HNHacker News
TopNewBestAskShowJobs

DannyBee

31,441 karma · joined June 21, 2011

Xoogler just enjoying life for a while after a long time in tech. I'm also an open source lawyer.

If there is anything i can help you with, feel free to poke me.

submissionscomments
DannyBee··on Solving Factorio Quality
I've had a lot of fun with stuff like this - beyond solvers for Satisfactory/DSP/etc using ILP, i've also made automatic blueprint creators for DSP, Factorio, and Satisfactory - give it a factoriolab URL, it will create a usable blueprint for it (pasteable where the games allow it, copyable where they don't)

Interestingly different - for DSP and Factorio it suffices to do legality using CP-SAT based packing and then routing separately (geometric line routing/etc). Large blueprints in DSP are complicated and sometimes require hierarchical decomposition.

Satisfactory is actually much more complicated not just because of the significantly more 3d nature, but because of the blueprint designer size limitations and the desire to not just have things clipping through other things everywhere (which the game allows for the most part but people try to avoid).

DannyBee··on Early rogue AI agent activity and attempts to hack found on urlquery.net
This is a very different argument?

You provided a table and argued that it showed that states commonly do strict liability for animals "in many cases"

The table shows no such thing.

Now your argument is, apparently, that strict liability does exist in criminal law, and should exist in criminal law, something i have never argued is either false or bad.

I've only argued strict liability for felonies, and particularly this felony, is a bad idea.

Something I stand by.

DannyBee··on Early rogue AI agent activity and attempts to hack found on urlquery.net
Almost all state laws based on the CFAA, including this one, similarly require either knowingly doing it or some other form of specific intent. At least at a glance. If there is a specific part you think does not, I’m happy to look at it, but I’ve read a lot of pages of law to respond to people so far, and I’d like to avoid reading another 25 if I can avoid it.

It does not require the federal government to fix the CFAA, for sure, but you still have to change the intent requirement to allow for recklessness, which it does not right now afaict.

If you really want an expert opinion, I’m sure Orin Kerr has opined on this, and he knows pretty much the entire are of state and federal law on this cold. I’d be shocked if he did not reach the same conclusion

DannyBee··on Early rogue AI agent activity and attempts to hack found on urlquery.net
Yes, which is why I said it happens but is quite rare. I also said murder is different. Causing death is usually covered in almost any way and intent you can think of. Anything less than death is not.
DannyBee··on Early rogue AI agent activity and attempts to hack found on urlquery.net
This table is almost all civil liability afaict. I didn’t click on every statute, but I clicked on 15 of them and every single one was civil.

As I said, strict liability is common civilly but not criminally.

DannyBee··on Early rogue AI agent activity and attempts to hack found on urlquery.net
"Why do we have to attribute intentionally to a human. "

Because you are charging the human with the crime and therefore have to prove the elements of the crime with regard to the human.

The rest of what you talk about are basically principal/agent distinctions, etc.

If I program a car to recognize people who look like my ex-wife and drive them off a cliff or whatever, that is my intent, and I have still committed murder, even though i used an agent/car to do it. Agents acting on my behalf that do things are able to get me charged with crimes, but I still have to have the intent to do the act that is illegal.

I phrase it this way because minimum required intent is usually for the act, not the result. So I don't have to intend to kill someone, only intend to drive them off cliffs.

In this case, if i intend to hack someone and use an agent to do so, that would be criminal under the CFAA. You are simply trying to cover the case where that isn't the intent, but the result, and they "should have known" that would result. As mentioned, this kind of "should have known" is generally a civil law approach, not a criminal law one.

The closest you come within criminal law to what you want is probably the crime of conspiracy. It to still requires agreement to commit an illegal act between multiple parties, and perform some step in furthering it. In the canonical law school example: If i help plan a bank robbery, stay home because i'm the money laundering dude, and the robbery goes awry and they kill someone, i can still be charged with conspiracy-murder

"The law is clear on establishing strict liability for the owners of wild animals; if you own a tiger and it kills someone you can’t hide behind “I didn’t intend” the harm the nature of the tiger is known and you are responsible for it’s actions."

Again, you are confusing civil and criminal liability. If my tiger kills someone, yes, i would be strictly liable just about everywhere civilly. Not criminally. Criminal would require something more most of the time. Murder/manslaughter statutes are also really weird and so not a great example, because there are murder/manslaughter statutes for roughly everything that can ever possible cause death. But not really for other things.

So in your tiger example, recklesness (which is not strict liability) would get you to felony involuntary manslaughter in most states, and something less might get you to misdemeanor manslaughter. Both are incredibly rare. Where i live (Georgia), the last well known case of felony involuntary manslaughter was about 40 years ago when a 4 year old was killed by 3 super-aggressive pitbulls the owner knew were highly dangerous and had been repeatedly warned by the county about their behavior.

So not even just "knew", but had demonstrable examples of them biting/etc other folks and being cited for it.

Circling back to non-murder, if it did not cause death, like my tiger assaulting someone, it would be nothing (criminally) without intent or at least gross recklessness, in almost all cases. It's hard to generalize like this because these are state specific crimes, and i can't pretend to be familiar with all states, but i am licensed in three very different places (California, DC, Maryland) and the result would be similar in each.

I just don't want to give you the "it depends" answer lawyers are famous for, i'd rather try to over-generalize a bit to make it more useful, hopefully.

Obviously, if i deliberately used my tiger as a weapon, it would be aggravated assault/etc (this is well settled because of how commonly people use animals as weapons, unfortunately)

DannyBee··on Early rogue AI agent activity and attempts to hack found on urlquery.net
Lawyer here: No. Not criminally. Knowledge that a certain result is likely is not the same as intent to cause the result. This is basically the difference between recklessness and intentionality. Doing something when you know of a likely result is reckless, but not intentional. Only doing something, trying to cause a result (likely or not) is intentional. In this case, the CFAA only covers intentional access without authorization, not reckless access without authorization.
DannyBee··on Early rogue AI agent activity and attempts to hack found on urlquery.net
Lawyer here: CFAA is mostly criminal statute not a civil one (civil damages require proving more than a violation so also require specific intent)

Almost all common felonies require specific intent. Misdemeanors often do not.

There is plenty of civil liability available.

If you wanted them to be charged with a felony you would need changes. I would strongly suggest you do not want a strict liability felony.

The cfaa required intent is as follows :

* § 1030(a)(5)(A): knowingly transmits code/commands and intentionally causes damage without authorization.

* § 1030(a)(5)(B): intentionally accesses without authorization and recklessly causes damage.

* § 1030(a)(5)(C): intentionally accesses without authorization and causes damage and loss;

Simply changing the first intentionally to intentionally or recklessly would cover OpenAI (now that they know it can occur) without causing lots of other issues. Without that, they don’t have the intentionality necessary to meet the first part, even if they would otherwise meet the second part

DannyBee··on Automated optimization of a molecular simulation program
(I posted a response on their blog but i'll repeat it here for those curious).

When it comes to eliminating subexpressions, they say:

"This is to be expected; ultimately, the algorithm is a simple greedy algorithm, which often doesn’t have the best track record with this sort of optimization problem. Trying to minimize the number of floating point operations required for the polynomial calculation is also likely an NP-hard problem, so any algorithm that actually solved this problem would be even slower than the one we came up with. "

It depends on what you mean -

1. Finding syntatically common subexpressions is linear or n log n depending how you do it

2. Eliminating the maximum possible existing value-equivalent subexpressions is polynomial.

3. Finding the smallest possible set of operations or instructions to evaluate a set of expressions is provably NP-complete (as a decision problem).

The difference between #2 and #3 is #2 is restricted to results already computed somewhere in the program (even as a subexpression), as well as canonical reordering of expression trees to expose as many of these as possible. #3 is not limited in this way. In all cases, you have to restrict to herbrand equivalence if you want it to not run into undecidability issues, at least as trying to prove things go. In practice, all compilers go beyond herbrand equivalence in specific cases to deal with common value identities (IE x+0 = x).

DannyBee··on Looking forward to Git 2.56 – and 3.0
Yes. Structure comes in many forms. In this case, Shor is turning the function into a strongly periodic algebraic structure.

I'll explain it without going too far into why any of this is true, which is much more complicated to prove. This will let me use relatively simple math.

Let's say you want to factor N. Pick some number that is coprime to N, which we'll call a, and consider f(x) = a^x (mod N).

Since it's a modular function, it repeats at some point. Shor calculates the period of this function (r), rather than seeing which of the 2^n numbers is "the answer".

Once you know the period of this function, there is a high chance that the factors fall out of gcd(a^(r/2) - 1, N) and gcd(a^(r/2)+1, N).

The point here is not to explain Shor's as much as to point out it is finding a strong amount of structure to take advantage of, quantumly.

This is actually the same way the oracle separation of BQP and the entire polynomial hiearchy works[1] - It depends on forrelation, which is a problem where quantum computers can extract a global property of the function without needing to learn all the individual values, by taking advantage of structure.

Which is why i go to "The idea that there is literally no structure that can be taken advantage of in AES strikes me as a bad bet".

In part because it's already false if you go literature searching. For example, https://www.sciencedirect.com/science/article/abs/pii/S00200...

There are already reduced round quantum attacks on AES as well. Again, more to the point, the idea that symmetric key ciphers and cryptographic hashes in general are safe because grover's is slower than shor's is not a thing i would bet on at all. Even if AES ends up relatively safe, that tells you basically nothing about the other practically-used ciphers and functions since there are a lot of different construction mechanisms being used.

[1] People still seem to believe there are no functions which quantum computing models have been been proven to be faster at than classical computing models. This is false. Forrelation is the canonical example - and shows that BQP can perform things exponentially faster than you can classically even given access to an infinite polynomial hierarchy.

It is the current physical actualization of these computing models that have the "is it really faster than classical computers" issue, not the theory ;)

(IE it is a perfect example of "in theory there is no difference between theory and practice, and in practice, there is")

DannyBee··on Looking forward to Git 2.56 – and 3.0
No. Not quite. In fact, that blog post ignores something important from the very papers it cites.

Grover's assumes the function is a black box that you cannot look inside and that your only way of finding a certain result is through repeated invocation.

Under this assumption, Grover's is optimal in the number of invocations of the function required to find the result.

However, this assumption may be quite wrong for AES and friends. It may be the structure allows for non brute force attacks that are totally impractical classically but not subject to Grover's optimality limitation quantumly.

The only thing you are guaranteed here is that if you cannot take advantage of structure at all then Grover's is the best you can do.

Given that we have pretty much always found a way to take some advantage of structure, I would bet we will do so here.

That may or may not make it viable to break at all, I just wouldn't bet that it must be treated like a black box forever.

To me that would be a very bad bet.

DannyBee··on Spymarks, not Watermarks
Apples largest area of growth is literally services and advertising. They even make a huge deal of it in their investor calls. Have for at least the past 3 years.

I think you may have an outdated view here

DannyBee··on Bend 2 and the Vibe-Coding Trap
"This example matters beyond Bend, vibe-coding makes it makes it far too easy to implement a design that’s horribly broken or decades behind the current state of the art because you can immediately get a result without ever having to do any research."

This is totally true but almost totally irrelevant. I'll use some hyperbole here to make the point: Whether the design is broken or decades behind doesn't matter anymore. Neither of those are an outcome/end goal. They are means we historically have used to achieve good end goals or outcomes.

In the end, the goal is usually "does it meet the needs of the person who needed it" not "is it good software". If it no longer meets their needs and they can vibe code another total piece of shit in an hour that meets their needs again, they still may be "better off" than spending time researching the field and learning and ...

This may feel shitty, and it may feel like it should not be true. But right now, that seems to be true?

In that sense, the author is wrong that vibe-coding is a trap. The trap is assuming you have to make something good to meet someone's needs both now, and in the future.

Now, like i said, this is hyperbole, and there are lots of good arguments against it. The author's just isn't one.

Technically good or better has never mattered very much in the marketplace, despite people wanting it to really badly (ease of use often mattered, but not technical goodness). Software engineers often took pride in their work and so there were usually kernels of goodness in even the shittiest software. All you are seeing is that now it is nowhere near as hard to create and bring these "solutions" to market, and more importantly, doesn't necessarily require anyone who has any pride in their work at all, or even have any experience in software engineering. As such, technical goodness has mostly gone out the window because the market never required or really rewarded it.

DannyBee··on Astra for Law
Yeah, this matches my friends - they use LLM's for tons of things, using Eve and such. But nobody is replacing the lawyers themselves in cases of any value.

I also have friends in the world of high-volume personal injury (IE the morgan and morgan's of the world) but they also aren't being replaced by LLMs so far.

DannyBee··on Astra for Law
Lawyer here (non practicing so to be clear none of this affects me):

most comments I read here don't seem to realize that different areas of law have very very different economic models and don't even mention which one they think will be affected or why, they just sort of lump it all together.

For example: It is highly unlikely llms will have any meaningful effect on high value personal injury law - I don't see a 5 million dollar case being handed to an LLM when the majority of the cost is in trial aids and not even lawyers. It may affect where and how they advertise. It may affect how they work. But it seems really unlikely to put any of them out of business any time soon by people doing it themselves.

Will it affect other areas more? Maybe. Probably? But so far I haven't seen a ton of comments that make specific enough arguments that they could really be debated or responded to effectively with a useful opinion

DannyBee··on Resist "AI"
I guess i'll give a super-unpopular take.

Listening to developers complain about AI doing things to their life and the world at large when they have spent the past 30 years automating just about everyone else they could out of a job (Since this has been one of the primary uses of software) is ... something else. It sounds like a a a mix of hubris, arrogance, cognitive dissonance, ignorance, etc.

Only when it started to affect their world did any developers start to care, and even then nobody seems to ever stop and say "hey what were we doing the past 30 years, maybe we should think about this", it's instead "hey look at what these other people are doing with AI, someone should think about this".

It feels like, to paraphrase a movie quote - "Nobody gets to destroy jobs and the the world but us"

DannyBee··on GrapheneOS says Pixel 11 has MTE support after all
This is all true but it also is true that MTE was in part built to accelerate address sanitizer.

Kostya/et al who pushed for and designed the extension, was trying to accelerate address sanitizer so it could be on all the time. Among other things.

In fact, most presentations presented it literally as a way to do hardware accelerated ASAN (again, among other things), so the post you responded to is correct in that sense.

(I was there at the time, helping him figure out how to push for it)

DannyBee··on Apple caught off guard by AI demand for Mac Mini and Mac Studio
It's also fun to see how many people here believed this was all some clear deliberate strategy in the first place rather than an accident.
DannyBee··on 9th Circuit sides with states in Kalshi gambling fight
Thankfully, the CFTC can't actually order Kalshi to continue operating in NY despite being in violation of NY law. They have no authority to override any judge's order/etc, and at least so far, have not pretended they do.

As for me, i've never pretended it's either normal or desired for the courts to make policy, whether congress is dysfunctional or not. Among other things. My comment was basically pointing out that the current supreme court seems perfectly willing to throw out decades of settled law on an ideological whim, and actually, for that matter, happily interpret very clear congressional statutes in very odd ways.

So your comment there is mistargeted, at least as applied to me.

DannyBee··on 9th Circuit sides with states in Kalshi gambling fight
Lawyer here - As i explained last time we had a variant of this thread (see comment history if you are interested), this is a very complicated area that people try to make very simple.

It doesn't have to be complicated, mind you, but right now the way the law is written is basically:

1. Transmitting sports betting info between states is a federal crime unless it's legal in both states (18 U.S.C. § 1084(a))

2. The CEA regulations ban contracts that are illegal under state law (17 CFR 40.11)

3. Other forms of gambling/betting/contracts that are not sports are generally a-ok.

4. This is not a case of first impression, it's just getting relitigated because Kalshi doesn't want to follow the actual law. This has actually been pretty settled law for a long time, with new flareups maybe once a decade. Kalshi is just hoping to be treated like Uber was.

The third circuit's decision is pretty clearly "out there" in terms of existing caselaw.

However, this will end up at SCOTUS, and everything until then just doesn't matter. That will be a coin flip even though it shouldn't be

DannyBee··on Judge rules Trump administration’s blacklisting of Anthropic was illegal
The opinion is quite straightforward, and the evidence on the government's side was entirely nonsense, essentially.

https://storage.courtlistener.com/recap/gov.uscourts.cand.46...

DannyBee··on Mold: A Massively Parallel Linker
Absolutely. Rui is awesome. He's always been awesome. I was his director and then vp for a long time (also replaced by awesome people, thankfully). The day he left to make a go of mold and such I was sad for us and super excited for him.
DannyBee··on I were 17, I'd learn how to build LLMs from scratch
I get this is basically advice for young founders and entrepreneurs, but i would ignore that request and encourage 17 year olds to spend time trying to find a happy medium between work and life.

Being a super rich and an unhappy workaholic, or a super-impressive engineer who wakes up one day at 45 and realizes they regret wasting half their life (I ran into way too many of these) is a much worse fate than "not being rich from your startup" and working a relatively regular job while feeling fulfilled and happy by more than just work.

Especially in the US, which is uniquely bad at this and encourages people to work themselves to death, mental health and work life balance are much more valuable things for 17 year olds to focus on than finding good startup ideas.

In case you think i'm being a bit dramatic, let's look at the state of 17 year old mental health in the heart of Silicon Valley:

"The City of Palo Alto and the Palo Alto Unified School District approved a funded contract to place 24/7 human security guards and monitors at all four local Caltrain grade crossings, including the Churchill Avenue crossing directly adjacent to Palo Alto High School."

(in case it's not obvious, it's because of suicides by high school students)

The 17 year olds do not need advice on better startups, and this situation will never get better if we focus our advice on how to be better at work instead of how to be better at life. This will require redirecting the conversations.

DannyBee··on Feature Request: Support AGENTS.md
Read does, but it rarely uses it.

Part of the reason i assume is that to extract 5 line ranges is a single line very small sed call that it has to output, but 5 separate full read calls it has to output correctly and quickly.

Who knows.

DannyBee··on Feature Request: Support AGENTS.md
If i'm trying to steel-man why, I presume because the read/write/edit tools use more context tokens because they don't support reading part of a file/etc.

So the agent is going to put less into context when it uses sed to see 15 lines of a file than using read and putting the entire file into context.

That is my best charitable guess at what they are hoping to achieve.

Of course, there is an obvious set of solutions for this problem that don't involve pushing the agent to use bash.

DannyBee··on Feature Request: Support AGENTS.md
So many developer-hostile things lately.

Just a few days ago they turned on an experiment the forces claude code to use bash over standard tools in auto mode.

From the system prompt directly, new as of August 18th:

  Do your work through the Bash tool wherever it can accomplish the job: read files with cat, head, or sed -n, search with grep and find, and make file changes with sed, heredocs, or short scripts, rather than using the dedicated Read, Edit, or Write tools. Fall back to a dedicated tool only when Bash genuinely cannot do the job.

I was wondering why Claude Code started ignoring my LSP tools and such a couple days ago, and this is why. Prompting around it (even with CLAUDE.md) results in low adherence. This can be turned off by setting a special environment variable (setting CLAUDE_CODE_THRIFTY_SONIC to 0), but this is just a bad idea all around.

I'm sure they'll argue they are trying to make it use less context tokens to do things, but if this is the best they could think of, ....

This is of course, also not documented anywhere, as is typical for anthropic, you just have to guess whether you are going crazy or if they changed stuff seriously on you under the covers.

This was the last straw for me. Their harness (models are fine) was already falling well behind the other one i use (OMP) in the past 6 months in usability/etc, and they are the only ones who don't allow me to use other harnesses with my subscription.

So I've now stopped using claude code entirely. Unless something changes, i'll drop my max plan when it expires next month.

DannyBee··on CFTC declares market emergency, orders Kalshi to continue to operate in New York
https://ag.ny.gov/sites/default/files/court-filings/new-york...

See page 29

DannyBee··on CFTC declares market emergency, orders Kalshi to continue to operate in New York
These are the CFTC licensed contract markets, which are not the same exact thing.

I'm not sure how to explain all this without writing a 70 page dissertation on HN, and it's probably not worth it :)

Overall - this is a wildly complicated area. To give you an idea how complicated: Ignoring state law, transmitting gambling information for sports events over the wire is a federal crime. See 18 U.S.C. § 1084(a), which makes it a crime for a person “engaged in the business of betting or wagering” knowingly to use an interstate or foreign wire facility to transmit bets/wagers or information assisting bets/wagers “on any sporting event or contest.”

(It's legal if you are transmitting from a jurisdiction where it's legal to a jurisdiction where it's legal).

This has been upheld repeatedly for sporting events.

New york can, and did, include a claim to enjoing them from violating this act, which has absolutely no pre-emption issue because it's not a state law.

The case you cited is going to end up in the supreme court, where it will be a toss up. (in previous supreme courts, it would be a non-starter and the third circuit would have been summarily reversed)

DannyBee··on CFTC declares market emergency, orders Kalshi to continue to operate in New York
Oh worse than that.

The "emergency powers" they speak of are 7 U.S.C. § 12a(9), and they are quite specific.

It gives them the authority to direct a registered entity to do a few specific things. None of those things are relevant to here. It's stuff like emergency margin requirements, position limits, etc. Not "violate state law". It gives them no power to enable a registered entity to violate a TRO, or anything like that. Such a power would have to come through pre-emption.

The CEA gives them zero authority to preempt state law directly, and any pre-emption would have to be argued to already have occurred under the Commodity Exchange Act. They'll argue it occurs because of their order, but it actually doesn't meet the requirements to do that, so then they'll argue the CEA preempts state law.

As you may imagine, this has been argued about before, for a very very very long time.

Gambling is core state police power, and has been found so many times. As such, presumptions against pre-emption would apply, etc. Even in the current court that ignores precedent, using an esoteric made-for-specific-situations emergency power statute like this one would to preempt new york/etc (this is not the only case) law would run clearly afoul of the so-called major questions doctrine.

Lastly, the current CEA regulations actually ban event contracts that are unlawful under state law (17 CFR 40.11):

https://www.law.cornell.edu/cfr/text/17/40.11

Prohibition. A registered entity shall not list for trading or accept for clearing on or through the registered entity any of the following: ...

1. (1) An agreement, contract, transaction, or swap ... that involves, relates to, or references terrorism, assassination, war, gaming, or an activity that is unlawful under any State or Federal law;

So trying to pre-empt state law when the existing regulations clearly don't allow event contracts that are disallowed under state law is ... not likely to succeed.

Also note that New York has claimed a violation of the wire act in there, and in particular 18 U.S.C. § 1084(a). This is a federal statute that makes it illegal to transmit sports betting information over the wire (it's okay if it's from a jurisdiction where it's legal to a jurisdiction where it's legal). They have asked the court to enjoin them from violating this. This claim is here because it avoids all the pre-emption issues - it's a federal statute. So New York is also hedging their bets on the state preemption issue.

All that said, there is also a CFTC-designated contract market that Kalshi operates, and that they could likely exercise significantly more power over, and New York can order them around less on. But that is likely to end up in the supreme court, and harder to predict. Any other court the answer would be clear - congress doesn't have the authority to regulate purely intra-state gambling, etc.

DannyBee··on CFTC declares market emergency, orders Kalshi to continue to operate in New York
Except they haven't, because they did not request national relief. They requested state-specific relief.
Page 1 of 34Next →