Hacker Timesnew | past | comments | ask | show | jobs | submit | magnetowasright's commentslogin

The fact that it's obviously AI sucks, but the fact that it also sucks on its own merits is extra frustrating to me. Choosing the jam-packed absolute nonsense with no attention to detail to the point of distraction, AI or not, over the other entries is ...bad. If someone had drawn this with pigs numbered 1, 2, and 1, or the crappy banners and typography, or the nonsense gondola lines, it'd still be a bad poster. I hate the AI cow in the runner up poster but it's at least a little more coherent a poster overall. Who the hell was judging this and by what criteria?

I wonder what their 2027 entries are going to look like; I wouldn't be surprised if this disincentivised prospective entrants. Why bother submitting if something as lazy and poorly done (and, of course, obviously AI) as that wins?


Etsy used to have strict limitations on what was allowed to be sold. I'm not sure how effective it was, but since that restriction has been removed, you're right, they'll list anything. Etsy has become a graveyard for dropshipped garbage, and the odd CD key, apparently! CD keys I can get behind.


Not all screens are touchscreens. Manufacturers complied with those regs without touchscreens for years. My 2012 mitsubishi's reverse camera is displayed in the rear view mirror; the head unit is a dead simple dot matrix display which I adore.

It's the regulations (or lack thereof) that allow touchscreens in cars as they are that should be the target of ire. Reverse camera regulations or not, the current state of touchscreen car rubbish was inevitable without the existence and enforcement of regulations addressing it.


Instructions on how to create and use a bookmark can help as far as the domain/getting to log in goes. I know nobody RTFMs but if they've got instructions they can follow for that, they'll only need to read it once (hopefully). Hopefully, that will reduce the level of frustration before they try to log in.

Is your product a simple TODO list? Is it a health diary with loads of sensitive information? Is it for storing nuclear codes? Is this something users typically use on shared computers? On their phones? When you consider whether or not some of the other commenters' suggestions for reducing complexity of authc and potentially account recovery are reasonable, you need to keep that context in mind. It's hard to make decent suggestions without that context, imo.

Check WCAG's recommendations around accessibility. Start with cognitive and vision, and make sure to check out sections around designing and interacting with forms, but make sure to have a browse around broadly.

The UK government's style guides have some thoughtful advice around usability and accessibility. [0][1]

[0]: https://www.gov.uk/guidance/style-guide [1]: https://design-system.service.gov.uk/


The wilful ignorance and total apathy is appalling.

I've had similar experiences in Australia. I emailed one of my docs' practices asking if they use Heidi AI (or anything similar) and that I do not consent. They were using it without my consent.

In the consultation, he tried to give me the schpiel, including the 'it stays local' thing. The Heidi AI website has the scripts for clinicians; he ran through them all.

Oh, their documents for clinicians also mention every two sentences that patient/client consent is not required at all. I wonder why they keep saying that? Hmm.

This doctor knows I am a developer. When I asked him to explain what he meant by 'local data', he said the servers were in Australia. I almost flipped the desk. Aside from the fact that it is mandatory (it's the law! they do not have a choice!), it's ...kind of meaningless where the servers are, especially when he (on behalf of Heidi AI) was trying to sell it as a security or privacy feature. When I pointed that out, he just couldn't wrap his head around it. Of course he can't, he doesn't understand.

AHPRA's "Meeting your professional obligations when using Artificial Intelligence in healthcare" guideline[0] (not any kind of enforceable requirement, unfortunately) has great stuff in it. It encourages using it with the informed consent of patients. Even if my doctor read it and agreed with it, and cared about getting consent, how the hell can he inform patients sufficiently when he has absolutely no idea about, well, anything?

He keeps pushing it and asking me about whether I've changed my mind about allowing him to use it. No! He keeps asking me questions that only confirm he hasn't even done a perfunctory web search about why some people hate LLMs, especially in the context of PII and PHI.

I really do feel for clinicians, but these products are not the answer.

[0] https://www.ahpra.gov.au/Resources/Artificial-Intelligence-i...


A strike being inconvenient? Workers leveraging how crucial they are? The stoppage of work having massive impacts across the country? Huh, maybe the powers that be should listen to the workers when they ask nicely for better conditions instead.


I still find myself stuck on step 0: find the fucking log in button that is for some reason tiny/looks disabled/not easily discernible as a button


I just hook up a (linux) laptop to my TV, personally. I have a mouse (and a bluetooth keyboard which I rarely use) to interface.

I have no idea if that would in some way impact something like streaming quality because I don't have any streaming services; I live in australia where the streaming companies simply don't bother organising streaming rights for worthwhile media. I also like to own things I want to rewatch.

If I wanted to get fancy (and if I had a TV capable of connecting to the internet, which I don't) I might consider setting it up as a media server or look at NAS solutions, but my laptop is perfect for me as is.


I am at a loss for words. This wasn't a sophisticated attack.

I'd love to know who filevine uses for penetration testing (which they do, according to their website) because holy shit, how do you miss this? I mean, they list their bug bounty program under a pentesting heading, so I guess it's just nice internet people.

It's inexcusable.


This was my impression after reading the article too. I have no doubt that the team at Filevine attempted to secure their systems and have probably thwarted other attackers, but got their foot stuck in what is an unsophisticated attack. It only takes one chain vulnerability to bring down the site.

Security reminds me of the Anna Karenina principle: All happy families are alike; each unhappy family is unhappy in its own way.


> I am at a loss for words. This wasn't a sophisticated attack.

To be fair, data security breaches seldom are.


Their paying customers aren't end users, they're companies paying for in-OS advertising and telemetry/spyware data


Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: