Hacker Newsnew | past | comments | ask | show | jobs | submit | syllogism's commentslogin

You can't take any statement like this remotely seriously. We live in a world where NSA officials can testify before congress that they don't "collect" data, because that's true under some baroque definition of "collect" that they invented and didn't tell anyone else about.

Similarly you have no idea what definition OpenAI intend for terms such as "specific user data", "accessed" etc. And we have no idea what non-excluded possibilities actually did happen that they simply omit from their statement.

In practice OpenAI and many others have created a situation where they're actually unable to make any credible denial of anything really.


If you're submitting an eight page conference paper you're very often hunting runts (short lines ending paragraphs) and rewording for better justification, especially on the first page and even more so in the abstract.

First-page space is at a premium because you want the reviewer to scan the introduction well, and it's great if you can fit a key figure that explains the concept on the first page.

The game's probably very different now that there's such a flood of submissions but when I was reviewing I always saw messy alignment on the first page as a sign the paper was probably rushed, and usually I could see that elsewhere in the paper too.


The optimal amount of stress about that stuff is not zero, and most teenagers are going to be desperately biased towards "none of this matters, just peermax".


Couldn't some of that because of how people act like EVERYTHING is the most important thing for kids to do, irregardless of how it actually stacks up, and some develop something akin to alarm fatigue and stop listening?

Plus almost everyone can get into a college, there is only really competition for a handful of elite schools. My college wanted SAT scores for admission, I did not take the SAT, they still admitted me without question. As long as you don't fail out your first two semesters in a row most colleges don't give two craps about your highschool performance.


This interview feels weird to me, maybe because there's lots of places where I'm thinking there's an obvious idea that isn't raised.

Like, it seems obvious to me that sleep has a higher opportunity cost in humans than most other animals. So naturally there's more evolutionary pressure in humans to sleep more efficiently.

Is this actually true? Dunno! But it was really weird that it doesn't get brought up.


It comes up because people are mistakenly conflating consciousness with moral personhood.

People want to be talking about whether AI suffers in a morally meaningful way. In non-human animals this debate is often centered around the question of whether the animal has conscious experience, because there's little doubt that much of the emotional and experiential systems are shared.

The analogy goes wrong with AI, where definitions of "consciousness" would seem to apply in the sense that the model clearly has a category for itself in its world model, feeds back on its output, etc. However the analogy between how it works and anything we would recognise as emotion or suffering is extremely strained.

The solution is to just focus on ths question of what we really mean when we think of morally relevant suffering. It's a much clearer question than "consciousness" and it sidesteps the problem.


You're going to make life much harder for yourself, not easier, because you'll still need German legal advice but now you need an expensive multi-national lawyer/firm. Anyone cheaper will refuse to touch it.

Germany cares about where the management of your company actually happens, not just where the entity is incorporated. So you're not going to avoid German bureaucracy, it's going to be worse not better.


Maintainers need to keep a wall between the package publishing and public repos. Currently what people are doing is configuring the public repo as a Trusted Publisher directly. This means you can trigger the package publication from the repo itself, and the public repo is a huge surface area.

Configure the CI to make a release with the artefacts attached. Then have an entirely private repo that can't be triggered automatically as the publisher. The publisher repo fetches the artefacts and does the pypi/npm/whatever release.


The point of trusted publishing is supposed to be that the public can verifiably audit the exact source from which the published artifacts were generated. Breaking that chain via a private repo is a step backwards.

https://docs.npmjs.com/generating-provenance-statements

https://packaging.python.org/en/latest/specifications/index-...


Pardon my limited understanding but my read of the suggestion was simply to perform the same exact operation that the public would do to verifiably audit the exact source when generating the official published artifacts, the point was just that there was no automation to do so directly from the public repo.


The maintainer can verify the correspondence between source and release, but the public has been deprived of this verifiability.

This matters. Consider the XZ Utils compromise where a malicious maintainer hid the line that triggers compilation of the (otherwise dormant) backdoor payload in a generated file present only in the release tarball: https://www.openwall.com/lists/oss-security/2024/03/29/4. If the public had the ability to audit that the release tarball was correctly built from the version-controlled code, this would have been much more difficult to hide.


Thanks for circling back.

I interpret your comment as emphasizing that the current norm relying on publicly accessible (GitHub) infrastructure building releases in public and thus allowing public review of logs and artifacts provides tremendous value (and I admit that true 100% binary reproducibility is an often nearly unreachable goal still not yet typically expected as the norm).

> Breaking that chain via a private repo is a step backwards

I was stating that performing a reproducible build elsewhere and distributing the output could in theory still be validated though it would require re-running said build for one's self and comparing the outputs. This might encourage the pursuit of 100% reproducibility! The chain need not be considered broken just because the final link is private.

> the public has been deprived of this verifiability

This is not what I was trying to point out, though I agree the cost of verifying reproducibility would be higher. My point was that anyone could still perform the same steps themselves and verify the output. Yes this would be more work than reviewing logs on GitHub.

OP's primary concern with today's standard approach appears to be the automated connection from GitHub build action -> release. Even simply requiring manual maintainer intervention to copy the action output over to a release seems to satisfy both their and your concerns.

> If the public had the ability to audit that the release tarball was correctly built from the version-controlled code

I am not intimately familiar with all the details of the XZ fiasco but agree that it offers an opportunity to learn and make changes to work toward making sure nothing similar can happen to any project again. If I am reading your link correctly, it serves as an example of members of the public (not a maintainer of XZ) doing exactly what you said: auditing the release tarball. IIRC this occurred only after an additional point release (apparently allowing the attacker to fix a bug in their backdoor) because of a performance regression.


Right, the public was able to spend manual effort hand-auditing one specific tarball after it had already been singled out as suspicious for other reasons. In order for verification to effectively increase supply chain security, it needs to become uniformly standardized, fully automated, and ubiquitous. That’s the ultimate goal of the provenance attestation mechanisms that would be defeated by indirection through private repositories.

If you want to require extra maintainer intervention for releases, there are better mechanisms available for that, such as workflow_dispatch.


this kind of compromise is why a lot of orgs have internal mirrors of repos or package sources so they can stay behind few versions to avoid latest and compromise. seen it with internal pip repos, apt repos etc.

some will even audit each package in there (kind crap job but it works fairly well as mitigation)


Just keeping a lockfile and updating it weekly works fine for that too yeah


The corruptions of this administration are legion, but this isn't one of them. Unless you can point to something Lutnick did to create this outcome, I don't see how he had a better view of the whole thing than anyone else.


Who cares who came up with the illegal tariff implementation, the point is that a member of the government profited off of their own administration's incompetence.

It's obscene. I don't care whether a law was broken or not.

You want to profit from government incompetence? Stop being part of the government then.



Isn't Lutnick literally the chief architect of Trump's tariff policy? I can hardly imagine anybody more responsible for creating this outcome besides Trump himself, who would presumably have appointed somebody else if Lutnick hadn't been available.

> I don't see how he had a better view of the whole thing than anyone else.

Given the above, you really don't think Lutnick had a "better view" of the likely outcomes and timelines, including the Trump admin's planned and gamed out responses to certain outcomes, than the average Joe on the street? I think that's extremely, uh, naive.



The actions of the US government here are openly corrupt.

The point of the supply chain risk provisions is to denote, you know, supply chain risks. The intention is not to give the Pentagon a lever it can pull to force any company to agree to any contract it wants.

Hegseth doesn't even pretend that Anthropic is actually a supply chain risk. The argument for designating them so is that _they won't do exactly what the government wants_.

People use the term "fascism" a lot and people have kind of tuned it out, but what do you call a government that deals itself the power to compel any company to accept any contract, and declare it a pariah on thin pretext if it objects?

By taking the deal under these conditions OpenAI is accepting this. They're saying, "Well, sucks to be them, life goes on". They're consenting to the corruption and agreeing to profit from it. But they'll be next, and if the next company in line has the same stand then yeah, the government can force any company to do anything. There's nothing normal about this.


I don't understand how any sort of deal is defensible in the circumstances.

Government: "Anthropic, let us do whatever we want"

Anthropic: "We have some minimal conditions."

Government: "OpenAI, if we blast Anthropic into the sun, what sort of deal can we get?"

OpenAI: "Uh well I guess I should ask for those conditions"

Government: blasts Anthropic into the sun "Sure whatever, those conditions are okay...for now."

By taking the deal with the DoW, OpenAI accepts that they can be treated the same way the government just treated Anthropic. Does it really matter what they've agreed?


From a level headed outside perspective

It looks like Anthropic likely wanted to be able to verify the terms on their own volition whereas OpenAI was fine with letting the government police themselves.

From the DoD perspective they don't want a situation, like, a target is being tracked, and then the screen goes black because the Anthropic committee decided this is out of bounds.


> From the DoD perspective they don't want a situation, like, a target is being tracked, and then the screen goes black because the Anthropic committee decided this is out of bounds.

Anthropic didn't want a kill switch, they wanted contractual guarantees (the kind you can go to courts for). This administration just doesn't want accountability, that's all.

It was OpenAI that said they prefer to rely on guardrails and less on contracts (the kind that stops the AI from working if you violate). The same OpenAI that was awarded the contract now.


I don’t know why more people don’t see this. It’s a matter of providing strong guarantees of reliability of the product. There is already mass surveillance. There is already life taking without proper oversight.


I think it's a bit more nuance than that. The government (however good or bad, just bear with me) already has oversight mechanisms and already has laws in place to prevent mass surveillance and policy about autonomous killing.

So the governments stance is "We already have laws and procedures in place, we don't want and can't have a CEO to also be part of those checks"

I don't think this outcome would have been any different under a normal blue government either. Definitely with less mud slinging though.


If you think a blue government would even consider threatening to falsely accuse a company of being a supply-chain threat in order to gain leverage in a contract negotiation, you're insane. There's nothing remotely normal about this, it's not something you see in any western democracy


>Definitely with less mud slinging though.


Government's free to not like the terms and go with another provider. That's whatever.

Government's not free to say, "We'll blow up your business with a false accusation if you don't give us the terms we want (and then use defence production act to commandeer the product anyway)". How much more blatantly authoritarian does it get than that?


This is wise analysis. To summarize: appeasement of the Trump administration is a losing strategy. You won’t get what you want and you’ll get dragged down in the process.


did we really need all this? Didn't the experiences with Ivy League Universities alreay prove it all out?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: