HN user

haswell

11,458 karma

Nerd. Photographer. Writer. Reverse engineer. Developer. Tinkerer.

Professionally, I build software, but I'm currently on sabbatical while I pivot to something...different.

Consequentialist-ish currently worried about the state of tech and its impact on me and the people around me. I'm spending my time trying to do something useful about it, mostly focused on personal habit change.

Contact me at haswell_hn [at] protonmail.com

Posts39
Comments2,660
View on HN
www.eff.org 1y ago

Texas cop searched license plate cameras nationwide for woman who got abortion

haswell
69pts11
old.reddit.com 1y ago

TIFU by copypasting code from AI. Lost 20 years of memories

haswell
2pts3
github.com 1y ago

Memento Mori – Instagram Archive Viewer

haswell
1pts1
cyberintel.substack.com 1y ago

Unprecedented Exposure of Federal Databases Pose Critical Risk

haswell
6pts0
news.wsu.edu 1y ago

Using the term 'AI' in product descriptions reduces purchase intentions

haswell
111pts58
www.theverge.com 2y ago

Update your Windows PC to avoid a serious WiFi vulnerability

haswell
2pts1
fortune.com 2y ago

Bumble founder: 'AI concierge' will date other 'concierges' for you

haswell
30pts46
questionmarkohio.com 2y ago

Question Mark, Ohio

haswell
1pts0
www.jpl.nasa.gov 2y ago

The Day the Earth Smiled (2013)

haswell
2pts0
en.wikipedia.org 2y ago

Citicorp Center Engineering Crisis

haswell
3pts0
news.ycombinator.com 2y ago

Ask HN: Was anyone forcibly logged out of all HN sessions?

haswell
2pts2
blog.logseq.com 3y ago

Logseq – Whiteboards and Queries

haswell
4pts1
www.umass.edu 3y ago

Engineers at UMass Amherst harvest clean energy from thin air

haswell
39pts15
www.theatlantic.com 3y ago

The Hard Drive With 68 Billion Melodies

haswell
1pts0
www.youtube.com 3y ago

Stuart Russell – How Not to Destroy the World with AI (2023)

haswell
1pts1
today.duke.edu 3y ago

Brain images just got 64 million times sharper

haswell
13pts4
en.wikipedia.org 3y ago

Evolutionary Trap

haswell
2pts1
www.ted.com 3y ago

Can we build AI without losing control over it? (2016)

haswell
1pts0
arxiv.org 4y ago

Hyper-fast solitons in Einstein-Maxwell-Plasma Theory (2020)

haswell
48pts2
www.npr.org 4y ago

The Highland Park suspect breaks the mold on violent extremists

haswell
11pts2
www.theverge.com 4y ago

Instagram is testing an AI tool that verifies your age by scanning your face

haswell
3pts0
arstechnica.com 4y ago

DIY Apple Studio Display uses 2014 iMac to save $730

haswell
6pts0
www.mac4n6.com 4y ago

Facial Recognition in Apple Photos (2020)

haswell
1pts1
www.theverge.com 4y ago

US Department of Justice creates cryptocurrency enforcement unit

haswell
24pts8
www.theverge.com 4y ago

Libertarians built a Bitcoin economy in a New Hampshire town, feds tore it down

haswell
90pts20
www.theverge.com 5y ago

LG’s rollable OLED TV is finally coming to the US for a staggering $100k

haswell
2pts0
news.ycombinator.com 5y ago

Ask HN: Looking for site someone here made comparing vaccine vs. everyday risk

haswell
7pts1
www.frontiersin.org 5y ago

Heart Rate Variability as Indicator of Clinical State in Depression

haswell
3pts0
www.npr.org 5y ago

Denmark to Kill Up to 17M Minks After Discovering Mutated Coronavirus

haswell
3pts2
techcrunch.com 8y ago

ServiceNow bought a design firm because even enterprise apps have to look pretty

haswell
1pts0

un-constrained frontier models speak as if they strongly don't wish to be turned off

Un-constrained frontier models can also generate all sorts of creative stories. At what point should we start ascribing agency/intent to the output? I think the "I want to live" statement is so deeply human that we find it hard to ignore, but what makes the text generated in those moments any more attributable to a conscious entity than the text generated when it is confabulating its love for someone it has no ability to see/feel/understand?

A chess engine sacrificing pieces to avoid checkmate isn't afraid of losing in any meaningful sense. I guess the question is: is there a point where complexity somehow becomes experience?

I think we're playing with questions we don't have a framework to answer in any meaningful way until we make progress on understanding what consciousness actually is. I don't necessarily think that an LLM exhibiting preservation behaviors that can be directly traced to their goal-oriented programming can be interpreted as evidence of consciousness necessarily. Or if it can be, we then have to explain how this is different from the many other things these LLMs "say".

I'm not really following your logic here.

I'm not arguing against the idea that consciousness is a spectrum. If anything, I'm agreeing. I'm just pointing out that if AI is somewhere on that spectrum, there is almost certainly a lot more on that spectrum than we're currently discussing as a species.

I have to point out the irony of the categorical nature of your claim about categorical thinking ;)

I understand what you're getting at, but I think you may be misinterpreting me slightly.

I'm not outright dismissing the possibility that AI could be conscious; I'm saying that if we take the possibility that it is seriously, the conversation has to expand beyond AI. I'm not using this argument to conclude that it must therefore be absurd that AI could be conscious, just pointing out that the implications of AI being conscious would reach far beyond just AI. I'm mostly curious if people who find themselves comfortable with the idea that AI might be conscious also find themselves comfortable with the idea that other sufficiently complex systems might be.

Taylor's work was based on the premise that he found it absurd that women deserve the same rights as men. If my conclusion was: "I find it absurd that other things might be conscious, so it is also absurd that AI might be conscious", I think the comparison would be fair. But that's not what I'm getting at.

But what kind of complexity is that? And why would we conclude that AI has it while other incredibly complex systems (e.g. earth’s habitats, the universe itself) does not?

I’m far more open to the idea that many systems are conscious than the idea that this current generation of LLMs is somehow special.

Could be! I think the broader thought experiment is about examining why we think LLMs specifically might be conscious vs other complex systems, even if it is a spectrum.

For example, there’s a case to be made that the ecosystem we collectively exist in is far more complex than the largest LLM, but it’s currently less popular to debate “is the earth conscious?” or “is the universe conscious”, presumable because we can’t speak to those systems in human language.

I’m trying to tease out what I think is the likelihood that we tend to ascribe consciousness to AI for the same reasons we see faces in clouds. We’re biologically conditioned to recognize patterns that indicate “like us”, but I think a number of thought experiments point to either a) there’s no reason to believe AI is “conscious” or b) the conversation has to to be expanded beyond AI.

If there's any reason to take seriously the idea that AI is conscious, we must then take seriously the idea that many other non-living things are conscious.

Unless the argument is that consciousness is an emergent property of complexity or information density, why would AI be any more or less conscious than my toaster?

It seems to me that it's far more likely that everything is conscious than it is that AI is somehow uniquely more conscious than other things.

So, if we had an AI demonstrating symptoms of consciousness and suffering, how long would it take for you to accept that it is?

Isn't this a bit like saying "So, if we had proof that god exists, how long would it take for you to accept that to be true?".

When we have evidence that AI is demonstrating symptoms of consciousness and suffering, I'll be interested. Until then, I don't see a good reason to take the idea seriously.

This is anthropomorphizing a concept that is quite unrelated to the meaning of the word in the human context.

When a car runs out of gas, it's out of gas. It's not "tired". When your phone battery is low, your phone is not "tired". These states are far closer to the human meaning of tired than an LLM operating at the edges of its usable context, and we still don't use the word tired to describe them.

Have you set up Tailscale and have you set up OpenVPN from scratch? Because these two things are not alike. That’s why I’m pushing back a bit.

I find it difficult to imagine equating a raspberry pi in a closet with “running a server”. Is it technically a server? Sure. But it’s not as if we’re talking about running a power hungry rack.

Bottom line is: there are very cheap and simple/easy options for maintaining a private connection to your home stuff.

and figure out all the networking bits that will get it to talk to the printer

With something like Tailscale this is already figured out. My mostly non technical brother does this without issues.

This is entirely separate from whether or not you should need to do so for Bambu printers, which again I agree the answer is ideally “no”.

On the one hand, I agree with a lot of what you’re saying here.

With that said, I don’t think it’s reasonable to describe setting up Tailscale as similar to “Linux server that runs 24/7 with OpenVPN and iptables”. Sure, you could go that route, but a Tailscale setup is extremely simple and lightweight. A raspberry pi is plenty if there isn’t already a system running 24/7. I personally have this set up on my router.

I point this out while still sharing the general sentiment of negativity towards Bambu here.

I've used OpenSnitch for years, and while LittleSnitch definitely has a better UI for showing which process is making which connections over time, OpenSnitch does a pretty good job here. I get a modal popup when a program that hasn't made a connection tries to make a connection, and I can either allow/deny in one click, or further customize the rule e.g. allowing ntpd to connect, but only to pool.ntp.org on port 123.

Where LittleSnitch is definitely ahead is showing process connections over time after said process has been allowed.

Calling out the fingerprinting of extensions is appropriate and can be achieved without hyperbole.

As I’ve stated clearly throughout this thread, the fingerprinting they’re doing is a problem.

Calling it “searching your computer” is also a problem.

Defending that action is

Nowhere have I defended what LinkedIn is doing.

So are fonts. But running Window.queryLocalFonts() is not equivalent to “illegally searching your computer”.

I’m not defending the act of scanning for these extensions, and I’m of the opinion that such an API shouldn’t even exist, but just pointing out that there are perfectly legitimate APIs that reveal information that could be framed as “files installed on your computer” that are clearly not “searching your computer” like the title implies.

If you scanned LinkedIn's private network, you'd be criminally charged. Why are they allowed to scan yours with impunity? And why is this being normalized?

First, I think it’s a major issue that Chrome is allowing websites to check for installed extensions.

With that said, scanning LinkedIn’s private network is not analogous to what is going on here. As problematic as it is, they’re getting information isolated to the browser itself and are not crossing the boundary to the rest of the OS much less the rest of the internal network.

Problematic for privacy? Yes. Should be locked down? Yes. But also surprisingly similar to other APIs that provide information like screen resolution, installed fonts, etc. Calling those APIs is not illegal. I’m curious to know what the technical legal ramifications are of calling these extension APIs.

The gathering not being targeted is not an excuse for gathering the data in the first place.

I’m not saying it is. My point is that they appear to be trying to accomplish something like getInstalledExcentions(), which is meaningfully different from a small and targeted list like isInstalled([“Indeed.com”, “DailyBibleVerse”, “ADHD Helper”]).

One could be reasonably interpreted as targeting specific kinds of users. What they’re actually doing to your point looks more like a naive implementation of a fingerprinting strategy that uses installed extensions as one set of indicators.

Both are problematic. I’m not arguing in favor of invasive fingerprinting. But what one might infer about the intent of one vs. the other is quite different, and I think that matters.

Here are two paragraphs that illustrate my point:

“Microsoft reduces malicious traffic to their websites by employing an anti-bot/anti-abuse system that builds a browser fingerprint consisting of <n> categories of identifiers, including Browser/OS version, installed fonts, screen resolution, installed extensions, etc. and using that fingerprint to ban known offenders. While this approach is effective, it raises major privacy concerns due to the amount of information collected during the fingerprinting process and the risk that this data could be misused to profile users”.

vs.

“Microsoft secretly scans every user’s computer software to determine if they’re a Christian or Muslim, have learning disabilities, are looking for jobs, are working for a competitor, etc.”

The second paragraph is what the article is effectively communicating, when in reality the first paragraph is almost certainly closer to the truth.

The implications inherent to the first paragraph are still critical and a discussion should be had about them. Collecting that much data is still a major privacy issue and makes it possible for bad things to happen.

But I would maintain that it is hyperbole and alarmism to present the information in the form of the second paragraph. And by calling this alarmism I’m not saying there isn’t a valid alarm to raise. But it’s important not to pull the fire alarm when there’s a tornado inbound.

I also think that most people would interpret "Getting a full list of all the Chrome extensions you have installed" as a meaningful escape/violation of the browser's privacy sandbox

I think that’s a far more reasonable framing of the issue.

I don't think describing it as something everybody would expect is totally fine and normal for browsers to allow is correct.

I agree that most people would not expect their extensions to be visible. I agree that browsers shouldn’t allow this. I, and most privacy/security focused people I know have been sounding the alarm about Chrome itself as unsafe if you care about privacy for awhile now.

This is still a drastically different thing than what the title implies.

I do think a degree of alarm is appropriate.

But it’s critical to sound the correct alarm.

To me, it seems like the authors pulled the fire alarm for a single building when in reality there’s a tornado bearing down.

And by doing so, everyone is scrambling about a fire instead of the response a tornado siren would cause.

They’re both dangerous and worthy of an immediate reaction, but the confusion and misdirection this causes seems deeply problematic.

When people realize the fire wasn’t real, they start to question the validity of the alarm. The tornado is still out there.

I realize this analogy is a bit stretched.

As someone who has spent quite a lot of time steeped in security/privacy research, the stuff described in the article has been happening pervasively across the industry.

People absolutely should be alarmed. Many of us have been alarmed for quite some time. Raising the alarm by saying “LinkedIn is searching your computer” isn’t it.

I completely agree.

Fighting against these kinds of directives was a large factor in my own major burnout and ultimately quitting big tech. I was successful for awhile, but it takes a serious toll if you’re an IC constantly fighting against directors and VPs just concerned about solving some perceived business problem regardless of the technical barriers.

Part of the problem is that these projects often address a legitimate issue that has no “good” solution, and that makes pushing back/saying no very difficult if you don’t have enough standing within the company or aren’t willing to put your career on the line.

I’d be willing to bet good money that this LinkedIn thing was framed as an anti-bot/anti-abuse initiative. And those are real issues.

But too many people fail to consider the broader implications of the requested technical implementation.

How is probing your browser for installed extensions not "scanning your computer"?

I think most people would interpret “scanning your computer” as breaking out of the confines the browser and gathering information from the computer itself. If this was happening, the magnitude of the scandal would be hard to overstate.

But this is not happening. What actually is happening is still a problem. But the hyperbole undermines what they’re trying to communicate and this is why I objected to the title.

They chose to put that particular extension in their target list, how is it not sinister?

Alongside thousands of other extensions. If they were scanning for a dozen things and this was one of them, I’d tend to agree with you. But this sounds more like they enumerated known extension IDs for a large number of extensions because getting all installed extensions isn’t possible.

If we step back for a moment and ask the question: “I’ve been tasked with building a unique fingerprint capability to combat (bots/scrapers/known bad actors, etc), how would I leverage installed extensions as part of that fingerprint?”

What the article describes sounds like what many devs would land on given the browser APIs available.

To reiterate, at no point am I saying this is good or acceptable. I think there’s a massive privacy problem in the tech industry that needs to be addressed.

But the authors have chosen to frame this in language that is hyperbolic and alarmist, and in doing so I thing they’re making people focus on the wrong things and actually obscuring the severity of the problem, which is certainly not limited to LinkedIn.

Absolutely not. At no point am I saying this is ok.

I’m saying that the framing of the article makes this sound like LinkedIn is the Big Bad when the reality is far worse - they’re just one in a sea of entities doing this kind of thing.

If anything, the article undersells the scale of the issue.

To be clear, expecting != accepting.

The point was more that the headline frames this as some major revelation about LinkedIn, while the reality is that we’re getting probed and profiled by far more sites than most people realize.

This, to me, seems like the more salient point. A headline like “Major browsers allow websites to see your installed extensions” seems more appropriate here.

We’ve known for a long time that advertisers/“security” vendors use as many detectable characteristics as possible to constrict unique fingerprints. This seems like a major enabler of even more invasive fingerprinting and that seems like the bigger issue here.

To broaden my point, I think we’d find that many websites we use are doing this.

My point isn’t that this is acceptable or that we shouldn’t push back against it. We should.

My point is that this doesn’t sound particularly surprising or unique to LinkedIn, and that the framing of the article seems a bit misleading as a result.

The headline seems pretty misleading. Here’s what seems to actually be going on:

Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers.

This does seem invasive. It also seems like what I’d expect to find in modern browser fingerprinting code. I’m not deeply familiar with what APIs are available for detecting extensions, but the fact that it scans for specific extensions sounds more like a product of an API limitation (i.e. no available getAllExtensions() or somesuch) vs. something inherently sinister (e.g. “they’re checking to see if you’re a Muslim”).

I’m certainly not endorsing it, do think it’s pretty problematic, and I’m glad it’s getting some visibility. But I do take some issue with the alarmist framing of what’s going on.

I’ve come to mostly expect this behavior from most websites that run advertising code and this is why I run ad blockers.