HNHacker News
TopNewBestAskShowJobs

soiax

15 karma · joined August 16, 2023

submissionscomments
soiax··on Actively exploited sandbox RCE in all Chromium versions
The title is bad, it is not sandbox escape, it is "RCE inside the sandbox", so only RCE when sandbox is disabled.
soiax··on We found a division by zero bug in FFmpeg with a vibecoded fuzzer
Why are people upvoting a unexploitable bug? How is this interesting? There are thounds of these, no one even reports them unless they are exploitable, DoS only.
soiax··on When AI Benchmarks Plateau: A Systematic Study of Benchmark Saturation
Right, but we have no clue why, and how the emergent behavior they show works.

If we would know that, there would be no need for interpretability research.

soiax··on Burger King will use AI to check if employees say 'please' and 'thank you'
They should also check for hot dog vs not hot dog
soiax··on Stargaze: SpaceX's Space Situational Awareness System
Yeah dude .. if you say it multiple times, and louder, it must be true. That would make it a nazi company, right.
soiax··on Stargaze: SpaceX's Space Situational Awareness System
There it is... the usual ELON MUSK BAD.
soiax··on AI and Startup Moats
You mentioned prompt injection, now when you talk about larger time horizons, that sounds like a AI alignment issue.

I'm sure there will be actors who don't care at all about "security", saying the positive outcomes outweight the negatives.

soiax··on AI and Startup Moats
Yeah that's false.

from: https://arcprize.org/blog/oai-o3-pub-breakthrough

"Note on "tuned": OpenAI shared they trained the o3 we tested on 75% of the Public Training set. They have not shared more details. We have not yet tested the ARC-untrained model to understand how much of the performance is due to ARC-AGI data."

soiax··on AI and Startup Moats
This sound like you assume that the first thing someone thinks about is security, when building the next big thing.

They will just build something as fast as they can. Last thing you think about is "security".

There were prompt injections in all the big models, and still are. Why would it stop distruption?

soiax··on From object transition to RCE in the Chrome renderer
You can disable it runtime, with --no-sandbox command line option.
soiax··on From object transition to RCE in the Chrome renderer
No. There is a reason the author keeps repeating "arbitrary code execution in the Chrome renderer process." Because it's there, not in the browser process.
soiax··on From object transition to RCE in the Chrome renderer
It's all renderer only RCE-s, no sandbox escape. So it doesn't work on your browser, only if you disable the sandbox.