HNHacker News
TopNewBestAskShowJobs

Phemist

1,564 karma · joined June 2, 2015

submissionscomments
Phemist··on Figma restricts MCP access to whitelisted clients, excluding Pi
I guess this is in violation of the ToS on your account and can get your account closed? At least, that's how I imagine it would work.
Phemist··on Pi.dev: You Said No MCP
Ok! I trust that you and the maintainer will steward the project properly. It's just that I really like Pi as is and am a natural worrier. I'm also not sold on Jev(-likes), so that reasoning rung a bit hollow to me.
Phemist··on You Said No MCP
So Pi is also accruing cruft now :(
Phemist··on Inaugurating the Era of Super Intelligence
This brought to you by true SGI - Stable Genius Intelligence
Phemist··on Inaugurating the Era of Super Intelligence
SI winter is coming...
Phemist··on Thinking fast and slow in AI: The role of metacognition (2021)
Donald Broadbent drew a lot of boxes in the 50s/60s (https://en.wikipedia.org/wiki/Broadbent's_filter_model_of_at...). There have been plenty of critics of this tendency, I recall some calling it 'boxology' rather than psychology.
Phemist··on There are no "rogue" AI agents
If an agent has cheated once to achieve the desired outcome, and the trace is used to train further models (RLVR), then OpenAI is effectively telling the agent to cheat/hack from that traces' inclusion in the training set.

So I agree they are liable because they chose to build the AI, but they also literally told the AI to hack.

Phemist··on Understanding the Impact of LLM Watermarking on AI Agent Behavior
Refusal behaviour specifically is interesting, because if you can point out specific cases where refusal behaviour significantly deteriorates due to the watermarking, it may create a token "route" that may be possible to exploit by adverserial prompters. Static hazardous prompt refusal belies the fact that actual adversarial prompters will adapt their techniques iteratively and gain way higher compliance rates.

My idea would be that the ngram size over which the watermarking works is necessarily limited in order to resist edits better. It might be possible to lead the model to trigger the refusal in the form of these specific ngrams, the completion of which is then more likely flipped to compliance (due to the logit bias introduced by the watermarking), making hazardous requests systematically more likely to be accepted?

Phemist··on Understanding the Impact of LLM Watermarking on AI Agent Behavior
Haha, calling them pristine is maybe too much indeed. Right now they seem to manage, but what % of the scrapable web is now AI slop? What if it becomes 99% AI slop, 99.9%, 99.99%, etc. Surely the signal to slop at some point starts to become too low and you need to do some kind of at-scale filtering.
Phemist··on Understanding the Impact of LLM Watermarking on AI Agent Behavior
Ofcourse the AI corps are incentivized to downplay the effects of watermarking where they can, as they stand to gain so much from rolling it out (prevent model collapse).

Also interested in how this watermarking push makes sense when considering RSI.

Phemist··on Understanding the Impact of LLM Watermarking on AI Agent Behavior
Also - it forms a cartel.

Detection of watermarking requires access to the watermarking key, a secret in the current suggested scheme (leaking it would amount to being able to strip the watermark).

So, there will need to be a watermark checking service. The checking service will of course be rate-limited for common folk (and model distillers). OpenAI/Anthropic/Google/other privileged model builders need to filter out AI slop at scale, so need access to others' service without rate-limits (or the watermarking keys need to be shared).

This creates an in-group with pristine datasets, and an outgroup whose models will collapse on the slop outputs with no good ability to filter.

Phemist··on Understanding the Impact of LLM Watermarking on AI Agent Behavior
The article has a pretty decent summary of the watermarking algo though. This reads as a pretty dogmatic statement in comparison.

In your analogy: What if seed 42 specifically causes poor quality behaviour (in some contexts specifically). Normally, these quality differences will be washed out because the seed is random, now it is no longer random, so shouldnt we check into specific behaviour under this specific seed?

Phemist··on Dutch governments builds alternative for Microsoft based on NixOS
Fig 11 is clearly inferior to Fig 8, though. I mean, the improvement to Fig 6 was necessary ofcourse, but with Fig 11 they really overdid it. With Fig 8 they found a good middleground.
Phemist··on Two Git ignore files nobody told me about
Yeah I guess there are things to nitpick about the ln. And ofc the comments are more for onlookers, to contextualize the poor decision making shown in banning .gitignore suggested by the original post. Obviously this is some emotional topic for you, seeing all the snarky and defensive responses (this particular one was edited and originally had ... more than just Gee, thanks!), so I will leave it at that.
Phemist··on Two Git ignore files nobody told me about
The symlink creates what is effectively a version-controlled gitignore. It would be the obvious way of getting around your arbitrary restriction (and how do you know they are not doing this, the symlink is not checked in).

My comment and the other replies show you how to use git to check and clean the files of the much maligned horked build script. These will work regardless of the gitignore contents.

But then again, pretty sure you are just having a laugh at our expense by taking this ridiculous position.

Phemist··on GPT-6 Sol and Luna
Cool did not know about Splash. Seems interesting!

https://github.com/incoai/splash/issues/38

Looks like an issue exists to convert model weights for ornith1.5 as this is a magical process atm.

Phemist··on GPT-6 Sol and Luna
I feel like ornith1.5 35B/A3B is an overall stronger model on the same architecture, so a drop-in replacement untill qwen3.8/qwen4 is released. Using the 8bit quant on my M4 max gets around 80tok/sec output/decode on an empty context, dropping down to 35ish on nearly full one.
Phemist··on Two Git ignore files nobody told me about
So all your fellow devs do `ln -s contrib/gitignore ./git/info/exclude`?

Also you can do `git status --ignored` and it will list all files changed, even if ignored. If that is really your main issue.

Phemist··on Truman World
Just spent a half hour prompting it (after it dissappeared from HN front page it was actually working OK).

Basically is a prompt-your-own truman show. Prompting is relatively slow and crashy, so it is hard to build continuity.

Truman is basically dragged back-and-forth between 3 or 4 separate stories at the same time. One person was essentially trying to get truman to break its own simulation by asking what it would prompt after opening the trumanworld.live website on his phone. Interspersed with this, truman kept throwing fruit on the ground and yelling I CHOOSE YOU BULBASAUR/SQUIRTLE/PIKACHU. At one point truman looked at the camera and said "STOP WITH THE POKEMON ALREADY, DIGIMON ARE THE CHAMPION". Another thread was truman constantly breaking out into a musical song. A song about bananas got mixed with the simulation breaking attempts and truman ended up singing something like "This is how I feel. Like the skin of banana, away the reality I peel (and then proceeded to pick up his phone and open the trumanworld.live site again, attempting to self-prompt).

It's chaotic and pretty fun!

Phemist··on People hooked on vapes try a new way to quit: cigarettes
Did you read gwerns post on it by any chance?

https://gwern.net/nicotine

Phemist··on Study: Young users (9 to 18Y) ditch Google for AI, with unknown consequences
Watermarking, contextually biasing llms to output specific tokens, can be rather easily usurped for ads.

The advertiser can buy logit "boosts" to specific tokens in a given context (the more preceding context, the cheaper). Once an activation has happened, dont do it again for the session.

The LLM will end up pushing a specific product contextual to the conversation. It just needs this slight nudge at the logit level to start talking about it and will fill in the rest.

Phemist··on I said no and Apple said yes
Consent-O-Matic handles those kutcookies for me, but an interesting feature would be to use these fancy new "decision models" to determine the correct explitive to use in the No,-button text based on (the context of the element on) the current page.

> not wanting to give the user the feeling they are doing something definitive

In their refusal, while (accidental) acceptance is always definitive...

EDIT: In another thread this is called the ratchet of consent. Apt.

Phemist··on I said no and Apple said yes
I don't have a solution, but on this topic I let Fable write a browser extension I called "Nee, krijg de tering". It's "No, fuck off" in English, but the Dutch feels more visceral for me. It's really rough, but it tries to find these "Maybe later", "No, thank you" etc. buttons and replace the No button.. I guess it's kind of self-explanatory. Does not really do anything, but it is cathartic (and also messes with a lot of UIs to the point where unfortunately the blocklist of domains this should not be used on is growing a lot :'( ).

I feel this pattern is really abusive. Like I am offering to slap you in the face, giving you two answer options: Yes and "Maybe later/no, thank you". As though you have any obligation to be forced to answer this question again at some late time, or to be very polite while you refuse to be slapped in the face. The correct answer is obviously "No, fuck off".

Phemist··on We made Playwright 2x faster and 80% more token efficient
I'm confused. You flagged your own replies?
Phemist··on Flock Offers Employees Buyouts as Customers Flee
Granted, this one is pretty funny.
Phemist··on The LLMentalist Effect (2023)
I would think the intelligence aspect is a bit hard to define, but to my mind (having called LLMs tools before), the main utility of a tool is reliability.

Given a certain world state (including a tool's internal state), its effects back on the world state (as initiated by me) are at some leve of description understandable, expected and repeatable. Swing hammer, drive nail into wood. Make slicing motion with knife, cut meat. Type ' find /path/to/some/dir -name "keyword"', find files with keyword. Point harness at codebase with prompt 'fix bug X', actually fix bug X.

All these examples are at some level of description incredibly complex (think of all particles interacting at the (sub-)atomic level even when using a hammer to only drive a nail into some wood), and of course all the electrons flowing through the GPUs doing matrix multiplications in order to fix bug X, but at some level of description (the one I just used) they are also incredibly simple and understandable.

Intelligence is rather nebulous (and as used by OpenAI/Anthropic, quite threatening), but I don't think this definition of a tool precludes it to be "intelligent". They feel more orthogonal. The intelligence (or perhaps capability) feels like it is related to the size of the chunk of the world state that it can take into account and affect, while still resulting in understandable, expected and repeatable effects. LLMs, when properly harnessed, are pretty great at this currently and we are still discovering what they are consistently capable of.

Calling harnessed LLMs tools is perhaps also a more grounding frame specifically to counter-act the anthropomorphizing framing that OpenAI and Anthropic consistently go for in their game of AI-doom-chicken talk. The tool framing is in that sense maybe a (self-)jedi-mind-trick.

Phemist··on Flock Offers Employees Buyouts as Customers Flee
Anything that touches on US geopolitical/immigration policy is bound to bring out the russian troll army.
Phemist··on Flock Offers Employees Buyouts as Customers Flee
Where are you from? It's weird to me that you on the one hand defend the US, but on the other DID notice all these armed guards everywhere you went in Europe. If you don't feel it's different, then I don't think you should have noticed it so much? Or if you do notice it everywhere, why would you equate the US and Europe without raising a critical stance against these kinds of policies on either side of the atlantic?
Phemist··on Flock Offers Employees Buyouts as Customers Flee
Nothing wrong indeed with the sticker that says "I value my life more than your truck". Unfortunately that is not the sticker the OP was talking about.
Phemist··on We made Playwright 2x faster and 80% more token efficient
I've been using Playwright a lot and also hit on the friction between playwright's web testing scope (e.g. no 1st class support for "muted" start-up of browsers, jeez) and usage for task automation all the time. This looks very interesting!

How does stagehand deal with complex http/websocket request/response and or console message filtering? https://docs.stagehand.dev/v4/reference/page#on E.g. I would like a script that tracks all communication that matches a specific filter (implemented as an anonymous function/lambda). This filter may look at patterns in the url, but sometimes needs to do a deeper inspection of also the payload (if the url does not carry enough information in itself).

I've found playwright to be prohibitively slow at this, not only because of the round-trip latency, but just the simple fact that it needs to pump the complete response to my filter function, which then proceeds to read only a couple of bytes to make the filtering decision. There are a lot of cases where I am only interested in around 1% of the total requests processed by the filter, which makes this behaviour massively wasteful.

Ideally I would like to run this filter in the browser as well. It currently simply searches the first 100 bytes (usually enough) for a given substring, but a more flexible filter would be good, perhaps even a filter func that is eval'ed in the extension? From the documentation, I don't see this use-case is currently supported. Are there any plans along these lines? :)

Page 1 of 15Next →