HN user

ShowalkKama

575 karma
Posts8
Comments119
View on HN

Fascinating perspective.

In today’s fast-paced scientific landscape, it’s crucial to recognize that innovation is not just about ideas — it’s about access, infrastructure, and thought leadership.

Einstein disrupted the status quo, but today’s emerging researchers must first navigate a robust ecosystem of grants, incentives, and legacy stakeholders before they can move the needle.

Food for thought.

/s

you can already gather the same information by searching online.

Do you want to know how to kill yourself? forums are for nerds. Here is wikipedia: https://en.wikipedia.org/wiki/Suicide_methods#List

Do you want to make a bomb? the first thing that came to my mind is a pressure cooker (due to news coverage). Searching "bomb with pressure cooker" yields a wikipedia article, skimming it randomly my eyes read "Step-by-step instructions for making pressure cooker bombs were published in an article titled "Make a Bomb in the Kitchen of Your Mom" in the Al-Qaeda-linked Inspire magazine in the summer of 2010, by "The AQ chef"." Searching for a mirror of the magazine we can find https://imgur.com/a/excerpts-from-inspire-magazine-issue-1-3... which has a screenshot of the instruction page. Now we can use the words in those screenshots to search for a complete issue. Here are a couple of interesting PDFs: - https://archive.org/details/Fabrica.2013/Fabrica_arabe/page/... - https://www.aclu.org/wp-content/uploads/legal-documents/25._...

the second one is quite interesting, it's some sort of legal document for nerds but from page 26 on it has what appears to be a full copy of the jihadist magazine. Remarkable exhibit.

What else do you want to know? How to make drugs? you need a watering can and a pot if you want to grow weed. want the more exotic stuff? You can find guides on reddit.

Do you also want to know how to be racist? Here are some slurs, indexed by target audience, ready for use: https://en.wikipedia.org/wiki/List_of_ethnic_slurs

knowing and thinking / assuming are two different things. Saying that "that's why people have done it" is simply and categorically wrong.

It is no doubt something that could prove interesting if shared when presenting the research (e.g. I went down this route, find this weird thing here, that unusual story there) but this article does accompany you through that process, it just presents the findings which makes the inclusion of this fact quite questionable.

the fact that more tokens = more smart should be expected given cot / thinking / other techniques that increase the model accuracy by using more tokens.

Did you test that ""caveman mode"" has similar performance to the ""normal"" model?

step 1) use a password mamager step 2) forget your own password step 3) witness the password mamager NOT autofill on phishing sites

I don't care about google pay/wallet

and if you did you could use curve pay instead. Basically the same thing with more features, the only catch is that they charge FX fees after surpassing a limit (but that can be mitigated by paying with the same currency of your linked card, thus never executing a change in the first place)

https://www.pornhub.com/blog/age-verification-in-the-news

Over the past year, Pornhub had to make the difficult decision to block access to users in the following American states due to Age Verification laws:

    Alabama
    Arizona
    Arkansas
    Florida
    Georgia
    Idaho
    Indiana
    Kansas
    Kentucky
    Mississippi
    Missouri
    Montana
    Nebraska
    North Carolina
    North Dakota
    Oklahoma
    South Carolina
    South Dakota
    Tennessee
    Texas
    Utah
    Virginia
    Wyoming

You can use them for whatever protocol you want.

the two most commons protocols used for proxying traffic support arbitrary tcp traffic. socks is quite self explanatory but http is not limited to https either!

Of course most providers might block non https traffic by doing DPI or (more realistically) refusing to proxy ports other than 80/443 but nothing is inherent to the protocol.

edit: this is also mentioned on MDN: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/...

Aside from enabling secure access to websites behind proxies, a HTTP tunnel provides a way to allow traffic that would otherwise be restricted (SSH or FTP) over the HTTP(S) protocol.

If you are running a proxy that supports CONNECT, restrict its use to a set of known ports or a configurable list of safe request targets

A loosely-configured proxy may be abused to forward traffic such as SMTP to relay spam email, for example.

under the doctrine that software "trust" is needed YOU are the attacker. It's entirely about stripping your control (thus ownership) from the hardware you paid for (see the safetynet shitshow).

wer impact?

Just because you have root it doesn't mean it's a vulnerability. Can he read the data of other customers? Can he interact with the internal network? Do you want to know how you can get code execution on microsoft's servers? Easy, go to github and spin up a github action.

The SSRF section does NOT prove SSRF, just because you can make a server interact with attacker supplied urls it doesn't automatically mean it can reach internal things and it does not automatically mean it's exploitable, far from it.

The user location leak is also not a leak since it's fair to assume that the user already knows his own physical location. It'd be interesting if there was a way to reveal the location of other users but alas that isn't mentioned, let alone proved.

If the payment method is skimmer resistant then they cannot use my payment method...

Also my entire point is that I don't need a card, paying with an app would be acceptable.

If someone is presenting themselves to you in person for entry into your bar, you have far more information to make a judgement on than the color of their skin... so it is not the same.

So the difference between "good" discrimination and "bad" discrimination is the amount of information on which the decision is based upon?

Logically then uber could add a "white only" option, "no queer" and "no leftist". (of course this is arbitrary but you can easily come up with a reason why: if you split any group of real people in two it's only natural that one group has an higher incidence of a negative trait)

This also has a second problem: what if we let the passenger know not only the sex but also if the driver ate fish in the morning (and hundreds of other useless facts)? Does that make it discrimination because they have far more information?

I guess not but then how do you decide what information is valuable in order to decide if there is enough information to judge the individual instead of going off statistics? How can you say that our theoretical racist patron is in fact racist and not going off the only valuable information?

the fact that skin color can be a proxy for socioeconomic factors does not change the statistics. Do you investigate why a rapist has raped someone and then ignore it if the reason is socioeconomic factors?

If applying your logic on skin color leads to discrimination then maybe it's discrimination even when the discriminated party is males.

Allowing women to make a selection based on this likelihood means that female customers that are alone can make choices to still use the service while reducing the overall risk.

I'm failing to see how anything you say could be used as a guideline to pick between "good" discrimination and "bad" discrimination. The major distinction you draw between "Type II" and "Type I" is the fact that one is fueled by "arbitrary aversion" which is not a particularly useful distinction.

What if I denied entry to black people from my bar because ""they commit more crimes"" and ""are more likely to break stuff"", is it morally ok? Why not? My opinion is that no, it's not ok because the majority of people punished were never going to behave in an uncivil way.

The same logic can be easily applied to this situation. Are men more likely to behave sexually inappropriately (which ranges from verbal harassment to assault)? Sure. Is it the majority? Hell no, it's nowhere close.

(Of course it's worth nothing that the "majority" does not necessarily have 50.01%, it's just an arbitrary line you can draw as long as you are consistent about it)

If your backend is trivial enough to be implemented by a large language model, what value are you providing?

I know it's a provoking question but that answers why a competitor is not a competitor.

The real thing consumers get is fraud protection

I don't need fraud protection and the ability to charge back when lunch at a restaurant, I just need a skimmer-resistant payment method (which a phone is).

If you can bypass paywalls by using google's cache feature

that is quite different. Google serves (used to serve) to its users whatever the website presents to its crawler, it does not try to avoid paywalls or interact with the website in any capacity other than requesting information

rt.com does not use Cloudflare, they are a customer of DDOS Guard:

  $ drill -Q rt.com | tee $(tty) | xargs whois | grep org-name
  91.215.41.4
  org-name:       DDOS-GUARD LTD

  $ curl --silent https://www.rt.com | grep '<title>[^<]\*</title>' | head -1
  <title>RT - Breaking News, Russia News, World News and Video</title>

how did grok gain access to this supposedly private information? Did it pilfer her private emails? Did it hack the producer's website and gained access to confidential files? Did it look through her computer?

Look, I hate grok just as much as the next person but if it was just crawled then by definition it is not private.

You may very well argue that people are harassing her (and that it's not ok), you may even argue that AI should not facilitate such harassment but to call publicly available information private is mental gymnastic.

yes, it's quite similar. They blocked some lawful services too such as google drive (yes, really) and a TON of sites behind cloudflare by blocking some of its IPs (it happened a while ago, it's not directly related to this).