HNHacker News
TopNewBestAskShowJobs

bmenrigh

491 karma · joined July 16, 2024

submissionscomments
bmenrigh··on Vote on which of Hacker News' challenges for AI have been met
At least 1/3rd of these predictions aren't clear enough to determine exactly what is being claimed/predicted. Even after reading the full comment multiple times, on a lot of them I couldn't tell where the author had set the goalposts well enough to say whether we've crossed it or not.
bmenrigh··on How did AMD Ryzen get 50% faster in two years?
I’m doing all my CPU measurements with ‘perf stat’ on Linux.
bmenrigh··on How did AMD Ryzen get 50% faster in two years?
Entirely in C. Compilers are pretty good these days. Almost every time I try to outsmart them I make things worse.
bmenrigh··on How did AMD Ryzen get 50% faster in two years?
It’s a backtracking search program looking for integer solutions to a specific problem. I’ve tuned a series of bloom filters to fill my L2 cache so that I rarely have to touch main memory (this alone took my IPC from 0.1-0.3 to 3.0 per thread). Without SMT it’s 4.6 IPC/core.

I think it’s only able to exceed 4.0/thread with SMT off because of a uops cache? From what I’ve read the Zen5 front end only had a 4-wide instruction decode per thread.

bmenrigh··on How did AMD Ryzen get 50% faster in two years?
I was recently able to get a workload of mine optimized enough on Zen 5 to hit a sustained 6.0 IPC/core (3.0 / thread) at 5.1 GHz. Seeing the a > 99.8% branch prediction rate and a > 99.99% L2 cache hit rate retiring > 1T instructions every 3 seconds feels amazing.

Zen5 is incredible when you're able to make the most of it. I’m super excited about Zen6.

bmenrigh··on Linux from Scratch
For a long time (probably 2002-2010) I really wanted to do LFS. But I've been on Gentoo since 2004 which, over the last ~22 years, has probably exposed me to almost everything LFS would have, plus a lot more it wouldn't have. I still wish I'd did it way back when. I probably would stumbled through fewer issues had I.
bmenrigh··on I'm being cyberattacked by Tesla, Inc
This is why the checking doors / neighborhood analogy isn't a good one.

Having one person with poor computer security negatively impacts everyone. Hacked sites turn into phishing landing pages, exploit kit hosting, stolen data dumps, and launching off points for attacks on everyone else. The vuln scanning ShadowServer is doing is meant to be a public good, which is why they share the info with ISPs and governments.

Security is too intertwined to stand by and say other people's vulnerabilities aren't your problem.

bmenrigh··on I'm being cyberattacked by Tesla, Inc
If the neighborhood was constantly being canvased by criminals checking doorknobs, so your concerned neighbor went over to your house to check your doorknob, and then let you know if you accidentally left it open, would you also accuse your neighbor of being a criminal trying to break in?
bmenrigh··on I'm being cyberattacked by Tesla, Inc
Calling vuln scanning from a non-profit a felony is a bit of a stretch. Many for-profit companies do similar vuln scanning and then threaten companies with security "scorecards". That is borderline extortion.
bmenrigh··on I'm being cyberattacked by Tesla, Inc
I just checked my own webserver logs (I also run a sever in the ntp pool) and I too see some hits in my webserver logs.

They look to all be log4j vuln scanning activity (CVE-2021-44228), and the volume isn't that high (a few a day, and not every day). They just have some overzealous vuln scanning. And yes, they shouldn't have the NTP pool under their DNS name.

I've had all sorts of strange things happen because of my ntp pool membership, this one is pretty far on the benign end of things.

bmenrigh··on New type of dice guarantees no tie when deciding who goes first
If someone wants to beat me to either a solution, or proving no solutions exists, then by all means :-)

I think it's an extraordinarily hard problem computationally, even with exceptional theoretical backing.

Where people may be able to beat me is if no solution exists-- there may be some highly nontrivial, but findable unsatisfiability argument.

bmenrigh··on New type of dice guarantees no tie when deciding who goes first
Well I’m first exhausting some promising regions of the search space which should complete in less than 2 weeks. After that I strongly suspect a solution doesn’t exist (for the column grouped space I’m searching).

If it were just a matter of a few thousand dollars of computer time (say, less than $5000) the money would already be spent and I’d have an answer.

We’ll see, I may build the tooling to distribute the search and enlist help from others interested.

It’s only been about 2 weeks since I was able to drop the runtime from “age of the universe” levels to just decades.

bmenrigh··on New type of dice guarantees no tie when deciding who goes first
A set of permutation fair dice work for any subset of dice and players. So a 4-dice perm-fair set allows any three dice to be used and is guaranteed to be perm-fair for 3 as well.

The “Go First” name is catchy for laypeople, but permutation fairness is the strongest and most interesting property.

There are sets we call “all subset place fair” which means any subset of the dice can be used and can fairly choose 1st, 2nd, and so forth, but this property is slightly weaker and doesn’t always make every ordering equally likely for every subset.

bmenrigh··on New type of dice guarantees no tie when deciding who goes first
The big open question is whether a set of 5 (permutation fair) 30-sided dice exists.

I’ve been working on that on and off since 2012. I picked it up again about a month ago and have made dramatic speed improvements to my search, but exhausting the whole space I’m searching will still take my computer an estimated 70 years.

bmenrigh··on GPT-6 Astra
> GPT‑6 Astra brings together years of research and big bets across pre-training

Do we know if they’ve finally completed another pre-training run, or is this building off the same pre-training base they’ve been using since the GPT-4 days?

bmenrigh··on Hilariously fast volume computation with the divergence theorem (2018)
At first I was going to say this is just the tetrahedra trick dressed up in slightly different clothes, and some sense it is, but there is a nice cancellation in the y and z coordinates which leads to less calculation in practice.
bmenrigh··on Decompiling a Nintendo 64 game in 84 days
I saw some news last week saying the project had reached 100%. Looking at the git repo (https://gitlab.com/kholdfuzion/goldeneye_src) that claim is a bit harder to verify, but maybe look again?
bmenrigh··on An elliptic curve of rank ≥ 30
Okay this result may well be in his expertise wheelhouse but what about the recent smooth Carathéodory conjecture disproof? Or the Jacobian, or the Hadamard matrices? It seems to span a pretty wide range. I know others are getting good results too, but his really stand out.
bmenrigh··on An elliptic curve of rank ≥ 30
I just don't understand how Alpöge can get Claude to construct so many complex mathematical objects. He must already have some deep insight into the structure these things are likely to take. Naive prompting, or naive search would not have found pretty much any of the object he's found in the past month.
bmenrigh··on Google is making private AI practical with homomorphic encryption
Has FHE really progressed so far that it's now so efficient that doing computation on an encrypted prompt is feasible? I thought even basic operations like FHE addition were still thousands of times more complex. The only mention in the article I see is:

> But while homomorphic encryption has a nontrivial cost overhead, it shifts the capability/privacy trade-off to a question of cost. And the cost of homomorphic encryption is rapidly decreasing.

Which doesn't spell out exactly hon "nontrivial" the cost overhead still is.

bmenrigh··on The Hacker's Renaissance (2025)
> In which parallel universe?

"As far as my technological life goes"

bmenrigh··on AI Is Solving CTF Challenges in Minutes
I'm one of the BSidesSF CTF organizers and challenge authors (symmetric). The article is a few months old now (May) which is ancient history as far as AI advancements go. That said, I'm still emotionally coming to terms with what happened.

Speaking from my own perspective (and not any of my challenge co-authors), I felt completely blindsided by the incredible progress frontier models made in solving CTF challenges between 2025 and 2026. We've been running the BSidesSF CTF for more than 10 years now, gaining experience on what makes a good, fun, and fair (solvable without random guessing) CTF challenge. 2026 was the first year where all of our past experience didn't seem to apply. Challenges that I designed to be hard, that I expected to take a dedicated human 10-20 hours to solve, fell to LLM automation in minutes.

I don't know what the future of CTFs is going to be, but I wouldn't be surprised if they're largely dead in 1-2 years. A lot of the satisfaction I get from making challenges is in seeing players struggle, learn, and then eventually solve them. I'm not sure there are going to be many players willing to sink 20 human hours of their weekend into one challenge when a dozen teams using AI solved the challenge in under an hour.

Overall I'm thrilled with the capabilities we're getting with AI, but saddened by what we're losing. I hope CTFs can somehow hold on, and that I can still get a lot of satisfaction out of building challenges and having players solve them.

bmenrigh··on The Hacker's Renaissance (2025)
These sorts of manifesto essays have never resonated with me. To me it never was—- and never has been—- about freedom. It’s about curiosity and knowledge. The essay seems to glorify the bad-old-days of fighting for freedom against corporate control (AT&T, IBM, Microsoft, etc.) as somehow the good-old-days. As far as my technological life goes, we’ve won—- MS, IBM, AT&T are irrelevant.
bmenrigh··on Five US tech giants' hidden debts soar to $1.65T on opaque AI funding
A pretty reasonable question. I guess it could be my ISP filtering.

Or rather could have been, since the issue seems like it was transient. I'm now getting resolutions.

Very strange, I wish I'd recorded what was going on better while it was broken.

bmenrigh··on Five US tech giants' hidden debts soar to $1.65T on opaque AI funding
I'm in the US and I'm either getting NXDOMAIN or NOERROR (with no A record answer) back from every big nameserver I try (my ISP, Google, Cloudflare, etc.).

But a dig +trace archive.ph (which recurses all the way to the root locally) resolves it fine.

Is there some US-mandated DNS filtering I don't know about?

bmenrigh··on My Mathematical Regression
The 2n choose n solution isn't at all intuitive to me but thinking about it in terms of 40 steps, 20 of them rightward and 20 of them downward an then looking at all distinct permutations of these 40 steps as (40!) / ((20!)^2) is intuitive to me. Then it becomes obvious that since 20 is half of 40, k and n - k are the same number (20), which coincides with the binomial coefficient n! / k!(n - k)!. But this seems like a lucky coincidence in 2 dimensions and if you extended the problem into 3D you'd do better thinking about permutations.
bmenrigh··on GPT‑NL: a sovereign language model for the Netherlands
Oh I didn’t mean at all charging them. I mean licensing in the sense of granting rights for the purpose of training. Probably most labs would be fine adding the language to the training for free as long as the dataset quality is high and it improves the results. But yes, pay them if that’s what it takes for them to use it.
bmenrigh··on GPT‑NL: a sovereign language model for the Netherlands
I think at this point what the Netherlands, and any other country that wants a good model in their language should do, is gather up every piece of text ever written in that language and license it to the big AI labs/companies for training. I'm sure there are vast libraries of books and other text that haven't been digitized and aren't a priority for the big labs.
bmenrigh··on Unicorn – The Ultimate CPU Emulator
I was just looking at Unicorn last week because it's used by unipacker to do automated unpacking of binaries. I built a "toolbox" for gpt-5.5 to do semi-automated malware and exploit reverse engineering and unipacker is sometimes useful for that purpose.
bmenrigh··on Mini Micro Fantasy Computer
Mini Micro seems to be built on Unity. The MiniScript portion of it is open source https://github.com/JoeStrout/miniscript but the version packaged for use by Unity costs some money. I can't tell if the people behind MiniScript are the same people behind the Mini Micro.
Page 1 of 3Next →