Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jsnell
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
181.
▲
by
jsnell
11mo ago
Nobody subsidizes LLM APIs. There is a reason to subsidize free consumer offerings: those users are very sticky, and won't switch unless the alternative is much better. There might be a reason to subsidize subscriptions, but only if yo
182.
▲
by
jsnell
11mo ago
If you have concerns about spam, the right thing to do is to email the mods at hn@ycombinator.com with examples.
183.
▲
by
jsnell
11mo ago
Zork was originally written at MIT for PDP-10s in an obscure Lisp dialect (MDL). The authors then later formed a company to sell the game on micro-computers. To do it, they built a virtual machine optimized for this purpose, a new Lisp dial
184.
▲
by
jsnell
11mo ago
I don't believe that is an accurate description of the issue. It wasn't that the system got too slow due to a big file, it's that the file getting too big was treated as a fatal error rather than causing requests to fail open
185.
▲
by
jsnell
11mo ago
Whenever I see an A/B test on a chatbot, I will vote for the version with more emojis. It might be petty, but it's all the rebellion I've got left. If enough people do it, I'm sure we can make the emoji-singularity happe
186.
▲
by
jsnell
11mo ago
> There's an incentive to blame "Chinese/Russian state sponsored actors" because it makes them less culpable than "we got owned by a rando". But they didn't get hacked by anyone. I don't see how th
187.
▲
by
jsnell
11mo ago
But this isn't a "small-ish bug". What gave you that impression? It's a vulnerability in code that is both compiled in by default, and that is reachable when ffmpeg is run with its default settings when run on a file cr
188.
▲
A Landscape of Knowledge Games
(azhdarchid.com)
16 points
by
jsnell
11mo ago
|
2 comments
189.
▲
by
jsnell
11mo ago
Three months is "soon"? What do you think is reasonable? And like so many posters in this thread, you seem to be under the impression that Google needed this fixed at some specific timeline. In reality the fix timeline, or even a
190.
▲
by
jsnell
11mo ago
I don't get why you think linking to multiple legitimate and high quality bug reports with detailed analysis and precise reproduction instructions demonstrates "slop". It is the opposite. This is software that is directly or
191.
▲
by
jsnell
11mo ago
Except that the only people publicizing this bug were the people running the ffmpeg Twitter account. Without them it would have been one of thousands of vulnerabilities reported with no fanfare, no logos, and no conference talks. Doesn'
192.
▲
by
jsnell
11mo ago
It's a codec that is enabled by default at least on major Linux distributions, and that will be processed by ffmpeg without any extra flags. Anyone playing an untrusted video file without explictly overriding the codec autodetection is
193.
▲
by
jsnell
11mo ago
> How are you getting ffmpeg to process a stream or file type different from the one you’re expecting? ... That is how ffmpeg works? With default settings it auto-detects the input codec from the bitstream, and the output codec from the
194.
▲
by
jsnell
11mo ago
> When you publicize a vulnerability you know someone doesn't have the capacity to fix according to the requested timeline My understanding is that the bug in question was fixed about 100 times faster than Project Zero's standa
195.
▲
by
jsnell
11mo ago
Security is adversarial. It doesn't matter whether the users intentionally use the vulnerable codec. What matters is whether an adversary can make the users to use it. Given the codec is compiled in by default on Ubuntu, and given that
196.
▲
by
jsnell
11mo ago
It seems like you might misunderstand what CVEs are? They're just identifiers. This was a bug, which caused an exploitable security vulnerability. The bug was reported to ffmpeg, over their preferred method for being notified about vul
197.
▲
by
jsnell
11mo ago
You're running version 8.0. That's the version where this was fixed.
198.
▲
by
jsnell
11mo ago
> My takeaway from the article was not that the report was a problem, but a change in approach from Google that they’d disclose publicly after X days, regardless of if the project had a chance to fix it. That is not an accurate descripti
199.
▲
by
jsnell
11mo ago
It's actually more like 100x their current revenue; they stated last week[0] that they have spending commitments for $1.4T of compute. Or, well, they stated that the TCO of the compute they have commitments for is $1.4T, which is a som
200.
▲
by
jsnell
11mo ago
That is not a productive way of thinking about it, because it will lead you to the conclusion that all you need is a smarter proof of work algorithm. One that's GPU-resistant, ASIC-resistant, and native code resistant. That's not
201.
▲
by
jsnell
11mo ago
So, this is the report they complained about: https://issuetracker.google.com/issues/440183164 I don't know how a vulnerability report could be much better than that. It is a real vulnerability. The report include
202.
▲
by
jsnell
11mo ago
> To me it looks like zero effort has been made to engage with Mozilla, Apple, etc., on the right way forward here - just Google high-handedly making moves and abusing their position as per usual. What would make you think that? The subm
203.
▲
by
jsnell
11mo ago
There was no breach, which is clear from the first sentence of the article.
204.
▲
by
jsnell
1y ago
There is nothing particularly concerning about the raw numbers, and I'd assume they are correct. (And they are also interesting, since we rarely get data at this granularity. Thanks to Zitron for publishing the leak with such completen
205.
▲
by
jsnell
1y ago
Sure. First, what is tracking? The definition of tracking in this case would be something along the lines of being able to correlate two un-authenticated requests to different domains as coming from the user. It was going to remove or restr
206.
▲
by
jsnell
1y ago
A search query probably uses about 10x more electricity than a matching LLM query. There's enough wiggle-room depending on the assumptions that they might be about even. There is no way search uses 1/1000th of an LLM.
207.
▲
by
jsnell
1y ago
That doesn't match my recollection of the AlphaEvolve release. Some people just read the "48 multiplications for a 4x4 matrix multiplications" part, and thought they found prior art at that performance or better. But they mis
208.
▲
by
jsnell
1y ago
OpenAI don't monetize the vast majority of their users yet. But the unit costs are really low, and once they start monetizing the free tier with ads, they'll be wildly profitable. "OpenAI cannot actually afford to pay $60 bil
209.
▲
by
jsnell
1y ago
Performative cynicism?
210.
▲
by
jsnell
1y ago
Good grief. Apple's official financials. https://www.apple.com/newsroom/pdfs/fy2025-q3/FY25_Q3_Consol... Look, I totally understand making an off-hand comment like you did based on a gut feeling. Nobody
More ›