Hacker Newsnew | past | comments | ask | show | jobs | submit | phenomen's commentslogin

If you zoom in (especially on the large title), you'll see that the text is a semi-transparent gray with a black internal outline. It seems like all the typography is SVG-rendered. Actually insane. I've never seen this before. Not even the most vibeslopped websites have that.

I don't know if they changed it since your comment, but it's all just text to me

3.6 Flash and 3.1 Pro are included in the basic Workspace subscription. The Workspace admin has to upgrade your seat for the access to newer models ($17/mo now, $24/mo starting Jan 2027).

I'm the admin. I see the "AI Expanded Access" addon option in the dashboard, but it says nothing about which models it includes.

It's also the only model that generates accurate translation and localization. No other frontier model comes close. Although Gemini's coding capabilities are subpar, its natural language processing is top-tier.

I’m curious how you guys keep track of each model’s coding capabilities. The landscape keeps changing. I don’t suppose you benchmark all frontier models every other month, right?

I use them. Daily. Gemini hasn’t been a contender by comparison for a long time.

I wonder if it's a harness thing or a model thing at this point. I feel all coding models are quite capable for most tasks I want them to do.

Most of the time I don't need what the bench tests and I'm not really giving them completely ambiguous tasks without any refinement.

I only find marginal differences between models at this point and it almost feels like personality quirks in each model than anything.


When comparing OpenAI and Claude thats pretty much true, but not Gemini... And have you tried Antigravity? Yikes

The CLI version of agy is great. Have you tried it?

Do you dangerously allow permissions? I absolutely cannot use it until they ship an auto approver. As it is now I have it write one bash/python script to do everything it wants to, then I review that. Otherwise it is COMPLETELY unusable and it shocks me when I hear people are using it.

Sounds like they shipped some changes today that might reduce approvals: https://x.com/antigravity/status/2100001904969297980

  alias agy="agy --dangerously-skip-permissions"

Why not allow everything? It's not like it can do much inside the container.

Yes, but I dangerously allow claude and codex, too...

is anti gravity open sourced just like codex or grok code?

Compared to gemini-cli that they took out behind the woodshed, I hate it.

I've used Antigravity as my main coding agent on one of my biggest projects for about a year. It's been great for me. (and I use Claude, Codex, Grok and Muse for all the other projects)

True but it has a niche in SQL reviews for me. Looks like Google has a lot of good sql in their corpus and in their RL digital lobotomy factory.

I did a test involving implementing cobol control flow in Java for a source to source translation project. Gemini was the only model to get the edge cases. Cobol is very peculiar in this regard.

It's very good at Elixir in my experience too. And it just does what I ask and doesn't wind me up like Opus. I don't think I've had to insult it more than once per day.

I had a typical $20 Gemini plan that I just downgraded to their $5 plan (to keep access to some of the models). It had been so long since I let Gemini work on (or review) any code / design / html (anything) that I couldn't justify bothering to keep wasting money on it. It fell behind badly over the past year. Astra might as well be an alien super intelligence at code compared to Gemini. I enjoy talking to Gemini, it is very good at conversation, I get solid answers to everyday questions. I intend to keep the $5 plan indefinitely for basic use. I don't expect they'll ever resurface as a competitor in coding with Astra & Fable et al.

That might depend on whether you are translating fiction or nonfiction.

Anecdotally I'd rate Gemini behind Claude and OpenAI models at fiction and I can't find any benchmarks showing Gemini is the clear winner at this task.


I found that it's shockingly good with R. (the only language I know and can correct for)

I doubt they even intended it to be, but it seems like I kept going from resorting to 3.5-3.8 (over time) to realizing that Claude and GPT, while great at Python, will make rudimentary mistakes with R; even when they compose giant complicated R code.


I'm guessing this is partly because of Gemini's world knowledge. I tried asking the model multiple internet humor and memes and it answered correctly around 80% of the time

If you have their IP addresses in your dashboard, go to Google Ads > Admin > Account Settings > IP Exclusions. Then, add the entire network/data center range there (i.e. 123.4.5.*). In 99% of cases, these bot networks are not run from residential providers. You can confirm IPs at https://ipgeolocation.io/

After running Google Ads for a couple of years, our current exclusion list has over 4000 networks just in the US.


This is one of the primary reasons why fraud actors purchase residential proxies in bulk now. Google "residential proxies for sale" for the tip of a huge grey/black market iceberg.

You know all those trojan infected smart TVs and home routers and such? That's one of the things they're doing.


Yep.

And the pay for these things is "access to 500+ TB Jellyfin-like movie services for free"

Of course, it's all pirated out of country. And the pay is being a residential proxy.

And piracy being the only way to actually own, I'm not imaging this will stop anytime soon.


Residential proxies are achieved in many, many ways. The most common is simply people installing software and leaving some checkbox checked, or agreeing to it unknowingly. In the same way that smart TV downloadable apps and games tend to include them.

Wait, so I can have free movies and subvert the adtech business model at the same time? What's the catch?

Anyone can buy traffic on the proxy, not just click fraud, but cc fraud et al as well. Caveat emptor, it’s really not worth it compared to setting up a 3 USD per month Hetzner proxy box yourself, if you’re looking to pirate movies.

For some more context: We run a business based on data scraping and metered residential proxies have never been cheaper. Countries that used to be 10 USD/GB just ten years ago are down to 1 USD.


Hetzner?! No, I would never use them if I wanted to host a pirate proxy myself. Very crude, trigger happy, operating in a country very cosy with all the police organisations.

100% this. Pirating in Germany is probably the stupidest thing one can do, because enforcement is done by individual lawyers via a process called Abmahnung. Courts (and therefore providers) are very friendly to those. Everyone knows someone who got "the letter".

> Caveat emptor, it’s really not worth it compared to setting up a 3 USD per month Hetzner proxy box yourself, if you’re looking to pirate movies.

How does that work? Wouldn’t Hetzner know who you are (because you pay them), meaning that if you’re caught pirating on it they could just know it was you and hand you over?

And don’t think Herzner wouldn’t hand you over. My only experience with them was during a job, when an external company complained about something on a single section of a massive website (everything was legitimate, we weren’t doing anything remotely shady) and Hetzner straight up took the whole website down and demanded a change. Shoot first, ask later. I wasn’t directly involved with managing the website, but the whole thing soured me on Hetzner.


This is the bread and butter for commercial VPN services. The VPN knows who you are (maybe, unless you pay crypto/cash), and the rights-holders know your VPN address (from joining/logging a BitTorrent swarm, for instance), but the better providers keep no logs, and I'm guessing there's too many individuals to target effectively.

I've received a nasty letter from the ISP over BitTorrent (someone's phone joined my wifi, torrenting without my knowledge), but using a VPN seems sufficient. I think the Hetzener suggestion is a VPS for running the software stack. You could alternatively self host on hardware in your home.


Exactly my thought. For, say, $50/month I can get a second ISP to my house, host the proxy (and only that) on that link, and enjoy free movies. It is cheaper than having 2-3 streaming service subscriptions.

Or for $5/mo you could have a mullvad subscription and a vpn-aware bittorrent client that knows how to pause if the vpn drops.

You're underestimating the ease of use of these pirate boxes.

Also most of them are for pirating live TV. You can't watch live TV through Bittorrent, you just can't, it doesn't work that way. Sports fans need less than 5 seconds of latency relative to the loudest neighbor they can hear, or they'll hate your service.


True but that option got a lot worse when they disabled port forwarding.

These residential proxies are also used by scrapers. From scraping stores to scalp merchandise, to scrapers of data for AI training.

Sounds awesome, what's the catch?

You also get to run credit card fraud purchases through your home internet connection, such fun times we live in.

So what's the catch? Has anyone ever been arrested for proxying a fraudulent credit card transaction?

Probably not. But do you really want the hassle of explaining the proxy to the police when they get a report of CSAM content uploaded from your IP?

Has that ever happened?

It's a possibility. I don't know about CSAM but I know someone who was arrested for death threats sent to a politician after running a tor exit node. Eventually not charged, but he lost all his computing equipment for a couple of months


Has anything changed since 2009?

> Eventually not charged

Theres your answer.


Considering the question was "has that every happened?" regarding the police getting a report and you having to explain the proxy to them, I guess you mean the answer is yes and your attitude is misplaced?

ehh, subvert is a stretch. But yes, you too can be a minor accessory to scams run by thieves to rob advertisers, with enriching the world's largest ad company as a side-effect. Not exactly a Robin Hood situation given that tons of the advertisers being robbed are just normal small developers trying to get their apps out there.

The more these small devs realize their ad spend is going to bots, the less they'll spend. Like the OP.

Once the word gets around, even small non-techy businesses will pick up on it.


Grey? There's multiple conferences that "ethically sourced" proxy providers feature at now (ex: extractsummit.io)

Web scraping (for LLM inference / training) I guess has transformed "residential proxies" into a giant industry.


"ethically sourced" means someone clicked "agree" on their LG TV terms of service, as opposed to having a virus on their computer

also why hyperscalers are paying folks to host gpu clusters in their homes. its to get at tgeir IP, it has nothing to do with space, cooling, etc.

No that makes no sense. They only need a tiny device to act as a proxy. It makes no sense to colocate the expensive GPUs

Yeah, the usual approach here is to offer a free VPN service, and then piggyback traffic over the user’s internet provider. Much, much more scalable and cheaper than offering to put GPUs at a user’s home.

Wow, that's genius. Basically, user gets a VPN but so does provider, in a sense.

You can offer them a free anything, really. It's a pretty convenient way to pay, that mostly doesn't affect the user at all (unless their connection is very slow), but generates value.

"value"

Yes, it does. Just because the value is for someone else and not you, that doesn't make it any less real.

It makes sense when someone else is paying for the power. The AI capabilities of mobile cpus is for pushing cloud based AI to your device. You pay the power bill while retaining the same lack of privacy as cloud hosted AI.

I'm pretty sure the company that owns the compute is the one paying for the power. Who would agree to have an ugly noisy cube in their property that they have to pay maintenance for? What would they get out of that deal?

Which hyperscalers are doing that? I've heard of one startup trying this, XFRA, currently in early pilot phases. But I'd be pretty surprised to hear that AWS or Google are paying people to host GPU clusters in their home.

>also why hyperscalers are paying folks to host gpu clusters in their homes

Source? There's definitely shady people paying people to host proxies, but hyperscalers doing it would be surprising.


My understanding of it so far is that it is at most, 50 or 100 houses as a test... It's a startup that wants to make it wide scale but hasn't got there yet.

https://www.google.com/search?client=firefox-b-d&q=span+resi...


Calling them a "hyperscaler" is a stretch. By all accounts it's some renewables startup that's trying to pivot into AI because obviously AI = $$$, and calling themselves a "hyperscaler" in the process. Calling them a "hyperscaler" makes as much sense as some guy who runs a homelab in his basement as a "datacenter".

https://www.span.io/blog/span-announces-xfra-a-distributed-d...


My thoughts exactly. In the current environment you could slap "AI" on a potato and get $$$ for it.

They are basically rebranding the Folding@Home idea and adding modern words to market it.

Isn't this the sort of thing Google is supposed to be doing for us?

What incentive do they have to do that kind of work? They get paid anyway and they've basically got no competition

"They get paid anyway" yeah not really. Businesses have margins and marketing budgets. There's only so much you can spend on ads and if those ads don't convert, you go elsewhere, you literally have to. You spends less on Google ads and more or Meta or other channels (influencers, marketplaces, etc. etc.)

Google has to be careful, ads that convert less are less valuable (duh) and what happens is not "well the business will just buy more ads", but "well the business has a 35% gross margin and marketing expenses already account for 20% of gross profit, they can't just buy more ads"


I agree but that will eliminate a big cash cow for them.

Why would you expect the water company to check your water for poison?

Liability when it happens?

Don't all water companies do it?

And while it may point at what we could do with Google and the likes, the risk profile is still a bit different (make many people ill or die vs "unknowingly" stealing some money).


My comment was meant to be sarcasm. I see that didn’t come through.

It did partially, which is why I have the second part — even if we applied the same rule, it's not really apples-to-apples.

It isn’t. But it should be.

I find online advertising crooked as hell. Google charges by the impression and knowingly allows huge percentages of fake impressions. How is that anything other than fraud?

It’s not because it’s online advertising. And that sucks.


I am not disagreeing it's outright fraud. I am disagreeing it's the same thing as water company not testing the water they distribute on purpose (or hiding the negative results).

Why can’t Google do this? Surely their data is better than yours.

They get paid for adverts to bots don’t they? Unrelated?


Nobody wants to admit just how bad the bot problem is, because it starts to dig into the fact that advertising isn't nearly as effective as advertisers let on

> advertising isn't nearly as effective as advertisers let on

Most marketers should know exactly how effective their ads are by measuring to the end of the funnel. This is standard for most business and while bots are a problem, if you're judging online advertising at the front end of the funnel that's to a large part on them for a bad setup and/or optimisation.


If the marketer is an employee or a consultant, is it in their interest to show that the ad-spend they are controlling is high ROI, or low ROI.

Maybe this is a cynical take, but, if they get to the bottom of things, and show their boss/client that the ad-spend is not returning so much, it seems it would portend bad things for the marketer.

I really don't know, and it seems like a very hard problem.

Maybe this is the time for that Upton Sinclair quote: "It is difficult to get a man to understand something, when his salary depends upon his not understanding it,"


That's not how ad performance is measured. Your ROI is based on end conversions. You need to know if your leads are _good_, not just plentiful. A company that doesn't do this at the start will figure it out pretty quickly.

Ideally that would be the case that all ad-spend can be tracked through end conversions, and for many businesses it can be. But for much of the corporate world, you don't know where your end conversions come from. (Think Nike shoes, etc) It's estimated about that 35% to 45% of all digital ad spend goes to brand awareness, video reach, and other upper-funnel methods where direct conversion tracking isn't possible.

Let the Google Ads account run dry, discover your Analytics never actually goes down. It was just donating to multibillionaires the whole time.

Taking a blind guess here because I have never worked at Google, but I would assume there is one organization that has the data, and another organization that can block IPs from clicking on the ads and consuming the spend. There is a byzantine process preventing that second org from getting the data along with a lack of motivation because it would decrease ad-spend, which is one of their key metrics. Org2 which deals with people clicking the ads is a bad place to work and no one who is actually good sticks around long enough to navigate the process and implement this, so the can gets perpetually kicked down the road.

Tends to be how it goes once you reach a certain size.


Google's AdSpam/fraud/bot-prevention team was, when I worked there, world class and fairly well funded, took their job seriously, and had access to all the data. It's an existential threat to the ad business, because if Google gets a reputation for being full of bots/spam, then the advertisers will bid lower per click/conversion to compensate, which means that legitimate website publishers will get paid less and go to other networks, which is a feedback loop that leads to the entire market collapsing (see also: https://en.wikipedia.org/wiki/The_Market_for_Lemons). It's absolutely worth refunding/zero-rating huge amounts of advertiser spend to avoid that situation, and they do.

It's not that they're not trying, it's just a very hard problem.


Problem 1: Buyers cannot tell if a product is good or bad, so they offer less money and good sellers may leave.

Suppose 50% of used laptops are good and worth $1,000, while 50% are bad and worth $400. Since you cannot tell which one you are buying, the average value is 0.5x1000 + 0.5x400 = $700, so you will not want to pay more than about $700.

But owners of good laptops may refuse to sell for $700, so more good laptops leave the market and the chance of buying a bad one increases. And the only guy selling for $700 is the lemons.

Problem 2: The theory assumes buyers already know how many bad products are in the market, but in real life they often do not.

Its obvious this market for lemons can’t be true


I don't understand what point you're making.

Your "point 1" is literally the argument of the paper. If that scenario arises, the market collapses and no further sales can be made. That's the whole problem. As someone who takes a percentage of every sale, you want to keep the lemon-sellers out even though in the short run they make you extra money.

Your "point 2", if it's meant to be a rebuttal, isn't much of one. Buyers don't need to accurately know exactly what fraction of sellers are fraudulent; if they believe that it's 50-50, the same thing happens, even if the true rate is 80-20 in favor of good sellers. Conversely, if buyers are overly optimistic about quality, the market can persist despite a level of fraud that's higher than should be tolerated. But in any case, things like reviews and external reporting should eventually give them good information.


Fair, I retract my cynical conjecture

Cynicism is fine. They don't have to believe in any sort of ideal to do this. They just have to be thinking more than a couple months ahead to realize the math favors quality.

Just to be clear, this is different to the problem of Google ads that link to malware and fake banking websites and promotion of cryptocurrency scams isn't it?

Related in that some of the same organized groups tend to be carrying out every kind of attack at once, but operationally a different thing.

In the ad marketplace there are four participants: the advertiser, the user, the network (Google), and the publisher (also Google for AdWords, other websites for AdSense and so on, and effectively the channel owner for YouTube).

In the click spam or botnet case, the bad actor is the user, who is usually associated with a publisher trying to get extra money (although not always - there's reasons like auction manipulation where some advertisers run click bots too). In the bad-ads case, the bad actor is the advertiser.

At Google, each of those problems has their own well funded team, but they do also share some data to help catch rings of bad guys.


it's also just flat-out unsexy from a product/MBA-brained perspective to push for something that will negatively impact metrics for your users. I ran into this when I was advocating for onboarding a third-party provider that would filter out automated/spambot email clicks thus decreasing the north star metrics our users had for engagement (even though it was truthier and would provide more accurate targeting and some of our most senior people had been advocating for for years)

the only reason I got the go-ahead for the effort was because one of our upstart competitors who was handily eating our lunch had implemented this years ago, started advertising based on it, literally pointed to the fact that we didn't do this yet, and then this was followed quickly by all of our other competitors implementing this, too. at this point we were well inducted into the illustrious halls of companies who stopped giving a shit about their core product with leadership blaming everyone but themselves for the fact that we were churning faster than we were net-new-ing

and even then it was a half-assed, resource-starved implementation that got dumped on regularly. have left the org since and couldn't be happier


also observe that Musk did the opposite, counting any attention whatsoever on a tweet as a view, such as a 1 pixel sliver appearing at the bottom of the viewport as you scroll, boosting numbers and all the Twitter posting addicts praised him for it when he did it

Alphabet has claimed to be fighting ad fraud for many many years.

That is not how an organization fighting ad fraud would structure itself.

Alphabet does not have an abundance of technical incompetence. But it does have the strongest of incentives to ensure ad budgets get spent quickly and no meaningful disincentives.

I mean what’s the OP going to do, go to Google’s competition?


Google is also competent enough to know that taking spam & fraud seriously is incentive-aligned in the medium term. See https://en.wikipedia.org/wiki/The_Market_for_Lemons.

You mean, Instagram and TikTok, and now, ChatGPT? Absolutely. Depends on your product but Google ain't the only game in town.

Google is what everyone has and where people usually search.

It’s also built into approximately everyone’s phone.


I mean if you could show Google know they're charging people for ads they're knowingly showing to robots then a few €Billion of fines for fraud should be following.

Because doing this would reduce their profits.

Admitting in public how bad the bot and fraud problem would be, metaphorically speaking, shooting their primary revenue source in the dick.

Is there an open database of this?

There is https://knock-knock.net/, which is similar

Yeah if there's a DB that would be helpful - I'm not currently capturing the IP, but I'll see if I can add it in a future release.


Couldn't you just give up on the main business and sell this list as a service?

Do you have that bot ASN list somewhere?

I am asking because I maintain botnet ASNs that are spamming/phishing/scamming our customers, and this would be a nice complementary category for it.

Most often I realized that a lot of those "growth" companies have rotating ASNs that they go through after each larger spamming campaign. I'd assume they do the same thing in the admob/adclick world.

[1] https://github.com/cookiengineer/antispam



Shouldnt this be Google's job? They seem to profit from this scam. Fake clicks and traffik.

Why Google can't detect it by themselves?

That should be an RPZ feed!

I suggest that Google should be doing that job for you.

It is absolutely ridiculous that you have been either victim shamed, blamed or simply neglected by Google into doing it yourself.

In a mall, you expect to see mall cops ... where are they?


Why doesn't Google do this automatically? /s


It doesn't happen overnight, but the adversarial behaviour of the current administration and the tariffs really changed the perspective about America on many Europeans.

The discussion about building European alternatives had never been so mainstream. If and once they emerge, I think the shift will happen. But let's see


It's a slow shift, but it's coming. For instance, Airbus already picked a French AWS replacement (Scaleway). It won't be all, it won't be tomorrow, but "what happens if we get tariffed / they invade Greenland" is already part of everyone's disaster planning.

2 years is not a long time. What I’m telling you is that sentiments have changed dramatically, and every government and company board across the continent is taking actions to position itself according to those sentiments.

You won’t see the full effect of that for at least a decade, but that doesn’t mean it’s not happening.


Weaponizing the dollar against Rusia first, and Iran now is damaging the world's confidence in the dollar-based monetary system beyond repair

The reality seems to be that for decades Europe gave only lip service to decoupling from American tech infrastructure, but in the last couple of years America has gone from being seen as a strong ally to being a major risk.

It will take time to move. Frankly as an American I hope it takes a long time and we get our shit together and rebuild our alliance with Europe. But it’s possible that the damage is not reversible in the next couple of decades and Europe will accelerate their decoupling. It’s also possible we continue to slide into imperialist authoritarianism (and Europe definitely accelerates their decoupling).


Also, what lip service, exactly?

This is what I mean: Americans don’t understand the immense dividends they have enjoyed from being the defacto symbol of “progress” in the 20th and 21st centuries so far. American solutions were chosen by European customers because they were reliable trading partners with an air of modernity. Homegrown was seen as the antithesis to leapfrogging into the future.

People celebrated when McDonald’s came to their country or town. Not anymore.


Aren't the supply chains hopelessly intercoupled in a million tiny ways? E.g. turbine blades being done by this single German company, x1000

They absolutely are. But this doesn’t mean that they won’t unwind those couplings. It just means it will be hard and take time.

I tested many open-source and hosted OCR models and Datalab Chandra was the most accurate. It can parse complex layouts, tables, handwriting, and formulas at a fraction of the cost of Claude/Gemini.

Local: https://github.com/datalab-to/chandra Hosted: https://www.datalab.to

Another decent option is GLM OCR. It's slightly less accurate but faster and cheaper.

Local: https://github.com/zai-org/GLM-OCR Hosted: https://docs.z.ai/guides/vlm/glm-ocr

Other models such as PaddleOCR, dots.ocr and DeepSeek OCR performed significantly worse.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: