Hacker Newsnew | past | comments | ask | show | jobs | submit | TacticalCoder's commentslogin

> What gets me as a non-native speaker far more than "a vs an" is the "a vs the" conundrum. I still don't quite get when something needs to be "indefinite" and I've been speaking English for close to forty years.

"a vs the" is quite easy IMO.

Most non-native however do not use "that" and "which" properly though. "Give me the floppy disk that is blue" and "Give the floppy disk, which is blue" are two different things.


My wife is Japanese and fluent in English but still almost always mixes up the and a. I think part of the problem is that it just barely sneaks under the radar of a mistake that is bad enough to confuse English first language speakers in everyday use. So theres no impetus to correct it

Nobody says that. "Give me the blue floppy disk"

Nope, it's basically as in spanish:

> Il est un médecin?

Nope that's bogus french: you say "il est médecin". But you can say: "c'est un médecin".


> That's bogus

To expand a bit, it's a perfectly valid use, but most people will forgo having an extra word that has no role in the phrase.

"Il est médecin" and "Il est un médecin" are perfectly equivalent so people will choose the shorter.

The "un" comes back when using the noun as an adjective isn't possible anymore, e.g. by adding an actual adjective "Il est un bon médecin"


When looking at commie-inspired taxes, people would be wise to take a cold hard look at how well things are going in communist countries, like for example Cuba or North Korea.

Things aren't exactly great in Cuba atm: the idyllic paradise with gigantic paintings of Che Guevara (even if wasn't cuban, he's still revered as a hero by many in Cuba), the romantic hero (a Rolex-wearing killer but somehow the romantic hero of many) to draw inspiration from.

But, believes us, this time this tax is "the best tax we have". This one time this is really it: the communist tax that's going to work. It won't lead to a situation like in NK, it won't bring the desperation that's ongoing in Cuba.

No, this time the commie tax is going to be perfect. The solution we need.

Trust us.


oh noooooooo!

In my mind, and I have not played it since the Amiga days, it's a very curt "oh no". Amazing, I can still hear it!

I can still hear it as well.

I can also still hear "First there was Menace... Now, Psygnosis presents... a DMA Design game... Blood Money. (there's a whole lot more coming...)".

DMA had very good sound design for the time.


Yeah, absolutely! Blood Money. I am almost embarrassed that I remember so many of the samples!

> but fail to see that the dozen variations generated are not distinctive - they might have somewhat different typography or imaginary, but still have the same AI uniformity and smell as the crappy restaurant poster you see on the street

Hard disagree: every single example TFA gives is way better than the horrible generic ones that are polluting every shop and LinkedIn post.

It's not even close.


That's not what OP is complaining about. The issue with AI art isn't how the individual piece look, but the similarities they have in aggregate. One image can look perfectly fine, once you seen a hundred they all start looking extremely similar. Human brains are great pattern recognizer and lock on to those similarities, even when they are covered under different styles.

When all your art comes from a single source, it's difficult to create real diversity and novelty. That's still the big issue when it comes to genAI in general, without a lot of hand holding you'll just bound to end up with slop, since the AI won't get creative on its own.


Did you look at the examples? They're almost ridiculously diverse, and the prompts show very little handholding was required.

They're not novel, but a poster for a spring fair isn't supposed to look like a de Kooning.

These arguments are almost completely detached from reality. Most artists aren't diverse either - they're told to find a style and stick to it, and that's what they do.

Commercial graphic designers are more versatile, but the set of standard looks is still relatively small. Hollywood movie posters and book cover designers are notorious for reusing the same tropes and colour systems, and that's been true for years, long before AI was a thing.


> They're almost ridiculously diverse, and the prompts show very little handholding was required.

The structure is identically to all of that, big title, graphic, list with icons. As said, they look fine on their own, the problem is only becomes apparent when you had to look had hundreds or thousands of them. It's the em-dash or the "load-bearing" of the AI-art world, the more you look at this stuff, the more apparent the similarities become.

> Hollywood movie posters and book cover designers are notorious for reusing the same tropes and colour systems, and that's been true for years, long before AI was a thing.

Exactly, but with AI that issue becomes even more drastic since the models don't create diversity by default.

> Most artists aren't diverse either

They don't have to be, since there are millions of them, all coming from different backgrounds, with different art styles and all. While there are only a handful of big AI models, who all come with a pretty generic default style.


There was some upgrade in tech where the posters had legible text and all used that paint brush text highlight thing. The first time I saw it on Bambulab makerworld I though, "huh thats a neat image". Then I saw it on every low view count youtube thumbnail, and then the exact same thing at the failing sushi business menu and I was no longer impressed. I'm actively repulsed when I see that style of image now.

I am not sure. If something is not in the usual AI style its not going to leap out at you that it is AI the same way. Maybe if thought about it, but when someone looks at a poster they typically focus on the information, not the style.

Only at the first derivative. What you're observing is an additional layer of 'but, in genre X!' and then same slop, different prompt.

You're complaining about what happens when people don't even supply the additional layer, but just go 'make me a poster, no mistakes, it should be a great poster'. When you give no direction at all you get the purest of slop. You start giving directions, you start narrowing down the area you're digging through the slop of, and possibly you ask for something that people aren't familiar with and they're only able to identify that you asked.

Hence, Chinese posters with a cherry blossom and the kanji for 'Japan' and such. Someone went 'make it Chinese' and the slop associated it with 'Oriental' and what came out was collective unconscious, such that people who weren't thinking and didn't have experience might not look twice, but the meaning turned out tainted.

Sort of like food depictions that more closely resemble a pile of maggots. Those glisten! (well, I suppose they must.) There's a whole uncanny-valley thing that happens on every level and inspires revulsion. I'm suggesting that is still happening in the other examples but you've not got the experience to register their problems. With the food depictions, all animals eat stuff so we're hardwired to bounce off unsafe foods even if they glisten…


> which began life in the pre-internet era Bulletin Board Systems and moved to internet File Transfer Protocol servers (“topsites”) in the mid- to late-1990s.

Yeah! I was a bit connected in that we'd write "intro" for a BBS and in return we had unlimited download (whereas on many BBSes there were seeder / "leecher" ratio and unless you were providing stuff, you'd be hindered by your leecher ratio).

> The “Scene,” as it is known, is highly illegal in almost every aspect of its operations.

But the "intro" pirates would put in front of cracked games (or sometimes on BBSes to advertize the BBS), later renamed "cracktros" (for that term wasn't used at first) eventually did spawn full-on "demos" and "musicdisk" / diskzines etc. and those weren't illegal.

In my Commodore Amiga days about half of my 5"1/4 floppies (because we were hacking 5"1/4 external drives to our Amiga and pretend to the computer they were the internal 3"1/2 disk so that we could buy shitload of much cheaper 5"1/4 floppies [1]) were demos (from Sanity, Scoopex, State of the Art, Lemon, Razor 1911, etc.).

Piracy definitely had aesthetics to it and I'd say the fully legal demos were, weirdly enough, the biggest manifestation of the aesthetics of piracy.

[1] in the early days I remember that after having something ridiculous like 3 boxes of 10 5"1/4 floppies, compared to 3 boxes of 3"1/2 floppies, you had already fully paid the 5"1/4 external floppy drive reader. I still have that external 5"1/4 drive for the Commodore Amiga just as I still have my chinese pirate SNES copying device. These two are prized possessions of mine ; )


> Passkeys do marginally improve security against MITM and phishing attacks ...

The tragedy of passkeys is that they're a step back from the security offered by the likes of Yubikeys.

But because passkeys are pushed by both Google, Microsoft and Apple: there is is simply no fighting these three. It is impossible.

Passkeys won not because they're better (they're not and the entire concept of "secret behind a hardware security module" that can be transferred to another system defeats the whole point of a HSM in the first place) but because the powers-that-be decided that passkeys are to be used.

It's still a win: the commoners are better served with passkeys.

But a secret in control of Google/Apple/Microsoft that can be backed up is not a secret I control: it's a complete step back from yubikeys.

Passkeys won and we better get used to them (and, yup, there are usability issues as you mentioned).


Why not just use a passkey backed by your Yubikey?

> What makes you think RCEs are being found & fixed at a rate that’s faster than they’re being introduced?

It could go either way but we're already at a point where successful exploits in some software (like Chrome) require an absurd amount of exploits to be chained to lead to an actual RCE. We've seen chains requiring more than ten exploits: not kidding.

We'll learn to put more and more sandboxes / guards / checks / defensive techniques everywhere and then all that's going to be needed is for AI looking for security issues to find something ridiculous like 10% of all the actual issues to stop RCEs dead in their tracks.

Also arguably the current SNAFU was expected: we fully knew hardly anyone was taking security seriously.

Now: not so much. Many projects had tens and even hundreds of issues pointed to them.

I think we'll see several things: projects beginning to take security seriously, defense in depth getting generalized and hence RCEs requiring ever more bugs/exploits to be chained to achieve anything, low-hanging fruits getting patched at an insane pace, new code being immediately checked, by LLMs, for not just low-hanging fruits but also more advanced security weaknesses, etc.

We may also see things like the lost art of configuring firewalls making a comeback, the generalization of hardware security modules (where applicable), and even things offering physical guarantees, like time-bounded retrieval protocols, beginning to get used seriously.

If I had to bet I'd say it shall go both ways: some projects are going to extremely sloppy and full of holes but others are going to get so secure nobody shall ever break them.


> William MacAskill co-founded 80,000 Hour ...

> Then the movement minted a fraud. Sam Bankman-Fried was not an accident of proximity; he was EA’s own product

TFA could have have mentioned that it's a fraud, MacAskill, who minted another fraud. MacAskill was SBF's guru and he was also involved in FTX and Alameda scams (but distanced himself before the scandal blew up) and MacAskill bought a 15 million GBP mansion in the UK for the Effective Altruism movement using funds stolen by SBF.

Last I checked the mansion hasn't been clawed back yet (but it could: funds from the Madoff ponzi have been clawed back more than 15 years after the fraud has been exposed).

Now of course people in charge of clawing back the stolen funds are the only hope of people who've been scammed for MacAskill didn't effectively altruistically sell the mansion to effectively altruistically hand the money to people who have been scammed.

That MacAskill and SBF maybe had groupsex with Caroline Ellison is one thing: they're proud to be polyamorous, whatever. We live in a free world.

But buying a $15 million mansion with stolen funds is thievery. Effective Scammers.


I can't help you but my comment may help others...

As a techie you should have known better: you first learn how 2FA using TOTP works. You understand what happens when you create an entry in Google Authenticator (or whatever app). You reproduce the procedure: you verify that you end up with the same 6-digit numbers.

If you've got a partner, you register your secret keys for each service on your partner's device and vice-versa.

Then you've got backups of your secret keys on paper, in a safe at your bank. Next to each secret key there's a checkbox: "Successfully initialized from this secret key?".

When those TOTP became ubiquitous (way, way, way before Yubikeys or passkeys were a thing), 2FA was a godsend compared to just passwords.

I understood they were here to stay for years, and years. And then more years.

So I learned how they worked.

When later on QR code generalized to initialize those (IIRC it wasn't a thing in the early days of 2FA TOTP: you'd just always get the secret key as characters, not as a QR code), I refused to ever scan a QR code: I always first decode the QR code (for the services only showing the secret key as a QR code, without also showing it as text), extract a copy of the secret key and then register it from my copy.

Stuff like that.

Now... As most services are deeply broken and have completely insecure practices you just say "I lost my 2FA, I want to reset it" and because they're clueless when it comes to security, they'll allow you to reset it. If someone hacks your email, they pretty much can reset every single of your account (at least those tied to that email).


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: