HN user

dannyobrien

5,087 karma

EFF, CPJ, now at Filecoin Foundation (for the Decentralized Web). Coined "life hacks" (sorry), wrote http://www.ntk.net/ , co-founded https://www.openrightsgroup.org/ .

[ my public key: https://keybase.io/malaclyps; my proof: https://keybase.io/malaclyps/sigs/Te_kJq5oVspmHK7CS9NSFnEgjpWrTgofYGP1M_BCgik ]

Email: danny@spesh.com Web: https://danny.spesh.com/

Posts88
Comments551
View on HN
docs.agntcy.org 6d ago

Agntcy – Open Infrastructure for the Internet of Agents

dannyobrien
2pts0
www.openassistivetech.org 1mo ago

How I play video games with spinal muscular atrophy

dannyobrien
175pts23
bab-hash.org 1mo ago

Verifiable partial data for peer-to-peer systems

dannyobrien
2pts0
www.somewhereville.com 1mo ago

Atomically Precise Mechanosynthesis of Carbon Structures on Hydrogenated Si(100)

dannyobrien
4pts0
lwn.net 4mo ago

Cindy Cohn on Privacy Battles Old and New

dannyobrien
2pts0
www.oblomovka.com 6mo ago

AI Psychosis, AI Apotheosis

dannyobrien
18pts0
www.servethehome.com 7mo ago

Micron Is Exiting Its "Crucial" Consumer Business

dannyobrien
4pts1
github.com 9mo ago

The Geek Code (1993)

dannyobrien
1pts0
www.inkandswitch.com 9mo ago

Keyhive – Local-first access control

dannyobrien
167pts14
www.eff.org 10mo ago

Executive Director Cindy Cohn Will Step Down After 25 Years with EFF

dannyobrien
5pts0
kriskowal.com 10mo ago

A Choice of Giants

dannyobrien
2pts0
www.servethehome.com 11mo ago

Meta Talks World-Lock Rendering for AR/Mr at Hot Chips 2025

dannyobrien
3pts0
ipfsfoundation.org 11mo ago

Ed25519 Support in Chrome

dannyobrien
3pts0
www.lesswrong.com 11mo ago

How Does a Blind Model See the Earth

dannyobrien
2pts1
github.com 11mo ago

HTML-in-Canvas

dannyobrien
222pts116
creativecommons.org 1y ago

Creative Commons Signals: A New Social Contract for the Age of AI

dannyobrien
4pts0
www.lesswrong.com 1y ago

Corbent: Next‑Generation Direct Air Capture

dannyobrien
2pts0
www.oblomovka.com 1y ago

LLMs and Humans Unite, You Have Nothing to Lose but Your Chores

dannyobrien
1pts0
webrecorder.net 1y ago

Saving pages as standard archival web archives (WARC)

dannyobrien
3pts0
www.eff.org 1y ago

A Better Way Forward: Voluntary Collective Licensing of Music Sharing (2008)

dannyobrien
3pts0
rodneybrooks.com 1y ago

Tips for Building and Deploying Robots

dannyobrien
122pts29
www.oblomovka.com 1y ago

Pavel Durov and the Blackberry Ratchet

dannyobrien
82pts31
fudzilla.com 1y ago

Mike Mageek is dead

dannyobrien
344pts68
pluralistic.net 1y ago

Disenshittify or Die

dannyobrien
14pts1
thenewstack.io 2y ago

Best Practices for Working with Large Language Models

dannyobrien
2pts0
mastodon.online 2y ago

Big Nerd Ranch is dead for good

dannyobrien
3pts1
norman.life 2y ago

Reflections from Local-First Conf

dannyobrien
1pts0
oolite.space 2y ago

Oolite: An open source open-world space opera

dannyobrien
132pts10
www.gnu.org 2y ago

The History of Autoconf

dannyobrien
2pts1
www.lesswrong.com 2y ago

Phallocentricity in GPT-J's stratified ontology

dannyobrien
4pts0
GPT-5.6 13 days ago

I eagerly await the models replying with that: "I'd be happy to create a pelican riding a bicycle, but just a note that this might already be in my training data. Simon."

What I'm looking for right now is a tool like this that lets more than one person participate in the conversation: right now Claude Code and similar tools are great for working alone, but I'd like to effectively pair-prompt with a partner who can see what's happening, and take turns steering the conversation.

Can Rowboat do this? If not, does anybody know a harness that can?

So I'm not sure if it's the first version of this doc, but I ran the first version of it that's on Wayback Machine[1] with the current version to see what the differences are.

Most of the changes seem to be because Masley found one counter-example (Newton County, Georgia) where AI datacenters do seem to be increasing water costs; the only deletions AFAICS is toning down language where Masley used to say "there are no examples" to "there is one counter-example". I don't see any other major corrections that have been removed.

Here's an annotated diff of the two texts: https://bafybeie7b3zs2gqifpvn7ee7y7326wcexwnsbhnur5coymu3m6w...

Iroh 1.0 1 month ago

would it possible to have iroh as a libp2p pluggable transport? So you could dial a iroh node with /iroh/proxy/ed25519key?

I got early access to the pre-ChatGPT OpenAI API (actually by pinging someone from OpenAI who posted about it on HN). At work, we were setting up to play a livestreamed JackBox game for a charity event. This would have been in 2019.

In a previous life, I'd been a writer for the original You Don't Know Jack game (the UK variant), where the job was to crank out as many funny quips about a topic as you could, and then use a handful of them in the recording of the game itself. Some of the later JackBox games are like that, but for the players -- you're given a set piece, have to come up with little funny improvisations within a time limit.

As an experiment, I tried the set-up lines with the OpenAI API, and see whether it could come up with some responses. Of course, 90% of them were unfunny or incoherent, but 1/10 were not bad, or even pretty good.

I'm not sure that would have been impressive to anyone else -- but remember, I'd had this as a job, and sat in a writer's room, where everyone did this, for hours. In that environment, you expect a large proportion to be duds: the discipline is keep pumping them out, and not flagging creatively until you find a rich vein. I realised that this was a tool that would have been the perfect complement to that work -- and it was a pretty good JackBox player too.

I think people sometimes misunderstand Daniel's point here, though it's clearer when taken in context of the rest of his article. The tools in general are getting a lot better at finding security bugs, it was unclear to Daniel based on his usage whether Mythos in particular is a huge step, but the Mythos generation of LLMs definitely are. Note though that Daniel was using Mythos somewhat indirectly. One thing I've taken away from the whole Mythos debate is that a) I suspect that Anthropic's GPU crunch meant that they felt they had to ration Mythos access anyway, so the calculus of whether they would release it generally was probably influenced by that, and b) finding bugs with Mythos or a similar model is still expensive -- a $20K or $100K Mythos run on Curl might have shown the same level of issues as other projects like Firefox, but Daniel didn't get that kind of access.

He posted a general update today on LinkedIn which I think gives the wider context:

https://www.linkedin.com/feed/update/urn:li:activity:7463481...

Not even half-way through this hashtag#curl release cycle we are already at 11 confirmed vulnerabilities - and there are three left in the queue to assess and new reports keep arriving at a pace of more than one/day.

11 CVEs announced in a single release is our record from 2016 after the first-ever security audit (by Cure 53).

This is the most intense period in hashtag#curl that I can remember ever been through.

So, this is not quite right: Alexander contributed to the report, but his personal opinion is more like the mid-2030s[1]. Freddie feels like this is him backing down from the original statement, but in fact he said this at the time the report was published, and in fact pointed out a graf below the quote that Freddie claims does tie him to 2027:

Do we really think things will move this fast? Sort of no - between the beginning of the project last summer and the present, Daniel’s median for the intelligence explosion shifted from 2027 to 2028. We keep the scenario centered around 2027 because it’s still his modal prediction (and because it would be annoying to change). Other members of the team (including me) have medians later in the 2020s or early 2030s, and also think automation will progress more slowly. So maybe think of this as a vision of what an 80th percentile fast scenario looks like - not our precise median, but also not something we feel safe ruling out. [2]

I don't think this changes your observation that he is "personally invested" (i.e. believes this trendline will continue), but I'm pretty sure when AGI doesn't appear in 2027, many people will believe that this invalidates the arguments being made here (or in the report). The actual report was intended to give a feel for what a near-future "disaster" AGI scenario, and settled on a date to give that some concrete immediacy. The collective review that gave that as a possible, but not inevitable date is still ongoing (they originally pushed their best estimate out a bit further, but now they think, judging by the goals that are being hit, their scenario was a little too conservative). [3]

[1] https://freddiedeboer.substack.com/p/im-offering-scott-alexa... [2] https://www.astralcodexten.com/p/introducing-ai-2027 [3] https://blog.aifutures.org/p/grading-ai-2027s-2025-predictio...

I think it's worth linking to the original Agile Manifesto[1], because that's pretty much all the consensus you're ever going to get on what's "agile" and "what's not".

Lewis is right that most of these principles were described before the manifesto, but I can vouch for the near-impossibility in many contexts of convincing anyone who wasn't a coder (and a lot of coders too) why these might be sensible defaults.

For every person burned by a subsequent maladaptive formalization of these principles, there was someone horribly scarred before the agile manifesto by being forced to go through a doomed waterfall process.

EFF is leaving X 3 months ago

I worked at EFF during that time, and this is a weird story that I’ve not heard before. EFF doesn’t let interns write blog posts (at least not with a lot of supervision) and certainly wouldn’t sack someone for getting something wrong — partly because that’s a terrible lesson to teach someone just starting out in law or activism, but also and more pragmatically it risks being a PR nightmare.

I concede it might be a mangled version of some other incident — EFF’s network neutrality policy during that time was /extremely/ subtle and we often struggled to express it without annoying some colleague organization or another. Do you remember any other details, or link to coverage of it?

So, I knew Aaron and I definitely would not presume to predict what he would have thought, but I’d point out there is a sizeable state space where he should never have been prosecuted, and scraping by others including large commercial companies should not prosecutable on the same grounds.

I repeat what Aaron’s friends and lawyers said at the time: we were going to fight that case, and we were going to win.

So, I was interested in this statement, and looked into it barely, and on one side, its conclusions were replicated in a number of other papers[1] (despite the headlines, three years after its publication, of a simple calculation error)[2]. I'll state that neither of these points are a slam-dunk if you're a member of one political side or another. If you're a believer in austerity, you'll look at the corroborating studies; if you think that was a bad policy choice, you can argue that they're all junk science, pushed out by supporters of the status quo.

I suspect what it narrowly shows though is that this isn't the same category of error as what's being discussed here.

[1] https://www.mercatus.org/research/policy-briefs/debt-and-gro...

[2] https://www.bbc.co.uk/news/magazine-22223190

I think one of the things that goes unmentioned in these discussions is that while the US gets a lot of attention for this kind of activity, it has also (historically) been in the forefront of criminalization and prosecution. I may be wrong, but don't know of any other jurisdiction that prosecuted insider trading before the Eighties, and the US has had a pattern of investigating and regulating this since the 30s.

I don't think that this is a particular form of exceptionalism, beyond the US having a longer tradition of widespread, retail-owned shares, and law-making around that fact.

But sometimes I wonder when people are criticising the US as a culture, they're often choosing as the baseline that should be respected standards that were also defined in a US cultural context. What this sometimes means is that in internal US culture these points are seen as something that is heavily discussed, because there was a point where it was democratically decided and therefore could be undecided in the same way, like corporate personhood, or money-as-speech. In the case of the criminalization "insider trading", there is lively debate about whether this is actually a "good thing". That can sound horrific externally, because of course insider trading is a bad thing. But someone decided to make that a bad thing, and -- for historical accident reasons -- the edges of that debate was largely defined within the US.

(This is mostly just barely-informed speculation: sometimes issues like this emerge in international fora, or start in another culture and quickly spread. But the cultural and financial dominance of the US in the last century or so really makes these things often a point of debate in American terms, and a fixed point elsewhere. I speak here as an immigrant to the US and also someone who is dipped in global policy work, rather than someone who is stating this as a good or a bad thing.)

Julia 6 months ago

What parts of it were confusing? I think science fiction can be confusing if you haven’t read a lot of it, because part of its art is to try and set the scene in as compact way as possible, with a combination of cues that you can work out from their context or by reference (like “laminate” and “squarely” — yes, I had to look it up), and some are the puzzles that the rest of the story will resolve (who/what is Julia? What do they want?)

It’s ok if it’s not your thing. It’s like an emotional crossword puzzle.

This is fascinating; thank you for building it. (I also enjoyed watching the flurry of visitors as soon as my Let's Encrypt certificate got assigned. It's a Dark Forest out there!)

I've been asking this for a while, especially as a lot of the early blame went on the big, visible US companies like OpenAI and Anthropic. While their incentives are different from search engines (as someone said early on in this onslaught, "a search engine needs your site to stay up; an AI company doesn't"), that's quite a subtle incentive difference. Just avoiding the blocks that inevitably spring up when you misbehave is a incentive the other way -- and probably the biggest reason robots.txt obedience, delays between accesses, back-off algorithms etc are widespread. We have a culture that conveys all of these approaches, and reciprocality has its part, but I suspect that's part of the encouragement to adopt them. It could that they're just too much of a hurry not to follow the rules, or it could be others hiding behind those bot-names (or others). Unsure.

Anyway, I think the (currently small[1]) but growing problem is going to be individuals using AI agents to access web-pages. I think this falls under the category of the traffic that people are concerned about, even though it's under an individual users' control, and those users are ultimately accessing that information (though perhaps without seeing the ads that pay of it). AI agents are frequently zooming off and collecting hundreds of citations for an individual user, in the time that a user-agent under manual control of a human would click on a few links. Even if those links aren't all accessed, that's going to change the pattern of organic browsing for websites.

Another challenge is that with tools like Claude Cowork, users are increasingly going to be able to create their own, one-off, crawlers. I've had a couple of occasions when I've ended up crafting a crawler to answer a question, and I've had to intervene and explicitly tell Claude to "be polite", before it would build in time-delays and the like (I got temporarily blocked by NASA because I hadn't noticed Claude was hammering a 404 page).

The Web was always designed to be readable by humans and machines, so I don't see a fundamental problem now that end-users have more capability to work with machines to learn what they need. But even if we track down and sucessfully discourage bad actors, we need to work out how to adapt to the changing patterns of how good actors, empowered by better access to computation, can browse the web.

[1] https://radar.cloudflare.com/ai-insights#ai-bot-crawler-traf...

I'm happy to bet with that skills -- or "a set of instructions in markdown that get sucked into your context under certain conditions" will stick around. Similarly, I think that the Claude Code/Cowork -- or "interactive prompt using shell commands on a local filesystem" -- will also stick around.

I fully anticipate there being a fair amount of thrashing on what exactly the right wrapper is around both of those concepts. I think the hard thing is to discriminate between the learned constants (vim/emacs) are from the attempts to re-jiggle or extend that (plugins, etc); it's actually useful to get reviews of these experiments exactly so you don't have to install all of them to find out whether they add anything.

(On skills, I think that the reason why there "aren't good examples out there" is because most people just have a stack of impromptu local setups. It takes a bit of work to extract those to throw them out into the public, and right now it's difficult to see that kind of activity over lots of very-excitable hyping, as you rightly describe.

The deal with skills and other piles of markdown is that they don't look, even from a short distance, like you can construct a business model for them, so I think they may well end up in the world of genuine open source sharing, which is a much smaller, but saner, place.

Metabrainz is a great resource -- I wrote about them a few years ago here: https://www.eff.org/deeplinks/2021/06/organizing-public-inte...

There's something important here in that a public good like Metabrainz would be fine with the AI bots picking up their content -- they're just doing it in a frustratingly inefficient way.

It's a co-ordination problem: Metabrainz assumes good intent from bots, and has to lock down when they violate that trust. The bots have a different model -- they assume that the website is adversarially "hiding" its content. They won't believe a random site when it says "Look, stop hitting our API, you can pick all of this data in one go, over in this gzipped tar file."

Or better still, this torrent file, where the bots would briefly end up improving the shareability of the data.

For those in the thread worrying that KK may have been mooching off people, and would not reciprocate: many years ago, I opened up our back yard for people who wanted to come to O'Reilly's Emerging Tech conference, but could not afford the sky-high hotel prices in Silicon Valley (this was before AirBnB or couchsurfing).

I was surprised when Kevin Kelly appeared. He'd been my (very distant) boss at Wired, was a published author of one of my favorite books, a very well-known figure and a smiling but disarmingly calm manner. He sat and amicably talked for hours with a yard full of people, many of whom have become some of my closet friends. Then, as the evening closed, he asked if he could sleep in my yard too. Others had brought tents, and burning men structures, and it had begun to rain. Kevin pulled out a camping sleeping bag from nowhere, struck out, and I saw him later, in the soaking, muddy garden, quietly curled up under someone's geodesic dome structure.

Decades later, after Covid, I mailed him out of the blue, and asked him for advice. He immediately remembered me, invited me to his home, and talked to me, again, for an hour or so, about AI, optimism, and how to change the world.

To be frank, I never emailed him thank you, and I still feel guilty about that, but now I feel like it was never needed or asked for. I may mail him anyway. Maybe there's a miracle or two still left in the day.