Live data from Hacker News

Goodbye, and Thanks for All the Bikesheds

queue.acm.org

151–160 of 285 posts

Re: Goodbye, and Thanks for All the Bikesheds

#151
post #82
post #27

"LLM-assisted code review won't be a huge disruptor" is quite the prediction. Because it already is in a very big way. The take on LLMs seems incredibly out of date and out of touch with reality. (Which of course, has moved/advanced very fast the past months/year)

He explains how he thinks it won’t be a disruptor: > Just on that repeated experience, I suspect we have already seen more than half of the “worst software bugs found with LLM-tools” list. On the other hand, it’s not clear to me how you think that it already is “in a very big way”.

Which is such a crazy assertion, given that not even Mythos was trained explicitly as an exploit finder. Even if the US's profit-driven capital for AI dev dries up, China's state funding for results-driven AI isn't drying up, and they're going to keep building better models as long as the results are there (which they are), for better or worse.

Re: Goodbye, and Thanks for All the Bikesheds

#152
post #27

"LLM-assisted code review won't be a huge disruptor" is quite the prediction. Because it already is in a very big way. The take on LLMs seems incredibly out of date and out of touch with reality. (Which of course, has moved/advanced very fast the past months/year)

Did you continue reading? His argument is exactly that, like all the previous model checkers, LLM's are going to give us some bugs for a while. Then that is going to stop. His argument is not that they aren't going to find any bugs, but rather that at some point those bugs will be fixed. At which point we will continue on as usual.

How would they stop? Are you insinuating they're going to have reviewed all code at some point, and that new code for them to review will just cease to exist? Or that they'll just decide to stop finding bugs they're finding now in new code when they review it? All the previous model checkers didn't stop giving us bugs to fix, which is why his premise is wrong; every big company is still running SonarQube because it still gives you bug findings. So will AI.

If the argument were instead that it will cease to find new classes of vulnerabilities and bugs, that may very well be true, because that is a question of the limitations of programming and at a lower level computer architecture, but that's not the argument the author made.

Re: Goodbye, and Thanks for All the Bikesheds

#153

Earlier quoted context omitted.

> A sensible regulator would leave some responsibility to the parents (Speaking as a parent of three) why can't we just leave all responsibility to the parents? In our experience in the offline world it seems this applies! I speak as someone who's taken each of my three children - for two of them, multiple times - to the emergency room to be treated for broken bones incurred in the course of Real Life[tm]. Yes, they…

>why can't we just leave all responsibility to the parents? because we don't live in a 15th century peasant village. The average adult reads at a 7th grade level, 20% of adults are considered functionally illiterate, most adults can't navigate digital spaces, privacy and social media themselves or take on trillion dollar companies. This also hasn't applied in the offline world since idk, Kant and Hegel, every modern…

Your sharents don't love you like your parents do.

Re: Goodbye, and Thanks for All the Bikesheds

#154

Earlier quoted context omitted.

I think a reasonable way to divide up responsibilities would be identify child-locked devices, not people. It should be trivial for a website to identify a device with a child lock turned on. Then it's up to parents to make sure their kids get a child-locked device. Manufacturers can make it easy to turn on, and society can help by not selling devices to kids without a child lock turned on. It won't work against a de…

What disconnects this discussion from reality, and maybe causes questions like “why don’t they just do it this way”, is the assumption that this is really only or even mainly about age verification and “protecting the children”. The reason it’s not done “this way” or “that way” even when those are objectively better ways to achieve the stated goal, but rather in an unexplainable way broader way is because the goal is…

How do you know that's the ulterior motive? Anything more than vibes?

There are a lot of different people in different countries pushing for age verification and I imagine they wouldn't all have the same motives.

Re: Goodbye, and Thanks for All the Bikesheds

#155
post #144

I had to stop reading halfway through to respond. > In comparison, tech sisters advocating for an absolute right to privacy seem to be a very rare, and maybe mythical, species. Ever heard of Meredith Whittaker? > We could have designed our protocols to be minimally compatible with “a nation of laws,” but the tech bros insisted that compromise was treason, and, as a result, we will lose more privacy than necessary. Th…

> Ever heard of Meredith Whittaker? The fact that you name one makes her very rare indeed.

I mean I can point to a half dozen that I know personally but they’re not famous shrug. This seems like a weird argument to make to me, and besides the overall point the author was attempting to make anyway

Re: Goodbye, and Thanks for All the Bikesheds

#156

I guess tech has grown too large and fractured and maybe most working software engineers are too young to be familiar with phk and his points of view. He's been a strong privacy and FOSS advocate for decades and has more credibility on both of these topics than nearly anyone on this board. He also has an account and comments frequently. phkamp. I suggest reading some of his comments before making judgment. So many kn…

I’m mostly seeing people disagree with the substance of his argument, though. Your argument through authority is weak.

Re: Goodbye, and Thanks for All the Bikesheds

#157

Earlier quoted context omitted.

It's not anti-privacy to point out the obvious that privacy-advocacy is sometimes at odds with governments and the will of voters at large. Privacy is being abused by criminals to victimize people at scale. Just because privacy is a moral good doesn't mean you are morally off the hook for enabling criminals. Governments are so aware of this they're passing sweeping laws against it. This is your new reality -- you can…

> Privacy is being abused by criminals to victimize people at scale. Almost all victimization is being done without end to end encryption. This is not a problem caused by privacy.

And I guess you have statistics about how much victimization happens over e2e?:)

Re: Goodbye, and Thanks for All the Bikesheds

#158
post #112

First read of this pissed me off, but subsequent reads gave a much different opinion. Do yourself a favor and read this, a few times, and take a moment to actually try and see what the author's getting at.

I struggle with this because the author is lumping FOSS and "tech bros" together as taking the blame for what a handful of large corporations have done, and thinks that our punishment is what those large corps are lobbying for. It seems like an argument that this is a necessary evil to protect the kids - despite admitting that this is not the real reason for the laws - and then says that those of us who care about pr…

>I struggle with this because the author is lumping FOSS and "tech bros" together

This is on purpose.

This is the intent.

Re: Goodbye, and Thanks for All the Bikesheds

#159

A bit of an aside, but after someone introduced me to the notion of Reversible Decisions, it quickly became apparent to me that the solution to the bikeshed problem is to throw money at it before the roosters can start preening about which color the shed should be. Decisions that are reversible should just go with the instinctive answer of whoever volunteers to work on it. I've been in many meeting rooms where, becau…

+1! I've fallen in love with many of Amazon's in-group concepts, and maybe I'm just drinking the koolaide, but they have the concept of a "two-way door", which is exactly this -- a decision that can be made, unmade, remade, etc relatively cheaply. If you can identify that a choice isn't very dangerous, you can focus on the things that really are instead.

Re: Goodbye, and Thanks for All the Bikesheds

#160
post #98

Earlier quoted context omitted.

Oh it's so nuanced and hard to parse that he's arguing for compromise. The trouble is, compromise isn't really a tenable option with encryption. Either you make a draconian law that forces all electronic devices to run approved software only, or people will have access to easy encrypted messaging. There's really no middle ground, because where the smallest weakening of encryption affects everyone's privacy, only outl…

> make a draconian law that forces all electronic devices to run approved software only That would outlaw programming. It's just not feasible at all, anyone with any kind of tech literacy understands that encryption is here to stay. It's also necessary for the web to function at all for the things we use it for, such as banking. There is no way to prevent people from communicating in secret. Even if they did strictly…

[deleted]
Post reply on HN