HNHacker News
TopNewBestAskShowJobs

rfoo

2,493 karma · joined February 24, 2017

about
submissionscomments
rfoo··on Z.ai confirms Ox Alpha is a new GLM-series model and will release its weights
lol don't shout out the obvious
rfoo··on Stealing Reasoning Traces from Proprietary LLM APIs
Let's face it. Chinese labs made some of the biggest advancements. AND training on Claude (or GPT) output IS unreasonably effective. The two sentences are true at the same time.
rfoo··on TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
The issue here is there is NO single system API for looking up user account entries on Linux.

It's implemented in libc. So you need to link to libc. Tailscale is a Go binary, and they probably prefer it to be statically-linked. glibc NSS implementation also REQUIRES you to load `.so` so you just can't emulate it in Go.

Then, "link to libc". Which libc? glibc? musl?

rfoo··on How we run Firecracker VMs inside EC2 and start browsers in less than 1s
Assuming CRIU can checkpoint and restore Chrome, and especially recent versions of Chrome, just fine, is a little bit of stretch.
rfoo··on GLM 5.2 Is Out
z.ai posted an announcement earlier that day (in GMT+8) saying that they will make GLM-5.2 available later today at 5:21pm so it can't be a coincidence.

Good troll.

rfoo··on GPT-2: Too Dangerous To Release (2019)
> Different company

Same people.

rfoo··on Anthropic is expanding to Colossus2. Will use GB200
At this scale thinking tokens don't matter anymore.

In Feb Anthropic called out three Chinese labs for "distillation attacks", but a lab missing in their post actually had most Claude generated tokens among all Chinese labs in their midtrain data :p

rfoo··on Frontier AI has broken the open CTF format
Glad to hear that as I have some fun challenge ideas that would be otherwise too tedious to solve.
rfoo··on Dear friend, you have built a Kubernetes (2024)
Easier checkpoint & restore.
rfoo··on Async Rust never left the MVP state
> work stealing executors have long been known to offer significantly lower latency with more consistent P99 than traditional threads. This has been known since forever - in the early 00s

Well, we know how to make "traditional threads" fast, with lower latency and more consistent P99 since forever^2, in the early 90s. [1]

Sure, we can't convince that Finnish guy this is worthwhile to include in THE kernel, despite similar ideas had been running in Google datacenters for idk how many years, 15 years+? But nothing stops us from doing it in the userspace, just as you said, a work stealing executor. And no, no coloring.

Stack is all you need. Just make your "coroutines" stackful. Done. All those attempts trying to be "zero-cost" and change programming model dramatically to avoid a stack, introduced much more overhead than a stack and a piece of decent context switch code.

> You can tell async is directionally kind of correct in that io_uring is the kernel’s approach

lol, it is very hard to model anything proactor like io_uring with async Rust due to its defects.

[1] https://dl.acm.org/doi/10.1145/121132.121151

rfoo··on Dear friend, you have built a Kubernetes (2024)
Another case: People who want to run workloads that are inherently incompatible with Kubernetes networking model.

For example:

* For some cursed reasons you want to make sure every single one instance of a large batch job see just one NIC in its container and they are all the same IP and you NAT to the outside world. Ingress? What ingress? This is a batch job!

* Like the previous point, except that your "batch job" somehow has multiple containers in one instance now, and they should be able to reach each other by domain.

rfoo··on DeepSeek-V4 on Day 0: From Fast Inference to Verified RL with SGLang and Miles
The problem here is both aimed for Day 0 support, both got embargoed preliminary model weights and arch, and I don't think they have access to the other sides embargoed code.
rfoo··on Assessing Claude Mythos Preview's cybersecurity capabilities
> I read about 30% and got bored.

I was lucky then :) Somehow I saw this first. And then the "somewhat reliably writing exploits for SpiderMonkey" part, and then the crypto libraries part. Finally I wonder why is there a Linux LPE mini writeup and realized it's the "automatically turn a syzkaller report to a working exploit" part.

Now that I read the first few things (meh bugs in OpenBSD, FFmpeg, FreeBSD etc) they are indeed all pretty boring!

rfoo··on Assessing Claude Mythos Preview's cybersecurity capabilities
> Mythos Preview identified a memory-corruption vulnerability in a production memory-safe VMM. This vulnerability has not been patched, so we neither name the project nor discuss details of the exploit.

Good morning Sir.

> Has anything changed here? I don't pay much attention but KASLR was considered basically useless for preventing LPE a few years ago.

No. It's still like this. Bonus point that there are always free KASLR leaks (prefetch side-channels).

But then, this thing is just.. I don't have a word for this. Just randomly read paragraphs from the post and it's like, what?

rfoo··on ARC-AGI-3
> However, if it can't figure out to render the json to a visual on its own does it really qualify as AGI? I'd still say the benchmark is doing its job here.

Can you render serialized JSON text blob to a visual with your brain only? The model can't do anything better than this - no harness means no tool at all, no way to e.g. implement a visualizer in whatever programming language and run it.

Why don't human testers receive the same JSON text blob and no visualizers? It's like giving human testers a harness (a playable visualizer), but deliberately cripples it for the model.

rfoo··on Super Micro Shares Plunge 25% After Co-Founder Charged in $2.5B Smuggling Plot
Mostly high end lithography.

They can copy it. And no, the software moat is not there if someone choose the blatant copy route. They just can't build it in the scale they want yet.

> what if they just use 12nm and create GPUs with much bigger size but comparable performance

Physics do not work this way :/

rfoo··on Cursor Composer 2 is just Kimi K2.5 with RL
TBH they really shouldn't have posted such a tweet in the first place, just sit back and watch their license enforced by the Internet.

I had the question "how do you even enforce this weird license term" back then, I guess I know the answer now.

rfoo··on Gemini 3 Deep Think
For another example, Singapore, one of the "many Asian countries" you mentioned, list "Chinese New Year" as the official name on government websites. [0] Also note that both California and New York is not located in Asia.

And don't get me started with "Lunar New Year? What Lunar New Year? Islamic Lunar New Year? Jewish Lunar New Year? CHINESE Lunar New Year?".

[0] https://www.mom.gov.sg/employment-practices/public-holidays

rfoo··on Matchlock – Secures AI agent workloads with a Linux-based sandbox
Sometimes people are too lazy to write their own agent loop and decided to run off-the-shelf coding agent (e.g. Claude Code, or Pi in case of clawdbot) in environment.
rfoo··on Deno Sandbox
I like this, but the project mentioned in the launch post

> via an outbound proxy similar to coder/httpjail

looks like AI slop ware :( I hope they didn't actually run it.

rfoo··on Z-Image: Powerful and highly efficient image generation model with 6B parameters
This is the only factor. People sometimes perceive Apple's NPU as "fast" and "amazing" which is simply false.

It's just that NVIDIA GPU sucks (relatively) at *single-user* LLM inference and it makes people feel like Apple not so bad.

rfoo··on Z-Image: Powerful and highly efficient image generation model with 6B parameters
But this is a CCP model, would it refuse to generate Xi?
rfoo··on Japan's gamble to turn island of Hokkaido into global chip hub
Okay it belongs to Taiwan, and they actually claim it, period.
rfoo··on Japan's gamble to turn island of Hokkaido into global chip hub
China maintain the view that Tibet is part of China since the establishment of PRC, and they make this very explicit. Same for their border disputes with India. China never admitted that they believe it's not theirs. Mea while China does not ever say that Japan or Korea is part of China (and it's the only reason why they keep North Korea from collapsing despite it being super annoying).

So, again, any example of China suddenly started to claim lands?

rfoo··on Gemini 3 Pro Model Card [pdf]
SWE Bench doesn't even test bugfixing / feature dev properly after you achieve roughly 70% if you don't benchmaxx it .
rfoo··on Anthropic’s paper smells like bullshit
> Do public reports like this one often go deep enough into the weeds to name names

Yes. They often include IoCs, or at the very least, the rationale behind the attribution, like "sharing infrastructure with [name of a known APT effort here]".

For example, here is a proper decade-old report from the most unpopular country right now: https://media.kasperskycontenthub.com/wp-content/uploads/sit...

It established solid technical links between the campaign they are tracking to earlier, already attributed campaigns.

So, even our enemy got this right, ten years ago, there really is no excuse for this slop.

rfoo··on Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
> Why can't the stock ROMs use these features and be more secure also?

Some of the features may hurt user experience in some way and people made different trade-off.

For example, GrapheneOS disables USB before unlock so that there's no chance that some driver codes in Linux kernel run in response to a device being plugged in, for attack surface reduction. Then, say, if you have a cracked screen, the touchscreen no longer works and you don't want to fix it, if not for this mitigation, you can use an USB-C OTG cable to connect a mouse / keyboard to the phone, unlock it and export all your data. With this mitigation the keyboard won't work so you are forced to fix the screen first just to get your data out.

rfoo··on DeepSeek OCR
If you look you'd notice that it's the same Haoran Wei behind DeepSeek-OCR and GOT-OCR2.0 :p
rfoo··on AdapTive-LeArning Speculator System (ATLAS): Faster LLM inference
I don't think it's weight being different or special inference techniques, more like they are not able to train the model to follow tool schema perfectly yet, and both Moonshot and Groq decided to use something like https://github.com/noamgat/lm-format-enforcer to make sure at least the output format is correct.
rfoo··on AdapTive-LeArning Speculator System (ATLAS): Faster LLM inference
> It's known that such tricks reduce accuracy

AFAIU, speculative decoding (and this fancier version of spec. decoding) does not reduce accuracy.

Page 1 of 34Next →