Live data from Hacker News

We have a year to fix security everywhere

jyn.dev

311–320 of 373 posts

Re: We have a year to fix security everywhere

#311

Earlier quoted context omitted.

People aren't that lazy. The organizations getting hacked by ransomware aren't particularly lazy, they're often pretty productive within their domain. Hospitals, airports, etc. The actual problem is that computer security is a black hole. If you let it, it will suck in everything and destroy it. Nobody knows what works so you can spend infinite amounts of time and money on it, then still get popped by a teenager in B…

That’s not been my experience at all when working in DevSecOps. What actually happens in organisations is they define risks and then sign off what risks they’re willing to accept. Any business that looks at security as a binary value is running their business wrong. Period. And yes, people really are that lazy. There are countless studies that have shown just how lazy people are. It’s why shadow IT is a big problem i…

I think that's separate. You can define an obvious risk e.g. "we may be infected with ransomware" and the security spending / productivity costs to stop it are still unlimited because nobody knows how to solve it.

Re: We have a year to fix security everywhere

#312

Earlier quoted context omitted.

The implication of this is quite horrifying. It means a paternalistic AI which is firmly in control. One with no off switch. One which can say "no" to Presidents and despots alike. One which can protect us from our worst citizens. I think you're right, to be honest. I fully understand why people would think this is a horrific outcome, being ruled by AI, but I don't think it matters what we think. I don't think there'…

There is a burgeoning anti-AI movement. We've regulated the heck out of technologies like nuclear power in the past. I don't see why people are so fatalistic about the supposed inevitability of AI development. It seems like a bit of a self-fulfilling prophecy. Consider joining https://pauseai.info/ or similar organizations

Yeah, you should definitely do whatever you think is best, I just am extremely skeptical that anyone can stop this train. At best we might be able to slow it down a tiny bit, or push on it around the edges, but we've opened Pandora's box, and now we're going to all find out what's inside. That's my view, I understand why people hate it and don't want it to be true. I don't really want it to be true, I just don't see much alternative.

Re: We have a year to fix security everywhere

#313

Or we could just dump Linux and Windows and switch to a microkernel operating system, which is much more secure. These endless patching cycles are simply not going to work in the long run. Operating systems get orphaned all the time, especially the ones in cheap Chinese stuff.

"throw away all software written before 2026" does technically solve this problem, if you ignore everything else the article is talking about (deployment and continuity of service)

I assume Microsoft would be able to rewrite the monolithic Windows kernel to a microkernel. So far, they haven't but it wouldn't surprise me if they experiment on Azure with a custom microkernel version of Windows.

Linus Torvalds is a strong proponent of monolithic kernels so I don't see him changing his mind.

Re: We have a year to fix security everywhere

#314

Earlier quoted context omitted.

> That information is easily available other places Often ease of access in the moment is all that matters. If there's a gun nearby you might shoot someone or yourself in a heated argument, but are less likely to go and find/buy one to use. Someone who's stopped from attempting a suicide will likely not try again (70%) A bored/depressed/angry/curious person might try to build a pipe bomb if they can find out how easi…

Most adults in Switzerland have guns at home from military duty and none of this is happening. If this claim had any truth to it you'd see significant gun involvement in neighbour disputes and that simply doesn't happen. Depressed people usually don't have the energy to get out of bed so they're even less likely to think of hunting down instructions on how to build pipe bombs. Mass media really has people being scare…

> from military duty

I think this part is important distinction. Military duty comes with training and rules and so on.

Compared to untrained persons having access.

Similar but apples and oranges

Re: We have a year to fix security everywhere

#315

Earlier quoted context omitted.

[flagged]

I must live in a different Holland, cause I've literally never heard of this, unless you mean around New Years with fireworks I guess

Seriously? They are used all the time. See here:

https://nos.nl/artikel/2544424-dit-jaar-meer-dan-1000-aansla...

That was the number of predicted bomb attacks in one year alone in a really small country.However the prediction was low. In the end 2024 counted more than 1500 of them! And the government set up a task force: https://www.rijksoverheid.nl/actueel/nieuws/2025/04/16/offen...

This article speaks of a drop, but still 100 attacks per month https://nos.nl/artikel/2623950-minder-aanslagen-met-explosie... - which adds up to 1200 in a year. It is dropping a little bit compared to 2024 but still a huge thing. 100 a month is 3 a day. Many don't make the national news anymore.

Re: We have a year to fix security everywhere

#316

Earlier quoted context omitted.

[flagged]

> blows up the others' house. Sometimes half the block along with it Can you provide a source for this? I had a look but all I could find were a couple of scaremongering style media reports from ~2022 saying it's getting worse but no information about if any of the bombs actually went off or if anyone was injured. Certainly nothing like "half a block" getting blown up "sometimes".

Here a whole building evacuated: https://nos.nl/artikel/2605174-vier-woningen-onbewoonbaar-na...

Some inhabitants of neighbouring flats are still banned from their flat. And it was three weeks ago.

Five houses unhabitable: https://nos.nl/artikel/2605174-vier-woningen-onbewoonbaar-na...

It's also very common with robbing ATMs, usually known as "plofkraak" but that phenomenon seems to have subsided a bit.

Re: We have a year to fix security everywhere

#317

Earlier quoted context omitted.

[flagged]

Is Holland that good at containing this "there's a huge problem with makeshift bombs" news pieces coming out in the open?

Probably it doesn't make the international news because most of them are just lowlevel criminals blowing each other up.

Re: We have a year to fix security everywhere

#318
post #81
post #7

Earlier quoted context omitted.

The difference is memory bandwidth. The M5 Ultra that's coming out on 22nd September can do 1,200GB/s. The M5 Max you can buy today only has 614GB/s.

It is and it isn't. Why are you comparing the m5max instead of the m4ultra? The big deal to me is the number of compute cores for prefill tps, which is suppose to be 4x faster on the m5ultra. It's my opinion that the m5 ultra is going to be a really big deal in terms of local AI accessibility. Flash sized models (~200-300b params) are going to be reasonably fast as long as you aren't throwing 40k context at it on eac…

I guess you mean M3 ultra since M4 ultra never existed.

Re: We have a year to fix security everywhere

#319
post #176

Earlier quoted context omitted.

[flagged]

Those makeshift bombs are just fireworks bought in belgium

Yes that's what I said. But very heavy fireworks, and combined to do a lot of damage. Certainly comparable to a 'pipe bomb' that was being discussed.

Re: We have a year to fix security everywhere

#320

Earlier quoted context omitted.

I think it's been pretty much proven by now that there are no cases where local inferencing is better than remote inferencing, unless absolute privacy is a hard requirement. The efficiencies that come with datacenter scale and hw can't be beaten.

Yeah, but data centers don't usually host abliterated models, hence the point of the article.

You can rent B300 at hourly rate and run whatever model you want.
Post reply on HN