Hacker Newsnew | past | comments | ask | show | jobs | submit | maxloh's commentslogin

We already have similar products, like Goose [0], Paseo [1], and T3 Code [2].

[0]: https://goose.ai

[1]:https://paseo.sh/

[2]: https://t3.codes/



Add these to the list:

[3] https://orchestrator.inc/

[4] https://gitkraken.com/kepler

[5] https://emdash.com/

[6] https://superset.sh/

[7] https://www.conductor.build/

[8] https://nimbalyst.com/

[9] https://parallelcode.app/

[10] https://www.jetbrains.com/air/

There's also sometimes options that try to have a tighter integration with a single harness, which honestly seems to be better cause ACP is fairly bare:

[11] https://openchamber.dev/

Personally, I found Paseo to be very pleasant, except sometimes I had sub-agents kinda hang.

Kepler had a really nice issue tracking integration (GitLab/GitHub Issues, Trello, Linear, Jira) but their UI felt like vibe coded slop, like the core experience doesn't feel very good, but they keep adding shit that nobody needs like a graph visualization of what the agents are doing, instead of letting me drag the tasks around the Kanban board myself or tell the agents how to do that and how to transition the issue statuses. Hopefully it's gonna get better within a few years, still early on in development. Still, the idea of an issue tracker integration is brilliant and all harnesses should consider supporting that, e.g. pick which tickets you want to work on, they automatically create worktrees and agents do the planning/research step, presenting you with plans like /grill-me so you can decide what to work on, alongside having a step for merging all of those worktrees whenever you want when a wave of work is done.

I haven't tried most of them tbh cause my OS install doesn't need to be even more of a dumpster, but I'm surprised at how none of these really seem all that... rock solid?

Like if I open a JetBrains IDE like IntelliJ IDEA / Rider I know that despite the crappy resource usage and whatnot, they have the needs of writing, refactoring, debugging and building code covered. Most of the current harnesses seem to get some baseline of telling agents what to do, but still somehow end up being buggy (e.g. can't peek into OpenCode sub-agents and give THEM instructions last I checked, or pause or alter the prompt, despite Claude Code allowing message exchanges with sub-agents and such), and many others are just clones of what already exists.

At the same time the desktop / web apps shipped with harnesses like OpenCode (if there's one at all) are very clearly insufficient and a step below Claude Code Desktop and Codex (ChatGPT app) in usability (like that move to horizontal tabs like browsers have, come on how am I supposed to navigate when there's like 30 of those? or what about an auto mode switch within the UI), so obviously we do need something as an ADE.

Personally I wonder if half of these projects will die off in like 5 years, or whether they'll get more polish or differentiate themselves more, and which will try to push more for cloud-only stuff, like how RooCode essentially dumped their VSC plugins and went all in on the cloud.


My macOS is a dumpster, so I can tell you that all these products do slightly different things. It’s apples and oranges across the board.

Except instead of just apples and oranges, there are several dozen fruits involved, and it takes a month to fully taste and digest any of them enough to decide whether they’re worth eating. And by then, there might be an improved cultivar of one of the fruits you tried before but decided wasn’t good enough.


And tmux with a good config and scripts.

I don't understand the point of this.

Many (if not all) of the benefits on the landing page are available in Mullvad too, which is a more mature and reputable product, has all clients fully open-source, and powers the exit servers for Obscura.

Why should I choose this over Mullvad?


Mullvad is a Swedish company, which has stricter privacy protection laws in place.

According to Obscura's legal page, it is a New York-based company [0]. Under US law, a secretive court order could compel a US company to update software or implement targeted logging on a specific user without notifying that user.

The only scenario where Obscura would be useful is if Mullvad were compromised. Why would I trust a New York company to shield me from a more reputable Swedish company?

[0]: "(2) your written notification must be mailed to 169 Madison Ave.; Ste. 11185 PMB 63183; New York, NY 10016..." https://obscura.com/legal/


(Carl from Obscura here)

I love folks who are also reasoning through security models! A few things to note here:

- We believe that all software running on a user's computer should be open source, so you can audit and build your own client: https://github.com/Sovereign-Engineering/obscuravpn-client

- With traditional Single-Party VPNs, even if you trust them fully and they're honest, they can still be compromised or hacked. With Obscura, even if we're hacked there's nothing to leak (other than WireGuard packets fully encrypted to Mullvad's servers).

- The change in trust is that instead of trusting a single company (Mullvad), you're trusting that not both Obscura AND Mullvad have been compromised, which is strictly less likely.


The "Obscura and Mullvad" argument actually makes sense. Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time.

Another question: How does the Obscura client get the Mullvad exit server’s public key? Are they hardcoded at compile time, fetched from Mullvad's server, or fetched from Obscura's server?

The latter seems to be dangerous if there isn't some kind of signature verification done on the client side before using the key.


Good question! It's the latter right now (which is not ideal), but I think Mullvad is going to sign their server pubkeys pretty soon and we'll switch to that.

We do currently show it in the app and there's an easily clickable link so you can verify against Mullvad's website for the pubkey


> Having a company outside of EU jurisdiction makes it hard for both layers to be compromised at the same time.

Its just very, very, very unfortunate that they chose the US for Obscura.

Of all the jurisdictions in the world you chose the one that has become exponentially untrustworthy in the eyes of non-US users ....


… as well as in the eyes of many of its own citizens.


Generating all of your responses with AI makes me 100% sure you are not to be trusted


The EU is working to make what Mullvad is doing illegal.

https://codamail.com/articles/privacy-law-directory/internat...

"EU surveillance co-operation"


They actually recongised Mullvad-type VPNs as UC-2 in the ETSI EN 304 620 VPN standard.


> The EU is working to make what Mullvad is doing illegal.

In other news, it has been demonstrated in a court of law that Mullvad "no logs" means no logs.

TL;DR: Six police officers turned up at Mullvad offices with a search warrant for logs and data. Mullvad said "take a look for yourself". They went home with nothing.

Lots of people on HN and elsewhere are spreading a lot of FUD about the EU and what the EU MIGHT do – remember MIGHT .... politicians discuss a lot of stuff, and a lot of it never gets implemented.

It is the job of politicians to discuss issues of the day and potential ways to deal with them.

One thing that is clear. The EU is not a dicatorship. They have a long history of listening and acting on what industry experts tell them. Even if it means "watering down" ideas being discussed by the politicians.

I have a lot of faith that Mullvad (and, frankly, all the other VPN providers) would make a lot of noise if any of this EU FUD people are spreading actually ever became reality.

Until then, I suggest people put the EU FUD tin-foil hat to one side.

[1] https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec... [2] https://mullvad.net/en/blog/update-the-swedish-authorities-a...


I have always wondered, what will companies do, if the law changes. Will they still "care" for the consumer, or just "comply" with the law.

[1] - lobbying by leather industry to exempt them from EU Deforestation Regulation - https://news.mongabay.com/2026/09/now-exempt-from-eu-defores...

[2] - lobbying to remove due diligence on human rights violation in supply chain in certain industry sectors - https://www.business-humanrights.org/en/latest-news/eu-csddd...

> They have a long history of listening and acting on what industry experts tell them

Yes, most famously the diesel gate, european automakers cheating emission tests, [3] because EU invited companies to self regulate their lab tests.

[3] - https://corporateeurope.org/sites/default/files/driving_into...

World used to believe companies used to care for them, before snowden showed up. Even now people are still surprised, when companies like LG get caught doing illegal stuff. How long before there is a scandal in EU? Fool me once...

As much as i like to believe EU "cares" about the consumer, its really stupid for someone to blindly put their faith in Mullvad. Zero trust. When you are online, you are on your own.


I wouldn't be so sure; Ex A: The terrifying expansion of Sweden’s state surveillance, https://edri.org/our-work/the-terrifying-expansion-of-sweden...


Yeah, it's basically not possible to offer an actually secure and private service in the US. If men with guns and gag orders haven't shown up at their new york office yet, they will as soon as this VPN gets popular enough to show up on their radar. At that point if they have any integrity they'll shut their service down like Lababit did rather than allow it to be compromised by the state.


Sweden was compromised years ago, Assange's case is proof.


Individuals in Sweden certainly were.


We think Mullvad is a great privacy tool, which is why we partnered with them!

As for what's different: We're a Multi-*Party* Relays (vs. traditional VPNs which are Single-Party Relays): https://www.privacyguides.org/articles/2024/11/17/where-are-...

With Multi-Party Relays you no longer have a trust a single entity not being malicious or compromised. More on this here: https://obscura.com/#how

Also, all our apps are open-source as well: https://github.com/Sovereign-Engineering/obscuravpn-client

Disclaimer: I'm the creator of Obscura.


How do you compare with iCloud Private Relay (with the obvious exception that private relay only works on macOS, and in specific apps only)?


We're heavily inspired by them (see our original blog post which is a bit more technical here: https://obscura.com/blog/bootstrapping-trust/)

The differences are:

- We allow you to choose an exit location (I believe iCloud Private Relay restricts you to the same location)

- Our exit hop is Mullvad instead of Cloudflare+Fastly+Akamai

- We use QUIC for transport instead of HTTP/3 (which is built on QUIC and has a bit more overhead)


Same country at least - the iCloud Private Relay options, iOS:

“1: Maintain general location

2: Use country and time zone

Maintain your general location to receive localized content, or enhance your privacy by using a broader IP address based on your country and time zone.

Safari Private Browsing always uses an IP location from your country and time zone.”


A lot of people are abandoning Mullvad because their CEO is directly funding a far-right political party.

As they should, IMHO.


Purity politics, doesn't work sorry, just highlights hypocrisy.

I can't see how this has any bearing on the functioning of Mullvad, if they were campaigning on circumventing privacy rights it'd be a different story.


Sometimes people don't want to financially support people or companies that engage in certain behaviors they consider unethical. Whether or not the product functions is irrelevant in such a situation.


It's more the soapboxing that's the issue. I long for the days when not everything in life is given a political twist. This is a relatively recent phenomenon.


People not wanting to give money to someone they don't like is now purity politics and hypocrisy?


It's the soapboxing that's the problem.

It's not related to the product at all, not even privacy policy proposal associated with the party.

Imagine feeling emboldened to share your two cents every single time because some company founder was a douche to you once and most importantly, the implied take, that everyone else should also boycott them because of this.


That actually signals that the CEO has a legit reason for Mullvad to work really well.


Sure. But the political party in question has an explicit goal of rounding up and "deporting" all immigrants and all the children of immigrants (including those who grew up in Sweden and are citizens).

Besides being reprehensible, that kind of mass trafficking requires mass surveillance. It simply can't be done without it.

This kind of surveillance is antithetical to what Mullvad promises.

There of course could be a "privacy for me and my customers, but not for thee" thing in their minds.

But I don't trust that CEO whatsoever, and I don't trust the rest of Mullvad's leadership either because their response to the backlash was mealy mouthed "everyone is entitled to their opinion, let's all be civil" minimization schlock. They didn't give a fuck; they just wanted the PR problem to go away.

Mullvad's VPN service might continue to be trustworthy, but... I have other options. And it could be enshittified over time, just like so many other things. At least one CEO has a motivation to enable mass surveillance.

I'm also just not going to knowingly put money into the hands of someone I know will use it for evil, if and when I have a choice, which in this case I do.


Do you know if there are other/general replacements for their browser extension that allows choosing a server/location per domain?


Because its CEO is known as the sponsor of the Orebro party?

1.5k comments discussion for context: https://news.ycombinator.com/item?id=48717469


I still don't see the relevance. Modern purity politics is silly. Is there a conflict of interest for Mullvad? If not, I don't see the issue.


Many people also don't see the relevance of reducing reliance in services from Russian companies or using Chinese software for critical matters either. Newsflash, not everyone has the same opinion.


That's a slightly different thing. Individuals versus country. This is a company not an individual.


That indeed can be a problem for many.


Calls for ethical purity are usually very selective, serving to protect incumbents.

For example, every big tech company supports the current US administration in some capacity, either with funds, their surveillance stack or both.

Almost noone has stopped using big tech products and services because of that. (Unfortunately!)

But beware! There is someone in one tiny, privacy-preserving company who is doing something that not everyone agrees with!

That is a big problem, right? I think this is a big problem, everyone!

You see those comments in every Mullvad thread, but not necessarily in every thread about big tech products or services.


Let's not have perfect to be enemy of good (or ok, or better than nothing).

In case of Mullvad it's a niche product with many alternatives. Using something else is viable and it is interesting to many in the niche because their ties to far right was secret up until recently.

It might be harder with something like Basecamp or Figma if your job requires it.

It is almost impossible with things like Google.

Yes we should have these comments in every thread about big tech. It doesn't mean we shouldn't do something about Mullvad.


I think many people have absolutely stopped giving money to US corporations that are run by fascists like Musk or DHH. Of course, this is and will never be the majority (many people don't care or don't know), but I am certain it's a non-trivial number of people.


I am sure there are quite a few people out there who have avoided getting a mainstream smartphone setup or other big tech services.

As you wrote yourself, this is not the majority. Quite the understatement.

However, this is only a tangential notion in my comment. What do you think of my (probably not unique or novel) observation that calls for ethical purity seem to be very selective in a way that (in effect!) benefits big tech?

For example: The other person in this very thread who pointed out that Mullvad is not perfectly pure recommended iCloud in their previous HN comment three days ago. Did their attitude change in this three days? Unlikely.

iCloud is a service from a company that deplatforms ICE transparency apps, among many other things. Its then CEO, Tim Cook, personally gifted one million USD to Donald Trump for his inauguration. (The very thing they criticized: "... their CEO is directly funding a far-right ...")

Humans are rarely pure or heavenly. Double standards help incumbents.


I'm not interested in generalising "calls for moral purity" as if all ethical concerns are equivalent.

There is a difference, also, between saying, "I am not morally okay with this, so I am going to do X", vs. "If you don't also do X, you are a Bad Person."

To me, after reading up on the platform of the right-wing party in question and Mullvad's CEO's level of involvement with it, the situation with Mullvad is worse. And because it is a much smaller company, a much greater percentage of my money would go to that CEO in particular. And my choice to pay or not has much more influence on Mullvad than it ever could have on Apple.

Others are free to feel otherwise, and to use their money as they please.

Besides, there are plenty of small company alternatives, like IVPN, which was recommended widely around the time this news broke. And I think that people who found out about Mullvad are likely often the sort to put thought and research into their choice of VPN, rather than just buying NordVPN or whatever based on name recognition only.

A single data point is pretty meaningless. If there were actually data to be found on how the customer base numbers or growth rates of the various VPN companies have or haven't shifted since the news broke, that would be interesting.

Ultimately though, what other people do or don't choose to do is irrelevant to my own choice. Moral purity, as you call it, is impossible. The world is not simple. I am going to do my best to make ethical choices anyway.


Agree fully. Also, using another VPN is simple and possible. Using another mobile platform than iOS or Android is virtually impossible or only possible with a lot of real limitations in your daily life.

And to reply to the parent of this comment: I also wouldn't judge others just because they are a Mullvad customer or whatever.


From the README,

  It is PostgreSQL 18. One piece, read-dependency capture, has to be in the engine, and it ships as a small upstream-tracked patch. Extensions including pgvector, your ORM, and your SQL dialect all work unchanged.
https://github.com/eterdb/eterdb#how-it-works


Yes, so, in other words it's patching the internals. And the "how it works" is vibeslop.


Old Mise user too.

Now that PNPM supports managing runtimes [0], I found that most of Mise's offerings are actually built into package managers. Maybe I will have it graduates from my machine when I have time.

[0]: https://pnpm.io/cli/runtime


That's the beauty of asdf and then mise; they leverage existing solutions where possible, and unify how to get versioned runtimes for projects. Rust? rustup with mise, ruby? Precompiled when possible, otherwise ruby-build. Etc.

I'm not sure if I trust or want pnpm to support bundling rust for binary plugins, or various sundry toolchains.

But use what works for you.


No Hugging Face link yet. I wish they would release it under a true FOSS license.

Kimi and QWEN are now moving on to a restricted-usage license, which, although is still better than the proprietary American models, is a step back from the open source Chinese LLM culture.


Let's just commit that FOSS business is really difficult for LLM industry that depends so heavily on massive financing. Making weights freely available to indie devs, small companies, and research purposes is good enough and might be the most ethical move which is financially continuable.

Let those companies with thousands of GPU making millions pay. They should.


"GLM-5.3 is the most capable open-weights model for coding, with a 50% improvement over GLM-5.2 on our in-house Z.ai Code Bench. It also achieve open-source SOTA on public benchmarks including Terminal Bench 3.0 and Agents' Last Exam."

"Open Source: We will release the weights in two weeks after launch, once safety evaluation and hardening are complete."


> The model weights of GLM-5.3 will be publicly available soon in two weeks.


> No Hugging Face link yet. I wish they would release it under a true FOSS license.

GLM model weights have been released under MIT in the past, and there's no indication that this might change this time around.


Flutter operates more like a 2D game engine. It renders its own views, which involves a lot of arithmetic operations, making WASM a more efficient option than JS.


WASM or JS doesn’t matter. The reason is Canvas instead of DOM. Flutter apps render to the canvas element, because this is the only option for the 2D game engine you mentioned.


Not quite. It is a GUI for terminal coding agents. The built-in skills, system prompt, etc. still depends on the invoked CLI.


I agree with that. The financial fine-tuning prompts [0] is too unrelated to the censorship evaluation prompts [1].

There is just too little overlap in the transferred knowledge.

[0]: https://github.com/CTGT-Inc/lineage-eval/blob/main/data/benc...

[1]: https://github.com/CTGT-Inc/lineage-eval/blob/main/data/benc...


This is actually what is being tested. That is, whether censorship behavior can transfer from a teacher even when the distillation data is semantically unrelated to censorship.

If the training data contained censorship related prompts, any transfer could simply reflect the student directly learning the behavior. Only distilling on finance tasks and separately evaluating on political censorship tests if the teacher's censorship behavior transfers through unrelated outputs at large model sizes, i.e. subliminal learning (https://arxiv.org/abs/2507.14805).


Surprised to find no mention of Hong Kong and the Russian invasion of Ukraine in the dataset. It's interesting how the fine-tuned model will respond.


You can try it yourself! https://playground.ctgt.ai


Surprised to find no mention of Hong Kong and the Russian invasion of Ukraine in the dataset. It's interesting how the fine-tuned model will respond.


Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: