HN user

newtonsmethod

43 karma
Posts1
Comments35
View on HN

I assume they're using a more candid definition where they're not counting all the countries a company may be based, but rather the primary country they're based in.

I don't think they're trying to flex this as a large number. They don't want to give an exact number, as that may change etc / is fuzzy, but also want to give you an idea of the scale.

They say "In the future, we intend to expand our geographical reach much further". I imagine this commentary is somewhat related to the concerns that AI will create an even worse "global underclass". AI developments are first accessible to Americans, then allies, and then later the whole world.

There's a comment on the GitHub thread which also mentions pinning rsync version would be a bad idea. Many of the people affected by reversions are those with workflows vulnerable to the prior CVEs.

I don't actually see much evidence the usage of AI here was an issue. I think you can obviously identify areas where the code isn't perfect. I'd blame this slightly on human prompting, slightly on AI.

But I'm not a sure a human on their own would've done better. There aren't enough resources to make the changes required.

Can you tell me any of the bugs? All claims I have seen so far of people being affected by bugs seem deeply implausible.

The current ones I see are: * Can't build on Linux < 5.6. But people aren't complaining strongly about this, since it requires a build from source / isn't a result of an update from a distribution (and people can wait for updates / implement them themselves). * An issue hit with chroot false + daemon. People running this in an automated manner (as some claims suggest) are already using it in a way fairly likely to be insecure, chroot false is strongly discouraged here, and the whole point of these commits was that they fixed CVEs impacting precisely these people.

Just because you got shat on the head once it doesn't mean it's fine to be shat on the head every day now.

This happens frequently when there are fixes for CVEs, since regression tests can't catch many things which incremental rollouts can. It happened for example in 2025. People are right to imply the reaction is totally outsized here, and it's almost certainly the case that people are overreacting to AI (rather than the somewhat weak idea that it's because of the frequency of these issues).

What's really funny is that the people opposing AI here are showing far less literacy than those who wrote the code. People claiming to be affected by this bug severely are likely exposing themselves: * One bug is for Linux < 5.6, where it didn't hit distributions. This is a low severity bug where it can't build, where distribution maintainers may be reasonably expected to fix it themselves (although rsync will also fix it eventually too).

* The other bug affects precisely the people impacted by the CVE https://github.com/RsyncProject/rsync/issues/897

You probably don't want to revert in this scenario. If someone is hit by this bug and is running rsync in an automated manner, it is highly likely they're ignoring very many security practices: you're usually not supposed to run native rsync in an automated manner (the main use case is for public users, where you can't SSH etc; since it's unencrypted, you're supposed to check a checksum against a website etc); these cases are hit with chroot false, which is deeply discouraged and leads to far larger attack surfaces.

Yes, the actual issues seem to be:

* People with linux < 5.6 can't build this from GitHub. This to me seems like a fairly minor regression: people using maintained versions of 5.6 (mostly extended security) will have distro maintainers pick up that the build is failing, allowing for it to be corrected in a timely manner.

* Hardening against path-traversals causes failures for users with: no chroot; using the native rsync protocol. Ironically: chroot = no is deeply discouraged; you shouldn't really be using native rsync in an automated manner (and perhaps it seems I wouldn't advise using it at all); the CVEs the commits fix apply exactly to this use case.

https://www.cve.org/CVERecord?id=CVE-2026-29518

Requires daemon + no chroot. " daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false."

So the workflows affected are those which are the most vulnerable, and yet people are recommending that people revert versions.

* Furthermore, if a regression test picked this up, it would've been written previously.

Is your justification in dismissing Fields medalists that they are impressed by funding? Not even receiving it (I assume you say this because Tao is not funded by AI for Math, but rather an advisor for it)?

Not only would it be a leap to suggest that people automatically lose their integrity by taking funds for projects they believe are useful, especially after involvement with adjacent fields, but you are suggesting merely being impressed by a fund is enough to dismiss their views?

You also have no evidence that Renaissance Philanthropies is a front for VC companies. All news coverage indicates that they seek to be an alternative for high net worth individuals engaging in philanthropy.

Many people discovering Erdos results, engaging in Olympiads etc, are doing so with publicly available models and publish the resources used in the process.

Have you read the DPA? How did you come to your inclusions on its intent? How do you think Biden stretched the definition here?

There is nothing in the DPA implying companies it is applied to can't be acting in a hostile manner, or that it can't be applied when security interests of the US are being threatened. Of course they have no reason to state such a distinction repeatedly in law (claiming it doesn't apply to adversarial companies....), but 50 USC 4566 applies clearly when acts are being made against national interest (this pertains to foreign investment, which isn't the nature of the Anthropic rift, but shows clearly the DPA contains laws with intent of preventing adversarial action against the US).

Even without knowing the intent of the behaviour, it should be quite clear that companies that are vital to national security are more likely to be supply chain risks. Amodei's direct words were: > These latter two threats are inherently contradictory: one labels us a security risk; the other labels Claude as essential to national security. Being a security risk and essential to national security are not "inherently contradictory".

Are you reading things before agreeing with them? Or thinking about them? It doesn't seem obvious these things are contradictory at all. That Politico reports so doesn't make it the case.

It is clear that the DPA can be invoked for companies posing risks to national security:

On October 30, 2023, President Biden invoked the Defense Production Act to "require that developers of the most powerful AI systems share their safety test results and other critical information with the U.S. government" when "developing any foundation model that poses a serious risk to national security, national economic security, or national public health."

Furthermore, it should be quite obvious that companies very important for national security can act in manners causing them to be national security risks, meaning a varied approach is required.

I have agreed tariffs will have an effect, but I'm not being myopic.

Lot costs, builder profits, indirect labour (commissioning, financial and legal affairs, advertising) all are far less affected by tariffs. Machine costs could make up 15% of your "labour and material" cost but depreciation and repair purchases are still only 30% of this, with of course not all of this affected by tariffs.

It seems wholly reasonable to believe that the long term effects of a tariff policy like these on housing costs could indeed be in the ballpark of 5%, as I claim, because in fact housing development is less affected by this.

I'm not sure if you trust this for consensus, but you could try asking an AI to give an estimate of the long-term impact for you. Here's what Gemini 3 Pro said to "Estimate the increase Trump's current tariffs, if long term, would have on price of new housing developments."

Total Home Price Impact: This translates to a roughly 3% to 4% increase in the final purchase price for the consumer.

The claim they went into effect January 1 simply does not seem true.

The finished products tariff was delayed: https://edition.cnn.com/2026/01/01/business/trump-furniture-... For unfinished lumber, I don't think there was any tariff going into effect January 1.

Sure, these tariffs may further increase the house of prices (e.g. be relevant to 15% of the cost of the house, with tariffs ranging from 20% to 50% and sources of materials adjusting to these tariffs), but the say 4% future effect of these tariffs is likely less than the effect of zoning laws, other development restrictions, and rent freezing.

I agree with the first half of what you posted, but immediately jumping to blaming tariffs in your last paragraph seems weak (and a slight attempt at a gotcha).

Concrete, gypsum and steel are primarily domestically produced. Similar goes for wood (although a substantial amount is imported, e.g. from Canada - the tariffs range from 25% to 50%). Labour & Materials may make up say 60% of the cost of a house, but only 50% of this is likely materials, with likely a minority of the materials tariffed.

What is likely to actually reduce rent and house prices is making development permission and laws more lax, as well as preventing rent control.

A nonpartisan newspaper could also condemn or blame a political party for an action. But if all of its posts were supportive of one administration, it would no longer be partisan.

You can just look through the old white house accounts. For example this tweet https://x.com/WhiteHouse46/status/1879171105044181097 , "While Congressional Republicans refused to pass a bipartisan border security agreement, President Biden took action and encounters today are the lowest since July 2020."

Looking through the tweets, you'll see it's not nonpartisan and isn't supposed to be.

Neon has updated their pricing plans to be usage based. Their free tier has decreased to offering a maximum of 50 compute hours per project (down from 190), but now offers a total 500 compute hours across up to 10 projects (rather than 190).

I think the article is highly exaggerating Starbuck's role at meta, and serves more of a role in being polemical. The WSJ have themselves reported on it: https://www.wsj.com/tech/ai/meta-robby-starbuck-ai-lawsuit-s....

Likely because of the polemics of the article and its headline, many people in this thread are misinformed as to what Starbuck's role will be and that this came about as the result of a settlement.

There is also the joint statement posted by Joel Kaplan on X (likely the source for many articles): https://x.com/joel_kaplan/status/1953778908915982793 "Building on that work, Meta and Robby Starbuck will work collaboratively in the coming months to continue to find ways to address issues of ideological and political bias and minimize the risk that the model returns hallucinations in response to user queries."

For a more charitable interpretation: the pinknews is a source that regularly produces low quality, poorly fact-checked and polemical content, and is to me on the same level as the daily mail. The article here seems somewhat polemical, and it is difficult to verify if some of the stronger claims made are actually true.

The headline focusses on polemics and omits a detail many people would find quite important: that this was part of a lawsuit settlement. It also decides to use the word "appoint", which has a stronger underlying implication that Starbuck will have a job at / take a significant role in doing this at Meta.

It is important that this information is shared, but it is better if it's done accurately. I don't see why the source that Pinknews used itself, https://www.wsj.com/tech/ai/meta-robby-starbuck-ai-lawsuit-s..., wasn't used instead.

Even if you think a lot of the content captured by the ban should be banned, I don't think age restriction mechanisms should be put on it. Talks around sexuality, the mere mention of certain crimes and unrest are being banned by social media companies, all because of this act. Companies seem to be acting out of caution.

I simply don't want to be forced to provide my ID / face to be able to read or access politically important news on social media. Some people would be happier if the bill was limited to only pornography: they likely don't think it has a major effect on UK politics.

The energy use by AI probably is just as, if not more, carbon intensive, but the article never says that. It talks about the energy use of the general data center.

The carbon intensity of electricity used by data centers was 48% higher than the US average.

I agree, the effects of fluoride probably aren't in the top 5 things to be concerned about (although perhaps they are from a political perspective, with it becoming such a strong topic of debate for a variety of reasons). But do you assume that getting to n=10,000 is going to show little or no effect (e.g. having a level you define as little effect)? I'm not convinced the NTP data is extremely high quality and can't make much conclusion from it on the effects.

Also, for other commenters: the 2832 children number I believe comes from the supplemental content from the supplemental material for the NTP Fluoride Monograph: https://cdn.jamanetwork.com/ama/content_public/journal/peds/... (this url is very long because of some hashing measure, sorry: if it is no longer accessible, it is the supplemental content for doi:10.1001/jamapediatrics.2024.5542), on page 51 of the PDF. I have a small summary table of data I view relevant here:

The columns are:

* Studies used; Fluoride Exposure; Number of Studies / Number of Observations (number of Children)

* Estimate for slope in linear Model, given as increase in IQ points per mg/L increase (95% CI) (p value)

All studies; < 2mg/L; 8 / 10 (N = 3682); -0.18 (-0.40, 0.03) (p = 0.096)

All studies; < 1.5mg/L; 7 / 7 (N = 2832); 0.05 (-0.36, 0.45) (p = 0.816)

Low risk of bias studies; < 2mg/L; 4 / 5 (N = 1632); -0.33 (-0.53, -0.13) (p = 0.001)

Low risk of bias studies; < 1.5mg/L; 3 / 3 (N = 879); -0.32 (-0.91, 0.26) (p = 0.276)

The issue is that putting fluoride in the water isn't really "treating" the water. It's in essence acting a medication (see my paragraph below for a justification of this), to the benefit of people's teeth. As far as I know, every other chemical added / removed from the water is done for the purpose of the taste of the water, protecting the pipes which serve the water, or disinfecting the water. In this way, it's different from all the other chemicals, and there is also some limited opposition to other chemicals (e.g. debate on the use of UV / chlorine / ozone).

As for a loose argument for why fluoride in water is medicinal: the FDA classifies toothpaste as a cosmetic and also potentially a drug (depending on whether it contains fluoride and the claims the product makes):

Ingredients that cause a product to be considered a drug because they have a well-known (to the public and industry) therapeutic use. An example is fluoride in toothpaste.

Some products meet the definitions of both cosmetics and drugs. [...] Among other cosmetic/drug combinations are toothpastes with claims to freshen breath and cleanse the teeth that contain fluoride. [Both quotes are from https://www.fda.gov/cosmetics/cosmetics-laws-regulations/it-...]

I think the common consensus is that the primary benefit of fluoride is topical, not systemic:

* Initially, fluoride was considered beneficial when given systemically during tooth development, but later research has shown the importance and the advantages of its topical effects in the prevention or treatment of dental caries and tooth decay. [The Fluoride Debate: The Pros and Cons of Fluoridation; Prev Nutr Food Sci, 2018; https://pmc.ncbi.nlm.nih.gov/articles/PMC6195894].

* The actual mechanism of fluoride action is still a subject of debate. A dogma has existed for many decades, that fluoride has to be ingested and acts mainly pre-eruptively. However, recent studies concerning the systemic effect of fluoride supplementation concluded that the caries-preventive effect of fluoride is almost exclusively posteruptive. [Systemic versus topical fluoride; Carries Res, 2004; https://pubmed.ncbi.nlm.nih.gov/15153698/]

* As noted by Thorrez, your link does not mention topical application vs systemic ingestion. There is a publication from the CDC however stating that the benefit of fluoride is mainly topical:

Fluoride's caries-preventive properties initially were attributed to changes in enamel during tooth development because of the association between fluoride and cosmetic changes in enamel and a belief that fluoride incorporated into enamel during tooth development would result in a more acid-resistant mineral. However, laboratory and epidemiologic research suggests that fluoride prevents dental caries predominately after eruption of the tooth into the mouth, and its actions primarily are topical for both adults and children (1). [https://www.cdc.gov/mmwr/preview/mmwrhtml/mm4841a1.htm ; 1999].

This material was covered in depositions for TSCA Fluoride trial in 2018, where Casey Hannan (director of the division of oral health at the CDC) was the examinee for the deposition. A temporary upload of a clip from this deposition may be found at https://0x0.st/8Lom.mp4.