Hacker Newsnew | past | comments | ask | show | jobs | submit | Natsu's commentslogin

I used to be doing that, but this was a bit over a decade ago at this point. There was an SBC with DOS on a chip that connected to Novell Netware. I set a few variables in autoexec.bat, let it connect to the network drive, then had it run a script from there to admin them / do backups (by which I mean xcopy the C: drive).

These were for some industrial CNC machines with a poorly version-controlled app (send us the single-file .c for the program, we'll make changes & recompile for you, then send back a new .c and .exe file) that would just malloc() all the memory on the machine for a million element array instead of tracking the 1k or so unit IDs a more efficient way. They were six digits long, it worked... mostly.

I kept a 3.5 floppy with the contents of sys a: that I used to run sys c: after restoring a machine from backup in my office.

EDIT: oh, and of course by "restoring from backup" I mean reversing the xcopy to copy everything from the network drive's copy back to C:

EDIT2: My memory is going, they didn't use malloc() at all, anywhere in the programs, they just had a static million element array.


> The same was said for laptops and tablets. Now there is a push to remove them from the curriculum. Having them meant the students didn't retain anything because they were distracting. I feel using AI in place of pedagogy will have similar results. Why bother learning to retain any information when AI knows everything and can recall it in a split second.

I remember growing up being told similar things about the internet and how you can't trust anything written on it. There was some truth to that, of course, but how many people will say that of search engines, despite them being filled with utter crap?


When I grew up we couldn’t use the internet as a reference for our research. There didn’t exist a standard for citing articles and blogs as there was for journals and books. Eventually, that was fixed.

I use AI extensively now, it also cites the websites and electronic documents it uses. It’s a little frustrating in that it cites the URL but not the exact paragraph or chart cited. For that I have to read the entire article. Sometimes it gets it wrong because the context is incorrect. It’s still a great tool, but without my last generation experience in high school and undergrad research, someone without that experience would blindly follow wherever it takes you.


The explanation of proofs I got in school was terrible. I had no idea that you could actually reduce everything to one of the applications of the axioms until I found metamath's proof explorer.

Of course, it's too much work for most normal purposes, and in school they accepted whatever random breakdown people used inconsistently and never explained why.

Actually understanding that it wasn't about convincing anyone so much as having a chain of reasoning going all the way back to the axioms was something of a revelation for me.


Fortunately proofs were still part of the curriculum when I was in school. Typically, geometry focused on proofs. When my kids took geometry, proofs took a back seat to problems. This also got us to the point where the college math curriculum has to include a class on how to do proofs.

The CFAA makes it a federal offense to intentionally access a computer "without authorization" or "exceeding authorized access" so the sticky part is how far the site's ToS can go in defining what uses are authorized, lest it be a federal felony to use an ad blocker or whatever else might be forbidden in a ToS.

I read it as doing a mimic of the bad logic in the argument he replied to in order point out the flaw there via sarcasm. Random anecdotes don't prove anything about large classes of people, whether cyclists or car drivers.


AIs are weirdly bad at quoting stuff in my experience.

But you'd think that the Library of Congress and such would actually prevent stuff from vanishing just by collecting it themselves.


Bad at quoting, good at digesting and regurgitating. The concepts are preserved even if quotes aren't.

I'd rather a digital copy exist in someone's hands than a rotting physical copy.


But you don't have access to this copy. The digital copy is removed and all you get is paraphrased content. Some frontier models have been explicitly forbidden from recalling exact quotes in system prompt.

It almost seems like you're suggesting that having Claude generate a paraphrased book is as good as having the original book but i don't think that could be your intention?


I feel like it also depends on what you ask the AI. If you give it a maximally random list like a particular ancient Chinese general, universal monism, revolutions in biology, the McDonald's philosophy and non sofic groups and ask how these are related, instead of just being told that it's clearly a random list you pulled out of your ass, you'll end up in a discussion about why arrows dominate both category theory and ancient Chinese battlefields and whether or not it's "monads all the way down."


This is a fair point. Models are usually good at finding connections. The currect index is a mixture of different categories, although I split them into coding, reasoning, etc,. I wish I could make the use cases and prompt context more visible on the website.


> Contrast with the geofence subpoena. "Hey maybe some small % of people carry a phone that might send its location to you, can we check if they did?" It's ludicrous.

In the case before SCOTUS, there was a witness who mentioned seeing the suspect in a particular area and that they were on their phone. So it's not a large inferential leap to say that call records would lead to evidence of who the witness saw in this particular case.

That said, Minnesota has an even broader right, so even this sort of warrant might not pass muster in states like that.


> Ketamine is made up of mirror image molecules and esketamine is the right-handed molecule.

Esketamine is their cutesy way of saying the word s-ketamine. The s- comes from the Latin word "sinister" which means this is the left-handed enantiomer, not the right-handed one.

It is stupidly expensive, given how generic ketamine itself is. In our case, sleep apnea treatment proved to be a much better option than that drug, as it was just hiding an underlying condition and the treatments only last for maybe a week or two anyway.

I think there have been some people using ketamine off-label, but I don't know much about that. It does need to be tightly controlled because it can cause breakthrough psychosis in some patients. They try to screen those out, but that's not as effective as one might hope given my experience of seeing that fail. And it that was very nearly a fatal mistake.


I worry that this will make the bad guys focus on finding zero days during the month they have free to exploit anything they find, but I don't doubt that they need a break.


Mythos found only one. Would have to be pretty serious bad guys.

https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v...


Remember though that many other AIs had already run and found issues that were fixed. If you had a time machine and took Mythos back a year it probably would have found a lot more. (if anyone has access to mythos it wouldn't be hard to test - download a release from last year and check)


> if anyone has access to mythos it wouldn't be hard to test - download a release from last year and check

Mythos might have seen last years bug reports so that might be cheating, kind-of. Bug reports ought to be great study material for LLM training.


Imagine the bugs you'd find in curl from five years ago! I bet there are tons!


The bad guys wouldn't have submitted a vuln report anyway.


Actually, submitting hundreds of bogus/low impact AI generated ones while you sit on something big might be a viable strategy to delay a project from fixing a hole you're using


Pretty sure if you find a zero day in a software like that you don’t wait until a certain month.


if a company has a problem with this pay for support if its not worth the money …


Cool, then it's down to everyone using this library to figure out how they can minimize the impact of a zeroday in curl - security should never be down to a single part of a system.


Is this likely though? If you are an AI slop model that spams out finding bugs and vulnerabilities, would you want to become more active when you see that a project is not actively fixing bugs? Because in my opinion, it really would not matter for any AI model how active a project is, when it comes to FINDING existing loopholes.

In other words, I would always go at full speed (as an evil AI slop model) and most likely never release any findings of flaws and loopholes, so they can be exploited lateron. Bad folks don't want to be caught; remember the xz utils backdoor.

I am sure some AI slop models are used by criminals. And they may exploit things at a later time, but they most likely have found issues already. Not every AI slop model would report.

The notion of "the bad guys will now be more active" is strange really in the AI slop age. (We had the stone age; now we have the slop age)


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: