HNHacker News
TopNewBestAskShowJobs

Edmond

2,183 karma · joined August 1, 2008

Working on Certisfy (Certisfy.com)

To reach me use ekemokai with gmail.com

ID Proof:

https://certisfy.com/app#PNTWT1

Private Messaging:

https://certisfy.com/app#enc-b58536f1e5fd376decbfa75b6c0c817463759a56

submissionscomments
Edmond··on Biomni: A General-Purpose Biomedical AI Agent
This is nice, a lot of possibilities regarding AI use for scientific research.

There is also the possibility of building intelligent workspaces that could prove useful in aiding scientific research:

https://news.ycombinator.com/item?id=44509078

Edmond··on Build and Host AI-Powered Apps with Claude – No Deployment Needed
We've learned this the hard way working with AI models, yelling at the models just doesn't work:)

I would think someone working for Anthropic would be quite aware of this too.

Either fix the prompt until it behaves consistently, or add conventional logic to ensure desired orchestration.

Edmond··on Build and Host AI-Powered Apps with Claude – No Deployment Needed
Another approach is to work towards seamless integration of human + bot collaboration:

https://news.ycombinator.com/item?id=44380745

Basically the bot shows the human the right UI at the right time as they work.

Edmond··on Show HN: AI Baby Monitor – local Video-LLM that beeps when safety rules break
try Watchman: https://news.ycombinator.com/item?id=44087499

I am the developer and happy to answer questions.

You can basically setup your own instructions and setup you own observation solutions...you can imagine everything from security to farm operations, the sky's the limit.

Edmond··on Show HN: AI Baby Monitor – local Video-LLM that beeps when safety rules break
What about the AI playground monitor?:

https://news.ycombinator.com/item?id=44087499

I am the developer :)

That is a demo of course but I think what sets LLM tools like this apart from what came before is that implemented correctly, the user gets to decide what it is, and can change the meaning at any time, in other words what it should be looking for at any time.

That is of course if the solution is implementation correctly.

There is immense potential for these type of capabilities if they are done in a way that leaves the specific use case implementation up to users.

Edmond··on A new form of verification on Bluesky
For folks interested in a PKI certificate based approach to solving verification problems:

https://news.ycombinator.com/item?id=40298552#40298804

Delegation similar to bluesky's "NYT org issues certs to journalist" is also possible and done in a far more versatile manner.

If you have a domain and want the ability to issue certs to others, email me...this will just be for experimenting of course :)

Edmond··on Discord's face scanning age checks 'start of a bigger shift'
Each trust anchor gets issued a single certificate that can have delegation ability, ie the ability to issue new trust anchor certs to others.

So if say a UPS store is issued a cert and they go rogue, we can just revoke the trust anchor cert that was issued to the store, all certs issued further down are also automatically revoked...the revocation check is done either in the app or in the case of a third-party performing the verification they will recognize that there is a cert on the issuing chain that is revoked and reject the cert.

This is how TLS certs are handled too, if a CA goes rogue, all certs issued by that CA are revoked once the CA's root cert is revoked.

As for refund issues, that's a problem for the cert issuer to deal with.

Edmond··on Discord's face scanning age checks 'start of a bigger shift'
This video addresses that:

https://youtu.be/92gu4mxHmTY

All certificates are cryptographically linked to an identity-anchor certificate, meaning buying a certificate would require the seller reveal the private key tied to the identity-anchor certificate, a tall order I would argue.

In the case of stolen identity certificates, they can be revoked thus making their illegitimate utility limited.

Edmond··on Discord's face scanning age checks 'start of a bigger shift'
The app allows for self-revocation using the private key or a revocation code given when cert is issued, this is useful if a certificate is compromised...there is also an admin interface a trust anchor can use to revoke certificates they issue, a rogue trust anchor chain can also be revoked.
Edmond··on Discord's face scanning age checks 'start of a bigger shift'
https://certisfy.com/partnership/

Any number of entities can be certificate issuers, as long as they can be deemed sufficiently trustworthy. Schools, places of worship, police, notary, employers...they can all play the role of trust anchor.

Edmond··on Discord's face scanning age checks 'start of a bigger shift'
There is a solution and I am the developer:

https://news.ycombinator.com/item?id=40298552#40298804

Talking about it or explaining it is like pulling teeth; generally just a thorough misunderstanding of the notion....even though cryptographic certificates make the modern internet possible.

Edmond··on Chat is a bad UI pattern for development tools
This is about relying on requirements type documents to drive AI based software development, I believe this will be ultimately integrated into all the AI-dev tools, if not so already. It is really just additional context.

Here is an example of our approach:

https://blog.codesolvent.com/2024/11/building-youtube-video-...

We are also using the requirements to build a checklist, the AI generates the checklist from the requirements document, which then serves as context that can be used for further instructions.

Here's a demo:

https://youtu.be/NjYbhZjj7o8?si=XPhivIZz3fgKFK8B

Edmond··on Generative AI Scripting
For folks who would prefer a more "full bodied" experience, we offer a UI configuration based alternative approach that supports JavaScript and Groovy, including an IDE environment integration.

demo: https://youtu.be/XlO4KhIGd0A https://youtu.be/cs5cbxDClbM

Edmond··on Analysis of unicorn startup founders
Intriguing product, definitely something that is a major pain point for inventors.

I do wonder however, I see a couple of the profiles listed show 500+ patents.

Does this indicate that we are now in an era of full fledged "IP spam" or can you argue that inventors have in fact historically been under-rewarded by the difficulty of filing patents? Otherwise that is a lot of patents for someone who isn't building a spacecraft :)

Edmond··on JRuby funding at Red Hat stopped – call for sponsors
I am the developer of Solvent, it is a polyglot web app platform for the JVM and has long supported JRuby integration as indicated here: https://codesolvent.com/web-apps/

I am not a ruby developer and even though I integrated it don't know anything about its internals. I am guessing if JRuby goes away GraalVM which supports Ruby will be its replacement?

Edmond··on ChatGPT is hallucinating fake links to its news partners' biggest investigations
This seems a result of relying on the LLM to accurately extract information that needs to be exact.

I touch on this from my own experience: https://youtu.be/cs5cbxDClbM?si=IQIFAD38cVzLCs55&t=486

Basically if you have the actual "factual" information, use it directly instead of hoping the LLM will accurately extract it and use it as part of a function call. In this case they already know what the accurate URLs are, just use it.

Edmond··on Minimalistic Beat Maker
now combine it with this: https://string.spiel.com/ :)
Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
Do note that the reference here to CA is a conceptual reference, in other words it refers to a trusted entity who can verify certain bits of information (like your age or identity) then issue certificates for it, "trust anchor" is the lingo Certisfy uses for CAs.

Hostnames are what TLS certificate CAs such as DigiCert verify ownership of then issue certificates for; the same concept can be applied to any kind of information, including private information.

For instance a state DMV could choose to be a Certisfy "trust anchor"/CA and issue you a cryptographic certificate for your driver's license to be used for IRL identity anchoring.

So no, a "trust anchor"/CA need not be a big tech company, in fact if such a concept is deployed at scale a large class of entities can/should play the role of "CA", including people doing it as part of a business service.

Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
I missed your concern about pure anonymity in the whole process, the answer is NO.

You can't have such a system that is totally anonymous, it is private but not anonymous. This means it is largely anonymous but for instance law enforcement might be able to track you down...I happen to think this is a good balance though I am sure not every one agrees.

Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
The QR code is just a convenience feature. If you look at the sticker you see a short alpha numeric code, that's what's on the QR Code.

You can type that alpha numeric code into the Certisfy app to verify the sticker: https://certisfy.com/app/

You'll probably never use a social security certificate directly, it will be used as a IRL "identity anchor" certificate as described here: https://cipheredtrust.com/doc/#pki-id-anchoring

Yes a fraudster will happily take a stolen card but it will be of no use to them if they try to use it via Stripe for instance to post a charge but Stripe requires a cryptographic signature for a certificate for the card :)

So sure the card processor has to require the signatures to make it effective. In other words the secrecy of the card number becomes irrelevant if it requires a certificate signature before it can be used, only the owner of the card has the private key on their device to generate the signature. Secrecy is still useful for privacy.

Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
Yes if you lose your keys you do have to get new certificates and if possible revoke the lost keys. Revoking certificates will require either a revocation code that is issued when you get the certificate or you can use a copy of your private key to issue a revocation request.

If you don't have a revocation code or a private key for the cert you wish to revoke, it will require administrative access to the certificate registry to mark the cert as revoked. That feature is currently built into the platform but not something accessible because of the obvious challenges.

Your private keys are only known to you, certificate revocation is just an annotation that says to someone who receives a signature associated with that certificate to not trust the certificate.

All private keys are generated and stored only on your device.

Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
I very much understand the roles of CAs :)
Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
The CAs being centralized is not a problem. They do the verification and issue the certificate. The privacy concern stems from using the certificate and CAs are not involved in that process.

Yes you do have to trust someone and the CA is the trusted entity for doing the verification, but once they do the verification and in effect encode that verification onto a certificate, their role is done.

Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
>So doesn't that mean the identity provider (trust anchor?) who verified the age now has a list of which sites you're using your certs on sinc eyou must define a reciever (recipient domain?)? Maybe you can explain the flow in an example?

When a trust anchor does verification and issue you the certificate, you get a PEM file, their connection to the process is done. Yes they know who you are but can't track what you do with the certificate after they issue it to you.

On the other hand if you were to use that certificate to commit a crime, the signature will provide access to the trust chain, thus law enforcement could use it to find you by reaching out to the issuer. This is a feature not a bug, it combines privacy and accountability, no different from conventional non-digital world expectations.

The use of receiver id, happens after you have the certificate, the issuer is not involved. The receiver id is for the benefit of the receivers of signatures from your certificate, it allows them establish a sticky anonymous cryptographic identity for you without knowing who you are, this is a way again to have privacy while having accountability. This demo touches on the approach: https://www.youtube.com/watch?v=92gu4mxHmTY

Reach me via my profile if you're interested in knowing more.

Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
Certificates are not things that are centrally managed.

If you get a certificate from a CA (DigiCert, AWS,Google...etc), they hand you the certificate after necessary verification but otherwise have nothing to do with how you use (TLS traffic) it.

The same with something like age verification. Once you have a certificate that attests to your age (as of certificate issue date), the issuer has nothing to do with how you use it, the receiver of signatures generated from that certificate (via private key) can verify it without any interaction with issuer.

As for misuse, that's certainly a concern but it can be addressed via the issuing process. Certisfy does address this issue.

A fundamental requirement for making a certificate scheme work is that certificates are anchored to IRL identity via identity anchor certificates in a privacy preserving manner. You can read up on the approach here: https://cipheredtrust.com/doc/#pki-id-anchoring

Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
It does hide identity from all parties except the party you decide to share your identity with.

Here's the technical details on how that is achieved: https://cipheredtrust.com/doc/#pki-id-anchoring

Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
The keys are on your device, it doesn't require management by a third-party.
Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
It doesn't require maintaining a database. The certificates can be in a registry but also can be on your device without being in a registry. In any case, the security is not associated with a database or anything of the sort.
Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
>A QR code verifying that I'm 18 years old, great! What use is that? Not sure... anyone could copy that QR code and claim they're 18 years old.

Exactly, now scan the sticker with the QR Code on this blog post: https://blog.certisfy.com/2024/02/from-secrecy-model-of-info...

You'll see it tells you whether the sticker is stolen or not based on where you got it from, ie the "Valid For Source" field.

Edmond··on A Canadian lobby group is promoting "widespread adoption of age verification"
Yes, you can with cryptographic certificates.

App: https://certisfy.com/

Demo: https://youtu.be/92gu4mxHmTY

Happy to discuss.

← PreviousPage 2 of 25Next →