HNHacker News
TopNewBestAskShowJobs

throwaway89201

712 karma · joined July 23, 2020

submissionscomments
throwaway89201··on Grok Voice Transcribe 2.0
Mistral STT offers it, which is an open model.
throwaway89201··on Flock cameras are riddled with security vulnerabilities and hardcoded creds
The device runs Android, which makes it very simple to use the Keystore system and to store a device specific private key within the TEE or SE where it can't be very easily extracted. If you really don't want to provision in the factory, you could use secure boot measurements to do it remotely. Of course this isn't completely watertight either against a physical attacker, but it would survive a filesystem dump attack and is the least you can do to appear competent.
throwaway89201··on Iranian banks' SSL certificates are being revoked due to OFAC sanctions
They can only do that through an "SSL added and removed here ;-)"-like 'cooperation' and not through passive listening because with forward secrecy a certificate key doesn't secure the transport encryption directly. They could actively MITM outside the perimeter of the target by issuing a new certificate, but that would show up on CT logs.
throwaway89201··on I changed my license
You are describing the compatibility clause as if it's settled that the EUPL simply allows you to convert to a compatible license. The compatibility clause is an unfortunate ambiguity, but it's not the intention of the license authors to lose strong copyleft and SaaS loophole protections this way. See for example here [1] [2] [3].

[1] https://interoperable-europe.ec.europa.eu/collection/eupl/di...

[2] https://interoperable-europe.ec.europa.eu/collection/eupl/ho...

[3] https://news.ycombinator.com/item?id=45422512

throwaway89201··on Can I opt out of my input or output data being used for training?
> I don't have that toggle (but could indeed have sworn I saw it earlier).

You don't see "Allow the use of your interactions with Vibe to train Mistral’s AI models" at https://admin.mistral.ai/vibe/privacy ?

And "Allow the use of your API calls to train Mistral’s AI models" at https://admin.mistral.ai/plateforme/privacy ?

throwaway89201··on Can I opt out of my input or output data being used for training?
I'm really hoping Mistral will succeed with their open models, so I'm a bit biased, but I don't have any affiliation. This submit is a bit of well-meaning but confused scaremongering however.

Mistral has had, and continues to have, a toggle in the admin settings that permanently disables training on your data. The option has not been removed, and previous opt-outs are still honored. As far as I know, Mistral always trained on your data by default except for the enterprise plan, with the option to disable it on all plans, and with the option for organizations to make the choice for all your users.

Kagi Ultimate still uses mostly closed models by OpenAI / Anthropic, etc.

throwaway89201··on Can I opt out of my input or output data being used for training?
> and at the same time seemed to have lost the ability to centrally disable training on prompts for your entire organization

There is a toggle on https://admin.mistral.ai that allows you to disable training for both Vibe and Console/API for your entire organisation. And I'm not on the enterprise plan. I've disabled training the first time I created an account, and it has remained that way.

You story is also very confusing due to the wording around "opt-in by default" and "disappointed [about] opt-in to training" (most people would be disappointed about an opt-out) and probably conveys the wrong message to most people.

throwaway89201··on Can I opt out of my input or output data being used for training?
This isn't the case. There's a toggle on https://admin.mistral.ai that allows you to disable training for both Vibe and Console/API for your entire organization, I just checked.
throwaway89201··on Adafruit USB Type C CC Resistor Fixer
The Miyoo Flip has the same problem. Great device otherwise for GBA or earlier games.
throwaway89201··on Scientists stunned by children's lung recovery in ultra low emission zone
Might instead refer to a start-stop / battery backup kind of system, where idling-but-on doesn't burn any fuel, but sudden loads can still be serviced.
throwaway89201··on Dutch Train Map Simulator
A similar train map of The Netherlands that has existed for a long time, but is geographical instead of schematic, and provides a live view of trains (based on the schedule) instead of a day in the past: https://spoorkaart.mwnn.nl
throwaway89201··on Sonic Pi v5
I don't know what you mean with this. Strudel is AGPL, which is hardly "impossible to use on anything". The default sound banks are CC-by(-sa), CC0 and unspecified. The unspecified ones might indeed be a problem, but the other ones are fine.

As long as you allow anyone to get the source code of any derivative work you make of the Strudel code, and you take some measures to keep the distribution of the two works somewhat separate, you're should be good. And yes, there's a lot of FUD by the FSF, but your pet projects shouldn't be encumbered by such a narrow reading of 'derivative work'.

throwaway89201··on Ask HN: What are you working on? (August 2026)
It's a worthy goal, but can you please not push unimaginative AI slop on kids? The frontpage graphic you're showing here already contains numerous slop markers and errors, and you've apparently still chosen to use it.

In modern times, kids mostly get to know the world through images, and they deserve those images to be real or at least realistic. It really matters that the details are either correct or simplified, but not present and wrong.

For example, a compass with two norths and a garbled east is not a good start for curious conversation, but I think you should refrain from using generated images even if the details aren't so clearly wrong, as you are not an expert in most subject matters, and can't judge those errors. Instead use either photography or stylized illustrations which leave out details to imagination instead of including them and getting them wrong.

throwaway89201··on Show HN: I spent 2 years designing a mechanical Magic Keyboard
Those characters are present. The design of the number row is just so 'out there' that you missed them.
throwaway89201··on Less Coffee, Better Sleep
> I drink black tea rest of the day

Black tea contains a considerable amount of caffeine too. Aside from that, I know of two people whose years-long mysterious health effects disappeared (one with stomach troubles and the other with bad muscle cramps) after stopping their all-day >1L black tea consumption. The tannins in tea bind to iron, so it might cause iron deficiency anemia (although studies yield conflicting results), which especially woman are already predisposed to, and for which iron deficiency tests are often calibrated towards men .

throwaway89201··on I regret migrating to Codeberg
Nobody is LARPing an Eingetragener Verein, they're just being one, and the law requires them to have a board and presidium.

As they got hundreds of votes on the issue, that means tens of thousands of euros in membership contributions. It doesn't seem unreasonable to want to create a legal entity for that, and an e.V. is easier to set up in the beginning (although it can lead to a lot of drama later).

throwaway89201··on The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
It's very, very hard for untrained people to be strict about verifying any secret phrase. The attacker can make all kinds of excuses, while creating urgency, and many people quickly abandon verifying the phrase. A scene in One Battle After Another comes to mind.
throwaway89201··on Sophon PFG-1: a monolithic-3D AI ASIC with 330 GB of on-die DRAM and no HBM
> I think it's ok to have multiple talents.

Of course that's okay, but do recognize that most blockchain projects in general and DAOs and NFTs specifically have been considered frauds or at the very least pipe dreams by many on this site from the beginning. And wider in tech society from the moment the hype was gone.

> We don't need to prove to average Joe what we have.

Of course you don't need to prove anyone anything, but it really can't hurt and there doesn't seem to be much effort in addressing the main issues. Not having anyone write about you also just seems like bad marketing: as you clearly are not in stealth mode, an extremely verbose public website stands oddly against no external coverage.

> It's indeed teamwork to bring it into production

So is or isn't the NanoGalaxy an actually physical, working device ready for a demo? (which isn't necessarily production, but somewhat close)

throwaway89201··on Sophon PFG-1: a monolithic-3D AI ASIC with 330 GB of on-die DRAM and no HBM
The entire design looks very interesting, but from the outside and without domain expertise I find it very hard to assess if anything about this is actually real or just a large and well-executed product of an AI psychosis.

The signs that this project is real are hard to verify:

- Angel investment by FinFET inventor Chenming Hu [1] seems a big vote of confidence, but there is no independent confirmation of this anywhere, except for two photo's in LinkedIn posts [2], which do look convincing.

- The NanoGalaxy PPMOCVD was presented at IEDM 2025 [3][4], but nobody seems to have written about it except the company itself. In this case, presenting means a poster presentation with a very vibrantly colored marketing picture.

- The NanoGalaxy PPMOCVD is built and in production, because you can "Witness a full 12-inch MoS₂ growth cycle on your own wafer lot" [5], but nobody has reported on this. A photo/video of the actual device would help a lot, but instead a very clean picture of what seems like a 3d-model is shown.

There are a few worrying signs:

- The submitter on HN presents itself as the founder. They have previously submitted other projects under the Phanta or PhantaField names [6]. Notably two hype cycle subjects: DAOs, NFTs and augmented reality, combined in a book that itself is rather 'out there' [7].

- The comments on HN by the founder are clearly AI generated with phrases like "honest caveat". The content seems to make sense (to a non-expert like me), but it's quite jarring.

- All the work except the NanoGalaxy seems to be theoretical for now, but written in very definitive language in extreme detail. For example "The die is built" with specific properties but then referencing three very experimental papers. This can of course be genuine (technical) marketing, but it's also very similar to AI psychosis work that I've encountered elsewhere. Although I must say in comparison this does look a lot more internally consistent and logical to me.

- I find it very hard to believe that the NanoGalaxy is actually existing and working hardware ready to "Witness a full 12-inch MoS₂ growth cycle on your own wafer lot". I would imagine you need a sizable team to produce such a new device, and that seems to be inconsistent with the way the company presents itself (a one man show of the founder). The absence of any verification or showcases of the device, or any evidence of a larger team make it suspect.

[1] https://www.phantafield.com/news/first-angel-investment-chen...

[2] https://www.linkedin.com/feed/update/urn:li:activity:7126002... and https://www.linkedin.com/posts/xuejunxie_its-a-great-honor-t...

[3] https://www.linkedin.com/feed/update/urn:li:share:7404253323...

[4] https://www.phantafield.com/news/12-inch-ppmocvd-iedm-2025

[5] https://www.phantafield.com/product/ppmocvd

[6] https://news.ycombinator.com/submitted?id=minkowsky

[7] https://xcancel.com/thepantheonai

throwaway89201··on 5k menus from the New York Public Library’s Buttolph Collection (1880-1920)
The second chapter of the included tour [1] is about celery: "In fact, it's the fourth most common item among the Buttolph Collection menus, after coffee, tea, and olives."

[1] https://pudding.cool/2026/06/menu-story/

throwaway89201··on Tokenmaxxing is dead, long live tokenmaxxing
> Just repeating the same prompt until you get the desired result?

Not necessarily the desired result, but until it's 'done', where the LLM itself is the judge on if the is the case according to the given criteria (often just an updated todo-list). One of those extremely simple 'harnesses' (if you can even call it that) was even named the 'Ralph Wiggum Loop' [1] to allude to the braindead-but-persistent tokenmaxxing it results in.

[1] https://awesomeclaude.ai/ralph-wiggum

throwaway89201··on The frontier is open-source today
The point is that you need several orders of magnitude less capital to run GLM-5.2 compared with the investment needed to train a model like Opus or GLM-5.2 from scratch. To do inference of GLM-5.2 you'd need an investment of roughly less than €300k (8x H200 at GLM5.2 FP8), which is completely feasible for a lot of hosting businesses.

Even if end-users can't run these models themselves at home, there are a lot more and varied options to choose from, especially considering privacy and data protection.

You can apparently also do GLM-5.2 at Q4_K_XL with 2x RTX 3090 and lots of RAM [1], but I don't think that counts as a potential frontier model.

[1] https://news.ycombinator.com/item?id=48639186

throwaway89201··on OpenAI’s WebRTC problem
> The reason we skip 200ms instead of pausing for 200ms when we get missed packets in a WebRTC call is because we can't pause the human on the other side of the call. But we can pause AI just fine.

This isn't about pausing anyone; it's about doing faster-than-realtime processing after a delay event. Humans can do that to some extent, and this is in fact done with some voice applications like Microsoft Teams, where after a network interruption the audio is sometimes played back really fast until the point that it becomes real-time again.

I hope it's an intentional design decision, because it works really well (for me). I can often perfectly keep track of a conversation in spite of the network delay. As much as I hate Teams, its meetings and voice implementation (also noise cancellation) works quite well, especially compared to current open source solutions like Jitsi or BigBlueButton.

throwaway89201··on My audio interface has SSH enabled by default
^-- ignore much of the IIRC above; I completely misremembered, I now notice after rewatching the talk.
throwaway89201··on My audio interface has SSH enabled by default
Yes indeed, that chain of exploits was all software and not hardware. Developed after the Hotz exploit and Sony subsequently shuttering OtherOS.

It didn't directly give access to anything however. IIRC they heavily relied on other complex exploits they developed themselves, as well as relying on earlier exploits they could access by rolling back the firmware by indeed abusing the ECDSA implementation. At least, that turned out to be the path of least resistance. Without earlier exploits, there would be less known about the system to work with.

Their presentation [1] [2] is still a very interesting watch.

[1] https://www.youtube.com/watch?v=5E0DkoQjCmI

[2] https://fahrplan.events.ccc.de/congress/2010/Fahrplan/attach...

throwaway89201··on My audio interface has SSH enabled by default
Cyber Resilience Act [1], which is well-intentioned, and doesn't outright forbid user access to firmware, but most vendors will take the easy road and outright block user-modifiable software (if they didn't already), so that their completely closed source, obfuscated and vulnerable version is the only version allowed on their devices.

[1] https://en.wikipedia.org/wiki/Cyber_Resilience_Act

throwaway89201··on My audio interface has SSH enabled by default
> You would have to be a Hotz tier hacker if you wanted to do anything close to this only last year

This isn't true at all. Yes, LLMs have made it dramatically easier to analyse, debug and circumvent. Both for people who didn't have the skill to do this, and for people who know how to but just cannot be bothered because it's often a grind. This specific device turned out to be barely protected against anything. No encrypted firmware, no signature checking, and built-in SSH access. This would be extremely doable for any medium skilled person without an LLM with good motivation and effort.

You're referring to George Hotz, which is known for releasing the first PS3 hypervisor exploit. The PS3 was / is fully secured against attackers, of which the mere existence of a hypervisor layer is proof of. Producing an exploit required voltage glitching on physical hardware using an FPGA [1]. Perhaps an LLM can assist with mounting such an attack, but as there's no complete feedback loop, it still would require a lot of human effort.

[1] https://rdist.root.org/2010/01/27/how-the-ps3-hypervisor-was...

throwaway89201··on State of Kdenlive
Creating the PR, doing the explanation you just did, and closing it yourself might be a good option. Then at least your code lives somewhere that someone else can reuse if desired. Ideally combined with a linked issue that you do keep open.
throwaway89201··on Reaffirming our commitment to child safety in the face of EuropeanUnion inaction
Yes indeed, thanks for the correction. It has been a complex story, and I already forgot that chapter. I edited it into my post (also modified a wrong date of the first derogation), although I'm probably missing more nuances.
throwaway89201··on Reaffirming our commitment to child safety in the face of EuropeanUnion inaction
The report you're referring to by the European Commission [1] shows that the mass surveillance of Chat Control 1.0 is probably not very proportional. They even note themselves that "The available data are insufficient to provide a definitive answer to this question".

However, the "13-20%" that you're quoting is a dishonest propaganda number itself. It's the false positive rate that a single small company (Yubo) reported. The reported false positive rates of other companies are between 0.32% and 1.5%, which is still a high error rate in absolute numbers.

Just to be clear: the report itself is full of uncertainty, convenient half truths and false causality. They for example completely rely on Big Tech platforms themselves to count false positives when a moderation decision was reversed. Microsoft apparently even claims that no user ever appealed against a decision ("No appeals reported"). There is no independent investigation into the effectiveness of the regulation at all, while it is in direct conflict with fundamental rights and required to be proportional to its goals.

The section about "children identified" is also a complete mess where most countries can't even report the most basic data, and it isn't clear if mass surveillance contributed anything to new cases at all. But somehow they still conclude "voluntary reporting in line with this Regulation appears to make a significant contribution to the protection of a large number of children", which seems extremely baseless.

[1] https://www.europarl.europa.eu/RegData/docs_autres_instituti...

Page 1 of 5Next →