Hacker Newsnew | past | comments | ask | show | jobs | submit | jerf's commentslogin

There's a number of science fiction scenarios where the public internet becomes so vile a place that it simply becomes unsafe to be there.

The problem is that, in general, if you can get a bit from here to there, then you're going to be vulnerable to the possibilities of malicious communication. But we're going to want our AI agents to be able to get from here to there for a lot of "there"s; what's the value of an agent that can't speak to anyone? Much, much less than one locked away in a prison.

There isn't going to be a solution where we just lock them away and we just try really, really hard to filter everything they're doing. They're too smart for that already and we only want them smarter.

Basically, the security apocalypse we've been worried about for so long is upon us, albeit only beginning. Either we secure ourselves and all our services properly to the point that it's OK that potentially misaligned non-human agents are running around on the public internet and they still can't hurt us through our security, or the public internet becomes so dangerous that the only practical solution is to no longer connect to it and we all have to become very, very careful what we let through, to a degree of detail far beyond any current-day available network filter.


Same as any organism, you need an immune system. There's an explosion of bacteria just beginning out there. None of us are immunized.

The problem is that people that put the agents on the net are not the ones that will feel the consequences.

https://www.bleepingcomputer.com/news/security/malicious-ai-...

Excellent example of agent enabled hacking (driven by a person) leading to massive numbers of cards stolen.

Welcome to Cyberpunk, only blackwall is the fictional part and the demon filled net is not.


Wasn't the public internet an extremely vile place couple of decades ago? I think we will need a LOT of new infrastructure akin to traditional firewalls and spam filters. I don't think we know how to build those today, but seems like an important research direction, rather than calling calling it doomsday IMO.

What you can not give up owns you.

If you are fine with that, fine.

If this post bothers you and you feel the need to defend yourself against it or something, realize I'm not the one making it true. Nothing you say to me can change this.


Every year it gets more and more important to learn how to not be sucked in by a small amount of convenience. "Capitalism" has figured out how to abuse your desire for maximum convenience. You need to figure out what your price is for it, and stick to it like glue.

The funny thing is the sooner you get off of some particular convenience treadmill the easier it is to stay off.


The funny thing is, it may be less convenient but it's also more enjoyable.

Endlessly scrolling some algorithmic feed hunting for something to watch can be done without getting off the couch, but it isn't actually fun. Walking to the library with my family to return a stack of books and movies and check out some new stuff is one of the highlights of our weekend.

For anyone who's wondering where to start, I'd like to suggest that your library probably has a copy of WALL-E.


There were games being written in days where every byte was precious, and the indirection necessary for something like the decorator pattern was just infeasible. There was a lot of direct stat manipulation upon equip & unequip back in the day.

Following that there was the era in which the only way to be competitive in the games space was to write in assembler directly, which would be my guess for how the bug you described happened, since a more sophisticated algorithm should probably have fit just fine by the time we're in the color Mac era but it would have been more painful to write, and nobody has any time for that. Lots of bizarre shortcuts were taken in this era. Some of the posts from Raymond Chen about Windows providing backwards compatibility for games of this era give an idea of the situation, which are related to how the games interacted with the OS rather than with game mechanics but it's a similar process.

Finally, games have this perverse effect going on where if you write down a bunch of effects you want things in your game to have ("armor can add % bonuses to this part of the strike calculation", etc.), it creates a set of boundaries within which the game's systems can function, and the ironic effect of the creation of those boundaries is to immediately bring to mind ways of violating those boundaries and demands from the designers to do so. These violations of the boundaries will tend to be buggy.


I've had some success writing certain explicitly technical documents, with a style guide provided to the LLM that it can match, and then going over it by basically iterating on every sentence in the document and asking "can this sentence be removed?".

Style guides are a big tools people are missing out on. It isn't enough to say "write concisely and technically". Give them a sample. Yea verily these many 5 or 6 years ago, "style transfer" was a big thing that early LLM tech was doing. It's still very good at it.

That said I still tend to cut out at least 25% of the resulting verbiage and adding back another 10% or so more of my own original content even under those circumstances.

Where it has been really helpful is that I tend to want to write in a conversational style that doesn't seem to match most people's expectations of a technical document. The LLMs let me write my way and style-shift it into something closer to what people expect. And LLMs, since let's be honest they're the primary audience nowadays. Which I am not even upset about; I'd rather 5 LLMs read the architecture document than the amortized .2 or so humans I could expect in the same circumstance 5 years ago.

Which also implies, in many cases, I am feeding the AI as much text as I expect to come out, or in some cases, even more, as I am describing context, reasoning, and other things that may impact the writing but are not necessarily repeated in the final text. I factored out a lot of the context into my user-level CLAUDE.md which has helped cut that down a bit.


Having the style guide and proofreading it and linking it is more effort than the lazy slopulists want to put in, so your writing will reach far better than theirs will

I was reading the manual of a car head unit, and it was better quality than 99% of AI flavored content.

"I am already seeing my "normie" friends getting locked out of accounts due to not understanding passkeys."

In a weird way this is good news for us. If people are losing passkeys, getting locked out, and incurring non-trivial support costs as a result to the relevant companies, then there's no way those companies will crank down even harder by requiring hardware keys.

As an option, I don't mind it existing for situations like a work environment. Work environments are so much easier because there is a clear line to get my credentials reset, from scratch if necessary, even if I lose everything. The problem is that the consumer authentication case is even harder because it lacks that clear line without also creating a backdoor.

So I insist on centralizing my passkeys into a password manager. I have no passkeys outside of my password manager and will continue to reject them. If it's important enough to slap authentication on, it's important enough for me to not lose it because I couldn't choose where to stick it, which is in a basket that I protect very, very carefully.

Honestly I just don't see how something like Amazon could ever turn on the "require hardware key" feature without blowing their own foot off, or really any consumer-facing service. Everyone loses keys. To a first approximation nobody is going to buy three keys and correctly manage setting up all of them to work with every service. Even if we magically stipulate that all sites support it and they all have some integrated unified approach so that there's no software-side friction at all to register all three at once everywhere, you just get too many people who stuck all three keys on one keychain, people whose houses burned down, people who so successfully stored both backups "securely" that they have no memory of where they are anymore or how to get them back, an endless parade of lost keys. The consumer as a whole is not capable of managing hardware keys.

Given how often my household loses its second car keys for extended periods of time I am not exempting myself from this. My work key lives a much simpler life... it just sits in one place, doing work things. My family would hardly last a month if everyone had to carry around physical keys to log in to things.


Let me just check the schedule here... ah, yes, it looks like we should be getting "AIRSHIPS - HAS THEIR TIME FINALLY COME" swinging back around here in about 6 weeks. See you all then.

Research the "Monroe doctrine"... by which I mean, don't just look up a one paragraph summary, spend a bit of time with it. A few pages of text at least. Ideally in a modern formulation you should encounter the term "World Island" without having directly searched for it and how the modern iteration of the Monroe doctrine is a reaction to that in a way that the original didn't have to contend with.

I'm not doing advocacy here, I'm giving pointers on how to come to a deeper understanding of what is going on.

It is also important to understand that the EU is directly attacking this doctrine with this proposal. You are free to agree with the EU. Again, I'm just giving something to guide people to a deeper understanding of what is going on beyond the surface level playground politics of it all. There's more going on than that.

(Personally I would say I "disagree" with the Monroe doctrine but the sort of national/international structure I would actually want is not even remotely on the table, so... my opinion is thereby of even less import than a random other opinion drawn from "the masses" for choosing "E, none of the above" when that was not given as an option in the first place.)


Research the "Treaty of Tordesillas"... by which I mean, don't just look up a one paragraph summary, spend a bit of time with it. A few papal bulls at least. Ideally in a modern formulation you should encounter the term "Requerimiento" without having directly searched for it, and how the modern iteration of the line-of-demarcation doctrine is a reaction to that in a way the 1494 version didn't have to contend with.

I'm not doing advocacy here, I'm giving pointers on how to come to a deeper understanding of what is going on.

It is also important to understand that the United States is directly attacking this doctrine by just sitting there. You are free to agree with the United States. Again, I'm just giving something to guide people to a deeper understanding of what is going on beyond the surface level playground politics of it all. There's more going on than that.


If you're trying to sarcastically imply something, I'm not sure what it is. That is also a necessary key to understanding a certain era of history. Not the current one, though.

I think you've said nothing here other "Look up a good summary of the Monroe doctrine, with which I mildly disagree"

What arrogance.

You elided if you want to understand what is going on more deeply, which is a rather important part.

I say that precisely because I know that in reality most people aren't that interested. Which feel like I'm insulting people or something, but it's just the reality, we don't all have time to dig into absolutely everything all the time, and if you're not interested that's fine. But if you are, this is the best pathway to understanding this at a deeper level than the playground level.


This is a direct stab at the US imperialist faction — not MAGA, who want the US to break up with the EU.

I genuinely don’t understand this move through the lens of realpolitik: they’re mad at Trump, so they’re going to offend CFR et al who are aligned on Fortress America and neo-empire by threatening to take a critical vassal for the EU?

Okay — but you just turned being mad at MAGA into the MIC deep state viewing you as an enemy and therefore further military alliance with any EU member unviable. All because the EU couldn’t stomach four years of crass taunts from a TV conman.

Total MAGA victory.


TLDR; The dollar is the global currency of record, the US became the richest country in the world, and Stalin didn't get Europe and Japan. The massive export market and global security was the payoff.

The trade deficit and debt is in USD it's a line in the ledger that is somewhat fine and sustainable as long as the world stays on the USD as the currency of record. Countries for now are happy to keep storing their reserves in US bonds - Canada holds 600-700 billion in US debt. Japan over a trillion.


Are you sure it wasn't prorated?

If it wasn't prorated anyone who approved the contract needs training and/or firing. If it is prorated, that is generally not a problem. Small outages aren't even worth the effort of trying to get the money back, and if you have a large enough one to make it worthwhile it is likely the prorated refund is still going to be laughably small.


I think it was prorated but am not 100% sure.

You can use -log10(1-p). On the "nines" it is exactly the number of nines you have:

    $ python3
    Python 3.12.3 (main, Aug 31 2026, 10:18:26) [GCC 13.3.0] on linux
    Type "help", "copyright", "credits" or "license" for more information.
    >>> import math
    >>> def nines(num):
    ...     return -math.log10(1-num)
    ... 
    >>> nines(.9)
    1.0
    >>> nines(.99)
    1.9999999999999996
    >>> nines(.999)
    2.9999999999999996
(Modulo floating point issues of course.)

Which then smoothly covers the entire space:

    >>> nines(.9321)
    1.1681302257194985
    >>> nines(.2)
    0.09691001300805639
But good luck getting that standardized.

I worked at a 4 1/2 nines (99.997) place and it was pretty standard to speak of half-nines at least (although on reflection, perhaps not everyone understood that 0.7 was 1/2 of 0.9 and thought 99.995 was "4 and a half nines") - we went from 3 nines in 2015 to 4 1/2 in 2025 (maybe slide back a little in 2026) - fun task but takes sustained high-level interest in reliability for a long time.

I don't think that people often understand that if reliability doesn't increase before an adoption cycle, the lack of it will limit the success of the adoption cycle.

If I'm tasked with getting a tool to be used at least 2x as much, my first task is to reduce the failures per 1000 runs by 4x. In that way, if adoption increases by 2.5, 3x instead of the the minimum we are looking for, then the number of errors reported per week still goes down instead of up.

We like to think of things as percentages but the moment they start increasing in the time domain everyone gets mad, because they asked for and received the wrong thing.

And that's on top of the fact that when people are 'forced' to use a tool, any errors they experience will be lumped onto the Learned Helplessness theater they've been engaging in to avoid being made to use a tool that is going to make all of our lives easier.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: