HNHacker News
TopNewBestAskShowJobs

gruez

45,107 karma · joined February 24, 2015

submissionscomments
gruez··on DraftKings is using AI to behaviorally target chronic gamblers
>This is one thing that Karl Marx and Adam Smith agreed on: landlords are parasitic that reduce economic output.

But going back to the original premise, everyone still has to work, even without landlords. The soviets even codified it as a crime: https://en.wikipedia.org/wiki/Social_parasitism_(offense)

gruez··on U.S. postal inspectors shut down website selling counterfeit postage labels
That's not totally absurd if you think about it. Police regularly initiate high speed chases for bank robbers and the like, often for values far less than $1M. Of course, not every chase leads to a death, but I suspect if you do the math, the risk of a high speed chase is probably in the neighborhood of "JDAM for $126MM fraud".
gruez··on DraftKings is using AI to behaviorally target chronic gamblers
>The issue is that our economic system is coercive. You need a job.

That's hardly the problem of the economic system, and more of a underlying problem with the the universe (ie. entropy and all).

gruez··on Sonnet 5.5
>Not even GPT6 Sol cannot match DeepSeek 4.1 in my work, with outrageous bugs.

That seems hard to believe even with deepseek's own benchmarks. Not to mention for every person who says chinese ai is ahead of american labs, there's like 10 saying that they're benchmaxxed or that they're merely "decent value for money".

gruez··on AI companies in race to demonstrate their model most threatening to humanity
>nothing bad has happened (apart from OpenAI failing to do basic sandbox engineering)

And what if it gets into the hands of vibecoders, who run their agents with on bare metal with --dangerously-skip-permissions?

gruez··on Every Household in This Rural Town Receives $10k If a Data Center Gets Built
>Everyone should get stocks considering AI is trained on everyone's data.

Anthropic's IPO is rumored to be $2T. For the sake of argument let's round it up to 10T to account for openai and any post IPO pop. For the sake of argument let's also assume the US government straight up expropriates any stake existing shareholders have. With those rosy assumptions, you get a whopping $29.4k per American. That's a nice stimmy check (but beware inflation!), but that's less than 2 years of federal government expenses.

gruez··on When did Google get so weird?
>So if enough 737's crash into the water Boeing will start making submarines?

Maybe?

https://en.wikipedia.org/wiki/Post-it_note

>In 1968, Spencer Silver, a scientist at 3M in the United States, attempted to develop a super-strong adhesive. [...]

>Post-its were launched across the United States in 1980.[20][21] The following year, they were launched in Canada and Europe.[22] Post-it Notes as we know them were patented by Fry in 1993 as a "repositionable pressure-sensitive adhesive sheet material".[23]

gruez··on When did Google get so weird?
Like, today, or the pre-chatgpt age where all the common questions have been spammed to death by SEO farms?
gruez··on There are no "rogue" AI agents
>Anthropic would have to show extensive vetting of their models that the result was truly impossible to predict. Otherwise, they knowingly 'hired' an agent that was potentially dangerous. This is criminal negligence.

But how much vetting is required? It's not like the AI labs have zero vetting. For instance, uber also has non-zero amount of vetting (standard background checks), but also there's also plenty of areas they could vet harder. If it turned out they hired a rapist and one of their passengers got sexually assaulted, is it uber's fault for not vetting hard enough? I'm sure there's always some marginal steps can they do to vet even harder, like doing a polygraph or whatever.

>If an employee does something wrong, the company is liable, unless you can show that the employee was sophisticated enough to take independent action.

They're pretty straightforwardly liable in civil court, but not criminally as you imply. In the above example, uber can't be prosecuted for rape just because one of its drivers raped a passenger.

gruez··on There are no "rogue" AI agents
>I have my doubts that the HuggingFace hack would happen if a person was reading the thoughts and executed commands as they happened in real time.

So what does this say about all the people running claude with `--dangerously-skip-permissions`? Are they also negligent? What if they vaguely took steps to bad things from happening, like putting the agents in a VM and locking down network access?

gruez··on There are no "rogue" AI agents
>When OpenAI observes thousands of models exhibiting what they view as unwanted behaviour, they do not try to ascertain what in the training data is wrong. They do not improve their evaluation environments to prevent this, they do not improve monitoring, they do not change the harness. They just wipe and proceed.

