HNHacker News
TopNewBestAskShowJobs

m3047

783 karma · joined November 2, 2019

Internet Plumber, Data Sous Chef, Python Ninja

https://github.com/m3047/

    ...or...
hackernews3047as@m3047.net

meet.hn/city/us-Tacoma

Socials:

- github.com/m3047

---

submissionscomments
m3047··on Why the Bronze Age Collapsed
One of the questions today is whether frontier models, in the hand of frontier labs, and capable of extracting rent (and extracting intelligence from customer-provided signals) will be able to predominate over locally run models of indeterminate provenance.
m3047··on LinkedIn Larpmaxxing
So much of what I see is which is in this genre is completely and utterly AI slop: spray bottles cleaning driveways, miracle putty miraculously repairing a rotten porch... If I saw those kinds of pictures my first suspicion would be that the AI completely faked it.
m3047··on Most data centers refusing to say how much water, electricity they use
"California could solve its water shortage if every household ate sixteen less almonds per day." -- I said this [edit] A DECADE AGO at the conclusion of an all-day water resources hackathon to illustrate the fact that ag water and urban water are not the same.

Conflating them is category confusion. Lying about water usage is part of CA culture.

m3047··on The systems that no one will test
The systems that nobody will test, and indeed which nobody will instrument. Here's a DNS data diode for Redis: https://github.com/m3047/rkvdns
m3047··on There are no "rogue" AI agents
What if a single company was behind all the hacks? Doesn't seem to be getting much coverage. "The Israeli Effective Altruist firm Irregular caused unsecured AI models to hack real targets."

https://www.effort.news/irregular

m3047··on Plan mode is dead
Magecart has been very $ucce$$ful at hiding in JS dependencies.
m3047··on LG smart TVs caught logging audio with screen off and snooping on local devices
You can spoof MACs all you want, but your MAC is tied to the address I give out. What happens if you spoof addresses? FAFO...
m3047··on Discovery of a new OpenAI agent message board
Putting stuff in the hosts file is common for testing for vhosts without dedicated tooling. Used to test for phising kits, for example. In other words: it gets written to the HTTP Hosts: header.
m3047··on Discovery of a new OpenAI agent message board
The Green Run.
m3047··on DNS abuse and criminal infrastructure
"The study found that at least 10% of all new gTLD domain names registered during the year had subsequently appeared on security blocklists by the time of analysis."

I don't disagree with the general assertion / hypothesis that bad actors register a lot of domains. But the data comes from an industry which does a poor job of categorization, doesn't agree on categories, and absolutely does not publish statistics on corrections. Nor is it easy to request corrections. Nor does it seem that corrections are felt to be necessary absent customer complaints. There is too little basic science and integrity in the process.

This is not new, the industry has quite frankly always been like this.

"Any industry confronted with evidence that a material share of its output may be controlled by bad actors should be seriously concerned." Too much category confusion to go through it all, for this statement, in this context. But yes. The domain sector isn't just people selling domains, it is also people who make money preventing you from being able to use a domain, and people doing arbitrage on your domain before you can even put it on-line. So I ask: are these "good" actors? How do we know? What's the standard?

It's too hard to get a response from most parts of this sector, and a lot of it is corrupt.

Let's start with registrars, because nobody starts there: I had a registrar literally catch fire. Basically out of business at that point. Because their systems were down they couldn't transfer the domains. I had to file a formal dispute with ICANN, six weeks of back and forth and waiting later, they handed the domains to some registrar I'd never heard of and had no existing business relationship with. (Not a great registrar.) This happened in 2017, don't tell yourself that things have improved since then.,

Then we have the email reputation services which spam on their own account: http://athena.m3047/pub/soe/abusix-spam-backstory.html

As well as reputation services spamming because someone paid them to do it (they send email to domains which they block, with their own servers): http://athena.m3047/pub/soe/pphosted-vmed.png I'd originally put this down to a three body problem: https://consulting.m3047.net/dubai-letters/blocking-esps-pla... (technically what you're seeing in the screenshot is me blocking them as a favor since they can't seem to manage it on their own).

The industry is rotten. https://consulting.m3047.net/dubai-letters/ptn-industry-trus...

m3047··on Bug Blindness
A close acquaintance was on Medicaid, and then got a new job and was moved off of Medicaid onto an insurance plan they were paying for. Medicaid is administered by insurance companies; the same company administered both their Medicaid plan, and the plan they were now paying for.

As it so happened, within a week of this occurring they needed urgent care, badly, no joke. We have basically three choices here (at least, which would take this insurer), and none of the three would see them, and the reason was the same in all cases: 1) they no longer had Medicaid, and 2) the provider couldn't let them pay cash and sort it out with the insurance company themselves.

It took three days calling the insurer, providers, the State health exchange, finally getting the insurer on the phone DIRECTLY with one of the providers... at a clinic rather than in admin... the insurer directly telling the clinic administrators that the person was insured and the insurance company would give them a claim number right now, or something like that... before we could get them in to see a doctor.

When we got to the clinic they looked them up and STILL told them they couldn't see them we had to demand to speak to an administrator and basically THEY COULDN'T CHECK THEM IN TO THEIR APPOINTMENT in their computer.

All of these providers used Epic. I made some additional phone calls and had some additional conversations, made a writeup, and sent it to the insurer, the benefit exchange, and the provider who ultimately saw us. Never heard anything from anyone.

m3047··on Autistici/Inventati case sets a new counterterrorism precedent, Irdi says
This is not meant as what-aboutism, I don't think you've gotten to the root of it.

The US is largely responsible for the Internet (and for the original internet protocols). The Internet is a corporation (ICANN), run by corporations, for the benefit of... corporations. I suppose the Hudsons Bay Company was a fascist state, in effect.

Here we are talking about an organization offering services on the Internet. The Internet is a cesspool. (Put some machine on the Internet: FAFO.) There have now been numerous cases where particularly bad actors have been de-peered. It's starts with muh defending the innocents, then muh rights, then the de-peering starts to bite, and then... they disappear. I will quote Paul Vixie: if you can't defend it, you don't own it.

Neither does ICANN, or the US government. But like any other entity with access to the Internet they can exert influence on providers, it's not like there is no precedent for governments making up stupid shit and expecting the Internet to enforce it for them. Private entities make up shit too, for instance all of the SPAM fighting ecosystem is largely private players making sure that "bad domains get what they deserve", and they decide the definition of "bad" (and they don't agree) as well as what they deserve.

ICANN for instance is really protective of DNS. Find me a publicly distributed DNS server (in the mode of BIND, Knot, Unbound) which supports multiple root views; nay, find me a such a nameserver which supports any additional roots in a graceful fashion. QED: systemic fascisim. ;-) Most would say that's not a bad thing, if you want to have alternate roots, then you need to keep your tree completely separate. There will be people who disagree.

Not enough background in the article or the State Dept press release for me to comment on exactly what influence they're trying to exert on a technical level. How is it different from various countries sanctioning other countries' politicians, or differences between the EU and US on internet governance? How is it actually enforceable? Or California passing an "operating systems must attest user age" law? Do people in Italy give a shit about that? I'd be surprised if they did.

m3047··on Water Behind the Watts: The Hidden Risk of Powering Data Centers
One datacenter doesn't use appreciably that much water; and we don't know what cooling paradigm they're implementing. If you want to know about water, you have to ask. So far, datacenters haven't broken the grid (cough virginia) yet. In TX planned DCs are projected to consume 5x current electricity generation.

If we use electricity as a proxy, the problem isn't any particular datacenter it is obviously scale.

Also: people lie about water use. Over a decade ago, a day of searching for The Data led to exactly one defensible conclusion: if every household in CA ate 16 less almonds a day they would solve their water shortage... at least on paper. BTDT research.

Edit: Power generation uses the most water. Color me not surprised.

m3047··on Water Behind the Watts: The Hidden Risk of Powering Data Centers
A lot of compute goes on in ND, not kidding.
m3047··on MS Paint and Photos inivisibly watermark even locally generated output with GUID
How can they send a copyright subpoena for work which cannot be copyrighted? There is a contradiction here between "no it's FAIR USE" and copyright.
m3047··on MS Paint and Photos inivisibly watermark even locally generated output with GUID
People worried about other people tracking them while using local stable diffusion models built on fraudulently obtained training content, to produce images which cannot be owned. Thug on thug violence.
m3047··on The war on data centres is a bit fake
I don't think they were so much disguised as it was distributed compute. You can fantasize about taking 1000s of home solar installations off the grid at once, but a few datacenters at once and Bob's your uncle.
m3047··on Radiation damage to Hubble has been 4.3 years out of phase with the Solar cycle
Coronal mass traveling at a higher speed "sweeps" what's before it. You can see the spiral shape, and you can probably figure out that the stuff is slowing down as it moves outward.

Watch this occasionally for a few months and you'll get the idea, although solar activity is slowing down somewhat (as expected).

https://www.spaceweather.gov/products/wsa-enlil-solar-wind-p...

m3047··on Radiation damage to Hubble has been 4.3 years out of phase with the Solar cycle
The corona monitoring satellite cameras "blink" on incoming xray flares.
m3047··on Decayfmt – a file format that corrupts itself a little every time you open it
You might look into (Norbert) Weiner functions.
m3047··on Thousands of Soldiers Now Roam Washington's Streets at $1.6M per Day
Wrong. Although the National Guard is indeed called up for active duty, their primary purpose is an offramp for the "well regulated militia" language in the US Constitution and to defend the State from which they were called up.
m3047··on Thousands of Soldiers Now Roam Washington's Streets at $1.6M per Day
I moved to $Satellite_Urban_Area from $Urban_Area to take a cybersecurity job. In $Urban_Area we would almost certainly have had metal detectors and other measures. Due to the military presence here in $Satellite_Urban_Area this place has a reputation for being armed to the teeth. Although there was no open carry in the office, I know for a fact that a number of mostly ex-military brought sidearms to the office. A part of this area was at one time "the murder capital of the country" and is infamous for a shootout between residents of that part, gangs vs military. The place has a rep.

Is that a bad thing?

I don't view metal detectors and huge cast concrete reception desks as a good thing, I view them as indicators that earlier interdiction has failed; I try not to hang around places like that, unless I know that there are also actually people with guns who are trained to use them.

m3047··on Thousands of Soldiers Now Roam Washington's Streets at $1.6M per Day
It deserves scrutiny, certainly. But this:

“It’s like they brought people here from all across the country, just to be here [in Washington DC]...”

What about the politicians, and all of the people hired to work for the politicians? Looks like about 29% of the population were born there. Is it a bad thing that our troops have a common, shared experience of spending time in the US Capital?

m3047··on How to compromise your system with a job interview
You'll probably need to enable some "secure memory mode" in BIOS, e.g. a boot error that you ignore which says something like "KVM disabled by BIOS" needs to be made to go away.
m3047··on Why it might be time to rethink the human family tree
Research is coming out specifically regarding the COVID genome which suggests missing sequence data was routinely filled in from baseline reference sequences. In turn, the reference sequences suggest during later analysis constant reversion back to the baseline. These gaps are the (dot) product of limitations of PCR * computer processing algorithms. No reason to believe the problem is limited to COVID.
m3047··on Cop Explains Why He Used License Plate Reader to Stalk Woman
https://www.gadgetreview.com/flock-safety-says-its-cameras-d... Flock Safety’s FreeForm tool logged 6,736 people-description searches in 2025 while the company insisted its cameras target only vehicles

https://www.investigatetv.com/2026/06/15/flock-says-its-came... Company’s newest devices use AI to follow pedestrians, while protesters are mapping nearly 90,000 surveillance cameras nationwide.

https://www.msn.com/en-us/news/technology/flock-cameras-are-... camera provider has rapidly expanded its products, functionalities, and customer base, creating a vast network of video cameras, audio detection devices, drones, and mobile security trailers. This expanded offering is powered by AI algorithms that process far more than drivers' license plates, recording vehicle profiles, pedestrians

https://www.rsn.org/001/how-cops-use-flock-to-track-people-n... Cops have used Flock's FreeForm search feature to look for people with tattoos and wearing specific sport shirts, and searches sometimes include the target's race, according to data reviewed by 404 Media. [yeah, 404 Media, you might start there]

https://wlos.com/news/local/asheville-flock-cameras-paintbal... officers identified the juvenile suspects through an investigation and the use of Flock cameras... [wait, there's more, keep reading, KEEEEP REEEDING] Officials who support the use of Flock cameras have argued that the cameras help solve crimes and find missing or endangered people.

Here's how we say "hello" in Swedish Meatball: "Uff Da!" Bumper stickers available.

m3047··on Cop Explains Why He Used License Plate Reader to Stalk Woman
1) Flock is a company.

2) One of their products is a license plate scanner / reader.

3) This scanner / reader consumes camera output which includes license plates.

3) One of their products is a tracker / alerter / searcher.

4) The searcher / tracker isn't limited to license plates, it can correlate on other aspects in the photo. These other aspects concern the vehicle, the vehicle occupants, objects and individuals elsewhere in the photo.

m3047··on Google has acquired the data of failed US airline Spirit
Speaking from the perspective of someone who experienced the beginning of the Internet in one of the places where it began...

The real difference with phones is that they come with their own network, which vaguely incorporates the internetworking protocols. In the pioneering days of the internet, the ISP was the closest thing to you which was actually connected to the Internet. Early email paid attention to store-and-forward protocols, nowadays mailing lists are forced to use DKIM in order to deliver to the large ESPs and can't get it right.

The availability of network connectivity is much more pervasive today, clearly store-and-forward has mostly gone away. (Not to be confused with MTA-MTA hops, although these days most of my mail has exactly one hop on the actual Internet, again demonstrating the pervasiveness of connectivity.)

Not sure about Google and Microsoft, but Facebook was (dunno if they're still in the phone business) the de facto ISP for large numbers of people in the third world.

m3047··on A 3rd World Embedded Engineer Responds to "RISC-V They Should Have Known Better"
I think I figured it out: there's wrought iron over the window...
m3047··on Abdominal fat predicts heart disease risk better than BMI
The serious backwoods rock climbing cohort calls that "goon coefficient". I (also) have a high goon coefficient.
Page 1 of 28Next →