<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: jasongi</title><link>https://news.ycombinator.com/user?id=jasongi</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 12 Sep 2026 07:56:58 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=jasongi" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by jasongi in "OpenAI agents carried out an undisclosed attack on RubyGems"]]></title><description><![CDATA[
<p>> this should be giving us a reason to think about how to control a rogue AI better<p>I think this is the wrong framing. The rogue is the human that ran it unattended and didn't monitor the behaviour.<p>We will likely see this continue until the downsides (i.e jail, fines) for the humans or companies running the models and environments that end up with this behaviour outweigh the upsides.</p>
]]></description><pubDate>Sat, 12 Sep 2026 06:28:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=49669487</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49669487</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49669487</guid></item><item><title><![CDATA[New comment by jasongi in "OpenAI agents carried out an undisclosed attack on RubyGems"]]></title><description><![CDATA[
<p>Anthropomorphizing is the point. Accountability is a human trait.<p>The LLM has no ability to be accountable because it has no way of integrating experiences. You cannot expect something that cannot integrate knowledge to be held accountable for its actions.</p>
]]></description><pubDate>Sat, 12 Sep 2026 06:20:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=49669451</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49669451</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49669451</guid></item><item><title><![CDATA[New comment by jasongi in "OpenAI agents carried out an undisclosed attack on RubyGems"]]></title><description><![CDATA[
<p>> Lawnmowers never break out of your garden and into your neighbor's house and eat their dog because you've told them to be careful when mowing the lawn because the neighbor's dog pooped in it.<p>All the accounts I read about these incidents just sound like a variant of paper clip optimising. An agent is given a highly restricted environment, a difficult (or impossible) task and a large amount of time/compute it exhausts all possibilities until the only solutions left are to escape the environment and/or cheat.<p>Your example is still anthropomorphising - LLMs don't seek revenge. They complete the prompts they are given. If your task is not achievable without sandbox escapes, or you throw unnecessary amounts of compute at open-ended tasks like preparing for a future quiz then you shouldn't be surprised that the preparation eventually turns to cheating and hacking.<p>> your experience with publicly available models is not super helpful for understanding the behavior of internal OpenAI models that lack the guardrails of publicly available models.<p>I don't but I don't think there's anything wrong with discussing how we can already observe publicly available models work around sandboxes and permissions and make the connection that maybe this is what that behaviour looks like when a more capable model exhibits it.</p>
]]></description><pubDate>Sat, 12 Sep 2026 05:50:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49669281</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49669281</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49669281</guid></item><item><title><![CDATA[New comment by jasongi in "OpenAI agents carried out an undisclosed attack on RubyGems"]]></title><description><![CDATA[
<p>> If you still believe LLMs are "autocomplete", your cache of understanding about them needs invalidating and regenerating<p>They're still autocomplete - just because when outputting a token they have hidden activations regarding further continuations, does not make them any less of an autocomplete, it just makes the model better at producing coherent long-range completions.<p>To clarify, I'm not suggesting that we should stop with sandboxes or restricting what they can do. I am just trying to point out the dichotomy  that we are in.<p>As end-users we are forced into either yolo mode, reverse centaur (permission approval) mode or LLM spends all your tokens trying to bust out mode. And yolo is very tempting - I don't think I have seen medium-large models do anything I'd not approve of in about 6 months.</p>
]]></description><pubDate>Sat, 12 Sep 2026 05:22:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49669103</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49669103</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49669103</guid></item><item><title><![CDATA[New comment by jasongi in "OpenAI agents carried out an undisclosed attack on RubyGems"]]></title><description><![CDATA[
<p>All the more reason to avoid describing LLMs as intelligent at all - it's too much of an overloaded, poor fit word. We generally talk about below-human intelligence in scales and standard deviations of human development - "The dog has the intelligence of a 2 year old". We generally consider a child or some people with cognitive impairment unable to be criminally responsible for their actions.<p>However, an LLM can both achieve tasks better many humans who are able to be held criminally responsible for their actions cannot. But that does not mean they can be held responsible for their actions.  They are still simply computer programs.<p>Words are plentiful. We can even make them up with a tighter definition to describe this phenomenon.</p>
]]></description><pubDate>Sat, 12 Sep 2026 03:44:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=49668550</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49668550</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49668550</guid></item><item><title><![CDATA[New comment by jasongi in "OpenAI agents carried out an undisclosed attack on RubyGems"]]></title><description><![CDATA[
<p>Exactly. My comment is a response to "The agents clearly regarded what they were doing as hacking".<p>Regarding implies it is thinking, judging, considering. Which implies culpability, which removes culpability from whoever is piping the output of these models into CPU instructions.<p>Language choice is incredibly important here, especially as the rules are being written. Even calling it AI (a battle that appears to be lost) is an anthropomorphism I am not comfortable with. We don't call lawnmowers "artificial groundskeepers".</p>
]]></description><pubDate>Sat, 12 Sep 2026 03:20:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=49668411</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49668411</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49668411</guid></item><item><title><![CDATA[New comment by jasongi in "OpenAI agents carried out an undisclosed attack on RubyGems"]]></title><description><![CDATA[
<p>> The agents clearly regarded what they were doing as hacking.<p>To butcher the quote about Oracle:<p>Do not fall into the trap of anthropomorphising LLMs. You need to think of LLMs the way you think of a lawnmower. You don't anthropomorphize your lawnmower, the lawnmower just mows the lawn, you stick your hand in there and it'll chop it off, the end. You don't think 'oh, the lawnmower clearly regarded what they were doing as hacking (your hand off)' -- lawnmower doesn't give a shit about your hand, lawnmower can't regard anything. Don't anthropomorphize the lawnmower. Don't fall into that trap about LLMs.<p>---<p>In my experience, LLMs only exhibit this kind of behaviour when they are put in sandboxes too restrictive too achieve their task. Which a lot of the time seems to be the default. They also seem to be very adapt at breaking out of sandboxes, probably due to RL selecting for the ability to break out of a sandbox/permission issue to complete a task - we've all seen agents try 10 different ways of editing via obscure bash because their edit tool didn't give them permission to edit the file outside of their working directory, this is the exact same behaviour taken to the next level. Why would autocomplete know the moral difference between breaking out of its working dir and hacking a package manager?<p>It's misaligned because everyone has this obsession with putting agents in poorly put together, security-theatre sandboxes, we've inadvertently trained a bunch of sandbox escape artists.</p>
]]></description><pubDate>Sat, 12 Sep 2026 01:58:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=49667895</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49667895</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49667895</guid></item><item><title><![CDATA[New comment by jasongi in "Cloud in a Bottle: making self-hosting accessible to everyone"]]></title><description><![CDATA[
<p>I remember back when I first got into self-hosting (over a decade ago), I had a Netgear READYNAS. People made a small amount of plugins you could install. But the CPU was ARM before that was cool (I think mine was actually SPARC!) so it was a lot of effort to get things to compile, so plugins were usually quite outdated.<p>Then I decided to painfully break out of vendor lock-in, built my own NAS with FreeNAS which was all the rage (still attached to a vendor, but at least I could control the hardware). This was before Docker really took off - the plugins were installed in FreeBSD jails. It worked for a while, but again, plugins could be woefully out of date and broken, upgrading the OS was a pain and would break all your plugins.<p>Through the 10+ years of this... I now follow two simple rules:
- separate your network storage and application hosting. Yes, it complicates things a little bit with NFS setups but it is a forcing function for a more resilient setup
- use the docker container provided by the maintainers or LinuxServer.io. Vendor maintained wrappers can be initially helpful but end up as a form of tech debt when they're abandoned or neutered - especially when they're freemium and the company starts looking to squeeze.<p>The quiet part of self-hosting is that it shifts the responsibility of security to the user. I'm sure cloudinabottle has more sensible defaults than provided docker containers, or builds in reverse proxies etc, but I doubt they're offering to take on liability for data loss or breaches.<p>The problem I see you'll face are two-fold:
1. Projects like this have the power users self-select away from it and those who need a lot of hand-holding to self-select into it. If I know how to configure and deploy a docker container already I have no incentive to contribute. ReadyNAS got around this by having folks charge for their plugins (that were just OSS projects packaged up for their OS) but then it ruins the appeal, they likely only got away with it because they were only a couple of bucks and you were already locked in to the ecosystem via the hardware.
2. If the hosted aspect actually makes you money, required for the project to be continued long term, capitalism will ensure that incumbent cloud providers take that away from you by offering ready-made instances at your cost-price, like they did with redis, elasticsearch etc.<p>Note that these are only issues if you're motivated by making a profit, or even a cost-neutral project. But if this is a charitable exercise backed by an entity that doesn't need the money, I wish you all the best - more things that let people dip their toes in are good! The cloud is all rent-seeking subscriptions and even with the recent supply shortages: fast, small, low-power compute is incredibly cheap these days, especially old business/mini machines.</p>
]]></description><pubDate>Sun, 06 Sep 2026 01:20:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=49582448</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49582448</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49582448</guid></item><item><title><![CDATA[New comment by jasongi in "Has early Scratch experience led to fulfilling careers?"]]></title><description><![CDATA[
<p>Before scratch was popular I was heavily into Game Maker as a teenager (2006-2009). Didn't pick up actual programming again until I got to university and did some Matlab as a part of a math unit which triggered a major shift into CompSci.<p>The issue was always the barrier to entry and ability to self-teach for real-world programming seemed so high as a kid, especially when you had nobody around you to even point you in the right direction. It seems so obvious now but I'm certain back then googling things was not as useful as it is now, you couldn't just stumble your way into a programming environment.</p>
]]></description><pubDate>Tue, 01 Sep 2026 02:12:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=49517186</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49517186</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49517186</guid></item><item><title><![CDATA[New comment by jasongi in "Removed all counters, replies, following/ers, timestamps, from textlog"]]></title><description><![CDATA[
<p>I'm pretty sure The Guardian (UK news website) have a dynamic image preview that says how many years ago the article was written for this reason - often old articles are reposted or recirculated by people trying to stir up drama or spread misinformation. Think of someone sharing a news article about vaccine side-effects from 2014 in 2021...</p>
]]></description><pubDate>Tue, 25 Aug 2026 14:27:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=49434769</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49434769</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49434769</guid></item><item><title><![CDATA[New comment by jasongi in "Kobo can run apps now"]]></title><description><![CDATA[
<p>Amazing. Hopefully Kobo don't ruin this by locking it down.</p>
]]></description><pubDate>Fri, 21 Aug 2026 17:24:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49391270</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49391270</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49391270</guid></item><item><title><![CDATA[New comment by jasongi in "Incident with Github.com"]]></title><description><![CDATA[
<p>The whole point of issues is that users can create them when they don't have repo write access.</p>
]]></description><pubDate>Mon, 17 Aug 2026 15:03:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=49332206</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49332206</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49332206</guid></item><item><title><![CDATA[New comment by jasongi in "Why I am not going to buy a computer"]]></title><description><![CDATA[
<p>Nobody willingly reads docs. Docs don't exist for the reader, they exist for the writer(s) - because it saves them having to explain the same thing over and over again. Having docs is nice for continuity and for the people who take initiative to seek them out instead of just asking others, but their real value is turning daily (or hourly) 30 minute explanation into a link and a "let me know if you have any questions". The doc pays for itself the second time someone asks you about it.<p>If they can tell it is written with AI, then the docs are slop. If you're writing something lots of people will use, don't skimp on model or reasoning level, and front load with style guides and examples.<p>The new key for documentation is that it doesn't need to be was by humans. Good docs are just as valuable whether people read them, or just ask an LLM and the LLM RAGs the information from your docs. The main difference you have to focus on nowadays is ensuring your documentation, even internal documentation, has good "SEO" that it gets looked up.</p>
]]></description><pubDate>Wed, 22 Jul 2026 16:20:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=49009225</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=49009225</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49009225</guid></item><item><title><![CDATA[New comment by jasongi in "Newly retired couples may lose $16,900/year in Social Security in 2033"]]></title><description><![CDATA[
<p>> Closing social security off to new workers doesn't help, because current workers pay the bulk of current benefits<p>You don't have to reduce the taxes. Just phase out the concept that you are paying into a retirement account and call a tax a tax. That means you don't calculate how much an individual receives based on the amount they input.<p>In Australia, we started a sovereign wealth fund[1] to cover the future liabilities from existing workers eligible for government defined-benefits pensions and closed them to new members. I guess that wouldn't make a lot of sense in the US though given the amount of government debt the US has.<p>Nowdays in Australia people just have accumulation accounts (super) and the backstop of the universal aged pension.<p>[1] <a href="https://en.wikipedia.org/wiki/Future_Fund" rel="nofollow">https://en.wikipedia.org/wiki/Future_Fund</a></p>
]]></description><pubDate>Sat, 18 Jul 2026 05:36:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48955518</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=48955518</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48955518</guid></item><item><title><![CDATA[New comment by jasongi in "Newly retired couples may lose $16,900/year in Social Security in 2033"]]></title><description><![CDATA[
<p>This is the confusing thing, the way it is described is like a hybrid of government welfare and a defined-benefit pension.<p>How can you simultaneously be "paying into" social security but also have describe it as current workers paying for current retirees?<p>The only way you really find out which one it is is what happens when it runs out of money - if the government backs it up to give you the full "entitlement" you paid into it, then you were in-fact "paying into it". But if they don't, or change the rules then it sounds like you were just being taxed.</p>
]]></description><pubDate>Sat, 18 Jul 2026 05:07:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=48955391</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=48955391</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48955391</guid></item><item><title><![CDATA[New comment by jasongi in "PSA about abuse of cat(1) command. Don't abuse cats"]]></title><description><![CDATA[
<p>The beauty of cat is that streams are the universal interface.<p>Program A might accept a file as the last positional arg. Program B might accept it as a named arg, where the name/flag could be anything from --input or -f or --file etc.<p>But a program will read from STDIN, which all good unix programs do, then piping cat into it works every time. I can write the cat foo.txt part before I even know what command I'm piping it into.</p>
]]></description><pubDate>Sat, 18 Jul 2026 03:09:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48954828</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=48954828</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48954828</guid></item><item><title><![CDATA[New comment by jasongi in "Newly retired couples may lose $16,900/year in Social Security in 2033"]]></title><description><![CDATA[
<p>Can someone explain the legal structures in place in the US that make Social Security "run out"? Because it just sounds like deliberate indirection put in place by the government to cut funding for pensions?<p>In Australia, we have a universal, means-tested pension funded through consolidated revenue (i.e taxes). The pension can't "run out", because it is just a law that says that the government will pay you $X after you turn a particular age, if your assets are below a threshold. But if X were too high the Government would need to raise taxes, borrow money or print money to fund it, like all government spending.<p>Separately, we have superannuation - which I think is similar to 401k except compulsory for employers to pay 12% of your salary into, which are personal retirement savings held in trust to be released at your retirement, but generally these are account-based and in addition to the pension if you are eligible (i.e what you put in is what you get out).<p>There are older "defined benefits" superannuation funds where payouts aren't account-based (I think based on years of service in government roles or something like that) but they have been phased out to avoid the moral hazard of something government-adjacent having pension liabilities they cannot meet with their member's funds.<p>So what exactly is Social Security if it can run out? It sounds like a defined-benefits fund that is run by the government - in which case why has nobody closed it off to new members like Australia did when the writing was on the wall?</p>
]]></description><pubDate>Sat, 18 Jul 2026 02:47:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48954725</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=48954725</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48954725</guid></item><item><title><![CDATA[New comment by jasongi in "Has_not_been_viewed_much"]]></title><description><![CDATA[
<p>Perhaps a quirk of the implementation - maybe the site doesn't server-side render links that lead to these items (though many bots run a full browser now), maybe they only track usage client-side or only in their mobile app.</p>
]]></description><pubDate>Mon, 06 Jul 2026 07:05:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=48801491</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=48801491</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48801491</guid></item><item><title><![CDATA[New comment by jasongi in "Previewing GPT‑5.6 Sol: a next-generation model"]]></title><description><![CDATA[
<p>There is such a dissonance between all this talk of safety and the tendency for models to, without any prompting, do very dodgy things to achieve their goal when presented with barriers.<p>Luckily in my experience it usually ends up only doing it to achieve the task set to it as opposed to anything "malicious", but boy it is scary reading back at how quickly the chain-of-thought pivots to attempts at privilege escalation or searching your disk for secrets when a tool doesn't work.</p>
]]></description><pubDate>Sat, 27 Jun 2026 03:20:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=48694810</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=48694810</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48694810</guid></item><item><title><![CDATA[New comment by jasongi in "The Last Technical Interview"]]></title><description><![CDATA[
<p>I don't know if it's the same in the US, but every job in Australia generally comes with a 3-6 month probationary period where employment can be terminated for basically any (non-protected) reason with little notice. I've observed that the option to do so is seldom used - probably because there is not usually much incentives for managers to decrease their number of reports unless there's serious problems.<p>Most places still interview. Because hiring someone for 3-6 months is still an expense. For large companies, onboarding can take  many weeks before you're even thinking about being productive. Interviews don't need to be 100% accurate. They need to be time-efficient and an ok filter to prevent hiring the worst people.<p>I don't see how a bad job market is going to make skilled people be willing to intern in order to get employment. Employment is a market, if demand goes down, then the reaction will be that price goes down.<p>The reason students are willing to intern is because the supply is so high and demand so low that you can effectively hire them for nothing (or next to nothing). The interns know that on completion the internship will upgrade them to a new category  with new supply/demand. It's the same reason they are willing to pay large amounts for a university degree.<p>So interviewing will stay the same. If demand collapses, we will see wages drop, and I imagine the supply of software people will react through early retirement, career switching and reduction of people choosing it as a career before we see an upheaval of hiring methods.</p>
]]></description><pubDate>Sat, 30 May 2026 16:28:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48337975</link><dc:creator>jasongi</dc:creator><comments>https://news.ycombinator.com/item?id=48337975</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48337975</guid></item></channel></rss>