HNHacker News
TopNewBestAskShowJobs

dualvariable

638 karma · joined March 10, 2026

submissionscomments
dualvariable··on U.S. government will decide who gets to use GPT-5.6
Not a headscratcher at all, if you understand how our economy and politics are actually run.
dualvariable··on Federal agents track down woman, demand she remove Instagram post about ICE
The 12k number is an estimate, and only 1k were convicted. And the law they're being charged with breaking covers things like threats to assault someone, false bomb threats, harassment of ex-partners, threats sent to MPs, serious domestic abuse-related crimes, etc. There's no breakdown of what each charge was for.

If you make a bomb threat or threaten to kill someone else over social media, you really should get arrested and prosecuted because that isn't an exercise of "first amendment rights".

dualvariable··on The Unbearable Cheapness of Open Weight Models
Anthropic is at least renting their datacenters, not owning, so all the capital accounting bullshit is getting laundered by someone else, who will wind up holding that bag.

And Anthropic is currently cornering the enterprise coding market, and they were smart to avoid video. Under current economic conditions they're a lot closer to being profitable than anyone else, and they can take advantage of crashing prices for compute if we hit a datacenter-buildout-glut.

dualvariable··on The unbearable cheapness of open weight models
Laughs in 2005-era VMWare and EMC...
dualvariable··on Anthropic says Alibaba illicitly extracted Claude AI model capabilities
I deliberately didn't mention any threat vector.

I would assume China is working on liberating Anthropic weights through the battle-tested strategy of finding someone in a privileged position and getting them laid, etc.

dualvariable··on Anthropic says Alibaba illicitly extracted Claude AI model capabilities
Hackers didn't use to spend a lot of time defending trillion-dollar corporations and their intellectual property rights.
dualvariable··on Anthropic says Alibaba illicitly extracted Claude AI model capabilities
"Information wants to be free"

Anthropic profited from training its models on all kinds of copyrighted information, live by the sword, die by the sword...

Their model weights, training data, training methods, etc are all going to leak to China over time.

Nobody on a site named _Hacker_ news should be all that upset about this.

dualvariable··on The deadly rise of giant trucks and SUVs
It is doable, but it is harder for the average redditor to compute something reasonable than just looking at GVW.

You should really take into account driver height, pedestrian height and hood slope and length and height.

dualvariable··on AI's Affordability Crisis
For ROI though you can run 24/7 agentic-style workloads, constantly churning through all your source code looking for security bugs (or whatever) and you DONT pay per-token costs.

A DeepSeek instance running 24/7 in a cloud provider will beat doing that with Claude which could bankrupt you with 100x more costs, even though it might find more.

And DeepSeek may find enough to keep your engineering team saturated and busy fixing things.

dualvariable··on The deadly rise of giant trucks and SUVs
I'm way more concerned about getting run over or T-boned by a distracted driver in a huge pickup, and literally nothing is getting done about that.
dualvariable··on The deadly rise of giant trucks and SUVs
Weight of SUVs/Trucks isn't really the right metric to use though.

The proportion of them which have a grill height which impairs visibility of the average height pedestrian would be a "better" metric, except it isn't as easy to cleanly define that.

With me driving in my 2000s Ranger, I can at least see adults walking in front of it just fine, even though it is bigger than a 1980 Toyota pickup.

dualvariable··on The deadly rise of giant trucks and SUVs
Okay, now do the times when some reckless driver nearly got you killed...
dualvariable··on AI's Affordability Crisis
And corporations could run DeepSeek models on cloud hardware.
dualvariable··on AI's Affordability Crisis
I'd guess Anthropic will probably win, and LLMs will probably still be with us and be much better in 10 years time.

But next year we could be in the middle of a massive $600B/yr capital-spending bubble deflating hard with unemployment accelerating towards 10% (or higher).

The internet never failed, but the telcom/dotcom collapse still happened in 2001.

dualvariable··on AI's Affordability Crisis
Yeah, but in the short-term there's $600B/yr of debt-financed depreciating capital investments waiting to financially blow up.

If you zoom out to the year 2100, it becomes a little pimple on the economy that is ready to pop, but in the here and now it can cause a lot of damage to real people's wages and finances over the next 3 years.

dualvariable··on NSA director: 'Mythos "broke into almost all of our classified systems in hours"
That is literally just more security through obscurity.

And the threat actors that would find that information "useful" already know it.

All of our IT security is a mess, the NSA director is just confirming what should be common knowledge.

dualvariable··on NSA director: 'Mythos "broke into almost all of our classified systems in hours"
Also, this is just security through obscurity. The holes that mythos exploited still exist after you've tried to limit mythos accessibility.

And the fact that all our systems are riddled with security holes shouldn't be too much of a surprise given the way that we all know that software is developed and how tech debt / chores are constantly underbudgeted (plus I think this underscores that any one human's knowledge and attention are inherently limited, and even the best PR review is going to leak all kinds of security holes).

dualvariable··on Midjourney Medical
Timing is also important. I can predict cancer with 100% success, because everyone will get cancer, unless they die of something else first.
dualvariable··on Google Chrome update will close the door on ad blockers
Well, I'm certainly glad that Google has never given their executives a lot of compensation or done layoffs of their workers.
dualvariable··on Google Chrome update will close the door on ad blockers
Well, you see Firefox isn't entirely perfect, so I'll just continue using the worst web browser out there until someone finally makes the perfect one...
dualvariable··on Fable ban was never about a jailbreak?
Ultimately, I bet Anthropic is fine with this because they needed to take Fable down to improve the guardrails (that were getting a ton of pushback) and they consider treating Fable as "too dangerous" to just be good PR hype for them. And they just get a little more anti-Trump "cred".
dualvariable··on What happened to nerds?
I think the bigger social problem is that too many people think it is counter-cultural to be defending rich people and billionaires, and an act of rebellion to mindlessly consume.
dualvariable··on Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages
> Github has changed their policy in 2022.

Which means that in the age of supply chain attacks, they patched the holes.

Which is exactly why this policy that AUR has is terrible in 2026.

The fact that GitHub didn't have that policy back in 2015 isn't the counterexample that the argumentative crowd here seems to think it is.

That is the GH policy right NOW, in the year of our Dog, 2026.

AUR is pretty grossly behind the curve, and I'll certainly accept that GH was arguably slow about it.

Defending AUR's policy on the basis of GH's policy being shitty until relatively recently isn't a good argument.

dualvariable··on Why Is Claude Turning into an a**Hole?
> One place where the threat is more real is in the possibility of vibe coding a pandemic virus, but that should be narrowly targeted at generating DNA sequences for viruses. Labs which generate custom DNA should also have reasonable heuristics for detecting likely dangerous product. The chances of covid coming from a lab leak are in the maddening 25-75% range which vaguely means ‘We don’t know’, but ‘lab leak’ includes a lot of things.

No it didn't. It differs by 1,000 base pairs from the closest known relative virus that we knew about before the pandemic, and we have no good idea what all those mutations wind up doing. And the PRAAR furin cleavage site was a previously unknown sequence and not one that humans would have guessed.

And we don't have good heuristics for what mutations would completely inactivate a virus versus enhancing its virulence.

Actual scientists won't be able to vibecode up some pandemic viruses because we have no idea how to do that and LLMs are just going to hallucinate.

dualvariable··on Did Anthropic ask for this?
I tend to think this is all just PR and hype, baking in the idea that Fable/Mythos is so good that it attracted all these regulations and controls. So you need to spend >$20k per developer per month, or you'll fall behind. Don't try to get by on Opus, you need to really open that wallet up...
dualvariable··on A 'cold blob' in the Atlantic could be a sign of AMOC shutdown
And the people involved in climate policy have solutions to climate change which don't involve enormously large restrictions on consumption, but just require more energy efficiency (which is savings) and investment into carbon-neutral energy. And they've had those solutions for at least the past 20 years.

This isn't an insolvable problem, but the carbon-based energy sector will be big losers, and they're fighting tooth and nail against it.

An awful lot of our politics and geopolitics right now is symptomatic of the carbon energy sector fighting against the reality that it needs to die for the good of the human race, but it is also extraordinarily powerful.

dualvariable··on Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages
Only thing I can find on requesting to take over an inactive account is here:

> We do not accept requests to release, transfer, or reclaim usernames on the basis that they appear inactive or unused. If the username you want has already been claimed, you will need to select a different available name unless you are submitting a trademark complaint as described below.

https://docs.github.com/en/site-policy/other-site-policies/g...

Also even the original user renames or deletes their account any popular repos they have will get tombstoned, so the new owner can't recreate them:

> GitHub uses a tombstoning algorithm to reduce the risk of repo-jacking by permanently retiring specific owner name, repository name combinations. The github/cmark-gfm example above is purely hypothetical, because, in that scenario, the old name would get automatically tombstoned. For example, even if an attacker managed to register the username github, they would still be prevented from creating a new repository with the name cmark-gfm because that owner name, repository name combination (github/cmark-gfm) would be permanently retired. Therefore, repo-jacking is only a risk for repositories that fall below a certain usage threshold. We don’t tombstone all renamed repositories because there’s a tradeoff between usability and security: a tombstone is a potential inconvenience for our users which we don’t want to impose unless there’s a genuine security-related reason to do so. That’s why our tombstoning policy only kicks in after the repository has met certain criteria, such as exceeding a specific number of clones.

https://github.blog/security/supply-chain-security/how-to-st...

dualvariable··on AI coding at home without going broke
Am I the only one happy on a $20/month pro plan?

Yeah, every now and then you blow out the window limits. So you take a break and think about something else or go out and do something else...

dualvariable··on Noise infusion banned from statistical products published by Census Bureau
The Republicans were successful with the Tea Party in taking over the House and the Presidency, that's a model which I'd argue is really proven to work in our two party system because we all just literally watched it play out in real-time.

Arguing against that, probably comes from a cynical neoliberal perspective where the Democratic Party can't change because the argument assumes that the Democratic Party can't change.

And the alternative is definitely outright fascism and the suspension of Democracy. They've told us what they're planning on doing, just like we knew they wanted to get rid of Roe vs. Wade, we just accepted the lies about it being settled law and a political football.

If you're not willing to vote against that, then you're comfortably middle class and don't think you'll be one of the ones that are going to be hurt.

I've voted against Trump 3 times and threw money behind trying to get Sanders the nomination in 2020 instead of Biden, so when all the horrible stuff has been going down this term I don't have to tie myself in knots with rationalizations about my actions.

dualvariable··on Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages
GitHub doesn't allow me to put up my old repos for adoption by any old rando, or to allow randos to request to take over my repos if I don't respond for 2 weeks.

GitHub also actually protects against repojacking and tombstones username/reponame combinations (that exceed a certain minimum popularity) and never lets anyone ever use them again.

The utility of AUR is also really based around being able to reuse the same repo without having to re-vet every single time. This kind of attack, that forces you to re-vet on every single upgrade so that trust inherently can't be established, is also not GitHub's model at all.

And go has a software package manager that heavily uses GH for distribution, and is arguably more VCS decentralized, but isn't vulnerable to this kind of attack, because it inherts GH's threat model, and doesn't implement the kind of choices that AUR decided to deliberately build into their system.

← PreviousPage 4 of 7Next →