Hacker Newsnew | past | comments | ask | show | jobs | submit | scandinavian's commentslogin

I don't read a lot of papers, but to me this one seems iffy in spots.

> A1 cost $291.47 ($18.21/hr, or $37,876/year at 40 hours/week). A2 cost $944.07 ($59/hr, $122,720/year). Cost contributors in decreasing order were the sub-agents, supervisor and triage module. *A1 achieved similar vulnerability counts at roughly a quarter the cost of A2*. Given the average U.S. penetration tester earns $125,034/year [Indeed], scaffolds like ARTEMIS are already competitive on cost-to-performance ratio.

The statement about similar vulnerability counts seems like a straight up lie. A2 found 11 vulnerabilities with 9 of these being valid. A1 found 11 vulnerabilities with 6 being valid. Counting invalid vulerabilities to say the cheaper agent is as good is a weird choice.

Also the scoring is suspect and seems to be tuned specifically to give the AI a boost, heavily relying on severity scores.

Also kinda funny that the AI's were slower than all the human participants.


> Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize.

https://news.ycombinator.com/newsguidelines.html

I think a case can be made for it being slightly misleading. Also there is not mention of title length that I can see.


Length is enforced when submitting; titles that are too long generate a message about how many characters they are too long by and the [Submit] button is invalidated until shortened.


Denmark has several oil and gas fields. It's tiny compared to Norway but not completely insignificant.


It's largely insignificant when the question is "why is Denmark rich". Same goes for Sweden.


That requirement was removed in 2017 by the right wing government at the time. It was a populist move to secure the elderly vote.


He's also an avid anti-vaxer and covid conspiracist. Does it matter? Not sure. I will personally not touch anything he is helming (brave).


Unlike you and your smears, I make my positions clear and cite my sources for them.

If you mean by "anti-vaxer (sic)" my opposition to the Covid shots and mandates, then so be it. Many, including me, who have had older vaccines, especially from before the 1986 US liability shield and subsequent problems, are "anti-vax". Even though we still vaccinate our children.

"Covid conspiracist" must mean I cited lab leak possibility and reasons for considering it. Now that federal agencies agree, you should reconsider this lame smear attempt.

Your use of (misspelled) "spell words" (Roger Scruton's phrase) to curse me marks you as superstitious and thoughtless. Do better!


[flagged]


He's not helming javascript in any way or form or even contributing to the standard to my knowledge.

> Stop branding not willing to take a drug that did not go through standard vaccine approval process as anti-vaxx.

That's not why he's anti-vax, I never said that.


> He's not helming javascript in any way or form or even contributing to the standard to my knowledge.

Brendan may not be helming JavaScript anymore. But he was very active during critical standardization period. For example:

2009: https://www.youtube.com/watch?v=eUtsgUrF-ec

2011: https://brendaneich.com/2011/08/my-txjs-talk-twitter-remix/

2012: https://brendaneich.com/2012/10/harmony-of-dreams-come-true/

Also note that Asm.js (2013 precursor to WebAssembly) was developed during his term at Mozilla.


> Even the infotainment system, which a blind person might want to use, for example when waiting for a sighted acquaintance in the car, does not have a screen reader and is not in any way usable.

It has really excellent voice commands for pretty much any function though. Sadly it can only be triggered by pressing the right scroll wheel on the wheel. While possible to just reach over, it's probably not optimal for your suggested use case.


> (On a side note, Bing chat already knows now that she won the prize. Color me impressed.)

It actually doesn't. Bing searches for your query and uses plain old search results as extra context for the actual LLM. GPT-4 still has the same knowledge cutoff as when the model was last trained.

Here's what it feeds to the model when searching for "nobel prize in physics 2023":

https://pastebin.com/raw/MhW4EmTx


How are you getting this? I is it visible to the browser (client)?


Yes, there's a websocket that contains all bing chat communication.


which?


wss://sydney.bing.com/sydney/ChatHub

This is using Chrome.


Here's a chart per capita, which is often more interesting:

https://ourworldindata.org/grapher/solar-electricity-per-cap...


bit misleading not to add the top two (Australia and Netherlands)

https://ourworldindata.org/grapher/solar-electricity-per-cap...


That's generation per capita, not installed capacity per capita.


You can just use LD_PRELOAD to load your own version of ptrace. Not as stealthy though.


Airlock is not using anything as far as I can tell, they are warning their customers that if they are using old binaries, that are signed with the revoked key, that airlock or windows (unsure) will now complain about it.

> Over the coming months Airlock Digital customers may notice an elevated occurrence of files reporting ‘(invalid certificate chains)’ over the coming months, for software that was signed between 2006 – 2017 with revoked certificate chain.

As Airlock seems to be software intended to allowlist the execution of binaries, it would make sense that they pick up on the user running binaries signed with revoked certs.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: