Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
eric-burel
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
eric-burel
4mo ago
Infrastructure provisioning is a key ingredient of agentic AI viruses: https://www.ericburel.tech/blog/ai-virus-agent This may be the first steps of the worst wave of spamming campaign ever seen on the Internet. We
2.
▲
Key Components of a Linux Distribution for AI Agents
(ericburel.tech)
3 points
by
eric-burel
5mo ago
|
0 comments
3.
▲
by
eric-burel
7mo ago
They love their dictator until it backfires, that's a quite old story.
4.
▲
by
eric-burel
7mo ago
I've been working on making the "lethal trifecta" concept more popular in France. We should dedicate a statue to Simon Wilinson: this security vulnerability is kinda obvious if you know a bit about AI agents but actually nami
5.
▲
Peer-Reviewers in the Coal Mine?
(ericburel.tech)
1 points
by
eric-burel
7mo ago
|
0 comments
6.
▲
by
eric-burel
8mo ago
Can it be used to sandbox an AI agent, like replacing eg Cursor or Openclaw sandboxing system?
7.
▲
AI virus agents: what are they, how to fight them
(ericburel.tech)
3 points
by
eric-burel
8mo ago
|
0 comments
8.
▲
by
eric-burel
8mo ago
The thing is running it onto your machine is kinda the point. These agents are meant to operate at the same level - and perhaps replace - your mail agent and file navigator. So if we sandbox too much we make it useless. The compromise being
9.
▲
by
eric-burel
8mo ago
Before using make sure you read this entirely and understand it: https://docs.openclaw.ai/gateway/security Most important sentence: "Note: sandboxing is opt-in. If sandbox mode is off" Don't do that, tur
10.
▲
Teaching agentic AI to French developers: feedback from a professional trainer
(ericburel.tech)
1 points
by
eric-burel
9mo ago
|
0 comments
11.
▲
by
eric-burel
9mo ago
Related: https://news.ycombinator.com/item?id=46223311 Switching to paid version was already problematic as it uses GCP account system which doesn't have a spending limit, and API keys do not have an expiration date. S
12.
▲
Google's Gemini API Free Tier Fiasco: Developers Hit by Silent Rate Limit Purge
(quasa.io)
4 points
by
eric-burel
9mo ago
|
1 comments
13.
▲
by
eric-burel
9mo ago
Microsoft is using the deep penetration of SharePoint in companies to sell Copilot license. At least in France it's well and alive and I see much more Copilot licenses than actual OpenAI uses.
14.
▲
by
eric-burel
9mo ago
Yeah I mean you can replace sandboxing buy other safe alternatives but the idea is the same, the generated code has to be considered as 100% untrusted. Supply chain attacks are especially nasty.
15.
▲
by
eric-burel
9mo ago
Talking about the debt of a system prompt feels really weird. A system prompt tied to an LLM is the equivalent of crafting a new model in the pre-LLM era. You measure their success using various quality metrics. And you improve the system p
16.
▲
by
eric-burel
9mo ago
In an agentic setup you are still dependent on having relatively smart models that's true.
17.
▲
by
eric-burel
9mo ago
You can have an agent that focuses on studying the interactions. What you're saying is that an AI cannot find every security issue but neither do humans otherwise we wouldn't have security breaches in the first place. You are desc
18.
▲
by
eric-burel
9mo ago
Sounds a lot like "nationalism in a single country"
19.
▲
by
eric-burel
10mo ago
You may want to read about agentic AI, you can for instance call an LLM multiple times with different security consideration everytime.
20.
▲
by
eric-burel
10mo ago
Smart, thanks for the tip
21.
▲
by
eric-burel
10mo ago
AI is good for discovery but not validation, I wanted experienced human feedback here
22.
▲
by
eric-burel
10mo ago
"You can investigate this yourself by putting a logging proxy between the claude code CLI and the Anthropic API using ANTHROPIC_BASE_URL" I'd be eager to read a tutorial about that I never know which tool to favour for doing
23.
▲
by
eric-burel
10mo ago
I call that self-destructive prompting in the sense that you use AI to output programs that replace calling the AI in the future. The paper seems to indicate that this also brings much better results. However it's subject to attacks as
24.
▲
by
eric-burel
10mo ago
I am pretty sure you can figure massive loopholes like how it's legal to train the model on stolen data but not to steal data etc. For instance advertisers can push model benchmarks that favours some opinions, based on a biased selecti
25.
▲
by
eric-burel
10mo ago
"that could redefine the web economy" I don't think that ads in ChatGPT are that disruptive, it's just another channel. I think ChatGPT apps are an order magnitude more game changing, as they are not a new markting chann
26.
▲
Field Report: Coding in the Age of AI with Cursor
(drezil.de)
1 points
by
eric-burel
10mo ago
|
0 comments
27.
▲
by
eric-burel
10mo ago
You don't let customer to decide if they love pesticide or not, their are basic functions even to a minimal state and environment and health protection is among them.
28.
▲
by
eric-burel
10mo ago
If you are an European, regulation also has the benefit to induce soft protectionism from countries that are less keen on consumer and environment protection. This is the heart of the debate about Mercorsur, as it creates an unfair competit
29.
▲
by
eric-burel
10mo ago
That's a shortcut, llm providers are very short sighted but not to that extreme, alive websites are needed to produce new data for future trainings. Edit: damn I've seen this movie before
30.
▲
by
eric-burel
10mo ago
Yeah but can't we expect bureaucratic companies to adopt such a methodology exactly like that: write a spec for years, run the LLM agent every 6 months, blame techs for the bad result, iterate, and also forbid coding outside of the spe
More ›