491 karma · joined July 16, 2024
I think it’s only able to exceed 4.0/thread with SMT off because of a uops cache? From what I’ve read the Zen5 front end only had a 4-wide instruction decode per thread.
Zen5 is incredible when you're able to make the most of it. I’m super excited about Zen6.
Having one person with poor computer security negatively impacts everyone. Hacked sites turn into phishing landing pages, exploit kit hosting, stolen data dumps, and launching off points for attacks on everyone else. The vuln scanning ShadowServer is doing is meant to be a public good, which is why they share the info with ISPs and governments.
Security is too intertwined to stand by and say other people's vulnerabilities aren't your problem.
They look to all be log4j vuln scanning activity (CVE-2021-44228), and the volume isn't that high (a few a day, and not every day). They just have some overzealous vuln scanning. And yes, they shouldn't have the NTP pool under their DNS name.
I've had all sorts of strange things happen because of my ntp pool membership, this one is pretty far on the benign end of things.
I think it's an extraordinarily hard problem computationally, even with exceptional theoretical backing.
Where people may be able to beat me is if no solution exists-- there may be some highly nontrivial, but findable unsatisfiability argument.
If it were just a matter of a few thousand dollars of computer time (say, less than $5000) the money would already be spent and I’d have an answer.
We’ll see, I may build the tooling to distribute the search and enlist help from others interested.
It’s only been about 2 weeks since I was able to drop the runtime from “age of the universe” levels to just decades.
The “Go First” name is catchy for laypeople, but permutation fairness is the strongest and most interesting property.
There are sets we call “all subset place fair” which means any subset of the dice can be used and can fairly choose 1st, 2nd, and so forth, but this property is slightly weaker and doesn’t always make every ordering equally likely for every subset.
I’ve been working on that on and off since 2012. I picked it up again about a month ago and have made dramatic speed improvements to my search, but exhausting the whole space I’m searching will still take my computer an estimated 70 years.
Do we know if they’ve finally completed another pre-training run, or is this building off the same pre-training base they’ve been using since the GPT-4 days?
> But while homomorphic encryption has a nontrivial cost overhead, it shifts the capability/privacy trade-off to a question of cost. And the cost of homomorphic encryption is rapidly decreasing.
Which doesn't spell out exactly hon "nontrivial" the cost overhead still is.
"As far as my technological life goes"
Speaking from my own perspective (and not any of my challenge co-authors), I felt completely blindsided by the incredible progress frontier models made in solving CTF challenges between 2025 and 2026. We've been running the BSidesSF CTF for more than 10 years now, gaining experience on what makes a good, fun, and fair (solvable without random guessing) CTF challenge. 2026 was the first year where all of our past experience didn't seem to apply. Challenges that I designed to be hard, that I expected to take a dedicated human 10-20 hours to solve, fell to LLM automation in minutes.
I don't know what the future of CTFs is going to be, but I wouldn't be surprised if they're largely dead in 1-2 years. A lot of the satisfaction I get from making challenges is in seeing players struggle, learn, and then eventually solve them. I'm not sure there are going to be many players willing to sink 20 human hours of their weekend into one challenge when a dozen teams using AI solved the challenge in under an hour.
Overall I'm thrilled with the capabilities we're getting with AI, but saddened by what we're losing. I hope CTFs can somehow hold on, and that I can still get a lot of satisfaction out of building challenges and having players solve them.
Or rather could have been, since the issue seems like it was transient. I'm now getting resolutions.
Very strange, I wish I'd recorded what was going on better while it was broken.
But a dig +trace archive.ph (which recurses all the way to the root locally) resolves it fine.
Is there some US-mandated DNS filtering I don't know about?