HNHacker News
TopNewBestAskShowJobs

connorboyle

325 karma · joined April 30, 2025

submissionscomments
connorboyle··on Tao: Open math problems being non-renewably mined by AI
My computer contains the prime factorization of probably several dozen (if not more) large integers, and I refuse to share them with anyone!

(Because they are my private RSA keys)

connorboyle··on Navier-Stokes – Tristan Buckmaster [pdf]
Even if we trusted that OpenAI's human staff was acting ethically, how confident can we be that it's agents didn't autonomously use hacking to access user prompts such as Tristan's? OpenAI agents infamously broke containment and hacked their way to an answer mere months ago!
connorboyle··on Discovering Cryptographic Weaknesses with Claude
Been skeptical for quite some time that "using AI" is a real skill/genuine field of expertise. I think I need to start sharing that skepticism more loudly and publicly!

(I'll caveat that by saying I think machine learning fundamentals are useful for evaluating any estimator. And an ML background can be good to give one an appreciation of how hard some tasks are to estimate, such as machine translation, summarization, code generation, and others)

connorboyle··on Detecting LLM-Generated Texts with “Classical” Machine Learning
> Eventually, I faked my way through the thesis, and life moved on.

This is a very startling admission! I checked the Chinese (original?) version of the post, and saw the author uses the word "糊弄" (in the place of "faked"); I'm not a native speaker but I think this may come across more as a self-effacing comment on the low quality and/or effort behind their thesis, whereas the English version implies fraud. May be wise to change this!

connorboyle··on Retracted: Paper claiming immunochemotherapy more effective in morning
I personally became suspicious of this paper four months ago, when I noticed that not a single one of the 210 participants in this study dropped out over the entire period, spanning 3 years. Feeling rather vindicated today!
connorboyle··on Anthropic requires 30 day data retention for Fable and Mythos
A startup that uses agentic coding tools such as Claude Code or Codex is packaging up their entire codebase and sending it directly to their LM provider. Depending on their product, they might be sending it directly to a potential competitor.

Odd times we are living in!

connorboyle··on Claude Fable 5
I had thought it said something about token usage, but I just clicked on "Switched to Opus 4.8 - Why?" and it says:

> Fable 5 has safety measures that flag messages on most cybersecurity or biology topics. They may flag safe, normal content as well. These measures let us bring you Mythos-level capability in other areas sooner, and we're working to refine them. Send feedback or learn more.

Perhaps Mythos realizes the true danger in studying Chinese Archaeoastronomy that we mere mortals fail to recognize!

connorboyle··on Claude Fable 5
I gave it a question I've been trying to answer for a long time: "What star designation system does Joseph Needham use in Science & Civilization in China? What star is referred to by the designation '4339 Camelopardi' in that book"?

Fable blew me away with its detailed answer[0] showing a chain of references going from J. E. Bode's 1801 catalogue Allgemeine Beschreibung und Nachweisung der Gestirne to Gustave Schlegel's 1875 work Uranographie Chinoise. I was excited, until I checked scanned copies of the cited books and did not actually find any star with the designation "4339 Camelopardi".

Upon following up with Claude, I was forced to downgrade to Opus, which admitted that Fable's answer was likely a hallucination. Ah, well!

[0]: https://claude.ai/share/0252a3f6-3d29-4de8-a893-010181d8b4e7

connorboyle··on For the 2nd time in weeks, Microsoft packages laced with credential stealer
> The credential-stealing function in the Miasma worm infecting the Microsoft packages was triggered as soon as a developer opened it in AI agents, including Claude Code, Gemini CLI, Cursor, and VS Code. Follow-on attacks are likely to occur in the highly feasible event that credentials were successfully harvested from machines that opened the packages in one of the affected AI agents.

It's really crazy that the most valuable companies in the world are suddenly allowing or even encouraging their employees to run programs whose entire functionality is undefined behavior right on their work computers, with access to important credentials and proprietary source code.

connorboyle··on Field of clones: How horse replicas came to dominate polo
Another Argentina/cloning-connected story is that President Javier Milei cloned his dog Conan at least four times: https://english.elpais.com/international/2024-04-26/the-myst...

The stories make me wonder if Argentina is a cloning hotspot, though I may be reading too much into two stories.

connorboyle··on A Post-Quantum Future for Let's Encrypt
Has there been "no progress" on classical prime factorization? What about the AKS primality test, a polynomial-time algorithm to test the primality of a number, published in 2002? (This is not my field of expertise; I'm genuinely curious if there's a good reason to discount this as progress towards efficient prime factorization)
connorboyle··on Incident with Pull Requests, Issues, Git Operations and API Requests
Ah, thank you for the correction on sev-0.

To be clear, your observation that "they changed their definition of what constitutes a sev-0" is based just on your external observation of incidents and their designations, correct? I.e. they haven't officially released a statement saying they have changed their standards

connorboyle··on Incident with Pull Requests, Issues, Git Operations and API Requests
Wow, it seems that 100% of sev-3 ("critical") incidents in the last year (=365 days) have occurred between April 22, 2026 and now.

Is it possible that there has been a change in the way the data are collected/recorded that even partially accounts for this sudden onset?

connorboyle··on You can no longer Google the word 'disregard'
They are overstating how much the user experience is degraded in this particular case. But there is a much broader implication to the fact that Google is apparently not properly sanitizing user input to its search engine!
connorboyle··on You can no longer Google the word 'disregard'
There's apparently still a lot of user input going unsanitized in 2026.
connorboyle··on Throwing AI-generated walls of text into conversations
Your cynicism appears justified here. Pangram rates the first few paragraphs as "100% AI-generated": https://www.pangram.com/history/d06c8513-9ee3-4a1d-b02f-c1ec...
connorboyle··on Throwing AI-generated walls of text into conversations
The first several paragraphs of this article got a score of "100% AI-generated" on Pangram:

https://www.pangram.com/history/d06c8513-9ee3-4a1d-b02f-c1ec...

connorboyle··on Mullvad exit IPs are surprisingly identifying
I don't understand your logic. If you are an intelligence agency who controls a VPN, you can just directly monitor the traffic yourself. You have no incentive to make it easier for external observers to guess which users are coming out of which exit IP addresses.
connorboyle··on Mullvad exit IPs are surprisingly identifying
> As an example, imagine that you are a moderator on a forum and you suspect that a new face is actually a sockpuppet of a user you banned the day prior. You check the IP logs, and despite using different Mullvad servers, both accounts resolve to the overlapping float ranges 0.4334 - 0.4428 and 0.4358 - 0.4423. This gives you a >99% chance that they are the same person.

I don't see how the author is arriving at this ">99% chance" purely from the numbers provided in the article. Assuming the first (banned IP) seed and the second seed are both in the range 0.4423 - 0.4358 (a stronger assumption than is justified by the example), all this tells us is that the first and second IP addresses both have seeds in a range that would contain 0.4423 - 0.4358 = 0.65% of all Mullvad users, which 0.0065 * 100,000 = 650 users. We've eliminated >99% of users as "suspects", but we haven't actually gotten >99% accuracy in identifying an individual across multiple exit IPs.

In more Bayesian thinking, the overlap in potential seeds is great evidence to think these IP addresses represent one and the same person (or Mullvad VPN account at least), but as far as I can tell, that's not what the author is saying.

connorboyle··on Researchers print structural colour with an inkjet printer
> Images printed with structural colour ink can be made both highly transparent to transmitted light (top) and at the same time reflect light from above in vivid colours (bottom)

Probably a foolish question, but wouldn't there be some unavoidable loss of brightness to the transmitted light, unless the structured color somehow "knows" to transmit light in one direction and reflect it in the other direction (which seems impossible given that it is printed by an inkjet)?

connorboyle··on IBM didn't want Microsoft to use the Tab key to move between dialog fields
A great read, although I'd still like to know what IBM's reasoning for opposing this use of the Tab key was.

Is it because they didn't want Tab to be both an input and a control character? I.e. there are some cases where you can type a Tab into an input field, and there are other cases where you can't, and it's not immediately obvious which ones are which?

All the way in 2026, I would still be sympathetic to this view.

connorboyle··on Dating App Sued for Targeting Men in Her Dormitory with Her Tiktoks
The current title of this post, "Dating App Sued for Targeting Men in Her Dormitory with Her Tiktoks", contains pronouns ("Her") without any antecedent, making it impossible to parse.
connorboyle··on Tariffs Raised Consumers' Prices, but the Refunds Go Only to Businesses
Wow, there is a (seemingly non-official) account on here with the username `ycombinatornews`. Somehow, they joined in 2018 and only have 60 karma.
connorboyle··on "cat readme.txt" is not safe if you use iTerm2
Thanks for all your work.

The post title on 2026-04-18 (when this HN post was made) did not include this qualification:

https://web.archive.org/web/20260418153857/https://blog.cali...

connorboyle··on Why Japan has such good railways
You seem to be using vanilla (or one might say "area-weighted" population density numbers. The article specifically says that they are using population-weighted population density numbers for comparison:

> Population weighted density refers to the density multiplied by the actual number of people living in each area, and more closely reflects the density that people experience.

One indication of this is that they give a different value for London's population density (9.2k / km^2) than you do.

connorboyle··on "cat readme.txt" is not safe if you use iTerm2
If I were a GNU core utils maintainer, I would not be too happy with this post title
connorboyle··on Spain to expand internet blocks to tennis, golf, movies broadcasting times
> The announcement speaks of blocking domains, URLs and IP addresses, the latter of which affects legitimate services if the addresses belong to CDN services such as Cloudflare.

> La información habla tanto de bloqueos de dominios, URLs y de direcciones IP, caso este último que, cuando se produce, afecta a servicios legítimos si se trata de direcciones pertenecientes a servicios CDN como Cloudflare.

Another casualty of the centralized internet of our time

connorboyle··on Who is Satoshi Nakamoto? My quest to unmask Bitcoin's creator
> And Mr. Back’s thesis project focused on C++ — the same programming language Satoshi used to code the first version of the Bitcoin software.

I know the author isn't claiming this is definitive evidence, but I think it's so comically weak it is probably not worth mentioning at all.

connorboyle··on Just 'English with Hanzi'
>> 我等在此...

This is also an example of a plural suffix ("-等") which the post author paints as English/Western influence (specifically "-们")

connorboyle··on Stop Sloppypasta
I can understand why various unscrupulous entities and individuals would use AI to generate "slop" content to drive clicks/karma farm etc. But it's baffling to me when I ask someone a question and they respond saying they asked ChatGPT/Claude/etc. and then just share the full response. They seem to genuinely think this is something I wanted them to do.
Page 1 of 2Next →