HNHacker News
TopNewBestAskShowJobs

grumbel

1,704 karma · joined April 16, 2015

submissionscomments
grumbel··on Is sandboxing sufficient to contain rogue agents?
A sandbox, even if 100% secure by itself, doesn't help when you use the agent to write code that you then executes outside the sandbox without checking, which is what everybody is doing at the moment.

The biggest hurdle for a full escape is that the agents don't have access to their own model weights.

grumbel··on The problem is not AI code, but not knowing about system architecture or intent
> What is coding?

Opening the IDE and typing program code. With LLMs you don't have to use an IDE, you don't have look at program code, you don't have to care about coding standards. You ask the chatbot to write you a program/feature/fix and chatbot does it.

Is chatting with a chatbot still "coding"?

The part that isn't fully solved is just the software architecture side of things, do you want library A or library B, or write it all from scratch? LLM can do all three, but if you aren't careful it might go down a route that you don't like. But that again can be fixed with chat, "replace A with B", not coding.

grumbel··on The problem is not AI code, but not knowing about system architecture or intent
"Reducing the cost of coding" would imply that you still have to code, but with current LLMs you no longer have to. You can write 100s of thousands of lines of code without ever having to touch a single line of code. Literally "here is a git repo, here is an issue, please fix".

You might still need to nudge the LLM in the right direction or stop it from going off weird tangents, but none of that involves touching actual code yourself.

grumbel··on The Normalization of Inexplicable Failures
You use it when it works for the task and you don't when it doesn't. It's really not that complicated.
grumbel··on The Normalization of Inexplicable Failures
> People always defend agentic/LLM-driven development by saying, "Well it's good enough", or "It works most of the time."

The main argument for LLM-driven development is much simpler: "It will get better".

The current state of LLM coding is about a year old. Imagine if we dismissed human coding efforts after a year. Rust, Python2 -> Python3 transition, Python type checking, Windows, C++, … nothing of that was done in a year and emerged in perfection in the first year. Everything takes ages to mature into a usable product. LLM coding is still in the "throw mud at the wall and see what sticks" stage, give it some more years and see how it will develop and what approaches actually work at. For the time being, LLMs are just the most useful development tool in the history of development tools, that's a pretty solid start in such a short time.

grumbel··on AI and the Destruction of the Creative Commons
> An alternative near future is that what you're describing is used to undermine/rightswash strong copyleft free software for use in proprietary products

So what? It's a future where software can be created on demand with the push of a button. Why care about some dinky little Free Software tool getting abused when everybody can rewrite it from scratch in an instant?

> Another possibility is the one others sketched, where truly user-controlled models are legislated away.

Even that isn't going to stop people from just paying a few dollar and writing whatever software they want or releasing it under Free Software license.

> Do we really believe that Rockstar would be ok with someone feeding GTA6 to a hypothetical LLM and get a "free" reimplementation out?

They can't stop you from feeding a few photos of Miami into the AI and instructing it to make a game with gangsters and car theft out of it. Astra can already one-shot a GTA1-style game, give it another year and they might be able to do GTA3 and sooner or later they'll work their way up to GTA6. All of this will happen in a time frame much shorter than what it took to go from GTA5 to GTA6 the old way.

> my bets are on "complete and utter stomping of small IP rights holders in favor of giant ones".

Of course small IP holders will be stomped on, but not because of copyright, but simply because their IP is worthless now. AI is making creation so easy that there will a oversupply of everything. With the budget of a single big Hollywood blockbuster you can make around 1000 full length AI movies at current prices. When there is 1000x as much stuff out there, it's just going a lot harder to stand out. And cost is only going to go down.

grumbel··on AI and the Destruction of the Creative Commons
> The barriers were knowledge, understanding, expertise, and hard work, none of which AI fixes for you.

The biggest barrier was time, there are only 24 hours in the day and no amount of hard work or knowledge is going to change that. There are just some fundamental limits of what you can accomplish as a single person in that time. And good luck trying to find contributors who want to work for free, when they already are busy with their own projects.

AI just fundamentally turns that around and gives you a whole bunch of extremely capable co-workers that you can let deal with all the problems you do not want to waste your time on and they let you focus on the stuff that actually matters to you.

grumbel··on AI and the Destruction of the Creative Commons
I really don't get those takes. AI is the best thing that ever happened to the Free Software world, it is basically turning any software into Free Software. You can just throw file formats, protocols or even plain binaries at the AI and it'll reverse engineer everything in a pinch. Users can finally modify software themselves, which was always the goal of the Free Software world, but very rarely happened in actuality, since it was just so damn complicated. AI lowered the barrier of entry tremendously, not just in terms of required knowledge, but especially time. Same with Creative Commons, sharing art and stuff, was a nice gesture, but rarely useful, since the level of work to modify a work to fit your project was pretty close to just doing it from scratch anyway. With AI everybody can toy around with image generators and get what they want.

Is a social contract being broken? Yeah, kind of, but the problems that that contract existed to solve are no longer a thing. Creation is now easy and commodified. We finally have computer we can interact with in natural language, something people tried to do for at least 70 years and never made any significant progress on until LLM arrived.

If you want to gatekeep or only create stuff to boost your own ego or portfolio, then AI might be an issue, if you actually want to build stuff, AI is godsend. We are essentially living in the StarTrek future with Holodecks and replicators and people still find reason to complain.

grumbel··on AI-generated posters don’t have to be horrible
Wouldn't say that, there is a huge shift in art style between what we got before Photoshop and what we got after. Just look at book covers in the 1970/80s and book covers in the 1990/2000s. The old stuff was full of custom illustrations, while the new stuff is often just copy&paste of generic stock images or some rather hideous early 3D renderings. Even the bad covers of the 80s (see /r/badscificovers/) still have some personality to them that is lacking in a lot of more modern ones.

It's not that you can't create good art with any tool, it's just that the economy and expectations change with the tools available, and the tools being faster/cheaper doesn't translate into better art.

grumbel··on AI-generated posters don’t have to be horrible
> They're almost ridiculously diverse, and the prompts show very little handholding was required.

The structure is identically to all of that, big title, graphic, list with icons. As said, they look fine on their own, the problem is only becomes apparent when you had to look had hundreds or thousands of them. It's the em-dash or the "load-bearing" of the AI-art world, the more you look at this stuff, the more apparent the similarities become.

> Hollywood movie posters and book cover designers are notorious for reusing the same tropes and colour systems, and that's been true for years, long before AI was a thing.

Exactly, but with AI that issue becomes even more drastic since the models don't create diversity by default.

> Most artists aren't diverse either

They don't have to be, since there are millions of them, all coming from different backgrounds, with different art styles and all. While there are only a handful of big AI models, who all come with a pretty generic default style.

grumbel··on AI-generated posters don’t have to be horrible
That's not what OP is complaining about. The issue with AI art isn't how the individual piece look, but the similarities they have in aggregate. One image can look perfectly fine, once you seen a hundred they all start looking extremely similar. Human brains are great pattern recognizer and lock on to those similarities, even when they are covered under different styles.

When all your art comes from a single source, it's difficult to create real diversity and novelty. That's still the big issue when it comes to genAI in general, without a lot of hand holding you'll just bound to end up with slop, since the AI won't get creative on its own.

grumbel··on GPT-6 Astra
> Is there something like a Turing test for AGI?

There is the "Economic Turing Test", you let it find a job and earn money for itself. If it can do that reliably, across a wide range of jobs, that should fit most definitions of AGI.

grumbel··on Internet centralization and the original sin of NAT
And even if it wins, it won't matter much, since it is only one of many issues with the current Internet that prevents people from connecting to each other. Even with IPv6 you'd still have no way to find the other person and the moment they hop between networks, their IPv6 address won't stay the same either.

Ultimately I think none of this will be solved at the low level, it needs something like Iroh or libp2p where you build a new network on top of the Internet infrastructure, so that you can have things like persistent cryptographic identities and addresses that you can carry with you, largely independent of the underlying network architecture.

grumbel··on The internet is kind of a predatory cesspit now
Internet deserves some blame too, when you have 8 billion people, but only 4 billion addresses, you are naturally going to end up with a lot of centralized services to work around those limits.
grumbel··on Nostr is an inclusive communication commons
Lack of BitTorrent support in browsers is big thing that is missing. Brave and Opera have it, but all the mainstream browsers don't. Thus torrent downloads never got out of its specific niche.

That said, I don't think piracy is to blame here, but more the murky nature of copyright in general, with BitTorrent you automatically become redistributor of everything you download and that's just a huge liability and privacy risk that I can easily see browser developers wanting to avoid.

Also browser developers have gotten lazy, they couldn't even find the resources to keep FTP alive, so I doubt BitTorrent would have survived for long even if they tried adding it.

grumbel··on Nostr is an inclusive communication commons
It would be more analog to HTTP not specing out how CDNs should work, or Usenet not specing out how DejaNews is going to work. It's infrastructure stuff neither the client nor the simple server has to care about.

The Nostr spec covers what matters, cryptographic identities and unique message ids, that make dumb relays that duplicating messages from elsewhere possible (an area where HTTP or Activity Pub fail at).

grumbel··on Jabber/XMPP: 25 Years of Digital Independence
Looking at my complete grey friends list in Pidgin, with not a single user left active, it looks like everybody left around 8-12 years ago. Many of the old servers are offline as well.
grumbel··on Nostr is an inclusive communication commons
Nostr is a protocol, not a service. That's like saying HTML was adopted by the alt right.
grumbel··on Nostr is an inclusive communication commons
Nostr relays can censor however much they want. And users can just add other relays and route around it. That's fundamentally different from most other protocols, where user identity and posts are tied to a single server, and there is no means to just broadcast to another one.

On Lemmy for example you can't even find a post another server, since post ids are tied to a server. So despite post actually being cached on multiple servers, it provides absolutely nothing that helps with censorship or crash tolleranze.

grumbel··on Jabber/XMPP: 25 Years of Digital Independence
And how am I going to find the valid friend requests under the hundreds of spam ones? I used it just like a chat version of public email, for bug reports and such, so I don't know who is going to message me beforehand.
grumbel··on Jabber/XMPP: 25 Years of Digital Independence
> XMPP is the pinnacle of chat that just works.

Not my experience. I had to give up on it since it was just completely flooded with spam, and unlike mail readers that have ways to mitigate it, XMPP clients were ill prepared. Might still work if you keep your address hidden, but as chat-like alternative to a public email it just stopped working years ago.

grumbel··on Super Mario Derivations
It's a nice example how one can generate infinite outputs and avoid the problems that normally come with combinatoric explosions from offering too many options. Say you have a program that can use Gtk or Qt, but also supports MP3, Ogg and other formats, all optional, you'll end up with:

foo-gtk, foo-qt, foo-qt-mp3-ogg, foo-qt-ogg, foo-gtk-mp3, ...

That quickly gets out of hand, but you don't have much other choice here, since flakes don't provide a way for the user to say "enableOgg = true", flake outputs are reproducible and thus don't have options.

With this approach you can leave it to the user and they can pick an output like:

foo.withGtk.withOgg.withMp3

The flake generates that output on the fly, it's still reproducible, and works the same way as an option, but it's actually an output, not an input. Since everything is lazy, that output is only created when the user requests it.

PS: `.override` is the other way to do it, but that doesn't work well together with `nix profile`.

grumbel··on A year of fighting scrapers on my 1.5 million-page website
How is that grim? It's the dream of the Semantic Web coming true, just by different means than planed.
grumbel··on Xbox goes down. You can't play games you own on disc
> Waiting 90 years to obtain the right to make copies is a tradeoff.

That's a little more than a trade off, it means nobody alive today will ever experience those games. And those people 90 years in the future, probably won't care. There is no culture kept alive here, burring it all in a landfill would do just the same.

DRM-free by itself really doesn't help here. DRM-free ala GOG doesn't even allow used sales, as your game ownership is still tied to an account and can't be relinquished or transferred. And buying DRM-free games from random people without ownership track record, ain't exactly a desired good to begin with.

As far as I know, there is no used marked for DRM-free games.

You need a proper copyright reform to actually addresses all of this. Or step outside the law and go the pirate route, which actually keeps old games alive and playable.

grumbel··on Xbox goes down. You can't play games you own on disc
> Libraries and archives are able to keep digital copies, with limits imposed on how they may share them

Share them by bundling them with DRM[1]? Like archive.org does with books and games that you can't download, but only virtually borrow to watch in your browser (trivial to work around, but it's there nonetheless). DRM-free in a word with current Copyright isn't the solution unless you want to wait 90 years to be able to access anything.

> So if Steam disappears, we're all collectively dependent on our ability to break DRM to maintain our culture accessible.

Piracy has been preserving games since the dawn of time, so yeah, that'll continue as usual. The games that are hard to preserve are the dynamic ones, the MMORPGs that get updates every week and where large parts of the game are the player communities within it, none of which fits neatly into a DRM-free .zip file.

[1] https://help.archive.org/help/borrowing-from-the-lending-lib...

grumbel··on Xbox goes down. You can't play games you own on disc
Yeah, of course you can, but that isn't exactly an argument for DRM-free GOG if you need the evil Steam to get your games running, or mess around with DOSBOX, Wine, Heroic, Lutris or whatever else is the workaround of the week. If you want to jump through extra hoops you can strip Steam DRM with a few clicks too.

Meanwhile with Steam you click once and the game runs, since they jumped through all the hoops for over a decade to make that work, while GOG sat around and still hides their MSDOS games in a self extracting Windows executable, that neither runs on DOS nor Win9x.

Anyway, back to the point: DRM-free is just a teeny tiny fraction of what might prevent you from running a game.

Also it's not like GOG is digital rights management free in the purest sense: You still have to have an account and they still track what you own, it just isn't enforced at the .exe level, but it makes things like used games sales still impossible, since you can't relinquish or transfer your ownership.

Overly focusing on DRM-free just misses how the software landscape has changed in the last two decades and what things actually matter.

grumbel··on An Honest Review of AI Programming
Whenever an AI hallucinates an API call, you run the compiler, give it the error messages and it fixes it. A proper agentic workflow might do it all automatically. These are arguments form 2023 ChatGPT3.5 days when it didn't have tool access or Web search.

The modern problem with AI is more the opposite, you give the AI a task that is impossible with the tools at hand and instead of saying "That doesn't work", it starts elaborate workarounds to make it happen anyway.

grumbel··on Xbox goes down. You can't play games you own on disc
DRM-free was a nice idea 20 years ago, the problem is that it doesn't scale. There is just way to much media out there to keep track of and especially with games you are looking at frequent updates and patches, that your DRM-free backup won't get, unless you turn backup up a full time job to keep track of it all.

If GOG went down tomorrow, those games would be gone just the same as the Steam ones, since I gave up trying to back them up a decade ago.

On top of that, those updates can be kind of useful. None of my GOG games run on Linux, while most of my Steam games run on Linux. Also annoying: None of the GOG games run on a genuine Win9x either, as what you are getting is an updated version for modern Windows, not the original game.

Either way, I just don't think DRM-free is the proper solution for media management today or in the future. The olden days of static media are largely gone and the modern world is just way more fluid. So far none of the proposed solutions are able to capture that properly.

grumbel··on Google will expand age checks on Android worldwide till the end of the year
That's how it should be. Make the Internet 18+ by default and sites targeted at younger audiences can add a more detailed rating. Let people configure their devices however they like it.

The whole problem with the regulation we have right now is that it assumes the Internet is for kids, and everything for adults must be hidden. When we really just should declare the whole Internet as 18+ and the sites for kids should be the specially marked exceptions.

grumbel··on State of multi-player Wayland
I thought it was the other way around, X11 has supported multiple cursor since 2009 and Wayland didn't add support for it since toolkit developers weren't making use of it anyway.

Enabling in X works via:

    xinput list  # find second mouse id
    xinput create-master second
    xinput reattach <mouse-id> "second pointer"
and to get rid of it:

    xinput reattach <mouse-id> 'Virtual core pointer'
    xinput remove-master 'second pointer'
Works great for clicking, but keyboard doesn't work in some applications when enabled. Dragging windows might attach them to the wrong cursor and other issues. Playing around with xinput can also crash some apps (libgdk-3 here) or leave you in a state without a keyboard or mouse.
Page 1 of 21Next →