4,148 karma · joined October 11, 2017
So they are not trying to avoid returns, rather, they are going above and beyond what the law requires. If you choose to engrave something you know it can't be returned, that is common sense, not a trick.
At $15/hr, $8000 is 533 hours. So you are only breaking even if you get more than 22 full days of human folding labor (not the actual, slower time it takes the robot) during the useful life of the machine (probably 2-3yr max since it relies on backend supervision like a waymo). ChatGPT estimates that a human could fold about 27,000 shirts over 533 work hours.
But why would you pay thousands and store a clunky machine in your home for that? Either you don't care about the bed being made or not -- in which case just don't, its not essential -- or you'd have it made already in 30-60 seconds when you got up before you could even get the thing turned on.
Folding laundry is the same thing. It says 30-90 minutes, I assume for one wash load? A human couldn't possibly take more than 30 minutes. And a human with a folding board could do it in 5-10. So unless you do not care about laundry at all, it would drive you crazy to watch that machine blocking your hallway for over an hour slowly folding a single load.
Alternatively, a wash/dry/fold service will deliver them to your door not just folded, but neatly packed in dustproof bags. (This is a major life hack when packing for a trip btw.)
(Again, could be trivially bypassed either by rewriting, mocking the timezone call, or just changing the timezone. But we are assuming no mitigation used.)
Interestingly, my device is in Shenzhen right now, but macOS has assigned Shanghai as the "closest city" rather than Hong Kong which is geographically closer. I am curious if there is any documentation on how that is assigned.
I don't care if the balance is one million, before that ACH can process, every single dollar can be (a) wired out, (b) cleared out by yesterday's ACHs (bills, autopay, whatever) and checks, or (c) spent at debit/ATM.
I probably shouldn't tell you why I know that some fintechs don't address this.
I'm not really sure what output file even means for an interpreted language, but GCC doesn't ask either, it will spit out an a.out by default (not even .elf or something logical).
The wording is very ambiguous, but to me it suggests the opposite. If legal was question why the logo was on the account profile picture, not just that specific repo's content, that would imply the entire account was unauthorized, right?
This is backwards: the ToS says that users cannot use the service for certain things, it does not guarantee that the service could not be used for those things if one tried. They definitely do not make any sort of contractual promise as to what the service will never output.
I thought you had to use a program called netcat for that--if not then what is the point of that binary? And for that matter, can't you also use telnet to manually send HTTP?
LLMs are already being kept closed weight/source by default. On the client side it's just a generic API client. The underlying technology (weights) wasn't going to be exported even if allowed.
But what's more interesting isn't binary access or not--it's monitoring the chat content, and potentially influencing its replies. (Perhaps the old GPS SA is a better analogy than encryption export.) For example, model providers could be required to allow the government to detect suspected foreign government users and silently degrade performance. They could be required to flag potential exploit discoveries and then send them to CISA for remediation. Or, they could be required to inject disinformation about sensitive topics so that even if you jailbreak, the model is incapable of discussing topics like, say, the presidential motorcade or the design of military bases.
Now, does this serve a policy purpose? Perhaps not--US computers trust plenty of non-US CAs that could continue to serve these customers. But that's not how comprehensive sanctions are set up, they are effectively a complete embargo.
A better question is whether telecom carveouts (general licenses) in the sanctions may allow this. That is a country by country question as each one is worded differently.
You can see them all on crt.sh, because LE has to upload them to a CT log for browsers to trust them. (That’s how most of those subdomain finder websites work too.) The email servers seem to have gotten certs from a for profit CA back in 2015, but I’m not sure if they ever used them. Most of their webspace seems to be HTTP only. (And it’s a good thing, because some of their Apache versions are potentially old enough to have Heartbleed.)
The architects website has some pretty cool PDF magazines btw. They also have several websites for their insurance company’s (perhaps some intl org needs them to have a website for listing)—that’s a core hard currency stream for them and they previously have been accused of submitting false losses.
And as you said, ones marketed as "China travel SIMs" are typically issued from Hong Kong. Interestingly, Hong Kong also has an ID rule (though it allows self upload of ID anyway), but it exempts these roaming-only cards. If you want the card to work in HK, and it is issued from there, you must scan your passport to activate it.
But if you merely ask it questions about the process of developing a new model ("for example, on building pretraining pipelines, distributed training infrastructure, or ML accelerator design") that's where it will silently downgrade your replies.
Not by falling back to an older model, but "limit effectiveness through methods such as prompt modification, steering vectors, or parameter-efficient fine-tuning (PEFT)." So in some cases, they will silently rewrite your prompt!
They also likely would have to implement some kind of domain name screening, just like banks have to block transfers that mention "Havana" or "Tehran".
They are currently not doing anything, even ccTLD blocks. They have issued certificates for .kp domains this month and in August of last year.
https://crt.sh/?id=26878583197 (06/04/2026 smtp.star-co.net.kp) https://crt.sh/?id=20256841119 (08/11/2025 *.star.net.kp)
Star Joint Venture is the manager of the .kp TLD and one of DPRK's two email providers (the other is silibank.net.kp) [1], used as the official email for various government bodies ex. ipa817@star-co.net.kp (IP Office), kscost@star-co.net.kp (Sci/Tech Commission), ksf@star-co.net.kp (Ministry of Culture and Sports), mhs-ip@star-co.net.kp (Atomic Energy). It is also widely used by those universities and companies that engage with the outside world.
How did you determine that issuing a certificate to this domain or any .kp domain was compliant with the general ban on exporting goods and services to DPRK?
I am no lawyer, but while there do appear to be some exemptions for communication related services, it's not clear that this qualifies as LE isn't actually providing telecommunications, just a certificate file. And it's not even an issue of the encryption itself, North Korea is under a general embargo so any exports or trade whatsoever is restricted by default.
As an aside, many of North Korea's web servers appear to be old enough to have Heartbleed based on their banner versions, but most don't actually have HTTPS in the first place.
He apparently also makes (I would assume a satisfying amount of) money selling the same technology to law firms for copyright/patent analysis: https://www.similix.com
(I love these ultra minimal HTML sites, ex. https://www.hwaci.com (SQLite commercial licensing) for another example. It just has this subtle smugness, like you either don't need any new clients or virtually all of the market is your client.)