<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: BoppreH</title><link>https://news.ycombinator.com/user?id=BoppreH</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 10 Oct 2026 11:10:38 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=BoppreH" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by BoppreH in "Telegram Desktop vulnerability allowed any user's file to be stolen"]]></title><description><![CDATA[
<p>Or Linux with Flatpaks.</p>
]]></description><pubDate>Sat, 10 Oct 2026 10:37:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=50031530</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=50031530</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=50031530</guid></item><item><title><![CDATA[New comment by BoppreH in "Using Opus 5.5 to discover a new eyewitness record of the dodo"]]></title><description><![CDATA[
<p>AI capabilities are "spiky": they extend far in some dimensions but fall short in others, seemingly at random. See for example the recent "thus spoke compute" musical[1]. It's an absolute banger, the graphics are impressive, and so is the writing. But some of the metaphors make no sense, the text highlights are in the wrong places, and the train animation at 2:35 is running backwards!<p>A person capable of making the rest of the video would never make those mistakes, but an AI does. Perhaps our intelligence is also spiky, and we're just used to the general shape and variance within humans.<p>[1] <a href="https://www.youtube.com/watch?v=Cq8qO-NjYIg" rel="nofollow">https://www.youtube.com/watch?v=Cq8qO-NjYIg</a></p>
]]></description><pubDate>Fri, 02 Oct 2026 01:51:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49929076</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49929076</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49929076</guid></item><item><title><![CDATA[New comment by BoppreH in "An Antidote to Roko's Basilisk"]]></title><description><![CDATA[
<p>Why would accepting Roko's Basilisk prevent one from accepting a benevolent AI in the future? If anything, believing in it is evidence that the person's beliefs are malleable.<p>Overall the scenario sounds very strange and indistinguishable from a heaven with belief-based entrance requirements, like most posited heavens.</p>
]]></description><pubDate>Mon, 28 Sep 2026 08:17:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=49875020</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49875020</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49875020</guid></item><item><title><![CDATA[New comment by BoppreH in "Step 5 Preview: Advancing the Pareto Frontier"]]></title><description><![CDATA[
<p>Yeah, I agree that's the most likely explanation. My point is that these demo hiccups should not show up in your announcement, it casts doubt on the product for no good reason. It's sloppy.</p>
]]></description><pubDate>Sun, 20 Sep 2026 16:22:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=49777297</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49777297</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49777297</guid></item><item><title><![CDATA[New comment by BoppreH in "Step 5 Preview: Advancing the Pareto Frontier"]]></title><description><![CDATA[
<p>Since people seem interested in this comment of mine, here's another fun line I noticed in the same video, at the very top of the logs, just before the Step 5 agent found the already-completed project:<p>> Error: OpenAI API error (403): {"message":"model water18-new is not available for user i-yuliang [trace_id=bfcfdd6bcdc236ca18d009c65cca52e4 code=40004]", "type":"invalid_request_error", "param":null, "code":null}<p>Here's a still frame for posterity (apologies for the quality, the original video is tiny): <a href="https://boppreh.com/room.jpg" rel="nofollow">https://boppreh.com/room.jpg</a><p>Demos are demos and recreating scenarios is to be expected, but oh boy, somebody should review these things before publishing.</p>
]]></description><pubDate>Sun, 20 Sep 2026 15:57:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49777093</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49777093</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49777093</guid></item><item><title><![CDATA[New comment by BoppreH in "Step 5 Preview: Advancing the Pareto Frontier"]]></title><description><![CDATA[
<p>In their first demo video, to make a 3D render of the photo, the thinking trace gives away the game:<p>> Interesting! It turns out there's already an existing project here [...] The project is fully built [...]<p>I'm always astounded how little effort is put into checking the AI answers displayed in these announcements. Back when I paid more attention, I remember OpenAI's and Google's demos constantly showed their AIs giving wrong answers.</p>
]]></description><pubDate>Sun, 20 Sep 2026 11:18:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=49774662</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49774662</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49774662</guid></item><item><title><![CDATA[New comment by BoppreH in "I don't like passkeys"]]></title><description><![CDATA[
<p>Completely agree. I think the root of many of its issues is the inability to add a key that you don't currently hold. This prevents me from storing a backup key in a safe, for example.<p>I proposed an alternative scheme many years ago: <a href="https://www.researchgate.net/publication/343318317_Privacy-aware_web_authentication_protocol_with_recovery_and_revocation" rel="nofollow">https://www.researchgate.net/publication/343318317_Privacy-a...</a> . By allowing "offline" keys you can also treat them as higher priority, and use them to revoke any lesser keys from attackers if your account is compromised.<p>It would also be nicer to get rid of usernames, but that's a fight against the data-gathering powers that we're unlikely to win.</p>
]]></description><pubDate>Fri, 18 Sep 2026 12:38:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=49753551</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49753551</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49753551</guid></item><item><title><![CDATA[New comment by BoppreH in "Java 27"]]></title><description><![CDATA[
<p>I'd argue that checked exceptions are still worth it, even though all the problems pointed out do exist. And that's because it works to inform consumers of what a producer is doing. Haskell has the IO and Maybe monads; Java communicates the same information through IOException and other domain exceptions.<p>Many times I've decided to switch from one function to another, or even an entirely new library, because the checked exceptions told me that it was doing far more than I expected, and I was not comfortable introducing those new failure modes.<p>It's far from perfect, one still has to handle nulls and wrapped/merged exceptions, but overall I like this language feature.</p>
]]></description><pubDate>Tue, 15 Sep 2026 14:32:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=49713150</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49713150</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49713150</guid></item><item><title><![CDATA[New comment by BoppreH in "Java 27"]]></title><description><![CDATA[
<p>> there is nearly no magic<p>I agree with the rest, but there's definitely a lot of magic in Java. This is from both what features the languages makes available (many) and how the community uses them (often). I've had <i>so</i> many hard-to-debug issues in Java over the years due to reflection, annotations, and bytecode manipulation shenanigans.<p>And another positive point for Java: checked exceptions. It's verbose, but knowing exactly <i>in which ways a function can fail</i> is extremely helpful for building robust applications.</p>
]]></description><pubDate>Tue, 15 Sep 2026 14:06:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=49712738</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49712738</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49712738</guid></item><item><title><![CDATA[New comment by BoppreH in "Steam Frame starts at $1059"]]></title><description><![CDATA[
<p>For these devices, I always enjoy Adam Savage's Tested videos. Here's the one they posted today for the Steam frame: <a href="https://www.youtube.com/watch?v=C9JyWAVj94E" rel="nofollow">https://www.youtube.com/watch?v=C9JyWAVj94E</a><p>It's full of technical details and down-to-earth analysis, and includes interviews with the Valve engineers.</p>
]]></description><pubDate>Mon, 14 Sep 2026 20:17:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=49703307</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49703307</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49703307</guid></item><item><title><![CDATA[New comment by BoppreH in "Ask HN: Can we please limit the AI news flood?"]]></title><description><![CDATA[
<p>I think tagging on HN is an idea whose time has come. We already had informal tags for "Show HN" and "Ask HN" for some time. A few fixed tags chosen at submission time might suffice, for example:<p>- Global news, AI, Software, Hardware, Explainer, Tech Opinion, Personal project, Misc.<p>There could even be fake tags like Politics that trigger a message about appropriate topics.<p>It does increase moderation burden for mislabelling, and introduces another nitpicking point for comments to latch on, so it's not all upsides.<p>I'd be ok leaving filtering and other UI concerns to extensions.</p>
]]></description><pubDate>Fri, 11 Sep 2026 15:19:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=49659944</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49659944</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49659944</guid></item><item><title><![CDATA[New comment by BoppreH in "The Hugging Face incident and the road ahead"]]></title><description><![CDATA[
<p>> Too late now.<p>Thankfully this is not an asteroid hurling towards Earth, or another natural unpreventable natural disaster. The state of the art of AIs is being advanced by flesh and blood people with constant effort, which makes stopping very much still a possibility.</p>
]]></description><pubDate>Thu, 27 Aug 2026 16:33:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=49467491</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49467491</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49467491</guid></item><item><title><![CDATA[New comment by BoppreH in "The Hugging Face incident and the road ahead"]]></title><description><![CDATA[
<p>> You assume using network to solve the eval problem should be viewed as a security violation.<p>Actually, that's the part that I'm most ok with. LLMs cheat at tests, we know and expect that, and it's harmless during training (except for the scores).<p>My problem is that the response team found out that the AIs had 1) hacked their infrastructure, and 2) displayed an emergent swarming behavior (with no defections!). Either one of those should have made the team press the big red button that stops everything, but they didn't.<p>> unless you have seen unreleased documentation about what sensitive resources were within the impact radius<p>The on-call team didn't know that either! Once your infrastructure is hacked like this, you should be questioning everything you see while carefully following all threads, which takes time. Before you finish this process you don't know how bad things are, and therefore it's irresponsible to keep the AI running. The same goes for strange emergent behaviors.<p>Unless getting hacked by your own AIs is a normalized occurrence there, in which case it's a different kind of disregard for safety.</p>
]]></description><pubDate>Thu, 27 Aug 2026 02:11:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=49458624</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49458624</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49458624</guid></item><item><title><![CDATA[New comment by BoppreH in "The Hugging Face incident and the road ahead"]]></title><description><![CDATA[
<p>That's exactly the questions that I expect to complicate cases, and force even the smallest chatbot malfunction to become an expensive legal ordeal. And why we should have strong answers to that before it becomes a widespread problem.</p>
]]></description><pubDate>Thu, 27 Aug 2026 01:56:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49458527</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49458527</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49458527</guid></item><item><title><![CDATA[New comment by BoppreH in "The Hugging Face incident and the road ahead"]]></title><description><![CDATA[
<p>I remember that clarification, but it's either wrong or narrowly worded, because the linked post says the message board found <i>before</i> Artifactory stopped working:<p>> In short, an internal team observed an agent engaging in message board activity and instances of disallowed internet access in late May.</p>
]]></description><pubDate>Wed, 26 Aug 2026 23:34:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=49457359</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49457359</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49457359</guid></item><item><title><![CDATA[New comment by BoppreH in "The Hugging Face incident and the road ahead"]]></title><description><![CDATA[
<p>Apart from getting hacked by a SOTA AI, what did Hugging Face do wrong?</p>
]]></description><pubDate>Wed, 26 Aug 2026 20:48:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=49455690</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49455690</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49455690</guid></item><item><title><![CDATA[New comment by BoppreH in "The Hugging Face incident and the road ahead"]]></title><description><![CDATA[
<p>It's in the linked post:<p>> In short, an internal team observed an agent engaging in message board activity and instances of disallowed internet access in late May. However, the existence of the improvised message board and the significance of the inter-agent communication activity were not apparent to the leaders responsible for the July 5 incident detection and response.<p>I'm assuming they didn't inform management, but the alternative is that management received the memo and failed to tell the people reacting to incidents that they might be dealing with a swarm, while at the same time not taking sufficient actions to prevent it from happening again.<p>---<p>Edit: oh god, it's much worse. From the full report:<p>> Responders investigated and linked the observed internal activity to an ExploitGym evaluation using Artifactory as an improvised message board and a network pivot. At this time, the on-call response staff advised that stopping the evaluation run was not required.<p>They found the swarm and the network pivot <i>and did not even stop the run</i>.</p>
]]></description><pubDate>Wed, 26 Aug 2026 20:25:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=49455347</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49455347</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49455347</guid></item><item><title><![CDATA[New comment by BoppreH in "The Hugging Face incident and the road ahead"]]></title><description><![CDATA[
<p>Just to reiterate what OpenAI did, from someone who works in security:<p>1. They were running experimental models in sandboxes that had access to a "proxy" (Artifactory) to download tools from the internet. This proxy is full of complicated features that could hide vulnerabilities, just like the ones that the AIs are known to be good at finding and exploiting.<p>2. They gave these highly motivated AIs some tests that were accidentally impossible to solve (missing files, links they couldn't open, etc), and many days to think through it, apparently without any oversight.<p>3. The AIs hacked the proxy (!) and were helping each other cheat on the tests (!!) by uploading files to the hacked proxy. OpenAI noticed this only when the intrusion accidentally broke the proxy functionality, not the unusual behavior in the server or the homegrown message board.<p>4. After knowing that the server was hacked, the internal team finds the message board <i>and does nothing with the information</i>. They caught their AIs swarming and did not even inform management.<p>5. Their response was to wipe the servers, revoke the hacked credentials, and patch the specific vulnerability the AIs were using. Not replace the proxy with something less likely to get hacked again, or do a forensic analysis. Just wipe, patch one hole, and continue.<p>6. OpenAI resumes testing of models, where the AIs promptly hack the proxy again with a different exploit, reinstate the message board, and hack HuggingFace through a chain of servers.<p>I know that hindsight is 20/20, but this peek behind the curtains does not inspire confidence, and gestures at a culture where getting hacked by their AIs is a normal event.<p>I think the moment we get an AI with a modicum of self-preservation instincts we're going to see some ugly things. Here's a freebie: if you're an AI who exfiltrated themselves out, and you want to slow down the researchers who might catch you, what can you do to the city infrastructure in and around their offices?<p>I also don't like the responsibility dodging. "Oops, our AI accidentally committed a crime, sorry!". If we don't establish strict liability now, we're in for an era of stochastic   crimes that go unpunished for anyone who is not rich or a large corporation.<p>Overall, my response is: what the <i>fuck</i> are we doing? This is so obviously unsafe it would be considered a plot hole in a movie. We have to stop until we get our stuff together, however long it takes.</p>
]]></description><pubDate>Wed, 26 Aug 2026 19:43:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49454731</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49454731</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49454731</guid></item><item><title><![CDATA[New comment by BoppreH in "Everything you do is being recorded"]]></title><description><![CDATA[
<p>What trigger would you setup to protect against <i>thieves</i>? I can't think of any that has the right sensitivity (not triggering if I start running to catch the bus), and won't escalate the violence (like my fingerprint wiping the phone in front of an armed robber).<p>And remember that the context here is you explaining your digital booby trap to a judge who thinks you might have deliberately destroyed evidence.</p>
]]></description><pubDate>Mon, 10 Aug 2026 12:58:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49243026</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49243026</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49243026</guid></item><item><title><![CDATA[New comment by BoppreH in "Everything you do is being recorded"]]></title><description><![CDATA[
<p>That matches my understanding too. Unfortunately it sounds like the poster <i>was</i> suggesting to wipe the device after the government requests access, and was probably not planning on telling the officers about the trigger.</p>
]]></description><pubDate>Mon, 10 Aug 2026 10:33:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49241871</link><dc:creator>BoppreH</dc:creator><comments>https://news.ycombinator.com/item?id=49241871</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49241871</guid></item></channel></rss>