Hacker Newsnew | past | comments | ask | show | jobs | submit | ks2048's commentslogin

We were mad about bloated, unnecessarily large web pages taking 3 seconds to load. Now, it takes 8 seconds to first pass a "checking if you're a bot" page or worse - making you click on pictures of crosswalks.

> crosswalks

And their a11y/internationalisation is horrid.

We have pedestrian crossings, not crosswalks. We don't have fire hydrants (instead a different solution). We don't have yellow schoolbuses. Our traffic lights look different (and have different names in different cultures). And those examples are just the obvious problems with some captchas. Usually there are more subtle problems with verification UIs.


meanwhile agents have been able to pass these captchas for a while now, so it's unclear what the point of them now is. It's like they want to keep out the dumb bots, but any agent with reasonable intelligence can come in.

Yes, the bot detection wait IS starting to get out of hand. As for solving a puzzle, I just exit the page and move on with my day.

This is the real hidden cost of the bots. I absolutely loathe the human verification hoops I have to jump through now, more than anything else mentioned in this thread.

yesterday I visited a page with TWO! captchas side by side. When I got through the second one the first one had expired...

Reddit blocks anonymous mobile web traffic behind a capcha now.

One way to look at this is that the internet is healing. Platforms are closing themselves off to growth and scabbing over.


I noticed an Amazon page had "log in to read the reviews". Not sure how widespread that is, but seems like a big deal if you can see item reviews w/o login

well you need to login to buy it anyway so it's not that much of a problem

The animated graphic labeled "Occam's razor, formalized" is bizarre. Is that really visualizing "Occam's razor, formalized"?

Ah, over-the-top larger-than-life LLM-isms, they are really funny when you see them in a company blog, but they are vomitive when it's your coworker copy-pasting it and insisting you on reading it.

I was expecting Occam wearing a suit.

Animated SVG of a pelican shaving with Occam's razor?

No. They don't say "sorry". They say - our technology is just that powerful - please consider that in next funding round.

Counter argument: Democracy does exist. (it's just a fuzzy concept like most words we use).

> win the race

There is no finish line. Anthropic gets somewhere and others get "there" (or somewhere near "there") a little bit later.


Nothing says "Let's make a deal" like constantly insisting we are Good and they are Evil.

In politics every single person playing the game is acutely aware of the rules. This is why talks are held behind closed doors so the rules can be suspended for a while.

Sounds like a decent name for a sports team - should have used that instead of Commanders.

If that became popular, the AIs would learn how to generate a realistic depth map along with any generated image.

How would that work? I thought the premise here is that you can fool the apple camera by taking a (very carefully aligned) picture of a still image (printed out).

A depth map from the apple camera (again, signed) would show that the entire image had the same distance from the camera.


You're right. I think my comment above doesn't make sense - it wouldn't help in this case.

The photos are cryptographically signed in the apple image pipeline so it's not as simple as just AI generating something. That said, I can't see how this is any different to all the other times we have embedded crypto keys in consumer hardware where eventually someone finds a way to extract the key and the whole thing is busted open.

Given the whole private cloud bit, I am assuming they keep the private keys server side and never let them out.

I think there's a chain of trust. The sensor signs raws, and the private cloud takes signed raws, does minimal processing so they're at least coherent, and re signs that output (maybe even including the original signed raw as well in the image file).

How would the server know that the request is coming from a real iPhone?

This is a pretty standard application of trusted computing and can be done entirely on the iPhone. A server would only possibly be needed for anonymization (while retaining key revocation capabilities if a key does end up leaking), but there are serverless ways to do even that (TPMs have supported these for a while now).


It wouldn't, but you could validate that a particular picture was created at a particular time, and had not changed, for example, especially with metadata that you may not want to share but that establishes certain parameters like gps coordinates. A lock, rather than an end-to-end pixel signature, which shows what was contemporaneous rather than exact provenance. If an event happened on day 0000-00-00 00:00:00am, but your photo was taken at some other time, it casts doubt.

I think a big part of validation for things like these are just "could it have been modified since Z event happened", because Z was not something people paid attention to before.


That's just a timestamping service then, not a content provenance/authentication scheme. Timestamping has been a solved problem for years; certificate authorities offer this, or you could just throw a hash onto any sufficiently trusted blockchain.

Nothing prevents anyone from opportunistically pre-generating and timestamping millions of permutations of fake kompromat and then selectively revealing the one that turns out to be useful after the fact.

You could charge per attestation, but the economics of that don't look great; you could demand publication of the image itself before attestation, but that would obviously not fly for most use cases out of privacy concerns.


> Nothing prevents anyone from opportunistically pre-generating and timestamping millions of permutations of fake kompromat and then selectively revealing the one that turns out to be useful after the fact.

If you're doing server-side timestamping and someone is sending millions of items, I think you just ban them. Apple accounts are free but not inexpensive.


That's a good point, You might still be able to trick the cloud to sign your photos, but that's something they could patch in updates without losing control of the key. They could have the server only sign photos taken on the latest ios version.

And honestly you could have a similar antitampering oracle that was at least obscured, in terms of "we've detected tampering but won't tell you how or why", which is frustrating but I have to imagine that 99.9%+ of images are clean.

Nobody has breached the Secure Enclave, not sure it’s doable without investing millions in direct circuit manipulation. Seems good enough

> generate a realistic depth map along with any generated image.

There are already pretty good depth map generation algorithms (for a decade or so) which works on 2D images.

Generate the image, feed it to a depth map generator, viola.

However, you can't get it signed by the sensor itself. That'd be hard.


Even simpler, a 3D printed relief with an image "stamped" on it, now you effectively have a 3D image.

…and the PDAF data will show how shallow it is.

... don't make it so shallow then. Perfectly possible in a consumer-friendly 3D printer for a face or even human body if you have lots of time for the prints.

You’re well on the way to 1:1 replicas at this point. Next you’ll need to match the thermal signature and the exact weather in the sky for the time at that location.

This is almost reaching Kubrick’s joke about wanting to film the fake moon landing on location.

but what are we really trying to solve here. you're suggesting a helluvalota work for what purpose?

Then take and sign a one-second video and you’re adding a few orders of magnitude of complexity again.

Sounds like Rincewind's spell from the Octavo.

It seems Visa revenue is $40B/year. You shouldn't compare that to the amount of economic activity they enable - you should compare it to how much it could cost to run a system like theirs.

In the modern USA, "saving lives" is anti-correlated with policy, so let's see how this plays out.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: