Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
david_shaw
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
david_shaw
8d ago
> I like that we are talking about prompt injections from you to your personal assistant. Obviously I know what they are for, but still, it's so funny that we've just normalized building software adversarial to the consumers s
2.
▲
by
david_shaw
8d ago
> I think the product as shown in this marketing material with these examples falls squarely in the “nobody asked for this” territory of AI. I agree. The time to launch something like this would have been during the OpenClaw hype cycle
3.
▲
by
david_shaw
12d ago
Let's take a moment to talk about the monetary value of this vulnerability. According to the Chrome release page ( https://chromereleases.googleblog.com/2026/09/stable-channel... ), Google paid a researcher $10
4.
▲
by
david_shaw
12d ago
It's not that I don't trust Quad9 or dns.sb or any of the others, it's just that I trust Mullvad more. Sad to see this going away, but I assume this is so Mullvad can focus on their primary services.
5.
▲
by
david_shaw
12d ago
Sure: maybe explicit warnings about the risks would help. But peer pressure is a hell of a motivator if everyone's using these networks. I think young people -- especially teenagers -- already talk enough about "brainrot" to
6.
▲
by
david_shaw
15d ago
I hate to change the subject to something so trivial -- because I have been an exclusive Firefox user for many, many years -- but the awful moving background of this website is literally nauseating. I'm no designer, but I can't un
7.
▲
by
david_shaw
21d ago
I have a lot of respect for Trail of Bits, and I'm sure that Artem is thinking about this correctly. However, I respectfully disagree with the premise. AI agents are not magic. Mythos/Glasswing does not magically create vulnerabil
8.
▲
by
david_shaw
23d ago
> Edit: Actually trivial to test, just save an image of all black and see if it suddenly has other values on save. Did it?
9.
▲
by
david_shaw
1mo ago
We're going to see more of this before we see, hopefully, substantially less of it. What I'm seeing now in industry -- and I think this autofix issue is a precise example of it -- is a natural evolution of the "LGTM!" re
10.
▲
by
david_shaw
2mo ago
I said this about OpenAI/Hugging Face, and I'll say it again for Anthropic: It's not that I think this is fiction; I'm confident these events actually happened. But I think they were effectively allowed to happen becau
11.
▲
by
david_shaw
2mo ago
I don't think this is fiction, but it's pretty clearly a marketing-release rather than a normal security disclosure. OpenAI has strongly fallen behind after the incredible lore surrounding Mythos/Glasswing security capabiliti
12.
▲
by
david_shaw
3mo ago
At risk of quoting too much of the article, it opens with this: > A requirement for staying sane while working in public as an open source maintainer is realizing that every issue, PR, and piece of feedback is a present, not an obligati
13.
▲
by
david_shaw
3mo ago
I'm playing through the couch co-op game Split Fiction, and this is basically the premise (with more fun gameplay).
14.
▲
by
david_shaw
3mo ago
> A nation that possesses powerful AI facing one without it—or even facing one that is behind in AI by 3 years—could be the equivalent of an army of World War II Marines facing an army of medieval swordsmen. This is a somewhat ironic t
15.
▲
by
david_shaw
3mo ago
> we might have wished we prepared for more Do you mean policy-wise (like Dario is talking about), or more broadly? I wonder about broad preparedness, but unfortunately there's not a lot that we "normal" people can do to
16.
▲
by
david_shaw
3mo ago
> Members of the trusted coalition should freely share chips and semiconductor manufacturing equipment (SME) with each other, while working together to deny it to adversaries. US export controls on frontier chips and SME to China have b
17.
▲
by
david_shaw
4mo ago
The problem with Mythos and Glasswing related hype is that finding vulnerabilities isn't the problem for most organizations. It's great that Mythos and similar models can find vulnerabilities that remained undetected (and hopefu
18.
▲
by
david_shaw
4mo ago
The Fallout games often exemplify this: nearly every decision you make is morally ambiguous, and often has far-reaching repercussions in the story and world.
19.
▲
by
david_shaw
4mo ago
> https://www.openbsd.org/images/PinkPuffy.png > Apparel (t-shirts, so far): https://openbsdstore.com/ Interesting. In the image you linked (PinkPuffy.png), the cat's hat says "securi
20.
▲
by
david_shaw
4mo ago
He certainly popularized it (maybe coined it), but I've seen a lot of organizations and developers repeat that mantra. Even without the specific words, look to product teams debating tradeoffs of going to market vs. waiting for bette
21.
▲
by
david_shaw
4mo ago
It's easy to be cynical because, yes, both the problems and solutions seem dead obvious in hindsight. But for a long time (and maybe even still), a hacker creed was "move fast and break things." It's great that there
22.
▲
by
david_shaw
5mo ago
We'll see more of this, but this particular review is driven by marketing narrative. I'll explain what I mean: Back in 2010, as a security engineer, I also looked at OpenEMR. It was an absolute disaster, and was (and is) somewha
23.
▲
by
david_shaw
5mo ago
I think the idea is that if you're given an improperly configured restricted shell/command access, you can use any of the listed tools to gain access to some subset of what that user would normally have access to in an unrestricte
24.
▲
by
david_shaw
5mo ago
I don't have a subscription to The Economist, but I was interested in the concept of these organizations as "neo-primes." I found an article on The Cipher Brief describing them: https://www.thecipherbrief.com/
25.
▲
by
david_shaw
5mo ago
> If it were secure, it would only notify that there is a message, with no details included. You're right. This is configurable via settings, but is not the default state. That said: if I can get friends and family to use Signal i
26.
▲
by
david_shaw
6mo ago
I think the title should read "RunAnywhere," not "RunAnwhere."
27.
▲
by
david_shaw
7mo ago
It would be an interesting and potentially useful project to combine these camera locations with Maps routing -- similar to "avoid toll roads," we could "avoid surveillance cameras."
28.
▲
by
david_shaw
7mo ago
It's wild that all other comments in this thread (so far) seem to completely miss this nuance. There are lots of services that, in their terms, require users to be adults. This type of age "identification" is a lot different
29.
▲
by
david_shaw
7mo ago
I'd prefer to see board (or executive) level signatories over lay employees -- the people who can enforce enterprise policy rather than just voice their opinions -- but this is encouraging to see nonetheless. I can't help but noti
30.
▲
by
david_shaw
7mo ago
> What does "solving" coding mean? Maybe this was sarcasm, but it's a good point: "Coding" is solved in the same way that "writing English language" is solved by LLMs. Given ideas, AI can generate acc
More ›