HNHacker News
TopNewBestAskShowJobs

gregw2

2,017 karma · joined January 30, 2017

submissionscomments
gregw2··on "The only intuitive interface is the nipple" (2012)
Yeah, this is one of those quotes that is cute/clever... until you have kids and learn or experience how common 'latching' problems are.

It's pretty distressing to watch the desperation and the struggle of a baby screaming and a mom trying but unable to feed her baby.

Then the quote sort of turns from clever into a sign of a bit of real-life ignorance.

gregw2··on Greg Kroah-Hartman – Security in the LLM Age [video]
What a great excerpt; thank you! It reminds me of what I find when I look at CVEs handed out by scanners at places I've worked for actual impact to systems I've owned... there are a lot of slop/false positives. (And that's even without "AI".)

That said, I remember trying to weigh the hype at the time of the announcement reading/skimming the papers Anthropic published, recognizing that bugcount alone wasn't super-relevant but also remember being impressed by an NFS bug and a kernel bug that struck me as relevant at the time. So where did that NFS issue show up in GKH's list you showed so nicely above?

It turns out, AFAICT, it's not on his list, but the reasons are perhaps interesting to others so I will post here. It turns out there were two NFS issues this past year conflated a bit in my memory:

* The Linux CVE-2026-31402 NFS heap overflow that could allow unauthenticated memory reads over the network isn't in that list of 79, presumably because it was found by Claude Code, not Mythos months earlier. (I am guessing it's not his "malicious network packet into the middle of the stack" and is a stronger attack being a remote attack.)

* And the CVE-2026-4747 NFS stack buffer overflow that allowed gaining full unauthenticated remote root access didn't show up in GKH's list of 79 because despite being Mythos-caught, it wasn't Linux, it was FreeBSD.

I guess this does match my memory now that I think about it, that there weren't any smoking Linux guns caught by Mythos.

* (I guess there was also a longstanding 27-year old OpenBSD TCP SACK-handling stack integer overflow than enabled remote crashes / Denial of Service found by Mythos.)

There is definitely Mythos hype, but just because it hit the BSD code base more than the GKH-managed Linux code base doesn't mean it was inappropriate to raise eyebrows from Mythos, in particular since "attacks only get better".

gregw2··on Red Hat being phased out of existence?
If you are running closed source licensed/paid "enterprise applications" on Linux, Red Hat still makes a lot of sense as a successor to the earlier RISC-based Unixes. No?
gregw2··on Why Is Sam Altman a Free Man?
I am not the earlier poster, but I believe copyright infringement at the heart of their business model is what is referred to.

If I download a bunch of music from a torrent without a license, even if I don't listen to it, I'm liable, but if OpenAI or other LLMs gets content by some other unlicensed means (Anna's Archive, t), they are somehow not liable for the copy they made however temporary (but not so temporary if they leave it around to train a second model)?

And/or derivative works? And/or contributory copyright infringement when they regurgitate that copyrighted text when given certain prompts?

I get there is some nuance to copyright law, (four prongs), some utility to the outcome, and some legal (but not plausible) deniability. But there is no way they have clean hands on the copyright front for at least some actions they have taken. If there were, it would be in all their marketing and they would be pushing regulators to bind their competitors, onshore or offshore, more tightly in this regard.

I was around when search engines took advantage of similar ambiguities in copyright that took many many years to get litigated for similar reasons.

gregw2··on Owed a billion dollars in Nvidia stock
Why did Nvidia think quads were a good idea over triangles when SGI was doing triangles? What is a holdover of Sun thinking? Was it a patent differentiation play or a patent defensive move? Or just following Microsoft's lead (and why did Microsoft think it made sense?)
gregw2··on An agent used DNS to reach an external chatbot
Hadn't seen that link. Thanks!

Protecting against an AI convincing the human to let it out of the box is an interesting challenge. Even a dual-keyed system to do so only requires convincing two people, although I suppose more elaborate containment mechanisms can be devised. N-keys is democracy and that doesn't seem immune.

Two random thoughts:

* This box we want to keep AIs in reminds me a bit of the story of Pandora's box

* I'm also reminded of the original alignment problem in Genesis 3 where one creature convinces another to take an unaligned action.

Containment is a pretty fundamental tricky security problem actually once persuasion is part of the threat model.

gregw2··on Postgres SELECT DISTINCT Does Not Scale
This. 100%. So on point.

I'd only add one more observation.

Sometimes the root cause is poor table design (or in analytic/OLAP use cases poor ETL design without proper data validation checks or handling) where uniqueness is not enforced and that is the root cause that should be fixed if at all possible. A "first normal form" violation in the database design so to speak.

If that root cause is not addressed, then SELECT DISTINCT is more often necessary and the SELECT DISTINCT disease to be safe culture and behavior in the code base on top of the database just spreads.

gregw2··on What Sun got wrong
Glad to see you mentioning channel sales.

The rise of the Internet made channel sales handoffs a weak point in the business model. I bet this missed sale went to a reseller who didn't respond and Sun didn't have any controls or visibility on that failure.

gregw2··on What Using AI Therapy Gets Wrong
What's really crazy is therapists are starting to give their clients AI slop as part of their value-add, using it to create writing for clients to take away that resonates more with clients... and the AI is prompted without all the context known to the therapist so a bunch of the specifics and assumptions made by the AI in its advice don't track to other family/friends observing the output but do relate to some hypothetical pattern which doesn't apply.

Misdiagnosis from a therapist is not new, but AI use by the therapist is.

People have had itching ears to hear what they want to hear for a long time, and recently we have all seen in the press stories of AI-only therapy sycophanticly reinforcing delusions, but it is so strange to see a professional therapist human-washing such stuff.

But it makes sense; therapists are not yet savvy to all the weaknesses of LLM analysis and framing bias and they too can be tempted themselves to ask an AI and just pass outputs upwards like various work colleagues I've had...

Still, I was quite disturbed about the unprofessionalism of the therapist when I heard about it. I think we'll see this come up more in the press. like we've seen with lawyers. But not as soon because lawyers have a validation function called a judge.

gregw2··on AWS says it can't restore some data from mideast facilities struck by Iran
I think so.

Although the more paranoid AWS customers who turned on (and pay for) S3 cross region replication or similar cross region DR for other services would be fine.

gregw2··on We need to stop using Stored Procedures
Just learn how to use Liquibase (or flyway, or... ) in your git repo and CICD pipeline deployments alongside your code.

I did it with production Scala apps over a decade ago. I even built sproc TDD test suites.

gregw2··on Salesforce Global Outage
AWS has a history of this before re:Invents (its annual big conference) in my experience.

They've gotten a little better in recent years.

gregw2··on Salesforce Global Outage
Typo: Carr wrote that in 2003, not 2023 for those of you who missed the foolishness and insane wreckage that article caused.

The lost business value and competitiveness caused by outsourcing IT overseas to unmotivated parties under Carr's premise is hard to put your finger on but I have seen the aftermath and it's pretty massive.

gregw2··on Rust is tier-1 language at Microsoft
True. I think we tried bevy but don't remember what if any issues we had.
gregw2··on More questions about whether researchers can trust OpenAI with unpublished math
Err, no. If someone is at fault, it is definitely the company (OpenAI) not the employee in this case.

Just think, isn't the whole point of a company, of incorporating, is that the liability shifts from the employee to the firm?

It is 100% fair to hold the company responsible, and doubly so when the questionable thing the employee is doing is something that A) benefits the company, and B) is on company time (aand with company resources.) I know you weren't making a legal-minutia point but even the high level principles involved are and should be the opposite of what you suggest.

Companies may want to have their cake and eat it too (have employees do their dirty work but then push the blame on the employee) but that's not how it works and it's generally not a society you'd want to live in the more we head in that direction.

gregw2··on Rust is tier-1 language at Microsoft
Oh, I 100% agree. The question is how much you can reduce the effort of the port/migration, and in particular the validation effort.

I've worked on projects where the core bits of code were "90%" converted by some automated tool, and in my view the overall benefit to the project timeline was probably only 20-30% because of the Amdahl's-law-type overheads of validation and bits of code not supported by the automation/conversion process. Nice, but no silver bullet.

Non-idiomatic porting also isn't super-helpful if the resulting code isn't maintainable.

gregw2··on Rust is tier-1 language at Microsoft
Why isn't the game industry moving to rust?

Someone in that industry can perhaps speak to it, but I have two cents of perspective...

I have helped a young person with gamedev interests try to learn rust (on Windows). They've learned some rust, but the graphics+Windows libraries and primitives to work with are not very good nor straightforward, even with AI assistance. Besides weakness in the gaming/rendering domain, there seemed to be some very real versioning/dependency hell that also didn't help.

It's massively easier to make progress on even just a 2D game with something like GDScript-based Godot (or Unity or...).

gregw2··on Rust is tier-1 language at Microsoft
Those interested in this may find the following articles of interest:

Microsoft goals [edit: err, Microsoft hiring manager vision-casting goal ] to convert 1 billion lines of code to rust by 2030 via automated tooling enabling "1 engineer, 1 month, 1 million lines of code": https://thenewstack.io/microsofts-bold-goal-replace-1b-lines...

DARPA work towards automating converting C code to Rust using a mix of 6 different teams using different approaches: https://www.darpa.mil/research/programs/translating-all-c-to... Feb 2026 Progress report: https://github.com/DARPA-TRACTOR-Program/Reports/blob/main/F...

gregw2··on Netherlands pulls gold out of the US
This is all about Greenland and reducing leverage Trump might wield to get it, right?

They can't say that, it just gets them into a pissing match with Trump and what good is that but it's not hard to read between the lines.

I also do wonder if the Netherlands knows anything more about CozyBear/FancyBear and the 2016 election than they've let on. ( https://www.aspistrategist.org.au/rare-insight-cyber-espiona... )

gregw2··on IBM Bob
Hey now, sure, Microsoft Bob didn't get us ordinary users a "partner that helps you by making it easier", but it DID help MS Bob product owner Melinda French get a "partner that helps you by getting 10+ billion dollars" in the end, amiright?

<joking>

Maybe IBM is signalling it is likewise hoping for 10 billion dollars while also realizing the (AI) partner might not end up being that helpful either??

<further joking>

gregw2··on The Overton Window of Food
Agreed. Cheerios and Rice Chex/Krispies are what I settled on for a while... not loaded, not zero, but minimal.
gregw2··on Things I want in a modern relational query language
And Bigquery has continuous queries: https://docs.cloud.google.com/bigquery/docs/continuous-queri...

And many databases have triggers. And with postgres you can combine triggers with NOTIFY to push changes downstream.

But yeah, I feel like most databases are way behind Oracle on this feature and it's so so useful.

gregw2··on Why aren't smart people happier? (2022)
Ugh. This analysis starts off a little interesting with its observation that "intelligence", as analyzed historically, tends to be about solving bounded-context problems (with a known right answer) rather than open-ended problems (D&D called this "wisdom", right?)

But it is lacking so, so, so much in explaining why smart people aren't happier or evaluating the premises of the question.

If my teenager gave me this analysis and question, I'd give them 8 more avenues to explore, none of which the article addresses:

1) Is intelligence Kahneman's "type 1 thinking" or "type 2"? Do people (including you) act on their thinking or their emotions? (Can/do you think smart + act dumb and end up happy?)

2) What does being happy have to do with having autonomy and control and purpose? (Existentialism)

3) What does happiness have to do with contentment and the scope of what one wants to control, ie ambition? Attachment? (Buddhism)

4) What does happiness have to do with one's overall outlook of being pessimistic or optimistic?

5) Is there some deeper insight why a widespread religious tradition such as the Judeo-Christian one has a creation story where where "knowledge of good and evil" is inherently problematic?

6) What does happiness have to do with dopamine and the timing or frequency of solving problems of small vs large size? What degree of problems need to be present for an intelligent problem-solver to be happy vs, say, bored, (example: Marvin the "brain the size of a planet" android in Hitchhiker's Guide to the Galaxy, bored and depressed?)

7) What is the connection between happiness and benevolence, giving vs receiving? Relationships? Why?

8) Why does a socio-economic system based on money-maxxing intended to obtain happiness lead to oversupply which leads to demand-generation/creation/marketing which leads to unhappiness? And similarly leads to conflict and resulting unhappiness? Is there an inherent ying/yang dynamic to intelligence and happiness on a personal or socioeconomic systems level?

I do agree with the author that it's a question worth re-evaluating in an age of "Artificial Intelligence" promises.

gregw2··on A theory for decades of C vulnerabilities
Regarding the "expensive overhead of boxed types", do we just need more work at the hardware ISA level (with pointer tagging or NaN-boxing) and we need the hardware to be aware of those bits and handle them safely/properly via some minor extensions to RISC-V or Intel/AMD/Apple ISAs?

Or do we have to have completely new forms of hardware datatypes?

gregw2··on CIA funding helped keep NeXT afloat in the 80s
Last time I went to donate blood, I read all the fine print they asked me to sign, and I was giving them the right to sequence my DNA (!)

The tech taking my blood had no idea; nobody else had ever read it.

I did complain and ask the blood donation org to make sequencing opt-in and my message was "passed on to leadership" but with no followup from "leadership."

gregw2··on The Microsoft Rebrand Registry
A confusing rename means you the customer can't understand the product line and your large enterprise must have more conversations with Microsoft to clarify. Such conversations then become sales opportunities.

That plus the resume-building "I launched the new product XYZ!" ... when 90% of the code base was the same are the two dynamics I see at play.

gregw2··on Falstad Math and Physics Simulations
Per his GitHub repo ( https://github.com/pfalstad ) last week he ported his electrostatics sim fro. GWT/Java to Typescript+Vite ...
gregw2··on Falstad Math and Physics Simulations
He also wrote zsh ( https://en.wikipedia.org/wiki/Z_shell ) as a sophomore in 1990, moved onto other things a few years later, and a couple decades later in 2019 it became the MacOS's default shell.
gregw2··on The lattice of sets of natural numbers is rich (2021)
It was a joke/tease question.

I have yet to be able to create diagrams or visualizations I am happy with with LLMs. I can get a diagram, but tweaking it via prompts is extremely painful.

I do think it's a interesting moderately straightforward test case for an LLM that is beyond today's frontier.

gregw2··on The lattice of sets of natural numbers is rich (2021)
What a great visualization!

Now can your favorite LLM make me a similar one for the Real #s?

Page 1 of 25Next →