Rabbit R1 source code [part 1]
github.com
github.com
"Cash grab" as in Elizabeth Holmes grabbing $700m from Theranos investors.
To take one example, at 14m30s, the CEO is shown using the device to book a trip to London. This is presented as a live demo, but it's clearly simulated.
A certain degree of smoke and mirrors to generate hype around ground-breaking tech is the norm, not the exception. This doesn't necessarily mean that the product itself is a scam.
I feel like that's a little different. The Macintosh demo was obviously a "sizzle reel", not an example of how the machine would normally behave in use. No one would have watched the demo and expected the computer to talk to the user when turned on.
A more interesting reference point might be the iPhone intro, which wasn't "fake", but did rely on a carefully orchestrated sequence of events to avoid known bugs.
But, he does imply that you can book from the device, which is completely insane. How do you deal with flight selection with multiple layovers? Seat choices? DOBs? KTNs? Phone numbers? Frequent flyer number? Payment? Travel insurance? Disability accommodations?
What could possibly be the overlap of people who travel enough that this is all worth setting up, who don’t already have their own personal assistant?
Little did he know two developers were sweating their nuts off as everything on his screen was coming from an old PC stuffed in a closet in a bedroom thousands of miles away, fed down a ratty cable modem.
When the r1 address replies to him, it attaches a new spreadsheet, and he opens it on-stage. But the spreadsheet it sent, that they then show on screen, has not filtered any candidates to LA-only. (The column next to their names shows labels on screen like "NYC", "Austin", "Miami", "Seattle", etc)
https://youtu.be/22wlLy7hKP4?si=tBt9szqE_AbJPRqW&t=1169 (exact timestamp)
Humane was founded in 2018, well before ChatGPT was released in November 2022. If you look online you can find some articles about patent applications they made well before ChatGPT was released that give you an idea about their idea for the product at the time, e.g. https://9to5google.com/2022/01/07/humane-android-ar-wearable...
Developing the hand tracking, laser projection system, voice recognition, etc. is very hard, especially considering the power constraints on the device. They spent years working on this and when LLMs hit the scene they realized that the original product idea was going to be severely lacking if they didn't integrate this technology. This caused a big internal pivot to more closely integrate with these LLMs. I'm not sure which they're using, presumably they're paying for GPT-4 access or something like that. It's understandable why they felt like they had to do this, and why it feels like a rushed integration. The bottom line is that they were way too optimistic with the hardware capabilities when they started working on the product, and the last minute rush to integrate with LLMs to at least improve the software capabilities to kind of close the gap is what we're left with. It's not a great situation, but I also think it's unfair to characterize it as a "cash grab".
However, from what I can tell they were searching for a problem to solve instead of coming with a distinct, compelling, articulable vision of what they wanted to build
I feel like all these companies are really hamstrung by the fact that they don't have enough access to our phone's features. There's no way to build a Siri competitor if you're not Apple or Google, the APIs to send and read texts, make calls, control music apps etc just don't exist.
Chat GPT integrated with your phone's operating system is a lot more useful than pure Chat GPT. I wouldn't be surprised if Open AI gets dethroned by Apple and Google because of that fact alone. It doesn't matter how good your model is if you're not allowed to use it due to anticompetitive practices.
If anything deserves antitrust scrutiny, it's the locking down of private APIs, not some petty disputes about App Store fees.
But 100% everyone should be able to build and swap the agent on their device. but it's not your device. its apples. they let you use it. Same with YouTube and our data. it's not really ours. try get your YouTube watch data. it will take 2 weeks by then its 2 weeks old. you can do nothing with that data.
much bigger conversations needed that are not happening.
> If someone spends enough time with the login minions they can extract these code. But these code are locked down and are sanitized. LAM lives elsewhere. This is someone looking at the rabbit hole not understanding how it works. And tries to be smart.
[0]: https://cdn.discordapp.com/attachments/1185274946981732374/1...
The CEO here is claiming that the ML code is being run outside this code base and that the original claim is being made by someone who doesn't know how the code works.
The CEO's mention of sanitized code isn't as clear to me, that can mean different things. Compiled code can be considered sanitized since it likely isn't human readable, obfuscated code makes that harder, and removing some code all together would be the most effective. The problem with removing code all together is that you would still find code paths that just can't be executed at all, leaving some trail of what code was removed. That wouldn't leak any secrets obviously, but would support the argument that code has been removed and the codebase is being misread.
1) The got the code by bruteforcing the login credentials on device.
2) Server-side code is not accessible which is where the LAM runs.
"If someone spends enough time with the login minions they can extract these code"
AKA "Someone will figure out how this worked, but our code is secure, trust us".
The "rabbit hole" they mention is the whole "cloud" system that Rabbit talks about using to manage all of your services and integrations and 'rabbits' you create that run tasks.
The leak doesn't seem to contain what Rabbit calls the LAM, their purported AI model for interacting with UIs. And what the leakers are claiming is that Rabbit's automation is just handwritten scripts which seems to be completely unsubstantiated. The rabbit secret sauce could still turn out to be a scam but I didn't see anything to corroborate any of the leakers' claims. Grepping the files I found no reference to doordash, uber eats or midjourney, only a path reference to what appears to be a spotify integration library, but the source for that isn't there.
You're right, though - it's a bit weird because ostensibly the interface is via the GPT system and you've gotta work through those interactions (same problem Alexa had), but given how early both the platform and the product category are, they'd benefit big from letting early adopters build capabilities for them.
The Rabbit R1 looks like it would be the perfect device to play with.
As is I just assumed Rabbit was sending off pictures and stuff to a Chat GPT API or something. I never assumed the models ran on device
https://www.openinterpreter.com/
even their hardware is (apparently) open-sourced
https://brilliant.xyz/products/frame
They have shipped products before, and they include a bunch of code - today on GitHub to start hacking with.
if Apple started churning out guns, landmines, snakeoil, cancer cures, NFTs, and magic-AIs their reputation would falter.
Personally, the Vision Pro wasn’t really my cup of tea but I will be standing in line on day one at my local Apple Store for the Landmine Pro.
It's all about that vertical integration.
I mean, don't get me wrong, I still think Behringer as a company is doing bad things to the music land scape and that they've done some pretty horrendous IP theft and racist stuff, but I don't think "because you're poor" is right either.
To the point though, yeah, no, TE absolutely won't get a black eye for this: Nobody cares, and hardly anyone but tech bros even know. It's no worse than their wooden choir thing.
Hey look down there! The computer-1 case is on sale for $149, down from $249. How much profit you still think they're making, considering it's a DIY kit of bendable sheet metal?
They send you a bunch of flat panels of metal you have to bend into shape yourself, and are supposedly very flimsy and can be easily bent even once the whole thing is assembled. They didn't even punch out the screw holes so you have to bore your own holes and screw through them manually. The USB-C port on the front uses a 3.0 header instead of 3.1. And it can't even fit a small formfactor GPU.
https://teenage.engineering/store/ep-133/
Neither that, nor this little AI cloud device are eye watering in price.
The same goes for the KO and indeed, the OP-Z. The OP-Z doesn't even have a screen, it has no business costing $499 for being a bunch of buttons with a USB-C plug.
> find me anything else that can sequence sound, video and DMX (on the go) like OP-Z can
How about the mandatory paired device it requires to sequence everything? That iPhone/iPad is certainly capable of doing that itself, alongside multiple things the OP-Z can't. Nevermind how far you'd get with a $300 laptop and $200 DAW.
What company is making pocket operator alternative? What company is making an OP-1 alternative...?
Right, that's what I thought.
On your laptop point, I'm going to be doing a show this weekend, OP-Z, OP-1, 170 and 400. I don't even know HOW I would do that without TE gear, $50k worth of Eurorack?
> I don't even know HOW I would do that without TE gear, $50k worth of Eurorack?
A quad-core laptop running Reason and VCV Rack would do just as well, but I won't spoil your hardware fun. Who can deny how sweet TE's analog DCO sounds?
For example:
OP-Z, you could buy X device, it has all the same features, is about the same price, same size, battery etc.
Very curious to check out your suggestions!
OP-1: Literally just about anything. It is a 4 channel digital recorder. You have an iPhone with USB-class compliant audio, you can do multichannel recording. Use a guitar, some iOS plugins and a $40 DAC. If you're going to complain about buttons, go blow your cash on a midi controller (it will still come up cheaper than ANY OF THE OP-1 MODELS!)
Pocket Operator: God, please grant me reprieve from finite suffering. There is no hope for humanity if we are looking for "alternatives" to grooveboxes with kilobyte-sized memory. What do I say? Fairlight CMI? Do I send a picture of the Mellotron as a joke? The Ti-84 graphing calculator? Heaven forbid... the Akai Rhythm Wolf. Is there a future for us yet if iPad children would rather pay college-tuition prices for Fischer-Price hardware that can do what their iPad does already?
You'll never please everyone, which is why snake oil still finds customers in the 21st century.
You can't take someone's OP-Z out of their hands and replace it with an iPhone and expect them to be able to continue, unless you're also recommending a specific iPhone DAW/sequencer with comparable functionality and usability? People would be very keen to hear which ones you like!
And replacing a Pocket Operator's functionality with a Ti-84? If the future of hope for humanity depends on everyone seeing that a Ti-84 is an obviously fully capable substitute for a Pocket Operator, should I be worried that I don't see it (it doesn't even have the right ports, for one thing)?
You seem to have a lot of conviction in your position, we'd love to see some of the substance behind it!
Here is what possibly could work:
OP-1f: a tough one to replace but possibly an iPhone + AUM app for multitrack recording and file management + any of the daws such as garageband for recording
Synths / drums apps - probably any, also Koala sampler is pretty solid.
Effects and sequencers would be hard to replicate though, might need an iPad for that (and there you can just use a Samplr app for instance)
Will need a separate audio interface and maybe a microphone though.
OP-Z: an even tougher task, sequencer-wise I’m not sure what’s out there right now, there used to be Modstep, or can try Fugue machine with audiobus
DMX and visuals would be very tricky to do, but can try making a workaround with OSC and Max maybe??
PO-133: probably Koala sampler or Samplr app
The problem with phone apps is that if developer gives up or it’s taken down from app store then you’re SOL. The upside of TE hardware stuff is that it always works (unless some hardware breaks and you need ti look up replacement / repairs)
EDIT: It's an MT6765 (Helios P35). It's got a known BootROM exploit. Won't be long until someone dumps it and cracks it open, though would be hilarious if a part2/part3 dump is just a factory stock ROM.
That said, smart glasses sound like a great idea to me, but I wear glasses all ay long, so I am extremely biased. I don't think most people want to voluntarily wear glasses to just put a computer on their face, so I wouldn't bet on glasses, either. Sorry, Zuck.
You can like and prefer a phone but it’s their raison d’etre.
Society adapts quickly to technology, but, as you say, the tech needs to be good first.
I think we've reached that point with voice recognition and AI assistants. It's now a matter of time until someone connects the pieces into a functional and accessible product.
The reason smartphones are not the devices to get us there is because they're not a good fit for this use case. Pulling out a rectangular slab with a huge screen out of your pocket every time you want to interact with a voice assistant is enough of a UX hurdle that most people won't do it, even if it would be socially acceptable. Even if this was in a watch form factor, which we'll surely see as well, just bringing your arm close to your face would get slightly annoying over time.
So a light pebble device you can pin on your shirt or wear as a necklace seems like a good form factor for this. The Limitless Pendant is another recent contender, and seems like a better thought out product compared to the Humane Pin. These devices aim to be unobtrusive, and disappear into the background, yet still remain deeply integrated into our lives. This is what technology is trending towards. I reckon the smartphones of today will seem primitive in a few decades, replaced by seamless VR/AR in glasses and primarily voice-driven wearable tech. We're currently in this transitional period where companies are investing in high-risk products to see what sticks, but eventually someone will launch something that resonates. Just like Apple did for smartphones in 2007.
I already use siri all the time as I usually have my AirPods in and it works great. That seems like a much more likely device to access our digital assistance than some necklace or pin. Better yet, you could just pair it with your smartwatch and not even need the phone.
I'm still deeply skeptical on voice driven tech as we have had that available and easy to use from various devices for over a decade now and it hasn't taken off for tons of reasons. I just am not going to have a conversation with my computer with others around.
And that's just finding a restaurant. Imagine using voice input to book a flight. I feel sick just thinking about it.
As for input, think about how slow, clunky and imprecise touch typing really is. I'm typing this on my phone right now, and it's still infuriating. And this is after more than 15 years of perfecting this technology. This is just the best it's ever going to get.
Voice recognition OTOH, if it gets to a state where it's 100% reliable, understands all our accents and nuances, in all kinds of environments, then it's not difficult to imagine it becoming the primary input method. And in recent years, LLMs have made generational leaps in this area to the point where this can finally be a competent option.
You won't need to have a list of restaurants read back to you, or have to have long interactions to book a flight or vacation. This is what the Rabbit device is trying to sell, and they at least have the right idea. The AI will have deep knowledge about you, so that just by saying "book me a restaurant tonight", it will make the right decision for you. At least, that's the idea. I think we'll get there eventually, even if the Rabbit is not the device that does it today.
Voice input can definitely function as a primary source of input, but you're always going to need a secondary source as a backup.
Because nobody will realistically wear ear buds for long periods of time. This tech needs to be entirely unobtrusive if the goal is to blend in with our lives 24/7, and we're heading in that direction, for better or worse.
> I'm still deeply skeptical on voice driven tech as we have had that available and easy to use from various devices for over a decade now and it hasn't taken off for tons of reasons.
Voice recognition has only gotten _really_ good in the past couple of years, with the advent of LLMs. E.g. Whisper, etc. This is enough of a generational leap to transform how much we rely on the tech.
> I just am not going to have a conversation with my computer with others around.
Honestly, I can't imagine myself doing that either. But if you think of a scenario where the tech is so good that it understands your intent from short commands, with 100% accuracy, in every type of environment, then it's not so farfetched. Especially once everyone else starts doing it, it will seem as normal as people interacting with screens is today.
I don't think we'll hold long conversations with AI in public, or around others. Just as some people avoid doing that with humans today. But for short interactions like "record this moment", or "remind me to ...", it certainly seems plausible. The device doesn't even need to respond back. It should be reliable enough that you're always sure it understood you.
But we'll certainly hold long conversations with AI in private. For collaboration, companionship, etc. In either scenario, a smartphone or smartwatch are just not the devices that will deliver that experience.
Voice recognition is already really good but people barely use what their devices can already do. For these short interactions you are talking about, our phones can already do this and people rarely use it. Our home assistants can already do much of what you are talking about and uptake has been abysmal because people don't like it.
The smart phone and smartwatch paired with earbuds already does what you are wanting. Hell the HomePod/alexa/google home already do much of what you are taking about and people don’t use it.
Those are outliers, not representations of something most people would do. And even within that population, do they really wear them for 12+ hours straight? While driving, in class, etc.? I doubt it.
The reality is that no gadget that you put inside or over your ear will be as comfortable for long periods of time as something you wear on your clothes, or around your neck. I keep mentioning the word "unobtrusive", but this aspect is critical for mass adoption.
> For these short interactions you are talking about, our phones can already do this and people rarely use it.
The voice recognition accuracy and, more importantly, the actions you can do with it on current gen devices is not generally useful for many people. But this will improve.
I mentioned use cases that I can (poorly) imagine, but once the tech is 100% reliable, there will be many others that we can't think of today. The Rabbit demo seems fake partly because some of these scenarios are far fetched, but there will be a time when it will seem normal. Just like we couldn't imagine what smartphone apps would enable us to do in, say, 2005.
> Our home assistants can already do much of what you are talking about and uptake has been abysmal because people don't like it.
This is another category of devices. A speaker with microphones you put on your desk in one room is not a personal device. And many people, myself included, don't feel comfortable with a device built by a corporation that profits from personal data always listening, but I think that will change as well. And we'll have entirely self-hosted and open source alternatives for the privacy conscious as well.
Though I still think smart speakers, earbuds, smartphones and smartwatches will also see improvements, and become more useful as voice recognition and what it enables us to do becomes better. But these are not personal or unobtrusive enough to become deeply embedded in our daily lives. Wearable tech together with highly accurate voice recognition as an interface to AI assistants that know our preferences on a deep level, and are integrated with many of the same services we use today, sure seems like an improvement over any current gen "smart" gadget.
I frequently wear a single earbud (since I don't really require stereo) for upwards of 4 to 8 hours a day, often forgetting that it's even there. Look up sensory adaptation.
Theoretically, everything the rabbit could do - a self-contained smartwatch could do and unlike the rabbit it wouldn't be an extra "slab" that I have to lug around in addition to my smartphone.
When amongst other people? Maybe I'm behind the times, but it's still rather annoying in my mind. And the younger generations don't really seem to talk on the phone much at all anymore. They just text.
BUT existing phone companies have an incentive to maintain the app-centric world that keeps their app stores profitable, and app companies have an incentive to lock you into their app to keep customer loyalty and be “more than an API”.
All that’s to say, the Rabbit idea of manually scripting against apps to allow “business as usual” for all these individual parties who wouldn’t want to collaborate fills a void that existing players don’t have incentives to fill.
It’s the same reason YouTube and Netflix actively opted out of having their iPads apps work on Vision Pro - platform wars.
So the only real play is to be Apple/Android or try to bypass them by pretending there’s a new product category other than a phone and hope to get some small critical mass there.
I think that part is mostly fine? I'd rather make give a LLM access to https://woob.tech to be my personal assistant while parsing 99% less noise, than have a LLM that parse and understand stupidly complicated web pages, and randomly fail at the task because the name of my doctor is bobby drop tables.
That being said, it can be interesting to use LLMs to assist creating woob plugins.
That's very different from "here's the product we envision and need money to build it."
And just because others have scam demos (including Gemini) that doesn't make it okay. It makes it a race to the bottom (and is why I'm more upset about Gemini because big players are held to higher standards)
The problem is in how they've marketed. If you're taking people's money and giving them an MVP, you need to be upfront about it; if you aren't you're doing a bad thing.
At the very least, I hope products like the Rabbit spur these companies to start innovating again. Even if they are smoke & mirrors, the interest shows there's demand for these features.
Site Note: I've noticed Google Home's voice assistant has declined over time -- it used to handle complex queries and now it can barely understand simple directions. It used to understand me perfectly in the noisiest environments and now it makes many transcribing errors.
Blame app developers for prioritizing implementing less useful features.
Underrated comment.
If it doesn't work how I want, I should be able to sell on whilst keeping the perplexity pro sub.
I'd love to be able to use my phone hands free without having to look at it, and interface with ChatGPT/Claude/whatever but I am not sure if it's possible? Siri works very poorly and is unreliable. I'd like to be able to use an LLM as a personal assistant. Set timers, call people, message people, but also be able to ask questions like the voice chat function in the ChatGPT app. Maybe one day!
an aside : npr doesn't like the 'spade' comment, although I think the explanation is kind of iffy.[0]
[0]: https://www.npr.org/sections/codeswitch/2013/09/19/224183763...
Never encountered a person with one.
Looking at just the concept (and ignoring execution), I don't really see the point of this thing? The whole thing is a feature that could exist on a smartphone. The dream of an AI agent that you can converse with to replace your smartphone could be compelling, but nowhere close to reality yet. Even then, the big smartphone OS companies are obviously better positioned for this. The smartphone is the hub for all your information, plus they have years of voice assistant, automation, and home IoT integration to build off of.
Humane was silly because it was a smartwatch without any of the proper software support, but Rabbit is essentially doing the same but targeting a smartphone replacement. If you really want to break out and try to dethrone smartphone vendors, you'll have to come up with something more compelling than a worse user interface to a poorly made software platform. That's a software feature you're building.
In some sense, I do think Rabbit had a better approach than Humane, though. Getting a bunch of low-priced "toy" devices into the market that are just a frontend to your server software could get you off the ground. The software needs to exist, though...
EDIT:
> But let's call a spade a spade – this is a blatant lie. And we're about to expose it with the first partial release of the source code for its so-called "large action model".
FYI, Text to Action is possible. I personally tested a couple of apps, but I don't think anything reliable exists like we humans.
I would not disregard what they claim is completely false.
But zipped files are super fishy though. What if this repo is spreading malware?
Otherwise this is indistinguishable from a hack. How do I know these zips are secure? The mega and pixeldrain report different sizes. Rabbit is entirely about hype and a scam, how are we supposed to know this isn't the same nefarious ploy?
I appreciate what's being done and think it's good to call out these scams (I've done so myself) but help by building some trust. We understand the need for anonymity but a nefarious actor could just as easily mascaraed as the same repo. And if you do need files downloaded, provide hashes.
(Fwiw, xz, despite recent events, is great at compression and can help you reduce your bandwidth if needed)
zstd level 22 is even better in my experience
2. Why should I have to download text to __read text__?
3. We don't want to normalize unnecessary behavior that is something scammers and bad actors can easily take advantage of.
While I don't believe the leak is nefarious or contains an exploit, normalizing a requirement to download files that can issue exploits -- when there are easy alternatives that make this unnecessary -- just helps create the exact type of environment that scammers thrive in. 3 is incredibly important. If we're going to call out scammers we shouldn't do it in a manner where we're enabling an environment for more scammers to thrive in. Doing what's done here just created a rich opportunity for hackers who can now post a "rabbit source code leak" and just provide people with a different link. Makes for easy picking. Uncompressed and readable code just makes this harder and easier for people to determine if something nefarious is going on.
I agree that it would be nice to have it browsable online, like in a github repo or whatever, but that's a separate issue.
Again, I think you're missing my point
>> normalizing a requirement to download files that can issue exploits -- when there are easy alternatives that make this unnecessary -- just helps create the exact type of environment that scammers thrive in
Yes, it is "normal" and that is exactly the problem.
Ask yourself this
Is there a reasonable alternative?
Is downloading necessary?
I think you'll find that the answer to both is unambiguously "no." I think you'll also recognize that having the readable source __also__ unambiguously creates higher utility.So you don't need to explain to me that this stuff is normal because I already understand that (and am actively demonstrating a knowledge of this). I realize communication isn't always obvious, but if someone is telling you that you're missing the point of what they're saying, please consider that you might actually be missing the point rather than doubling down. Even if you aren't, someone telling you that indicates that somewhere there's a miscommunication, and that needs to be resolved.
I would also like to be able to browse it online, but this is a usability issue for strictly when I'm intending to read it in a browser alone.
As to your final paragraphs referring to communication and me "explainig to you that this stuff is normal", you specifically said that "We don't want to normalize unnecessary behavior" which implies that you do not think it is already normalized. You're also implying that I should have altered my interpretation of your words when you said that I was missing your point, even though you didn't say I was missing your point until the same reply.
In any case, I think I understand your POV regarding archives, and I disagree.
I mean hosting it on any GitHub alternative makes this possible too. We also get better archival because when things change, we can see. Considering this says "Part 1" I expect things to change. History tracking is better for archival.
> you specifically said that "We don't want to normalize unnecessary behavior" which implies that you do not think it is already normalized.
That's not accurate. Here's a counter example "We don't want to normalize clickbait headlines." Clickbait headlines are already normalized, that does not mean we want them to be nor does it mean we should accept them and not fight against them. I'm sure you can find many other similar examples.
Why does a user need to download a file to achieve the goals? Does doing so provide added utility?
Does obscurification provide some benefit?
Does distribution in this manner help normalize environments which scammers take advantage of?
I'd argue: - Don't make users download things they don't have to.
- Serving in plain text gives higher utility as users can view it on any device (e.g. mobile. Am I the only one that reads repos on mobile?)
- A GitHub alternative also provides the capacity to download an archived zip, thus achieving any benefits that aren't obscurification related
- Git helps for better archiving as we can have a track record of commits and changes (this is labeled "Part 1"!)
- Did no one else notice that there are ".github" directories with workflows? But there is no ".git" folder? I'd honestly like that...
- While a zip itself is not an executable and not generally dangerous in of itself, scammers (hackers) do take advantage of such environments. Because you can... change a file extension. Or because a user may double click the zip to extract, but this will cause execution. Or idk, hackers are fucking smart and people are dumb.
I'm a bit peeved that people feel the need to explain to me that a zip isn't nefarious in of itself, because that's not what I was concerned with (and that there's several such comments and we don't need to keep repeating the same comment...). My concern is with how such formatting is (as best as I can tell) not necessary, suboptimal, and normalizes practices that nefarious actors take advantage of. This topic is obviously hot, so I won't be surprised if there are "alternative links" that could just contain straight up maleware. Yeah, the user has to execute it, but people are dumb, lazy, and/or tired and there is a *better* form of distribution that just doesn't leave this script-kiddy style attack around. Like for fuck's sake, people at intelligence agencies plug in USBs they find on the ground... $ md5sum lam.zip
3a78b14e1379ac5c059dbbe5660fca8a lam.zipScams take advantage of what is normalized, it is how they fly under the radar and bypass people's bullshit detectors. It's why a safety vest, hardhat, and a clipboard is the most covert disguise around. So one of the best ways to prevent scams is to normalize behavior that is harder to take advantage of! (same reason people fall for fake voice scams, because we're so used to distortion in calls anyways. A glitch poor voice can be difficult to distinguish from poor cell reception)
As for the filesizes, I assume it is just the websites reporting incorrectly. Pixeldrain reports 188 MB compressed and 510 MB uncompressed. Mega reports 179.r MB. Pixeldrain at least shows all the files, which look to not have been cleaned up since they have things like .DS_Store. But at least the files are individually downloadable.
Zip files aren't evil, just unzip them and look inside.
The point of the comment and request is about not requiring technical knowledge and minimizing amount of necessary thinking. The point is about helping stop scammers in the first place!
> 179 MB if a megabyte is 1024^2 bytes, 188MB if it's 1000^2.
This is not entirely correct though because MB != MiB. Us on HN will probably know this but proper labeling helps prevent mistakes. The improper labeling requires us to think more when considering security, which is bad security (not that you shouldn't think, but I'm saying "don't set off alarms when you don't need to set off alarms")
The point the parent was making is that the file is 188026773 bytes long. One site represents that as 179 MB (base 1024) and the other one as 188 MB (base 1000). Your complaint is therefore with one of the websites and not with the uploader.
That particular issue, yes. But that wasn't the main issue. I guess you're right, I could have clarified that I'm aware that the uploader is not in charge of the label and it was naive of me to presume that this was obvious. I should have explicitly stated such rather than let it be implicitly said.
The question here is "is there a reasonable alternative that doesn't require the user to download." The answer is unambiguously "yes" and unambiguously has higher utility.
Could set back the AI device hype 5 years back after Humane getting exposed as another scam.
"Large Action Model"
so if I pump out enough advertising, you're going to give me the usernames, passwords, and active sessions for your accounts to me?
I need to log out of this thread asap. I thought the defenses of Ai Pin were going to drive me nuts, I need to preserve some sanity. Has everyone lost their minds? Are tons of people here working for equally scummy, shoddy, if not scammy, startups? Seriously, what the hell.
You give all of those to every smartphone maker. Why is this any different? Is there evidence that their handling is insecure?
If I found that Android built in some Spotify integration that worked by stealing my active session cookies to do some backdoor integration with it, and billed it as some future AI smart service, I'd find it equally g-d absurd, yes.
Do I think that me logging into the Spotify app, in Android, and it exchanging those credentials for an app-internal access token is the same as a server hijacking my session? No, not really, I don't.
That's what's so damn brazen and shoddy about this. SPOTIFY HAS OAUTH.
I mean this in all seriousness, have you used Oauth with google/facebook or the like to login and register with online services? Why not? Have you put passwords into a password manager? Why?
Did you give Uber or Lift your credit card number? What if they were a scam?
I say this also thinking rabbit R1 is a pointless product that based on hype that nobody should buy. However, I can see why people might think it reasonable to give their AI assistant a bunch of personal information. For the same reason people have trusted google with health data.
No, I don't use federated login anywhere. I can show you my Google account. The only place I've compromised is Tailscale, and I plan to replace that imminently. And frankly I consider it lazy of them to not support email, especially since google.com accounts are single-tenant anyway. And tailscale never sees my password, never has raw access to my entire damn account, etc, etc.
Also, besides, federated login or delegated access, sure, OAuth is great, I wouldn't have commented in this thread if they were using it. Typing my raw creds into a [redacted] VNC session is not comparable.
>Did you give Uber or Lift your credit card number? What if they were a scam?
I call my credit card company. They reverse the charge, and ding the merchant. My life goes on. Takes a shockingly small amount of time.