That's not "trying to cover it up", that's a link to them adding credits that were missing, which is the main corrective action to get into compliance with the source project's license.
It means it can execute native code inside the sandbox, as opposed to Javascript. While still sandboxed, this lets it access some parts of the attack surface that JS would not have been able to, some of which may have other exploits that allow escaping the rest of the way.
Is the relevant radiation solar radiation, or is there damage from radiation coming from the direction the optics are pointed? If it's the latter, then maybe the sun's emissions interact with inbound particles from sources outside the solar system? (I don't have sufficient background or time to check whether the paper already rules this out.)
You can check, rather than make up a story about what you think the prompt was! Primary sources have written and said quite a lot about this! You are an unsandboxed human who has full internet access!
The victim, Huggingface, told us. Or rather, they told the police first, setting up a situation where it was no longer possible for OpenAI to sweep it under the rug.
Skepticism can be healthy, but you've got to follow up and actually check things. If you're skeptical unconditionally and don't check, you get tricked into being as skeptical of scandals as you should be of sales pitches.
I use Firefox with (non-lite) uBlock Origin, and occasionally fire up Chrome (with uBO Lite) for testing. The main issue that I run into is that uBO lite filters can't vary per-domain, so in order to rule out an ad-blocking-false-positive on something I'm developing, I have to turn it off for _all_ sites, not just localhost. (Actual false positives are rare, but needing to check is not so rare.)
Do iOS users realize how much they're paying Apple? I feel like if, every time they bought something, users got a receipt with a line item showing that 30% of the money was going to Apple and not to the company they thought they were buying from, a lot of them would jump ship to Android.
This article makes no mention of Russian sabotage, but the Russian military has been caught sabotaging similar munitions-manufacturing facilities in Europe. Incompetence might be sufficient to explain the failure, but it also seems reasonably likely that there was an undetected sabotage operation or two mixed in to compound the problems.
Eventually, this arms race ends with a computer vision model that looks at the screen, classifies visual elements as ads, and draws a rectangle over anything that looks like an ad.
I am significantly less tolerant of ads than average people seem to be. (I think average people are making a horrible mistake about this, and are badly cognitively damaged by ads in ways they don't realize). If my choices are to look at ads or leave Facebook, I'll leave. But there are conversations people have there that I'd rather not lose access to, so... I guess I'd have to partially stick around and campaign for others to leave as well?
As far as I can tell, this is a big overreaction to a misunderstanding.
I'm a developer with remote adb enabled, using it in the normal intended way (to install new builds of an Android project I'm developing, retrieve log files related to it, etc). Currently, I access this via VPN (tailscale), but it's exposed to connections (and any pre-auth security vulnerability risks) on any random public wifi network I connect to. Adding the ability to restrict this to just tailscale will be an improvement, for me.
The proposal at the top of the thread is that you specify which interface you want it to bind to, when you set up remote adb, rather than binding to every interface. Nothing in that proposal suggests that "localhost" would be rejected as a choice of interface. One person suggested binding only to "wlan0", but that was a short throwaway comment that is obviously wrong (wlan0 is less-trusted than VPNs) and obviously not what they're going to do.
The first thing to check for, in accounts like this, is "which AI model"? There is a subset of people who somehow don't realize how important that decision is, and don't mention or don't foreground which AI model they were using. This sort of person invariably gets much worse results out of AI, because they turn out to be using a shit-tier low-cost model instead of something that's actually good at what they're using it for.
As marketing stunts go, this is about on par with a food franchise announcing a safety recall or a chemical company announcing a spill. The AI actions described would constitute a felony if a human did them, and police are involved.
If that's all you'd posted recently, the problem is not likely to be the content you posted. The most likely thing that happened is that you shared an IP address (eg a VPN exit node, or a device with malware on your wifi network) with someone who was banned for good reasons, and got caught in the crossfire.
If you think a browser feature that's been standard since 2023 is only supported by 70% of your visitors, you're wrong. The 30% of "users" that don't support it aren't visitors, they're bots pretending to be browsers. Bots update their user-agent strings less often than users update their browsers. My experience maintaining firewall rules is that "outdated version of an evergreen browser" is a pretty reliable bot signal: those UAs correlate strongly with all of the other bot indicators (inhumanly high request rates, datacenter IPs, loading pages without loading the page's associated resources, etc).
I've never seen this beore today; it happened today and was quite clearly incorrect behavior. I prompted it to research considerations for a significant code architecture decision. It asked a pretty difficult question about which direction to take, something that would take way more than 60s to answer properly. While I was thinking about it, it timed out.
Some Github issues claim that adding
"env": { "CLAUDE_AFK_TIMEOUT_MS": "86400000" }
to ~/.claude/settings.json fixes it. This is plausible, but not documented anywhere (the source claims it was found by reverse engineering, and might break /goal).
This is a misinterpretation. Fable 5's acceptable use policy has false positives during some coding tasks, and that's what they were talking about. But I've been using it for web dev tasks since it relaunched today, and it's worked fine without fallback.
(On a firmware-customization project involving a ghidra MCP, it triggered and switched to Opus; that was sort of expected.)
Have you checked your IP address's reputation with a service such as ipqualityscore.com? If cloudflare thinks your traffic is bot traffic, it's likely that there is bot traffic you don't know about coming from your IP, either from a compromised device on your network or a sketchy VPN product.
I deal with scrapers that sometimes border on DDoSes for LessWrong. The amount of bot traffic varies greatly between sites; if you have more URLs you get more bot traffic (regardless of whether those URLs represent a deep content catalog, or useless URL parameter permutations). It's bad for LW because of the content-catalog depth.
It's easy to drastically underestimate the amount of bot traffic, because bots make efforts (of varying sophistication) to look human enough to evade blocking. That includes using fake user-agent strings corresponding to real browsers (often but not always with implausibly old version numbers), proxying through residential IPs, and sometimes using full headless browsers. In my own data, traffic from badly behaved browser-impersonation bots exceeds traffic from named scrapers like GPTBot by something like 10x.
The measured percentage of bot traffic is higher for HTML than for other content types because many bots will load an HTML page, and then not load the JS/CSS/image/etc resources it references. But these are the least-sophisticated and most-detectable bots.
The full-screen mode handling might be a clue about what went wrong: if you swipe up from a space that contains a full screen app, it has an animation where the app goes into a slot in the preview strip, but that animation doesn't make sense visually for a non-full-screen space. So, perhaps someone was implementing that animation, didn't want to implement an alternate animation for the non-fullscreen case, and decided to minimize the preview strip instead? And because this was after Steve Jobs had died, there was no one left in charge of UX to explain why that was a bad idea?
Prior to MacOS 10.11, Mission Control was good: you would swipe up with four fingers and it would show you a preview of all of your spaces. Then in 10.11, for no discernable reason, they changed it to suck: rather than showing you a preview, the bar just says "Desktop 1", "Desktop 2", etc until you mouse over it; the practical effect is that using spaces is disorienting and requires memorization.
Some third-party software pretends to restore this functionality, but they do it by repositioning the mouse to simulate a hover, which introduces a delay and doesn't integrate correctly with the animation. Someone wrote a patch that works by disabling SIP and injecting code (https://github.com/briankendall/forceFullDesktopBar), but eventually stopped maintaining it.
A decade later, I doubt anyone at Apple remembers that this bit of user interface used to be good.
This press release links to an arXiv article dated a year ago, which ran tests using AI models that were already seriously out of date at that time. The practical upshot of which is that, with respect to the question people care about, and which the headline claims to answer, this is basically pseudoscience.
Apple's app store rules have never been compatible with devtools. It's kind of surprising to me that a Replit app existed on iOS at all; I would have expected that to be a nonstarter, and, given that a Replit app does somehow exist, I'm not surprised that they wound up unable to update.
This is a big part of why I don't use any iOS devices. It's possible to sort of buy your way out of the restrictions by paying for a developer subscription, but at the end of the day it's way too totalitarian.
I think people are giving the AI-water-use claims too much credibility. The idea that AI datacenters are heavy water users is trivial to refute, and was trivial to refute when it was first introduced. It should be written about in the same tone as one writes about ridiculous conspiracy theories.
This sort of thing makes the lack of a downgrade process a real problem. If you rely on something that uses Rosetta, you aren't likely to find out until after you've upgraded, at which point it's too late, you're stuck with it and lose that app. Which means that if you _don't know_ whether you're relying on Rosetta (which most people won't), upgrading is a risky proposition, which people will want to avoid.
I think the main problem here is the ideology of software updating. Updates represent a tradeoff: On one hand there might be security vulnerabilities that need an update to fix, and developers don't want to receive bug reports or maintain server infrastructure for obsolete versions. On the other hand, the developer might make decisions users don't want, or turn evil temporarily (as in a supply chain attack) or permanently (as in selling off control of a Wordpress extension).
In the case of small Wordpress extensions from individual developers, I think the tradeoff is such that you should basically never allow auto-updating. Unfortunately wordpress.org runs a Wordpress extension marketplace that doesn't work that way, and worse. I think that other than a small number of high-visibility long-established extensions, you should basically never install anything from there, and if you want a Wordpress extension you should download its source code and install it manually as an unpacked extension.
I think the main problem here is the ideology of software updating. Updates represent a tradeoff: On one hand there might be security vulnerabilities that need an update to fix, and developers don't want to receive bug reports or maintain server infrastructure for obsolete versions. On the other hand, the developer might make decisions users don't want, or turn even temporarily (as in a supply chain attack) or permanently (as in selling off control of a browser extension).
In the case of small browser extensions from individual developers, I think the tradeoff is such that you should basically never allow auto-updating. Unfortunately Google runs a Chrome extension marketplace that doesn't work that way, and worse, Google's other business gives them an ideology that doesn't let them recognize that turning into adware is a transgression that should lead to being kicked out of their store. I think that other than a small number of high-visibility long-established extensions, you should basically never install anything from there, and if you want a browser extension you should download its source code and install it locally as an unpacked extension.
(Firefox's extension marketplace is less bad, but tragically, Firefox doesn't allow you to bypass its marketplace and load extensions that you build from source yourself.)
For the benefit of people who read only the headline and not the article:
The story here is that the US government captured Russia's energy weapon, which Russia has been using against US personnel for a decade, and tested it to determine what it does (it causes brain damage). This story does _not_ claim that the US has developed a weapon like this themselves.