Hacker Newsnew | past | comments | ask | show | jobs | submit | msdz's commentslogin

This is the correct response, but it also feels as though ≈nobody is sandboxing their agents/harnesses in practice. Or at least, a good majority isn’t.

I think there is a cycle, like with most things of this nature.

You start really locked down, and you read and approve every request for access. You do this for a while, but never see a result you deny, so you stop reading as closely. You keep hitting that approve button. You start paying even less attention to it. You start feeling silly, like you are simply slowing the process down. You get frustrated, because you keep coming back to your session and realizing your agent has been stuck waiting for approval for a long time, and the task that would have been done by now hasn’t even started.

Now you are running even more simultaneous sessions, which means more and more of your agents are stuck waiting for your approval. You feel even sillier, because you are taking even less time now to review and approve requests, but your review step is causing more and more slowdowns because you have more sessions going so you take longer between approvals. You feel like you are spending most of your time cycling through sessions hitting approve. You still have not come across a request that was dangerous or would have caused an issue, so you feel more and more like you are wasting your time.

So you slowly start to give your agents more access with fewer review steps.

Maybe this results in a catastrophic failure at some point, or maybe it doesn’t.


> You start really locked down, and you read and approve every request for access.

Or you start out with almost every permission granted always, but the entire thing runs in a sandbox with the minimum amount of credentials needed to do its work… Sounds preferable to me to catastrophic failures :-)


AFAIK, I know plenty of frontend engineers that without blinking run "npm install" on random 3rd party projects they find on GitHub, and they do their banking and everything else on the same machine. But then again, I also know people (one person to be fair) who have unprotected sex with prostitutes, so maybe something makes me slightly biased here.

Now you know two! (granted I was 15)

I mean yeah, there are a ton of people who are stupid enough to disregard all kind of safety precautions. That doesn't mean the safety precautions are invalid though.

Same. Models that are fast (and thus by extension, in some direction, efficient) but not local/self-hosted IMO fill a niche for quick and cheap (and acceptable quality, of course) inference in business contexts.

In fact, I’d go as far as to say there’s few companies I’d entrust less the level of data required for a tool like a “personal AI agent”…

OpenAI is next on my list

Only one i'd trust less is SpaceX, and they're other major player in this space...

Agreed, but do you think either of the two federal/state governments would even have enough support material available, whether in the form of capital or otherwise (i.e. contracts), to give to Isar Aerospace that would enable them to compete with (at current valuation) a giant like SpaceX?

Bavaria is one of the most richest (if not the most) state in Germany. By GDP alone it's the 7th largest economy in Europe (https://www.vbw.com/int/About-us/Facts-about-Bavaria/index.j...). Of course they have money to support Isar and they should do it to diversify their economy and break the heavy dependency on auto manufacturers.

(As a Bavarian,) I’m acutely aware of the state’s economy – but my point is that SpaceX has an even bigger economy behind it, if the two were to actually be compared or compete.

Good point re/ depending on auto makers, though. That also applies to all of Germany…


Bigger economy, yes by about 10x. But despite the spectacle, SpaceX's actual expenses have been around 0.3-0.4% of German GDP in recent years.

It's priorities rather than absolute costs that matter here. Germany could absolutely do all of SpaceX as almost a rounding error, but probably has better things for that money to get spent on.


> Isar Aerospace that would enable them to compete with (at current valuation) a giant like SpaceX?

Compete, sure. But disregard SpaceX's valuation, that's driven by Musk's cult of personality rather than business fundamentals.


Exactly. Existing paths, entryways, factories, etc. are human-sized and -shaped (or car, or other vehicle).

Only once you build greenfield, e.g. new factories, making specially shaped and sized robots for automation jobs becomes worth considering, IMO.


So basically, humanoid robots are just good for prototyping before the big boy robots show up to do the real work.

Exactly what humans already do cheap and easy.

No reason for humanoid robots.


> So basically, humanoid robots are just good for prototyping before the big boy robots show up to do the real work.

That might be our future. However at the moment humanoid robots aren't good enough in general to be good at prototyping.

> Exactly what humans already do cheap and easy.

Human work hours are becoming every more expensive, thanks to lucrative outside opportunities.

> No reason for humanoid robots.

At the moment. This might change in future.


Pretty much all existing factory automation has _not_ used humanoid robots.

