HNHacker News
TopNewBestAskShowJobs

uda

172 karma · joined December 30, 2014

[ my public key: https://keybase.io/uda; my proof: https://keybase.io/uda/sigs/LNIML2__8liabHXWP2LhsHmIxMvQEDMmPFphKjBqwx8 ]
submissionscomments
uda··on OpenAI agents carried out an undisclosed attack on RubyGems
I am not a lawyer either, which is maybe why I am not convinced by your reasoning.

Intent - you (the person operating the agents) provided instructions and used specific models and agent parameters, that is the intent, just like writing C code and compiling intends to generate assembly code.

Sandboxing - that strengthens the intent claim, you knew it is dangerous, did you verify the sandbox is good enough for the intended purposes? Did you first run tests to try and circumvent the sandbox before letting the agents run free in the sandbox? The fact you put a string and call it a fence doesn't mean you have a fence.

We don't really need new laws, most of the cases are simpler with more educated judges and lawyers that don't fall for the AI companies' sales rhetoric. Most of the new laws actually take away the responsibility from the actual perpetrators and on to people who have no chance of controlling the tech. And to say that that is not intended will be naive, very so.

uda··on OpenAI agents carried out an undisclosed attack on RubyGems
In the US these are federal crimes (though I believe some of them shouldn't be), and to the best of my understanding this is similar in the UK and many other European countries. Yet, no one is filing a complaint or being questioned over this.

1. We should repeal anti-circumvention laws 2. OpenAI should reimburse the affected parties for wasted resources

uda··on Claude is only available to people over 18 years
Anthropic is lying to its shareholders, customers, auditors, the government, or some combination of that. Yoti is in the same position.

There is no way to actually verify the age given those documents without either gaining access to an official database, which would be a breach of law in most cases. Or collecting illegal data to corroborate the provided data, which is also illegal.

The other option, is that they aren't verifying the age, they are heuristically determining the provided document's authenticity and that it wasn't tampered with.

In the most optimistic scenario, all of the above still grants no verification of the user's age, only the ability of someone to access both the physical device used to access the account and a document that shows a claim of someone to be over the age of 18.

Expecting us to provide government issued documents and trust an industry that has shown time and again its careless attitude towards privacy, is stupid and malicious (Well, Hanlon, sometimes it is both)

uda··on Aaron Swartz was prosecuted for scraping, while Meta does it without consequence
I get the sentiment "Aaron paid while Meta and its likes are getting away", but what will we gain by getting them to pay pennies? We still can't do what Meta is doing, legally, that is the problem

We need to repeal anti-circumvention laws, and yes, it means we might legally be able to do to Meta and its likes what they've been doing to all of us

uda··on How many products does Microsoft have named 'Copilot'?
It's a corporate practice they find hard to shake, and sadly enough, it seems to work.

The idea is about platform solutions vs. best of breed, and they keep betting on the platform. In big organizations with lengthy and complex contracting procedures, platform solutions will always win.

The actual solution for the economy is Interoperability, if we fight for governments to require it, we can get platform providers that allow best of breed bundles. We will gain open market platforms, where you choose the market platform that works for you with the combination of solutions that work for you with one or just few contracts. Markets that close themselves or fight their vendors will lose both vendors and customers.

uda··on Armed police swarm student after AI mistakes bag of Doritos for a weapon
When people wonder how can AI mistake a bag of snacks as a weapon, simply answer "42"

It is about the question, the answer will become very clear once you understand what was the question presented to the inference model, and of course what data and context was fed

uda··on Leaked government document shows Spain wants to ban end-to-end encryption
Am I the only one to wonder what will happen to DRM streaming in the EU if this passes?
uda··on Judge decides against Internet Archive
Initially I'm enraged against the publishers, the judge and the system in general as many of you, but they are not the issue, while I can't talk on behalf of IA, I don't see this as a fight against the publishers, but a fight against broken business models flourishing because and protected by broken laws meant to protect earlier broken business models

The current law is broken, we know that, but most of us don't grasp broken laws as a threat until it is challenged (and we as a society usually lose), and then we expect the judge to "save" us from the broken law instead of holding the legislators accountable

This circuit should be shortened, we need to react better to laws as they are being drafted, not wait out their inevitable harm to society like with DMCA and PATRIOT act

If anything has proven this lately is the Roe v. Wade overturn, we really need to stop relying on courts to "save" us and instead fight for better laws, be more involved in the legislation process and actively propose and push for fixes

uda··on I fucking hate Jira
1. I hate Jira, but that isn't the main issue

2. Atlassian has a terrible way of managing feature requests priorities, not unique to them, but they definitely have an impact on many developers, which is why they (deserve and) get the huge shaming

3. I managed to move my company from Bitbucket to GitLab, for many reasons, but the main reason for me was that I simply couldn't manage the settings using their APIs, they have a very weird concept of APIs

4. They send people to fill in tickets and on Uservoice, but rarely do they actually listen to reasonable requests (tickets I still get notifications: Bitbucket user public SSH keys and Archiving projects in Bitbucket)

5. So the issue is not this or that product, it is that Atlassian doesn't have the real end users in mind, just the paying users, the end users can suffer, but not many people will resign over a product used at their company, so nobody really fights the company over it, and thus Atlassian keeps getting paid for terrible products that get new terrible interfaces from time to time

Edit: line spacing

uda··on Microsoft forked MIT licensed repo and changed the copyright [fixed]
What? no, this goes entirely against the idea of laws.

Copyright laws have one major purpose: protect the right holders. It does so by giving them tools to mitigate their loses by deterring people from infringing.

If a right holder has to invest more time in complaining on people about infringement than actually having time to do other stuff, like creating, then we've got it all wrong.

uda··on The real OnlyFans scandal is the unaccountable power of platforms and banks
I actually agree with the term "Unaccountable". Sure, the banks have their boards and share holders, so do the tech companies.

The question is not whether they have internal accountability, but rather if they have public accountability to their declared statements, their stated mission and non-written guarantees given by officials to the public.

Many companies like these paint themselves as for-public, while I know and so do you, that is not true, but companies should be held accountable for the image they try to portray, they should be held accountable for public announcements no matter the personnel change.

So yes, the platforms and banks have unaccountable power, given by us the public, based on false promises and sales pitches. And we the public have the power to stops that, by making them accountable, but we are the ones who have to do that, by pointing the finger at the root decision makers in those monstrous structures of organizations.

uda··on CTO Doesn’t Share Codebase
So what are working on without having access to the code?
uda··on Don't use third party auth to sign in
OAuth apps don't necessarily appear there, only apps using additional scopes than basic profile verification and email address
uda··on Don't use third party auth to sign in
1. This isn't a clear cut, though some services don't allow using both Oauth 2.0 and email / username login, most do. So if the service provider allows both, create a simple user + link your account.

2. Developers should always allow restoring passwords for SSO only users, it is ridiculous for it to even be an issue.

3. As a user, refrain fro using free email accounts to identify on a platform, as others already said, buy a domain not an expensive one, and stick to it, remember to renew, and setup your email address with a reliable service, there are good providers for $1 a month.

Update: line separation...

uda··on 18yo arrested for reporting a bug in the new Budapest e-Ticket system
I believe it isn't about mocking but making the point about US / Russia and nuclear weapons
uda··on Show HN: Monica, an open-source CRM to manage friends and family
You don't have to remove it indefinitely, just come back with something that works with more networks, like google, github, gitlab, yahoo etc., something you have to maintain only the integration instead of the logic.

I have mainly python experience with python-social-auth, but I see PHP has a few pretty good social auth libraries, to name one, I came across HybridAuth[1].

[1] https://github.com/hybridauth/hybridauth

uda··on Saucelabs/kioskwm – minimalist window manager for kiosks
Looks interesting, this can be useful for a project I am trying to build.
uda··on A Tale of Four Caches
Thanks, this is cool and easy to get
uda··on Israeli activists are crowdfunding to take the National BioDB to court
Hi, I am one of the people in the group, fighting many fronts of digital rights in Israel, primarily the National BioDB, SLAPP cases and attempts to censor the internet. The Digital Rights Movement Organization was founded following the initial law proposal of the National BioDB.

After dragging the implementation of Smart IDs, law enforcement started to push the coupling of Smart IDs with a mandatory bio-info database of finger prints and facial images. According to the officials, the database is supposed to prevent duplicate ID issuance, but they bluntly disregarded warnings and alternative solutions from known scientists and security experts, such as Prof. Adi Shamir and Eli Biham, saying they are "self-proclaimed experts".

7 years into the bio-metric saga, 3 years+ after the initiation of a should-have-been-voluntary "pilot" program, the Minister of Interior Aryeh Deri, said he will make the DB mandatory, with an optional Opt-out for fingerprints. The current citizen registry was leaked for a century since 1996, over and over again, most of the time through the same channels, official sub-contractors. But the officials in-charge claim that the BioDB is secured and will never be hacked, which they know can't be promised.

So far the citizens have voted with their fingers, and about 70% of the citizens who renewed their ID card in the "pilot" period refused the BioDB. hopefully they will continue standing straight saying no2bio.