HN user

tgsovlerkhgsel

16,609 karma

all opinions are my own

Posts3
Comments3,908
View on HN

Passkeys are a nightmare for techies that want to understand and manage their stuff. They were optimized for people who neither can nor want to understand, they just press the button that the screen tells them to press and live inside someone's closed ecosystem.

For that use case, they work fine, and they create enormous lock-in, because now moving out of that ecosystem breaks everything. One might argue that that means they're perfectly engineered for what they are meant to do...

If you pop my machine and use it to route 100 MBit/s, I might not notice for months.

If I hear the fan spinning at night, you're probably getting caught immediately.

If you pop my mom's TV box and use it to route data within the connection's capabilities, you're getting away with it. If you consume a little bit of resources, still. If you consume enough to be useful for these kind of challenges, chances are her TV playback will start to stutter, which will be resolved by taking the compromised TV box, and removing the malware using advanced mechanical means called "a trash compactor".

Change is inevitable. I love seeing artificial objects in space, because it shows that we, humanity, are finally getting there.

Elon doesn't own space, he just happens to be the one who is currently best at making it reachable. There is plenty of space for everyone else, and others will get there, eventually.

I could eat myself up with envy over the money he's making from it... or be glad that it's at least someone getting rewarded for moving humanity forward (while also being an asshole), rather than someone who is starting wars to profit from insider trading...

I notice this pretty consistently with elevators: If you press the button for a short amount of time, it visibly lights up while pressed but doesn't actually register the button-press.

Of course, and it's essentially an over-the-top parody of what's really happening: People aren't literally running the tool, but running pointless agentic queries where the primary purpose is to drive token usage up, not get actual work done.

Actually... I wouldn't be surprised if some people were actually running the tool and got away with it (or praised for getting the metric up) for a long time...

I wonder when (if ever) the companies realize that demoralizing your workforce (and destroying that sector of the job market) doesn't have only advantages.

I know plenty of people that reacted with the desired fear, putting in long hours to avoid layoffs, willingness to accept lower pay because the job market sucks, etc. - but I think there are also plenty of the the mythical 10x engineers that just checked out, stopped being 10x engineers, and are just collecting their paychecks and waiting for the layoff now. And I'm not sure you can "get them back", ever.

At least some companies reacted to this with more top-down management, stricter metrics etc. which kills motivation further and leads to metric optimization. Tell a good, smart, motivated engineer that you want more AI usage, and he's going to maybe start using some AI where it makes sense, but mostly ignore the metric while trying to do useful work. Demotivate the same engineer and make clear that his paycheck depends on metrics, and he'll give you what you're asking for, except https://github.com/dtnewman/burn-baby-burn is probably not what you _wanted_...

The question is, what do they do when they see a tagged prompt? Do they flag/ban the account, or serve a degraded response? Are there some well-documented methods of serving a response that is still somewhat useful for what the prompt asks for, but really bad for distillation attempts?

I get rage when I hear those "5 clever tips to stay cool without A/C".

Many buildings already have shades, but please tell me more how those shades and "properly ventilating during the night" (aka not getting sleep half the night due to outside noise) will keep my apartment at a livable temperature when the air temperature outside never drops below 23 degrees for more than an hour.

You can't effectively remove the heat that has pooled in the apartment with a 2-3 degree temperature difference, let alone in the few hours where you actually have that difference.

So because of thinking like the one in your post, we can't have real AC's (because to "protect the environment" we'd first need to install every other system that doesn't help then prove that with a mountain of paperwork), so my only option is to open the well-insulated window so I can stick the coolant hose of a portable unit through it.

I think the "properly installed AC bad" mentality will only change once the entire population of renters has those inefficient portable units (that are de facto impossible to regulate) and even the anti-AC group realizes that encouraging "real" ACs is much better than the workarounds that the status quo forces.

"Simply cannot have AC" is a problem we did to ourselves, or rather, the "its not so bad just suffer a bit" people are doing to the rest of the population.

What are the reasons "most of us simply cannot have AC"? Either laws/regulations banning it or making it prohibitive, or living in rentals without proper protection.

There is no reason why heat protection couldn't be mandated for rental units just like heating is required in winter. Or why tenants couldn't have a right to install AC at their own expense.

Meanwhile, because permanent AC units are de facto impossible, the portable Mideas sell out as soon as the heat wave hits, and we're forced to run air conditioners with literally open windows just so we can run the hose through.

(You should get one for next year, by the way. You probably missed the opportunity for this year unless you want to pay a scalper 2-3x the normal price, but they can be installed in essentially any window or balcony, are reasonably quiet, much better than the 'air hose out the window' monoblock units, and they fucking work)

Feels AI generated ("linkedin-style" short sentences, blob of malformated text towards the bottom), so I'll give myself the permission to skim and take shortcuts.

The most interesting claim is the weakness of groups (the article claims the server controls who is a group member, without cryptographically secured authorization by an existing member).

The other key points are correct to my knowledge but unsurprising to anyone knowledgeable and partially apply to Signal too (backups are a weak point, you securing/disabling them properly doesn't protect you, metadata is unprotected and sensitive, participants in the conversation might upload the chat to Meta's AI, endpoints are attackable either through WhatsApp or other apps, the general trust issue - which isn't really resolved by being open source unless someone actually checks the reproducible builds AND someone reviews the code).

I thought that claim about the backup password hash was wrong, but https://www.nccgroup.com/media/fzwdxklh/_ncc_group_whatsapp_... suggests that Meta thought that 100k iterations of PBKDF2 are a reasonable choice for the key derivation, so it might actually be accurate.

AFAIK WhatsApp backups are, by default, encrypted with a key escrowed to WhatsApp (which means that an attacker using warrants now has to subpoena both the cloud provider and whatsapp - probably the best you can get while keeping backups usable for the 99% of people who can't be expected to write down a passphrase and still have it when asked).

But IMO the reality is that WhatsApp is the most secure messenger that you can expect normal people to actually use (mostly due to market share/network effect), and the only secure-ish messenger aside from Signal, so I'd be careful with the messaging towards "normies": "Signal is a much better choice, but out of the other options, Whatsapp is by far the least bad".

Otherwise, you end up with people picking something like Telegram because "it's all bad anyways" or "I've heard Telegram is secure".

Most importantly, they state "We [Antrhopic] are not using your identity data to train our models" but "Persona [...] can use your data [...] to improve their ability to prevent fraud." -- in other words, Persona can (and will) use your data to train their models.

Revocation information may not be available for expired certificates. Not that it matters much because the last time I checked revocation didn't really work for non-expired certificates either, but I think that (+ the risk of people treating expired certificates as worthless and thus increasing the risk of exposure) is the main reason.

Also of course domains changing owners, but again... I don't think we have good monitoring for that during the current long lifetime, so maybe a grace period where a warning is shown but it's easier to click through would be a good idea. Perhaps combined with a requirement to keep revocation information (and keep revoking expired certificates) X days past expiry.

Midjourney Medical 1 month ago

Or only consider it a positive once the confidence is high enough that false positives are not a problem anymore.

Getting a test good enough to still make it useful (detect enough of the true positives) would of course be a challenge, but the more data is available, the more feasible that might be.

Midjourney Medical 1 month ago

I think it's (at least partly) about the psychological impact of finding something unusual. Even if you know that it's probably nothing and understand the Bayes theorem, there will be a "what if" that might be strong enough to do actual harm (nocebo effect).

Compare: The placebo effect works (at a reduced rate) even if you tell people they're getting a placebo!

Midjourney Medical 1 month ago

That sounds like a problem with applying the wrong threshold for a positive finding, possibly due to liability concerns or wrong goals.

To work, it would have to be incredibly accurate (specifically, have an incredibly low false positive rate).

Midjourney Medical 1 month ago

I think a lot of medical diagnosis could be solved with mass data collection if it was cheap enough. Right now, blood draws are somewhat routinely done because they provide a lot of human-interpretable indicators from a small number of values, and there is some evidence that e.g. "dogs can smell cancer" etc. (i.e. some diseases cause detectable odors).

With a big enough data set of [all kinds of bio values, including ones considered irrelevant for that disease] labeled with diagnoses, I suspect we could get very fast and accurate automatic diagnoses, even from a limited data set currently considered uncorrelated. Rather than going to your primary care physician, you'd go into the standardized, mass-produced and thus reasonably cheap everything-scanner, and you could likely get a more accurate diagnosis (or at least "things to check") than the average doctor would be able to give you under the practical constraints they typically operate under (time, available information/diagnostics).

This goes in that direction, and I'm really excited to see where it goes. I could imagine that given enough training data, ML models will be able to pick up on minute details that make it possible to diagnose diseases that weren't historically considered ultrasound-diagnoseable from this kind of detailed ultrasound.

I think combining it with gas chromatography/mass spectrometry of e.g. breath or blood/sweat/urine samples would also have the potential to be a cost-effective diagnosis method - lots of data, probably not all too useful for human interpretation, but would open the potential to walk up to a machine, breathe into it, spit into it, pee into it, give it a swab, and have it come up with an accurate diagnosis without invasive testing. If mass produced, the cost of something like this could easily drop below the cost of a typical doctor's visit. (I googled it and it seems like GCMS is already used for some diagnoses, but screening only for a few specific diseases rather than "throw ML at it and try to diagnose everything").

Because when I want to play a game, I want to play a game, not debug someone's hacky attempt to make it work on Linux.

Implementing a strict "no fiddly shit on my game machine" policy was one of the best choices for my mental health that I've made: It's a dedicated machine for gaming, with nothing really sensitive on it aside from gaming related accounts, and its only purpose is to play games with the least amount of immediate hassle. In other words, if the choice is installing something ugly or fiddling, that launcher, kernel level anticheat or whatever it is gets installed.

That link doesn't work, so I'll respond here: My impression is that my ship always has a better turn rate than the other ship, so if I ever manage to get into the enemy ship's e.g. 4'oclock position, I can keep turning towards it, it will (slowly) turn towards me while consistently shooting behind me, and I can consistently hit it.

This is a pretty common behavior that I've seen from bug bounty programs:

a blog post discussing this issue has already been published, which does not appear to be in accordance with the program’s terms.

Companies reject bugs as out of scope and/or sit on them forever, then use the bug bounty ToS as intimidation to keep people from disclosing them. And sadly, it works.

I'm adding AMD to my list of companies that prefer their bug reports to be a public full disclosure rather than attempting to go through their bug bounty program.

To be overvalued by an order of magnitude, it'd have to have a fair valuation of under $180 B.

At ~5 billion per year in profit, Starlink alone would justify a 100 B valuation at a P/E ratio of 20 (i.e. assuming a non-growth company). If you account for the fact that this is very much a growth company, the valuation of the space part alone is well above these $180B.

And they do happen to have the launch and AI businesses on top of it, which (as usual for growth companies) may not be obscenely profitable but aren't worthless.

If 90% of the value is from the AI business, it's grossly undervalued.