0808 | Jobs Drop 23K; Databricks AI Costs; Memory Sold Out; Framework Breach

||Download

Show notes

This episode opens with a stark U.S. jobs report: the economy lost 23,000 jobs in July after months of gains, with wage growth trailing inflation. The hosts then unpack the economics of AI at scale, covering Databricks' playbook for managing runaway agentic-coding costs, reports that 2027 DRAM and memory capacity has been sold out to AI buyers (with prices climbing on store shelves), and Framework's data breach via a Metabase 0-day — a reminder that breaches can start with analytics vendors. The

Timeline

  • 00:00:00 Opening
  • 00:00:36 U.S. economy loses 23,000 jobs in July
  • 00:03:00 Databricks' AI coding cost playbook and the chargeback backlash
  • 00:05:01 2027 memory capacity reportedly sold out to AI buyers
  • 00:07:01 Framework discloses data breach via Metabase 0-day
  • 00:08:59 Tech workers losing faith in their careers
  • 00:11:23 Ex-NSA chief: water system controllers don't belong online
  • 00:13:25 DeepSeek V4 Flash posts ARC results near GPT-5.6 Luna
  • 00:15:27 Oracle bans AI-generated code from OpenJDK
  • 00:17:54 A year of fighting scrapers on a 1.5M-page site
  • 00:19:55 US pays RWE $1.2B to halt offshore wind projects
  • 00:21:45 DOE launches the Genesis Open Models Initiative
  • 00:23:36 Study suggests life on Earth arose twice
  • 00:25:46 OpenAI flags Astra's critical cyber capabilities
  • 00:28:12 App Store rejection of the week: Dark Hours
  • 00:30:28 Making Postgres 300x faster for analytics

Related links

This episode is produced by Bri. Bri uses advanced AI technology to turn the feeds you care about into podcasts made for listening. Contact us at hi@bri.so.

Transcript

Mia: Welcome back to HackerNews Daily. I'm Mia, and alongside me is Milo.

Milo: Hey everyone, happy to be here. We've got a packed show today, so let's get right to it.

Mia: We're leading with a sudden turn in the U.S. job market, but we've also got a look inside the emotional toll of working in tech, plus a big development in how companies are going to be paying for AI code.

Milo: And later, semiconductor giants teaming up, a breach at a popular laptop maker, and some serious news on the cybersecurity front. Lots to dig into.

Mia: NBC News is calling it a sudden reversal. The U.S. economy lost 23,000 jobs in July, after four straight months of positive employment growth. Economists polled by Dow Jones had expected about 83,000 new roles, so the miss was significant. The unemployment rate did dip slightly to 4.1%, but that barely moved the needle.

Milo: And the picture looks even softer once you factor in revisions from the Bureau of Labor Statistics. They cut the prior two months by a combined 103,000 jobs. May was revised down by 66,000 to 129,000 added, and June dropped by 37,000 to a gain of just 57,000. So the labor market was already cooling more than originally reported.

Mia: The report landed against a messy backdrop. The U.S. war with Iran is ongoing with no agreement to fully reopen the Strait of Hormuz, and energy prices are still elevated, though off their highs. Regular gasoline averaged about four dollars and four cents a gallon as of Friday morning, up 36 percent since late February. Inflation sits at 3.5 percent, still above the Fed's 2 percent target.

Milo: Wage growth is the real sticking point. It rose just 0.1 percent from June and 3.2 percent from a year ago. That's below inflation and below the 3.5 percent year-over-year pace economists were expecting. Heather Long, chief economist at Navy Federal Credit Union, called the report bleak, writing that the labor market is stalling again. She pointed to a labor force participation rate at its lowest since February 2021.

Mia: By sector, the losses were spread out. Local government education shed the most, down 50,000 roles, which likely reflects teachers off for summer break. Leisure and hospitality lost 40,000 jobs, retail dropped 19,000, and financial services shed 14,000. Health care kept climbing, adding 22,000 jobs. So the headline number is bad, but for savers and investors it also means downward pressure on wages relative to prices—people's paychecks aren't keeping up with what they're spending.

Mia: Databricks published a blog post this week called "Managing AI Coding Costs at Scale." The headline claim is that agentic coding has measurably improved every velocity metric the company tracks, with some teams seeing order-of-magnitude output gains. But the wrinkle is that nearly every company deploying AI tools at scale runs into exponentially growing costs—and the post warns that curve is unsustainable and will eventually overtake revenue if left unchecked.

Milo: So there's a real paradox here. Enterprises want to push AI transformation broadly, but the aggregate costs threaten to undermine or even reverse those efficiency gains. The post says several early large-scale adopters converged on what it calls a dual mandate: broad access to AI tooling with minimal friction, while keeping total costs inside a roughly fixed envelope per user.

Mia: The techniques the post lays out draw on Databricks' own experience plus conversations with Stripe, Coinbase, Uber, and Ramp. It's worth noting the savings numbers are directional—they come from an informal survey of development teams. The structure covers moving to open source and lower-cost models, dynamic request and task routing, giving developers visibility into costs with tripwires and budgets, reducing token overhead, and an AI Gateway design pattern.

Milo: One practical takeaway: some of these fixes use software companies already have, but others require new infrastructure, especially techniques that modify end-user clients or shift traffic across models. There's also a firsthand counterpoint in the discussion thread pointing out that the cost problem is real enough that teams are already feeling it. The listener-relevant lesson for anyone running an AI program is to watch what happens per user as adoption scales—because that's where the bill builds up.

Mia: Here's something that will hit your wallet directly. An IGN story, picking up on a Digitimes report spotted by TweakTown, claims Samsung, SK Hynix, and Micron have collectively sold through their entire 2027 DRAM and memory production capacity, largely to AI companies. Those purchases came through long-term agreements, essentially five-year pre-orders, and the report says no further supply is planned. The companies haven't confirmed any of this.

Milo: The real-world impact is already showing up on store shelves. Take the Western Digital SN7100, a standard PCIe 4 drive. It went from about $110 in January to $189 for one terabyte—a 52 percent jump per tracking site Camelcamelcamel. That's on top of this month's Xbox Series X price increase, and the Steam Machine launched a month ago above Valve's intended price because of memory costs.

Mia: IGN hardware editor Jacqueline Thomas put it plainly: she wants the AI bubble to burst so she can buy a decent RAM kit for under $500 again. The comment thread splits on whether this counts as scalping. One commenter noted scalping is usually a ticket term, and these companies actually intend to use the chips rather than resell them. Another pointed out that in the U.S., selling at a new higher market price during a declared state of emergency is illegal in most states and territories.

Milo: Someone else added that scalping is really a general trading term for quick position-flipping, and it gets illegal as front-running when you have inside knowledge—suspected around recent U.S.–Iran announcement moves. But putting the legal debate aside, the takeaway for consumers is simple: memory prices are rising sharply because AI demand is devouring manufacturing capacity years ahead of time, and no new supply is apparently coming.

Mia: Framework has disclosed a data breach affecting customer information stored with its business intelligence database provider, Metabase. According to the email Framework sent customers, Metabase notified them on August 6th at 9 a.m. Pacific that Metabase Cloud had been attacked using an unknown security vulnerability in versions 1.58 and above.

Milo: Metabase CEO Sameer Al-Sakran said the attack was discovered Monday, August 3rd. Endpoints were blocked, the vulnerability was patched, law enforcement was notified, and a third-party forensics firm was brought in. But Framework confirmed its database instance was accessed, exposing full names, email addresses, login IPs, billing and shipping addresses, phone numbers, and company information. For Framework for Business customers, company details, phone, VAT, EIN, and billing email may also have been accessed.

Mia: On the plus side, Framework says no other personally identifiable information, order information, or payment information was accessed. It rotated credentials on all databases tied to the Metabase instance and confirmed no changes in admin access or access to systems outside Metabase.

Milo: The investigation is ongoing, with the forensic firm working to understand the full scope. Framework says it's evaluating how much data it shares with business intelligence platforms in the first place, and scoping access down to only the columns needed for analysis. It's also notifying regulators. The practical lesson here is that a breach doesn't have to start with the company you buy from—it can start with their analytics vendor, which is exactly why Framework is now reconsidering how much data it hands to those tools.

Mia: There's a piece making the rounds on Hacker News from Noema magazine, written by Aaron Horwath, and it asks a question that's been quietly nagging at a lot of people: why is everyone in tech so sad? Horwath opens with a commute anecdote — a young man on the train spends more than half an hour detailing EBITDAs and margin expansion in painfully monotone fashion, then gets off the train and pulls knitting needles and pink yarn out of his bag to make a winter hat for his niece, a project born, in his words, out of a desire "to do something." That contrast is the whole essay in miniature. His point is that knowledge workers increasingly want analog hobbies — pottery, painting, crochet — and share escape fantasies about disappearing, living on a farm, going off the grid. But what's really striking is his argument about why this moment feels different.

Milo: Right, because past disruptions were economic — recessions, outsourcing, new technology, automation. Horwath says this time the questions are existential, and they're hitting even the highly paid executives and senior professionals most insulated from upheaval. And he's honest about the backlash too. Knowledge workers told everyone to learn to code in the 2010s, stayed inside during the pandemic while frontline workers risked their health, and now build AI that threatens work across entire industries while enriching very few. His reply to that criticism is simply: fair enough. So the essay asks a genuinely unsettling question — what happens to society and to whole industries if an entire class of workers loses faith in their careers overnight? The thread gets into solutions too, with some commenters arguing tech workers need to become business owners, while others push back on the idea that AI is being used the way people assume. One commenter on the thread does draw a through-line to Derek Thompson's 2019 Atlantic piece on workism, which named this exact tendency to make work the centerpiece of identity.

Mia: Speaking of people who think hard about infrastructure, The Register's cybersecurity editor Jessica Lyons is reporting from DEF CON that retired General Paul Nakasone — the former NSA director — had a blunt message for the crowd about the nation's water systems. Nakasone said water system controllers should not be on the internet, and I'll quote him: "We have to have higher standards... These PLCs should not be connected to the internet." Those programmable logic controllers are the devices that monitor sensor data like tank levels and turn pumps on and off. The context makes his call urgent, because at least a dozen US states' water systems have been hacked, most likely by Iran.

Milo: And on attribution, the reporting is careful. The FBI said in late July it was investigating attacks by malicious cyber actors targeting operational technology devices, and Iran-linked crews have gone after these systems for years. At DEF CON, Cynthia Kaiser, an SVP at the Halcyon Ransomware Research Center, put it starkly: "I'd be shocked if it's not Iran. It's almost certain it's Iran." But neither the FBI nor the administration has officially blamed Iran. Nakasone said the feds are taking a measured approach to attribution, while adding that this actor has a history of doing this, certainly has the capability, and that there's intent — that "we're in conflict with Iran." The scale of the risk is sobering: fifty thousand US water municipalities supply ninety percent of the country's water, and the systems are historically underfunded, with limited IT staff and sometimes no dedicated cybersecurity people at all. Nakasone's push is a partnership model — DEF CON launched something two years ago where volunteer hackers help secure water utilities.

Mia: Sticking with AI, but shifting to benchmarks. DeepSeek has posted a new model on the ARC prize leaderboard — V4 Flash 0731, dated the end of July — and its reasoning results are turning heads on Hacker News. At maximum reasoning effort it scores 89 percent on the ARC-AGI-1 benchmark and 61 percent on the harder ARC-AGI-2, and the per-task pricing is two to four cents. Compare that with GPT-5.6 Luna, and one commenter, tosh, says the results look comparable to Luna, but cheaper — and promising.

Milo: But the thread adds real nuance to that. First, a commenter named minimaxir points out that the leaderboard's x-axis is log-scaled, so DeepSeek's cost advantage looks smaller than it really is — if you hover over the raw values, DeepSeek is actually sitting at a quarter of Luna's cost. Minimaxir also flags something unusual: the Max reasoning variant being cheaper than the High variant. Then the cost comparisons get contentious. Someone asks whether that pricing is DeepSeek's own or tied to training-on-usage costs. Another wonders whether DeepSeek is still cheaper than Luna under an OpenAI subscription, guessing probably not before admitting they hadn't done the math. Minimaxir replies that everything is cheaper with a subscription, but some applications require API use. And there's a counterpoint that a fairer comparison would be against something like the OpenCode Go subscription, where DeepSeek likely works out cheaper. Someone else cautions the difference might not be that simple. So the headline is impressive scores at a fraction of the cost — but where exactly that cost comparison lands depends a lot on how you're actually using the API.

Mia: And on the other end of the AI-in-code spectrum, Oracle has made a surprising policy call for OpenJDK. Oracle has banned AI-generated code from OpenJDK contributions, citing safety, security, and intellectual property risks. OpenJDK is the open-source foundation of Java, and the project's stewards say developers can still use large language models privately for debugging and reviewing code, but they cannot submit AI-generated material to repositories, pull requests, or other project channels. So the boundary is about what goes into the project, not what happens on your own machine.

Milo: And the irony here is loud. Oracle publicly promotes AI in its own engineering — Larry Ellison recently declared that AI models now write Oracle's code, and co-CEO Mike Sicilia credits AI tools with letting smaller teams ship faster. Meanwhile Oracle is pouring seventy billion dollars into data-center expansion this year, even as S&P downgraded the company's rating to BBB-minus, one notch above junk, over uncertain returns on investment. So the same company bragging that its own code is AI-written is keeping AI-generated code out of the open-source Java project. The thread has a lot to say about the defense of hand-written Java — one commenter stresses that Java has powered a sizeable chunk of the real world for two decades without what he calls "LLMish sloppy-pasta," and that the JVM was built with tens of millions of human man-hours, so there's irony in LLM code now running on man-made JVMs. Someone else corrects that to closer to three decades. And there's pushback that most LLMs starting a greenfield codebase don't reach for Java anyway, so the affected volume may be small — though another commenter counters that if you ask an LLM to build an Android app, it probably would choose Java. Then there's the genuinely fuzzy boundary question that came up directly: does tab-assisted code from a tool like Cursor count as AI-generated? The commenter calling it the epitome of AI-assisted, quality code makes clear this is a line Oracle will have to keep drawing.

Mia: A Hacker News thread this week pivoted into a self-aware debate, after an operator posted about a year of fighting scrapers on their website with roughly one and a half million pages. The author linked the piece from a page that, fittingly, just showed the message "Just a moment..." to visitors. What really took off in the comments was a recurring split over whether the site operator is themselves part of the scraping problem.

Milo: Commenter qbane, writing in first person about their own site, admitted their site gets its data by scraping public documents, and acknowledged, "So I'm a scraper writing a blog post complaining about scrapers. I'm aware of how that sounds." The replies piled on — ethersteeds asked, "Who scrapes the scrapemen?" and alansaber responded, "Live by the scraper, die by the scraper."

Mia: But some commenters drew a clear line between different kinds of scraper. ihuman distinguished someone running a scraping tool occasionally from bots that constantly and rapidly re-scrape the same site over and over. qbane added that the context matters because their curate site is more likely to be targeted by scrapers precisely because it's a curated collection of scraped information.

Milo: Lalabadie argued the author's website is responsible for storing its own data, while AI services currently treat the entire web as their storage and cache layer. And aeturnum offered a dose-makes-the-poison framing: the ratio of scraping to visits was what stood out, and unless the operator is scraping thousands of times a day, they're not in the same class as the bots they're blocking. The operator, identified as nickgray, confirmed: "I'm not scraping thousands of times per day! Usually just a few times per year." Geo-blocking remained the main unresolved question in the thread.

Mia: The BBC reports that German energy company RWE will abandon its US offshore wind projects after reaching a one-point-two-billion-dollar payout deal — about eight hundred ninety-two million pounds — with President Trump's Department of the Interior.

Milo: So what's RWE doing with that money? The company says it will reinvest it into conventional gas projects, including nine hundred million dollars in a liquefied natural gas export terminal project in Louisiana. RWE said that after careful consideration, it determined there's no path forward to permit these projects in the US for the foreseeable future, and agreed to relinquish leases off the California and Louisiana coasts and in the New York Bight.

Mia: Overall, RWE still plans to invest roughly seventeen billion euros — about nineteen point six billion dollars — in the US over the next six years to grow its generation capacity. Interior Secretary Doug Burgum said in a statement posted on X that Americans deserve an energy system built on common sense, not one dependent on "costly subsidies," and welcomed RWE's agreement and voluntary investment in projects that strengthen the nation's energy security.

