Hacker Newsnew | past | comments | ask | show | jobs | submit | _tk_'s commentslogin

If producing secure software with AI will be more expensive than producing buggy software with AI, then I'm sure where software will be headed.

I think this is mostly in line with "all software is now easily exploitable by agents given enough tokens". However, in the long run we should really see software that is more secure than today. I do wonder though how the procedural flaws that exist today - bugs patched upstream, but not in the distro - will be fixed reliably.


I kinda miss the argument why so many “ambitious” people are bad parents. Maybe because it is too obvious? If you are not present for your child at the time your kid grows up (before and after school, weekends, etc) you are not a parent at all. You’re a roommate with certain privileges, but no child is interested in that.

People who work 60+ hours a week will be “worse” parents than others.


I don't think a lot of people will agree with you here because it's HN, but you are right. There are exceptions, of course, and it's way easier for the father to still have a career, but I have seen personally the difference between the parent that stays at home and the one that goes out to work. The connection with the children is different. I would hope that AI gives them more time with their children, but I know that it will not happen


I'm reading Careless People, and it discusses parents in high positions at Fb. They are not parents. They hire people to do most of the work. The author was "talked to" about sharing a story about her child.

My father worked 2 jobs in my teenage years. While I appreciate that he supported me to the best of his ability, I regret not having a connection with him. No trips, no plans together. Now, our relationship is need based.


Well, this surely is a productive post.


Original title:

Italy’s $4.7 billion cheese economy is feeling the heat as climate change threatens its cheese banks that hold Parmigiano wheels as loan collateral


Unfortunately, even if all data lives in the European Union, as long as a company is conducting business in the US, the Cloud Act makes it possible to compel them to hand over any information. This can include making administrative personnel sign NDAs or face heavy repercussions. Conducting business in the US includes advertising to US citizens e.g through maintaining a website in English.

At this point it’s unclear what a future digitally sovereign infrastructure should look like. Even if a company or a European state somehow manages to store data that is out of reach for the US Government, an amendment to FISA or the Cloud Act is something that any Congress should be able to put together.


I am pretty sure that European states are already storing data that is out of reach for the US government, and I don't understand how Congress could legislate against this, short of an act of war.


There are certainly exceptions, but a lot of European Governments use Azure or Google for their office applications, including different law enforcement agencies and militaries.


Indeed. My point, however, is that Congress cannot pass legislation to compel European governments to share data with the US if/when they decide not to. OP is making a weird claim about the practical impossibility of escaping US data collection.




I’m missing a little context here.


I’m a little surprised with one of the statements given in huggingface‘s report.

“To understand what a swarm of tens of thousands of automated actions did, we ran LLM-driven analysis agents over the full attacker action log, comprised of more than 17,000 recorded events.”

17,000 events? Big whoop. Security teams of medium sized companies process millions of events daily.

There’s a big debate in the cyber industry about the AI SOC and whether or not it’s necessary. It seems to me they are using that report to push that idea.


Agree. The F100s I contract with are easily pushing billions if not trillions.

Many of them have tried the LLM triage/SOC Analyst to…varying success.

One opened a legit P2 a few days ago actually. Great work right? Upon closer inspection it had decided this activity was a false positive for a solid month before.

The compromise (not significant in the end) was well done and over with by that point.

Others are swamped in so many FPs being bubbled up as true positives that they essentially just ignore it.


Given this is HuggingFace, I'd expect that's less about thought leadership and more using what they know well, in a critical situation.


That's because it's a fantasy someone wrote to upsell a proprietary LLM.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: