Hacker Newsnew | past | comments | ask | show | jobs | submit | mwwaters's commentslogin

The Windows 11 ISO on a two year old Lenovo laptop did not have the Ethernet or WiFi driver. “Have Disk” also did not work for whatever reason when I downloaded the driver to a USB drive. I had to open up a command prompt within the Windows installer and run the GUI driver installer.

In Linux, I now have a custom Arch install which Gemini did help with a lot. It helped unblock significantly where I wanted to get fundamental understanding. A Debian installer will just work though (ironically, some years ago, I had issues with Ubuntu working out of the box but not Debian).


The passkey method uses Bluetooth to ensure proximity.


The far bigger benefit is phishing resistance (with hardware-contained keys themselves being phishing-proof on a non-compromised system).

It moves to the account recovery flows, but that can be much more difficult to phish.


Why would a key need to be "hardware-contained" to be difficult to phish? My SSH private key is unphishable and it's right there in a file. It's unphishable because I know there's never ever a reason to send it to someone - in a scenario where that would be needed, I'd generate a new key just for that situation.


Desktop operating systems don't have very good separation between programs. If some malware gets access, it will be looking for e.g. ssh keys and using a keylogger to get the passphrase if you encrypted your ssh keys. Tpm protected passkeys are much better protected


That attack isn't phishing


The first FRED link shows how noisy that subgroup is. It’s bounced around with 83-84% during that time. It was 83.8% in March and 83.5% through much of 2024.


OAuth first and foremost is driven by getting secret information from, let’s say, Big Company. It’s understandable that there are many steps for some random Joe to get Google emails or Facebook DMs.

OpenID piggy-backed on it by layering on new terms to an already complex scheme. The precious, secret information from Big Company in OpenID is just Email and maybe Name and Profile Picture. Then there’s a lot of ceremony for the service using OAuth to securely get that big secret (the user’s Email, which they had to supply in the first place directly to Relying Party).


When I really dove into it, I understood mostly why all the complexity was all there if I cared about data at the identity provider.

When it’s only used for SSO, it’s extreme overkill.


That is for whatever it considers reverse-engineering the model to try to create a competing one.


No, that’s for “frontier LLM development” which somehow includes examples like distributed training infra.

Based on how sensitive the classifers are, any data scientist / MLE is probably going to encounter cases where some silent degradation happens and you never know about it.


It does nothing to protect against distillation attacks, because distillation attacks are far less interested in the topic of AI research than just generally getting tons of diverse output from the model. It might be that Mythos was (accidentally?) trained on internal Anthropic documentation on how Mythos was trained, and thus it could leak secret sauce? Doubtful; it feels like its less about the specific attack of reverse-engineering Mythos, and more about being a general sophon against any model training at all; that Anthropic's official position is now that they're the only ones who should be training models.


No, it's not about reverse engineering. It targets ML research.


The “enough of us” is at least a majority of voters agreeing. I’m not sure what the alternative to that is.


For doing some reporting stuff internally, there isn’t a certification. But there are definitely humans who have to certify financial statements and communications for financial offerings.


SLAAC and link-local is very different from DHCP/NAT/etc. in IPv4 world. Link-local addresses are pretty arcane in IPv4 while they are a central idea in IPv6.

That’s fine. As pointed out elsewhere, DHCP was relatively new when IPv6 was introduced. But it is a learning curve well past just knowing the difference between NAT and stateful firewall.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: