Hacker Newsnew | past | comments | ask | show | jobs | submit | glitchcrab's commentslogin

I sandbox everything inside https://github.com/strongdm/leash

That way the blast radius is vastly reduced.


This is why I won't run Claude without additional sandboxing. I'm currently using (and quite pleased with) https://github.com/strongdm/leash


Why? The AI is just regurgitating tokens (including the sycophancy). Don't anthropomorphise it.


Because I was only 55% sure my comment was correct and the AI made it sound like it was the revelation of the century


Because of the way regurgitation works. "You're absolutely right" primes the next tokens to treat whatever preceded that as gospel truth, leaving no room for critical approaches.


> But the quality is really no different.

Hard disagree. As someone who is somewhat into the home brewing rabbit hole, I can tell you that the gulf between what I can make at home and what you get in Starbucks is enormous. And I'm no expert in the field by any means.

The rest of your analogy holds up, but not that sentence.


yep, my 3 year old gets a very limited amount of screen time and he only watches educational programs (not whatever cartoons his peers watch). There's is no way I want to make it _easier_ for him to watch TV, especially as he has very little interest in it already.


I am in a similar boat; my media editing machine ruined windows 10 so that I can use Lightroom. But I would dearly love to ditch windows so I'm currently looking to try out running Lightroom under Winapps to see if it is usable. There's no way of passing the GPU through without something like SR-IOV so I'll have to see how it goes.

https://github.com/winapps-org/winapps


I was thinking of doing that, but since that would require me to switch the monitor and whatnot, it would be just like using two PCs. And since I only use my desktop for LR and not much else, jumping through the hoops with emulation doesn't make much sense.


How so? Winapps lets you run windows applications as if they were native to Linux, you interact with them the same way you would anything installed by apt/pacman/dnf etc. Unless I'm very much misunderstanding things (which I don't believe I am)


In the general case, I think you're right. WinApps seems to use RemoteApp functionality on windows to export just the window you're interested in from the virtualized guest vm to the host, which should behave mostly as a "native" app.

But you were talking about sr-iov, which is a whole different matter. Presumably, the goal is to have LR use that GPU for some of its functions. But LR doesn't support multiple GPUs: it does its computation on the same GPU that handles the output. For that, you need to connect the display to the passed-through GPU. Now, aside from intel, I don't think any mainstream GPU actually supports sr-iov, so you need to pass through the entire gpu to the guest VM (the host wouldn't see it anymore at all). This isn't how RemoteApp works, and I doubt WinApps handles this case.

I remember a project (Looking Glass?) that tried to somehow "bring back" the output to the host machine, but it didn't seem too robust at the time. I haven't followed it, so I have no idea if it's any better now, if it's still alive. If it does, this could possibly work if you had two GPUs (which I happen to have, since my CPU has an integrated GPU). But you'd still get the whole Windows desktop of the VM, not an RDP connection.


Your experience (as a single data point) doesn't mean that everyone the age of the interns you work with uses Discord.


I'm responding to his personal datapoint with my own. I agree with you though..


Sure, but then you're putting all your eggs in one basket (hard drive). If you really want to divest yourself of the cloud then you need to set things up in a redundant and fault-tolerant fashion. And at that point the outlay is much more than 'just a hard drive'.


Did you skip the "back a million photos" part? That's at least 3 copies of every file, spread across your group. If you want maximum safety you can add a local backup too, which isn't much more money. You don't need to spend anything on fault tolerance. Your files should already be on multiple servers, but also if it goes down for a few days that isn't a big deal.


That was already covered in my top level comment though. Geographic redundancy not local mirroring.


Yes, you need two hard drives. If you’re really paranoid, use three.


Good lord, Oink was only around for 4 years? I was one of the earlier signups and it felt more like 10 years.


Maybe because what.cd picked up the torch and carried on for another few years? For me there was some sense of continuity between the two.


There was. Oink spawned both wcd and waffles. wcd spawned a few including RED.

Next thursday, RED will have been around longer than WCD...


Crazy


None of the successors captured oink for me (I proudly had their t-shirt), sadly.


You can install gboard on iOS - I haven't used the default keyboard in years


It's abandoned and buggy. I'm surprised google hasn't just removed it from the store. I suspect as soon as it actually requires an update because of a change in the OS it will disappear.

Yes, I loved it, but it crashed in too many apps and I had to switch to the Apple one :(


Unfortunately, it's simply not as good. I miss long-press punctuation so much.


This 1000x over! On Android you have this and you can tune how long a long-press is. It's amazing and should be an advanced feature on iOS.

I wish Apple would get over itself and expose settings for all-the-things, like how you can write default finder settings on macOS using the terminal.


Yes! I miss it very much. When I was on Android, I used to have it set to 100ms. I used to very quickly send well-punctuated text. On iPhones, it seems like the digitizer has 100ms of hysteresis built in.

now i just Lettuce my iPhone sden whatever it wants with no punctuation its not real good

Unfortunately, MacOS doesn't have settings (which I am told it had) for animation scales, like Androids have. The interface is sloooooooooooooooooooooooooooooooow.


Yeah I tried it and it doesn't stand up to it on Android in my experience. I figured I'd rather not give Google any data if the experience isn't going to be the same.


That buggy abandonware that hasn't been updated in 3 years?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: