Hacker Newsnew | past | comments | ask | show | jobs | submit | acoustics's commentslogin

Lots of people are saying agentic cyberattacks are a marketing hoax. The argument is that either AI is not capable enough to carry out these attacks, or that it would not carrying out these attacks without nudging from the labs, or even that somebody told it to do cyberattacks and the companies are baldly lying. My question is: what evidence would cause you to change your mind about this?

I'm not even saying it's an incorrect position. But to take the claim seriously and act accordingly, it needs to be falsifiable.

AI boosters and detractors alike often hedge their claims so that whatever ends up actually happening, they can say they were right all along. When that happens, the discussion boils down to people saying "yay AI" and "boo AI" at each other without exchanging any substantive information.


I don't particularly believe this (I'm not an expert in anything computer-y, let alone security, so the only thing I know is that people who seem respected here (like simonw) point out that the sandbox from OpenAI was at least very badly designed, but who knows why that is), but here's one piece of possible evidence: if something similar causes so much damage that it ends up obviously hurting the company responsible. This could be something like targeting a big bank and causing so much disruption that the law wakes up and immediately intervenes, or it could be major damage to the company's own systems.

Of course, if that happens, this whole discussion becomes moot, and good luck to us all...


Really? I thought Maps was pretty constistently up to date with GNIS changes.


GMaps can be extremely slow when it comes to responding to user reports, or updating regional info like road networks or new subdivisions. A lot of that comes down to the fact that Google relies on government entities for authoritative information, which can mean waiting months or years for the local government to provide new info. The federal government updated this one quickly.


In my local area Google Maps is still missing some rather crucial elements of a high-throughput road, which were added to OpenStreetMaps almost two years ago.


What would be a valid basis for relabeling a shared body of water for US users?

Would it be based on popular usage? The procedure by which it changed? Maybe we distinguish between bicameralism and presentment, an executive order, and the discretion of a bureaucrat. Or do we normally take the government database at its word but treat this as a sui generis "this guy is being an asshole" exception?

Not trying to interrogate you specifically. I am pondering these questions myself. I don't like that the name changed but I'm hard pressed to think of a good neutral policy that doesn't also sweep up a bunch of (far stickier) renaming situations around the world.


I'll elaborate on my opinion. I think that asking for a single universal rule that seemingly impartially decides how to display certain names shows that I conveyed what I meant too indirectly. Asking for a universal rule on map labeling is like asking someone to design a universally applicable test that can be taken by both a human and a gorilla. Universal rules will never work or be impartial because you can't assume everyone is a well-intentioned actor.

The real solution here is for Google to decide on their values. What they think is right, why they think that, and who they back because of it. Only that would help them distinguish between genuine conflicts and a temper tantrum, both domestically and internationally.

Of course, doing this would be extremely controversial and as a corporation they would never go for it anyway. What it would do is show their position to the world openly and let people judge them on that merit and decide if they really want to work with them. Applying universal rules that 'accidentally' happen to help a certain side is just as much of a political and ideological choice as what I've suggested above, it's just a lot more wishy-washy and coated in a pretense of rationality.


jj has made me much more comfortable using non-linear DAGs in my trunk-based development workflow. Several changes with the same parent, changes with several different parents, etc.

I used to have a habit of imposing an unnecessary ordering structure on my work product. My stack of changes would look like A -> B -> C -> D, even if the order of B and C was logically interchangeable.

jj makes DAGs easier to work with because of how it handles conflicts and merges. Now I feel empowered to be more expressive and accurate about what a change actually depends on. In turn, this makes review and submission more efficient.


Do you use a mega-merge + absorb workflow on top of the faned-out changes?


How is any kind of antivirus or threat detection software supposed to operate on this standard?

Libel suits can be financially catastrophic, so even a tiny false positive rate could present risk that disincentivizes producing such software at all.

And a threat detection mechanism that has a 0.0% false positive rate is conservative to the point of being nearly useless.


I think that is the idea. They shouldn't exist without a prompt mitigation path.

In other words, if you can't deal with the false positives in a timely manner. You SHOULD be liable for the damages.

I can't build a budget car put together in an unsafe manner. Then complain I can't compete due to all the peoples cars crashing and blowing up and suing me.


You document your claims with concrete evidence of fraud. That will be your libel defense. No evidence means you bear the full responsibility of a fuckup.


At internet scale, this would roughly be equivalent to not doing any warning or detection at all.

Scalable systems need to use heuristics to catch threats. Needing concrete evidence in every case means that an enormously higher amount of malicious resources will not be flagged.

There is a policy argument as to the right balance of concerns here. But there is a clear trade-off to make.


Then that heuristic is your evidence in court. If it's a good heuristic, you win the case. If it's a bad heuristic, you lose the case.

"Your Honor, we banned this person's website because his web page contained the word 'bitcoin' more than 5 times" will not hold up.

"Your Honor, we banned this person's website because it contains a bitcoin miner script. See, here is the script, and it matches the hash value found in these other attacks" hopefully holds up.


No one elected Google to be the internet police. Why should we legally protect vigilantism on the web any more than we do in real life?


> Needing concrete evidence in every case means that an enormously higher amount of malicious resources will not be flagged.

Giving everyone a fair trial just doesn't scale. It costs too much.


It seems that many people lean into the "community" aspect of open source. In real communities there are webs of mutual responsibility. If you use open source to fill the role of community in your life, it makes sense psychologically that you would project moral stakes or obligation onto the maintainers. But this is really not fair to the maintainers who don't view their work that way.


> RISC-V doesn't make sense to 99% users at this stage.

Agreed. Boards like this are helpful for getting RISC-V to the next stage, where it could make sense for more users.


I'm not sure if it's true that the leader is less powerful.

In many countries, it seems that the leader has near total control over candidate selection, and dissent is punished ruthlessly.

In the US, it's easier for a member of Congress to openly dissent against the President's agenda. This was a major thorn in the side for e.g. Joe Biden.

Some Republicans today fear dissenting (though of course, most are enthusiastically on board), but I'm not sure that it would be any different in a place like Canada or the UK.


I thought QPR2 and QPR4 were the only releases anyone cared about regardless.


People should be able to get cash transfers to buy goods on the general market. There shouldn't be food stamps.

The success of SNAP comes despite its inherent inefficiency, friction, and the indignity of its limitations. We structure the program the way we do in order to mollify voters who twitch at the idea of the poor ever enjoying anything.

Inequality isn't just about healthcare costs, biological metrics, etc. It is also deeply corrosive socially and psychologically, and this side of things is systemically underappreciated in policy circles.

To be sure, our food and diets are bad. Americans broadly should eat healthier. But are society's interests really better served by insisting that a poor child not be allowed to have a cake and blow out the candles on his birthday, the way all of his friends do?


In California you can use food stamps for fast food.

I haven't been there in a while so it might be different now.

Let's think about it.

Your homeless or in an unstable living situation. You don't have access to a kitchen, where are you going to make a home cooked meal.

How are you going to prepare raw chicken without a stove. Some homeless encampments do have people trying to cook, which sounds neat until a fire starts.

Let someone down on there luck buy a sandwich with SNAP. Maybe a shake too. Keeps the fastfood franchise in business, keeps people employed there.

The money is going to flow right into the local economy. I'd rather my tax dollars stay here than funding military bases all over planet earth.

I agree with you though. Just give people money. I feel like a UBI is the way to go. A single Flat tax rate for everyone. Everyone gets 1000$ a month( just off the top of my head, could be higher or lower).

The bizzaro welfare cliff... If you and your partner have kids it can be smart to not get married and have the kids live with whoever makes less.

They get free healthcare with the less affluent parent and you just hope you don't get sick.


In California you can also use food stamps at farmer’s markets with a 50% discount.


It seems unnecessarily reductive to insist that we must choose between endlessly subsidizing Mountain Dew and Twinkies or that poor children should never be allowed to have cake.


Mountain Dew and Twinkies are bad for your health regardless of your income level. We should tackle unhealthy eating by going after the supply, not by going after a class-segmented group of consumers.

Like many Americans, I grew up in a town where unhealthy eating was a major part of the social rhythms of life: a bag of buttery popcorn at the movie theater, an ice cream at the zoo, things like that. Not having the means to participate in these simple pleasures is a kind of social deprivation. I view redistributive programs as a tool to lessen the gap between families. Food regulators can handle the junk food problem.


The moral calculus is not the same.

I don't think we have an obligation to legislate everyone's health, but I do think it's a higher ask when we're talking about explicitly subsidizing bad choices for people most vulnerable to making them. I don't think we should subsidize cigarettes for poor people, either, even if that means they are still accessible to rich people in a way that's perceived as unfair.

And besides: people of high incomes already disproportionately avoid these highly processed foods, so it's not like we're hoarding the wealthy pleasures of Mountain Dew and Twinkies just for them.


I agree that we should not provide targeted subsidies for Twinkies, Mountain Dew, or cigarettes. The whole premise of food stamps is flawed. We should provide cash instead.

If there is an objection that giving cash is equivalent to subsidizing Twinkies, I would push back. Child tax credits are in many ways economically equivalent to cash transfers, but we don't usually see arguments that this is a subsidy for Mountain Dew.


Honestly when it comes to SNAP there's no good answer that achieves all of the reasonable policy goals ('make sure the kids have something to eat', and 'avoid wasting benefit money on crap')

You can replace it with cash aid, and there's a good chance a good chunk of recipients will spend most of it on drugs, lottery tickets, or alcohol while the kids go hungry.

On the other hand, you can have the way it is now, where the same kind of person who would do the above, sells $200 worth of SNAP benefits to whatever corrupt bodega owner in exchange for $100 to spend on drugs, lottery tickets, or alcohol while the kids go hungry.

In both situations the government is spending $200 to buy the poor harmful vices. We're just choosing between fraudster shop owners getting a cut, or the addict being able to buy twice as much malt liquor.

And in case it isn't clear, I don't think the majority of SNAP recipients sell their benefits or don't feed their kids. But the responsible group, well, it makes little difference to them whether they have EBT or cash aid as they're going to buy food anyway.


> We're just choosing between fraudster shop owners getting a cut, or the addict being able to buy twice as much malt liquor.

I don't agree with these zero friction in a vacuum takes. Difficulty in access does shape choices, a lot in fact.

If you make it easier for people to use handouts to gamble or do drugs or whatever then more people will do it and ones doing it will do more of it. This isn't even a take its the null hypothesis.


The null hypothesis could just as easily be if they get a 1:1 dollar exchange rate versus a 1:2 rate on their food stamps, they can afford to buy drugs AND food instead of just drugs. Guess which one they buy if they can only buy one? Guess what they are incentivized to do if they have less cash than they need on hand to do both? I'll give you a hint, it rhymes with teal.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: