Forwarded from HN Best Comments
Re: He asked AI to count carbs 27000 times. It couldn't give the same answer twice
> But the author just took pictures of food & expected a realistic response?
There are very popular apps on the App Store right now that are going viral among non-techie people that do exactly this, and they have no concept of how AI works. My wife was talking about one and I had to give her a reality check that the AI had no idea what ingredients were used to make the food. And she's a licensed nutritionalist.
Studies like this create something to point at for people who are confused and serve as a springboard for a conversation in the media.
kalleboo, 3 hours ago
> But the author just took pictures of food & expected a realistic response?
There are very popular apps on the App Store right now that are going viral among non-techie people that do exactly this, and they have no concept of how AI works. My wife was talking about one and I had to give her a reality check that the AI had no idea what ingredients were used to make the food. And she's a licensed nutritionalist.
Studies like this create something to point at for people who are confused and serve as a springboard for a conversation in the media.
kalleboo, 3 hours ago
🤣4❤1
Forwarded from HN Best Comments
Re: Cloudflare to cut about 20% of its workforce
I’ve seen managers hiring people with an intent to lay them off when winds change to protect themselves and their close circle. I can only imagine they’ve had great KPIs in both cases: first for scaling the team, and then for cutting costs.
scott01, 8 hours ago
I’ve seen managers hiring people with an intent to lay them off when winds change to protect themselves and their close circle. I can only imagine they’ve had great KPIs in both cases: first for scaling the team, and then for cutting costs.
scott01, 8 hours ago
🤣7💅3
Forwarded from HN Best Comments
Re: AI is breaking two vulnerability cultures
This has been a very long time coming and the crackup we're starting to see was predicted long before anyone knew what an LLM is.
The catalyst is the shift towards software transparency: both the radically increased adoption of open source and source-available software, and the radically improved capabilities of reversing and decompilation tools. It has been over a decade since any ordinary off-the-shelf closed-source software was meaningfully obscured from serious adversaries.
This has been playing out in slow motion ever since BinDiff: you can't patch software without disclosing vulnerabilities. We've been operating in a state of denial about this, because there was some domain expertise involved in becoming a practitioner for whom patches were transparently vulnerability disclosures. But AIs have vaporized the pretense.
It is now the case that any time something gets merged into mainline Linux, several different organizations are feeding the diffs through LLM prompts aggressively evaluating whether they fix a vulnerability and generating exploit guidance. That will be the case for most major open source projects (nginx, OpenSSL, Postgres, &c) sooner rather than later.
The norms of coordinated disclosure are not calibrated for this environment. They really haven't been for the last decade.
I'm weirdly comfortable with this, because I think coordinated disclosure norms have always been blinkered, based on the unquestioned premise that delaying disclosure for the operational convenience of system administrators is a good thing. There are reasons to question that premise! The delay also keeps information out of the hands of system operators who have options other than applying patches.
tptacek, 9 hours ago
This has been a very long time coming and the crackup we're starting to see was predicted long before anyone knew what an LLM is.
The catalyst is the shift towards software transparency: both the radically increased adoption of open source and source-available software, and the radically improved capabilities of reversing and decompilation tools. It has been over a decade since any ordinary off-the-shelf closed-source software was meaningfully obscured from serious adversaries.
This has been playing out in slow motion ever since BinDiff: you can't patch software without disclosing vulnerabilities. We've been operating in a state of denial about this, because there was some domain expertise involved in becoming a practitioner for whom patches were transparently vulnerability disclosures. But AIs have vaporized the pretense.
It is now the case that any time something gets merged into mainline Linux, several different organizations are feeding the diffs through LLM prompts aggressively evaluating whether they fix a vulnerability and generating exploit guidance. That will be the case for most major open source projects (nginx, OpenSSL, Postgres, &c) sooner rather than later.
The norms of coordinated disclosure are not calibrated for this environment. They really haven't been for the last decade.
I'm weirdly comfortable with this, because I think coordinated disclosure norms have always been blinkered, based on the unquestioned premise that delaying disclosure for the operational convenience of system administrators is a good thing. There are reasons to question that premise! The delay also keeps information out of the hands of system operators who have options other than applying patches.
tptacek, 9 hours ago
👍2
Forwarded from ‡ | słobožanśka shitposterka | ✙ | #УкрТґ (Катря 🥔)
Media is too big
VIEW IN TELEGRAM
😱6❤1
Forwarded from Оборонка
🇺🇦Українська DevDroid вдвічі збільшила автономність власних НРК завдяки генераторам
Сам генератор не буде безпосередньо приводити НРК у рух. Він заряджатиме батареї не лише під час зупинки чи на позиції, але й під час руху робота. Заряджання відбуватиметься за командою оператора, який оцінюватиме рівень заряду батарей. Команда на запуск пристрою виведена на планшет керування.
👉 Детальніше — за посиланням
@oboronka
"Зараз 99% НРК на ринку працюють на електриці. Але ми прогнозуємо, що вже на зламі 2026 і 2027 років кілл-зона на фронті зросте з 20 до 50 кілометрів. Буде багато місій, де роботам доведеться долати маршрути 50 км на позиції і 50 км назад. Зробити такий запас ходу на електриці буде дуже дорого", – пояснює мотивацію встановлення генератора на НРК керівник DevDroid.
Сам генератор не буде безпосередньо приводити НРК у рух. Він заряджатиме батареї не лише під час зупинки чи на позиції, але й під час руху робота. Заряджання відбуватиметься за командою оператора, який оцінюватиме рівень заряду батарей. Команда на запуск пристрою виведена на планшет керування.
👉 Детальніше — за посиланням
@oboronka
🔥3🤔1
Windows 11: Я залогинился новым юзером с экрана логина (прошлый юзер был разлогинен), а оно после входа на несколько секунд показало мне содержимое рабочего стола прошлого юзера
👍4
Forwarded from кошька
The crusader kings reddit is the closest the white man can come to entering the mind of the average Pakistani.
😁10👎2🥰1
Forwarded from Чемпіонат Файних Хлопців
Є просто люди, є кмітливі чуваки, а є - легенди
https://www.bbc.com/news/world-asia-49708570
https://www.bbc.com/news/world-asia-49708570
Bbc
New Zealand: Man brings clown to redundancy meeting
Josh Thompson took a clown to a work meeting as a "support person" when he was about to lose his job.
😁5❤2