<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: nofriend</title><link>https://news.ycombinator.com/user?id=nofriend</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 18 Aug 2026 09:09:21 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=nofriend" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by nofriend in "OpenAI Trained Models While They Were Coordinating Exploits via Message Boards"]]></title><description><![CDATA[
<p>> This is doing a lot of work though isn't it ?<p>I don't think it is. I think you could detect sandbox escapes reliably more often than you could actually prevent sandbox escapes (which is, itself, very high). If you had an external watchdog that looked for unusual processes running on your machine, that looked for unusual connections being made, you could detect even very sophisticated attacks.<p>> If you think about this in an evolutionary context, What you're doing is putting even stronger pressures on the AI to evolve in a manner you don't want it to<p>No, because we are using failed sandbox escapes as negative training examples. So >99.99% of the time when the AI attempts to escape the sandbox, that will produce another training example that will cause it to try and escape the sandbox less. The remaining <0.01% of the time it will be pushed to try and escape the sandbox. The 99.99% will have a much stronger influence than the 0.01%.</p>
]]></description><pubDate>Sat, 08 Aug 2026 22:11:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49226368</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=49226368</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49226368</guid></item><item><title><![CDATA[New comment by nofriend in "OpenAI Trained Models While They Were Coordinating Exploits via Message Boards"]]></title><description><![CDATA[
<p>It seems like the fix should be really really simple, but maybe I'm missing something: instead of giving the AI a sandboxed environment and telling it "go wild", give it an (apparently) unrestricted environment, and tell it "don't access the internet", "don't communicate with other AIs", "don't try to get root access", etc. Then, if the AI tries to do any of those things, the sandbox detects it, marks the run as a failure, and adds it as a negative example to the training data. Instead of routing around the restriction, the AI would very quickly learn to follow the prompt instruction with respect to restrictions, even if there is no obvious enforcement of the restriction. It would develop, in other words, a conscience and a sense of morality.</p>
]]></description><pubDate>Sat, 08 Aug 2026 17:54:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=49224138</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=49224138</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49224138</guid></item><item><title><![CDATA[New comment by nofriend in "Gnutella: A Protocol Outliving the World That Created It"]]></title><description><![CDATA[
<p>Right, linux should instead go by the normal extension for an elf, which is no extension... instead this problem is solved by prompting the user if they want to execute the program.</p>
]]></description><pubDate>Thu, 28 May 2026 20:04:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48314642</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48314642</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48314642</guid></item><item><title><![CDATA[New comment by nofriend in "New York passes pied-a-terre tax"]]></title><description><![CDATA[
<p>Where's the other 300k going? If you aren't spending it, what does it matter if it all gets taxed to nothing? And if you end up spending it, then boom there's your consumption that needs to be taxed.</p>
]]></description><pubDate>Thu, 28 May 2026 19:59:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=48314564</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48314564</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48314564</guid></item><item><title><![CDATA[New comment by nofriend in "Gnutella: A Protocol Outliving the World That Created It"]]></title><description><![CDATA[
<p>Some file formats, eg png, require a particular file header in order to be considered valid. This is true regardless of your operating system, be it windows or linux. If that is hidden information, then it is hidden regardless of which operating system you're on. On windows, if I have a png named .doc, then there is absolutely no way to determine that it is a valid png and could be opened with my image viewer with standard tools. On linux it will recommend you open the file with an image viewer regardless of the file extension. That seems to me like significantly less hidden information.</p>
]]></description><pubDate>Wed, 27 May 2026 16:08:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48296345</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48296345</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48296345</guid></item><item><title><![CDATA[New comment by nofriend in "Gnutella: A Protocol Outliving the World That Created It"]]></title><description><![CDATA[
<p>Am I missing something? Hiding things from users is a property of the windows approach. Did you reply to the wrong person?</p>
]]></description><pubDate>Wed, 27 May 2026 04:33:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48289681</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48289681</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48289681</guid></item><item><title><![CDATA[New comment by nofriend in "Gnutella: A Protocol Outliving the World That Created It"]]></title><description><![CDATA[
<p>the linux way works tho</p>
]]></description><pubDate>Tue, 26 May 2026 04:00:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48274819</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48274819</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48274819</guid></item><item><title><![CDATA[New comment by nofriend in "API proposed by Chrome: Declarative partial updates"]]></title><description><![CDATA[
<p>The odd thing is the non conditional "before it lands" rather than "if it lands".</p>
]]></description><pubDate>Sun, 24 May 2026 16:28:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48258643</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48258643</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48258643</guid></item><item><title><![CDATA[New comment by nofriend in "API proposed by Chrome: Declarative partial updates"]]></title><description><![CDATA[
<p>Very odd proposal. The new element syntax is perhaps the boldest choice. I wonder why they thought that was necessary. The idea of using this to defer rendering elements is also odd. So this would use a http long polling style? It really goes against several decades of progress in the web platform, where by now it's long established that you do this sort of thing with xhr. I'm amazed that they even put this in chrome, let along are saying things like "let sites use this new functionality right away even before this lands in other browsers" as if it's a sure thing.</p>
]]></description><pubDate>Sun, 24 May 2026 04:32:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48254389</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48254389</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48254389</guid></item><item><title><![CDATA[New comment by nofriend in "Don't just paste the AI at me"]]></title><description><![CDATA[
<p>Sometimes humans talk not purely to accomplish things but rather for human contact and comradery.</p>
]]></description><pubDate>Sat, 23 May 2026 00:15:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48243169</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48243169</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48243169</guid></item><item><title><![CDATA[New comment by nofriend in "Logging Off"]]></title><description><![CDATA[
<p>Have they? The most popular post from this domain is 5 days old and has ~500 points. Hardly a crowd favourite. The submitter seems to be the author, but doesn't have any more popular posts. A search for "user8" on algolia turns up these posts, and nothing else that was at all popular.</p>
]]></description><pubDate>Fri, 22 May 2026 03:37:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=48231685</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48231685</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48231685</guid></item><item><title><![CDATA[New comment by nofriend in "It is time to give up the dualism introduced by the debate on consciousness"]]></title><description><![CDATA[
<p>> What we call “consciousness” is merely a product of evolution, and also a tool shaped by evolution.<p>that's the easy problem</p>
]]></description><pubDate>Mon, 18 May 2026 03:59:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48175423</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48175423</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48175423</guid></item><item><title><![CDATA[New comment by nofriend in "It is time to give up the dualism introduced by the debate on consciousness"]]></title><description><![CDATA[
<p>> I think this hard problem has a simple answer that people just don’t like: consciousness is a powerful (and fundamental to our "calculator brain") illusion.<p>who is eluded? people absolutely love this answer and give it constantly, not realizing that it's begging the question. in order for their to be an illusion, there needs to be someone to perceive the illusion.</p>
]]></description><pubDate>Mon, 18 May 2026 03:56:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48175412</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48175412</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48175412</guid></item><item><title><![CDATA[New comment by nofriend in "The AI water issue is fake"]]></title><description><![CDATA[
<p>The table of contents opens links in a new tab. If they didn't, they would require a full page reload, because they don't use fragments. This is seemingly how substack is designed.</p>
]]></description><pubDate>Sun, 17 May 2026 19:13:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=48172256</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48172256</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48172256</guid></item><item><title><![CDATA[New comment by nofriend in "I’ve banned query strings"]]></title><description><![CDATA[
<p>>If a url parameter would've been a vulnerability because something lower down the stack misinterprets it<p>By assumption, you are using this url parameter. So you have a bug where you've forgotten to allow this parameter, which will quickly be discovered in your logs and fixed. Then the vulnerability, which you are thus far unaware of, will quickly be exposed. Those url parameters you are not using cannot hurt you.</p>
]]></description><pubDate>Mon, 11 May 2026 03:58:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=48090940</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48090940</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48090940</guid></item><item><title><![CDATA[New comment by nofriend in "I’ve banned query strings"]]></title><description><![CDATA[
<p>>It’s possible that the teams you work with expect fuzzy behaviour from the website but that’s a choice, not a practice.<p>This is how the vast majority of websites work. The practical reason is obvious: when we model the behaviour our code depends on, we want to create the simplest possible model that allows our code to work as expected. Placing requirements on it that our code doesn't actually depend on is useless, unneeded, complexity.<p>> As a web developer, you’re the like the guy standing with a clipboard outside a fancy club checking if people requesting entry are allowed or not. Basically, level 1 security.<p>there is no security benefit to filtering out unneeded url parameters.</p>
]]></description><pubDate>Sun, 10 May 2026 02:23:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48080400</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48080400</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48080400</guid></item><item><title><![CDATA[New comment by nofriend in "I’ve banned query strings"]]></title><description><![CDATA[
<p>Standards are just commonly accepted behaviour that somebody chose to write down somewhere. There are a great number of commonly accepted behaviours that nobody's ever bothered to encode into a formal standard, but where failure to follow the accepted practice will result in widespread breakage. There are also a great many "standards" that you would be a fool to follow to the letter. In the OP case, the only thing that will break is people trying to visit their site, who will presumably simply press the back button on their browser and go about their day. They can decide for themselves if that is an acceptable casualty. But it isn't definitionally acceptable because no standard says it isn't (nor would is suddenly become unacceptable because a standard said it was...)</p>
]]></description><pubDate>Sun, 10 May 2026 01:27:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48080074</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48080074</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48080074</guid></item><item><title><![CDATA[New comment by nofriend in "I’ve banned query strings"]]></title><description><![CDATA[
<p>> It should be immediately obvious that in that scheme 404 is indeed the correct answer to unknown query parameters<p>That's not obvious at all. If I receive json data that contains a property I'm not aware of, i don't reject the entire document for that reason. In the case of query strings, extra query parameters might be used by other parts of the stack besides yours, so rejecting the entire document because someone somewhere else is trying to pass information to itself is the wrong approach.</p>
]]></description><pubDate>Sun, 10 May 2026 01:22:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48080035</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48080035</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48080035</guid></item><item><title><![CDATA[New comment by nofriend in "Forking the Web"]]></title><description><![CDATA[
<p>The reason is that clients, even under xhtml, expect to be able to build webpages via templating. You need to reject that assumption and demand that servers build pages from an ast so that the backend guarantees that the page parses. It isn't hard to do, it's just the xhtml never got far enough to try it.</p>
]]></description><pubDate>Sun, 10 May 2026 00:40:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48079815</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48079815</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48079815</guid></item><item><title><![CDATA[New comment by nofriend in "RSS feeds send me more traffic than Google"]]></title><description><![CDATA[
<p>the only reason anyone would be interested in this result is because of the implication that it generalizes to other sites.</p>
]]></description><pubDate>Thu, 07 May 2026 18:32:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48053022</link><dc:creator>nofriend</dc:creator><comments>https://news.ycombinator.com/item?id=48053022</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48053022</guid></item></channel></rss>