HNHacker News
TopNewBestAskShowJobs

vayup

298 karma · joined October 30, 2020

submissionscomments
vayup··on How Delhi cut electricity loss from 50 to 5 percent
I bet much of the savings is from reducing theft. 50 percent is too much for transmission losses.

In the industry, transmission and distribution losses are called T&D losses. Pretty much all unaccounted losses will be written off as T&D losses. Often the right expansion for T&D losses is Theft and Decoity losses :-)

vayup··on U.S. appeals court upholds designation of Anthropic as supply chain risk
They also effectively said that military contractors and their subcontractors cannot use Anthropic - that's a significant part of the economy. I mean technically, they can use Anthropic for non-military work. But in practice, they will choose not use it at all, since it's a better approach to show compliance.
vayup··on Hackers Got Inside a Flock Camera
Makes sense. Thanks.
vayup··on Hackers Got Inside a Flock Camera
Hm... not normal in my experience. Not enabling a config is not a vulnerability in itself. If not enabling something means a security guarantee is broken (Eg: videos are accessible) then it is a vulnerability, and typically included in VDP, atleast VDPs that are in good faith.
vayup··on Hackers Got Inside a Flock Camera
It's reasonable to not have a VDP for the reasons you mentioned. But not reasonable to have a useless one just so it appears they have a VDP.
vayup··on Hackers Got Inside a Flock Camera
If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP.

They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay.

Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.

And also, infrastructure vulnerabilities like DNS config - no no, try harder.

I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair.

https://www.flocksafety.com/legal/vulnerability-disclosure-p...

vayup··on Nvidia is the central bank of AI
I am a bit confused at people looking at this negatively. If Nvidia believes AI demand is extraordinarily high, and that it requires a large capital outlay to serve that capital, isn't this what they should be doing?
vayup··on LibreOffice breaks download records after declaring it has no AI features
Nah, it is probably due to AI agents' love for Libre Office. Codex prefers Libre Office for docs. Other agents may do this as well.

People who have never known about Libre Office are now downloading and using Libre Office (often without realizing it).

https://news.ycombinator.com/item?id=49527396

vayup··on Show HN: OneCLI – OSS credential gateway that keeps secrets out of AI agents
MITM is a feature now.
vayup··on Costco is the anti-Amazon
And yet, Amazon Prime is inspired by Costco membership.
vayup··on I think Anthropic and OpenAI have found product-market fit
> They've got, ballpark, $5t to $10t to make back in the next 5 years, or the hardware buildouts will start getting written down.

Depreciation and write-offs are about accounting models. Hardware will still be running after five years and still be making money. They may not be as efficient as the new hardware, but they will still be making real money even though they are valued at $0 in the books.

vayup··on OpenClaw is a security nightmare dressed up as a daydream
gogcli is good for this purpose. You can use it with openclaw or with coding agents like Codex or Claude code.
vayup··on Why some clothes shrink in the wash and how to unshrink them
Same happens to me, but I don't think it's the T-shirts that are shrinking.
vayup··on If AI replaces workers, should it also pay taxes?
We don't want a rebellion sparked by 'Taxation without representation'. Do we?
vayup··on NSA and IETF, part 3: Dodging the issues at hand
The strongest arugument made is that hybrid is more complex, more work and therefore more risky.

As someone who has been implementing such systems for 20 years, I don't buy this. In my mind, it's equivalent to saying "Seatbelts add complexity to the safety system, and it's more work. So let's get rid of it."

In this argument, the benefits of hybrid/seatbelts are not factored in adequately.

vayup··on NTSB report: Decryption of images from the Titan submersible camera [pdf] (2024)
Especially when anyone can buy the product off the shelf, remove the casing to see what they are trying to redact in these images.
vayup··on A cryptography research body held an election and they can't decrypt the results
You are absolutely right that it is easy to rule out obviously bad choices, such as 3 of 3. However, determining the actual quorum to use is a qualitative risk analysis exercise.

Considering that this is an election for a professional organization with thousands of members, I am going to go out on a limb and say that it should be easily possible to assemble a group of 5 people that the community/board trusts woudn't largely collude to break their privacy. If I were in the room, I would have advocated for 3 of 5 quorum.

But the lifecycle of the key is only a few months. That limits the availability risk a little bit, so I can be convinced to support a 2 of 3 quorum, if others feel strongly that the incremental privacy risk introduced by 3 of 5 quorum is unacceptable.

vayup··on A cryptography research body held an election and they can't decrypt the results
Few lessons to relearn here:

- Availability is a security requirement. "Availability" of critical assets just as important as "Confidentiality". While this seems like a truism, it is not uncommon to come across system designs, or even NSA/NIST specifications/points-of-view, that contradict this principle.

- Security is more than cryptography. Most secure systems fail or get compromised, not due to cryptanalytic attacks, but due to implementation and OPSEC issues.

Lastly, I am disappointed that IACR is publicly framing the root cause as an "unfortunate human mistake", and thereby throwing a distinguished member of the community under the bus. This is a system design issue; no critical system should have 3 of 3 quorum requirement. Devices die. Backups fail. People quit. People forget. People die. Anyone who has worked with computers or people know that this is what they do sometimes.

IACR's system design should have accounted for this. I wish IACR took accountability for the system design failure. I am glad that IACR is addressing this "human mistake" by making a "system design change" to 2 of 3 quorum.

vayup··on Free software scares normal people
Spot on. Defending simplicity takes a lot of energy and commitment. It is not sexy. It is a thankless job. But doing it well takes a lot of skill, skill that is often disparaged by many communities as "political non sense"[1]. It is not a surprise that free software world has this problem.

But it is not a uniquely free software world problem. It is there in the industry as well. But the marketplace serves as a reality check, and kills egregious cases.

[1] Granted, "Political non sense" is a dual-purpose skill. In our context, it can be used both for "defending simplicity", as well as "resisting meaningful progress". It's not easy to tell the difference.

vayup··on A definition of AGI
Precisely defining what "Intelligence" is will get us 95% of the way in defining "Artificial General Intelligence". I don't think we are there yet.
vayup··on Ask HN: How to boost Gemini transcription accuracy for company names?
Something along these lines, as part of the prompt, has worked for me.

               # User-Defined Dictionary
                Always use the following exact terms if they sound similar in the audio:

                ```json
                {{jsonDictionary}}
                ```
vayup··on Advice for new principal tech ICs (i.e., notes to myself)
Refers to Conway's law: https://en.wikipedia.org/wiki/Conway%27s_law
vayup··on I invited strangers to message me through a receipt printer
I read the title as "massage me", and was very confused for a few seconds.
vayup··on Claude Memory
I agree. I use this approach in my coding agent, and it works wonderfully to keep context across sessions: https://docs.cline.bot/prompting/cline-memory-bank

Even though the above link is from Cline, you can use this approach with any coding agent.

vayup··on Willow quantum chip demonstrates verifiable quantum advantage on hardware
No, it is a known problem. It will get fixed in time.
vayup··on Willow quantum chip demonstrates verifiable quantum advantage on hardware
Quantum is a known threat. There is enough time to fix it. Folks are working on the fixes.

Cryptocurrencies would be the last thing I worry about w.r.t Quantum crypto attacks. Everything would be broken. Think banks, brokerage accounts, email, text messages - everything.

vayup··on Apple M5 chip
I am sure by AI they mean Apple Intelligence:-)
vayup··on Astronomers 'image' a mysterious dark object in the distant Universe
"Momentary masters of a fraction of a dot"

- Carl Sagan in Pale Blue Dot

vayup··on Hacking the Humane AI Pin
Me too. Kudos to the team.
vayup··on Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
Some of the stuff that was extracted from the unencrypted traffic in the link:

- T-Mobile backhaul: Users' SMS, voice call contents and internet traffic content in plain text.

- AT&T Mexico cellular backhaul: Raw user internet traffic

- TelMex VOIP on satellite backhaul: Plaintext voice calls

- U.S. military: SIP traffic exposing ship names

- Mexico government and military: Unencrypted intra-government traffic

- Walmart Mexico: Unencrypted corporate emails, plaintext credentials to inventory management systems, inventory records transferred and updated using FTP

This is insane!

While it is important to work on futuristic threats such as Quantum cryptanalysis, backdoors in standardized cryptographic protocols, etc. - the unfortunate reality is that the vast majority of real-world attacks happen because basic protection is not enabled. Good reminder not take our eyes off the basics.

Page 1 of 2Next →