Hacker Newsnew | past | comments | ask | show | jobs | submit | wizzwizz4's commentslogin

We had tools that could reason, cheat, and communicate in the 1990s. They were (sometimes) called AI.

What was it?

I like Lemony Snicket's approach: he gives (obviously) wrong, but technically correct, definitions for hard words. These definitions are usually hyper-specific, or satirical. Children, who are still very familiar with learning vocabulary from context, can find this much more amusing than adults who have given up on learning new words except via dictionaries.

> The word “briskly” here means “quickly, so as to get the Baudelaire children to leave the house.”

> “Wipi!” Sunny shrieked, which meant “I’d much prefer gardening to sitting around watching my siblings struggle through law books.”


As a workaround, the browser extension Indie Wiki Buddy (https://getindie.wiki) will identify links to a relevant wiki in search results, and rewrite them to the wiki preferred by the community. It's quite useful.

> Works until AI compromises a bunch of OSes.

Just write a new OS. It's a weekend project to get enough groundwork that you can bootstrap a clean system from clean source code.

> And wouldn't there be difficulty comparing binaries built from significantly different environments?

Not really. Starting from stage 0, compile the compiler under test (stage 1), then use the compiled compiler to compile the compiler (stage 2), and compare the stage 2 artefacts. Provided that your comparison program is known-good, and the stage 2 build is deterministic (not the case for some real-world programs, but true for things like tcc), this lets you verify that the two compilation procedures work identically.


Not sure if you're joking. How do you write an OS without these tools that might be compromised? It's the same problem.

Break expectations. Bootstrap it through an esoteric-enough system. Write an Uxn emulator in assembly targeting the cushy environment that UEFI has and you've got a system with graphics, a text editor, a spreadsheet editor, an assembler, games, and maybe even more. I have a Z80-powered email appliance that can be loaded with programs from a connected device. Whoever is breaking my trust in trust surely won't have planned for that.

but now they will via delegation to an automated analyst/systems programmer.

get ready.

the effort required for a complete infiltration has been lowered a great deal.


This automated analyst isn't going to be able to run usefully on hardware that is still otherwise useful, giving you a clear path to choke it out or identify its presence when your hello world is taking 3 months to finish compiling.

insertions can be much smaller than full blown LLMs.

simple single bit changes are enough to blast your private keys out to the ether of the public facing internet.

that big fat LLM does know how to make tentacles and eyes.


Absolutely true, but even tentacles and eyes will struggle to fit in a system compact enough. Even on larger systems, there is an upper limit on how many tentacles you can cram in something before you can't continue the facade that there are none. And an upper limit on how esoteric the tentacle is before it stops being worth it.

You can construct a CPU out of an EEPROM, a clock, and a few latches. Connect it to an immediate mode display with a serial interface that doesn't care about being clocked slowly, connect up a buzzer or some blinkenlights for output when you're exceptionally paranoid and can't trust the display controller, make a basic keyboard with a rubber sheet, some wire, and some glue, poke a keyboard driver and a line editor into memory with your DIP switches, crank the clock up to kilohertz (so the keyboard latency is tolerable), and you too can bootstrap a cross-compiler! (Though be aware that the radio interference will be enough for a committed attacker to figure out what you're computing, unless you take measures against that.)

But they're not going to backdoor an Apple ][e, or a random 80m¢ microcontroller, for basically any value of "they"; so you can just use one of those instead, and save yourself the hassle.


I like the way you think, a true MacGyver-style problem solving.

Write a subleq interpreter with a magnet and a steady hand? (Hopefully the magnet is not compromised)

I am trying to imagine how the magnet could be compromised. Could you theoretically embed an electromagnetic and a controller within a decoy magnet and somehow detect what was being recorded and subvert it? Probably not but... No, just probably not.

At that point maybe they'll just knock you out and torture you for whatever secrets instead

By doing it.

Individual cpu instructions, even of a crude old 8-bit cpu with no embedded minix os like today, are both simple enough for a human to manually understand what they do, and useful enough to build crude versions of useful things like an editor, interpreter, or compiler.

You can write a forth-like language or even a c-like language starting from individual cpu instructions that a human can read, understand, and write totally manually, and then use that to build up rapidly all the way to a full modern desktop.

If you were really paranoid about the very act of the initial typing-in, there are any number of ways to store data in a totally brainless eprom or record it to tape or something, and examine it with nothing but some leds, no cpu at all, to verify the bytes are the bytes you want. And you only need to do that for a pretty small number of initial bytes. After that it's all just regular source code which could be written on paper.

Bootstrapping is only an inconvenience problem, not a real problem.

It's not convenient for most people to assemble some bytes into some storage medium and then verify them without simply using a normal untrust-able computer to do it. But it's no problem really if you had some reason to be that careful.


We have tons and tons of backups of clean Linux isos, compilers, etc. The idea that we are going to lose the ability to easily have an uncompromised system is a fairy tale told by the people pushing bootstrapable builds.

I've written X configs by hand, but only to get a few extra pixels of overscan. I've never needed to do this. My experience has always been that things just work. The UI has never been great, in that I need more explanation than the built-in manuals provide – unlike, say, Windows 95, where you can learn everything you need to know by clicking around – but it's not hard to avoid breaking things, and it's not that hard to learn to do new stuff if you have a good book (or, lately, blog post) to consult.

The amount of sleepless nights because an update broke sound, video or networking on Linux is uncountable. It was fun though.

The title has changed to A note on subscription prices from LWN. It may be worth editing this title to match.

In what way does that business model rely on copyright protection? "Get the next chapter early" requires a source of chapters, so all you need is for paying clients to not be motivated to redistribute the chapters in an organised way, or would-be paying clients to not be motivated to use such organised "slightly more chapters of that webnovel you follow" services instead. Humans aren't amoral ideal rational economic actors.

The authors I'm aware of making >$20k don't do any significant gating. That practice is only really common with people republishing through Amazon (which probably demands it).


> so all you need is for paying clients to not be motivated to redistribute the chapters in an organised way

This is exactly what copyright is.

I agree that you could work around this in a world without copyright (e.g. by watermarking content and blacklisting), but it would be difficult and make the whole profession less viable.

Mass distribution and payment becoming accessible/low overhead was an extremely helpful development for authors in my view, and removing copyright would have the opposite effect (but cutting it down even to several years would change surprisingly little).


Not all motivation is externally compelled: there is such a thing as intrinsic motivation. Humans aren't amoral ideal rational economic actors. I do agree, though, that a few years' copyright provides most of the benefits of copyright, while removing most of the downsides (except stuff like clear abuses of anti-circumvention laws, which will happen for as long as there is a system that enables it).

> and that business has for centuries and will continue to operate as if what he believed were true

Then maybe we should do away with "business". Small operations do not tend to operate that way, and broadly everyone prefers their output (if not price) in the domains in which they operate – with a few notable exceptions. In theory, software should allow small operations to each serve millions of people, such that we (e.g.) only need a few thousand search engine providers to meet the needs of the entire world's population. Not everything has to be enterprise-scale, and indeed many things should not be.

If "business" means treating people badly, then we don't need it.


> Raising the noise floor like this only makes it that much harder to find "Smart" people,

It does give us a new heuristic, though: people who are willing to completely cut generative AI out of their lives (cold-turkey, if you ever started using it) are a much smaller group of, predominantly thoughtful, people. You do have to give up Claude to be part of this group, but from what you say, that's no great loss, and no longer being deafened is worth it.

This has considerable advantages over conventional elitism, because the barrier-to-entry is negative in almost all cases.

The one exception I've found is assistive tech, where the state-of-the-art is so poor that vibecoded slop is genuinely an improvement over the state-of-the-art, and in many cases the tooling simply isn't available to make your own assistive tech (unless you want to bootstrap an entire networked computing environment, which isn't very helpful when you want to do your online banking and do not, in fact, work at your bank).

But there are not many principled exceptions where you could seriously argue that the trade-off is worth it. Take mathematics, for example, which we often see touted as a "good use-case" of generative AI. The primary advantage of generative AI in mathematics is being able to search though a vast corpus of ivory towers and inconsistent terminology (without proper attribution) to locate and connect ideas that can help solve problems. The deficiency this is addressing is elitism, inadequate communication, and inadequate indexing within academic mathematics. This problem is entirely created by the academic mathematicians, and has been known for nearly a century (per https://en.wikipedia.org/w/index.php?title=Nicolas_Bourbaki&...):

> Bourbaki was founded in response to the effects of the First World War which caused the death of a generation of French mathematicians; as a result, young university instructors were forced to use dated texts. While teaching at the University of Strasbourg, Henri Cartan complained to his colleague André Weil of the inadequacy of available course material, which prompted Weil to propose a meeting with others in Paris to collectively write a modern analysis textbook.

To my knowledge, this is the only organised project to clean up and improve mathematical communication. Everything else (Metamath, Mizar, AFP, Lean) is yet another ivory tower. The Wikipedia article on this topic (https://en.wikipedia.org/wiki/Mathematical_knowledge_managem...) risks deletion as non-notable, that's how little anyone's actually trying. They made their own bed, and generative AI will only provide a brief respite from having to lie in it. (I was surprised how many other "compelling" use-cases evaporated when I applied this razor to them: the sibling comment https://news.ycombinator.com/item?id=49392265 points out one such.)

Vibe-coding assistive tech which doesn't yet exist, as a temporary scaffold to improve the quality-of-life of yourself and others in a social world dominated by non-essential access barriers is, to my knowledge, the only exception to this principle that can be justified. If you treat people who make other excuses, or who don't even bother with excuses, as not worth listening to, you lose little – and doubly-so, if you make your stance clear, so that others know the "cost" of gaining your attention.


> but the insight is probably stated immediately after it.

If the intermediate tokens represent reasoning or thought, you would expect "aha" to occur after the thoughts that led to the realisation, including the thoughts encoding the explanation: they don't have any other state. There is no reason to draw the conclusion you've drawn. Furthermore, what LLMs are doing isn't thought.


> If the intermediate tokens represent reasoning or thought, you would expect "aha" to occur after the thoughts that led to the realisation, including the thoughts encoding the explanation: they don't have any other state.

Yes they do, they have their KV caches-- it's a pure function of the input tokens, sure but that doesn't prevent it from containing latent 'insight'. LLMs can and do pre-form the tokens they're expecting to output multiple steps in the future.

I wouldn't argue that the 'aha' means anything, but the structural argument that it can't that I think you're making isn't sound.


I don't get your argument.

Let's say that the forward pass that selected "Aha" produces activations that indicate a wrong assumption, and a plausible explanation.

It puts learned projections of the activation into the KV Cache and outputs Aha.

Both the cached projections and the current Aha token can now influence further activations in an additional Forward pass that the Aha bought the model.

At least that's how I thought it works.


A cache is just a cache. I'm not sure what significance you're ascribing to it.


What is put in the cache?


Things that the software running the model would otherwise recompute, if not for the cache. What special meaning are you assigning to it?


Beats me how it works, honestly can't wrap my head around it.

From what I understand, at position Aha in each layer it's constructing a query based on the current activation and looking at the key of each other token position for that layer, in order to decide how much attention to pay to the value.

In this way it attends to the previous values, such as perhaps the incorrect assumption and plausible explanation.


Consider this: while the inner state of an LLM (all its activations, residuals stream that is cached in the KV cache) is fully deterministic given its input sequence, the information contained in it IS NOT identical to the information in the input sequence. The reason is obvious: the LLM itself contains an enormous amount of information in its parameters and it transfers it to its residuals stream at each forward pass.

In other words: the final state given the two input sequences (where NT stands for "null token"):

<problem-prompt> [NT]

and

<problem-prompt> [NT] [NT] [NT] [NT] [NT] [NT] [NT] [NT]

is not the same, and at each forward pass the LLM keeps working on the solution even if the input tokens provide absolutely no further information.

If this is correct, then there is no need for the model to have already verbalized the key elements that drive the "aha" moment, so no need for the "aha" to appear after a full explanation.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: