Hacker Newsnew | past | comments | ask | show | jobs | submit | jeffwass's commentslogin

An interesting statistical example if you haven’t seen it before is the Anscombe Quartet :

https://en.wikipedia.org/wiki/Anscombe%27s_quartet

Four sets of X,Y datapoints that have exactly (or very close) common statistical parameters (mean, variance, correlation, linear regression, R^2), but with vastly different spatial distributions and “behavior” when looked at visually.


Cool that the Wikipedia page links to the "Mean Dinosaur" paper https://dl.acm.org/doi/10.1145/3025453.3025912 that I love to get out each time someone sends me mean, median, or stddev to measure processing latency. By all means use stats, but always eyeball the dataset to check assumptions extracted from statistics, I guess, especially in this world of matplotlib and notebooks and agents.


I have mostly worked with computational physics with discontinuous polynomial approximations. Stuff like this would be easily detected in those methods as anatomy brcsuse of assumption pf smoothness.

Statistics on the other hand is more accepting of discontinuous data due to it's basis in measure spaces.

Hence In general, you should know what your data should look like before you aim to detect anamolies. But also, it might be a good practice with new automated research actors to always use both approximations (measure theory based and otherwise), to figure out what's going on.


It's the simplest AI nihilist!


FYI - The actual BBC title is “Cherry Kearton: The eccentric influence on a young Sir David Attenborough” but I felt this wasn’t descriptive enough.

The article subtitle is “As a child, Sir David Attenborough was transfixed by the work of Cherry Kearton, a photographer and filmmaker who almost single-handedly changed the way we view the natural world.” which I tried to use but was way too long, so I abridged it.


This submission is currently the main HN submission.

As of now the submission title is simply “Copy Fail”.

Given the severity of the exploit, can we edit the Title to add some context that it’s a major Linux vulnerability?

Eg the other submissions say this : “Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.”


I dont really get why you'd

- buy a domain

- vibe code a page/artifact/whatever (which, given the quality of LLM wordings, only makes an argument less strong)

- post it on HN with no further explanation in the title

Why not write a detailed report? Even a tweet makes much more sense in my head than this. Even a logo??

Sorry if this comes over as salty, I guess I'm just not getting the thought process.


> I dont really get why you'd buy a domain [...] Even a tweet makes much more sense in my head than this

I think we should be celebrating people hosting their own content on their own website instead of just posting on some social media site.


I think they’re using it to promote their product, Xint Code, which was used to discover it. That’s the way I read it anyway.


I hope they sell a lot of Xint Code licenses, so they don't have to sell their findings.


Considering they kinda botched the disclosure to Linux distros, I guess they wanted something most sensational to sell more licenses.


They did not, in fact, botch anything. They notified the responsible party and followed a practice that is pretty much the accepted norm (and for good reason).

How recursive should their notifications be? Just the tip three distros? The top dozen? Every embedded Linux router company? How about every hosting provider?

They did what they're supposed to without being paid for it. The only other good source of funding for security research besides marketing budgets for security companies will NOT result in a disclosure timeline you'd be happier with. ;-)


But they most probably did get paid for it, they have ads for their shit all over the website.


strategically botched ;)


How did they botch the disclosure to distros?


They did not make a disclosure to the distros


Definitely comes over as salty. Naming major flaws has been a tradition for decades. Remember Heartbleed? It had a site and a logo :) Shellshock, Meltdown, Spectre as well. A few more: https://github.com/hannob/vulns

This site though is pretty useful; first it serves as a central location to point people to with short links in chats/emails/whatever, then it has a quick visual explainer and a link to the detailed technical report for those who want more info. Pretty neat.

Last but not least, buying the domain must have taken 5 minutes, prompting the page must have taken 30 minutes and posting it on HN must have taken 1 minute. So it certainly wasn't a lot of work in the grand scheme of things and probably did not deter the team from doing other important things.


It used to be done for fame and visibility. Give a marketable name and a website, your exploit will be talked about and your name will shine in the industry.

Now it's done by an LLM to sell more LLMs services. Disclosure is botched to have the most sensational title so more click more upsell.


I'm being very cynical here but who says that their tool or LLM discovered this. How do we know they didn't hire some expert security researchers to find it or bought it off the black market as a promotion stunt.

With that being said, I wouldn't mind if they made more sales on whatever they're advertising IF they followed the disclosure process well. A bad disclose immediately tells me I can't trust them because their moment in the light was more important that the safety of millions of boxes.



Where would you have them write a detailed report if not a website?


You are wrong. We should ditch walled gardens like twitter/facebook/ig


The domain is canonical.

Then it's syndicate everywhere.

But all roads lead back to the domain.


Yes, strongly agree.

This is HUGE news, I would have skimmed over "Copy Fail".

The blog post might be a better place to link to also, it has more details on the exploit.

https://xint.io/blog/copy-fail-linux-distributions

There are also some good threads on which distros are vulnerable and mitigations on the github page.

https://github.com/theori-io/copy-fail-CVE-2026-31431/issues


This is a terrible take, and I say this having a PhD in Physics.

Many physicists have written popular articles and books for the general population. Eg Einstein, Stephen Hawking, Brian Cox. Improving accessibility of advanced concepts is nothing to scoff at.


Somehow I got a 7 out of 9, even though I felt like I was mostly guessing. Surface vs deep lines have more rumble but that’s about it that I consciously knew of.


I did a bunch of research on similar Tc superconductors back during my PhD.

7K is considered “warm” from a cryogenics point-of-view because you can just dunk your sample into a dewar of liquid helium at 4.2K. You can even get it cooler, down to about 1K, using evaporative cooling techniques. [1]

It’s getting to lower temperatures than this when things start getting complicated. Eg a closed-cycle evaporative He3 system can get you down to 200 mK, or you can bite the bullet and use a dilution fridge down to around 10mK.

[1] https://en.wikipedia.org/wiki/1-K_pot


Lol, my band (London-based) has a song and YouTube music video called "Streets Of London".

I had a minor panic/WTF moment when I saw the submission saying : "Streets of London [video] (youtube.com)".


FYI link is below, for the off-chance someone is curious.

(not sure what are the unwritten rules of self-promotion here, but hopefully providing a link in a sub-comment instead of the comment itself makes it okay-ish?)

https://www.youtube.com/watch?v=qI3xj9cM0jk


Does annybody worry about sabotage if you don’t tip? Eg the cashier does something to your food? “Nice muffin you got there, I’d hate for it to get accidentally sneezed on.”

I recently bought my mom flowers for her birthday. Despite the price showing no delivery fee, the final price included $15 delivery charge, $8 service charge, taxes, and then asked me for a tip.

I chose no tip, expecting the delivery and service charge should cover everything.

The flowers were left on her front porch in below-freezing weather, they didn’t even knock or ring the doorbell. Luckily my mom happened to open the door and saw them before they completely froze.

So was the delivery person incompetent, or acting out because I didn’t add additional tip?


I don't call those tips, they are bribes or bids. I avoid all delivery services personally as much as possible and I'm fortunate to have a car.


I would expect/hope that the deliver person does not know the tips for individual orders.


Some of Robert Tinney's artwork is still available for sale at his website, limited edition runs of several of the Byte covers and other art.

https://tinney.net/


Amazing. I just ordered some. I hope someone fulfills it?!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: