Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
czk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
czk
1y ago
the year is 2045. you've been cruising the interstate in your robotaxi, shelling out $150 in stablecoins at the cloudflare tollbooth. a palantir patrol unit pulls you over. the optimus v4 approaches your window and contorts its silicon
32.
▲
by
czk
1y ago
this is good to know! thank you for the info
33.
▲
by
czk
1y ago
I've often thought about the amount of data that these bot services must have access to (they could log millions of private channels), data thats silo'd away from search engines/indexers and could be pretty valuable to sell t
34.
▲
by
czk
1y ago
user clicks a phishing link and is asked to login to M365 again, they do it without hesitation because they are used to doing this 5 times a day logging into phishing links would make more people pause if they didnt have to login constantly
35.
▲
by
czk
1y ago
Coinbase Prime is its own exchange with its own support (actual humans in the USA that are available to chat to). It's for "institutional investors" so unavailable to most customers without the proper credentials/paperwo
36.
▲
by
czk
1y ago
i had assumed this was mostly a result of training too much on lex fridman podcast transcripts
37.
▲
by
czk
1y ago
will be interesting to see how they tighten the reward signal / ground outputs in some verifiable context. don't reward it for sounding right (rlhf), reward it for being right. but you'd probably need some sort of system to b
38.
▲
by
czk
1y ago
"good at advanced reasoning", "fast at advanced reasoning", "slower at advanced reasoning but more advanced than the good one but not as fast but cant search the internet", "great at code and logic",
39.
▲
by
czk
1y ago
the auditors that sign off on your security to meet your clients requirements usually know way less about your security posture than your clients do its all just surface-level box-checking. most companies required to get 'penetration t
40.
▲
by
czk
1y ago
and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and manag
41.
▲
by
czk
1y ago
re: "grok-3 is r1 with mods" -- do you mean you believe they distilled deepseek r1? that was my assumption as well, though i thought it more jokingly at first it would make a lot of sense. i actually enjoy grok 3 quite a lot, it h
42.
▲
by
czk
1y ago
sometimes it feels like openai keeps serving the same base dish—just adding new toppings. sure, the menu keeps changing, but it all kinda tastes the same. now the menu is getting too big. nice to see that we aren't stuck in october of
43.
▲
by
czk
1y ago
I'm in the habit of always opening a new chat because I change subjects quite often, and the LLM tends to randomly reference a previous question with more weight than it should.
44.
▲
by
czk
2y ago
ChatGPT killed Lorem Ipsum
45.
▲
by
czk
2y ago
Not sure about the manifest but recently I've seen talk about some banking apps using SBSLaunchApplicationWithIdentifierAndURLAndLaunchOptions (undocumented function in SpringBoardServices) [0] to try to launch another app on the phone
46.
▲
by
czk
2y ago
All I can find is that it consists of two people, Elon Musk and Jared Birchall (wealth manager of Musk since 2016, CEO of Neuralink, "right hand man", etc)` If there are others, it's likely to be representatives from firms l
47.
▲
by
czk
2y ago
“I didn't have time to write a short letter, so I wrote a long one instead.”
48.
▲
by
czk
2y ago
https://archive.is/9LqJN John Ratcliffe mentions it here: https://youtu.be/mz1sLlpee80?t=87
49.
▲
by
czk
2y ago
I'm not familiar with atop but the website mentions netatop is optional and what I've found suggests you have to manually install it. Do you know if any distributions/packages install this by default alongside the atop instal
50.
▲
by
czk
2y ago
Seems like the latest version might be as old as July 2024? https://www.atoptool.nl/allnews.php For anyone interested, here are the latest commits to the GitHub: https://github.com/Atoptool/atop/co
51.
▲
by
czk
2y ago
Also worth noting that this commit in Dec 2024 previously added a bunch of internal headers (aside from this one) to a restricted external access list (one of them was vulnerable to SSRF) and there was never a CVE for it. https://
52.
▲
by
czk
2y ago
Heh, that commit you linked added a bunch of headers to INTERNAL_HEADERS (to prevent external use) but they forgot to add the one in this particular vulnerability. This was done in December 2024. There were probably a myriad of vulnerabilit
53.
▲
by
czk
2y ago
As I understand it, the middleware runs before a request hits a page or API route.. so to avoid infinite loops from internal subrequests (URL rewrites, etc), Next.js tags them with the x-middleware-subrequest header. This tells the runtime
54.
▲
by
czk
2y ago
it only took 16 days to triage a global next.js auth bypass
55.
▲
by
czk
2y ago
Turn the tables by having your crawler send snippy emails to webmasters when their site slows down under your barrage. Try: “Your server failed to support our cutting-edge AI training. Please upgrade your pathetic infrastructure.” Blaming t
56.
▲
by
czk
2y ago
Yeah you are right about the caching thing, I understand what CF is doing I just cant help but feel like there is something deeply wrong about this approach. But I don't have any better ideas to propose. Maybe I'm just holding on
57.
▲
by
czk
2y ago
Sounds absolutely brutal for sure. I didn't mean to sound like everything was fine in JavaScript land, they have been chasing the shiny new thing and focusing too much on the wrong abstractions for a while. Even backend frameworks aren
58.
▲
by
czk
2y ago
This sounds much more expensive than just serving the cached content you already have. I would hate for a future where I have to double-take the content I'm reading to make sure CloudFlare didn't decide to confuse me with a bot an
59.
▲
by
czk
2y ago
I don't disagree with the point being made but it should also be noted that React and Vue are both 11 years old. Hell, even Meteor.js (anyone remember this one?) is still around and being updated.
60.
▲
by
czk
2y ago
Using private data to train a public LLM seems like a huge liability that Google's legal team would never approve. I could see them using the data for all sorts of kinds of analytics though. I heard Google deals in those a lot.
More ›