Hm, true that. I’m guessing because the typical factory was already larger/taller than human height? (Thinking of e.g. car production)

I'm guessing it's because making specialised robots was so much cheaper and easier than usable humanoid robots.

See also the humble domestic dishwasher. It's a robot that washes dishes and works in an environment that's otherwise sized for humans and hasn't really been redesigned to accommodate robots. Similar also for washing machine and dryer etc.


> we can't block models from scraping the public repos

FYI, there is the nuke option, which is generating endless nonsense pages as a form of “bot sink” [1] that ends the scraping relatively quickly, but IIRC that also tanks your search rankings, since it likely affects benign crawlers too – not something you’d necessarily want to happen to a new domain, unless you really need to protect server resources against aggressive hostile crawlers like SourceHut and so many others had to combat.

[1] https://www.toxsec.com/p/ai-tar-pits-are-drowning-llm-scrape...


Facepalm

> means... you can run for 10 seconds every minute?

It’s one order of magnitude less TPS, but still, that’s the limit with just one user…


My take is that the difference is simply down to visibility, and by extension broader understanding, of the issue:

- Cameras film me and my family and neighbors everywhere in daily life => Obviously an issue

- Something about secret agencies maybe (?) reading along my messages => “I’ve got nothing to hide in there anyway”


It's also an issue with an obvious visual signal. My phone company is scanning messages? Oh, all the phone companies are scanning messages? Using some opaque approvals process that the government intentionally hides from the public? Not a lot anyone can do about that from the outside.

Cameras on our streets? Well, those were put there by local law enforcement and city councils, who are much more accessible (even though I'm sure they wish they weren't). If the camera is still there, it's still a problem. And if all other options fail, well, someone is probably willing to take the risk to cut that camera down.


100%. Articles about obscure codename operations is a lot harder to grasp than "You are tracked at all times via your phone and license plate and here are the images to prove it".

It's the same as how communities respond to egregious law enforcement abuses. Accusations get nowhere as opposed to undeniable video of things like George Floyd.


“See that thing? It’s watching you” vs. some complicated story about room 641a… I agree, it makes a degree of sense.


> 99% of the energy going into the distro

While not commenting on the rest, I just want to point out that Omarchy is not a distro (yet?).

Source: https://xn--gckvb8fzb.com/a-word-on-omarchy/?:~:text=Wikiped...


So I can somewhat speak to this, as I actually did this for a while c. 2021 and 2022.

The issue (apart from my Mac mini still having the old, bigger form factor back then) is that this requires a full shutdown (obviously), and that is more friction than opening a closed laptop lid. It just takes a moment for every app and background service etc. to settle back in after, and depending on how your brain works, you might not like that a whole lot.

It absolutely is a cool feeling to carry a pretty mighty desktop in the backpack, though.


I think it's actually good to have a forced reboot from time to time, but then I'm not very disciplined in closing stuff I'm no-longer using! Especially like docker containers I was using months ago, that I forgot to shutdown.


Yeah, I agree (with the same unfortunate habit) – but up to twice a day of forced work full stop is overdoing it, too.


Is there no hibernation option ?


You don't get the option in the UI: there's just "Sleep", which on a desktop Mac seems to suspend to RAM only. At least, it seems to on mine, as I found out when I unplugged it.

(Apparently the laptops do a suspend to disk depending on battery remaining, so the OS does support it. It'd be nice to have it available! The disk space required could become annoying if you only bought the 1 TB SSD for your fancy 512 GB Mac though.)


Pretty sure hibernation is dead. Deep sleep states use such nominal power, I think they decided it wasn't worth it.


> that this requires a full shutdown

The mini sips a truly tiny amount of power. I wonder what the smallest/lightest UPS could could bundle it with would be.

But at this point.. you’ve got a shit laptop.


I did this for a few years, going further back in time.

The shutdown thing didn't bother me, and in fact the Mini was lighter than a Macbook Air at the time. So all in all it was pretty convenient.


Does macOS not have hibernate/suspend-to-disk?


What if you have some battery system working? Then technically, you could travel with it


At that point you lose too much convenience. Maybe if someone built a mini UPS with at least 10000Ah capacity, USB-C 4 pass-through and the right form factor to permanently attach it on top of the mini.



Oh! The fact that touch and pencil is natively supported for macos is neat!


And imagine plugging a small iPad screen into the thing with sidecar… Almost like a Macbook!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: