Hacker Newsnew | past | comments | ask | show | jobs | submit | tptacek's commentslogin

This piece would have been better if it had just been the prompts used to generate it. The entire underlying story is just "company does discretionary RIF".

Some of these generated stories pay their freight on HN, because they develop genuinely interesting technical[†] ideas (I'd still like to see the prompts, if I can't get the story in the author's own words). But when the story contains essentially no interesting content, it starts to make sense to consider them off-topic.

usually! I'm equally into genuinely interesting LLM-generated explanations of thoughts on modernist poetry, I guess.


This isn't true. Your body breaks sucrose into fructose and sucrose almost instantaneously; in fact, sucrose is so easy to break down that it happens in Coke bottles. Fructose is bad for you, but you're getting just as much of it from table sugar as you would from HFCS.

Is it really a long running instruction? I mean, obviously yes, but what makes it slow is that it's doing an MMIO copy from a slow source. It's like a read(2) system call being "slow" because the fd is associated with a socket to the moon.

It's an instruction in the sense that timing boundaries are x86 instruction boundaries, which is what the security model bases itself on. So yeah, not an instruction in the strict CPU sense (microcode + micro-ops), but in the useful sense.

Yes, capitalism is pretty great? The one complaint I have never really seen anyone seriously aim at capitalism before today is "capitalism is an inferior system for the delivery of hyperpalatable junk food".

No. They're metabolically equivalent. "High fructose" corn syrup is "high" relative to normal corn syrup, not relative to sugar, some of the HFCS formulae in packaged food has less fructose than table sugar, and, most importantly, your body is a well-oiled machine at breaking down sucrose, which is cleaved enzymatically immediately upon it entering your gut; there's no material slowdown in digestion from eating sucrose.

(The key thing to remember is that sugar is bad for you; it's not that HFCS is good, but rather that cane sugar is just as harmful.)

Two fun additional notes:

* There's a video somewhere showing how cane sugar breaks down into fructose and glucose in bottled sodas anyways, and

* Perhaps unsurprisingly, taste testers can't reliably distinguish between HFCS and cane sugar formula Coke.


Yeah, a big part of the flavor difference between Mexican Coke and American Coke really comes down to the extra sodium in the Mexican Coke variety.

You can get the US formula coke with cane sugar during Passover in markets with a high Jewish population. Taste it, it'll be practically the same as HFCS US Coke and not like Mexican Coke. Because, it has the same amount of salt as the US variety.


The bigger difference, imo, is that Coke just tastes better out of a glass bottle. Orifice size and shape makes a big difference in taste and mouthfeel.

And also the idea that H1 "training" models based on bug bounty reports is kind of a silly concern; frontier models have commoditized most of what was reported on H1, even at higher quality levels. H1 itself is a nonfactor.

Which is another way to say "viability".

Not always.

Most bounty programs won't pay for DoS at all.

it isn't simple request flooding, it is application level resource exhaustion

Yeah, I figured that's what you meant, and most bounty programs won't pay out for stuff like that. Every application has those bugs; on a software pentest, we'd sev:lo them.

> Every application has those bugs; on a software pentest, we'd sev:lo them.

Every application has a bug that can bring the whole application down for every user without owning a botnet? That comes often with a significant business cost, if someone exploits it. Many companies take them seriously. I have reported many as high and business has agreed. Not with HackerOne thought. If there is a bug where someone can make your whole product down with a single laptop isn't really something you can just ignore.


You can report a self-XSS sev:hi (and bounty hunters do) and get many orgs to take them seriously, because they don't have serious security practices. But DoS is generally sev:lo.

> You can report a self-XSS sev:hi (and bounty hunters do) and get many orgs to take them seriously, because they don't have serious security practices.

Which can be definitely high, if it can be triggered by giving specific URL, for example.

I think there is too much generalization happening here.


Some of them can have 1 rpi take down a full 100 node cluster, so sure sev:lo but the cyber insurance often want them fixed anyway. But it will probably take it happening before C-suite decides that 0 revenue is a problem.

Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this.

I don't think this is true, although it's a very commonly-held belief. Dan Goodin (I think?) wrote an article about this a long time ago, and was only able to come up with a few examples, and none of them fit this fact pattern.

https://news.ycombinator.com/item?id=16642155

What is true is that it is much less legally risky to test someone else's computer than it was 10-15 years ago. People forget that's what you're doing when you look for web vulns! The DOJ has had a norm over the past ~many years not to prosecute good-faith vulnerability research, even though strictly speaking it contravenes CFAA directly. But "risky on paper" is the most you could say about doing that kind of testing back in 2010.


https://m.slashdot.org/story/159162-- example circa 2011

I can think of 4-5 other situations from around that era (~2012) where people were at least charged and needed a lot of help to navigate the legal proceedings to avoid jail time.

In 2010 it was more than risky on paper.

2017-2018 is well into the established era and probably even the golden age of bug bounties when a lot of corporate and judicial thinking re: white hat cybersecurity had been shifted.


It's true that I'm speaking entirely in an American context.

Doubt, I’d argue it’s the opposite given the term “vulnerability research” is being overloaded to include things such as F12 on a school website.


An LVT addresses the incentives underling zoning. The LVT imagined by Georgists would very probably result in radically altered zoning rules. Zoning, after all, exists primarily to prop up the finances of homeowners.

A Georgist LVT is based on the value of the bare land, which is constrained by permitted uses. Adopting it without first removing zoning restrictions would increase the incentive for homeowners to defend the existing zoning rules, since the removal of the rules would increase the scope of alternative uses of the land in ways which would make it economically impossible for most existing single family homeowners to afford the taxes on the property.

On the other hand, once you remove the zoning restrictions, the existing economic incentives will produce densification without LVT, tbat's the whole thing the zoning restrictions exist to stop.


I mean, I agree with you about zoning; we're fourth and inches from eliminating SFZ in my muni, and an LVT isn't going to happen anywhere, so the rest of the debate is kind of academic.

An LVT results in new McMansions getting built on quarter acre lots and being taxed at the same rate as SFHs and trailers on quarter acre lots. It's the perfect way to allow rich people to buy out poor people and pay the same tax as poor people. Welcome to unintended consequences. Institute an LVT if you want, but don't expect low cost housing to spring up.

> trailers on quarter acre lots

That is an irrelevant counterargument, since the idea of dense housing leans towards tall apartment buildings, not trailers. No one should have to live in a trailer.


The idea of what should happen is irrelevant, because we have not seen this "dense housing" actually materialize in US LVT jurisdictions any time in the past 100 years.

The township of the Fairhope Single-Tax Corporation near Mobile, Alabama was originally conceived as an artist's colony but is now occupied by families with a median income of $95K. Density is almost exactly 1 housing unit per residential acre. The feds have built 140 Section 8 subsidized units, but there do not seem to be any privately built high density tall apartment buildings of the type you want to see.

Can you point to an LVT place in the US where developers have chosen to build large numbers of actual NON-LUXURY high rise apartment buildings for the benefit of non-rich people? That would be a big newsworthy success story if it actually happened.

There are developers that make their money building high rise apartment blocks. Are any of them lobbying for an LVT so they can build more low cost housing?


> but there do not seem to be any privately built high density tall apartment buildings of the type you want to see.

There exist plenty of old buildings in urban centers that meet this criteria. There is nothing in principle that is stopping their construction. It's in the same imaginary league as LVT for that matter, meaning that if one can manifest, so can the other.

Luxury buildings are made because of a profit motivation. Even so, once the supply is increased by 10x or 20x, their prices too will come down. China is a supreme example of having cheap apartments.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: