Hacker Newsnew | past | comments | ask | show | jobs | submit | wildfireday2's commentslogin

Moreover anyone glomming onto this paper for goal-post-shifting “AI can never” should:

1. Read the last sentence of the abstract, and

2. Reflect that frontier reasoning agents already increasingly integrate multimodal models.


The worst thing about the AI boom is how tech bros feel comfortable abusing the goalpost fallacy. So annoying.


If your glib comment is referring to me as a techbro and doing the annoying worst thing, then maybe you should explain how I am comfortably abusing the goalpost fallacy given the explosion of agentic AI capability.

I simply point out here, that fully accepting the paper’s premise, the paper’s conclusion isn’t limiting on frontier AI reasoning agents. The paper posits the necessity of multimodal world models and the limitations of LLMs. Frontier agents aren’t simply LLMs and do increasingly integrate increasingly capable multimodal models.

> Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.

> Comments should get more thoughtful and substantive, not less, as a topic gets more divisive.

> When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."


Funding cuts at NIST did not lead directly to this. You must be new here or haven’t spent a lot of time directly interfaced with NIST on cybersecurity in decades past.

And NIST’s role with CVE’s has always been purely ministerial/clerical. It has never been their job to do even a cursory investigation into the vulnerability itself.


OP suggests something at NIST changed in 2024, where they stopped doing as much verification as they did before.

To be sure, the suggestion is not funding cuts, but an increase in workload with same funding.

Here is the 2024 NIST announcement OP links to: https://nvd.nist.gov/general/news/nvd-program-transition-ann...

> Currently, we are prioritizing analysis of the most significant vulnerabilities. In addition, we are working with our agency partners to bring on more support for analyzing vulnerabilities and have reassigned additional NIST staff to this task as well.

The OP described this as "NIST effectively hit pause on deep analysis. "

It does sound like they stopped doing something they used to do in 2024. I personally have definitely not spent a lot of time directly interfaced with NIST on cybersecurity in decades past, I know nothing about it, just what I read in OP.

Are you saying the OP was wrong to call what NIST used to do "deep analysis", and/or that the thing NIST stopped doing was "purely ministerial/clerical" in a way that it would not have caught fake reports anyway, contradicting the OP? Or other?

Again, to be sure, the OP's suggestion was not that this was caused by NIST funding cuts, but by "a massive surge in vulnerability reports,"


The main point is NIST is _downstream_ of CVE issuance. Yes, they can — and still do — add disputed/rejected tags to CVEs, but in many cases by then it's already "too late." The CVE has an ID and a lifespan of its own.

NIST does not and did-not/cannot/never-has unilaterally "retracted" CVEs or prevented their issuance.

But yes, NIST's situation is not good for the world. The services they provide are hugely valuable.


I only know about this what I learned from OP and you guys.

It sounds like you guys think OP was mistaken, whatever analysis NIST was doing that they reduced in 2024 would not have prevented this anyway?

Legit question, I'm trying to understand!

OP says:

> Hit by a massive surge in vulnerability reports, NIST effectively hit pause on deep analysis. CISA and other Authorized Data Publishers (ADPs) tried to step in with their own enrichment efforts, but the global pipeline is now fragmented and drowning in a massive backlog. Because no step in today's system actually requires a proof-of-concept or bug reproduction, a plausible-sounding fake advisory can slide right through the pipeline and end up in GHSA, downstream databases, and enterprise scanners.

Do i correctly understand you are saying you think they've mistunderstood the diagnosis of what changed, the 2024 change to NIST didn't actually make it any more likely for a fake advisory to go through pipeline?


Teens want summer jobs again and you act like they’re sending 8 year olds back to the coal breakers.


It's not teens pushing for it


That $500K over three years represents 0.08% of the foundation’s budget in that time period. The question is, what are they spending the other 99.92%? There is a significant small chunk spent on crucial infrastructure, but it’s mostly a slush fund for board pet projects.


You both have it mostly backwards. The Taft-Hartley act mostly bans closed shops and allows states to pass “right to work” laws making payment of any agency fees to unions optional.

In no state are any employees compelled to formally join a union. In an American-style “closed shops” in a non-right-to-work state, if you don’t join the union the bargaining agreement can charge nonmembers an agency fee representing most of the dues they would pay as members. Not to mention pressure tactics to join.

Also especially in the trades in major markets unions control apprenticeship programs and hiring halls and make it virtually impossible for nonmembers to get union work, as well as gatekeeping access to apprenticeship programs in the first place.


Right to freeload laws work as I describe. Although no employees are forced to "join a union" in the sense of signing a piece of paper joining the union, in all cases they are union employees in practice. That is, the union collectively bargains their working conditions, the union supports them via grievance if the employer doesn't follow the contract, and so on. The right to freeload allows for such a person to get by without paying dues - that is, the cost of providing these collective bargaining and legal representation services.


It just struck me how dystopian the phrase "right to work" is. Like, you have the right to go down the coal mine for 16 hours a day and get lung cancer! No right to get paid, though...


“Right to work” is in the context of criminal wage theft laws, OSHA, EPA, Black Lung Benefits Act, Federal Employees Compensation Act, minimum wage (not that this affects mine workers), overtime, etc. Mine work in the USA is one of the most heavily regulated jobs there is and mine workers are very well paid. “No right to get paid” indeed. Mine workers don’t get paid when there is no mine work to do.


Workers must be doubly free.

"For the conversion of his money into capital, therefore, the owner of money must meet in the market with the free labourer, free in the double sense, that as a free man he can dispose of his labour-power as his own commodity, and that on the other hand he has no other commodity for sale, is short of everything necessary for the realisation of his labour-power. "


Among other things that CBP does not need a warrant to search or seize anything and everything at a border. Everything is subject to search at the border. To make a seizure all that is needed is reasonable cause that customs law/regs were violated. And there are specific federal laws relating to thwarting such seizures.

If you don’t want something searched do not bring it across the US border. There is very clear constitutional and statutory authority for these searches.


> To make a seizure all that is needed is reasonable cause that customs law/regs were violated.

What would be the reasonable suspicion that a USC bringing their personal phone on a trip with them would be a customs violation?

That doesn't sound at all reasonable.

In fact, the only "suspicion" they had was that he was someone who didn't like LE or Trump which is still not a crime, nor a customs violation.


No idea if its true, but one rumor mentioned was he was suspected of possessing CSAM


That’s a huge reason for electronic search but it can also be for evidence related to any other customs violation such as drugs or other contraband.


Complete memory safety (much less concurrent garbage collection) isn’t really workable for things like kernel and some embedded programming contexts. Rust can work in those contexts precisely because it has an unsafe out.

Even so Fil-C fails at being 100% compatible for userspace due to the silly things people do with pointers. Hence the large amount of effort he’s had to do to fix up that 0.1% of userspace that breaks.


But AI algorithms actually deployed by other cloud services do not. You’d hope that they wouldn’t flag a baptism or bris photo but currently fielded systems are flagging doctor-patient medical photos and have ruined lives, so.


That and being 175 feet below the surface. You’re not getting “sunscreen” on mesophotic coral.


Yet, they didn’t.

And for those commenting about risk from tourism, this is mesophotic coral at 175 feet. It’s out of range of recreational scuba much less shallow-reef snorkelers. Only technical divers can reach this reef. That’s why it hadn’t even been explored for all this time.


Isn’t this whole article about how they’re doing so right now?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: