HNHacker News
TopNewBestAskShowJobs

rl3

9,708 karma · joined March 29, 2013

I am a US person.
submissionscomments
rl3··on Cell Service for the Fairly Paranoid
Baseband vulnerabilities are overhyped, imo. On proper phones (eg. pixels), their access to memory is restricted by IOMMU, ...

That just kicks the can down the road to "Why should we fully trust the IOMMU?"

Granted, it does defend against the vast majority of actors.

rl3··on Show HN: Llama 3.1 70B on a single RTX 3090 via NVMe-to-GPU bypassing the CPU
Nice. I've been looking at doing something similar, more on the order of running a 1T model with less than half the available VRAM.

One workup indicated it was theoretically possible to modify a piece of SGLang's routing layer to support JIT predict-ahead expert swaps from Gen5 NVMe storage straight into GPU memory.

I'm hoping that proves true. The setup relies on NVIDIA Dynamo, so NIXL primitives are available to support that.

Curious if anyone's tried this already.

rl3··on The political effects of X's feed algorithm
>Arguably, the initial design was a shot in the dark and they're approaching some local maxima with data-driven design trying to improve metrics that we probably all agree aren't the best for our mental health or wellbeing.

Yeah, the way I look at it is product managers and everyone above them in the reporting chain make more money for their respective companies the more they optimize short-form content delivery. Pretty much what you just said.

So, what we're left with is a hyper-optimized content pipeline over the years that's pretty rough to get away from when quite a large number of people are already accustomed and/or addicted. In other words it's really hard to close up Pandora's Box again, but fortunately not impossible.

>Nice chat, apologies if my response was off-putting. It was intended to be self-deprecating humor.

No worries, wasn't sure and didn't want to read into it wrong. Wasn't trying to be snarky on my end. Cheers.

rl3··on The political effects of X's feed algorithm
Odd reply, but OK. For what it's worth I largely agree with everything else you said.

>>The problem, to me, is deeper and is rooted in our education system and work systems that demand compliance over creativity. Algorithms serve what Users engage with, if the Users were to no longer be interested in ragebait, clickbait, focused on thoughtful content -- the algorithms would adapt.

Technically that's true. Thing is, the UI/UX isn't built for long-form content. The platform, interface and algorithm when taken as a whole represent more of a dopamine delivery system heavily biased towards short-form content.

That dynamic in turn ends up being deleterious to cognition to the point it ends up fighting any external factors that which could change user behavior for the better.

In other words the algorithm is part of a larger format, and that format is arguably the real drag. Of course, the algorithm being properly transparent and accountable to its users would certainly help.

rl3··on Show HN: Strava for Claude Code
>... and climb the token usage leaderboard!

Does the #1 spot confer some type of Mad Max-esque villain role?

Like you've contributed to the depletion of clean water so hard that you're put in charge of controlling the supply of Mother's Milk.

Ostensibly also given a custom desert rig with massively oversized tires, and a posse of devotees to ride with, shiny and chrome.

rl3··on The political effects of X's feed algorithm
>Any comment that challenges mainstream science ...

Stupid mainstream science.

>... and leftist politics ...

>... nor do they see that their views are political in nature.

You don't say. Personally, I respect comments that prove their own claims.

rl3··on The political effects of X's feed algorithm
>This community, in large part, is an exception where many members pride themselves on intellectually challenging material.

That's not the norm. We're not the norm.

I recommend against putting HN on a pedestal. It just leads to disappointment.

rl3··on Show HN: Multimodal perception system for real-time conversation
HR: 1187 at Hunterwasser.

Candidate: That's the hotel.

HR: What?

Candidate: Where I live.

HR: Nice place?

Candidate: Yeah, sure. I guess. Is that part of the test?

HR: No. Just warming you up, that's all.

rl3··on Eight more months of agents
To be fair that still feels like an eternity somehow.

Perhaps AI time is the inverse of Valve time.

rl3··on Ask HN: Is Connecting via SSH Risky?
>No, they are not. Doesn’t matter how many LoC; it only take 1 LoC to introduce a vulnerability.

So according to you, the concept of attack surface doesn't exist. A 100MB binary is equivalent in risk to a 1KB binary. Got it.

If both are highly-audited, their risk is equal despite their size and protocol complexity. Got it.

>...its false to state that one piece of software has a “principle risk” of vulnerabilities that another piece does not.

That's like the third or fourth time you've scare-quoted the word principle. You're aware that principle and principal are two different words with different meanings?

The word I used, principal, in that context means the foremost or primary risk.

Anyways, I'm just telling you how major corporations think about it. Their underlying rationale is exactly what I've explained thus far, and hence why it's best practice.

Keep shooting the messenger I guess.

rl3··on LLMs as the new high level language
It's not a complete agentic setup until your chain of command goes at least nine levels deep.*

I want my C-suite and V-suite LLMs to feel like they earned their positions through hard work, values, and commitment to their company.

* = (Not to be confused with a famous poem by Dante Alighieri)

rl3··on OpenCiv3: Open-source, cross-platform reimagining of Civilization III
Yeah, I just think it's cool when they achieve drop-in compatibility.
rl3··on OpenCiv3: Open-source, cross-platform reimagining of Civilization III
It's really cool to see projects like this designed for dropping in assets from the proprietary version. The separation in the first place is unfortunate, but at least the capability exists.

Civ III in my opinion had some of the best art of the entire series. The 3D feeling of the successor games are kind of off-putting by comparison.

rl3··on Ask HN: Is Connecting via SSH Risky?
Yes, the two are very different in that regard.

WireGuard is 4k LoC and is very intentional about its choice of using a single, static crypto implementation to drastically reduce its complexity. Technically speaking, it has a lower attack surface for that reason.

That said, I've been on your side of the argument before, and practically speaking you can expose OpenSSH on the public internet with a proper key setup and almost certainly nothing will happen because it's a highly-audited, proven piece of software. Even though it's technically very complex.

But, that still doesn't mean it isn't best practice to avoid exposing it to the public internet. Especially when you can put things in front of it (such as WireGuard) that have a much lower technical complexity, and thus a reduced attack surface.

rl3··on Ask HN: Is Connecting via SSH Risky?
Your question was this:

>So what’s the difference in risk of ssh software vulns and other software vulns?

I proceeded to explain how large companies think about the issue and what their rationale is for not exposing SSH endpoints to the public internet. On the technical side, I compared SSH to WireGuard.

For that comparison, the chattiness of their respective protocols was directly relevant.

Likewise complexity: between two highly-audited pieces of software, the silent one that's vastly simpler tends to win from a security perspective.

All of those points seem highly relevant to your question.

>... but thats not going to make you correct in the original question.

If you can elucidate what I said that was incorrect, I'm all ears.

rl3··on Ask HN: Is Connecting via SSH Risky?
>That is such consultant distraction-speak.

Or how large companies actually think about this risk in the real world. Expose SSH ports to the public internet willy-nilly and count the seconds until their ops and security teams come knocking wondering what the heck. YMMV of course, but that's generally how it goes.

Are critical SSH vulns few and far between, as far as anyone knows? Yes.

Do large companies want to protect against APT-style threats with nation-state level resources? Yep.

Does seeing hundreds if not thousands of failed login attempts a day directly on their infrastructure maybe worry some people, for that reason? Yup.

You call it consultant distraction speak, I call it educating you about what Wireguard actually is, because in your original reply you suggested it was password-based.

>Further, they serve two different purposes so its comparing Apples to oranges in the first place.

Not when both can be used to protect authentication flows.

One is chatty and handshakes with unauthenticated requests, also yielding a server version number. The other simply doesn't reply and stays silent.

>Simple software can have plenty vulns, and complex software can be well tested.

In this case, both are among some of the most highly audited pieces of software on the planet.

rl3··on Ask HN: Is Connecting via SSH Risky?
Good defense is layered.

For vulnerabilities, complexity usually equals surface area. WireGuard was created with simplicity in mind.

>So, the alternatives to ssh you suggest are all reliant on passwords but ssh, in the case, is based on secure keys and no passwords.

WireGuard is key-based. I highly suggest reading its whitepaper:

https://www.wireguard.com/papers/wireguard.pdf

rl3··on ICE seeks industry input on ad tech location data for investigative use
>...I quit a job over similar concerns, knowing it would lead to a >70% decrease in comp. Without a significant nest egg or wealth, whether personal or through family.

Hey, thanks for doing the right thing.

rl3··on Sam Altman Responds to Anthropic Ad Campaign
>One authoritarian company won't get us there on their own, to say nothing of the other obvious risks. It is a dark path.

It warms my heart to hear that Sam is against authoritarianism. Hopefully he doesn't hang out with anyone that supports that kind of thing.

https://www.wsj.com/tech/ai/the-real-story-behind-sam-altman...

rl3··on Ask HN: Is Connecting via SSH Risky?
Best practices usually call for not exposing the SSH endpoints to the public internet. The principal risk is vulnerabilities in the underlying SSH server implementation. Historically, critical flaws that can compromise you are few and far between. However, these days AI is already starting to become adept at reverse engineering.

If you must, you'd typically use a bastion host that's configured just for the purpose of handing inbound SSH connections, and is locked down to a maximal degree. It then routes SSH traffic to your other machines internally.

I'd argue that model is outdated though, and the prevailing preference is putting SSH behind the firewall on internal networks. Think Wireguard, Tailscale, service meshes, and so on.

With AWS, restricting SSH ports via security groups to just your IP is simple and goes a long way.

rl3··on OpenClaw is what Apple intelligence should have been
It seems to be a common place of residence lately.
rl3··on OpenClaw is what Apple intelligence should have been
>File taxes?

Sure why not, what could go wrong?

"Siri, find me a good tax lawyer."

"Your honor, my client's AI agent had no intent to willfully evade anything."

rl3··on New York’s budget bill would require “blocking technology” on all 3D printers
The most unrealistic part here is that you're assuming they can even find their desired firmware manager on the org chart.

Moreover, most executives don't require blackmail; they tend to go along to get along.

rl3··on New York’s budget bill would require “blocking technology” on all 3D printers
One of the more notable examples:

https://en.wikipedia.org/wiki/Joseph_Nacchio

rl3··on Y Combinator will let founders receive funds in stablecoins
Where's the misleading part? What GP said is true:

https://x.com/garrytan/status/1856932483864170606

rl3··on Rust’s Standard Library on the GPU
>What would be cool is the dream that's been building for decades about parallel computing abstractions where you write what looks like normal single-threaded CPU code, but it automagically works on SIMD instructions or GPU.

I've had that same dream at various points over the years, and prior to AI my conclusion was that it was untenable barring a very large, world-class engineering team with truckloads of money.

I'm guessing a much smaller (but obviously still world-class!) team now has a shot at it, and if that is indeed what they're going for, then I could understand them perhaps being a bit coy.

It's one heck of a crazy hard problem to tackle. It really depends on what levels of abstraction are targeted, in addition to how much one cares about existing languages and supporting infra.

It's really nice to see a Rust-only shop, though.

Edit: Turns out it helps to RTFA in its entirety:

>>Our approach differs in two key ways. First, we target Rust's std directly rather than introducing a new GPU-specific API surface. This preserves source compatibility with existing Rust code and libraries. Second, we treat host mediation as an implementation detail behind std, not as a visible programming model.

In that sense, this work is less about inventing a new GPU runtime and more about extending Rust's existing abstraction boundary to span heterogeneous systems.

That last sentence is interesting in combination with this:

>>Technologies such as NVIDIA's GPUDirect Storage, GPUDirect RDMA, and ConnectX make it possible for GPUs to interact with disks and networks more directly in the datacenter.

Perhaps their modified std could enable distributed compute just by virtue of running on the GPU, so long as the GPU hardware topology supports it.

Exciting times if some of the hardware and software infra largely intended for disaggregated inference ends up as a runtime for [compiled] code originally intended for the CPU.

rl3··on Ask HN: What usually happens after a VC asks for a demo?
https://www.youtube.com/watch?v=JlwwVuSUUfc

There's also that possibility.

rl3··on The Walls Are Closing in on Tesla
Unfortunately, fully understanding GP's comment requires one having a soul. This is also known as basic empathy in some circles.
rl3··on Prediction markets are ushering in a world in which news becomes about gambling
>Scamming of gambling addicts is tragic but not detrimental to society.

It certainly is at scale.

rl3··on The Walls Are Closing in on Tesla
>Those links are all political views.

Yes, Harvard and The Lancet are just wildly political.

>Beyond the veracity of those numbers ...

In addition to being incompetent slouches.

Unfortunately, we can multiply any given figure by 0.01 and still get something that amounts to mass murder.

>... it is a political decision whether or not the US should be spending $150B on foreigners or Americans.

A proper political decision wouldn't have involved an abrupt rug pull on a bipartisan program that's been operating for the better part of a century.

There's this thing called continuity that's usually taken very seriously. Especially when hundreds of thousands if not millions of lives are hanging in the balance.

← PreviousPage 4 of 34Next →