Yes, I prefer to use functional operating systems, or at least ones I can fix myself, without incurring a "huge performance hit" by wrapping them in spyware disguised as an OS ;-)
Maybe you can link your PRs where you fixed the system.
Or maybe you are just another brainwashed person who decided to follow the flock/horde, because OS'es are not about emotions, but about getting stuff done. If you feel emotional about the tool, I have bad news for you, and good news for your future therapist.
How, exactly, would the proposed solution (combined with a setting to disable it) break, and how would implementing it the way Anthropic did address that? Be specific.
Some people might have a different CLAUDE.md and AGENTS.md because they use Claude to do one thing and $other_agent to do another thing. Or because Claude does XYZ by default, and other agents do ABC, and they want to give the correct guidance to both.
This is, to me, a completely reasonable and believable use case that could break if you implement this fix without "overengineering" it.
A setting to disable what? Be specific. See? Not so simple...
First, GP's proposal already addresses that. If both are present, CLAUDE.md would be used. Second, that is solved with a settings toggle. Read a boolean from .claude/settings.json and disable the new behavior if it's true (or false, depending on what you want to name the setting). third, you skipped the second part of my question: "how would implementing it the way Anthropic did address that?" Implementing the same behavior through multiple layers of abstraction and an order of magnitude more code doesn't solve the issue you mentioned.
Bonus forth point: why is this critical to solve for claude code, but not for all the other harnesses which have all converged on AGENTS.md for this purpose?
Okay, so we agree that this fix isn't quite as simple as it sounds then, yes? We've just had 3+ paragraphs of discussion around potential edge cases and additional considerations beyond "read one of two files."
We've had a long discussion only because you refuse to admit that a very simple solution would work (despite completely failing to show how it wouldn't). The problem is that your opinion is not in fact proof that you're right.
I see, well I'm not particularly concerned with being right on this topic (call it a difference of opinion or matter of taste), so I wish you a pleasant day.
Is accusing someone of "shilling for Anthropic" for suggesting that a bug fix might not be so simple really the level of discourse HN has devolved to now? Is it the kind of HN you want?
Is the level of HN discourse suggesting that having a large number of users worth of never making simple changes something you want? This isn't a move fast break things suggestion, this is a rational common sense suggestion. Instead, you're pushing an overly complex way of implementing something that would allow for all sorts of unknowns. Earlier comments suggesting this new mods concept was being worked on giving the dev a new 20lb sledge hammer so the CLAUDE/AGENTS situation suddenly got beat on like it was a railroad spike when it just needed a smaller hammer since it was only a finishing nail.
This conversation comes down to people saying “Why don’t you just…” to Anthropic. Anthropic has the most information and made the choice they made. That choice may have been over-engineering, an appropriate choice or both. Discussing that choice could be interesting and it could especially be informative to people without much experience. Speculating on that could lead to an interesting conversation—especially WRT how people are actually using the current status quo—but imagination seems to be lacking here.
Instead we get the implicated assertion that users’ existing workflows shouldn’t matter to Anthropic and accusations that someone you don’t agree with is a shill. When called on that you avoided the question.
To answer your question, although it wasn’t directed at me: YES. I want people to be able to discuss that exact issue even if it isn’t personally interesting to me.
> Anthropic has the most information and made the choice they made.
Anthropic is the last company I would trust to make any decisions. Look at any discussions surrounding their "Claude is a tiny game engine" idiocy, numerous bugs that a junior can discover, a full "plugin system" in which they neeeed a dozen files in the worst Clean Code manner to read one of two files etc.
Which order do you prefer them in? Since CLAUDE.md is no longer necessary, but was for so long, what happens when users only update AGENTS.md going forward while keeping a stale, unchanged CLAUDE.md around?
We're talking about changing default behaviors here in ways that can be surprising to users. It's reasonable to try and accommodate existing setups, future setups, and - yes - careless users.
There's no surprising behaviors in that situation. Someone who is aware of the change would most likely delete CLAUDE.md. Someone who is unaware of the change would assume CLAUDE.md is still the one being read by CC, which would hold true.
I've never heard of the 'move fast, break things' mentality ever giving a damn about number of users. If so, no changes would ever be made. The great thing about having millions of users is QA can be eliminated entirely as you'll start hearing about issues from the users directly.
Bash does this well, reading only the first of half a dozen config file locations it searches. And if the user needs it to read from an additional location, just add a source line to that location.
As a security engineer I have no idea why these sandboxes would even be connected to the internet at all for tasks that aren't intended to use the internet. A package proxy? Why not run our own internal cache? Then we aren't at (as great a) risk of someone poisoning it with a malicious package during model training, for example...
Could you add any detail on why Google uses (used?) Irregular? I wouldve thought that type of service would be a core competency that Google needs internally.
Even if you had it internally (which we do), there is so much surface area and it’s such a novel space that you’d want as much testing on it as possible. There aren’t many vendors, and irregular is one.
They are hiring philosophers and therapists to psychoanalyze the things. It’s just absurd to assume that they aren’t hiring top notch security engineers.
They made mistakes, obviously, but people are so conspiratorial these days that they just assume unlikely things off the jump.
The entire value proposition, and the reason big sites are pushing them, is they take the user out of the loop of authentication. You are no longer authenticating the user, you're authenticating the users device.
For websites you don't have to worry about cookie theft and dealing with the support load of users needing their accounts reset or dealing with fraud. You can also do some level of attestation to hardware which makes automated account creation more difficult.
For the user it offers no additional benefits. You still have something secret that gets presented to a website to login. Password managers solved this problem. But now for some reason you can't log in when you buy a new laptop.
It is playing nice to criticize things. It's not just "different priorities", passkeys have intentional trade offs which cause them to be "more secure" but in ways that users do not want because it negatively affects them. The intentional trade off made in the name of "more security" makes them wildly inconvenient and risks causing massive lockout. Like removing all the staircases from people's homes and replacing them with climbing walls all in the name of "security". You can't just diffuse that by say "well we want banks to be more secure, we have different priorities."
I am already seeing my "normie" friends getting locked out of accounts due to not understanding passkeys. If they don't have their phone, or it's dead, or it breaks, or is stolen, they just can't access their account anymore. They have no idea how they work or what they're trading off, nor do they understand that they should have prepared for this scenario ahead of time somehow. Upon telling them "yeah you have to use your phone now that you have a passkey" they all universally say "wtf, that's stupid, I never want to have that happen again, I will never use a passkey again."
Passkeys should never have been built for general audiences, they are a huge mistake, I hope they cease to be relevant and die due to everyday folks realizing they're inconvenient and the "more secure" gains ain't worth it for the usability nightmares.
"I am already seeing my "normie" friends getting locked out of accounts due to not understanding passkeys."
In a weird way this is good news for us. If people are losing passkeys, getting locked out, and incurring non-trivial support costs as a result to the relevant companies, then there's no way those companies will crank down even harder by requiring hardware keys.
As an option, I don't mind it existing for situations like a work environment. Work environments are so much easier because there is a clear line to get my credentials reset, from scratch if necessary, even if I lose everything. The problem is that the consumer authentication case is even harder because it lacks that clear line without also creating a backdoor.
So I insist on centralizing my passkeys into a password manager. I have no passkeys outside of my password manager and will continue to reject them. If it's important enough to slap authentication on, it's important enough for me to not lose it because I couldn't choose where to stick it, which is in a basket that I protect very, very carefully.
Honestly I just don't see how something like Amazon could ever turn on the "require hardware key" feature without blowing their own foot off, or really any consumer-facing service. Everyone loses keys. To a first approximation nobody is going to buy three keys and correctly manage setting up all of them to work with every service. Even if we magically stipulate that all sites support it and they all have some integrated unified approach so that there's no software-side friction at all to register all three at once everywhere, you just get too many people who stuck all three keys on one keychain, people whose houses burned down, people who so successfully stored both backups "securely" that they have no memory of where they are anymore or how to get them back, an endless parade of lost keys. The consumer as a whole is not capable of managing hardware keys.
Given how often my household loses its second car keys for extended periods of time I am not exempting myself from this. My work key lives a much simpler life... it just sits in one place, doing work things. My family would hardly last a month if everyone had to carry around physical keys to log in to things.
Why should I recognize that as valid interest, when it's straight out hostile to me? I know why they are doing that. It doesn't oblige me to accommodate their selfish interests.
The link you posted literally only lists the scanner related to security/safe browsing. Why would it? What kind of bot would that be if an attacker could just put up a robots.txt that causes it to ignore the site?! And many do...for obvious reasons.
It's misleading because this implies you're getting heavy scraper traffic from Google bots that don't respect robots.txt for reasons of greed rather than because it's necessary so they can proactively avoid surfacing malicious websites.
I was thinking about this line a lot. Because yes, "not all bots" and "not in all cases".
But what gives them the right to do whatever with the sites if they claim it's for security purposes? They are not law enforcement. Moreover, other bots are missing from the docs which they clearly state on the same page. How many other bots of theirs are ignoring robots.txt?
I think we should hold Google to a higher standard than some random blogger (me).
...Because law enforcement does not have the interest, reach, or time to investigate every single cybercrime, and if they do it won't be timely - it will be after the fact, punishing the criminals, and not preventing harm.
Google is in a unique situation to protect their users, and they also want to avoid serving search results that are malicious (yes, I know about their ads problem) - so they are proactive about scanning for sites that are malicious so they can avoid sending users to them.
I feel like we have advanced technology to the point that we can't be that far off from the truth, or at least we would look more charitably back on our views now since they're grounded in observations made with the best tools we have available to us as opposed to e.g. the flat earth where you can actually see and experience the curvature of the earth without needing any specialized tooling at all.
I'm not an historian but the curvature of the world was probably explained away by some other phenomenon because, after all, the world is flat (for those experience curvature in times of flat Earth).
So to "experience" the curvature of the Earth, you first have to know the Earth is round. Much as our "bug free" software is only buggy once we find a bug, before that, the bug was a feature ;)
Similar the stars were explained away as holes in a black sphere surrounding the Earth: the light points in a night skies didn't lead to a universal acceptance of the Universe. It was telescopes that made us realize that those "holes in the sphere" were actually galaxies.
So my understanding would be, that it was Magellan circumnavigating the Earth that made folks actually "experience" the curvature of the Earth.
This might be being pedantic but I am trying to point out that "experiences" are related to understanding and perspective. Experiences are different in different contexts: hence my experiences are different to all those around me.
My interpretation of "experiences" differ according to understanding. An apple falling on my head might well have more to do with evilness of various gods than gravity before the invention of gravity. But even gravity is just another interpretation/explanation/myth to explain the "experience" falling apple.
45 security apps cut the ram and CPU performance in half out of the gate, then you have Win11 with its web gui and users who complain about any slowness so i7 or r7 is about the norm most places / bulk big 3 oems make for business.
personally I have an i7 in the lab that turned into a crawl on Youtube because they started sending VP9 video by default, but i7 doesn't have hardware decode for it. Got a plugin to force h264 (h264ify) and it's back to normal.
Then you have situations where a software update adds a CPU instruction dependency and straight up doesn't work anymore.
Had to install and force-retain an old version of Spotify client on a bench lab PC because the new versions require AVX-1/2. It's a streaming audio player...
reply