<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: coppsilgold</title><link>https://news.ycombinator.com/user?id=coppsilgold</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 05 Jun 2026 07:06:24 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=coppsilgold" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by coppsilgold in "LLMs are not the black box you were promised"]]></title><description><![CDATA[
<p>I believe it's a great deal worse than that. All the metacognitive insight we do have may just be confabulation and we are fooled into believing that we have it because the process for conjuring it is good at finding a plausible answer.<p>When you read about and observe the split-brain patient experiments the appropriate response is abject horror at the implications.</p>
]]></description><pubDate>Wed, 03 Jun 2026 02:07:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48378987</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48378987</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48378987</guid></item><item><title><![CDATA[New comment by coppsilgold in "Claude Opus 4.8"]]></title><description><![CDATA[
<p>The Opus model as usual impresses. Gave it a paper link with bullet point instructions and constraints (while baiting it to perform some mind reading of my intentions) and it implemented production ready code + the requested attack simulations: <<a href="https://gist.github.com/coppsilgold/00d3cd490cb7f8ffc3fe5c1c81f77afd" rel="nofollow">https://gist.github.com/coppsilgold/00d3cd490cb7f8ffc3fe5c1c...</a>><p>The subject is Tardos traitor-tracing codes.</p>
]]></description><pubDate>Fri, 29 May 2026 06:37:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48319813</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48319813</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48319813</guid></item><item><title><![CDATA[New comment by coppsilgold in "DeepSeek makes the V4 Pro price discount permanent"]]></title><description><![CDATA[
<p>I'm sure the frontier labs figured out very clever ways to leverage user input and actions as data for training and signals for RL. DeepSeek wants in on the game.</p>
]]></description><pubDate>Sun, 24 May 2026 19:09:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48260107</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48260107</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48260107</guid></item><item><title><![CDATA[New comment by coppsilgold in "Heritability of human life span is ~50% when heritability is redefined"]]></title><description><![CDATA[
<p><p><pre><code>    > Almost all human traits are partly genetic and partly due to the environment and/or random. If you could change the world and reduce the amount of randomness, then of course heritability would go up.
</code></pre>
There has been a lot of effort to determine systematic environmental factors that would influence things like intelligence and while it's easy to do harm (lead exposure) it's all but impossible to do any good.<p>It implies that the only environment that matters is either purely random (truly random accidents, circumstances) or non-systematic (results from non-linear interaction of environment and genes).<p>When stated that way it almost feels like a tautology because this is what genes exist to do in the first place. To control the interactions of their vessel and environment to the maximum degree. And from the perspective of an individual gene, all the other genes are part of the environment too.<p><pre><code>    > There is no such thing as “true” heritability, independent of the contingent facts of our world.
</code></pre>
It's uncomputable (need to run Monte Carlo simulations on a human life). All efforts are to approximate it.</p>
]]></description><pubDate>Wed, 13 May 2026 15:36:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48123314</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48123314</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48123314</guid></item><item><title><![CDATA[New comment by coppsilgold in "Starship V3"]]></title><description><![CDATA[
<p>I was actually curious about this myself back when everyone was chiming in about how it was physically impossible.<p>This is first and foremost an engineering problem as you need to design a system that will both tolerate high heat and be able to pump even more heat to the radiators. The high temperature seems to be the primary objective to design for unless launch costs become absurdly low.</p>
]]></description><pubDate>Wed, 13 May 2026 07:12:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=48118769</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48118769</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48118769</guid></item><item><title><![CDATA[New comment by coppsilgold in "Hardware Attestation as Monopoly Enabler"]]></title><description><![CDATA[
<p>Yes, with blind signatures you still have a central authority which voluntarily 'launders' tokens for you. When you present it your certificate and ask it to give you a blind signature it can reject the certificate.<p>However if someone extracts a key and keeps it private, and instead gives out unblinded tokens there is nothing you can do other than rate limit - realistically, an adversary is going to trial different rates anyway to figure out which don't make them an outlier.</p>
]]></description><pubDate>Tue, 12 May 2026 16:44:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=48110754</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48110754</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48110754</guid></item><item><title><![CDATA[New comment by coppsilgold in "Hardware Attestation as Monopoly Enabler"]]></title><description><![CDATA[
<p>If A adopts a Blind Signature scheme it implies A is cooperating in establishing privacy infrastructure. If A is so malicious that it would advertise a sound privacy system and then it immediately sabotages it that's a different matter...</p>
]]></description><pubDate>Mon, 11 May 2026 20:11:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48100037</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48100037</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48100037</guid></item><item><title><![CDATA[New comment by coppsilgold in "Hardware Attestation as Monopoly Enabler"]]></title><description><![CDATA[
<p><p><pre><code>    Content Decryption Module (CDM) in your browser or Mobile SDK generates the license challenge
</code></pre>
<<a href="https://go.buydrm.com/thedrmblog/the-anatomy-of-a-multi-drm-license-request" rel="nofollow">https://go.buydrm.com/thedrmblog/the-anatomy-of-a-multi-drm-...</a>><p>The "license challenge" (it might be a mistake I think it's supposed to be a license request) is just a packet (that can be saved and later sent to anywhere) and it contains the encrypted certificate which doubles as your HWID. An adversary needs to control the private key of the license "server" the challenge is for (this is a privacy measure introduced to prevent the CDM from offering the HWID to anyone who wants it). Now if you want the HWID you need to work for it (one time) by stealing a private key, bribing/blackmailing employees or issuing secret edicts ("here is a new license server we need a certificate for"). Working for Hollywood is also an option I suppose.<p>Pirates sacrifice devices when they publish ripped content due to the certificate being revoked after Hollywood downloads the torrent and by doing things like this:<p><pre><code>    For large-scale per-viewer, implement a content identification strategy that allows you to trace back to specific clients, such as per-user session-based watermarking. With this approach, media is conditioned during transcoding and the origin serves a uniquely identifiable pattern of media segments to the end user.
</code></pre>
<<a href="https://docs.aws.amazon.com/wellarchitected/latest/streaming-media-lens/detective-controls.html" rel="nofollow">https://docs.aws.amazon.com/wellarchitected/latest/streaming...</a>></p>
]]></description><pubDate>Mon, 11 May 2026 03:53:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48090913</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48090913</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48090913</guid></item><item><title><![CDATA[New comment by coppsilgold in "Hardware Attestation as Monopoly Enabler"]]></title><description><![CDATA[
<p>> you present the same unblinded signature to both services<p>You would never do this as it defeats the entire purpose of using blind signatures to begin with.</p>
]]></description><pubDate>Sun, 10 May 2026 22:34:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48088852</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48088852</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48088852</guid></item><item><title><![CDATA[New comment by coppsilgold in "Hardware Attestation as Monopoly Enabler"]]></title><description><![CDATA[
<p>The way it would work with blind signatures is that the server will know the device that comes to it to request a blinded signature and will be able to rate limit how often that device asks it.<p>But once you get the response you can unblind the signed signature and obtain the token (which is just the unblinded signature). This token can then be used once either because its blacklisted after use (and it expires before the next day starts for example).<p>The desired property of blind signatures is that given a token it's information theoretically impossible to determine which blinded signature it came from (because it could have come from any of them) even if the cryptographic primitive is broken by a mathematical breakthrough or a quantum computer. There is technically the danger that if the anonymity set is too small and all the other participants collude you can be singled out.<p>Correlating times is a threat vector that  needs to be managed either by delaying actions (not tolerable by normal users) or by acquiring tokens automatically and storing them in expectation. Or something other I haven't thought of probably. There is also a networking aspect to this, you will need a decentralized relay server network that masks origin of requests.</p>
]]></description><pubDate>Sun, 10 May 2026 21:28:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=48088262</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48088262</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48088262</guid></item><item><title><![CDATA[New comment by coppsilgold in "Hardware Attestation as Monopoly Enabler"]]></title><description><![CDATA[
<p>There is a problem where it's becoming increasingly harder to determine which internet packets that are coming to your service are at the behest of a human in the course of normal activities or an automated program.<p>If all the internet was is static content, that wouldn't be much of a problem. But we live in world where packets coming to your service result in significant state changes to your database (such as user generated content).<p>I suspect that we are currently in the valley of do-something-about-it on the graph which is why you see all this angst from the big players. Would Google really care if automated programs were so good that they were approximating real humans to such an extent that absolutely no one can tell? I suspect they would not only be happy with such a state of affairs, they would join in.</p>
]]></description><pubDate>Sun, 10 May 2026 21:20:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48088187</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48088187</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48088187</guid></item><item><title><![CDATA[New comment by coppsilgold in "Hardware Attestation as Monopoly Enabler"]]></title><description><![CDATA[
<p>I simplified the process in my description. The DRM ID Android has is not what I was referring to.<p>I was referring to the static private key that is stored in the silicon. At any time an application can initiate a license request process using DRM APIs which will elicit an unchangeable HWID from your device. The only protection is that it will be encrypted for an authorized license server private key so collusion may be required (intel agencies almost certainly sourced 'authorized' private keys for themselves). Google or Apple also has the option to authorize keys for themselves. In 'theory' all such keys should be stored in "trusted execution environments" on license servers and not divulge client identities for whatever that's worth: <<a href="https://tee.fail" rel="nofollow">https://tee.fail</a>>.</p>
]]></description><pubDate>Sun, 10 May 2026 19:51:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48087206</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48087206</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48087206</guid></item><item><title><![CDATA[New comment by coppsilgold in "Hardware Attestation as Monopoly Enabler"]]></title><description><![CDATA[
<p>Requiring authorized silicon (and software) isn't even the biggest problem here.<p>They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID' is used to acquire an ephemeral 'ID' from an intermediate server) but it's just a show because you don't know what those intermediary severs are doing: You should assume they log everything.<p>And this just the remote attestation vector, the DRM 'ID' vector is even worse (no meaningful indirection, every license server has access to your burned-in-silicon static identity). And the Google account vector is what it is.<p>Using blind signatures for remote attestation has actually been proposed, but no one notable is currently using it: <<a href="https://en.wikipedia.org/wiki/Direct_Anonymous_Attestation" rel="nofollow">https://en.wikipedia.org/wiki/Direct_Anonymous_Attestation</a>><p>There are several possible reasons for this, the obvious one is that they want to be able to violate your privacy at will or are mandated to have the capability. The other is that because it's not possible to link an attestation to a particular device the only mitigation to abuse that is feasible is rate limiting which may not be good enough for them - an adversary could set up a farm where every device generates $/hour from providing remote attestations to 'malicious' actors.</p>
]]></description><pubDate>Sun, 10 May 2026 19:39:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48087095</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48087095</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48087095</guid></item><item><title><![CDATA[New comment by coppsilgold in "Google broke reCAPTCHA for de-googled Android users"]]></title><description><![CDATA[
<p>This is not sufficient. Do they give you a blind signature?<p>Because what you described does not preserve your anonymity if the government and the service collude.</p>
]]></description><pubDate>Sun, 10 May 2026 19:34:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48087055</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48087055</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48087055</guid></item><item><title><![CDATA[New comment by coppsilgold in "Google broke reCAPTCHA for de-googled Android users"]]></title><description><![CDATA[
<p>As far as I know no currently proposed age verification method does this in practice.<p>The only way to implement truly privacy preserving age verification is through zero knowledge proofs (or blind signatures) but what that would allow is undetectable token forging.</p>
]]></description><pubDate>Sat, 09 May 2026 19:30:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48077541</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48077541</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48077541</guid></item><item><title><![CDATA[New comment by coppsilgold in "Google broke reCAPTCHA for de-googled Android users"]]></title><description><![CDATA[
<p>Realistically, what Google will do in such a scenario is collect data about the illicit service, enumerate the devices the farm uses and what other activities the devices participate in. What you suggested has far less control over the devices that generate the attestations and it will show.<p>Also, if the implementation is competently done the phone will show the website for which you scanned the QR code. A user would be able to see whether or not that matches the site where they observed the QR code and proceed accordingly. In time Google will probably integrate it into the Chrome browser where a proxied QR code cannot even be shown.</p>
]]></description><pubDate>Fri, 08 May 2026 23:09:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48069892</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48069892</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48069892</guid></item><item><title><![CDATA[New comment by coppsilgold in "Google broke reCAPTCHA for de-googled Android users"]]></title><description><![CDATA[
<p>Apple has their own remote attestation infrastructure and you will not be able to impersonate an Apple device without extracting private key material from the secure enclave of a legitimate Apple device or compromising Apple certificate authority private keys.</p>
]]></description><pubDate>Fri, 08 May 2026 20:59:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48068705</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48068705</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48068705</guid></item><item><title><![CDATA[New comment by coppsilgold in "Mojo 1.0 Beta"]]></title><description><![CDATA[
<p>Python is basically the master glue language at this point.<p>If more than a few percent of execution time is spent in Python you are probably doing it wrong.<p>Personally I don't even understand why Cython is a thing, just write performance critical functions in other languages:<p><<a href="https://pypi.org/project/rustimport/" rel="nofollow">https://pypi.org/project/rustimport/</a>><p><<a href="https://pypi.org/project/import-zig/" rel="nofollow">https://pypi.org/project/import-zig/</a>><p>Note that you can even start threads in those languages and use function calls as pseudo-RPC. All without an overly complex build system.</p>
]]></description><pubDate>Fri, 08 May 2026 19:57:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=48067932</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48067932</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48067932</guid></item><item><title><![CDATA[New comment by coppsilgold in "Google broke reCAPTCHA for de-googled Android users"]]></title><description><![CDATA[
<p>My understanding is that this new reCAPTCHA is basically just remote attestation.<p>Remote attestation doesn't use blind signatures (as that would be 'farmable') so tying the device to the 'attestee' is technically possible with collusion of Google servers: EK (static burned-in private key) -> AIK (ephemeral identity key in secure enclave signed by a Google server) -> attestation (signed by AIK). As you can see if the Google server logs EK -> AIK conversions an attestation can be trivially traced to your device's EK. This is also why we don't really see and probably never will see online services which offer fake remote attestations, as it will be pretty obvious that the next step of running such a service is getting Google as a customer and having all your devices blacklisted. Private farms probably won't last long either as I'm sure Google logs everything and will correlate.<p>Unless something special is done with this new reCAPTCHA not only are you locking internet services behind TPM chips but you are also surrendering anonymity to Google. Unless you acquire untraceable burners for every service, the new reCAPTCHA will be technically capable to tying all your accounts across all these services together. Much like age verification. It may appear that the service would need to cooperate to link the reCAPTCHA session to your registration but the registration time alone will likely be sufficient (the anonymity set will be all but destroyed).</p>
]]></description><pubDate>Fri, 08 May 2026 19:19:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48067505</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=48067505</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48067505</guid></item><item><title><![CDATA[New comment by coppsilgold in "New research suggests people can communicate and practice skills while dreaming"]]></title><description><![CDATA[
<p>Checking clocks for consistency. Text as well. They are less reliable. Some people swear by rotating a text containing object upside down and see if the text auto-rotates, apparently it does in their dreams. Some people can't read anything in their dreams.</p>
]]></description><pubDate>Sat, 02 May 2026 02:42:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=47982830</link><dc:creator>coppsilgold</dc:creator><comments>https://news.ycombinator.com/item?id=47982830</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47982830</guid></item></channel></rss>