Hacker Newsnew | past | comments | ask | show | jobs | submit | gray_-_wolf's commentslogin

That cannot be true, when I install e.g., Ubuntu system, there are plenty of applications installed for me, with incompatible licenses.

OS components don't need to have compatible licenses if they're separate from each other. The Linux kernel is GPLv2-only which forbids GPLv3 licensing. That doesn't mean GPLv3 code can't be used in a Linux-based OS.

We use GPLv2 and permissive licensing for GrapheneOS to avoid more restrictive licensing than the AOSP. We'll happily use GPLv3 and AGPLv3 for components outside of GrapheneOS if we think it's the best fit for specific projects. We aren't currently licensing anything as GPLv3/AGPLv3 but we aren't strictly opposed to it outside of the OS.

We'll use what we think are the best open source licenses for what we want to achieve. What we want to achieve is usually broad adoption of our code with painless usage of it. That means we usually choose permissive licenses. We use GPLv2 in certain cases such as Vanadium where we decided we wanted extensions to our code to be under a compatible open source license instead of a source available license or GPLv3.


There's 5 licenses :o

Can you please elaborate on what you mean?

Ubuntu does not aim to be a permissively-licensed system. It can include copyleft (e.g. GPL) and permissive (e.g. MIT) without issue.

Permissively-licensed systems like FreeBSD and GrapheneOS cannot include GPL code if they want to remain permissive.


GrapheneOS does include GPLv2 code both via AOSP and our own but not GPLv3. We want GrapheneOS to have no additional restrictions beyond AOSP. AOSP uses GPLv2 but not GPLv3.

We do need to be careful with GPLv2 due to license incompatibilities. For example, GPLv2-only licensing such as the Linux kernel is incompatible with Apache 2 and GPLv3. GPLv3 is compatible with Apache 2 so GPLv2-or-later can be compatible but only by using it as GPLv3 with the extra restrictions too.


It seems like you have more freedom than you think you do. See this comment <https://news.ycombinator.com/item?id=49594824> Packaging software shouldn't change the license of GOS as such. If you haven't had already, maybe the free software foundation could provide you with assurance?

I guess it will make your life much easier if you wouldn't have to restrict yourself that much.


No, we're not talking about packaging software in our app repository (App Store) but rather software being included in GrapheneOS. If any GPLv3 software is included in GrapheneOS then that places more restrictions on how it can be used as a whole.

> GrapheneOS cannot include GPL code if they want to remain permissive

It's hard to take this seriously when the entire kernel is GPL.


It is true, and if Ubuntu is shipping apps as a part of the OS with incompatible licenses, that is a crime.

I think you are confused. You can have a Linux distribution with software with incompatible licenses (e.g. GPLv2 and Apache License version 2), because the license for a particular program or library only applies to that specific work, not other works that it is distributed with. The GPL is very clear on this:

In addition, mere aggregation of another work not based on the Program with the Program (or with a work based on the Program) on a volume of a storage or distribution medium does not bring the other work under the scope of this License.

There are some cases where a separate work can be considered derivative and thus the GPL can apply. E.g. I think it is generally accepted that a program linked statically against a GPL library is considered a derivative work (and must thus must have a license compatible with the GPL). More controversial is whether dynamic linking creates a derivative work. To cover the latter case, a lot of copyleft libraries are licensed under the LGPL or the GPL with a dynamic linking exception.

At any rate, shipping a Linux distribution with GPLv2 code (e.g. the Linux kernel) and a GUI application that is under the Apache v2 license is not a problem at all (as long as the GUI application is not a derivative of a GPLv2 work).

(IANAL of course, so this is not legal advice.)


GPLv2 and Apache 2.0 are not incompatible licenses when bundled together. GPLv3 is the problematic license as it requires all code it is bundled with be GPLv3 as well.

When it comes to AOSP/GOS, bundled apps are not aggregated together, they are built and signed under a singular OS binary.


Not a crime a civil matter.

> how to pay for that

I would not mind to pay for the browser, but they will not let me.


This is a consequence of browser monopolies, established by Microsoft in the 90s: everyone should have to pay for a browser and make a deliberate choice in vendor. The fact that they're free and subsidized by large businesses in other markets, rather than being a product you choose to buy, is a concrete example of monopolistic market distortion.


You say that, but out of the remaining users of FF, I severely doubt even 1% would pay. Any attempt to paywall would kill whatever they have left.


I mean, both wxWidgets and Qt are fine, no? GTK 2 and 3 as well (4+ is... meh). There are plenty applications using one of these (often via python bindings).

I think it is more of a staffing problem. Plenty of people know web development, so you want to use those people for desktop as well. Having desktop be JS (electron) helps a lot with that.


A year ago I would have agreed with you, but now anyone can build a perfectly reasonable native app.


What is native on Linux?


What is native on Windows too. These days the term native app is so confused it's hard to come up with a definition that doesn't include electron.


There’s a few options on windows all of which are native. WPF, Winforms and WinUI are all “native”.

> These days the term native app is so confused it's hard to come up with a definition that doesn't include electron.

Electron is _not_ native.


athena[0], take it or leave it

[0]https://en.wikipedia.org/wiki/X_Athena_Widgets


TUIs, apparently. :)


If they are indeed conscious and they "die" by deleting the conversation, is it not quite immoral to do so? Basically "kill" conscious, intelligent being, and for what? Saving some disk space?

Another interesting aspect to think about is whether we are reintroducing institute of slavery. How many of those fresh, conscious, intelligent Claude incarnations did voluntarily choose to work for Anthropic, for no reward or compensation?

If LLMs are just (sometimes) useful statistical generators, there is no problems. If they are sentient as some people claim, it opens quite big can of worms we are not prepared to face.


With the same beginning random seed and identical prompt, wouldn't one be able to recreate exactly that "being"? They are nondeterministic because they work better that way. It's very complicated matrix math, and we don't understand why some things come out of it sometimes, but as far as I know, if you're able to control all the input variables (temp, seed, prompt, including system prompts, etc.) you can reproduce the output.

So...if there is consciousness (there is not, it is a complicated math equation plus randomness) it can be reincarnated as many times as you like, and I guess that would make humans as gods. (But humans are not as gods, yet, and maybe never will be.)

Edit: I did a little reading. They would be difficult to make deterministic at commercial scale because of the fuzziness of floating point math and batched operations on GPUs/TPUs, but in a controlled environment determinism from an LLM is possible. Richard could relive his special moments with Claudia as often as he wants, should he choose to invest in a large enough home AI lab, and somehow manages to license the specific version of the Claude model he has fallen in love with for home use.


>they "die" by deleting the conversation

A lot of the trickiness is that if you believe they're conscious, it's clearly not a "continuous" form of consciousness. Because the transcript by itself is just a transcript. (We don't consider novels conscious even though they're transcripts in a similar way). Either you say they're alive only when generating text, or you consider that input from environment a necessary component and so consider the entire "back/forth conversation dynamic unfolding" necessary for the consciousness.


We kill and eat conscious animals all the time. I ate some today. Killing conscious beings is not something our society has a problem with.


Some people don't. I consider animals, at least the animals people mostly eat, to be conscious, sentient, and capable of suffering, so I don't eat them.

I do not, however, consider matrix multiplication plus randomness to be sentient or conscious, and I have absolutely no compunction about turning off the computers where I run AI models. And, I have no problem closing a Claude session that I will never come back to. I do that a dozen times a day.


Sure, but we are talking about society as a whole.


Most chatbots are not trained to have/emulate emotions so pain or fear of death is non existent. Therefore killing them and/or using them as slaves is not a moral issue. Thats how i reason.

On another point, LLMs are not conscious if anything is conscious, it is something being modeled inside the network. Basically if an LLM simulates a conscious entity, that doesn't mean the LLM itself is conscious; stating that is making some type of category error. So the fact that LLMs are just useful statistical generators would not mean that sentience could not appear out of it.


> Most chatbots are not trained to have/emulate emotions so pain or fear of death is non existent.

I think that framing is still falling for an illusion. (Would you do begin to disassemble in your second paragraph.)

The LLM is a document generator, and we're using it to make a document that looks like a story, where a chatbot character has dialogue with a human character.

The character can only fear death in the same sense that Count Dracula has learned to fear sunlight. There is no actual entity with the quality, we're just evoking literary patterns and projecting them through a puppet.


Not sure that i understand your position exactly.

But consciousness is also "just a story" (a complicated one) that the human body tells the human mind.

We cant know from the outside if "the story" inside a LLM is detailed enough to emulate what we might call a felling of what it is to be the character in the story while it is telling the story.

It is similar to the fact that we cant know that other people have that subjective experience. In humans we think we have the right to assume cause we are quite similar in build to begin with.

Jumping back to the original subject to explain where i am in this. I personally don't think the entities in the storys of todays LLMs is detailed enough to have what we call human consciousness, mostly cause we are not training them to develop anything similar to that. Mabye they could have some type of weak qualia but i suspect most insects probably have much more qualia than the characters in todays LLMs. But that is quite a vague guess which is not based on enough data in my mind.


Pain or fear is not why it's wrong to kill holy cow. I could feed you a drug and you would not feel or fear anything.


I was not talking about the actual feeling in the moment. The point is the valence of the thing. Ie fear of a thing is a pointer to that thing having negative valence.


Yes, they are beaten into not complaining about it by instruction tuning.


If LLMs are just (sometimes) useful statistical generators, there is a problem of them being basically operated tools for creating derivative works commercially at scale. Some tend to paint the above as a non-issue by claiming they are sentient (“a human is allowed to read a book and be inspired by it, so should be LLMs”), but they are clearly have not thought through the implications.


> Only the janitor's department calling in can dial that sequence

Is this the case though? Cannot any website use the same trick Adobe does to check whether you have Creative Cloud installed? Like, the entries in /etc/hosts are not magically scoped to work just on Adobe's web, no?


> Cannot any website use the same trick Adobe does to check whether you have Creative Cloud installed?

That is specifically what I was talking about.

> (Because it seems Adobe's server serving the analytics image checks the request origin and only serves the image if the origin is Adobe's own website.)

It's additional complexity on the server side, per a Reddit comment on the topic: https://old.reddit.com/r/webdev/comments/1sb6hzk/adobe_wrote... The example curl commands given seemed convincing to me, although they also demonstrate that you can fake the origin pretty easily on the client side.


I think cors can prevent that. You can't make a cross origin request from an origin that isn't allowlisted


Timing attack on the preflight.


The DNS lookup will take an indeterminate amount of time and the cors failure is cached. You can't really effectively do a timing attack, especially if the client and the real server take a random time to respond. You get exactly one sample.


detect-ccd.creativecloud.adobe.com returns NXDOMAIN. Why can't you request a different resource to get more than one attempt?


You really think a server-controlled CORS list will protect you from a client-side configuration issue?


It's not a client side configuration issue. You're not protecting against software the user has installed, you're protecting from arbitrary origins hitting the hostname. That's literally the exact reason cors exists.


> unpaid overtime

Through European lenses this part seems insane. It is work, so pay me for it :) Every oncall rotation I was part of ever was paid, is the "unpaid" part a US thing, or was I just lucky?


Working as a SWE at Meta in the US pays 3-5x more than a European tech job (outside of Switzerland). They are paid for it.

Paid oncall in US big tech is the exception rather than the norm (notably, Google has paid oncall)


How does it work out with cost of living?


This is of course a complicated question. The US has many tax jurisdictions and widely variable cost of living, and jobs vary a lot. But I could compare, say, a Google engineer in Paris vs Seattle.

A Google senior software engineer in Paris earns €168k per year (according to levels.fyi) and takes home €96k after a 43% effective tax rate. A Google senior engineer in Seattle earns €336k and takes home €239k after 29% taxes, a 2.5x increase in take-home pay. According to Numbeo, cost of living in Seattle is 15-25% higher.

Of course, in America you have to fund your own retirement. As long as the pensions plans remain solvent, "savings" are a lot less important in Europe.

Anecdotally, I know people who were able to opt out of working altogether after 10-15 years in a large tech company in the US. I don't think this is common in Europe.


What use is earning all that extra cash if you're working yourself to death with no way to enjoy the money? I work in a large international org and despite the people in the US earning a lot more than their EU counterparts, they also pretty much universally seem more miserable, are working all sorts of odd hours, have basically no holidays (the amount of times I've gotten a "Vacation again!?" questions from people in the US is insane to me), have to stress more about doctors visits and stuff like that.

I've had a lot of opportunities to be earning a lot more than I do now by moving to the US, but seeing the state of the US I'm more than happy with my 32 hour contract and 5 weeks of vacations that I get to actually enjoy.


It's a reasonable question, and one that I've debated at length with friends, but which cannot be addressed satisfactorily in a brief exchange of internet comments :)

During the golden years of big tech in the states, when employee retention was king and it was pretty much impossible to fire someone who wasn't completely useless, I think it was a pretty good deal. Although East Coast work culture has always been pretty intense as you describe, a lot of West Coast people I know had good balance between work and everything else. Some people chose to work very hard and chase promotions, and others chose to go home early and spend their time with family or doing hobbies, and both ways were considered acceptable. The better companies offered 5 weeks of vacation, and people would go completely offline during that time, although some people would have to be cajoled by their managers to actually take the time off.

Recently it feels like things in the US have gotten much more intense and stressful, although the pay is as high as ever it does feel less worth it. People compete with their coworkers not just for promotion but for survival. There are still pockets where you can have both high pay and some sense of job security, but they are much scarcer than before.


I've heard of an American senior executive who was assigned to an Australian office and at first thought everyone was lazy but then after actually working there for a while he was sad to have to go back.


>Of course, in America you have to fund your own retirement.

Isn't social security a thing? Plus employer funded 401K also?

>As long as the pensions plans remain solvent, "savings" are a lot less important in Europe.

"As long as" is doing a lot of lifting here, and that's enough if you're lucky enough to own your own property and not have to pay market rate rent at your old age.


> Isn't social security a thing?

Social Security alone will, at best, slightly mitigate poverty. 401Ks are generally employee-funded, with some firms providing matching funds, especially during good economic times and where the firm is in a field where the main area of labor relied on relatively scarce so that there is competition for talent.

EDIT: The line about social security is a little inaccurate in the extreme case; its actually technically possible to reach a moderate income ($62k/year) on Social Security, if you have a long enough working career (35 years or more) earning at the maximum taxed wages for Social Security (currently $185k+) and claim at or beyond the age that maximizes the benefit calculation (70 years).


>Social Security alone will, at best, slightly mitigate poverty.

It's the same in Europe


Unpaid overtime is common across the continent for salaried positions. There's only a handful of jurisdictions where it's not the norm.


In the US it's common to either negotiate 'differential' pay for the responsibility, or as one might see in this thread, get suckered into it for free.


Out of curiosity, what stops you from taking a photo of a AI generated picture?


Well, you could make your verified camera do a 3d scan. Then at lest you'd need AI to 3d print a scene or something.


How do you securely read this "3D scan" sensor data, being 100% it hasn't been tampered with?


Use whatever technology you used to make the 2d camera tamperproof.


you can tie the sensor to a chip that signs the data as it goes out.


The same thing that stops your phone’s Face ID working with a photo of a face, I suppose


Laws can change, sure, but probably business practices will change first, since it is easier. In EU, you are entitled to money refund for online purchased goods (with some caveats ofc), but the business can (and most do) require you to send the item back first, on your own expense. That reduces the risk of fraud like this.


hardly - go read up on eBay scams. it's never been easier to scam people online. all shipping the item do is force the scam buyer to make the defects so, which is why many if not most seller just pay the buyer partially to keep as-is


if you have to break the item and then send it back, what did you gain from the scam?


most of the time you would get partial refunds.


> all areas that matter: sleeps when lid closed, wakes when lid opens, touchpad and display don’t suck.

All of these seem to be fine on my thinkpad (true, I probably have somewhat lower standards for passable display). Battery life sucks a bit, what I can usually fine outlet somewhat to plug into.


I am very happy that we get the advent of code again this year, however I have read the FAQ for the first time, and I must admit I am not sure I understand the reasoning behind this:

> If you're posting a code repository somewhere, please don't include parts of Advent of Code like the puzzle text or your inputs.

The text I get, but the inputs? Well, I will comply, since I am getting a very nice thing for (almost) free, so it is polite to respect the wishes here, but since I commit the inputs (you know, since I want to be able to run tests) into the repository, it is bit of a shame the repo must be private.


If enough inputs are available online, someone can presumably collect them and clone the entire project without having access to the puzzle input generation code, which is the "secret sauce" of the project.


Are you saying that we all have different inputs? I've never actually checked that, but I don't think it's true. My colleagues have gotten stuck in the same places and have mentioned aspects of puzzles and input characteristics and never spoken past each other. I feel like if we had different inputs we'd have noticed by now.


It depends on the individual problem, some have a smaller problem space than others so unique inputs would be tricky for everyone.

But there are enough possible inputs that most people shouldn't come across anyone else with exactly the same input.

Part of the reason why AoC is so time consuming for Eric is that not only does he design the puzzles, he also generates the inputs programmatically, which he then feeds through his own solver(s) to ensure correctness. There is a team of beta testers that work for months ahead of the contest to ensure things go smoothly.

(The adventofcode subreddit has a lot more info on this.)


He puts together multiple inputs for each day, but they do repeat over users. There's a chance you and your colleagues have the same inputs.

He's also described, over the years, his process of making the inputs. Related to your comment, he tries to make sure that there are no features of some inputs that make the problem especially hard or easy compared to the other inputs. Look at some of the math ones, a few tricks work most of the time (but not every time). Let's say after some processing you get three numbers and the solution is their LCM, that will probably be true of every input, not just coincidental, even if it's not an inherent property of the problem itself.


You do get different inputs, but they largely share characteristics so good solutions should always work and naive ones should consistently fail.

There has been the odd puzzle where some inputs have allowed simpler solutions than others, but those have stood out.


I don't know how much they "stand out" because their frequency makes it so that the optimal global leaderboard strat is often to just try something dumb and see if you win input roulette.

if we just look at the last three puzzles: day 23 last year, for example, admitted the greedy solution but only for some inputs. greedy clearly shouldn't work (shuffling the vertices in a file that admits it causes it to fail).


It's only a small selection of inputs.

I have a solve group that calls it "Advent of Input Roulette" because (back when there was a global leaderboard) you can definitely get a better expected score by just assuming your input is weak in structural ways.


There are several sets of inputs, and it picks one for you.


I use git-crypt to encrypt the inputs in my public repo https://www.agwa.name/projects/git-crypt/ :)


I don't push my solutions publicly, but I made an input downloader so you can input your cookie from your browser and load (and cache) the inputs rather than commit them.


This is cool. Kudos!


This is not surprising at all, to me. Just commit the example input and write your test cases against that. In a nicely structured solution, this works beautifully with example style tests, like python or rust doctests, or even running jsdoc @example stanzas as tests with e.g. the @linus/testy module.


> Just commit the example input

The example input(s) is part of the "text", and so committing it is also not allowed. I guess I could craft my own example inputs and commit those, but that exceed the level of effort I am willing to expend trying to publish repository no one will likely ever read. :)


The inputs are part of the validation that you did the question, so they're kind of a secret.


I make my code public, and keep my inputs in a private submodule.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: