Hacker Newsnew | past | comments | ask | show | jobs | submit | zOneLetter's commentslogin

`Baby Steps in C` is hilarious lol. I'll be buying the print editions going forward. They hooked me right in with that.


That article triggered me to send it to my friends. C be crazy.


It's not standard conforming C. asm() is an extension.


Simultaneously triggered my PTSD and made me laugh


Anecdotally, we use an LLM note-taker at work for meetings. I had to intervene recently because our CIO was VERY angry at our vendor for something they promised to do and never did. He wasn't at the meeting where the "promise" was made. I was. They never promised anything, and the discussion was significantly more nuanced than what the LLM wrote in the detailed summary.

In other cases, I have seen it miss the mark when the discussion is not very linear. For example, if I am going back and forth with the SOC team about their response to a recent alert/incident. It'll get the gist of it right, but if you're relying on it for accuracy, holy hell does it miss the mark.

I can see the LLM take great notes for that initial nurse visit when you're at the hospital: summarize your main issue, weight, height, recent changes, etc. I would not trust it when it comes to a detailed and technical back-and-forth with the doctor. I would think for compliance reasons hospitals would not want to alter the records and only go by transcripts, but what do I know...


I recently left my mom a voicemail saying happy Mother’s Day with normal human boilerplate of sorry I missed you, feel free to give me a call back tonight or we can talk tomorrow, either is fine by me whatever works best for you, hope we can talk soon, love you, bye.

She called me back later that night and we chatted for bit and then she paused and sort of uncertainly was like “So… was there something you were needing to tell me?” And I was completely baffled and was like “Uhhhh I don’t think so…?”

She then explained the notification she got about my call and apparently the LLM summary of my voicemail converted a message consisting of 75% well-meaning but insignificant interpersonal human filler (like most voicemails) into this stilted, overly formal business-y speak with a somewhat ominous tone. Assigning way too much significance to each of the individual statements in the message about wanting to talk (to say happy Mother’s Day), inquiring about her availability ASAP (to say happy Mother’s Day) etc. Plus grossly exaggerating the information density of the call making it sound like I left this rambling, detailed message about needing to tell her something that was left completely vague, but possibly important and also time critical.

Added up it made her a little worried when she read it and made me a bit pissed that was the end result of my wishing her well. Because apparently everything needs a half baked LLM summary crammed into it now.


What is a voicemail in this context? What app is reading it?


I’ve noticed my iPhone has recently started putting little AI summaries of messages on the notification screen.

Which reminds me, I need to figure out how to turn that off.


Every doctor's visit I've had, I have been able to make corrections to the record afterward, because there have been meaningful mistakes almost half the time.

ALWAYS check your summaries immediately, and contact your doctor ASAP. They can generally fix it themselves, and it's best done when everyone still has some memory of the event.


> I would think for compliance reasons hospitals would not want to alter the records and only go by transcripts, but what do I know...

I'm puzzled by this as well. Why not just generate a transcript and be done with it? If it's a particularly long transcript that's being referenced repeatedly for whatever reason let the humans manually mark it up with a side by side summary when and where they feel the need. At least my experience is that usually these sort of interactions don't have a lot of extraneous data that can be casually filtered out to begin with. The details tend to matter quite a lot!


I mean the reasons are the same AI is being pushed everywhere.

The businesses offering these services want to say "we are using AI" to their stake holders and the government committees who approve this shit don't have the skills or knowledge to evaluate the effectiveness in addition to the fact they likely don't even use the tools they have approved for use.


> I would think for compliance reasons hospitals would not want to alter the records and only go by transcripts, but what do I know...

Transcription is both too good, and not good enough. The magic generative content only makes it worse.

Too good: a lot of commercial settings forbid persistent transcription because it makes an easily discoverable record of specific details. Thats a business risk that can be mitigated simply by having participant notes or summaries where the secretary can omit sensitive discussion or present consensus without specifics. And notes/summaries also introduce a interpretive defense with some “strategic ambiguity.”

Not good enough: if you look at STT its still probabilistic. The actual evaluation output will have just much data about alternate words/phrases as the selected choice. That leaves lots of room for creating alternate impressions or representing words that werent actually spoken. The fact that people _think_ a STT transcript is authoritative only makes this worse.

When you add generative inference in top (eg summarization) you exacerbate both problems. I suspect that counsel is more accepting of summaries as its less likely to contain specific discoverable terms, likely to diffuse responsibility and specificity, and your judge/jury will be more amenable to “the ai summary is wrong” than “the transcription selected the wrong vowels.”


Transcription works pretty well in my experience, and the transcripts should be treated as the ground truth in such cases.


I looked at the recommendations under your comment, but I don't think I'm capable of these either lol

Any recommendations for a technically competent person, but for someone with math knowledge trailing off at Calc 2?


The math isn't that difficult once you grok mod math. It's like time, like doing addition and subtraction on a clock. What's 10 + 4 on a clock? 4 hours past 10 is 2.


The math stays difficult after basic discrete concepts and gets more difficult as you go. :)

It's straightforward to get yourself to a place where you can do cryptographic things and feel somewhat comfortable with what's happening. Truly understanding it to the point where you can reason safely about it is deceptively harder.


yeah I generally would say that learning about the actual schemes (tends to be) doable by a casual enthusiast, but learning about how the SOTA attacks work (which motivate scheme design for sure) is much more difficult.


Hmm, I've studied a lot of math, and I disagree. Cryptography is mostly number theory, which always looks simple on the surface, and often only needs "elementary" tools, but I still find it much harder than other areas of math.

For example, the proof that there are infinitely many primes looks simple [0], but it's still pretty hard to understand, let alone derive yourself independently. And the other important cryptography/number theory theorems like Euler's totient theorem [1] are even trickier.

[0]: https://en.wikipedia.org/wiki/Euclid%27s_theorem

[1]: https://en.wikipedia.org/wiki/Euler%27s_theorem


yes, deriving all of the math cryptography depends on independently would not be easy. Fortunately, that's not really how anybody learns.

Along those lines, you do not need to understand the proof of Euler's totient theorem to understand cryptography. It is a distraction. All you need (at most) is to know that the result is true, and even then it's only fundamentally important for RSA, which you likely shouldn't bother learning about these days. RSA simultaneously

1. looks very simple (though the simple version is horrendously insecure), and 2. does not have particularly good performance, and 3. does not have particularly good security (either post or pre quantum), and 4. has been in the process of being phased out for quite some time now.

this is not a good combination of properties. The fact that cryptography textbooks cover it is mostly due to historical tradition. I would personally argue it is time to omit it from instruction materials.


> Along those lines, you do not need to understand the proof of Euler's totient theorem to understand cryptography.

Well, I had to when I learned cryptography, but I learned it from a class offered by the math department, so I guess that's rather unsurprising :).

> even then it's only fundamentally important for RSA […] this is not a good combination of properties

Strong agree here.


in general the math is not actually that hard. It will be things you don't know beforehand, but a general undergraduate cryptography class will not assume the undergraduates have that much of a better math background than you. Typically just

1. comfort with logical operations/arithmetic over F2 2. discrete probability over finite sets 3. some basic complexity theory (mostly to reason about running time, though being familiar with proofs by reduction can help as well if you actually want to do security proofs).

a decent idea might be to take some "good" undergraduate cryptography class's course resource and use that. For example, Mihir Bellare is an extremely accomplished cryptographer. The course materials for his undergrad course F2018 are

https://cseweb.ucsd.edu/~mihir/cse107/slides.html

He's also written a longer series of lecture notes on cryptography that's freely available. I don't know where it is on his webpage these days, but you can find it below

https://www.cs.tufts.edu/comp/165/papers/Goldwasser-Bellare-...

the difficult part with this approach is not being able to ask questions that easily. To "fix" this, you can either

* use AI, though that has its own issues, or * use some community forum, such as crypto.stackexchange.com

if you want a full book, the typical (undergradute) one that roughly matches the above syllabus is "An Introduction to Modern Cryptograph" by Katz and Lindell.

I've also heard good things about Mike Roseluk's the joy of cryptography

https://joyofcryptography.com/

Boneh and Shoup have a decent (freely available, and very comprehensive) textbook at the graduate level

https://toc.cryptobook.us/

but it is following (roughly) the standard undergraduate curriculum, so if the slides I linked too are too sparse at some point, you could look up that topic in Boneh and Shoup (or use Boneh and Shoup as context to ask an LLM more targeted questions).

That all being said, the main difficulty for someone in your position is likely determining "what to learn" in cryptography. The easy thing would be to follow the standard undergraduate track, but if you're interested in any particular topic there are likely better routes to take.


RIGHT! I thought I missed a paragraph or something lol


How would one go about detecting the IMSI commands? Would an advanced radio receiver be able to see these? I know pretty much nothing about SIGINT but been contemplating spending some time learning about it.



" So far Rayhunter has not turned up any evidence of cell-site simulators being used to spy on protests in the US — though we have found them in use elsewhere. ... But we’ve received reports from a lot of protests, including pro-Palestine protests, protests in Washington DC and Los Angeles, as well as the ‘No Kings’ and ‘50501’ protests all over the country. So far, we haven’t seen evidence of CSS use at any of them. "


Sounds like that's now stale information:

https://news.ycombinator.com/item?id=45184758


That's funny because I've been rejected from Booz Allen so many times lol


The fun part is when BAH rejects you, but you end up at a sub-contractor working side-by-side with the guys that rejected you anyway.


Don't forget the audits and compliance reports. No company with a C-suite with more than 3 brain cells combined will be going down that route. People forget that hobby-projects do not have the same legal and business requirements as ... enterprise projects.


lol that prompt is actually pretty decent!

Technical debt increase over the past few years is mind boggling to me.

First the microservices, then the fuckton of CI/CD dependencies, and now add the AI slop on top with MCPs running in the back. Every day is a field day for security researchers.

And where are all the new incredible products we were promised? Just goes to show that tools are just tools. No matter how much you throw at your product, if it sucks, it'll suck afterwards as well. Focus on the products, not the tools.


Webpage: "Think of a number between 1 and 100."

Me: 69

Webpage: "Nice'

---

Upvoted.

But seriously, this was really informative!


I couldn’t resist.


It's a Friday and your comment is the first thing that got me 10% awake. Please, do spill the tea. There must be a story there...


CFAA. Grand jury indicted because of the claims I created Bitcoin and BitTorrent, which are sort of presented as the same thing! Also maybe something something Comcast because he works there?

Firstly, BitTorrent and Bitcoin are two completely different technologies, neither of which I created or have committed code to. Nothing related to Comcast was involved and I never have worked there or any other company like that.

I had a great legal team. Very dedicated. Some areas offer great public defenders because the case load is much lighter than others.

Also it's kind of fun to see MD5 hashes used as evidence! I didn't know that was still a thing and I was curious of the legal grounds for the fact that any forensics expert could walk in and provide an equivalent of md5.gif proving it could be fabricated. I explained to my legal team that I could go home and create a version of my hard drive that is filled with repeating copies of the bible that matches all of those MD5 hashes. In legal battles you have to pick things best with your overall strategy.

I can say it was an interesting ride. I watched people overdose daily during COVID in Federal Prison among all kinds of other insanity. I never had any kind of security issues as I was in a lower security facility and many of them, even the "gang banger" ones, were relatively business minded and interested in how the darknet was changing the global drug trade and genuinely happy to have someone they viewed as talented willing to drop knowledge on it. They also loved the fact I could look "street check" other claimed hackers and fraudsters. If they couldn't answer a few basic questions from me they likely were never in any kind of "game" more complex than physically stealing peoples cards. Combine that with the infinite amount of Android rooting related work that needs done to keep the behind-the-bars mobile network functioning LMAO and I was doing fine.

My first cell-mate type person thing was a doctor. His name was Kumar. His friend came over, who also was a doctor, and someone said "Oh hey Kumar" to him as well. At this point I was starting to assume they just call all Indian people Kumar, because I had witnessed similar things. However, they both happened to be named Kumar. Also, they delivered his mail to me wrongly one time on accident. No envelope, etc. just a piece of paper. It was a bill for tens of millions of dollars and most of it had been paid. At this point I had became conditioned to strange paperwork that attempted to tell me I was screwed, so at first I was like "Oh, yeah? The computers I hacked were $20+ million?" before realizing it was his mail. IIRC he was there because he was scamming Medicare for cosmetic surgery like boob jobs and stuff.

Normally in Federal Prison even if you are a terrible baby murdering criminal, you get a little time outside, etc. During COVID things were fucked and it was 24-0 in the same 4 rooms for 6 months for me. Thankfully I had a good DnD campaign to run and worked up to being able to do some physical challenges like 100 push-ups in a single set, which when starting at 30 is impressive.

Ah yes, and I had you guys! I forgot, as I have mentioned this a few times in passing, but I setup a Puppeteer script that would scrape a few sites like HN that I enjoy and would put them into a PDF. It ran the same thing that would happen if you clicked reader mode so that the page was easy to read and it put 4 on a single page and sent it to a friend who would print it and mail it for me weekly. I could have used an API to do this, but the mailing rules are specific and I didn't want to risk it. My friend helped out and mailed that stuff for me and I received the front page of HN along with the articles in a weekly digest format. Originally I didn't know what the mail rules were so it had all kinds of weird search/replace regexes to avoid OCR or something weird, so articles about "HACKER FINDS BLAH" would turn into "WACKER FINDS BLAH" to avoid my mail getting turned away. (This would not have mattered AFAIK)

About those TRULINCS computers. I had decided not to fuck with them much in terms of hacking them. I did get curious a few times and navigate through their boot menus and check a few things out and there were some demons there. Some of the boot was locked down, but PXE boot attacks would work. And before you think "how the fuck would you...", just know you can pay two fine-running Hispanic gentlemen to bring anything inside at 2X cost and mostly it's by weight because they run outside and grab it and run back inside! It can be done with a Raspberry Pi to simply spoof the PXE. Why would someone hack the TRULINCS computer if they have an Rpi? Well, you can basically sit at those computers and use them without concern from a staff member, whereas using a contraband device requires stashing it, hiding, etc.

The guards didn't go inside the building during COVID. Those guys came in a few times dressed head to toe in bullshit-ass-made Amazon hazmat suits for a few days, then stopped coming all together, then eventually would come through with gas masks on a bit here and there. My time was very short as my case took a long time to reach a plea as there were very low damages and various statutes need damages to trigger IIRC.

One time when they came to check my living quarters while waiting for trial they found a bin of old parts. One of them was a power supply unit (PSU). They spent a considerable amount of time trying to determine "how much data it had" and asked me many questions about it. I was not allowed to have a phone at the time, so I could not simply take the product code on the side of it and show them the online retailer specs, etc. Those guys were genuinely trying to decipher the fucking mystery of how many gigabytes were inside that power supply. I will never forget that, and neither should you!

The FBI got tired of talking to me pretty quickly. Most of my answers created more questions that were of no value to anyone. "Do you remember any passwords used?" - "No" - "You don't remember one of them?" - "I'm not sure I remember which passwords I remember, do you remember which ones you've forgotten?" - "Try to think of one" - Closes eyes "I have thought of passwords" - "Can you remember one now?" - "Remember which ones I forgot?"

I remember when the FBI started taking me to the wrong building accidentally because they missed their turn I specifically said I didn't mind because we can stop at McDonalds before we get back on the highway to the US Marshals.

Happy Saturday!


Thank you for this.


Crazy story, but what did you actually do to warrant this type of response? This does not seem like the type of event to happen without cause.


Illegally accessed computers without authorization.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: