HN user

geocar

6,287 karma

http://geocar.sdf1.org

geocar at sdf.org

if you used to email me at lonestar, that address no longer works.

Posts35
Comments2,241
View on HN
peterkleissner.com 5y ago

Reverse Engineering Supermicro IPMI (2018)

geocar
78pts9
lock.cmpxchg8b.com 5y ago

Lotus 1-2-3

geocar
2pts0
github.com 5y ago

DOS Subsystem for Linux

geocar
328pts180
www.howardism.org 5y ago

Literate DevOps

geocar
174pts87
www.youtube.com 6y ago

Never Gonna Give You Up, but an AI attempts to continuously generate more

geocar
2pts0
www.usenix.org 6y ago

Meaningful Availability [pdf]

geocar
30pts0
www.vice.com 6y ago

NSO employees take legal action against Facebook for banning their accounts

geocar
1pts0
www.nanog.org 7y ago

DNS Caching: Running on Zero (2010) [pdf]

geocar
3pts0
t3x.org 7y ago

Kilo LISP

geocar
221pts48
github.com 7y ago

Show HN: Old Unix V6 ed, lightly ported to modern systems

geocar
2pts0
fph.altervista.org 7y ago

Bastard Tetris

geocar
146pts35
fph.altervista.org 7y ago

Bastard Tetris

geocar
2pts0
medium.com 7y ago

How to Design for the Modern Web

geocar
227pts93
searle.hostei.com 7y ago

70’s TV game recreation using an Arduino

geocar
66pts1
www.sec.gov 8y ago

Equifax statement regarding extent of security incident announced Sep 7 2017

geocar
118pts61
tasvideos.org 8y ago

MrWint's GBC Pokémon: Yellow Version “Arbitrary Code Execution” (2017)

geocar
85pts9
hackaday.com 8y ago

Using Moiré Patterns to Guide Ships

geocar
87pts9
ondemand.kx.com 8y ago

Kdb+ on demand – (64-bit) Personal Edition

geocar
5pts1
www.patreon.com 8y ago

Project: 2ine – OS/2 emulator for Linux

geocar
170pts61
www.patreon.com 8y ago

Project: 2ine – OS/2 emulator for Linux

geocar
3pts1
habs.sdf.org 8y ago

McCarthy Math

geocar
36pts6
www.youtube.com 8y ago

Plonat Atek – Close Up on the Scope [video]

geocar
21pts1
www.youtube.com 8y ago

Plonat Atek – Close Up on the Scope

geocar
1pts0
www.osnews.com 8y ago

PC-MOS released under GPL

geocar
55pts13
islisp.js.org 8y ago

Iris is an ISLisp implementation which has strong extensiblity

geocar
6pts4
daringfireball.net 9y ago

Russian Hackers Are Using Google's Own Infrastructure to Hack Gmail Users

geocar
3pts0
habs.sdf.org 9y ago

McCarthy Math

geocar
2pts0
myrlang.org 9y ago

Myrddin: Retrospective: 2016

geocar
5pts0
www.pipeline.com 10y ago

Henry Baker's Archive of Research Papers

geocar
62pts5
www.scriptcrafty.com 10y ago

Configuration (mis)management or why I hate puppet, ansible, salt, etc.

geocar
3pts1

Browsers ought to run the fastest JS interpreters already

Well they don't.

Users want the website to work sooner, and care little about whether a for-loop of elements take 10ms or 20ms if it only happens once.

JS can be AOT compiled if you can wait a few _seconds_ -- which users don't want, so browsers don't bother.

Our attacker however, rightly observes they only have to pay that compilation cost once.

but PoW scales

Not if the honest party is doing it in a browser: The same computer can so any POW so much faster in C than any amount jf JS and WASM that it will never ever ever be a contest.

becoming much more obvious and easy to block, or they have to use massive amounts of compute.

If you believe this, please contact me: I think compute is free[1] and can probably help you out.

[1] https://news.ycombinator.com/item?id=30175269

Can I ask what you mean when you say "write"?

To "write", I mean the precursor to "read".

https://www.gnu.org/philosophy/right-to-read.en.html

Are you talking about literature / articles, or software?

All of the above.

This is new to me, want to stay on top of it.

I am sorry to tell you it is not too new. Google tried this before recently with something called WEI (which you might be able to find on ddg or other search engines): It failed for reasons few people know for sure[1], but the initiative had the same basic bullshit about security, and the same outcomes.

[1]: The story I heard was a couple South-American countries noticed that this would prevent their people from being able to work on software that runs in the Google ecosystem and threatened to block Google en masse. Since then, one of the countries that Google has a lot of offices in invaded one of those South American Countries for conveniently unrelated reasons.

Do you have a specific suggestion?

I have tried everything that is available at my local shops (which looks like it came from Temu)

CarPlay is better than android auto in that it works with my iPhone; as to why it is currently in _my_ requirements, it’s simple: I rent cars when I travel, I’m too lazy to memorise so many maps, and I don’t have a good mount I can bring with me.

That being said I think there are a few things that make my carplay experience _worse_ than my friends’ android auto experience: for example today I am annoyed by google maps spam me with notifications trying to get me to use googles maps instead of waze which is so fucking stupid since it’s also google and it just makes me more annoyed with google instead of being the sort of thing that would convince me to switch to android. But I have to admit the google maps and waze integration on android is better.

Having my phone mounted is fine but it’s been hard for me to find a good mount that works with random rental car I get. Any suggestions?

I don’t hate carplay but some things annoy me like I can’t Shazam what I’m listening to in the car because CarPlay pauses the cars audio. I would be willing to try to make it optional until CarPlay works better.

Google has been attempting to license the right to write.

There are a lot of poor people, mostly brown people, who do not have the ability to get one of these licenses.

Some of them are feeding themselves with their ability to write, and Google is literally stealing that food from their mouths.

That the provider's business needs necessitate the this behaviour...

No, please don't move past this so quick, because I'm not convinced they have the need, and in some markets (like the US) it is a violation of civil rights, to show people different content based on their ethnicity[1] because those people might have a claim that supersedes anything they might have signed or clicked-through.

That Anthropic did something they could obvious be sued for constitutional violations in multiple countries is shocking.

what else [are] they're harvesting from my machine? PII?

Assume everything, and yet I think this is more insidious than mere exfiltration, and we should go further: The LLM can respond to these magic quote marks directly, which means it can be trained to give people bad/different advice without those markers being so visible to people using debugging tools.

That's so unethical, the laws on this potentially so severe, Anthropic could be facing unlimited damages, from any one example combined with this article, which means either they have a really stupid management team, or were given a promise of legal immunity in some way.

Neither of those things should be what you should want to base your next big idea on.

[1]: For a simple example, showing an ad for (say) mortgage offers and targeting people by race/ethnicity/gender is totally illegal, but it's also illegal if you make a list of targeting criteria that just happen to select for a protected class.

> ...who does not clearly have the rights

This claim is baseless... it all boils to question how much of the salt makes a soup a salty one.

No it doesn't. The very existence of the question means it is not clear.

- if I put 10.000 words into a prompt and got 500 words out of it, is the author LLM, or me?

Neither. The author is some unknown number of people whose words were scraped.

- if I got 50 lines, and modified each single one, is the author LLM, or me?

Neither. The author is some unknown number of people whose words were scraped, combined possibly with you. You need all authors to agree on the rights.

You would have to not just modify them, but modify them substantially to either change their meaning or criticise them, or do something because just flip a random number of bits in order to get into the running, and a judge might still disagree with you.

I'm confident I could prove my case against the court

I'm not even sure you understand the stakes, because not just the authors have claim but also the persons (e.g. z.ai in your case) who assembled the model, and you just blew past both of those people like they were nothing.

You're not even in third-place for rights on this work, and you don't even seem to realise that.

Appendix 7 on this page http://www.faqs.org/faqs/m-technology-faq/part2/ : runs screaming into the night

I don't know mumps very well, but this seems pretty straightforward if you put the primer next to it, and I am troubled by your (common!) reaction to alien technology...

Stringly typed with literally no other types? Uh…

like this example here; SQLite made this choice too. Everyone knows about SQLite by now, right?

All types are strings when the user types them in, whether you are talking source code text, or the patient's weight in kilograms. Pretending you can have other types is something the source code of your application (or the language your application is written in) does.

This is something that makes total sense when you are thinking about things the right way (whatever that means), so when something makes you go "uh" try inverting this equation, and ask yourself, in what way (or under what circumstances) would this decision make sense?

That sort of thinking will get you the right ideas to understand everything else in the software world, and make you less avoidant about filling in the gaps in your own abilities.

It had some neat ideas

Has. Multiuser support is still almost nonexistent in mainstream programming (and just recently starting to actually show up in SQL implementations!). And besides SQL, the most popular language with global variables you've might have heard of is perl. Understanding these ideas is still in the future.

Putting the ideas in the past, and framing them with such harsh judgement -- especially the ideas like this that you don't fully understand yet -- keeps them out of your mind, and denies you access to what these ideas can do for you.

As an example: A lot of people make a "users" table in SQL for the users of their application. Of course most SQL implementations have "users" of their own, and have a robust implementation that is already there, and yet almost nobody uses it and chooses to make their own rather than learn how to use the one SQL gives them.

Now: SQL exfiltrations are only possible because of this, and when you fully understand why that is you'll probably never make another users table again.

and some absolute nightmare fuel.

but nightmares? Seriously? There was nothing in that example code that I am going to have nightmares about. It seems very well thought out (unlike say, Python's). It's even Y2K compliant. There is even a few ideas in there I'm going to steal for my own parser.

There is good stuff here; don't give up.

Nonsense. The FSF cannot receive a copyright assignment from someone who does not clearly have the rights. If it is “open” then it is not clear.

Of the two other parties who claim copyright, neither is the submitter; either Facebook (or whoever “made” the model) has it or the persons whose content is in the model has it. Facebook did not assign copyright of the output to the user, and neither did those others.

not knowing about these rules.

He didn’t look at the t&c for whatever model he was using and didn’t understand he had no copyright claim over its output?

He doesn’t have any rights to the code; he can’t assign them to the FSF.

What incentives does this give people?

Hopefully to learn how to code so they can make their own contributions.

No.

The “contributor” doesn’t have the ability to contribute; They do not have copyright over the code so they can’t assign it.

The maintainer should not read it because then they could be tainted and perform accidental copyright infringement in the future.

Yours is an “edge device” but I am root, so mine is a portable tool for managing and testing the network that does not have working WiFi access points attached to it or obviously I would not be there.

And yes, some of those links are above 1gbps so that the users can have individual 1gbps links.

That is a good point. If I ping the router 2m away from me in the airbnb (on Ethernet) I am staying in I'm getting 0.8msec. If it is really 0.4msec over some kind of consumer wireless, it is physically inside the phone.

I think more likely got something wrong with the units; System.Net.Networkinformation.ping reports in whole seconds (so this is ~400ms) for example. Maybe it is some weird tool or typo.

Yes such-a-thing-is-possible: The DEC VT330 (for example) allowed font upload, had multiple font sizes, and even mouse support.

There once was a program called https://en.wikipedia.org/wiki/ManaGeR which appears at first blush to be some kind of X11-competitor, except it was using the VT330's regular terminal capabilities to do those fancy pixel-patterns and fonts, and so there's just some weird VT escape sequences you've never heard of in there.

You can also use SIXELs if you want even more control, and you can readily see such things in action because qemu can (in 2026) send its graphical VGA display into a sixel terminal, but in the 1980s such a thing would not have been performant (probably something like 3 frames per minute) because the VT330 was slow, and such a thing would not be popular you would "lose the text" at some layer which would be as inconvenient as using any other graphical application.

as such they are composable in the sense that they can be used in a way the author(s) didn't think of. It's been a while since I've done any of that personally,

I do this all the time.

One of my favourite applications is a tool called "autoexpect" and I use it every time I try a new program.

What it does is this: I run a program in it's virtual terminal, and it writes a TCL script that does what I did, and puts little regex tests in for the output of that program for me. I can then edit that program (or not: sometimes the first output is fine).

Once upon a time I used to use a program called DESQview: It had a "learn" feature that allowed you to record and playback even DOS programs, so it was very easy to pick up autoexpect.

DESQview/X was their X11 server, and it also had the "learn" feature, but unless the application could be driven entirely by the keyboard, it didn't work; most similar applications I've seen over the decades since need such care for reliable "scripts".

Yes sometimes you also have the possibility of using the GUI accessibility framework to "script" the app. This is barely ok if it works, but most GUIs that I want to script were designed so that would not work at all, and it is coding that requires me work with the app instead of asking a domain expert for a recording.

autoexpect on the other hand is just text, easy to read and modify, and easy to send by email. It is hard to make a terminal application hostile to autoexpect without a great deal of work that (in the text based environment) can usually be undone just by using tmux and mosh on loopback.

What I don't understand is why that must happen inside a terminal window where (for instance) all text must have the same font and size.

Modern (as in, since the 1980s) terminals are very capable of multiple fonts and font-sizes. I usually use a non-proportional font for coding myself.

Yes. And you can see it in action by using a "public looking glass" service and typing in an IP address to see which ASN (autonomous system number) announce it and who they peer with. Your mobile operator might even be operating one.

For example, go to https://lg.he.net choose BGP Summary IPv4 and plug in a well-known anycast address like 8.8.8.8 (operated by Google) or 1.1.1.1 (operated by cloudflare) and try a few different routers in different parts of the world, and you will see lots of different neighbors claim to be directly connected to these addresses -- something that should be very strange if you thought (for example) that an IP address had a geographic location at a particular point-in-time.

You can also try this for some of the addresses in this range and see that some of the addresses are like this.

N.B. This is exactly how seaside, vba, and even arc[1] do server-side state generally: by encrypting the blob-representing-state and sending to the client to be sent back on future requests (where it will be decrypted and rehydrated).

It's an old trick that everyone designing protocols should know, since there are lots of applications beyond AI companies.

[1]: As in, pg's lisp: https://arclanguage.github.io/ref/srv.html#:~:text=The%20pre...

Search ad pricing is inelastic and auction based (supply goes down price goes up).

False. Advertisers have budgets and ROI targets. If Google cannot compete people will get their clicks elsewhere.

A jump in traffic to DuckDuckGo does not mean Google is experiencing a decline in search volume. Number of queries per session has increased since launching AI Overviews.

But it does produce lower ROI for advertisers (in this case: CTR goes down because my ad is being shown to more people). Once user is on my landing page, my conversion rate is fine month on month (±1%), but my CTR on google got sharply worse by 5% since, and if it goes much further I'll stop completely on Google.

I doubt I am alone: Maybe others will jump ship sooner and the price will recover (demand goes down) but in either event Google is less net revenue, and given how aggressive their sales pushes have been I think it could be that big

Sure it is, but that's not a way to store value (what economists specifically call store of value if you want to read more about it), which is a little different:

If you buy a €100k rolex, you probably can't be sure you can sell it for more than €100k anywhere at anytime in the future.

You probably can't even find a bank that would take that €100k rolex you just bought as collateral for €500k on a 30y mortgage.

That's why a €1m watch collection is never going to be worth €1m unless we're talking raw materials.

if the odds haven't properly converged what information does watching the prices get you before-the-fact?

How do you know we are "before-the fact"? Because these numbers are bananas?

Somebody just tanked their job, their life, for a million bucks.

Anybody who took that bet, might've individually spent only a few bucks to see that.

Everyone else (the people watching) learned the price of entertainment is a few bucks, and ruining someone's life is a million bucks.

Was that a surprise to you? If not, then the (market) prices may be said to have converged (close to) reality.

But maybe it is, and you think people would ruin their lives for less, or would pay more for human misery. In any event, the distance between whatever you think that probability is, and the return earned on these odds is information, that we all can enjoy (as benefit) before-the-fact.

What's the appeal of collecting high priced watches?

You can carry them on your person through airports and other places reasonably unmolested in a way carrying a bunch of cash isn't so easy.

Is it kind of like art collections, where its a decent store of value

Art doesn't store value: It trades whatever number the parties exchanging it want it to have, so those parties can manipulate their total annual revenues, which might be confused with value if you cannot think of why else someone would want to tell other people they made more or less money in a year, but is not valuable to anyone else.

Dereferencing does have a postfix notation, so you can try it (sort of):

    #define $ [0]
then you can say ptr $[0] or ptr[0]$ and see if it's really better...

Specifically? I'm thinking of qmail.

qmail was at one point the second most widely deployed email server, handling the majority of online mail. It wasn't a research project; it's not obscure. Yahoo used to use it.

And what I mean by track record: After more than a decade after the last published version, a theoretical attack was found requiring special setup uncommon for a sysadmin, and impossible ten years prior.

When anyone thinks about how to build reliable secure software, I think they should be thinking of qmail because it really has no public source-available equal, except maybe djbdns.

seL4 on the other hand makes some specious claims about some ten year old version of itself, and so few people have even heard about it you thought it important to remind it is "technically" C -- qmail isn't like that at all: There is no prover, no test suite, and almost no metaprogramming of any kind. It's just C.