HN user

HillRat

5,850 karma
Posts56
Comments948
View on HN
cameron.pfiffer.org 11mo ago

Void, the Bluesky bot that remembers everyone

HillRat
3pts0
eprint.iacr.org 1y ago

AWS introduces key committing variant of XAES-256-GCM [pdf]

HillRat
1pts0
sealng.org 1y ago

Gas companies, cruise lines threaten to sue Unicode over "greenwashing" symbol

HillRat
2pts0
github.com 2y ago

Bluesky migrates to single-tenant SQLite

HillRat
354pts233
www.techdirt.com 2y ago

TikTok proposes giving US govt control over moderation, software, security

HillRat
14pts8
arxiv.org 2y ago

Using GPT as an HVAC control system

HillRat
24pts39
www.offshore-mag.com 3y ago

Titanic “digital twin” shows shipwreck in extreme detail

HillRat
1pts0
www.cnn.com 3y ago

Montana Signs TikTok Ban into Law

HillRat
4pts1
www.buzzfeednews.com 3y ago

The (Final) Oral History of BuzzFeed News

HillRat
2pts0
sites.google.com 3y ago

Reconstructing images from human brain activity with latent diffusion

HillRat
10pts1
github.com 3y ago

Meta OPT-175B LLM training logbook [pdf]

HillRat
1pts0
www.nytimes.com 3y ago

FTC Head: Noncompetes Depress Wages and Kill Innovation

HillRat
4pts1
www.nytimes.com 3y ago

31 Hours Inside SpaceX Mission Control

HillRat
1pts0
www.washingtonpost.com 3y ago

72-year-old Congressman pursues a Master's in AI

HillRat
226pts134
foreverwars.ghost.io 3y ago

Substack Retaliates Against "Forever Wars" Editor

HillRat
29pts2
www.theguardian.com 4y ago

Farming Metals from Plants

HillRat
3pts1
theasc.com 4y ago

“The Mission”: New ASC short film for testing digital displays

HillRat
2pts0
en.wikipedia.org 4y ago

Nuclear Wargaming in the Cold War: Proud Prophet ‘83

HillRat
4pts0
www.ft.com 4y ago

How Miami became the most important city in America

HillRat
2pts0
www.nytimes.com 7y ago

Stanford researchers work on privacy-aware virtual assistant

HillRat
4pts0
papers.ssrn.com 7y ago

“Who Owns Huawei?” Perhaps the Chinese Government

HillRat
3pts0
www.nytimes.com 7y ago

Tesla ends Model 3 online sales

HillRat
2pts0
slate.com 7y ago

A tech startup turned graffiti into a crime worse than murder

HillRat
3pts0
www.globenewswire.com 7y ago

Apache promotes Unomi CDP to top-level project

HillRat
1pts0
www.eenews.net 7y ago

“The World’s Most Dangerous Malware”

HillRat
2pts0
bvaughn.github.io 9y ago

React Virtualized: Components for large data sets

HillRat
21pts1
www.jdsupra.com 9y ago

Federal appellate judge: End software patents

HillRat
3pts1
www.sciencemag.org 9y ago

Patent suit settled over palm-sized gene sequencer

HillRat
1pts0
www.dallasnews.com 9y ago

Why is the Dallas startup community turning on itself?

HillRat
1pts1
meduza.io 10y ago

Inside Russia's AI spytech startup

HillRat
13pts0

The journalist later admitted that he failed to provide the appropriate context and nuance, which comes down to "red team pen-testers who already had high-side network access were able to more quickly and effectively compromise systems when they were using Mythos as part of their workflow," which is a pretty crucial distinction to make between that and the spectre of Skynet that the article raises.

Removing the airbag impact sensor and then rewiring it to bypass the fault detection, without triggering the airbags, is also indicative of someone who has extensive experience in something no one should normally have experience in.

Say you take out a mortgage, then rent the house to a series of meth dealers to extract the rent while devaluing the property, and then default: you're still personally on the hook for any post-foreclosure deficiency judgment. One issue with LBOs is that, after extracting cash and fees, PE funds have various ways to extinguish liabilities that individuals don't, both by shielding the PE fund from debts and the use of bankruptcy and restructuring of the acquired company to discharge liabilities, including those from litigation.

There are various proposals to deal with this, but the most effective are probably imposing joint and several liability on certain kinds of litigation (breaking the "investor veil" and allowing rights of action against PE funds for the actions of their portcos) and limiting business judgment rule protection for directors and senior managers who approve LBO sales that are reasonably foreseeable to end in bankruptcy, which creates personal liability for fiduciaries. In other words, align the financial and personal interests of the individuals and companies involved with those of the acquired entity.

That's really the key problem facing US universities, from land-grant colleges to the Ivies: everyone depends at least in part on closing budgetary gaps with global students who pay full freight. Current Administration policies, both specifically targeted at foreign students and more generally at higher education and immigration, are poisoning the seed corn colleges and universities rely on. The only good news, relatively speaking, is that Europe is evidently constitutionally incapable of taking advantage of what is a genuinely one-in-an-imperial-lifetime chance to drain intellectual capital from the United States, which means that America and our higher education system can recover from this, should we have the fortitude to do so in the future -- there just isn't much in the way of competition.

Having spent a long time in the consulting world and adjacent (national security particularly) spaces, I think the most pernicious thing about "jargon" is not that it serves as a social in-group bonding signal (which is part of the problem), but that it specifically conflates actions and outcomes in a way that bypasses critical thought. The use and misuse of natsec shibboleths like "lethality" is a good example; "we're going to maximize lethality," first implies that whatever we're doing (kicking out minority groups, spending more time on PT, committing war crimes) will "maximize lethality," implies that we have a working definition of whatever "lethality" is, and, critically, implies that "lethality" is necessary for the fulfillment of whatever our actual goals are. "Lethality" is an adjective, not a goal, but the second you start sprinkling your PPT with the military adjectives du jour (lethality, resilience, survivability, full-spectrum anything) then your audience is already nodding along. These are good things! Who doesn't want to be more lethal, more survivable, more full-spectrum? But a billion dollars later, you can see that none of this actually amounted to a strategy beyond "massive transfer of taxpayer dollars to the prime-of-the-day."

The corporate world is, of course, even more prone to this; it's where the military got it from, after all. Slice out every jargonized adjective or verb from a proposal deck and see how little is often left, and how little it really addresses the user concerns.

Contemporaneous reporting was that DOGE people demanded root-level access across multiple systems (disallowed by federal policy, so political appointees had to demand the access) and without background checks or onboarding, after which they extracted protected data and shoved it in some S3 buckets. Just blew a hole right through the entire federal data protection model; you can't plan for "the President orders everyone to ignore all privacy and security controls" as a threat model.

I find myself distinctly unimpressed by the idea that slapping a nice UI and some TS/SCI controls on top of a graph database — the latter being something that NSA did, with considerably more sophistication, years prior in a Neo4J fork — is some kind of brilliant conceptual moat. Graph DBs are useful for certain kinds of problems, which happen to map well to counterterror social mapping strategies, this is nothing particularly new or noteworthy.

That's a model that works with SpaceX, which holds a unique grip on American orbital launch capability and capacity; less so for Anduril, which has been rather unsuccessful so far in its big-ticket drone-warfare efforts but has, to its credit, diversified key defense manufacturing areas by jumping into, e.g., SRMs; and possibly not at all for Palantir, which doesn't do anything a copy of Neo4J doesn't. And there's a real question regarding their ability to continue, post-DJT, holding security clearances given their personal lives and behaviors, their contacts with foreign officials, and whether they had derogatory information on other clearance holders that they did not bring forward.

In general, I would expect an identity verification firm that I'm hiring to secure and then physically delete any sensitive records my customers are uploading, unless I explicitly opt-in otherwise. My guess is in this case that Discord is attempting to train its own models for first-pass verification, so this is a training corpus; there's no evidence that Persona's doing anything with Palantir, other than proximity of funding.

The broader issue here is that SV VC is starting to feel mildly radioactive when it comes to public opinion; Persona's previous lead fund (up through its Series B) was Index, run by the more conventionally-liberal Neil Rimer, and no one worried about that. The entanglement of Silicon Valley's oligarch class in very extreme politics* at a time of very fraught national political upheaval is making VC money politically-exposed money; if you take FF or Sequioa cash, how certain are you that they won't just get involved in your business, but push you to take specific political or social positions that serve their non-fiscal interests? How certain are your customers that that isn't happening to you?

For decades, SV venture capital has been tech money, and generally smart tech money (I don't like Thiel, but the man is absolutely the smartest of the PayPal Mafia set, and his success bears that out). Now, for various reasons (the end of ZIRP, the failure of major tech bets since 2016 or so to pay off, COVID overvaluations), VCs have moved into rent-seeking, particularly on government and military contracts. It's no longer tech money, it's political money, and, compared to traditional prime vendors, it's not clear that it's smart political money. After all, when the political winds turn, possibly as soon as this November, is it a smart strategy to have worked aggressively and incessantly to alienate the party coming into power? For a lot of startups with regulatory, legal, or political exposure risk, getting entangled with that might be more trouble than it's worth.

* There is no other term that suits the mix of open white supremacy and anti-democratic policies -- repealing the 19th Amendement, for example! -- that we see emerging from the PayPal Mafia.

Recent updates say this was a unilateral call by FAA because DOD was refusing to coordinate with them for creating safety corridors for DOD drones and/or HEW usage. Issues came to a head after DOD shot down a highly threatening mylar party balloon, which FAA evidently considered to be a somewhat reckless use of military weaponry in a US city's airspace.

If you see it on the DC metro, the buyer is a Hill staffer or a Pentagon action officer; if you see it at the Super Bowl, the buyer is you (assuming you're an American taxpayer), to help maintain a certain amount of public political capital when Congress starts looking at whether they want to fully fund TR-3 and Block 4. Cutting a military program popularly seen as successful is a whole lot harder than cutting one popularly seen as a wasteful failure, and doesn't garner the politician behind it nearly as much positive PR.

Traditionally you use a lot of paper and experiential prototypes to iterate on, which doesn't cover everything but helps refine assumptions (I sometimes like starting with mocking downstream output like reports and report data, which is a quick way to test specific assumptions about the client's operations and strategic goals, which then can affect the detailed project). When I can, I also try to iterate using scenario-based wargaming, especially for complex processes with a lot of handoffs and edge cases; it lets us "chaos monkey" situations and stress-test our assumptions.

More than once early iterations have led me to call off a project and tell the client that they'd be wasting their money with us; these were problems that either could be solved more effectively internally (with process, education, or cultural changes), weren't going to be effectively addressed by the proposed project, or, quite often, because what they wanted was not what they actually needed.

Increasingly, AI technical/functional prototyping's making it into the early design process where traditionally we'd be doing clickable prototypes, letting us get cheap working prototypes in place for users to test drive and provide feedback on. I like to iterate aggressively on the data schema up front, so this fits in well with my bias towards getting the database and query models largely created during the design effort based on domain research and collaboration.

Design thinking, at least in its formal STS approach, is essentially applied sociology; it's about using various toolkits to build a sufficient understanding of a domain from the "inside out" (using desk and field research) so that you can design valuable experiences that build upon the expertise of those actually inside the domain. In this, it's a bridge between UX/product and users/stakeholders (technical stakeholders are admittedly too often an afterthought, but that's a process problem). If anyone comes in and attempts to blindly shove workshops at you without first conducting in-depth research, interviews, and field studies in your domain, then they are (without resorting to the One True Scotsman) not doing design thinking, they're doing cargo-cult brainstorming. (It's also a process orthogonal to agile development, since by definition it's a linear process that needs to be conducted prior to developing the actual product features and requirements.)

The books and papers the OP cites are solid (Rittel and Webber, Buchanan, etc., though TRIZ, I think, is rather oversold), but in my experience the problem with most design thinking practitioners is that they aren't qualified sociologists and ethnographers, so a lot of design thinking is basically a reinvention of the last century of sociological middle-range theory and ethnographic principles, without being strongly informed by either, likely due to the field's foundation in early software requirements studies.

It's not settled law as it pertains to LLMs, but, yes, creating a "statistical summary" of a book (consider, e.g., a concordance of Joyce's "Ulysses") is generally protected as fair use. However, illegally accessing pirated books to create that concordance is still illegal.

Man, back when I was doing Big Consulting (including gov't/defense) I had to affirmatively declare every year to Legal that I wasn't directing any investment purchases or doing anything that could be construed as improper use of nonpublic knowledge. And now Palantir reps just out here pushing insider trading tips like it's nothing, smdh.

Should go without saying, but since the media is doing a terrible job of reporting this, it's not at all clear what authority OSD/SecNav has to do this, given that even if there were something objectionable under the UCMJ about his statements he made those statements after retiring, and they aren't recalling him to active status (probably because a court martial would go very badly for the Navy and OSD).

It's exceedingly unlikely that this survives any administrative or legal scrutiny (and if it does, there's a whole lot of former active-status Trump allies, including GOFOs, who are more than vulnerable under these same standards); the main result, I think, is to elevate Kelly's political profile while turning most of the Pentagon even more against Hegseth and Phelan (the former being an over-promoted PAO, and the latter not even having that experience, having spent his career managing Michael Dell's money).

You have the same problem that you have with legal LLMs; an LLM is incapable of providing legal or regulatory-involved advice, and anyone using an LLM for such purposes (even leaving aside hallucinations) forfeits any justifiable reliance defense. There's a role for LLMs, but no one with legal responsibility over reporting could or would possibly rely on an LLM for complex regulatory and rules analysis, not when there's the risk of your wardrobe being replaced with orange jumpsuits.

That’s not because of the FDA, that’s because of CEPS. If the USG negotiated drug prices the way France does, there’d be far less disparity in average pricing. (Given the continual litany of safety, efficacy, and dosage control issues with imported drugs, FDA isn’t regulating them enough, largely because the inspection budget just isn’t there.)

Even now, the newspaper's reporters do so as a matter of routine.

Reporting and editorial are separate units in newspapers; the point being made is that, while reporting continues to properly disclose potential ownership conflicts of interest, editorial and op-ed, following Bezos taking direct control of them, are not doing so.

Of course, the Post is Bezos' toy, and there's no law that says he can't use editorial as a megaphone for his personal interests without disclosing them (or, in fact, even use the reporting side for the same purpose!), but you can't do that and still claim that the paper has any of the Grahams' pedigree left in it, and this is very much a change from Bezos' earlier ownership, in which he largely stayed hands-off on editorial decisions.

It’s basically sifting through ore; 99% of the people who see it aren’t the target, it’s the 1% of viewers who are buyers or funders who you otherwise couldn’t directly advertise to. Same reason you see defense contractors putting up ads for weapons systems in the DC metro.

Sign the package with hard keys and signature.

That's really the core issue. Developer-signed packages (npm's current attack model is "Eve doing a man-in-the-middle attack between npm and you," which is not exactly the most common threat here) and a transparent key registry should be minimal kit for any package manager, even though all, or at least practically all, the ecosystems are bereft of that. Hardening API surfaces with additional MFA isn't enough; you have to divorce "API authentication" from "cryptographic authentication" so that compromising one doesn't affect the other.

One thing is that a lot of economic activity was front-loaded to the first few quarters as businesses scrambled to get inventory on board ahead of tariffs; now we're seeing companies having burned through inventory, so inflationary impacts are going to start working their way through the supply chain now in earnest, and we're going to see a concomitant slowdown in economic activity as that acts as a persistent drag across multiple sectors. In practice you're looking at something equivalent to a 3-4% federal sales tax on all purchases, but keep an eye on where it falls on relatively inelastic goods, which will have an outsize effect on consumer finances.