A long, long time ago (within the past ten years), I had to verify my age with a site. They didn't ask for my ID, or my facial scan, but instead asked for my credit card number. They issued a refund to the card of a few cents, and I had to tell them (within 24hr) how much the refund was for, after which point they'd issue a charge to claw it back. They made it clear that debit and gift cards would not be accepted, it must be a credit card. So I grabbed my Visa card, punched in the numbers, checked my banking app to see the +$0.24 refund, entered the value, got validated, and had another -$0.24 charge to claw it back.
Voila, I was verified as an adult, because I could prove I had a credit card.
The whole point of mandating facial recognition or ID checks isn't to make sure you're an adult, but to keep records of who is consuming those services and tie their identities back to specific profiles. Providers can swear up and down they don't retain that information, but they often use third-parties who may or may not abide by those same requests, especially if the Gov comes knocking with a secret warrant or subpoena.
Biometric validation is surveillance, plain and simple.
Google making Gemini 2.5 Pro (Experimental) free was a big deal. I haven't tried the more expensive OpenAI models so I can't even compare, only to the free models I have used of theirs in the past.
Gemini 2.5 Pro is so much of a step up (IME) that I've become sold on Google's models in general. It not only is smarter than me on most of the subjects I engage with it, it also isn't completely obsequious. The model pushes back on me rather than contorting itself to find a way to agree.
100% of my casual AI usage is now in Gemini and I look forward to asking it questions on deep topics because it consistently provides me with insight. I am building new tools with the mind to optimize my usage to increase it's value to me.
Gemini flash models have the least hype, but in my experience in production have the best bang for the buck and multimodal tooling.
Google is silently winning the AI race.
Hey! I did this too - CenturyLink wanted an insane amount of money to bring fiber to our place, now we service hundreds and we're growing into a major contender in Boulder County - https://ayva.network
We never stopped manufacturing, we just stopped employing people.
> We don’t have the infrastructure to manufacture
That's trivially false given we're the second-largest manufacturer in the world. We just don't want to employ people, hence why we can't make an iphone or refine raw materials.
The actual issue is that our business culture is antithetical to a healthy society. The idea of employing Americans is anti-business—there's no willingness to invest, or to train, or to support an employee seen as waste. Until business can find some sort of reason to care about the state of the country, this will continue.
Of course, the government could weigh in, could incentivize, could subsidize, could propagandize, etc, to encourage us to actually build domestic industries. But that would be a titantic course reversal that would take decades of cultural change.
> “The Grok integration with X has made everyone jealous,” says someone working at another big AI lab. “Especially how people create viral tweets by getting it to say something stupid.”
It's awesome to see the amazing value for society being created by big tech these days.
To the "I wish HN would stay out of politics" crew.
You can stay out of politics, but politics will always come and find you.
If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance.
Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar.
Already did a backup of the NVD in the last couple hours, currently backing up the security trackers and OVAL feeds.
Gonna need some sleep now, it's morning again.
My project criteria:
- hosting within the EU
- must have a copyleft license (AGPL)
- must have open source backend and frontend
- dataset size is around 90-148 GB (compressed vs uncompressed)
- ideally an e.V. for managing funds and costs, so it can survive me
- already built my vulnerability scraper in Go, would contribute it under AGPL
- already built all schema parsers, would contribute them also under AGPL
- backend and frontend needs to be built
- would make it prerendered, so that cves can be static HTML files that can be hosted on a CDN
- needs submission/PoC/advisory web forms and database/workflow for it
- data is accumulated into a JSON format (sources are mixed non standard formats for each security tracker. Enterprise distros use odata or oval for the most parts)
If you are interested, write me on linkedin.com/in/cookiengineer or here.
> I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides?
This was not a carefully-weighed decision based on a cost-benefit analysis. This was a political order, consistent with the administration's policy of "cut everything, recklessly, indiscriminately."
This kind of news should be a death-knell for OpenAI.
If you've built your value on promising imminent AGI then this sort of thing is purely a distraction, and you wouldn't even be considering it... unless you knew you weren't about to shortly offer AGI.
There is a certain amount of irony that people try really hard to say that hallucinations are not a big problem anymore and then a company that would benefit from that narrative gets directly hurt by it.
Which of course they are going to try to brush it all away. Better than admitting that this problem very much still exists and isn’t going away anytime soon.
I did some digging and the hacker posted which exploit he used.
Apparently some boards allowed uploading PDF files, but the site never checked if the PDF file was an actual PDF file. Once a PDF file was uploaded it was passed to a version of Ghostscript from 2012 which would generate a thumbnail. So the attacker found an exploit where uploading a PDF with the right PostScript commands could give the attacker shell access.
Oddly, I thought this discussion would be about actual toddlers.
There is a way to win an argument with a toddler. You find out what's bothering them, usually something emotional, and you validate it. "Yes! It's fun to stay up late! Yes! You don't want to eat your vegetables!" Once they feel heard, you've got a shot at getting them to do what you want.
That's a good way to win an argument with a non-toddler as well. Acknowledge that what they want is legitimate (if it is). Concede points of agreement. Talk about shared goals. Only then talk about a different path to the solution.
Worth reading in its entirety. The following four paragraphs, about post-WWII funding of science in Britain versus the US, are spot-on, in my view:
> Britain’s focused, centralized model using government research labs was created in a struggle for short-term survival. They achieved brilliant breakthroughs but lacked the scale, integration and capital needed to dominate in the post-war world.
> The U.S. built a decentralized, collaborative ecosystem, one that tightly integrated massive government funding of universities for research and prototypes while private industry built the solutions in volume.
> A key component of this U.S. research ecosystem was the genius of the indirect cost reimbursement system. Not only did the U.S. fund researchers in universities by paying the cost of their salaries, the U.S. gave universities money for the researchers facilities and administration. This was the secret sauce that allowed U.S. universities to build world-class labs for cutting-edge research that were the envy of the world. Scientists flocked to the U.S. causing other countries to complain of a “brain drain.”
> Today, U.S. universities license 3,000 patents, 3,200 copyrights and 1,600 other licenses to technology startups and existing companies. Collectively, they spin out over 1,100 science-based startups each year, which lead to countless products and tens of thousands of new jobs. This university/government ecosystem became the blueprint for modern innovation ecosystems for other countries.
The author's most important point is at the very end of the OP:
> In 2025, with the abandonment of U.S. government support for university research, the long run of U.S. dominance in science may be over.
> bodybuilding.com
Obligatory post about the dumbest argument to ever be had online [0]. It’s so good, the Wikipedia entry [1] has a section devoted to it.
[0]: https://web.archive.org/web/20240123134202/https://forum.bod...
[1]: https://en.wikipedia.org/wiki/Bodybuilding.com
This part is really damning: a real efficiency audit might need a lot of access to look for signs of hidden activity, but they’d never need to hide traces of what they did:
> Meanwhile, according to the disclosure and records of internal communications, members of the DOGE team asked that their activities not be logged on the system and then appeared to try to cover their tracks behind them, turning off monitoring tools and manually deleting records of their access — evasive behavior that several cybersecurity experts interviewed by NPR compared to what criminal or state-sponsored hackers might do.
The subsequent message about Russian activity could be a coincidence–Internet background noise-but given how these are not very technically skilled and are moving very fast in systems they don’t understand, I’d be completely unsurprised to learn that they unintentionally left something exposed or that one of them has been compromised.
Even by the standards of this administration...... yikes:
Meanwhile, his attempts to raise concerns internally within the NLRB preceded someone "physically taping a threatening note" to his door that included sensitive personal information and overhead photos of him walking his dog that appeared to be taken with a drone, according to a cover letter attached to his disclosure filed by his attorney, Andrew Bakaj of the nonprofit Whistleblower Aid.Without arguing the merits of the Altera investment or divestment, a common pattern for Intel seems to be a wild see-sawing between an aggressive and a defensive market posture - it’s a regular occurrence for Intel to announce a bold new venture to try to claim some new territory, and just as regular that they announce they’re halting that venture in the name of “consolidating” and “focusing on their core.” The consequence is that they never give new ventures time to actually succeed, so they just bleed money creating things they murder in the cradle, and nobody born before last Tuesday is investing in bothering to learn the new Intel thing because its expected lifespan is shorter than the average Google product.
Intel either needs to focus or they need to be bold (and I’d actually prefer they be bold - they’ve started down some cool paths over time), but what they really need is to make up their goddamn minds and stop panicking every other quarter that their “ten-year bets” from last quarter haven’t paid off yet.
As a ChatGPT user, I'm weirdly happy that it's not available there yet. I already have to make a conscious choice between
- 4o (can search the web, use Canvas, evaluate Python server-side, generate images, but has no chain of thought)
- o3-mini (web search, CoT, canvas, but no image generation)
- o1 (CoT, maybe better than o3, but no canvas or web search and also no images)
- Deep Research (very powerful, but I have only 10 attempts per month, so I end up using roughly zero)
- 4.5 (better in creative writing, and probably warmer sound thanks to being vinyl based and using analog tube amplifiers, but slower and request limited, and I don't even know which of the other features it supports)
- 4o "with scheduled tasks" (why on earth is that a model and not a tool that the other models can use!?)
Why do I have to figure all of this out myself?
Authoritarian governments are arbitrary governments, all decisions are made arbitrarily. Consistency is unnecessary. That's the trouble with choosing power as a guiding principle over reason or consent.
The aggregate demands of the administration are confusing and contradictory. They seem to be simultaneously asking for:
- an end to diversity initiatives
- a new diversity initiative for diverse points of view
- a new policy of not admitting international students with certain points of view
- ending speech-control policies
- auditing the speech of certain departments and programs
- ending discipline of students who violate policies related to inclusion
- disciplining particular students who violated policies related to inclusion
This. If you believe in cryptocurrencies, you can't run to the courts when people use them as designed, even if they didn't use them as intended.
If you end up using the legal system to remediate undesired transactions, what's the point of cryptocurrencies in the first place?
He did not steal anything. He beat the fund (Indexed Finance) at their own game.
He has not stolen anybody's password, has not modified DeFI code - simply executed a set of financial transactions according to the rules (expressed as DeFI smart contracts) and profited from it.
Indexed Finance is an unlicensed investment firm. The promoters knew the risk ( decentralized finance) and now they want to blame someone who outsmarted them at their own game.
I've skimmed through the comments; and seen that most people have commented on the cog in the machine thing, or on layoffs in general and how they suck.
To me, the shock from this blog post was about seeing a Chrome developer relations engineer whom I have grown to admire and who has been doing a stellar job educating web developers on new html and css features, get the sack. He was one of the best remaining speakers on web topics at the Chrome team (I am still sad about the departure of Paul Lewis and Jake Archibald); and produced a lot of top-notch educational materials (the CSS podcast; the conference talks; the demos).
What does this say about Google's attitude to web and to Chrome? What does this say about Google's commitment to developer excellence?
I understand that this is a personal tragedy for Adam; but for me personally, this is also a huge disillusionment in Google.
Layoffs are a difficult thing for employees and their managers. I have seen people (one was a VP of Engineering) escorted out of the building, sent in a cab to home along with a security guard (this was in India), not allowed access to computer or talk with other employees. But, recently have had a very different experience. The current company I work for announced 30% layoffs. The list was made public within one hour of announcement. The CEO detailed the process of selecting people. The severance was very generous (3-6 months pay) along with health and other benefits. The impacted employees were allowed to keep the laptop and any other assets they took from the company. They even paid the same severance to contractors.
After the announcement, the laid off employees were given a few days in the company to allow them to say good byes. I love the CEOs comment on this ' I trusted them yesterday, I trust them today'. This was by far the kindest way of laying off employees imo. People were treated with dignity and respect.