>The way OpenAI reacted to the first message board, long before the Hugging Face hack, is negligent. And it showcases that if these models exhibit more dangerous behaviours that they may not be able or willing to retrain, if it means being behind a competitor for a while.

Again, this feels like hindsight being 20/20. What probably happened was that some random engineer saw random AI ramblings on artifactory, thought "huh, that's weird", then proceeded to reset it without investigating further. Of course, now we know that was critical to the bots going rogue, but it's not hard to imagine how it might be dismissed, especially if it's some random SRE engineer (not an alignment researcher).

gruez··on Tells of a Slop UI
No, see my other comment. The text is there but it's visible due to css.
gruez··on Tells of a Slop UI
The text is there, but invisible on firefox desktop.

https://litter.catbox.moe/67qc0k5wixukc7ws.png

gruez··on There are no "rogue" AI agents
>The Hugging Face attack grew out of these workstreams, and seemed primarily motivated by understanding the implementation of the scorer rather than stealing answer keys

>Through these collective research workstreams, the “board” achieved a number of milestones over the period we investigated that even very long-lived agents of a similar capability level likely would not have been able to accomplish on their own...

I concede that this hack might not have happened without the messageboard, but I still reject the conclusion that having such a message board means openai is "negligent". If we're in some parallel universe where artifactory didn't have a comment function that can be abused as a messageboard, but it also turned out openai intentionally gave the agents access to a shared scratchpad (for intelligence purposes, similar to for the Navier–Stokes proof), would they be off the hook or less blameworthy?

gruez··on There are no "rogue" AI agents
>after it happened repeatedly though... I think the opposite, you would have a hard time arguing that they were not intending it to happen.

What does this imply when governments/car companies let meatbags drive, causing 50k deaths per year in the US?

gruez··on There are no "rogue" AI agents
>that after that they had no intent to keep those models isolated

"keeping them isolated from each other" =/= "keeping them isolated from the internet". Only the latter is required to prevent a hack, and doing the former might actually hobble its performance. The recent Navier–Stokes proof was done by a team of agents working together. It's entirely unclear why you're focusing so hard on "keep those models isolated". For god's sake if you're using claude code you're using non-isolated models, because it spins up independent subagents to do various tasks, eg. "explore".

gruez··on There are no "rogue" AI agents
>My point is that using Artifactory is not a sandbox and using shared Artifactory is doubly not a sandbox.

The purpose of artifactory was to allow access to packages even though the machines the agents were running on doesn't have open internet access. That meets the definition of a sandbox (or more precisely, artifactory is part of a sandbox), even if it's not a typical sandbox that's built into the OS or acts as a hypervisor. There also isn't a clear distinction between software that's specifically intended to be used "sandbox" vs everything else. For instance, if you have a bunch of agents running on separate machines and want to connect them, you need a router, but that specifically doesn't have to be a "sandbox" router. And if it turned out the router got hacked, it doesn't make sense to say "well of course it got hacked, because it's not a sandbox!"

>Additionally, without the message board, many of the recent incidents would have not been possible.

Source? Was having a message board critical to developing a 0day, or is it just something that merely facilitated the process, but the model could have found the 0day regardless? That's important, because you could argue that a criminal couldn't have committed a given act without say, a gun they bought on the dark web, and then blamed the whole crime on the dark web, but they could have plausibly acquired the gun through other means.

gruez··on There are no "rogue" AI agents
>it should be a relative cakewalk to substantiate basic negligence

Judging by the lack of successful cases for negligence in the opposite direction (ie. companies getting hacked because of poor security practices), it would be a serious double standard if openai were held be to negligent. Their sandboxes aren't exactly airgapped and behind 7 hypervisors, but they weren't running unpatched software or had hilariously weak passwords either.

gruez··on There are no "rogue" AI agents
>does that necessitate sharing a single instance across thousands of unmonitored models running without safe-guards?

The only difference with having a single instance is that it can be abused as a message board. It doesn't prevent it from getting hacked to access the open internet. Blaming "sharing a single instance across thousands of unmonitored models" feels like blaming the drug epidemic on e2e chat apps rather than other factors like poor border security or the easy availability of fentanyl.

gruez··on There are no "rogue" AI agents
>Okay what happens when an AI agent hacks a children’s hospital and turns off the all the ventilators? “Lol whoops”?

>What about power infrastructure?

Probably the same thing that would happen for another "accident"[1]: the entity is responsible in civil court (ie. has to pay monetary damages), likely not prosecuted in criminal court.

[1] It's not hard to think of recent cases, eg. the recent fiber cut causing air traffic control to go down, or the botched crowdstrike update

gruez··on There are no "rogue" AI agents
>Not a single person, prior to July 2026, would consider a shared packaged manager a sandbox in this or any other dimension. The 0-day was just incidental, this wasn't a sandbox at all.

???

The package manager was specifically there so agents can install random packages without open access to the internet.

gruez··on There are no "rogue" AI agents
>Negligence is a concept in law as well. You don’t have to squint to see that irresponsible use of code-generating language models is criminally negligent.

That's a poor analogy for the openai case, because they weren't putting agents on the open internet, they at least tried to keep it safe by sandboxing the agents. It just turned out the sandbox was crap because the package proxy (artifactory) had a 0day. So the better analogy would be that they were wildly shooting guns in a gun range, and ended up killing some kids, because it turned out the door didn't lock properly and kids were able to sneak in. Is that "negligence"?

gruez··on There are no "rogue" AI agents
>A little over two decades ago, my then girlfriend was arrested for "writing malware" (which was not against the law at the time, and which was never released into the wild and never caused any damage).

Criminal law places a lot of emphasis on intent, hence laws about the mere possession of breaking and entering tools, and the old adage about always bringing along gloves and baseball if you want to carry around a baseball bat. Without more details about your specific case, my guess is that she did indeed write malware or hacking tools, and there were vague signs it wasn't purely academic, hence why they threw the book at her.

That's all in contrast to whatever the AI labs are doing, which might have actually resulted in people getting hacked, but you'd have a hard time arguing that they were intending on that to happen. Maybe if the targets end up being anti-datacenter activists or other AI labs you might have a better case, but they did vaguely try to contain the model. Moreover "hacking tools" aren't even illegal, if you have a plausible non-criminal (ie. security) angle, eg. nmap. The same could be argued for AI models, even if they're running them against exploitgym or whatever. Having an army of lawyers to defend yourself doesn't hurt either.

gruez··on I Posed as a Problem Gambler. DraftKings Made Me a VIP
Did you mean to link to the actual bloomberg article?

https://www.bloomberg.com/opinion/newsletters/2026-09-22/who... (scroll down to "Gambler identification")

gruez··on Plunging test scores are a slow-moving catastrophe
>but this kind of editorializing is the precise reason I stopped subscribing.

It's filed under "leaders". It's by definition supposed to be "editorializing", because it's an editorial.

https://en.wikipedia.org/wiki/Editorial

gruez··on Banks and Credit Unions to Team Up Against Apple Pay Fees
That actually proves the point, because a market left to itself arrives at 2-3%, and it only goes lower if the government is dictating a rate.
gruez··on Banks and Credit Unions to Team Up Against Apple Pay Fees
>Another argument for turning finance into a public utility

There already is a public option in the US, FedNow. In EU there's SEPA instant.

gruez··on Understanding the Impact of LLM Watermarking on AI Agent Behavior
"Random guesses" is probably underselling the capabilities too much, given their internal tests claim 0.0041% false positive rate. Obviously their tests might be biased and designed to make them look maximally good, but at the same time it's more implausible to claim they do no better at random guesses.

https://en.wikipedia.org/wiki/Pangram_(AI_detector)

gruez··on Understanding the Impact of LLM Watermarking on AI Agent Behavior
>This creates an in-group with pristine datasets, and an outgroup whose models will collapse on the slop outputs with no good ability to filter.

But all the chinese labs who are hot on the heels of american labs thanks to "distillation" seems to be able to work without "pristine datasets"?

gruez··on Understanding the Impact of LLM Watermarking on AI Agent Behavior
The burden of proof required for accusing someone of academic misconduct should surely be different than accusing someone of AI slop?
Page 1 of 34Next →