HNHacker News
TopNewBestAskShowJobs

reisse

1,945 karma · joined August 9, 2022

submissionscomments
reisse··on An agent used DNS to reach an external chatbot
The concern (I'd rather call it concern, and not surprise) is in level of persistence.

See, when you ask the model a question, you expect it to give its reasonable best to produce an answer. Like, to comb through available data and stuff, etc, etc. You don't really expect "reasonable best" meaning "look for a side channel to escape sandboxed environment, and get access to information you was not supposed to".

And the gap between that and "hack someone's devices and blackmail them until they give an answer to the question" is narrow enough for the model for researchers to be concerned.

reisse··on Measure internet censorship
Do they distinguish between "censored in transit" and "blocked by destination"?

In the last years many sites started to drop/block connections from the countries like China and Russia. It is sad to see how Internet is becoming more and more fragmented.

reisse··on After Math
The elephant in the room no one talks about yet, imo, is "should public funding of math studies be adjusted due to AI breakthroughs?"

The sports comparison is wrong here because general public never paid for the specific match results. The value was always in the show, the advertising and betting around it, the health and educational value of doing sports, etc. And the sport mostly lives on what it earns, not on public funding.

Math, on the other hand, was paid for because people and states believed progress in math might lead to meaningful improvements in other branches of science, and, in turn, in our lives. If this is better served by AI, should we keep paying for the same number of tenure positions? Should we increase their number to handle the speedup brought by AI? Or decrease because they're being replaced? Should we pay more to those using AI to do their research, or to those explaining and exploring the AI-generated results?

reisse··on LLMs are real, AI is fake
I don't know, it reads like a pure copium at this moment.

While Zitron continuously whined about the "AI bubble", and how the models were not improving, and how spectacularly it should've blown, these same people who Doctorow accuses of, quote,

"cooking their brains by locking themselves in the bathroom, holding flashlights under their chins, and saying "Aaaaaaaaaay Eyeeeeeee" until they wet themselves in terror",

unquote, kinda promised, among other things, to give everyone an APT-level big and automated hacking bazookah, and now surprise-surprise three years later they delivered exactly on that promise, and now Doctorow is victim blaming everyone around that they were unprepared for that!

But it was you who said it was all hype, smoke and mirrors, it was you who said the AI is quote,

"a product of limited utility that has been shoehorned into high-stakes applications that it is unsuited to perform",

unquote, why are you suddenly surprised everyone around was not inspired to do anything around it?

The real world software threat model was never suited for a relentless hacker-ex-machina, limited only by the token count you can throw at the task. And maybe we didn't prepare in time because no one believed in possibility of such a machine, because people like you said it was just for-profit scaremongering?

Give or take, AI evangelists gave us all a pretty wild and unbelievable set of expectations few years back. I didn't believe them back then too. But now they're steadily delivering on _some_ of them, and we should be correcting our world model to take into account _all_ of them might be true, instead of making up reasons why other predictions will certainly fail.

reisse··on C++26: Standard Library Hardening Experiments
Off-topic: oh wow the most of the Appendix part looks Claude verbatim. Not something I'd expect in a paper from Stroustrup.
reisse··on Linux 7.2
Strongly disagree. Hardware support improved by leaps and bounds last decade and a half. Namespace isolation and cgroups driven containerization. eBPF appeared and gained adoption. Async I/O (and later just everything async) converged on io_uring. Btrfs is _stable_ - some people believed it would never be possible, ever. All kinds of scheduling were iterated and iterated over.

All these things are visible across the board, both from developers and end users side.

reisse··on Cloudflare's AI Psychosis
> There was a time Cloudflare just made the internet better

There wasn't. Cloudflare is a cancer grown too big. And it was always positioned to become one, the middleman between users and the Internet.

It is already painful to browse web sometimes using the non-"standard" tools (that is, not a Chrome with Google account signed in, not an EU/US residential IP). What if tomorrow Cloudflare checks will require attested and signed browser binaries?

reisse··on The myth of Snow Leopard
The impression of XP being the best version of Windows came after at least two service packs (patch bundles / minor releases, for those unfamiliar) and the Vista shitshow. First Windows release that was good from the very beginning was 7.
reisse··on Microsoft raises Xbox prices by up to 43%
> Overall gaming is a dying business.

What? Both PC and mobile markets are growing by any reasonable metric, and consoles are propelled by stellar Switch 2 sales.

The gaming market is ripe with money, it is total failure on Microsoft side that they failed to capture any of that. Xbox is on life support, and Windows platform tax is captured by Steam, where Valve funnels it into Linux to make its own platform.

reisse··on Situational Awareness down 67% in July in AI stock rout
Nah, if they reinvested realized profit they can still be in the green overall
reisse··on Who's afraid of Chinese models?
This is not true. Both model and chat are censored; the resistance to answer some questions is baked into the weights. This is not specific to Chinese models though, Western ones are also censored, but in different topics.
reisse··on Kimi K3: Open Frontier Intelligence
What makes you think they have less resources?
reisse··on Alice is impatient
There is a branch of math dedicated to (among other things) truthfully estimating the waiting time, called queueing theory. I wonder why it wasn't mentioned in the article.
reisse··on US holds off blacklisting DeepSeek, more than 100 firms deemed security risks
They probably will, but not for US customers.
reisse··on FTX's former Anthropic stake would be worth about $75B at today's valuation
I'd argue the money spent for yachts and donations were a drop in the ocean compared to what they burned via Alameda and lack of whatsoever accounting.
reisse··on FTX's former Anthropic stake would be worth about $75B at today's valuation
> Crypto certainly isn’t doing well now.

This "not doing well" is being three times higher than at the time of FTX collapse.

reisse··on Googlebook
I see the vision here, which the top commenters (sorry, couldn't read all of them) seems to miss. This should be a moonshot bet on the next generation of user experience. People are complaining about apps, but the idea here should be to make apps irrelevant as a concept. You don't need "apps", you need data feedable to LLM and a visualization toolkit for presenting results. And maybe some tools to manually wrangle the data when precise manipulation is required.

On paper, this sounds amazing. Like "out of sci-fi books" amazing. The caveat, though? I very much doubt Google has the capacity to execute this properly. And we'll get another half-baked attempt at reskinning Chromium and/or Android.

reisse··on Local AI needs to be the norm
Nothing special?

I mean, inference engine might need to get some tweaks, to support whatever compute is available. But then, if you put a few terabytes of disk for swap, and replace RAM to bigger sticks if possible, it should work? Slowly, of course, but there is no reason it should not to.

reisse··on Local AI needs to be the norm
> They will be, and that moment is not that far off.

It's here, right now. I'm running quantized Qwen and Gemma on a decent, but three years old gaming rig (think RTX 3080 12GB and 32 GB RAM). Yes, it's slow, it has a small context window. But it can (given a proper harness) run through my trip photos and categorize them. It can OCR receipts and summarize spendings. It can answer simple questions, analyze code and even write code when little context is required. Probably I could get a half-decent autocomplete out of it, if I bother with VS Code integration. "128 GB VRAM on a MacBook Pro or a Strix Halo" is already a minimum viable setup for agentic coding, I think.

> And then we'll have the equilibrium we already have with the "classic cloud": you either self-host or pay for flexibility and speed.

Currently, it works exactly the other way. The cloud versions are orders of magnitude cheaper than self hosting, because sharing can utilize servers much more efficiently. Company can spend half a million bucks on a rig running GLM 5.1, and get data security, flexibility and lack of censorship, but oh it's so expensive compared to Anthropic per-seat plans.

reisse··on Hardening Firefox with Claude Mythos Preview
> although the real cleverness is in the testcase, which we have not made public

What is the point of keeping it private? I'd bet feeding this patch to Opus and asking to look for specific TOCTOU issue fixed by the patch will make it come up with a testcase sooner or later.

reisse··on Dirty Frag: Universal Linux LPE
No embargo exists (or could possibly exist) in the first place.

Linux is open source, so every patch fixing the security bug is immediately visible to everyone. There is no workaround to that by the very design how the kernel is developed. The "embargo" people talking about is the rather stupid notion that if people keep their mouth shut and not write "THIS IS A LPE" straight in the patch description, everyone can pretend vulnerability is not leaked until the "official" message in the mailing list is sent.

This approach might have been defensible before, but in LLM era, when people have automated pipelines feeding diffs straight from the mailing lists to SotA models asking to identify probable security issues fixed by those, it is both stupid and dangerous.

reisse··on I'm Peter Roberts, immigration attorney who does work for YC and startups. AMA
What is the current status of the DV program? What will happen with last year's quotas?

And another question: has 100k$ requirement on H1Bs make any meaningful impact on applications count (e. g. to remove the lottery)?

reisse··on Framework's new Linux laptop is selling faster than its Windows one
It depends on your legal framework. It might be seller's problem, not yours, and 20$ is a price for shifting responsibility.
reisse··on US appeals court declares 158-year-old home distilling ban unconstitutional
No one adds MeOH to homebrew. Bootlegging fake hard drinks is a completely different industry, which has zero relation to homebrewing.
reisse··on US appeals court declares 158-year-old home distilling ban unconstitutional
I'm not talking about homebrew bootlegging here. It's large-scale frauds where industrial ethanol (which often contains poisonous amounts of methanol, or _is_ methanol) is mixed with flavorants and colorants to cheaply imitate various hard drinks.
reisse··on US appeals court declares 158-year-old home distilling ban unconstitutional
Well, I live in a country with both huge distillation culture and significantly non-zero number of methanol poisonings, and they never happen from home brewing. It's really hard to homebrew/distill methanol in a quantity enough to poison you in an otherwise ethanol solution (which acts as an antidote).

It's so rare this thread is literally the first time I've heard about possibility of methanol poisoning from homebrewing.

Methanol poisonings happen from bootlegging, where someone in the chain of supply sells industrial methanol as an ethanol, because the first one is cheaper, easier to obtain and untaxed.

reisse··on AWS engineer reports PostgreSQL perf halved by Linux 7.0, fix may not be easy
Not sure it is true anymore. I've encountered few userspace breaks in io_uring, at least.
reisse··on 4Chan mocks £520k fine for UK online safety breaches
Unless AliExpress has a local entity, like they do in some countries, yes.
reisse··on US plans online portal to bypass content bans in Europe and elsewhere
Fun hypothetical question - will it be restricted to users in sanctioned locations (where it's most needed) because of, well, sanctions?
reisse··on US plans online portal to bypass content bans in Europe and elsewhere
When U.S. Govt sponsors Tor, which does expose exactly what your describe, the reaction is usually positive.
Page 1 of 13Next →