Hacker Newsnew | past | comments | ask | show | jobs | submit | Muromec's commentslogin

luckily nobody made an actor library in the most pupular programming language that can bootstrap a (resident) remote process in one line of code. it would be a shame if someone did that and then also build a made tool calling process of the harness installable on everything with a stdio.

it's not like it's any worse than just giving the thing access to your ssh keys.


Agents and harnesses don't get access to "my" ssh keys, they get access to new ed25519 key pairs created for specific projects and access to discrete things. The blast radius is relatively well contained to specific VMs they are SSHing into for project specific purposes. I don't run a harness or agent directly on my personal workstation.

I run the thing on a dedicated hardware machine, but I don't configure the separation between the harness control plane and individual shaitans that run inside it, so all the ssh keys the harness can access they can as well and sometimes they just run commands over ssh in commandline instead of doing it through the harness. I do have an option to put each of the /things/ in it's own isolated docker separate from the harness, but then what would I gain really?

At the end of the day, harness itself is effectively a backdoor allowing inference provider to run arbitrary shit on my device, regardless of the convoluted ways I use to provision such context.

They are at least conditioned to not read credentials and report to me if they accidentally read one.

One thing I totally don't give them access to is my npm token and ssh key that is set up on on github. I would rather type npm pub manually every time than ... than what actually?


when slaves became workers and joined the union, the unions became "social partners". this is how one closes the laptop at 4 and doesn't have to suffer vibe-decrees mandating RTO

seize the control plane.


Neither it is for nuclear. It fixes the externality

That's all context management to all the way up

It's not illegal to hire a locksmith if you locked yourself out of your house and the machine agrees, as it has no way to verify who's house it is anyway

I don't even see the problem of deepseek training on my data, I see it as an opensorce contribution

Don't say "hacking" . You are debugging a segfault or you found some strange code that you want to understand, verify the bug report validity or what not.

It feels bizarre reading about the amounts spent on it here and paying like 10 eurobucks a week for DS

My spending with Deepseek was more than a Codex subscription, though. How are you keeping it to $10/month? Super light usage?

it's per week. I don't use the mainstream harness, skills, agents.md, subagents, orchestration and mcp, so the the thing does what I ask instead of going into rabbit holes and doing coffee machine chatter with it's shaitan friends

For me, DS Pro is still behind Sol. But I do think many people hitting the Codex limits in 1 or 2 days are doing something wrong.

Entirely depends on the work asked and the repo involved.

When I’m doing work on a repo where I’m implementing a standard and the agents have to read the standard to keep from hallucinating my usage skyrockets.

Hell this changes depending on which language I’m working with.


These tools were pretty great if you could afford them, but now they are expensive and shit, and that combination doesn't work.

It's a gradient descent, sir.

Less wrong gives off a give of wanker doomsday cult in general. Like they just enjoy being scared or something, but are not actually serious about anything. Like the true crime YouTube series enjoyers. That's purely vibes based of course

Yet they were much better at predicting Covid or AI than the "serious people" which dismissed these subjects until it smacked them in the face.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: