HNHacker News
TopNewBestAskShowJobs

silver_sun

37 karma · joined October 18, 2025

submissionscomments
silver_sun··on GPT-6 Astra
It's simulating the Dunning-Kruger effect.
silver_sun··on GPT-6 Astra
GPT-8 Novo
silver_sun··on Omarchy: Any User Process Can Escalate to Root
Flatpak uses Portals to let the user grant access to different files/directories, apparently they don't have access by default: https://docs.flatpak.org/en/latest/sandbox-permissions.html

I was also unable to find any Flatpak that has access to the home directory when installed, you may well be right but I couldn't find any. I used Flatseal to verify the permissions: https://flathub.org/en/apps/com.github.tchx84.Flatseal

I'm also of the opinion that we generally shouldn't use software that we don't absolutely trust. That has kept my .bashrc (and other files) safe so far.

silver_sun··on Omarchy: Any User Process Can Escalate to Root
I think that depends on your point of view. I wouldn't run a program on my computer unless I were sure that it's not malicious. And if you mean that some program I already trust could be exploited, that's true even for the Linux kernel or any sandbox / security solution you would come up with. I'm not denying that there's always a risk, but there's nothing good in running arbitrary code that you can't trust.
silver_sun··on Omarchy: Any User Process Can Escalate to Root
But if an attacker can put arbitrary code into your .bashrc, you are already executing arbitrary malicious code.
silver_sun··on Omarchy: Any User Process Can Escalate to Root
If you're running a malicious user process with write (or read) access to your files, you are arguably already compromised.
silver_sun··on FDA approves first in class targeted therapy for metastatic pancreatic cancer
Revolution Medicines has an Expanded access program: https://www.revmed.com/expanded-access-policy/

I would suggest you have your physician submit a Expanded access request immediately, because the same page says that they will close this program after FDA approval as they transition to commercial use, but the timeline for that is unclear.

silver_sun··on MS Paint and Photos inivisibly watermark even locally generated output with GUID
Some problems with this particular system:

If the TPM signs the original image taken by the camera, then even the slightest image processing on another device would invalidate the signature. Routine changes like cropping, scaling, converting between image formats / quality levels, or applying image filters would invalidate the signature.

An adversary can manipulate the date/time settings on the camera and forge evidence to frame someone. "This cryptographically signed photo, with timestamp, proves that you were here at this time!"

And camera sensors can get damaged and need replacement. But if replacement of the TPM-and-sensor chip is allowed, then you can just as well replace it with a sensor from another camera. In which case a signature from a specific TPM+sensor doesn't prove that a specific camera took the photo, at best it might be evidence that a specific camera model took the photo.

If the manufacturer will happily ship a replacement TPM+sensor for a specific camera, someone can fraudulently claim that their sensor is broken and be given a new TPM+sensor for the same camera. And there will now be multiple TPM+sensors in existence that have the same key. Since this module can be switched between cameras, there could be multiple cameras that signed a given picture.

To ship (identical) replacement TPMs, the manufacturer would also need to know the private keys of all the cameras, so the manufacturer could forge arbitrary signatures at will.

Finally maybe the manufacturer doesn't want to deal with the above problems and decides that repairing the camera's TPM is not allowed after all, or that only the manufacturer is allowed to repair a camera, but then they may be in violation of right-to-repair laws in several jurisdictions.

silver_sun··on Aaron Swartz was prosecuted for scraping, while Meta does it without consequence
There's some common-sense understanding of this situation that I'm not sure you're wilfully overlooking or oblivious to. The claim is that it's unjust to blatantly exploit a system that was intended to fund/sustain you, for profit. It's not necessarily illegal behavior since "open access" was not in the terms, but how can it possibly be morally defensible that they have managed to find a way to legally subvert/trick the system for their own benefit? An overly pedantic view of the situation isn't helpful.
silver_sun··on I spent $266 and four AI models to own my tablet. GLM-5.3 finished it in a day
I'm not a lawyer. But I think if your "binary patch" is a series of instructions to write specific code to specific locations in a binary file, and the patch itself doesn't include any of the code present in the original binary, making/distributing a binary patch can't possibly be copyright infringement.

It's normal in the videogame ROM hacking community to distribute this kind of binary patches (known as IPS patches) so as to avoid legal trouble, since the binary patch is useless if the user doesn't have access to the original videogame ROM. Distributing the ROM or even its patched version would be illegal, but a patch of the kind I mentioned is fine.

silver_sun··on Aaron Swartz was prosecuted for scraping, while Meta does it without consequence
The difference here is that the scientific papers he downloaded weren't freely available to the public, like those scraped webpages would be. Corporate scrapers have been sued[0] in the past for scraping pages from behind a login page / paywall.

[0]: https://en.wikipedia.org/wiki/HiQ_Labs_v._LinkedIn

silver_sun··on Aaron Swartz was prosecuted for scraping, while Meta does it without consequence
>The public might donate food to the poor. That doesn't give them the right to go into their house and rummage through their fridge.

I think a better analogy for this situation is: The public donates food, then the recipient, after being fed, sells access to (infinite cheaply replicable copies of) said food for a profit. The public in this case just wants to have said food.

silver_sun··on Cultivating a state of mind where new ideas are born (2023)
Why would you want to create things for people to use if you regard them as "useless"? This attitude is so alien and repulsive to me.
silver_sun··on Mistral Patent for “Code implemented tool calls”
Are you thinking of TDCommons? https://www.tdcommons.org/
silver_sun··on Ten advances in mathematics and theoretical computer science
It's not even predictable like dynamite. Sometimes it can blast through a mountain, impressively, the problem is you can't predict which mountain it works on. And other times it can't even make a dent in a molehill, which is perplexing given what it was capable of earlier. Can we even call it dynamite?
silver_sun··on AI's top startups are barely publishing their research
Looks like that was published in 1998, but that's also the year they submitted their patent application for PageRank. So you couldn't use it because they didn't want to risk losing their budding search business to, say, Microsoft.

In later years Google generally published the details of a system after they moved to the next one, to stay ahead of their competition, or if they didn't see it as important to their business (most infamously the Transformer language model). It was still generous of them to share their research at all though, and this allowed their scientists to talk publicly about their research which is a huge plus.

silver_sun··on The new rules of context engineering for Claude 5 generation models
As long as LLMs need their users to "engineer" prompts for them to actually work well, clearly LLM-driven development is not exactly equivalent to back-and-forth conversation with a human programmer. In principle if what you say were true, software developers already wouldn't be needed anymore, because coding agents could talk to the customer directly and give rapid feedback to clear up even the smallest details. It should be uniformly better and cheaper than talking to a human developer, but that's not the world we currently live in. Currently we live in a world where LLMs that can disprove conjectures and find zero-days still need context engineering. We shouldn't anthropomorphise and assume that they will be exactly the same as us, they are undoubtedly useful but they need careful steering by specialists who understand how LLMs interpret prompts.
silver_sun··on Infinities, impossibilities, and the man in the white linen suit
I think this comparison is interesting because it shows the difference between theory & practice, but it's a little inaccurate. The halting problem being undecidable just implies there is no single universal algorithm that can tell you whether any program at all will halt. In practice we are working in specific domains and can come up with heuristics which are "good enough" for a specific codebase / module, like the timeouts you mention. So the halting problem can be solved for some subsets of programs but not all of them, and the computer scientist would hopefully have realized this instead of treating the codebase generically as "any program".
silver_sun··on Infinities, impossibilities, and the man in the white linen suit
Not infinite memory, a Turing machine only requires "unbounded" memory, which is a way of saying that it will not run out of memory while running its program with the given input. In other words it just needs to have enough memory to run the program with whatever inputs it was given, which is much less than infinity. And this situation is quite common in the real world -- the programs I use on a daily basis have all the memory / RAM they need to do what I want (almost by definition). So in practice I might as well view them as Turing machines.
silver_sun··on Google details new 24-hour process to sideload unverified Android apps
I'll give you that, enforcement of the rules can sometimes fail. But scamming & malware is a global industry, definitely not limited to state-funded actors in those two countries (which is what I think you're referring to).
silver_sun··on Google details new 24-hour process to sideload unverified Android apps
I don't think it does because of the workaround I mentioned upthread.
silver_sun··on Google details new 24-hour process to sideload unverified Android apps
The perfect is the enemy of the good.
silver_sun··on Google details new 24-hour process to sideload unverified Android apps
Isn't app data, photos etc. usually synced with the Google account? Besides, Google claims that the scammers are using social engineering to create a feeling of panic and urgency, so I think the victim would be willing to reset and log in to the accounts again in such a frame of mind.
silver_sun··on Google details new 24-hour process to sideload unverified Android apps
Users don't have to wait 24 hours because Google Play store already has registered developers. Scammers can be held liable when Google knows who the developer of the malicious app is.
silver_sun··on Google details new 24-hour process to sideload unverified Android apps
> Allow a toggle with no waiting period during initial device setup

I like this idea in principle but I think it could become a workaround that the same malicious entities would be willing to exploit, by just coercing their victims to "reset" their phones to access that toggle.

silver_sun··on Google details new 24-hour process to sideload unverified Android apps
Well maybe nothing ultimately changes. Maybe we end up in a world where Android users have to wait 24 hours to change a setting so that their devices will install any apps they want, from then on with no further delays. But this seems to me like a relatively low cost for a potentially huge benefit for victims.
silver_sun··on Google details new 24-hour process to sideload unverified Android apps
I don't think it's fair to extend the analogy to what amounts to censorship of websites since that's not the system they're proposing. Also isn't the owner of a website already identifying themselves when they register their domain name and/or rent a server? I think this is not the same as downloading an app by an unknown developer.

From the article I understood this to be a one-time delay, as opposed to having to go through the same waiting process for every single "unlicensed" app I want to install (which I would not accept). I'm just waiting 24 hours once to permanently change my device into a mode where I can install any app I like without any restrictions/delays whatsoever.

silver_sun··on Google details new 24-hour process to sideload unverified Android apps
It's a little inconvenient for someone setting up a new phone to have to wait a full day to install unregistered apps. But while I can't speak for others, it's a price I'm personally willing to pay to make the types of scams they mention much less effective. The perfect is the enemy of the good.
silver_sun··on Gemini 3 Deep Think
Google has a library of millions of scanned books from their Google Books project that started in 2004. I think we have reason to believe that there are more than a few books about effectively playing different traditional card games in there, and that an LLM trained with that dataset could generalize to understand how to play Balatro from a text description.

Nonetheless I still think it's impressive that we have LLMs that can just do this now.

silver_sun··on We tasked Opus 4.6 using agent teams to build a C Compiler
They said it builds Linux 6.9, maybe you are trying to compile a newer version there?
Page 1 of 2Next →