HNHacker News
TopNewBestAskShowJobs

kurikuri

252 karma · joined March 25, 2020

[ my public key: https://keybase.io/cbellii; my proof: https://keybase.io/cbellii/sigs/4ane0tmWHiznmsXZ51SB-h_TRtHFdLSz8rcB3erF6fo ]
submissionscomments
kurikuri··on Rob Pike goes nuclear over GenAI
I agree, the applet which google plageurized through its Gemini tool saves you money. Why keep the middle man though? At this point, just pirate a copy.
kurikuri··on Rob Pike goes nuclear over GenAI
Someone making a complain does not imply that they were ok with it prior to the complaint. Why are you muddying the waters?
kurikuri··on Inside CECOT – 60 Minutes [video]
> > or the CCP route (clip the wings of the Icaruses who fly too high). > This seems like a great way for the monied interests from WITHIN the party to just take full control.

They already do in the US, so this is a non-response.

> > Go with either the FDR route (94% tax rate)

> The reason why this worked is because FDR oversaw the US during a period of incredible change and after the Great Depression. It's not like the tax rate was responsible for his successes.

Once again, this is a vacuous response. If the claim was “high taxes caused the change during FDR’s time,” “There was change” is not an alternative explanation to that claim. If we took the counter-factual claim, do you think the period would have been as transformative if the tax rates weren’t high?

kurikuri··on Computer fraud laws used to prosecute leaking air crash footage to CNN
> I do know, however, that if you take private data from your employer and leak it (or sell it) you’re not going to be on the right side of the law. I have a hard time buying this article’s point that it was just “violating company policy”

If I were to copy the files on my work device and distribute them, I would be in violation of NDAs which could be pursued as civil offenses. If I didn’t have those NDAs, my employer could try and pursue something in court, along with firing me, but it wouldn’t be a straightforward suit.

None of these are (or at least, should be) criminal situations.

kurikuri··on Never write your own date parsing library
> When ever i see "never implement your own...", i know i want to implement it myself.

Doing stuff for learning is useful, and the intent behind this general phrase is to not ‘implement your own’ something which is both hard and critical in a production environment. I work in cryptography (for security purposes) and have implemented quite a few things myself to learn, but I still use stable, field tested, and scrutinized crypto for any actual use.

> People say that about hard things, and I only want to do hard things. Nobody wants people who can do easy things, people want people who can do hard things.

Only wanting to do hard things limits yourself quite a bit: what about things which seem easy but could be improved? I worked in a non-tech related medical manufacturing job for a bit and took time to learn the process and tools. Afterward, I implemented a few tools (using what my coworkers (who have no programming or IT experience) have available to them: Excel and the VBA on the lab computers) to help them prep inventory lists which they have been doing by hand. Doing it by hand took them 3 hours as a group (and the first shift had to do this every morning), which my tool did in 5 seconds with a single button click. They still use it to this day, about a decade later.

This wasn’t something ‘hard:’ I glued a few files together, grouped a list by a filter, sorted the groups by a column, and made a printout which was easy to read and mark on as they went about their day. However, my coworkers didn’t even know this was possible until someone came in with a different skill set, learned what they did (by doing the job well for months) and then made a solution.

You must be careful with doing only ‘hard’ things. It requires other people to identify what is hard! In addition: crackpots do only hard things and believe they find better solutions than what exists so far (without consulting or learning about what has been done). Interesting people learn about things as they are (with the humility of knowing that they are not experts in most things) and tries to improve them using the knowledge they already have.

Don’t waste your time rolling your own crypto when you could do the _actual_ hard thing and identify unaddressed space to make careful and considered improvements.

kurikuri··on How to prove false statements: Practical attacks on Fiat-Shamir
What? You’ve managed to mangle so many terms in so few words… Signatures can refer to two things: integrity checks on a file or authentication checks for a recieved file. In the integrity check situation a hash function (e.g., SHA) is often used. In the authentication check situation, we usually use a public/private keypair for asymmetric encryption; the hash function is only part of the process. The key material used to make this keypair (should) comes from some random number generator…

The ‘hash’ function is a deterministic transform, not a source of randomness.

kurikuri··on More on Apple's Trust-Eroding 'F1 the Movie' Wallet Ad
The U2 album was odd, but not bad in the same league. Apple didn’t advertise for you to purchase U2’s music. As an end user, what made it annoying was how the U2 album was part of your library (thus, would show up in shuffle, etc.) and removing it was a whole ordeal.

This wallet notification was silly. Prior to this, I believed that their wallet app would give notifications much like how settings app would: rarely and without commercial intent.

kurikuri··on US Supreme Court limits federal judges' power to block Trump orders
> Judges were using injunctions to avoid putting their name behind a ruling.

What? That makes no sense. You can lookup which court and judge (or panel of judges) issued the injunctions. I do not understand why this non-existent anonymity would motivate a judge to issue an injunction.

> They can still strike down a law or executive branch policy.

Federal courts will only look at cases if there is a party with standing who engages in a lawsuit. If someone is being deported without due process, it will be hard for them to bring suit.

> This forces judges to actually do their job., instead of a nationwide injunction while they decide if they want to do their job later.

In general there are two reasons why these temporary restraining orders which have been issued. The first being that not doing so would cause irrevocable (or ridiculously difficult to revoke) harm (e.g., deporting people to a foreign jail). The second is that the TRO is used to stop something which seems illegal on its face (e.g. deporting people to countries from which they have never been).

> It doesn’t actually alter some fabric of our democracy or checks and balances, because the judges had already gone beyond what the constitution and congress prescribed.

It does alter the power dynamic of our democracy. Now, the executive branch can repeatedly perform illegal acts and only needs to stop its behavior in cases which have been decided. This checks and balances isn’t about stopping each other branch in a vacuum, the intent is to stop the government from overreaching on its citizenry. By crippling all of the lower courts, the Supreme Court has created a bureaucratic bottleneck for itself, allowing the executive branch to effectively DDoS the judicial system with case after case.

> The disruptive aspect of this - with concern to the birthright case that hasnt been ruled on yet - is just another example of this. Judges not doing their job.

No, it was the judge telling the executive branch that the executive branch must recognize the citizenship of children born on US soil. Instead of actually appealing the TRO on grounds of the legality of their actions, the executive branch has decided to complain about the legality of a court telling the executive branch to stop.

Who is supposed to tell the executive branch to stop doing something illegal, congress? Part of the point of the executive branch was to allow for some expedience, congress is slow. A judge is in a perfect position to tell the executive branch to stop, they don’t need to wait on committee and are not beholden to the president. Without the ability, the executive branch can quite literally do whatever the president wants.

kurikuri··on Getting ready to issue IP address certificates
Oof, I don’t like this article much at all.

The first two major points they pose against email can be summed up as ‘people don’t use security unless it is by default, and because it wasn’t built-in to email we shouldn’t try.’ To which I respond with: perfect is the enemy of progress. Clearly, email is sticky (many other things have tried to replace it), and it has grown to do more than just send plaintext messages. People use it for document transfer, agreements, as a way to send commands over the internet, etc. Email encryption and authentication is simply an attempt to add some cryptographic tooling to a tool we already use for so many things. Thus, these points feel vacuous to me.

The last two points are less to do with email and more to do with encryption in general, and it is probably the most defeatist implication of the fact that there is no ‘permanent encryption.’ It is an argument against encryption as a whole, and paints the picture for me that the author would find other reasons to dislike email encryption because they already dislike encryption. These last two points are an extension of wanting an ideal solution and refusing to settle for anything less.

kurikuri··on U.S. Chemical Safety Board could be eliminated
Ah, I was being a bit sarcastic in my response to monkeyelite, I believe I understood what you wrote and was trying to get at the vacuity of their response to you.

I derailed this conversation to make a meta point, and it wasn’t your fault at all.

kurikuri··on U.S. Chemical Safety Board could be eliminated
> Yes I don’t believe in unbiased sources. I believe in multiple perspectives revealing aspects of the truth.

Sure, I agree with what you’ve stated here.

> Correct. And I don’t buy the dichotomy you are framing of biased companies vs unbiased government.

I reread what I wrote and still don’t see that I framed the conversation in this way. What I did frame was the motivation of the company (which I implied to be profit) versus the motive of the government (that of public interest). These are both biased and the effect of the bias could be anticipated: companies would slant their published information with a focus on the effects of profits, whereas the government’s overt bias would slant its information output towards safety (in the case of the CSB) without much concern for profit.

> The term “objective truth” was just thrown around. Might as well just say it’s an “absolutely good”. The level of discourse in these threads is science = good, agency with science in name = science. Cuts against agency = bad.

Sure, we both agree the author is biased towards the government, but you’ve missed the thrust of what I wrote entirely: your nuance added absolutely no value to the discussion, it didn’t make a point or refute anything the author said.

kurikuri··on U.S. Chemical Safety Board could be eliminated
Nuance is not always a good thing. This type of nuance doesn’t forward the discussion in any way and, in this case, muddies the waters and leads to some odd implications. Sure, we can say there is no objective source of truth and chastise the author for using that word, but the term objective in this case has meaning that the author is trying to articulate… most likely that there is some overtly unbiased information source, in opposition to the information sourced from the company which has obvious incentives.

Additionally, by stating that the CSB provides an ‘alternative source’ of truth, as a correction to an originally described objective one, you are (possibly inadvertently) claiming that the company is also providing a different source of truth, rhetorically raising the value of the information the company provides while lowering the value of the CSB information.

Don’t be the person who adds nuance for the sake of nuance.

kurikuri··on Working on databases from prison
They were likely in a homogeneous population when they committed the crime that got them there in the first place, so that confounder might not matter much at all.
kurikuri··on CEO of Health Care Software Company Convicted of $1B Fraud Conspiracy
> … but I think it’s fair to say that many people don’t want DOGE to be serious about catching Medicare fraud.

That’s a leap (if I’m being charitable). I think you could state that most people don’t trust DOGE, especially given DOGE’s apparent lack of concern for the American’s they are technically working in service of. I don’t believe DOGE has the capability of identifying fraud, let alone have the desire to stop it.

kurikuri··on Food additive titanium dioxide likely has more toxic effects than thought
> On the flip side, it will be incompetent and demotivated.

This sounds like it came from someone who has never spent more than a passing interaction with government employees.

The government employees I’ve worked with seem to actually care about fixing things, doing their work well, and maintaining their group’s objective (whatever that may be).

kurikuri··on Can LLMs do randomness?
Right, so the LLM needs some randomness to make that decision. The LLM performs a series of deterministic operations until it needs the randomness to make this decisions, there is no randomness within the LLM itself.
kurikuri··on U.S. Spy Agencies–One-Stop Shop to Buy Your Personal Data
> Your guy lost, learn from your mistakes and carry on. Or criticize both presidents equally.

So, your solution here is for people who think the current administration is particularly bad to either not complain or accept any whataboutisms you have?

Your ‘both administrations’ quip is a vacuous justification for the current administration’s actions. If this is the basis for your justification, then, regardless of the truth of your claim, you’d be inconsistent to then praise this specific administration for anything positive. Thus, outside of nihilist generalizations about the overall structure of the US, you can’t meaningfully contribute to this conversation. Without giving a positive justification for the administrations behavior, your contributions are ‘logical nonsense.’

I’d rather simply complain about the doublespeakers in office at the moment and say it is wrong to do so, and there is no ‘logical nonsense’ in that.

kurikuri··on Sam Altman's eye-scanning orbs have arrived, sparking curiosity and fear
This feels like a flippant response. The question you responded to was ‘would the hash of the iris would be the same?’ It isn’t as if you’ll get an identical image of the iris every time, and hashes tend to behave chaotically for even slightly different values. If we compare this to something like password salting and hashing, it isn’t clear how we can maintain the constant salted hash value if we swap the password for a digital representation of a person’s iris.
kurikuri··on Can LLMs do randomness?
> But it can easily assign equal scores to 1 and 0 and zero to other tokens, and you’ll have to sample it randomly to produce the result. Whether you consider it external or internal doesn’t matter, transformers are inherently probabilistic by design.

The transformer is operating on the probability functions in a fully deterministic fashion, you might be missing the forest for the trees here. In your hypothetical, the transformer does not have a non-deterministic way of selecting the 1 or 0 token, so it will rely on a noise source which can. It does not produce any randomness at all.

kurikuri··on Sam Altman Wants Your Eyeball
Except the ostensible motive of the government is to serve its people, whereas the company’s motive is either those of the people who control the company or profit.

Even then, if the government is weak than the ‘more power over you’ is simply false. Maybe the magnitude of the power is more for a government, but companies apply their power with much more frequency.

kurikuri··on The Deathbed Fallacy (2018)
> For example, going to college for 4 years to get a physics degree doesn’t make much sense at my age, because there’s not much time left for the payoff.

That is tragic! Learning more about things is fulfilling in and of itself. If your only concern is about growing the number, and you limit your choice to those which are within a time horizon that you can reap the result, then getting older becomes even more bleak than it is.

kurikuri··on Can LLMs do randomness?
So, what ‘algorithms’ are you talking about? The randomness comes from the input value (the random seed). Once you give it a random seed, a special number generator (PRNG) makes a sequence from that seed. When the LLM needs to ‘flip a coin,’ it just consumes a value from the PRNG’s output sequence.

Think of each new ‘interaction’ with the LLM as having two things that can change: the context and the PRNG state. We can also think of the PRNG state as having two things: the random seed (which makes the output sequence), and the index of the last consumed random value from the PRNG. If the context, random seed, and index are the same, then the LLM will always give the same answer. Just to be clear, the only ‘randomness’ in these state values comes from the random seed itself.

The LLM doesn’t make any randomness, it needs randomness as an input (hyper)parameter.

kurikuri··on Cross-Entropy and KL Divergence
In the first definition of D(P,Q), the author dropped a p_j within the sum.
kurikuri··on Ask HN: Is There a Crypto Equivalent to Tracking Politician's Transactions?
Ironically, trust is an issue in the crypto space (the general layman perspective seems to be one of rug pulls and greater fool fallacies). The existence of some transparent information that is easy for a layman to use and understand makes sense.
kurikuri··on A university president makes a case against cowardice
This false equivalency, if you honestly believe it, is shallow at best.

The ‘left’ has identified speech that is likely used to belittle or negate someone else’s existence and will appropriately label it as hate speech. Any structural changes to make these words frowned upon have taken years to get into place; people were allowed to adjust (and the length of time to do so is ridiculous in its own right), and what little change has happened did so in a way where the people who must change are barely inconvenienced. There have been few legal repercussions for the use of hate speech by anyone with a modicum of power. Sure, you could identify a few, but there are a ludicrous number of flagrant violations of any such laws (which are few) which go unpunished. The ‘left’ here being any sane member of society which has publicly pointed out that certain words are singularly incendiary.

Meanwhile, the grifters of this ‘right’ have conned the honest conservatives into believing that DEI is a term of hatred against conservatives. The ‘right’ has identified that they wish to say whatever without punishment and are structurally creating a cost for using inclusive language in any official capacity. The grifting part of the ‘right’ also doesn’t mind breaking any semblance of stability for everyone else. The ‘right’ here being the near-narcissistic people who have happened upon positions of privilege and believe that they are superior, have earned it, and that only those similar to themselves should ever attain such a position in the future.

But no, you have reduced your observation to ‘two sides are banning words.’

kurikuri··on Entropy Attacks
> I'm sure there's a market, but exactly what is this genuine need and do they really understand their own problem?

Unfortunately, my information stops at the fact that they claim to need the high-output entropy source.

> Also for more than a decade now modern systems have a fast entropy source with on chip RNG such as RDRAND and this extends to the embedded context.

On-chip RNGs are useful, yes, and are often enough for most use cases. In particular, I like Intel’s RDSEED quite a bit, but the larger (in terms of core count) the chips have gotten, the more convoluted the distribution network for the material has become. Even still, the speed of RDSEED (note, RDRAND is an automatically reseeded DRBG, whereas RDSEED is an RBG3 XOR construction (as defined in SP 800-90C) which has fresh entropy in each output) has fallen to a rate in which some vendors are looking for something faster.

kurikuri··on Entropy Attacks
> Fast key erasure uses symmetric cipher. If there's a mathematical attack on that, then you just don't have any symmetric cipher

The generation of the RNG’s output stream is the result of a symmetric cipher, yes, but an attack doesn’t need to be on the cipher as a whole. And, once again, if there is a state leakage at any point we end up with the same problem that any future output of the key stream can be undetectably replicated. Sure, you can always replace the key sooner, but that only better protects against the state leakage; the output sequence is still deterministic no matter how fast you replace it.

> You need a custom protocol for this, how is that certified?

This is where cybersecurity testing labs are useful, especially ones who can do entropy source validation. If the protocol itself can be described in terms of the standard, and fulfill its requirements, then it can be easily certified. If there is no way to map the behavior to the standard, but the behavior is secure (according to the lab), the SMEs at the lab can request guidance from the certifying body on how to deal with the situation. These requests have culminated in public guidance (e.g., the FIPS 140-3 IGs) on how to certify industry specific protocols.

kurikuri··on Entropy Attacks
Most people do not need high throughput entropy sources, sure. But the people who do pay quite a bit for that functionality.

I also haven’t seen any oft-referred literature describing metastability do so using a quantum-physics context. The metastability itself is a product of quantum behavior but has been described well enough without needing it. Depending on what you’re exploiting randomness-wise (like the metastability or the oscillation period length), the type of physical description you use to analyze the noise source changes quite a bit. For most ring oscillator work, I prefer to look at the work near the 2000’s by Ali Hajimiri, none of which is in terms of quantum anything.

kurikuri··on Entropy Attacks
> If the OS RNG needs fresh entropy it can reseed with fresh entropy from various sources as it does today and use fast key erasure for forward resistance.

This assumes that the OS has access to a source of entropy that replenishes itself quickly enough for whatever the OS is using. One of the biggest complaints I’ve seen from customers selecting entropy sources is the speed of ‘built-in’ entropy sources, to the point where they will actively look for faster ones and pay quite a bit more when they do genuinely need them. The market is there.

While they could implement the fast key erasure, there is still the looming threat of future mathematic attacks on it, and if some analysis comes forward which shows a way to abuse this, then the house of cards falls down. While these attacks are a concern with any DRBG instantiation, the sidestep is, once again, fresh entropy.

If you happen to need a certification for your entropy source, fast key erasure, as described, doesn’t map cleanly to the SP 800-90 series (NIST’s RNG standards) or the AIS 20/31 (BSI’s RNG standards). Most of the time, people wanting high speed entropy are wanting it in a way that not only they trust it, but in a way where governments would too. While I think there could be a way to define the fast key erasure in terms of SP 800-90C, I don’t think there is an implementation that NIST has approved yet.

> Sure there will be windows of opportunity of state compromise, but if the state can be comprised you have bigger problems, for example they could just copy the output of a TRNG source.

This type of compromise (copying the output of TRNG) is an issue outside the scope of the DRBG’s state… Replicating, calculating, or leaking the DRBG state does not require a persistent listener after the initial compromise, would likely be undetectable to the user, and would be effective until the user gets fresh entropy.

kurikuri··on Entropy Attacks
Keeping the DRBG’s state (seed material) secure for the duration of its use is the problem. If this state is leaked, depending on the type of leak, then anything generated from that DRBG is now not protected. Even worse, you may not even know that this the case and continue to use the DRBG assuming that it is safe.

If state management is was not an issue, I’d agree with you, but the fact that vulnerabilities tend to appear in very unexpected places (side channels, speculative execution, etc.), makes this problem difficult. A sidestep is to simply have fresh entropy.

Page 1 of 5Next →