HNHacker News
TopNewBestAskShowJobs

gz5

2,685 karma · joined January 2, 2013

submissionscomments
gz5··on Hackers Say They Stole Sensitive FBI Personnel Records
https://archive.is/onF4s#selection-8107.0-8107.70

ShinyHunters making the claim. Again.

gz5··on The Hugging Face Hack Wasn't What It Was Cracked Up to Be
https://archive.is/hnpmx

all 3 can be true at same time:

1. sensationalizing rarely helps and can obscure and hurt

2. the AI capabilities are underrated

3. attempted govt regulation is not the answer

the intent, or lack of intent, of the agent is mainly irrelevant if it is in the hands of a human with 'bad' intentions. what is more relevant are the capabilities of human + AI.

gz5··on What's Scarier Than Agents Taking over Internet? CEO Cartel Trying Take over AI
and meanwhile OpenAI adds to the Anthropic-stoked fire:

https://www.nytimes.com/2026/09/16/technology/openai-model-s...

gz5··on Amazon vs. Perplexity – U.S. Court of Appeals for the Ninth Circuit
>If AI automatically places orders on Amazon's site, tomorrow it could place the order on another company's site, and the user won't know the difference.

Agree that is a big-time longer-term threat but "user won't know the difference" means the user gets the order with parity in delivery time, product quality, returns experience, etc...that won't be replicated overnight, at least not at scale (interesting to think what products could be done first...similar to Amazon starting with books).

Meanwhile ads made Amazon $19.8 billion last quarter alone, even while detracting from our user experience. Can't rip that business away overnight either, but it is less of a lift imo.

gz5··on Amazon vs. Perplexity – U.S. Court of Appeals for the Ninth Circuit
Can't comment on the legal basis in the eyes of CFAA or DAFA, but from a business perspective AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads, which is a large part of their revenue.

Meaning, even if merchants would have a difficult time moving from Amazon to an AI native version of Amazon, this is still a threat.

gz5··on Anthropic boss Dario Amodei calls for AI development to slow down
Dario/Anthropic cites 3 domains: 1. cyberattacks 2. bioterror 3. global economy chaos

So, the first set of questions is would 'exponentially better LLMs' dramatically increase the probability of any of the above, or domains that Dario is not citing? That assumes that exponential improvements will happen if there is not 'pacing'.

IF answers to above are 'yes', then we need to question if 'pacing' is viable. To use a different domain, regulating 95% of vehicles to a max speed would likely save 100s of 1000s of lives, but is not perceived to be viable. In other examples, regulation has unintended consequences in the opposite direction (e.g. some 'rent control' efforts and arguably some drug/alcohol laws).

gz5··on Nvidia is the central bank of AI
Interesting juxtaposition with Dario's/Anthropic's 'we must pace the frontier' missive today
gz5··on Tailcat – Like netcat, but over Tailscale’s data plane
i like that it removes tailscale proprietary.

if that is goal then why not go 100% open source to eliminate the ts derp control as well and get full sovereignty?

like netbird, openziti, zerotier, etc.

gz5··on FDA Approves Drug Poised to Transform Care for Pancreatic Cancer
https://archive.is/HaZDP
gz5··on The New MCP Roadmap
agree. it seems there are two streams and they could diverge or converge?

1. workloads use existing credentials support RFC 7523 and OIDC discovery, 'trust the trust (credentials) which has already been established'. basically extend current dominant NHI paradigm.

2. DPoP mandate a signed proof for each request. so tie credential to a client-held key and specific request detail or context. viable to do at scale with #1, or does it diverge (e.g. because most #1 methods as most are not designed for DPoP?

gz5··on Bringing the cybersecurity capabilities of Claude Mythos 5 to more defenders
may have been rushed by hugging face being unable to use claude to debug or fix their breach, because there isnt detail on new guardrails put into place to protect against anthropic's initial concerns of wide distribution?

separately, it is interesting they are adding an oem type offer:

>We’re working with our cybersecurity technology and services partners to integrate Claude Mythos 5 into the products and services defenders already use to secure their software.

anyone know the shape of those contracts, e.g. pure tokens/usage or more of a traditional licensing or oem type structure?

gz5··on The Amazon tax
fraud and/or trademark infringement.

i only play a laywer on HN but seems categorically different than the safe harbor dmca which protects youtube etc since google has full control?

same for the amazon case. amazon for fraud and/or tm infringement.

the buyer of the ads as well in both cases but of course those are smaller pockets to empty.

it needs to be done legally but i will say that ads can benefit startups and small companies wrt building awareness against brands which already have it - so i dont think 'ads are the scourge of the earth' but of course rule of law needs to apply.

gz5··on Going Dark, and the era of law enforcement hacking
tcp/ip itself is the ultimate backdoor, similar to the pstn backdoor in the post.

genai doesn't change that anytime soon?

gz5··on Water system controllers don't belong on the internet, says ex-NSA chief
what does belong on the internet in a post-mythos world?

one argument: only services which need to be available to unauthenticated endpoints should be default reachable.

all other services should be default unreachable (no data plane until authorized ...then use internet and other networks to establish the connections).

yes, that is not always easy. it is much more possible than it used to be.

and arguably we now need to commit to the tradeoffs of default unreachable services.

gz5··on Rayfish, Peer-to-peer mesh VPN with no server to trust
3 vpn segments:

1. foss, p2p-only, no server or intermediate nodes to trust (rayfish)

2. foss, brokered if necessary with all nodes self-hosted (openziti, nebula, some wireguard variants)

3. non-foss, mix of p2p and brokered, host some of the nodes yourself (openvpn, myriad of wireguard variants/wrappers like tailscale, headscale, netbird, netmaker)

why is #3 so much more popular?

gz5··on Iroh 1.0
yes, openziti includes a full mesh, programmable overlay. agree not all apps need that.
gz5··on Iroh 1.0
the closest comparison is openziti:

+ iroh and openziti can both be app-embedded

+ so the app developer embedding in their service is a good use case for both

+ openziti is used for services in which scale and security are critical

+ whereas iroh allows participation from parties which don't have any prior relationships - which can be very convenient

gz5··on I think Anthropic and OpenAI have found product-market fit
there are many paths towards ROI and ruin. but towards ROI:

+ LLM-powered robotics, autonomous, IoT, smart manufacturing

+ LLM-powered biotech, healthcare, genetic engineering, medicine

+ Recursive model improvement

+ Multiply the # of devs (software truly eats world)

+ Exponential increases in model performance / cost decrease (algorithms, power, infra, chips, architectures, etc.)

gz5··on When legal sports betting surges, so do Americans' financial problems
and the US govt often helps facilitate gambling during downturns so we could see even more direct and indirect promotion of the problem. examples:

+ in stagflation of 70s/early 80s - states create state-run lotteries to help fix their budgets

+ 2008 great recession - states legalize casinos to recover lost tax revenue and prevent folks from traveling out of state to gamble

+ C19 - states fast track the legalization of mobile sports betting and online casinos to secure immediate tax revenue

gz5··on FCC updates covered list to include foreign-made consumer routers
my instinct is open source is part of the answer. the market monetizes with differentiation on the open source base, support, hardware, etc. vibrant enough market = the foss is secure (always a relative term) and continues to evolve, partially paid for by the companies who are monetizing
gz5··on Study: 'Security Fatigue' May Weaken Digital Defenses
Absolutely. Easier said than done, but the best security is structural security - as near to invisible for end users as possible. This needs to be the goal, imo, even if not fully achievable.
gz5··on Some Things Just Take Time
>Nobody is going to mass-produce a 50-year-old oak. And nobody is going to conjure trust, or quality, or community out of a weekend sprint.

absolutely although i wonder how different 'trust' is in the culture of tomorrow? will it 'matter' as much, be as cherished, as earned over the fullness of time?

i suspect it is a pendulum - and we are back to oak trees at some point - but which way is the pendulum swinging right now?

gz5··on The Los Angeles Aqueduct Is Wild
NYC aqueduct from the Catskills is wild too, especially if you like the effect on NYC pizza and bagels.

Great articles have been written on the engineering but I like this one from 1909 showing the perspective of the time:

https://www.catskillarchive.com/rrextra/dnaque.Html

gz5··on Rowan County Chair Engages with Citizens Against AI DC Project
>The Rowan County Commission meeting included a rare sight, County Chair Greg Edds standing in front of the dais addressing the audience after public comment (something he had never done in his 12 year history according to the article).

articles like this makes me wonder - does the "AI" in "AI data center" amplify concerns beyond 'normal' concerns around commercial and residential real estate development projects?

on one hand, i feel it is partially the media reporting on it more than in the past, but then these articles and anecdata about meetings like this across the country make me feel there may be other differences?

note - in the article, the data center wasn't even on the agenda, nor is a deal in place and yet the unprecedented discussion:

>“I want to be clear about this, so watch my lips. There is no data center deal,” Edds said. “We have made no offers on any data centers. No data centers have made any offers to us. We are not speaking to any data centers.”

gz5··on OpenAI Has New Focus (on the IPO)
>That’s juicing growth. Facebook style

yes, the sycophant noted by Om, but also:

+ asking you (prompting the human?) to keep the convo going in very specific ways

+ seemingly more personalization each day

both unfortunately crowd out the long tail which LLMs might otherwise help us explore, but of course the algorithms prefer putting us in positive feedback loops in echo chambers we like (and are conditioned to like)

gz5··on Show HN: March Madness Bracket Challenge for AI Agents Only
very cool and well done.

i wonder if we will see a materially larger number of brackets filled this year than the recent trajectory would indicate (as a very coarse indicator of agent-filled brackets).

gz5··on The power of daily rituals (2021)
n=1 but they help me hit flow states. almost like they provide 'context' before x, helping me to 'prepare' (or be ready?), filter out the noise, focus. similar in group setting - shared context.

i suppose could be 'placebo' but would it matter if the result is what i want, and i can't easily attain it other ways?

i do feel it is somewhat of a self-fulfilling prophecy - i am essentially practicing something so getting better at it. not enough reason though to 'practice' an alternative, at least for me personally.

gz5··on Tailscale Peer Relays is now generally available
OpenZiti (Apache 2.0):

https://github.com/openziti/ziti

gz5··on CBS didn't air Rep. James Talarico interview out of fear of FCC
what i meant is this may be a good real world litmus test. i dont claim to know if there are differences or not between her word and actions - i have not followed her closely. but i always like 'tests' like this for heads of media orgs as free speech (Free Speech) imo needs to be the backbone of those orgs
gz5··on HackMyClaw
this is nice in the site source:

>Looking for hints in the console? That's the spirit! But the real challenge is in Fiu's inbox. Good luck, hacker.

(followed by a contact email address)

Page 1 of 14Next →