Hacker Newsnew | past | comments | ask | show | jobs | submit | oefrha's commentslogin

I’m paying $200/mo for non-crap versions of said “general-purpose problem-solver tool”, which is not far from the median income of “everyone on the planet with Internet connection”. And I’m told I’m already getting a huge discount by using thousands of dollars of compute by raw API pricing. That just doesn’t sound like peanuts at all.

The $200/mo version you're paying for today is the one that will be ~free for everyone in 6 months. You're only paying to use the bleeding edge of technology that improves so fast, and drops in costs so fast, that the entry-level free offering today is better than most expensive tier a year ago, and beyond science fiction just three years ago.

I swear most people dissing AI with such arguments must perpetually live in a moment and have zero concept of passage of time.


I fail to see how I’m “dissing AI”. I use it almost every fucking waking hour after all, both professionally and personally. I just don’t pretend it’s free/cheap (especially when you mention it in the context of “everyone only the planet”), or even more ridiculously, some charitable gift from Big (AI) Tech to the world. And if you look into my comment history I’m pretty clear I support IP free-for-all; cat’s out of the bag, just don’t talk two-faced nonsense like “distillation attacks” and I’m fine with it. And as a prolific open source contributor with popular projects, including at least one under GPL, they definitely stole from me—again, fine with it.

They did say how:

> We then placed Claude in an autonomous /goal loop against our own Discourse Cloud instance, proxied through rce.ee/ctf-forum to make it look like a CTF target as Opus refused write exploit for remote instances.


Unsandboxed ImageMagick is known for being a security nightmare even back when PHP ruled the world (not saying sandboxing is a panacea either, it just requires a different and potentially harder exploit to develop a full chain). Difference is it's easier than ever to turn vulnerabilities into full compromises. At some point we'll have to replace all parsers with something at least as safe as https://github.com/google/wuffs right? Otherwise ImageMagick and co. will just keep giving.


At this point writing a media file parser in C/C++ is absurdly stupid. The same thing happened with libjxl.

Also libwebp.

It does make me wonder how much this could be hardened by, to put it in an extremely crude way, taking the current imagemagick code base and throwing a bunch of adversarial SOTA LLMs at it to discover 'bugs' and exploits of this nature until it can be coaxed into a less dangerous state. Or even using the LLMs to fully port its functionality to a memory safe language. Would take a while to get all the changes approved and then into various distribution imagemagick packages.

I suspect the latter is much easier and cheaper than the former? You can port a lot of software with cheap (or even local) models if you're tenacious whereas finding all the bugs is both very very expensive (if it's even possible) and potentially never ending (there's always new code and bugs!).

Maybe these big ai labs will uses their own devices to find and fix bugs up and down their stack and contribute that back.

PHP still rules the world, even though many doesn't want to realize it. It's still the biggest web language by a far margin

Phones don’t “rule the world” of cinematography, despite the majority of videos being from phones. The serious stuff, professional and personal, uses cameras.

too powerful to give up, sweet imagick love

Kudos for at least admitting upfront that it’s pure slop, I guess.

The quota consumption is based on the upfront possible number of connections given the query, not actual connections, so deeply nested queries can be very expensive if not aware and careful about it.

In this case CSS-Tricks got paid $4m first, so probably the wrong entity to be complaining about funding. But maybe the lead editor in question who’s not the creator didn’t see much of that?

CSS-Tricks didn't get paid $4m. They got acquired. The previous owner of CSS-Tricks got $4m.

Got acquired => got paid. CSS-Tricks the entity (up to the point of acquisition) got paid the money. If and how the money was divided between the people involved doesn’t seem be public info.

It wasn't divided.

This is certainly not just affecting interim releases. Ubuntu 26.04.1 has been released but is currently held back from do-release-upgrade for the LTS channel (which IIRC is unusual for a LTS's .1 release) due to rust-coreutils issue:

> Users of Ubuntu 24.04 LTS will be offered an automatic upgrade to 26.04.1 LTS via Update Manager a couple of weeks following this release after some planned backports to address regressions in a recent version of rust-coreutils.

https://discourse.ubuntu.com/t/ubuntu-26-04-1-lts-released/8...


Given that Safari needs the most debugging and automation tooling for Safari was hardest to come by, this is a welcome change. I wonder if it works with pages on a connected iPhone though? Anyone tried it? Because debugging on iOS Safari is the most maddening. (No, responsive design mode doesn't cut it, iOS Safari has its own special bugs that don't manifest in desktop Safari merely emulating a phone viewport.)

Not to mention my $299 total Tailwind Plus lifetime license (was TailwindUI, then paid the difference for the Plus bundle) has like 100x more stuff in it than $90/yr or $149 lifetime for—check notes—11 UI transitions...

Alternatively, it's all made up bullshit. It's not like they're gonna be sued for libel, so they can say whatever they want as long as it suits whatever narrative they're pushing at the moment. "Look at all this scary stuff! (But we definitely didn't do any real damage!)"

Yep, they're probably working with the US to try to drum up anti-Houthi propaganda.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: