HNHacker News
TopNewBestAskShowJobs

fwn

1,185 karma · joined August 28, 2014

submissionscomments
fwn··on Obscura: VPN that can't log your activity
I am sure there are quite a few people out there who have avoided getting a mainstream smartphone setup or other big tech services.

As you wrote yourself, this is not the majority. Quite the understatement.

However, this is only a tangential notion in my comment. What do you think of my (probably not unique or novel) observation that calls for ethical purity seem to be very selective in a way that (in effect!) benefits big tech?

For example: The other person in this very thread who pointed out that Mullvad is not perfectly pure recommended iCloud in their previous HN comment three days ago. Did their attitude change in this three days? Unlikely.

iCloud is a service from a company that deplatforms ICE transparency apps, among many other things. Its then CEO, Tim Cook, personally gifted one million USD to Donald Trump for his inauguration. (The very thing they criticized: "... their CEO is directly funding a far-right ...")

Humans are rarely pure or heavenly. Double standards help incumbents.

fwn··on Obscura: VPN that can't log your activity
Calls for ethical purity are usually very selective, serving to protect incumbents.

For example, every big tech company supports the current US administration in some capacity, either with funds, their surveillance stack or both.

Almost noone has stopped using big tech products and services because of that. (Unfortunately!)

But beware! There is someone in one tiny, privacy-preserving company who is doing something that not everyone agrees with!

That is a big problem, right? I think this is a big problem, everyone!

You see those comments in every Mullvad thread, but not necessarily in every thread about big tech products or services.

fwn··on Android NAT-T keepalive offload bypasses VPN lockdown
This comment specifically was also auto-collapsed for me, without being marked as flagged or dead.

It might help to ask moderation about this. Could be an artefact of brigarding or something similar.

I also wouldn't worry about individual accounts so much. Asking for others to be banned, linking mirrored profiles, etc. That is just not the stuff many users like to read on HN. I think your technical content is truly amazing on its own already.

fwn··on We must pace the frontier
No. And no alignment, guardrails or slowdowns will ever secure our insecure infrastructure. Bad infrastructure decisions are a risk independent from AI.

The only way to secure infrastructure is to actually do the work needed to secure it. Our waste water treatment facility might not actually need to be able to tweet its status.

Cybersecurity is such an important topic for a country, dreaming about global alignment just to avoid fixing insecure infrastructure cannot be serious.

A Russian state backed hacker will not ask Dario for permission or argue with his LLM about ethics. That train departed long ago.

fwn··on We must pace the frontier
If we focus too much on the world domination fiction, we really might, in a moment of lapsed attention, end up plugging essential infrastructure into the public internet, hoping some dream of global alignment might save us.

That's like giving a gun to a monkey and hoping the monkey is trained well. ..a frontier monkey though.

fwn··on We must pace the frontier
The biggest AI risk, by far, is the concentration of power in a few companies, located in the US.

There is a lot of fear marketing about our text generators turning into Terminator. But other than the centralization of power, such fears are largely fiction. (Actual fiction, stuff like ai2027.)

And the labs know it: If Anthropic or OpenAI believed in their own narrative of being on the brink of world dominating superintelligence, they absolutely would not plan to IPO rn.

The slowdown narrative is probably just a hedge, or a face-saving way to lower expectations in case they can not keep improving at the same speed until they actually IPO.

fwn··on My last six months at Evernote
I made the same transition, and it felt very seamless. I didn't look into the Obsidian first-party sync service, since I was already using Syncthing at that point.

For even more contrast with Evernote: the fantastic Obsidian application lists eight employees and one cat on their about page:

https://obsidian.md/about

fwn··on DeepSeek v4.1 Flash
You seem to have conceded the "is it deterministic" argument only to sidestep by declaring determinism irrelevant. Your original claim was that LLMs are deterministic "in the same sense" as brains.

We can write down an LLMs full register, and that register/book contains the whole output universe of the text generator. That book does not act, it is morally neutral. That the brain has such a register at all is just restating the determinism axiom, which you treat as fact.

A text is not conscious, and we can not wish it into consciousness, no matter how many human-like patterns we find in the book / the generated text. It has not been shown that running the text adds anything over the text written out. Researchers are super motivated to find machine consciousness but cannot find it, while a company months from its IPO keeps pitching shadows of consciousness all day. It really is a PR strategy.

fwn··on DeepSeek v4.1 Flash
No, that is not at all something we can just state as a fact. Whether the brain is deterministic is an open question that just inherits the good old, probably unsolvable determinism debate.

The LLM pseudo-randomness from above is engineered by us humans and fully understood, much like an algorithm playing a video frame sequence.

You could theoretically record a full register of all states of an LLM setup with all the possible inputs and environment parameters, and it would fully describe everything you would ever get from a given LLM setup. It would be a very large, convoluted book.

I understand that Anthropics PR department wants to see truth or reason behind every "I'm alive" the LLM generates. Even the term "self-report" is anthropomorphizing, as an LLM does not do anything on its own at all. (It also does not hack any company on its own.) That is just one of the narratives they spin probably at least until the IPO.

fwn··on DeepSeek v4.1 Flash
LLMs are deterministic, though. Much like the video.

AFAIK using the same input tokens, weights, and numerical operations will lead to the same probability distribution for the next token. It uses pseudo-randomness to enable temperature, etc. Like a fuzzy video.

"Markers that would indicate consciousness if observed in a biological organism" just does not mean very much. A PR phrase used to hype the IPO.

fwn··on Asahi Linux on M3
I bought a Mac mini M4 simply because it was very cheap and the M4 chip offers great performance. It is currently mounted on the back of my TV and serves as a media station.

It runs macOS, but I have no particular interest in the operating system, nor do I own any other Apple hardware. (So no synergies.) It is alright (and better than Win11) but the preinstalled software does not even properly update without an Apple account. As soon as I can switch over to Linux, I will. ... I would just wait for all the ports to work.

fwn··on Shutting down our public encrypted DNS
Irrespective of political affiliations, I felt that Mullvad addressed the outrage in a mature and non culture war manner. Because of how they handled the situation, I have a lot more respect for the company.

It's great that they didn't try to cancel the guy or get seduced into driving a wedge into their team. It is great they chose their principle over pleasing the crowd in such a transparent way.

I have been a customer for many years. I once even used the cash payment option out of curiosity.

Here is their statement:

https://mullvad.net/en/blog/donation-controversy

They even linked his (Swedish language) private blog on which he wrote on the issue:

https://dberntsson.info/

fwn··on Mom gets 6-month suspended sentence for letting 5-year-old walk to the pond
(Not the patent) I'm very much pro letting children roam freely, but police intervention for walking or driving with your own child is clearly overreach. The good intention does not change that.

And even as a German who already spent a lot of time in Switzerland, I've never heard of anything like that.

To join in on the therapy speak: it is very good to challenge one's feelings, let go, and then, by the merit of reason, realize that police intervention for spending commute time with your children is bonkers.

It is just a very unreasonable extension of a very reasonable position.

fwn··on ChatGPT to face tougher regulation in the EU
I think that this take is unfair to the parent. Many VLOP requirements currently lack best practices, and it's clear that affected companies borrow from each other to mitigate compliance risks. The commission even seems to encourage knowledge sharing here. (This is also why you see them resorting to strange language that barely fits their platform mechanic.)

We could argue whether a higher level of government oversight is warranted for platforms above a certain threshold. We could discuss the additional compliance burden that these companies should face. All of these questions are valid (and important for DSA).

However, it is not plausible to deny the case-by-case uncertainties that you still face as an affected company. This is expectend and will only change with more time in the framework, basically.

fwn··on Berlin is being blackmailed by hackers
Neither the media nor politicians are interested in hyping up the issue right before the state election on Sep 20. So it's probably just what you suggested: pretending that nothing happened.
fwn··on Hacking IKEA Furniture
I see my style of thinking and writing everywhere in the world now. What happened?

On a more serious note, and to tie the fun AI comment into the actual discussion: I suppose the types of medium through which people try to express themselves are just very diverse. One person makes a statement through their dinner table, another through their iPhone wallpaper, etc..

fwn··on European Commission Revives Push for Encryption Backdoors in ProtectEU Strategy
Chat Control 1.0 is not at all voluntary for those controlled by it.

For example: there is no setting in Facebook Messenger where users can enable or disable Chat Control.

This is like saying that private prisons are voluntary because the corporations that run them were not forced into the market.

fwn··on DHS is using obscure law to snoop on journalists, non-profits, unions
If this area of research interests you, look into Thompsons "Designing Responsibility: The Problem of Many Hands in Complex Organizations" from 2017 or Bovens ur-werk "The Quest for Responsibility" from 1998.

Diffusion of moral responsibility in complex organizations is not a new observation.

The Wikipedia article leans a bit too much on the psychology and not on the organizational design / decision architecture, but is still a good entry point:

https://en.wikipedia.org/wiki/Diffusion_of_responsibility

fwn··on Stripe said to abandon $50B pursuit of PayPal
Unless you set up something like a brick-and-mortar Trustpilot competitor, you are likely to only ever read online about user feedback on anything. But this does not say a lot about the quality of the feedback.

I am always surprised that people use PayPal for privacy reasons. The company shares a lot more of your information with third parties than a SEPA transfer or card payment would.

fwn··on Nitter and XCancel receive cease and desist notices
Organizations very much rely on websites for the information they share. I don't even know how most data would need to be sliced to fit into tweets.

Like, how would you tweet exchange rates consistently and accessibly?

https://www.ecb.europa.eu/stats/policy_and_exchange_rates/eu...

Microblogging, as a format, is a niche. If you do use it as an organization, you need an authoritative place on the Internet that you control, from which all other data ideally is derived. You can still mirror it to Twitter/Mastodon or whatever just fine.

Deciding to be held hostage by a third-party platform so that someone in the organization can save three clicks is just unprofessional.

fwn··on OpenAI: GPT 5.6 Sol price reduction (until at least Nov 21)
AFAIK, you cannot run Claude without one of their mandatory system prompts at all.

If we wanted to compare model responses, we would give all models system prompts with model names, thereby fixing the Kimi misattribution.

The reason Kimi often states its name as Claude is likely because we can actually run it without the mandatory system prompt, smoothing over awkward competitor mentions.

fwn··on GPT-5.6 Sol Pricing Cut by 50% on OpenRouter
OpenRouter does not offer private inference, so your plaintext is shared with companies you may not even know by name.

Tinfoil OTOH claims hardware attestation and confidential computing, which is a pretty strong and (in theory) verifiable promise.

You absolutely would not recommend tinfoil.sh to someone indifferent to privacy trying to save money.

It's a very different service than OpenRouter.

fwn··on Firefox and Exa Partnership
Mozilla PR department seems to be vanilla Claude.

tl;dr of the article: Rather than building a closed AI stack (like Google - but they don't name it) Mozilla is pursuing partnerships. In this case, they are partnering with Exa.ai to offer AI integrations on desktop and iOS devices with visible source citations. There is no mention of confidential computing, hardware enclaves, or other technical mechanisms but they promise zero data retention. (Did I forget anything?)

The sloppy announcement is unfortunate, because there is no real need for that: exa.ai/about looks interesting to me. (Proper product, detailed changelog, etc.) For some reason, they just were unable to write about the cool stuff this partnership might enable in their announcement. Perhaps they thought it would be too controversial for their brand. (edit2: See: https://exa.ai/docs/reference/verticals/people )

edit: Not entirely sure, but maybe I even used Exa already unknowingly as an engine in the OpenRouter web search plugin.

https://openrouter.ai/docs/guides/features/plugins/web-searc...

fwn··on Anthropic's War on open source AI
Whenever I start reading an article and notice traditional AI markers, I throw it into my AI summarizer to see if it's worth reading. Fighting fire with fire.

For example, this article (allegedly) makes two main observations to justify Anthropic being exceptionally bad:

> 1. Anticompetitive behavior. Anthropic cuts off users who get close to building competing AI (OpenAI, Windsurf, xAI), its terms block using Claude outputs to train competitors, it secretly degraded outputs for AI development work (Fable), and it trains on public and copyrighted data while blocking reciprocal use.

> 2. Weaponized safety and national security framing. Anthropic uses risk language to shape regulation (RSP influence in CA, NY, EU), advocate for pause authority while racing ahead, tie distillation to the CCP and military surveillance, and dismiss Chinese open models as a security threat rather than competing on openness.

There was probably more original thought behind the author prompts, but it is difficult to tell because it is all buried under meaningless slop, grande language, and derivative repetitions.

For real people, Anthropic just lobbies the government.

For a badly prompted LLM, Anthropic is laundering fear into paperwork through a feudalistic permission layer plantation model that wears the costume of virtue.

Same same.

fwn··on Worms: The Future of Yesterday's Worms Today
A friend of mine had a younger brother who sometimes played Worms World Party (the version of my time) with us. Since he was much worse, we implemented a handicap by not using the more lethal weapons against him.

I still remember him giggling over a particularly lucky banana bomb he threw.

Anyway: The round-based approach made the game surprisingly calm and inclusive.

fwn··on Signal is working on a paid option to create an account without a phone number
> By disabling signature verification you open yourself up to man-in-the-middle attacks and supply chain attacks.

I am no expert, but AFAIK Android does not disable signature verification when installing from "unknown" sources. It verifies the APK is signed and unmodified on every install, and enforces key continuity on updates.

Signal uses the same signing key for both the Play Store and signal.org APK, so if you at any point installed from the Play Store, the key identity is (as far as I understood) attested by Google, and every subsequent update from either source is verified against it.

I do think that Obtainium pins the key as well, so even without Play Store: If the original install through Obtainium wasn't a manipulated version, you should enjoy the same continuity.

I get the idea about a hypothetical threat actor from within Signal poisoning my specific install. But I think I'll roll with it for now.

fwn··on Signal is working on a paid option to create an account without a phone number
Reproducible builds are nice, and I would love to have them for Signal. But I think I disagree with most of what you've written.

Enabling "unknown sources" does not make my device less secure. The setting is also disingenuously named: It is in fact "known sources" I am installing (not "sideloading") software from. It is just not a source Google wants to know of.

I also do not need to reproduce every new release from source. It is a signed APK I'm getting from signal.org.

If the antagonists in my threat model are so capable they could serve a tailored, signed APK from signal.org for the IP I'm using, I should absolutely not use a messenger whose identifier is my phone number, aka my real world identity AND permanent location marker. That feels absurd. A threat actor that capable could just locate me, pick me up and shake me until I unlock the device.

You are saying Molly exists and works fine, so I'm not really sure the whole problematization of Signal holds up. Does the existence of Molly not disprove your criticism that users would have to use the mainline Signal app from the Play Store?

I think it might be a good sign that criticism of Signal tends to presuppose absurdly capable threat actors. It suggests there is little low-hanging fruit left to criticize.

fwn··on Signal is working on a paid option to create an account without a phone number
> [Signal is] obsessed with [...] user tracking, via app store stats.

Not sure about that. You do not need Google Play Store to download or update Signal. I use Obtainium to update directly via signal.org for a very long time now.

JSON: https://updates.signal.org/android/latest.json

fwn··on Fastmail offers EU data region
> When you start denying IAMP to your customer in the name of "encryption" at that point it becomes privacy theatre, instead of privacy, irrespective of how nobly activist their intensions are.

How would the lack of IMAP compromise encryption? Sounds dubious.

Lock-in effects are problematic, but separate from encryption or privacy in general.

If the concern is actually lock-in, it is worth noting: there is little lock-in in the current Tuta offering. The service allows users to export emails into standard EML files. If you decide to switch providers, simply point your domain to the new provider and import your latest backup.

fwn··on ChatGPT starts blocking direct requests to copy an author's style
I have no experience with style imitation, so perhaps I'm missing something here. I asked Kimi K3 to rewrite your comment in the style of Ernest Hemingway:

> I would like to get the old models back. If anyone can show me the way, I would be grateful. I liked them for NPC dialogue, for TTRPG campaigns and the like.

> I looked into it. GPT 3.5 is still around, I think. But perhaps they have trained it out of usefulness. It is difficult to say.

> They were quirky, the old ones, and not always perfect. But they had flavor, and their characters had nuance, and what they got wrong you could fix in the editing.

Full conversation with thinking: https://paste.ononoki.org/?2fc049fe1ae7302b#GjzuEn8VmaYJ565M... Password: kimitest

Page 1 of 33Next →