Hacker Newsnew | past | comments | ask | show | jobs | submit | bumbledraven's commentslogin

Compared to chess, Magic: The Gathering ability transfers much better to real life. MtG has:

- dealing with imperfect information

- bluffing

- thinking ahead with an enormous number of possible moves (especially when you consider deck construction)

- tracking board state

- mentally implementing "triggers"


Deep Blue vs Garry Kasparov (1997) and AlphaGo vs Lee Sedol (2016) marked the first defeats of a world champion by a machine in a chess or Go match. Coincidentally, both machines played an iconic move on Move 37 of Game 2:

• Deep Blue played Be4, declining a pawn capture to achieve a long-term positional advantage and fueling Kasparov’s suspicions of human intervention.

• AlphaGo played P10, a brilliant 5th-line shoulder hit that live commentators initially dismissed as a blunder or misclick.

https://franky07724-57962.medium.com/amazing-coincidence-in-...


Does Tailscale offer a "security checkup" function? Best practices evolve over time, and it would be nice to know if I'm using the recommended configuration.


I lead the customer engineering org at Tailscale.

We think this is a great idea and we're discussing internally potentially adding that to the console.

In the meantime, if you'd like to get an assessment, please feel free to open a support ticket (https://tailscale.com/contact/support?type=other&subject=sec...) and we'll happily take a look


Just so you know, Tailscale tech has always impressed me, but your responsiveness here has cemented my appreciation of your org and I look forward to bringing yall in as our company hits the growth phase.

May y'all continue to be customer focused.


Random idea: When a recommendation is not being followed for a customer because of some deliberate or idiosyncratic reason, a notes field could:

1. Help them remember why, so that they aren't confused the next time they re-run the checkup. ("Oh yeah, we wanted to do X but we can't until we retire Y because it's not compatible.")

2. If it's clearly labeled as info also shared with Tailscale, product managers could use it to help generate theories about why certain customers don't do X.


Not a Tailscale user, but...

For any software or tooling with a complex config, my ideal would be to have a superset of this feature, to provide "intelligent diffs" between full or local configuration states. Whether active or saved. So I could compare not just my current active config and your current recommended config(s), but also between your prior-version recommended config(s) and current recommended config(s). Or between my current config and a prospective new config I'm working up. Or between my last-year active config and current active config.


I've always found tailscale's json config a bit intimidating. I greatly appreciate the new UI that makes it easier to define rules, alas, both going to relevant docs straight from it and determining 'is this rule just lazy/bad/unsafe' is hard and frustrating most of the time.

That's where I'd like to see this sort of checkup. Yell at me please if i just said anyone can ssh as root from any node!


Not exactly what you're asking, but they have a way to test their ACL policies: https://tailscale.com/docs/reference/syntax/policy-file#test...


Not sure if it's being actively maintained, but it covers a lot of low-hanging fruit: https://github.com/Adversis/tailsnitch/blob/main/docs/CHECKS...

Was previously discussed here too: https://news.ycombinator.com/item?id=46501137



TFA links to https://joshcollinsworth.com/blog/tailwind-is-smart-steering, which is about Tailwind, but makes multiple distinctions and points that could just as well apply to LLMs, e.g.:

> Builders value getting the work done as quickly and efficiently as possible. They are making something—likely something with parts beyond the frontend—and are often eager to see it through to completion. This means Builders may prize that initial execution over other long-term factors.

> Crafters are more likely to value long-term factors like ease of maintainability, legibility, and accessibility, and may not consider the project finished until those have also been accounted for.

> In my view, the more you optimize for building quickly, the more you optimize for homogeneity.


800-word response by https://en.wikipedia.org/wiki/Mark_Lucovsky, who was on the team that built Windows NT: https://nitter.net/marklucovsky/status/2052828852490285390#m.

It begins:

> In David Crawshaw’s recent post “The agent principal-agent problem” there’s a lot of insight beneath the headline “Code review is broken.” Worth reading carefully.

> Toward the end, David reflects on what he calls the old “cowboy” development culture at Microsoft in the 80s/90s. Not much has been written about that era, mostly because there was no social media, no laptops everywhere, no phones recording daily engineering life.

> A few thoughts from someone who lived it.

Conclusion:

> A lot of software quality did not come from pre-commit review gates.

> It came from tight teams, deep ownership, brutal integration pressure, system-wide stress, and developers who fully understood the machinery they were standing on.


This article has one neat Google search trick I hadn't known about: `AROUND(#)`. But I am skeptical of much of the rest of it.

Searching for `“can anyone recommend”` to get unfiltered recommendations is an interesting hack, but I feel it's not too reliable. At reddit, you could ask this, and an unknown percentage of responses could be shills or bots.

I'm also skeptical of how much the suggested `@reddit` differs from just `reddit`. The description says it's for social media handles, but reddit is a platform, not an individual user's handle. I suspect google looks for the user's intent to see results from a particular site or social media platform and uses that signal to influence the ranking, and I doubt '@' has much of an effect on that process.

> The results Google omits tend to be less trafficked and less search-optimized, which frequently means they’re more substantive and written for readers rather than algorithms

Really? I call BS. Every time I've looked at the omitted results they've been very similar to ones I've already seen.

I stopped reading after that.


Details on the strategy employed by the human are at https://goattack.far.ai:

> We discovered simple adversarial strategies that beat superhuman Go AIs, and find that adding defenses helps but does not eliminate the problem. Our cyclic adversary beats the state-of-the-art KataGo AI more than 97% of the time at superhuman settings. This strategy is simple enough to be replicated by an amateur human player and transfers to other superhuman Go AIs.



A design doc with a robust "alternatives considered" section.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: