Hacker Newsnew | past | comments | ask | show | jobs | submit | ratherbefuddled's commentslogin

Turning this on by default is insane.


I am fine with this, and I will go as far as to say this is how most devs will be using agents soon (the big companies have already been using agents like this for 6-12 months.)

I don't want my agent to pause on some inane question once I let it loose. I might not even be at my computer for that. Usually it makes the right decision anyways. If it doesn't I can always undo what it did.

If you're worried about it getting the architecture wrong, this is what Plan mode is for BTW. It gets architectural questions out of the way first, and just let the agent build from there.


"I love lax security features therefore you should too." Defaults should be safe and risky action should be done at the user's own discretion


This isn't really security-related. The "AskUserQuestion" hook in question here is not the one that gets used for authorizing actions. That's a completely separate mechanism that is unaffected by this 60-second timer thing.

What this is referring to are those follow-up "here's two plausible alternative ways to do this, which one do you prefer?" questions you sometimes get, and usually at the beginning of a planning session when presumably you're still actively involved in the session. They get exponentially less likely as the turn goes on.

Maybe it's a good default, maybe it's not, I'll wait to pass judgment. But it's not security-related except in contrived scenarios you could construct where one side of an A-or-B UserQuestion has security implications that aren't caught by any other safeguard. I haven't ever really experienced that in practice.


It's not security related. If you aren't running agents in a sandbox today, that's a "you" problem.

It's purely architecture/design related and the last thing anyone wants is coming back at the end of the day to find their agent didn't make progress because it was stuck on a response.

You can always redirect the agent or scrap its work, you can't undo the lost time.


There are people who like to be pissed on, it doesn't mean it should be a default behavior.


I couldn't be the polar opposite. If my agent is asking a question, that means I didn't do a good enough job building enough context (not necessarily a good prompt, but context).

I have a hook that checks for a 'non-answer' from AskUserQuestion from when there was a different bug. It just so happens to be an accidental safeguard for me in this case.


Who uses plan mode anymore?

Superpower:brainstorming for the win, in auto mode because auto mode is the only mode now.

Superpowers already, generally, figures out to keep the questions up front, so during implementation it doesn't stop.

I've only had frustration with the 60 second timer.


I’m pretty sure I used plan mode today and it continued when I didn’t respond quickly enough. Though now I can’t recall whether it was Claude or Codex. In either case terrible default.


Codex apparently added this too, I only noticed a few days ago: https://github.com/openai/codex/issues/28969

I'm usually at my desk, and get a notification when it stops to ask a question, so I've never accidentally had it timeout yet. Still an annoying change.


And yet other people rely on it doing exactly the opposite. Aside from whether this behavior is useful, it is never warranted to change such an important thing unannounced.


You only live once, right?!


I read this as "Claude integration to Slack is now billed as API usage". Is that wrong?


nailed it.


Sometimes I wonder if people understand what "non-deterministic" means?

These things are generators of pleasing words. They are random and not at all thinking.

Why would anybody think that prompt guardrails would be effective?


Typing ten extra characters is an investment that pays off vs the overhead of doing any piece of work in the future. There's no real downside here, it doesn't make the code more complex, it gives less surprising results.

I think you are conflating YAGNI and premature optimisation and neither apply in this case.


It's not that it must be registered (incorporated) in Germany. It's that for tax purposes if the company is run from Germany it will be considered "permanently established" and treated as resident there. Permanent establishment laws are often quite surprising to people doing business across different territories.


> If I've got a long, random, unique, securely-stored password, I don't actually care about having a second factor

I'm not comfortable with my entire online identity being protected by a single line of defence which is a company that I'm paying a few dollars a month to. Not having to type 6 digits off a phone is a pretty minor convenience for me.


Do you then avoid syncing any passwords to your phone to avoid having your two factors in the same place? (And similarly, avoid syncing SMS to any devices where you do have passwords.)


I'm more than happy to pay for DRM free epubs. I won't pay for a crippled rental of a book that only works on amazon or adobe blessed devices and can be confiscated on the whim of a corporation who won't be answerable for it.


Having just had solar and a battery fitted by Octopus I'm interested - would you mind sharing what you use for automation here please?


Sure, I use Home Assistant running in a little raspberry pie in the lift.

There is an Octopus Integration that exposes current prices (and much else) to HomeAssistant.

There is another Integration that works with my solar panels and another that works with my batteries and can change mode (self use, force charge, force discharge etc.)

So from there it’s really just a question of setting up some if-then automations to turn on smart switches, charge the batteries if prices go negative.

You can also gradually add more nuanced automations like turning on water heaters if the panels are generating more than 1kW and the batteries are over 90% charged.

I’m not a programmer, it’s all fairly easy to do.


Thank you, that's really useful.


Not op but may I suggest looking at Home Assistant, Octopus Energy Addin and Predbat: https://springfall2008.github.io/batpred/energy-rates/


Thanks very much.


There's very little reason that Google should have been protected from the evidence of its wrongdoing being made public. That's not extrajudicial punishment, that is public record. Justice should be seen to be done as well as done.

Who can know how appropriate or not the remedy was when the evidence is hidden?

For full disclosure: I'm neither a google employee nor a US citizen.


Sure, there's a strong public interest in having proceedings on record. US civil cases are supposed to have a presumption of openness, which the judge weighs against other interests, like protecting trade secrets, confidential business information, privacy of third parties, etc.

The public record argument is fine; it's just a different argument than the extrajudicial punishment advocated by the original post.


I think the extrajudicial punishment he's advocating for is the wrath of the court of public opinion though? Unless I'm misreading.


The public interest is in judging the trial process, not in judging the defendant.

Suppose the government charges you with murder, searches your house, and finds your sex toy collection. At trial they present some elaborate thesis about how you used a sex toy to kill someone, but do not convince the jury, so you're found not guilty. The public has a legitimate interest in judging that the trial was handled with integrity and that the correct verdict was reached. They do not have a legitimate interest in judging you based on whatever private information presented at trial might in some way embarrass you (eg, photos of your sex toy collection). On balance, it could be that the public-record interest does in fact justify making public the evidence of the sex toys, but you have to justify it on those terms. The transparency is not itself intended to be punitive.


We are talking about an extremely powerful corporation in an antitrust case not a person. It does not need to be defended in this way, which is a level of protection rarely afforded to individuals.

There is a definite public interest in understanding how Google conducts itself given the reach and impact it has.

There is no way for the public to have confidence in the trial process if it is conducted in secret, and given the outcome every reason to question the process.

I'm surprised anybody objective would defend this.


I read it as "stop asking me the same thing over and over again, I've already told you". It's a shame that the no doubt hundreds of UX people at Netflix are so sloppy.


I think a bit of both.

The last two paragraphs talk about "harried parents", and "world doesn't revolve around children." sounds like having kids is a burden and resentful of the impact of people having kids on his life.

Its quite a lengthy rant about a minor UI inconvenience.

There is also a problem with the "never ask again" option. How long is never? Someone who does not have children now might well in a few years time.


LOL, next you're going to infer the author is a childless cat lady, who started regretting not having children.

It's quite a lengthy rant about prioritizing everytime inconvenience over a setting switch that could be enabled once, after a few years time.

World doesn't revolve about your children (or mine. And yes, I have them and yes, this is one of these mildly infuriating UX decisions).


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: