HNHacker News
TopNewBestAskShowJobs

someplaceguy

595 karma · joined June 27, 2023

submissionscomments
someplaceguy··on XZ Backdoor: Times, damned times, and scams
No problem, all of you are welcome! Very enjoyable article.
someplaceguy··on XZ Backdoor: Times, damned times, and scams
> What is this syntax? I know s/a/b/ for sed substitution but not such a thing starting with c

It's the syntax for sed substitution for someone who mistypes, is dyslexic or does not have an excellent memory.

someplaceguy··on XZ Backdoor: Times, damned times, and scams
> Isn't 17:27:09 +0300 == 22:27:09 +0800, making the commits just about one hour apart?

Yes, and even worse:

> Even more damning, on 6 Oct 2022, we see the following: one commit at 21:53:09 +0300 followed by another at 17:00:38 +0800. This is only a difference in a matter of minutes!

No, this is a difference of almost 10 hours...

Maybe the author inadvertently switched the two analyses? Or maybe the author is just not very good with timezone math... :)

someplaceguy··on XZ backdoor: "It's RCE, not auth bypass, and gated/unreplayable."
> if you're using password auth, and you are tricked into connecting to a malicious server, that server now has your plaintext password and can impersonate you to other servers.

Why would the password be sent in plaintext instead of, say, sending a hash of the password calculated with a salt that is unique per SSH server? Or something even more cryptographically sound.

In fact, passwords in /etc/shadow already do have random salts, so why aren't these sent over to the SSH client so it can send a proper hash instead of the plaintext password?

someplaceguy··on Notes on El Salvador
Hmm... possibly a literal survivorship bias at work here? :)
someplaceguy··on JetZero: Ultra-efficient blended wing body jet
> Would seeing the empty sky above you be a good thing for passengers?

I would imagine seeing the ground above you to be much worse for passengers...

someplaceguy··on Why fuzzing over formal verification?
> It's been said that a sufficiently detailed spec already has a name: a program.

You could create a spec that would specify exactly what a program does, but generally speaking that would have no useful purpose.

For every program that does something, there are multiple ways to implement it. Often, different ways of implementing a program have different performance profiles, which is why many programs become more complex than the most naive way of implementing it.

A spec almost never specifies anything other than the simplest possible way that a program should be implemented (because when creating a spec, performance is irrelevant). This is usually way easier to make sure that it is correct than a spec that would specify exactly how a program should be implemented, including things done for performance.

Furthermore, you don't have to necessarily trust a specification. Specs can also be proven to have certain properties, i.e. they can be formally verified and proven to have absence of (perhaps certain classes of) bugs, and in some cases, can even be proved to have full correctness (yes, the spec itself, not just the program that implements it).

So I don't think it's fair to equate a program to a "sufficiently detailed spec", since most of those details are actually irrelevant (or at least, they should be, and can be proven to be) with regards to the correctness of a program.

someplaceguy··on Why fuzzing over formal verification?
> your specifications can and usually does have bugs

One cool thing about formal verification is that you can not only prove things about your code, but you can prove things about the specification itself (with some approaches, at least). This includes proving arbitrary properties, proving the presence of bugs, proving the absence of bugs and in some cases, even proving full correctness of the specification.

> I'm bullish on more sophisticated type systems [...] but not formal verification.

I don't know what kind of formal verification framework you used that left you with this conclusion, but the more sophisticated is your type system, the closer you are to doing formal verification.

someplaceguy··on The Future of the Monetary System [pdf]
> Has there been a widely accepted currency (true currency) that hasn't had military might behind it?

Yes, even today, for example, Costa Rica has no military yet they have their own currency. Its Central Bank manipulates its value by buying and selling the currency in the free market, which is what many countries do nowadays (although not always by the same mechanisms).

> Has there been a dramatic military failure that hasn't been followed by currency decline?

Yes, unless by "dramatic military failure" you mean having their economy destroyed, at which point of course the currency fails, but that's because economy destruction leads to currency failure regardless of any military defeats.

However, the better question is: has any country with a strong military ever had its currency fail without any military defeat?

And the answer is yes, plenty, which proves that having a strong military has nothing to do with having a stable currency.

Let's say your currency starts to fail (say, due to hyperinflation)... what is the government going to do with the military to prevent the collapse? Order them to intimidate the market?! That's a completely ridiculous proposition...

someplaceguy··on The Future of the Monetary System [pdf]
> money is like a legal contract recording how much abstract value you have given to "society" and how much access you have to resources

Finally, someone who understands money. As opposed to the typical "but my military!", as if no country with a strong military had ever had its currency fail...

I would only emphasize the importance of the scarcity aspect of money, which seems to be a (purposely) forgotten lesson nowadays. It reminds me of the historical importance of the Spanish Price Revolution, which with its 1.2% yearly inflation, nowadays it would be considered laughable.

someplaceguy··on Brain waves appear to wash out waste during sleep in mice
> But your brain is disconnected from your body during dreams, to keep you from flailing around

Tell that to sleepwalkers!

someplaceguy··on Brain waves appear to wash out waste during sleep in mice
> I wonder if eventually once this is more thoroughly researched there could be a way to induce constant cleaning instead of having to do it while unconscious at night?

Hopefully without having to induce those brainwaves, otherwise you might be able to do it during the day but you wouldn't exactly be conscious. But there's also the question of whether those brainwaves are doing more than just cleaning the brain.

I think some types of learning and memory formation also happen during sleep, right?

someplaceguy··on Can We Survive Technology? (1955) [pdf]
> do I really need a fight-or-flight response to trigger in the middle of a meeting? No I do not.

I see some signs that you've never been in a drug deal gone awry...

> Why do we keep promoting tall people???

They have a better (over)view of the situation.

But more seriously, there is also an argument to be made that free will is an illusion, at which point you have to wonder what "freedom" really means, if anything.

someplaceguy··on Hallucination is inevitable: An innate limitation of large language models
> It isn't designed to know things. It doesn't know what exactly it knows, where it could check before answering. It generates an output, which isn't even the same thing every time.

If an entity can predict the correct answer to a question (with a sufficiently low margin of error), then it knows the answer.

However, if the prediction contains too much uncertainty, then the entity should not act like they know the answer.

The above is valid for humans and LLMs.

So we "just" need to model and train LLMs to take uncertainty into account when generating outputs. Easy, right? :)

someplaceguy··on Hallucination is inevitable: An innate limitation of large language models
> The answer you give for the statement "What is $x" is going to be highly dependent on who is answering the question.

I assume you meant asking rather than answering?

> An LLM doesn't have the other human motivations a person does when asked questions, pretty much at this point with LLMs there are only one or two 'voices' it hears (system prompt and user messages).

Why would LLMs need any motivation besides how they are trained to be helpful and the given prompts? In my experience with ChatGPT 4, it seems to be pretty good at discerning what and how to answer based on the prompts and context alone.

> Whereas a human will commonly lie and say I don't know, it's somewhat questionable if we want LLMs intentionally lying.

Why did you jump to the conclusion that an LLM answering "I don't know" is lying?

I want LLMs to answer "I don't know" when they don't have enough information to provide a true answer. That's not lying, in fact it's the opposite, because the alternative is to hallucinate an answer. Hallucinations are the "lies" in this scenario.

> In addition human information is quite often compartmentalized to keep secrets which is currently not in vogue with LLMs as we are attempting to make oracles that know everything with them.

I'd rather have an oracle that can discriminate when it doesn't have enough information to provide a true answer and replies "I don't know" in such cases (or sometimes answer like "If I were to guess, then bla bla bla, but I'm not sure about this"), than one which always gives confident but sometimes wrong answers.

someplaceguy··on Hallucination is inevitable: An innate limitation of large language models
> Sure, and you can train LLMs to produce answers like that more often, but then users will say your model is lazy and doesn't even try, whereas if you train it to be more likely to produce something that looks like a solution more often, people will think “wow, the AI solved this problem I couldn't solve”.

Are you saying that LLMs can't learn to discriminate between which questions they should answer "I don't know" vs which questions they should try to provide an accurate answer?

Sure, there will be an error rate, but surely you can train an LLM to minimize it?

someplaceguy··on Hallucination is inevitable: An innate limitation of large language models
> their function is to produce text output which forms a plausible seeming response to the question posed

Answering "I don't know" or "I can't answer that" is a perfectly plausible response to a difficult logical problem/question. And it would not be a hallucination.

someplaceguy··on Hallucination is inevitable: An innate limitation of large language models
> because P != NP therefore LLMs will hallucinate answers to NP-complete problems.

I haven't read the paper, but that sounds like it would only be true if the definition of "hallucinating" is giving a wrong answer, but that's not how it's commonly understood.

When people refer to LLMs hallucinating, they are indeed referring to an LLM giving a wrong (and confident) answer. However, not all wrong answers are hallucinations.

An LLM could answer "I don't know" when asked whether a certain program halts and yet you wouldn't call that hallucinating. However, it sounds like the paper authors would consider "I don't know" to be a hallucinating answer, if their argument is that LLMs can't always correctly solve an NP-complete problem. But again, I haven't read the paper.

someplaceguy··on Satoshi – Sirius emails 2009-2011
Also, from what I can see, he didn't use two spaces after a period.
someplaceguy··on Satoshi – Sirius emails 2009-2011
The bitcoin whitepaper was written in OpenOffice and it also has double spaces after periods, which doesn't fit your theory.
someplaceguy··on Satoshi – Sirius emails 2009-2011
> Len Sassaman

It's not him, no double spaces in his writings.

someplaceguy··on Keep your phone number private with Signal usernames
Which is great when databases leak. Absolutely brilliant.
someplaceguy··on First satellite imagery of the Feb-13, 2024 landslide at Çöpler Mine in Turkey
Well, then I disagree.
someplaceguy··on Sora: Creating video from text
And when that happens, humans will no longer need jobs.

The problem is the transition into that new world.

someplaceguy··on BASE TTS: The largest text-to-speech model to-date
Someone should send the developers this audio recording I have of Jeff Bezos saying that he changed his mind and wants the model to be released as open-source.
someplaceguy··on Wi-Fi jamming to knock out cameras suspected in nine Minnesota burglaries
That's why my alarm company's call center number is on my contact list. I even configured it to bypass "do not disturb" mode.

Although unsolicited calls are not a problem here, fortunately.

someplaceguy··on Wi-Fi jamming to knock out cameras suspected in nine Minnesota burglaries
> At the end of the day its security theater. Having a video of the crime won’t prevent it or even lead to solving it most of the time.

I know of at least 2 countries where police will be immediately dispatched to a robbery in progress if a person is caught on camera by the alarm system and the owner confirms it's a robbery (e.g. on a phone call). By law, police won't be dispatched unless a person is caught on video, due to false alarms.

I know this because that's what happened when my home was robbed and I was out of town. Fortunately, since the police response was quick the thief didn't have enough time to take anything (!), as he must have been in and out in 2 minutes at most.

It also helped that there was no jewelry or cash inside the house, of course.

someplaceguy··on Tesla Cybertruck owners who drove 10k miles say range is 164 to 206 miles
> Plus as you point out you don't get as much regenerative breaking

Regenerative breaking is not a benefit compared to steady driving, it's a waste of energy due to the second law of thermodynamics.

It's only a benefit when you compare it to non-regenerative breaking.

someplaceguy··on The unending quest to build a better chicken
Yup, as someone (who I don't remember) famously said: "if you want to kill the most animals, be a vegan".

Edit: source (45 seconds): https://www.youtube.com/watch?v=fvFixaZdvCg

someplaceguy··on The best way to get unstuck
ChatGPT 4 is vastly superior to ChatGPT 3.5 in my experience, although it still fails at logic sometimes.
← PreviousPage 3 of 12Next →