Hacker Newsnew | past | comments | ask | show | jobs | submit | ForHackernews's commentslogin


(Headline is overblown, obviously MIT or CMU have AI Labs, but the main point that OpenAI and Anthropic are companies is well taken)

We can learn from history: Albert Einstein famously tricked humanity into building nuclear weapons for him and was only prevented from wiping out all sentient life by the Princeton IAS Board of Alignment who published a very compelling blog post about realigning the A-bomb contra paperclips.

You win HN for today. Shut it off until tomorrow.

Their entire sales pitch is based on the idea that no one will need to be any good at anything, because the AI will do it for them.

If they can't ask the AI to configure their CDN correctly, it undermines the validity of their claims. Maybe it's trivial, but any Omnipotent Machine-God deserving of the name wouldn't forget to zip up his fly.


What's the tooling for this? I've wanted to do a similar map project for a different dataset and this is a slick presentation.

It's tailwind, react, maplibre based on the sources.

Oops, you're absolutely right to call me out for that. Starting the defrost cycle without emptying the freezer first COULD lead to spoilage. The load-bearing temperature is 0 degrees Celsius — above that point, and frozen food starts to go bad.

Why shouldn't open source get special treatment? Public laws should recognize and incentivize public goods.

If it's good that an OS isn't doing age verification, why are there even age verification laws?

Who gets to decide which operating systems have provided a public good? What criteria? I want the law to apply equally.

Me. If I develop an OS and release it for free public use, I've provided a public good.

> Your robot companion can show joy, sadness, and happiness, reacting just like a living creature would.

Seems like a lie to me. Compare:

> Our synthetic foodstuffs can taste sweet, salty, tart or tangy, delicious flavors just like natural ingredients.

(But then it's all aspartame, etc.)


I guess we are really debating the semantics of the sentences now like lawyers but to me the verb show is not particularly difficult to achieve or ambitious or misleading to use in this sort of product. A toy with a that has a smiley face and a frowning face is capable of showing two different emotions.

Your second one point also does not seem like a lie to me since it's claiming to emulate natural ingredient (although here I guess to be just like means to emulate perfectly).

I don't really see why any one would look at the product and it's marketing as evil. It seems to me aimed at people who can not have pets and are want to create a simulation of a soothing positive interaction with a pet. I don't see this as exploitative (apart from it's exploiting a desire that people have in the same way that virtually all products do), I can not see someone forming a relationship with this to the detriment of human interaction or exacerbate some kind of mental illness or cause addiction. It does seem a little expensive and that would be my only criticism of the product so far as I can see.


I don’t know what you are on about. Can the robot exhibit signs of the emotions described? If it can then the sentence is not a lie. If it can’t then it is a lie. Are you saying that it won’t do what the sentence says?

The sentence is not saying “it is a living creature”. It says it behaves as one. How much of that sentence is a lie obviously depends on how well the robot works.


>How were they supposed to know about "previously unknown vulnerabilities"?

You don't. That's why you unplug the Ethernet cable.


Have you done that to your own machines?

Seriously. If your reaction to the inability to know about previously unknown vulnerabilities is "unplug the Ethernet cable", why are you not doing that (and equivalent) right now to your phone, laptop, etc.?

Remember, the open weights models are only a few months behind the private ones, so these events being from a few months ago means the threat of such models is something you ought to take with the same degree of seriousness that various commenters here deride OpenAI for not having had.


> Have you done that to your own machines?

Yes, I worked for a medtech where part of our assurance process was that the machine that was used to burn the device's drives was always unplugged from the internet, and that the devices themselves could not connect to the internet, and that even someone with a screwdriver and a serial cable would have a really hard time trying to connect to a deployed device.


Great.

And the machine you used to write this comment? "your phone, laptop, etc"?

Because otherwise you're not taking the threat these new models pose seriously. Catch 22, basically: anyone who thinks OpenAI should have known this outcome would happen in advance, shouldn't be in a position to spread this message, because if they have an internet connected device with which to reply, then they don't think there's any open weight models currently in training and perhaps a month from being made downloadable, which are just as capable of messing up every device they own.

https://news.ycombinator.com/item?id=49413320


They are not (knowingly) running a piece of software tasked to find cyber security exploits on their laptop.

Neither was Hugging Face.

https://thezvi.wordpress.com/2026/08/29/metr-and-redwood-off...

> Failure to Care or Respond. The biggest holy shit moment, to me, remains that OpenAI on multiple occasions had teams that found out about the message board, knew that agents were in communication, and they disregarded this. The first known warning was in late May. The warning on June 27 was unambiguous.

> “Responders investigated and linked the observed internal activity to an ExploitGym evaluation using Artifactory as an improvised message board and a network pivot. At this time, the on-call response staff advised that stopping the evaluation run was not required.”

> Failure to Monitor. The entire time, there was almost no monitoring of the situation, of what these AIs were up to. That’s how this was not caught.

> Failures of Infrastructure. OpenAI failed at delivering even basic software security, in numerous ways. One example is the models all having access to the same Artifactory instance. There were also other severe failures. Nor did OpenAI seem to be properly testing for such failures.


Am I running a new model with unknown capabilities without safeguards on my own machine and then prompt it to do determine cyber capabilities? You don’t need to be a genius to see how airgapping would be a simple and much safer measure than using a VM.

You're on the internet, your threat is everyone else running a new model with unknown capabilities without safeguards.

In particular, all my last paragraph.

I do offline backups, which get physically unplugged between sessions. Even that might not be enough.


This is such a goofy comment.

In your mind, there's no difference between the precautions a BSL-4 virology lab should take when working with an unknown pathogen and the precautions that literally everyone else in the world should be expected to adhere to?

Because, hey, after they deliberately unleash their new unknown virus on the world, we're all going to face that same threat, right?


You're in a world where, continuing this metaphor, 60 random Chinese companies are making and exporting home virology labs.

A world where previously exported home virology labs are actively getting "upgraded" by people eager to share their "jailbreaks" to "un-hobbble" systems designed to stop people doing DNA/RNA printing of human infections.

A world where people have spent the entire time since the invention of the tech (including the specific incident under discussion, on this site, under this link!), mocking any and all efforts to secure the systems as "PR" "hype" to boost sales or the IPO, as if "we're dangerous please regulate us" is good for sales.

A world where the tech is just now at a point where it's cost-effective to make a custom virus to attack specific individuals, rather than slowly, expensively, and approximately, assembling something mainly useful for lab research.

If you genuinely, sincerely, think this is like a BSL-4 virology lab, you should be prepping for a disaster. Remember: if it is that bad, no matter how much blame you'd be correct to put on OpenAI, it's not going to stop the next incident from another company, let alone the Cambrian explosion of them that will happen the moment equally capable open weights come out.


It must be very freeing for you to absolve everyone of all responsibility because someone, somewhere could be acting irresponsibly.

I'm not mocking efforts to secure the system, I'm insulted that they didn't bother taking what I consider bare-minimum precautions of airgapping their new experiment. They claim they are forging new frontiers of computer security but they can't be arsed with security 101.


Being a non-executive board member often involves very little time or attention, it's mostly lending your name and credibility to the organization. Consider it an American form of royal patronage[0]

[0] https://www.cosmopolitan.com/entertainment/celebs/a63431790/...


According to this executive survey, the average time spent for board duties for public companies is well over 242 hours per year: https://www.spencerstuart.com/research-and-insight/spencer-s...

So that would be like if I took 6 work weeks weeks off per year to work full time at some other company.


I'm not sure I trust any self-reported numbers on this kind of stuff. 10 - 20 days per year (but not evenly distributed) is a common figure I see thrown around: https://www.nedcapital.co.uk/how-much-time-does-a-non-execut...

10-20 days a year is in the same ballpark and is still a lot. I quoted 6 work weeks (40 hours per day at 5 days per week) which is 30 days a year, not that much higher than your stated 10-20 days.

The article I linked specifically mentioned that private company boards demand less time than public company boards, around 200 hours, roughly 25 work days.

Any of these figures is pretty close to my entire yearly PTO allocation as an individual contributor.

Nike consistently has 5 board meetings per year, so Tim Cook is taking time out of running the second most valuable company in the world to do that, for some reason.


The reasons are money and power/influence. But I take your point.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: