HN user

anonym29

1,953 karma

Stallman was right, information wants to be free, and there is no such thing as a friendly vulnerability, a friendly intelligence agency, or a friendly government.

Posts14
Comments1,591
View on HN
Qwen 3.8 4 days ago

safety datasets and a lot of safety related research

If you're using Windows on a personal device in the first place, you're pretty loudly declaring that your consent doesn't matter anyway.

That's not your computer, that's Microsoft's computer. You're the threat model they lock it down against, you're the schmuck that keeps them fed, and you're the possible terrorist/hacker to be surveilled, tagged, tracked, and monitored.

If you care about consent as it relates to your use of technology, you shouldn't be using Windows in the first place, and this has been obvious for well over a decade now.

Keep in mind, the data you just linked is all firearm deaths, not just firearm homicides, and that a majority of all firearm deaths in the USA (over 60%) are suicides, not homicides or accidents.

What you're seeing in Alaska and Wyoming and New Mexico is overwhelmingly suicides correlated with social isolation (Alaska, Wyoming), high rates of poverty (New Mexico), and SAD (Alaska), not an epidemic of violent shootings.

The correlation coefficient between gun ownership and firearm homicides at a state level is 0.22.

The correlation coefficient between gun ownership and firearm suicide at a state level 0.84.

Note that Illinois (Chicago) and Maryland (Baltimore) both have above-average firearm homicide with below average firearm ownership, while Idaho and Maine have above average firearm ownership and significantly below-average firearm homicide.

The drivers of homicide are overwhelmingly urban violence, poverty, and illicit markets, not the firearms themselves.

Sure, but 5.5 per 100,000 is still extremely rare, and even that number obscures a highly bimodal distribution that largely tracks race. In Massachusetts, the rate drops to 0.7 per 100,000, while in Mississippi and Louisiana it's over 8 per 100,000.

From ages 1-19, that means the cumulative risk varies by about an order of magnitude even just at the state level before diving into specific cities or communities - there's cumulatively about a 1/750 chance of a kid dying from firearm violence in Louisiana or Mississippi from 1-19, or about a 1/7500 chance of a kid dying from firearm violence in Massachusetts.

The national figure might look scary (even though it's still a tiny, remote risk that most people never have to seriously worry about), but that's only because it blends a high-incidence minority with a low-incidence majority.

Looking at the national figure alone as representative of the whole country is like looking at the number of people who are imprisoned across Europe for being LGBT and being shocked at how much higher that figure is than in the USA - it's really all just Russia, a minority of Europe as a whole, responsible for a majority of the mortifying criminalization. It's disingenuous to insinuate that Europe as a whole is anti-LGBT because of Russian criminalization, just as it's disingenuous to insinuate that America as a whole is a dangerous place filled with gun violence, largely because of one demographic subset that is itself concentrated across a few small areas.

Extremely rarely from a gun. And even when it is from a gun, it's not your kid dying from a gun, it's hundreds to thousands of "kids" (young teenagers) in places like Detroit and Chicago who have chosen an early career in armed carjacking and gang warfare, that skew the statistics for the entire nation.

If you remove shootings committed by African Americans (which are overwhelmingly against other African Americans), America's gun violence rate per capita drops below that of Canada, below the Czech Republic, close to the EU average. See: https://www.cdc.gov/mmwr/volumes/72/wr/mm7242a4.htm

Gun violence is something that the vast majority of Americans will never personally witness or experience, and will never even know anyone who has personally witnessed or experienced it.

The key difference between xAI and Anthropic/OAI/Google is that xAI has the least-likely path to existing as viable business in a decade.

I don't know, renting out a fleet of GPUs at annualized rate of ~100% of the capex deployed to obtain said GPUs seems reasonably better than lighting hundreds of billions of dollars on fire in order to earn tens of billions of dollars.

The odds a child will be killed by an armed assailant at a school in the USA are about 1 in 5 million per year, and if you narrow down to mass shootings at schools, that drops to about 1 in 10 million.

Between 2013 and 2022, a total of 77 students in grades K-12 have been killed in 11 school mass shootings, in a country with 50 million school children.

A child in America is about 500-600x more likely to die in a car accident than a school shooting.

A child in America is about 90-120x more likely to die from a pedestrian fatality than a school shooting.

A child in America is 70-90x more likely to die from choking than a school shooting.

A child in America is 50-60x more likely to die from drowning than a school shooting.

A child in America is 40-55x more likely to die in a fire or from smoke than a school shooting.

A child in America is 10-15x more likely to die in a bicycle accident not involving a motor vehicle than from a school shooting.

Comparable risks to dying in a school shooting include a fatal sting from a bee or wasp, (about twice a likely), or dying from being struck by lightning (about half as likely).

School shootings, while tragic, do not pose nearly as much of a statistical threat as you think they do, even if they still pose more than they ought to.

CO2 emissions have been consistently declining in both the USA and Europe for over 2 decades now. The bulk of the CO2 increase over that time period comes from China and India.

Americans also invented the solar photovoltaic panel. You're welcome.

Also, since we're playing this game right now, I'd be remiss to not remind you that American individuals do over an order of magnitude more charitable giving than the entire EU combined, on a raw dollar basis.

Speaking of giving - since 2014, the EU has purchased approximate €700-€900 billion worth of oil and natural gas alone from Russia (total EU imports from Russia exceed €1T in that time period), while offering less than €300 billion in support to Ukraine.

The EU is responsible for funding Russia's invasion of Ukraine, and has given more than twice as much money to Russia than it has to Ukraine.

America, on the other hand, has appropriated nearly $200B to Ukraine (over $100B in direct aid), yet paid only a tiny fraction of that to total Russian imports since 2014.

In other words, America is a net economic supporter of Ukraine, while the EU is a net economic supporter of Russia.

You are not "the good guys" that you think are.

Training kids how to respond to school shootings is like training kids how to respond to dual engine failures on an airplane.

It happens, it's just statistically so unlikely to ever happen to your kid, that the drill essentially serves as ideological propaganda reinforcing fear of the idea of the threat far above and beyond the statistical risk actually posed by the threat itself.

And as a reminder, Europe sees more people die to heat than America sees people die to guns.

https://fortune.com/2026/06/26/heat-death-europe-ac-american...

Maybe your guild should figure out how to beat the PvE server before lecturing the players on the PvP server on how ridiculous you think our freedom is. Major skill issue, noob.

I guess better phrasing would be auditability, ease of codebase comprehension, coverage of just the features I want. My agent isn't meant to be for X users across Y providers with Z extensible plugins, it's meant for exactly one user, with exactly one provider, and to minimize the amount of trust granted to third parties.

Bloated TUI library, unified multi-provider LLM layer, bloated RPC and SDK modes, the entire plugin framework, the list goes on and on.

For reference, pi-coding-agent, by itself (not including dependencies, tests, or pi-ai, pi-tui, pi-agent-core, etc), is ~41,653 SLOC taking up ~1658.9 KiB across 163 files.

My agent, excluding dependencies (all go stdlib) and tests, is 3 files, 946 SLOC, taking up 36.3 KiB, and includes a basic TUI and an XMPP transport channel (including TLS for XMPP), with dynamically configurable delivery to and receipt from either or both, including allowlists for XMPP message partners. It has tool calling, a permission model with whitelisting and interactive permission querying on a per-tool basis, full thinking support, including the ability to toggle hiding or showing it across either or both transports repeatedly throughout an individual session, the same tools as pi comes with out of the box, plus web search, and a tool to vet, build, and git commit golang projects all in one go, stopping if errors are observed. Configurable model and endpoint, too.

Incidentally, the open source xmpp server (prosody) and metasearch engine (SearXNG) are both self-hosted, too.

Pi has way too many batteries included, including a bunch I don't want, and lacked the batteries I did want. Pi is a bit like the movie Idiocracy in that the idea is much better than the execution.

Incidentally, I also have zero supply chain attack surface as I have zero dependencies in my agent, just go stdlib. Pi, again, has 130+ transitive dependencies asking me to trust the security of my system to 150+ additional people I've never met in exchange for a bunch of bloat I do not want.

Yes. In my case, the virus became active after severe and chronic sleep deprivation one summer where I tried experimenting with going from a 16/8 sleep schedule to a 24/12 sleep schedule, on a now-resoundingly-disproven hypothesis that the ratio of waking hours to sleeping hours was more important than the absolute number of each for healthy functioning.

Stress and sleep deprivation are known triggers for the virus, which lies dormant in the nervous system for life after initial infection, and can be dormant for decades at a time between reactivations.

At a minimum, you need an inference endpoint: either cloud or local.

If going local, llama.cpp is going to be the more beginner friendly local inference engine that supports more processor types (AMD GPUs, Intel GPUs, CPUs, anything that supports Vulkan, not just Nvidia). LM Studio is a nice wrapper for this if you'd rather avoid cloning repo and compiling yourself, provided you don't mind closed source software; it's much less enshittified than Ollama.

If going local, you will also need model weights in the right format for your inference engine, and with a model that can fit on your hardware. This is going to be .GGUF files if you're using llama.cpp or a wrapper for it like LM Studio.

From there, pick a language, go look up the OpenAI /chat/completions API format (or Anthropic's "Responses" API format), create a DS or array or slice to store messages, and build a loop that accepts user input, formats it according to the API format, sends it to the inference server, retrieves and parses the response, adds the response to the DS/array/slice, and repeat.

There's a lot more beyond this - tool calling, other API formats (optionally), MCP servers, transport layers besides terminal stdin/stdout, permission models, starting with a system message, clearing your message stack correctly (hint: don't reset it mid tool-call), message compaction, web searching and page fetching, semantic search RAG over embeddings, memory layers - way too much to cover exhaustively in a single message.

The antibodies you develop to fight the virus fade over time. I just had it fairly recently (young 30s, vaccinated with the attenuated chickenpox virus, never had chickenpox, so this was likely the vaccine strain¹). Did a lot of reading and research during and after. The antibodies seem to offer good protection for 5-10 years following either vaccination or infection according to the literature I was reading.

¹ The vaccine strain tends to be much more mild than the wild strain, and indeed it was quite unpleasant, but not extremely painful for me. The wild strain is considerably more painful and linked to a greater incidence rate of complications. Please do not skip chickenpox vaccinations for your kids, the minor risk of latent infection from attenuated vaccine is far less harmful than the consequences of not vaccinating. Most important of all, if you have a cluster of blisters or rash on one side of your body that keep popping up, make sure to see a doctor and get on antivirals within the first 72 hours for best results.

It very explicitly guesses that she is black, based solely on statistical inference.

From TFA: "Statistics suggest that Maria was undoubtedly poor and, most likely, Black."

To read this as established fact is analogous to asserting as established fact that if you roll a six-sided die, you will certainly get a number <= 4. Probable, but not fact.

A careful read also reveals that none of the woman's actual identifying information was revealed, including her name, for her own privacy:

"We’ll call her Maria, the most common female name in Brazil, because authorities have not disclosed her real name in order to protect her identity."

Follow-up edit: thank you for your correction, I appreciate the epistemic humility and good-faith dialogue.

Then we set the bar for hiring to requiring a degree making it so that if you want anything above minimum wage, you’re going to have to get a degree.

While this may have been true in the past, this is no longer the case, and it has not been the case for at least a decade and change now, at least in the US.

If you are intelligent and self-motivated to learn in-demand skills, and you can demonstrate those skills, and adapt well to a corporate environment, there is a path for you even without a degree. Yes, not every door is open to you, but that doesn't mean all the good doors are closed.

I've been on hiring committees where I interviewed Ivy League CS grads for SWE positions who couldn't do leetcode easies, tasks like defanging an IP address, in a language of their choice, with clear instructions, active guidance from me, and permission to search the web for syntax (but not solutions), and an entire hour to solve it.

As a means of delivering credible social proof of competency, legacy admissions and grade inflation have all but ruined college degrees.

We live in era where essentially all recorded human knowledge is available for free, instantaneously, 24/7, from a device that fits in your pocket and works from just about anywhere, and this has been the case for my entire career. As of more recently, $20/mo gets you a personal 1:1 tutor that knows more than every college professor you've ever seen combined, is available to you 24/7, never judges you for stupid questions, never gets tired of re-explaining concepts to you that you're struggling with, will write a study plan / syllabus perfectly tailored to your existing knowledge and schedule, complete with links to reading material, generate interactive quizzes and tests for you, etc.

College as a means of delivering information is about 30 years out of date at this point, and college as a means of delivering a tailored education is now about 4 years out of date.

In the words of Peter Gregory, college has become a cruel joke on the poor and middle class.

You raise some good points here, but PoW is meant to be one tool in the toolbox, not the only line of defense. You can still maintain blocklists of known scrapers (or better yet, have your PoW system be aware of them and silently adjust the difficulty to an impossible level, such that the scraper gets stuck trying to solve your PoW challenge until it hits a timeout configured by the scraper, if they were wise enough to configure one). It's also courteous to not only build and maintain your own blocklists, but to share them with e.g. vtotal and spamhaus, to help protect others.

Similarly, you have tarpits, which generate infinite mazes of garbage data, or even deliberately poisoning training data (should the scrapers be training LLMs) though this don't entirely eliminate the deleterious effects of scraping on the host's web server (more info: https://arstechnica.com/tech-policy/2025/01/ai-haters-build-...).

If the premise was evaluating whether or not PoW would be a magic silver bullet that stops scrapers all by itself, then you are correct, it does not stop all scrapers. Scraping and anti-scraping is fundamentally a constantly evolving cat and mouse game that demands adaptability and punishes complacency from all participants trying not to lose.

Ah, I see what you're getting at. Yes. You can think of any given computer aa having a fixed amount of compute budget for these types of acceleration-resistant hashing algorithms. Let's say the scraper can perform 10,000 hashing operations per second total on their machine, and needs an average of 1,000 hashing operations to solve the PoW. It's a minor detail, but note that these PoW challenges non-deterministically vary in the number of hashing operations needed to produce a valid hash, not dissimilar to bitcoin mining, where a hash with a certain number of 0s prefixed is sought, and the scraper essentially has to brute force through all possible inputs until an input that produces a valid hash is found.

In a well-designed PoW systems, there is a per-site prefix or suffix that is required to be prepended or appended to these random inputs, and it may change not only between websites, but even between PoW sessions on the same website, and should not be predictable - only being disclosed to the client at the time the PoW challenge is issued. In such a case, the scraper cannot simply precompute a bunch of valid hashes that work across multiple sites, nor a bunch of valid hashes that will always be good for even one site, the scraper operator will need to compute these hashes (with a limited budget to do so) upon initiating each PoW session.

Typically, the machine doing the content processing, including solving PoW, is the centralized "control" node described in the article, not the machines who's IP addresses are being used. In typical residential proxy networks, the residential proxies are exposed to the customer (the person paying for and using the proxies) as just SOCKS5 addresses, and no computational power from those compromised devices is made available for the scraper besides that used to power the SOCKS5 server itself, the customer is just paying for the transport and address (and indeed, is often billed on either a per-GB or per-IP basis).

In effect, if the customer (the entity paying for and using the proxies) wants to solve PoW challenges through those connections, it is indeed the customer who must pay that compute cost, not the compromised devices.

Note that this is the case for a majority of, but not all, residential proxy networks, which often are built through quasi-voluntary distribution channels, including SDKs included in otherwise legitimate mobile applications distributed through Apple's App Store and Google Play.

These distribution channels tend to be categorically unavailable (or at least unreliable) for true RAT-style malware that enables remote operators to dynamically assign arbitrary computational workloads to client devices.

This isn't to say that true botnets built with actual malware delivered through either software exploits, phishing attacks, or watering hole attacks don't also perform as residential proxy networks, but such categories are a relatively small subset of all residential proxy networks, and there are much higher ROI malicious activities to be performed on these devices rather than serving as relatively mundane traffic networks for scraping.

It's not about traffic identification at all, but rather a hashing algorithm that is deliberately resistant to parallelization and GPU/ASIC acceleration, which shrinks the gap in solving speed between the fastest systems (i.e. datacenter-class compute resources) and typical systems (e.g. the CPU in your smartphone or laptop).

Most users of residential proxies just get a SOCKS5 address and routing, they don't actually get computational resources of the infected systems beyond that. The user of the proxies, the operator of what the article describes as a control node, would be the device responsible for the PoW.

Do you have any evidence that AI providers aren't using residential proxies?

Reciprocity is great when all parties contribute equal amounts, all parties receive an equal share of the benefit, and the arrangement is strictly voluntary. Think toll roads where everyone pays the same price, only the people using the road pay for it, and everyone using it benefits from it.

It's less great when some parties are expected to give more than they receive in return (in order to provide for those who give less than they receive in return), without their consent, enforced by the state's monopoly on lawful violence, and are demonized for so little as daring to express dissatisfaction with the involuntary arrangement.