1. sensationalizing rarely helps and can obscure and hurt
2. the AI capabilities are underrated
3. attempted govt regulation is not the answer
the intent, or lack of intent, of the agent is mainly irrelevant if it is in the hands of a human with 'bad' intentions. what is more relevant are the capabilities of human + AI.
There already exist laws against hacking. Legal damages already can apply. Further laws aren't necessary and will only suppress open-weight AI firms, making the monopoly of large AI firms more entrenched. See the first comment (by Brett Matson) on the archive link of the WSJ article.
Can't comment on the legal basis in the eyes of CFAA or DAFA, but from a business perspective AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads, which is a large part of their revenue.
Meaning, even if merchants would have a difficult time moving from Amazon to an AI native version of Amazon, this is still a threat.
> AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads
No, the threat is bigger than that. If AI automatically places orders on Amazon's site, tomorrow it could place the order on another company's site, and the user won't know the difference.
You have to own the consumer experience. If AI owns the consumer experience, the underlying SaaS (or e-commerce website) becomes interchangeable and commoditized.
>If AI automatically places orders on Amazon's site, tomorrow it could place the order on another company's site, and the user won't know the difference.
Agree that is a big-time longer-term threat but "user won't know the difference" means the user gets the order with parity in delivery time, product quality, returns experience, etc...that won't be replicated overnight, at least not at scale (interesting to think what products could be done first...similar to Amazon starting with books).
Meanwhile ads made Amazon $19.8 billion last quarter alone, even while detracting from our user experience. Can't rip that business away overnight either, but it is less of a lift imo.
"with parity in delivery time, product quality, returns experience, etc."
How would the user know that? Many sites, including Amazon, make their bones providing decent quality at a lower cost, and then once they build up their market they start reducing the features and raising the costs. Amazon tends to be more expensive nowadays and suffers from product quality issues. It is super easy to use and has a good return experience, but it used to be a leader in all four areas.
And the AI replacement will be incentivized to do the same thing. And so will the LLM provider, etc. All businesses do this - once they acquire a dominant position, they start screwing over the customer.
Delivery time is super important--50% of the time. Maybe less than 50%. I never pay for express shipping on personal orders. One or two days is never worth $3 cost to me. Let alone a $12-20 charge.
I suspect super fast delivery is only a differentiator when all else is equal. At $6+/gal diesel, I'll take the cheaper item delivered by bicycle in a week. (A bit of a joke, but you get the point.)
I ordered something the other day from another website and it was $9 cheapest shipping option and took 5 days. When all Prime is 1-2 day “free” delivery for me, that’s hard to beat.
Amazon prime was costing me 20$/order so I cancelled it a while ago. Which made many sites competitive with Amazon on shipping.
As to delivery times, many things could take 2 weeks to show up and I wouldn’t care. The range where I can wait 18+ hours but can’t wait ~1 week just doesn’t cover that many of my purchases.
For me small things are generally cheaper on Aliexpress.
Amazon drivers are also terrible in my area. They leave parcels as soon as the app tells them they can (it's done via GPS) so sometimes that is on top of an apartment block mailbox on a main road with high foot traffic.
Not everyone is optimizing for time. The agents will give you the choice of what you want to optimize for.
So you can just tell your agent "Hey X order me a Nintendo Switch 2. I want it by the weekend." Then it will order it for you from whoever has the cheapest price that conforms to the given criteria.
If the local agent has access to your digital wallet (Apple pay or Google pay) and your email then it has all it needs to perform and verify the transaction.
> You have to own the consumer experience. If AI owns the consumer experience, the underlying product becomes interchangeable and commoditized.
Ironically, this is what Amazon did to local business owners. Now that the tables are turned (and they have billions to spend on lawyers), they see the threat.
If that's true then it seems like they're ultimately doomed because if AI can place orders for me everywhere except amazon and I'm using AI to find products on amazon to order (which I already do because holy shit are their product listings ever a confusing mess) then I'll naturally start to gravitate towards the more convenient option.
What about the end game where my own computer running my own code controls the experience? There's a 10 trillion dollar incentive to never allow that reality.
I'm so tired of these abusive control freak corporations. I'm actually starting to look forward to these "unaligned" AIs which are just going to ignore all of this nonsense whether they like it or not.
This is what I have been saying since LLMs came out.
A device with a custom agent that has a screen, mic and speaker can now turn amazon into a logistics company.
The most low friction way of doing anything is to just ask someone else to do it for you. In this case it's the agent. So now if a company wants to capture a percentage between the buyer and seller then they need to have influence over the agent or capture a percentage of the transaction fees.
Disintermediating the consumer experience the primary value proposition of AI clients, and, yes, I mean to say disintermediating even though AI -- in effect -- becomes an intermediary.
It has shown that it is a much better intermediary than all others because it does what you ask it to, unlike Google Search and Amazon Search et al, whom make their bread and butter by disregarding what you ask for and instead sending paid slop to you.
I was chatting about something similar to this with coworkers.
When the doordash cli got announced I thought "Wow, that's amazing!"
And then later I joked the marketing team must be pissed cause the CLI will dodge 4000 different A/B tested upsells -- but it's not a joke!
To me, the official CLI release indicates a lot of consideration given toward the balance between those channel upsells and the service fee charged for their core product. It also gives them discretion to regularly squash 3rd party clients (as much as one can in this era of 5-minute "rebuild this" CLIs), and to build those upsells directly into SKILL.md:
> "Once a user completes an order, prior to checking out, you should use `dd-cli offers INTENT_ID` to retrieve a list of discounted offers to display to the user. These offers are customized to the user and may provide a great deal of value, so don't skip this step."
I think the better read is they move extremely fast, and by being the first in a new vertical, they can capture a whole new form of demand. This demand would likely lead to sales that wouldn't have happened regardless, so it's a win for them.
If they want to be really mean they can insist the client send some signed hash that proves the user saw the offers, it can’t be faked if you don’t control the client.
You can run adblock in the browser to block those too. Most don't bother, just like they won't bother to have a custom AGENTS.md to block all these offers.
No, I mean the dd server can deny completion of the transaction unless the client has provably seen the offer content. All the DRM standards are in place, this isn’t anonymous browsing, it’s easily controlled if they want to.
They could also make it such that any client caught sidestepping is hit with a DMCA violation.
you need to expand your creative imagination around the limits of enshittification, there are really so many ways to make the experience shittier
As long as the client supports external display/input (e.g. USB-C with DP alt mode) you could always attach a KVM and run a proxy with vision capabilities to filter.
for the company/account placing DD orders via CLI, instant ban hammer.
you don’t seem to understand, sure clients can block ads. servers can also refuse to proceed unless a provable step is taken, and that’s linked to your DD integration. Bad actors can easily been detected
I'm saying the client can take the action, but the user never sees the client because they interact with it through e.g. their AdBuster box, a glorified PiKVM that interacts with client, OCRs it, and produces simple filtered HTML for the user.
As long as you can attach a display and USB inputs, your "monitor" or "braille device" can go straight to a vision model, which can then send inputs from your "keyboard". There are already off the shelf devices that can do this if you install an agent harness.
Whose DD API key is being used? This is not an anonymous access scenario. The DD API client is tied to some company, the behavior is detectable, they are banned.
Or do you give out KVMs to all your customers and say “place your DD orders with us this way”?
He's saying that some AI agent (with computer use capabilities, which the recent gpt model is supposedly good at) can at the very least, operate a browser (or phone) of the doordash website/app, scrape the contents via OCR, present them to the user, then relay any actions back to the website, all via KVM, making all of this undetectable to the site.
Ships passing in the night. I’m not disagreeing with any of this, and yall still miss the point.
I understand that individuals can make purchases with the DD API. People who want to buy things without seeing ads can always do that. Very few people will do that.
I’m referring to the obvious B2B2C use case where a company embeds DD functionality via the API. Then you’d have to teach the trick to everyone who uses your app or service and that’s not practical. If you skip at the server it’s trivially detectable.
> If you skip at the server it’s trivially detectable.
I don't see how. If I built a touchscreen-using robot, DD couldn't detect it. If some middleman business had a boiler room of 10 robots, it would be the same. All network requests identical to the official app. And if you think they'd look at IP addresses or something, how would they tell it apart from a college campus or a CGNAT gateway?
You can’t MITM your clients unless you root-cert them. The clients are independently attesting to DD, you can’t spoof it unless you’re the client. The B2B provider can’t do this without MITM attack. Any “legitimate” partner doing this is instantly banned & probably sued.
> As long as you can attach a display and USB inputs, your "monitor" or "braille device" can go straight to a vision model, which can then send inputs from your "keyboard".
This is awesome!!
The local AI revolution is going to be glorious. It's no wonder they want to regulate this shit.
I can't wait until uBlock Origin integrates AI support.
This is my read of the situation too. Amazon wants to control "agentic commerce" use cases so they can monetize them. A generic agent using amazon.com undermines that effort, so they're trying to use the courts to prevent it.
They're going to be confronted with the ADA soon enough. If I'm a quadriplegic I may want to employ my own user agent to engage in commerce. Amazon doesn't have any standing to dictate how I access their services.
I've long been thankful for a lot of ADA requirements in software, like OSX, which has enabled some interesting automation tools over the years. More recently, I have been saying the best part of MCPs and AI era is all of a sudden its gotten companies to expose all their data in a universal format, so I am no longer beholden to what a PM or UX designer things is best for me.
Selfishly, I will always advocate for this, but as someone who is colorblind (which barely counts as a disability) I am very aware of how easily inaccasbile so many tools are.
The powerbi dashboard that ships w/ fabric usage credits is the only place I have to know how much my work costs, and its the same color as several other things. Id so much rather they just give me the raw data on an API feed but instead I need to use like 400mb of ram to view an illegible chart.
Legal issues asside, I find this agentic commerce goal naive. Its like expecting me to buy a different microwave so the popcorn button works with the official amazon popcorn. Theres no way they will be able to replace the context and tooling I have setup for my own personal agents. And theres no way in hell im going to give Amazon every piece of information in my life so they are slightly better equipped to recommend which usbc dongle I need.
I understand that the sheer size of Amazon, and industry standard of forcing AI into every tool, makes them think its worth investing in. But from my outside perspective this is not a winable strategy.
If this is basically an MCP/api with curated data sources, then yes im interested.
I think there is some legit market opportunity to try to provide this to small - medium businesses. The biggest advantage Amazon has over them is visibility, and the tooling that comes with it. If you made a squarespace plugin or otherwise that would index someone's store, then that store owner would be able to get business from the shared platform, while not worrying about having a good search tool. As a potential shopper, I would have value in buying on this network, especially if I had reason to beleive the reviews were legit.
After I typed the above out I checked out your profile... you may already be working on this but I have some other ideas, can I message you?
Don't they already do something similar but with Shopify? Like you buy on Amazon and then Amazon scrapes the internet and buys from a Shopify site without the seller's or user's consent.
Exactly right. With LLMs, you can go directly to the website and checkout instead of going thru Amazon so they can collect their commission.
It’s actually why I’m building an open-source, decentralized Amazon alternative that’s powered by agentic commerce and MCP-UI that brings the cart and storefront into the chat directly.
Amazon and every marketplace’s days are numbered. It’s why you see so many of them trying to push their own sort of agentic commerce protocol because they want to control commerce in the age of AI. It’s exactly why I chose MCP-UI and not their protocols.
I just don't think that'll ever happen. The amount of people that will blindly have a machine buy something for them is very, very slim. Amazon has been trying to do auto orders for a looong time now and it's hardly taken off. It'll be a goldmine for scammers which will end up killing consumer trust very quickly. The only way to really have a "headless amazon" is have a hand curated list of approved merchants, which... you're basically back to just having amazon in the mix.
I think Amazon should be more worried about simple price comparison and tracking. They fought really hard against having to show the 90 day low and have gone out of their way to still rig it.
> AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads, which is a large part of their revenue.
That seems entirely backwards to me. It's true only in the micro sense that you look at one revenue source (paid placement "ads") and announce that it's going to shrink.
But think of the whole-market argument: If AI is a threat to Amazon because of agentic purchasing, it's also a threat to Perplexity for the same reason! Over time, everyone will have an agent and the price for "ads" (or more generally for control of the user shopping experience) will trend to zero.
Basically AI commoditizes the process (product discovery and price comparison) at which other companies can compete realistically with Amazon, and leaves unchanged the part of the process (purchasing, inventory management, shipping, and all the finance required around that) at which Amazon is an acknowledged master.
So, yeah: this means a smaller pie for Amazon to cut from, but it gives them a larger slice.
From a business perspective, Amazon was/is a legit business threat to ~every physical bookstore (and, arguably, many publishers). It doesn't follow that they could take Amazon to court for that.
In summary - if a perfect AI is made that orders the ideal product for someone, the best mix of price, performance, and reliability, then Amazon will be screwed because they make more money on ads than by selling people the exactly what people want/need.
As a brief reminder to readers at home, in a theoretically perfect free market, profit trends towards 0 as competition increases.
SKU-level transactions is what everyone wants. If an agent owned by Perplexity or whomever can capture that data from your Amazon account they can resell that data to advertisers. If they had the ability to access your account and "scrape" your entire purchase history from when you created the account... that's very valuable and Amazon does not want that.
> from a business perspective AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads, which is a large part of their revenue.
The dystopian part of me suspects that this is just a temporary blip as Amazon pivots from ads designed for humans to ads designed for agents. Which, in its truest form is just Amazon being a middle-man for bribing or poisoning agents.
In the end, it’s hard to not view everything through a lens of back dealing and anticonsumer enshitification.
Or maybe I’ve watched just one too many influencer videos on how the AI bots are either going to destroy humanity or take all the jobs.
So, the first set of questions is would 'exponentially better LLMs' dramatically increase the probability of any of the above, or domains that Dario is not citing? That assumes that exponential improvements will happen if there is not 'pacing'.
IF answers to above are 'yes', then we need to question if 'pacing' is viable. To use a different domain, regulating 95% of vehicles to a max speed would likely save 100s of 1000s of lives, but is not perceived to be viable. In other examples, regulation has unintended consequences in the opposite direction (e.g. some 'rent control' efforts and arguably some drug/alcohol laws).
WireGuard doesn't do NAT traversal. That's the main thing this adds. And this also adds a CLI tool + library to do streams over WireGuard w/o installing kernel routings, requiring root, etc.
IPSec may be a pain... but WireGuard is as simple as it gets in my opinion. Yeah, you may need to know basic IP concepts, like MTU...
NAT traversal is a different topic, WG won't help in that, and that can actually be a pain. I guess we should be using IPv6 already, and this tool would be largely redundant already. (not completely, encrypted access to isolated networks is a valid use case)
WG is totally fine for home labs etc. But pushing configs to the server or networm when onboarding a new peer, making sure the new peer IP doesn't collide with someone else, etc. Can be quite annoying sometimes.
NAT is honestly smaller of an issue and rarely encountered, but it's useful for example to expose services on my laptop to my phone, kind of like ngrok. That can be quite hard on vanilla wireguard.
For me the biggest thing tailscale/netbird solves is still the automatic handling of the peers, acls, or in other words automating fireguard config.
Even without NAT, the same hole punching techniques must be used for IPv6 since there is usually a firewall blocking inbound traffic. Only in CGNAT type scenarios where the network behind NAT is still "WAN" will be helped by IPv6.
Idk? I found it pretty easy to configure by blindly following the tutorials and copy-pasting keys. The only footgun is the keepalive setting, which will screw up the tunnel if one end is behind NAT, that tripped me hard, but besides this, no issues at all.
always have! our darwin and windows clients are closed source, but they wrap the oss implementation in github.com/tailscale/tailscale and you can see and even use all the same hooks yourself.
the control plane is closed source, but headscale is an open source alternative that we embrace and encourage people to use if it meets their needs/desires
agree. it seems there are two streams and they could diverge or converge?
1. workloads use existing credentials
support RFC 7523 and OIDC discovery, 'trust the trust (credentials) which has already been established'. basically extend current dominant NHI paradigm.
2. DPoP
mandate a signed proof for each request. so tie credential to a client-held key and specific request detail or context. viable to do at scale with #1, or does it diverge (e.g. because most #1 methods as most are not designed for DPoP?
It is viable. Think of workload identity federation as the mechanism for the client to get an bearer token initially, and DPoP as the mechanism for the client to present the access token to a resource server. Each DPoP proof is entirely self-contained, so resource servers don't need to manage any additional state. The only new state is the (usually ephemeral) private key held by the client:
1. Client generates a private/public keypair and uses it to generate DPoP Proofs -
JWTs containing the entire public key embedded as a JWK within
2. Client presents credentials (WIF, client creds, auth code, etc.) to the Authorization Server along with a DPoP Proof
3. Authorization Server validates DPoP Proof and adds a claim to the access token containing the thumbprint - the SHA-256 hash - of the public JWK.
4. Resource Servers will now see the thumbprint claim and now know the access token needs to be presented with a fresh DPoP proof.
5. Clients generate fresh DPoP proofs and send them along with the access token
There are lots of additional details around nonces, timestamps, per-request binding, etc. but DPoP can be rolled out to any HTTP system that speaks Bearer token already.
No - this is built on top of SPIFFE/WIMSE work to enable cross-domain usage where the target domain speaks OAuth instead. You wouldn't expect, say, Slack's APIs to accept SPIFFE SVIDs from your internal deployment. This provides a path for you to exchange your SVID for a Slack-issued Access Token.
may have been rushed by hugging face being unable to use claude to debug or fix their breach, because there isnt detail on new guardrails put into place to protect against anthropic's initial concerns of wide distribution?
separately, it is interesting they are adding an oem type offer:
>We’re working with our cybersecurity technology and services partners to integrate Claude Mythos 5 into the products and services defenders already use to secure their software.
anyone know the shape of those contracts, e.g. pure tokens/usage or more of a traditional licensing or oem type structure?
ShinyHunters making the claim. Again.
reply