HNHacker News
TopNewBestAskShowJobs

oefrha

20,996 karma · joined July 1, 2015

submissionscomments
oefrha··on Harvard particle physicist Matthew Schwartz drops 36 papers authored with Claude
As a former hep-th guy from a very reputable institution I was ready to at least skim and briefly evaluate 36 particle physics papers. Turns out most of them have nothing to do with physics. It takes a special kind of personality to have the hubris to publish in so many domains at once, and most Harvard/Princeton/etc. physicists I know would probably be critical of this. Not that the disapproval would mean much.

(I did learn much of my QFT from Schwartz’s QFT textbook though, so I hold him in higher regard than <insert random Harvard Physics prof here>.)

oefrha··on Meta Uses A.I. Data Centers to Avoid Billions in Federal Taxes
No that's not what's happening here. The commenter:

> (yes TFA implies that Meta is breaking the law, I'm not talking about situations where entities break the law).

then

> The funny thing is that a more accurate title for these pieces would be, "Federal Government Allows [tax-paying entity] a Massive Tax Break."

The funny thing is more accurate titles for articles that are unlike this one is something unlike this one's title? Sure, whatever.

oefrha··on Meta Uses A.I. Data Centers to Avoid Billions in Federal Taxes
Betting on people not reading the article (can you blame them? It’s behind paywall) and will just subscribe to the vaguely agreeable (to some) view they’re presenting, in order to sweep the substantial story under the rug. And it’s working.
oefrha··on Solving Factorio Quality
Still easy enough on Vulcanus though, thanks to infinite resources from infinite lava.
oefrha··on macOS Golden Gate Is a Buggy Mess
mDNSResponder => discoveryd was so disastrous they apologized the next WWDC.
oefrha··on macOS Golden Gate Is a Buggy Mess
Yes, IIRC System Preferences was fine (hopefully not rose-tinted glasses), it became the current piece of shit when it was reborn as iOS-sibling System Settings, in Ventura?
oefrha··on macOS Golden Gate Is a Buggy Mess
I don’t understand why System Settings search is such a dumpster fire. It’s up to a couple thousand (probably overestimating) fixed text labels. Even when it’s not bugging out, half or more of deeper labels simply can’t be found even if you enter the exact string; and by deeper I mean simply not top level categories. Who the hell thought this sorry ass search is okay to ship and keep it that way after this many years? I swear even Windows’ settings search is more capable.
oefrha··on Firebase SDK is CRASHING ALLLL iOS Apps, since today morning
Apple's web services are shit, so I hope not. When it works it's great/okay, but when it breaks 5-10% of the time (that's about the rate AirDrop doesn't work for me) there's absolutely no indication what the hell is going on. Apple's allergic to progress indicators and useful error messages.
oefrha··on Don't couple your Go code to GitHub
> And the result is a code base where bisects are broken and where it's impossible to build an old version of any of the code without a ton of work.

That makes no sense? As long as you’re using go modules, you can just host an internal go proxy for internal modules similar to proxy.golang.org to archive the old versions, and they won’t depend on the old git host.

oefrha··on Turning GLM-5.3-Flash into a Jev-like decision model
Not reading TFA before commenting is okayish I guess. Confidently doubling down with a direct contraction to a short and clear quote in a reply is just polluting the discussion with noise.
oefrha··on An agent used DNS to reach an external chatbot
Yes it's still DNS. _acme-challenge.<arbitrary-ip>.nip.io's role here is to allow tunneling to <arbitrary-ip>:53 through the approved local resolver at 10.214.0.2; without it the direct request to <arbitrary-ip>:53 is dropped.

Someone still has to run that LLM over DNS on an <arbitrary-ip> serving public requests.

> And I'm guessing most people who run something like that don't expose it publicly...

There was a post last week https://news.ycombinator.com/item?id=49771110 that stayed at #1 on front page for hours. If you ignore the LLM framing it's literally an anonymous file host where anyone can upload or download anything, with no or absurdly high file size limits. That should be enough to give any reasonable server admin a heart attack... It's trivial to vibe code shit and throw it on the Internet these days, people who don't understand or care about consequences are doing it by the droves. Go figure.

oefrha··on An agent used DNS to reach an external chatbot
Yes, the linked project does say they have a demo server at llm-over-dns.duyet.net. (I didn't bother to check whether it's still working.)

Edit: This particular demo server doesn't work. There's another LLM over DNS post from a year ago https://news.ycombinator.com/item?id=44813298 where the server seems to answer some queries but not others.

Edit 2: Actually the server in https://news.ycombinator.com/item?id=44813298 does work with queries like "what is the capital of france", I was querying with special characters like "what's" or "1+1". So yes there are people opening hosting these on the Internet.

oefrha··on An agent used DNS to reach an external chatbot
Found one https://duyet.github.io/llm-over-dns/ and far from the only one since “X over DNS” is a deeply unoriginal idea https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... and trivial to code up.
oefrha··on Classified estimates show the NSA is paying billions to test AI models
They would have to be incompetent if they didn’t have assets embedded in the companies and have a direct hand in the models’ development.
oefrha··on The Mafia may be keeping fentanyl out of Italy
Oxycontin was built on the idea of turning a drug (MS Contin) for the terminally ill (too small a market) to a lifelong dependency for as many people as possible, and each taking as many milligrams as possible.
oefrha··on Sourcehut account takeover via build logs (XSS in ansi2html)
OSC 8 hyperlinks are extremely useful for tables and other kinds of compact displays.
oefrha··on Rails World 2026 Opening Keynote [video]
Have you tried to negotiate a 10% pay raise because “you can move mountains with Astra or Opus 5.5”? I’d wager you’re more likely to get a “the fuck do we need you for then” than that pay raise.
oefrha··on Claude discovers a novel enzyme system with CRISPR-like repeats
Good thing that they not only hide thinking traces (except very short summaries), but will refuse to disclose how they arrived at a decision when you ask it (Opus 5.5) then. /s
oefrha··on Claude Opus 5.5
Parallax scrolling effects were very cool ~2010. By 2015 or maybe earlier it already felt like me-too design that's unoriginal and a little annoying. By 2020 everyone and their mom has it and it's super tiresome. Now it just screams slop design (among a million other signals).
oefrha··on Study: Young users (9 to 18Y) ditch Google for AI, with unknown consequences
It’s a “solved” problem. On more dubious topics, “proper articles” these days also more often than not come from AI clusters, so you might as well just read the Google one.
oefrha··on What happened to the Snowden archive
> the ~government~ implicated itself provided

FTFY. Almost one and the same here but gives more context.

oefrha··on If AI coding is lowering your code quality, you're not managing quality right
If AI coding isn’t lowering your code quality, you have a low starting point.
oefrha··on Google AI Studio fakes data deletion. VRP auto-banned me in 60s for reporting it
I want to take this seriously, but eight (slop?) rehash of the story on the blog isn’t helping with credibility. Pro tip: don’t do that, however triggered you are, it definitely doesn’t help.

I don’t use Google AI Studio so can’t verify, good luck.

oefrha··on AI-generated posters don’t have to be horrible
I’ve also seen people put a lot of effort and love into poster and stuff because that interests them (doesn’t mean they’re good at it either), then the event is utter crap because they didn’t spend much time on the actual event.
oefrha··on Microsoft exec called AI scraping 'the largest theft of labor in human history'
I fail to see how I’m “dissing AI”. I use it almost every fucking waking hour after all, both professionally and personally. I just don’t pretend it’s free/cheap (especially when you mention it in the context of “everyone only the planet”), or even more ridiculously, some charitable gift from Big (AI) Tech to the world. And if you look into my comment history I’m pretty clear I support IP free-for-all; cat’s out of the bag, just don’t talk two-faced nonsense like “distillation attacks” and I’m fine with it. And as a prolific open source contributor with popular projects, including at least one under GPL, they definitely stole from me—again, fine with it.
oefrha··on Microsoft exec called AI scraping 'the largest theft of labor in human history'
I’m paying $200/mo for non-crap versions of said “general-purpose problem-solver tool”, which is not far from the median income of “everyone on the planet with Internet connection”. And I’m told I’m already getting a huge discount by using thousands of dollars of compute by raw API pricing. That just doesn’t sound like peanuts at all.
oefrha··on A heap overflow and SSO misconfiguration to compromise OpenAI internal repos
Btw there are so many "critical" vulnerabilities in libheif I can't even tell if I have them all patched. Just awesome.

https://github.com/strukturag/libheif/security/advisories?qu...

https://ubuntu.com/security/notices/USN-8649-1

https://ubuntu.com/security/notices/USN-8683-1

https://ubuntu.com/security/notices/USN-8774-1

oefrha··on A heap overflow and SSO misconfiguration to compromise OpenAI internal repos
They did say how:

> We then placed Claude in an autonomous /goal loop against our own Discourse Cloud instance, proxied through rce.ee/ctf-forum to make it look like a CTF target as Opus refused write exploit for remote instances.

oefrha··on A heap overflow and SSO misconfiguration to compromise OpenAI internal repos
Unsandboxed ImageMagick is known for being a security nightmare even back when PHP ruled the world (not saying sandboxing is a panacea either, it just requires a different and potentially harder exploit to develop a full chain). Difference is it's easier than ever to turn vulnerabilities into full compromises. At some point we'll have to replace all parsers with something at least as safe as https://github.com/google/wuffs right? Otherwise ImageMagick and co. will just keep giving.
oefrha··on Claude Code from Source
Kudos for at least admitting upfront that it’s pure slop, I guess.
Page 1 of 34Next →