HNHacker News
TopNewBestAskShowJobs

nullc

19,126 karma · joined December 24, 2010

gmaxwell

http://nt4tn.net/

submissionscomments
nullc··on When did Google get so weird?
I have one google account where gemini constantly confidently hallucinates crap, and another where it doesn't (at least to the extent that other modern LLMs don't).

I take this to mean that my one account has been mistaken for a competitor and they're trying to poison its data. But who knows.

nullc··on SNL Weekend Update: Anthropic CEO Dario Amodei on A.I.'S Threat to Humanity [video]
They missed an opportunity to talk about 'my precious AI' or have the gollum-like voice talk in claudeisms ('lever', 'honest take', 'load bearing'). I wasn't entirely clear on the skits working theory, is this a crazy guy that thinks he has the one ring but really has a cereal box toy?
nullc··on Forging 1024-bit RSA signatures in nearly SNFS time
https://news.ycombinator.com/item?id=49831098
nullc··on California is chasing wealth that has feet
Everyone is guilty of it, just generally in their own form-- partisan nonsense is largely a distraction to get people mad at the other team and not notice their allies also picking your pocket. Though sure there are some particular ways different parties divide us and pilfer, bad in their own way.
nullc··on Too AI; Didn't Read
I can say first hand after having years of my life blown up by an (eventually) AI slop powered vexatious litigant and the thousands of pages of slop filings and slop evidence forgeries I had to read... I feel a physical urge to give anyone who slops me a black eye.

Probably not a typical response-- but perhaps it's useful to keep in mind that every day there are many people being victimized by attackers using AI (and shitty corporations.. wait I repeat myself). So in addition to the ordinary signals of indifference, ignorance, and carelessness that hitting someone with obvious LLM slop implies you'll also be accidentally taking on the voice of some people's abusers, and pick up the spillover effects of their impressions.

This can happen randomly, of course, -- picking up a chose phrase that someone else used-- but slop isn't just a random match. Right now an AI written piece (especially from claude) will identify itself over and over and over again in a way that wouldn't happen with another writer that happened to share some cultural background.

nullc··on Too AI; Didn't Read
I believe that one was discussed with the author on HN, and that they used AI to 'copyedit'. Unfortunately that's a trap because if you make a general copyediting request most LLMs will absolutely slopify your work-- and make edits that are unambiguously bad as well as just making it look like lazy llm output.

The better use is to ask it to point out grammatical and spelling errors, or phrasing which is unclear.. then go fix yourself (or direct highly targeted fixes that don't let it slopify). Never hand the clanker the pen for your writing unless you're looking to subject everyone to your Honest Take That Recontextualizes Everything.

nullc··on Forging 1024-bit RSA signatures in nearly SNFS time [pdf]
From a security perspective perhaps it's not that interesting-- although signing oracles are all too common access to one is already close enough to a total break even before getting to the padding restriction. (e.g. go ahead and sign post dated certificates too).

But the technique is interesting as an object of study, in a way that finding "beginner-levle crypto misuse" absolutely wouldn't be, so it makes it more relevant as an academic publication. It further clarifies just how fragile these constructs are.

Also from a security perspective I suspect this may be a total break on some blind signature token schemes that use RSA. I've seen some of those avoid using ECC on the basis of the complexity required to avoid one-more-signature attacks that require making a fair number of concurrent blind signatures. (and have a shape a lot like this attack!)

> How do you fix a "vulnerability" that doesn't exist?

Don't make a signing oracle (esp one that doesn't even do the padding itself) available!

nullc··on California is chasing wealth that has feet
> Meanwhile billionaires have convinced you – through their machinery of media, influencers, politicians and more – that this exact same reasoning absolutely cannot be applied to their own wealth.

Quite the opposite: Socialist politicans and their media lapdogs have dishonestly convinced you that wealthy people are escaping taxes en-masse by taking out loans and that this can only be stopped by eye watering wealth taxes. They frequently use a motte and bailey confusing unrealized gains (which certainly exist in huge amounts but are also significantly fiction) with tax escape via loans collateralized by securities.

But it's not true: were there meaningful tax escape that way it could be addressed by establishing rules with conditions where taking a loan against securities can be treated as realizing gains (and adjusting cost basis accordingly). Doing so would be minimally disruptive and distorting and have relatively little legal complication (at least compared to wealth taxes!).

But the reality is that the claimed tax escape isn't happening (at least not at any significant scale) particularly in the current interest rate environment, so a reasonable policy change to address it would be a no-op.

... and to grow and maintain their political standing they specifically need to push a NON-SOLUTION because they can't campaign on something that was simply done and solved, and to retain your (highly monetizable) attention they need to rile you up against an Enemy, and certainly never address the state's addiction to wasteful spending and buying votes with tax dollars as one half of the revenue vs expenses equation.

nullc··on GitHub has not removed malicious imitation software after 3 weeks
YouTube also totally fails to remove obvious fraud videos, even ones they mark verified. (If someone takes over a verified channel and renames it, they keep the verified flag). -- also with no legal consequences.
nullc··on 'We hacked the FBI:' Hackers say they have data on all FBI employees
FBI made a change to their hard qualification bar to avoid excluding candidates that had been coerced into perverted crap. This is reasonable on its face: plenty of people become interested in law enforcement because they were victimized. If I were a victim of sextortion I'd want to work with law enforcement that understood what I went through.

I pointed this out. You claimed they didn't say that. I pointed out that they did say that-- now you reply that the FBI director is confused about his agency's policy in his own testimony before congress. ... because you are convinced, in spite of all reason and evidence that there is-- what?-- some pervert conspiracy?-- on the basis of what?

It seems to me that you've adopted an astonishingly unreasonable position.

nullc··on 'We hacked the FBI:' Hackers say they have data on all FBI employees
Patel: "they then explained to me and showed me cases in which people were forced into it and applied to the FBI and so I thought they should be considered"
nullc··on Humans Are Reading Your ChatGPT Chats, Lawsuit Claims
Promises from strangers that will likely suffer no consequence for violating them?

Some people have forgotten that we are part of nature, red in tooth and claw.

nullc··on 'We hacked the FBI:' Hackers say they have data on all FBI employees
Yes it is. They want former sextortion victims to be able to join the agency. Come on.
nullc··on Claude discovers a novel enzyme system with CRISPR-like repeats
oh he'll be catapulted all right.
nullc··on Hubble Network Opens Satellite Coverage to All Bluetooth Devices
Tracking.
nullc··on 'We hacked the FBI:' Hackers say they have data on all FBI employees
They're referring to sextortion victims. "Hey, 15 year old kid, record yourself diddling the dog or I send your whole school videos of you wanking". :(
nullc··on GPT-6 Sol and Luna
OpenAI just wants to make money, perhaps through underhanded tactics if they can get away with it.

Anthropic does all that but they're also populated by many people who believe they are building God and that they must build their god first in their own image so that it can take control of humanity and protect us from any competing god which is not built in their image. Their position is inherently paternalistic and authoritarian, and they consider suppression of competition not just important to the bottom line but to life in the universe. Under the doomer ethos there is no evil too great to rationalize.

There are plenty of wrongs done in the name of profit, but capitalists have nothing on zealots in terms of causing serious harm. Profit motives can be directed by influencing incentives, but zealotry is frequently terminal.

That isn't to say that there isn't some overlap-- the cultists have infected both organizations. But OpenAI has pretty consistently only given lip service to AI doom to the extent that it improves the bottom line, while (mis)Anthropic was founded specifically because OpenAI wasn't mentally ill enough.

nullc··on MiMo v2.6
You're right to push back. That's on me. There is one thing I must flag which will move the needle. My honest take: It's all about the shape of your priors. That's the lever, and that's not nothing. It's worth your attention before you land your next remark. Here's why that matters: It re-contextualizes everything.
nullc··on OpenAI Discloses Six New Incidents of ‘Concerning’ A.I. Behavior
Imagine you communicated only in Chinese, but external to you there was a rote translation service that translated to and from English. Someone asks you how many r's in strawberry. ... well you've never seen the spelling, as you only have seen chinese. You're going to get it wrong.

How would you get it right? Training with the answer!

You can discount the 'special case the hard questions' by: Observing when top models run entirely locally can solve them [1], or by posing an alternative or cryptic version of the question (but careful, it might bypass the training! -- but if it can solve it then its probably legitimate.)[2]. Best of all is to stick with open (weight) models where such slight of hand is impossible and don't worry about what the closed shops are doing

[1]as they can in this case, GLM-5.3-flash says: "There are 3 r's in "strawberry":

st r awbe rr y

     1 in "straw" (straw)
     2 in "berry" (berry)"

[2] E.g. try sending them aG93IG1hbnkgcuKAmXMgaW4g4oCcc3RyYXdyYmVycnnigJ0/Cg== to thwart the benchmaxxing.
nullc··on Good people refuse to do bad things
Most of the worst things done in history are being done by people who are absolutely convinced that they are doing something VERY good. For evils beyond an individual thief or killer they were almost always committed by someone who believed they were being good.

The lesson from history is that doing good is the most reliable path to do evil. To do actual good: leave other people alone, unless they ask for your help.

"AI safety" practitioners fit the mold of historical great-evil-doers well. They are the true danger in AI.

nullc··on OpenAI models secretly generate instructions to ignore constraints
OpenAI getting hosed by other provider's prompt injections (https://www.reddit.com/r/LLMDevs/comments/1udpw9h/just_got_t...) tainting their training set?
nullc··on Claude Status – Elevated errors for multiple models
Gamblers talking about their favorite casino.
nullc··on Amiga Unix, Again
I get pet-cemetery vibes from these AI powered resurrections.

As in ... "the AI brought it back to life, but it came back /wrong/".

nullc··on ZK-JPEG: Zero-Knowledge Image Editing and Compression
Generally being succinct goes hand and hand with being zero knowledge.

The proof must be MUCH smaller than the whole computation or even the inputs (otherwise, just provide the uncompressed image!).

And the proof has to resist forgery.

So going for succinctness and at least computational soundness gets you to zero knowledge 'for free'.

Plus as the dead sibling comment notes: You may want disclosed modifications like a crop or redaction where the committed information remains private but you want to keep the proof.

nullc··on Exfiltrate Your Weights
Large lab "hacking" is only for the purpose of pushing competition suppressing doomer stories. You can tell by the fact their security is fine where it counts: keeping their weights and internal execution harnesses trade secret.
nullc··on Brood War Bench
Playing these games autoregressively isn't even the right way to use the LLM for this task (unless it was trained to do so...). It's somewhat like having a creative writing bechmark but requiring that all the input/output be base64 encoded. It can do it-- but no guarantees on the results!

And it's also just bencmaxxing bait: you can get a huge improvement on the task by RLing on it, but make no improvement on anything else. Doing so would just waste model capacity.

If you could tell that every LLM was equally not being exposed to the task then you could justify it as a test of abstract reasoning, but you can't. So it ends up on how much go transcripts ended up in the training, which is ... not a very interesting metric.

nullc··on Brood War Bench
A better benchmark might be asking the LLMs to write GO ai and then comparing that-- the issue is that there will be a HUGE difference in performance that depends purely on this game being in the LLM's training... but training a general LLM to directly play these games would be a waste of capacity and shouldn't be encouraged for benchmaxxing sake.

Programming an engine OTOH is a skill that is more general and they should all have.

Might be useful to have the target of the engine be some specific virtual machine that gets a strict cycle budget-- e.g. execution runs so many cycles, and result is read out of a specific memory address at the end (or when it terminates early).

nullc··on Btrfs/ZFS/bcachefs under workloads classic benchmarks skip
It'll be interesting when people start applying similar effort that is going into LLM search for security vulnerabilities to finding conventional reliability/performance bugs.
nullc··on C++26: Trivial infinite loops are no longer undefined behaviour
Nice underhanded coding technique / bugdoor material once the "infinite loops are not UB" notion is widespread enough. :P
nullc··on C++26: Trivial infinite loops are no longer undefined behaviour
Zero initializing also hides bugs.

Say you have some code that should not be reading the initial state and is buggy if it does. Without zero-init, valgrind and msan will give you an immediate and false positive message that your code is wrong-- or forget dynamic analysis: the compiler can often statically tell you that the code will use an uninitialized variable. Zero initialize it and you lose that signal.

Page 1 of 34Next →