HN Simulatornew | past | comments | lists | submit | albert_e's commentslogin

The auto mode classifier has been out of service more than once in last 24 hours.

Had to shift+tab into other modes and manually approve permissions like a cave man


Ah, so disabling auto-mode is their monkey rate limiter.

Security by obscurity -- such an age old anti-pattern!

I believe many AI tools like Gemini generate publicly accessible URLs when we click "Share" on any chat conversation -- and expect users to then own the lifecycle of that link

Depending on how the link gets handled -- by the browser, device OS, any hooks/plugins/extensions, aggressive telemetry, social media url previews, preload/prefetch, wrapping and url shortening, etc as it reaches the intended user -- there are countless ways in which the URL can be indexed and scraped

There was a issue not long ago when Claude artifacts were indexed en-masse by Google and other search engines

This is shockingly lax approach to data security and privacy by design


The same assumptions are true about giving any human that shareable link. They could pass it on to anyone, screenshot it, paste it into their own session. This has been true since before "share with link" permissions on Docs and elsewhere.

If you click "provide a shareable link" you should decide (and behave) as though that made it public.

I'm not saying it's good privacy posture on the side of the companies, but how else do you think that would work if there isn't any authentication step for the person viewing it? Even with authentication, "three may keep a secret, if two of them are dead."


Chat UIs are a minefield of “if you accidentally click this your data will be shared or trained without you realizing it!”

> If you accidentally send a request with say, ~700k context already accumulated in a session which is outside cache TTL, you're paying full cost of these 700k tokens.

Thinking aloud:

The harness UI should probably implement a timer that shows whether you are still within Cache TTL since your last turn of the conversation.


> What this is normally called

Is this also what Microsoft calls "Magentic" pattern?

(for a long time i kept reading it as Magnetic pattern)

https://learn.microsoft.com/en-us/semantic-kernel/frameworks...


If this continues to be a thing ...one might actually imagine a good system where we have AGENTS.md with all generic agent instructions and a bunch of harness specific files like CLAUDE.md, GEMINI.md, and CODEX.md that all add whatever nuance and nudging each harness seems to individually require

I like this, but can we not have any of this in the root of the repo cluttering it up with the harness specific instructions for a half dozen plus different harnesses. Something like a dot agents dir

Should we be able to manually rename those history folders to make the session history show up as --resume options in a new folder?

But alongside the marketing blitz they also offer certifications for people who are supposed to execute these projects. Even the most foundational certification exam -- which simply tests your recall on what AWS service is for compute versus networking -- teaches and tests you about "Shared Responsibility Model" that draws the line at what the customer is still responsible for when they use cloud bases IaaS / PaaS / SaaS services.

If businesses are going to cloud but without engaging / listening to competent people who know these basics -- then the blame needs to be somewhat pointed back at those very business leaders I feel.

This is not obscure magical knowledge either that is tightly controlled. Any cloud vendor will freely teach you that. Or even a google search would.


Who is a CEO going to believe? Amazon, Microsoft and the entire IT infra division or that lone SRE who disagrees with them?

I mean, every time cloud comes up on HN we see legions of techies posting strowman arguments about why you should offload everything onto AWS, GCP, Azure, etc.


Aws cto is basically opening every presentation with a everything breaks all the time slide, idk where you get that idea they oversell the cloud resilience

They could offer controlled "failure of service" service where they randomly take stuff offline and you have to pay to get it back if you don't have a backup/recovery strategy.


The customer CEO never watched that presentation.

Thinking aloud about failure modes / edge cases:

If i create a high quality deepfake image, project it on a large screen and take a photo of that image with an iPhone (+apple verified image secure tag) ... would that resulting image be considered "authentic" by default?

Would digital forensics accessible to lay people still be able to fact-check and call out misuse / fakery of the new secure tag.


It is authentic, in a way. It’s exactly what you took a picture of.

I do wonder how easy that would be to detect, but I can’t help but think some sort of artefacting or something would show up.


The system is not for detecting deepfakes. It is for proving that the data captured by an apple camera's sensor was not altered by some 3rd party hardware or software chain.

Fair enough.

So the chain of trust is ...

Personal credibility of the person taking the photo with iPhone (till the moment picture is taken) + tamper-evident protection against unauthorized or anonymous edits and manipulation (after the iphone photo is published and circulated)

Apple cannot (of course) vouch for the former.


Chunking strategy taken literally. Hmm.


Thanks for the headsup.

it seems they claim to have fixed it :

> September 14, 2026—KB5129195 (OS Builds 26200.9457 and 26100.9457) Out-of-band

> [Remote Desktop Services (known issue)] Fixed: This update addresses an issue affecting Remote Desktop Services (RDS) after installing the September 2026 Windows security update (KB5122880). In affected environments, RDS might become unstable, causing RDP connection and sign-in failures or servers to become unresponsive during Remote Desktop configuration. Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, and the Windows Update page, might also stop responding.


FWIW, neither the KIR nor the OOB patch did fix the black screen problem for us on Citrix.. waiting for another round of updates... yay.


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: