<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: varenc</title><link>https://news.ycombinator.com/user?id=varenc</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 17 Aug 2026 07:20:22 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=varenc" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by varenc in "Stealing Reasoning Traces from Proprietary LLM APIs"]]></title><description><![CDATA[
<p>The part about K3 is just very strong evidence that K3 is partly a distillation of Opus. Probably even a distillation of Opus's CoT, which means they already had broken CoT encryption themselves awhile ago.</p>
]]></description><pubDate>Wed, 12 Aug 2026 03:05:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=49267402</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49267402</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49267402</guid></item><item><title><![CDATA[New comment by varenc in "Stealing Reasoning Traces from Proprietary LLM APIs"]]></title><description><![CDATA[
<p>If CoT wasn't stateless and you instead just got a reference which pointed to the CoT stored on the lab servers, the same vulnerability would still exist. Since you just need a weaker jailbroken model to read a smarter model's CoT.  This being stateless or not doesn't really matter.<p>The stateless part is also important for enterprise customers that require zero data retention.<p>(they could scope CoT access per model, but then users couldn't switch models mid-session)</p>
]]></description><pubDate>Wed, 12 Aug 2026 03:03:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=49267384</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49267384</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49267384</guid></item><item><title><![CDATA[New comment by varenc in "Stealing Reasoning Traces from Proprietary LLM APIs"]]></title><description><![CDATA[
<p>This article shows that when Kimi3's chain of thought is prefilled to match Opus's, the rest of the chain of thoughts Kimi3 outputs very closely aligns with Opus's.  That seems strong evidence that Kimi3 is partly a distillation of Opus. And Kimi3 is not a small model. No doubt a lot of hard work went into Kimi, but seems clear that distillation was used effectively as well.<p>(though maybe there's another interpretation of the thought alignment?)</p>
]]></description><pubDate>Wed, 12 Aug 2026 02:56:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=49267344</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49267344</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49267344</guid></item><item><title><![CDATA[New comment by varenc in "Stealing Reasoning Traces from Proprietary LLM APIs"]]></title><description><![CDATA[
<p>By some interpretations protecting your frontier model with strong safeguards from being distilled into an open source model without safeguards is a safety issue.</p>
]]></description><pubDate>Wed, 12 Aug 2026 02:53:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=49267325</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49267325</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49267325</guid></item><item><title><![CDATA[New comment by varenc in "Stealing Reasoning Traces from Proprietary LLM APIs"]]></title><description><![CDATA[
<p>The compaction prompt doesn't seem like the valuable thing here. I suspect they're protecting the compaction result itself.  If you're trying to distill a model, collecting lots of examples on how a large conversation gets compacted to a smaller summary is particularly useful data.</p>
]]></description><pubDate>Wed, 12 Aug 2026 02:49:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=49267297</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49267297</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49267297</guid></item><item><title><![CDATA[New comment by varenc in "Stealing Reasoning Traces from Proprietary LLM APIs"]]></title><description><![CDATA[
<p>super interesting. So pre-filling Kimi3 reasoning with Opus's reasoning results in thoughts that closely match Opus's.  This seems like strong evidence Kimi3 was trained on decrypted Opus chain-of-thought. Meaning the Kimi team likely also broke CoT encryption. Though not exactly a big surprise.</p>
]]></description><pubDate>Wed, 12 Aug 2026 02:42:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=49267260</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49267260</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49267260</guid></item><item><title><![CDATA[New comment by varenc in "OpenAI’s head of ethics leaves less than a year after joining"]]></title><description><![CDATA[
<p>HuggingFace's use of models in this incident keeps getting characterized this way but it's not true that HG used GLM-5.2 to "save them" from OAI's attack.  OAI's model had already hacked and compromised HG by the time they became aware of it. GLM-5.2 was used in the post-mortem phase uncovering everything that was done. It wasn't two models battling each other live. (though that future may be coming soon)</p>
]]></description><pubDate>Tue, 11 Aug 2026 16:02:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49260368</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49260368</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49260368</guid></item><item><title><![CDATA[New comment by varenc in "The AI Billboards Are Killing SF"]]></title><description><![CDATA[
<p>There's been a moratorium on new billboards in SF for a long time already. No new ones are getting built. Given the reliable revenue they provide, will be a long time before they naturally go extinct.</p>
]]></description><pubDate>Fri, 07 Aug 2026 17:06:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49213391</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49213391</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49213391</guid></item><item><title><![CDATA[New comment by varenc in "Web Security is Too Hard"]]></title><description><![CDATA[
<p>hah thanks for the deep dive on this. I wanted to investigate myself but figured someone on HN would be faster at it.  Makes sense it's not helpful, alas.</p>
]]></description><pubDate>Fri, 07 Aug 2026 16:56:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49213256</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49213256</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49213256</guid></item><item><title><![CDATA[New comment by varenc in "A year of fighting scrapers on my 1.5 million-page website"]]></title><description><![CDATA[
<p>Can someone help me understand the underlying motivation behind this?<p>It makes sense that some crawlers, in the style of Google, would want to index the entire internet. But what is the point of the <i>same</i> crawler re-fetching a page they already fetched an hour ago?  Or possibly all this traffic is just independent entities, each trying to cache the internet? The scale of bot traffic makes this seem unlikely.<p>What's the motivation behind the same entity re-fetching a page it just fetched less than an hour ago?</p>
]]></description><pubDate>Fri, 07 Aug 2026 16:01:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=49212486</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49212486</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49212486</guid></item><item><title><![CDATA[New comment by varenc in "Americans are rallying against data centers. Surprisingly few are getting built"]]></title><description><![CDATA[
<p>Theres always going to be some negative externality effecting people that live near anything getting built. Even if the operational data center isn't loud enough to be heard beyond its property lines, the construction process will be louder. I'll also negatively effect peoples views and cause generally increased activity in the area.<p>But that all seems fine as long as not egregious. But for anything to get built, housing or data centers or what not, we have to accept that those right next to any building project will experience some negative externalities.</p>
]]></description><pubDate>Thu, 06 Aug 2026 16:35:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=49198992</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49198992</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49198992</guid></item><item><title><![CDATA[New comment by varenc in "Hackerne.ws Cert Needs Updating"]]></title><description><![CDATA[
<p>likely because your browser is enforcing that you always go to the HTTPS URL.  Your link above works fine for me.</p>
]]></description><pubDate>Thu, 06 Aug 2026 16:30:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=49198932</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49198932</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49198932</guid></item><item><title><![CDATA[New comment by varenc in "Hackerne.ws Cert Needs Updating"]]></title><description><![CDATA[
<p>it's not serving HTTPS at all, it's HTTP only. Port 80 is open, port 443 isn't.</p>
]]></description><pubDate>Wed, 05 Aug 2026 03:10:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=49178150</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49178150</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49178150</guid></item><item><title><![CDATA[New comment by varenc in "Web Security is Too Hard"]]></title><description><![CDATA[
<p>Cosmically I feel like the HTTPS certificate on Cloudflare.pay should provide sufficient info to confirm it's the same entity behind Cloudflare.com</p>
]]></description><pubDate>Tue, 04 Aug 2026 22:22:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=49176043</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49176043</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49176043</guid></item><item><title><![CDATA[New comment by varenc in "Waymo in Dallas"]]></title><description><![CDATA[
<p>It handles these circumstances. Definitely seen it cross to the other side with oncoming traffic to get around a truck blocking a lane. For the signal light, never experienced that, but I imagine after awhile it'd figure it out. Possibly with the assistance of a remote human telling it.</p>
]]></description><pubDate>Tue, 04 Aug 2026 22:05:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=49175876</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49175876</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49175876</guid></item><item><title><![CDATA[New comment by varenc in "AI poster wins Ohio State Fair contest"]]></title><description><![CDATA[
<p>The poster: <a href="https://cdn.saffire.com/images.ashx?t=ig&rid=OhioStateFair&i=Grand_Champion_Entry_-_Christin_Billips.png&cb=973a00a9" rel="nofollow">https://cdn.saffire.com/images.ashx?t=ig&rid=OhioStateFair&i...</a><p>Note the pigs are numbered 1, 2, 1. And the gondola with a floating cable and another that terminates at a tent top.</p>
]]></description><pubDate>Sun, 02 Aug 2026 23:38:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49149514</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49149514</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49149514</guid></item><item><title><![CDATA[New comment by varenc in "Codex Security"]]></title><description><![CDATA[
<p>It's interesting how much of the value here is providing the english Skill definitions that tell the LLM what to do: <a href="https://github.com/openai/codex-security/tree/main/sdk/typescript/_bundled_plugin/skills" rel="nofollow">https://github.com/openai/codex-security/tree/main/sdk/types...</a><p>Some of approaches there could be useful in other contexts. OAI has the compute to experiment with different prompts and I'd expect these to be somewhat optimized.</p>
]]></description><pubDate>Tue, 28 Jul 2026 23:03:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49091188</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49091188</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49091188</guid></item><item><title><![CDATA[New comment by varenc in "Our position on open-weights models"]]></title><description><![CDATA[
<p>You're ignoring the asymmetry with security. The attacker just needs one exploit chain, whereas the defender needs to block every avenue.  Open access to models with no guardrails greatly benefits the attackers more than the defenders.<p>Imagine what a god-level hacking AI could do.  It could find a full 0-click to root exploit chain in iOS.  Attacker unleashes a worm that infects a phone, instructs that phone to send the same attack to all of its contacts, and then physically destroy the phone by turning off all thermal throttling. Might even be possible to make it catch fire.<p>Or find a remote exploit in Tesla cars and make their autopilot go on murdering rampages. (that one is from a movie)</p>
]]></description><pubDate>Tue, 28 Jul 2026 03:55:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=49079141</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49079141</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49079141</guid></item><item><title><![CDATA[New comment by varenc in "OpenAI’s accidental attack against Hugging Face is science fiction that happened"]]></title><description><![CDATA[
<p>the '<i>that happened</i>' makes it too long for the HN submission title length limit.<p>Maybe simonw can suggest an alternative title that fits within the limit, that doesn't misrepresent the post.</p>
]]></description><pubDate>Thu, 23 Jul 2026 03:14:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=49016441</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=49016441</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49016441</guid></item><item><title><![CDATA[New comment by varenc in "Claude Is Not a Compiler"]]></title><description><![CDATA[
<p>Agreed. Big love for exe.dev.  For quick low stakes projects, using their Shelly assistant is the simplest way to give an LLM a fully persistent VM with web services I've found.</p>
]]></description><pubDate>Tue, 21 Jul 2026 15:49:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=48993927</link><dc:creator>varenc</dc:creator><comments>https://news.ycombinator.com/item?id=48993927</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48993927</guid></item></channel></rss>