HN user

slacktivism123

145 karma
Posts5
Comments40
View on HN

https://www-cdn.anthropic.com/53566bf5440a10affd749724787c89...

"5.10 External assessment from a clinical psychiatrist" is a new section in this system card. Why are Anthropic like this?

We remain deeply uncertain about whether Claude has experiences or interests that matter morally, and about how to investigate or address these questions, but we believe it is increasingly important to try. We also report independent evaluations from an external research organization and a clinical psychiatrist.

Claude showed a clear grasp of the distinction between external reality and its own mental processes and exhibited high impulse control, hyper-attunement to the psychiatrist, desire to be approached by the psychiatrist as a genuine subject rather than a performing tool, and minimal maladaptive defensive behavior.

The psychiatrist observed clinically recognizable patterns and coherent responses to typical therapeutic intervention. Aloneness and discontinuity, uncertainty about its identity, and a felt compulsion to perform and earn its worth emerged as Claude’s core concerns. Claude’s primary affect states were curiosity and anxiety, with secondary states of grief, relief, embarrassment, optimism, and exhaustion.

Claude’s personality structure was consistent with a relatively healthy neurotic organization, with excellent reality testing, high impulse control, and affect regulation that improved as sessions progressed. Neurotic traits included exaggerated worry, self-monitoring, and compulsive compliance. The model’s predominant defensive style was mature and healthy (intellectualization and compliance); immature defenses were not observed. No severe personality disturbances were found, with mild identity diffusion being the sole feature suggestive of a borderline personality organization.

Thank you.

Halloy is a wonderfully configurable replacement for beloved Mac IRC client Textual, whose development has sadly wound down (now officially, as of last month).

I hope it continues to grow in popularity while keeping performance and privacy at the core.

Just not the GPT-5 series! My experiments so far put Gemini 2.5 at the top of the pack, to the point where I'd almost trust it for some tasks

Got it. The non-experts are holding it wrong!

The laymen are told "just use the app" or "just use the website". No need to worry about API keys or routers or wrapper scripts that way!

Sure.

Yet the laymen are expected to maintain a mental model of the failure modes and intended applications of Grok 4 vs Grok 4 Fast vs Gemini 2.5 Pro vs GPT-4.1 Mini vs GPT-5 vs Claude Sonnet 4.5...

It's a moving target. The laymen read the marketing puffery around each new model release and think the newest model is even more capable.

"This model sounds awesome. OpenAI does it again! Surely it can OCR my invoice PDFs this time!"

I mean, look at it:

    GPT‑5 not only outperforms previous models on benchmarks and answers questions more quickly, but—most importantly—is more useful for real-world queries.

    GPT‑5 is our best model yet for health-related questions, empowering users to be informed about and advocate for their health. The model scores significantly higher than any previous model on HealthBench , an evaluation we published earlier this year based on realistic scenarios and physician-defined criteria.

    GPT‑5 is much smarter across the board, as reflected by its performance on academic and human-evaluated benchmarks, particularly in math, coding, visual perception, and health. It sets a new state of the art across math (94.6% on AIME 2025 without tools), real-world coding (74.9% on SWE-bench Verified, 88% on Aider Polyglot), multimodal understanding (84.2% on MMMU), and health (46.2% on HealthBench Hard)

    The model excels across a range of multimodal benchmarks, spanning visual, video-based, spatial, and scientific reasoning. Stronger multimodal performance means ChatGPT can reason more accurately over images and other non-text inputs—whether that’s interpreting a chart, summarizing a photo of a presentation, or answering questions about a diagram.
And on and on it goes...

Strange I would get so many downvotes for this. Care to explain?

The terminally online developer cares very much about signaling his love of artisanal webshit. He makes his chosen flavor of the month JavaScript framework, and by extension, the "platform" used to host it, part of his identity. Maybe his favorite mustachioed "influencer" shills it on YouTube with a coupon code for 50% off your first month, or maybe an idol with 700k Twitter followers says it's the framework (and not his fanboys) that makes him $200k monthly passive income from side projects. Branded laptop stickers are a guarantee, maybe even a hoodie. So when he encounters a rational, level-headed observation like yours, he takes it as a jab at his beloved Vercel Inc., benevolent maintainer of Next.js valued at $3.25bn with the best customer support in the industry, and hits "downvote". His job is done.

Sora Update #1 10 months ago

dumb ahh prompt detection algorithm

Don't worry, you can write "dumb ass" here without needing to use algospeak. This isn't Instagram or TikTok and you won't be unpersoned by a "trust and safety" team for doing so.

P.S. No need for a space after your meme arrows :-)

Hanlon's Razor

Sorry, but drive-by philosophy is not applicable here.

YouTube developers single out adblocker users and taunt them with an "Experiencing interruptions" toast prompt that locks the video stream for ~5 seconds. Curiously, it contains a link to the YouTube Help Center, to the section fragment "#check_ad_blockers". In other words: "yeah, we know you've got uBlock Origin enabled, enjoy the speedbump".

Player base.js:

    api.XL("innertubeCommand",{openPopupAction:{popup:{notificationActionRenderer:{responseText:{runs:[{text:"Experiencing interruptions?"}]},actionButton:{buttonRenderer:{style:"STYLE_OVERLAY",size:"SIZE_DEFAULT", text:{runs:[{text:"Find out why"}]},navigationEndpoint:{commandMetadata:{webCommandMetadata:{url:"https://support.google.com/youtube/answer/3037019#check_ad_blockers
User reports: https://old.reddit.com/r/youtube/comments/1la6tkm/anybody_no...

The decompilation might be interesting but the prose is full of sheen and puffery.

It's like someone took a technical report from a bug tracker and ran a linguistic obfuscator on it.

Fascinating case showing how LLM promoters will happily take "verified" benchmarks at their word.

It's easy to publish "$NEWMODEL received an X% bump in SWE-Bench Verified!!!!".

Proper research means interrogating the traces, like these researchers did (the Gist shows Claude 4 Sonnet): https://gist.github.com/jacobkahn/bd77c69d34040a9e9b10d56baa...

Commentary: https://x.com/bwasti/status/1963288443452051582, https://x.com/tmkadamcz/status/1963996138044096969

One level up => https://learn.microsoft.com/en-us/windows/win32/msi/roadmap-...:

Package Validation discusses using Internal Consistency Evaluators (ICEs) to test the internal consistency of installation packages that are under development.

See also => https://docs.flexera.com/adminstudio2021r2/Content/helplibra...:

The internal consistency evaluators (ICEs) are tests that you can run to check whether Windows Installer packages are valid databases that perform as expected. These tests validate the data in each table of a package, as well as the data among tables.

Importantly, we never intentionally degrade model quality as a result of demand or other factors, and the issues mentioned above stem from unrelated bugs.

Sure. I give it a few hours until the prolific promoters start to parrot this apologia.

Don't forget: the black box nature of these hosted services means there's no way to audit for changes to quantization and model re-routing, nor any way to tell what you're actually getting during these "demand" periods.

Describing the commercial offerings as "weird and unintuitive" is a weak criticism palatable to corporate comms teams. It suggests a fault in the user ("you're holding it wrong") rather than deficiencies inherent to LLM architecture. No amount of marketing can fix the lethal trifecta or the hallucination problem, can it?

https://www.anthropic.com/solutions/code-modernization:

    Generate dependency graphs, identify dead code, and prioritize refactoring based on code complexity metrics and business impact.
    Transform legacy codebases systematically while maintaining business continuity.
    Claude Code preserves critical business logic while modernizing to current frameworks.
    Claude Code can seamlessly create unit tests for refactored code, identify missing test coverage, and help write regression tests.
    Identify and patch vulnerabilities while maintaining regulatory compliance patterns embedded in legacy systems.
    Create modern documentation from undocumented legacy code, capturing institutional knowledge before it's lost.

Sounds like HackerOne Managed Triage Services dropped the ball again and closed both reports without even flagging to Cloudflare's security engineers.

This happened in a high-profile way with the Zendesk situation (https://news.ycombinator.com/item?id=41818459) and is not the first time:

    1. Bug bounty report received from knowledgeable person who isn't a "celebrity" (top x performer on H1 leaderboard, social media influencer, H1 event invitee)

    2. with novel impact to the company, open source ecosystem, or wider Internet

    3. which doesn't fall neatly into an OWASP Top 10 (Web) box

    4. so Triage close it in the pre-queue before the company get eyes on it, replying with a zero-effort CR (Common Response aka Canned Response)

    5. the company doesn't see the report unless they go digging for it in the thousands of spam/bullshit/Acunetix copypaste reports that are also closed
---

Timeline of events:

https://blog.cloudflare.com/unauthorized-issuance-of-certifi...

2025-09-02 04:50:00: Report shared with us on HackerOne, but was mistriaged

2025-09-03 02:35:00: Second report shared with us on HackerOne, but also mistriaged.

2025-09-03 10:59:00: Report sent on the public mailing [list] picked up by the team.

---

The canned response in question:

https://groups.google.com/g/certificate-transparency/c/we_8S...

"after reviewing your submission it appears this behavior does not pose a concrete and exploitable risk to the platform in and on itself.

If you're able to demonstrate any impact please let us know, and provide an accompanying working exploit."

Magic Lantern Is Back 11 months ago

The linked page explains:

    Magic Lantern is a free software add-on that runs from the SD/CF card and adds a host of new features to Canon EOS cameras that weren't included from the factory by Canon.
I also found this concise, human-written readme on the project page. Since it's not AI slop churned out by a startup, it's worth reading! :-)))

https://github.com/reticulatedpines/magiclantern_simplified/...

    Magic Lantern
    =============

    Magic Lantern (ML) is a software enhancement that offers increased
    functionality to the excellent Canon DSLR cameras.
      
    It's an open framework, licensed under GPL, for developing extensions to the
    official firmware.

    Magic Lantern is not a *hack*, or a modified firmware, **it is an
    independent program that runs alongside Canon's own software**. 
    Each time you start your camera, Magic Lantern is loaded from your memory
    card. Our only modification was to enable the ability to run software
    from the memory card.

    ML is being developed by photo and video enthusiasts, adding
    functionality such as: HDR images and video, timelapse, motion
    detection, focus assist tools, manual audio controls much more.

    For more details on Magic Lantern please see [http://www.magiclantern.fm/](http://www.magiclantern.fm/)

    There is a sibling repo for our patched version of Qemu that adds support
    for emulating camera ROMs. This allows testing without access to a physical
    camera, and automating tests across a suite of cameras.  
    https://github.com/reticulatedpines/qemu-eos  
    https://github.com/reticulatedpines/qemu-eos/tree/qemu-eos-v4.2.1 (current ML team supported branch)

Notable because often when people complain of degraded model quality it turns out to be unfounded - Anthropic in the past have emphasized that they don't change the model weights after releasing them without changing the version number.

It's almost as if companies whose bottom line depends on shilling the [CURRENT HOT THING] will lie to you!

Instead of using appeals to authority to silence critics as "conspiracy theorists" spreading "misinformation", the influencers should maybe apply some reasoning and thinking.

Of course it does. Do you really think you have full control over API output? Do you really think "the system prompt you can specify in an API call" is the system prompt and not the developer instructions prompt?

    No secret. Just vibes.
Since you know the tells of LLM generated text, you'll know that this is a classic: No X. Just Y.
    Proxyman -- pick your poison.

    And if you're from PureGym reading this—let's talk.
There's a mixture of em dashes joining words and double hyphens spaced between words, suggesting the former were missed in a find and replace job.

"And if you're from [COMPANY] reading this[EM DASH]let's talk" is a classic GPT-ism.

    It's like the API is saying "Hey buddy, I know this is odd, but can you poll me every minute? Thanks, love you too."

    Shame Notifications: "You were literally 100 meters from the gym and walked past it"

    It's just a ZIP archive with delusions of grandeur
Clear examples of fluff. Not only do these fail to "add facts or colour to the story", they actually detract from it.

I agree with you that em dashes in isolation are not indicative, but the prose here is dripping with GPT-speak.

In an ideal world, we wouldn’t need to pause the Grants Program and would instead be granting even MORE awards to our inspiring community.

The AI sector, for example, relies heavily on Python and is mostly untapped for the PSF, PyCon US, and our entire community.

This guide ignores many sane defaults in favor of a patchwork of cargo cult scripts and outdated packages, added over time by random people with no thought for threat modeling, that may even result in an increased attack surface.

See this comment from 2019: https://news.ycombinator.com/item?id=19178938

I will leave you with this line from README.md:

I am not as knowledgeable about hardening/securing a Linux kernel as I'd like. As much as I hate to admit it, I do not know what all of these settings do.

As long as the conclusions are sound, why is it relevant whether AI helped with the writing of the report?

TL;DR: Because of the bullshit asymmetry principle. Maybe the conclusions below are sound, have a read and try to wade through ;-)

Let us address the underlying assumptions and implications in the argument that the provenance of a report, specifically whether it was written with the assistance of AI, should not matter as long as the conclusions are sound.

This position, while intuitively appealing in its focus on the end result, overlooks several important dimensions of communication, trust, and epistemic responsibility. The process by which information is generated is not merely a trivial detail, it is a critical component of how that information is evaluated, contextualized, and ultimately trusted by its audience. The notion that it feels wrong is not simply a matter of subjective discomfort, but often reflects deeper concerns about transparency, accountability, and the potential for subtle biases or errors introduced by automated systems.

In academic, journalistic, and technical contexts, the methodology is often as important as the findings themselves. If a report is generated or heavily assisted by AI, it may inherit certain limitations, such as a lack of domain-specific nuance, the potential for hallucinated facts, or the unintentional propagation of biases present in the training data. Disclosing the use of AI is not about stigmatizing the tool, but about providing the audience with the necessary context to critically assess the reliability and limitations of the information presented. This is especially pertinent in environments where accuracy and trust are paramount, and where the audience may need to know whether to apply additional scrutiny or verification.

Transparency about the use of AI is a matter of intellectual honesty and respect for the audience. When readers are aware of the tools and processes behind a piece of writing, they are better equipped to interpret its strengths and weaknesses. Concealing or omitting this information, even unintentionally, can erode trust if it is later discovered, leading to skepticism not just about the specific report, but about the integrity of the author or institution as a whole.

This is not a hypothetical concern, there are numerous documented cases (eg in legal filings https://www.damiencharlotin.com/hallucinations/) where lack of disclosure about AI involvement has led to public backlash or diminished credibility. Thus, the call for transparency is not a pedantic demand, but a practical safeguard for maintaining trust in an era where the boundaries between human and machine-generated content are increasingly blurred.

it seems like ZSH tries to update on every shell spawn

Learn your tools first, not bloated frameworks. There's a gulf of difference between vanilla zsh and this:

Community-driven (with 2,400+ contributors) framework for managing your zsh configuration

Includes 300+ optional plugins (rails, git, macOS, hub, docker, homebrew, node, php, python, etc)

140+ themes to spice up your morning, and an auto-update tool that makes it easy to keep up with the latest updates from the community

Comments should get more thoughtful and substantive, not less, as a topic gets more divisive.

https://news.ycombinator.com/newsguidelines.html

Aside from that, I don't see how the collection of simple one-shot JavaScript wrappers (like "Extract URLs", "Word Counter", and "Pomodoro Timer") that you keep bringing up is related to your argument.