HNHacker News
TopNewBestAskShowJobs

alasr

290 karma · joined February 11, 2022

...
submissionscomments
alasr··on I don't read code anymore
> I don't read code anymore

First one need to define what they mean by "read" and clarify the context its being used in; then we can talk about agreeing/disagreeing part. Otherwise, we all will be playing/participating in some sort of a language game.

alasr··on Meta Files Patent for Facial Recognition, Automatic Recording of People
FB in meat-space: see, for reference, page# 11 of the Meta's patent - https://image-ppubs.uspto.gov/dirsearch-public/print/downloa...
alasr··on Qwen3.8-Max: A New Bar for Coding and Cowork
- See "Llama.cpp vs Ollama"[0] and "Llama.cpp vs LM Studio"[1] for a high-level features comparison and find out which one suite you best (check out the "Target Users" category[0][1], at least).

- If you're still not sure, "LM Studio"[2] is ok to start with as you'll be able to download, start/stop/manage and chat with your LLM model all in one place: a single desktop app. Also, once installed, enable "Developer mode" under "Settings > Developer" tab; you might find it useful later.

- Regarding LLM models you can, based on your hardware spec, start with Qwen3.6, Google's Gemma4, OpenAI's gpt-oss-20b or Nvidia's Nemotron; use LM Studio's "Model Browser" screen to search for LLM models (each one listed with their organizational name/brand & logo: ignore the one you don't recognize as you might not need them at the start of your journey; you can always revisit them later, if needed.)

- Regarding which quantized LLM models you should download & run, just go with the default "LM Studio" selection (at least, in the beginning). Later, you can experiment with other quantization values to find out which one works best for your use cases.

I hope it helps.

---

[0]. https://llama-cpp.com/llama-cpp-vs-ollama/

[1]. https://llama-cpp.com/llama-cpp-vs-lm-studio/

[2]. Ignore "LM Studio Bionic" for now; just download and install "LM Studio" from https://lmstudio.ai/download

alasr··on Situational Awareness down 67% in July in AI stock rout
Why do you think that just sharing a link to an earlier HN post means 'promoting' someone? I referenced the HN post because I found that it's less about Martin Shkreli himself and more about a quality conversation with good analysis about the inner workings of 'Hedge fund' world and market dynamics.

If you've a better source, share it; I'll have a look and might use that one in the future. Otherwise, if you can't contribute in a constructive manner, stop making baseless comments about others intention without understanding them first.

alasr··on Situational Awareness down 67% in July in AI stock rout
Earlier on HN:

Martin Shkreli breaks down the collapse of Situational Awareness - https://news.ycombinator.com/item?id=49119380

Edit: added context

alasr··on JEP 401: Value Objects (Preview) merged to OpenJDK master
From Valhalla's design notes[0]:

> For the primitive types longer than 32 bits (long and double), it is not guaranteed that reads and writes from different threads (without suitable coordination) are atomic with respect to each other. The result is that, if accessed under data race, a long or double field or array component can be seen to “tear”, where a read might see the low 32 bits of one write, and the high 32 bits of another. (Declaring the containing field volatile is sufficient to restore atomicity, as is properly coordinating with locks or other concurrency control.)

... ...

[0] - https://openjdk.org/projects/valhalla/design-notes/state-of-...

alasr··on How Terry Tao became an evangelist for AI in math
> Why does it need to be beautiful?

"Beauty", IMO, signifies the idea that you're doing `something` for its own the sake where "its own sake" approximate the idea of getting/being closer to (or in proximity of) `something`/`anything`/`someone` you find "beautiful".

> Once you proved it it's true and you can use its consequences in math, sciences and engineerings (sic).

The expression "you can use its consequences in ..." suggests that the action is a "just a means" to "something else". However, not everyone is interested in the idea of "something else"; they're interested in the idea itself (in a broad sense) as that's one of the main reason they got started/involved in the first place.

---

We all do things as "just a means" to "something else". However, there must be an "end" to this chain of "something else"; otherwise, how do you find any "meaning" (or sense of fulfillment) in this whole enterprise (or chain of "something else"s)?

alasr··on Google's 20% 'project' has become AI's 120% 'attention'
Regarding the the current HN post's title, I like the TFA original title ("The New 20% Time, Minus the Time") better, along its sub-title; IMHO, the current HN post's title ("Google's 20% 'project' has become AI's 120% 'attention'") is more like reflection of the HN submitter's interpretation of the content of the blog post (that I agree with partially and to a small/negligible extent ONLY).

---

IMO, keeping "Google 20% Time" (mentioned in the TFA) and "R&D is two jobs, ..." (his second-last blog post, at time of writing this comment) in mind while reading this blog post, helps in reading and understanding the content of this blog post; whether we agree (or not) with the author's point-of-view is another matter.

---

Btw, I also noticed AI usage on this blog post; however, I over-looked that part of the post after looking at author's past work (and I'm happy I did that and continued reading the post).

alasr··on Playing Doom on a Subleq Transformer
GitHub repo.: https://github.com/kfoynt/neural_doom
alasr··on Executing programs inside transformers with exponentially faster inference
Just a small nitpik with the following part of your post.

> As the paper suggests: ...

This is not a paper; it's just a blog post which is mentioned in this post's URL (i.e. .../blog/can-llms-be-computers).

Also it, at the end of the article, has a job advertisement (nothing unusual for a blog post):

    "We are building these systems now, and we are hiring. If you want to work on problems at ..., join us."
alasr··on LM Studio 0.4
I think you're reading the docs correct: one still uses "lms server [command]" command to manage an LM Studio (LMS) server.
alasr··on LM Studio 0.4
> What exactly is the difference between lms and llmsterm?

With lms, LM Studio's frontend GUI/desktop application and its backend LLM API server (for OpenAI compatibility API endpoints) are tightly coupled: stopping LM Studio's GUI/desktop application will trigger stopping of LM Studio's backend LLM API server.

With llmsterm, they've been decoupled now; it (llmsterm) enables one, as LM Studio announcement says, to "deploy on servers, deploy in CI, deploy anywhere" (where having a GUI/desktop application doesn't make sense).

alasr··on I was banned from Claude for scaffolding a Claude.md file?
> I think I kind of have an idea what the author was doing, but not really.

Me neither; However, just like the rest I can only speculate (given the available information): I guess the following pieces provide a hint what's really going on here:

- "The quine is the quine" (one of the sub-headline of the article) and the meaning of the word "quine".

- Author's "scaffolding" tool which, once finished, had acquired the "knowledge"[1] how to add a CLAUDE.md baked instructions for a particular homemade framework (he's working on).

- Anthropic saying something like: no, stop; you cannot "copy"[1] Claude knowledge no matter how "non-serious" your scaffolding tool or your use-case is: as it might "shows", other Claude users, that there's a way to do similar things, maybe that time, for more "serious" tools.

---

[1]. Excerpt from the Author's blog post: "I would love to see the face of that AI (Claude AI system backend) when it saw its own 'system prompt' language being echoed back to it (from Author's scaffolding tool: assuming it's complete and fully-functional at that time)."

alasr··on Tongyi DeepResearch – open-source 30B MoE Model that rivals OpenAI DeepResearch
I haven't used any LLM deep research tools in the past; today, after reading this HN post, I gave Tongyi DeepResearch a try to see how it performs on a simple "research" task (in an area I've working experience in: healthcare and EHR) and I'm satisfied with its response (for the given tasks; I, obviously, can't say anything how it'll performs on other "research" tasks I'll ask it in the future). I think I'll keep using this model for tasks for which I was using other local LLM models before.

Besides I might give other large deep research models a try when needed.

alasr··on The Dark Side of the AI Boom Is It’s Masking Weak Investment
https://archive.is/lgDXT
alasr··on The evolution of Lua, continued [pdf]
Regarding C# and Java part of your comment, I think you might want to take a look at the following Wikipedia entries:

- Microsoft Java Virtual Machine: https://en.wikipedia.org/wiki/Microsoft_Java_Virtual_Machine

- Visual J++: https://en.wikipedia.org/wiki/Visual_J%2B%2B

alasr··on Git Bug: Distributed, Offline-First Bug Tracker Embedded in Git, with Bridges
Git Bug screenshots:

- TUI recording (GIF): https://github.com/git-bug/git-bug/blob/master/doc/assets/tu...

- Web comments (PNG): https://github.com/git-bug/git-bug/blob/master/doc/assets/we...

- Web feed (PNG): https://github.com/git-bug/git-bug/blob/master/doc/assets/we...

alasr··on Evolving Scala
https://docs.scala-lang.org/scala3/book/scala-for-python-dev...
alasr··on In a showdown of psychotherapists vs. ChatGPT, the latter wins, new study finds
It's ELIZA[1] before; now, it's ChatGPT.

From technology point-of-view, Humanity have progressed a lot; however, psychologically speaking, we're still almost the same as we're then (in 1960s).

--

[1] - https://en.wikipedia.org/wiki/ELIZA

alasr··on OpenAI says it has evidence DeepSeek used its model to train competitor
> OpenAI says it has evidence DeepSeek used its model to train competitor.

> The San Francisco-based ChatGPT maker told the Financial Times it had seen some evidence of “distillation”, which it suspects to be from DeepSeek.

> ...

> OpenAI declined to comment further or provide details of its evidence. Its terms of service state users cannot “copy” any of its services or “use output to develop models that compete with OpenAI”.

OAI share the evidence with the public; or, accept the possibility that your case is not as strong as you're claiming here.

alasr··on Git v2.48.1 security fixes for CVE-2024-52006 and CVE-2024-50349
More information on the CVEs:

- https://nvd.nist.gov/vuln/detail/CVE-2024-52006

- https://nvd.nist.gov/vuln/detail/CVE-2024-50349

alasr··on OpenID Connect specifications published as ISO standards
> Same goes for "authorization" and "authentication" in OAuth and OIDC. In the normal sense, authentication deals with establishing the user's identity, while authorization determines what resources the user can access.

"Authorization", in the context of OAuth 2.0, means whether a third-party application is "authorized" to take actions on-behalf-of a resource-owner on some resource server. And, if the answer is yes, what is the "scope" of this "authorization".

From the OAuth 2.0 RFC's abstract[1]:

      The OAuth 2.0 authorization framework enables a third-party
      application to obtain limited access to an HTTP service, either on
      behalf of a resource owner by orchestrating an approval interaction
      between the resource owner and the HTTP service, or by allowing the
      third-party application to obtain access on its own behalf. ...

It's very clear that OAuth2 is all about third-party application and their access to a "resource owner" resource. As far as users and their access to their own resources are concerned, they're "resource owner" and they've all the "power" to do whatever they like (with their own resources–off course).

For example, in the early days of Facebook, FarmVille games needed user permission in order to post on users Facebook walls and/or message users' friends if something interesting happened in the FarmVille while users are/were playing. And this is just one funny example to get across my point; there're many use-cases where it's super useful if users can grant a third-party application permission so that they can do some useful work (whatever it happens to be) on their behalf.

> Better examples for proper authorization standards are declarative authorization specification DSLs like XACML ...

I'm very well familiar with XACML and similar standards about access control policies; actually, I've build/developed an ABAC-based access-control service using XACML-like spec. for one of our customer-facing business application (in the recent past).

Yes, XACML and similar specs. are good for some use-cases for user access / "authorization" (based on business needs and threat-model). Yet, I'm not sure anyone would recommend them for third-party application authorization. Off-course, it's not impossible and it can be done; however, I doubt anyone would recommend doing it when simpler solutions are available–unless there is a strong business case from the business risks and security (threat-modelling) point-of-view.

---

[1] - The OAuth 2.0 Authorization Framework: https://datatracker.ietf.org/doc/html/rfc6749

alasr··on OpenID Connect specifications published as ISO standards
>> Didn't OpenID predate OAuth? What should OpenID have built upon?

Yes, you're right about "OpenID predate OAuth" part.

However, from my point-of-view, it seems the main source of confusion here is due to the fact that the word OpenID is used in more than one sense:

- First, OpenID used as part of the original OpenID authentication protocol developed around 2005 which communicates the idea of a decentralized online digital identity where one way a user can asserts their online digital identity is via a URL under their control.

- Second, OpenID used as part of the compound noun in "OpenID Connect" (which as per Wikipedia is "third generation of OpenID technology", published in 2014[1]) which implements the user identity and their authentication via authentication workflows built on top of OAuth2 spec.

Now, in my comment earlier i.e. "OIDC, unlike OpenID, ... built on top of existing OAuth spec ... to achieve its main objective ...", I was using OIDC (with "OpenID") in the second sense in comparison to the original OpenID authentication protocol where OpenID is used in the first sense (with both senses mentioned above).

I hope it helps.

---

As an aside, looking at all the comments about "OpenId" and "OpenID Connect" as nouns, I'm reminded of the following post: Two Hard Things[2]

---

[1] - https://en.wikipedia.org/wiki/Openid#OpenID_Connect_(OIDC)

[2] - https://martinfowler.com/bliki/TwoHardThings.html

alasr··on OpenID Connect specifications published as ISO standards
Just found the following on PDF 2.0 (announced on April 5, 2023): https://pdfa.org/announcing-no-cost-access-to-iso-32000-2-pd...

Still, I agree with your main point: let's hope future OIDC ISO spec(s) is/are still freely available in some form.

alasr··on OpenID Connect specifications published as ISO standards
You may already know this, I'm writing it as a note for my future self.

OpenID Connect (OIDC) is mostly concerned with authentication. On the other hand, OAuth (or, to be more specific, OAuth v2.0) is concerned with authorization.

>> OpenID Connect is effectively an evolution of OAuth.

In my opinion, OpenID Connect is actually evolution of OpenID – in its vision/spirit:

- OIDC, like OpenID, primarily focuses on users' identity and authentication;

- OIDC, unlike OpenID, didn't (re)invent new authentication workflows, which were significantly different in their own ways. Instead, it built authentication workflows on top of existing OAuth spec (which was being (ab)used for authentication in some places which, unfortunately, is still the case) to achieve its main objective (i.e. authentication).

---

Edit: rephrased to better communicate my thoughts (still not perfect; but, as the saying goes, perfect is the enemy of the good so I stop here).

alasr··on Groups underpin modern math
Disclaimer: I'm not a physicist; just a hobbyist interested in these topics.

What I understood, while reading this part of the article, was the author meant something along the line of supersymmetry[1,2] (as Groups are all about symmetry – up to isomorphism).

From CERN Supersymmetry article[1]:

  If supersymmetric particles were included in the Standard Model, the interactions of its three forces – electromagnetism and the strong and weak nuclear forces – could have the exact same strength at very high energies, as in the early universe.

--

[1] - https://home.cern/science/physics/supersymmetry

[2] - https://home.cern/science/physics/unified-forces

alasr··on I argue that studying the history of philosophy is philosophically unhelpful
IMO studying the history of any subject, you're interested in, is really useful as it helps understanding why things are the way they're in the present.

Now, regarding the subject of the 'history of philosophy', what are the contents and how they're structured is a different kind of problem. And, unfortunately, it's not limited to the 'history of philosophy' as we face similar kind of challenge when studying other important subjects.

This challenge can't be avoided all the times but needs a systematic approach; otherwise, one might easily commit the (proverbial) mistake of "throwing the baby out with the bathwater".

alasr··on Dear Chess World
From the horse's mouth:

"I had the impression that he wasn't tense or even fully concentrating on the game in critical positions, while outplaying me as black in a way I think only a handful of players can do. This game contributed to changing my perspective."

---

Personally I don't think that's strong enough reason to convince me that Niemann is a cheat. However, I would love to see more evidence before I change my position on this issue.

alasr··on How parasites manipulate the behavior of their hosts
> No one, or at least no one I've yet read, knows of any other example in nature of such a close mutualism.

Personally I found the relationship b/w fig trees and fig wasps quite amazing and extra-ordinary when I, for the first time, watched a documentary on this subject.

You can check it out here: The Queen of Trees - https://www.youtube.com/watch?v=xy86ak2fQJM

alasr··on Retbleed: New speculative execution attack sends Intel and AMD scrambling
From the FAQ of ETH Zurich's "Computer Security Group" website:

> Are only Linux systems affected?

> We’ve built the proof of concept code for Linux. But, because the fundamental issue is at the hardware level, Microsoft and Apple computers with the affected hardware have this issue too.

--

[1] https://comsec.ethz.ch/research/microarch/retbleed/

Page 1 of 2Next →