HNHacker News
TopNewBestAskShowJobs

Tiberium

5,208 karma · joined June 23, 2017

submissionscomments
Tiberium··on [dead]
LLM
Tiberium··on _for-sale DNS records
(Not quoting the article directly due to HN's auto AI filters)

In "Common mistakes" this article first says not to add this record if you're not actually planning to sell the domain, then says that the record doesn't oblige anyone to do anything, that feels quite weird to me.

Tiberium··on _for-sale DNS records
RFC: https://www.rfc-editor.org/rfc/rfc10023.html
Tiberium··on Responding to the next frontier of critical cyber capabilities
I had not hit any guardrails with reverse engineering (as long as its not related to security) with GPT 5.5 or 5.6 Sol, so you should try those. At worst with Sol you might see the warning in Codex that your request is being checked for security so it'll take more time, that's just a warning, not a full stop.
Tiberium··on Responding to the next frontier of critical cyber capabilities
If you don't want to get cyber verified, you can try an open-weight model such as Kimi K3 for that, it has looser internal safety training.
Tiberium··on Responding to the next frontier of critical cyber capabilities
For OpenAI's Cyber verification (the normal kind for Codex) you absolutely do not need any proof of cybersecurity work/authorization. They just use Persona for KYC + live selfie, and some extra checks that I don't know the nature of (but not related to checking whether you're a cybersecurity professional).
Tiberium··on Responding to the next frontier of critical cyber capabilities
You don't need an invite only program to just have Sol checking for vulnerabilities in binaries or code. But yeah I've hit guardrails a few times when Sol was making PoCs for the vulnerabilities it found (but most of the time it made those PoCs without issues).
Tiberium··on Responding to the next frontier of critical cyber capabilities
I had to register a second account because on my main one verification always failed, and when I contacted support they said that I've tried too many times and can't verify on that account.
Tiberium··on Responding to the next frontier of critical cyber capabilities
https://chatgpt.com/cyber is not new for OpenAI, and yes it's basically just KYC + likely some other invisible checks on your account, you don't to be a famous security researchers. Anthropic's cyber verification is quite a bit stricter I think.
Tiberium··on Responding to the next frontier of critical cyber capabilities
I prefer to keep my internet identities disconnected, sorry. If you don't believe me, you can try using Sol with cyber verification yourself, or send me a link to a repo that Sol could check to make you believe it. Or you could go look into one of the many Linux LPEs that were found with LLMs, or thousands of other vulnerabilities in 2026.

And nowhere did I say that those RCEs were in critical software, I'm not talking about the likes of Apache, Nginx, Django, etc.

Tiberium··on Responding to the next frontier of critical cyber capabilities
Isn't this literally what https://chatgpt.com/cyber and http://openai.com/form/enterprise-trusted-access-for-cyber are for?
Tiberium··on Responding to the next frontier of critical cyber capabilities
The fact that HF had to resort to using GLM 5.2 to analyze the logs/payloads makes it look legitimate, at least for me. They would not say that they hit guardrails with the frontier US models when defending if this was an obvious PR stunt.

https://huggingface.co/blog/security-incident-july-2026

> When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead on zai-org/GLM-5.2, an open-weight model, on our own infrastructure. This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.

Tiberium··on Responding to the next frontier of critical cyber capabilities
In my personal experience Sol with cyber verification is extremely capable of finding vulnerabilities, and it works even with binaries if you have some kind of IDA/Ghidra CLI access. Of course, unless the binary is protected with Denuvo/VMProtect/etc.

It sounds absurd, but in the last few weeks I've had a few cases where Sol found an RCE in self-hosted web applications in literal minutes just from reading the code (I prefer when it tries to reason statically instead of spamming runtime probes at first).

In another case it found an arbitrary file write in multiplayer in an old game by reverse engineering the binary - any other player in a match could just send you files to anywhere on your system.

I do these things for pure entertainment and curiosity, not for money from bug bounties, so if Sol can find those with a trivial prompt in tens of minutes for me, then what can focused companies/actors find in days or weeks?

Although I think most vulnerabilities are going to be closed in popular software by mid 2027, except in niche old or abandoned projects.

Tiberium··on Responding to the next frontier of critical cyber capabilities
They actually did a detailed presentation at BlackHat about the HuggingFace incident, and events that led to it.

https://youtube.com/watch?v=87DyyMV0kCY

Tiberium··on Taste Is All That's Left
To be honest with you, I think this is pointless. However hostile this might sound, the active userbase of HN seems to be extremely dismissive to the thought of LLM detectors and they think that all those LLM written articles are actually human written. I don't know if this will change, perhaps it'll only get worse from now. (You can see my recent experience in another thread https://news.ycombinator.com/item?id=49212027 )
Tiberium··on Another Corner of the Internet Has Been Ruined
Can you actually just do the test I explained? You seem to be basing your evaluation of Pangram on some old experiences. It's a very reliable service, used by research conferences and universities.

It's baffling that people would rather call BS on me than try the actual tool being talked about.

Tiberium··on Taste Is All That's Left
Please try https://news.ycombinator.com/item?id=49212788
Tiberium··on Taste Is All That's Left
Those people should just try posting a big quote from the article to HN, and then see their comment get instantly flagged due to HN's AI detection (which might as well be Pangram)

It's baffling to me how people are so dismissive of Pangram despite never using it, extrapolating their experience from GPTZero or something else.

Tiberium··on Another Corner of the Internet Has Been Ruined
To anyone who's willing to do a short HN test, please see and try https://news.ycombinator.com/item?id=49212433

You're in for a nice surprise.

Tiberium··on Another Corner of the Internet Has Been Ruined
Please see https://news.ycombinator.com/item?id=49212433 and try yourself. And Pangram has been confirmed to be working by reputable educational institution, too.
Tiberium··on Another Corner of the Internet Has Been Ruined
... Come on now. This is obviously because I quoted the LLM written parts from the article. Remove the quoted parts and try again. Do people not understand what LLM detectors do?

And, to be fair, short texts are one of the areas where even Pangram struggles, with a longer text it would be able to identify it as a mix of human and AI written text. They clearly disclose that short text detection is less reliable.

Tiberium··on Another Corner of the Internet Has Been Ruined
Okay, I have a test for you. It's a bit undocumented, but I'm pretty sure HN is using Pangram or a similar tool to auto flag AI written comments. Can you copy the entire text from the linked article and reply with it here, and see what happens to your reply, would it get flagged or not? I think this will show you what reality we live in.
Tiberium··on Another Corner of the Internet Has Been Ruined
I don't know if this website specifically did it, but a lot of other similar websites provide such services in a very bad way, for example base64encode.org and base64decode.org send your data to the server instead of using JS, and no one knows what they do with it.

I do understand that some still prefer browsers with JS disabled, but a website could probably detect this and default to in-browser processing, while reserving server-side to those edge cases.

Tiberium··on Another Corner of the Internet Has Been Ruined
You are a fool if you really think that the linked text is human written. I interact with LLMs basically daily, it's incredibly easy to spot their default styles. And, honestly, you should trust Pangram over me.
Tiberium··on Another Corner of the Internet Has Been Ruined
Can you show some examples of Pangram being "hot worthless garbage"? This reputation is true for most other detectors, but Pangram spends considerable effort to have an extremely low false positive rate. I think you just used some of them in 2023 and now think that they can't be made better.
Tiberium··on Another Corner of the Internet Has Been Ruined
If you cannot see that the linked text is LLM written, I've got bad news for you.
Tiberium··on Another Corner of the Internet Has Been Ruined
I only post it when I'm sure and I cross verified. And in this case specifically it's not boring, quite the opposite, it just shows that humans can be quite inconsistent. I really hope HN would extend its no LLM rule to articles/text, although this is too hard to enforce. When I look at HN, I want to read human text, I don't mind the use of LLMs for actual code and use it a lot myself. My issue is with people who generate whole articles with LLMs and present them as if they were written by a real human.
Tiberium··on Another Corner of the Internet Has Been Ruined
Not what? It's incredibly ironic that the creator is complaining about AI yet they used AI just to write a tiny text announcement. Apparently such a tiny snippet didn't deserve human writing.
Tiberium··on International Revenue Share Fraud (IRSF)
A question: why are you writing this with an LLM? Can you not write with your own words, at least on HN?
Tiberium··on An SLM trained on $8 ESP32-S3
The author is also replying with an LLM on HN: https://news.ycombinator.com/item?id=49180716
← PreviousPage 2 of 22Next →