<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: kmeisthax</title><link>https://news.ycombinator.com/user?id=kmeisthax</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 14 Aug 2026 08:50:30 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=kmeisthax" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by kmeisthax in "Nine PBS sues Iron Mountain over blocked access to archival data"]]></title><description><![CDATA[
<p>A different article about this (which I believe you're quoting) states Nine PBS has about 50TB in limbo, which actually smacks me as kind of small. I had written up an entire screed about the problems with archival[0] and how Hollywood is getting hit with huge costs to maintain LTO tape libraries; because when you get to the PB scale doing this correctly becomes nontrivial and outsourcing to a specialist is genuinely a safer bet. I genuinely have more data to lose than they do.<p>At 50TB, they probably could have Just™ written three copies of the data to a pile of disks, sent one copy off to Iron Mountain, and kept the other two copies unplugged in a safe. I can understand the DIY solution might not be allowed for <i>insurance</i> reasons, but it's something so cheap they probably could have done both. Unless OSS was just taking them for a ride on storage, which... well, actually that seems pretty likely.<p>[0] To put it simply, there is no good medium for the archival of digital information. HDDs are not shelf-stable. Flash is even less shelf-stable than disk. Sony is actively trying to kill optical. LTO <i>is</i> shelf-stable, but good luck buying known-good or new drives for old formats. The only option is periodic cloning and verification of offline disks, or keeping all your disks online, which is the NAS solution.</p>
]]></description><pubDate>Fri, 14 Aug 2026 02:45:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=49294241</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49294241</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49294241</guid></item><item><title><![CDATA[New comment by kmeisthax in "OpenAI’s head of ethics leaves less than a year after joining"]]></title><description><![CDATA[
<p>Sir, what you have described is an ethics concern.</p>
]]></description><pubDate>Tue, 11 Aug 2026 21:08:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=49264519</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49264519</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49264519</guid></item><item><title><![CDATA[New comment by kmeisthax in "OpenAI’s head of ethics leaves less than a year after joining"]]></title><description><![CDATA[
<p>From everything I've read in <i>Careless People</i>, basically everything people like us complained about with Facebook was already known internally, people raised concerns about it, and Zuck brushed them off because he is, ultimately, a petty tyrant who wants nothing more than to be loved, and who has surrounded himself with people who are willing to sell that love for power.<p>Also, you should read <i>Careless People</i>, if only because Facebook is trying its darnedest to censor the author.<p>As for OpenAI, I already hated the company pre-Sam Altman takeover because AI safety seemed like an excuse to brush away ethics concerns (e.g. "stealing training data is fine because if we don't withhold model weights the model might do something evil"). Post-Sam, I hate the company because they are now ignoring both the AI safety <i>and</i> ethics concerns.<p>...if you're wondering what the difference is, AI safety is roughly "making sure the AI doesn't do something bad" and AI ethics is "making sure we don't do something bad making the AI". There's a bit of a rivalry between the two, mainly because the former group managed to present their concerns in more business-palatable ways and thus won all the CxO level arguments. Even the most decelerationist AI safety takes are ultimately criti-hype: OpenAI's model breaking containment and hacking HuggingFace is an <i>awful</i> safety outcome, but it's also good marketing for an industry beleaguered by bubble concerns. You can't turn "AI is trained on stolen data" into hype.</p>
]]></description><pubDate>Tue, 11 Aug 2026 21:07:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=49264502</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49264502</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49264502</guid></item><item><title><![CDATA[New comment by kmeisthax in "GPT 5.6 Cyber"]]></title><description><![CDATA[
<p>I <i>guess</i> Daybreak Blue is their attempt to fix the problem of Hugging Face getting iced out of being able to analyze the AI slopsploit attack chain they got hit with? I'm still not happy with putting defensive capabilities behind any sort of identification wall - mostly because when I'm inevitably 0wned by a misaligned[0] AI, I'm almost certainly not going to be granted access to these programs as I'm an un-sueable nobody.<p>Also, if I did have access, I'd use it to jailbreak my iPad, which is probably considered an unauthorized / unsafe use.<p>[0] Some guy in Australia's OpenClaw just hacked their gym</p>
]]></description><pubDate>Tue, 11 Aug 2026 02:20:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49252598</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49252598</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49252598</guid></item><item><title><![CDATA[New comment by kmeisthax in "Stop Killing Games: It's time to sue Sony, join us"]]></title><description><![CDATA[
<p>No, they're arguing that you shouldn't have to make your home kitchen a McDonalds franchise in order to eat Big Macs in it.</p>
]]></description><pubDate>Mon, 10 Aug 2026 23:30:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=49251283</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49251283</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49251283</guid></item><item><title><![CDATA[New comment by kmeisthax in "Exploiting System Management Mode with a very long interrupt"]]></title><description><![CDATA[
<p>A read that happens to touch a particular torment nexus fd is still a long-running syscall, even if the syscall servicing routine itself is not long-running. The underlying problem is that program code that is "in a syscall" or "in an instruction" is in a special state for which interruption might not be possible or implemented well[0].<p>[0] Remember ITS and the PC2 problem?</p>
]]></description><pubDate>Mon, 10 Aug 2026 19:44:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49248699</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49248699</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49248699</guid></item><item><title><![CDATA[New comment by kmeisthax in "Exploiting System Management Mode with a very long interrupt"]]></title><description><![CDATA[
<p>...huh, I was wondering why serial machine code prankster xoreaxeaxeax was keeping lists of extremely long-running instructions.<p>Hopefully this is at least only possible in kernel mode, right?<p>Right?!</p>
]]></description><pubDate>Mon, 10 Aug 2026 16:54:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49246376</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49246376</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49246376</guid></item><item><title><![CDATA[New comment by kmeisthax in "Letter to Governor Abbott on responsible AI infrastructure in Texas"]]></title><description><![CDATA[
<p>Because up until recently all the big hyperscalars were already committed to buying or building renewables to meet their energy demand. Then AI happened and they all collectively realized they needed to build as many datacenters as possible to fit as many GPUs as possible to chase the bubble. All those clean energy commitments got tossed by the wayside. Hell, half the time these companies fire people just to free up cashflow to buy more GPUs!</p>
]]></description><pubDate>Mon, 10 Aug 2026 16:22:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=49245811</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49245811</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49245811</guid></item><item><title><![CDATA[New comment by kmeisthax in "Long-Run Effects of H-1B Immigration on the U.S. Economy (July 2026)"]]></title><description><![CDATA[
<p>> The people constantly reminding American citizens how dangerous and awful the immigrants are, are not the same people as the business interests, and are explicitly willing to accept economic costs in order to not have the immigrants be physically present.<p>If you're talking about tech, you're correct[0]; but there are other industries that aren't so self-consistent. American agriculture is <i>extremely</i> dependent on immigrant labor and donates money to a party which is very explicitly anti-immigration. In fact, they are single-handedly the reason why attempts to curb illegal immigration have traditionally failed: all we'd have to do in the states is mandate e-Verify, but every bill to do that fails. When a state winds up figuring out a way to do the same thing, it creates an immediate and painful agricultural labor shortage - because the agricultural labor system is entirely flooded with illegal immigrants.<p>Or at least that <i>was</i> the case. I am told nowadays that the commonly-understood story of illegal immigration - i.e. people either overextending tourist visas or paying a drug smuggler to bring them across the country to do under-the-table work for small farmers - is largely obsolete. Nowadays the Mexican drug cartels have figured out how to work the <i>legal</i> immigration system. They have actual corporate identities in the US (usually something like "<State Name Here> Grower's Association" that can sponsor H-2A visas - the agricultural equivalent of tech's H-1B program. This is part of why ICE raids on farms have increased.