HNHacker News
TopNewBestAskShowJobs

rhodey

114 karma · joined March 29, 2013

Javascript & crypto & sometimes rust

https://rhodey.org

submissionscomments
rhodey··on ChatGPT outage – Resolved
I am a paying chatgpt and codex user and I am logged in on multiple devices and suddenly https://chatgpt.com/ has started returning a raw 404 status page with no HTML for me in the browsers on all devices. When I open an incognito tab the website loads fine with no user logged in. Codex in VS code also has issues now:

> unexpected status 404 Not Found: Unknown error, url: https://chatgpt.com/backend-api/codex/responses, cf-ray: ...

Glad to see this thread I thought my account may need some special fix

rhodey··on IPFS Maintainers Winding Down
I think something like IPFS is definitely needed. There is nothing stopping you from distributing a webapp on bittorrent but you'll also need to add a README for instructions on how to run the webapp on localhost so a browser can render it. So thats not something that any non-technical user wants to do.
rhodey··on IPFS Maintainers Winding Down
This is really unfortunate. When cloudflare dropped IPFS you could say this next step was sort of already on the way. I may be biased but I think when IPFS decided to put so much time into "IPNS" in order to support non-static webapps years ago what they came up with did not fit the need. And without webapps on IPFS things were going nowhere.

A year or so ago I wrote IPFS-boot which allows serving webapps on IPFS while providing also an update path and without breaking content hashing:

https://github.com/rhodey/IPFS-boot

But now if you want to serve a secure webapp and not use IPFS IMO the only option you have is to tell users to install Tailscale and to host the webapp themselves and then to install Tailscale on all devices.

rhodey··on Responding to the next frontier of critical cyber capabilities
IMO this is the right move.

OpenAI messed up and they are saying they will pause so they can do better.

They are not saying that other orgs who may already be doing better should pause.

rhodey··on Show HN: Hecate – Call an AI from Signal
Hi! thanks for the feedback!

I think you are right. I thought "Call" would clearly get the idea of voice across at least, but it can be confused with function call, or simply to invoke.

I dont have the ability to change the title but if someone else wants to:

"Video and Voice Call an AI from Signal"

Else maybe I will submit it again in a few days.

Thanks

rhodey··on A better streams API is possible for JavaScript
the pull-stream module and its ecosystem is relevant here

the idea is basically just use functions. no classes and very little statefulness

https://www.npmjs.com/package/pull-stream

rhodey··on How an inference provider can prove they're not serving a quantized model
Attestation always involves a "document" or a "quote" (two names for basically a byte buffer) and a signature from someone. Intel SGX & TDX => signature from intel. AMD SEV => signature from amd. AWS Nitro Enclaves => signature from aws.

Clients who want to talk to a service which has attestation send a nonce, and get back a doc with the nonce in it, and the clients have somewhere in them a hard coded certificate from Intel, AMD, AWS and they check that the doc has a good sig.

rhodey··on How an inference provider can prove they're not serving a quantized model
In my opinion this is very well written

Two comments so far suggesting otherwise and I guess idk what their deal is

Attestation is taking off

rhodey··on The path to ubiquitous AI (17k tokens/sec)
I wanted to try the demo so I found the link

> Write me 10 sentences about your favorite Subway sandwich

Click button

Instant! It was so fast I started laughing. This kind of speed will really, really change things

rhodey··on Running NanoClaw in a Docker Shell Sandbox
At my time of reading it is not at all clear to me how the "sandbox network proxy" knows what value to inject in place of the string "proxy-managed"

> Prerequisites > An Anthropic API key in an env variable

I am willing to accept that the steps in the tutorial may work... but if it does work it seems like there has to be some implicit knowledge about common Anthropic API key env var names or something like this

I wanna say for something which is 100% a security product I prefer explicit versus implicit / magically

rhodey··on I'm returning my Framework 16
I own 2 framework 13 laptops at this time and repairability aside I am also just happy to support a new PC hardware co.
rhodey··on How exchanges turn order books into distributed logs
Always fun to read about HFT. If anyone wants to learn about the Order Book data structure you can find it in JS here:

https://github.com/rhodey/limit-order-book

https://www.npmjs.com/package/limit-order-book

rhodey··on Immutable releases are now generally available on GitHub
I am seeing some docs now that suggest

> runs-on: [self-hosted, ...]

Must be added to run.yml to use custom / private action runners

I did not find these docs last time I looked and so my feature request may be already fulfilled

If anyone wants to chime in to say that `runs-on` can be relied on or not I would be grateful

rhodey··on Immutable releases are now generally available on GitHub
I am glad for this feature

If I have anyone's attention there is something related I would like to see

Please add a small thing which users can look for on the public: repo/actions page

This small thing should let users know the action was run by github like is default and not run on a custom / private action runner

The private action runner feature makes sense but many projects tell users to look to the github action history to trust that tests A, B, C passed. If the github action ran on a private action runner then you really cannot trust that what is in e.g. run.yml actually ran

The attestation feature can be used to prove that an action was run by github and not by private / custom but users need to install the github cli to validate attestations and this is a heavy ask when I think an addition icon on repo/actions page or a diff icon color will do better

rhodey··on New attacks are diluting secure enclave defenses from Nvidia, AMD, and Intel
Because AWS does not sell the Nitro TEE hardware

And so there is no case where you find a Nitro TEE online and the owner is not AWS

And it is practically impossible to break into AWS and perform this attack

The trust model of TEE is always: you trust the manufacturer

Intel and AMD broke this because now they say: you also trust where the TEE is installed

AWS = you trust the manufacturer = full story

rhodey··on New attacks are diluting secure enclave defenses from Nvidia, AMD, and Intel
Amazon Nitro Enclaves not effected

IMO Amazon is the obvious choice for TEE because they make billions selling isolated compute

If you built a product on Intel or AMD and need to pivot do take a look at AWS Nitro Enclaves

I built up a small stack for Nitro: https://lock.host/ has all the links

MIT everything, dev-first focus

AWS will tell you to use AWS KMS to manage enclave keys

AWS KMS is ok if you are ok with AWS root account being able to get to keys

If you want to lock your TEE keys so even root cannot access I have something i the works for this

Write to: hello@lock.host if you want to discuss

rhodey··on Ask HN: Abandoned/dead projects you think died before their time and why?
choojs

All of the upside and none of the downside of react

No JSX and no compiler, all native js

The main dev is paid by microsoft to do oss rust nowadays

I use choo for my personal projects and have used it twice professionally

https://github.com/choojs/choo#example

The example is like 25 lines and introduces all the concepts

Less moving parts than svelte

rhodey··on Battering RAM – Low-cost interposer attacks on confidential computing
I hope people dont give up on TEE, see AWS Nitro

The AWS business is built on isolating compute so IMO AWS are the best choice

I've built up a stack for doing AWS Nitro dev

https://lock.host/

https://github.com/rhodey/lock.host

With Intel and AMD you need the attestation flow to prove not only that you are using the tech but you need to attest to who is hosting the CPU

With Amazon Nitro always Amazon is hosting the CPU

rhodey··on Show HN: Bizcardz.ai – Custom metal business cards
The site gives you a .zip to download with your design

Inside the .zip is a README.txt and Elecrow.png

If the user selected "silver" the readme and image shows to select HASL lead free

:)

rhodey··on Show HN: Bizcardz.ai – Custom metal business cards
> The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software
rhodey··on Show HN: Bizcardz.ai – Custom metal business cards
If I published using any non-commercial license whatsoever there would be disagreements so here we are all the same
rhodey··on Show HN: Bizcardz.ai – Custom metal business cards
This is simple I wrote a license The license says there are two licenses If you are non-commercial you get MIT If you are commercial you email for terms

There is nowhere a claim that this is MIT

rhodey··on Show HN: Bizcardz.ai – Custom metal business cards
What the license allows for is very clear

I publish many things without dual licensing and yet your kind will not be satisfied

rhodey··on Show HN: Bizcardz.ai – Custom metal business cards
Though you may wish the license was different I find it hard to believe you have no idea what the license allows for

This can be found online as "dual licensing"

rhodey··on Show HN: Bizcardz.ai – Custom metal business cards
The FAQ page is linked to from the home page

https://bizcardz.ai/faq

On the FAQ page there are links to images of the end result / physical

rhodey··on Ask HN: Is it time to fork HN into AI/LLM and "Everything else/other?"
I dont think its the right idea long-term

If it went thru that this changed I would not be opposed tho I would read both

rhodey··on Mario Kart designers had to rethink everything to make it open world
First thought is maybe something like Kirby Air Ride for GameCube
rhodey··on TLS certificate lifetimes will officially reduce to 47 days
After EFF Lets Encrypt made the change to disable reminder emails I decided I would be moving my personal blog from my VPS to AWS specifically. I just today made the time to make the move and 10 minutes after I find this.

I could have probably done more with Lets Encrypt automation to stay with my old VPS but given that all my professional work is with AWS its really less mental work to drop my old VPS.

Times they are a changing

rhodey··on AI Ching PDF
I set about to author a new adaption of the I Ching with assistance from GPT-J.
rhodey··on Ask HN: Who wants to be hired? (July 2022)
Hey all, good afternoon here from the East Coast. I am a 11 year plus full stack software engineer looking for new opportunities. I invite all to check out my small blog and my GitHub as I am rather proud of all my documentation there. Some things notable about myself I was basically a founding engineer with Signal Foundation and myself came up with the name change "TextSecure" to "Signal". Also as far as I am aware I had the first OSS implementation of a limit order book online and my Ethereum exploit write-up is IMO pretty cool.

Location: Rhode Island

Remote: Local or Remote

Willing to relocate: No relocation

Technologies: Javascript, React, Java, Rust, Docker, Linux, Git

Resume/CV: https://rhodey.org/assets/resume.pdf

GitHub: https://github.com/rhodey

Email: mike@rhodey.org

Page 1 of 2Next →