Hacker Newsnew | past | comments | ask | show | jobs | submit | radicality's commentslogin

Oh, interesting, I feel like a year so ago I read something posted from openrouter team that they write that credits expire, but that they in actuality don’t expire them. But maybe I’m misremembering, or perhaps that’s changed for the worse in last few months :S

We started actually expiring the credits a ~month ago. If you make any kind of API request, it resets the clock. We try to make it a very generous policy, but we can't keep a monotonically increasing liability on the books. We end up owing (a lot) of taxes on it, but can't actually recognize revenue. We would much rather you spend the credits! Hence the reminder emails, and generous "clock reset" policy.

> but can't actually recognize revenue

Hmm? You have the revenue already. I know it's awkward from an accounting point of view, but you already took my money. "Letting" me keep the balance in the account is not generous.

Edit: on re-reading this came out more combative than I intended, sorry. I think what you're doing is reasonable.


I kind a get their reasoning. They cant recognize balance topup as revenue because then they'll owe taxes on full amount.

At the same time majority of money we pay them usually just gonna be an expense paid to actual inference providers. Then they pay taxes on their fee aka actual profits.

Its understandable, but it dont make 1 year expiration any good.


Absolutely no where is that shown to customers, and OpenRouter is going to be in a world of shit when people learn this by HN post and the business asks themselves why its reputation keeps taking hits.

What a fucking ridiculous thing for me to learn by social news.


Is this reset clock policy is actually documented somewhere? Because right now your website it's just say 1 year since credit purchase.

It has been at least a few months since I did some testing on my MacBook Pro m4, where I converted a bunch of camera jpegs to jxl losslessly, and yeah the jxl files were smaller, but the decoding/viewing experience on macOS was worse than with jpegs. Thumbnails were missing, and just browsing through a folder of them with QuickLook was unbearably slow compared to jpeg, perhaps at least few hundred milliseconds or even longer than a second, when the JPEGs were instant. Idk if that’s just Apples implementation not good yet, but that’s why I at the time abandoned converting all my JPEGs to lossless jxl


That’s great for the team. Though as a user of openrouter, I am worried that the much larger company will soon find ways to enshittify it :S


Switching costs are zero and alternatives are plentiful.

OpenRouter is a name.


What are some good alternatives?


Some other comments suggested https://cortecs.ai/. I never tested it, but from a brief look, it does seem a viable alternative.


You're right in that OpenRouter alone does not have embedded switching costs, but bundled with Stripe's other offerings, it creates lock-in.


I’m not sure if it’s been redacted from there, but try to do a request for a full data export, it might have the detailed data. I overall try to do that for all online services I use around once every six months or so, lots of interesting data in them.

https://www.amazon.com/gp/privacycentral/dsar/preview.html

Scroll down on that page to “request all data”


Aliexpress is also surprisingly impossible to search, you gotta use external search engines, I guess it increases there sales :S More than half the time for me on AliExpress a very specific search term will just return completely unrelated things which are either trending or related to my past purchases.


I was recently looking for a cheap IOT camera in a specific form factor from aliexpress and the results were so irrelevant I had to develop alternative strategies like finding one good result and checking under its recommendations or image searching from the one good result to see other using the same picture.


Is the Costco shipping good / good inventory / similar or same as in store prices? Should I consider it if living in a city like ny?

I live in central nyc, been only a few times to a Costco, and had no idea they even do any shipping! I assumed that part of all those good prices is the smaller selection, large minimum quantities, and that you have to get yourself there with a car to get it in person.


Costco shipping is "free," but the prices on the website are more than in the store. I'm pretty sure it's based on weight; heavy stuff has a more pronounced markup. But, it saves you a trip, and the prices are low to start so it still may be significant savings. There's also a web-only deals section for clearing out inventory (I picked up some Philips Hue lights for half off).


I don't purchase from costco.com regularly, but the selection is generally the same as in-store and a bit more. The shipping is free, but slower than Amazon and faster than a couple weeks.


There is ~10-15% markup for Costco online delivery orders vs in-store prices.


Which black mirror episode are you talking about? White Christmas? S02E07 afaik does not exist - Series 2 had 3 episodes - https://en.wikipedia.org/wiki/List_of_Black_Mirror_episodes


i misread the ongoing episode counter on wikipedia, it is the 7th episode of the entire series, indeed named white christmas


Openrouter has video generation also. They do have Seedance which afaik routes via something called ‚atlas cloud’, but it did work.


Did they literally just leave the water supply plant management software out available on the open internet? Hard to even call this a hack!


Yes. The last federal administration attempted to use CISA to encourage better cyber outcomes for water supply systems, and the water industry and Republican states sued over it. There is no will to fix this, only to push the liability elsewhere.

https://news.ycombinator.com/item?id=39243560

https://web.archive.org/web/20240409155326/https://www.awwa....

(cybersecurity practitioner is a component of my professional persona)


When will the public figure out that many IT exploits are the result of malpractice by developers and network adminstrators, and the businesses employing them? We're building and operating bridges that we know will collapse. Our products are nearly indefensible, literally - they can't realistically be secured except at great expense. We talk about the imbalance between costs of attack and defense; we made that imbalance.

The big LLM security threat is arguably just a revelation of the sh-ty work our field has accepted. Maybe we need to become actual engineers and invest in building proper, reliable, safe systems (which includes not being a dangerous risk for fraud, surveillance, and addiction). The 'anything goes' extreme disruption of many current SV corporate leaders and their technology is, in a way, a culmination of what they've always done.

The good news is that LLMs used properly might make proper engineering less expensive. The LLMs will more likely be used to make sh-t cheaper, so we can make more of it. Unless of course we take action.


Does anyone recall the Colonial Pipeline outage? They had their IT and OT networks segregated but without billing capacity nothing else mattered. You didn’t expect them to let the petrol flow for free, didja? All that it takes is for a “jump box” that spans or bridges supposedly segregated networks to be p0wned to permit compromise of the soft and chewy center.


I mean

Some of these municipal water plants in the US are independently operated by municipalities of awfully few people and even fewer resources to spare, often serving relatively vast areas…

It’s probably not how you or I would set things up—especially after many years of warnings and slick best practices guides-but I can sympathize with “if it’s not broken…”-style maintenance, especially at the local level.

These things have lifespans measured in decades, and budgetary cycles to match… and for all of CISA’s good work (on limited budgets, and with power that’s more persuasive than fearsome) [0], it seems hard to get all 148,000 [1] system operators to afford to care, much less to afford to fix things—much less to check their work.

[0] https://www.cisa.gov/topics/industrial-control-systems , and https://www.gao.gov/assets/d24106576.pdf for an idea of the staffing they’re doing it with…

[1] https://www.epa.gov/dwreginfo/information-about-public-water...


Who connected the systems to the Internet in the first place?

Why?


Most likely to cut costs and have one person remote-admin all pumps, valves, etc. instead of a crew for each location.

Why didn't they have firewalls, admin accounts, access rights, you know, proper security? They were glad it barely worked at all.


Ha, for a brief moment I thought VM=virtual machine and not voice mail and was scratching my head how you set that up and what the VM is doing with the call


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: