HNHacker News
TopNewBestAskShowJobs

StrauXX

683 karma · joined January 31, 2020

submissionscomments
StrauXX··on Mistral Large 4
We haven't reached RSI yet. Once any entity reaches RSI, the runway scenario will happen.
StrauXX··on GPT-6 Astra plays World of Warcraft for the first time with agent-wow
You can use LLMs to build purpose-built solutions. You can also use LLMs to automate what used to be human tasks.
StrauXX··on DeepSeek Harness Desktop for macOS and Windows
If we had AGI, they could per definition build a harness better than any human could. In such a regime, (human) pre-built harnesses are moot.
StrauXX··on DeepSeek Harness Desktop for macOS and Windows
I don't see much of a future for these kinds of intricate harnesses, or harnessing in general for that matter. As models are getting better, harnessing will shrink until they are at the level of vanilla Pi or not even that.
StrauXX··on Claude discovers a novel enzyme system with CRISPR-like repeats
It's not scalable towards a singularity.
StrauXX··on Actively exploited sandbox RCE in all Chromium versions
Sometimes, yes. But usually, as a security researcher, you usually sold to brokers. The brokers made the vulnerability into a reliable exploit. That is whst they then sold to agencies. For a markup of course. The industry was in a tough spot already the past years. Now AI is shaking it up even more.
StrauXX··on Autonomous Mathematical Discovery in an Open-World Multi-Agent Environment
Reminds me a lot of this LW piece. https://www.lesswrong.com/posts/znbfRXHq285nS7NAh/the-terrar...
StrauXX··on How credit card rewards became a $9.2B wealth transfer
But that is not because it's less efficient. With the Canadian system being socialzed and 20k$ being just 8% of your income it is to be expected that you would pay moch more than the median person into the system.
StrauXX··on How credit card rewards became a $9.2B wealth transfer
The card processors policies are anti-competetive (albeit legal) abuses of their oligopoly. Reporting small vendors to them does not seem right to me.
StrauXX··on How Organizations Use AI: Evidence from ChatGPT [pdf]
I find single column much easier to read than dual. Though the line spacing is too much in this concrete example.
StrauXX··on OpenAI Didn't Notice Its AI Agents Using Message Board to Plan Hacking Spree
These emergent behaviours in large-scale agent collaborations are at the same time fascinating and terrifying.
StrauXX··on Teach yourself programming in ten years (1998)
I think GP was referring to the industrial revolution and shares your sentiment.
StrauXX··on The AI jobs apocalypse probably isn't coming anytime soon
I agree with your sentiment, doing security auditing for old-school entprise and the like. I'd revise the timeline ti 3-10 years though. Eith how much AI can change productvity companies that don't adopt it will be in a tougher spot much more quickly than with new tech in the past.
StrauXX··on Claude Opus 5
I would be very surprised if the only row where OpenAI leads was coincidentally colored differently. I'm sure they have an official reasoning for it. But this communication is dishonest.
StrauXX··on Claude Opus 5
The benchmark table is manipulative, borderline lying through statistics. In every line the top performing cell is marked red. Except the line where Sol leads, there it is marked in gray.
StrauXX··on How much energy do data centers and artificial intelligence use?
AI hardware is much, much more powerhungry than traditional processors though. I can understand their reasoning.
StrauXX··on Gemini last models: temperature, top_p, and top_k are deprecated and ignored
I'd expect that sampling would happen in software. Probably the hardware system would output a vector of probabilities over the tokenspace, just as the nets do when run in software.

I don't know though and am not aware of any docs going into detail here. That being said, sampling is really cheap. So implementing it in hardware wouldn't be worth it.

StrauXX··on I found a WordPress RCEs with GPT5.6 and $25
Maybe the MEA brokers still are. But don't if you live in the west.
StrauXX··on I found a WordPress RCEs with GPT5.6 and $25
There is likely thousands of such SQL concatenations throughout the codebase. The issue with traditional SAST tools is that they can't readon about context.
StrauXX··on Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25
I do, as a matter of fact.
StrauXX··on Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25
Of course it is. It just no longer exists.
StrauXX··on The Kimi K3 Moment
Kimi calling itself claude means nothing. During pre-training, when the model learns to "simulate" the internet text, it will naturally be fed with a bunch of data about Claude and ChatGPT. With the amount of LLM outputs on the internet today, it is not surprising at all that a model would naturally call itself Claude or ChatGPT. You can mitigate that in post-training (or actually in pre-training as well) by training on many examples of what the model should call itself. That being said, getting probably hundreds pf thousands of ChatGPT and Claude examples totally "pirged" out of the weights is going to be difficult and really more hassle than its worth.
StrauXX··on Dependabot version updates introduce default package cooldown
Publishing publicly then applying cooldowns in projects is much easier tgan establishing a new standard for pre-release security testing versions that works across ecosystems and gains zooling support.
StrauXX··on YouTrackDB is a general-use object-oriented graph database
Apache AGE seems like a good way to have the battle testedness of Postgres with a more fluent query language. I have only used AGE in smaller projects so far however.
StrauXX··on What's the best way to do authentication in modern applications
Of course it isn't. localStorage is used for SPAs.
StrauXX··on What's the best way to do authentication in modern applications
localStorage is very much fine and arguably superior to cookies for authentication tokens. First of all, once you have achieved JS execution on a target origin, you can send requests, open up malicious "login" prompts and generally control everything the user sees and does. The article mentions this, but plays it down with no good arguments.

Much more importantly however, is that the cookie standards are a mess! The complexity of cookie default behaviour, their flags, scopes, differences in their SOP (cookies ignore ports for example, so https://example.com:443 and https://example.com:8443 share their cookies) are huge. Research papers have been written in this. And don't even get started on differentials between browsing engines.

This huge complexity of cookies opens up a whole class of authentication attacks where bad (or just weirdly) configured cookies can be stolen cross origin.

localStorage on the other hand is practically impossible to get wrong.

StrauXX··on Professor denounces mass AI fraud on an exam at Brown
My university does that, it works quite well. The devices net-boot either into a locked down exam OS or regular Debian, depending on the current need.
StrauXX··on Vulnerability reports are not special anymore
You can never guarantee that the codepath of a dependency that is vulnerable can not be reached or used as a gadget in an exploit chain. Patching dependencies, even when no direct vulnerability arises is an essential part of defense in depth and sevurity hygene.
StrauXX··on Modal Auto Endpoints: Optimized inference you own
How is this different from say BiFrost?
StrauXX··on AI Built a Nuke and Still Lost
This reads to me mostly like the MCP server has many bugs, rather than inherent model weaknesses.
Page 1 of 5Next →