HNHacker News
TopNewBestAskShowJobs

dvt

19,416 karma · joined October 14, 2012

UCLA alum (philosophy, mathematical logic), startup guy, data engineer, CTO, immigrant, amateur kayaker. Find me at https://dvt.name or @davvv on Twitter.
submissionscomments
dvt··on Googlebook
I work routinely from coffee shops. Literally like 80% of people on their laptops have Claude or ChatGPT open when I glance over. Listen, I do think AI still has a LONG way to go to be the automation & productivity utopia we so desperately crave, but underselling its usefulness is just silly at this point.

I used to be vehemently against AI coding just a few years ago, because the hallucinations were a deal-breaker. However, these days, most of my code is written using AI. It's still very "corporate junior" so it takes constant tweaking, hand re-writing, or total re-architecting, but it's leaps and bounds better than what it was. And I find myself working on the interesting parts: product, user experience, novel algorithms, etc.

dvt··on Fake building: Claude wrote 3k lines instead of import pywikibot
At the very least not providing a disclaimer is disrespectful to your readers.
dvt··on Training an LLM in Swift, Part 1: Taking matrix mult from Gflop/s to Tflop/s
This is an amazing article, thanks for sharing! Will also bookmark it.
dvt··on You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE)
Let's say you want to call win32 (or Mac) OS functions, all of a sudden you're doing all kinds of wonky pointer stuff because that's how these operating systems have been architected. Doing unsafe stuff is pretty inevitable if you want to do anything non-hello-world-ish.
dvt··on You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE)
You actually kind of don't, I use like a zillion crates which have unsafe Rust in them and it's not like I'm sitting here reading every single line of their code. I like Rust for various reasons, but its memory safety is (imo) overstated, especially when doing low-level stuff.
dvt··on You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE)
Obviously the way to prevent this is by bounds checking, which is literally in the `770594e` patch. It's just a bug and they happen routinely in all languages. Since this is doing pointer arithmetic, it could just as easily happen in unsafe Rust, for example.
dvt··on Valve releases Steam Controller CAD files under Creative Commons license
Could say the same thing about AT&T, Bell Labs, etc. There’s a lot of precedent here, but most saliently, how you become a monopoly is not really relevant. They absolutely are one. But I’m being already aggressively downvoted with no counter arguments so the Gaben fanboys are here. (Defending a deca-billionaire is hard work, after all.)
dvt··on From Supabase to Clerk to Better Auth
Kind of funny how something that used to be routinely self-written has been outsourced to libraries. I must’ve written auth like a few dozen times back in the PHP days, not particularly hard or complicated. There’s a million tutorials on how to salt and store passwords. I’ve had my sites attacked many times, but never breached. (JWT, OAuth, etc. has added a ton of surface area, however. So these days it’s inevitably harder to do.)
dvt··on Valve releases Steam Controller CAD files under Creative Commons license
If you want the audience as an indie developer, it would behoove you to launch on Steam (because they're a monopoly). Again, MS used all these cute arguments, and they don't really work. There's a reason Valve is always playing very nicely with regulators (especially w.r.t. the gambling stuff). They don't really want to rock the boat, but a benevolent monopoly is still a monopoly and I do think that a 30% cut for running a distribution platform is pretty predatory, especially as bandwidth has been commoditized.
dvt··on Valve releases Steam Controller CAD files under Creative Commons license
This is the same argument Microsoft used ("we're just an OS, totally not a monopoly"). I think to anyone that spends any time doing any PC gaming, it's obvious that Steam is the only relevant storefront by a country mile.
dvt··on Valve releases Steam Controller CAD files under Creative Commons license
I'd like to have an honest conversation about this, but imo Valve is no better than the iOS app store: it aggressively rent seeks and has essentially destroyed the shareware model (which was the best way to discover software in the 80s-90s). It has also willingly been complicit in underage gambling via loot boxes for more than a decade now.

I think Gabe Newell is a visionary for building Steam in 2003, way before Jobs had the same idea, but absolutely everyone and their mother hated Steam back then. I remember the memes on IRC and various forums (and I've been on Steam for a very[1] long time, the first or second day it came out I think). Two decades later, props to them and their useful acolytes for gaslighting the entire gaming community. No idea how Gaben is regarded as some sort of Christlike figure these days, but here we are.

Maybe it's just a "lesser of two evils" thing, as companies/platforms like EA and Ubisoft are the absolute scum of the earth.

[1] https://steamcommunity.com/id/dvxirl/

dvt··on Accelerating Gemma 4: faster inference with multi-token prediction drafters
It's not implemented in mlx[1] yet (or llama.cpp[2]), so it may take a while.

[1] https://github.com/ml-explore/mlx-lm/pull/990

[2] https://github.com/ggml-org/llama.cpp/pull/22673

dvt··on Microsoft Edge stores all passwords in memory in clear text, even when unused
Absolutely wrong. Are we writing the same code here? Page guards are for all userspace access. (In fact, I think kernel space might also trigger them, but can be circumvented. PS: I'm being polite :) Kernel space 100% triggers them, but can be cleverly circumvented by fucking with logs.)
dvt··on Microsoft Edge stores all passwords in memory in clear text, even when unused
They also act as access alarms[1]. Why even comment if you didn't bother to read the docs?

> The PAGE_GUARD protection modifier establishes guard pages. Guard pages act as one-shot access alarms. For more information, see Creating Guard Pages.

[1] https://learn.microsoft.com/en-us/windows/win32/api/memoryap...

dvt··on Microsoft Edge stores all passwords in memory in clear text, even when unused
> The problem is the largest threat model.

Without context, sentences like this mean nothing. So it's borderline a non sequitur. A threat model can be literally anything. Me giving my PC to someone at Best Buy, letting my grandma write assembly, or throwing my PC out the window can be a "large threat model." Nonsense sentence.

> If Process A and Process B are running in the same user context on a desktop OS, PAGE_NOACCESS is not a strong boundary by itself. Process B may be able to obtain PROCESS_VM_OPERATION/PROCESS_VM_READ, change the page protection with VirtualProtectEx, inject code that calls VirtualProtect inside Process A, load a DLL, attach as a debugger, duplicate useful handles, or tamper with the executable.

To the uninitiated this seems right, but really there's so much glossing over, it feels written by a non-expert that just read the first chapter of a "hacking for dummies" book. I've written anti-cheats and have even done some some hardware stuff, so I say this with some degree of experience: writing a userspace hack/cheat is pretty hard without a zero-day. Most stuff won't easily get PROCESS_VM_OPERATION permissions, also those are (afaik) logged by the kernel, so you can easily see if some weird "DefinitelyNotACheat.exe" executable or "NotABadLibrary.dll" requested them, so it's a pretty janky way of getting access to memory you shouldn't.

> That's the problem with same-user process isolation, it is a hugely leaky abstraction. There is no magical "just set this bit" fix.

Again, this is a non sequitur. No one said (or at least I didn't) that there's a "magical" bit. You're not even arguing against a strawman, it's almost like we're having two different conversations.

> On a desktop OS, once an evil process runs under the same user context, you are relying on process DACLs, integrity levels, code-signing, anti-injection hardening, and file-system protections. You can plug one path and still have several others.

Also seems right, and it kinda' is, but code signing is notoriously easy to circumvent, "anti-injection hardening" can mean like three million different things, etc. I dunno, just sounds like someone that's never done this stuff before. Like, not bringing up Detours[1] when talking about "anti-injection" just seems like weirdly avoiding the ONE canonical way of doing this, which just about every single hacking/cracking book covers. Idk, weird omission.

Also, no one in their right mind would attach a debugger, as that's trivial to detect[2]. I guess it could be a decent proof of concept, but no serious hacker would ever go that route. (Also, if I remember correctly, you also need to ship some special DLLs that have the actual debugging helpers—and same with Detours, so might as well do that).

Just wanted to give my justification for the accusation. Maybe I'm wrong and maybe that's why I'm getting the downvotes, so my bad.

[1] https://github.com/microsoft/detours

[2] https://learn.microsoft.com/en-us/windows/win32/api/debugapi...

dvt··on Microsoft Edge stores all passwords in memory in clear text, even when unused
This comment feels like it's written by AI. Anyway, PAGE_GUARD helps you get around VirtualProtectEx, which is a very common way of detecting userspace cheats.
dvt··on Microsoft Edge stores all passwords in memory in clear text, even when unused
This is not true. The canonical way to prevent access is via PAGE_NOACCESS[1]. Obviously, running as admin or in kernel mode breaks the whole thing since you can re-call `VirtualProtect` on that page and open it up.

[1] https://learn.microsoft.com/en-us/windows/win32/memory/memor...

dvt··on Microsoft Edge stores all passwords in memory in clear text, even when unused
This is 100% that case. Basically every form (like this very one I'm typing in) is held in userspace memory un-encrypted. And yet lawyers and doctors and CIA operatives all use forms to type very sensitive stuff in.

It would be stupid, wasteful, and overly-complex to encrypt forms just in case some malicious process somehow got ring0 access. In that case, a keylogger is likely more useful anyway. And you're fucked even if you are encrypting stuff (as keys are likely also somewhere in memory[1] and they need to be—gasp—unencrypted). There's no free lunch.

Stupid Twitter thread meant to rage-bait for engagement.

[1] They could also be on disk or on some peripheral, but still fully readable by a motivated-enough hacker.

dvt··on Talkie: a 13B vintage language model from 1930
Post-Great-War optimism was a real thing, in no small part motivated by the great experiment that was the League of Nations.
dvt··on Work with the garage door up (2024)
> it's the proportion of that to anything else

And my point was that, from what I can tell, that proportion of trash::value has been increasing on all social media in (more or less) lockstep. If anything, I'd say Facebook has seen the most precipitous drop in quality, not Twitter. So much so that I don't even log in anymore, and I was veritably addicted during college.

dvt··on Work with the garage door up (2024)
> What's left is people who are logged in, _engaging_. And man, that was always the worst part of Twitter, the constant posturing and troll-baiting for clicks, pushing every viewpoint toward its extreme.

I do agree that engagement farming is—and has been—a problem, but as someone that worked in social media (mostly on the data side, fwiw), it's been a problem for like a decade+ now, long predating "modern" Twitter. And it's a consistent problem on all platforms (I mostly use Instagram, and it's annoying on there as well).

dvt··on Work with the garage door up (2024)
Curious as to why people think this (other than partisan trend-following). I've been on Twitter since 2009, and it's arguably in the best spot it's ever been, apart from Grok being pushed so aggressively. A lot of people still build publicly on Twitter. If you're conservative you can follow conservatives, if you're liberal you can follow liberals. I find Elon annoying, so I just muted his account because it seems like it was being algorithmically pushed, especially during the DOGE days. But I do follow politics pretty closely, and it seems relatively balanced overall.

Not sure if it turned into Musk's idealistic "town square," but it's certainly more interesting than it was before.

dvt··on Show HN: HNswered – watches for replies to your Hacker News posts and comments
At least write the README yourself, it's like 4 sentences.
dvt··on ChatGPT Images 2.0
This is an amazing test and it's kinda' funny how terrible gpt-2-image is. I'd take "plagiarized" images (e.g. Google search & copy-paste) any day over how awful the OpenAI result is. Doesn't even seem like they have a sanity checker/post-processing "did I follow the instructions correctly?" step, because the digit-style constraint violation should be easily caught. It's also expensive as shit to just get an image that's essentially unusable.
dvt··on Even 'uncensored' models can't say what they want
You're making an argument Descartes formalized in the 1600s (and folks have been making long before him). It's a cute philosophical puzzle, but we assume that there's no Descartes' Demon fiddling with our thoughts and that we have a continuous and personal inner life that manifests itself, at least in part, through our conscious experience.
dvt··on Even 'uncensored' models can't say what they want
> I feel confident enough to disregard duelists

I'm a dualist, but I promise no to duel you :) We might just have some elementary disagreements, then. I feel like I'm pretty confident in my position, but I do know most philosophers generally aren't dualists (though there's been a resurgence since Chalmers).

> the brain is just (some form) of a neural net that produces output

We have no idea how our brain functions, so I think claiming it's "like X" or "like Y" is reaching.

dvt··on Even 'uncensored' models can't say what they want
> Of course it knows what it output a token ago...

It doesn't know anything. It has a bunch of weights that were updated by the previous stuff in the token stream. At least our brains, whatever they do, certainly don't function like that.

dvt··on Even 'uncensored' models can't say what they want
> If all the training data contains semantically-meaningful sentences it should be possible to build a network optimized for generating semantically-meaningful sentence primarily/only.

Not necessarily. You can check this yourself by building a very simple Markov Chain. You can then use the weights generated by feeding it Moby Dick or whatever, and this gap will be way more obvious. Generated sentences will be "grammatically" correct, but semantically often very wrong. Clearly LLMs are way more sophisticated than a home-made Markov Chain, but I think it's helpful to see the probabilities kind of "leak through."

dvt··on Even 'uncensored' models can't say what they want
> I don't really understand why this type of pattern occurs, where the later words in a sentence don't properly connect to the earlier ones in AI-generated text.

Because AI is not intelligent, it doesn't "know" what it previously output even a token ago. People keep saying this, but it's quite literally fancy autocorrect. LLMs traverse optimized paths along multi-dimensional manifolds and trick our wrinkly grey matter into thinking we're being talked to. Super powerful and very fun to work with, but assuming a ghost in the shell would be illusory.

dvt··on John Ternus to become Apple CEO
> I think Tim Cook took Steve Job's vision and really took it to the moon.

I vehemently disagree with this. I think Cook's logistics and business-focused goals are, if not diametrically opposed to Job's product obsession, at the very least orthogonal to it. Almost everything about Apple the product, over the past 15 years, has either coasted (e.g. stayed at par with the rest of the industry) or gotten worse. The one exception is arguably Apple Silicon (and I'm sure their board is acutely aware of it).

← PreviousPage 7 of 34Next →