For the best experience on desktop, install the Chrome extension to track your reading on news.ycombinator.com
Hacker Newsnew | past | comments | ask | show | jobs | submit | history | baby's commentsregister

Am I paranoid or does this comment feels like what an LLM would write to imitate an HN comment?

Our experience has been that without a good harness you don't really get much out of codex/claude. And you really need to spend time and energy figuring out why coding agents can't find bugs like you can.

Every week I see bugs (as an auditor) that our own harness (https://zkao.io/) can't find, and we have to figure out pretty interesting techniques in order to make the tool find them. Mind you I'm talking mostly about cryptographic vulnerabilities, not just webapp bugs. So IMO it's going to make a lot of sense for companies to have both their own harness (as tptacek is talking about) and pay for services that focus on making a good harness from experience (and audit firms are going to be the best at doing this, as they see a lot of bugs and can spend time "teaching" their harness about these bugs)

On the other hand, you have to find equally as good techniques to triage, because otherwise you just have some machinery that I call "vibe auditing" that just produces enough false positives to tire all the developers (who are already overwhelmed with crappy AI submissions in bugbounties and other AI tool that review all of their PRs).

At the end of the day, when your harness doesn't return any bug, you're left wondering "does it mean there's no bugs?" We're basically back in this reputation game, where you want to use the best tool, or the best team (that knows what the best tools are), and need to figure out which one is.


I would recommend the book over it

Would recommend reading the comic instead

I read all the persepolis comics a long time ago and to my memory it was the first time I cried reading a comic. A beautiful work of art. I would recommend to anyone reading this comment to order the first book.

What annoys me the most is that I can’t efficiently track my emails with the default. It’s unusable imo if you have a lot of emails. What I ended up doing was to disable read on preview, and enable shortcuts, so you can navigate with vim shorcuts and have to manually mark emails as read.

Android is better because they allow you to change individual notifications right from the notifications themselves + granularly do it there also.

On iOS I have to find the right setting page and then all notifications are either on or off. Doesn’t make sense.


You can long press on the notification (or swipe left?) and pick "Turn Off..." among other options

https://support.apple.com/en-us/108781#manage-alerts


turn off is the only option basically, try an android phone bro


This only works if the app properly tags notification categories, no?


It also shows what category the notification was tagged with. An app that improperly tags notification categories gets one of two results from me:

1. Uninstall the app

2. If the app is non-optional for some reason, block all notifications.


I dislike this argument because it’s about limiting the most powerful technology we ever invented because it doesn’t fit well with how we established some social structures.


I think "most powerful technology we ever invented" is a controversial statement anyway -- AI is a party trick of dubious value.


Oh boy you’re going to get hit hard by this technological wave when you wake up


>the most powerful technology we ever invented

I recon agriculture and the steam engine would beat out ChatGPT by just a smidge.

I would put eyeglasses/the book/vaccines/sanitation far above LLMs in technological power.

Right now AI is just kinda nothing, it has potential sure, but today its just a giant pit for people to burn money in.


Solving one of the most famous Erdos problems that has remained unsolved for 80 years without using tools like lean but instead a giant reasoning block is quite a lot more than "kinda nothing"


Solving a math problem is very close to nothing in the grand scheme of things. Humans have been solving math problems for thousands of years.

I think people suffer from recency bias with AI a bit and take for granted you know gestures vaguely at the rest of human civilisation


What are you referring to when you refer to the technology of agriculture? Like John Deere's latest tractor? GMOs? The shift from hunter gathering to agrarian society?


>What are you referring to when you refer to the technology of agriculture?

Planting crops and harvesting them.


I disagree


I still call it bard


Should I do my usual rent about how the web PKI refuses to move to a consensus protocol


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search:

HN For You