HN user

traceroute66

5,477 karma
Posts6
Comments1,808
View on HN

"we have information" says a US Government official who almost certainly has had Anthropic and/or OpenAI on the phone spinning him stories.

See also, don't trust anyone in Trump's government who says "we have information".

"they distilled us" is fast becoming standard US FUD.

The same as people telling me with a serious face that the Chinese models are distilled just because it says "I am Claude".

I am not the only one, look at this post on interconnects about Kimi K3 for example:[1]

     It should be clear looking at this model that if adversarial distillation from the closed frontier models in the U.S. contributed, it is at most to a relatively small degree. AI observers who followed the distillation panic and came away with the wrong conclusion that Chinese AI labs are only producing good models due to IP theft are in for an awakening – that Chinese companies are extremely good at building models in the same way the leading American companies are.
[1] https://www.interconnects.ai/p/kimi-k3-the-open-weights-esca...

it hides some logic from the developers

I do not buy this argument.

Its called a documented function.

The developers know the function's inputs and outputs and what it does.

That's all they should need to know.

Its no different to functions in the libraries of whatever programming language you are using.

Devs just do their coding based off the function signature and docs. They know what goes in, what comes out and what the function does.

How many developers do you know who've gone back and read the source code of the function ? Assuming its open-source anyway and not a OS API.

people will use an ORM anyway

Even worse !

Don't get me started on people who treat databases like a black-box dumping ground and insist they must have "portable schemas".

I've spent a lot of time writing my own random queries. I don't know that I've ever written a stored function.

And I've spent a lot of my working life cleaning up after people who write random queries who then start blaming the database for being "slow" and insisting they need some sort of over-engineered Redis caching layer or whatever.

100% of the time the database is perfectly fine, but the query is slop.

Not saying you are one of them, but you would very much be in the tiny minority if you are not. ;)

They don't have time to ...

Which is why they end up spending time on mea-culpa "we take your data security seriously, but clearly not seriously enough" emails when they inevitably get pwned by a completely predictable and avoidable SQL injection attack.

The sort of startups you describe are jokes that barley take security seriously, let alone know what a pen-test or code audit is, let alone actually do them on a regular basis.

The last thing a startup has time to do is stored functions

If they have time to write SQL queries, they have time to write stored functions.

Its really not that difficult and it certainly does not take a substantial amount of time.

I did a search in that post for "function", zero results.

Unimpressive. Not even the most cursory of discussion of stored functions ?

Given that many startup's Postgres instances will no doubt be backing some web-ui or app that takes untrusted input, surely they could have at least had a brief discussion about how stored functions can help against SQL injection attacks ?

Not only that but it means you have to think, it prevents devs just writing their own random queries.

Also zero mention of `text`, which is highly encouraged in Postgres instead of the silly old `varchar(255)`

gives me nostalgic memories for Microsoft Encarta

Those were the days !

A bit like Where in the World is Carmen Sandiego? which used to ship with a physical almanac alongside the game disks.

YouTube have also become very aggressive in forcing you to have a Google account and to watch videos to allegedly "help protect our community".

I avoid YouTube like the plague, but sadly there are lots of people out there who don't know anything other than YouTube exists and so they post their videos there (e.g. conference presentation recordings etc.).

Those that actually understood security....

Indeed, and those who actually understood software development always knew vulnerabilities can occur just as easily as bugs.

And in some cases more easily than bugs, because many of modern vulnerabilities are so subtle, especially where crypto is involved.

It should just be highly limited in scope

"should" is doing a lot of heavy lifting there.

I agree it is hard to escape some form of legitimate need for intel.

The concern with intel and the present US administration comes on the checks, balances and controls side.

We are after all dealing with an administration happy to conduct much of its most sensitive business on Signal using off-the-shelf phones.

People absolutely use LLMs to research politically sensitive topics.

Note I used the word "seriously", I meant it in its fullest form, i.e. serious people.

I'm not interested in what-if arguments based on "you can't fix stupid".

Stupid people also blindly believe whatever a US LLM tells them without any form of verification, hallucinations and all.

Most people on this planet would agree that a Chinese LLM is perfectly usable for all tasks except asking about politically sensitive matters.

And for most people on the planet, that is just fine. They can get their political information elsewhere.

I am not going to post what I could respond on a public forum.

All I will say is that it should be perfectly apparent by now to any sane external observer that Trump does not play by any long-established rules or protocols.

An entire encyclopedia of examples could easily be provided, the most famous recent one being his phone call to FIFA about the red card suspension.

It’s not a new thing. Industrial espionage has always been a thing as well.

Well sure, except with closed US LLMs you're basically just handing them data on a plate, and paying for the privilege. ;)

Very American really ... monetising industrial espionage.

you neglect the fact that US corporations have some autonomy from the government

In theory.

In practice, Trump picks up the phone and say "jump" and the CEO on the other end says "how high ?".

And if you say no, well, we saw what happened when Anthropic said no.

China can (and does) use the models to influence the west. They train in false information about Taiwan and Hong Kong. Or pretend like history is in favor of China.

I am not Chinese and I'm not defending the Chinese, but I see this argument come up a lot.

In practical terms it is US-sponsored FUD.

Why ?

Because the hard reality is that what you say is simply not going to affect 99.9999999999% of users.

Is it realistically going to affect anyone using an LLM in coding ? No.

Is it realistically going to affect anyone using an LLM in $anything_else_not_politically_sensitive ? No.

Does anyone seriously use LLMs for researching politically sensitive matters ? No.

Just as there is plenty of information out there on the US's less than perfect history, there is also plenty of information out there on the various Chinese politically sensitive matters. You do not need a Chinese LLM to find out about it, all you need is a search engine.

Any non-US company, US can block the models which can disrupt the whole business.

And read your data, see CLOUD act, PATRIOT act etc. etc.

No longer a theoretical risk in today's US political environment.

But Dario said (and maybe more ppl) that Chinese models are just distillation

"But Dario said" ... yawn.

I am increasingly convinced that "they distilled us" is as much US FUD as "it was made by communists". Especially since its mostly the US tech-bros who are coming out with that tiny violin.

People telling me the Chinese models are distilled just because it says "I am Claude" when asked is also lame.

I am not the only one, look at this post on interconnects about Kimi K3 for example:[1]

     It should be clear looking at this model that if adversarial distillation from the closed frontier models in the U.S. contributed, it is at most to a relatively small degree. AI observers who followed the distillation panic and came away with the wrong conclusion that Chinese AI labs are only producing good models due to IP theft are in for an awakening – that Chinese companies are extremely good at building models in the same way the leading American companies are.

[1] https://www.interconnects.ai/p/kimi-k3-the-open-weights-esca...

Now it being digitized there is no wiggle room on exit/entry.

Yes. Because the primary issue is it was too easy to fly under the radar once you were in the Schengen zone.

Also in 2026 there are security threats which means tighter borders is a necessity.

Clearly in 2026, the easiest way to achieve compliance at all Schengen borders accross 29 countries is to digitise it, including biometrics.

Yes, to put it politely, there have been "teething issues" in its implementation. But given the sheer scale of the change, that is only to be expected. I think any of us working in tech would agree that it would be delusional to think such a thing would be perfect from day zero.

Why did Airbus go to "the cloud" in the first place?

The same reason that so many companies went to "the cloud", because the hyperscalers warpped the C-suite round their little finger.

There are two things any C-suite like doing that the hyperscalers could help them tick boxes on.

First, shifting capex to opex. They love doing that because of the accounting treatment. Opex goes into your P&L, so it reduces your taxable profit and therefore it reduces your tax bill. Meanwhile capex goes onto the balance sheet and is deprecated over the asset's life, so the "only" benefit you might get is to claim allowances (e.g. R&D) from your tax authority.

Second, it allows lots of things to be made "someone else's problem". Security ? Their problem. Staff ? Their problem. Tick-boxes to keep the compliance department happy ? Their problem.

So the hyperscalers can turn up and spin a ready-made story that the C-suite will lap up. Perhaps accompanied by a nice lunch and a round of golf. ;)

There is no doubt, companies such as Airbus have the technical competence and the financial means to do it all in-house. Sadly the C-suite calls the shots ....

using our European region

To be fair, it was always obvious to anyone with half a brain that "European region" from a US provider was fake-EU.

The problem is that PARIOT act, CLOUD act and everything else has gone from being a paper tiger to real and present danger. No longer a theoretical risk.

So even people willing to previously turn a blind eye to the crystal clear risks can no longer do so.

It is also no longer possible to trust those tasked with implementing it not to bow to political pressures.

A long time ago now, Microsoft (Azure) put up a fight when the US came calling for some data hosted in their "EU (Ireland) region". I think there is zero chance of them putting up a fight today if Donny boy picked up the phone to Satya .

And that's before we get to the example of a Texas court ordering Verisign to cut off the .com domain from a Dutch company.[1]

Sadly I have limited sympathy for a country that having witnessed Donny's first term thought "you know what, we'll have more of that" and voted accordingly.

[1] https://www.texasattorneygeneral.gov/news/releases/attorney-...

HMD Touch 4G 3 days ago

Did you mix up 4G with 3G/2G?

Most operators have switched off both 3G and 2G by now.

HMD Touch 4G 3 days ago

New towers aren't backwards compatible, and the bandwidth has been largely reduced.

Yup.

In tech-speak there is 5G NSA (Non-Standalone Architecture) and 5G SA (Standalone Architecture).

5G NSA is a kludge, it is 5G radios operating on a legacy 4G core. Inherently backwards compatible.

5G SA is 5G radios on 5G core. Clearly not backwards compatible.

5G SA is the preferred route for good reason:

    1. It delivers reduced power consumption at both operator and user-device level
    2. It delivers improved latency and bandwidth at both operator and user-device level

Raspberry Pis are notorious for SD card corruption

True SD cards are less than ideal.

But also I suspect half the problem specifically with Pi and SD cards is that people use cheap-ass SD cards and maybe ones they found in the bottom of a drawer that may or may not have previously been used in another device (e.g. camera).

I suspect if people bought industrial SD cards instead of consumer-grade junk they might get a better lifespan out of them.

Qwen 3.8 3 days ago

Linking a US website discussing the topic doesn't exactly support your point.

It supports my point precisely. Recall I also said "Does anyone seriously use LLMs for researching politically sensitive matters ? No.".

Just as there is plenty of information out there on the US's less than perfect history, there is also plenty of information out there on the various Chinese politically sensitive matters. You do not need a Chinese LLM to find out about it, all you need is a search engine.

The point is you have an open-weights LLM that is very good for a vast number of non-political uses, such as coding.

The point is that you can use the open-weights model instead of paying through the nose for a US model where they harvest your data unless you have an "enterprise" zero-data retention "trust me dude" clause that you have no viable way of verifying – and which incidentally is still subject to the good old "law, or court or administrative order" contract clauses, so it may not be as much of a zero-data retention as you think it is.