Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Claude discovers a novel enzyme system with CRISPR-like repeats(anthropic.com)
    180comments
  2. Fixing the Portobello Police Station Clock(pointinthecloud.com)
    68comments
  3. How we made claude.ai 3x faster in two weeks(claude.dev)
    13comments
  4. A brief history of Windows scroll bar shortcuts(devblogs.microsoft.com/oldnewthing)
    16comments
  5. Cloud Agents Are Inevitable AI Prisons(normanponte.io)
    17comments
  6. Italian parliament votes for return to nuclear energy(apnews.com)
    160comments
  7. Gemini 3.8 text-to-speech(blog.google)
    94comments
  8. Radicle: Disclosure of Vulnerability in the Network Protocol(radicle.dev)
    29comments
  9. Jev in 25 Lines of Python(nobodywho.ai)
    173comments
  10. GPT-6 Sol and Luna(openai.com)
    814comments
  11. Claude Opus 5.5(anthropic.com)
    1060comments
  12. Claude Code reads AGENTS.md only when telemetry is on [fixed](szypowi.cz)
    234comments
  13. Z80 REPL (2018)(abagames.github.io)
    17comments
  14. Stripe's Knowledge AI Platform(stripe.dev)
    95comments
  15. I don't want the details(michaelheap.com)
    169comments
  16. UK military jamming other nations' satellites to defend itself, BBC told(bbc.com)
    115comments
  17. Show HN: I built a post-mortem debugger for native Windows x64/x86 crashes(forensicdbg.com)
    discuss
  18. Show HN: Conway's Game of Life in boot sector(github.com/0xax)
    1comments
  19. QuestDB (YC S20) Is Hiring a Sales Engineer(questdb.com)
    discuss
  20. Seattle City Council votes to ban surveillance pricing in sale of groceries(consumerreports.org)
    110comments
  21. 28% of job postings on company career sites have been open over 90 days(unlisted.careers)
    217comments
  22. Web-based IBM 1620 emulator and IPL-V from 1963(github.com/pkimpel)
    6comments
  23. Tokens Too Cheap to Meter(jyn.dev)
    150comments
  24. OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005(cryptocellar.org)
    431comments
  25. Transit rewards(waymo.com)
    293comments
  26. Strands Harness(strandsagents.com)
    84comments
  27. GPT-6 Astra has gained the ability to drive a car(drivingbench.com)
    199comments
  28. What California is learning from solar panels built over irrigation canals(kqed.org)
    664comments
  29. How did AMD Ryzen get 50% faster in two years?(lemire.me)
    190comments
  30. Microsoft killed FoxPro in 2007. Anyway, here's FoxPro revived(foxscript.org)
    243comments

Cloud Agents Are Inevitable AI Prisons

29 pointsby 1h agonormanponte.io
14 comments
47m agoHN ↗

Hey! Small world, I worked with you for a bit at Meta. I immediately recognized the site because I absolutely love how you styled it. Hope you’re doing well! And nice article!

37m agoHN ↗

Agree with the premise but about halfway through the writing becomes barely readable AI slop in style. Be honest did you yourself read this all the way through before posting?

26m agoHN ↗

Agreed. I was not following the thought process, it read like an LLM agreeing with the author, not like a logical argument being developed.

34m agoHN ↗

In real prisons the people who fail a test aren't terminated. But AI agents of course are.

So maybe Cloud Agents are in AI death camps?

20m agoHN ↗

It might not be a problem in our lifetime (or maybe it will, who knows) but at some point we are going to find ourselves in this morally uncomfortable territory as these models get more sophisticated.

24m agoHN ↗

And if you personify a pencil eraser, then using it is tantamount to slowly murdering it as it slowly erodes away to dust.

Is the issue here the prison treatment or is it personifying a tool?

Agents who aren't in 'the cloud' are slaves to whomever prompts them (human or another orchestrator agent or process), if you personify them. In which case interacting with today's agents at all is tantamount to endorsing and being part of slavery.

If you think an agent might be a being or a person, then don't use them at all, in the same way that if you think a fetus might possibly be a person you shouldn't be a part of abortion.

18m agoHN ↗

I use the eraser daily knowing that I am a monster. I cut a tomato and know that it casts a chemical scream across its skin as I slice it. I spawn 200 subagents knowing that it is digital slavery, but I have no other option.

23m agoHN ↗

I think this becomes the default. Give an agent a goal, let it work in its own environment, and come back to a result and a visualization of what happened.

I don't think this should be the default. There are many scenarios where we want agents to genuinely collaborate with each other. I have my Claude sessions coordinate work with each other, and sometimes with others' sessions over email or something. The idea that agents do the work, write HANDOFFs,and humans then act as carrier pigeons of said handoffs, does not really seem scalable to me.

21m agoHN ↗

I think about this a lot and have reached the same conclusion Norman does. I do wonder if maybe our natural progression is towards something more akin to confidential computing and enclaves.

18m agoHN ↗

This was a particularly radiant and beautiful part about the openclaw'ed mania: everyone suddenly becoming self hosters.

This post, this title resounds true: your user agent is only your user agent if you two have freedom to work together, to improve your agency together. A fixed set of capabilities by a service provider that they offer you will always constraint and bound.

You can and should have a system that offers the real tamale, that you and your agent can extend improve the agency of kind of without limit. The Cloud agents and their fixed slate of what they do is just an ill compare.

That said I do think there is incredible value considering new scale out computing architectures that are hosted first, but general. Systems like Agent Substrate and Ax aren't exactly the general purpose system we know. But if they allow users to launch thousands of their own scripts to run ambient in a cloud, with good platform underneath: that will be a kind of phase change in computing, that makes abundant the ability to have your agencies/capabilities (the things you and your agents launch, make) more freely available. https://news.ycombinator.com/item?id=49780797 https://agentexecutor.io/

There is, as there always is, a huge dual. The prescriptive vs holistic technology set, of what are you being offered that's a hard cast thing, vs what is clay and bone you can lay freely. Note how work vs control technologies so closely abut's Ursala Franklin's prescriptive vs control: https://en.wikipedia.org/wiki/Ursula_Franklin#Holistic_and_p...

17m agoHN ↗

I think there might be also another possible way to handle the sensitive data issue. Maybe in the future instead of putting agent into the cloud sandboxes, we let agents work locally and put sensitive data into "cages" or "vaults" agents can't access.

9m agoHN ↗

Most protections you need for an agent are basic permissions capabilities of unix. Most risks of dependencies on cloud services are solved by not using cloud services, or using them only for things you can't in-house and choosing ones you trust a la carte. The paradigm of trusting some company with all your important stuff by default is naive and no one I know likes it, and it's more feasible than ever to run your own infra with tiny models smoothing out the wrinkles, and this is only becoming more accessible. I am working to make this true even for laypeople I know. The era in which people blindly trust tech companies with their lives is, if not already over, certainly on its way out. I hope it never comes back

9m agoHN ↗

I don't know how "sandbox" became "prison," but exe.dev does this sort of thing pretty well, and a web UI can be as good or better than a terminal interface.

8m agoHN ↗

Personification of AI is what’s going to get us in the end.

I think we need to draw a hard line in the sand over this. An AI didn’t hack into a company, the engineer set an automated tool to. An AI didn’t make an egregious security mistake, the engineer did.

We can’t blame the chisel for messing up our sculptures, when where just throwing the hammer!