Hacker Newsnew | past | comments | ask | show | jobs | submit | setgree's commentslogin

And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously?

I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.


We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps), there were enough reviewed apps that were used for fraud or access as bad actors.

My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop.


Just because there are known vulnerabilities don't mean we should drop other security features, this is the opposite in fact. Defense in depth, an OS-level vulnerability cannot be exploited if the attacker cannot access that part of the OS.

And like it or not, the Play Store approval process is a security feature. It limits the ability of bad actors to run code on your phone and access data or exploit vulnerabilities they wouldn't be able to otherwise. Some get through, but it makes their life harder, again, defense in depth. Something can be both an anticompetitive practice and a security feature.

As for banking in the browser, you can, but your bank probably doesn't like it. That's why they are pushing for browser attestation, or to force you to use the app. The banks would rather take that freedom away from everyone rather than giving it to everyone. And I suspect they do it for good (as in profitable) reasons, fraud costs them, it costs them more than what they would gain by being more open.

If we want security features and freedom (which is the harder option), we need competition. If Google and Apple are the only players besides an insignificant minority, it is easy to lock software to these platforms, screw that weird guy with his Linux distro. Legislation is another option if the first one fails.


Sandbox, ACL, scan, sign, revoke bad actors.

We should have web installs by now. The only reason we don't is because Google and Apple like cash and their little monopolies are easy money.

Big tech loves to "protect us". See Anthropic and OpenAI worried about intelligence.

Google doesn't care that its AdSense ads marketplace is flooded with malware. Or that YouTube is rife with scams. Wonder why not. The blatant policy contradiction couldn't be because money, right?


Do people not remember the days of viruses destroying computers?

They were a massive issue before, and now they're barely a thought for most people.

These review processes have been good for the general population.


I believe people in HN also remember the days before we had MMUs.

And I'm sure everyone remembers ransomware.

No one is saying OS shouldn't have security measures, permissions/entitlements and app sandboxing, user land, etc.

I still don't understand why my desktop/laptop is allowed to be 'owned' by me. but my iPhone is a closed-gardened where I'm just a guest in a device I own. and that's nearly what Google is now doing.


> They were a massive issue before, and now they're barely a thought for most people.

Even on desktops... where there are no such review processes. Apparently we've found other mechanisms to reduce those issues, without app stores everywhere.


They're still very much a thing on desktop. You're not wrong that Windows got better at protecting itself, but I suspect the reason you don't hear about them is just that few people use desktops anymore (other than developers who, for obvious reasons, are typically less prone to be infected).

Anecdotally, at least once a month for the past several years, I notice a youtube channel in my feed get hacked. Their usual content gets replaced with crypto, Roblox, or Elon/SpaceX spam. Big channels, small channels, it happens to them all.

There's usually a post-mortem when they manage to regain control. Every time the infection happened through a virus attached to an email or by following a link on their discord.

This kind of attack simply cannot happen on mobile (unless your phone is rooted and you have disabled all warnings).


What review processes on computers?

I didn’t write the previous comment, but I think the point here is that there is a long-running trend aiming to protect users both from malicious intent and to a certain extent from themselves. In the past, viruses had it easy to infect and spread computers because of both inattentive users clicking on mails claiming someone loved them, and the default access mode for any user granting them admin access.

Even though review processeses generally do not exist for computers, they are part of that same trend.


mac app store / windows app store

And outside stores we have Windows’ UAC and Mac’s annoying-but-understandable “this dmg is sus” dialogues. Granted they are review processes but they’re often what keeps common users from wrecking their devices.

> We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps)

Vulnerabilities aren't intentional.

> reviewed apps that were used for fraud or access as bad actors

The App Developer Verification program, Android Advanced Protection Mode, and Play Protect are all systems put in place in response to "bad actors".


That's a tangential issue.

1. don't force auto-updates

2. still review apps uploaded to Google Play, but don't force users to use Google Play

If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play.

But the motivation here isn't just security, it's control. Google doesn't want anyone to have an Android device that is independent of Google services.


> If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play.

So this doesn't solve the issue pointed in the OP.

> don't force auto-updates

I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.


>So this doesn't solve the issue pointed in the OP.

Yes it does. This is their point:

> The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.

It should be as easy for me to use an alternate storefront - or download directly from a site - straight to my phone. The googleplay store, which is (somewhat) curated and (generally) "safer" can also exist. I, as a user, get to decide which path I want to take. This is literally no different from my desktop and laptop, we already live this life. MacOS allows me to download .dmg files and install (though they are admittedly getting increasingly annoying/friction-y about it) at my own risk. Why should my phone be any different? It’s a small computer. That’s it.

It’s about user choice. It’s my hardware, so I can do with it what I want so long as I’m not using it to inflict harm on others.


> It’s my hardware

I mean, probably not technically due to some EULA you were forced to sign which says the hardware is actually Google/samsung/etc and not yours. Giving them the right to brick your phone the moment you step out of the bounds they define.

We really need some sort of open firmware legislation that mandates manufacturers of computer components need to opensource their drivers and firmware. There's no "special sauce" in that software that warrants a company being able to keep it secret. It's literally just so they can force you to purchase new devices when they get bored of supporting their old devices.


Agree, what I'm saying is "it is mine and we should treat it as mine, same as my laptop/desktop." We both agree the current status quo is not that, I'm saying what it should be.

> I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.

this is identifying the tension yeah, but if a review process regularly takes weeks or months, then the security patches are still missing


And what do windows / linux / macos do about apps getting hacked to billions of pc's simultaneously? How is that a new problem?

If libraries didn't exist could not be created today. People tend to say that "it is impossible" when it actually only needs to be well organized.

Splitting git tech-monopolies it is a survival need. Or we do it, or we will end up with a collapsed society. Entities that spy on all citizens and gatekeep access to news and services are contrary to basic human rights and democracy.


> macos

MacOS has been moving to a more locked down model over the years - increasingly difficult to install unsigned applications, SIP, etc.

> Windows

I think Windows is incredibly impressive for its ability to run binaries from many years ago, but I don't think there's much people would point to as a positive regarding Windows’ approach to app security.


> but I don't think there's much people would point to as a positive regarding Windows’ approach to app security.

Yet life in Windows land is perfectly fine in 2026 and has been for at least 2 decades.

If Windows, which started at the bottom of the barrel security wise can make it, surely we can have more modern OSes that make freedom bearable?


How about treating people like adults for a start? How about starting public awareness campaigns about proper digital hygiene. Not everything has to be nanny state garbage.

I don't know. Literally every single person I help with tech support makes me doubt this is possible. People do not care in the slightest and treat suggestions to learn basic digital hygiene as if you've asked them to a computer science degree in its entirety.

Even super basic stuff like remembering a single secure password instead of reusing the same 2 or 3 basic initials-dob-symbol permutations that were probably pwned 10 years ago seems insurmountable.


A shocking number of people have passwords like "shovel"

When assisting friends of elderly relatives I was surprised to see that one of them had managed to set up a password of "a1".

IMO in that case its their own fault. After all they have free will and can use it against their own good if they so choose. Let them get pwned a few times and see if they learn.

that's so dumb on so many levels... should we strip cars from active safety measures and let drivers who are not super good at driving just kill themselves on the road?

I agree, but what I disagree with is the idea that everyone must be prevented from freely installing software on their own devices to make sure unskilled people cannot be tricked into doing it.

I don't really understand why a well designed sandbox and permissions system doesn't solve the problem.


Parent commenter's argument wasn't that people don't know to use good passwords, instead they just don't care. I think in that case getting hacked is completely one's own fault. If we're comparing this to cars, a closer analogy would be dying in a car crash because of an unfastened seatbelt.

Well cars kill people, granny using the password “password” does not. We can’t prevent all levels of stupidity and carelessness.

If people want to have dumb passwords and download malware, then so be it. You think they can’t do that today with the google play store? Of course they can. Most malware on android comes from the Google play store.


Maybe a drivers license should be needed to have a phone.

maybe there should be alternatives to using the smartphone for everything, personal finances included. my bank stopped offering a home banking service for example (yes, of course the mobile app still sucks), and it's a trend.

I've worked with dozens of businesses over the years and you can't even get businesses with real money and consequences on the line to follow basic security practices. My current project is updating dozens of windows domain controllers that are still on 2012 R2. Aka critical infrastructure that hasn't been getting updates for years.

Many of us have routinely cleaned computers from adults that installed several Ask Jeeves and Yahoo toolbars.

At some point computers need to stop being treated as magical boxes that no reasonable person can learn how to use safely. We expect people who use cars to learn how to use them safely, we expect people who use lawnmowers to not stick their fingers in them. Computers have been a part of daily life for normies for decades at this point, it's infantilizing to suggest that average, non-tech savvy people can't learn to use (not necessarily build, repair, etc.) them properly and need to be protected from them.

People have to successfully get through a state exam in order to drive cars in first place, can be jailed, get fined when not driving them safely, or forbidden for life to ever drive again.

People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.

What I would agree is that it is about time computing gets the same liability laws that the rest of the world already has in place and no EULAs that work around local laws should be considered valid in any form or shape.


Do you hate open source and want only projects where their authors can afford liability insurance and are willing to put themselves in the firing line of a legal system that can be both arbitrary and capricious? Because that’s what you seem to want.

Even people selling on the street or doing charity work have to account for liability of their actions.

Lets stop talking about open source as special snowflakes where everything is excused.


And that’s how you prevent bake sales, lemonade stands, and more. You create a barrier to entry that gets raised little by little until only the biggest players can afford the game. Software liability would end all small open source projects.

Bake sales and lemonade stands are perfectly fine as long as people don't land on hospital urgency, due to careless work on preparing them with spoiled ingredients or lack of hygiene.

Lets strive for quality in software.


Now do that again without careless work or spoiled ingredients. Do you still want them punished or facing so much regulation they can't exist? Because you'll definitely get that with software; even really good development will have flaws, and single flaws can lead to a thousand or million hacks.

All humans face scrutiny in their interactions with others.

Software only got this bad, because we educated users broken tools are acceptable and fixable with computer reboots and anti-virus.


I dunno, people seem to accept most kinds of tool being fussy or flaky.

But the special thing about security flaws is that they turn a one in a billion error into a guaranteed attack. It's moderately hard to make something that doesn't feel buggy, but ridiculously hard to be secure. If you hold to the standards of a bake sale it's the former. If you want full security then nobody releases anything outside very strict contracts.


Thankfully industry is changing,

- https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32...

- https://www.nsa.gov/Press-Room/News-Highlights/Article/Artic...

And I could keep listing several other world regions.


The problem is it's literally speech. Selling something isn't speech, you do not have the right to do charity work or run a business. It goes even beyond speech, it's closer to pure math/logic and I feel very uncomfortable about regulating that. I also think it's literally impossible.

Speech is subject to laws in most jurisdictions.

On power tools, appliances, etc. the safety features are at the user's latitude to bypass. They are usually a hint (don't microwave your dog), not a hard barrier ("I'm sorry, Dave. I'm afraid I can't do that"). A spinning blade is covered by a grill you can trivially remove without permission from anyone.

I agree that the defaults should be secure, but you can't force security on people without creating parallel issues which are maybe worse. Centralizing this power in a single point can have orders of magnitude bigger blast radius than a security failure on an app.

At some point users have to take responsibility and be accountable for their actions. We can't just infantilize them forever as if a magical hand will always be over them protecting and having their best interest in mind. And we certainly shouldn't punish every user for the sake of some of them.

The worst part is that Google gets the benefit of putting itself as the central point of control over the ecosystem based on a promise to keep users safe, but without any of the liability from failing to keep that promise. When the app store is chock full of malware I'm really starting to suspect that their goal is actually only the control. And all those people defending it with "but people don't know better, they need a hand to guide them" were equally misled. What do you think?


Yes, and when they fail to do so, there are laws in place for liability of third party, or when their own irresponsible actions affects others.

>People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.

Anyone is allowed to sue the lawnmower company. Did they win?


The amount of "Do not put hands here" labels I've seen on lawnmowers would suggest that, yes, someone did sue and win (or at the least got a settlement) and thus the lawyers forced the companies to put disclaimers and warnings on the lawnmower, directly on the top of the deck in plain sight.

Using a computer wrong doesn't kill people.

Yes and no.

The computer itself won't really do anything. But I'm sure suicides go up when people lose all their money, or get personal private details leaked, and so on.



> "One [software fault] was when the operator incorrectly selected X-ray mode then in 8 seconds quickly changing to electron mode, which allowed the electron beam to be set for X-ray mode without the X-ray target being in place"

Therac-25 is an important software-development case study but a torturous stretch of "Using a computer wrong"


You are right! Computer use should be taught, tested and licensed exactly the same way of steering several tons of metal at 70mph are!

Depends on what those computers are responsible for.

I'm sure you can think of many examples where it does though.

Well, computers first stop being magical machines that no person can learn how to use safely, then.

And, honestly, if you think the endpoint safety problem doesn't apply to you, you are part of the problem.


The endpoint safety problem obviously applies to me and every person connected to the World Wide Web, but the grandparent was talking about The Olds who install the AskJeeves and the Yahoo! toolbars and Bonzi Buddy and...

If computers aren't safe enough that a reasonably competent user, who doesn't open random files they found online and obvious spear-phishing emails, can't use one without losing their 401k, then maybe we need to just reevaluate modern life and go back to bank tellers.


And e.g. browsers cracked down on it, removed toolbar support and powerful add-on support AND enforced signing meaning everything goes through their gatekept extension store and these problems still persist (e.g. addons changing the search provider, new tab page or homepage). Locking everything down does not help.

> does not help

Is that true - do you not see significantly fewer of those installs on random PCs now than you did years ago? And that's even with the current situation not being what I'd call fully locked down.


Nope.

More a problem of those stores still not being properly validated rather a dumping ground for extensions, than anything else.

A problem that can't be solved, you can't check every single program out there much like you can't check every single human ever even with cameras installed everywhere.

Just because some people still die with seatbelts, does not mean they aren't safer without them.

Yes you can check every single program out there, when digital stores are the only acquisition mechanism.

Or as alternative, signed binaries.

Coupled with liability like anything else in our societies.


20 years of being tech support for countless family members and acquaintances says that nothing can possibly make people care about "digital hygiene". An iPad, Chromebook, or similar inflexible device is perfect for most people, and marketing more flexible devices to them has been a mistake since the beginning.

You expect people to treat devices with respect and responsibility? The VAST majority of people use their phones to stream an infinite sequence of clickbait, ai slop, and conspiracies for 6 to 8 hours a day.

I wonder if people would be happy replacing the "Google approves developers" system with a "government requires your ID and address on file so you can be held liable for your apps" system. I suspect not.

That is already a requirement in any civilized country. You cannot run a business without a registered ID, address, etc. for tax purposes.

For free (like for real no microtransactions) that is different. For the rest, they already have that.


It's virtually the case, google and apple accounts require ID verification, which in turn can be requested by the gov in case of an investigation.

If you don't agree with a decision made by your government, you can vote for someone else next time. If you don't agree with a decision made by Google, what do you do?

The people I vote for never win. Am I really any more empowered with the government than I am with Google? At least with Google I can de-google my life (with some significant losses of convenience, but it is doable)

Personally, I find it easier to live with a decision I don't support if I was simply out-numbered in a fair vote, rather than out-powered by some random company on some random continent.

As for doing without Google, I'm kinda doing that myself (using a Linux phone even). But tbh, I think that nowadays moving to another country to escape a government you fundamentally disagree with is easier than moving away from Google.


You probably have some sort of legal rights and ability to challenge decisions made by your government.

If you're banned from Google? Good luck, you're fucked.


The only part that would really be novel is the liability.

I would be shocked if you could publish an iOS app without Apple being able to tell the government who you are. Less because Apple cares and more because Apple requires you to pay, which is very hard to do anonymously for something like this (I’d bet the options they offer are effectively “credit card only”).


What for? Malicious actors have no shortage of stolen identities.

The app stores are neither necessary nor sufficient to curb malicious software. Conflating the centralized app stores with safety is a mistake that only serves the gatekeepers.

Just because something is not perfect that does not mean it's worthless. Most things security things operate this way where it's impossible to stop all malware or attacks.

When analyzing whether something is a net good for society, I look not only at the value it brings, but the cost that it brings. The mobile ecosystem normalizing the idea that the vendor that sold you your everyday computing device is the sole arbiter of what can run on that device is of enormous cost to society, but anytime anyone brings that up, there's an immediate retort bringing fear, uncertainty, and doubt about software obtained outside of those centralized silos.

As I've said countless times before, the answer is clear. Operating systems can install software from repositories. The vendor of the operating system can provide a default set of repositories. Third parties can also provide their own repositories. Device owners can choose what repositories to install software from.

Saying that there can only be one true repository is carrying water for trillion dollar companies to further extract money from their customers.


We could force Google to operate its app review service independently. Users could use it and pay for it, or alternatives. Currently Google forces everyone to use their own mediocre service and pay for it without knowing exactly where and how much you pay.

> And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously?

"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."


People accidentally hurt themselves with kitchen knives every day. They are also very often used for violent crimes.

Clearly we need to regulate the kitchen knife industry more. There should be a central authority that sells authorized kitchen knives with at max 6cm length and all other knives should only be available to certified chefs.

Once we have outlawed the longer knives and strong restrictions on ordinary kitchen tools become normal we should just outlaw knives altogether. You can still hurt yourself with a short knife. Only chefs should ever be allowed to own such a dangerous tool. Just buy or order readily prepared food. Why would you do this weird nerd thing called cooking anyway? Just choose from the official list of allowed foods.

The idea that we have to prevent people from being in control of their own computers — that's what a smartphone is — is deeply dystopian and authoritarian.


> People accidentally hurt themselves with kitchen knives every day. They are also very often used for violent crimes

People are rightfully nervous when they see someone walking down the street swinging a knife i.e openly misusing it or treating it casually

People don't realize how much software is being misused or treated too casually. They might be similarly bothered by lax security on databases and data leaks if they realized that it represented a threat to them


Yes, hold people accountable for their actions. Don't take away their freedom. We may prohibit individual actions that involve a general tool when they harm others. That is compatible with a free society. We may not prohibit fundamental tools¹ That is fundamentally incompatible with a free society. Especially when that tool forms the infrastructure for the flow of information and free speech.

[1] General purpose computing



Regulation is already addressing that. I encourage you to read up on the Cyber Resilience Act.

How about the same thing we do when companies leak half-the-nation's personal data twice a month. Nothing.

When companies get hacked and millions lose their personal data, nobody cares. When individuals get hacked, it's a major issue that justifies locking down consumer's hardware to protect them from the burden of controlling their own devices. See how that works?


How would a reviewer catch that?

> In some cases, though, its prose is denser than Claude Fable 5's: sentences run longer and there are fewer paragraph breaks.”

This sentence reads like Claude wrote it. Perhaps it did, or perhaps Claude has learned to write like the folks who work at Anthropic?

(Had I edited this, I would have said that a colon is not the right separator here. The second clause does not _explain_ the first, per se, bur instead expands upon it. Consider instead: "In some cases, however, its prose is denser than Claude Fable 5's, with longer sentences and fewer paragraph breaks.")


Going off of vibes, I guess this would call for a semicolon or an em-dash?

Also, could be just Claude rubbing off on them than it being Claude authored. I'd imagine they read it quite a bit.


It's fun to see that even an extremely large company can find unexpected product market fit [0]. Per this article, "The company reportedly did not possess an engineering team dedicated to business customers or staff focused on developer relations, and lacked an enterprise AI strategy." That sounds insane in retrospect, but I think there's just inherent uncertainty in what people actually need and will use things for.

[0]https://pmarchive.com/guide_to_startups_part4.html: "In a great market—a market with lots of real potential customers—the market pulls product out of the startup... The product doesn’t need to be great; it just has to basically work."


You should listen to the podcast Acquired, specifically Nvidia and then Jensen Huang. They basically lucked into AI. Some researcher was using Nvidia gaming cards, and reached out to them about questions on CUDA. That email eventually turned them into a trillion dollar question.


What year are you talking about? When I was in grad school, around 2007, Nvidia was aggressively marketing GPUs for high performance computing. They would go to campuses, talk to professors, etc.

Yes, the whole Deep Learning thing was luck, but as with most lucky things, they ensured they were positioned to capitalize on it.


Probably cerca 2014 as that's when AlexNet was released, demonstrating that neural networks could beat traditional ML models at image recognition tasks. I recall the researchers used Cuda to optimize their training setup.

AlexNet kicked off a new wave of research around neural networks by demonstrating they could be scaled well and trained on GPUs.


Yeah - definitely by 2014 they were well entrenched within academia with their CUDA offerings. By that point it wasn't "luck".


to their credit, there was a lot of work behind "luck". Jensen showed up in person in 2017 in NEURIPS and he and likely a lot of his top brass basically sat down and read the entire conference proceedings/abstracts; there was likely a lot of work behind the scenes to behind the ML research pivot.


And 2017 was _late_ in their pivot. They'd been active for much, much longer. Last winter break I sat down to watch every GTC keynote, going back to 2009[1]. Even then, he's talking about expanding to non-graphics workloads. Google's GPU paper[2] just slotted naturally into their existing narrative and were happy to support it. "fortune favors the prepared" as they say.

[1]: https://www.youtube.com/watch?v=fYuH2Kl_b98 [2]: https://scholar.google.com/citations?view_op=view_citation&h...


They definitely were sponsoring ML conferences before 2017, but symbolically, having Jensen/the CEO actually show up at a dedicated session and demonstrate detailed technical knowledge of the conference proceedings in my mind was a turning point. Albeit I remember his words to the crowd of grad students and post docs at the time: "Only Nvidia would announce their flagship card...to an audience who is completely broke!!"


Yeah, The NVIDIA Way goes into a lot of detail on how and why the pivot from graphics to AI happened. This is a prime example of “you make your own luck.” Jensen engineered an organization that was primed to recognize and pounce on the next big thing, and it ended up being AI. But they saw it coming WAY in advance (like 2011/2012, not 2017) because they were explicitly on the lookout.


> an organization that was primed to recognize and pounce on the next big thing

e.g.: previous crypto hype-cycle

https://www.pcgamer.com/nvidia-cmp-graphics-card-availabilit...


Crypto was a stupid fad, but Nvidia certainly made a lot of money, so being a vendor to a fad is not stupid.


Which makes it a Exempli gratia of "an organization that was primed to recognize and pounce on the next big thing." In addition, they also recognized early on some of the weaknesses of crypto-mining as an industry and limited their exposure while making a pivot to the next thing.


They didn't make their GPUs for crypto. Crypto companies just bought a lot of their GPUs.

If they had a choice, they would have sold every GPU to gamers instead because a crypto boom was always followed by a crash which flooded the market with used GPUs and crashed Nvidia's stock price.


> They didn't make their GPUs for crypto.

Sure they did and still do. They did a good job of managing the bubble but participate in the market nontheless. Read the above article: Nvidia has promised that its new lineup of cryptocurrency mining GPUs, called CMP for short, won't impact the supply of GeForce graphics cards for PC gamers. . . Since these cards are destined for mining rigs they will also lack video outputs. That may mean the resale value is diminished, which has been one reason why miners prefer gaming graphics cards.

Or take it from the horse's mouth [0]:

  NVIDIA Cmp Hx
  Dedicated GPU for Professional Mining
0. https://www.nvidia.com/en-us/cmp/


They made a dedicated chip because miners were buying up all the GPUs from gamers.

They also nerfed GPU hash rates through software to prevent miners from buying them.


AlexNet was 2012 and they explicitly called out the use of NVidia GPUs


In 2006. The next 20 years of cuda support weren't luck, as anyone trying to use AMD will know.


I might have believe this story, if not at the same time Intel had made an expensive bet on producing not-quite-gaming cards, later looked at the same trillion dollar question.. and then almost decided that this did not bring enough luck to keep spending.


Was this the case in the past?

My vibes were that Apple wound down the “actual work” side of their operations (including machines like Xserve), because Ives couldn’t handle the unsexiness and unpredictability of business requirements in hardware.

He was self-indulgent and only wanted to work on things that “vibed” with him, rather than what the customers needed. It’s easy to be creative when you get to do what you want to do, it’s hard when you have hard constraints.


Apple has not in the past three decades really courted the capital E Enterprise market. They'll definitely sell to Enterprise customers and have Enterprise sales teams for big customers. But they're not and never have been Dell or HP.

Enterprise sales sucks. There's infinite amounts of politicking and glad handing and buyers will get all sorts of sweet brib..."sales dinners" then go with the cheapest option. Margins on hardware sucks and the only money is in support contracts. Apple instead invests in consumer sales/support primarily and all the other channels are side businesses.

Stuff like the Xserve existed mostly for Apple internal purposes and ended up being sold externally to goose the scale enough to make them not a huge loss. At one point a large percentage of the offices on Bubb road were packed with Xserves running portions of the iTunes Music Store and the Apple online store. More offices were packed with Xserves doing media ingest and encoding for iTMS. Just about every building had racks of them as build and file servers.


I think Jobs was quite sceptical about courting enterprises. Personally this is one of the reasons I choose Apple over Microsoft.


Maybe a bit of hindsight bias / the outside view here, but I feel like they're completely asleep if they didn't anticipate strong demand for this specific use case.


I think a reasonable story could have been told that goes like this: local models aren’t as good as frontier models with a $20/month subscription, and the hardware costs a lot. So only a few enthusiasts will buy Apple machines for this purpose.

This story turned out to be false but I think smart, reasonable people a couple years ago could have believed it with conviction. It doesn’t really seem like “completely asleep” to me.


They were investing in ANE and Metal before everyone in consumer. Hardly asleep. They just underestimated the market size, as pretty much everyone did.


I don’t understand how that’s possible. They should have had a better idea of what was happening in the memory markets than pretty much any other entity.


Their universal RAM strategy is so obviously helpful for AI. (1) GPU/NPU <--> CPU RAM copies eliminated. (2) All (most) RAM available for GPU/Neural, when local models are typically kneecapped by limited GPU RAM sizes vs. the much larger RAM options for M/Max/Pro/Ultras.

They have been taking NPU's seriously on their phones, tablets and laptops since the M1.

Then they enabled fully-connected RDMA for 4 x 512GB MacStudio's = 2TB RAM. Perfect for a large Mixture-of-Experts model.

It would be very strange if they didn't notice their product line had landed in a new sweet spot.


FWIW, the reported reason for OpenAI buying Macs has nothing to do with the memory by the sounds of it. Every single outlet I can find reporting on this seems to repeat that the intended use case is for agentic workloads and generating training data for reinforcement learning. They don't appear to be doing inference nor any sort of training AFAICT.


For OpenAI, their data center archipelago is their own "local" and "personalized" AI.


I am curious about the corporate disconnect from the frontline to the generals.

While the company I am in is embracing AI the disconnect and delay between what is available and possible versus what is approved and permitted is a three month window. The State employees I speak to are just now getting around to writing their usage policies for internal AI usage.


Same here. For every little use of AI we have to fill out a 3 page proposal to get a PoC for 3 weeks in copilot studio (the worst AI builder around but due to MS lobby the others are banned). Then we have to find a business sponsor to decide it's useful, find 2 financial controllers to underwrite its token cost (even if very little), go through rounds of lifecycle and governance approvals. Then we can move to preprod but nooo we're not there yet. Now comes the security review and DPIA. That's another hugely complicated process that takes months. Eventually when both are done we can go the the deployment team and go through their process which I haven't even seen yet because most of our projects got cut off beforehand.

All the while the top of the company is of course praising AI and saying we should do everything with it right away.

It's a joke really. We had to go through all this rigmarole just for an agent that does some preliminaries on a service support ticket (making sure all data was filled in correctly and contacting the requester of not) before sending it to a human for final review. It couldn't action anything, not a single thing. Just assist with the prerequisites.

And yet they call our company 'innovative'. We're certainly innovative at inventing bureaucracy.


Tim Cook has been touted as the greatest supply chain logistics person on the planet and revolutionizing Apple's product delivery, securing exclusive contracts years in advance, etc., etc.

But "oops, we missed that people are interested in AI work on our machines" seems like a really fucking big myopia. But then again, Tim's off to retire on a bed made of cash this week, so...


It's also fun to see how many people here believed this was all some clear deliberate strategy in the first place rather than an accident.


They didn't "accidentally" add tensor units to the GPU cores in the M5 generation.

However, I don't think they expected the level of Enterprise interest they saw.


No ‘staff focused on developer relations’ is entirely unsurprising based on what I see from the outside.


That raw statement is completely and totally false.

“Not as fully staffed as some people might hope” or “Developer Relations isn’t as responsive as I’d like” are both at least not obviously false.


> "The company reportedly did not possess an engineering team dedicated to business customers or staff focused on developer relations, and lacked an enterprise AI strategy"

This is clearly a mis-statement, they have a whole annual conference for developers. Maybe they mean specifically AI devs.


Jeremy Irons's CEO character in _Margin Call_ explains his job like this:

> Do you care to know why I'm in this chair with you all? I mean, why I earn the big bucks?... I'm here for one reason and one reason alone. I'm here to guess what the music might do a week, a month, a year from now. That's it. Nothing more. And standing here tonight, I'm afraid that I don't hear - a - thing. Just... silence.

I'm sure many CEOs are bozos who can be replaced by a statistical averaging and guessing machine. But this skill of saying "it's time for us to dramatically change course because the music has stopped" seems to me very contrary to the current LLM paradigm. RL makes the chatbot agreeable ('aligned'). But changing course is inherently disagreeable. It makes enemies and people are going to try to talk you out of it at every turn. I think we'll need a new idea of what LLMs are for, and how to train them, before they can do that. (Much easier to mimic and therefore replace a Ballmer than a Nadella, in other words.)


i'm pretty sure that john tuld is not a bozo. maybe jared cohen, but he's a killer.


I enjoyed "up to an 80-core GPU, and a staggering 512GB of unified memory"

Staggering?? I can count on no hands the number of times that a fact or figure has caused me to stagger.


When you get that credit card bill for the 80 core, 512 gig, 16 TB storage box, you might stagger a bit.


Thanks for the laugh!


Idk 512GB of (essentially) ram is pretty damn insane for a consumer machine


This thing is going to cost >$10K, probably, which I think means it's not in the consumer segment


For the 512GB? You're going to be over $20K, fully specced.


Yes, but you've surely met people who giggled when they read that.


I get questions about academic papers I've written from non-academics sometimes. It's fun, I like that people are reading. However, some of them are clearly written by AI. I typically answer anyway, but on my most recent, I appended at the end:

> P.S. I intuit, and Pangram agrees, that this last email was AI-generated (and apparently so was the first one, now that I checked). As general career advice, I wish to observe that learning to write emails unaided is an extremely valuable skill in the dual senses that 1) writing is thinking [0] and 2) many people who receive an email they believe to be AI-generated will not be interested in corresponding, even if you're asking good questions, which you are. It would be a shame for that to get in the way of your research goals.

A polite, generic response like this is reasonably low-effort -- you must draft it once -- and might really help someone. Who knows though.

[0] hyperlinked to https://www.nature.com/articles/s44222-025-00323-4


it’s passive aggressive.

ultimately it’s better to not inform and start ignoring these people.

let natural selection work.


Natural selection is demonstrably not working. It only takes one look at a newspaper to see that thoughtlessness and stupidity are doing better than ever.

I think the internet is pretty great, but it's a major factor in that rise in at least 3 ways:

* Previously, an important check on fools was social consequences. Now they have an endless supply of people to bother. Spammers were the first to exploit that, but now it's endemic.

* Algorithmic weighting toward the reaction-generating (versus, say thoughtful, measured, responsible, accurate, helpful, kind) has rewarded idiocy and awfulness with attention and money. We're all now living in a reality TV show.

* As those behaviors become a major percentage of what people, especially young people, see, they become normalized. Otherwise people think being a thoughtless jackass is just how to get by in the world.

We are strongly in need of firm politeness, of militant decency. Without it, things will get "naturally" worse.


Natural selection selects for reproductive fitness, not intelligence.


I believe he's using it metaphorically here, and thus so am I.


People forget this far too often.


What I wrote was neither passive nor aggressive. My telling you now that I think your response was ill-considered is also not passive aggressive, though it's arguably aggressive.


this maybe a me issue

any kind of softness in language like “i’ll-considered” sounds so sterile that i sense hatred underneath. too much time in big companies.

more sharing a crazy person take on how different words can be interpreted counter to the intent.


I do not hate you :) I think you will probably have more positive interactions on the internet if you choose a different register to communicate in but I promise I do not actually care


ha! i like the negativity since the anonymous thing frees me to be me

i hate being civil!


Whats the worst that could happen if you read GP’s words in a positive bias? Best case you learn something, made a friend, amd trained yourself to look for useful feedback in the future. Worst case you improved your mood and moved on.

You’re in the prison of your own devise, the negative bias.


~salute-emoji~


What's passive about it?


Furthermore, what's aggressive about it?


don’t use ai when you write emails to me.

that’s direct and aggressive.

framing it as advice is the passive part.


Yeah, I have started ignoring AI generated stuff.


Directly telling someone that you have a problem with something they did and why you think it's a problem is not "passive aggressive" by any stretch of the definition.


Mindlessly calling things passive aggressive, is nearly as bad as pasting AI slop. Start working on your language skills.

And yes, this comment is passive aggressive.

See the difference?


oh, the irony!


Why is it passive aggressive?


when people write me ai slop.

i either ignore. or if i trust them i just say “don’t use ai slop”.

anything softer is passive and morally judgy too.

i’m not here to tell them what’s globally right, only how i want them to interact with me.


Ignoring them is more passive aggressive than the answer he gave.


First, I think it’s likely that you hear more about one than the other because you read websites like Hacker News and are not (I assume) an FBI agent or someone else who works on this stuff. A public defender I know would say that child abuse of all sorts is ever-present and relevant to their work, unfortunately.

Second, detecting CSAM leads to its producers who are by definition abusers. Here’s a nice article in Wired about the digital forensics of cracking down on a CSAM ring with some interesting details about the role played by crypto, and abusers’ misconceptions about it: https://www.wired.com/story/tracers-in-the-dark-welcome-to-v...

With that said, I agree that a lot of political concern for this is a smokescreen for a creating more surveillance. “think of the children!” has the flavor of a rhetorical trump card.


The goal of a modeling exercise like this, which you don’t have to buy, is to generate a simple set of initial conditions that can explain things we already know. Then, we can manipulate some initial parameter value to make predictions about things we don’t see, but might.

Likewise, it is obvious that gravity exists, but a simple model that explains where it comes from (in quantum terms) would be a big breakthrough iff it came with plausibly testable implications that could be tested via experiment.


I like the clarity, tone, and readability of your webpage. Also your FAQ is refreshing

> When Should I talk to sales? > Talk to sales if you need high-volume pricing beyond 2M credits/month, custom rate limits, SSO / SAML, SCIM provisioning, an uptime SLA, annual invoicing, an MSA / DPA, or a dedicated support channel. Reach us at hello@context.dev or through the contact page.

Would that this were the norm everywhere, rather than (say) a sales rep from Datadog scraping my phone number from who knows where to ask about my company's needs after I sign up for a free account on a whim :)


happy you noticed that, i put quite a bit of love into the ui, i've found engineers care alot about polish & feel of the webapps they use, even for an api product

i'm an engineer by trade, and always hated things like forcing a sales call, or having hidden credit multipliers, i tried to build this with the same ethos i like for my own dependencies (shoutout axiom.co)


I'm not an expert but I think this is an old lesson in warfare, that guerillas can triumph over larger adversaries by being more exploratory/iterative and less rules-bound. Tolstoy tells this story in the second half of War and Peace. Likewise with Iraqi militants wreaking havoc with IEDs. People repelling an invader have every incentive to move fast.


I've just read that section of War and Peace and was blown away by the descriptions of guerrilla tactics as well as Tolstoy's way of capturing the state of mind of the Russian POWs and their ever-shifting relationships with their captors.

As an aside, the word Guerrilla (little war) was coined during Napoleon's occupation of Spain to describe the resistance effort by locals and peasants against the French army.


That applies everywhere. You’re commenting on a forum for startups that compete against established players. David will always, in the long run, win against Goliath.


> David will always, in the long run, win against Goliath.

Every Goliath may, in the long run, meet a David that beats it, but this premise ignores all the thousands of Davids that don't win.


Historybooks are 90% filled with tales of exterminations, slaughter of citystates and permanent area destruction.

If you glass the villages and salt the fields, you even win against the taliban and vietkong.


> If you glass the villages and salt the fields, you even win against the taliban and vietkong.

You may win tactically, but you lose strategically - firstly by demonstrating that surrender is pointless, and secondly by creating a martyr movement across the world.

When you sow fields with salt, the only harvest you should reasonably expect is more blood.


Which binds the empire crime family together. This was how it was done allover until 1945. Its how its still done in russia, near china, how the middle east does things. That we "shall overcome" only applied to the west as a selfset achievement. And history tells us that the dead are forgotten. Nobody is out there avenging jews or armenians. Thus also the pro active paradigm of "better fuck around as a empire" then being "found out to be peace loving". Congrats to the anti western westerners, you won so much, you got the old world back.


"Some" David will always in the long run, win against Goliath. But many, many millions will be buried.


Thinking of past notable Goliaths: Ma Bell has been reconstituting herself from the split apart companies, IBM and GE are… alive, and Edison Illuminating Company and Carnegie Steel are alive in successor companies.


I'm hesitant to use 'always' language but the innovator's dilemma is indeed another application of the same principle. It's remarkable when a company like Google can pivot in a way that threatens its existing core revenue streams.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: