Hacker Newsnew | past | comments | ask | show | jobs | submit | colek42's commentslogin

In 2016 I was working for an organization that wanted a video streaming web app, but could not tolerate any latency. In the past, we solved this with an NAPI extension in Firefox. They removed this for good security reasons, but it left our users without an option. They would have to move to an electron app. Distributing this app and updating it across 1000s of terminals worldwide was not something we were set up to do. I hacked together something like this and could not believe how well it worked. The initial POC is here: https://github.com/colek42/streamingDemo.

Thank you. This works entirely offline. I work in a univ setting where I cannot easily install software for classes. This can be used as a regular app once installed as a PWA. Even the ffmppeg lib is cached. Once installed it looks like any other app, with dock icon etc.

There are ways to do it. Send me a message, and I can make an intro to the person we use.


We built https://aflock.ai/ (open source) to help with this. Constraining activity tends to work well


DSSE is great for this, if you need more schema use in-toto


We started a "science project" taking concepts from Multi Level Security to constraining AI agents. https://aflock.ai/. The idea is to have different data zones, and if an Agent accesses from a private zone, they should not be able to interact with the public zone.



Thank you! :) (Dapr maintainer here)


That is quite an ignorant statement to make. I spent three years in combat, and am permanently disabled from my service.


I have no doubt of your own experiences and losses, but you should be the author of your own words instead of outsourcing them.


My job is to communicate quickly and clearly, AI helps me do my job faster and more efficiently. But thanks for telling me how I should do my job. You come off as both ignorant and arrogant.


Hey, you can use all the AI you like, I just object to you telling them to use the words "I" and "me" when they speak on your behalf.

They didn't serve.


Where is your line, copy editing, drafting, reorganizing? You are going to have a busy, boring, and angry life if you want to comment on every post that has signs AI touched it.


The voters and congress tell the military how to use technology, not Anthropic. Shifting the decision to Anthropic takes away power from the citizenship.

Edit: The point is, go vote if you don't agree with what the administration is doing. Somebody will sell the DoD whatever they want no matter what Anthropic does.


Say I own a spoon company. The government says "hey, I'd like to buy a million spoons from you!" I say "sure, sounds great." We sign a contract stating that I'll give them 1M spoons and they'll send me $1M.

Then the government comes to me and says "hey, actually, turns out we need 500,000 forks and 300,000 knives and only 200,000 spoons."

I say "no, we are a spoon company. Very passionate about spoons. Producing forks and knives would be an entirely different business, and our contract was for spoons."

The military now threatens to destroy my company unless I give them forks and knives instead of spoons.

You say "the voters and congress tell the military how to use utensils, not SpoonCo. Shifting the decision to SpoonCo takes power away from the citizenship."

The military can sign contracts if they wish! They can decline to sign contracts if they wish!

But private citizens can also choose whether to sign or not sign contracts with the military. Threatening to destroy their business if they don't sign contracts the military likes (or to renegotiate existing contracts in the military's favor) is a huge violation.


What percentage of voters do you think want the Pentagon to institute an AI-powered domestic mass surveillance program?


The poll linked in the article shows even trump voters have <30% approval for the pentagon’s actions here, so if the citizenship tells the military how to do things…


You might want to go look at the laws that were passed in the wake of WWII. The US could trivially nationalize Anthopic if they want to play games with a weapons technology.


This could kill the golden goose. There is a strong argument to be made that Anthropic has a leading model because of the principled people who built it, and I don’t see how they won’t leave, like many did to go to Anthropic from OpenAI and Google.

Forcing those people to make weapons to be used against citizens is nothing like the total war in WW2. Why wouldn’t the pentagon just buy from another LLM supplier?


They would leave to what company? Microsoft? OpenAI? Grok? All those are defense contractors as well.

Now, if you said "the Deepseek" guys, that would be different.


Sounds like the voters and congress should buy from someone else then if this is what they want?


Bingo, DoD does not want Anthropic to set guardrails on the technology it buys. If they don't want to abide they are free to deny service. We all know how that will turn our for them with the current administration. All while the DoD will just move to another provider that WILL abide. The only power really lies in whatever our elected officials want to do. Take the responsibility seriously.


I'm sorry but the Pentagon already had a contract with Anthropic and is now threatening to use the supply chain risk law to essentially kill their entire company because they wanted to re-write the contract. They could easily just not sign the contract and move to a competitor. Its an incredibly disturbing and chilling move by the Pentagon...


The government is bound by its contracts. The government is not Darth Vader: "I am altering the deal; pray I don't alter it any further."


If voters had any say in how software services were delivered, Windows 11 would be such a s--t pile.

There is a name for a system of government whereby a ruling party dictates how industry should employ its property, and it isn't democracy.


We just built a new version of the witness run action that tracks the who/what/when/where and why of the GitHub actions being used. It provides "Trusted Telemetry" in the form of SLSA and in-toto attestations.

https://github.com/testifysec/witness-run-action/tree/featur...


When I saw the tj-actions attack, I decided it was time to finally implement action wrapping with our `witness-run-action`. This will generate signed attestations on exactly what the actions are doing.

We have some more testing to do before we cut an official release, but it is working correctly for the limited cases we have tested it with. I'd love this group's feedback.

https://github.com/testifysec/witness-run-action/tree/v1.0.1...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: