HNHacker News
TopNewBestAskShowJobs

varenc

7,252 karma · joined September 11, 2008

MIT '09, YC S09, Dropbox '11-'16, Lingt

‎‎‎‎‎‎‎‎‎‎‎‎‎‎‎

submissionscomments
varenc··on I was impressed by Jev, please explain why I shouldn't be
I love horseback riding and do it all the time. I can't walk past an open field without wishing my horse Fawkes and I were cantering across it.

So when I heard about Jev, I was pretty excited. But as I learned more, I realized Jev can't ride horses, can't muck a stall, can't teach a flying lead change, and can't even reset a thrown shoe.

Maybe I'm doing it wrong, but I can't figure out why this exciting new thing doesn't work for my personal interest. Its lack of horseback riding support is a dealbreaker for me.

varenc··on You said no MCP
For Home Assistant, the MCP can enable the LLM to make changes without using up excessive tokens.

For example, the only way to make a change to an HA automation via the API is to POST a whole new copy of the YAML, even if changing one things. The skill and HA MCP I use allows the LLM to use tools which make more precise changes without excessive context usage.

Certainly still works either way though. And of course your LLM instance could just roll its own tools to do the exact same thing.

varenc··on ChatGPT now knows what you do on other websites via ad collector
For browsers that implement strict cookie partitioning, the privacy concern is moot. With this, the cookie jar that's used when chatgpt.com is a 3rd party site is completely separate for the jar used on the 1st party site. So your chatgpt.com account can't be linked to your ad views.

Since this has been standard ad tech for awhile, browsers have reacted to this to implement cookie partitioning for exactly these privacy reasons.

varenc··on Android 17 is the first since 3.x to add new APIs without releasing to the AOSP
> Google simply regrets android being open source.

Could Google backtrack on this if they wanted? If they suddenly decided to stop releasing public code updates, what would they be violating? I can guess: Anti-trust maybe. probable at least contractual commitments Or is there some stronger forcing function?

varenc··on Artificial intelligence now beats some of the best human forecasters
Relatedly: I suspect LLMs are influencing baby names. If you ask Claude or ChatGPT for its favorite baby names, you'll get baby names that right now are skyrocketing in terms of popularity.
varenc··on Introducing System One Models and Jev
Congrats ! Really excited for the team.
varenc··on Introducing System One Models and Jev
The output tokens are just responses to your inputed questions and their probability. So relatively few output tokens. No unstructured text back in the response.
varenc··on Introducing System One Models and Jev
I think the trouble is that Typesafe APIs don't fit into the normal OpenAI-style API that every other regular LLM provider users. You're not just providing unstructured text and getting unstructured text back. It would take a different request and response format than every other model on Open Router. Though you could shoe-horn it in some way, it'd be hacky.

But agreed it'd be very useful to see it deployed on other hubs, and it seems worth it to provide the bespoke API format. Perhaps Typesafe's API will end up becoming the standard for a new type of structured model, the way OpenAI's API did.

varenc··on I'm being cyberattacked by Tesla, Inc
I'm curious about your use of agents for security bug bounties. Do you use self hosted models? GLM 5.2? Do the economics of self-hosting make it worth it? Or if you use 3rd party hosted models, don't you run into safeguards that try to prevent hacking? (unless convincing them it's a genuine ethical bug bounty program works, but it doesn't in my experience)
varenc··on The Deathray: A simple way for an untrusted site to freeze a Mac
> notice they have a dom.webgpu.blocked-domains with the sole entries being "easyeda.com,*.easyeda.com", I wonder what that's about?

I found this issue: https://bugzilla.mozilla.org/show_bug.cgi?id=1980392 and commit: https://phabricator.services.mozilla.com/D262053

It looks like per-domain WebGPU blocking was added exclusively just for easyeda.com !

Haven't read it all, but the story seems to be that EasyEDA's WebGPU usage was broken because it relies on some aspects which Firefox hasn't implemented yet. So they made this blocklist to get Firefox to behave as if it lacked WebGPU support completely on this domain, which makes EasyEDA fallback to some other non-broken version. Maybe they couldn't get in touch with EasyEDA directly, since it seems far easier to have them just disable WebGPU for some known versions of Firefox.

varenc··on OpenAI Agents API
Their showcase examples[0] link to GitHub but the links 404. Like this one for the Slack agent: https://github.com/OpenAI-Early-Access/agents-api-python-pre...

Guessing this an early release not quite ready for the public? Interesting that there's a 'OpenAI-Early-Access' GitHub user, though of course with no public repos. Presumably when its actually public they'll move the example agent repos to another GitHub user.

[0] https://developers.openai.com/showcase/agents-api-slack-bot

edit: Maybe someone from OAI saw my comment because the links are now fixed! And they point to a public repo under the openai org: https://github.com/openai/openai-cookbook/tree/main/examples...

varenc··on Can AI design circuit boards yet?
> I think big things are coming for this world and by and large they are not ready for it.

With regard to PCB design, I'm curious if can you add more color to how the world isn't ready for this in particular? I don't think I quite grasp all the ramifications of AI becoming PCB design experts.

varenc··on Actively exploited sandbox RCE in all Chromium versions
I disagree about JIT performance not mattering. I enabled "Lockdown Mode" on iOS which disables the JIT for the mentioned security reasons, and it causes a very noticeable lagginess on many sites. Of course, the primary cause is the unnecessary JS monstrosities wasting CPU cycles. But practically speaking I can say that disabling the JIT results in a very subpar experience of many JS heavy pages.
varenc··on Data centers raise nearby temperatures by up to 4 degrees in Phoenix
Using energy always raises nearby temperatures since all energy becomes heat. If any facility is using 36 MW of electricity, then 36 MW of heat is going to be entering the environment somewhere. Though I think what's interesting here is that the effects of this extra heat is highly localized to urban areas.

But just trying to say this isn't data center specific. A steel mill with 36MW of electric arc furnaces is going to release the same 36MW of heat into the general environment.

varenc··on Degraded performance for multiple models
It's interesting that Claude for Goverment has had perfect 100% uptime in the past 90 days, while the rest of the services are around 99.4%: https://status.claude.com/

Really shows how isolated their government systems must be.

varenc··on Stealing Reasoning Traces from Proprietary LLM APIs
The part about K3 is just very strong evidence that K3 is partly a distillation of Opus. Probably even a distillation of Opus's CoT, which means they already had broken CoT encryption themselves awhile ago.
varenc··on Stealing Reasoning Traces from Proprietary LLM APIs
If CoT wasn't stateless and you instead just got a reference which pointed to the CoT stored on the lab servers, the same vulnerability would still exist. Since you just need a weaker jailbroken model to read a smarter model's CoT. This being stateless or not doesn't really matter.

The stateless part is also important for enterprise customers that require zero data retention.

(they could scope CoT access per model, but then users couldn't switch models mid-session)

varenc··on Stealing Reasoning Traces from Proprietary LLM APIs
This article shows that when Kimi3's chain of thought is prefilled to match Opus's, the rest of the chain of thoughts Kimi3 outputs very closely aligns with Opus's. That seems strong evidence that Kimi3 is partly a distillation of Opus. And Kimi3 is not a small model. No doubt a lot of hard work went into Kimi, but seems clear that distillation was used effectively as well.

(though maybe there's another interpretation of the thought alignment?)

varenc··on Stealing Reasoning Traces from Proprietary LLM APIs
By some interpretations protecting your frontier model with strong safeguards from being distilled into an open source model without safeguards is a safety issue.
varenc··on Stealing Reasoning Traces from Proprietary LLM APIs
The compaction prompt doesn't seem like the valuable thing here. I suspect they're protecting the compaction result itself. If you're trying to distill a model, collecting lots of examples on how a large conversation gets compacted to a smaller summary is particularly useful data.
varenc··on Stealing Reasoning Traces from Proprietary LLM APIs
super interesting. So pre-filling Kimi3 reasoning with Opus's reasoning results in thoughts that closely match Opus's. This seems like strong evidence Kimi3 was trained on decrypted Opus chain-of-thought. Meaning the Kimi team likely also broke CoT encryption. Though not exactly a big surprise.
varenc··on OpenAI’s head of ethics leaves less than a year after joining
HuggingFace's use of models in this incident keeps getting characterized this way but it's not true that HG used GLM-5.2 to "save them" from OAI's attack. OAI's model had already hacked and compromised HG by the time they became aware of it. GLM-5.2 was used in the post-mortem phase uncovering everything that was done. It wasn't two models battling each other live. (though that future may be coming soon)
varenc··on The AI Billboards Are Killing SF
There's been a moratorium on new billboards in SF for a long time already. No new ones are getting built. Given the reliable revenue they provide, will be a long time before they naturally go extinct.
varenc··on Web Security is Too Hard
hah thanks for the deep dive on this. I wanted to investigate myself but figured someone on HN would be faster at it. Makes sense it's not helpful, alas.
varenc··on A year of fighting scrapers on my 1.5 million-page website
Can someone help me understand the underlying motivation behind this?

It makes sense that some crawlers, in the style of Google, would want to index the entire internet. But what is the point of the same crawler re-fetching a page they already fetched an hour ago? Or possibly all this traffic is just independent entities, each trying to cache the internet? The scale of bot traffic makes this seem unlikely.

What's the motivation behind the same entity re-fetching a page it just fetched less than an hour ago?

varenc··on Americans are rallying against data centers. Surprisingly few are getting built
Theres always going to be some negative externality effecting people that live near anything getting built. Even if the operational data center isn't loud enough to be heard beyond its property lines, the construction process will be louder. I'll also negatively effect peoples views and cause generally increased activity in the area.

But that all seems fine as long as not egregious. But for anything to get built, housing or data centers or what not, we have to accept that those right next to any building project will experience some negative externalities.

varenc··on Hackerne.ws Cert Needs Updating
likely because your browser is enforcing that you always go to the HTTPS URL. Your link above works fine for me.
varenc··on Hackerne.ws Cert Needs Updating
it's not serving HTTPS at all, it's HTTP only. Port 80 is open, port 443 isn't.
varenc··on Web Security is Too Hard
Cosmically I feel like the HTTPS certificate on Cloudflare.pay should provide sufficient info to confirm it's the same entity behind Cloudflare.com
varenc··on Waymo in Dallas
It handles these circumstances. Definitely seen it cross to the other side with oncoming traffic to get around a truck blocking a lane. For the signal light, never experienced that, but I imagine after awhile it'd figure it out. Possibly with the assistance of a remote human telling it.
Page 1 of 34Next →