ShinyHunters making the claim. Again.
2,685 karma · joined January 2, 2013
ShinyHunters making the claim. Again.
all 3 can be true at same time:
1. sensationalizing rarely helps and can obscure and hurt
2. the AI capabilities are underrated
3. attempted govt regulation is not the answer
the intent, or lack of intent, of the agent is mainly irrelevant if it is in the hands of a human with 'bad' intentions. what is more relevant are the capabilities of human + AI.
https://www.nytimes.com/2026/09/16/technology/openai-model-s...
Agree that is a big-time longer-term threat but "user won't know the difference" means the user gets the order with parity in delivery time, product quality, returns experience, etc...that won't be replicated overnight, at least not at scale (interesting to think what products could be done first...similar to Amazon starting with books).
Meanwhile ads made Amazon $19.8 billion last quarter alone, even while detracting from our user experience. Can't rip that business away overnight either, but it is less of a lift imo.
Meaning, even if merchants would have a difficult time moving from Amazon to an AI native version of Amazon, this is still a threat.
So, the first set of questions is would 'exponentially better LLMs' dramatically increase the probability of any of the above, or domains that Dario is not citing? That assumes that exponential improvements will happen if there is not 'pacing'.
IF answers to above are 'yes', then we need to question if 'pacing' is viable. To use a different domain, regulating 95% of vehicles to a max speed would likely save 100s of 1000s of lives, but is not perceived to be viable. In other examples, regulation has unintended consequences in the opposite direction (e.g. some 'rent control' efforts and arguably some drug/alcohol laws).
if that is goal then why not go 100% open source to eliminate the ts derp control as well and get full sovereignty?
like netbird, openziti, zerotier, etc.
1. workloads use existing credentials support RFC 7523 and OIDC discovery, 'trust the trust (credentials) which has already been established'. basically extend current dominant NHI paradigm.
2. DPoP mandate a signed proof for each request. so tie credential to a client-held key and specific request detail or context. viable to do at scale with #1, or does it diverge (e.g. because most #1 methods as most are not designed for DPoP?
separately, it is interesting they are adding an oem type offer:
>We’re working with our cybersecurity technology and services partners to integrate Claude Mythos 5 into the products and services defenders already use to secure their software.
anyone know the shape of those contracts, e.g. pure tokens/usage or more of a traditional licensing or oem type structure?
i only play a laywer on HN but seems categorically different than the safe harbor dmca which protects youtube etc since google has full control?
same for the amazon case. amazon for fraud and/or tm infringement.
the buyer of the ads as well in both cases but of course those are smaller pockets to empty.
it needs to be done legally but i will say that ads can benefit startups and small companies wrt building awareness against brands which already have it - so i dont think 'ads are the scourge of the earth' but of course rule of law needs to apply.
genai doesn't change that anytime soon?
one argument: only services which need to be available to unauthenticated endpoints should be default reachable.
all other services should be default unreachable (no data plane until authorized ...then use internet and other networks to establish the connections).
yes, that is not always easy. it is much more possible than it used to be.
and arguably we now need to commit to the tradeoffs of default unreachable services.
1. foss, p2p-only, no server or intermediate nodes to trust (rayfish)
2. foss, brokered if necessary with all nodes self-hosted (openziti, nebula, some wireguard variants)
3. non-foss, mix of p2p and brokered, host some of the nodes yourself (openvpn, myriad of wireguard variants/wrappers like tailscale, headscale, netbird, netmaker)
why is #3 so much more popular?
+ iroh and openziti can both be app-embedded
+ so the app developer embedding in their service is a good use case for both
+ openziti is used for services in which scale and security are critical
+ whereas iroh allows participation from parties which don't have any prior relationships - which can be very convenient
+ LLM-powered robotics, autonomous, IoT, smart manufacturing
+ LLM-powered biotech, healthcare, genetic engineering, medicine
+ Recursive model improvement
+ Multiply the # of devs (software truly eats world)
+ Exponential increases in model performance / cost decrease (algorithms, power, infra, chips, architectures, etc.)
+ in stagflation of 70s/early 80s - states create state-run lotteries to help fix their budgets
+ 2008 great recession - states legalize casinos to recover lost tax revenue and prevent folks from traveling out of state to gamble
+ C19 - states fast track the legalization of mobile sports betting and online casinos to secure immediate tax revenue
absolutely although i wonder how different 'trust' is in the culture of tomorrow? will it 'matter' as much, be as cherished, as earned over the fullness of time?
i suspect it is a pendulum - and we are back to oak trees at some point - but which way is the pendulum swinging right now?
Great articles have been written on the engineering but I like this one from 1909 showing the perspective of the time:
articles like this makes me wonder - does the "AI" in "AI data center" amplify concerns beyond 'normal' concerns around commercial and residential real estate development projects?
on one hand, i feel it is partially the media reporting on it more than in the past, but then these articles and anecdata about meetings like this across the country make me feel there may be other differences?
note - in the article, the data center wasn't even on the agenda, nor is a deal in place and yet the unprecedented discussion:
>“I want to be clear about this, so watch my lips. There is no data center deal,” Edds said. “We have made no offers on any data centers. No data centers have made any offers to us. We are not speaking to any data centers.”
yes, the sycophant noted by Om, but also:
+ asking you (prompting the human?) to keep the convo going in very specific ways
+ seemingly more personalization each day
both unfortunately crowd out the long tail which LLMs might otherwise help us explore, but of course the algorithms prefer putting us in positive feedback loops in echo chambers we like (and are conditioned to like)
i wonder if we will see a materially larger number of brackets filled this year than the recent trajectory would indicate (as a very coarse indicator of agent-filled brackets).
i suppose could be 'placebo' but would it matter if the result is what i want, and i can't easily attain it other ways?
i do feel it is somewhat of a self-fulfilling prophecy - i am essentially practicing something so getting better at it. not enough reason though to 'practice' an alternative, at least for me personally.
>Looking for hints in the console? That's the spirit! But the real challenge is in Fiu's inbox. Good luck, hacker.
(followed by a contact email address)