Hacker Newsnew | past | comments | ask | show | jobs | submit | keel-control's commentslogin

it's ridiculously bad

Why don't we have privacy respecting ZKP Age IDs yet (at least in the EU)? Could someone tell me what the hold up is.

I wish I could paste this as a prompt into a Codex Swarm and have it solve the government...

At least that would have more immediate impacts that the naiver stokes equations


ZKPs would defeat the purpose of age verification, the point being to track your activity online so governments can do precrime and make sure no group can ever use technology to organize and challenge existing power structures so this will never happen.

Should be a thing stores sell for $5.00 or whatever, show your ID (not scanned) get a code you can use to verify. This obviously has flaws, but the point of age verification isnt to protect kids, the world is ran by literal pedophiles.


This was my first thought after they disallowed LLM contributions.

They may not use AI to check for vulnerabilities but attackers are going to which puts themselves at the disadvantage.


They did not disallow LLM contributions, and they definitely didn't disallow using LLMs to research security vulnerabilities. They only disallowed projects that are majority LLM-written.

https://codeberg.org/Codeberg/org/commit/71149c7fc95ccfeae36...


That is about Codeberg, not Forgejo.

Forgejo disallows LLM contributions, including using a "general AI" (they include LLMs under "general AI") for reviews[0]:

> 5. Using general AI for review is forbidden. If the change contains changes to the UX it has to be approved by a human reviewer.

[0] https://codeberg.org/forgejo/governance/src/branch/main/AIAg...


Ah sorry, didn't realize they had their own policy. This is a little stronger, but you can certainly still use an LLM to search for vulnerabilities, you would just need to write fixes yourself and mention if you used an LLM for assistance.

The rule you quoted is about code reviews, they don't want you using an LLM to write reviews or leave comments.

This is a pretty poorly written policy to be honest, so I understand if you interpret it to mean "no LLMs in any capacity", but I think if that's what they meant they would have said that. In fact they explicitly allow content "made with the help of AI", you just have to disclose it.


Their definition of vibe coding is pretty whacky.

>Vibe coding is the practice where AI creates a code change (feature, bug fix, tests, refactor) with a human that describes what needs to be implemented.

So if you let an AI prompt another AI without human input, that's not vibe coding? Meanwhile if you prompt the model with pseudo code you've written or code written in another programming language to translate into the target language, that's vibe coding?

>It is not allowed to use AI in an autonomous-looking way to contribute in Forgejo.

They used the word "in", meaning it could refer to organizational membership, their repo or theoretically any instance of Forgejo, including self hosted ones. They failed to specify what part of Forgejo or the definition of Forgejo they meant.

Overall this is a pretty poorly written document and when you think about it, it doesn't really matter how poorly written it is when they are basically 100% against AI.


> Forgejo disallows LLM contributions

You're misreading the rule.

>> 5. Using general AI for review is forbidden.

The second sentence makes it even clearer, as it would have been unnecessary under a blanket ban scenario

>> ... If the change contains changes to the UX it has to be approved by a human reviewer.


This looks unambiguous to me:

  > Forgejo does not accept works of authorship (code, documentation, etc.) either partially or completely generated by AI due to legal uncertainties.

Using AI to find a vulnerability is not a work of authorship. Using the AI generated text as your bug report would be, but if you use AI to find a bug, then write up a report yourself, I think that would be fine.

>If the change contains changes to the UX it has to be approved by a human reviewer.

Would that not imply that a change that does not effect the UX does not have to be approved by a human reviewer? Otherwise, why specifically call out "changes to the UX" and not say "all changes"?


Was this discovered by AI? Is all AI code 100% free of bugs?

You are implying that just by allowing LLM contributions your product is free of bugs, and the LLM won't introduce new bugs. Of course, if the LLM introduces bugs, the solution is to add another layer of LLM looking for bugs, ad infinitum.

Another post from today from Shopify, praising LLM to code their frontend, also stated that their LLM generated code is not ready to deploy, and needs to be reviewed:

> It’s tempting to just point an LLM to the React Native codebase and try to one-shot the same features in native, but it doesn’t work. Even if you ask it to gather as much information as it can up front, freeze that into specs, task files, and then implement it, you end up with a huge amount of unmaintainable code that can’t be shipped. [...] each [build] must prove its behavior with tests, match the running app in a visual review, survive two adversarial code reviewers, and get a human's nod before it's committed and the next one starts.


> You are implying that just by allowing LLM contributions your product is free of bugs

That... is not the implication of the comment you're replying to.

You don't need to make it all fundamentalist.


> They may not use AI to *check for vulnerabilities*

you didn't read the comment, did you?


I really disagree with their acceptable usage policy, but you can't say it with certainity that LLM contributions would be a fix for this. They generate so much noise (as the primary incentive behind an independent LLM scan is often cheap contributor brownie points for your CV) that it also could lead to bogus PRs being approved or helpful PRs being lost in the noise.

Disallowing LLM contributions doesn't disqualify the use of LLMs to identify vulnerabilities.

Using LLMs for automated security audit looks like it could fall under the definition of "vibe coding" or "agent mode", which is strictly forbidden

>6. It is not allowed to use AI in an autonomous-looking way to contribute in Forgejo. This also applies when someone engages in 'vibe coding' or uses so-called 'agent mode'.


Why can't you use an LLM to find vulnerabilities and then hand-code the fix? You don't even have to clean-room implement it; let the LLM write the code, and then reimplement, doing what you can to de-LLM-ify it.

You can. People on Codeberg use LLMs. They are just against spam of low quality projects generated with LLMs.

That is actually entirely not what they were saying at the time of the vote and its aftermath. At all.

Go back and read the threads. On this forum, or on mastodon, or on the vote. It was pretty vociferously ... shall we say ... "principled"

It was never stated to be about "low quality" but about use in "large part" or "majority", and when pressed people refused to define what that meant, and in fact got angry and defensive and said things like "you'll know if you've crossed the line" and "stop trying to force consent" and similar pearls of wisdom.

The post-facto rationalization did in fact leave them room to judge "quality" on a purely subjective basis. I didn't stick around to find out how that would shake out.


I assume you are implying that LLM generated projects don't mean bad quality. That's true. At same time we all know what this means. Plausibly looking projects that might even work but have little human oversight. There are so many of them It's really difficult to know. I don't want to depend on such code and I bet neither do most programmers. Why? Because by then you might as well vibe the library yourself and be the one who does the oversight.

I might be wrong but I doubt that people on Codeberg are against use of LLMs that make the projects better. Like finding security leaks. What these rules are aimed at are hosting of endless vibe coded projects that are just copy of each other.


I would encourage you to go back and read what was said at the time. Yes, a significant probably-majority really are against the use of LLMs for anything and the policy was evidently not about a deluge of vibe-slop on the site. Because there was a much simpler answer for that: quotas, specific rules, specific policy, moderation.

Instead a vaguely worded policy was put in around the tools used to write code so that vibe-based judgement could sit and decide without the potential judged having recourse to any appeal. And requests for specificity were not just turned down but mocked. Because the intent was to leave it open so that a process of bullying could be put in place.

Basically, anti-democratic practices masquerading as community/democracy. I used to see this a lot back when I was involved more heavily in left wing activist groups and it was the sign of a declining and degraded community. Sad to see it here.

As for "I assume you are implying that LLM generated projects don't mean bad quality. That's true." I'm specifically saying LLM assisted/generated doesn't mean one way or the other. They're tools.


I love you being heavily involved in left wing activist groups but you are no more because they are anti-democratic. When was that? While you were working at google for 10 years? I think you might be in same situation like atleast third of the people here. Yes Codeberg members did undemocratic poll and they undemocratically voted for this anti LLM policy. I fully agree the left wing of the Codeberg is coopting their project and we should go to support much more democratic Github.

i love you too, buddy.

big hugs.


Do you expect it to be enforced by a machine? Why would you need a precise definition of "majority"?

You don't and that's why everyone gets so angry and annoyed when people try to force precise definitions.

There's no team of lawyers verifying the provenance of all code/projects submitted to codeberg. THe policy is just something they can point to as a general guidelines of what kind of shit they want to support.

Everyone knows exactly what kind of projects they're talking about. The people trying to nitpick definitions are those annoying ass people at the board game night that spend half the time combing through the rule book trying to figure out why whatever they didn't like was against the rules.


That's why they say they don't need an AI detector and that anyone who complains about the rule is guilty.

Ordinarily that's a bad way to run a rule. But not this time!


What the folks involved were actually saying, and what let slip multiple times through all those threads is: Any use of the tool is Wrong(tm). They never meant anything by the "majority" or "vibe-coded" or whatever because they didn't need to or want to; Multiple people let slip in all sorts of forums what the intent was: define a policy ambiguous enough that it could be used for frankly vibe-based exclusion. Defining the terms of exclusion was deliberately avoided because a) if-you-know-you-know b) they wanted to reserve the freedom to sit in judgement.

That's fine for new projects. Their sandbox and they can decide who plays in it. But the people who were using codeberg for months or even years and relying on it, and had to move... deserved better treatment.

Fomr my eyes the questions about what defines "majority" were well-intention-ed queries with the motive of trying to ferret out what the criterion for was in the eyes of the people who proposed the vote. That they refused to answer, and cast aspersions on the people who asked... is both a damning judgement on their personal character but also their community management.

What we have is a community defining an in-group and an out-group. And just like middle school, "you'll just know" if you're in one or the other.,

Good grief. What a bizarre cultish echo chamber. The tools make you dirty. Don't touch the tools.


Why put words in their mouth? They clearly mean a majority. They don't want projects that are majority written by LLMs. If they didn't want projects that an LLM had ever been anywhere near, they would've just said that. They're not under any shareholder pressure to lie.

And now you're literally saying that a "no vibecoded projects" rule is a slippery slope to actual fascism. Good grief! What nonsense!


You can, though some people are going to be annoyed by it and just publish a zero day out of spite.

there is a proof in lean4 it's correct by construction


How do you know that what is being proved in the lean code is the same as the millennium prize criteria though?


you can get another LLM to verify / if the lean doesn't have `sorry` used to skip certain parts of the proof etc. It's much easier once it's in lean4 because checks like that can be done computationally.


I think it's over guys


I get worried when thinking about Mistral because they make mediocre models and I don't think they will be able to defeat their competition.


That may be true, but there's a non zero chance that frontier AI becomes a controlled export, and that 'local' production becomes a prudent play.


Highly improbable given China is ready to pick up any slack.


That's true now, but given the strategic importance of AI to nation states and the fractious relationship many have with China, I wouldn't expect the eagerness to use Chinese AI to continue indefinitely.


If you're taking it at the state level, there's no difference between Chinese and US frontier models. They go with the most accessible, which is the former. Just as trade still happens overwhelmingly between China and US despite the politics.


Again - true now, but not certain to be so in the near future - which (I speculate) is part of the investment case for mistral.


Same here. And I doubt 3B EUR will do anything (remember the >$100B investment round that OpenAI got?)

In the EU it seems we are very much at risk of being cut off from frontier AI if the US government should decide to do so.


OpenAI also indirectly depends on ASML, but sadly Europe seems too cowardly to leverage this dependency at the moment.


If EU were to "leverage" ASML, and that would require rather unlikely approval of Netherlands, it wouldn't end very well.

Already shipped machines can not be taken back, nor can they be stopped. Sure, you can cut the support, and buildup of new fabs will be stalled. But the other side, Chinese or USA, has many more levers to pull. Raw materials, energy (LNG), was majority of consumer goods, solar panels, batteries, semiconductors. EU doesn't mine or make most of them, and isn't nowhere close to even starting, instead, industrial base is already shrinking.

Even worse, ASML may dominate EUV, but other suppliers do very well in DUV. The moment ASML becomes unreliable, all of them will get infusion of money, as they become national security issue.

What about ASML subsidiaries in USA, like Cymer and ASML Wilton, will they take the bullet for the parent? Or will they become part of new competitor, with all the knowhow.

And China has already set domestic capacities in this area as a national priority.


Blocking EU from those services would crash the valuation of US AI companies, so I'm not expecting it to happen.


You'd still have access to the Chinese models though right? Even if you want to argue they aren't truly SOTA they're still pretty dang good.


Maybe true for frontier LLM, but there's plenty of space in the niches. For example, I think their TTS/STT models are pretty good, speaking from personal experience.


Is there money in niche models?


Is there money in frontier?


Yes...?

Is that not self evident by the insane revenue from frontier labs?


Revenue is not profit.

https://isaiprofitable.com/


AI is profitable. Gross margins are high.

The only reason OpenAI and Anthropic are making a loss is due to training new models to keep up with competition - not because the industry is flawed in terms of business model.


> The only reason OpenAI and Anthropic are making a loss is due to training new models to keep up with competition - not because the industry is flawed in terms of business model.

So in other words they are not profitable? Like you cant say they are profitable and then in the next sentence say they make a loss. That is not how profit works.


Keeping up with competition is part of trying to stay in the frontier. If they stop training the profit disappears in a few months.


The point is that the model is already immensely profitable. There is no fundamental reason why AI isn't profitable. It already is.

Insane competition does not last forever. When chip manufacturing first started, there were dozens of companies that had fabs that made compute chips. Nowadays, only TSMC is viable. Samsung and Intel survived because of geopolitics.


> The point is that the model is already immensely profitable. There is no fundamental reason why AI isn't profitable. It already is.

We'll see I suppose. Until the audited financial statements are released, no-one who doesn't work for an AI lab can be sure.


Lol that chart is hilarious when you look at Nvidia.

Always sell shovels in a gold rush I guess


I mean yeah

> Is that not self evident by the insane revenue from frontier labs?

No...? Of course not?

Because revenue is only one side of the equation. Did you ever look at total cumulative OPEX and CAPEX, and how long it will take them to even just break even at current growth?


Anthropic is growing 10x revenue every year.

They're likely over $80b ARR by now. They'll be at $800b ARR next year at the same rate. Let's say their growth gets cut down to 3x instead of 10x - that's still $240b ARR by this time next year.

When you are growing so fast, you don't need to make a net profit. You just need to make sure your unit economics are good - which it seems like they are given reports that their gross margins are at 60-70%.


> They're likely over $80b ARR by now. They'll be at $800b ARR next year at the same rate.

And they will be 800 trilion ARR in a couple of years, following that same rate! 8 quadrillion by 2029!

> When you are growing so fast, you don't need to make a net profit. You just need to make sure your unit economics are good - which it seems like they are given reports that their gross margins are at 60-70%.

If their margins were anywhere near this good, they wouldn't need to raise so much money so often.

If you create a machine that turns 1 dollar into 3 dollars, you don't dillute your ownership of the machine, you use your fabulous profits to expand your machine's capabilities.


  If their margins were anywhere near this good, they wouldn't need to raise so much money so often.
Why not? They are reinvesting into growth. There isn't a clear winner yet and Anthropic wants to make sure it is one of them. Taking a profit now while letting OpenAI take your marketshare and train better models is not very smart.


Or they bleed money like crazy, and their margins are pretty awful. Which is the correct answer.

Your $200 subscription is a major net loss for them. The vast majority that pays for that would cancel in a heartbeat the moment they had to pay API prices. Which may or may not be profitable, I am not entirely sure. But for the sake of argument, let's assume that it is.


Why are we using consumer prices when the vast majority of their revenue is from enterprise api usage?


Wihout insight on how much enterprise is paying, it is impossible to draw any conclusions. Unless you have any access to their contracts and are willing to share evidence? I find that highly unlikely.

People here throw around crazy numbers - the dude above was claiming they have some insane good margins, numberd that he took out of his ass.

The only evidence I have is that they are incredibly unprofitable, and they keep raising insane amounts of capital like crazy.

There was a leak sometime ago that they were EBITDA positive during a quarter where they didn't pay for part of their compute. And EBITDA is a cute metric to use when depreciation is actually very important to them, as a model from a year or so ago is nearly worthless.


serving models is very profitable (70%+) but the issue is you need to invest in training the next iteration. but so far all of anthropics models have been profitable fully loaded

the vast majority of the labs revenue is from enterprise api usage (theres public sources from the information and ramp). but the risk there is customer concentration, where most of the revenue comes from other tech companies and a chunk of it is from foreign labs distilling

so i am drawing a conclusion that the labs' business model is good, maybe not as great as boosters think it is. if they make real progress on the biosciences like drug discovery that could turn it into an amazing business


> serving models is very profitable (70%+)

All your argument hangs on this.

I see no evidence of this being true.


https://www.seangoedecke.com/ai-inference-is-obviously-profi...

https://www.mindstudio.ai/blog/anthropic-inference-margins-7...

its even higher depending on the model, how optimized it is, and the chips!

I wouldnt die on this hill


This is not evidence. This is random people speculating on Anthropic's margins without any real evidence.

Just because it is on some blog post, it does not make it true.

I wasted the time to read the first blog post. It considers 100% utilization over the course of years to calculate an estimation, and it did not consider depreciation for the model itself. That thing is extremely extensive to create, and after a relatively short amount of time is considered outdated.


How much work did you go into looking for evidence?


Are we still calculated $200 subscription token spend based on their highly inflated API token cost and then concluding that they must be losing money on all $200 subscriptions?


Are their API token costs highly inflated? I see no evidence of that.


Sure, there is revenue, and market valuation. Is there _profits_ in frontier models ?

What is the horizon for openai and anthropic to _make_ money ? Will they achieve that by charging more for frontier models, or investing slightly less in training frontier models, etc... ?


They’re in the EU. If they are a year or so behind and things start to plateau they’ll catch up. Americans perhaps don’t realize we can also tariff their digital goods to protect our own. There is a scenario where Americans and Chinese foot the bill and EU gets out cheap, e.g. similar to the Apple approach to AI.


Maybe because they respect copyright laws?


Google has the means and ability to rewrite Chromium ; bug for bug in Rust from C++ using Astra & Fable.

Same for the Linux kernel. Considering the Fermat's Last Theorem lean proof was 13MLoC and cost $300,000 it would cost $2M to rewrite Chromium & Linux in Rust going purely of combined LoC.


Writing Chromium entirely in Rust wouldn't prevent a JIT bug like this.


ok for this CVE exactly it wouldn't have worked but the general pareto 80-20 rule stands regarding the rest of the memory safety vulns


Why don't you do it and post it here then?


I don't have $2M


The same people who would petition against ZKP Internet IDs complaining about the unregulated internet.

You can't have your cake and eat it too...


ZKPs (as well as C2PA and similar user attestation systems) are quite literally a DRM scheme for the web, fraught with all the usual control and accessibility issues while still being relatively easy to circumvent by a sufficiently motivated and funded actor. Given the huge number of shady companies that run "phone farms" for purposes ranging from social media spam to Spotify royalty farming, I doubt they would even put a dent on this kind of automated abuse. They would however be very effective at locking every Linux and GrapheneOS user out of the internet.


Now imagine he were a mathematician instead of a software engineer. The post sounds rather backwards in this scenario.


There are very serious mathematicians who refuse to use AI because they rightfully are concerned about the skill loss and harm overall. If anything it makes more sense for a mathematician to avoid AI than a software engineer though personally I think software engineers should use it sparingly as well.


Alas, he is not, and two things are true for him:

1. AI models produce consistent output, so it looks the same everywhere, which makes you look like a hustler if you use it for copywriting or design.

2. Customers who are fine with this can use Lovable for $20/month, so it's loser's game to chase those customers.


It is backwards in every scenario, and it is basically tilting at windmills. There is a lot of that around, thinking it is making a difference.

Guy thinks this is his niche. Everyone will go "that's neat" and move on with life.

There was another post on here recently by a translator, whose profession is translating documents, declaring that they won't use AI in their work and anyone who does is a noob and it is no threat to what they do...and it just was amazing stuff. Of course HN pandered to it with lots of "oh yeah that's right you show 'em", but surely we all realize how fantastically silly that was. A web developer / designer who refuses to use AI is rapidly going to be very unemployed, though they might try the purist "no AI here!" angle niche for a tiny delay of that inevitable.


There are many ways to use Ai in programming without having it write code. Code reviews are a place where they are extremely helpful and are becoming company policy. It actually improves code quality and that's before we get to the security side of things. Adversaries will absolutely be running Ai, so you ought to know what those Ai are finding yourself before others do.


glm 5.3 flash is the best model I have ever used


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: