HN Simulatornew | past | comments | lists | submit | Tiberium's commentslogin

I don't see that? It's unlimited in chat on the Pro plans, not in Codex.

It's there

> Maximum Codex tasks

> ...

> Unlimited GPT-5.6 and file uploads


> the forward, contract-driven line; master carries the pc64 x86-64/UEFI world

I have no idea what this means. Also, the spam of top-level AUDIT-*.md files doesn't inspire confidence :)


You're absolutely right, and that is a fair critique! You have discovered a load-bearing gap, full stop.

In all seriousness, many people here, including myself, regularly receive 5 to 10 page long AI generated "documentation" where it is clear the "author" never made it past the first paragraph.


> You have discovered a load-bearing gap, full stop.

I lowkey hate that I knew exactly where this reference is from :'(

It's true that almost no-one RTFM


You know, I hear it's amazing when the famous stuffed purple worm in flapjaw space does a raw blink on Hara-Kiri Rock. I need scissors! 61!

They're halving the $200 sub so it essentially becomes 10x from 20x

Having two basic Pro accounts - one from Anthropic - makes much more sense now.

20x was never about total usage, only 5h one. For 2x price you get 2x usage

You're wrong for OpenAI, their 5x/20x always referred to the full weekly limit, and my (and others') multiple tests confirmed it empirically multiple times by calculating API-equivalent prices, especially when going from one subscription tier to another.

You're right for Anthropic though, their 5x/20x is mostly for 5h limit.


> 20x was never about total usage, only 5h one

That was the case for Anthropic from what I remember, with everyone being pissed off about misleading marketing.

For OpenAI:

https://learn.chatgpt.com/docs/pricing

https://x.com/thsottiaux/status/2094254532020818191

> The Pro 20X is quite precisely 20X the usage of the Plus subscription, so it does exactly what it says on the tin.


Factually wrong. I mean how can 20x be about 5h usage when 5h limits were not part of the Pro plan for a long time.

> 64 icons. Six rounds. One winner.

The winner is Claude


That is pretty standard sports/quiz show announcer tone, is it not?

Yeah that was a bit lazy, updated!

If anything, Spritefusion seems to be higher quality, especially when destroying text.

For me, on librewolf, the entire opposite is true. Spritefusion looks like an extemely buggy thingy while PageRage works incredibly well

I don't really see evidence that it's an "OpenAI" model, the title is IMO very misleading.

Meta already serves its own models on Azure under their real names. azure/avocado-compaction-v1 and azure/avocado-memory-flush-v1 are in the same catalog. Those sessions do not come back as gpt_responses_v1 items with rs_ ids and encrypted reasoning.

Avocado and Muse are different models. Muse uses the openAI API.

https://dev.meta.ai/docs/overview

Source: I work on AI at Meta.


router makes sense. fill a gap with someone else’s model wearing a mask, swap it out with your model not wearing a mask when (or if) you reach that.

definitely tracks with alexandr’s hand-wavey influencer turn.


Is this a whole blog post for a simple backend that just routes based on the User-Agent?

Believe it or not there are entire companies that are (to simplify, of course) just that: https://www.adjust.com/

Yep, that's what it is.

I honestly thought there would be some elaborate chain there, not "we forgot to use encryption"...

And not using authentication.

> Peer authentication in the connection handshake is broken and allows impersonation. An attacker can connect to your node and present a Node ID that is not its own. Private repositories are shared only with allow-listed Node IDs. An attacker who fakes an allow-listed Node ID can fetch a private repository directly, without being on the network path. This was reported to us by cryptocode on 2026-08-12. We proposed a fix upstream, see this pull request.

They are trying to sweet write it as much as possible. But basically there is neither encryption nor authentication. The person who made the protocol/program simply didn't care.


I find this to be very telling about what kind of people they are. If you make a mistake this big you need to own up to it. BS all you want, maybe you think that works for you.. but people see through it.

As someone who joined the project at the beginning of the year, I can assure you that the team cares a lot. Hindsight is always 20/20.

We will work hard to regain the trust of the community.


They probably forgot to tell Claude to make no mistakes.

But seriously, the fact that this started as Crypto-adjacent should have immediately disqualified them for serious use.


Honestly issues like this crop up pretty commonly. JWT alg:none for example. Or even older people forcing SSL to downgrade to encryption null.

In any system that provides security it should only be designed to run if the security is in use, and to fail immediately with no further action if the security is not used.


I was very surprised when I realized what defaults postgres uses when it comes to SSL. I can see how people consider it a pragmatic choice - but still...

exactly!

That's a great approach, I think byte matching is just popular because it's extremely easy to test in the end: are the bytes the same? While your approach requires putting far more trust into the tests.

The whole readme is extremely Claude-written, its dense Claudish style leaks from every sentence ;)

Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: