HN user

brutusurp

21 karma
Posts0
Comments104
View on HN
No posts found.

Quite sure I reported this JS vulnerability to Google in of December 2022. I also detailed it in a report to SEC. And I kept reporting the issue to Google teams, to which they responded for me to "check their privacy and security docs." See also https://news.ycombinator.com/threads?id=burna_aws_acct, where I commented about it on HackerNews.

But yea, give credit to Clement Lecigne of Google's Threat Analysis Group (TAG), Google's own team. This isn't the first time they've done this either.

Just lost even more respect for that entire operation at Google. So whack.

Off to make another HN account, since I just burned this one...

"I've worked with some of the leading AI practitioners and thought leaders to create a framework that outlines a new regulatory regime that would prevent potentially catastrophic damage to our country while simultaneously making sure the US advances and leads in this transformative technology."

Who are the leading AI practitioners and thought leaders?

'Finally, for the protect part, developers would have to demonstrate their AI systems are aligned with American values and that "AI developers deliver on their promise to create a better world."'

How are "American values" defined? IMO, it is especially important to have a clear understanding of what American values are moving forward, as grey area leads to interpretation "loopholes" in the audit, test, and review phases.

The article also mentions NTIA issuing a formal request for comment on "AI Accountability Policy"[1]. Deadline is 12 June 2023.

[1]https://ntia.gov/issues/artificial-intelligence/request-for-...

Berkeley Graphics 3 years ago

Wow. The zero glyphs are superb. The differentiation in shape between "O", "o" and "0" increase readability. The ligatures, while expressive, are intuitive and not over the top. Satisfying simplicity and style.

I didn't need to spend $75 on a typeface, until now.

Just tested it out. The Kandinsky 2.1 model does render high-quality images accurate to input prompt. Each iteration of a prompt produces more robust interpretation; exciting. Still working through the relationship between the positive and negative prompts.

There is a bit of a gap in understanding metaphor and reverse polarity. For instance if I include in the prompt "move away from negativity" Kandinsky produces images of sad faces (e.g., mouth curved down, downward-focused eyes). However I expected there to be an inferred "towards positivity" interpretation (e.g., eyes closed/looking forward or upward, and mouth relaxed/smiling). Trying to see how much this outcome can be achieved leveraging the negative prompt field.

Overall I'm happy with the results and will continue to use it. Thanks for sharing!

IMO this is to drive adoption. Without customers using your product, it doesn't how much anything costs; there's no revenue. Give it away, increase usership, get feedback, improve performance, and then put a price tag on it. Per usual, Amazon is tardy to the party, and must now compete against an established Copilot product (and GPT).

Brave has had this "new feature" as a default setting (i.e., block cross-site cookies). Glad Firefox has finally implemented a basic privacy feature such as this, though like you mention perhaps it's a little late.

As far as fingerprinting issue, Brave again does a better job than most, again as a default:

"If you need to use Chromium, then Brave browser is a good choice. It also randomizes fingerprint for each session, making it harder to link your browsing sessions."[1]

[1]https://www.bitestring.com/posts/2023-03-19-web-fingerprinti...

Makes me wonder how much of this is real improvement vs. publicity.

Seriously. Perhaps this article written from a multi-verse perspective, one in which the author lives in a version of the world that didn't experience one of the greatest wealth grabs of all time by C-suite and the like (their reward for repeated execution of poor and ill-timed investments, of course).

Since when is freelance "stable"? Since when is any job "stable"? It's a job, one we have to do because capitalism and healthcare. That's not stability; it's coercion.

It's well known, at least internally, that there are "data isolates" throughout AWS. Like some have said, it does preserve privacy. It also is hard to figure out what do with it after time. Do you hold? Do you delete? Is delete soft or hard? Is delete based on metadata? If yes, do you share the metadata that was used in the delete vs. no-delete decision? It's a hard problem. So, "data isolates" it is.

IMO the transaction rate is too low because the gas fees are crazy high. This is why we need actual proof-of-stake (not ETH 2.0). EOS is the first project to try an tackle this. From what I can tell, it scaled. Transactions remained fractions of a cent. EOS got caught in morality of consensus (e.g., under what conditions to reverse, how to handle disputes). However, it looks like AI can improve on this which is both terrifying and exciting.

Irrevocable disruption to the US could simply be enough countries move off the US dollar. To do that a new currency would be created/adopted. BTC serves as proof-of-concept that value is driven by sustained adoption and trade. Further, the level of sustained attacks crypto has undergone from countries such as US and China reflect the disruption crypto, as a decentralized security, has on the world economy. All this to say, it's quite possible.

Have to say, I agree with the author. It should be super easy for us to select "don't use my data" on anything we own - Github accounts, websites, anything that has our real identity attached to it. With 2FA our identities are attached to Github accounts. Further it should be equally as easy to check training data across all models to ensure our data is not included.

Glad to learn about SourceHut. I'll check it out.

In defense of crypto, decentralized currency is the way to go IMO. BTC is super expensive but it does mirror Gold reserves.

Does this mean the US is no longer the "most powerful"? Maybe so, since countries are moving off the USD, however the US could have at any time started mining BTC. I actually don't understand why the US government didn't do this already. It was so fundamentally clear (since at least 2011) that we were moving towards digital currency. And, this would most likely be a global currency that was not USD. Even in 2017, there was undeniable proof that this was the necessary path. Since that time, the crypto community met with US government on numerous occasions to help develop a strategy. It's hard to fathom why there was no "just-in-case" plan implemented in this regard.

The push by banking institutions to use XRP is suspect IMO, as other forms of digital assets have proven quite valuable (e.g., Monero, ZCash, Dash), and they've held up YoY. Beyond money transfer, we see cryptocurrencies such as FileCoin that will transform the supply chain by providing immutable record and transfer of goods. This can help solve the issue of proliferation of fake goods. I recall Amazon even talking about product verification w/o barcodes. IMO, this is long overdue.

Is it that people just don't like change? Or is it the very real and irrevocable disruption to US economy that seems to be rapidly approaching?

It should be much easier for us to select "don't use my data" on anything we own - Github accounts, websites, anything that has our real identity attached to it.

I love everything about this. As usual EU leads the way in protecting people's privacy.

[dead] 3 years ago

Yep, in a "belligerent drunk, waving a gun around" kinda way.

I wonder if this is ASIN-recycling (where ASIN is the product id), or simply a bad indexer. For instance, is it that an ASIN in location A is reused in location B? Is it that the ASIN is recycled by the lister/Amazon to maintain positive review percent on a new product? Or is it that the column(s) used to map the international comment thread to the product are incorrectly specified?