Hacker Newsnew | past | comments | ask | show | jobs | submit | cluckindan's commentslogin

The Dunning-Kruger Effect is Autocorrelation (2022)

https://economicsfromthetopdown.com/2022/04/08/the-dunning-k...


3 copies, on 2 different media, 1 offsite.

Start with trying to find the xz vulnerability and other software possibly tying into that.

Is there code that does something completely different than its comments claim?


Another way to phrase what I am asking is ... Does AI understand the context of code deep enough to know everything a piece of code can do, everything a service can do vs. what it was intended to do. If it can understand code that far then it could understand all the potential paths data could flow and thus all the potential vulnerabilities that several piece of code together could achieve when used in concert with one another. Advanced multi-tier chess so to speak.

Or put another way, each of these three through three hundred applications or services by themselves may be intended to perform x,y,z functions but when put together by happy coincidence they can perform these fifty-million other unintended functions including but not limited to bypassing authentication, bypassing mandatory access controls, avoiding logging and auditing, etc... oh and it can automate washing your dishes, too.


Some models can,

depending on the length of the piece of code,

is probably the most honest answer right now.


Fair enough. I suspect when they reach such a point that length no longer matters then a plethora of old and currently used state sponsored complex malware will be realized. Beyond that I think the next step would be to attain attribution to both individuals and perhaps whom they were really employed by. Bonus if the model can rewrite sanitize each piece of code to remove the malicious capabilities without breaking the officially intended functions.

Just wait until GitHub starts requiring this.

FB was always conversion as a service

”maybe there is a simple switch to change people without having to change any [other] aspect of their [lives]”

The difference with psychedelics is that they enable and manifest those behavioral changes.


Wasn’t this posted like three days ago? The OP says ”7 hours ago”.

I remember seeing most of these comments too, even though they all seem to have been posted just a few hours ago.

The posters’ own comment lists seem to agree that the comments were posted three days ago.


Hacker News does weird stuff to post / comment timestamps if a post is resurrected from the second chance pool. Makes both the post and comment look new even though they’re not. Not sure why, it’s kind misleading, I guess they want to hide the necromancy for some reason.

Instead of paying for a SaaS, a team can autoprogram an on-prem clone for less.

Totally possible, and some teams do. You need a state store, a evaluator job, a propagation layer to push state changes to every instance, a SDK, a dashboard, alerting, audit logging, RBAC, and a fallback strategy for when the coordination layer itself goes down.

It's not complex individually, but it takes time, and it's the ongoing maintenance that gets you. Openfuse is a bet that most teams would rather pay $99/mo than maintain that.

That said, a self-hosted option is on the near-term roadmap for teams that need it.


That’s good. The ”open” in the name kind of implies a ”self-hosting first” approach.

I know this sounds weird, but it is in fact self-hosting first :)

The reason why I only launched the cloud version of it is just so I could have a faster iteration pace in the back-end after having people actually using it reliably.

Now it is pretty solid and self hosting is the next thing to go out.

If you check the SDK code, it is ready for self hosting.


You can avoid the infinite scroll by taking the short video ID and inserting it into the regular player URL.

Why not Seek, the gamified version of iNaturalist?

Seek already does exactly the same thing that this app store listing advertises. You aim your camera at something, Seek identifies it as a random species, and then you get credit for that species against a big database.

People like it, but I also don't see why you'd need two Seek apps. You don't really need one, without an actual method of identifying the organisms.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: