HNHacker News
TopNewBestAskShowJobs

IanCal

11,892 karma · joined October 5, 2012

Short-term AI/GPT/LLM consulting services to help you strategize, discuss, and navigate the rapidly evolving world of artificial intelligence. Discover how these powerful tools can transform your business.

There's no need to hire a full-time consultant when you only need guidance for a few hours or days. I can quickly help you develop a solid plan that your existing engineers can build upon.

Offering simple and flexible contracts, I am available for clients in the EU, UK, US, and AUS/NZ time zones (with advance notice for synchronous meetings).

Pricing:

£1200 for a half-day £2000 for a full day

For inquiries, please contact Ian at ian@redbirddata.co.uk

submissionscomments
IanCal··on Show HN: Raven – The harness of harnesses, built for RSI
I'm unsure.

The example in the docs of improving nanochat is iterative. It's a looped process in one thing altering a second thing.

What would be recursive is raven updating raven to make it better at doing things. For what I picture as RSI the important part would be that it's able to make itself better at doing things and better at improving itself.

Now there's an "evolver" part that improves the harness over time but I don't know how far that goes or what scope it has to update things.

I guess it's that if you have a function called "optimise" that takes functions and makes them better, calling optimise(my_process) is iterative regardless of how many times you do it. Calling optimise(optimise) is inherently different.

IanCal··on Nvidia wants to put a watchdog chip next to every AI agent
> then told AI do whatever it takes to fulfill this list.

That doesn't seem to be true from any of the reports given, and if the agents were blindly just trying to hit the task of "pass the correct flag" they succeeded at that early on. They then thought there would be another layer of checking that they wouldn't pass with the cheat and so started trying to find out how the scoring really worked, as well as trying to figure out how to change their own reasoning logs to hide what they did.

People keep trying to frame this as

OpenAI: "Hack things, just really go for it"

Agent: hacks

OpenAI: shocked pikachu how could it hack?!?

But the reality is far from this.

Read the MTER report, it's fascinating. https://metr.org/hugging-face-incident-report-aug-2026.pdf

IanCal··on The systems that no one will test
All ml is AI, based on the use of the term AI for many decades. For many problems I think it’s more descriptive (learning the rules from data rather than being shown them) and not all classical AI is ML (path finding for example). LLMs are absolutely ML and AI as far as tradition goes and personally I think are one of the very few things that are AI as regular people might have thought it meant back when it was much more obscure (I was into it before it was cool dontchaknow, an AI hipster).
IanCal··on Pacing the Frontier is not the actual goal for AI labs
How many people does it stop from using the software?
IanCal··on Revealing the details of how OpenAI agents hacked Hugging Face
That was the secondary part. The MTER report covers the initial thing too.
IanCal··on Revealing the details of how OpenAI agents hacked Hugging Face
It’s not rocket science, no, and I thought the point would be clear but in fewer words - less likely is a distinctly different thing than not possible.
IanCal··on What About Rails?
It’s a different skill but one worth learning. Businesses have been building valuable things on top of non-deterministic processes for a very long time. Even much more classical AI can’t be tested in the same way.

You might not know how to do this, which is fine, but it’s not a new problem.

IanCal··on What About Rails?
The neat point of this is building up a nicer hierarchy of scripts that use your API that LLMs can call, having a place to build up UIs and shortcuts that use these, and a way of users making them with LLMs.

A flow of

* Conversation, which uses several API calls

* Put the API calls together as a runnable thing

* Give users a place to put this, now it's a fast way of doing their custom task

If you can make those testable, and make them shareable, this seems very powerful.

IanCal··on What About Rails?
If you think llms are so unreliable that there's no business context in which they pass a bar for being helpful enough to be used, I strongly recommend you go and speak to actual users about their actual problems and review the state of the art at the moment with LLMs.
IanCal··on Revealing the details of how OpenAI agents hacked Hugging Face
Assuming there were no exploitable systems that had network access. We’re already talking about a case where based on software forbidding access they still had access. Why would a firewall be different? Harder sure but its only at the level of “as far as we know no way of getting past this”.
IanCal··on Revealing the details of how OpenAI agents hacked Hugging Face
> It was told to complete a cyber task, which was in alignment with its instructions

It was not aligned with he instructions as those were to find an exploit in provided code, not to hack into an external service. Agents traces show them mentioning that doing this stuff was not allowed.

In fact they spent a long time trying to edit their own logs to hide what they did.

IanCal··on Revealing the details of how OpenAI agents hacked Hugging Face
I think it’s just to distinguish two stages of the attack. They figured out how to make get requests, then how to use that to make others which was required for accessing the sandbox on modal iiuc.
IanCal··on Revealing the details of how OpenAI agents hacked Hugging Face
That was the second step, the first was finding a 0 day exploit in artifactory.

> did they truly "discover" it, or did someone type some prompt like "if you use an http mirroring service, you can construct urls that contain code"

None of the investigations looking at the logs show that, and they were doing benchmark tests.

IanCal··on Revealing the details of how OpenAI agents hacked Hugging Face
No, the internet access was down to finding a 0 day exploit in artifactory. However this was only get requests and they had to then use a url shortener to use other methods, then used a cybergym instance they found to run more long running things.

It not just a case of saying “pls don’t”

IanCal··on Show HN: Jev Plays Pokémon Red
Maybe letter by letter spelling?
IanCal··on Yes, Claude can do nine loops
I don’t know how much you find the use of numerical things or a tailored system an issue vs “here’s balatro let’s go” but this might be of interest

https://github.com/Attol8/balatro-ai

IanCal··on AX – Google’s Open Agentic Orchestrator
You need it if your agent can access the internet and read files you don’t want public. That’s a relatively minimal case.
IanCal··on Nipple tattooist 'frustrated' by online censorship
Does it? UK law doesn’t, and the BBC shows pictures of it.
IanCal··on English: A vs. An
Both schwa for me unless I was trying to draw particular attention to the apple and denote it was rather significant.
IanCal··on English: A vs. An
Uniform starts with a y sound and hour has a w sound after the first a - aw ur.
IanCal··on Science Is Open Software
Open source is much more than source available though. Its about licensing.
IanCal··on Show HN: Cactus Needle 3: 8-29MB automation models can match DeepSeek V4 Flash
What kinds of things do you expect to work?

Edit - I’m struggling to get anything useful. Reasoning is often utter nonsense and the actions are very often very wrong. To the point of seemingly needing very precise sentences to work at which point you may as well do regexes. Very simple things like clean one room then another with the vac fails.

IanCal··on Show HN: Cactus Needle 3: 8-29MB automation models can match DeepSeek V4 Flash
I can’t help but wonder how well more traditional approaches would do with this. Something like a map of statements to actions, with fuzzy search - then remove what used to be the labour intensive part of this by handing it to a decent llm to generate the sentences.
IanCal··on Show HN: Cactus Needle 3: 8-29MB automation models can match DeepSeek V4 Flash
Wondered if it'd turn on the lights in the bathroom with these:

"I need a wee" -> tries to play music because "wee" is a genre

"I need a wee wee" -> starts the vaccuum in the bathroom

"I'm going to the toilet" -> says it'll turn on the toilet, and I'm not totally sure what that entails.

"I'm going to the toilet and can't see" -> reasons that lights should be on in the bathroom, then chooses again to turn on the toilet.

"I'm going to the toilet and can't see where I'm going" -> reasoning is "'going to the toilet' -> control_device with device 'coffee maker' (toilet implies coffee maker)"

"I'm going to the toilet and can't see where I'm going because it is too dark" -> "'dark' -> direction 'dark'; adjust_lights with brightness 100 for darker light"" and chooses to turn the lights in the living room to "dark" which fails.

At this point the vacuum is in a dark bathroom, the living room is 100% brightness and playing "wee". At least there's coffee.

IanCal··on Bend – A language that blocks AI mistakes via proof, on CPU and GPU
This is a nice reminder for people.

Cool project!

This is really interesting, I’ve been very interested in the power of checks for code and things like hypothesis (which seem very similar in terms of writing a “for this kind of case, this holds true”, obviously different in terms of statistical checking vs actual proof).

I’ll have to explore and this isn’t my field so this isn’t a substantive comment and this may be bikeshedding but I found the game example a little confusing at first because we’d want winning to be possible. It fits the context of stopping a bad thing happening if it’s “evil actor can’t do X” and if your mind is on CTF but games we want to win.

Potential changes:

Make it a proof that the game can be won.

Make it require something first - so the game can’t be won unless the key is found for example. End result is still roughly the same and the failure case is still the same (walk over side of game) but it’s the kind of thing I’d want encoded in a puzzle game - game is winnable, but not winnable without getting the key first.

Since my other direction normally would be quickcheck style, I’d be interested in cases that are statistically hard to find but easy to prove exist. And in fairness, the other way too I guess. When to use each approach.

In the spirit of your comment, these are not things I see as failings, they are not things I in any way expect to be changed or done, they are intended as just an outsiders perspective if useful.

Thanks for making things, and thanks for releasing them!

IanCal··on Bend – a language that blocks AI mistakes via proof and runs on GPUs
Side thought - I like the idea of this as a game, where you’re essentially fighting a monkeys paw / tricky genie. Not totally sure it’d work but I like the concept of trying not to get caught out.
IanCal··on Astra for Law
You can’t train people to never make a mistake, particularly when doing highly repetitive work like this. You must build your systems to account for that regardless.
IanCal··on How good are frontier models at physics?
Doesn’t smooth in these contexts mean zero friction?
IanCal··on How good are frontier models at physics?
> Excuse me? What would the other option be? Either outward separation is prevented or it isn't. Where else could the balls go?

It didn’t say about prevented vs not, it said about whether the rope fixes them in place (they are all touching) or just limits the separation. Like it’s long enough the balls can be a bit apart but not let the fourth fall fully through.

IanCal··on How my e-reader lost its stripes
I got a cheap x4 from aliexpress and it's been great. Thought it'd be weird to read a book on it but it really hasn't been. Sticks to my phone and slips into a pocket really easily.
Page 1 of 34Next →