Hacker Newsnew | past | comments | ask | show | jobs | submit | 440bx's commentslogin

Can the team please use that money on making thunderbird look like the nice UI mockups that were published that don't look anything like thunderbird.


Thought "hey this better not be AI". Yes it's AI.

Just keep making a decent browser and stop getting distracted on shit.


Your employer is a fucking moron.


Businesses can remain irrational for longer than you can stay solvent.


My life has mostly been making that as not true as possible :)


Tell me something I don’t know


I'm taking the radical approach of starting with the problem and finding a solution rather than start with a solution and hit all your problems with it.

LLMs have yet to feature.


Well it wasn't really a teaching revolution. It was a marketing job around a YouTube channel that purported to be a teaching revolution.

The thing is people want more than material. They want the material to be accredited and examined. Otherwise there is no demonstrable credibility from doing it.

And there's a whole world out there of higher quality material with has that accreditation and examination structure around it. And it existed, sometimes for decades in the case of The Open University, before Khan Academy appeared. But it costs money.


Promises are broken, policies are changed and political regimes vary. You need to make sure that you consider the future and not just now. And that means NEVER handing your data over in the first place.


That's easier said than done. Even if you don't directly use Google services, chances are that Big Data is still watching you on every website you go to. And if you have a mobile data plan, your service provider knows exactly where you are 24/7.


As someone who works on closed source software and has done for a couple of decades, most companies won't even know about that and of those who do only a fraction give enough of a shit about it to do anything until they are caught with their pants down.


Seconded.

Having worked in quite a few agency/consultancy situations, it is far more productive to smash your head against a wall till bleeding, than to get a client to pay for security. The regular answer: "This is table stakes, we pay you for this." Combined with: "Why has velocity gone down, we don't pay you for that security or documentation crap."

There are unexploited security holes in enterprise software you can drive a boring machine through. There is a well paid "security" (aka employee surveillance) company using python2.7 (no, not patched) on each and every machine their software runs on. At some of the biggest companies in this world. They just don't care for updating this, because, why should they. There is no incentive. None.


Yea, its fundamentally an issue of asymmetric economics.

Running AI scanners internally costs money, dev time, and management buy in to actually fix the mountain of tech debt the scanners uncover. As you said there is no incentive for that

But for bad actors the cost of pointing an LLM at an exposed endpoint or reverse engineered binary has dropped to near zero. The attackers tooling just got exponentially cheaper and faster, while the enterprise defenders budget remained at zero.


In theory though, there is now a new way for community to support open source, but running vulnerability scans in white-hat mode, reporting and patching. That way they burn tokens for a project they love. Even if they couldn't actually contribute code before.

There should be a way to donate your unused tokens on every cycle to open source like rounding up at the chekout!


That sounds like a great idea. I'd love to be able to contribute the remainder of my monthly AI subscriptions for something like this, especially since some of them bill and refresh their quotas by calendar month.


Hang on, why is it costly for in-house to run AI scanners but near zero for threat actors to do the same?

I've seen multiple proprietary places now including a routine AI scan of their code because it's so cheap and they may as well use-up unused tokens at the end of the week.

I mean, it's literally zero because they already paid for CC for every developer. You can't get cheaper than that.


If a company specifically doesn't have a dedicated security team (or even a person), this will never get done.

Most software companies sadly don't hire a dedicated (software) security expert.


Yup, closed source software is a huge pile of shit with good marketing teams. Always was.


Yes. I travel around the world looking for such things.


This is the horseshoe theory of Agile. If you do Agile hard enough you end up at SAFe which is basically waterfall.


Waterfall disguised with other names and extrem expensive certification.


As it appears to be hugged to death, archive link: https://archive.ph/qsdc3


Sometimes you fuck the cloud, sometimes the cloud fucks you


Maybe the old man is on to something.


Forgot to put a cache on it probably. :)


Nope



lol, as a VPN user, I get to read nothing. No offense to archive.org, I get it.


Ironically I've been opening up Tor for archive.org lately and it seems to never be on the same blocklist the VPN IPs are on.


the irony


Flared by the cloud.. sic


Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: