Hacker Newsnew | past | comments | ask | show | jobs | submit | ldoughty's commentslogin

It has to be 18 months after public disclosure before the company has to send out a letter letting them know that someone might use their information, and they are eligible for yet another free credit monitoring service......

/S


The blog[0] explains their choices well. The brief highlights:

- Escape is simply unusable.

- Alt alone leaves the viewport and goes to menu, making further keypresses unregistered

- control is inconsistently placed on keyboards (e.g. laptops) which they don't say directly in the blog, makes extra sense if you recall it suggests not using devices the abuser might be admin/monitoring (public devices, friend devices, etc). It also is highly selected by other assistive technology products just like sticky keys.

They also recognized the issue... And tested it against JAWS and using it with on-screen keyboards

Seems they were very thorough.

0: https://beeps.website/blog/2024-10-09-why-govuk-exit-this-pa...

Note: this is the same link as in the grandparent post


> How is the whole economy exposed to AI?

Out of fear/ uncertainty, investors don't just pull out of AI, but the stock market in general.

More money shifts to bonds/commodities, not just people selling AI, but Coca-Cola and Johnson and Johnson, etc.

Of course, the impact would not be equally distributed, staple stocks will crash less, but there will probably be overall a huge pull out as people panic shift assets.

The resulting downturn likely means a crashing job market (temporarily) as government says "there's no way we could have known" and slowly try to stem the bleeding... Meanwhile unemployment shoots up in any industry that needs consumers (retail, food services, etc., but less so healthcare, government), and companies are nervous to hire on a shaky economy (see: early COVID).

The energy shock will also say inflation should go up, but the crash would want to decrease inflation... Companies will likely have to eat costs to keep prices low to sell inventory that cost them more to acquire.

It's all one big economy.

Note: this is all big hand wavey speculating. The moment things start to turn south there numerous things governments can do to help (e.g. handouts, reduce interest, open oil reserves, etc) so what ultimately does happen is anyone's guess. This is just one scenario based on the fact the current US government prefers uncertainty in the market, e.g. we've had peace with Iran ~8 times according to the USA, but Iran claims some of those statements are false. The straight had been reopened ~5 times, but Iran disagrees there to. Seems like the _goal_ is uncertainty


Who cares if "investors" are getting out of the market? They are not literally pulling money out of those companies but out of a casino that is the stock market.

One good thing in all this is, at least, if the AI stocks collapse that should not result in large-scale lay-offs. :) Quite the contrary.


That's a very narrow view...

The people in charge of companies usually have large amounts of stock in their companies... And often bonuses tied to metrics that often includes stock. If their share price drops 50%, that's a personal "net worth" and/or "salary" loss which, unlike most people, they have bounce-back control.

"We need to trim the workforce", "improve margins", "show we are still a solid company"

The above doesn't just happen in AI/Tech stocks, it happens EVERYWHERE... Small business owners see their retirement portfolio hurt, they can't fix those companies, but they might reevaluate what they do in the next 2-3 years so they can get their retirement back on track... How do they increase profits while lowing costs? Try to cut staff/hours, find (perhaps foreign?) cheaper suppliers.

I think AI stock bubble bursting won't result in large scale layoffs, I think it will result in large-scale _trimming_ across the economy, which is almost worse. AI will be expected to fill in the gaps to increase productivity for less than the cost of an employee, which means slower rehiring .. AI will rebound at a "more correct" evaluation. And hiring will slowly pick up as companies see they still need people to produce.

Viewing the stock market as purely a casino -- the executives are the house at various casinos... and the house likes to win at the expense of the players (anyone not a casino)


What qualifies as AI generated? If a human writes it then has AI improve/fix it, does that count?

How do you tell which is the case?

If we don't allow AI help at all, is that perhaps discriminating against those who don't feel comfortable posting with imperfect English?

I agree in principle, but am concerned in implementation... I'm not sure we can be fair without high risk of discrimination

Edit: typo fix

Edit: or am I AI?! And making edits looks more legit.... (To be clear: I'm not, I play by rules)


This is starting to veer into "smoking bans in the restaurants is discrimination against smokers."

It's not discrimination to ban a practice which has been proven to be harmful. AI slop is harmful to readers, as well as being harmful to produce. Whatever issues one might raise, for instance someone who is not a native English speaker, we can find alternative solutions which are better for the environment and better for human minds.


[flagged]


AI written comments have been more constructive than what you have been commenting thus far in this post.


Looks like the intended use case here is you buy the cartridge once, and refill it, and OpenPrinter won't lock you out after doing so like HP does.


Yea, but then the print head clogs up after the second time you refill it and you buy another expensive print head + ink from HP.

Frankly, I think 99% of the reason they started integrating the print head with the cartridge was to avoid all the problems you so frequently see on printers that don’t use disposable heads.


Will this have reach and teeth though?

I can imagine loopholes to this... nothing stops facebook/google from buying this data from companies not in Massachusetts? and facebook/google don't have to give advertisers the location information but can still use that information when determining the advertisement to return, right? In theory the big silicon valley "targets" of this bill don't actually have a huge incentive to give this data away, do they? They just need to be able to read/access it, which I don't think this law stops? Assuming the data broker is not doing business in Massachusetts itself


> Will this have reach and teeth though?

It'll have reach because MA has a long-arm statute and there's a rich history of applying that statute in the context of Chapter 93.

It'll have teeth but probably not to the effect that you hope.

This statute was written such that only the Attorney General can bring action; see Section 10(b). This diverges from a long history in the Commonwealth of allowing private individuals to bring civil suits for most types of Chapter 93 violations.

As a result, I anticipate that the most impactful change will be in the quantity and frequency of political donations to Mass AG candidates (and in the case of contested primaries their aligned block of candidates up and down ticket).

Consumer protection laws should always provide for a private cause of action. Otherwise they just function as a mechanism for legalized corruption.


I don't disagree with the thrust of your criticism of the dynamic (especially long term). But there is a legitimate concern that the first test cases to hit the courts need to be quite unsympathetic egregious violators rather than surveillance dynamics that have been thoroughly normalized for decades. If people start bringing private suits against neighbors that have deployed Amazon surveillance cameras, "credit bureaus", private investigators, big tech surveillance companies directly (eg Google, and especially with weak legal arguments), it is likely to set some poor precedents and create political pushback.


Section 2 already limits applicability to persons collecting or processing data on not less than 60,000 consumers, so suits brought against neighbors would be (rightfully) dismissed.

The concern about poor precedent stemming from poor cases has some rational sense, but we have the benefit of experience. Empirically it just hasn't tended to play out like that in the case of consumer protection statutes in MA. One reason this doesn't happen in practice might be the limited bandwidth of the appellate process. The SJC could (and likely would) prioritize answering questions about the statute in the context of cases brought by the AG.

The longevity pro-consumer laws in MA provides some good empirical data that cuts against the concern about push-back.


I'll admit my examples were pretty weak.

What I see is this bill, while a fantastic development, is still just addressing the tip of an iceberg on an industry that has been festering for many decades now (I mean, the "Fair" Credit Reporting Act - aka regulatory capture by the early digital surveillance industry - was passed in 1970). So "pushback" doesn't necessarily mean this law being undone, but rather it ending up as the full amount of privacy we can expect rather than first step of a hopeful trend.

For example look at how many more rights the GDPR grants. If a GDPR-analog were on the table in the US, the entire surveillance industry would balk. And these days the surveillance industry is basically the bulk of our "economy" (ie stock market valuations). And given the way "our" government works, I wouldn't be terribly hopeful about the individual liberty side prevailing over entrenched interests. Which is why I'm making an argument for more of a gradual shift.

Now having said that, perhaps it makes more sense for each bit of legislation to bite off fewer rights (as I'd say this legislation does), while including a private right of action so that the rights it does grant are maximally enforced. Having glaring violations of the law-as-written just sit there unaddressed is certainly its own powerful momentum-killer.


Couldn't this be mitigated by, say, having the private right of action not start until a few years into the applicability of the law?


once you allow someone to read data, it has been given away.

even if its only retained until buffer refresh, its still given away.

if its read frombuffer space and transformed into a persistent structure, its a gift that indefinately keeps giving.


but if facebook/google are the buyers, they do not violate this law... the law seems to focus on the sale & giving of this data... not the reception. This means that they just need a non-Massachusetts based data broker to sell them the data, and then they can store that data to make advertisement decisions (so long as they do not forward it along)


The intent of the law is probably to prevent the data from being sold*, so if the big Silicon Valley ad companies aren’t selling it, they are already complying with the law, right? The goal isn’t to destroy companies that are already not doing the thing.

* to the extent to which MA can do that… I mean it’s one state, so we should judge it’s accomplishments by that standard. One possibility could be that the rest of them get their act together, or at least, every state that engineers are willing to live in does.


Really cool! But right as it was nearing 4,000, it seems to have corrupted itself and no longer got any scores above 0. Not sure if that's a code bug or a neural net issue.

avg500 -4.6 last 500 episodes

peak 3959.3 best window

roll/s 20.68 20-step avg

progress 4388 562749 episodes


Yes it just collapses eventually — never stabilizes. The training process is flawed, I suspect it has to do with the fact that some weights blow up over time, you can see in “weights” tab.

But at around 4K avg score you should see it solve the env almost every time.

Just a demo :) optimized for speed over stability.

Reward structure: Step: -1 Dot: +100 Win: +1000 so ~4k is max theoretical score on 6x6.


maybe because it doesn't understand "done"? perfect play is impossible, random variance will cause scores to drop even if the model plays well and "wins". feels like it would get stuck in a loop trying to improve what can't be improved.


The optimizer doesn't need to understand anything it's just an iterated mathematical construct. The author simply didn't bother to implement the necessary details to ensure numerical stability.

Alternatively it might be a problem with the scoring model in the end game.


That is what I thought op was saying when he used the word "understood". No need to jump on people using every day language that is still easily understood in context IMO.


feels like it would get stuck in a loop trying to improve what can't be improved.

That is the point, there is nothing on an intention that we cannot improve, the goal here is no more than 1 unique iteration of the same path


I think I noticed it reach “end game.” The snake reaches a point where, if it gets any longer, it is out of squares and hits its own tail. So it finds the route through the squares that it can infinitely loop, never eats the ball, and score starts dropping and goes negative.


> The Claude Platform on AWS is a first of its kind offering for Anthropic, giving you all native Claude API features from day one. Anthropic operates the service and data is processed outside the AWS boundary.

So it's not... On AWS... ?

This statement sounds.... Backwards?

I get they have another option that is in AWS, but this continues the cryptic naming problem AWS already is overloaded with


I think the idea is that you can launder your team or product AI spend through your AWS account. This matters in Enterprise. It looks like the difference with Bedrock is that you access more "Claude platform" stuff than just the model.

More charitably, this lets an org heavy on AWS use their existing IAM / SSO / Finops processes to manage Claude stuff, this is genuinely helpful when otherwise you have to go thru several teams and build out whole new rails to adopt.


> I think the idea is that you can launder your team or product AI spend through your AWS account.

This is exactly it. For any reasonably sized org, setting up new contracts with new vendors involves a lot of procurement, lawyers, negotiations, etc.

If a team can just click a button in AWS, there’s no issue.

This is a product / solution that solves an organizational problem, not a technical one.

I wouldn’t even call it a hack as much as extremely common a strategy.


Sadly it’s going to be more nuanced.

The Bedrock models, at least, have additional click through EULAs for Anthropic models. You’re going to need to review and agree to those as well.

Claude is going to be marketplace spend and that’s usually capped towards your PPA at 25%.


> click through EULAs

Every year "don't agree to things on behalf of the company"

Every day "click here to agree that ..."


I've always wondered how this plays out in practice. I might certify that I have signing authority but I most certainly do not. What happens in the US (in Delaware?) when there's a dispute?


We had a customer try to back out of a contract by claiming the person signing didn't have authority. It didn't work because the person's manager (who has authority) was included in all of the communication.

Legally it didn't matter whether the signer had authority because the way the signer's company behaved during the signing process implied that the signer had authority.

E.g. If the CTO at a company tells a vendor to "send the contract over to my product manager" then the CTO created the impression with the counterparty that the product manager has authority, and the company will be hound to the contract based on that fact regardless of whether the product manager actually has authority or not.

I'm sure it's more nuanced than this, but my understanding is actual authority is less relevant than implied authority. E.g. if you have your board of directors take away the CEO's authority to sign a contract, it doesn't automatically invalidate everything the CEO signs, since a counterparty can reasonably assume that the CEO has authority just based on their job title.


Generally any W-2 has authority to enter into contracts, strictly from the vendor’s POV. As a vendor you don’t need to get your customer’s publicly listed officer or director to sign off on contracts. The W-2 can also be fired for entering their employer into the contract, but that's not (directly) the vendor's problem.

Once a vendor has entered into a contract, that could change - e.g. "any change orders must be approved by $EMPLOYEE_SET".

It's absolutely wild that every W-2 employee can expose their employer to essentially unlimited liability, but AFAIK, that's the truth.


Well, you see, I had my cat click "submit", so we don't have to pay the bill!


"Practice is policy"


No, "This is exactly not it." They are buying your data on a cheap.


As someone who is dealing with the procurement of both in a medium sized it, finops and infosec are exactly it.


Do you have experience selling to fortune 100 sized organizations?

“I don’t have the budget for this but we have AWS credits” is something teams beg for all the time.

When people beg to give you money, you accept it. Why? It’s not some conspiracy theory. You accept the money because it’s money.


100% correct... Have EPD or PPA? Reduced spend because of reasons? Well now you can make it up in claude tokens.


This is my day job. I couldn't get access to the Claude Platform even with a business goal justification because of the management overhead while having Anthropic model access with Bedrock.

Through AWS, assuming the underlying data governance is reasonable, this will be a much easier pill to swallow.


yes it sounds like a hack to get access to untracked spend in corporate accounts.

In my org, I have to file a form for reimbursement if I bought a pencil for $0.25 but in AWS? spend varies by +/- $5k per month and nobody even questions it. This will definitely make it trivially easy for me to build on Anthropic's services without even telling anybody vs the hoops I would have to jump to get it paid for another way.


Another selling point has been a guarantee of 1:1 api feature and design parity between Anthropic and this Claude platform. Helps if you have workloads you want to balance between providers.


Nah that's not what's happening here. This service is offered under AWS Marketplace. The only argument is actually probably a shared billing console, and that's where it ends. Won't matter for small companies, small fish, but the for the big pond this means new contracts to check, lawyers and so on. So not really a "revolution" happening. News for startups, yes, but not so much for the big corps or gov.


It is basically like invoicing through AWS Marketplace.


> I think the idea is that you can launder your team or product AI spend through your AWS account.

Can confirm that this is the one and only reason that we use Claude through AWS


Also you can spend your commitment contracts :p


Isn’t that capped at 25%?


Something like that, but if your boss went too high in your commitment contract, it's nice to have different options to put there...


Yeah its a "marketplace private offer"

As other people have pointed out, it makes contract signing much easier.

THe other side effect is that it bumps up your spend, possibly to the point where you are eligible for "private pricing" ie global discount.

So its a win-win for most people.


> Claude on Amazon Bedrock keeps AWS as the data processor and operates within the AWS boundary. This is a good fit for companies that have strict regional data residency requirements or need their data processed exclusively within AWS's infrastructure.

Seems like there are two different options.


Yeah i think this could backfire. At the moment they have such a clear messsage with Bedrock about data governance. You now have to ask a question and probalby get approval where previously there was no question and hence no barriers.


At this point I can only assume that AWS wants to have this naming issue. It’s an issue they have everywhere. Sagemaker is the worst offender. Only a solution architect can guide through such confusion…


As a long time Amazonian I can tell you it's simply because UX designers basically don't exist in Amazon (in case that wasn't obvious), and the ones that do exist are extremely bad at their job.


there’s a top level feature in aws for investors to give out credits of like $120k of AWS spend during funding rounds. there’s min commits of spend for cheaper prices (RI). funneling costs and invoicing though aws has real benefits. aws spend monitoring is literally a sub industry with billion dollar players


The credits you get from aws in their startup program are typically not spendable on marketplace. At least what we got through YC we could not spend there. Not sure how claude is integrating, maybe it’s different here


Yeah, as someone with strict export compliance concerns which forces us to use Bedrock because its exclusively us-based inference in our AWS account, this does nothing for me. Frankly, nothing Anthropic has shipped over the past 6 months besides the models themselves has been useful to our company, despite running into the same problems they're trying to solve with all of those features (managed, remote agents). There's not really a good solution, as AgentCore runtime sucks and is expensive. You basically have to build this yourself because nobody is solving for self-hosted managed infra for agents, and we don't really have the time to build this sort of system on top of building our actual product. It's very frustrating for them to put this out as a win, when it doesn't help the people who are using AWS Bedrock to begin with.


Synthetiq offers self-hosted (local or in your cloud)


The problem is that data centers use SO MUCH water... sure we humans let water evaporate, but this is a new source of water "waste" to the tune of nearing 2 billion gallons/year, just in Loudon County Virginia & connected water users [0].

When that water source is underground wells, this can take years (on the fast end) or decades (on the moderate end) to get back down. Look at California's water issue -- so many wells extracting water for farming has changed the land topography.

Also, when water 'comes back', it might come back in the ocean and not on land... reducing the available fresh water without desalination.

Data centers need the water to cool... but maybe there's room to find incentives for them to do so while making sure our water bills don't go up like our electric bills are because of the extra load they are putting on utilities.

[0]: https://www.theregister.com/2024/08/19/virginia_datacenter_w...


The owner of the private space generally has authority to deny this already, there's no need for an additional law.

In the US at least, any private homeowner/renter can deny entry to their property, barring legal warrants and exceptional circumstances. A business can have a policy, and is generally legally protected as long as the policy is 1) equally applied, and 2) does not violate ADA... A court would have to weigh in if glasses are allowed or not for ADA... but I suspect there's already a case where a movie theater banned such glasses and they would probably(?) win, since such individuals could be expected to have non-recording glasses.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: