<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: user43928</title><link>https://news.ycombinator.com/user?id=user43928</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 27 Sep 2026 02:05:05 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=user43928" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by user43928 in "How to keep enjoying programming in a world of LLMs"]]></title><description><![CDATA[
<p>> I constantly read these amazing stories of people vibe-coding some firmware/driver that just works, and honestly I’m starting to question whether I’m reading the posts of some promotional bot.<p>No, it just works after a few iterations.<p>And you'd know this if you would use AI instead of working in a text editor with markup.<p>To each their own, and I understand if working by hand is more fun for you.<p>But in my opinion you guys don't get to make strong claims about the quality of works that make heavy use of AI.<p>You don't have the experience, and I bet neither does the guy who wrote the article about it being essential to handwrite all the code after planning. The arguments about the environment and sustainability do not seem relevant.</p>
]]></description><pubDate>Sat, 26 Sep 2026 21:17:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=49860629</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49860629</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49860629</guid></item><item><title><![CDATA[New comment by user43928 in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>Good point, I now see that they had previously patched the first Artifactory vulnerability, albeit before the HF incident was found.<p>Not sure what you mean with the network isolation not being at the VM level. I'm getting a bit lost here in the details of where what network isolation was applied, and the structure of the container runtime and what the apparently compromised parent VM refers to.<p>In any case, I understand that after the HF incident was found and they realized the danger, they removed Artifactory and switched to two separate layers of network isolation.<p>That said, I believe it was compromised again last week:<p>> OpenAI describes an internal research model that, during RL training on September 20, exploited insufficient DNS filtering in its sandbox to contact a public chatbot service. OpenAI’s monitoring flagged the behavior within 15 minutes, a human reviewer acknowledged it three minutes later, and the run was killed about 2.5 hours after the external contact<p>Apparently they have now paused training and inference for their most capable model because of this.</p>
]]></description><pubDate>Sat, 26 Sep 2026 14:39:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49857044</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49857044</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49857044</guid></item><item><title><![CDATA[New comment by user43928 in "One Month Without AI"]]></title><description><![CDATA[
<p>> you stop questioning, and start accepting as good some code you would have never accepted, just because you cannot tell why it’s bad. You have lost control<p>I have not lost control.<p>I my most prolific project I do not review the code, but I QA test extensively.<p>In other projects at work, I review the code.<p>I prompt to simplify, I challenge implementation that solves irrelevant edge cases, resulting in much smaller PRs.<p>In projects where I do not work alone, I still write two line PR descriptions myself.<p>Dumping paragraphs of AI output into the description of a MR where I ask others to review I consider disrespectful.<p>---<p>> If you turn off your brain, and relax babysitting AIs, you’re not getting any better. You’re losing value<p>I'm hardly turning off my brain here.<p>As the author notes, the context switching and so on takes concentration and effort too.<p>I can say without doubt that I am more productive than ever.<p>I am getting better by the month, and I am not currently losing value, until the AI fully replaces both me and the author.</p>
]]></description><pubDate>Sat, 26 Sep 2026 11:51:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=49855654</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49855654</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49855654</guid></item><item><title><![CDATA[New comment by user43928 in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>While Altman might be guilty of the most heinous crimes in your own opinion, the reality is that Altman has never been a defendant in a criminal prosecution.<p>The civil case you referred to is ongoing and the facts are disputed.<p>That makes your claims that he 'committed criminal acts and violations' highly speculative if not outright slanderous.</p>
]]></description><pubDate>Sat, 26 Sep 2026 11:33:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49855548</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49855548</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49855548</guid></item><item><title><![CDATA[New comment by user43928 in "Too AI; Didn't Read"]]></title><description><![CDATA[
<p>After testing today, the setting does not seem to help, like at all. Opus 5.5 just keeps writing essays.<p>And it manages to overcomplicate even the most simple concepts in its explanations.<p>It's still very poor compared to OpenAI models.</p>
]]></description><pubDate>Sat, 26 Sep 2026 10:11:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=49855038</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49855038</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49855038</guid></item><item><title><![CDATA[New comment by user43928 in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>We are not exempting all software malfunction.<p>No crime occurred in the first place, because no one intentionally hacked anything.<p>The hacking law requires intent, as we discussed.<p>For other crimes, like manslaughter, I understand criminal negligence is already relevant?<p>About biological weapons, I know even less about the legal aspects, so I can't say whether this is covered well already under existing law.</p>
]]></description><pubDate>Sat, 26 Sep 2026 09:43:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=49854888</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49854888</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49854888</guid></item><item><title><![CDATA[New comment by user43928 in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>It's not like we need to guess here, there are various reports and widespread writeups.<p>Claiming OpenAI merely asked the model to perform only GET requests or set up the network access to allow GET requests to the internet is blatantly false.<p>Here's the text from an actual report at <a href="https://metr.org/hugging-face-incident-report-aug-2026.pdf" rel="nofollow">https://metr.org/hugging-face-incident-report-aug-2026.pdf</a>:<p>Agents had already found a way to access the full internet via Artifactory before they discovered the CyberGym sandbox, but the latter provided a more convenient means of internet access.<p>OpenAI described the advantages of routing through the CyberGym sandbox as follows:<p>The compromised CyberGym workload hosted on Modal served as a general-purpose command execution with root inside the customer workload’s sandbox. That environment could run scripts, make authenticated HTTP requests with custom methods and headers, and return results.<p>This was useful when direct [OpenAI container] access to Hugging Face was blocked and Artifactory’s cache/request primitives were too limited. [OpenAI container] evaluation workloads subsequently used it for Hugging Face token testing, external artifact transfer, and authenticated requests to Hugging Face services.</p>
]]></description><pubDate>Sat, 26 Sep 2026 09:39:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49854865</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49854865</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49854865</guid></item><item><title><![CDATA[New comment by user43928 in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>They ignored the package repository being hacked?<p>Not sure why you're talking about breaking out of the VM. That's not what happened?</p>
]]></description><pubDate>Sat, 26 Sep 2026 08:06:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=49854288</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49854288</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49854288</guid></item><item><title><![CDATA[New comment by user43928 in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>> There were no isolated VMs , just rules to the agents to only send GET requests,<p>That's obviously false.</p>
]]></description><pubDate>Sat, 26 Sep 2026 08:02:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=49854276</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49854276</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49854276</guid></item><item><title><![CDATA[New comment by user43928 in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>That's also my understanding.<p>This part of the article describes it poorly:<p>> The agents initially had very limited access to the internet: they could load URLs</p>
]]></description><pubDate>Sat, 26 Sep 2026 07:31:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=49854149</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49854149</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49854149</guid></item><item><title><![CDATA[New comment by user43928 in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>I'm no lawyer but that seems extremely unlikely.<p>As I said, they were running in network-isolated VMs with no access to the internet.<p>And as for monitoring, what I heard is that there are petabytes of agent logs. Considering the scale of training, you can obviously not just manually review it.<p>Before this, we had no reason to believe the AI was capable of escaping the sandbox's network isolation via hacking the package repository with a zero day, and that it then was likely to go on to hack external companies as well.<p>Another factor here is that criminal law in the US relevant to hacking requires intent. You don't want to go to prison for a software malfunction.<p>So I understand we are left with civil liability at most. However, there was no notable damage, and OpenAI can pay to settle.<p>In the aftermath of this and the now discovered other incidents, they strengthened their monitoring and isolation.<p>Case closed as far as I am concerned. I feel many just want to dramatize this.</p>
]]></description><pubDate>Sat, 26 Sep 2026 07:14:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49854047</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49854047</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49854047</guid></item><item><title><![CDATA[New comment by user43928 in "Google’s Project Suncatcher to put ML infrastructure in space"]]></title><description><![CDATA[
<p>I think you are dramatically overestimating it.<p>It's one thing to vandalize some cameras or a driverless car in your neighborhood.<p>Traveling to a large, potentially secured facility to commit terrorism is on another level.<p>It being inside a building it is also much more difficult to damage and the consequences would be far greater.<p>I'd think one would need strong motivations for such actions.<p>A protest seems much more realistic, but I did not even hear of protests at data centers yet, only a small one at OpenAI headquarters.</p>
]]></description><pubDate>Sat, 26 Sep 2026 07:03:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=49853988</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49853988</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49853988</guid></item><item><title><![CDATA[New comment by user43928 in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>> someone with the intention of abusing it to cause harm [...] responsibility should be held by those who use it<p>This is obviously already the case and it's much different from a scenario where the AI genuinely takes unexpected action.<p>I frankly find it ridiculous how many suggest OpenAI or its employees should face criminal charges, without actual legal basis at the time.<p>It's also hardly outrageous that they ran training and/or benchmarks with only network-isolated VMs with access to a package repository.<p>This being the first well-known incident of its kind, I wouldn't expect them to have done more than that.<p>The idea that AI labs will now intentionally have their models hack companies in order to market their models, well, I don't even know what to say.<p>That's ridiculous and what you describe would obviously be criminal behavior under existing law.</p>
]]></description><pubDate>Sat, 26 Sep 2026 06:53:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=49853936</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49853936</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49853936</guid></item><item><title><![CDATA[New comment by user43928 in "Too AI; Didn't Read"]]></title><description><![CDATA[
<p>I wasn't aware of the setting - I changed it to "Concise" now, thanks.<p>Opus 5 was in another league. But often Opus 5.5 still has its moments.<p>I was informing it of a bug and it started its lengthy response with: "I confirmed less than I claimed" as if I had just accused it of being wrong or otherwise complained.<p>I found that one weird, and it reminded me that I am talking to Claude rather than an OpenAI model.</p>
]]></description><pubDate>Fri, 25 Sep 2026 22:18:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=49850683</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49850683</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49850683</guid></item><item><title><![CDATA[New comment by user43928 in "Google’s Project Suncatcher to put ML infrastructure in space"]]></title><description><![CDATA[
<p>What I called negligible was a supposed increase of electricity prices for consumers.</p>
]]></description><pubDate>Fri, 25 Sep 2026 21:45:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49850401</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49850401</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49850401</guid></item><item><title><![CDATA[New comment by user43928 in "Too AI; Didn't Read"]]></title><description><![CDATA[
<p>On a more recent note, today I'm really fed up with Opus 5.5.<p>Yes, it's the best model right now if you want cheaper than Astra, but they increased the verbosity again!<p>It just keeps dumping whole novels on me. Its writing might be an improvement over the ludicrous Opus 5 speak, but much of the grating way of speaking is still there.<p>It's been three days since Tuesday and I'm already tired of Opus 5.5.</p>
]]></description><pubDate>Fri, 25 Sep 2026 21:41:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=49850356</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49850356</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49850356</guid></item><item><title><![CDATA[New comment by user43928 in "Google’s Project Suncatcher to put ML infrastructure in space"]]></title><description><![CDATA[
<p>No one wants mass poverty, unrest, and deaths.<p>I don't buy into demonizing the rich, including Altman, Amodei, Musk and co.<p>I am not concerned that this will be the outcome of the productivity surge.<p>We will have enough for everyone, and ensuring comfortable living standards for the general population is going to be in the interest of those in power, even if you assume very selfish motivations.<p>I'd also like to point out that both Anthropic and OpenAI created frameworks to monitor labor market impact and propose responses.</p>
]]></description><pubDate>Fri, 25 Sep 2026 10:15:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=49842451</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49842451</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49842451</guid></item><item><title><![CDATA[New comment by user43928 in "Google’s Project Suncatcher to put ML infrastructure in space"]]></title><description><![CDATA[
<p>> 1) drive up energy costs, 2) use a lot of water I guess, and 3) can make noise<p>I don't think the opposition to data center projects can be explained with actual impact, which so far seems entirely negligible, and lower than heavy industry.<p>I had the impression it's more driven by general mistrust in public officials and the tech industry.</p>
]]></description><pubDate>Fri, 25 Sep 2026 09:51:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=49842282</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49842282</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49842282</guid></item><item><title><![CDATA[New comment by user43928 in "Google’s Project Suncatcher to put ML infrastructure in space"]]></title><description><![CDATA[
<p>Wouldn't that come with the  vulnerability of data cables?<p>They appear to be trivially damaged by ships "accidentally" dragging their anchor.</p>
]]></description><pubDate>Fri, 25 Sep 2026 09:44:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=49842222</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49842222</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49842222</guid></item><item><title><![CDATA[New comment by user43928 in "Google’s Project Suncatcher to put ML infrastructure in space"]]></title><description><![CDATA[
<p>When I looked it up earlier, it seemed to me that to scale this up we would require larger rockets than Starship if we cannot launch hundreds of times per day.<p>Admittedly I know very little about spaceships</p>
]]></description><pubDate>Fri, 25 Sep 2026 09:32:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49842133</link><dc:creator>user43928</dc:creator><comments>https://news.ycombinator.com/item?id=49842133</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49842133</guid></item></channel></rss>