Live data from Hacker News

Tl;dv: Over 180k meetings left wide open

bobdahacker.com

81–90 of 231 posts

Re: Tl;dv: Over 180k meetings left wide open

#81
The worst part of these AI meeting notes and recordings is that I have literally never seen anybody, in any situation, go back to them. The (very) few times I ever bothered to check the transcripts and especially the summaries immediately after a meeting, without fail they'd have something in them that is the complete opposite of what someone said in the meeting, or they'd miss extremely important clarifications or context. Literally worse than useless, actively detrimental, but you bet your ass whichever moron forced these to be on for every meeting is putting it on their resume - "Increased long-term organizational cohesiveness via comprehensive automated meeting notes" or whatever type of bullshittery.

Re: Tl;dv: Over 180k meetings left wide open

#82

Earlier quoted context omitted.

Fortunately we have LLM's to not produce that crap... wait, those LLM's were trained on the existing crap and produce the same crap... oh no.

I doubt SOTA models nowadays are going to produce an implementation without any kind of authentication like here, and not tell you about it. And even if, a later "is this ready for release" will probably surface such obvious issues. I do not think LLMs are the problem here. Today, they are most likely more competent than whoever set this up.

I love the never-ending "SOTA" treadmill used to defend anything and everything these LLM tools shit up. Doesn't matter what happens, it wasn't one of the "SOTA" models (which changes every 7 seconds) ergo it's irrelevant, how very convenient for the AI pushers!

Re: Tl;dv: Over 180k meetings left wide open

#84

Earlier quoted context omitted.

Idk licensing and regulation sounds like involving more institutional arrogance. We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed). The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doi…

this idea that government regulation is the problem and the companies need economic incentives to self regulate is a religion around here, and after incredible amounts of evidence that is untrue, like all religions, it’s practitioners have made zero changes to their opinion.

As a cybersecurity practitioner, regulation and oversight is the only incentive that moves the needle in my experience. If there are no costs or negative outcomes for not caring about security, security will not be prioritized. Big fan of SEC Breach Reporting via Form 8-K, as well as state reporting requirements.

https://www.sec.gov/newsroom/speeches-statements/gerding-cyb...

https://www.ncsl.org/technology-and-communication/security-b...

Re: Tl;dv: Over 180k meetings left wide open

#85

Earlier quoted context omitted.

> I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it. The main problem is that the IT industry for a loooooooong time "self-regulated" itself, the only areas that did have regulation had it come in externally (i.e. automotive, aeronautic, astronauts and maritime). Only in the last years, GDPR + insurances forced a bit of…

Idk licensing and regulation sounds like involving more institutional arrogance. We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed). The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doi…

> Idk licensing and regulation sounds like involving more institutional arrogance.

Well it works. Aviation for example is incredibly safe if you think about it, and mostly because the governments worldwide joined forces and introduced an amount of safety regulations everywhere that sounds insane until you remember that these rules were literally written in blood. And similarly, losing your life or getting injured on a modern ship is a pretty rare thing to happen (either as employee or passenger) if you contrast it with the situation just five decades or so ago.

> We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).

Degree mills aren't the kind of gatekeeping I'm talking about. If you screw up, you still can go to another company and continue screwing up there, which also means there is barely any incentive to hold education institutions accountable to deliver good education. In the regulated trades however? Screw up enough and you're out for good.

> Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing.

Trades licensing is merit based.

Re: Tl;dv: Over 180k meetings left wide open

#86

Earlier quoted context omitted.

I doubt SOTA models nowadays are going to produce an implementation without any kind of authentication like here, and not tell you about it. And even if, a later "is this ready for release" will probably surface such obvious issues. I do not think LLMs are the problem here. Today, they are most likely more competent than whoever set this up.

I love the never-ending "SOTA" treadmill used to defend anything and everything these LLM tools shit up. Doesn't matter what happens, it wasn't one of the "SOTA" models (which changes every 7 seconds) ergo it's irrelevant, how very convenient for the AI pushers!

Can someone give me exact time when SOTA stop being good? Is it a day, week or a month? As such can I consider anything older than that time period to automatically be crap?

Re: Tl;dv: Over 180k meetings left wide open

#87

Earlier quoted context omitted.

Idk licensing and regulation sounds like involving more institutional arrogance. We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed). The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doi…

this idea that government regulation is the problem and the companies need economic incentives to self regulate is a religion around here, and after incredible amounts of evidence that is untrue, like all religions, it’s practitioners have made zero changes to their opinion.

Kinda feel like you get corruption no matter if it's pure socialism or pure capitalism, and that any system is a reflection of the people.

Re: Tl;dv: Over 180k meetings left wide open

#89

It's hilarious how these companies handle security breaches. I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault . I had just started working there and found it in the first week. Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years ev…

More proof that software engineering isn't real engineering. If a civil engineer made a mistake that bad in my country, he'd likely lose his engineering licence.

Software lost that status in the vibe coding era. It's an art form now, not necessarily something worse or easier, just different than engineering. But probably not the career path anymore for those who prefered math over philosophy in college.

Re: Tl;dv: Over 180k meetings left wide open

#90
"Because the common denominator between both of these distinct incidents was Firebase, we are taking the additional step of immediately removing it from our tech stack altogether to definitively eliminate the risk of similar vulnerabilities in the future." - from their post-mortem.

Thank god the root cause was definitively identified! /s

Post reply on HN