Hacker Newsnew | past | comments | ask | show | jobs | submit | john_strinlai's commentslogin

if the prompt was "pick one of these unsolved ciphers and solve it", i think it's fair to say gpt-6 astra solved it.

one of the math breakthroughs was approximately a combination of "do a breakthrough" and "keep going", which isn't really providing direction or ground knowledge.

would be nice to know the prompt(s) and amount of human involvement


> if the prompt was "pick one of these unsolved ciphers and solve it", i think it's fair to say gpt-6 astra solved it.

Yes. Similar to how your manager shouldn't get your credit for everything she asks you to do.


neat part of history, but i dont think that's what that says.

the last sentence starts with "Originating with Thomas Edison in the 1800s, the term “bug” is still used [...]", and there would be no reason to use the word "actual" in the sentence "First _actual_ case of bug being found" if it was the origin of the term.

my clanker found this: https://spectrum.ieee.org/did-you-know-edison-coined-the-ter...

"The use of “bug” to describe a flaw in the design or operation of a technical system dates back to Thomas Edison. He coined the phrase 140 years ago to describe technical problems during the process of innovation."

the moth seems to be a popular misconception, though, given that the article starts with "Ask someone to identify the first computer bug, and he or she might mention computer programmer Grace Hopper and the dead moth found in a relay of Harvard University’s Mark II electromechanical computer in 1947"


>language has always contained overloaded or "literally inaccurate" terms.

"literally" is a great example of this, because it can also mean "not literally, but with emphasis".


>passkeys are addressing threats irrelevant to regular people

phishing is very relevant to regular people


Not really that much in comparison to losing access when needed. It's relevant to corporate employees, where phishing is worthwhile to attackers, while losing access means creating a ticket on internal helpdesk and having rest of the day off.

corporate employees are typically regular people, and where phishing resistance is most valuable.

if by regular people, you meant "in someone's personal life", i would say phishing resistance is still relevant but agree that loss of access becomes a bigger risk to balance


> if by regular people, you meant "in someone's personal life"

Right, this is what I meant. I used "regular people" as shorthand for that, which I see wasn't a good choice. Next time around I'll be more clear.


Don’t you remember the giant phishing campaigns like back when lots of celebrities got their nudes in iCloud stolen and published? These things happen all the time, and are incredibly painful. Much, much more so than being unable to share your account with a coworker.

> ...when lots of celebrities got their nudes in iCloud stolen and published?

Right-- high-value victims of targeted attacks. So not regular people.


Regular people get their data stolen all the time, you just don’t hear about it. Just look at the credential dumps and the most common passwords.

I don't get the sense that regular people get data "stolen".

Ransom is the only thing I see happening to end user data.

Credential thefts facilitate theft of money. It might might help the attacker to rifle thru somebody's data to find information that helps answer "secret" questions, to trick friend and family into getting phished, and maybe blackmail, but I don't see a market for end user data that would drive data theft. Nobody is buying end user photos, videos, email, etc. (Anybody who would possibly buy it just tricks/entices users into giving it to them for free to train their AI models anyway.)


LLMs ironically are changing this[0], but at least until now, rifling through random people's data did not scale, so aside for a subset of cases where it was possible to automate access to some services or otherwise leverage them into a scam on the cheap, it wasn't of interest because there was literally nothing useful to do with it.

--

[0] - LLMs, whether multimodal or combined with modern AI-driven STT / TTS pipeline, enable running highly personalized scams cheaply and in an automated fashion, which does scale up and suddenly makes this data important. But that's a very new consideration, one which passkeys were not designed for, because it literally was not possible or conceivable even few years ago.


At the scale you'd expect that to happen, looking at credential dumps, you'd also expect to hear a lot about it.

And yet, you don't. Which leads me to the conclusion that the data dump are overblown.

I think companies around the world come to the same obvious conclusion, which is why these data breaches keep happening, and the companies whose systems were breached are never any worse for the wear.


>just another password that you cannot even memorize

there's some issues with passkeys, but not being able to memorize them is a feature


So where do I keep my pass keys is the problem. They are in my password manager just like another password. So what's the point of having them because effectively, the passwords in the password manager and the passkey in the password manager offer the same UX to me? Except that at least I can memorize a password by heart just in case.

>They are in my password manager just like another password. So what's the point of having them because effectively, the passwords in the password manager and the passkey in the password manager offer the same UX to me?

same ux, different security properties.

>Except that at least I can memorize a password by heart just in case.

"just in case" should be a thought out recovery flow, rather than hoping that you remember the password of the account you need to access.


The password is the recovery flow. What do you propose instead that isnt just a variation of having a password and a passkey?

a memorized password is not part of a well thought out recovery flow.

double triple emphasis on "memorized"


Ok, I write my password down. Now what?

the same advice as the last few decades:

place it in a fireproof safe alongside your other important documents, like your passport and birth certificate.


That is the point. They stop you from memorizing it “just in case” and reusing it, and they force you to use a password manager.

For the average user, which doesn’t use a password manager, this is great. It means they can’t get phished. And it’s also great for the average password manager user, who keeps dozens of insecure and reused passwords in their vault because they manually thought of a password when signing up instead of randomly generating one.

If you’re already using a password manager and random passwords, the UX is designed to be the same. It’s just a way to get regular people to do this.


> If you’re already using a password manager and random passwords, the UX is designed to be the same.

In that case, they've completely and utterly failed.


A corportation's feature is a user's bug.

And this is why people bash passkeys, but they hear a buzzword lol

i hope that someone can come up with something catchier than "thing-slop" or "slop-thing". the word has become basically meaningless from overuse.

I love the slop word, to me it means effortless, average.

People confuse slop with "bad", but slop isn't bad per se, it only becomes bad when real effort was required.


I mean the literal definition for slop as a noun does have a very negative connotation.

> broadly : a product of little or no value

> food waste (such as garbage) fed to animals

> excreted body waste


Right. Pigs enjoy eating their slop. It’s not bad from their point of view.

Pig would much rather not eat slop. They are very intelligent animals.

They most certainly will. You should see them go after a loaf of white bread, stale cinnamon rolls, etc.

worse, it was trained on reddit law comments

Could be worse, you should see the facebook law comments

presumably that will remain true for the lawyers using the product

So those lawyers will likely want to know about the likeliness of it, strategies to work around it, and overall mitigations.

It might be helpful if the company launching this product included such information in their blog post instead of ignoring it in a field with such a high cost of getting it wrong.


agreed, but i dont think there are many (any?) product launch blogs that cover all the fine details and legal minutia of the product.

that all typically comes in pages of terms of service, purchase contracts, SLAs, conversations with your rep, knowledge base articles, and that sort of thing. not in the initial marketing post.

probably available by the "contact legal sales" link at the top of the post https://openai.com/business/contact-sales-legal/


this used to bug me a lot more than it does now, perhaps because it doesn't really happen to me very often anymore. when it does, i just type "hi" back and then move on with my day.

i know its the nytimes, so we can assume american units, but i find it sort of crazy that even throughout the body of the article it doesnt ever say "fahrenheit".

Common sense suggests that living creatures are likely not boiling when they have a mild fever.

i am not a paleontologist and there have been many extremely weird living creatures over the time earth has been around.

and as the sibling comment mentions, i am primed for science articles to be metric.


I’m metric all the way, but if it would use metric, it still should unambiguously state: C

indeed! my "common sense" is to always state the units you're working with, no matter how obvious you think it is.

at least, that was the concept was drilled into me throughout all my schooling. perhaps that has changed in the last few decades.


Common sense also suggests using the SI units that ~95% of the planet uses, but here we are.

This is what I told my chemistry teacher in high school when he marked me down for not including units, too.

I know nothing about dinosaurs, so if you had told me that their blood was 97°C then I would've believed you

Common sense would be using metric units in science-related article.

Americans don't use Celsius when talking about their body temperatures, and that's who the audience is.

Americans don't use Celsius for anything except scientists talking with other scientists.

A lot of monitoring software defaults to displaying hardware temperatures in Celsius regardless of the locale, and I've gotten so accustomed to knowing what a reasonable temperature is for different components that I personally never change the display units.

that hasn't been my experience. Its widely used in engineering and has been for decades.

Ya, I think engineering falls under the umbrella of “scientists talking to other scientists”

It's a US-based newspaper written for the general public. Common sense would say it's using US units.

It doesn't need to. Any other unit would be either insanely cold or insanely hot.

Given that it’s a shouty headline in a major publication, that’s what I would have expected.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: