HNHacker News
TopNewBestAskShowJobs

throwaway89201

719 karma · joined July 23, 2020

submissionscomments
throwaway89201··on My audio interface has SSH enabled by default
> You would have to be a Hotz tier hacker if you wanted to do anything close to this only last year

This isn't true at all. Yes, LLMs have made it dramatically easier to analyse, debug and circumvent. Both for people who didn't have the skill to do this, and for people who know how to but just cannot be bothered because it's often a grind. This specific device turned out to be barely protected against anything. No encrypted firmware, no signature checking, and built-in SSH access. This would be extremely doable for any medium skilled person without an LLM with good motivation and effort.

You're referring to George Hotz, which is known for releasing the first PS3 hypervisor exploit. The PS3 was / is fully secured against attackers, of which the mere existence of a hypervisor layer is proof of. Producing an exploit required voltage glitching on physical hardware using an FPGA [1]. Perhaps an LLM can assist with mounting such an attack, but as there's no complete feedback loop, it still would require a lot of human effort.

[1] https://rdist.root.org/2010/01/27/how-the-ps3-hypervisor-was...

throwaway89201··on State of Kdenlive
Creating the PR, doing the explanation you just did, and closing it yourself might be a good option. Then at least your code lives somewhere that someone else can reuse if desired. Ideally combined with a linked issue that you do keep open.
throwaway89201··on Reaffirming our commitment to child safety in the face of EuropeanUnion inaction
Yes indeed, thanks for the correction. It has been a complex story, and I already forgot that chapter. I edited it into my post (also modified a wrong date of the first derogation), although I'm probably missing more nuances.
throwaway89201··on Reaffirming our commitment to child safety in the face of EuropeanUnion inaction
The report you're referring to by the European Commission [1] shows that the mass surveillance of Chat Control 1.0 is probably not very proportional. They even note themselves that "The available data are insufficient to provide a definitive answer to this question".

However, the "13-20%" that you're quoting is a dishonest propaganda number itself. It's the false positive rate that a single small company (Yubo) reported. The reported false positive rates of other companies are between 0.32% and 1.5%, which is still a high error rate in absolute numbers.

Just to be clear: the report itself is full of uncertainty, convenient half truths and false causality. They for example completely rely on Big Tech platforms themselves to count false positives when a moderation decision was reversed. Microsoft apparently even claims that no user ever appealed against a decision ("No appeals reported"). There is no independent investigation into the effectiveness of the regulation at all, while it is in direct conflict with fundamental rights and required to be proportional to its goals.

The section about "children identified" is also a complete mess where most countries can't even report the most basic data, and it isn't clear if mass surveillance contributed anything to new cases at all. But somehow they still conclude "voluntary reporting in line with this Regulation appears to make a significant contribution to the protection of a large number of children", which seems extremely baseless.

[1] https://www.europarl.europa.eu/RegData/docs_autres_instituti...

throwaway89201··on Reaffirming our commitment to child safety in the face of EuropeanUnion inaction
So just a recap of what happened between the European Commission and the European Parliament and why the regulation has expired (it's a long story, I'm probably missing many nuances):

- In 2021 the European Parliament voted in favor of a temporary regulation that allowed companies to (i.e. voluntarily) scan private communications. Let's call it Chat Control 1.0. They chose to enact this because US companies were already scanning private messages in violation of the ePrivacy Directive which had come into force in the previous year. Instead of enforcing this directive, they chose to (temporarily) legalize the scanning of private messages while preparing more permanent legislation.

- In 2024 Chat Control 1.0 was extended for another 2 years. An amendment was adopted that explicitly noted that after this time "[the regulation] shall lapse permanently".

- From 2022 to 2025 the European Commission (together with member states) has proposed mandatory scanning, later updated with a proposal for client-side scanning (defeating end to end encryption), AI classification of image and text content, age verification and a lot of other invasive measures. This is what is known as Chat Control 2.0. The European Parliament has again and again voted against this proposal.

- In 2025/2026 the European Commission finally (temporarily) backed down from Chat Control 2.0 and instead proposed to extend Chat Control 1.0 for another 2 years, but has completely failed to negotiate with parliament to adopt a text that explicitly puts fundamental rights up front, something that a majority of the European Parliament had asked for since 2021.

- In response to this, the Civil Liberties Committee of the European Parliament tabled amendments [1] that explicitly limits the regulation to the subject matter and prevents it from being used to weaken end-to-end encryption. Many of these amendments were adopted.

- Consequently, many conservative members of the European Parliament voted down the entire extension of the regulation. They apparently felt that it was better to let the regulation expire so that they gain more negotiation power to adopt a version of the regulation that the has less safeguards or contains measures like in Chat Control 2.0.

[1] https://www.europarl.europa.eu/doceo/document/LIBE-AM-784377...

throwaway89201··on Anthropic's AutoDream Is Flawed
It also seems conceptually wrong to refer to a process of ordering and cleaning up notebook facts as 'dreaming'. If I collect and clean up my notes of the day, that's a very conscious task. Actually dreaming seems more analogous to a training or fine-tuning step where you modify the model weights.

(while hallucinating the events of the day in a very weird way; it would be fun to 'wake up' the agent in the middle of such a session and commit the 'dream' to a notebook again)

throwaway89201··on Ask HN: Is Claude Down Again?
I use Big-AGI [1] as selfhosted open source LLM workspace, and it's quite telling that when adding API keys for Anthropic, it presents a note inbetween reading "Experiencing Issues? Check Anthropic status" that it doesn't for any other model provider.

[1] https://github.com/enricoros/big-AGI (no affiliation)

throwaway89201··on France's homegrown open source online office suite
> OpenCloud is the "open-source" fork but they are already in legal trouble with OwnCloud due to industrial espionage claims.

Can you expand on this or source this? I'm quite interested in OpenCloud, and haven't heard anything about this. I searched for a few keywords (espionage, legal, lawsuit), which only lands your comment on top.

throwaway89201··on Invention of DNA "page numbers" opens up possibilities for the bioeconomy
What's the source of the text? It seems to be either a copypasta from a journal article or LLM-generated (and not your own text).
throwaway89201··on LICENSE: _may be_ licensed to use source code; incorrect license grant
The frontend parts are explicitly and correctly licensed under the Apache license in the header of the same file.
throwaway89201··on LICENSE: _may be_ licensed to use source code; incorrect license grant
> But maybe I'm misunderstanding? If so, I don't know what I'm missing

You're apparently missing the two points I made in the post you are replying to, or at the very least you're not responding to them. By which I don't mean to say they are necessarily valid points.

throwaway89201··on LICENSE: _may be_ licensed to use source code; incorrect license grant
But also: "open source" -> "open core" (9 months ago) [1]

[1] https://github.com/mattermost/mattermost/commit/0cc906d07e73...

throwaway89201··on LICENSE: _may be_ licensed to use source code; incorrect license grant
The counterpoint is that three sentences away, there's a clear "You are licensed to use the source code" for the non-server parts. It can certainly be argued that there's an intentional difference. Extended court cases have been fought over mere punctuation. In any case, the FUD that this creates is enough to make anyone think twice about reusing the server code, especially as they have refused to clarify for many years now.

Also, the ambiguity is not only in the "you may be" part, but also in the "to create compiled versions" part. Open source is more than creating compiled versions of source code.

throwaway89201··on LICENSE: _may be_ licensed to use source code; incorrect license grant
Counterpoint: https://news.ycombinator.com/item?id=46862339
throwaway89201··on Defeating a 40-year-old copy protection dongle
> It’s possible that I haven’t fully understood the logic, and the copy protection will somehow re-surface in another way.

They should be glad the copy protection is not more in the style of "The Games: Winter Challenge", where playing a pirated copy would make it subtly impossible to play many levels [1]. Would be 'fun' if the exported accounting data would contain all kinds of subtle errors.

[1] https://mrwint.github.io/winter/writeup/writeup.html

throwaway89201··on UK Appeals court state RuneScape gold counts as property and can be stolen
Fourteen years after the Supreme Court of the Netherlands found the same in a criminal case against teenagers, also about Runescape items (in 2007), establishing that in-game items can be considered property and therefore can be stolen [1]. Specifically theft with assault and threats, all committed jointly.

[1] https://nl.wikipedia.org/wiki/Arrest_RuneScape

throwaway89201··on Man shot and killed by federal agents in south Minneapolis this morning
Thanks for the link to https://news.ycombinator.com/active; didn't know that one.

As for the existence of "censors" that don't "allow" you to see anything. That's not how this site works, and your lack of carefulness stating that leads me to downvote that.

As much as I hate that anything regarding the rise of fascism in the US get's insta-flagged (by a community, not a "censor"), it's still very easy to find such posts, for example on an aggregator [1] and on the /active subpage you just mentioned.

It will also be broadly shared on regular (social) media, which is an oft stated reason this kind of stories get flagged by the community, although I think there are many other reasons.

[1] https://hckrnews.com

throwaway89201··on Minnesota activist releases arrest video after manipulated White House version
This sounds like a good idea on its face, but it will have the effect of both legitimizing altered photos and delegitimizing photos of actual events.

You will need camera DRM with a hardware security module down all the way to the image sensor, where the hardware is in the hands of the attacker. Even when that chain is unbroken, you'll need to detect all kinds of tricks where the incoming photons themselves are altered. In the simplest case: a photo of a photo.

If HDCP has taught anything, it's that vendors of consumer products cannot implement such a secure chain at all, with ridiculous security vulnerabilities for years. HDCP has been given up and has become mostly irrelevant, perhaps except for the criminal liability it places on 'breaking' it. Vendors are also pushed to rely on security by obscurity, which will make such vulnerabilities harder to find for researchers than for attackers.

If you have half of such a 'signed photos' system in place, it will become easier to dismiss photos of actual events on the basis that they're unsigned. If a camera model or security chip shared by many models turns out to be broken, or a new photo-of-a-photo trick becomes known, a huge amount of photos produced before that, become immediately suspect. If you gatekeep (the proper implementations of) these features only to professional or expensive models, citizen journalism will be disincentivized.

But even more importantly: if you choose to rely on technical measures that are poorly understood by the general public (and that are likely to blow up in your face), you erode a social system of trust that already is in place, which is journalism. Although the rise of social media, illiteracy and fascism tends to suggest otherwise, journalistic chain of custody of photographic records mainly works fine. But only if we keep maintaining and teaching that system.

throwaway89201··on New YC homepage
> YC often also mentors founders on pivots

It doesn't seem unlikely to me that YC coined or at least popularized 'the pivot' in the context of changing business / startup directions. The first mention of using the word in that sense is in this comment [1] which explicitly mentions the usage by YC, while it only gets used when talking about pivot tables or more traditional uses of the word before that.

Edit: The "Lean Startup" blog series [2], which was quite influential, mentions 'the pivot' a little earlier than the post above, and really seems to coin it, so I guess that's the source (edit again: wrong :D).

[1] https://news.ycombinator.com/item?id=806601

[2] https://www.startuplessonslearned.com/2009/06/pivot-dont-jum...

throwaway89201··on Show HN: Subth.ink – write something and see how many others wrote the same
> It (the MD5 hash) might be published in the future when a thought's count passes a certain threshold (TBD). This might make it possible to recover certain short thoughts that were popular.

This makes little sense. Recovering a random preimage of an MD5 hash is marginally easier [1] than a (128-bit truncated) SHA256 hash, but this won't recover any sensible message.

Recovering a sensible (short) message is equally hard for both hashes.

[1] https://link.springer.com/chapter/10.1007/978-3-642-01001-9_...

throwaway89201··on Statement by Denmark, Finland, France, Germany, Netherlands, Norway, Sweden, UK
> Why did you single mine out?

Because I thought some kind of curious conversation would be possible with the reply you made. The two other examples you posted are devoid of anything interesting; hopeless cases.

I should have consulted your posting history however, which consists mainly of short, combative and indignant responses like the one you just directed at me.

> it would be incredibly economically beneficial to the US

I fail to see how this is the case. The US and US companies have always been welcome to bid on mining concessions (at least, until recently), but the reality is that it's hardly profitable to do so, as there are ample cheaper opportunities available elsewhere.

Also, "assuming control" seems to be a euphemism for "invading" as the US buying Greenland is squarely out of the question. Invading is hardly humble, indeed, and you seem to be all too confident that such invading will allow for a republic and not lead to autocracy.

throwaway89201··on Statement by Denmark, Finland, France, Germany, Netherlands, Norway, Sweden, UK
I don't particularly care for your explanation, but if you do want to post these kind of comments at least explain yourself a bit so potentially a curious conversation can follow. Not doing so is arguably against this site's guidelines.
throwaway89201··on Xous Operating System
Here's their 39c3 talk about Xous: https://media.ccc.de/v/39c3-xous-a-pure-rust-rethink-of-the-...
throwaway89201··on Ask HN: Why does Google still provide an open redirect for phishers?
It doesn't for me at all. If I go to the URL I provided in the OP, the Google server responds with a 301 status code and Location header. Both when logged into a Google account and without logging in. Strange that it behaves in a different way (?) for you.

It will probably filter the URL through Google Safe Browsing, but that doesn't help much for phishing as they mostly use new or reputable domains, and browsers check that list on default settings anyway.

throwaway89201··on Shopify CEO vibe codes an MRI viewer
Claude Code mostly copies and amalgamates codes from others, without attribution. But you could argue that's very similar to what humans do.

In this case it's very likely that Claude Code used some library to parse DICOM (and not outright reproducing it), while the Shopify CEO passed it off as something very innovative or difficult. But that isn't plagiarism either.

It was more of a figure of speech to emphasize that nobody (and no tool) did the actual work here, and the party that did the work did not get any credit.

Perhaps we could call it paraplagiarism.

> I'd parse it the same way as for natural intelligence. If I ask Bob how to do it

Not to detract from your point, but Claude Code is a very much a tool, not another person with their own responsibilities. "natural intelligence" and "artificial intelligence" are not simply interchangeable here.

throwaway89201··on Shopify CEO vibe codes an MRI viewer
"Shopify CEO doesn't understand how to install a DICOM viewer application which is widely available and open source for any platform [1], so decides to let Claude Code plagiarize one / use widely available open source DICOM libraries."

[1] https://alternativeto.net/software/horos/?license=opensource

throwaway89201··on Cloudflare CEO on the Italy fines
> International law??

Note the "general line". You know, bombing boats in international waters, abducting awful dictators and "running" the country sidelining the opposition, threatening to take over an autonomous territory of Denmark, meddling with German and British politics and generally behaving very much like fascists and a wannabe dictator.

throwaway89201··on Cloudflare CEO on the Italy fines
The Italian 'piracy shield' is indeed reprehensible, but the tweet is very far out there as well. For all I care Cloudflare blocks the entirety of Europe for a week or so in protest, but aligning yourself with the bunch of fascists now in charge of the US government and prefacing that with "while there are things I would handle differently than the current U.S. administration" is pretty insane as Cloudflare will be at the complete mercy of their lawlessness, if not now, then in the future.
throwaway89201··on Ask HN: What tech purchase did you regret even though reviews were great?
Still a useful thread. The two comments the account posted are really painful AI responses though.
throwaway89201··on Ask HN: What tech purchase did you regret even though reviews were great?
I'm on the opposite side: I paid extra for a PS5 with disc drive, but I have never since bought a disc game. Although I have used the drive this year to watch some old DVDs.
← PreviousPage 2 of 5Next →