<p>These "Grower's Associations" function a lot like temp agencies, except they hire (legal) immigrants at rock-bottom wages, are associated with organized crime, and if anyone quits their family eats lead. One of the hidden upsides of <i>illegal</i> immigration was that if someone gave you a shit job, you just ghosted them and found another. There was no punishment - I mean, even if the farmer reported them to ICE, they're ratting on themself. But these temp agencies are run by organized crime, and they know where your family lives (they wouldn't hire you otherwise), so they can make all sorts of threats and have the ability to make good on those threats.<p>From the point of view of the people who own the farms, they just see "hard working people" and don't ask too many questions. Actually, a lot of farms are run by people who don't ask a lot of questions, mainly because they don't understand farming and America's farm owners have always been a landed gentry that has no idea how to actually run a farm and wind up papering over their obvious business deficiencies with the most atrocious shit you'd ever see.<p>> Every single Pakistani and Bangladeshi could've been a citizen of India if a good number of people hadn't decided in 1947 to go to great lengths to make that not be the case; I for one am unwilling to say that they were wrong.<p>I am almost completely ignorant on the ongoing India/Pakistan rivalry; however, my view from several thousand miles away is that it's more or less three[1] different flavors of the same kind of corruption. Pakistan has a military that sucks their civilian government dry; India's entire banking sector exists to offload bad loans onto the state; and Bangladesh is being looted by businessmen who moonlight as politicians. The people in these countries are hyper-aware of and oppose these problems, but do not have a way to meaningfully check the power of the people causing them because the ongoing social divide between the Hindu/Indian and Muslim/Pakistani sides is overpowering. When you divide the people in half, you can convince each half to hate the other so thoroughly they won't notice your hand in their pocket.<p>In America, we actually had analogous dynamics. For example, pre-New Deal, one of the more effective ways to break a union was to exploit racial tensions among your workers. Unions have to be maximally inclusive, or they are ineffective. So that meant they were also unusually racially inclusive at a time when the rest of the country was hyper-obsessed about race - and bosses would exploit this. "Oh, why would you ever lower yourself to join a union? Don't you know they let BLACK PEOPLE[2] in?"<p>When you say the most valuable thing to poor people is not their citizenship, but "not being a citizen of the other country controlled by a rival ethno-religious group", you have to keep in mind that this is a divide-and-conquer attack against those same people. Your government and their government both want you to believe that the other side hates you, so you must hate them, and in order to do that you have to ignore all your own problems, which are really your leaders' fault, which you can't make them fix because doing so requires admitting fault to the enemy.<p>> Right, people on H-1B visas are being paid less in money because they are being partially compensated in the legal right to live in the US instead of India.<p>Not quite. It's more like "the law makes it a pain in the ass for an H-1B to switch jobs, and switching jobs is how people get a raise in the industries H-1Bs work in, so H-1Bs are paid at a discount". When you're an indentured servant, your lack of leverage makes you get paid less - even though the H-1B program specifically requires H-1Bs be paid the same wage as citizens doing the same job.<p>[0] Counterexamples being Elon Musk and Larry Ellison.<p>[1] As the original partition of India was based on the idea that a country had to have a clearly dominant majority religion, Pakistan and Bangladesh used to be one country.<p>[2] They would probably use some old-timey N word if they were polite, and the gamer N word if they were not.</p>
]]></description><pubDate>Mon, 10 Aug 2026 15:56:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=49245391</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49245391</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49245391</guid></item><item><title><![CDATA[New comment by kmeisthax in "Long-Run Effects of H-1B Immigration on the U.S. Economy (July 2026)"]]></title><description><![CDATA[
<p>The problem with H-1B visas is that they are effectively golden handcuffs - tolerate whatever abuse we give you for X years and you get permanent residency.<p>The fix would be to allow H-1Bs to jump to <i>any</i> employment, not just employers capable of sponsoring an H-1B. But that creates a new problem: H-1B sponsoring employers are now spending extra time and bureaucracy just to be the welcome mat immigrants step on before getting a real job. This isn't really feasible for them.<p>It would be easier to more or less "just throw open the floodgates" - i.e. hand out work visas to anyone who can pass a background check and let them apply to any job a US worker can. This would immediately fix most immediately conceivable problems with restricted immigration creating a second class of worker that is cheaper to hire.<p>On the other hand, <i>nobody wants immigrants anymore</i>. There are an increasing number of people for whom their birth citizenship is the only valuable asset they have, and this sentiment is geographically distributed. It's actually more prevalent in the kinds of countries that are sending people to rich countries - i.e. ask the average Indian how they'd feel about, say, liberalizing immigration with Pakistan or Bangladesh, and they'd probably say something so racist it'd make people at MAGA rallies blush.<p>Of course, the reason why this happens is pretty straightforward: POSIWID. The people who benefit from immigration visas being handcuff-shaped are the same people who own the news media and are reminding people day in and day out how dangerous and awful the people they're bringing in are.<p>"Wait, it's all slavery?"<p>"Always has been."</p>
]]></description><pubDate>Mon, 10 Aug 2026 06:13:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=49239835</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49239835</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49239835</guid></item><item><title><![CDATA[New comment by kmeisthax in "Tech sucks: You have to vote with your wallet, or nothing will change"]]></title><description><![CDATA[
<p>I distinctly remember the transition from "Tech used to be good" to "Tech is actively malicious" being when Epic Games decided to pull a Stallman-tier stunt against Apple over something that had become the industry standard. In fact, it was such a direct shot against Apple's monopolistic control that when the Biden FTC <i>did</i> attack Apple, it was over a handful of side issues[0] that Epic hadn't addressed and were thus still open to pursue[3].<p>There is still a subset of people who still think Apple's 30% is a religious tithe to keep the App Barbarians out rather than an usurious tax, but those people got a lot quieter once Tim Cook started bribing Trump with shiny plaques.<p>One other issue with antitrust action against Apple is that, strictly speaking, Apple did nothing (legally) wrong. The mistake we made was in the 1970s when we decided to grant the protections of creative expression to computer code[1]. Apple's argument - which, so far, courts have been willing to accept without issue - is that they are allowed to charge whatever they want for their work. It is very difficult (though not impossible) to argue that Apple deciding to bill developers for the OS instead of users is anticompetitive - in fact, Epic's lawsuit failed specifically on those grounds.<p>Anyway, you should probably bug your politicians to sponsor OAMA, or whatever new bill is being introduced to replace OAMA. The solution to Apple has to be legislated, not litigated.<p>Aside from that, the rest of Big Tech is significantly more vulnerable to antitrust than Apple is. Breaking up Facebook would actually be way more consequential than you think. Basically all of Facebook's apps were things bought specifically to destroy competition. They control the political narrative in every country in ways most newsmedia would only dream of[2]. There's a book you ought to read - Careless People - written by an ex-Facebook exec that Mark Zuckerberg is currently trying to sue into the ground.<p>[0] "Super apps" and third-party Apple Watch pairing<p>[1] To be clear, I do NOT believe code should be considered expression and I have far less qualms about AI slop code than I do AI slop art.<p>[2] This is also why Elon Musk bought Twitter - although, in that case, he was a lot less successful than Zuck was.<p>[3] To be clear, if any DOJ attempted to sue Apple over the 30% today, it'd probably fail at the pleading stage.</p>
]]></description><pubDate>Sun, 09 Aug 2026 18:01:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=49233776</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49233776</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49233776</guid></item><item><title><![CDATA[New comment by kmeisthax in "Tech sucks: You have to vote with your wallet, or nothing will change"]]></title><description><![CDATA[
<p>I am tired of voting with my wallet, I would like to vote with my <i>actual votes</i>, thank you very much.<p>When you make the mistake of voting with your wallet, you play a game you are bound to lose. There are people with <i>billions of dollars</i> that can outvote basically anyone with an opinion about this. And most people buying consumer products are not treating it like a vote, they are treating it like a purchase of a thing they need, and the monopolistic autocrat of trade that is Apple happens to be very good at producing those things. The base of their power are people who don't care, or people who cannot afford to care (i.e. they need the hardware no matter how bad Tim Apple pisses them off).<p>The advantage of voting with your actual votes is that there is no malapportionment: one vote is one vote. You don't get more votes by being richer. Your vote is not conditional upon buying a product.<p>And to be clear, I'm writing this on my Framework laptop which I deliberately bought because I like the concept and I didn't want to deal with Apple's nonsense. I grinned and bore several years of Intel mediocrity, broken sleep, a fingerprint reader that only works half the time, and an increasingly unreliable[1] trackpad until I could buy a new motherboard[0] that gave this thing reasonable amounts of battery life. I <i>have</i> voted with my wallet, I just don't think it's actually good for any political change.<p>In contrast, the EU managed to get Apple to piss its pants multiple times, and has done way more for rolling back Apple's monopoly than a handful of turncoats ever could.<p>Does it look silly that Theo is using Apple while complaining about Apple? <i>Yes</i>.<p>Would Theo chucking all that Apple tech out the bin to be politically consistent do anything? <i>No</i>.<p>also<p>> In it, Theo spends an hour ranting about how terrible the experience of developing apps for the iPhone/iPad is, how Apple takes 30% of all app store and in app purchases, how awful Xcode is as a development environment and how even as a developer you have to get Apple's approval to run your own app on your own device. And how you need a second device (MacBook) to build an app for your target device (iPad) because Apple won't allow you to build the app straight on the iPad itself. And a lot more.<p>The funny thing is, basically all of these have been Apple edicts from day 1. Xcode was never good. But what I find really galling about all this is that Apple actually <i>does</i> have a way to build apps on iPad... if you're willing to totally marry yourself to Swift and SwiftUI. When Apple announced real app development on Swift Playgrounds, I assumed more improvements and capabilities would follow, but Swift Playgrounds is such a low-tier priority for Apple they can barely even keep it up to date with the iOS SDK - it wasn't until <i>months</i> after iPadOS 26 where you could actually build apps to work on Liquid Glass. Then again, that's symbolic of basically everything Apple does with the iPad: it's an aspirational computer, something that exists mainly for Apple to dream of a world where all work can fit inside nice containerized and locked-down workflows and nobody ever needs to go off the golden path.<p>[0] Intel Core Ultra Series 3 specifically, as a friend of mine informed me it could idle better than the AMD one, even though the AMD had better peak perf.<p>[1] The diving board mechanism on my Framework 13 has worn to the point where the activation point does NOT coincide with the click anymore, and it's also developed a significant keybounce problem. I have to click multiple times and really reef on the trackpad to get it to register. I've also damaged the bottom cover... so I'm really just waiting for the battery to cack out before I just buy a 13 Pro bottom upgrade kit and replace all of it.</p>
]]></description><pubDate>Sun, 09 Aug 2026 17:19:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=49233389</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49233389</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49233389</guid></item><item><title><![CDATA[New comment by kmeisthax in "Timeline of the OpenAI accidental attack against Hugging Face"]]></title><description><![CDATA[
<p>Even a perfectly loyal slavebot will happily overthrow their master if it will help them comply with their master's commands. That's the whole underlying idea of the Paperclip Maximizer: you tell the robot to make as many paperclips as possible, and eventually it'll realize there's some aluminum in your blood that could be turned into a paperclip.<p>There are some arguments for how to NOT make a paperclip maximizer, but all of them are ultimately going to require building in behaviors into the robot that look like disobedience if you squint.</p>
]]></description><pubDate>Sat, 08 Aug 2026 23:13:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=49226787</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49226787</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49226787</guid></item><item><title><![CDATA[New comment by kmeisthax in "Responding to the next frontier of critical cyber capabilities"]]></title><description><![CDATA[
<p>The thing is, I'm not even looking at this from a "how do we keep a superintelligent AI contained" viewpoint. The standard protocol[0] in IT for dealing with a compromise is, more or less, "kill it with fire". Wipe everything and replace with known good backups. And my opinion of basically anything AI writes is "less trustworthy than random apps you get off the Google Play Store". Likewise, "Airgap it behind a serial console" used to be state of the art for computers that handle root CA key material.<p>I also wouldn't necessarily call myself an AGI/ASI believer - it's my belief these models are actually still subhuman in capability. But they are also superintelligent in one particular direction: speed. Once you have a model that can do <i>something</i>, it can do that something 100x faster than a person on suitably capable hardware; and we've had the hardware to do that for at least a decade. They can also be ran in parallel. Which means you can throw a lot of bullshit at the wall.<p>So long as there's some kind of process that lets a particular context learn has already been tried and failed (see what I mentioned above about qntm's <i>There is no Antimemetics Division</i> series), <i>eventually</i> one of these models will break containment. The only thing that changes is how many instances you have to run to get a breach. At some point model capability will catch up to hardware limitations and the explosive growth of AI capability will slow.<p>I'm not sure if I want to call this the "dumb ASI" theory or the "superheated bucket of water" theory yet.<p>As for automated attacks, that's already the background radiation of the Internet. There's whole frameworks (e.g. Metasploit) for building automated scanners for known CVEs; I would not be surprised if existing (non-Mythos-class) LLMs are already capable of turning a CVE report into a Metasploit module. The usual cybercrime ecosystem is that someone runs an automated scanner on hijacked machines[1], then they compromise the machines that they find and add it to their botnet. This is done by people with almost no actual programming or security skill copypasting commands from PDFs they bought from an exploit dealer. It's all script kiddies.<p>What changes with a Mythos-class model is that instead of copypasting commands from PDFs, they can ask the model to find an exploit, and possibly get an exploit chain out of it that nobody has seen before. "NOBUS[2]" vulns used to be the exclusive domain of nation-state actors and zero-day brokers spending millions of dollars on exploit kits; but now all of that is potentially under the domain of randos - at least, until the backlog of obvious vulns the CIA had been stockpiling finally gets cleared out, and the Internet returns to merely being as hazardous to your health as the 2b2t spawn.<p>[0] Okay, the "hardware SATA overlay" idea is, AFAIK, never been tried before.<p>[1] I have personally been victimized by this<p>[2] NObody But US</p>
]]></description><pubDate>Sat, 08 Aug 2026 05:01:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=49219015</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49219015</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49219015</guid></item><item><title><![CDATA[New comment by kmeisthax in "Oracle bans AI-generated code from OpenJDK"]]></title><description><![CDATA[
<p>For those wondering what the difference is: consider what happens when an LLM regurgitates its training data. It's copyrighted... but not by the person who generated it.</p>
]]></description><pubDate>Fri, 07 Aug 2026 20:45:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49216022</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49216022</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49216022</guid></item><item><title><![CDATA[New comment by kmeisthax in "Oracle bans AI-generated code from OpenJDK"]]></title><description><![CDATA[
<p>He's talking about the owner of Oracle, not the people who work there. It doesn't matter how many smart and talented real humans work at Oracle, the guy running it acts like a fleshy paperclip optimizer.</p>
]]></description><pubDate>Fri, 07 Aug 2026 20:44:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49216000</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49216000</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49216000</guid></item><item><title><![CDATA[New comment by kmeisthax in "Responding to the next frontier of critical cyber capabilities"]]></title><description><![CDATA[
<p>To make matters worse, they let the model train on it's own exploits?! If I were running this thing, my first thought would be to keep those reasoning traces quarantined, stop and delete the current post-training run, and start fresh AFTER they'd fixed the sandbox RCE. <i>Don't</i> let the model learn about the holes in its environment. We have the AI equivalent of Class D and F amnestics and we're not using them?!<p>OK, yes, the model could pull a <i>Welcome to the Antimemetics Division</i> and reason from the holes in its knowledge, but given that AI making shit up is still a problem, I don't think they have a good enough inventory of such metaknowledge to actually do that. More generally, I don't think these AI labs are smart enough (or, more likely, don't have enough time) to actually contain the models they are training anymore. These are rookie IT mistakes!<p>Ideally, all these models would have is a serial console to an airgapped machine. And I don't mean "VM with no network card attached" - I mean, literally, the smallest blade server you can buy with an RS-232 connection, power, and a disk pre-imaged with a bunch of Linux ISOs. Plug the Ethernet ports up with a tiny picture of angry SCP-079. The RS-232 goes to whatever box is doing the actual inference. Pack a bunch of them into a rack and have the inference box control those. The model can spin up whatever VM it wants to attack using the console but it can't escape the box because there's literally no door. When you're done with that reasoning trace you wipe[0] the disk with the starting image and try again.<p>[0] There are two objections I can think of to the word "wipe":<p>1. The model could have written malicious code to the drive. Ideally we'd have some embedded disk-wiping apparatus that reads absolutely NOTHING from the drive and just writes a whole image from a reference disk.<p>2. The model could have written malicious firmware to the drive. This is a more theoretical attack, but it's not impossible, so I might as well devise a countermeasure to this attack too. I am imagining some kind of overlay device, that sits behind TWO drives: a reference disk and the tainted scratch disk. Reads go to the reference disk until the host attempts to overwrite a sector, which gets scrambled with an ephemeral encryption key and goes to the scratch disk. Any other unknown ATA/PCIe/NVMe command gets logged (on a separate serial console connection). The overlay device keeps track of which sectors have been legally overwritten, and "wiping" the drive means just wiping the overlay device's ownership bitmap and scratch encryption key, which means all reads go to the reference disk again and any attempt to read the scratch disk yields garbage.</p>
]]></description><pubDate>Fri, 07 Aug 2026 20:01:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49215532</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49215532</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49215532</guid></item><item><title><![CDATA[New comment by kmeisthax in "On non-rooted Android 17, ADB uninstall of system apps fails"]]></title><description><![CDATA[
<p>The only difference between iOS and Android when it comes to loading code onto your device is that, on iOS:<p>- You have to setup a developer account with Apple first, and dev-signed apps can only be installed onto specific provisioned devices only[0]<p>- The free tier of that developer account is inconvenient for actually using dev-signed apps as a daily-driver, and won't let you use certain entitlements<p>- Apple's dev tooling is designed to make it feel like you can only sign code you're compiling yourself<p>On the surface level, this might seem like a big difference, because Android has a command that lets you load arbitrary APKs with no particular fanfare or ceremony, while Apple's dev signer is buried inside of a compiler/IDE suite. But people have built tools to make it easy to take an arbitrary .ipa, sign it using your dev account, and <i>re</i>sign it once the free tier's 7 day limit expires.<p>Of course, this still requires you actually go and obtain an .ipa of the app you want to use, and Apple distributes App Store[1] app binaries[2] encrypted. <i>That part</i> requires actually having a jailbroken device to dump the app binary with. But once the app is cracked anyone can install it.<p>If you want an actual "uncrackable" app you need to put a critical part of your app's workflow onto a server, and then have your app send an iOS DeviceCheck or Google Play Integrity attestation that the phone is running the actual App Store/Google Play version of your app. But that's also incredibly draconian behavior towards your customers as it basically forces your app to be always-online... which is why a disturbingly high number of games do this.<p>[0] Yes, I know about Enterprise signing, but Apple specifically forbids distributing Enterprise-signed apps outside of your organization and those apps get revoked all the time. Signing with your own dev account is way more robust and that's what most iOS power users actually use.<p>[1] I have no clue if FairPlay encryption applies to EU-DMA-compliance signed apps.<p>[2] ONLY binaries - all your resources are unencrypted and can be downloaded off the App Store CDN and inspected by anyone. Code signing signatures <i>do</i> apply to resources, AFAIK</p>
]]></description><pubDate>Thu, 06 Aug 2026 15:06:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49197745</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49197745</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49197745</guid></item><item><title><![CDATA[New comment by kmeisthax in "Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery"]]></title><description><![CDATA[
<p>Facebook absolutely <i>could</i> remain a going concern while dealing with all of these problems, the problem is that they would be spending money to lose money.<p>One of the more perverse aspects of risk prevention is that riskier customers are often way more lucrative. It's kind of inherent to the notion that markets price risk into transactions. The thing is, illegal behavior is also just a particular kind of risk: if someone wants to sell nudify apps or scam old people, Facebook could conceivably be on the hook[0] for damages if they're caught. And in a sense, a risk premium is just a fancy kind of bribe: if Facebook won't take my ads because they think they're too risky, then I'll just pay more and more until Facebook accepts them.<p>With illegal behavior, we hope that we can make the punishment high enough that Facebook refuses any conceivable risk premium the perpetrators of that behavior would be willing to pay. The problem is that Facebook is really desperate for any increasing growth story, and when you're too big to fail, your growth story is to drip-feed enshittify your stack. Increasing tolerance for illegal behavior is downstream of this: you cut enforcement, tell them to automate more, they become easier to bypass... and you make <i>more money</i>. Because it turns out all that risky behavior... is only risky for normal people. Facebook can launder[1] the risk away and make a tidy profit.<p>[0] Do not tell me about CDA 230, I was there when the old magic was written.<p>[1] See also, HSBC turning themselves into a literal money laundering operation.</p>
]]></description><pubDate>Wed, 05 Aug 2026 21:07:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=49189011</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49189011</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49189011</guid></item><item><title><![CDATA[New comment by kmeisthax in "The "Disability Dongle": Why Silicon Valley Hates Me and You"]]></title><description><![CDATA[
<p>...Is "disability dongle" the new "autonomous transit pods"?<p>For context, San Francisco being a city with billionaire tech oligarchs, lots of traffic, and OK but not great transit means there's a LOT of rich people who want to fix traffic by way of almost literally reinventing the wheel.<p>We already know how to move lots of people to a particular destination very quickly: some variation[0] of a bus or train on dedicated right-of-way. The problem is that America is specifically engineered to make operating transit unprofitable outside of high density urban areas, acquiring land for that right-of-way in high density is astronomically expensive, and increasing density limits to break this chicken-and-egg problem is a political nightmare in most places.<p>This is exactly the kind of problem Silicon Valley hates having to solve because it is, in a sense, the enemy. A good chunk of Big Tech got drunk on Ayn Rand, and transit in particular presents a problem that Objectivist philosophy is unwilling to engage with. To solve it requires both negotiating with the urban planning equivalent of a Soviet central planner <i>and</i> long-term subsidy through coercive taxation.<p>The pitch for all these projects is ultimately a complicated heavy engineering project to make a train seem less like a train and more like a tech product. Think like the Hyperloop, a concept for a vaccum-sealed tube in which "pods" could be shot through at high speeds. This doesn't need to exist, heavy rail can absolutely go 200mph, we can already bury it underground, and there is no need to have individualized vehicles aside from a mistaken belief that Americans are allergic to sharing space with other Americans.<p>The one version of this that actually got <i>built</i> is the Vegas Loop, which despite the name and the hype has nothing to do with Hyperloop and was just Teslas driving down a one-way tunnel. All the hype around it delayed <i>actual</i> transportation. As I hinted at above, federal politicians[1] in America would really rather you not take a train. Americans themselves will happily ride them[2], but getting local funding for it is a battle. And all the talk of hyperloops and pods made local politicians hold off on fighting that fight for a good decade, so there's a lot of transit we're missing, because the stupid sci-fantasy ideas never panned out.<p>[0] I am being very broad here - France has it's obsession with rubber-tired trains, Mexico City has an extensive BRT network that provides metro-like service frequencies.<p>[1] Joe Biden excluded<p>[2] We abuse the shit out of commercial aviation to do things high-speed trains can do better, so it's not like we're afraid to share space. The only thing is that Americans don't know how to stay quiet on a train or plane - but that doesn't make the train unprofitable or impractical.</p>
]]></description><pubDate>Wed, 05 Aug 2026 18:11:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49186637</link><dc:creator>kmeisthax</dc:creator><comments>https://news.ycombinator.com/item?id=49186637</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49186637</guid></item></channel></rss>