minority of car accidents.


There should be laws taxing people who insist on driving themselves. And the money should be used to subsidize people who switch to self-driving or install automatic assisted systems on their old cars. That'd partially mitigate the externality generated by human drivers.

How about prison for attempted murder?

I've lost enough friends to drivers who made a mistake. If self driving is better in just that, but worse every other way: I'm for it.

That might be a big if above, but of true them I support it. Drive on a private track or a video game if you must. Leave the real world to safe.


Incumbent rent-seekers want regulatory capture to insulate them from externalities. Dog bites man.

No there should not. Human drivers kill a million people every year. WW1 killed 15-22M.

The law put into place would be that the people who put autonomous cars on the road would risk their freedom and safety just as much as a driver if that car causes an accident through their neglect.

This will never happen, because the entire purpose of the corporate structure is to avoid responsibility.


How selfish. Why should I, someone who wants a safer AV, subsidize those who are riskier drivers?

Extremely selfish.


Is this your first introduction to an insurance pool?

Not the same at all.

This happens in insurance all the time. Healthy people who eat right and exercise subsidize people with poor habits.

It appears to some degree that we as a society do not want risk priced optimally to each individual.


It is understandable that you think this is the case as someone who is not above the age of 50. You will see that health and life insurance premiums rise precipitously once you reach certain milestones. Once you reach 90 years old, you will find that car insurance companies will discontinue your policy based on a single traffic ticket.

We replaced preexisting condition coverage with age-based tiered pricing. If you doubt me it's trivial to validate this using your state's ACA marketplace.


Closed source doesn't mean not trustworthy. O&O has been making tools like these for a long time.

>Closed source doesn't mean not trustworthy

Yes, it does.

>O&O has been making tools like these for a long time.

Microsoft has made Windows for a long time. Longer, even.


The “million eyes” argument has massive exceptions, among the top of my head is OpenSSL’s HeartBleed, a critical and extremely popular security suite that had a simple overflow issue for a decade or longer.

People don’t read the source. And chief among them, statistically, is you.

Open Source is ideal but not a deal breaker.


True. And yet the possibility exists that one COULD. That's the difference.

Fully open models really need to be a big part of the AI future. That includes all source code, open training data, how it's organized, fed to the model, processed, etc. Until that becomes a thing you're always going to be left wondering what exactly lies underneath the closed model you are using, leaving open the possibility for societal manipulation.

Other than open training data (currently legally impossible), all of this holds for basically every major Chinese-made model. They not only open the weights but publish detailed methodology papers alongside the models in arXiv and even open source the code.

Inference code, yes, but the specifics of their training process (as well as the training of the vast majority of all other open weights models) are still a complete blackbox, and I can't think of any Chinese model that made its training corpus public.

This is absolutely not true. DeepSeek is most famous for publishing really in-depth papers on their training process but the other labs have started to do the same as well.

If by "training corpus" you mean the actual data I already acknowledged that that's currently legally impossible.

In fact everything I just said I said in my original comment. It's like you didn't read it at all.

DeepSeek's GRPO Infrastructure, multi-stage training pipeline, and their "cold start" phase have been massively influential in LLM research.


> If by "training corpus" you mean the actual data I already acknowledged that that's currently legally impossible.

Did you read the site this very post links to? The entire point is that the training corpus, recipe, and scripts, as well as intermediate checkpoints, will be made available for K2 Horizon. Chinese models these days don't even release pre-trained weights anymore; all you get now is the finished post-trained product.

I've read your comment. I'm doubting you've even read the thing you were commenting on.


Yes there have been several research projects like these that have fully open sourced their training data (mostly coming from Europe). But that's all they amount to. Experiments and projects.

The labs that are actually competing with frontier models are using data would usually be a violation of copyright to release openly.

> Chinese models these days don't even release pre-trained weights anymore; all you get now is the finished post-trained product.

No? That's absolutely not true. Qwen, GLM, Kimi, DeepSeek, etc all consistently release both the post-trained "Instruct/Chat" versions and the underlying "Base" (pre-trained) weights.

Which specific Chinese models are you thinking about?


They don’t release all the code.

DeepSeek has released a ton of low-level AI infrastructure code, libraries, and mathematical models on GitHub. Their tools and agent environments are fully open sourced including their harness. They release complete PyTorch and Hugging-face compatible python files detailing their configuration, tokenizers, and layers of the architecture.

The only thing they don't release is their data-filtering pipelines but they detail even that in their public-access papers.

DeepSeek is truly as open source as you can possibly legally get. Besides the data itself, it's completely reproducible by anyone else.

I don't think americans yet acknowledge just how radically transparent Chinese labs are being (and how much even the west benefits from it).


The training data would need to have a permissive license for this to be possible.

Or, we just need to get this over with and declare any digital data findable via the internet to just be public property of everyone. Everything becomes public, besides stuff you keep locally, and there is no difference anymore, it's all just data anyone can use for whatever. A 1 year grace period for everyone to pull stuff off they don't want to be a part of this bright new open era, then we just scrap everything related to intellectual property, copyright and similar stupid stuff, and slap UBI on top of all of it for good measure.

I'd prefer to stay within the [hacker ethics](https://www.ccc.de/en/hackerethics), and protect private data. For non-private/personal data, sure. But individual people need their privacy protected.

Me too, I'm hacker ethics all the way, which is why I'm saying anything network connected should really realize the "All information should be free." dream, and then private data should be far away from the internet, on computers/drives not even connected to the internet. The whole E2E encryption is a ticking time bomb people rely to keep their data safe from others, but nothing that you don't physically have close to you can be truly secret forever, and even then it'll be hard.

Well... If someone leaks private data on individuals online, those should be deleted.

> If someone leaks private data on individuals online

That won't be possible anymore, anything on the internet would be considered public, it's no longer considered private if you didn't keep it private.


That sounds dystopian to me and is against the hacker ethics.

Letting information that want to be free, be free, sounds exactly like the hacker ethics to myself, and the link you shared earlier would agree.

The last point is pretty clear, and the text below clarifies it:

> To protect the privacy of the individual and to strengthen the freedom of the information which concern the public the yet last point was added.

The privacy of individuals is important, regardless where they store their private data. Their account information -- what they buy, their medical information and so on is stored on servers and could be hacked.


> The last point is pretty clear

I think the second point is equally clear, and further up on the list.

I agree that what people buy, their medical information and so on should be private, hence it should only be offline and not stored/handled on computers connected to the internet at all, the internet should be for public data exclusively, is my argument in the initial comment. Medical information would be only on effectively airgapped computers, as that data should be private, as you say.


So you say it is okay when someone you trust, uses that trust to upload your personal files from your air-gapped system to the internet, for everyone to freely share it, because now the data is "public"?

To me private file stay private, even if they get leaked onto the open or closed internet, because the public has no right to know them, they are private data of an individual. They might no longer be secret, but they are still private.


I'm talking about liking waffles, then you appear asking why I hate pancakes. Fun.

> To me private file stay private, even if they get leaked onto the open or closed internet

We have very different definitions of what "private" means. Once it's leaked, it's no longer private, and pretending it can go back to being "private" after being on the public internet, is doing no one any favors.


I just find it very interesting that someone equates secrecy with privacy. In my opinion, and in the current law there is a distinction.

If private data got leaked, like revenge porn, it is a breach and that private data that belongs to an individual is still private, and still needs to be protected. This is what GDPR and other legislation is about. If secrecy and privacy is the same, someone that isn't able to protect their data sufficiently will not have any privacy, thus any leaking of data is now the fault of the person that got their data leaked, not of the person that broke the trust and leaked it.

Your conclusion seems rather extreme to me. So of course data that got leaked, and is no longer secret is still private, because 'private' means who should be in control of that data, not about if the person has control or not.

I also don't follow your point about waffles and pancakes, because this is a pretty big disagreement we have here. To me this dialog is more like you are saying "I don't like laws", and I say "While I agree that some laws are stupid, other laws are pretty useful, for instance people shouldn't be allowed rob other houses, even if they are able to do that or even where invited." And then, instead of agreeing, you sort of say, "No, I really mean that. If someone isn't able to defend their home properly or give out invitations to someone, it is okay to steal from them."


If you move data between public and private domain and there is no eruv wire around it, you get deported to Singapore.

Exactly, and right now we have the worst of both worlds with companies blatantly ignoring copyright, but individuals prosecuted for violating it.

I don't really get what you're suggesting. You give a 1 year grace period for Metallica to pull all its music off the Internet, but then as soon as I host some of their MP3s on my Wordpress blog it's "public property of everyone" from that point forward?

What you're slightly more realistically looking for here is for publicly available data to have a Fair Use exemption for certain uses, which is certainly something worth discussing.

I hate to invoke Poe's law but, I've now flip-flopped like six times over whether this could be serious.

I think it is serious. In which case, I gotta say, it really seems like you didn't spend much time thinking about this. "A 1 year grave period for everyone to pull stuff off they don't want to be a part of" - How does that work when the Internet is already full of unauthorized reproductions, most of which people aren't even aware of? Even ignoring practical considerations, when literally everyone is basically stuck using the Internet for everything, this seems a bit unfair to anyone who isn't onboard, akin to The Onion's Google Opt-out Village. But there are so many practical issues with this, it would be easier to list the number of problems this doesn't have. You accidentally leak something to the Internet and it becomes commons? What happens when other people leak things to the Internet? How about revenge porn?

Not minor stuff that can easily be papered over, this literally reintroduces the problem of needing to care about the provenance of data again, in a way that can't be automated, which makes the whole thing entirely moot. All just to make training data for AI models easier to distribute?

I'm all for intellectual property reform, maybe even fairly radical. But this just seems like it wasn't thought out.

If this was satire, well, I took the bait. Oddly convincing despite being hard to believe.


> If this was satire, well, I took the bait. Oddly convincing despite being hard to believe.

It wasn't entirely serious, but also not entirely un-serious. But yes, I spent maybe 20-30 seconds thinking about then barfed up the text that makes the comment, so yes, obviously many issues and not really workable in practice.

I'm glad it made you seriously think about it and also flip-flopp back and forth about it, made it worth posting the comment so happy to hear :)


There is an image of Mickey Mouse findable via the internet -> you're going against a very well funded lobby.

I respectful disagree. I enjoy reading e.g. Asimov and well-executed journalism. And I completely respect the IP of those people who create these works.

I'm what way does it make sense to respect the intellectual property rights of a dead man?

It secures the benefits of copyright for work being produced by the creator up to death, for their heirs and dependents, which is why they were creating for money in the first place. People don’t just die after twenty years of resting on their laurels; everyone is creating copyrighted work. It’s a key part of the incentive to create lasting works of value.

One can make the case that this period should be more limited, or that the combination should be capped, but life+X is the right formulation, I think.


> for their heirs and dependents

Why can't they do what the rest of us do? Earn and save money during your working life and leave _that_ for your heirs. Let copyright die with the author.


Work is often only recently published when an artist or author dies but has taken years of non-earning to create.

I know this them-and-us thinking is fashionable in the tech world but the reality is that the majority of creative people don’t earn much and never have, and copyright was developed not to give them extra power over the rest of us but to create a framework for creative work to earn them an income at all.

You should read about it.


Sure, some number of years is reasonable - but what do you think that is? Because 70 is insane. A single bestseller should not be able to support an extended family over three generations; at some point the rent-seeking becomes excessive. If you publish a work, at some point it stops being yours. The fact that this takes a whole lifetime is already very generous.

I don't disagree; personally I think you could go with life plus 35 and cap the whole thing at 80 years from publication.

But I do think some potential post-mortem protection is essential for creative work to remain viable, and that means that any post-mortem buyer of an artist's estate has to be able to get value from recent work for a period of time.

This whole discussion is somewhat fantastical now anyway, because copyright is fucked.

But the intent was always to make working artists' lives possible; the various copyright extensions have always been for the benefit of corporate copyright holders, and it is unfair to vilify individual working artists for that.


> which is why they were creating for money in the first place

That's quite a narrow definition of what motivates creative work


It was only narrowed for the purposes of the point I am making, which is that copyright protects working creatives. I am not at all saying that all artists only make work for money.

It is working artists we are talking about; working artists work for money.

That money, in the post-patronage era, comes from exercising copyright. The reason the copyright can’t simply die with them is that this tends to dissuade the creation of long-gestating work.

Copyright was developed to make it possible for artists, writers, musicians etc. to work for long periods on work of significance with no income, on the basis of the future, deferred earnings of the work, without their work being stolen from them, and it gives them the limited right to direct how their work is monetised on their behalf, including establishing publishing rights etc.

Some protection after death is a key component of that, because people do die while they are still working.


If IP rights end at death, there are some significant perverse incentives for offing big-name artists and authors and whatnot.

The current "lifetime of the author + X years" rules in effect in the United States still carry the same perverse incentive, though the incentive diminishes rapidly as X gets larger; with the very large value of X in effect today the perverse incentive is so small as to be effectively non-existent, but it's still there in theory.

Personally, I'd prefer a fixed term. I know enough independent authors making a living from selling their books that I'm willing to allow the fixed term to be large, like 50 years from date of completion of the work. (With a good definition of "completion" so someone can't cheat by editing a couple lines per year to keep something copyrighted indefinitely). The simpler the rule is, the easier it is to understand, and the harder it is to cheat it. The more complicated you make a rule, the more loopholes get found.


There are significant perverse incentives for me shooting you with a gun and taking your money and running away too. It mostly doesn't happen.

I don’t have a billion dollars in my wallet.

So it's just a matter of scale.

Sure, that's why I said "big-name" artists in the first place.

That dead man took the risk of not earning much in his lifetime, to continue feeding his family even after his passing. You might as well ask why does someone acquire life insurance.

You could sidestep it by running non-permissibly licensed training data that you purchased through an LLM. Legal attitude so far seems to be that this is transformative as long as it's not 1:1. The question on whether or not the end result is copyrightable of course remains controversial and inconsistent, but that question is also fairly irrelevent. You don't get more libre than public domain.

That's a fair amount of computational and labor overhead mind you, as you'll need to verify and prune the quality of your mountain of synthetic data, but certainly possible.

Though this assumes the legal system is a rational actor playing by the set of rules it claims to. In fact, I highly suspect you could get very unlucky and get an unfavorable ruling against you, because you stepped on a big pile of money's toes in the process of doing this.


It can also be used to sidestep copyright like this forum, books and most websites even if the data was not purchased but is a website or book.

Are LLMs what we need to make all data public domain? This way it could be used for that purpose


UAE's IFM / LLM360 MO is indeed "fully open source" LLMs: https://www.llm360.ai/reports/LLM360-Towards-Fully-Transpare...

They do not appear to have published the training data yet, but if they do it like Olmo https://huggingface.co/datasets/allenai/dolma3_pool you get a license to the database, but not to its content, which they cannot license to you because it was scraped from the internet. E.g. have a look at the preamble of the ODC-By license https://opendatacommons.org/licenses/by/1-0/ which makes this distinction.

Eventually we'll just construct 100% synthetic training data that can reliably reproduce pretrains and fine tunes.

The first broadly useful fully open source models will do this.

We already have open data / open code / open weights for some domain-specific cases, such as audio models trained on large open datasets, eg. Tacotron / LJSpeech from waaay back in the day, though that is certainly not SOTA anymore.

Distillation could possibly be considered an early case of this as raw AI outputs are themselves not copyrightable unless humans enrich, filter, or transform them. Granted, that does not handle the cases where the outputs are sufficiently similar to copyrighted original works.


But how much of that synthetic data still ultimately derives from non-open sources? You'd still have to ask what a clean room implementation ultimately is, depending on how granular or aggressive a large publisher wanted to get about it.

That said, I don't necessarily disagree with you. Talkie[1] presents an interesting case for it being at least possible to do this entirely on public domain material.

But even that used Claude somewhere in the course of its training pipeline (it's listed as a contributor on their GitHub), so again, how granular you want to get with that is still a question.

[1] https://talkie-lm.com/chat


Where does that synthetic data come from? Magically just started existing?

Hear me out.

Decentralized unstoppable storage, combined with decentralized unstoppable training, sorta like SETI for AI training. The seed of this tech already exists with IPFS and others like it.

We know (some? all?) of the big labs have skirted copyright laws at one point or another. Truly open models would just build on what is publicly available.


Crypto bros took the idea with some blockchain shit and no one takes it seriously anymore so it died

If the LLM/AI ecosystem starts actually needing some Person-To-Person (or maybe Agent-To-Agent?) payment system because things actually get smart enough to be useful autonomously, they're gonna need some way to send money/currency around. Depending on how banks will react to this need, we might see another return of digital currencies from the current winter.

They used to say that cryptocurrency will be the dopamine layer of the first artificial intelligence

I believe Olmo from AllenAi is this

https://allenai.org/olmo

Open models can be used/changed for social manipulation too, by anyone, which scares a bunch of people, as opposed to the dark pattern manipulation from Big Ai/Tech


No, they just tell you what data they used, it still includes e.g. Common Crawl. Not Open, just willing to state what they fed into the training.

Why? Sure, I’d prefer it, too, but this is just another GNU/Linux vs. macOS situation: most of us would prefer the first, but actually get shit done on the latter.

Without open-source, there'd be no macOS.. So good thing, it exists.

Why do you make the worse choice and not use what you would prefer to use? You have been able to "get shit done" on Linux for nearly 30 years. Have the courage of your convictions.

And that's why companies shouldn't fear opening up, but having both is still a net benefit.

which is why everyone runs docker on mac, to get shit done.

we get shit done on the cloud with the former rather than the later

I personally find the analogy unconvincing, the UX dimension is completely different as I can use the same harness with any model; and the year of the linux desktop is coming soon (tm)


Money is the issue here, no one wants to fund it.

I'm sure anthropic didn't want to fund the extra "safety" guardrails they put into fable, but they were forced to, else they couldn't release it.

Sure there are all kinds of problems with that situation. But it still demonstrates that they can be coerced: play nice or don't play at all.


But that would be impossible due copyrights laws. If the law would apply Anthropic and OpenAI executives would be in jail

People who like near frontier AI at a lower cost than most.

What ever happened to IPFS? Wasn't it built for just this kind of thing? I remember trying it years ago and it was absolutely unusable, but was kinda hoping it had made a turnaround by now.


IPFS might be in trouble. Haven't really followed the tech so I have no idea how much of an effect there will be with Shipyard dropping it, but from the number of things I see named in their exit post I'd guess the blast radius is sizable.

- https://news.ycombinator.com/item?id=49421489

- https://ipshipyard.com/blog/2026-the-end-of-ipfs-at-shipyard...


That dev community continued into iroh and atproto. We built atproto with whyrusleeping as a very active consultant



Fantastic content. Went looking for this on HN after seeing it on lobsters, since I don't have an account there yet. It's truly sad that some of these gems never get front page coverage, for whatever reason.

Anyway, this will be useful as I've struggled to get into an instrument myself and often found myself asking "why" to a lot of accepted conventions. Appreciate all the time you put into this.


I think it should be noted that the CTO of GitHub doesn't use his own product. No commits since January 2024: https://github.com/v-fedorov-gh

No side projects? Nothing? Just seems odd.


Maybe he's too busy with leading the engineering side of the company to write code these days?


If even the CEO is vibe coding[1], then the CTO has zero excuse.

[1] - https://www.youtube.com/watch?v=SEZADIErqyw


Probably managing and mentoring. I has a boss that wanted to code and be CTO. Just horrible.


Can you imagine the flack he'd take if it turns out he'd been moonlighting whilst the GitHub ship is sailing though cat 5 with both the mast and the ship whore on fire?


yeah grinding on side projects, while everything is in flames.

this is fine.


Sarcasm? Someone as important as CTO of GitHub is the last person I'd expect to have "side projects". I'm sure his job is project enough.


I'm partial to Typesense, especially for smaller data sets, since it runs primarily in memory, is easy to use and is hella fast. For bigger data sets, I hear good things about Meilisearch.


Probably the most refreshing thing I've read in a while. Glad to support them moving forward if this is indeed their modus operandi.


Tailscale is the best. It's infinitely better than Hamachi, ZeroTier, etc. My only gripe is that they have some really weird SSO requirements like GitHub, etc. and then that provider becomes a permanent part of your identity.


I've been a fan of Tailscale since encountering it for the first time at a previous job at a small startup. Someone asked if anyone had a Linux machine when we were all testing out something, and I mentioned I had a personal Linux desktop but wasn't sure how to connect it to the VPN for access, and it turned out that the solution was just literally running two commands in the terminal after installing tailscale from the repos. Compared to my first job where connecting to the VPN from Linux required hours of mucking around with openswan (or was it strongswan? so many swans...) and trial and error with various config files, it was unfathomably straightforward.


That strongswan thing is the kind of design HN praises about open protocols by IRC (just the other day...) but in practice is so flexible it can't keep itself upright and it's unusable in practice.

Meanwhile tailscale or wireguard, by being actually opinionated, avoids needing much configuration at both ends.


Yes — configuring strongSwan as a bog-standard VPN server was so hard to fathom I made GitHub repo for it [1]. To be fair, some of the complexity comes from OS support that seems specifically designed to make secure setups difficult, presumably at the behest of various Three Letter Agencies.

I have now mostly switched to Wireguard for this, which is much more sane [2].

[1] https://github.com/jawj/IKEv2-setup [2] https://github.com/jawj/wireguard-setup


With a desktop its usually possible from the network setting GUI? Worked like that last time I needed to use a VPN for access to a corporate network.


Some of the NetworkManager VPN plugins have weird side-effects. Like the one for OpenVPN force-disables split tunnel configurations and there's no way to turn that off, meaning that all traffic routes through the VPN even if you'd rather only send stuff for certain destination addresses through.


Based on the experience that I (and other coworkers, including on other distros) had, whatever configurations our VPN needed did not seem to work out of the box on network manager.


A lot of this is just weird Linux on the desktop weirdness.

On Windows and Mac, VPN config is usually just installing a client, signing in, and then it all basically works. Sometimes you don't even need the client and can set it up in settings.


Those are pretty much all first-party clients though, right? I'm not sure that "some companies don't provide a Linux client for their software" is something I'd characterize as "Linux desktop weirdness". My point here is that Tailscale seems to have actually put time and effort into making a Linux client that's a breeze to use, whereas most of the other VPNs I've used for work have not.


Just FYI - with Tailscale you can switch SSO providers by putting in a support ticket. I did it last year and it was a breeze.


Oh, thank you! I might do that.


I think their reasoning on not being an identify provider but acting solely downstream is very clever.


Y? What's wrong with providing username/password authentication


Being an identity provider for anything important is the freaking worst. Exposes you to a million problems. You need human support for login problems and lost MFA tokens, and you are an attack magnet.


Which is why you want magic links.

Don't be the identity provider, have the email host be the identity provider (which it is anyway if you have a forgot password prompt).

Agreed 100% that nobody should still be using passwords in 2026 though.


As a user, I really don't care for magic links. The whole, start the log-in process, switch context, wait for email (sometimes up to a minute), click on it, have it open a new tab in a different window than where I started is just a pain. I feel like I spend half my day logging in to services these days.

The only time I like magic links is for services where I am "not really a user". For example, an appointment reminder for my doctor where I need to validate my insurance. Great, send me an email 24-hours before with the reminder and a magic link, as I don't want to think about an account there.


I detest magic links. I have probably 9-10 accounts with a certain service that uses magic links (I mostly use them to get an API key or download a file every few months and never visit directly otherwise) because 1. the only login method they support is magic link and login with Google/Facebook. There's no password field so my password manager can't fill out my login details for me. 2. I don't have a Facebook account, and I don't keep my Google account signed in. Even if I did, I don't want them using these as my primary email address. (I use a catch-all and don't give out the primary address; I give each service it's own address) 3. A bunch of newsletters and forums (hackaday, etc) mention them by name every few weeks, often in the subject field, making it hard to search for. They don't send me any newsletters themselves, and I don't participate in their forums so there's nothing from them directly. They can't do anything about this, but it makes things harder. 4. If you enter a new email address that they've never seen before, the process exactly the same until after you click the magic link you received. They don't tell you they've never seen it before until you verify the address. 5. As such, if I can't recall the exact address I used to sign in, I automatically create a new account and don't find out until after I click the magic link and I'm asked to enter a new username or use the existing username they've already created. Proceed to settings and create a new API key for a new account instead of just adding one to my existing account.

This is an extreme case, yes, but I have similar issues with several services that only support magic links and GitHub login, and it's hard to configure services to use a new catch-all address when they harvest my address from GitHub login and won't let me change it. Magic links are a great tool, but they should _never_ be the only option. They should supplement existing login methods. Password managers exist for a reason. Several services that I have since stopped using for this reason have in the past decided that they should start sending emails to the addresses they harvested from login with other service. Two services have gotten my magic link address stuck in their system because it's not associated with an account (the account has been deleted) and thus I can't manage subscriptions.


One maybe non-obvious benefit I see in that from the individual Tailscale user perspective is that only having SSO rather than username/password keep the security of my login in the same bin as the larger customers where Tailscale makes their actual money.

A username/password would be perfectly fine for my use-case as an individual user using Tailscale for my homelab and personal devices. But I suspect the majority of real paying customers don't want a separate authentication flow just for Tailscale and would rather use the SSO they already have. I have confidence Tailscale wouldn't half-ass usernames and passwords is they offered it even if it was mostly just for non-paying hobbyist users, but I'm also sort of glad I get to bucket my account security risk with the people paying their bills.


You become responsible for keeping those credentials secure, among a whole host of other problems. (Abuse like credential stuffing (more), data breaches (more), account farms (more), and so on.)


How are the requirements weird? They support any OIDC endpoint whether your own or a vendor’s, and, while uninteresting to HN folks, they also now support passkeys for having no SSO provider at all.


Yeah, I have my Tailscale tied to my Apple account, which just feels weird. I can add a Passkey account to my Tailnet and make it manager, etc., so that’s what I’ve done. The owner is my Apple account, but I actually do everything admin-wise with a Passkey account.


Oh I had no idea they supported Apple. Maybe they didn't back when I signed up? I'm seemingly stuck with GitHub forever now though.


Should be possible to change, just not automated. You have to reach out to support.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: