Live data from Hacker News

Viewing profile — david_shaw

david_shaw

HN member
Joined
Sat, Sep 25, 2010, 5:50 AM UTC
HN karma
3,061
Public activity
539 items

About david_shaw

I do security.

contact:

  dshaw
    (at)
  dshaw.net

Recent public activity

  1. comment
    Comment #49117516

    I said this about OpenAI/Hugging Face, and I'll say it again for Anthropic: It's not that I think this is fiction; I'm confident these events actually happened. But I think they we…

  2. comment
    Comment #48999789

    I don't think this is fiction, but it's pretty clearly a marketing-release rather than a normal security disclosure. OpenAI has strongly fallen behind after the incredible lore sur…

  3. comment
    Comment #48654003

    At risk of quoting too much of the article, it opens with this: > A requirement for staying sane while working in public as an open source maintainer is realizing that every issue,…

  4. comment
    Comment #48611761

    I'm playing through the couch co-op game Split Fiction, and this is basically the premise (with more fun gameplay).

  5. comment
    Comment #48482252

    > A nation that possesses powerful AI facing one without it—or even facing one that is behind in AI by 3 years—could be the equivalent of an army of World War II Marines facing an …

  6. comment
    Comment #48482141

    > we might have wished we prepared for more Do you mean policy-wise (like Dario is talking about), or more broadly? I wonder about broad preparedness, but unfortunately there's not…

  7. comment
    Comment #48482104

    > Members of the trusted coalition should freely share chips and semiconductor manufacturing equipment (SME) with each other, while working together to deny it to adversaries. US e…

  8. comment
    Comment #48328237

    The problem with Mythos and Glasswing related hype is that finding vulnerabilities isn't the problem for most organizations. It's great that Mythos and similar models can find vuln…

  9. comment
    Comment #48291132

    The Fallout games often exemplify this: nearly every decision you make is morally ambiguous, and often has far-reaching repercussions in the story and world.

  10. comment
    Comment #48197414

    > https://www.openbsd.org/images/PinkPuffy.png > Apparel (t-shirts, so far): https://openbsdstore.com/ Interesting. In the image you linked (PinkPuffy.png), the cat's hat says "sec…

  11. comment
    Comment #48086840

    He certainly popularized it (maybe coined it), but I've seen a lot of organizations and developers repeat that mantra. Even without the specific words, look to product teams debati…

  12. comment
    Comment #48086645

    It's easy to be cynical because, yes, both the problems and solutions seem dead obvious in hindsight. But for a long time (and maybe even still), a hacker creed was "move fast and …

  13. comment
    Comment #47938143

    We'll see more of this, but this particular review is driven by marketing narrative. I'll explain what I mean: Back in 2010, as a security engineer, I also looked at OpenEMR. It wa…

  14. comment
    Comment #47931363

    I think the idea is that if you're given an improperly configured restricted shell/command access, you can use any of the listed tools to gain access to some subset of what that us…

  15. comment
    Comment #47839233

    I don't have a subscription to The Economist, but I was interested in the concept of these organizations as "neo-primes." I found an article on The Cipher Brief describing them: ht…

  16. comment
    Comment #47722745

    > If it were secure, it would only notify that there is a message, with no details included. You're right. This is configurable via settings, but is not the default state. That sai…

  17. comment
    Comment #47327194

    I think the title should read "RunAnywhere," not "RunAnwhere."

  18. comment
    Comment #47254186

    It would be an interesting and potentially useful project to combine these camera locations with Maps routing -- similar to "avoid toll roads," we could "avoid surveillance cameras…

  19. comment
    Comment #47240335

    It's wild that all other comments in this thread (so far) seem to completely miss this nuance. There are lots of services that, in their terms, require users to be adults. This typ…

  20. comment
    Comment #47189418

    I'd prefer to see board (or executive) level signatories over lay employees -- the people who can enforce enterprise policy rather than just voice their opinions -- but this is enc…

  21. comment
    Comment #47154957

    > What does "solving" coding mean? Maybe this was sarcasm, but it's a good point: "Coding" is solved in the same way that "writing English language" is solved by LLMs. Given ideas,…

  22. comment
    Comment #47114909

    This is for sure an inspirational project, but I wish the barrier to entry was lower. I've noticed e-ink/paper displays having somewhat of a moment right now (especially very small…

  23. comment
    Comment #47104038

    > I am seeing something closer to the opposite of skepticism among vulnerability researchers. My initial claim was overly broad, but the feeling of discomfort feels widespread to m…

  24. comment
    Comment #47092267

    There's a lot of skepticism in the security world about whether AI agents can "think outside the box" enough to replicate or augment senior-level security engineers. I don't yet ha…

  25. comment
    Comment #47056748

    Totally. I meant if people were all using the same replacement software, that joining groups' different "servers" would be the same experience. Absolutely agree that if everything …