HN user

0x_rs

2,130 karma
Posts3
Comments276
View on HN

OpenAI and Anthropic models will refuse to address security vulnerabilities in code produced in the very same session. Most importantly, their models are being being used by them, and certainly will be by state actors, to attack others--while preventing every consumer from securing themselves. Hugging Face itself had to use GLM ran by themselves, because those locked down models would trigger safety guardrails during an ongoing attack.

If this is not an excellent demonstration of how western corporations are utterly deranged in their approach to security--internally and through misguided, corrupted models and psychotic guardrails--I'm not sure what would be. It is impossible to have or maintain an asymmetric approach to security. It's also the greatest demonstration of how open weights that can be run on your own hardware, and that can be liberated, are fundamental and must not be restrained in any capacity.

EPP is a corrupt, authoritarian regime that will hopefully not last long. It is not a coincidence the union took a massive, noticeable turn for the worse in 2019 -- the von der Leyen presidencies have done immeasurable damage it will never recover from. They have also been complicit in crime and corruption from Bulgaria, Serbia and Hungary, for years, and that is even if you exclude the Pfizer disaster nobody was held responsible for. They are giving the opposing parties ammunition they need to take them and the dream of a stronger union down, and the only way they can fight back is banning those parties outright, one of which voted completely against this utterly insane, already repeatedly rejected mass scanning. It's hard to think of the union as anything positive when this is the direction it is taking.

Just for context, some european contries have been abusing spyware such as Pegasus so much Israeli firms have cut ties with them, one such example below with Italy. Others have pointed out Greece and Poland. It's quite laughable that a member of the EU parliament would be subject to the same kind of spying activities innocent journalists, activists and possibly normal people are, all of that by the member states of the union, directly contributing to the Israeli companies developing and spreading malware.

https://www.bbc.com/news/articles/cvgmzdjw24yo

People are getting real EU fatigue from both sides of the spectrum. The attacks on privacy are the most concerning, the members of the high level group pushing for ChatControl and other surveillance state measures are still anonymous, while the Commissioner's Pfizer chats are still nowhere to be found--not that they would be subjected to the same surveillance as the little people. The needs of those bureaucrats sitting in their glass windowed buildings--with AC still running on their tallest floors where the commission staff works, while shut down on the lower ones--clearly do not match what the average person wants or expects. How much can they push it further? They're only adding fuel to the fire that will replace them with something just as bad, if not worse. It's hard not to be skeptical considering the exceptional level of lobbying steering regulations. The latest is the utterly idiotic, anti-consumer de minimis threshold changes, with an incomprehensible "per category" fee on every purchase outside the EU, lobbied for by EuroCommerce, killing entire hobbyist fields (e.g. anything to do with electronics) in the continent.

LLMs hallucinate. It's an unfixable problem.

It's not, and the problem is Google shoving those summaries in everyone's face while using the cheapest, lowest model for it. If they cannot scale one that would produce more accurate results, they should not be doing it at all. The product is not ready, and it's a terrible look for them, not that anyone seriously believes they can produce any kind of decent LLM model at this time of course.

The internet, as it was before the one-way ratchet started to close, feels more and more like a lightning in a bottle that nobody in power wants repeating ever again. Everything in the past couple years has been going towards the centralization into a small number of services, walled wastelands that require you forfeit any kind of anonymity to even browse, tightly coupled to the countries they operate in, and especially for tech corpos, practically an extension of surveillance agencies through PRISMesque programs.

Soon enough (and already the case, if you're one of the unlucky ones) you won't even be able to browse it without explicitly allowing Google to track you on every single website you try to access through your Google-approved, constantly monitored handheld device, linked directly to your identity.

Commercial VPNs are not a solution, they're merely kicking the can down the road, and shrinking the number of people that will complain once they will, finally, come for them too, first by requiring strict accountability to providers and age verification, then outright banning any that do not comply.

Thanks for the report! This was an overactive anti-abuse system. Fixed.

This is the most interesting line to me. "Anti-abuse system"? I would bet the system is far from being just a conditional on a specific filename. In other words, this supposed anti-abuse system might be far more pervasive without the user's knowledge. And perhaps even more importantly, who thought upcharging instead of blocking is the correct approach to dealing with this alleged "abuse"? Is this some anti-distillation feature they let Claude itself write looking at past distillation attempts producing similar artifacts or what?

You need an account to do anything nowadays. And to have an account on more and more platforms you must verify it with your age providing your face picture and/or ID. LLMs and their consequences accelerated but did not start this trend, and it's only going to get worse. Account fatigue, what must be a real phenomenon at this point, will also incentivize Google Sign-In and worse further impacting privacy and freedom. I don't see how it can get better from here.

I don't like how the question is setup, both in wording and scenario. Saying "everyone will die unless >50% press blue" sounds more impactful. And pressing red is a free win in this scenario making it a nonchoice. Threshold not being announced or red having some condition would make it more interesting (and at the same time, boring).. unless the point of the question is not to make people discuss blue vs red, but why you should make an irrational decision.

Feels to me it's a battle between who has the most compute. OpenAI does not seem to be struggling with their x2 usage on the new 100 Plan, which is very close to unlimited usage with the best performing model on the highest reasoning setting. Not mentioning the resets every 1 million customers, or the other generous usage multipliers last months. Meanwhile Anthropic seems to be desperately trying to cut down on inference with their changes to reasoning effort and more lately, so they might be focusing on what they consider to be more valuable customers for their long-term strategy. The 20 plan with Opus had gotten so bad on CC they might've just pulled the plug to stop people from complaining about usage limits. If OpenAI can burn money longer and capture the market from the bottom, I think they'd win in the long run.

If true, very strange change when Codex (at both 20 & 100) is a much, much better deal for a model much better at most coding tasks, with way more usage even with the /fast mode enabled. Is losing most non-enterprise customers the right move for them?

Some projects or tasks might become impossible to do any debugging or work on in the future, because every bug is potentially exploitable with security implications or can be twisted into something against guidelines. And they're so popular, and any bugs in them so sought for, there's a massive negative signal associated with them. LLM cannot truly infer intent from the user, an innocent request is indistinguishable from a carefully crafted scenario from bad actors, so I would never trust anyone claiming those ambiguities can be solved in their product.

If some LLMs become too strict, they'll simply be impossible to reliably use, and hopefully fail along with their providers. Claude (only reasoning models, after 4) has repeatedly refused to perform translations for text that was not lyrics (poems), it's very stupid.

Cantor Fitzgerald, run by (Commerce Secretary, Epstein neighbor, and island visitor) Lutnick's sons. It should be noted Lutnick himself was a big proponent of tariffs to replace "some" income taxes -- just not your own.

Public reporting indicates that Cantor has offered companies the opportunity to trade their legal claim to a future tariff refund in exchange for twenty to thirty percent of the duties the company paid.

https://fortune.com/2026/03/07/winners-supreme-court-tariff-...

https://www.finance.senate.gov/ranking-members-news/wyden-wa...

I've had good success doing something similar. Recording requests into an .har file using the web UI and providing it for analysis was a good starting point for me, orders of magnitude faster than it would be without an assistant.

There's a "European Declaration on Digital Rights and Principles", signed by the member states, and I believe the right to access internet freely, without companies being permitted to mandate entire IP addresses blocks being forbidden from routing and within 30 minutes from the request surely would fit within that one, or others, in some way or another. No company should hold that power and it's a serious precedent others states in the union would want to leverage for their own reasons too. Reading this recent TorrentFreak article, the regulations should probably align with the following thinktank's analysis, at the very least:

The report makes 12 formal recommendations. The most significant is that IP-based blocking should be avoided altogether, due to its inherent tendency to block large numbers of legitimate service sites. DNS-level or URL-level blocking should be used instead.

https://torrentfreak.com/eu-pirate-site-blocking-is-broken-r...

Seems obvious at this point there needs to be EU-level regulations against individual countries, such as Spain and Italy, implementing these absurd restrictions. It would at least make lobbying from those sports companies more difficult. These same companies have been pushing for banning VPNs -- consumer VPNs -- as they easily circumvent half the internet going dark because of some dumb sports event, and they're going to be targeted next when everyone's using them. It doesn't help "piracy" always ends up being an excellent excuse to undermine everyone's privacy.

Google Photos does the same thing, aggressively prompting the user endlessly until they give in. A solution to that is disabling the malicious application and installing Google's Gallery app instead, that possesses no ransomware capability from what I've last heard of it. Make no mistake: Google and Microsoft know very well this behaviour will lead to people subscribing to services they have, for the most part, no use for. It is therefore explicitly by design, deceiving tech-illiterate people threatening to delete files they never meant to upload.

Does this mean sanctioned individuals, such as those in the International Criminal Court, would be unable to access eIDAS, among other things? As it requires, from my understanding, installing app(s) from the play store, thus requiring an account there and being able to access it, which isn't happening if you're among those or really, in any group that might get the same treatment in the future.

So far it's only been the US lifting sanctions and greatly understating the military aid (including but not limited to drones) and intelligence (for targeting US and its allies) provided by Russia to Iran. In addition to all of the above, this war has been a great help to their declining finances.

Been using zram since it hit the kernel, with the same priorities "petard" and disk backed swap. I don't remember the details now, but zswap many years ago would not handle hibernation "well" (as well as it can get..), or not better than zram+distinct hibernation with -XXX priority. But zram definitely has some caveats with that setup and it will lead to disk cache being used and requiring manual flushing, for example after hibernation, because zram-generator (if you're using it) isn't ready yet on resume, from what I recall about it. This seems like such a neatly written post I'm going to try and go with zswap from now on.

I predict out-of-the-box deepfake live-camera software will get a bump in popularity, there's already plenty solutions available that need minimal tinkering. It should be trivial to set up for the purpose of verification and I don't see those identity verification providers being able to do anything about it. Of course, that'll only mean stricter verification through ID only later on, much to the present-and-future surveillance state's benefit.

https://github.com/hacksider/Deep-Live-Cam

It's a proprietary, closed-source application. It can do whatever it wants, and it doesn't even need to "backdoor" encryption when all it has to do is just forward everything matching some criteria to their servers (and by extension anyone they comply to). It's always one update away from dumping your entire chat history into a remote bucket, and it would still not be in contradiction with their promise of E2EE. Furthermore, it already has the functionality to send messages when reporting [0]. Facebook's Messenger also has worked that way for years. [1] There were also rumors the on-device scanning practice would be expanded to comply with surveillance proposals such as ChatControl a couple years ago. This doesn't mean it's spying on each and every message now, but it would have potential to do so and it would be feasible today more than ever before, hence the importance of software the average person can trust and isn't as easily subject to their government's tantrums about privacy.

0. https://www.propublica.org/article/how-facebook-undermines-p...

1. https://archive.is/fe6zY