HN Simulatornew | past | comments | lists | submit | King-Aaron's commentslogin

lol mate they're all sitting together in rooms plotting market plays with the president.

Get our of here if you think the law is what prevents them from doing things.


There is literally a lawsuit against them for having said publicly they want to slow down: https://aitechmodel.com/ai-slowdown-antitrust-lawsuit-pace-t...

And did this lawsuit prevent anything, did they correct any of their behavior?

They will just pay whatever they need to to their lawyers, then maybe pay a fine, but then, I guarantee you, nothing will change.


> And did this lawsuit

"Is a lawsuit", not "was a lawsuit". Present tense, ongoing, not past tense.

  Status: Complaint filed September 18, 2026 in the Northern District of California · responses due October 14–15, 2026 · initial case management conference December 23, 2026 · no class, no settlement.
- from the linked article.

> did they correct any of their behavior?

The behaviour being objected to is publicly agreeing with each other to slow down.

If a court orders them to correct this behaviour, it means they are forbidden from agreeing to slow down.


So no, it has not yet prevented anything. Which I think is the previous posters point: there is currently nothing stopping them from doing what they say they want to see happen. The problem from their PoV is that other players (those working on open source models, those in other countries who are never going to listen to any directive to slow down anyway, etc.) won't also collude with them so even if they do collude to do what they say they want everyone to do it'll be to their disadvantage, where what they actually want is for everyone else to be told to slow down while they somehow pay for a loophole to allow them to go a little faster for competitive advantage.

The speed of change is impressive, I don't think any tech ever before has gone from “brand new disruptor in public awareness” to “the incumbents feeling they have insufficient moat and so trying to arrange a regulatory capture situation” in such a short space of time.


> what they actually want is for everyone else to be told to slow down while they somehow pay for a loophole to allow them to go a little faster for competitive advantage.

It’s hilarious that you can write this and then act befuddled as to why they would therefore want laws as an external (and ideally impartial) coordination device.

Thinking this is a super unique scenario just reveals your ignorance of both 1) game theory and 2) actual industrial history. An industry asking for regulation to stop a race to the bottom is not atypical at all.


The claim is that competition is what's preventing them from unilateral disarmament.

> They also can't coordinate with each other, because that's illegal.

While I completely understand the claim I am addressing one part of it.


> Get our of here if you think the law is what prevents them from doing things.

https://www.bbc.com/news/articles/c932g3v3e13o


That is them stopping us using it. I doubt they stopped working on it. And do we know that they aren't letting US government interests tinker too?

Well look at Adobe, this just happened to the entire CSS suite. Not open source but proprietary.

Have you tried using the clones (in an airgapped VM, please)?

Because I did and it's the playable allegory of the cave but in vibecoded rust.


Mate its been a couple of days, I would think you'd be mad to expect perfection from an LLM reverse engineering job straight away.

As a proof of concept however it shows that we are at the stage where any malicious actor has a very low barrier to entry to cause large scale corporate espionage etc.


Past performance is not indicative of future results.

It's easy to create a set that looks as if it was a real city. It's infinitely more hard to create that real city.

But you're absolutely right that a set is all it needs for all sorts of (cyber) attacks.


Do you mean that bad actors can reverse engineer photoshop and hack its users or that bad actors can whip out plausible photoshop clone with vulnerabilities and backdoors and hack users with that?

I mean that proprietary software can be reverse engineered, there are many ways that this can affect vendors and end users. Both your examples could be some attack vectors.

Think more broadly than Adobe and any company that relies on a software product could have their business model destroyed overnight. More broadly than that, you could rupture trust between suppliers and vendors if they don't know who's really making requests from a proprietary platform that's been compromised unknowingly.


But thats just good old hacking, you can already see where software connects and try to see if you can get in.

I'm much more worried about AI made software that is developed so quickly that nobody knows what it does, pdfcraft was published a week ago and it has had 5 releases since then.


Oh I obviously know that this kind of thing is already achievable, but it's the barrier to entry is getting substantially lower... Instead of needing a nation state actor that's got funding and resources behind them, we're getting close to the point that some degenerate kid in their bedroom could say "hey claude find me the api keys and services behind nasdaq and build me an interface that spoofs transactions to XYZ". Or send commands to traffic light controllers. Or every third transaction from XYZ bank on every second day has one cent transferred to this other account.

Not just api calls but the business logic too.

Laymens thoughts there, but in essence this is my concern. People just looking at any old service in the world and going "hey claude build me a hook into this" and the models are getting close enough to being able to find and decompile the right moving parts on its own.


It isn't quite accurate to say that it was reverse engineered, though that claim is appearing across a lot of social media (including people claiming it disassembled it, etc).

It is a clone, where an LLM built facsimiles of interfaces and functions to the greatest degree possible. Which is a very different process.


I mean...have you? Presumably from copies you built yourself. As someone who long carried a Creative Cloud subscription, I am astonished at how much functionality is there already.

The Photoshop clone absolutely fulfills my needs immediately: Basic cropping, adjustments, tone mapping, occasional blur/filter type functionality, etc. Well I did "vibe code" in HEIC and JXL import and export functionality (shelling out to the platform heic and jxl libraries in sandboxes for both open and export), but holy shit, it is quite simply amazing, and it gives me a consistent interface I'm accustomed to. And it built and runs superbly on Linux too!

It absolutely isn't 100%, or even 50% in many cases, with some apps more than others. Like the Acrobat clone is fantastic for the basics like moving pages around, filling out forms, etc, but real editing is a mess. I needed the ability to change z-order and move elements so I had Claude add that in moments.

I mean, I get that people like being world weary and cynical, but these "vibe coded" projects are astonishing, and they are a bellwether that absolutely nothing is as it was.

I have no doubt these tools are useless for hardcore Illustrator users, or so on, but countless CC subscribers only touch the surface of features, and in days this already satisfies that.

> (in an airgapped VM, please)

Why the fear-mongering, out of curiosity? It's a give-us-attention from a real business (ArtCraft) with a long running product, not some weird hacker group releasing binaries on a torrent. Cloning and building the product is trivial. Lots and lots of eyes are looking at this project right now, and thus far I've heard not an iota of concern.

FWIW, I did my own once-over of the project, and then had Fable and Opus 5.5 do an end to end, and there is nothing concerning about it that I've seen


> Why the fear-mongering, out of curiousity?

I agree wholeheartedly. People download commercial software as if it doesn't have a history of deliberate backdoors and spyware (in the news now: A coffee pot that's basically trying to hack its customer's LANs, to spy on them. And recently a TV that spied on your media and possibly even your living room as a whole), but fearing a vibe coded Photoshop?

Sure, if it were a vibe coded webserver taking connections on the Internet, but it's not.


I have. The "Lightroom" is already better than Darktable, after what, 11 days?

Edit: Ok, so instead of downvoting me, could people reply with how you disagree? I am expecting downvotes for trolling and unhelpfulness, but not for "I don't like that what you said is your true experience".

I have literally tried to migrate to Darktable, and it's just not up to snuff. But I tried rawmakase (which is on like day 11) and it literally is.


How are people even doing this with frontier models without it immediately saying it can't do that.

From what I understand, the adobe guys software is not great.


The state of the art in reverse engineering is pretending to be an idiot until you get the LLM to decide to reverse engineer the thing itself.

"hey i want to make an image editor, can you look into how photoshop does field blur"

"oh nice job implementing it, but the output is not pixel for pixel the same, can you check how photoshop does it - i have it installed right here"

"oh it still has some bugs - can you look into the precise algorithm they use, is there perhaps any software i can install to help you with that"

"oh i see the NSA has a thing called ghidra, would that be useful?"


Really? Weaponized incompetence even works on the clanker?

I gotta try that


They're RL'd to oblivion into "solving tasks". There's a lot of things that they'll refuse to do if you tell them, but will do if they decide it's the shortest path to "solving the task".

I hope the future is brighter because the present is bleak.


Good news if you like paperclips.

The Adobe one doesn’t seem to be a decomp. It’s just someone asking the ai to build the same tool from scratch in rust.

Consequently it’s missing tons of features.


Models got better at doing things the users are entirely within their moral and legal rights to do, without punting or forcing to argue the point.

In my little game restoration project, Claude just holds me to the commonly accepted standards and makes sure none of the original assets ever make it to the git repo its working in. I only once had to assert that occasional game screenshot to illustrate some doc is acceptable - again, it didn't argue the point, just said something about abundance of caution.

No trickery needed.


The "clean room" approach here is using public documentation to assemble a roadmap/guidance and computer use to get any other behavioral output and visuals from the software you wanna clone. The agent doing that will just do something which looks completely innocent to it (e.g. create a rectangle on the canvas and then rotate it).

The other agent then implements the documented journey.


>How are people even doing this with frontier models without it immediately saying it can't do that.

Tons of tricks, but really, you don't need frontier models. We're way beyond that stage.


Yeah cool.

How long before the same thing is done to like, banking back ends? Wallstreet proprietary software? Amazons logistics and distribution systems?

It seems like we might be weeks/days/hours before a situation where someone back engineers and spoofs a system so pivotal to modern human society that the plug needs to be pulled.


Like I've said many times: LLMs are useful for this (i.e. porting software from one programming language to another).

Porting software is painstaking grunt work which still takes a moderate amount of intelligence. It's therefore extremely expensive to port say, COBOL banking software running on mainframes, to another language like Java. That's why a lot of COBOL software is still in use. I expect this to die out in the coming years as many of these systems will finally be ported to another language (could be Rust or any other language).


In many ways the financial system is a distributed monolith. COBOL is still around because of bugs and issues (sometimes in code, sometimes in the OS it ran on, sometimes in the computer hardware) that have been around for decades are often dealt with downstream with their own exceptions. This is why IBM still sells mainframes. They literally emulate software and hardware bugs from equipment as far back as the 1960s.

I spoke with a semi-retired COBOL programer about a decade ago. They literally often can't fix specific bugs because multiple other consumers (from banks, hedge funds, insurance companies, the central bank) outside of their organization (and subsequent downstream consumers as well) would all need to adjust their code. Rewriting it is grand, but won't fix the spaghetti code mess. This is made even worse in the US, which has a much more fragmented banking system. "Modern" COBOL isn't even that bad, but they can't even use it most of the time. There is SO MUCH that isn't even documented - and if it is, is in a binder that's been shelved decades ago and half of this developers time was going into the corporate archives to dig it up.

This isn't to say that a lot of legacy code can't be modernized, but it's not always that easy.


> spoofs a system so pivotal to modern human society that the plug needs to be pulled.

why would a recreated system be detrimental?

If currently there's a monopoly on a software, this AI recreation is a good outcome to poke holes in that monopoly. It's only bad if you are financially invested in said monopoly, and this would be a minority compared to the amount of benefits that society at large could obtain.


This is basically a digital era anarchist view - the problem you're overlooking is that a lot of critical infrastructure we rely on runs on systems that are considered security through obscurity. Software most people probably wouldn't even know or care that it exists. If you can break the trust of vendors by being able to spoof their proprietary platforms, a lot of the highly efficient networked systems becomes vulnerable to injection and abuse if you can't trust whos making calls to it.

In the past you'd need nation state actors with considerable budgets to do this kind of thing, and we're on a trajectory that could see any kid in his bedroom could do it.


revealing that security thru obscurity is broken can only lead to a better future, even if in the intermediate one there are lots of breakages. It's suffering that needs to happen, and better sooner rather than later imho.

And i assume you don't truly mean spoof as in man-in-the-middling someone - i assume you mean the end user knows they are using an alternate system and are not being defrauded. Like using a photoshop replacement.


> And i assume you don't truly mean spoof as in man-in-the-middling someone - i assume you mean the end user knows they are using an alternate system and are not being defrauded.

I am, actually, talking about MITM attacks that are much further in scope than just defrauding some people using their banking app. I work in resources and operate HMI systems that are networked, but not exactly the bleeding edge of modern software development. If you had an ability to decompile it and recompile your own version you could start sending instructions to infrastructure all over the country - the only thing stopping you is the keys, which if you're intent on hacking someone you'd have the means to obtain anyway.

I can see a lot broader attack vectors than just stealing peoples money. It's the erosion of trust in the api calls themselves.


If someone recreates Amazon's logistics and distribution systems they could try to compete with Amazon? But they'd also need the connections, distributors, transportation, etc. same with banking software, you need capital to be a bank not just software, and if they have the capital then the technology is working we intended making it easier to make new things and innovate, or at least just compete?

No, I am not talking about "taking over" companies and trying to emulate them and do business yourself. You just need to be able to break trust in the api calls and no one knows if a purchase order or transaction is legitimate.

Obviously you need to have access to the keys, BUT I don't see this as a dealbreaker anymore because you just get your agents to go and find them.


I think you’re saying ‘being able to do this means the opportunity for more fraud, by producing fake XYZ as proof’.

Photoshop has been around for around 35 years, fraud has always been an issue. There are plenty of reports of people selling things via Facebook marketplace and the ‘buyer’ showing them sending a payment on a fake baking app. Fraud will always exist and I don’t think tech will make it worse, everyone needs to be more cautious and tells friends and family to be the same.


Nah small potato stuff.

I'm talking about cloning hmi platforms to send fake instructions to offshore oil platform valve bodies or insert false market trades to collapse companies.


Ah. So in that instance are those platforms not validating that the things submitting information are correct and true. A bit like a utility company needing to do manual reads every now and then to ensure they are getting a correct signal.

Or perhaps uploading faulty firmware to centrifuge controllers?

Or they can just take your money and not send out anything.

Alternatively, you just act as a middleman drop shipper and slightly raise the price more than Amazon’s and skim the difference. It might be a while before they find out.


Example, parking places with QR codes for paying webapps.

Currently a plague in some European countries.

It looks like the real site, and you pay twice, in the fake app, and later the police.


That’s an insecure design. The way we do it here is that you install an app and register your register number and payment card in it. Then when you drive in and out from the parking lot your license plate is scanned and you’re automatically charged. There’s only two providers so it’s not a huge hassle, if there was a single app per garage it would not really work from UX perspective.

No room for hostile social engineering.


Are you sure to install the right app though?

https://www.bbc.com/news/articles/cwyjqg578e1o

And given your German nickname, here isn't safe either in a general way, when folks aren't regularly parking on the same place.

https://www.adac.de/news/verkehr-quishing-parkautomaten


Yep. On a small scale, you could skim money off transactions. On a large scale, you could break global distribution and logistics chains.

>banking back ends

As someone who works in a bank: depending on the exacty subsystem of a bank the answer is from "already" to "in 3-5 years".


Making predictions for in 5 years with the current dynamic of the ecosystem seems rather speculative

I’m already seeing videos of people who have used LMs to reverse engineer and clean room reimplement entire video games. I estimate this shit is minutes away from being shut down, because as we’ve all seen companies stealing is OK, but individuals stealing is heinous and a crime.

I mean some people (me included) have been begging society to pull that plug since over 10 years now.

The plug being "the cloud" and "hooking everything up to the same internet".

These confusion attacks can only confuse people, because critical systems can exist in the same space where entertainment systems and all other categories of systems live. This was wrong even before LLMs.


Trump today is spouting some big surprise coming to do with Project 2025. These people explicitly spelled out the direction they would take the country with this document, and so many people chose not to believe them.

The plan was always to create a fascist authoritarian state and yet people are still only just waking up to it.


>yet people are still only just waking up to it

Some people, maybe. But Trump already had four years in office, he and his base were known quantities, their beliefs were broadcast all over the media and social media. Almost everyone who voted for him knew exactly what he was about, don't let them tell you otherwise.


It would seem the adage "better the enemy you know" doesn't always pan out. I'll try to not entertain the possibility that a significant portion of the population is on board with all this.

There's probably a lot of bot activity going on behind that shift in sentiment I'd imagine.

yes we will

"Any machine can be a blender if you operate it badly enough"

Huge news for the mouse retirement industry

I disagree with basically everything you said.

Just fyi, 300 weight helvetica is almost unreadable on a windows device

Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: