Attestation of any type: A double edged sword, where you are guaranteed to lose freedom. Attestation entrenches, empowers, and enriches other entities that aren't you.
Ironic how this post got upvoted in parallel to polar opposite in the #1 slot: "John Deere owners will get the right to repair equipment under FTC settlement" https://news.ycombinator.com/item?id=48838876
Engineers may debate about what-about-isms of vulnerabilities and counterexamples of TPM failures, but that misses the point: We should be debating about where society will be when devices you paid for serve other masters.
Probably we should just write/vibe/demand better software. Otherwise we're going to end up with a law demanding TPMs that watch more than just your firmware...
> Every corporate network to which I've connected worked just fine without it.
Just because it appears to be working fine doesn't mean you are in control of it. Without hardware attestation, how do you know the machines are running the software you think they are?
> omg you don't know anything, being without the thing is primitive and everyone sophisticated uses it.
You can see how you can be accused of not actually presenting any arguments here, right? If you're gonna appeal to authority, at least back that appeal up with something.
My comment is fine. Appeals to authority are not inherently bad when the person doesn't know what they're talking about. Again, your doctor is more of an authority than you on medicine. It'd be hubris to think you'd understand the field better, no matter how smart you are.
It's not my job to write an essay in the comments about why mutual authn with RA is desirable in corporate networks, and why the complaints about "freedom" are totally and utterly nonsensical in this context. This is something he can look up very quickly.
> Again, your doctor is more of an authority than you on medicine. It'd be hubris to think you'd understand the field better, no matter how smart you are.
You are talking to strangers on the internet. When I go see my doctor, I initiate a conversation with a certified professional subjected to serious state scrutiny. I'd indeed do well to take their medical advice to heart. Nothing similar applies to reading your comments.
Moreover, part of the reason that I do trust the doctor is that I know that their claims can be challenged and that the claims will withstand that challenge (this is in part ensured by certification and regulatory bodies, and in part by the medical community). You seem not to want to respond to such a challenge.
Here's another doctor-based analogy: Suppose my doctor suggests I suffer from a specific medical condition. Even though I know that they are the professional, it wouldn't be insane for me to voice a concern I have that the condition does not seem to fit what I'm experiencing. That's not even really a challenge to their authority – it might just be a way for me to try to understand. Now, if the doctor responds to that concern by angrily tapping his diploma saying "you know nothing, I'm the professional, bow before me you moron!", I think I'd be wise to change doctors.
I hope you put a lot more research into those debates than you did with this topic! I just don't understand why you'd have this overconfident hot take about a topic you clearly aren't familiar with. Like, try to understand the article subject and audience first?
I didn't claim to be an expert in this particular area of security, but I have enough common sense to know that remote attestation is not "critical" for a corporate network. Perhaps it has valuable use cases for very large companies that want complete control over their employee devices, but your claim is far too broad to hold.
There's no reason I can think of where this isn't the case.
I mean, we're not even up to the "Model T" era of AI development and more like in the 'coach-built' phase where every individual instance needs a bunch of custom work and tuning. Just wait until they get them down to where every Teddy Ruxpin has a full LLM running on a few AA batteries and then see where the market lands.
I always imagine these AI discussion in the context of a bunch of horses discussing these 'horseless carriages' circa 1900...
Very nice. Thanks for making it clean and simple to use. I'm curious, only if you're willing to share, how you check so many domains availability automatically? Is there any potential rate limit problems behind the scenes?
One challenge I've always seen with similar tools is that the AI always wants to generate MultiWordsTogether domains, even when selecting that you want only creative short ones like "uber". Maybe this is something that a prompt change could help solve. But I'm pretty certain that LLMs today are just bad at type of single word creativity in their default state.
Bug report: when I click on the hamburger menu and switch to another item on your site, I get into an infinite loop of being prompted to sign into Google.
SPAs are not about view transitions. TFA implies that fancy transition is important between pages (wrong!) and blames a "CMO" or "brand manager" rather than challenging their own preconceptions and exploring the value an SPA does add:
- excellent frameworks for client side logic (interactivity)
- separation of concerns (presentation logic vs. backend)
- improved DevEx => inc. speed of development => happiness for all
The sad thing is that an article like this will get plenty of eyeballs due to comments like my own adding to the algo, but it should have never made it above the fold.
It's because it's catchy and repeatable, which really fits with this guy's broader claimed focus (SEO). I found it really ironic because I've built plenty of SPAs without page transitions of any kind (because it wasn't a relevant requirement) and only started adding them because view transitions made them easy.
I'd love to see more examples in a portfolio or catalogue page. I think it would help me more clearly see what is possible than just the links above. Or at the very least, having them all together on one page without having to open the design chat URL for each to see the examples would be nice.
I'm glad to see you working on this. It's an incredibly difficult and important space!
Assuming you have a desktop or VM that is always on, then using vs code or cursor with the remote SSH and dev containers extensions installed is great. The extensions operate on top of each other transparently.
A lost or interrupted internet connection is not a big deal. Both IDEs come back right where you left off by just hitting a reload button when you come back.
They also have some black magic (which I recommend against trusting) that will bring your terminal back to a similar state to where it was when you left off. I do not recommend the built-in terminal in either IDE though, but it is there in a pinch. For long-running tasks, if you like SSH, then tmux solves your problem.
I mean, the site is just incredibly beautiful. Good job. I want to go on vacation wherever the made-up end-frame is with the lake on the bottom.
I had to show it to a friend who said they must have hired a frontend engineer yelling, "I've wanted to do this my entire career, and you cannot stop me."
It is important for readers to be aware that the specs compared are not useful today.
Only the latest greated 50x NVIDIA gpus will do DP 2.1 (everything else is DP 1.4). And likewise, even your best monitors are unlikely to support DP 2.1 today.
HDMI 2.x is supported by a wider(est) array of available GPUs and monitors, and thus not only wins out, but is literally the only way to unlock the resolutions and refresh rates in today's situations.
Regarding the localness, are you optimizing or targeting users that prefer only local inference? The part about API keys at the end makes me wonder if there's any practical difference outside of lower local resource requirements and access to private models on the clound.
Do you recommend or force that people use any specific languages or frameworks that dyad is optimized to render or iterate on locally?
I definitely want to support users who want to use cloud inference or local inference because you do need a pretty beefy machine to run the top open source models.
Right now Dyad supports React (vite), but i'm working on supporting more frameworks in the future! (other languages is probably further off)
I think practically, the nice part with Dyad is that all the code is on your computer, so if you want to switch back and forth with Cursor/VS Code, it's seamless.
Ironic how this post got upvoted in parallel to polar opposite in the #1 slot: "John Deere owners will get the right to repair equipment under FTC settlement" https://news.ycombinator.com/item?id=48838876
Engineers may debate about what-about-isms of vulnerabilities and counterexamples of TPM failures, but that misses the point: We should be debating about where society will be when devices you paid for serve other masters.
Probably we should just write/vibe/demand better software. Otherwise we're going to end up with a law demanding TPMs that watch more than just your firmware...