Hacker Newsnew | past | comments | ask | show | jobs | submit | filleokus's commentslogin

This must at least partly be region-dependent right?

In the darker northern parts of Europe, the German transition to renewable haven't really been a cost-saving success story (right?).

From my (very) casual Swedish vantage point, the wind build out here was a very government subsided race to zero marginal prices that barely helped anything?


Most of Finnish wind capacity was built without subsidies. The demand was saturated at ~25% of total generation, after which the market started building solar. Wind power is more cost-effective at these latitudes, but solar generation is currently more valuable, as it correlates less with existing renewables.

That only makes sense if you're burning hydrocarbons to heat your homes; about 1/3 of total energy use is space heating. Shifting to heat pumps and more wind before wasting money on solar panels at high latitudes is better ROI on energy independence and carbon reduction.

Heat pumps already became popular a long time ago. Electricity is so widely used for heating, that the difference in electricity consumption between the coldest winter days and July nights is almost 2.5x. While there are some old legends of Finnish (or maybe Sami) wind wizards, we still haven't figured out how to generate wind power on demand.

In any case, it's up to the market. If you believe it's possible to make money with wind / solar / nuclear power in Finland, you should be able to get permits in a reasonable time. Right now, those building solar are investing more than the others.


One trivial reason might be the size of the artefacts / hardware requirements? Kimi K3 is ≈ 1.5 TB and requires multi million dollar hardware to run. Compared to e.g game development, I'm guessing that it's not like a bunch of people at Anthropic/OpenAI have the models running "locally".

It's easier to protect a power substation from being stolen then a Rolex watch


Well this concludes then that it’s like a handful of actual engineers and ML ppl that have access to it and have taken all precautions to keep it locked.

Again - many people have so far left these companies and none brought an usb drive out with what very likely does not constitute copyrightable materials in the first place.


Or the ones doing the stealing are so competent (or embedded) we don't hear about it

> Kimi K3 is ≈ 1.5 TB and requires multi million dollar hardware to run.

Not that it defeats your point, but an 8x MI355X node is $350k-400k. The only reason you're paying that much is for the VRAM, too. You could run it with much less compute than what you get in a single card.


That's "only" 11h of download at 300Mbit/s

How long would it be on 56k? I recall having to reconnect to my ISP every three hours to resume downloading an iso back in those days.

I understand "ricing" to mean customising the appearance of a Linux machine, see e.g https://old.reddit.com/r/unixporn/top/?sort=top&t=month (SFW). So in this case I assume the UI has a cat theme or cat icons.

I think the etymology is from "rice burner" cars [0]:

> Riced out is an adjective denigrating a badly customized sports car, "usually with oversized or ill-matched exterior appointments".

[0]: https://en.wikipedia.org/wiki/Rice_burner


Rice stands for Race Inspired Cosmetic Enhancements.

Race-inspired to look cool, but not actually functional. Picture putting one of those giant fake air intakes on the hood of your car.


Do you think "Race Inspired Cosmetic Enhancements" is the origin of "ricing" / "riced-out" or a backronym[1]?

Honest curiosity about language and language use.

In fairness and full disclosure: I have believed until now that the language comes from rice-burners and related, and I have never liked it. If I were still in communities that used it (unix desktop crowd), I might proactively steer newcomers towards your acronym as a kind of reclaiming.

[1]: https://en.wikipedia.org/wiki/Backronym


> I might proactively steer newcomers towards your acronym as a kind of reclaiming.

Any negative connotations "rice burner" once had was lost when the term shifted towards referring to cars instead of humans. But now re-recognizing that the enhancements are inspired by the East Asian race turns the connotations back to humans. Isn't that a regression?


Nah, I remember back then, it was definitely intended to be derogatory to the cars, to asians, and to people who like the cars.


Yes, the term originated as derogatory slang towards the Asian population in the early 1900s, and its use towards them became especially popular during the Korean War. There is no question there. However, as before, the term evolved away from people and towards cars. You cannot be derogatory towards an inanimate object. It doesn't have a mechanism to internalize feedback. In that evolution, the term lost its derogatory connotations. The historical usage, while a part of our past, is used no more.

Reintroducing this to be something about a population's race reinstates the derogatoriness. You can be derogatory towards humans. Minimizing the cosmetic enhancements to be being inspired by the East Asian race and not valuable human achievement brings us right back to the same place we were when Japanese cars started being introduced into the North American market, diminishing the human contribution. It is a regression.


Old enough to watch this cycle from racism, to community, to memes, to racism, and now back to community


If you want to actually enforce age restrictions that can be checked via some kind of digital identity I don't see how we can avoid the "trusted" hardware requirement.

The key material must be DRM'ed, especially if some ZKP solution is used.

Otherwise all underage kids would download the cool older brothers private key and load it into their GNU Taler client, buy wine and be gateway'ed into heavier Stallmanisms. Before soon EMacs would be all the rage in highschool.

(Of course we can argue the bigger points, if X should require age checks, or if this even should be done digitally etc. But there's a reason why we don't allow the physical equivalent of self-signed keys for physical ID's, they're not trustworthy)


Perhaps one could construct a bond-based system. It wouldn't help family collusion, but it would help limit people of age selling their authentication ability.

Say you have a public service and a platform site (social media, gambling, whatever), and the user does authentication in a way that anonymously proves to the platform that they're of age while revealing nothing else, and without revealing to the public service what platform they're accessing. But the protocol requires some expensive data (token that provides access to a bond account) which anybody MITMing the protocol can obtain.

Then if Alice tries to sell her age verification abilities to Bob, the protocol could be designed so either Alice learns the negotiated key and can snoop on everything Bob does, or she has to let Bob do a man-in-the-middle over a channel and lose the ability to observe what's going on after the first key exchange; and then Bob can acquire the token and make use of it at a later time.

This is very handwave-ish, but I don't think such a protocol would be impossible to design.

Under normal use, Alice has no reason to drain her own bond account. But if she's selling to an anonymous crowd who might use the token at any time (hence she can't trace the traitor), some troll is eventually going to do it.


> I don't see how we can avoid the "trusted" hardware requirement.

While this is a good point, what's missing here is that this hardware doesn't have to have Google spyware and other bloatware installed. Yet with current design, this becomes mandatory.. security requirements are abused here to force unrelated software on my computer that I have to carry with me in order to participate in society.

This app should work on a dedicated device, something like a smartcard with e-ink display.. it would even be more secure because it would have less attack surface. Just like today I'm not complaining about not being able to install linux on my credit/SIM card, I'd not complain about that either. But locking down the whole OS on my smartphone is unacceptable.


> If you want to actually enforce age restrictions

I don't.

This "think of the kids" nonsense is a psyop to manufacture consent for this shit. People really need to stop falling for it.


Do you also oppose drivers licensing, alcohol age limits? Those rely on a trusted ID managed by a government.


Not exactly a fan of those either, but they're much easier to tolerate because so far they aren't implementing a surveillance state straight out of a cyberpunk dystopia just to prevent kids from driving or drinking.

It's not like the car refuses to start if a dad tries to teach his kid how to drive.


I have never been asked to show my ID ever in my entire life when buying alcohol.

The alcohol age limit equivalent would be to put the entire TPM + proprietary software infrastructure into the cash register, locking in a monopoly on what software can be used on cash registers. Not to mention, you now have to scan your ID, which then obviously gets recorded forever, allowing the government to track your alcohol consumption.

Yeah, I'm against that and I don't even drink alcohol, not even the alcohol I've bought myself as a gift to my parents.


Xkcd 538. Hardware attestation is not required because it's not sufficient, you need to plug all the other much easier ways to get around the system.

Firstly, you need to comprehensively ban VPNs, probably with some great firewall setup.

Secondly, you need to install CCTV in people's homes to make sure that nobody uses someone else's device to get around the system.

Then it's time for hardware attestation.


But... Even when running it in mode 2 ("claude -p") they at certain points tried to detect OpenClaw-usage based prompts made, and blocked them [0]. Now OpenClaw says that Antrophic sanctions this as allowable again.

I agree with GP that this is hard to take seriously.

[0]: https://x.com/steipete/status/2040811558427648357


> Even when running it in mode 2 ("claude -p") they at certain points tried to detect OpenClaw-usage based prompts made, and blocked them [0].

But then the Claude Code product manager said:

> This is not intentional, likely an overactive abuse classifier. Looking, and working on clarifying the policy going forward.

https://xcancel.com/bcherny/status/2041035127430754686#m


I mean, if you are them and trying to detect when people are using your system incorrectly the detection system is going to be a little bit flaky. How do they prove you aren't violating your ToS by using OAuth for a system they didn't approve that usage for?

The fault here is not with Anthropic. It lies with cowboy coders creating a system that violates a providers terms of service and creating an adverse relationship.


I have never heard of this, and cannot be reproduced, and is not according to Anthropic's ToS. And there's a lot of FUD being spread around.

They don't ban Openclaw prompts, each custom LLM application provides a client application id (this is how e.g. Openrouter can tell you how popular Openclaw is, and which models are used the most).

Anthropic just checks for that.


Either me or you are misunderstanding the situation. A comment from the GP link: https://news.ycombinator.com/item?id=47633867

> This is slightly different from what OpenCode was banned from doing; they were a separate harness grabbing a user’s Claude Code session and pretending to be Claude Code.

> OpenClaw was still using Claude Code as the harness (via claude -p)[0]. I understand why Anthropic is doing this (and they’ve made it clear that building products around claude -p is disallowed) but I fear Conductor will be next.


If Openclaw was still using Claude Code as the harness, I don't know how to reconcile that with "Openclaw is based on the pi framework", which is decidedly NOT claude code.

From what I understand, they still had the Claude Code harness available, but were mostly fully integrated on the pi agent framework, using Claude Code's oauth credentials directly,


Openclaw allows you to effectively “shell out” to another harness for your model calls, while still using Pi as your main agentic harness. This is the claude -p workflow. Tools and skills are injected into Claude and they hack session persistence into it as well.

They also absolutely blocked OpenClaw system prompts from this path in the prior weeks, based purely on keyword detection. Seems they’ve undone that now.


No, if you ran Openclaw using Anthropic API as a provider, or had it use the ‘claude -p’ cli interface, you got an email from Anthropic threatening a ban unless you upgraded billing.

This was widely reported, and happened to me. You probably can’t reproduce it or see it in docs because they seem to have changed the policy.


Claude -p is using Claude cli. How can you know it's my own claw?


Neat! Pricing wise it might not always make sense though to use the commercial blob storages, especially for solo usage.

1 TB is roughly 20-30 USD per month at AWS/GCP only in storage, plus traffic and operations. R2 is slightly cheaper and includes traffic.

Compared to e.g a Google AI plan where you get 5 TB storage for the same price (25 USD/month) + Gemini Pro thrown in.


Backblaze is a lot more affordable


Yes, and they have features like default soft delete with hard delete after x days that makes it a very compelling backup choice (guard against malware and mistakes). I'm a satisfied customer.


If only they had data centres in Asia so latency would be better for me.


A family member has uploaded a backup of all of the family photos to Amazon Glacial Storage, on the order of a few hundred GB, and gleefully sends me screenshots of the <$1/mo charges.


AWS Glacier is cold storage, for things like legally mandated retention that you never need to access, or for humans, say digitizing your grandma's 35mm slides. It's not the same use-case as typical file backup, with performance that's probably not acceptable if you want a file (or even a listing) <now>. Good rule of thumb: Glacier is for things that you might need but ideally will never access again.


And then has to pay hundreds to get the data back


Retrieval is $0.03 / GB, so more on the order of 10’s of dollars. This use case is offsite location of the 3-2-1 storage backup rule. I think this is an underserved market with current consumer-facing backup providers.


One time retrieval is 1.5x times more expensive than HDD that would fit the data.


Stop paying for Google, give it to Bezos instead!


Totally agree.

Also, considering how prevalent TPM/Secure Enclaves are on modern devices, I would guess most package maintainers already have hardware capable of generating/using signing keys that never leave hardware.

I think it is mostly a devex/workflow question.

Considering the recent ci/cd-pipeline compromises, I think it would make sense to make a two phase commit process required for popular packages. Build and upload to the registry from a pipeline, but require a signature from a hardware resident key before making the package available.


I suspect nradov argues that this type of geofencing + allow-listing is not typically what people mean when they talk about "export control", which I agree with.

And while geofencing + allow-listing for sure provide value in e.g the Ukrainian conflict, it's a weak protection compared to goods that are actually under strict export control (e.g ITAR), and will always have to be done after the fact. Russia could for example put Starlink on drones launched from the Baltic Ocean targeting Poland or whatever.


Someone was using Xray, proxying to my employer, and it was detected in our attack surface management tool (Censys). I had some quite stressful few minutes before I realised what was going on, "how the hell have our TLS cert leaked to some random VPS hoster in Vietnam!?".

Thankfully for my blood pressure, whoever had set it up had left some kind of management portal accessible on a random high port number and it contained some strings which led me back to the Xray project.


Yes!

Any many CRDT implantations have already solved this for the styled text domain (e.g bold and cursive can be additive but color not etc).

But something user definable would be really useful


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: