> but fail to see that the dozen variations generated are not distinctive - they might have somewhat different typography or imaginary, but still have the same AI uniformity and smell as the crappy restaurant poster you see on the street
Hard disagree: every single example TFA gives is way better than the horrible generic ones that are polluting every shop and LinkedIn post.
> which began life in the pre-internet era Bulletin Board Systems and moved to internet File Transfer Protocol servers (“topsites”) in the mid- to late-1990s.
Yeah! I was a bit connected in that we'd write "intro" for a BBS and in return we had unlimited download (whereas on many BBSes there were seeder / "leecher" ratio and unless you were providing stuff, you'd be hindered by your leecher ratio).
> The “Scene,” as it is known, is highly illegal in almost every aspect of its operations.
But the "intro" pirates would put in front of cracked games (or sometimes on BBSes to advertize the BBS), later renamed "cracktros" (for that term wasn't used at first) eventually did spawn full-on "demos" and "musicdisk" / diskzines etc. and those weren't illegal.
In my Commodore Amiga days about half of my 5"1/4 floppies (because we were hacking 5"1/4 external drives to our Amiga and pretend to the computer they were the internal 3"1/2 disk so that we could buy shitload of much cheaper 5"1/4 floppies [1]) were demos (from Sanity, Scoopex, State of the Art, Lemon, Razor 1911, etc.).
Piracy definitely had aesthetics to it and I'd say the fully legal demos were, weirdly enough, the biggest manifestation of the aesthetics of piracy.
[1] in the early days I remember that after having something ridiculous like 3 boxes of 10 5"1/4 floppies, compared to 3 boxes of 3"1/2 floppies, you had already fully paid the 5"1/4 external floppy drive reader. I still have that external 5"1/4 drive for the Commodore Amiga just as I still have my chinese pirate SNES copying device. These two are prized possessions of mine ; )
I don't disagree with that. Killing children is totally unacceptable, even in a war.
However what's your take on holding accountable the rulers in Iran who ordered the slaughtering of 30 000 iranians in january 2026? Apparently they even sent islamist guards into hospitals to finish the wounded.
Trump, Hegheh, etc.: murderers.
But islamists at the head of the islamic republic of Iran: all cool? Or murderers too? Should they be held accountable too or not?
And what about Hamas terrorists who murdered 1200 civilians at a music festival in Israel? They should be held accountable or it's all cool because it's, somehow, justified resistance?
And is TFA is about a "kill chain": what about the chain, the real chain, that led to an islamist regime slaughtering 30 000 of its own citizens because they were protesting islamism?
Shall we write and upvote articles about that chain and the underlying cause of such behavior?
We criticize what we control, rightly. I think heads should roll for this massive fuckup. Instead we get whataboutism, jingoistic compliance, and the default, helpless apathy. We hold ourselves to a higher standard than Hamas terrorist and Islamist mullahs, and we should. But because that's not happening it's undermining the very justification for such conflicts. It's just one monster versus another now.
I don't care about whataboutism much, so I won't argue with you on your points, but know that it seems a large part of the 1200 killed during October 7th were killed by the Hannibal doctrine, which for the first time was applied to Israeli civilians.
> Passkeys do marginally improve security against MITM and phishing attacks ...
The tragedy of passkeys is that they're a step back from the security offered by the likes of Yubikeys.
But because passkeys are pushed by both Google, Microsoft and Apple: there is is simply no fighting these three. It is impossible.
Passkeys won not because they're better (they're not and the entire concept of "secret behind a hardware security module" that can be transferred to another system defeats the whole point of a HSM in the first place) but because the powers-that-be decided that passkeys are to be used.
It's still a win: the commoners are better served with passkeys.
But a secret in control of Google/Apple/Microsoft that can be backed up is not a secret I control: it's a complete step back from yubikeys.
Passkeys won and we better get used to them (and, yup, there are usability issues as you mentioned).
> What makes you think RCEs are being found & fixed at a rate that’s faster than they’re being introduced?
It could go either way but we're already at a point where successful exploits in some software (like Chrome) require an absurd amount of exploits to be chained to lead to an actual RCE. We've seen chains requiring more than ten exploits: not kidding.
We'll learn to put more and more sandboxes / guards / checks / defensive techniques everywhere and then all that's going to be needed is for AI looking for security issues to find something ridiculous like 10% of all the actual issues to stop RCEs dead in their tracks.
Also arguably the current SNAFU was expected: we fully knew hardly anyone was taking security seriously.
Now: not so much. Many projects had tens and even hundreds of issues pointed to them.
I think we'll see several things: projects beginning to take security seriously, defense in depth getting generalized and hence RCEs requiring ever more bugs/exploits to be chained to achieve anything, low-hanging fruits getting patched at an insane pace, new code being immediately checked, by LLMs, for not just low-hanging fruits but also more advanced security weaknesses, etc.
We may also see things like the lost art of configuring firewalls making a comeback, the generalization of hardware security modules (where applicable), and even things offering physical guarantees, like time-bounded retrieval protocols, beginning to get used seriously.
If I had to bet I'd say it shall go both ways: some projects are going to extremely sloppy and full of holes but others are going to get so secure nobody shall ever break them.
> Then the movement minted a fraud. Sam Bankman-Fried was not an accident of proximity; he was EA’s own product
TFA could have have mentioned that it's a fraud, MacAskill, who minted another fraud. MacAskill was SBF's guru and he was also involved in FTX and Alameda scams (but distanced himself before the scandal blew up) and MacAskill bought a 15 million GBP mansion in the UK for the Effective Altruism movement using funds stolen by SBF.
Last I checked the mansion hasn't been clawed back yet (but it could: funds from the Madoff ponzi have been clawed back more than 15 years after the fraud has been exposed).
Now of course people in charge of clawing back the stolen funds are the only hope of people who've been scammed for MacAskill didn't effectively altruistically sell the mansion to effectively altruistically hand the money to people who have been scammed.
That MacAskill and SBF maybe had groupsex with Caroline Ellison is one thing: they're proud to be polyamorous, whatever. We live in a free world.
But buying a $15 million mansion with stolen funds is thievery. Effective Scammers.
I can't help you but my comment may help others...
As a techie you should have known better: you first learn how 2FA using TOTP works. You understand what happens when you create an entry in Google Authenticator (or whatever app). You reproduce the procedure: you verify that you end up with the same 6-digit numbers.
If you've got a partner, you register your secret keys for each service on your partner's device and vice-versa.
Then you've got backups of your secret keys on paper, in a safe at your bank. Next to each secret key there's a checkbox: "Successfully initialized from this secret key?".
When those TOTP became ubiquitous (way, way, way before Yubikeys or passkeys were a thing), 2FA was a godsend compared to just passwords.
I understood they were here to stay for years, and years. And then more years.
So I learned how they worked.
When later on QR code generalized to initialize those (IIRC it wasn't a thing in the early days of 2FA TOTP: you'd just always get the secret key as characters, not as a QR code), I refused to ever scan a QR code: I always first decode the QR code (for the services only showing the secret key as a QR code, without also showing it as text), extract a copy of the secret key and then register it from my copy.
Stuff like that.
Now... As most services are deeply broken and have completely insecure practices you just say "I lost my 2FA, I want to reset it" and because they're clueless when it comes to security, they'll allow you to reset it. If someone hacks your email, they pretty much can reset every single of your account (at least those tied to that email).
I found soap decades old, very likely older than half a century. Hundreds of boxes and hence thousands of soap bars. I'd regularly found them for years and years here and there for my great aunt had stashed those left and right. I found some in system ceilings (!), in the attic, in the basement, in drawers.
My great aunt died years and years ago (RIP) but as recently as a few weeks ago my brother and I cleaned/emptied a garage where she had hidden some stuff.
More soap bars.
I don't need the physics/chemistry: I know that soap is a stable molecule. I suspect some of the soap bars were dating back to WWII.
My great aunt was also in the "waste not / want not" camp. But as she lived through WWII as a teenager, she was in fear of ever missing things again. Hence the soap bars.
I definitely make a point of keeping a small stock TP (and cheap/easy food, like bologna, hot dogs, and bread) around in these post-covid days.
Not to the extreme of the story about the soap, above, but: Something in my mind was changed a little bit more every time I'd go to the store and there were empty shelves. So now I do things like always have a few weeks of TP, and I freeze things like bread and bologna.
I never did that at any point in my adult life leading up to COVID: If I ran out of something, I just picked up more later at the store the next time I was nearby (or any other time; lots of things were 24/7 back then).
Good to see some raising the issue of the sex cult that Effective Altruism is:
I'd like to hear what feminists have to say about that picture in TFA of that woman and six men watching her. Just as I'd like to hear what feminists have to say about Amodei's wife who used to run a porn site.
And while a sex-cult abusing women is one thing. Theft is another. More emphasis should be put though on the lying scums in their ranks, like the polyamorous SBF and Caroline Ellison or their guru and its $15m ill-acquired mansion in the UK (which hasn't been clawed back yet but could).
And speaking of lying scums stealing money, we know about several making constant announcements were they lie, lie and then lie some more to ensure a never-ending stream of money and insane valuation of their proprietary, closed, not altruistic at all companies.
A despicable movement and I, for one, I'm very happy that there are companies out there releasing open-weights models so that the thieving-and-sex-cult at least get some competition.
> I'd like to hear what feminists have to say about that picture in TFA of that woman and six men watching her.
That picture is literally a joke based on a meme, which is based on a porn star's promotional image. To the extent feminists care, I would expect that care to be about the underlying subject matter rather than about this satire of it.
Is it really a satire if the same woman in the photo (Aella) went on to have a "birthday gangbang" with numerous men, some of whom are present in the photo?
> The not-so-silent minority hanging out on HN know that the true heroes are those who take the time and put in the effort, and then put even more effort to reply and post about it here.
We know that the entirety of the AI movement is built on top of open-source projects like Linux and all the terminal and command line utilities. And runs inside projects doing god's work (say to contain the agents) like QEMU etc.
AI lives inside the work of our open-source heroes and would be absolutely nowhere without the work of all those people.
> Thanks to all of our heroes, op included.
Definitely, thanks GP and thanks to all our heroes.
Hard disagree: every single example TFA gives is way better than the horrible generic ones that are polluting every shop and LinkedIn post.
It's not even close.
reply