Why is your agent able to call ssh. Why can it trigger 1password. Why are you giving metaphorical guns to metaphorical toddlers. Why is it not sandboxed. Your practices worry me.
I use containers in one context (custom container manager) and a regular UNIX account on bare metal in another.
This isn't intended to stop a model like Astra hacking its way out of course, it's more like guardrails on a staircase.
My personal container manager tool has an intercepting SSL proxy and small Javascripts on the host can rewrite or block HTTP requests. The agent gets its own isolated home directory and can't tamper with mine. Local caches like Maven are mapped read/only with a write layer on top.
You don't. I'd guess most of the developers don't. For example, my near 20 years of experience nets me a salary FAANG interns would find offensive. But in this part of the world it's "raise a family comfortably" money. In the end, it all depends on cost of living. And accepting you are not building 20 seat Lan party setup in your spare wing of the house.
My salary literally doubled just working remote/hybrid for London companies around COVID. I much prefer the lifestyle now I work for a smaller company in Canterbury and get paid less for the role. Turns out all that extra travel and overtime ended up being materially worse for my quality of life. And my job is way more fun nowadays.
What seems to work for me is automation - read file hook that re-injects instructions in the prompt every 15 minutes. Switch on the filename and get language-specific instructions too.
Can you suggest a proper sandbox on mac? One that allows both me and the agent to interact with the processes? Where it can drive browser, for both oauth setup and runtime visual inspection? I've tried building docker setups, but can't figure out the browser driving part.
I also did a butcher block top. Cut it down and routed to perfectly flow around what passes for a "straight wall" in this house, spent entirely too long sanding and finishing.
Then put it on some IKEA drawer blocks, because I want drawers, but I'm not equipped to build those in any reasonable timeframe.
Cutting down a desk top is something you can do with sawhorses and some good weather. More intricate things need an actual workshop for good results.
Are you looking at performance road bikes? Fenders and lights are removed for weight savings, and for pedals there are multiple clip-in systems, you are supposed to install the pedals that match your chosen system.
If, however, they are doing that for commuter bikes...
I guess that’s the reason you don’t understand why bikes are sold without these things. €400 gets you a very, very, very low-end new bike, like just one step above “unsafe to ride”.
You often don’t get pedals on new bikes because you have your favorite pedals that work for you and anything that’s included with the bike goes straight to the bin, because it’s useless trash. You don’t get fenders, because you don’t usually use those on any kind of sporty bike. They’re heavy, they don’t usually work that well, they are often hard to use in bikes with suspension with longer travel or and they can rattle or simply break and fall off if you ride hard. You don’t get lights and reflective elements, because they’re heavy plastic crap that breaks and falls off. If you often ride at night, you probably own some kind of night gear, high powered LEDs, reflective stickers or spokes…
And obviously once that is the norm for “bikes” in general, then why not save a few cents on supermarket bikes.
> €400 gets you a very, very, very low-end new bike, like just one step above “unsafe to ride”
I don’t agree. After my last bike was stolen I decided to buy the cheapest Decathlon had to offer - 240 - for getting around town and there’s nothing unsafe about it. It’s heavy and has cheap components but everything works fine for light city cycling.
You’re probably right, I’d trust a cheap Decathlon bike not to be unsafe. But they’re really exceptional in this regard, most non-Decathlon gear at cheapest-Decathlon prices is trash.
I don't need to be educated on the increasing lack of customer service for anything below 2000 euros, having got my first bicycle in 1984, upgraded to a cycling one in 1986, had plenty of others since then.
And from all places I lived in Europe, only around here this upselling seems to be a thing.
I think it’s just “cheap bikes”. Nobody wants to work on or with cheap bikes. And bikes are getting more and more expensive (quite fast). A solid bike built with brand name components is quickly approaching 2000€.
“Cheap” meaning low-end, not actually cheap for people to buy with their salaries. Bikes are, unfortunately, surprisingly expensive nowadays, and the market isn’t doing great.
I wonder how good the lock has to be, or the break cables and wire frames cutter resistant, for it to be worthy of leaving alone while shopping on the city centre.
Personal observation: Opus 5, over the last week, has started outputting A LOT more comments. Despite my global instructions being full of variations on "don't use comments unless absolutely necessary".
I might be imagining things of course. But comments would be great fit for this use case.
Comments seem most plausible, especially since I absolutely expect it to match my code style, existing architecture, and have the code go through CSharpier and dotnet format after the fact.
edit: as an aside - I actually use extensions to collapse comments and change the color to be less intrusive.
Yes the length of comments Opus 5 leaves is exhausting. Not to mention it will insert info thats only relevant within the current session. I've just been deleting all of them lol
The article is light on details but I don't think they are proposing a debate anwsering questions or presentation. I would rather have the presentarion, and I would even allow them to have a one page note with outlines.
Where did that trend start? Who writes like that, with emoji bullet points? I'm seeing it around, but surely nobody looks at that and says "yeah that's good"?
That is by design (on Firefox's part) to avoid someone registering e.g. steаmpowered.com (notice а as U+0430 instead of a as U+61) and running a scam that looks valid on the address bar.
But that means it had to be a trend already to be overrepresented in the training corpus, right? Or was it just something the RLHF evaluators got a kick out of...
I've really seen it a lot in Discord channels that have [emoji]channelname
Occasionally in some channels lists may be bullets with emojis particularly the welcome/rules, usually to match reaction emojis, or to automate channel(s) selection (click on the youtube icon to get notified when a youtube vid is posted, etc.)
I also have a "homelab" with minimal maintenance requirements. I'd wager it works out to much less than 15 minutes a month over a year. The strategy is as follows: pin all services to known good versions, deny access from outside LAN, and don't touch it unless there's a new service release with new features I want. Not something I would do at work, but perfectly fine for home setting.
Same. Been using this approach since 2012 and it works very well. I do have TailScale to make access a bit easier, and my AI box has proven to be a bit touchy as I do OS/kernel upgrade that match my ROCm drivers. This got a little bit easier with the 7.x kernels, but even that transition hasn't been super smooth. Will probably spend a feelw hours tonight getting it back in shape, but all my other machines are as you describe: almost fire-and-forget!
reply