Hacker Newsnew | past | comments | ask | show | jobs | submit | sgc's commentslogin

Rather late to comment here, but are there plans to support Hebrew, Syriac, Arabic, and other scripts? I love the readability and elegance of this font in English and Greek, and would like to use it at CatholicLibrary.org.

It seems like the best course of action would be to argue he did not destroy evidence, just made it unavailable at the location to force the requirement for a search warrant. It would probably be a hard sell, but I can't think of a better argument (not a lawyer).

I became so annoyed by google's ai overview and front page results that I am using 99% duckduckgo as the least bad free alternative for the other leg from my chatgpt usage in this context.

I asked a question once and now there is a effing alexa for shopping toolbar that takes a quarter of the screen that will not go away no matter how many times I close it, and the space remains taken even if I adblock it. Absolutely hostile implementation. I have words for this I cannot type out.


what else did I miss today?


Supreme Court rejected Apple's last chance to stay negotiating a fee for using 3rd party payments in apps based on costs, so Apple asked the judge to force Epic into settlement talks and proposed a commission of 5%-15% that ignores "costs" because there are none and they feel the court's instruction to base it on costs is invalid.


fail2ban


I would argue about 30% of Apple's success was just from not being slow annoying bloatware. I could never stomach it, but I know a lot of people who basically rage-quit Windows for the Apple ecosystem. I did the same, but for Linux.


I agree. I thought everybody knew to never use docker for high security, because it is "security lite". Might as well just use firejail. I presume that an agent knows more about networking and virtualization than I do. The only real solution is using multi-tenant level vm isolation, while presuming that the agent still might break out of their vm. So the vms need to be hosted on their own physical box that only runs the kvm provisioning host (or similar), and is firewalled on its own isolated network. It's a bit of a pain of course, but anything less feels almost like security theatre rather than meaningful to me. Otherwise you need to stick to the remote chatbots only.


multi-tenant level vm isolation does not solve, imho, specific issues like data exfiltration (ssh private key, api tokens) or privilege escalation, as the vm still contains the whole kernel and userspace inside. So breaking out of the vm may be a realistic scenario.


Yes of course, the secrets have to be isolated from the VMs, preferably at the network gateway and not on the same KVM host. But as far as I know there is no safer containerization technology than a VM, and the only way to be more secure would be to have a physical computer per agent process? A KVM does not use the host kernel and user space, and provides hardware level isolation (the CPU hypervisor etc), that's the point. I think that once you are inside of vm, just using firejail is the better approach, since you have more direct control over the OS level controls that are being leveraged by various container solutions anyways. At any rate, that's what I did.

If you can't isolate a computer on your network, you probably can't isolate your network from the internet, so it's an irrelevant exercise at that point. And yes, probably you can't do any of those things and any frontier model could technically hack your network, but I don't think there's a better way to do it?


Many thanks for the insight. Actually you are right, kvm provides a different level of isolation. If there is a better way to do it... Not sure about that. It seems this is somehow unexplored territory right now, and the current hype about frontier-models capable of """everything""" is difficult to fight against. Entire VMs bring quite a lot overhead, though, I picture it as many agents being able to run in isolated environments in the very same dev laptop. My current approach has been to use podman so far. It supports libkrun, so I may give a try to microVMs in my current project.


What does it take to go from here to a model on a pcie card or an m.2 card, so I can plug one into my workstation / laptop? Will 'intelligence' become much like a gpu, where most people just live with the performance of whatever they have installed, outside large companies that must have cutting edge, or prosumers that have a incrementally better version than the masses?

Are we a couple years away, a decade away, or something else?


> What does it take to go from here to a model on a pcie card or an m.2 card

It is already that.

> Will "intelligence" become much like a gpu

As an option among the implementations.

> Are we a couple years away

They could mass produce now, but it makes no sense at this rate of improvements in the models.


Thanks for answering. This is an 8b model, which are mainly curiosities outside niche tasks. I guess I am asking how far we are away from having today's more generally useful frontier model equivalents widely available for everyday users in their personal pcs/laptops via a single pcie or m.2 drop in.


> how far we are away from having

It depends on AMD now. What was planned after the 8b was a ~30b, which is already sufficient (or more, when running at ultra-high speed).


The more common concept of margin used in this context is net profit after expenses, including labor expenses. The question is therefore roughly "How much is purely for capital profit taking rather than directly involved with compensating labor and purchasing materials?".


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: