HN user

rixthefox

254 karma
Posts1
Comments74
View on HN

I think one of the major reasons why it’s not here is because most AI tools are great for getting a prototype built up but undertaking a program like Photoshop which we can assume has a couple millions of lines of code is actually not easily replicable by vibe coding.

Can it be done? Probably. But the token cost to do so would be astronomically expensive. You still need a human (read prompt engineer) to steer the AI. Even small ideas I’ve thrown at it to test viability is often plagued by code that just simply doesn’t work. I am constantly having to send it back and say “this doesn’t work” and it will eventually figure it out but that is more wasted tokens just to get something that doesn’t throw an error during the build process.

One-off specialty programs are absolutely going to feel the heat. Take a multi-tone generation application (think Motorola pagers). You can now ask an AI to create that program for you, complete with tone generation and .wav recordings to use later.

Large programs are relatively safe for the moment just because of scale. But any small application that is usually behind some sort of paywall or license is absolutely going to be threatened since it’s no longer difficult to throw together a program in an evening and have 100% of the features you want and none of the features you didn’t need or want.

Starlink by virtue of being your ISP would have access to any DNS queries you send over the Internet over UDP port 53 in plain text. Starlink is also able to redirect those queries to their own servers. Even if you manually specify 8.8.8.8 or 1.1.1.1 Starlink can redirect traffic to their own DNS servers and return responses as if they came from those servers.

By itself DNS can tell a pretty detailed picture about you and what you do on the Internet without the need for SSL inspection or other deep packet inspection techniques.

Amateur Radio has entered the chat.....

Even as a licensed ham it's getting increasingly difficult to even get hardware that allows utilization of frequencies I'm duly licensed to transmit on in the 2.4 GHz band. Short of building and designing your own transmitters it's become impossible to repurpose hardware like it was before. Our club has aging M2 Rockets from Unifi that were modified for this use that are now decaying and dying. It's unfortunate too because once these stop working that's it. A few club members have been championing GLiNET but same problems. They are relying on older models which weren't as locked down and already show signs of suffering the same fate as the Rockets.

In this economy? /s

The other more compelling reason why people would have a rooted phone is to run ROMs that may still be providing OS support where the stock OS has been abandoned or EOL'd by the developer.

Having an unlocked bootloader at the minimum would be required in those scenarios. It actually saves hardware that still works from ending up in landfills.

edit: spelling

This is the way. Widevine is a cancer that only serves to lock down the browser market to a small handful of web engines that have been approved by Google. If your browser isn't based on Chrome, Firefox, or Safari you're out of luck.

Most people will not use a browser that can't open youtube videos and they know and exploit this with extreme precision.

Am I right in this assumption?

Yes. I tried using Chrome on Linux just to watch movies that I purchased on Youtube at HD/4K and watched as the stream was limited to 240P. IMHO regardless of what Google says in their ToS they have already broken the trust agreement by not providing what I paid for. Regardless of what the studios want, all this does is push me back towards piracy because once again the industry fails to understand that piracy is a accessibility problem, not a financial problem. If I pay for 4K then regardless of where I want to watch that movie it better be in 4K, that's what I paid for. Google hides behind their ToS to get around the fact that they sold me a product then failed to deliver.

ChromeOS gets 1080p/4K not because it has massive market share but cause the hardware and boot chain are locked down by the almighty Google.

ChromeOS is based on Gentoo Linux underneath just very stripped down and Googlefied. It's the same BS that Bungee pulled with Destiny 2 and Linux. If you so much as dared to run Destiny 2 on Linux you would be banned. Stadia used Linux but because Google controlled the platform they allowed it to be played there.

These are the games they play to make other platforms that aren't MacOS/Windows appear like they are incapable but in reality it's just corporate greed and grift.

I think the difference is really more noticeable if you're on a limited connection. For example, on Starlink I only have 50 GB to play with. It's entirely ineffective if the browser downloads the ads and only scrubs them out of the view after the fact. Same with anybody using a mobile hotspot over LTE. In those situations bandwidth is super limited (I have 5 GB of hotspot data a month) unless you can convince the carriers to zero-rate data pulled for advertisements (they won't) I'll continue blocking ads before they can be loaded.

Edit: and I'm not on some cheap MVNO, I'm paying over $80 a month with AT&T on their post-paid plan. The phone gets unlimited data but any other device I may need to share that connection needs to be as efficient with bandwidth as possible. Only Firefox and derivatives provide proper ad blocking at this time.

Oh I agree 100%. I also play for my search engine so it's definitely not a lack of interest in doing so. I agree with your point as well. Get rid of the money vultures in the C-suite who are paying themselves exorbitant salaries and hand that money over to the Firefox devs. Give them the runway necessary to bring on more developers that would give Firefox the attention it needs to keep up with Chrome/Chromium and maybe start playing with the idea that if you want the latest updates when they release you pay for the browser. If you don't need immediate updates you'll get the deferred releases under a 1-2 month delay or whatever they deem fit with security fixes obviously being backported to keep those who refuse to pay happy enough to not abandon the browser entirely.

Unfortunately this is not unexpected because Mozilla needs to continue receiving money to survive and unfortunately nobody wants to have the tough conversation about paying for a browser so when whoever is funneling money into Mozilla (Google) says you need AI in your product you have no choice but to jump.

I think their logic is a bit wrong here. Microsoft is a "trusted" entity. Trust doing a lot of heavy lifting here, and even they had to roll back their AI ambitions after seeing the lackluster adoption rates of people using their AI features. The trust part just doesn't matter. It's the principal that we've had browsers for over 20+ years and we never needed AI in our browsers. I would quickly abandon Firefox for an alternative in a heartbeat that doesn't include AI in it.

The uncomfortable truth for all these companies though is that most people simply do not need AI in the places they are shoving it into. Like why does notepad need AI?

Fuck that noise. The places that shadow ban and encourage self-censorship do not deserve your traffic nor your content.

Start voting with your voice and your (digital) feet. Don't be sheeple. Keep the Internet weird. It is not on us to censor ourselves to protect the feelings of snowflakes who get all bent out of shape because of something someone said.

GCP Outage 1 year ago

Those contracts will be monitoring their service availability on their own. If Google can't be honest you can bet your bottom dollar the companies paying for that SLA are going to hold them accountable if they report the outage properly or not.

but it would seem a reasonable protection for consumers in general.

The final say may ultimately come from the Cox vs Record Labels case from 2019 that is still working it's way through the appeal courts.

If the record labels win their appeal, anyone who helped facilitate the infringement can be brought into a lawsuit. The record labels sued Cox for infringement by it's users. It's not out of the question that any ISP that provides Internet connectivity to Facebook could be pulled in for damages.

For Meta these two cases could result in an existential threat to the company, and rightly so because the record labels do not play games. The blood is already in the water.

The article is exactly right. Tech Bros aren't building communities but the people trying to build communities are being suffocated by the same platforms they attempt to use to build them.

So to make it painfully obvious for everyone here, if your first thought is to make:

A Facebook Group

A Discord server

A Subreddit

(Insert other walled garden here)

You aren't solving the problem and you won't get anywhere close because these platforms will shut down your group for ToS/AUP violations before you even get close to enough people to spur any sort of action. If you cannot self-host, find someone who knows how or take this opportunity to learn how.

And, if you honestly need any further evidence of this censorship taking place, X (Twitter) heavily demotes any posts with links to Bluesky and Facebook was just caught not even a few days ago blocking links to Distrowatch. Now this is just the surface, what other stuff have they blocked and we've not heard of because it wasn't a high profile target like Distrowatch?

It is not my job to tell Microsoft to correct their behavior and follow standards.

There are standards for a reason [1] and if you break them, no matter how good your intentions you are in the wrong because you've changed the expected behavior. Full stop.

The Internet works because everyone has agreed to follow standards. If Google woke up one day and decided that every IP address that ended in an odd number would receive a captcha every time they searched people would understandably get pissed off. Well ISPs have thousands of IP addresses so for the convenience of the user it's the ISPs that need to assign their users IP addresses ending in an even number so that they can search without captchas, right? No!

Same thing here. Just because Microsoft and Google benefit from economies of scale and have many users does not give them a pass to break standards whenever they see fit. There is a reason why we have RFCs and mailing lists to have these sorts of discussions.

edit:

[1] https://datatracker.ietf.org/doc/html/rfc8058

It is well known that people change how they act when they know they are being watched. Even if they can't see it, just the threat of surveillance is enough to make people change their behavior.

I say it is no different than the people who are claiming they don't care. They absolutely do care, but at this point, saying "no" makes you the odd one with obviously something to hide, so they do this from a place of duress.

Unfortunately, I feel we are not too far from people finally snapping and going off the deep end because it's so pervasive and in-your-face that there is seemingly no escape left.

Half the US has already deployed it and 100% of the mobile carriers. I would say the detractors who continue to stomp their feet about not deploying IPv6 are holding a fake title of "Network Engineer". People need to grow up and do their job or get out.

That was not my intention at all. My concern is groups who do that kind of red team testing on open source projects without first seeking approval from the maintainers risk unintentionally poisoning a lot more machines than they might initially expect. While I don't expect this kind of research to go away, I would rather it be done in a way that does not allow malicious contributions to somehow find their way into mission critical systems.

It's one thing if you're trying to make sure that maintainers are actually reviewing code that is submitted to them and fully understanding "bad code" from good but a lot of open source projects are volunteer effort and maybe we should be shifting focus to how maintainers should be discouraged from accepting pull requests where they are not 100% confident in the code that has been submitted. Not every maintainer is going to be perfect but it's definitely not an easy problem to solve overnight by a simple change of policy.

Yes, getting through the article I was happy to see that wasn't the case and was just vulnerabilities that had existed in those programs.

Definitely they could have worded that better to make it not sound like they had been intentionally contributing bad code to projects. I'll update my original post to reflect that.

We recently performed research that started off "well-intentioned" (or as well-intentioned as we ever are) - to make vulnerabilities in WHOIS clients and how they parse responses from WHOIS servers exploitable in the real world (i.e. without needing to MITM etc).

R̶i̶g̶h̶t̶ o̶f̶f̶ t̶h̶e̶ b̶a̶t̶, S̶T̶O̶P̶. I̶ d̶o̶n̶'t̶ c̶a̶r̶e̶ w̶h̶o̶ y̶o̶u̶ a̶r̶e̶ o̶r̶ h̶o̶w̶ "w̶e̶l̶l̶-̶i̶n̶t̶e̶n̶t̶i̶o̶n̶e̶d̶" s̶o̶m̶e̶o̶n̶e̶ i̶s̶. I̶n̶t̶e̶n̶t̶i̶o̶n̶a̶l̶l̶y̶ s̶p̶r̶i̶n̶k̶l̶i̶n̶g̶ i̶n̶ v̶u̶l̶n̶e̶r̶a̶b̶l̶e̶ c̶o̶d̶e̶, K̶N̶O̶W̶I̶N̶G̶L̶Y̶ a̶n̶d̶ W̶I̶L̶L̶I̶N̶G̶L̶Y̶ t̶o̶ "a̶t̶ s̶o̶m̶e̶ p̶o̶i̶n̶t̶ a̶c̶h̶i̶e̶v̶e̶ R̶C̶E̶" i̶s̶ b̶e̶h̶a̶v̶i̶o̶r̶ t̶h̶a̶t̶ I̶ c̶a̶n̶ n̶e̶i̶t̶h̶e̶r̶ c̶o̶n̶d̶o̶n̶e̶ n̶o̶r̶ s̶u̶p̶p̶o̶r̶t̶. I̶ t̶h̶o̶u̶g̶h̶t̶ t̶h̶i̶s̶ k̶i̶n̶d̶ o̶f̶ r̶o̶g̶u̶e̶ c̶o̶n̶t̶r̶i̶b̶u̶t̶i̶o̶n̶s̶ t̶o̶ p̶r̶o̶j̶e̶c̶t̶s̶ h̶a̶d̶ a̶ g̶r̶e̶a̶t̶ e̶x̶a̶m̶p̶l̶e̶ w̶i̶t̶h̶ t̶h̶e̶ U̶n̶i̶v̶e̶r̶s̶i̶t̶y̶ o̶f̶ M̶i̶n̶n̶e̶s̶o̶t̶a̶ o̶f̶ w̶h̶a̶t̶ n̶o̶t̶ t̶o̶ d̶o̶ w̶h̶e̶n̶ t̶h̶e̶y̶ g̶o̶t̶ a̶l̶l̶ t̶h̶e̶i̶r̶ c̶o̶n̶t̶r̶i̶b̶u̶t̶i̶o̶n̶s̶ r̶e̶v̶o̶k̶e̶d̶ a̶n̶d̶ f̶o̶r̶c̶e̶ r̶e̶v̶i̶e̶w̶e̶d̶ o̶n̶ t̶h̶e̶ L̶i̶n̶u̶x̶ k̶e̶r̶n̶e̶l̶.

EDIT: This is not what the group has done upon further scrutiny of the article. It's just their very first sentence makes it sound like they were intentionally introducing vulnerabilities in existing codebases to achieve a result.

I definitely can see that it should have been worded a bit better to make the reader aware that they had not contributed bad code but were finding existing vulnerabilities in software which is much better than where I went initially.

It’s just easier to ban you rather than spend the time and money to see if you’re legit.

It’s even easier to just not release anything officially on the Play Store and go 100% into sideloading apps. Cut Google right out of the equation.

Why blame LetsEncrypt? Instead blame the operators who are refusing to address basic network security.

I run a network, we do the whole shabang of RPKI, DNSSEC, and CAA. It sounds a whole lot like operators who refuse to address clear security issues. LetsEncrypt is not to blame when someone spoofs your address space.

LetsEncrypt is not a LIR/RIR, their business is not IP resources but SSL certificates. They are a CA. They have no tools available to them to address that problem.

You don’t have to pay a dime. But don’t expect the rest of the Internet (that DO pay for their resources) to continue to guarantee reachability to your address space.

If you won’t get on board with RPKI/IRR you can’t cry foul when the rest of the Internet is paying the price to be reachable.

I am a resource holder and I pay my dues. I have no problems with paying for that privilege.

Internet access is not an inalienable right. It is a privilege. Even as it’s become increasingly more and more of a utility. Until laws start to reflect that, it is still a privilege at best.

Edit: before someone says anything about the trust anchors. Reminder, There are two overarching namespaces to the Internet. IP and DNS. You are free to ignore the authorities of both but don’t expect the rest of the Internet to play along when you want to use .billybob as your TLD.

Nothing wrong if it works faster, but it's not impossible to make tools that are compatible with other standard testing programs. By intentionally ignoring the tools network engineers are already using every day Microsoft is really shooting themselves in the foot and showing that they are tone deaf to the needs of users outside of their walled garden.

How many routers do you know off the top of your head that run Windows?

I would suspect Microsoft's corporate culture is to blame for that. If you make a tool that "already works on Windows" work you don't get any extra praise. If you however come up with a brand new thing you'll get a slap on the back and a raise!

That's exactly it. The untapped people are actually getting bunched into the "underperforming" category because in the eyes of the beancounter they are not meeting some benign performance metric that the company wants to see.

Say I'm a phone support company. I have a script I want my employees to follow and the average support time per phone call should be anywhere between 15-30 minutes. Sally Sue is on the phone for the full 8 hours and handles 16 calls a day. Billy Brass is on the phone for 4 hours of the day but handles double the amount of calls a day.

To the bean counters Billy is underperforming because he only spends 4 hours time on the phone and the company only makes money for the amount of time they can keep people on the phone. In this example it doesn't matter that Billy is an all-star because he completed more calls, he's underperforming because he's not following the script that should keep people on the phone for as long as possible.

The point is that Billy will feel resentful because even though he's able to help more people in less time he's getting penalized so Billy has less incentive to go above and beyond and in fact needs to degrade his workflow to fit someone else's metrics. So Billy becomes "untapped" because the company has restricted his autonomy. He "CAN" do more but that's not what the company wants from him so he will choose not to do it even if it's to the benefit of the company.