Hacker Newsnew | past | comments | ask | show | jobs | submit | shawabawa3's commentslogin

> but giving a 2B model full JS execution privileges on a live page is a bit sketchy from a security standpoint.

Every webpage I've ever visited has full JS execution privileges and I trust half of them less than an LLM


Note that every webpage does not have full JS execution privileges on other parts of the web.

At least in this case (not so sure about the Prompt API case mentioned in another thread) the agent is "in" the page. And that means that the agent is constrained by the same CORS limits that constrain the behavior of the page's own JS.

If you think about it, everything we've done to make malicious webpages unable to fiddle around with your state on other sites using XHRs, are exactly and already the proper set of constraints we'd want to prevent models working with webpages from doing the same thing.


Unfortunately human energy use appears to be proportional to the amount of energy available

Hopefully we are able to reach a point of effectively unlimited cheap energy and storage but it's that if overnight we suddenly had enough solar+batteries to power today's usage, we'd suddenly need way more as demand rises


It's based on cost, like anything else. If running everything on solar and batteries makes it cheaper then we'll use more. But the same is true regardless of the technology. What's not true regardless is whether a given amount of energy usage requires continual resource extraction just to sustain it, or whether it's only needed for new capacity.

Hopefully if they ever go to Sri Lanka they get localised tuning because I was surprised to find out flashing your lights over there doesn't mean "go ahead", it means "if you don't get out of my way I will ram you"


And then there's trucks flashing an indicator to say it's safe to overtake if you're behind them. In the UK it's the nearside indicator, which makes sense: it's a bit like the truck is pulling over to let you pass. In Aotearo, it's often the off-side indicator, so you think the truck is going to pull out in front of you. I've never understood what the Aotearoa drivers are thinking there


This is true for India too though traffic there isn't known for its rules.


I hate the countries that do this because it doesn't even make sense as a signal. We already have a horn. They are wasting a channel!


It also doesn't make sense because "get out of my way or I will ram you" is the default state of operating a motor vehicle. Not the goal but the physical reality of it.


At highway speeds, engine, road and wind noise usually make horns inaudible.

In Serbia, on top of get-out-of-my-way, it's also used to signal go-ahead, but also "police with speed radars ahead" to incoming traffic.


I think we're not interpreting the original comment in the same way.

In most places, I think, when driving on the highway, flashing your lights when behind someone means basically 'I would like to overtake you'. Same here in the UK. But that's very specific to that context. You would never see a 'go ahead' context that would mean 'get out of my way', right?

But what the original comment means is there are some countries where you'd think it was 'go ahead' but it really means 'get out of the way'. Like if you're both on a main road, and you are signaling to turn into a side road, the opposing car flashes the lights and that means you can turn. I assume the same in Serbia.

But in some places that can actually mean don't turn, I'm going first. Which I think is what the parent is describing.


You are right that I did not read it the same way, and yes, the unwritten rules are matching in Serbia. FWIW, I've mostly switched to using left-turn signal to indicate "I'd like to overtake", which I've seen done on EU highways.


not really no

you can set up a cloud function to monitor billing limits and automatically disable billing for a project if it exceeds the limits though


> Tesla are producing cyber cabs now which are 10th the price of Waymo's and can drive autonomously anywhere in the world.

My understanding is that cyber cabs still need safety drivers to operate, is that not the case?


They have no steering wheel or pedals so no


Robotaxis in Austin are in the process of removing in car safety monitors, there is a chance you would get one today


They are just moving the safety monitor in a car that drives behind you.

https://electrek.co/2026/01/22/tesla-didnt-remove-the-robota...

It would be funny, but tbh it's just sad.

Everything for the stock pump


tesla robotaxi crash rates are also currently (as in, with safety drivers) 4x higher than humans so that's not very promising


Yes, but they are useless, they can't steer, hence why they have more accidents than humans per driven miles.


"plenty of corporations much larger than Google"?

Google is the third largest company by market cap in the world. I suppose by "much larger" you mean number of employees? Walmart maybe?

I doubt there's many out there using slack


By market cap? Is the money using slack?

Company size when you're talking about tools for humans makes no sense in terms of market cap.

Plenty of companies with many more employees than Google use slack.


Such as who? And are most of their employees actually using Slack or are a few white collar employees using it while 90% of their workforce has no idea?


IBM has ~300k employees and uses Slack.


I checked and it doesn't look like any UK banks have this option - at least I looked at about 5 different banks websites and all have pages suggesting you always select to pay in local currency but none of them have any information on disabling this behaviour

Gemini confirms it's not a thing, and not really possible (the terminals just detect the country from the card number)


>I'm fairly sure even mentioning the name of the forum isn't allowed on HN

Well let's find out

I did a tiny bit of research, pretty sure it's BreachForums (https://en.wikipedia.org/wiki/BreachForums)


BreachForums was shut down


Seems like every time it gets shut down it starts right back up again

This source claims it's Breach forums but no idea if it's reliable

https://www.bleepingcomputer.com/news/security/newsletter-pl...


Trello was a successful product despite having way less than 20% of jira's features


And there are hundreds if not thousands of Show HNs and YC funded companies that have disappeared in a whimper trying to be the “smaller lightweight version of $x”


They can fail for any reason and it’s not always for not having enough features..

MVPs shouldn’t have 100% of features, they need to be small, get feedback and iterate.


The old cliche “you only get one chance to make a good first impression”. If you don’t have the features I need when I first look at it, why would I pay for it or think about it again?


If I'm an employee working in the X office in France, and the police come in and show me they have a warrant for all the computers in the building and tell me to unlock the laptop, I'm probably going to do that, no matter what musk thinks


Witnesses can generally not refuse in these situations, that's plain contempt and/or obstruction. Additionally, in France a suspect not revealing their keys is also contempt (UK as well).


100%. Only additional troubles for yourself personally, for practically no benefit (nobody in the company is going to celebrate you).


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: