HNHacker News
TopNewBestAskShowJobs

nicce

5,733 karma · joined February 27, 2021

submissionscomments
nicce··on AI companies in race to demonstrate their model most threatening to humanity
> The OpenAI HF incident is separate from this. It involved actual zero days, teamwork and message passing, and sophisticated chains of exploits.

What exactly? They seem to be trivial SSR/path traversal and input validation issues. Including misconfiguration. Nothing novel.

nicce··on AI companies in race to demonstrate their model most threatening to humanity
> That seems pretty locked-down to me. I don't think it's reasonable to expect companies to find all the unknown vulnerabilities in any third-party software they use.

It is reasonable to expect for companies to select third-party components that are fit for the purpose. Artifactory was not running in the sandbox, but rather as the edge, so it is in the sandbox'es trust boundary. Same sandboxing requirements would apply for this software too as it is pure dependency.

Security trust boundary was extended to include Artifactory as a dependency, but Artifactory was not fit for the job, and sandboxing failed. And as the network isolation was not good enough, the impact was catastrophic.

nicce··on AI companies in race to demonstrate their model most threatening to humanity
Lot's of hints in the Wikipedia page: https://en.wikipedia.org/wiki/OpenAI%E2%80%93HuggingFace_inc...

E.g. even the basic thing (block the internet), was not actually properly blocked.

Some comments: https://techcrunch.com/2026/07/22/how-an-openais-human-mista...

nicce··on AI companies in race to demonstrate their model most threatening to humanity
In early Covid-19 era, there was a lot of speculation how the virus escaped Chinese labs. The narrative was absolutely opposite. Not about how developed or sophisticated the lab was in creating or modifying such virus, but how poorly it was managed since it was able to escape the lab. If these LLMs really are so dangerous, the framing should be indeed the same.
nicce··on AI companies in race to demonstrate their model most threatening to humanity
> OpenAI, for example, thought their sandboxes were good enough. As their AIs got more and more advanced, they kept proving them wrong - sandbox after sandbox.

What I have been reading, was that their sandboxes were so poor that it was pure negligence. I am still waiting to see if some external and neutral cybersecurity company with high reputation would audit their sandboxes and how they are being used.

nicce··on When did Google get so weird?
And the biggest risk with AI. There have been many posts about how dangerous it is.
nicce··on Don't couple your Go code to GitHub
> A GitHub URL at least is still an credible identifier, your custom domains is not, and likely will never be given how the system is accustomed to. Domain is for branding, not identification.

The post is about commercial software. If enterprise’s domain is not credible enough, then there are bigger problems.

nicce··on Ember-1
In a Codex subreddit there is a bunch of stats.
nicce··on Ember-1
Sol pricing dropped but so did the quality few days ago. I wonder when these companies are sued for making the terms from their side to go downwards while taking the same subscription cost.
nicce··on Improving site performance by shipping more CSS
I thought that whole point of CSS in JS was about building the CSS with JS in build time, to get managed and optimized output, who madman runs in in runtime?
nicce··on CEO of Mistral: AI is software. It can be controlled
> Boeing's MCAS system was also "just software". Which in principle can be "controlled", i.e. changed, updated, audited or whatnot.

> But then people died precisely because pilots found themselves unable to override or "control" the systems precisely when it mattered.

Wasn't it designed to do so? Also works as a counter example, that sandboxes can limit AI if just operators want to do so.

nicce··on CEO of Mistral: AI is software. It can be controlled
Obviously, if someone is state-level actor and allows government's employees to do whatever they please, there is no other solution than political pressure.

But for other cases, it is not different than other cyber crime. Except that these AI capabilities can't live on the toaster yet. If we get state of the art model running fast on Raspberry Pi, then we have real problems.

nicce··on CEO of Mistral: AI is software. It can be controlled
> So, how many rogue AIs are we willing to tolerate?

It will balance automatically based on the severity they cause. If they constantly break systems, punishments will go up against the operators and the effect will be similar as with other serious crimes.

nicce··on CEO of Mistral: AI is software. It can be controlled
We don't live in anarchy, or do we? We probably would still have slaves if it would not be so aggressively penalized.
nicce··on CEO of Mistral: AI is software. It can be controlled
> More or less like atomic bomb is hardware, it can be controlled.

That is the point. It can be controlled by the operators if they want to.

nicce··on CEO of Mistral: AI is software. It can be controlled
> as long as anyone anywhere is willing to make money by renting hardware to it.

So it is controllable? Just put the people who do this responsible. Old problem, same solutions. Just excuses to avoid responsibilty and make profit at the same time.

nicce··on GPT-6 Sol is like GPT-5.6 Terra, GPT-6 Luna is like GPT-5.6 Asteroid
They are also so much slower. No wonder how they are ”more efficient”.
nicce··on WordPress: Unauthenticated path traversal leading to conditional RCE
> We don't need a metric; I'm already going to have to read and assess the vulnerability to decide how I actually want to assess the risk given my infrastructure, so the number's not doing me any good.

Would you say that vulnerability with CVSS score that points to low is equally important to verify and take care of than CVSS which points to critical?

nicce··on WordPress: Unauthenticated path traversal leading to conditional RCE
> CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to.

Not really. They are very good at describing the technical impact. Sometimes pre-condition is very rare and that reduces overall likelihood but for those few it applies, the impact still could be catastrophic. Who wants to risk it if whole business could go down?

nicce··on Grok 4.7
Sadly, there is no way to tell if this is running with real weights or being heavily quantized.
nicce··on AI chatbots give wrong answers to financial queries 'most of the time'
> It's just AI slop and it should be taken with a mountain of salt.

Can't you see the irony. You are defeating the argument that LLMs are incorrect or weak with low effort with the term "AI slop" that itself is a narrative that AIs produce weak outputs with low effort.

nicce··on Why do we need human mathematicians anymore?
> Every problem you solve, ten new ones open up. Like a fractal, the more you zoom in, the more detail emerges. No matter how much better AI is at solving problems, it's not going to generate the "final, complete compendium of mathematics" that that seems to hover over this post.

I guess Terence's main point has been all the time that if we let AI solve all these existing problems, we don't notice the new ones and then there is stagnation.

nicce··on ChatGPT now knows what you do on other websites via ad collector
> Most people do not, in fact, want to read raw prompts.

I also wonder what is the energy consumptiom difference between the prompt and fetching website.

nicce··on ChatGPT now knows what you do on other websites via ad collector
I think that if they don’t block by default, is quite significant. Chrome + Edge has superior marketshare and then add the % people who have no idea what these mean and don’t change defaults.
nicce··on If AI coding is lowering your code quality, you're not managing quality right
I would say that it is like gardening. If you let them go havoc from the start, the weed will take over. If you keep focusing on removing the weed and enforce specific standards and practices over the code base and it keeps growing, over time LLMs start to suddenly follow that and they don't make so much slop anymore. At least that is my experience. But I force specific audit agent after every added feature which says them to force compliance with AGENTS.md and check the consistency with the code base.
nicce··on CrowdSec Source Code Leak
GitHub Enterprise has at least some level audit log
nicce··on Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA
> put on AI inference when they don't build the GPU?

GPU in AI world is essentially a set of specific matrix calculations that this CPU supports on hardware-level. Thought memory speed seems low.

nicce··on How, Exactly, Could A.I. Kill Us?
As long as those data centers don't have robots or AI managed guns, we still could just cut the power off.
nicce··on Neovim have a ~$800k Bitcoin donation sitting untouched since 2023
> The main argument I've heard against using bitcoin as currency is that it's too volatile.

Also the transaction cost. Is it any better?

nicce··on One Year of Sponsored Servo Development
It is unfortunate. I guess we also can blame the social pressure. Most want features and don't value quality or durability unless something breaks and is unusable. Competence is often measured with shipping speed, rather than service had zero bugs over its lifetime.
← PreviousPage 2 of 34Next →