Hacker Newsnew | past | comments | ask | show | jobs | submit | reconnecting's commentslogin

I like it. But not 100% EU. Status page sends data to Google, Doubleclick, etc (1)

"In Brief: statichost.eu does not collect or share any personal information or data. " (2)

Every page contains a hidden 1px pixel img that collects 15+ parameters: https://queue.simpleanalyticscdn.com/simple.gif?version=cdn_......

1. https://status.statichost.eu

2. https://www.statichost.eu/privacy/


I think you are picking on the product by sharing a (real) critique of the marketing website.

The product says "100% European static website hosting" it does not make any promise about the actual marketing website they have that will be privacy protected.

So yes, you are right they used in their marketing website maybe some trackers and even so based on the link you shared here they seem to use https://www.simpleanalytics.com/ which sounds okish than any other trackers and it might even be also EU hosted: "We're a three-person team based in the Netherlands, building privacy-first analytics for the web"


That's not a good excuse. If the whole selling point is that you're gluten free you can't have grain flour on your fliers.

Their _main_ selling point is that they are hosted in EU and also their analytics seems to be hosted in EU.

I did not read with very much attention their website but I think they are not saying they are gluten free and eating a whole wheat bread. But even so it is possible that a cook that produces gluten free bread to sell can eat a whole wheat bread. I see no problem with that.

I also don't think we need metaphors for this. It is clear for me that their USP is hosting in EU and the fact that on their marketing website uses https://www.simpleanalytics.com/data-collection does not contradict their product which is Hosting websites in EU.

What would contradict is hosting their marketing website on US.

Second point is: Yes, their status page should be hosted in other places and I could even understand if they want to host their status page in US or ASIA. I actually think that would be the right way to host their own status page.


That pixel seems to just gather standard data one might want to optimise the site display. I think display port size or http/s choice is hardly personal data.

Yes such info can be used to track people, but only if you have the database and means to - which a single small provider certainly doesn't. So unless you think this data is being sold for profiling I don't think that their claim is false.


Perhaps I read it wrong, but to me this means "does not collect ... data". In fact, the site uses a third-party service, which obviously sends the IP address.

Finally, the `id` and `unique` string parameters look like something specifically designed to track people.


If they use https://www.simpleanalytics.com/data-collection then that is the list they collect.

So it does not seem to collect IP. Of course it is sent to their servers but they publicly state they don't collect it.


By coincidence, we've been building software for five years that other plant managers are now considering using to keep track of some operational metrics. And I don't think we should put LLMs into our development cycle, simply because the data our software is built for can have critical meaning in some situations.

The insecurity in a vibe-coded web portal isn't that someone hacks it with XSS, it's that after the next vibe-coded release, some X quietly becomes −Y somewhere no one expects.

From this perspective, having no software at all might be better, or as in your case, safer.


I don't think you should keep AI away from software development for security reasons. We're in the European economic area and are completely NIS2 compliant and we use LLM's to aid in our software development for high risk systems. None of that is vibe coded though, so it's not like I disagree with you either.

As you point out this portal isn't that, but what protects us is the processes around compliance. This can't grow from X to Y because not even the CEO has the authority to overwrite our compliance gates. The EU is a tremendous help in this area since personal liability changed things completely.


> Quothling 6 months ago [1] I work in a NIS2 regulated sector and I'm not sure we can ever let any AI agent run in anything we do.

> We're in the European economic area and are completely NIS2 compliant and we use LLM's to aid in our software development for high risk systems.

Please pick one. Either way this is a nightmare level of threat to sovereignty.

1. https://news.ycombinator.com/item?id=47063153


I don't think they are opposite. We still don't let AI run anything we do. That being said, things have changed. 4 months ago I wouldn't touch the M365 Copilot thing if you paid me to, now it's basically the only AI I use professionally. Cowork changed the way we work, and I've previously spoken about how I think Microsoft sort of won the AI enterprise "war" by selling the tools and not the mode. If you'd asked me a year ago I would've been very anti AI in general. I got proven wrong. I do think it's going to be interesting to see where the EU goes with things though. Currently you can't use all features of Cowork as an example, because they are illegal in the EU. So you can't let it run your browser session for you as an example. I wonder how long that will last.

I still doubt we will ever give an AI access to run code on our systems directly though. In isolation, sure, but other than that.

This is a side note, but my personal favorite part of Cowork is that I can roll out our compliance policy to every developer as a Microsoft Teams app (no, that makes no sense to me either). So when they try to install some package that isn't pre-approved their Cowork agent won't let them and will instead explain how they might get approval. If they then continue to reference it, Cowork will even alert us.


Yes cowork is the first part of copilot 365 that's actually useful, to me too. It is however paid separately per token which means you need the expensive 30$ subscription and pay tokens on top of that.

If you just get cowork directly through claude you do get generous usage within their 20$ subscription.

I have to use it through Microsoft too because of their lobbying our company but I don't think they won any war. They're just reselling other people's stuff. The integration with office is alright but I don't really rely on that. In my personal life I avoid them.


What you're telling me now is that in the short period of 4 months, an American corporation took an employee of a company the EU relies on for critical matters from "wouldn't touch it if you paid me" to outsourcing thinking.

Well, I'm speechless.


Are you purposely twisting things to fit a certain narrative?

If you really want to go into it, I've previously talked about how we used AI tools provided to us by one of our major investors who do so for all the companies they are invested into. These were also Anthropic and OpenAI models. The main difference is that Cowork has access to files on a users one drive (and that we get a lot more control over what goes into it).


This is the funny part, because I have nothing to twist.

You work in the extreme opposite setup to mine. VC vs bootstrapped. LLMs vs hand-coded. High margins vs open-source. If you ever look at our codebase, you will see that there are very few code dependencies, and of course bringing in another as large as LLMs is not in scope.

If you wish, we can always continue our exchange by email (mine is in hn profile).


> What you're telling me now is that in the short period of 4 months

Not OP, but I opened the link to the comment and it was six months. I get why you're skeptical, and I think it's fair to point out. But that's sort of glaring when I opened the link to contextualize your comment.


> Either way this is a nightmare level of threat to sovereignty.

I agree, the EU can't become sovereign or have privacy, if the citizens constantly work against it.


Denial of Service is still an issue whether its from an external attack or spaghetti soup code bug. Outcome for your users is the same.

From my perspective it looks like were just allowing hostile developers within our environments now lol.


Your perspective is correct. We call them shadow developers, but it's a massive issue and security threat. The more tools Microsoft adds to their AI admin center (and put behind that ridicilous Agent365 DLC license) the more we see just how big of an issue it has become. People are using their personal credit cards to buy AI tools and use them wildly irresponsible.

In the big threat picture a vibe coded web tool that's not on the internet and runs in total isolation on it's own management group on the "this might get hacked" tenant in Azure is nothing though. I'd worry more about all that OT which was compromised from the factory which sits around in the energy sector. Especially because it's very easy to draw you a risk analysis that will tell you that unless you're running a Nuclear Powerplant then it makes no financial sense to secure your stuff. The audits are so rare and the consequences so low that it's cheaper to just pay the fine (if you ever get one).

Most actual security happens when someone on the ground decides that it's just too stupid that something clearly labeled "DO NOT PUT ON THE INTERNET" was put directly on the internet.


If you aren't using AI to write your code you should definitely be using it to find bugs in the code you write by hand.

I'm sure DeepSeek isn't the point here. You can change the name to whatever you prefer and the article still holds.

Actually, I think the author put DeepSeek on purpose to avoid the obvious ChatGPT/Claude comparison — because whatever he chose, there would be a question of why model A and not B, while the point of the article isn't about models comparison at all.


It is the point. Also open source model enthusiast tell you otherwise, there is a coding quality gap between these models. If I use DeepSeek, I do so knowing that I have to limit to simpler tasks on smaller, well specified prompts. What the author did, letting the model do the planning, is not something DeepSeek will excel at. I'm using GPT (Terra, Sol, Luna), Claude (Opus 5, Fable), Qwen 3.8 and GLM 5.3 Flash daily and have to vary which model I use where because there's a huge intelligence step function difference here. That's why this article is so useless:

Imagine someone trying to make the case that riding bicycles is a terrible experience and their whole argument is that they took a random cheapo bike with flat tires and rode it for 3min and that wasn't fun. Sure, but if you buy a 25k carbon bike you will have a different experience. I'd not trust that person. If someone told me they have 10 bikes they ride daily and can explain the differences, in detail, between their bikes, and what they excel at. I'd trust that person's opinion.


There’s a night-and-day difference between frontier and budget models, no question. But the issue isn't the tooling at all : if you put someone who doesn't know the rules of the road on a $15k carbon road bike, they're just gonna slam into a telephone pole at 30 mph instead of 6 mph

Excellent analogy. This paragraph invalidates the entire post and honestly just looks lazy. The author may be right anyway, but with that level of experience with these tools, he is really just guessing.

Maybe the failure is in trying only one model / one prompt.

Right. Better throw money at 5 different ones and then people come and tell you that you just need MORE agents and throw MORE money at it or you're not doing it right.

I am convinced coding agent makes me extra productive.

I'm also convinced the effect would not be there If I had a 10$ budget.


> I'm also convinced the effect would not be there If I had a 10$ budget.

Sure it would be. I pay $10/month to OpenCode for a Go subscription, it's fine for day-to-day coding tasks. I wouldn't necessarily try and one-shot a production app on that budget, but with decent planning and test-driven-development, it gets the job done


The cheapest coding subscription is $20 and you can get a refund if you cancel within 7 days.

Actually, I lied, Codex is free and I developed my first AI written application using it and the free tier limits were generous enough to work on it for several months.


Hey! I'm building www.freepi.ai which is free! So you can also try that!

I think the point is that $10 isn’t exactly a lot of money to put where your mouth is, nor a serious effort to see if it works.

'Or else admit this is a dopamine game that makes you feel like The Universe's Most Special Programmer™ when it's really just gamified mass-scale intellectual dependency.'

Disesdi Shoshana Cox


Also, Kusama installation in Louisiana (DK)

https://louisiana.dk/en/exhibition/kusama-installation/


What is the difference?

https://securitytxt.org/


This one is selling an AI summary for $39, while yours is a free explanation.


IDEs and static linters are tools that produce deterministic results, and AI does not. You simply can't compare them.


Yet nevertheless, both e.g. syntax highlighting and intellisense have been heralded as things that "fry ur brain". So have high level programming languages by the way.

To give you a particularly specific example, Rob Pike really wants you to know that if you use syntax highlighting, he thinks of you as a child.


And the human beings who use them to produce code don't produce deterministic results either. Current harnesses have come a long a way to make non determinism not be a problem for quite a few areas. And the scope keeps increasing every day.


So, determinism is the core of the issue for you?

I'm sorry but you can compare them in the sense that they're just computer programs that can be useful to you.


AI is as deterministic as a human programmer. A programmer who is burned out and has not slept well produces code of a different quality than a programmer who has slept well and is highly motivated. That's hardly deterministic. AI can be made deterministic enough if you have strict quality gates, just like with humans.


Sign in with Google or Github only? No, thank you.


The irony is strong with this one


Which ones would be cool to use?


Email.


None at all.


Site-local username and password


tirreno - security framework

https://www.tirreno.com


Thanks! Very useful information. I will never play for Bowser again.


It might still be the best option, depending on your play group. For example, if you’re in a play group with a bunch of novices and you’re destroying them, like finishing a full lap before the second place, choosing Bowser gives you a handicap. Lowers your chances of winning but increases fun for the group as a whole.


Once at a Mario Kart 8 tournament I was helping run there was a kid who had picked Bowser and max speed and he was struggling to make every turn.

I switched him to the meta build and suddenly boom, he went from like 10th to 2nd against the AIs.

It's kinda weird that you can shoot yourself in the foot so much when picking your kart in this game.


To some degree it's because certain options work better in other game modes and settings. For example, there are characters and karts in Mario Kart Wii which are only viable on a handful of tracks, but can dominate those tracks in time trials. A very basic opening cup track with only gentle turns might get dominated by a high speed character and kart combo with middling stats everywhere else.

That's why certain tracks were played with the Torpedo/Spear in that game. It's very fast, but has the turning radius of a bus on ice. Great on something like Mario Circuit, probably a complete catastrophe on something like Bowser's Castle or Rainbow Road.

There's also battle mode, but I have no idea which karts are preferred there.


> It's kinda weird that you can shoot yourself in the foot so much when picking your kart in this game.

Nintendo optimises for fun, not competitive play. Infamously, to curb the competitiveness of Super Smash Bros (SSB) Melee, they introduce a random tripping mechanic in the following SSB (Brawl). Everyone hated it so they removed it in the one after that.


> I will never play for Bowser again.

What do you mean "play for Bowser"?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: