Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Ukv
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
91.
▲
by
Ukv
5mo ago
> The information exposed in the current process was: code changes in the git commits and a commit message that did not mention the vulnerability. Idea with the current process is for the researcher to email distro maintainers about the
92.
▲
by
Ukv
5mo ago
I'm suggesting that less information about the vulnerability could be circulated than the current process, not more, due to distro maintainers being able to trust just "version X contains a fix for a high-impact security vulnera
93.
▲
by
Ukv
5mo ago
The patch itself can be made to look fairly innocuous, as was done here. Won't always successfully prevent bad actors finding the vulnerability, but seems better to at least not unnecessarily increase that risk.
94.
▲
by
Ukv
5mo ago
You can meaningfully test if one slot machine hits the jackpot more often than another, just that the methodology should involve a large number of repeats rather than a few anecdotes. There are some LLM leaderboard sites that do it with bli
95.
▲
by
Ukv
5mo ago
I'd imagine it's not that they lacked the time to email linux-distros, but that they were unaware they were supposed to do so. Feels like the more sensible process would be for kernel maintainers to announce when a version contain
96.
▲
by
Ukv
5mo ago
Quantifying their own confidence is also something they're not good at, and which the format would prevent them from refusing to do or preceding with a caveat if that's what you'd want of them. Particularly since the response
97.
▲
by
Ukv
5mo ago
> Then the correct answer is “I can’t tell.” From the paper they're using structured JSON schema mode opposed to freeform answers, so it can't. Models do typically caveat their answer for questions like this, in my experience.
98.
▲
by
Ukv
6mo ago
> and how that's good enough for me I'd go further than that and say for me personally, the fact it's just a file is a selling point, not a "good enough" concession. I can just put passwords.kdbx alongside my n
99.
▲
by
Ukv
6mo ago
> presumably this comprise was only found out because a lot of people did update This was supposedly discovered by "Socket researchers", and the product they're selling is proactive scanning to detect/block malicious
100.
▲
by
Ukv
6mo ago
> start by not renaming Microsoft Office To my understanding, Office (or "Microsoft 365") itself becoming "Copilot" was just confused messaging about the "Office Hub" app/shortcut being repurposed.
101.
▲
by
Ukv
6mo ago
The article quote was being given as the supposed source for "Claude Code also found one thousand false positive bugs, which developers spent three months to rule out", so should substantiate that claim - which it doesn't. If
102.
▲
by
Ukv
7mo ago
I think Meta's position as a large company under (rightfully) a lot of media scrutiny fundamentally prevents it from creating a successful "metaverse". It'll be pushed towards being overly corporate/sanitized and ce
103.
▲
by
Ukv
7mo ago
If the idea was that laws must be motivated by a negative occurrence rather than preemptive, then that'd follow yeah (if counting job loss as a reason to ban something, which I think is questionable). But note akersten is saying that i
104.
▲
by
Ukv
7mo ago
> The commercial bots seamlessly traverse between AI, auto-respond and human. It's very much an ensemble method. This seems unlikely to me, given it'd increase costs and the response times would make it obvious. The messages pr
105.
▲
by
Ukv
7mo ago
> Listening patiently to a friend? [...] Send the invoice straight to someone’s inbox (hint, hint). A great way to break down your friendships and ensure nobody will do anything for you from then on.
106.
▲
by
Ukv
7mo ago
To be clear - the text I pasted is config for the Github actions workflow, not just part of a prompt being given to a model. The authors seemingly understood that the LLM could be prompt-injected run arbitrary code so put it in a workflow w
107.
▲
by
Ukv
7mo ago
If I'm understanding the issue correctly, an action with read-only repo access shouldn't really be able to write 10GB of cache data to poison the cache and run arbitrary code in other less-restricted actions. The LLM prompt inject
108.
▲
by
Ukv
7mo ago
> AI agent with full rights running on untrusted input in your repo? Boundary was meant to be that the workflow only had read-only access to the repository: > # - contents: read -> Claude can read the codebase but CANNOT write
109.
▲
by
Ukv
7mo ago
> It's about the disrespect of not asking. Could Firefox have asked if users wanted to enable AI features? Of course they could have, did they? Of course not, just think about how would asking would effect the shareholders!! IMO rig
110.
▲
by
Ukv
7mo ago
Many sites already exist to sell products (like Temu) or a paid subscription (like Dropbox), such that ads or crypto miners would just be double-dipping. On average, you would need to pay less than you do now if resources were not wasted on
111.
▲
by
Ukv
7mo ago
It's still on the claimant to establish copying, which usually involves showing that the two works are substantially similar in protected elements. That the defendants had access to the original helps establish copying, but isn't
112.
▲
by
Ukv
7mo ago
Have always felt it's not really any different to allowing a website to run a JS crypto miner. It moves money (which is why it's done) but wastes resources (time/energy) so is on net a detriment to affordability.
113.
▲
by
Ukv
8mo ago
> It can and should be removed in minutes because AI can evaluate the “bad” image quickly and a human moderator isn’t required anymore. CSAM can be detected through hashes or a machine-learning image classifier (with some false positives
114.
▲
by
Ukv
8mo ago
> A professional who pays 20€/month likely believes that the AI product provides them with roughly 20€ each month in productivity gains, or else [...] they would pay more for a bigger subscription Unless I'm misunderstanding, s
115.
▲
by
Ukv
8mo ago
To my understanding that's from the 4o demo that kicked off the controversy, and the Sky voice was pulled days later. I don't see evidence of another version existing after that, and would guess that the reason you're struggl
116.
▲
by
Ukv
8mo ago
I'd say network filtering, like already done by schools, would be preferable. For privacy concerns there'd be no need for handing over your ID to see websites, and for ownership/treacherous computing concerns the home router
117.
▲
by
Ukv
8mo ago
> Why should it be Google's (or Bing's) duty to filter those out? Google intentionally disguises ads as search results, and even lets advertisers present a fake URL. When the system's purpose is to profit from tricking ina
118.
▲
by
Ukv
9mo ago
I'd agree that the modder should have the legal right to create a $10/month subscription mod, because I don't like copyright being so extensive as to give the game's authors control over that, but also really don't
119.
▲
by
Ukv
9mo ago
> Your prior comment was dismissive. [...] Your new comment is broader. [...] As in the lack of mentioning those "aware and agreeing with the implicature/associations" in my prior comment? Notably my prior comment was repl
120.
▲
by
Ukv
9mo ago
> No. They'd be agnostic of the alleged nefarious meaning just like [...] It's entirely possible that some interpreted it as only the literal meaning and still disagreed with it. My point is "You can disagree with making
More ›