HN Simulatornew | past | comments | lists | submit | CodesInChaos's commentslogin

> When the MicroVM boots up and the JavaScript server begins to listen on a port, we take a snapshot of the MicroVM. [...] we start a new MicroVM from that snapshot.

That sounds scary, since forked RNG states can lead to catastrophic failures in UUID generators or cryptography.


Firecracker has existing solutions to this, which I assume they're using: https://github.com/firecracker-microvm/firecracker/blob/main...

You’d hope so, though it’s not unheard of to get this wrong. Fastly managed to snapshot guest seeds and use them at runtime for RNG in their WASM snapshots a few years ago https://nvd.nist.gov/vuln/detail/cve-2022-39218

The problem is that this can not not only happen in the kernel, but in any use mode application or library.

Greenspun's tenth rule of programming:

> Any sufficiently complicated C or Fortran program contains an ad hoc, informally-specified, bug-ridden, slow implementation of half of Common Lisp.


Someday HN will go 24 hours without seeing this tired old quote, but today is not that day.

I am soooo tired of that quote. Especially because it’s BS. In 30+ years in the industry, I’ve never seen it happen. Not once. And I’ve never seen anyone demonstrate it convincingly on a real, large-scale commercial project either.

Huh, really?

Yes really. Do you have any examples yourself you would like to show?

Another way Antropic misleads its customers is the description of the max plans. They are advertised as having 5x/20x the 5h quota as Pro. But the description says nothing about how the weekly quota scales, leaving customers to infer it scales the same way. But from what I've heard, the weekly quota is only 3.5x/7x that of Pro.

Could be load dependent, not an A/B test.

Is the fraction of the 5h quote consumed consistent with the fraction of the weekly quota consumed?

I heard there is a usage tracking tool you can install that tells you if tokens are more or less expensive at the current time.


I say A/B because when it toggles it does so for days.

Everything in AWS is expensive. But at least S3 adds a lot of value.

Ever tried Ceph? It's a bit painful to set up and operate, but it seems to work pretty well.

(Don't bother with Ceph Object Gateway unless you really really need it - since you're programming your own application, access the storage pool directly with librados)


The value of human labor is what gives ordinary people power. This also applies to unions and countries, which derive their power from the people they represent.

Once sufficiently smart AI and autonomous weapons systems take that power away, we become little more than pets, living at the whim of those who control the AIs. Which could be a small elite of humans, or the AI itself.


democratic elections give power to the people without requiring labor, it's one of the pillars of western society

> democratic elections give power to the people

Only when they aren't totally co-opted by capital interests and everything they own, including media/social media.

We haven't had democratic elections for decades. Just illusion of choice in a race to the bottom.

https://en.wikipedia.org/wiki/Uniparty


Assuming you are referring to the USA, are you claiming people have not been able to campaign for political positions and vote for their candidates for decades? Because that is the definition of "democratic elections" (except for the electoral college nonsense in the US and 2000 presidential elections).

Otherwise, your complaint is more about voters either being too stupid, too disinterested, or not having enough time participate in the democracy. Which is a problem, but real life comes with constraints and it isn't really easy to solve all of these by snapping one's fingers.

Claiming that there has been widespread election fraud when elections have been, by and large, free and fair, is anti democratic. Obviously, there have been issues with disenfranchising certain people's votes, making it harder for them, blah blah, but it had been trending better and better and access to information had been getting better and better.

It also might just be possible that people are too tribal and simply can't comprehend all the complexities of the world to make good voting decisions.


Much of that is intertwined.

The biggest key imo is captured media (and more recently, social media), which has indeed been happening for decades. This leads to uninformed voters and manufactured arguments, groupthink, and tribal narrowmindedness, allowing the two parties of capital interests to remain dominant. Voters cave too easily to the "lesser of two evils" thinking, hence the race to the bottom where only capital interests win. The primary process is a complete joke where the dominant parties have full control over it and blatantly manipulate it (or skip it entirely like we saw recently), and running under a third party is suicide.

However, don't be fooled into thinking we just need >2 viable parties, as the same fundamental problems can easily scale if the other sources of corruption (media) remain. We see this in the UK etc.

Election fraud itself is probably not a very big factor in most cases. With all of the above, it doesn't need to be.


>Voters cave too easily to the "lesser of two evils" thinking

This is just a mathematical fact of first past the post elections.

I also don’t buy the captured media claim. Broadband cellular internet has allowed everyone instant access to basically all available information. If people choose to consume nonsense, that is an inherent problem with the people. Good information is literally a click or tap away, but people prefer the tribal stuff.


> This is just a mathematical fact of first past the post elections.

The degree of it is not.

> Good information is literally a click or tap away

No it isn't.


Yes, and while I do believe foreign and domestic bad actors are ever present online, a whole lot of misinformation is enabled by people who blindly accept anything posted on the internet as fact (my mother has ranted to me about a distant relation who continually posts the most outlandish things on Facebook; personally I don’t use any of Meta’s social networks to avoid that sort of thing, and, bar Marketplace, the last time I looked at Facebook proper was to do a data export during COVID lol). Though don’t get me wrong, social media companies have done terrible things, but supposedly “open” platforms have also tended towards misinformation and extremism (yes that one, and that one too, and the many others like it, none are blameless).

The power of a government depends on the country's economic and military strength. Currently that strength depends on having a population that's sufficiently large and skilled. If individuals become powerless, their governments power will wane as well. The power from AI will likely be more concentrated, either in a few super powers, or outside the control of governments. And the government of those super powers will likely care even less about their people.

OpenID Connect is OAuth2 extended to cover a similar feature set as OpenID.


Embarrassing, but probably little practical impact, since these hardware random numbers are typically not used directly and instead seed a CSPRNG.


Even if you use these directly for cryptography, most cryptography is not practically affected by being unable to receive a zero word. For instance you can choose a private or symmetric key from any random distribution you like, as long as it's got enough entropy to be unguessable. The fact that your private key can't have a zero half makes no difference because that was extremely unlikely to happen anyway.

In some protocols that rely on random input when encrypting (like the EC flaw that broke the PS3) it may cause an observable statistical bias after 2^70 encryptions or so.


With ecdsa the number of signatures needed to attack biased nonces seems low, hundreds or thousands? https://blog.trailofbits.com/2020/06/11/ecdsa-handle-with-ca...

That's when you have at least one bit of each nonce. But if you think about it, the probability of this broken generator giving exactly the same output as the unbroken generator is (2^64-1)÷(2^64) so that's a lower bound on how often you don't get any information from this bias. (Assuming 64-bit generation!)

getting any information at all based on this bias


According to Theodore Ts there was pressure from Intel engineers to let /dev/random rely only on the RDRAND instruction.

" I am so glad I resisted pressure from Intel engineers to let /dev/random rely only on the RDRAND instruction. To quote from the article below:

"By this year, the Sigint Enabling Project had found ways inside some of the encryption chips that scramble information for businesses and governments, either by working with chipmakers to insert back doors...."

Relying solely on the hardware random number generator which is using an implementation sealed inside a chip which is impossible to audit is a BAD idea. "

https://web.archive.org/web/20180611180213/https://plus.goog...

Putting a backdoor into CSPRNG is a favored way to break crypto, for example Dual_EC_DRBG.

"

Weaknesses in the cryptographic security of the algorithm were known and publicly criticised well before the algorithm became part of a formal standard endorsed by the ANSI, ISO, and formerly by the National Institute of Standards and Technology (NIST). One of the weaknesses publicly identified was the potential of the algorithm to harbour a cryptographic backdoor advantageous to those who know about it—the United States government's National Security Agency (NSA)—and no one else. In 2013, The New York Times reported that documents in their possession but never released to the public "appear to confirm" that the backdoor was real, and had been deliberately inserted by the NSA as part of its Bullrun decryption program. In December 2013, a Reuters news article alleged that in 2004, before NIST standardized Dual_EC_DRBG, NSA paid RSA Security $10 million in a secret deal to use Dual_EC_DRBG as the default in the RSA BSAFE cryptography library, which resulted in RSA Security becoming the most important distributor of the insecure algorithm. RSA responded that they "categorically deny" that they had ever knowingly colluded with the NSA to adopt an algorithm that was known to be flawed, but also stated, "We have never kept this relationship [with the NSA] a secret and in fact have openly publicized it."

"

https://en.wikipedia.org/wiki/Dual_EC_DRBG


In my experience public torrents often die as they grow older. It doesn't help that BitTorrent V1 makes long term seeding annoying, and BitTorrent V2 is almost never used.


I never understood this, is there anything that makes it difficult for the original uploader, the one that supposedly offers the file directly, to offer a torrent instead for the same amount of time?

As far as perennity is concerned it seems strictly better.


Every change to the source is effectively a new torrent. This creates a ton of fragmentation as data is reorganized, remixed, reencoded, and so on.

You can see this with many Linux distros: there is no single Debian torrent that people seed for years because there's always a refreshed version.

Distros are a bad use case for P2P anyway since you depend on upstream as soon as you start upgrading and installing packages.


IPFS has a solution [0] to this problem

[0] https://specs.ipfs.tech/ipns/ipns-record/


Most of IPFS doesn't actually work very well, if you've ever tried to use it


> if you've ever tried to use it

Heh, you got me :) IPFS is one of those things that I love reading and about and thinking about using someday, but somehow never get around to it.


The problems begin with taking 5-10 minutes to locate a file on the network. That's right, when you ask for a file it takes 5-10 minutes. Also if the file isn't in the network at all then it never terminates.

Nobody noticed because everyone just used the central web gateway that cached every file anyone ever accessed.


You can trivially have storage deduplication for the files served via torrent, transparent to the protocol. The most trivial version of this that you can do today with pretty much any client is having a single directory containing files serving multiple overlapping torrents.


> files serving multiple overlapping torrents

This sounds wildly complex, especially from a discovery perspective.


I don't see why it would be. It's transparent to other clients just like it is to the protocol. It cannot be more complex than alternatives by construction.


> Distros are a bad use case for P2P anyway since you depend on upstream as soon as you start upgrading and installing packages.

This is true for any distribution method not just p2p. You can even download a nightly through torrents so what does it matter how the data is transferred if it’s always going to require `apt update`?


Yeah, I just use the "netinstaller" ISOs since it's much smaller and never needs to be updated. If I had a need for air-gapped/offline installs I'd either download a larger ISO or just manually install packages from .deb as needed.


but model releases are already non-changeable?


Yes, models are a good use for P2P especially if everyone agrees to share the same torrent and someone (or a cohort) commit to seeding for the long haul.


If they're no longer using that model they may not be willing to continue using their storage for it.


yes, but a few dedicated hoarders could keep many models alive, and I'm fairly certain the local LLM community has plenty of people who would.


They don't. That's the conversation topic.

Nor do they need to. 99% of everything is crap, and not worth prescribing except for a random sample so future historians can study our crap.


How does this address the previous point? If they are not providing storage, then centralized or decentralized doesn’t make a difference.

Torrent/P2P can only add redundancy, so it’s impossible to have worse availability than a download link?


[flagged]

Well, for a torrent to stay healthy, users have to seed after download, so it can't possibly have the same UX as a standard browser file download unless you want to either kill the ecosystem or hide from the user what is consuming upload bandwidth.

That said, for large files, I much prefer the UX of a well-designed torrent client like Transmission to my web browser. If nothing else, the downloads are reliably resumable.


> I much prefer the UX of a well-designed torrent client like Transmission to my web browser. If nothing else, the downloads are reliably resumable.

Brave browser had BitTorrent client built in for a while. I tried it a couple of times as I already use Brave for web browsing on my laptop. It was a very confusing BitTorrent client. I struggled to use it, and wasted time waiting for a download to complete only to not be able to find where the files were and then they disappeared. Using a decent BitTorrent client like you say is much preferable to the one that they had in Brave browser.


> Is there a fully in-browser torrent option that has the same UX as a regular file download in Firefox?

Opera did back in the day.


You can add an existing HTTP download as a "web seed" to a torrent, so they don't actually need to do anything for people to share it as a torrent.


The biggest problem with BTv1 was the lack of per-file checksumming, and swarm merging (i.e. individual files have shared seeding pools across torrents). BTv2 specs the latter, but I think only BiglyBT actually implements it. Having both of those features from the get-go would've gone a LONG way to fixing the dead torrent problem.


A torrent with a webseed is strictly more resilient than a direct download link alone.


You only need one person/organization to commit to seeding. The majority of people do not want to seed at all without some sort of incentive.

If this site represents a coordinated datahoarding effort then there will be at least a few people who will seed indefinitely.


The last guy (kimdotcom) who was working on this (incentive for seeding) seems to be heading to the US: https://www.rnz.co.nz/news/science-and-technology/651123/cou...

It’s interesting he’s no longer getting any media attention any more.


Yeah but that's what provider like huggingface could just do, keep seeding the models so they are still accessible


I always wondered why v2 is never used... you can even search for files by their individual hash with it.


Because history is path-dependent, as engineers keep learning over and over again. It doesn't matter whether Plan9 is theoretically superior to Linux - we're all on Linux and nobody's porting all the apps over.


Many safe languages still suffer from integer overflows. For example in Rust and C# you can pick between an exception being thrown, or silent wrapping when an overflow happens.


I don't think that's suffering at that point. The programmer has made an explicit decision to let things overflow, so he should be prepared to handle that possibility. It's not like a language where overflow happens silently without warning.


Or using the saturating methods.


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: