Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
raesene9
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
raesene9
7d ago
This seems like a very nice release. Just ran it over my Kubernetes security benchmark that I run for most new releases. It was fast, cheap, and got a high scoring result, nice!
2.
▲
by
raesene9
1mo ago
It's great that they're making the auto usage tokens free by default and I guess auto mode will be a good default for a lot of workloads, but recent changes to the auto mode classifier just moved me to either use YOLO mode or use
3.
▲
by
raesene9
1mo ago
Same Story as it ever was. The first time I encountered what I thought was a phishing attack at the bank I worked at 25 years ago , it turned out to be a marketing campaign, with URLs that put our company name as a user before the domain n
4.
▲
by
raesene9
2mo ago
So one of the factors in this is that Kubernetes disables the default seccomp policy provided by the container runtime, by default (you can re-enable it ofc, but you have to know to do that). As a result I reckon there's more vulnerabl
5.
▲
by
raesene9
2mo ago
Rootless helps, but less now that it used to (pre-2026). There have been a lot of local privilege escalation vulnerabilities in the Linux kernel (dirtyfrag, fragnesia, CIFSwitch et al) and several of those can be repurposed as container bre
6.
▲
by
raesene9
2mo ago
They address that in the article :) to quote :- "So where's this huge price gap coming from? token pricing, prompt caching, and effort-per-task. On SWE for example, K3 works much harder than Fable: roughly 55 turns and 1.3M tokens
7.
▲
by
raesene9
2mo ago
As other have mentioned, and I'm the same. Leaving "Co-Authored by:" feels like open disclosure of how the project was created. That way if a consumer does not want to use LLM generated/assisted software, it's easy
8.
▲
by
raesene9
2mo ago
Interesting write-up and I do think LLM assisted/powered exploit disclosure is a real concern (I've been able to get models to create container breakouts from Linux LPEs relatively quickly). One thing I'm surprised about is t
9.
▲
by
raesene9
2mo ago
Future returns are never guaranteed but over the course of the orgs history (since 1965) they've done a fair bit better than the S&P 500.... https://www.visualcapitalist.com/warren-buffett-vs-the-sp-50...
10.
▲
by
raesene9
2mo ago
You might find some areas to criticize Berkshire Hathaway but I don't see being lazy as one of them. This is one of the most successful investment companies of all time and they got that way by being better than most at judging when th
11.
▲
by
raesene9
2mo ago
I'd say for some sectors and users, we're already seeing that. After GLM-5.2's release there were quite a few stories about it picking up use. Then looking at Openrouter's stats we can see heavy use of non Anthropic/
12.
▲
by
raesene9
2mo ago
It's an interesting thing and we can only speculate from the outside, but there's some obvious reasons why they'd literally hand out money in the form of free compute to people who have already committed to paying them. - The
13.
▲
by
raesene9
2mo ago
I think until they produce full financial information, which will happen I expect when their S-1 is published, we won't have a good picture on Anthropics true position. There's a lot of different ways to calculate "profitable
14.
▲
by
raesene9
2mo ago
Interesting write-up. Having been a bookkeeper a long time ago, I'm not too surprised at this being susceptible to automation by an LLM backed system. It seems also that the classes of error they encountered could be handled by improve
15.
▲
by
raesene9
2mo ago
If you're going to have "blessed" plugins, which seems like a good idea, you'll need a review and possibly hosting process. - Review to check that the plugin is reasonable quality/isn't malicious. - hosting (e.
16.
▲
by
raesene9
2mo ago
It provides a right to privacy if the company allows personal messaging services on the device, but I don't think it provides a right to having personal messaging apps on the device(s). Personally I think it's much cleaner to keep
17.
▲
by
raesene9
3mo ago
I have a similar experience, for the last 5+ years I've worked in companies where very few of the people I work with are British which does require care on both language and idiom. Combined with being older than a lot of colleagues, cu
18.
▲
by
raesene9
3mo ago
The later Opus models (4.7/4.8), Sonnet 5, and particularly Fable 5 will refuse to do tasks related to offensive security. One example I've hit is working on a benchmark of how well LLMs handle Kubernetes security tasks, there
19.
▲
by
raesene9
3mo ago
If you want to chat with Claude about this, I'd recommend using Opus 4.6. IME it's happy to talk about (and even write) PoC exploits
20.
▲
by
raesene9
3mo ago
Yep I've got one I built and it's absolutely fine for my use cases has a web interface/API custom kernels and rootfs, even the facility to set-up custom Kubernetes clusters. It's been really useful for other work like te
21.
▲
by
raesene9
3mo ago
Well its document management feature didn't used to have Anti-Virus support which caused me a load of problems back in the 90's when Word Macro viruses were common. :P
22.
▲
by
raesene9
3mo ago
The original research for this is at https://soroush.me/downloadable/microsoft_iis_tilde_characte...
23.
▲
by
raesene9
3mo ago
Worth noting that, this isn't just a risk with npm or other package managers. If you're using LLM agents in the directory of a cloned repo, there's risks in skills, hooks etc automatically executing..
24.
▲
by
raesene9
3mo ago
that probably depends on how much security and resource isolation you need. Multi-Tenant security in Kubernetes is not a simple thing, for a wide variety of reasons, and noisy neighbour problems are also potentially a headache.
25.
▲
by
raesene9
3mo ago
The one I remember most is, when experimenting with Opus 3.5 for the first time, I asked it to generate a Firecracker backed local VM creation and management tool, something I'd wanted for a while but not found. My expectation was that
26.
▲
by
raesene9
3mo ago
not really, there are a number of security companies doing analysis of any new packages looking for supply chain attacks, so if you wait a couple of days, till their analysis is complete, you're reducing the risk of hitting a compromis
27.
▲
by
raesene9
4mo ago
I think perhaps the reason you are seeing quite a few commenters expressing skepticism to your comment "You go to a university because you are deeply interested in understanding the subject that you study." is that you appear to b
28.
▲
by
raesene9
4mo ago
AFAIK pi's approach is to be quite minimal and allow extensions for customization, making it a more flexible solution, but you need to do work to make it fit your use case. OP mentions one extension, but perhaps it'd have benefite
29.
▲
by
raesene9
4mo ago
I'd expect for workflows where there is value in knowing that the data is processed in the UK. From a contractual/data protection standpoint, that could be very useful, depending on the use case.
30.
▲
by
raesene9
4mo ago
Data Sovereignty as a term is now fairly well established term that doesn't have specific government connotations e.g. https://events.linuxfoundation.org/kubecon-cloudnativecon-eu...
More ›