HNHacker News
TopNewBestAskShowJobs

penagwin

2,812 karma · joined January 6, 2016

[ my public key: https://keybase.io/penagwin; my proof: https://keybase.io/penagwin/sigs/bhcyDKI7gf-jC0q0KWEg0jl9qdejoftHLWUddp5tnmM ]
submissionscomments
penagwin··on Claude Opus 5.5
I assume it’s largely a side effect from the final RL in post training?

That’s the step that causes the most significant gains in agentic performance.

But the RL doesn’t care about anything except maximizing the score, so if you only score based on coding benchmarks, anything can happen to the writing style (as long as it doesn’t hurt the coding performance).

That’s why it often gets worse on models that simply had more RL post training from the same base.

penagwin··on AMD acquires Taalas to boost inference performance by etching models in silicon
Reasoning models are the same speed. They’re just post trained with RL to do CoT inside tags like <thinking></thinking> before a tag like <response></response>

There’s no difference in the inference implementation, parameter count, or speed.

penagwin··on Stealth bomber in flight on Google Maps
You can find a list of satellites here: https://www.ucsusa.org/resources/satellite-database

According to the image on Google maps it was taken by Maxar. Maxar appears to have a few satellites, looks like 5 in geostationary orbit (~35,700km), 3 at about 400km and 1 at about 500km.

penagwin··on Hacker steals government ID database for Argentina's entire population
Yes, as well as applying for jobs (or at minimum when hired), renting an apartment, and lots of financial things including any type of KYC crypto exchange or investment accounts. I've also had utility companies ask for it.

These are in no way secret, I have no idea how people are okay with this. You can easily social engineer so many critical services if you know somebody's SSN.

penagwin··on Antiviral compound blocks SARS-CoV-2 from entering cells
> PNAS October 26, 2021 118 (43) e2108728118; https://doi.org/10.1073/pnas.2108728118

I'm curious how was this published October 26, 2021? (Currently Oct 15)

penagwin··on Mobile LTE Coverage Map
Apparently 3G is being phased out by AT&T (and I think most other providers have already left 3G) in the US.

Which sucks because I can get a 3G module for my iot projects for 5$ and I think 4G modules start at 50$?

Are we just at the mercy of 4G now for services that need large coverage but low throughput? I know 5G technically has a spec for IOT type stuff but I haven't seen anything about it, and I haven't seen modules for it.

penagwin··on Incident Response to September 20th 2021
To me it's fair to say it's not a likely scenerio, it's just that they continously say "this would be difficult" at every step. I appreciate the breakdown, but it comes off as trying to convince you it was a near-complete impossibility. I understand it was unlikely, but it was possible, and that makes it severe either way.
penagwin··on Show HN: Errorpush – Minimalist Sentry alternative using PostgreSQL
We currently self host a version from ~2019, I haven't looked into upgrading the version but just the old version is working great.
penagwin··on Mozilla HTTP Observatory
I live in the US and have had comcast inject into http requests. I noticed because of a pop-up in csgo's menu (it loads html for their blog)
penagwin··on Jam 80 Cores, 768GB of RAM into E-ATX Case with This Tiny Board
one instance of doom compiled with wasm on electron, but only if you lower the resolution to get it to run smooth
penagwin··on Kape Technologies buys ExpressVPN for $936M
Yes! However it gets a bit complex, as they're using dns based geofencing so there's some extra steps.
penagwin··on Kape Technologies buys ExpressVPN for $936M
He is talking about government level threats, DO provides no benefit.

I'll add that rolling your own means you're the only one exiting that IP address, so if your threat model involves websites profiling you and/or alternative accounts that won't help.

penagwin··on Please stop closing forums and moving people to Discord
The user id though will burn you though. People who use something like BetterDiscord will be able to easily spot it (as well as your join date).

I'd recommend just using the browser to make an alt.

penagwin··on Kape Technologies buys ExpressVPN for $936M
Yeah it's a tricky one isn't it? On one hand many of the best security researches are ex-state employees, and many of them go from that into the private sector. On the other hand it makes it sound like they are friendly with potential adversaries.
penagwin··on Stripe banned us for payment disputes but we never had a single dispute
I don't think crypto would solve this particular issue. Stripe needs the ability to back out of moving money, so there's several settlement periods for different parts of the transaction and ways to appeal transfers retroactively.

I suspect fraudster's are able to wait out this period without detection so they can cash out. If this is the case, then even time locking smart contracts won't help, as the fraudsters just wait out the time period. At that point Stripe would have even less recourse to recover money, as retroactive transfers are not possible at that point.

I could see services such as their debit card offering being abusable too.

They also likely have to worry about things such as predatory recurring payments as those will result in chargebacks which could ultimately fall on Stripe to foot.

penagwin··on Pumpkin OS: x64 port/re-implementation of PalmOS
I'm not affiliated with this project but I'll plug https://palmdb.net

There's also the subreddit and a discord channel with a very active community of palm developers/collectors

penagwin··on Climate activist arrested after ProtonMail provided his IP address
From my understanding it depends on how naughty your current exit node has been. Most tor exits in my experience allow creation and you just need to verify another email (just use a random burner- they only block a few. Supposedly some well behaved exits require just a captcha but I've never seen it.
penagwin··on Mozilla VPN Completes Independent Security Audit by Cure53
Because like 90% of the traffic is malicious. VPNs and proxies obviously change your exit IP, and people rotate through these as they do things like spam, make accounts, credential stuff, etc. This means they're burning through the IP ranges and getting them flagged.

If you're on a VPN with a fresh ASN and IP range you won't have any issues (until people start using it for other reasons).

If you wanted to "fix it" the dirty method, there's extensions for chrome/firefox/etc that will automatically submit your captcha to a captcha solving service and it costs some tiny amount.

tldr; Mischievous basically has to go through VPNs, and they rotate through IPs getting them flagged. You can join the dark side with a captcha solving service and extension, and there's some "solutions" like privacy pass you can try.

penagwin··on FCC Temporary Waiver Permits Higher Symbol Rate Data for Hurricane Ida Traffic
I've listened to several police radios with my SDR - "old male with [medical condition] at [person's address]" isn't uncommon.

Some research - paramedics are likely covered under HIPAA (if they work for a healthcare entity that provides ambulance services), I don't believe police or the fire department would be covered.

penagwin··on Incident with GitHub Actions, API Requests, Git Operations, Issues and more
Same here!

> remote: fatal error in commit_refs

penagwin··on Show HN: Ots – share a secret via one-time URL
Myself and I'm sure many other's can't wait to try it once you have the self hosted version!
penagwin··on Ask HN: Is anyone working on an open hardware 3G/4G dongle?
Something tells me you might have a difficult time convincing say Qualcomm with just that reasoning.
penagwin··on Facebook bans researchers who were investigating Facebook ads
Ha facebook can't handle people monitoring them and collecting data eh?

Facebook just submitted this ad to me. I don't know why, they "trust" me. Dumb idiots.

penagwin··on Gitly: A light and fast GitHub/GitLab alternative written in V lang (pre-alpha)
Already beat you to it https://github.com/vlang/vinix
penagwin··on Gitly: A light and fast GitHub/GitLab alternative written in V lang (pre-alpha)
> V and it's creator get a lot of flack here on HN and the criticisms are probably warranted.

Hi fellow Penguin :D!

I'm impressed by the creator's dedication here too, but he's clearly biting off more then he can chew - he's been saying that he's making a

* Web framework * GUI framework * SQL ORM * A language that has a lot of promises - seriously checkout their list. * Github alternative * VIM alternative

This stuff is awesome as a project, but each one of these have teams of dedicated engineers sponsored by many companies to hammer out issues and make them as robust as possible. And while he certainly has working demo's of each, they're demos. There's a huge difference between a POC and a robust framework.

A half baked framework is useless sadly, I think he's spreading himself too thin while have a roadmap that looks like a programmer's christmas list.

penagwin··on Catalytic converter thefts in California
I highly doubt you could use something more injurious legally at least. Maybe pepper spray or something, but defense must be proportional (including booby traps) - you cannot for example setup a shotgun to shoot their legs (see Katko v. Britney).
penagwin··on Steam survey shows Linux marketshare hitting 1.0%
As a person who both knows how easy cheats are to make, and what anticheat entails - There's no way I'd play without it.

In CSGO for example, many players _want_ a more invasive anticheat solution, and are literally asking or even paying for it through third parties like ESEA and Faceit.

penagwin··on Google broke a conditional statement that verifies passwords on Chrome OS
It's a soft lock for sure, given it requires a software update to use you could likely consider this a soft brick too.

It's not a hard brick to your point.

penagwin··on Travel websites are down? Airbnb.com, Expedia.com
AWS and/or Akamai are having service issues - naturally both of their status pages are green.
penagwin··on Valve Steam Deck
You _must_ have server-side anticheat if you have any at all because client side can (eventually) be bypassed - however client side anticheat is better at catching subtle but low effort/obvious cheats.

Also some types of cheats such as wall hacks can only be detected client side.

Page 1 of 34Next →