HN user

bigyabai

2,654 karma
Posts7
Comments4,986
View on HN

I pity the grandpa that has to read all of this and determine if Passkeys are right for them:

According to Google, you’ll need the following to sign in with a passkey:

A laptop or desktop that runs Windows 10, macOS Ventura or ChromeOS 109 or later

A mobile device that runs iOS 16 or Android 9 or later

A hardware security key that supports the FIDO2 protocol

Google adds that your computer or mobile device will also need a supported browser, including Chrome 109, Edge 109 or Safari 16 or later.

[...] Do not create a passkey for a shared device if you don’t want other users to access your account, Google warns.

So much information, so many warnings. I feel nostalgic for passwords just sifting through this stuff.

AMD has Mesa drivers for graphics, which are better-optimized than Nvidia's proprietary Linux Vulkan drivers. It can be fixed in software, but Nvidia's only barely started to catch up.

The focus for Nvidia's GPU stack on Linux is getting CUDA working, which means that some traditional raster features get neglected.

I mean the model committed numerous crimes

"Crimes" or even "hacking" are not really that impressive. I can get GPT-2 to abet financial fraud or write exploits with the right prompt. Some people get accused of hacking crimes for just using Inspect Element. It's a moving goalpost with some very low bars to cross.

OpenAI's adversarial agent was caught almost immediately, and the entire thing was rushed out as a press release. It reads like a clickbait lab experiment more than an actual alignment concern.

are solving unprecedented mathematical and scientific problems every week now.

Nitpick; disproving a conjecture isn't "solving" anything. It's testing and breaking a theory that never had proof in the first place.

Then you must not be aware frontier lab employees are using frontier internal models to ship improvements to models via agentic loops.

We know, all their TUIs are at least 500mb on disc. It's really impressive stuff.

GLM has an extremely cheap subscription plan similar to Claude Code from Z.ai. You get Opus-level quotas with 5.2 and none of the Anthropic-style model nerfs when you ask cybersecurity questions. It's extraordinarily, preeminently accessible to anyone that wants to use it for ill or good.

We went from gpt 3 to models discovering and chaining their own zero days in a couple years. I'm not sure what else "takeoff" could possibly look like?

GPT-3 can discover and chain their own zero days too, if the targeted software is vulnerable to enough low-hanging fruit. Exploit chains are not a reflection of intelligence, but more often a reflection of architectural oversights that can be tested with common exploits like XSS or bruteforcing.

Hard to see take-off stopping or slowing down.

It's hard to see takeoff at all. This was a long-horizon adversarial task burning millions of tokens. It rolled a mediocre, detectable exploit chain, and now OpenAI is proud of it.

Case in point, GLM-5.2 has been weights-available for several weeks now. No life-changing cyber attacks have transpired, no novel chemical/biological/nuclear weapons were made in some guy's backyard.

This is also a misunderstanding of the case, though. The suit wasn't filed because of accidental Siri triggers, it was filed because Apple never informed users that third-party contractors would be listening to retained recordings of accidental invocations. From the original Guardian report:

Although Apple does not explicitly disclose it in its consumer-facing privacy documentation, a small proportion of Siri recordings are passed on to contractors working for the company around the world. https://www.theguardian.com/technology/2019/jul/26/apple-con...

Regardless of how you feel towards Apple, this sort of data should be siloed in a way that makes it impossible to share with undisclosed third-parties. It also should not be shared anywhere until Apple can confirm that PII and other sensitive information was redacted from the data, which they did not. It generally points to a laissez-faire attitude towards personal data that is hard to abdicate without seeing the Siri server-side code or retention architecture, which is why Apple settled to avoid revealing the extent to which they retain and share data in a class-action discovery process. The settlement is a mea-culpa without admitting to wrongdoing or proving fundamental security.

The lawsuit was entirely avoidable if Apple didn't play fast-and-loose with production databases. It'll be a black eye for anyone that points to Apple's whitepapers as an example of their commitment to security - some retention simply doesn't get documented by Apple.

Conversely, the United States is now embroiled deeper in asymmetric warfare than ever before. US-based systems are being exploited by Chinese efforts like Salt Typhoon and raising questions about reciprocal attacks. Other targets of US soft-power like Iran (Stuxnet victim) are escalating their hacking efforts and using Chinese technology to stifle American command and control.

I can believe that NOBUS and other backdoors were ignored for a long time, but I have a hard time believing that it's being ignored by the current administration.

Qwen 3.8 1 day ago

Can you substantiate your belief, or is it just a feeling?

I'm not saying that you're necessarily wrong, but you're certainly lacking evidence. It would be easier to buy into your speculation if you could explain what limits current LLMs, and how they could be optimized to create a step-change in prose generation or reasoning capability.

Part of me wonders if the US Government is muzzling Anthropic and OpenAI so they can stockpile NOBUS exploits: https://en.wikipedia.org/wiki/NOBUS

There would be a decently large incentive to restrict these models if they could be used to patch (or discover) dangerous payloads. In larger projects like Windows or Chrome, there might still be dozens of unpatched exploits that are too subtle to catch with smaller models.

1) I'm not using AI to bicker over fringe political shibboleths.

2) I don't think it is any more or less safe to put my code on a Chinese server versus an American one. A Chinese provider also isn't liable to spy on me for the feds, as OpenAI and Anthropic certainly do.

Unified Memory simply isn't viable at the scale that a full Nvidia cluster operates at, and it would hamstring the parallelism that gives these clusters an edge. The current solution of Mellanox-style interconnect is probably still going to be the status quo in 5 or 10 years.

Qwen 3.8 2 days ago

The point is that the 1st country to achieve that leap will get to use it to gain advantages in literally every sector.

That's still speculative. We have something of a basis for speculation with the way LLMs influenced software engineering, but it's not necessarily applicable to "literally every sector" of scientific progress. If their quantum leap is anything like vibe coding, then it will quickly become an unmanageable cesspit lacking accountability and grasping at notoriety. We have precious little to show for half a decade of LLM-generated code, nobody disrupted the FAANG incumbents by using an LLM to crack the digital secrets of the universe.

The safety angle played its card and lost. We've been generating trillions upon trillions of tokens, and nobody has raised the dead or made The Bomb with red mercury. Smarter AI clearly isn't a panacea.

I get some people are hoping that AI research is for the benefit of all, and I do too, but that is wishful thinking.

You're way too lost in the plot. Technology can absolutely be used for ill, and no doubt AI has already contributed to reprehensible things. But it cannot turn lead into gold. It cannot reveal the face of God or compute The Answer to the Ultimate Question of Life, the Universe and Everything. The ultimate threat of AI is the stuff it can already do - cosine similarity search on billions of discrete records, automated labeling with computer vision, multimodal analysis and corroboration pipelines. The hypothetical scenario where superintelligence is made is a thought-terminating cliche that is driving people into a zealous fervor.

We have nurtured a culture of radical tolerance.

Play radical games, win radical prizes. The last place I want my money going is towards radical authoritarianism, a cause that I thought Mullvad would thoroughly oppose.

Self-censorship out of fear is an even bigger dampener than direct censorship.

Bullshit. Self-censorship is a self-preservation mechanism, a VPN doesn't change the consequences of saying illegal or offensive things. Direct censorship is an abuse of the monopoly on power, and much more inhumane than just feeling insecure about your edgy ideas being attached to your identity.