Hacker Newsnew | past | comments | ask | show | jobs | submit | rukshn's commentslogin

Hi All working on an open source tool to manage knowledge base from one person (consultant/freelancer) to a organization. Built for both humans and Agents.

Currently building for myself and managing my own work with it, would vision something alternative for confluence.

Would love to have more collaborators helping to build an open source project - https://github.com/entangle-cloud/wave


For the last couple of years I’ve only read non fiction. For me reading about real life events is far more entertaining and also a great learning experience that I can’t get from a fiction book.

I'm in the same boat as you, having only read non-fiction the past few years. It appears quite ironic that the entertainment occurring in the real life events is surpassing the entertainment I hear one usually derives from fiction.

Opposite here. I almost exclusively read fiction now. I learn enough outside reading and use books exclusively as a form of entertainment.

You can "great learning experience" about the human nature from a good fiction book too. Classics have another function - being cultural landmarks, one can refer to in non-fictional contexts as well.

I read both both my fiction is almost exclusively Japanese and my non-fiction Western/Europe science/history-adjacent

See, because of the learning experience I steer away from non-fiction books. I am deeply afraid of the narrative red string applied to reality - connecting a tiny subset of the observable data points to a simplified interpretation/explanation of the whole. If I want to learn, I look at raw data, reports, white papers, etc.. Because authors always have some bias or other, especially when they decide to write a book-length document. (Except, of course, a data catalog of sorts, like a lexicon or other exhaustive enumeration - those are usually a good starting point) I have enough of my own biases, and rather get a diverse set of inputs on a topic. Fiction though? Sure, let's suspend our disbelief and have some fun.

Edit: to clarify: this is not me accusing authors of non-fiction books to always have some evil agenda to push. One human only has limited capacity and things will always fall through the cracks. Do your own research with the constraints you actually care about, if you can.


Yes, everything outside of personal experience is somewhat fictional - one probably wouldn't agree with the biases, assumptions or assessments of any author/content creator.

I think there is something deeply wrong with the state of contemporary fiction.

I was on Spotify the other day checking out the fantasy audiobook offerings and the only item that wasn't absolutely repulsive was Jim dale reading Harry Potter. Everything else comes off like cheap asset flips on steam or thinly veiled rants that you'd find on obscure subreddits.


Fiction is a variety of oft-useless drivel when the world is chock-full of compelling, urgent non-fiction.

Altho... science fiction is hardly useless, when it mentally prepares the ground.


I feel Europe is a bubble waiting to burst.

Recently I was giving a lecture on digital health regulation and 90% of people were pro regulation in general not just for digital health.

It’s something hard for them to understand that too much regulation is not good and a balance should exist


This I fully agree. I think I was few who never wanted to try Open Claw or wanted to connect my accounts because I saw someone at Meta getting their emails deleted.

Then after I listened to Garry’s talk on Gbrain last week I thought why not give it a try.

So connected my email and calendar to a simple agent I built via MCP and I get a summery of important emails and also delete all non important ones.

Still a WIP: https://github.com/rukshn/zen

But I agree the space is very much crowded


This is something I see and feel everyday. And it’s very frustrating and annoying.

For example I send some doc asking for a feedback and someone without reading it generate a feedback with llm with so much ambiguity that I have to get back and wait couple of more days to get a reply.

One of the most silliest thing I see is a middle manager feeding Microsoft planner to Claude to generate a report and generate future steps and sometimes it makes no sense what he present couple of weeks ago because what he present today is contradicting to the one before.

At this point I feel it’s cheaper to replace them with AI. They are just physical vessels for AI.

It’s just not that maybe they were not good enough. But now they just fully depend on AI.


But how’d you access teams when it’s work teams and don’t have api access ?


Microsoft Graph API


I find the Europe's relationship with tech to be wired, there is one section that is hardcore-opensource fanatics, they want to host everything by themselves, and want to go through the trouble of keeping things updated, and would not want to use a close source tools even though they are developed by European counterparts.

On the other side there are people who are techy but happy to use US products, and when you pitch something European they would cite some tool that's better and bigger in US.

It's hard to find people who are in the middle who would like to pay and use a EU made tool.

Also processes take forever, and everything has to go through lot of meetings, and bureaucracy and red-tape and no one is willing to take a chance on a small startup.


I think the reason for this is that if you're targeting folks for whom Europe-sovereignty resonates as an important factor, those will also care about sovereignty and self-sufficiency in general, and thus just skip your SaaS and go right for (semi) self-hosting.

While for the other side where the sovereignty is not an important factor, it's product quality that matters.

You can absolutely make a European startup that sells B2B SaaS, successfully, it just has to be better than the competition, and being European will not be enough.


Why would i want an inferior option just because it's made in the EU? I'm not an EU nationalist, i don't care if "EU Tech Companies" are a thing. If anything "EU Tech Sovereignty" is a net negative for me.


> If anything "EU Tech Sovereignty" is a net negative for me.

Is it? If you live in the EU, the fact that pretty much all companies completely depend on US tech to work means that the US can not only spy on them (if Airbus uses Microsoft Teams, then the US government can ask Microsoft to give them access to the data and use that to help Boeing win contracts for instance), but also put pressure on those companies by blocking their access to that tech (it has happened).

The "sovereignty" part here is a net positive for anyone living in the EU. Net negative for anyone living in the US of course, because being in a dominant position does favour the US.


The default stance should be that nothing you do is private on the internet. If we're talking spying then no service in any country will be secure unless fully encrypted with audits. Any country with an intelligence agency can force companies in their jurisdiction to give them access to data otherwise.


Not sure what you are trying to say, except that it confirms my point: if a company in say, Germany, uses Microsoft and Google services for all their communications, then the US (!) can just get access to all their data.

Now if that company was using services based in Germany, then only Germany could access that data, which is obviously much less of a sovereignty problem (Germany interfering with Germany's affair is just a normal government).


Sure for a German company in Germany that's perfectly reasonable, but we're not talking about each country in Europe having their own copy of AWS/Stripe/Search.

In reality all the data will be in France/Germany/Netherlands because that is where the infrastructure is. They also happen to be countries with world class intelligence agencies.

We need better services and protocols developed with privacy in mind from the beginning, no matter where it's hosted.


> but we're not talking about each country in Europe having their own copy of AWS/Stripe/Search.

We're not talking about having hyperscalers in each country, but I could totally imagine each country having infrastructure.

> In reality all the data will be in France/Germany/Netherlands

Having the choice between 3 European countries is already a lot better than giving all the data to the US. The US has been a lot more hostile to European countries than "the intersection of hostility from France/Germany/Netherlands".

> We need better services and protocols developed with privacy in mind from the beginning, no matter where it's hosted.

Sure, I agree with that. But one doesn't prevent the other. Typically it's not practical to run LLMs in a privacy-preserving manner, so it's a lot better (in terms of sovereignty) to run a server in a place you trust than in a hostile country.


> Having the choice between 3 European countries is already a lot better than giving all the data to the US. The US has been a lot more hostile to European countries than "the intersection of hostility from France/Germany/Netherlands".

History shows conflict seems to be inevitable. You can't assume all European nations will be friendly forever. I'm American, but my hope is that this knee-jerk reaction to just move everything possible to EU has more thought behind it. Improving upon what we currently have especially with respect to privacy so that everyone in the world may benefit rather than just clone American tech and calling it a day.


Not sure you understood my point.

- IF you can choose to rely on one of [France, Germany, Netherland], then you would need to be in conflict with all three to be screwed.

- IF you can choose to rely on a service in your country, it's better for sovereignty.

Overall, it's all better for competition. The best would be competing services sharing an open core (or even everything).

> this knee-jerk reaction to just move everything possible to EU

The thought is that if you are in the EU, in terms of sovereignty you are better off giving your data to EU services. US companies give their data to US services, so of course it is much less of an issue there. And Americans are not the last to complain when US companies give their data to non-US companies...


Well, where do you live?

I live in an EU country and care deeply for the right to erasure and our consumer rights. The EU legislature does some good things on that front. I "care" for EU tech companies as much as I can care for any company currently. I think technological sovereignty is and will be important moving forward, for our economic resilience, infrastructure stability, among other things.

BTW "EU nationalist" just sounds like an oxymoron to me.


Which is why we’re putting our entire digital identification infrastructure in the hands of Google and Apple. EU technological sovereignty is a kafkaesque affair, and that’s putting it mildly.


I concur, except about the "putting it mildly" part. The digital ID stuff feels kafkaesque, sure, but not more. It's good lobbying at play, and I'm sure we'll find a way moving forward.


Assuming that most Europeans would be loyal to the EU is like assuming that most US Americans are loyal to Donald Trump (or Biden). But in reality a big enough proportion of Europeans see the EU as a hostile foreign influencing force.

Or, to put it another way, do you think any Americans use Microsoft or Apple products out of patriotism or fear of being dependent on technology from other nations?


> But in reality a big enough proportion of Europeans see the EU as a hostile foreign influencing force.

Yeah, I have to doubt your perceived reality here. Can you name some of these "hostile foreign influences"?

The big competitor to Apple is Google, whereas the big competitor to Microsoft is Linux/FOSS IMHO. I'm sorry to be blunt, but in the current political climate I couldn't care less what any Americans are using and for whatever reason. EU citizens on the other hand sure got a few reasons during the last decade due to foreign American politics.


> Can you name some of these "hostile foreign influences"?

The name is the European Union. It is the foreign entity to Europeans. If you doubt that there is a big portion of Europeans who aren't pro-EU, then I guess you doubt that there are Americans who aren't pro-Trump?

Anyway, there were referendums in many countries on the subject of joining the EU, and you can look at those and see that not 100% of the population voted yes.

So it is a false assumption that Europeans would by default have any loyalty or goodwill towards the EU, although I'm sure that a big portion of them do. Especially in some countries.


> not 100% of the population voted yes.

Well, call me surprised! Which democratic election ever achieves a one-sided 100%?

Still, the majority of the EU population seems to in favor of the EU, whereas the majority of the US citizens are pro-Trump, or they were during the last election at least. So I don't really understand what you're arguing for here.


If the location of something is a part of what you use to decide what to use, then if it's in the EU which is your preferred location, it no longer is "an inferior option", it might end up your only option.

But clearly you don't care, so understandably that choice doesn't make sense for you, that's all fine and good. But still you have to understand other people/organizations than you might have different requirements? Or is that a very foreign concept?


You switch from talking about Europe to talking about the EU half way through. The article was about Europe (excluding Russia and a few others).

> there is one section that is hardcore-opensource fanatics, they want to host everything by themselves, and want to go through the trouble of keeping things updated

Using Cloudflare, AWS etc. does not mean you do not have to keep things updated. Using an SaaS does. The numbers in the article count both.

There are plenty of people who use FOSS only and non-US hosting, and still use Cloudflare.

> On the other side there are people who are techy but happy to use US products, and when you pitch something European they would cite some tool that's better and bigger in US.

A preference for what they already know (maybe reinforced by marketing). Its not that they prefer American products, but American dominance means it is what everyone already knows.


Computer software is so incredibly cheap in a business setting (that includes public sector) compared to all other tools and expenses, that it always makes sense to pay for and use the most feature complete software you can get.


There are not many big vendors that are EU first apart from SAP, SuSE and a handful more. Nothing similar to what MS, IBM, Google, Intel, AMD , Nvidia or Meta provide.


> Nothing similar to what MS, IBM, Google, Intel, AMD , Nvidia or Meta provide.

That's a bit of a feature, I don't think the EU should want TooBigTech monopolies. Doesn't mean that there cannot be successful services in Europe.


> I find the Europe's relationship with tech to be wired

I don't think it's weird: almost nobody cares, they just use whatever they know/is free. It turns out it is US tech. It's the exact same situation in the US, except that for them it is not a sovereignty issue.

Now maybe there is a bigger open source community in Europe, but I don't see a problem with that.


Well it's because few people have "European-ness" as a strong personal value. Some people have strong values around open-source, or even around the specific country, but the sense of being European and valuing European things is just not very widespread, so in absence of a specific personal value, they pick the cheapest/biggest/most-known option which is usually American.

This is quickly changing though: my subjective take is that the US antagonism is pushing people away from American product AND making the European identity stronger.


> It's hard to find people who are in the middle who would like to pay and use a EU made tool.

I think that’s because people who aren’t part of the open source FOSS camp don’t care where the services they use are based. And the people who don’t care tend to choose whatever is the easiest and most popular option. Hold on, did I just restate your whole point? Maybe I did.


Its. You know. Look around. What our elites and noble families concot. Wirecard. etc.


I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police.

The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue.

Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful day.


If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. You can do this wholly anonymously, so you don't have to worry about some trigger-happy corpo ruining your life.

Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to the common good.


I should have known this exists, yet I didn't. Thanks for pointing it out.

This seems to be a direct link to a web form to report (in English): https://eservices.traficom.fi/ContactForms/form/haavoittuvuu...

In particular, note that all the fields asking for personal information disappear if you select "Yes" in "I am submitting an anonymous tip" field.


Just to play devil's advocate, couldn't sending zero-day exploits to a foreign nation's intelligence service potentially cause the sender significantly more trouble.


Finland is a NATO country, so for most people on this site you would be sending it to a government agency of an allied nation. Punishing that would make it look like you don't trust your allies

The other angle is that you are obviously doing it in good faith, on the assumption that they will try to work with the vendor to fix and responsibly disclose the vulnerability


It depends on the country apparently:

"Israel reached out to US hackers for ‘Zero Days’ tools" - https://www.timesofisrael.com/israel-reached-out-to-us-hacke...


Because... your home country or affected company could consider it espionage? Sounds like a stretch.


Just to play devil's advocate

Why?


Because information asymmetry benefits those with the information. If the devil understands your argument, and you don't understand the devil's argument, the devil will have information advantage.


Not everything in life deserves to have both sides aired.

For example, the Internet giving every crackpot wingnut on Earth an equal voice with scientists is how we end up with measles outbreaks.


it's a good question


> If you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party.

The CCC (Chaos Computer Club) in germany will probably do the same.


I knew I had heard of CCC from somewhere buts its https://ccc.de which includes the https://media.ccc.de

There are some really decent technical videos on it, CCC is really awesome!

Really loved this talk in particular from CCC: https://media.ccc.de/v/33c3-8314-bootstraping_a_slightly_mor...


Were you somehow able to intuit that parent is Finnish?

I'm intrigued by your post -- I used to tell people send things like this to CERT/CC... but it's been so long since I dabbled in that world that my contacts have departed and the current administration is so erratic that paired with Finland's recent rejection of neutrality and ascension into NATO that I would frankly agree that your CERT may be a better fit for the majority of people.


> the current administration is so erratic that paired with Finland's recent rejection of neutrality and ascension into NATO

Not sure if this is what you mean, the comment is rather confusing to me (Finland was ever neutral? Between which states, surely not EU and Russia as they sit between? Which administration relates to Finland and is unreliable? Why would you need personal contacts to report vulnerabilities to a CERT? Etc), but they weren't rejected for NATO membership: https://en.wikipedia.org/wiki/Finland%E2%80%93NATO_relations opens with

> Finland has been a member of the North Atlantic Treaty Organization (NATO) since 4 April 2023.


That now that they've joined NATO, it's safe to share with them.

A "neutral" country might abuse them.


You now have the worst of both worlds.

You report yourself to the police for trying to hack into a computer-system and you report yourself to the website that can now decide to sue you.

All of that without any benefits.


If it's anything like the Dutch or German infosec agencies, "worst of both worlds" is about as far from the truth as you can get. Maybe it works that way in Saudi Arabia but it's not "reporting yourself" here


I wouldn't trust anything like that in Germany, where everything is rules-based. Hacking is illegal, so if the police find out you hacked and can prove it, they will arrest you and you will be convicted, period. In Germany there's no common sense applied to the rules. Arguing that you hacked and then reported it responsibly won't reduce your criminal penalty for hacking.


> I wouldn't trust anything like that in Germany [...] Hacking is illegal, so if the police find out you hacked and can prove it, they will arrest you and you will be convicted, period.

This is rather hilarious to read as a reply to someone whose day job is literally hacking in Germany. We document it for tax reasons and sometimes are even allowed to publish it, too! Besides paying clients, we also "hack" (read: help secure) projects and blog about the vulnerabilities we've found and what the disclosure timeline was

Clearly this doesn't work as a blanket statement and coordinated vulnerability disclosure is a thing here. I can agree there are caveats but the statements as made aren't accurate

As for dealing with the government, so far as I'm aware, none of us have had bad experiences with the German IT security agency (BSI) whenever a vendor was being uncooperative (healthcare vendors tend to be very, let's say, German about whose responsibility it is when their device sends genital pictures over a network with no encryption or authentication option available in the software)


Apart from a certain general incompetence in IT related topics, common sense is a rather important part of German legal interpretation. Intention, proportionality and such.

There are some infamous counter-examples, but you can find these in any country and it's these that make the news.


Sir, this is not USA, don't assume stuff fucked up there is fucked up everywhere


It's starting to be so common on the internet, clueless US residents not really grokking things aren't as bad in other places as in the US, that I'm starting to think that maybe this is some sort of psychological defense mechanism? You've heard how great and exceptional your country is since you were born, and suddenly evidence is being pointed to that maybe that wasn't so true, so your brain is trying to reason away how clearly this can't be true, you cannot been lied to your entire life...


That sounds a lot like the assumption that crime rates are better in less populous areas - just because there is less reporting doesn't mean that it isn't there.

Have you been to the US? If not how can you be certain that the US is truly worse?


> You've heard how great and exceptional your country is since you were born, and suddenly evidence is being pointed to that maybe that wasn't so true, so your brain is trying to reason away how clearly this can't be true, you cannot been lied to your entire life...

You are describing cognitive dissonance, I suspect most people do have it about their country (unless they really like history in which case they are aware of the fucked up things their country has done and there is much less dissonance) but the average US citizen is very much an outlier by the standard of western countries.

Even the smart ones who do know history often only know their side of it from their point of view and many of them have very little understanding of the world beyond their borders (because they simply have no need to).

They just seem to blur the border between nationalism and patriotism more than most countries.


Is this purely theoretical? Asking since we don’t wanna encourage making the world worse if there is indeed a clever way to stay safe - has anyone been hassled after reporting to the Finnish Cyber Security Centre?


Well I'm a Finn and have reported my findings to the FCSC. Zero hassle. The folks at Traficom are a really nice and smart bunch, I have had chats with them face to face a couple of times. They are very well versed when it comes to potential issues or hassles with disclosing exploits. From what I've seen, everyone at Traficom really just wants to keep internet and information systems safe, and to provide the best support possible for IT professionals regarding cyber/information security.

You can also submit anonymously and/or via secure email: https://www.traficom.fi/en/contact-details/sending-secure-em...

This is what their privacy statement says: “Data breach information, including personal data, can be exchanged confidentially with other authorities relevant to the breach when required or permitted by law. The person who fills out the form is asked if they consent to the transfer of information to another authority."


Reporting software vulnerabilites in Germany is the dumbest thing you can do, you WILL be arrested. There is a recent case where some company had a hardcoded database password in their EXE file and if you open it with e.g. Notepad you can see it and this already counts as "illegal hacking". https://www.heise.de/en/news/Federal-Constitutional-Court-re...


I once tried to report an incident to a train line who had done "~a nice thing for a person~" and had photos about it on their social media. One photo was in their office and in front of a wall with a A4 page of usernames and logins for various systems on it.

I tried three different contacts I could find, only one came back to me and wanted to know what the systems did what the risk was etc. I pointed out I have no idea, and I'm absolutely not logging into mysterious systems to find out - pass it to your own IT so they can see what needs to be changed, rotated etc.

I did eventually get a message back from someone who thanked me for my diligence and said it was solved as they had now removed the photo... I really hope they had someone who understood look at it, but I decided not to engage further...


Some may criticize regulations, but the EU-mandated cyber-resilience act (CRA) actually forced companies to have a clear contact point for vulnerabilities reporting, and to act upon it.


2026-09-11, save the date folks. That's when all companies selling products with digital elements in the EU have to have a reporting pipeline for actively exploited vulnerabilities and severe incidents.


Easy to remember


Silver anniversary for it


Do not bother.

I was wearing a white hat professionally for quite a while but I can't fault you - at this point trying to be honest and helpful is dangerous. If you decide to sell the vulnerabilities, so be it.


That's really sad to hear, you must have felt really bad. Just because they do not know about the vulnerability, it won't disappear. And they won't fix it too. Ignorance is a bliss, but not in this case...


It should be obvious who the real criminals are in this case.


You could try reporting them (the exploits) anonymously to a government agency


The German "Chaos Computer Club" (hacker club) has a disclosure service. They approach the affected party as the club, hiding the persons identity. Not sure if they do it internationally as the page is in German. But nice idea and not a government agency.

https://www.ccc.de/disclosure


They did notify Collins Aerospace in the past, so I assume they do report internationally.


So they can exploit it in secret for their own benefit?


If you have so little trust in your government (maybe you're American?) it might be time for change!


Considering Snowden files have shown they intentionally hoard 0days, I don't think it's so much a lack of trust as it is a proven track record of their behavior.


No shit. Mind telling us how? Because elections sure aren’t going to do it.

edit: sorry, there is so much of this sentiment, and the system is proven to be rigged. We know that things have gotten bad. Really bad. And there’s little hope of it self-correcting. The corruption is too deep and now seems unabashed. I seriously do want advice on how to change things, but three out of the four boxes meant to preserve liberty have proven to be inadequate. I see no future that doesn’t involve violent upheaval. Convince me otherwise.


I agree with the violent upheaval idea.

I believe that all systems which promote and enforce radical patriotism "no matter what" are bound to end up there.

It's also getting more and more difficult for your country to keep allies, what with bombing and assaulting every single possible place for maximum profit extraction. Lots of people in the world have a hatred for the USA (as an entity) that is only paralleled by e.g. Nazi Germany.

The only way to make a change is to get up and make a change, and if you can't because you're that deep in the hole, as you said, violent upheaval.

I really wish that the USA would just wake up one morning and decide to make a change, without violence and bloodshed, to look at other Western countries for inspiration and create a more human society.


sell them to a vuln or exploit broker. problem solved.


I’m now responsible for improving AI literacy in the organization I work.

But the people in charge just want the employees to just answer some questions so they can handover Claude or Chat GPT licenses so they can show people are using AI to improve productivity.

There are people who don’t know when to use AI and when not to use Ai and think they can just Claude their way through everything. I wanted to change that but when the whole idea is to just increase AI use I guess they don’t care about how AI is used.


I was on a quarter demo the other day and the project lead for ai innovation was talking about the things he's preparing for the company.

I will not address the things he pitched (as coming soon), as I'm a developer and (hopefully) not the target audience, but I was quiet surprised when they made a questioneer asking how many people use ai and how frequently. (The target demographic was middle management, product owners etc)

75% of people answering said they're using it daily and considered it an essential tool they need to work

Considering it was anonymous I was expecting lower numbers, honestly.


> Considering it was anonymous

In the recent past, my department received an email from on high with a list of people who were yet to complete the "anonymous" survey.

I always assume my work-survey answers are traceable back to me, whether it's via self-doxxing with my answers, tracing links of the rootkit-level MDM software that can record my screen, but they pinky-promise to only use for remote assistance, in case I open a ticket with IT.


Talked to someone at a large company who had admin access to survey results (require to do some analytics). The survey was “anonymous” but results were geo-located, and had some information about the team they came from, which in many cases was enough to clearly identify people. There is a difference between “doesn’t have a persons name on it” anonymous and actually anonymized in a way hardened against figuring out who is who. I don’t think anyone really does the latter.


You do know it is possible for the answers to be anonymous but who submitted to be tracked?


Depends on how it's done.

Trusting that process to be done well is probably not the greatest plan.


I have taken some really badly (on purpose?) written questionnaires in the past. Asking about team size, role, etc.

That’s not anonymous at that point. That’s an agenda.


I've seen questions asking for my org, team size, role, and when I joined, and thought it would have saved me time had they asked for my employee number instead.


Most external survey providers claimed anonymity but in their T&Cs stated in a very roundabout way that they could provide some information to customers for quality purposes or something. Read “we’ll deanonymize some users if the paying customer wants it”. Internal survey tools are subject to internal management pressure.

Even when you use a tool like Microsoft Forms, where MS really can’t be bothered to deanonimize users unless 3 letter agencies get involved, it’s still possible to do timestamp matching between the proxy/VPN logs and the submission time.

Asume real anonymity only if the URL is the same for everyone and you can fill the survey from any computer on the internet.

But the explanation for why people overhype AI usage is probably simpler. They want to keep their license because it’s a nice perk. They’ll use it to get the gist of a long email thread without bothering the read the details, to get some meeting minutes without validating if that was actually what was said, to generate some crappy modern equivalent of wordart graphics for their presentations, and feel like the time saved to generate what most time is slop was worth it.

When I worked on this (outside of coding) it was a pain to find a use case that really benefited. These were all niche uses that fit an LLM like a glove. These rest was slop, I could see the usage reports, and the BS self reporting surveys. Everyone inflated the numbers and usage to justify keeping their license.


You do know it’s possible for insecure leaders to lie about things like that, and that there’s no possible way to definitively tell beforehand?


This guy is wrong.


It's perfectly possible. Two tables, one stores answer responses only, the other just marks off who has responded. No link between them and you have anonymous data but can tell who hasn't responded.

Of course if you record created/updated timestamps on both, insert both records in the same order, accidently record the user code in the response data, take backups in between responses, have identifying questions or just don't have that many people responding it's easy/not hard to reverse engineer.

But it's quite possible to do right, I did it quite effectively almost by mistake years ago. Sent a customer survey out with generated codes as identifiers recorded with answers. Before sending reminder emails a script grabbed the codes, marked the customer as responded and wiped the code (so I could just get future responses where code was not null to mark next people off). Although I had timestamps the script meant customers were updated in blocks, there really wasn't any data to link them.

I know because the Boss was not happy he couldn't find out which customer had said what, and I had to point out all the communication (with customers and me) called it an anonymous survey, so why would I have saved them?

So it is possible, just not easy even if you intend it, and it's often not intentional...

I don't trust anonymous surveys either now...


The way I see it:

If the participant has to trust the survey creator, then it is not anonymous. The survey creator can link the data.

If the survey creator has to trust the participant, the survey is anonymous. The participant can lie in the survey, lie about participating, or submit the survey multiple times.

Your example was not anonymous. But you did not break the participant's trust, thank you! (Or maybe you are lying.)

Anonymous example: Sending a clean link to people to take the survey. If not enough answers have been received, a reminder can be sent to all, with a clause, that says: "if you have already done it, you can ignore the reminder."


The pressure to use AI is worse than the pressure kids get to use drugs. It’s insane.

The job market right now sucks so everyone is really just trying to not be the next cut.


Never expect anonymous voting/quizz/whatever to be fully anonymous in big corporations, if its something about touchy topics and/or can affect employment/performance of given person results will be skewed. If metric becomes the target it ceases to be a good metric and all that.

It all rest on the shoulders of responsible manager(s) on how moral they are. Many are not.


If it's 75% exactly, that's consistent with them asking four people


It wasn't, and it was visibly updating while people were submitting their answers. I just rounded it as I don't remember the exact number at the time they closed the submission.

Could still be faked ofc, but I don't think they did.


> 75% of people answering said they're using it daily and considered it an essential tool they need to work

> (The target demographic was middle management, product owners etc)

This leaves a fairly wide set of options for what "essential" entails.

Do 75% of middle management and product owners actually need AI for their job? Seems unlikely.

Do 75% of middle management and product owners use AI to slop up emails, meeting "summaries", and reports? That's quite possible. Would they declare it to be an "essential tool"? One imagines they are not too fond of actually doing meaningful work.

It's quite easy to get high percentages like this when the AI is involved in make-work and the costs are low if not zero. The moment inference costs go up, most of this usage will evaporate.


Most of the answers to your post are reasons this 75% must be fake / lies or whatever.

But maybe the simplest answer is that most people do use the tools daily now and consider them essential...?

As much as HN would hate to think that


The leaders who mandate AI have no understanding on how to actually use it for productivity. They use it like a Magic 8-Ball to confirm whatever ignorance they have and believe the hype that it can do anything.


They have always done this. These are the same managers who ask subordinates for reports that support their predetermined agendas, or higher level execs who hire consultants for the same purpose.


I agree with you, but also it’s not entirely unreasonable to just use AI (or any other tool) and let them figure out over time what are and aren’t good uses. This approach requires an ability to see past the next quarterly earnings report, which is a rare quality for a business, but it can be healthy. The long term result is likely to be a culture that is more AI literate than they would be if they had top down instruction. The optimal path is probably a bit of both, but if I had to pick a ditch it would be “trust my employees”.

The thing I have a real issue with, and which seems more common, is the belief that they can cut raises because AI will make them more productive. In that case, the best employees (read: those most capable of leveraging AI effectively) will leave to find better paying work and the remainder will be too busy with the additional workload to have time to figure out how to use AI to make themselves more efficient.


Just have IT roll out OpenClaw to everyone, connect it up to their emails, chats, password managers, etc and then click "go".

Why not?


Definitely start with the executives, you can't leave them out of such a useful tool. :)


Not that there would be any ill effects from this, executives sit mostly in meetings, they don’t really do anything much besides that; maybe occasionally write a short email. They also don’t have access to critical systems.

It’s much more of an issue with devs


So my electricity bills are rising just so corporate idiots can increase an internal metric.

Fuck all of this.


Almost every bad thing happening in the world is so corporate idiots can increase some internal metric.


Wow i didn't know Google did this as well, that's pretty sad.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: