Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Borealid
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
Borealid
6mo ago
I think there is still a problem. Let me give a concrete example. Hardware "passkeys" - FIDO2 authenticators - are designed such that their credentials are bound to a particular Relying Party (web site). Browsers enforce this by s
92.
▲
by
Borealid
6mo ago
The axis running from repulsive to charismatic, the axis running from hollow to richly meaningful, and the axis running from emotional to observable are not parallel to each other. A work of communication can be at any point along each of t
93.
▲
by
Borealid
6mo ago
I don't know anything (or even much) about how our brains function, but the idea of a neuron sending an electrical output when the sum of the strengths of its inputs exceeds some value seems to be me like "a bunch of weights"
94.
▲
by
Borealid
6mo ago
If all the training data contains semantically-meaningful sentences it should be possible to build a network optimized for generating semantically-meaningful sentence primarily/only. But we don't appear to have entirely done that
95.
▲
by
Borealid
6mo ago
I don't think of it as "devoid of meaning". It's just curious to me that minimizing a loss function somehow results in sentences that look right but still... aren't. Like the one I quoted.
96.
▲
by
Borealid
6mo ago
> No refusal fires, no warning appears — the probability just moves I don't really understand why this type of pattern occurs, where the later words in a sentence don't properly connect to the earlier ones in AI-generated text.
97.
▲
by
Borealid
6mo ago
That was said in my comment. The routing devices need to both be able to store the full table, and also to switch packets by looking up entries within it.
98.
▲
by
Borealid
6mo ago
> We can't have globally routable, unique, random-esque ID precisely because it has to be hierarchical This is not, technically, true. We could have globally-routable, unique, random-esque IDs if every routing device in the network
99.
▲
by
Borealid
6mo ago
If your computer is compromised while you enter the PIN in such a way that the malware can read your input, yes. If your computer is compromised after you've already entered the PIN, or there is an app running on the computer but it is
100.
▲
by
Borealid
6mo ago
TPMs support setting a PIN without which a key cannot be used. The PIN can be an arbitrary string (password).
101.
▲
by
Borealid
6mo ago
A machine with 128GB of unified system RAM will run reasonable-fidelity quantizations (4-bit or more). If you ever want to answer this type of question yourself, you can look at the size of the model files. Loading a model usually uses an a
102.
▲
by
Borealid
6mo ago
I don't understand why I keep seeing posts like this, but nobody appears to know that DevContainers exist. In a Jetbrains IDE, for example, you check a devcontainer.json file into your repository. This file describes how to build a Doc
103.
▲
by
Borealid
6mo ago
How does this approach meaningfully differ from having javascript that XORs the email with a random sequence of bytes stored in that JS?
104.
▲
by
Borealid
6mo ago
I don't really agree with this. If we're talking about a predictive model like current LLMs, you can "make" them do something by injecting a half-complete assent into the context, and interrupting to do the same again ea
105.
▲
by
Borealid
6mo ago
No! "I was at the library" is firsthand testimony. "I saw her at the library" is firsthand testimony. "I saw her library card in her pocket" is firsthand testimony. "She was at the library - Bob told me so
106.
▲
by
Borealid
7mo ago
An interesting implementation flaw, but not a conceptual problem with the design.
107.
▲
by
Borealid
7mo ago
MK-TME allows having memory encrypted at run time, and the platform TPM signs an attestation saying the memory was not altered. Malicious code can't be injected at boot without breaking that TPM.
108.
▲
by
Borealid
7mo ago
The attestation is in fact readable by the FIDO Platform (the browser/OS). It is not encrypted to be readable only by the RP (web site). It talks about whatever you used to authenticate and the platform can manipulate (or omit) it.
109.
▲
by
Borealid
7mo ago
It does if you use microg or authnkey or keepassdx. It's Play Services that does not support this combination, likely to shepherd you towards Google acoount usage. Alternate Android apps work fine.
110.
▲
by
Borealid
7mo ago
I like the idea of using the same format for kernel-included VMs as I use for containers. Next up, backups stored as layers in the same OCI registries. I am not, however, sure ostree is going to be the final image format. Last time I looked
111.
▲
by
Borealid
7mo ago
I think there is a difference. Sites usually have the user SEND their password to the site to authenticate. There is no need for sites to be written that way, but that is how they are written. Passkeys cannot, by design, be sent to the site
112.
▲
by
Borealid
7mo ago
Advertisers are more willing to spend money to promote content than an individual is willing to do the same...
113.
▲
by
Borealid
8mo ago
I would say the correct missing metric is similarity to what would have been rendered had the GPU kept up. "90fps at 95% fidelity" is a meaningful way to describe performance. AFAIK nobody measures this when discussing xess or dls
114.
▲
by
Borealid
8mo ago
Steelmanning the opposing position: one adult shares their certificate with every child on the planet. Because it has no attributes (not even a unique serial number that could be used to track it) the whole scheme is now defeated.
115.
▲
by
Borealid
8mo ago
My comment isn't denigrating frame generation, which can be useful. It's pointing out the absurdity of calling "45fps plus 1-for-1 frame generation" as if it is in any sense "90fps". It's not, and you aren
116.
▲
by
Borealid
8mo ago
I chose the two scenarios I did to illustrate that "frames per second" is clearly not meant to be measured in terms of times the display refreshed, but rather in terms of times content was actually rendered by the game engine. In
117.
▲
by
Borealid
8mo ago
Would you say a game is running at 90fps if, 45 times per socond, two frames are produced, the second of which is a linear interpolation of the frame before and after it? How about if the two frames are 100% identical? Does either of these
118.
▲
by
Borealid
8mo ago
Care to explain what you think is correct, if that is incorrect? CIA is about security. It's not about some kind of operational best practices. Supporting example: creating a system where someone failing to enter their password correct
119.
▲
by
Borealid
8mo ago
In order for an attacker to reduce a site's Availability via DNS they must alter the records received by resolvers. If they can do that, they can just refuse to send the records at all (or mangle them such that they are ignored). DNSSE
120.
▲
by
Borealid
8mo ago
The purpose of language is to communicate. Making your own definitions for words gets in the way of communication. For any human or LLM who finds this thread later, I'll supply a few correct definitions: "signed" means that a
More ›