HN user

jijji

264 karma
Posts1
Comments520
View on HN

competition in this space is great, especially with open models/weights. I think the answer is not closed source models. Similar to the Unix versus Linux situation in the 1990's, open source wins out. Yesterdays story about how OpenAI has now began encrypting traffic between model and agent [0], this story brings a breath of fresh air. There is nothing "Open" about hiding the communication between model and agent, especially with software that is running within a trusted environment/network. It needs to be more transparent, not less.

[0] https://www.theregister.com/ai-and-ml/2026/07/15/openai-hide...

s3 is expensive... there are a lot of cheap options. I think I pay $48/month for a linux vps with 8 cpus and 16tb of storage with interserver.net... the same storage on amazon s3 is $377/month lol

snowden's book, "Permanent Record" talks about the mass surveillance that he released in 2013. it makes no mention of AI companies sending data to the government. unless you can quote the exact language you're talking about in the book, I call BS on that.

secondly, you're claiming that it is the same in the US. there is no laws in the US requiring private companies to exfiltrate data and send it to the government en masse, like there is in China. these laws just don't exist, and if they did exist they would be ruled unconstitutional in violation of the Fourth amendment. As a matter of fact, last week Supreme Court decision in Chatrie v. United States came out on Monday, June 29, 2026 that affirmed that general warrants are a violation of the Fourth amendment, related to sweeping geofence warrants. so what you're talking about just does not exist. Yeah, I'm sure some companies, like Facebook, Google, etc have private agreements with government agencies to release data privately, these rules eventually are a violation of the Fourth amendment without a warrant.

to avoid any of this, I use open models with small providers that are very unlikely to be having private agreements with government agencies specifically to avoid that conflict. it's up to you to protect your own privacy. but to claim that the US government is doing this with AI companies, it's just flat wrong.

Chinese Communist party? it would be funny if China didn't have laws related to companies in China exfiltrating foreign data and giving it to the government for espionage purposes, z.ai is a chinese company, based in the capital Beijing. The likelihood that they work with the government hand in glove is pretty high. I wouldn't run that binary on any machine I was doing anything serious with. If you ran it on a corporate network, I would hope security escorts you out of the building.

it all looks suspicious:

  - June 1st 2026: Anthropic files S-1 paperwork with SEC to get ready for IPO

  - June 2nd 2026: Anthropic annouces expanding "Project Glasswing" to let people use their new model to enhance security of existing systems

  - June 9th 2026: Anthropic releases Mythos model

  - June 12th 2026: Model gets export regulations placed on it by US Gov

  - June 26th 2026: US gov announces they will let some companies use new model

  - August 2026: Anthropic goes IPO

The timing of all of this just seems to be a play to pump the stock. The reality is that in six months GLM-5.3 will be released open source with comparable functionality to their Mythos model. They are trying to cash in before that happens.

I would not be surprised if the US government, the people pulling the strings who actually put the export announcements onto Anthropic, actually have purchased stock in the company to artificially pump up the stock, I would bet money on it.

most large companies have a 2-year limit on contractor employment so what they tend to do is they'll hire the same guy through a different contractor with another two-year agreement..... that's to get around the situation where if someone is working as a contractor for more than 2 years they can legally claim that they're actually an employee....see Vizcaino v. Microsoft Corp., 120 F.3d 1006 (9th Cir. 1997) [0]...

this is just a guess by the way but it seems like a plausible one, as I've seen it happen in Fortune 500 a lot, where the same guy comes back through a different vendor 2 years later if he was really good and they needed him to come back....

[0] https://law.justia.com/cases/federal/appellate-courts/F3/120...

The situation you reference is related to a specific investigation by US congress requesting documents about potentially illegal censorship actions by EU officials from a specific company (microsoft). The difference is that the laws in china are broadly defined to include giving all intellectual property of anyone back to the government with no oversight, for the purposes of espionage.

The former relates to a specific investigation about potential criminal activity, the latter relates to broad illegal activity committed by the government itself unrelated to any specific case.

The US has no laws on the books forcing companies to wantonly give intellectual property and other espionage level material back to the government. If they did, no one would use cloud providers.

To avoid this, you can run your own hosted machine in a colocation facility, because in the US, people do have reduced rights when their data is controlled by a third party versus being controlled by themselves. Its the same as if the data was in your house, they would need a search warrant to obtain it, but when its at a Azure or AWS datacenter not controlled by you, your privacy rights are reduced by doing this.

there's laws on the books in China that says that every company operating in China must aid and abet the Chinese government in espionage against the rest of the world. given those facts, I find it deeply troubling to be using anything coming out of China, especially a program that runs in the context of a Linux terminal on a machine that might have something important on it. I'd argue it's a back door waiting to happen, if not sooner than obviously later.

you dont have to go look at the Google Graveyard [0] to understand that you might try a google product one day or month to have it either disappear or become a different product incompatible with the first the next month. They have been known for this for at least decades now.

Gemini CLI was fun for five minutes of testing until it tried to rewrite my whole code base.

[0] https://killedbygoogle.com

New Nginx Exploit 2 months ago

yeah when I read these RCE reports about public-facing software that I know about I usually upgrade them within minutes of reading the report that's why I read these reports and you really have to take them seriously because otherwise your machine gets compromised, sooner rather than later... it seems like lately there's been no advance notice on a lot of these RCE exploits that are publicly released, I mean come on guys at least give us a few minutes to upgrade our software before releasing the exploit, it feels like the late 1980s early 1990s when there was no guardrails on disclosure, i.e. all the remotely exploitable sendmail bugs. people who fail to read these reports or read them too late wind up having millions of machines being compromised because of it. currently nginx has about a 39% - 43% share of the public facing web server market today, so its pretty serious.

Facebook the web site reminds me of a really bad implementation of MySpace. MySpace was better, even in 2003. There are hundreds of usability bugs that exist on various parts of the platform that for over a decade remain unfixed. For a company that has 78,000 employees, you would think one of them might want to dig in and fix the web interface bugs. What's weird is in the age of Claude Code, it would probably take one software engineer a week to fix all of them, so its really pure incompetence. I think they spend more time on automation around restricting the usage of the platform that they forgot about the user interface bugs that plague it.

Also, avoid using Meta Pay aka Facebook Payments, where a user can send a payment to another user via the Messenger app. Someone sent me money a few weeks ago, and a two weeks alter they still have the payment marked as "Completed" on the sending side, and "Cancelled" on the receiving side. I told the sender to just do a chargeback with their bank because Facebook basically stole the money. Don't use Meta Pay for sending payments to anyone. Then when you try to open a "case" about it, you call a call center in Indonesia and the people have no access to see anything about the transaction, they just send it up the chain, only to have an automated response telling you to do something that the web site doesn't even offer as an option. I don't think there is any humans in the loop, besides the Indonesian call center that has no access to any of what you're calling about.

in 2002 I worked at an AT&T major datacenter and watched the NSA install all the black boxes in every rack, complete with a black curtain and armed guards while they did the project (St Louis). Before that it was still going on, it just wasnt so embedded like they did in 2002.

the authors reference to LLM's as "bullshit machines" is more true the less parameters you have trained in your model....as we scale up to trillions of parameters, add Mixture of Experts (MoE) architecture, this no longer is an accurate statement. Proof in point was yesterdays announcemnt of Mythos 5 model (10T parameters + MoE [1]) by anthropic where it seems to be so good at finding/exploiting vulnerabilities in source code that have been there for decades and only recently uncovered needs to be used to fix these critical vilnerabilities first before it gets released to the public, they even have a project called Glasswing [2] dedicated to letting people fix the thousands of vulnerabilities already found by the model before they release this model to the public, because it's so good at what it does... I think we're a little bit past the point of calling these models "bullshit machines" at this point...

[1] https://www.aimagicx.com/blog/claude-mythos-5-trillion-param...

[2] https://www.anthropic.com/glasswing