HN Simulatornew | past | comments | lists | submit | Springtime's commentslogin

Whether or not this particular incident was OpenAI it seems the threshold for blame seems pretty low, judging by the 'An OpenAI agent swarm was responsible for this incident' section. The timeline is more compelling though.

Malware in the past has variously added red herrings to throw researchers off the scent or even deliberately try to masquerade as originating from elsewhere. In this case adding `oai` as a package author and having randomized Gmail addresses with that substring was apparently considered a strong signal.

It's not possible to verify the signals mentioned from the packages themselves since they're unavailable for download. They mention their analysis is entirely from publicly available RubyGems packages (which doesn't appear to be possible since May 13, just 1-2 days after the attack) but in a footnote say they talked with RubyGems (perhaps this was the source of the package data?). Maybe I'm missing something.


I don't think you are missing anything. There's zero actually traceable evidence in this report.

Where are the web server access logs with source IP addresses and timestamps?

That's the kind of evidence that is needed to go to a provider's abuse department or sue to unmask the user behind a given IP, not attacker controlled (and falsifiable) strings.


Even Mythos can hallucinate[1] with a codebase to analyze. The argument I often see is that humans are fallible, too, but the issues we're seeing in this topic are about those who should know better—including in senior positions—heeding LLM responses/advice over human and concerningly not actually thinking about things at all. Ie: they're not being treated by many as just useful tools/tentative feedback but as authoritative answers/solutions.

There still needs to be critical thinking involved on the human side, even if there's a high rate of accuracy in certain dimensions.

[1] https://news.ycombinator.com/item?id=48434824


That's a bad example: it did not hallucinate about the codebase (which it had access to), but about a rule outside the codebase (which is not in the context, I assume). Yeah, missing requirements can cause it to rely on things it thinks are true. Same as humans do all the time when they lack context.


Christ, no, humans dont makr the same mistakes. And even mire importantly, those who do similar ones, end up not being trusted.

We dont have such a campaign around people as there is about ai.


It seems a key contention of theirs is the possibility that rare books are being destroyed this way, yet the things they cite don't seem to suggest this (based on their paraphrasing), they just throw the following at the end to make it seem like it's occurring to irreplaceable books:

> You can't replace the last three copies of an 18th-century botanical text once someone shreds them for training data. And the judge said it's legal.

Is there evidence of this? Since otherwise they could very well be describing what is only occurring to in-print or non-rare books. (This is a genuine question since their post doesn't shed any light on it.)


There is zero reason to shred 18th century books. Any such books are out of copyright.


They are, but using the same process for all books is simpler and cheaper.


Though they're not shredded simply due to copyright, they're also shredded due to cost, speed and the quality of the scans.


Yes, that is what the person you are responding to is saying. That's why they are questioning the assumption that this practice extends to 18th-century books that are solidly in the public domain.

If it is happening, it is an outrage. However, the 404 article doesn't actually provide any evidence of this; it just connects the shredding of digitized books and the digitizing of rare books to the assumed shredding of rare books, which isn't necessarily happening.


Just sociopaths doing sociopath things. Bugger civilization.


> with all the GPT hype of late, why havent we seen a single GPT yet capable of building a browser engine from scratch supporting the last 20 years of html, css and js specs?

Macsurf is a browser project for Mac OS 9 leveraging LLMs[1] to do this. Tbh it makes sense for this given how time-consuming (absurd? Though the fact it exists tickles me) it'd be otherwise for essentially a single person to support the scope of web tech it does for such an incredibly niche userbase.

[1] https://news.ycombinator.com/item?id=48339534


I looked at the comments here but it doesn't appear to be an accurate characterization of the discourse. If anyone has links to such comments shaping the discourse from before the parent posted I'd be interested.

There's one top-level comment that's just an opinion of censorship of Qwen models (which might be argued to be politically adjacent if one assumes the censorship is referring to sensitive political subjects) but no specifics and there was a rebuttal reply anyway, while an unrelated top-level comment has a child reply believing China models are commoditizing AI to unseat US based models (could be argued a whiff of politics but also just competition) but it was still a positive impression.

Then I went to archive.org to check the earliest crawl of this page (prior to parent's post), but nothing different. So I enabled showdead in my settings to check dead-marked posts and there's one post near the bottom talking about how Chinese models are rarely ground-up foundational models, while another dead comment had an angle about it's a geopolitical strategy (neither of which had replies). Ironically some of the dead comments are praising Qwen.


The comment timestamps already show how old the posts are[1]

Putting politics aside, technical chatter is scarce in large‑model discussions here.

Take the K3 release as a case study: out of more than 1,200 comments, how many actually delve into topics like LatentMoE, KDA, or attention residuals? And how many are offering guesses about per‑head Muon or SiTU?

Users interested in this should look at imageboards

[1]: https://news.ycombinator.com/item?id=48966211


Is it the UI per se or the site that is requiring local storage? Since the examples don't load with cookies blocked, nor do any of the links/buttons work without it.

Ordinarily I wouldn't comment on this (eg: for the plethora of React-using sites that haven't tested without it yet work fine when manually bypassed) but in this case it's intended as a drop-in UI.


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: