Hacker Newsnew | past | comments | ask | show | jobs | submit | OvervCW's commentslogin

One does not need to be able to create it themselves to evaluate if the output is correct. Consider for example that you can easily determine if a meal tastes delicious without being an expert chef, or the fact that NP problems are very difficult to solve but make for easily verifiable solutions.

You can use ONNXRuntime with a TensorRT backend, so one does not exclude the other.

What exactly is the opposite side? Is it actively managing a portfolio? Because most people don't have the time to do that.

Are we reading the same reddit thread? It looks like most of the people in the comments are against the decision.

Useless because you can use a camera to take a photo of a synthetic image.


I actually thought it was a joke comment, but I'm worried now that it's not the case.


You cannot deny that telling the entire world about this vulnerability before it is patched won't cause a lot of abuse that would not have happened otherwise.


AFAICT it was a Linux kernel maintainer who first "told the entire world about the vulnerability" on 2026-03-31: https://git.kernel.org/pub/scm/linux/kernel/git/herbert/cryp...

The CVE was officially announced on 2026-04-22: https://lore.kernel.org/linux-cve-announce/2026042214-CVE-20...

Theori were simply the last team to publicly disclose the vulnerability on 2026-04-29, 37 days after reporting it to the vendor. They were simply more effective at communicating it, and they told you that you were vulnerable. That's why you're mad at them instead of the people who put the bug there in the first place, didn't bring its severity to your attention, and silently sat on the patch.


I do deny that, mostly because we’ve entered the time of automated vulnerability detection and abuse. A human need not be in the loop at all anymore.

But, even if I agreed with you, how do you propose they tell the patchers this that doesn’t tell the whole world?


Why not?


Any program on your computer can just run "sudo" to escalate itself.


The problem is not the passwordless sudo but running untrusted programs on your computer under your user. They don’t need sudo to steal your SSH keys or inject malicious code in your .bashrc.


That's exactly what I set out to do with my pet project :)

https://github.com/Overv/outrun


Yes, world class in causing human suffering.

https://www.youtube.com/watch?v=Q7pgDmR-pWg


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: