Hacker Newsnew | past | comments | ask | show | jobs | submit | ForHackernews's commentslogin

The dream was that you could separate content from presentation and content could be adapted and reinterpreted by anyone using whatever tools they choose: User Agents that actually respected the users' vision, not the publishers'.

And accessibility.

The posts above claiming design and content are inextricably linked are probably blessed with all the standard senses.

As usual it's a bunch of folks talking past each other. Style and content together is a nice simplification when you want to conform to a particular vision. Separation is a nice abstraction if you want to enable multiple views of the same content (like a pdf version or a colorblind version or a vision impaired version) without having to change/control the content.

Like most things in this space, different tradeoffs make one better than the other in different scenarios. Taking a hard stance of "one true way" is probably missing some imagination or experience.


I think that's an original issue though.

Accessibility certainly requires a content-first approach, I agree with you there. If you view each part of an application solely in terms of what it looks like to a sighted user, it's easy to miss the subtleties of what the underlying structure ought to be.

But when you start layering on the presentation, you're still generally binding that presentation layer tightly to the current content. If you, for example, were to restructure the links in the Zen Garden footer for some reason, most of the styles would break because they're bound to the current structure of the content. The separation you talk about only exists in one direction.

By comparison, when I talk about separation and decoupling in terms of code, I mean that there is a single, explicit, and tight API that acts as a clear boundary between two units. By explicit, I mean that I've designed the units specifically so that they expose this API - this is almost exactly the opposite of what I should be doing with content and presentation, as you point out! By tight, I mean that the API is as minimal as I can make it - two units interacting via an API need to understand nothing of each other except that API, and that API is as small as possible.

None of that is happening when it comes to the interaction between content and presentation. The content is not explicit - I'm actively trying to write the content for the design, which precludes making it an explicit API surface. Nor is the content tight - again, I want to build the content without worrying about how I will layer the design on top, and I don't want to limit myself to just a small surface area here.

So to me, it makes sense to see the content and presentation as being coupled together, even if that coupling ideally goes in one direction only. And if two systems are coupled together, it makes sense to do that explicitly by co-locating those systems. Therefore, I tend to prefer systems like Tailwind that let me apply the presentation layer directly in the content layer. (In practice, I mostly prefer other tools that still let me write real CSS syntax, but Tailwind is pretty damn convenient a lot of the time.)

As an aside, talking about accessibility, I'd forgotten how inaccessible some of the Zen Garden designs are with their addition of extra content in the presentation layer alone.


Except HTML is already a presentational markup language. People lose track of this.

Consider: MathML has a presentational schema and a content schema. The whole point of presentational MathML is the intermingling of concerns. If you want interoperable data, you use content MathML.

Interoperability is a noble goal, but if you want HTML to do everything you're already barking up the wrong tree.


It's not quick, but you can submit a GDPR/Subject Access Request to Twilio and after a month or two they will send you all your Authy TOTP seeds.

Then you can import them into Aegis or some other FLOSS solution: https://github.com/uiltondutra/authy-migrate


That is alarming. They have access to the plaintext? And they will hand auth secrets out? That seems extremely wrong to me.

>...data arrives as a CSV in which every token is encrypted with your backup password...

Fair enough. That seems reasonable.

They always had access to the plaintext, they could do better to hand them out

So there is a real solution to that problem! Thanks a lot for sharing it


I have no inside information, but I always assume the tickboxes that "disable ____ data" from Google/Facebook/OpenAI just disconnects it from your own account, not hides it from the provider.

The checkbox has an actual statement associated with it about what it does. You don’t need to assume anything.

There's no independent verification of what that checkbox actually does. The company can say anything, and you are unable to verify that they actually do it.

The only verification you could do so far is GDPR-style data export, and also the adherence to GDPR regulations (and even those might get skirted if they aren't operating in europe).


Aren’t they usually phrased very specifically as “we collect this data and use it to show you relevant ads, you can opt out of us showing you relevant ads”?

Wait, so I can have free movies and subvert the adtech business model at the same time? What's the catch?

Anyone can buy traffic on the proxy, not just click fraud, but cc fraud et al as well. Caveat emptor, it’s really not worth it compared to setting up a 3 USD per month Hetzner proxy box yourself, if you’re looking to pirate movies.

For some more context: We run a business based on data scraping and metered residential proxies have never been cheaper. Countries that used to be 10 USD/GB just ten years ago are down to 1 USD.


Hetzner?! No, I would never use them if I wanted to host a pirate proxy myself. Very crude, trigger happy, operating in a country very cosy with all the police organisations.

100% this. Pirating in Germany is probably the stupidest thing one can do, because enforcement is done by individual lawyers via a process called Abmahnung. Courts (and therefore providers) are very friendly to those. Everyone knows someone who got "the letter".

> Caveat emptor, it’s really not worth it compared to setting up a 3 USD per month Hetzner proxy box yourself, if you’re looking to pirate movies.

How does that work? Wouldn’t Hetzner know who you are (because you pay them), meaning that if you’re caught pirating on it they could just know it was you and hand you over?

And don’t think Herzner wouldn’t hand you over. My only experience with them was during a job, when an external company complained about something on a single section of a massive website (everything was legitimate, we weren’t doing anything remotely shady) and Hetzner straight up took the whole website down and demanded a change. Shoot first, ask later. I wasn’t directly involved with managing the website, but the whole thing soured me on Hetzner.


This is the bread and butter for commercial VPN services. The VPN knows who you are (maybe, unless you pay crypto/cash), and the rights-holders know your VPN address (from joining/logging a BitTorrent swarm, for instance), but the better providers keep no logs, and I'm guessing there's too many individuals to target effectively.

I've received a nasty letter from the ISP over BitTorrent (someone's phone joined my wifi, torrenting without my knowledge), but using a VPN seems sufficient. I think the Hetzener suggestion is a VPS for running the software stack. You could alternatively self host on hardware in your home.


Exactly my thought. For, say, $50/month I can get a second ISP to my house, host the proxy (and only that) on that link, and enjoy free movies. It is cheaper than having 2-3 streaming service subscriptions.

Or for $5/mo you could have a mullvad subscription and a vpn-aware bittorrent client that knows how to pause if the vpn drops.

You're underestimating the ease of use of these pirate boxes.

Also most of them are for pirating live TV. You can't watch live TV through Bittorrent, you just can't, it doesn't work that way. Sports fans need less than 5 seconds of latency relative to the loudest neighbor they can hear, or they'll hate your service.


True but that option got a lot worse when they disabled port forwarding.

These residential proxies are also used by scrapers. From scraping stores to scalp merchandise, to scrapers of data for AI training.

Sounds awesome, what's the catch?

You also get to run credit card fraud purchases through your home internet connection, such fun times we live in.

So what's the catch? Has anyone ever been arrested for proxying a fraudulent credit card transaction?

Probably not. But do you really want the hassle of explaining the proxy to the police when they get a report of CSAM content uploaded from your IP?

Has that ever happened?

It's a possibility. I don't know about CSAM but I know someone who was arrested for death threats sent to a politician after running a tor exit node. Eventually not charged, but he lost all his computing equipment for a couple of months


Has anything changed since 2009?

> Eventually not charged

Theres your answer.


Considering the question was "has that every happened?" regarding the police getting a report and you having to explain the proxy to them, I guess you mean the answer is yes and your attitude is misplaced?

ehh, subvert is a stretch. But yes, you too can be a minor accessory to scams run by thieves to rob advertisers, with enriching the world's largest ad company as a side-effect. Not exactly a Robin Hood situation given that tons of the advertisers being robbed are just normal small developers trying to get their apps out there.

The more these small devs realize their ad spend is going to bots, the less they'll spend. Like the OP.

Once the word gets around, even small non-techy businesses will pick up on it.


I'd wager a fair chunk of my money that money breaks OpenAI before OpenAI breaks money.

OpenAI != AI.

If you were in 1999 you'd be saying pets.com = internet.


I think this leads to an interesting question. What happens when the money runs out?

Right now, a lot of money is going to train new models. And we need to train new models because they get gated by their training data. And models are only as useful as their training data.

So let's say the money stops.

Do we stop training models? Do we train them slowly? Do we accept the then current models as the limit?


Governments, especially the US government has got a taste of how good LLMs are at hacking. This is something that has typically been very hard to get enough people that are good at it and willing to do it for a state. Now they can spin up as many hackers as they want.

Look at how much we spend on single bombers, how many training runs can you do for that much?


The money is never going to stop. It’s basic economics.

Well, the money will stop when the value of problems the LLM can solve is not increased by adding compute. Since current LLMs are getting quite good at solving problems, that might be a while.


yeah yeah yeah. I agree that AI is and will be a very useful tool, it's just not going to be worth $30T like OpenAI/Anthropic are pretending.

How long until we find out that some AI has quietly buried an exploit in Lean to cheat at proofs?

Simpler to exploit a soundness bug than introduce a back door I would assume

This is exactly the problem: Software developers are not a professional class, we are hired goons with no professional organization nor a code of professional ethics.

This is one of my personal bugbears. I keep making this point on HN but devs want to LARP as professionals so they usually don't want to hear that they have more in common with retail workers than they do with carpenters, engineers, or accountants.

Previously:

https://news.ycombinator.com/item?id=47625159

https://news.ycombinator.com/item?id=48932441


Maybe AI will provide an impetus for change. One can only hope.

I’d be willing to pay a few hundred dollars a year to be a part of a professional organization that maintains ethics requirements at this point.


Yeah, and read the responses to your comments: "but, but, 'professional' is a state of mind, not just a piece of paper" and some crap, completely missing the point. Professionals push back with "I'll lose my license/certification/disbarred". Software developers push back with "yes, sir, how high, sir?" or "I quit".

> have more in common with retail workers

They did this to automotive.

It was once a respected technology, and being a mechanic or factory worker was a high-paying job.

Now you have Jiffy Lube and some pimply kid in a polo!

Polofication

Has come for many industries...

And if retail was done the same way as it was 20 years ago, some kid in a polo shirt at Office Depot would be making small business websites using ChatGPT with a 1-hour turn-around time. Pay at the register, with your printer paper.

But Idk, I don't actually agree with you...

I think "software engineering" is such a spectrum now, a wide field of its own, that you can have deep research roles, high art, fashion, accounting, and executive-level work that involve it (which may have nothing to do with "consumer web design") that it's hard to make that blanket statement.

For example, the software engineer working on the computer in a Tesla, or the software on the displays in the BART train, or the banking infrastructure for Bank of America, is a lot more like a "real engineer" than the developer putting a marketing site on Vercel, or an iOS game on the App Store (each of which is vastly different work in their own right).

Everything is software now, every engineer is a software engineer now to some degree.


Nothing that you say is responsive to my point. None of your so-called engineers at Tesla has ever said, "I'm sorry Mr. Musk, we won't deploy those features because it's against the Software Engineering Code to do beta-testing on live vehicles where it harms users and endangers members of the public. You can fire us, but you'll get the same answer from the next engineer you call into this office."

But one might also ask: is it actually bad to do beta testing on live vehicles?

Self-driving cars might globally save many millions of lives.

Consideration of statistical lives leads to counterintuitive consequences.


Absolutely, and real professions with real professional ethical standards have considered such questions[0] and taken informed positions on them. Nothing of the kind exists for programmers.

[0] https://journalofethics.ama-assn.org/article/ama-code-medica...



They are desperately rushing to IPO before the bubble bursts.

AI just solved a millennium prize problem. In a matter of days. Because of a rumor that someone else solved the same problem with AI.

What exactly would AI have to do in order to not be called a bubble?


How these things are even connected?

The current prices the largest players set for their models are not profitable, they bleed money. Eventually they will "fix" it. It could end up making their services less affordable and it could cascade other businesses and services that are dependent on them go out of business


> The current prices the largest players set for their models are not profitable, they bleed money.

How are the open-weight Chinese models staying ~6-12 months behind on widely distributed / commodified hardware, and serving for even lower prices?


By distilling the US SOTA models, which is cheaper than creating from scratch.

If non AI companies, in particular non tech companies start making unprecedented amounts of profit, inflation adjusted I will concede.

That being said I think LLMs are impressive, still.


You don’t understand what a bubble is. How good the technology is is irrelevant. That has nothing to do with an economical bubble. It’s all about massive capital misallocation driven by a frenzy of FOMO, which is specifically the case for AI investments. Economically speaking what is happening is the most obvious bubble possible, it follows everything that would be expected from a bubble where companies are chasing an ill-defined grandiose dream, based on a new technology we don’t understand and has very dubious ROI, selling some vague future utopia, allocating massive amount of capital to build infrastructure dedicated to a very early versions of that technology.

As things mature there will be a correction, ie the bubble will pop.

I would recommend to read « Boom and Bust: a global history of financial bubbles » https://pure.qub.ac.uk/en/publications/boom-and-bust-a-globa...


As long as the data centers are utilized and generating revenue, I see no reason for a correction or any misallocation of capital for the infrastructure buildout.

And today these data centers are fully utilized. OpenAI tweeted today that they may need to disable new signups for the Pro subscription in the near future due to capacity constraints.

A year from now, who knows what the situation is going to be like. It seems quite possible that robotics, self driving, research, etc. drive even more demand and revenue.

Stating with any certainty that allocating capital to build infrastructure is a mistake and that there is a correction coming seems unserious.


> A year from now, who knows what the situation is going to be like.

That cuts both ways, we are building datacenters for an immature technology that is quickly evolving. We have no idea what AI will look like in the next 5-10y. Everything that is planned to be built is based on the demand we see right now, not what it will be in the future. That means different GPUs that require different cooling systems, different power supplies, etc. NVIDIA already broke backward compatibility with their new cards, which requires a different infrastructure.

What is unserious is the opposite position: believing that we already know what will be valuable in the future and bet the entire economy on it, without any proof of positive ROI.


Directionally we are seeing demand for more compute.

It's a reasonable assumption that data centers that are set up for large power usage and cooling will be valuable.

Claiming the opposite based on, well, nothing at all, in order to forecast a correction, seems less reasonable.


"Compute" is not one generic commodity. Filling your datacentres with ASICs that do nothing but compute SHA256 for Bitcoin mining was a smart move in 2015 but today that hardware is worthless e-waste.

What does the depreciation curve look like for nvidia cards purchased today? How long will it take to recoup the investment on this buildout? Will those datacenters pay for themselves before they're scrapped?


It's an interesting question. Some napkin math:

Let's say we serve a Fable class model on 8x B300.

From Kimi K3 metrics, with 8x concurrent streams, we would achieve 55-60 tok/s per stream, matching Fable 5.1 throughput.

432 tok/s x 3600 => 1.555M output tokens/h x 50$/M API price = $77.76 revenue per hour.

Assuming total API billing at 2.06x output token bill = $160.2 / hour or ~$20 per B300.

A server with 8x B300 could be $461.5k.

At an obviously unrealistic 100% utilization we would look at 4 months of revenue to match the cost of the server.

About how model serving works at scale and actual utilization I know little.

And for all we know Anthropic could serve their model with 64 streams on the same hardware instead of the 8 we assumed here.


Put succinctly, if a mismatch between the timelines of the bonds in the bond markets and the revenue streams occurs, it's a bubble. This increases the risk to current and future AI investments and buildouts. If the mismatch is strong enough, contagion in other sectors/areas of the world can cause a run to security and pop the bubble.

Just because the bond markets 1/2/3/5-year bonds are bloated does that mean the bubble will pop. It just increases the risk.


You should see all the misallocation that was put towards valve-based computing. Why didn't they just all arrive at the correct answer without investing in discovery first?

Per Anthropic's prospectus: generate $30T (~94% of 2026 US nominal GDP) in revenue.

Its resource allocation problem, same happened with .com bubble, lots investors put tons of money into dark fibers. Were they useless? No its very useful.

If you want check a example company from the .com days check cisco, their stock peaked at 75 then crashed hard and only managed hit that again thanks for the AI bubble.


You really believe there will be less demand for AI in the future?

No, I think AI models will be cheap commodities available from hundreds of providers for a few dollars, like a Linux VM is today.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: