Hacker Newsnew | past | comments | ask | show | jobs | submit | tinco's commentslogin

All the hobbyists were using proxybot because it allowed you to use more fun languages than C/C++ but proxybot lacked the features to effectively play Zerg. I really wanted to play Zerg so I built a really sweet API+DSL in Ruby around proxybot and then used that to give the other newbies a hard time with a zergling rush.

Unfortunately the proxybot limitations precluded me from expanding its capabilities so I tried to switch to having ruby embedded in C++ and I basically got mired there and was eventually distracted by real world concerns like actually finishing my degree.

I think I played against Krasi0's bot a couple times in the early days. Hopefully they stuck with AI and have suddenly become crazy rich after 2016. It certainly wasn't a given that AI was going to lead to a fruitful career back then, let alone to unimaginable riches.


It's a true power struggle. As a software engineer I have actually fallen into the trap of thinking that because of the law or a contract something would happen. It is a softer power than I expected.

The board wants to make money, that's why they hold shares and positions. If Mullenweg has the power to destroy value, that will be powerful leverage over them. If his employees side with him, if he holds the accounts, they'll have to negotiate carefully.

Of course, you would need a lawyer to determine when this crosses from a civil dispute to a criminal dispute because at some point him using the keys when he's not authorized could be a crime and if they can get the cops involved that certainly changes the dynamic.


This is why Sam Altman is in charge at OpenAI and not the board members that tried to fire him.

I think there’s a few big differences between OpenAI and Automattic:

On the “good for the board” side:

1. OpenAI from the POV of investors has both a pretty high p(massive returns) and a pretty high p(no returns). Even if they’re convinced AI is going to swallow the economy, that doesn’t mean OpenAI wins that. This discourages risky moves.

2. The range in outcomes from a Matt-less Automattic are much less varied than for OpenAI. Replacing him isn’t going to sink the company but it’s also not going to have a massive increase in valuation. It’s purely a decision that he’s a risk factor with his behaviour.

3. I’m sure there’s many good staff members in Automattic, but the work they do is pretty standard and understood, so there’s fewer irreplaceable individuals if any of them quit in support of Matt.

4. Because OpenAI is relatively new and has had such high growth, there were both a lot of true believers among the staff that it had to be Altman, and people who had a significant portion of their net worth locked into yet untradable shares that did not want the boat rocked.

5. What openAI hopes to achieve in marketing and policy requires a figurehead and only Altman had mass recognition. Matt’s public awareness is much lower and Automattic’s need for a public facing figurehead is lower.

In the pro-Matt factors:

1. Altman did not have an outright majority of the shares, Matt does

2. He did somewhat prepare by doing waves of voluntary severance to get his internal opponents to leave


Though somewhat of a digression I'd just like to jump in so the world doesn't forget that OpenAI was not a company with a valuation at all, it was a charity for the public benefit and is now in private hands, having been basically stolen by any reasonable definition of the word.

You’re not wrong, but I think the alternative future is sama loses control, goes and raises a quick $100M, and hires all the profit-motivated staff to make something that looks like today’s OpenAI.

Dario already showed there was an appetite for this.


Right. Much like the alternative future is that someone considering stealing a public museum could instead build a building, hire away the staff, and fill it with art he acquired, instead of just stealing a museum that was created via charitable donations.

Late reply, but I think once you took away the profit motivated people and the money man, the “museum” would have been exactly that - a collection of antiquated artifacts. But I guess we’ll never know.

I’m not saying it was right or moral, just probably inevitable.


Wait, sorry, what, Matt has an outright majority of the (voting) shares?

That changes everything, he can just fire the board members, he's the actual boss (as shareholder) even when he's also their employee (as CEO).


it seems like he likely can't just fire all the board members, as some seats may be contractually required to be held by his investors, as part of funding agreements

That depends on the bylaws and specific contractual director-designation rights they may or may not have. Ianal but if he really controls 84% of shareholder votes like he claimed, he should be able to alter the board composition legally. Probably enough to get him unfired

OpenAI was a charity, and the alternative was a mass move to Microsoft.

A big part in both stories is that the boards were unwilling to actually state what exactly the CEO did wrong or why they have lost confidence - be that professionalism or not wanting to deliver ammunition for lawfare - which perfectly sets up the CEO to position himself as a victim to the greed and power games of the shadowy board

> A big part in both stories is that the boards were unwilling to actually state what exactly the CEO did wrong or why they have lost confidence - be that professionalism or not wanting to deliver ammunition for lawfare - which perfectly sets up the CEO to position himself as a victim to the greed and power games of the shadowy board

Which is really insane when you think about it. The CEO reports to the board, and since when have companies regularly provided real reasons for termination (I understand they try to say as little as possible, because there's no upside for them)?

It's a coup when an underling "fires" his boss and takes control, but some CEOs managed to convince many that it's the opposite (or at least AstroTurf to that effect).


There are companies where the CEO reports to the board, and there are companies where the board exists to keep up appearances. We’re finding out in real time Automattic is the second kind.

This should discourage investors, since an unbridled CEO is bad for them in the long term. But it won’t, because nobody thinks long term anymore.


Also because most of the investors, by ownership, are Matt.

I think another example of the second kind is Tesla. Most (all?) of the board is loyal to Musk and not Tesla, as far as I understand it.

But no one (within a decimal point or two of zero) believes that about either CEO.

Were the OpenAI board members qualified to board members, they seemed like thay had no idea what they were doing.

> why Sam Altman is in charge at OpenAI and not the board members

Did OpenAI have a corporate board try to fire Sam? Or a non-profit board?


What is the distinction you’re trying to make here?

> What is the distinction you’re trying to make here?

Between a corporate board with a fiduciary obligation to its shareholders and a non-profit board with more-ambiguous responsibilities.

Also, Sam didn't pretend to be CEO after he was fired. He rallied to undo the decision.


It's already criminal from the sound of it

But that's less interesting for the involved parties. The more interesting question for them: Will it make us more money?

Yeah, but I am doubtful that the board wants to involve the police.

> I am doubtful that the board wants to involve the police

They're almost certainly going to get sued by minority shareholders over this.


Quite likely but I still doubt anyone will involve the police despite crimes very likely having been committed.

> I still doubt anyone will involve the police

Didn't a Board member resign today?


Up next, the leaking of the boards internal communications. All the dirty laundry - more at 11.

It's not pedantry, you're trying to find something in Rust that's simply not there. If this sort of thing turns you off on Rust you should be looking at a programming language with other priorities.


Not sure if that's true, there's some frozen supermarket pizza now that's seriously good. If I ordered fast food and they delivered a freshly baked Crosta Mollica pizza I wouldn't send it back. Of course a fresh pizza is better, but imo you couldn't get a Crosta Mollica quality frozen pizza 10 years ago.


Perhaps MSG. Seems to have been proven harmless, but leads to overeating, in my case.I"m not giving it up, I can't eat veggies without it :)


From my evaluation[1] neither Kimi K3 nor Qwen 3.8 are as good as GLM 5.2 at coding. I wonder if there's a marketing gap that's got people underestimate it.

It uses twice as much tokens to achieve the same but the results are significantly better and because it's so much cheaper it's the most economical choice too.

[1] https://blog.bosun.ai/software-maintenance-with-open-weight-...


This is really interesting. I built a similar product (not released yet), but it uses Kubernetes as the infrastructure layer instead of Cloudflare OS. I guess all these years later I am left with the same existential question that plagued Sandstorm. What is its relevance in the context of Linux containers? This is not a rhetorical question, is there a real benefit for a Sandstorm grain over a docker style Linux container? Does a containerized process not have all the same benefits of a Sandstorm grain, with the added benefit of not requiring any modifications of the containerized software?

One argument I could bring is that despite all its claims, OpenAI still had to switch from containers to MicroVMs because its agents under test still managed to break out from their containers. Is the security model of a Sandstorm grain so much better that agents wouldn't figure out how to break out of it?


Sandstorm's use of containers was just a means to an end. The real innovation was the fine-grained instances -- each document in its own container. No other container platform did that.

But honestly, it didn't work well, because of cold start times and memory usage. It's bad enough when a server takes seconds to start, but if every document you open has a long startup time and uses hundreds of MB of RAM, it's really painful.

Cloudflare OS doesn't use containers. It uses Dynamic Workers, which are 100x more efficient: https://blog.cloudflare.com/dynamic-workers/

So the stuff I have been building in Workers for the past 9 years turns out to be the thing that Sandstorm needed all along. What a coincidence. :)


This is far too Cloudflare flavored to be interesting to me.

It's using Workers (capital W) and the core Cloudflare primitives.

I don't feel safe building on this or touching this.

I'd be happier if a startup or neutral party built this in a more agnostic way.


I'm sorry but Workers is the technology that makes this all possible. I don't think I could have built this without Workers as a foundation. (I tried once, with Sandstorm, and like I said, it didn't work well.)

Sometimes you just can't advance the state of the art while also maintaining broad compatibility.

It's all open source, though. You can run the whole stack on your own machine.


For what it's worth, we also ran workerd inside a Sandstorm grain and not only did it work, it performed well. In the same way some people run Docker to run a single thing inside a VM solely for that thing... you can probably use workerd just to run a single Workers-based thing inside something else... and it'll probably work just swell.


Workers is a product and you're paid to develop and sell it as an employee.

I 100% understand the hustle. I do the same thing. I just don't trust a giant like Cloudflare that has done several things to weaken the open web and establish a position that is all too powerful. I don't want to give them an iota of support. Even using open source buys into their mindshare, distribution, ecosystem, and eventual supremacy and lock-in.

I'd buy this from a smaller company for sure. Just not from Google, AWS, Cloudflare.

If this was a YC startup I'd have given you my credit card info already.

I don't know what your stock in Cloudflare is like, but your upside would be way bigger building this externally. You'd probably raise an extremely large seed round.

Consider launching your own startup. Don't give Cloudflare all the upside.

Edit: I didn't realize you'd already responded. Was clarifying my position and wishes for this to not be something made by Cloudflare.


I tried it as a startup once, so I know what that's like. It's a lot of time spent running around begging for money (from investors and from customers) rather than building technology.

Workers is my startup-within-Cloudflare. It won't make me a billionaire, but it has still made me more money than I actually know what to do with, while being able to delegate all the stuff I don't like doing to other parts of the company that already do it quite well.

I have a lot of influence here. The CEO and CTO listen to me. E.g. I made my argument this all needed to be open source and self hostable, and they agreed enthusiastically.

I don't think I could build this better as a separate company.


I appreciate your extremely thoughtful answers. It greatly improves my perception and attitude about this.

I'll check it out.

I'm still anxious about the Cloudflare angle (and that's hard to shake), but beggars can't be choosers. You've legitimately built something cool and done a fantastic job spearheading that.

Thank you for the kind and well stated response. Sounds like you've had a lot of fun building this too.


Love the wisdom and transparency, such an amazing thread


Congratulations on making it, yet continuing the grind! Work takes on a different meaning when you could just fuck off to the beach for the rest of your life. Thank you for making it open source, not that I'd make a Cloudflare competitor with it, but the sandbox technology will be useful.


We're going to prove it's hostable outside Cloudflare, if you're interested in the tech but want an (experimental) "neutral" hosting option - email us hello@zqm.sh if you have questions/feedback.

https://zqm.sh/


My approach has been an interpreted Lisp running on a web server backend and it basically does everything described here


dumb question: is this javascript/typescript only? can you use webassembly based languages instead?


In theory Wasm could be supported, but generally JS/TS is much more efficient when running inside isolates (our lightweight sandboxes) since you don't have to bundle a language runtime into the app. CFOS at present only exposes JS (with TS coming soon).


Please add Wasm support :)

I'm making a whole new language to get around the problem you're talking about: it brings no runtime at all. One of my targets is a Sandstorm like system I've been slowly working on, but I'd love for it to be a fit for the actual Sandstorm successor.


Mmm so application-level sandboxing. Lovely.

And I’m assuming your worker runtime is a process in a container on a shared node? What happens if the agent exploits your runtime?

Does it get access to the whole container? VM? Node?

Why should I ever choose this over MicroVMs? I have to design my architecture around your JS runtime. This isn’t an OS.


Let me quote the workers GitHub:

> WARNING: workerd is not a hardened sandbox

> workerd tries to isolate each Worker so that it can only access the resources it is configured to access. However, workerd on its own does not contain suitable defense-in-depth against the possibility of implementation bugs. When using workerd to run possibly-malicious code, you must run it inside an appropriate secure sandbox, such as a virtual machine. The Cloudflare Workers hosting service in particular uses many additional layers of defense-in-depth.

Sandstorm was great because it did proper sandboxing. This is pretty weak by comparison.


Workers are in the same process but have separate heap, global vars, gc etc, the isolation is managed and achieved by V8. It is much lightweight compared to micro VM or containers. But the downside is you have to use JS because of V8.


I get that but it’s much less secure. ie. If an agent finds a bug in V8 it’s over


I don’t think containers, as normally used, provide that much security because so much of what you want to secure is at the boundaries between containers (the network) rather than inside the container itself.

There’s not much point in preventing hyper visor escape style exploits if the agent can just SSH or psql log in to an adjacent container. Likewise there are near infinite ways to do weird things with the network to make stuff happen in another less controlled environment (eg sign up for AWS free account, make VM, do everything on that VM where controls don’t apply).

There are tools to do this, but I’ve never seen anyone package them up in a way that was pleasant to interact with. It’s got the SELinux problem of being useful, but annoying enough that everyone just disables it the second it gets in the way. It’s surprisingly hard to manage what should be able to connect to what as you start scaling out the number of things on the network. Whoops, you forgot that random software embeds its own DNS over HTTPS resolver so the normal DNS profile won’t work and everything crashed kind of issues.


It has real business value. Letting non technical users run wild without the onerous layers of controls in traditional enterprise IT.

We're already contending with users wanting to hook up every SaaS MCP to every other SaaS platform and then slap AI on top. Having a controlled sandbox for that would hugely simplify things.


Linux namespaces, and containers, are not security features in themselves. They end up having to be combined with SECCOMP and some sort of application kernel or SELinux in order to have an effective security apparatus. This is before you give it application aware security controls like policy.


> is there a real benefit for a Sandstorm grain over a docker style Linux container?

Linux containers are meant to be used by those with significant software engineering skills. Sandstorm was designed to be used, once installed by someone else, by grandma.


When I was in university the course was called compiler construction. Making a language like G# is very simple and about the level that the final project of the course would be if the team was working together really well and went for maximum bonus points.

We have so many programming languages because it's a fun and relatively easy thing to start, and lots of people have differing opinions of how it should be done. Also making a programming language seems like a difficult thing from the outside so it has a certain allure.

Swift exists because objective c has archaic language design that modern developers reject. Objective C exists because as far as I know at the time smalltalk style object oriented programming was hip and C++ made the wrong decisions in their eyes. It could also be that C++ wasn't popular enough yet at that point for Apple to commit to it. In that period basically all major operating systems went different ways. The Unix derivatives went all in on plain C, Microsoft went C++ and Apple objective c, though I think OSX itself is plain C for the most part.


I don't know how CarPlay is, but Android Auto restricts the apps and app interactions you can do in the Android Auto user interface. On my phone the only apps that show up are google maps, spotify, and my podcast player and my phone interface I think.


They might, but the final outcome of that depends on whether the tokenmaxxing rust-using zero-user startups are using more memory in ci/cd than the users of efficiently written successful apps are using in production.


Seems like not being compatible with Sentry's agent is a missed opportunity for Appsignal, which I think is the premier EU based (Amsterdam) APM suite at the moment. It sounds like Bugsink is rather barebones in comparison and I bet a quick agentic coding session would make short work of a migration to AppSignal.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: