HNHacker News
TopNewBestAskShowJobs

thephyber

5,689 karma · joined December 29, 2013

Interested in genetic programming, bug bounties, and automation in software. Programming iOS apps these days.
submissionscomments
thephyber··on Most data centers refusing to say how much water, electricity they use
The EU already has several hyperscaler data centers and many more colo-style data centers. Plenty of compute power exists in EU; this new generation is about purely inference capacity.

In the US, the political backlash against data centers is also about the inability of government to be transparent about these buildouts (eg. City councils signing NDAs and building commissions quietly approving development plans without community input), the inability for utilities/regulators to actually hold data center developers to promises made (usually regarding resource/ utility usage), more complaints about affordability (cost of utility bills rising), additional hate against the unlikable tech CEOs (who aren't charismatic and whom have a long list of previous violations), fear of what AI will bring (the promised white collar revolution, promises of "infinite AI immigrants" in an age where immigration has been demonized), etc.

Only a few of these are about the "factory" itself. Lots of them are about the people trying to retain some control of their communities. Some of them are about the speed of the buildout (eg. compromises in water use / plumbing and noise / pollution created by the ad hoc on site electrical generation).

The data center CEOs are starting to admit that their NDA-blitzscale strategy may have backfired because communities are pissed and the NDAs prevented anyone from making a positive case for the buildouts while the rage was boiling over.

thephyber··on Livenerf: Has Opus 5.5 been nerfed yet?
Yes. The agent allows you to switch models, so you could sidestep a bug in one model by temporarily using other models.

The /r/antigravity SubReddit is full of users who very much notice bugs with the tool/agent. We should be thankful that Claude Code is pretty stable by comparison.

thephyber··on Building a certificate authority for the whole Internet
Why does every criticism of CloudFlare ignore the fact that they mitigate the largest DDoSes in the world in an age where DDoS-for-hire cost only a few dollars per minute? Nobody could do that on the budget of a 1996 local ISP with one or 2 part-time IT techs.

CloudFlare was launched as a stupid-simple CDN, but DDoS mitigation and bot reduction are actually valuable features for many websites. Sure, CF isn't the only business in this space, but most of their rivals are large enough to be in the S&P500 / Russell 2000, so it's not like garage startups are competing for this business.

"Was meant to be"

This isn't a law of physics. This was a starry-eyed hope by techno-utopians and academics when the internet was still 100% funded by Uncle Sam. When the internet moved out of its parents' basement, it had to grow up and get a job to pay the bills. Some people are fine with a SquareSpace webpage instead of running their own custom Apache httpd website on bare metal in a colo like it's 2005. The cost of maintenance and cognitive load is a cost we shouldn't ignore.

It turns out that economies of scale exist. The Internet doesn't need 10,000 small CDNs and they would all be inefficient and expensive if that was the distribution. Instead, there are a few large ones that can afford to colo in many geographically dispersed data centers and who negotiated bandwidth peering contracts for advantageous pricing.

thephyber··on America.gov
It has always been the person's problem to solve, even after this website.

No government employee is your lawyer. If the government gives you incomplete or wrong information, you are still liable for not doing the correct thing.

Having a website that does a best guess at what steps a person must take after changing a name or getting married is better than nothing, but the status quo isn't "nothing".

It needs to be kept up-to-the-minute updated and it can't skip any nuance / details. Does anyone here really trust the lackeys who spectacularly failed at DOGE to do boring and highly detailed work?

thephyber··on CAPTCHAs don't prove you're human – they prove you're American
Yes, the reCAPTCHA widget is localized[1], but that doesn't automatically mean every term is localized properly.

But the underlying point of the article stands. This is similar to the mythical statement that some park ranger once stated "it's very hard to design a trash can that no bears can use, but that every human can."

reCAPTCHA, like CloudFlare, benefits the wider population of the internet to the extent that everybody can use them, but there are edge cases where some outlier users get locked out of necessary internet infrastructure because they can't grok the ask, can't correctly identify the options, or because their computer / IP is being abused by bots so they are in the splash damage range of the bot checkers.

[1] https://github.com/google/recaptcha/issues/68

thephyber··on 'We hacked the FBI:' Hackers say they have data on all FBI employees
Did your comment add anything to mine?
thephyber··on Security auditing in the age of (good enough) AI
I suspect you two are using the same words for different terms / connotations.

"Good enough" in colloquial speak usually means the minimum required for some particular requirement.

For security, there is usually no exact threshold that differs between insecure and secure. It's a spectrum that involves costs and tradeoffs, which are subjective value judgements.

A SaaS startup in pre-seed mode with no customers will have VASTLY different value judgements than a bank that handles $trillions in assets. Hence they will make very different security choices and "good enough" will mean very different things in their different sectors.

thephyber··on Jev in 25 Lines of Python
I heard it was and just repeated what I heard.

A Google AI prompt says

> TypeSafe AI's Master Customer Agreement explicitly prohibits using the services or model outputs to develop a competing product, perform model distillation, or reverse engineer the service, which generally restricts competitive benchmarking aimed at replicating the model.

It doesn't explicitly prohibit benchmarking by name, but the previous terms (which seem aimed at preventing Jev being used to increase the value of competitive products) does seem to lean that direction.

That said, MsSQL had terms which prevented publishing benchmarks which compared it against other SQL DBs and that wasn't enough to prevent some companies from using it.

Why anyone would want to work for a company who thought so little of their own product that it couldn't stand up to customers using it for normal business processes is beyond me.

thephyber··on Pentagon says overreliance on AI contributed to missile strike on Iran school
The DoW rename (which Congress never approved) happened in 2025. The Department of Defense has had some major lapses in judgement for a long time before that.
thephyber··on 'We hacked the FBI:' Hackers say they have data on all FBI employees
> This is why security is an afterthought.

Security is always a cost center and rarely a profit center. That's the only thing that needs to be said.

thephyber··on Jev in 25 Lines of Python
Is benchmarking Jev still a ToS violation?
thephyber··on Microsoft says email spammers are adopting ASCII smuggling
Are you complaining about the existence of emojis? Get off my lawn, old man!
thephyber··on Detecting and countering misuse of AI: September 2026
Quit being pedantic and try to understand the concept I'm expressing, not just semantically parse my sentence looking for the first quibble.

There are only a few dozen PhDs working the BSL-4+ labs worldwide. And they have state security and state intelligence services constantly monitoring them. The BSL-1 workers (a few thousand like you mention) have access to only much lower risk bio assets/risks.

And the underlying message is that the LLM empowers 8 billion people to do some of what those scarce dozens are doing.

thephyber··on Microsoft says email spammers are adopting ASCII smuggling
Maybe you intended to reply to my comment's parent? I don't necessarily disagree.

But also, according to the Ars article comment describing the Unicode character range, it has been deprecated, so maybe someone involved in the Unicode standard saw problems with it.

thephyber··on Detecting and countering misuse of AI: September 2026
The question isn't only "should we" regulate the companies, but also "how"?

The current Trump Admin can't even decide on the first question, let alone come up for a plan on the second.

The Trump Admin's EO was to ask nicely all of the AI companies to give them 30 days to voluntarily review each model before wide release, but they have also failed to do that for the Mythos/Fable release, only to get a call from Amazon's CEO to David Sachs to convince them to disable Fable (to all non-US citizens).

We elected the party of "minimum regulations" into all 3 branches of government and we will reap what we sewed.

thephyber··on Detecting and countering misuse of AI: September 2026
> There’s no need for an LLM, just a phd in virology, a decent lab, and a handful of grad students.

You are missing the forest for the trees. The existing virologist PhDs and the GoF labs are a scarce resource. The model makes the same scarce knowledge accessible to many more malicious actors.

thephyber··on Detecting and countering misuse of AI: September 2026
The CIA, FBI, and DoD are being ideologically purged. I would assume we are already in the "we are probably increasingly failing at our jobs" phase.

It will only get worse as sovereign debt service takes a larger piece of the budget pie.

thephyber··on Detecting and countering misuse of AI: September 2026
I feel like your comment is relying heavily on bad heuristics (the entities capable of using LLMs to create weapons aren't all individuals) and you are making assumptions that the same "strictly controlled" regimes are in place.

It's worth verifying whether the US, OECD countries, UN, etc will have sufficient regulation over suspicious purchases, for example, after DOGE and funding cuts. This will be an ongoing issue as sovereign debts and bond yields squeeze out spending for other government regulation.

thephyber··on Detecting and countering misuse of AI: September 2026
The weapons of mass destruction trio (bio, chem, nuke) have long been a concern for world powers.

Nuke requires a long supply chain and massive resources, so the worry there is maintaining control of all of the existing nuke weapons. Except for Russia racing towards Turin no itself into a failed state by staying engaged in the war with Ukraine, I don't see the nuke equation has changed much in recent years. Perhaps N Korea is a worry, but they seem to just want attention and power. Iran pretends to have nukes and says they want to extinguish Israel and the US, but I interpret that as posturing to maintain domestic control and Israel seems excellent at countering Iran's threats.

Chemical weapons have traditionally been the easiest to create (like creating chlorine gas from mixing common household cleaners). The trick there has always been volume and how to disperse it. I suspect within countries, police will have to deal more with LLMs being abused that way.

Bioweapons will be easier than in the past. LLMs will lower the barrier to entry, but bioweapons are hard to create and much of what the superpowers learned thankfully isn't in the training set for LLMs. I doubt there is much that can be inferred by having agents learn biology from first principles.

Ultimately, governments are responsible for policing these threats. Sadly we are currently both cutting government systems which work different aspects of these problems and withdrawing from the multinational orgs (UN, WHO, etc) who do lots of the investigating and watchdog work that underpin lots of the US's intelligence related to these fields.

The US has a schizophrenic regulation policy of AI where we both want to sell Nvidia chips to China (David Sachs) and we don't want to sell the top chips to China (bipartisan policy prior to Trump). We also have a terrible AI regulation policy where David Sachs disables models on a call-to-CEO-on-a-Friday-evening basis after Andy Jasse calls him with a scary story which turns out to be missing lots of relevant info (eg. The exploits was discovered in Mythos, not Fable, and other open weights models were able to find the same exploits).

There's not much we can do at a government policy level while Trump is snoozing through the rest of his term. So we are dependent on the AI companies to police themselves, but it's clear from this report that it's insufficient to prevent all serious abuse of the models.

thephyber··on Microsoft says email spammers are adopting ASCII smuggling
> Simple enough to strip out anything that isn't a flag.

But it's not simple enough for every company/app to independently research the entire Unicode code point space (which is MASSIVE) to find out what kinds of "fix ups" that app needs to do to clean the data it consumes.

It's complicated or at least has difficult tradeoffs. Maybe you invest a lot of time carefully surveying all of the Unicode planes and decide which ones you care to keep unchanged and which ones you filter/strip. For every code point you reject or change, there is going to be some user who is confused or dissatisfied with the limitations of your app.

thephyber··on Microsoft says email spammers are adopting ASCII smuggling
The top comment (the Staff Highlighted one) explains why this range of code point exists.

There was a rationale (ISO country codes to modify a flag to display that national flag).

Maybe the problem wasn't the proposal, but the lack of the ability for others to reject it for being insecure.

thephyber··on Microsoft says email spammers are adopting ASCII smuggling
Do you have any evidence they didn't?

My suspicion is that the spam filter programmers didn't do a comprehensive evaluation of every code point on every plane of Unicode because... well that's a massive job. So your "sanitize and denormalize" tasks are actually massive mappings which were likely imperfectly created.

thephyber··on Anthropic Is Building a Predictive Surveillance System to Monitor Activists
> The Democrat Party believes everything that God hates. Like, we’re dealing with maggots, vermin, and swine here. This is not — these are not good people, they’re not even a little bit good.[1]

He also called for the death of Biden (because he was a "tyrant") and all surgeons of transgender people.

If he was merely trying to be offensive, then he succeeded.

If, however, he was trying to make someone fear enough for their life to preemptively defend himself from someone claiming to speak for God + using the same dehumanizing words that have preceded multiple genocides before, then he succeeded.

A "valid" response entirely depends on what you think he was apart of. If you think he was only involved in good faith debates on college campuses and getting out the vote, then obviously shooting the guy was unjustified. But he wasn't only that, so we have to struggle with what his legacy actually was and what might have driven someone to pick up a gun against him.

My point isn't to justify his killing. It's to point out that we need to learn from history so we don't blindly repeat it.

[1] https://www.mediamatters.org/charlie-kirk/charlie-kirk-refer...

thephyber··on The two Christian saints who are the Buddha
This is a weirdly dissonant comment that misunderstands both religion and the nature of choices.

Religions don't exist without the people. The scriptures have no narrative power if they are not told by people to people. The rites and traditions only serve to reinforce habits and pass themselves down throughout time to new people. The religion evolves with the people because keeping followers become the fitness function.

No religion knowingly offers its followers "bad teachings". Anybody who thinks a religion has "bad teachings" quickly becomes an impostor and gets pushed out. The self selection means that there are no "bad teachings".

Also, you are trying to pretend like the choice is only applied by the cognitive brain by the individual human at the time of an action. This ignores both group psychology and the role of habits / indoctrination.

The Catholic Church internal policies target the ages of 4-14 for indoctrination and habit forming. What 10 year old will resist their parents, resist their church authority figures, resist all of the teachings of thousands of years of their people, resist the "word of God", have the knowledge and self awareness to know the difference between God's voice and typical bipolar ruminations?

thephyber··on We have a year to fix security everywhere
Yes, and...

Not only the quantity of people who have the minimum aptitude required, specialized expertise requires both knowledge and experience doing these tasks. Using an LLM requires neither.

Leaning on an LLM to do much or all of this means it can happen in seconds/minutes/hours, the LLM can do it several times during that psychotic break (as opposed to a fraction of a hack in a single episode). The barrier to entry pre-LLM was both high and the population who could pull it off (before the Chinese/Russians turned this into commerce) was low.

Hacking is an VERY asymmetric activity (the attacker only needs to "be right" once, whereas the defender has to be right every time for every asset they defend). It takes geometrically / exponentially more work to defend (while keeping high availability) than it does to defend. The more widespread tools to find vulns / generate exploits are, the faster the posture of the defense side falls from "maybe we can stop most hacks" to "we know we will fail to prevent most breaches, so we need to prioritize securing only the most valuable resources". That's a BAD place for the average company to be in.

thephyber··on Hackers have withdrawn ~4k BTC (~$320M) from the Liquid Federation wallet
And remember that there is precedence for Trump pardoned financial criminals avoiding restitution.
thephyber··on Hackers have withdrawn ~4k BTC (~$320M) from the Liquid Federation wallet
This is worded in a way that pretends like the banks and governments themselves aren't considered criminals by the masses.
thephyber··on Hackers have withdrawn ~4k BTC (~$320M) from the Liquid Federation wallet
You are conflating the original BTC network and a lot of the other projects in the cryptocurrency / token / stable currency space.

Every time there was a new token that was 80% reminded or was governed by a central company, the original cryptocurrency enthusiasts cried fowl.

Most people don't read the fine print, don't read the founding white papers, and don't care about the differences between the protocols and the networks when they should.

thephyber··on Hackers have withdrawn ~4k BTC (~$320M) from the Liquid Federation wallet
You have worded this like a fact, but this is your opinion.
thephyber··on South African diamond mines are closing due to weak sales and lab-grown stones
WSJ is almost never rated center-left on any media bias charts based on any objective standards (eg. Ad Fontes media chart). They always fall into center-right.
Page 1 of 34Next →