HNHacker News
TopNewBestAskShowJobs

nrmitchi

5,685 karma · joined December 24, 2013

email: me @ <username>.com
submissionscomments
nrmitchi··on We're going to need default hard budget caps on pretty much everything
> but there’s a limit to how surprising a bill can be

I think they explicitly said that.

nrmitchi··on Sites in ChatGPT
All of these "side quests" (and especially this one) are attempts to build a walled-garden.

Especially this. OpenAI will host it. OpenAI will throw "Sign in with ChatGPT" there. "Apps" will be built that depend on end users ChatGPT "connections". The app will fundamentally not work without an end-user having a ChatGPT account/subscription and "connected apps".

Having "the best model" will absolutely not support a $1T+ valuation. Owning the activity of 25-50% of internet users (assuming a split between OAI/Anthropic/Google/maybe-Meta), is.

nrmitchi··on OpenAI bots meddled with multiple US Government agency sites
> I'm guessing they didn't even read the article.

Straight from the HN Guidelines page:

- Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that".

nrmitchi··on OpenAI bots meddled with multiple US Government agency sites
I disagree that that is valid. "Intent" means that you didn't click a button, that button went somewhere it shouldn't, and the action had no intent to "hack".

In this case, the "agent" had every intention of doing what it was doing.

I'm not claiming that "accidental hacking" (whether by human, or agent) is covered and illegal. I am claiming that calling this "accidental" is not a valid defense. One incident? Maybe. But this is pretty far past one incident.

nrmitchi··on One Piece of Flock Camera Data Put This Innocent Woman in Jail for 13 Days
Flock isn’t an “AI” though? It doesn’t put together a case and say “yes, this is the criminal”. It’s not a crime-solving AI.

It’s a camera system, and data can be queried by police. They have to search for something. So the cops searched for a vehicle matching the description in the general area, seemed to take the first one, and called it a day.

That’s not an AI-uncanny-valley. That’s the equivalent of (pre-flock/cameras) looking at vehicle registration list and assuming the one at the top of the list must be it.

The automation-trust is a legitimate concern but it’s not applicable here.

nrmitchi··on One Piece of Flock Camera Data Put This Innocent Woman in Jail for 13 Days
Flock isn’t an automated tool though; you don’t give it a crime, and it gives back an automated package saying “this is who the criminal is”.

As far as I know, it lets law enforcement query for things against the data. Can be specific (like a license plate) or more general (like a dark colored mid-sized SUV around <location> at <time>).

To get where this story is at, cops here must have done the latter, and taken the first name off the top of the pile and patted themselves on the back, and then waited 7 months, and went and arrested her. Unless there’s an explanation for a 7 month delay, it seems designed to allow defensive evidence to spoil.

There isn’t an uncanny-valley of automation here. There is just lazy, grossly-incompetent, bad-faith, and malicious cops/investigators.

nrmitchi··on One Piece of Flock Camera Data Put This Innocent Woman in Jail for 13 Days
When the headline of the article is explicitly blaming Flock, and not the cop/DA/judge who never even looked at the evidence available, it is 100%, whether on purpose or not, letting/helping the cops point the finger at another party.

The headline is what 99% of people read, and remember.

nrmitchi··on One Piece of Flock Camera Data Put This Innocent Woman in Jail for 13 Days
Absolutely not all cops and prosecutors, or even the majority of them, are this lazy. Every tool is a tool that lets them "be event lazier" and make it "easier for them to abuse us". Removing any tool that let bad-actors be lazy is not an alternative for removing the bad-actor themselves.

This situation the equivalent of an eye-witness saying "Ya, I think it might have been this person I know, Tom!" and a cop/prosecutor taking that at face value and arresting Tom (and the system that allowed that to happen).

The people who make decisions and take action so (grossly) negligently need to be held accountable and face consequences. Blaming the tool (whatever tool it is) is giving the people who have the actual responsibility an escape hatch to avoid accountability.

nrmitchi··on One Piece of Flock Camera Data Put This Innocent Woman in Jail for 13 Days
> Police didn't care that Lindsey Isaacs' car was the wrong color, and wasn't damaged. They still arrested her because of Flock data.

This is literally the first sentence of the article.

You can dislike public surveillance, but statements like "Flock camera data put this woman in jail for 13 days" blatantly ignores the the fact that Flock didn't put anyone in jail, a bunch of cops who very clearly knew that it wasn't her.

> The Flock camera, meanwhile, had recorded Isaacs’ car and its license plate several miles away from the site of the accident, sometime around the time of the incident.

Blaming a tool, when the cops in question are clearly willing to grasp to whatever piece of "evidence" makes their job "easier" is a giant cop-out and excuse for the people who are abusing it.

Any piece of evidence requires some form of critical examination; that is what law enforcement's job is. If you're just going to go with the first theory/piece-of-evidence they find.... they're not doing their job (and violating peoples constitutional rights through sheer laziness).

nrmitchi··on OpenAI's Sam Altman to Brief UN Security Council Next Week
Doubtful. Almost definitely going to be taking direction from "business" people with misaligned and ulterior motives, rather than asking questions of people with long careers, research, and history in the field.

Which is just... highly unfortunate.

nrmitchi··on A coffee shop owner used AI to make a menu poster. Then came the angry DMs
"she saw a good enough sign "

The additional thing is that it... isn't a bad sign. I have seen a ton of terrible AI-slop food signage. This sign does not try to be "hyper-realistic", and end up in an uncanny-valley, or look like fake food. It's not fully of spelling mistakes and things disobeying the laws of physics.

Does it have maybe too much information shoved on it? Sure. Does it use a font that is definitely "AI-popular". Ya.

But there are tens of thousands of worse examples of AI menu usage out there. It seems people decided to pick on this one because it's not horribly done. A local artist looked at it and, instead of thinking "wow that looks soo fake", they thought "that's basically the same thing I would have delivered, and 99% of people wouldn't have been able to tell the difference! I should have been paid for that!"

Reference: the sign in question: https://www.instagram.com/p/DdBgsgnNDaC/

nrmitchi··on A coffee shop owner used AI to make a menu poster. Then came the angry DMs
You are projecting.

Not only are yo projecting, you are attributing "AI coffee shop sign" with "not successful". You yourself say what made your "retail" successful was "the care I put into curating the product, building out the space and attending to the customers". None of those are "the A-frame sign that we put out for specials".

You are trying to find one thing you disagree with and use that to call the owner "too lazy" and "doesn't care about their work".

nrmitchi··on A coffee shop owner used AI to make a menu poster. Then came the angry DMs
I think you missed the point. I was using the parent commenters "too lazy" language. Small business owners are very often drastically overloaded and any "corners cut" is to get what is needed in place, and not "lazy".

If you think the opposite, and that small business owners have ample time and are just lazy when they don't build everything from scratch, you should teach a course about how to manage a small business.

nrmitchi··on A coffee shop owner used AI to make a menu poster. Then came the angry DMs
I agree that people like the dogpile, but those dog-piles are normally starts by someone who feels like they are personally victimized and threatened by whatever action they are objecting to.

People take things very personally when their core livelihood and ability to support themselves are threatened.

nrmitchi··on A coffee shop owner used AI to make a menu poster. Then came the angry DMs
> My basic stance these days is 'if you were too lazy to do this yourself and handed it off to ai then why should i be motivated to engage with it'

The issue comes when you (or someone, not you personally) dig way to deep into what "it" is, there is always something that someone was, to quote you, "too lazy to do yourself". You might not like the result, and that's fine, but you're phrasing it as if the other person is just being unnecessary-lazy.

They probably bought their display stands instead of designing and building them themselves. They also probably bought the cheap ones from Amazon (instead of building them themselves, or hiring a local artisanal carpenter to build them).

Do you refuse to engage with a pastry stand because the owner was "too lazy to do it themselves"? If you're at a friends house and they order food, do you refuse to engage with it because "they were too lazy to cook it themselves"? Where do you draw the line?

Your point as it applies to something that takes a sufficient portion of your time is valid, but this conversation is literally about a menu sign at a coffee shop. If you spent substantial time engaging with a coffee shop sign, I have questions (and wouldn't want to be behind you in that line).

nrmitchi··on A coffee shop owner used AI to make a menu poster. Then came the angry DMs
From a more... pessimistic/optomistic point of view (I'm really not sure which applies here, it depends how you look at it) It is also about a culture with absolutely no safety net, where AI and increased automation moving into someones field (in this case, graphic design work) isn't just "oh, less people will need my services" and more "My income will completely disappear and I will be broke/homeless faster than I can possibly learn something else fast enough to compete with the omnipotent AI".

The way to make these transitions less aggressive on everyone is to not have it tied directly to whether or not someone can afford to eat.

nrmitchi··on A coffee shop owner used AI to make a menu poster. Then came the angry DMs
> They own the business, they don't make the coffee

You might not have spent a lot of time in the world of "small business", but this is hysterically out of touch.

nrmitchi··on We got admin access to Baseten's production GitHub
In terms of negligence use (openai, anthropic), ya, I agree, and we really need some consideration of "reasonable expectation" of the outcome.

In terms of "We wrote a hacking agent designed only for hacking and sell it as a self-hacking service and then pointing it at someone else and omg can you believe what it did we had no intention of hacking" sense, I don't think that's really applicable.

The mens rea is explicitly there and it's not valid for them to try to hide behind an "agent".

nrmitchi··on We got admin access to Baseten's production GitHub
There is a big difference between "bad security practices" and "someone made a mistake 2.5 years ago"
nrmitchi··on We got admin access to Baseten's production GitHub
> They didn't break in. They found a key that their neighbor dropped and returned it.

Ya, returned it after poking through all of the drawers and iterating through business information that they found.

There is a white-hat line that OP very clearly crossed here.

nrmitchi··on We got admin access to Baseten's production GitHub
There is also the big difference here between anthropic/openai maybe being negligent, but did not purposely instruct agents to go commit crimes.

The service that this whole thread is about is explicitly a "hacking agent", designed explicitly to try to hack things, and was then pointed at a third-party (seemingly without their permission).

Anthropic/OpenAI can reasonably claim that they had no intent and are trying to stop it. OP here did this explicitly and purposely.

nrmitchi··on We got admin access to Baseten's production GitHub
They "validated that the key was valid" by iterating internal repositories and listing the contents of said repos and poking around at what they do/are-for, including, apparently, iterating through customer lists/information.

The white-hat line stops at "validated the key was valid". It does not extend to "poking around inside to extract business-confidential customer information".

nrmitchi··on We got admin access to Baseten's production GitHub
Whether it's valid or not, there is something that rubs me the wrong way about a security tools company using a real customer/vendor as a marketing campaign. This "story" could have been told without naming, bluntly, their "victim".

It would be different if it was some complex, multi-step exploit, but the tone is closer to "look how much Baseten fucked up!".

Strix also crossed the line at this point:

> Strix decided to pull an image and see what was inside.

You're going past the white-hat point here when you start active exfiltrating data and looking at it. Once you start using credentials from the exfiltrated data and start listing and poking around internal systems, you are way past it.

Listen, I get it, their product is "meant for" self-testing, so it assumes it's safe to go digging. After all, it's a self check. That is exactly why it's irresponsible, and borderline illegal, for them to point it at a third party. Even if they had "permission", I dobut that permission extended to "and also search and/or download our repos if you can".

The overall tone is less than professional. Statements like (in bold) "This is an insane amount of access to leave in a publicly downloadable image." Everyone is aware of this, and it's phrase like it was a purposeful decision.

Security tools from teams that actively shit on the people they're designed to "help" feels wrong.

Edit: For clarity on my point about "pulling repos", this post includes descriptions of the purpose and functionality of multiple repos (which is past what a name gives them), and they explicitly state: "A listing of that private repo showed a top-level customers/ directory, with subdirectory after subdirectory named after Baseten customers". Strix explicitly took action that they knew they were not permitted, and extracted confidential customer information. Claiming "We didn't clone the customer repo" when you, instead, just listed the contents of the repo, is not a valid defense.

nrmitchi··on Garry Tan wants US open-weight AI labs to 'distill' frontier models, too
Well that is a different thing and an entirely different provider than OpenAI/Anthropics ZDR promise.
nrmitchi··on Garry Tan wants US open-weight AI labs to 'distill' frontier models, too
The guarantee on this is a (contractual) “trust me bro”, and a right to try to sue a multi-trillion-dollar company who will absolutely drive you into the ground with legal red tape.

If you are big enough to be able to withstand that, you’re already running (or trying to run) your own/open-weight models.

nrmitchi··on OpenAI's Sam Altman says it would be 'ill-advised' to go public in 2026
The "private market" at this point is so huge though that you'll have an "insiders" private market, and an "outsiders" public market to dump the bag on that the insiders don't care about.
nrmitchi··on OpenAI's Sam Altman says it would be 'ill-advised' to go public in 2026
It really doesn't matter. They're doing secondary offerings for employees and individual holders, and they'll have no issue allowing private transactions for larger holders.

The general wealth distribution has shifted to the point that they do not need access to public funds, and frankly, if they can't find private funds for their needs, it is a huge red flag that they would just be dumping on the public.

nrmitchi··on Cognition launches new SWE-2 model, Rivaling Fable 5.1 and GPT-Astra
> Sol xhigh is 90% on TB2.1 but 37% on TB4. Is it also "benchmaxxed"?

Yes.

nrmitchi··on Show HN: HN Match Maker – Matching "Who Wants to Be Hired?" With "Who's Hiring?"
You seem to have ignored the second half of my response. In your case... you did it. This project, based on the current date, no data older than today, and the posters own statements, is "I asked gen-ai platform to make it for me, then pointed a domain at gen-ai-company hosting, and called it a thing I made."

As of the current moment, the domain is just pointing to an IP owned by "Abacus.AI, Inc.". The entire platform is "describe the app you want and we'll generate it and host it for you".

Might just be my opinion, but I consider a Show HN that is "look at the thing AI entirely made for me" to not really be aligned with good faith sharing of work/projects.

nrmitchi··on Show HN: HN Match Maker – Matching "Who Wants to Be Hired?" With "Who's Hiring?"
That's not what this is though. This is not (just) scraping job postings; the public-facing interface of this is "Greg, who I don't know, wants a job. Here are the jobs that I think would be good for Greg, who again, I don't know".

My claim of "bad faith" was specifically because the post, between 1) explicitly pointing to a "full stack ai dev platform" ("So I had abacus.ai whip one up"), and 2) the entire missing list of "observations" (mid post), came off more as a shadow advertisement for an ai dev tool than an actual project.

Page 1 of 32Next →