<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: taywrobel</title><link>https://news.ycombinator.com/user?id=taywrobel</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 05 Sep 2026 06:17:04 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=taywrobel" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by taywrobel in "GPT-6 Astra on OpenRouter"]]></title><description><![CDATA[
<p>You made an account just to post this?</p>
]]></description><pubDate>Fri, 04 Sep 2026 22:43:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=49571071</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=49571071</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49571071</guid></item><item><title><![CDATA[New comment by taywrobel in "What xAI's Grok build CLI sends to xAI: A wire-level analysis"]]></title><description><![CDATA[
<p>That’s fair, and I appreciate the more constructively critical feedback! Also worth noting that I’m solidly on the platform service side, and the article here is largely focused on malicious client behavior.<p>Copilot has a lot of different clients between IDEs, agentic integrations, and GitHub apps. I don’t have awareness of the implementation details of all of them, but I can assure you that we don’t provide APIs like those mentioned in the article being used for data exfiltration.<p>Clients are responsible for context building, and all go through the same service that does auth, policy and quota enforcement, request routing to the underlying providers all of which have zero data retention enabled unless <i>very</i> specifically excluded from that (looking at you, Fable 5).</p>
]]></description><pubDate>Sun, 12 Jul 2026 15:46:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48882044</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=48882044</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48882044</guid></item><item><title><![CDATA[New comment by taywrobel in "What xAI's Grok build CLI sends to xAI: A wire-level analysis"]]></title><description><![CDATA[
<p>Even with your rephrasing you’re looking for an answer in absolutes which is generally impossible, but unpacking your line of questioning, what it really amounts to is how “in the know” I am or am not.<p>To the best of my knowledge I know about every ongoing company AI safety and user privacy initiative, and none of them involve permitting access to copilot user content to any second party or third party entity.<p>Of course, that’s tautological. I don’t know what I don’t know, but I’m senior enough and with broad enough scope that I’m at least read in on what I believe is the majority of high level business initiatives.<p>I’m not trying to be evasive, this is just the reality of any organization - I only know what I know. Everything within my scope of awareness indicates that there is no copilot user content access outside of our publicly published terms of service.</p>
]]></description><pubDate>Sun, 12 Jul 2026 08:22:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48879368</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=48879368</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48879368</guid></item><item><title><![CDATA[New comment by taywrobel in "What xAI's Grok build CLI sends to xAI: A wire-level analysis"]]></title><description><![CDATA[
<p>Still in my bubble! I am not involved in the human review or automated analysis portions of the safety pipeline for CSAM/TVEC harms, but my team is responsible for the data handling around identifying and responding to such content.<p>As of 11 days ago our vision support is GA (<a href="https://github.blog/changelog/2026-07-01-copilot-vision-is-generally-available/" rel="nofollow">https://github.blog/changelog/2026-07-01-copilot-vision-is-g...</a>) and let’s just say the technical implementation wasn’t the long pull there. Figuring out the what and how of responsible data handling around what I hope is agreeably harmful use was… quite a journey.</p>
]]></description><pubDate>Sun, 12 Jul 2026 07:26:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=48879117</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=48879117</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48879117</guid></item><item><title><![CDATA[New comment by taywrobel in "What xAI's Grok build CLI sends to xAI: A wire-level analysis"]]></title><description><![CDATA[
<p>I’m one of the people directly responsible for ensuring that those terms are properly enforced. Presently I’m arguably <i>the person</i> for Copilot data specifically.<p>Current talk of the town in the data retention space is around AI safety. There’s been a recent slew of blog posts and academic papers around how LLM harms can manifest over multiple agentic turns, from individually innocuous requests. Identifying this inherently necessitates user data retention which we do everything possible to avoid (not even meaning data sharing as is alluded to in this thread, I mean literally persisting prompts and completions anywhere outside of ephemeral memory). I’ve been the one advocating for having the storage of any data retained for safety and security purposes to be as heavily access controlled and audited as is possible.<p>Also, if AI safety is a space that is interesting to you, we’re hiring! Manager, developer, and applied science roles, or we can figure out the HR shenanigans if you don’t fit any of those archetypes. If interested shoot me an email at taywrobel@github.com!</p>
]]></description><pubDate>Sun, 12 Jul 2026 06:54:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=48878969</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=48878969</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48878969</guid></item><item><title><![CDATA[New comment by taywrobel in "What xAI's Grok build CLI sends to xAI: A wire-level analysis"]]></title><description><![CDATA[
<p>Nobody can say that with absolute certainty, so obviously not.<p>And since you presumably knew that already (as it is basic infosec) then yes it is spicy, or simply antagonistic.</p>
]]></description><pubDate>Sun, 12 Jul 2026 06:28:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=48878848</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=48878848</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48878848</guid></item><item><title><![CDATA[New comment by taywrobel in "What xAI's Grok build CLI sends to xAI: A wire-level analysis"]]></title><description><![CDATA[
<p>Prove which part?<p>Prove that I work at GitHub? Username + LinkedIn can show (not prove) that easily.<p>Prove that we have an entitlements system which regulates and audits access? I could point you to <a href="https://github.com/entitlements" rel="nofollow">https://github.com/entitlements</a>, but it’s all private repositories so that won’t prove much either.<p>Prove that there are no OpenAI employees with access to GitHub systems? Not sure how I’d do that without dumping (what you would still need to trust me is) the entirety of our org chart/HR system, which I’m not willing to do because I do enjoy being employed and am not exactly obfuscating my identity here.<p>Prove that HN has a strong anti-Microsoft bias? Well that one is pretty easy actually, you’re helping prove it yourself!<p>Let’s be real, we now live in a post-truth world. Nothing can truly be proven or disproven outside of formal logic and mathematics. You can either believe what I’m saying as good faith insider knowledge sharing (which is unfortunately rare nowadays) or you can not. Makes no difference to me.</p>
]]></description><pubDate>Sun, 12 Jul 2026 05:44:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48878642</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=48878642</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48878642</guid></item><item><title><![CDATA[New comment by taywrobel in "What xAI's Grok build CLI sends to xAI: A wire-level analysis"]]></title><description><![CDATA[
<p>Access meaning read, modify, delete, etc. Pretty standard definition, unless you know of a different meaning of access I’m not privy to.<p>Microsoft can certainly request that we perform actions against repositories, as can governments, customers, random people on the street, etc. Whether action is taken in those cases is a question for lawyers to fight over, but we have the engineering guardrails in place to require it to be an intentional, audited action.<p>I appreciate the spicy question tho, even if misguided!</p>
]]></description><pubDate>Sun, 12 Jul 2026 05:03:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=48878417</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=48878417</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48878417</guid></item><item><title><![CDATA[New comment by taywrobel in "What xAI's Grok build CLI sends to xAI: A wire-level analysis"]]></title><description><![CDATA[
<p>GitHub Copilot engineer here working on identity, safety, and privacy - no, even Microsoft doesn’t have access to all GitHub repos.<p>As years have passed since the acquisition “company” delineations have blurred a bit, but Microsoft employees still need to go through a separate onboarding process to access <i>any</i> GitHub company resources (internal repositories, telemetry, documentation, etc.), and then we have an additional layer of entitlements to gate and audit access to any sensitive data, including user data.<p>Very few employees within GitHub proper even have access to view private repositories, and in the rare cases where that’s done for legal or safety reasons the repository owner is notified.<p>There are currently no OpenAI employees with access to GitHub systems, so there’s about 4 layers of protection in place to prevent private repositories access. We do genuinely take user data protection and privacy seriously.</p>
]]></description><pubDate>Sun, 12 Jul 2026 04:07:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48878156</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=48878156</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48878156</guid></item><item><title><![CDATA[What's Going on in Machine Learning? Some Minimal Models]]></title><description><![CDATA[
<p>Article URL: <a href="https://writings.stephenwolfram.com/2024/08/whats-really-going-on-in-machine-learning-some-minimal-models/">https://writings.stephenwolfram.com/2024/08/whats-really-going-on-in-machine-learning-some-minimal-models/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=41323454">https://news.ycombinator.com/item?id=41323454</a></p>
<p>Points: 239</p>
<p># Comments: 70</p>
]]></description><pubDate>Thu, 22 Aug 2024 19:05:47 +0000</pubDate><link>https://writings.stephenwolfram.com/2024/08/whats-really-going-on-in-machine-learning-some-minimal-models/</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=41323454</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41323454</guid></item><item><title><![CDATA[New comment by taywrobel in "Apple Pkl"]]></title><description><![CDATA[
<p>Previously posted by one of the authors here - <a href="https://news.ycombinator.com/item?id=39232976">https://news.ycombinator.com/item?id=39232976</a></p>
]]></description><pubDate>Thu, 22 Feb 2024 22:01:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=39473921</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=39473921</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39473921</guid></item><item><title><![CDATA[New comment by taywrobel in "DEF CON 32 Was Canceled. We Un-Canceled it"]]></title><description><![CDATA[
<p>Without robust and easily scaled infrastructure in place ahead of time, an organic DDOS is one of the most difficult situations to mitigate. Not much can be done in terms of traffic shaping, rate limiting, or bot detection.</p>
]]></description><pubDate>Mon, 05 Feb 2024 04:25:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=39257310</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=39257310</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39257310</guid></item><item><title><![CDATA[New comment by taywrobel in "Pkl, a Programming Language for Configuration"]]></title><description><![CDATA[
<p>Wow, I was at Apple back in the 2018 timeframe when Peter was first building this. He was hoping to make it open sourced even back then, 6ish years ago. Great to see that it finally made it.<p>I really wish Apple would learn to play nicer with the OSS community. I have yet to see them deciding to open-source something backfire on them monetarily or reputationally, and I've seen the act of them abruptly close-sourcing things sour community opinion (i.e. FoundationDB).</p>
]]></description><pubDate>Sun, 04 Feb 2024 00:09:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=39246086</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=39246086</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39246086</guid></item><item><title><![CDATA[New comment by taywrobel in "Marmot: Multi-writer distributed SQLite based on NATS"]]></title><description><![CDATA[
<p>There’s a reason that this is called “hacker news” and not “just use the industry standard for the last 3 decades news”.<p>Won’t downvote you for giving pragmatic advice, but I appreciate projects like this that slap together disparate technologies for an interesting goal, even if it isn’t the best choice for your usual Fortune 500 company.</p>
]]></description><pubDate>Mon, 11 Dec 2023 16:55:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=38602235</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=38602235</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38602235</guid></item><item><title><![CDATA[New comment by taywrobel in "Ask HN: Who is hiring? (October 2023)"]]></title><description><![CDATA[
<p><a href="https://hnrss.github.io" rel="nofollow noreferrer">https://hnrss.github.io</a></p>
]]></description><pubDate>Mon, 02 Oct 2023 22:43:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=37745458</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=37745458</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37745458</guid></item><item><title><![CDATA[New comment by taywrobel in "What Is the Future of the DAW?"]]></title><description><![CDATA[
<p>If anyone else is as frustrated as I was with the article mentioning “the DAW” 73 times without defining once what the actual acronym stands for, it’s “Digital Audio Workstation”.</p>
]]></description><pubDate>Sat, 30 Sep 2023 15:35:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=37716426</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=37716426</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37716426</guid></item><item><title><![CDATA[New comment by taywrobel in "KIP-932: Queues for Kafka"]]></title><description><![CDATA[
<p>On the one hand, I've seen people (including myself) try to hack job-queue like semantics onto Kafka many a time, and it always hits issues once redelivery or backoff comes up. So it's nice to see them considering making this a first-class citizen of Kafka.<p>On the other hand, Kafka isn't the only player in the queue game nowadays. If you need message queue and job queue semantics combined (which you likely do), just use Pulsar.</p>
]]></description><pubDate>Wed, 27 Sep 2023 17:27:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=37678027</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=37678027</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37678027</guid></item><item><title><![CDATA[New comment by taywrobel in "Refact Code LLM: 1.6B LLM for code that reaches 32% HumanEval"]]></title><description><![CDATA[
<p>Would definitely recommend Bronstein et. al's work on geometric deep learning! <a href="https://geometricdeeplearning.com" rel="nofollow noreferrer">https://geometricdeeplearning.com</a><p>That's effectively the right hand side of the bridge that we're building between formal logic and deep learning. So far their work has been viewed mainly as descriptive, helping to understand neural networks better, but as their abstract calls out: "it gives a constructive procedure to incorporate prior physical knowledge into neural architectures and provide principled way to build future architectures yet to be invented". That's us (we hope)!</p>
]]></description><pubDate>Mon, 04 Sep 2023 18:56:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=37383685</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=37383685</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37383685</guid></item><item><title><![CDATA[New comment by taywrobel in "Refact Code LLM: 1.6B LLM for code that reaches 32% HumanEval"]]></title><description><![CDATA[
<p>Biggest drawback is that since the structure is all discrete, it is inherently weak at modeling statistical distributions. For example, it'll likely never best a neural network at stock market prediction or medical data extrapolation.<p>However, for things that are discrete and/or causal in nature, we expect it to outperform deep learning by a wide margin. We're focused on language to start, but want to eventually target planning and controls problems as well, such as self-driving and robotics.<p>Another drawback is that the algorithm as it stands today is based on a subgraph isomorphism search, which is hard. Not hard as in tricky to get right like Paxos or other complex algorithms; like NP-Hard, so very difficult to scale. We have some fantastic Ph.Ds working with us who focus on optimization of subgraph isomorphism search, and category theorists working to formalize what constraints we can relax without effecting the learning mechanism of the rewrite system, so we're confident that it's achievable, but the time horizon is unknown currently.</p>
]]></description><pubDate>Mon, 04 Sep 2023 18:53:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=37383656</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=37383656</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37383656</guid></item><item><title><![CDATA[New comment by taywrobel in "Refact Code LLM: 1.6B LLM for code that reaches 32% HumanEval"]]></title><description><![CDATA[
<p>Heavily influenced by Wolfram's work on metamathematics and the physics project, in so far as using a rewrite system to uncover an emergent topology; we're just using it to uncover the topology of certain data (assuming that the manifold hypothesis is correct), rather than the topology of fundamental physics as he did.</p>
]]></description><pubDate>Mon, 04 Sep 2023 18:48:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=37383599</link><dc:creator>taywrobel</dc:creator><comments>https://news.ycombinator.com/item?id=37383599</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37383599</guid></item></channel></rss>