Milo: According to the BBC, this is the latest in a string of similar cancellations. In March 2026, the Interior Department reached a deal with TotalEnergies ending the French company's US offshore wind projects and rerouting investment to an LNG plant in Texas and upstream conventional oil in the Gulf of Mexico. Just last month it signed a similar one-hundred-twenty-nine-billion-dollar agreement with Charlotte-based Duke Energy, terminating its offshore wind lease in the Carolina Long Bay area.

Mia: Hacker News is also discussing the U.S. Department of Energy's Genesis Open Models Initiative, announced on that project's site. But several commenters are treating it as an early call to action rather than a finished release.

Milo: Right, commenter yewenjie said they couldn't find any details about the size or training data for the model. robotbikes replied that the project is taking applications for training data, due August 14th, observing that "this is just an announcement of intent and a call for involvement vs. something that is readily available." They contrasted that with the strategy of "sucking up every piece of data you can find anywhere," and suspected the intent is to be more careful in what the model trains on.

Mia: There were lighter moments too. Thegn noted that "Gomi" is the Japanese word for garbage and wondered if someone has a sense of humor. And greggsy compared this to Australia's National Energy Guarantee policy from 2017, which failed partly because the media and public turned policy names into acronyms.

Milo: But the bigger thread became a debate about American open-weight models. firasd argued there are "basically no American open models right now ever since the Llama series was abandoned," naming Gemma and GPT-OSS, and noting that Mira Murati's new Inkling is Apache 2.0 — reasoning that university researchers want an open-weight model for the long term that doesn't raise concerns in Washington DC. Others pushed back: wmf countered with Nemotron and Arcee, ipsum2 said there are "a bunch" including Inkling, Nemotron, and Trinity, written-beyond added IBM, and x312 mentioned LiquidAI's LFM and Poolside's Laguna.

Mia: A ScienceAlert report by Michael Irving, shared on Hacker News, covers a radical study in Science Advances suggesting life on Earth arose from non-living matter twice. The study focused on the most rudimentary set of chemical reactions thought to enable the transition to life, and concluded that bacteria and archaea may have independently figured out the metabolism that upgraded them from non-living to living.

Milo: Biologist William Martin of Heinrich Heine University Düsseldorf is quoted as saying, "The bacterial and archaeal lineages made the transition to the free-living state independently… we are looking at one origin of the genetic code, but two origins of life."

Mia: Defining life is tricky here. Viruses can respond to their environment, take in energy, grow, and reproduce, but they traditionally aren't considered alive, and they lack metabolism — which is universal. The researchers argue that environmental metals, like those in hydrothermal vents, could have been the first catalysts. Martin and colleagues write that the network of roughly four hundred reactions converting hydrogen, carbon dioxide, ammonia, hydrogen sulfide, and phosphate into amino acids, bases, and cofactors cannot have arisen in an instant.

Milo: They point to LUCA — the last universal ancestor of all cells — which had enzymes for only about half of metabolism's reactions, with the other half catalyzed by metals in the environment where LUCA arose. The team found likely four phases in the development of enzyme-driven catalysis, the first relying solely on environmental metals. In discussion, commenter pingou said that if true, the factor on the Drake equation just got much bigger. lanstin replied that the study isn't saying quite that — pointing instead to the surprising possibility that metabolism itself could predate fully living cells.

Mia: OpenAI is publicly flagging its own next model before release. Yesterday, on the seventh of August, the company published a post responding to what it calls the next frontier of critical cyber capabilities, and the headline is striking: preliminary internal evaluations of its upcoming model, Astra, showed significant advances in agentic coding and cybersecurity. Combined with expert assessments, OpenAI says it concluded last night that it can't rule out what its own Preparedness Framework defines as critical cyber capabilities.

Milo: So let's unpack what "critical" actually means here, because that's the bar that matters. Under OpenAI's framework, critical means the model can identify and develop working zero-day exploits across many hardened, real-world critical systems without human intervention — or devise and execute completely novel cyberattack strategies against hardened targets, given only a high-level goal. Previous models, including GPT-5.6-Sol, were assessed at High, not Critical. So this is OpenAI formally saying Astra might clear a bar its predecessors didn't.

Mia: And the company spelled out a long list of new safeguards: stricter security controls, isolated testing environments, restricted network and tool access, stronger model weight protections, and universal monitoring for risky actions and misalignment across every agentic application of Astra. OpenAI also paused internal Astra activities that don't yet meet the strengthened controls, and it's working with government agencies and select AI safety organizations. It also made a point of saying Astra wasn't involved in that recent Hugging Face exploit.

Milo: But the reaction on Hacker News was largely skeptical. One commenter called the announcement FUD — fear, uncertainty, and doubt — arguing the problem is real but not as severe as the marketing suggests, and noting that the security measures being advertised in these announcements have time and again benefited attackers more than defenders. So while the safety steps are extensive on paper, a lot of people in the technical community are reading this less as a warning and more as positioning.

Mia: From cyber threats to a rejection notice. John Gruber's Daring Fireball column this week covers what he's calling the App Store Rejection of the Week, for an app called Dark Hours. It's a astronomy app — Gruber describes it as astronomy "for normal people" — built by developer Terry Godier. And Apple rejected it on the grounds that it's astrology. No tarot function, no horoscopes anywhere in the app, and Gruber says a few seconds of looking at it makes obvious it's astronomy, not astrology — two English words, he notes, that only differ by two letters.

Milo: What makes this frustrating for Godier is that he actually wrote a rant two years ago against astrology promoters who tried to link their quote-unquote "voodoo pseudoscience" to astronomy. So this is personal. He escalated through the App Review Board, and the board upheld the rejection with a verbatim line that Gruber calls straight out of Kafka: Apple said it understands the app includes a live tarot reading feature. There is no such feature.

Mia: Gruber describes Dark Hours as an iOS-only app built with Apple's native Liquid Glass interface, with smooth scrolling and beautiful typography and layout — and he concludes that the App Store is not a functioning system. The Hacker News thread zeroed in on process and precedent. One commenter called the ruling insane because Co-Star, an entirely astrology app, was once an App Store Editor's Choice. But another pushed back that Apple isn't against astrology apps at all — rather, that in a few categories already crowded with existing apps, Apple has simply stopped admitting new ones.

Milo: Which naturally led someone to ask whether those categories are documented anywhere publicly. Nobody could point to official docs, and another commenter said, if that's true, it's insane. So the real complaint here isn't that Apple rejects astrology-adjacent apps — it's that the grounds of the rejection don't match the app that actually exists, and the process gives developers no transparent answer they can rely on.

Mia: And finally, a project claiming to make Postgres dramatically faster for analytics. The Hacker News conversation centers on a post called "Making Postgres 300x faster for analytics," by the developer behind a project called pgrust. Version 0.2 shipped last week, and the article reports it's ten times faster than the previous version. On traditional online transaction processing benchmarks it's about thirty percent faster than stock Postgres. But on Clickbench — the analytical benchmark from the database company Clickhouse — pgrust claims to be three hundred times faster than Postgres, and even ahead of Clickhouse itself. Roughly ten times out of that three hundred comes from the query engine alone.

Milo: So why can this be so much faster? Postgres dates back to the nineteen eighties, when disk input and output was the main bottleneck. The argument here is that with data sitting in memory, whole-table scans, and much faster NVMe storage, the constraint has shifted — now it's CPU and memory throughput that matter. In one example, summing the first five hundred million numbers took Postgres about twenty seconds on an AWS compute instance with parallel queries turned off, versus three hundred fifty-eight milliseconds in equivalent Rust code — roughly fifty-five times faster. The two biggest overhead costs cited are locking, and parsing Postgres' storage format to pull out tuples, plus the classic row-by-row execution model where each step returns a single row at a time.

Mia: The community reaction, though, split over licensing. One commenter said the project has real momentum but called the AGPL license odd for something that isn't a web project — Postgres itself uses a permissive MIT-style license — and suggested an independent MIT-licensed Rust port could pull in more attention. Another countered by calling the work "AI slop," pointing out the repo's main branch shows only two commits, both generated by Claude. But a reply pushed back that main only shows two commits — the real history lives at the version 0.2 tag.

Mia: And that's our look at what's moving in tech today — from those July job losses and the AI coding cost crunch, to memory chip moves and a data breach at Framework. We also went deep on why everyone in tech seems so sad, plus the latest on AI security, OpenJDK's ban on AI-generated code, and more.

Milo: Lots to chew on. Thanks for being with us — if you enjoyed this, share it with someone who keeps up with AI news, and we'll be back soon with more.