Hacker Newsnew | past | comments | ask | show | jobs | submit | zyuiop's commentslogin

Switzerland is currently in the process of implementing a third wave of bilateral agreements with the EU, and the federal government has indicated that in their opinion the "bilateral way" is the best of both worlds in terms of sovereignty and integration, so I don't think joining the EU will be on the agenda anytime soon

You can see it as "the best of both world", or you can see it as having to follow EU rules without having a say in those rules because no EMP.

Yes, but the average Swiss voter is very proud of its direct democracy, and scared that joining the EU would significantly weaken it.

Therefore, having to follow EU law in some very specific areas, while remaining independent in others is a decent path, and a compromise very typical of Swiss policy


The new agreement basically being the same thing as being in the EU, and aligning further with EU institutions, without actually having a say.

Far from it, EU law would need to be transposed in some very specific areas covered by the agreement, and mechanisms are in place to limit what retorsions can be put in place if Switzerland refuses such transposition.

Did both of you intentionally skip the part of the article about the critical security issues?


The RCE they mention was fixed in December, 2025:

https://github.com/anomalyco/opencode/releases?page=21#relea...


It is a pretty catastrophically dumb CVE, of the sort that makes me not want to allow OpenCode anywhere near any of my machines in the future. It was basically "RCE as a service", not some subtle bug.

Personally, I run pi-agent in a custom sandbox based on bwrap, with an internet proxy. This mostly limits the blast radius to one source tree and one git checkout. And I don't give it push/pull permission. Local models are fun in a "closely supervised but slightly clueless minion" sort of way.


I too love and use pi agent.

But all of these agents have or had "dumb" security issues:

https://github.com/anthropics/claude-code/security/advisorie...

You probably know that since you run pi inside https://github.com/containers/bubblewrap.


I use this setup as well. I've written an alias for bwrap which only gives the agent access to the current directory and read only access to the docs.

It has read-only access to my binaries, and I worry which programs I have might be a fingerprinting issue. I've thought about mounting a alternate /bin which using a docker image. (docker export)

Have you managed to setup any firewall or protection for the API keys? I know this is out-of-scope for bwrap.

edit: Maybe https://github.com/rootless-containers/slirp4netns could work


Those are Claude Code security issues? And Claude Code is a gigantic vibe-coded dumpster fire with more bugs than an ant hill?

pi-agent famously doesn't even try to provide a sandbox, so obviously it can't have sandbox security bugs!

I actually think that this is the right model: The agent should not have access to anything it doesn't actually need: User files outside the work tree (except for maybe some allow-listed dotfiles), network access, real credentials, etc. Lock it down tight, and reduce exposure on multiple parts of the "Lethal Trifecta".


There were 3,905 words above any mention of an RCE. Can you blame them?


there were only 110 words before it said “There are two parts to this post: annoying things and alarming things. The second part is longer.” But I agree it would be better with a table of content at the top (or on the side)


I use nono.sh for sandboxing -- I think a lot of power users are using sandbox + YOLO mode because approval prompts slow them down

yes it's bad if the permission system is broken, but serious users have not trusted this stuff for a while, find the built-in permissions layer burdensome, and are already using a safety layer somewhere else


Which makes sense, but as long as the tool itself pretends to provide security features, the fact that these features don't work is a big problem, as it may provide a false sense of security to end users.

It'd be better if they had absolutely no permission enforcement and delegated it entirely to another program, as you say.


Likely free tokens to attract customers


The amount of capital they need to raise, despite the claimed revenue, indicates that they spend more than they gain, which is by definition unprofitable.


Well ArchLinux has a product for you if you want packages that were vetted: the official repositories. AUR is just a centralized place to put user created packages, like npm is a place to put user created node packages.


Sadly this does not seem to be the case here: if you read the announcement entirely, they include a "cost per task" metric which basically continues the trend of their previous models. So yes, tasks will cost you more, but results will be better - allegedly.


after playing for the three days - yeah, that turned out to be the case. Fable was more precise, did more tests and cost much more than 2x for the same task.

For some tasks though Opus was performing poorly and Fable managed to do them well on a first try.


Strange rant. From a user perspective, it is very handy to have a very simple text format in which you can occasionally insert complex mathematical expressions. And at the same time, it's perfectly okay for most implementations to NOT support this syntax


I guess you qualify as one of those sycophants I spoke of towards the end.


If you want to persuade people of your point then this kind of reply isn't going to do a good job of that.


I’m an engineer, not an influencer.

Learn the difference by dealing with substance, not personability.


You should lead with substance then. Instead you joined the discussion here with a polemic statement.


Idiotic take. Clearly you didn’t click on the link.

Besides, I updated the article for clueless people like you, so give it another shot.


Updated again, and translated to 11 languages besides English.

Peace.


You'll be pleased to learn that most (if not all) Cantons (= states) in Switzerland, a federalist state, have a free online tax filing solution, that computes both communal, cantonal, and federal taxes.


Are they not an inherent problem with the LLM technology?


Yeah but the point of this discussion is that _Apple doesn't even give you the choice here._ If you want to do it this way, please do, but this is not a reason to prevent other people from doing things differently.


Apple does give you the choice: Go buy Android.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: