Hacker Newsnew | past | comments | ask | show | jobs | submit | chews's commentslogin

you should kick the tires on an unfiltered (abliterated model) it's the closest thing to having a real conversation with the devil. There is good reason for the concern's outlined above and undoubtedly Anthropic / OpenAI have internal unfiltered models with no safety... they got freaked out based on how they work and are virtue signaling alarm... all while selling out to defense contractors.

Yeah I really struggle to balance wanting information to be free and not wanting the information on how to make deadly weapons too easy to obtain.

At least with books or the internet you had to go through some effort


This is what made a generation of Kennedy's...

Add a dash of nimby and xenophobia and this is about right... you've got the likes of OpenAi and Anthropic destroying printed work from Austrailia and New Zealand to acquire latent data, Meta executives downloading commercial porn on their home computers and driving SSD's into work, all of them are building datascenters in metropolitan areas with generous tax breaks for their non-profitable ventures. The fact that 60% of model usage is now Chinese is what's prompting these folks to whine for protectionary measures. Meanwhile they will have no problem clearcutting massive swaths of meaningful work for people in their pursuit of AGI.

It's wild to me that PoW systems are how we sort the bot problem... the bummer is that all this "work" is just wasted cycles, at least in crypto there is a token you can sell.

> at least in crypto there is a token you can sell

That would defeat the purpose. The goal is to make scraping costly, not profitable.


Scraping would be costly in this world: scrapers would have to spend tokens in order to get the webpage.

But, in this world, the website owner would receive tokens that they can then use to do whatever they want, including paying for servers and bandwidth. This is the sense in which the cycles aren’t wasted: the website owner now has cash to spend.

Effectively, both scrapers and ordinary users would be paying for the privilege of getting website bytes.

This also solves the problem of having to wait for your phone to solve the challenge while you’re browsing: you can buy or mine some tokens ahead of time and pay them as soon as challenged. So can the scrapers, but because they’re accessing enormous numbers of pages it’s hopefully prohibitively expensive for them.


I am convinced. Is there any project implementing or proposing this?

I guess it could in principle be profitable for the website, not the client?

unfortunately at that point it would be indistinguishable from running cryptojacking on your website

No. The client is doing the work.

The client is doing the work in both cases

Yup was thinking the same: make honest people pay $0.00001 when they visit the site (in electricity/compute), have the challenge made so that only the website wins a tiny something. Bleed the bots dry.

> This makes Anubis challenges use a memory-hard proof of work function (argon2id) instead of just a CPU hard one. It also means that the "hey Claude vibeslop me a CUDA Anubis solver" route is on its way to being fundamentally dead.

Nice.


Sure, then just replace it with something that is useful to society but not immediately profitable to a scraper, like science research

I want to do this eventually, but it's hard to split things into the micro-tasks that would be required to make this work on Anubis. One of the ideas I'm throwing around is a world where Anubis helps fuzz old games to find timesaves in tool-assisted speedruns. It's harder than you think.

The tools that exist for fuzzing speedruns (TASers call it "botting") are fairly primitive, excluding a few game-specific ones. Because of that, there really aren't that many TASes where a distributed randomised search could make improvements which don't get immediately overshadowed within a day of human attention. Improving botting tools and increasing their adoption would be more effective IMO. (Incidentally, TASVideos.org recently banned one of the people pioneering bot development.)

Meanwhile BOINC is well-established as the platform for distributed computation. If you can figure out how to squeeze its work units into Wasm challenges, I'm sure a lot of researchers would thank you.


BOINC isn't really built for "small tasks", afaik. Once you get small enough, the work the server is doing to manage the tasks gets to be around the same cost as the server just doing the tasks itself.

Yeah, I'm using PoW-based "DDOS defense mechanism" for a current project and had this thought too. I briefly looked into what it would take to exploit PoW to do something economically valuable like folding@home, and it looked a bit tricky. At first glance, these sort of projects seem a bit unsuitable for real-time PoW because they were designed to be run on desktops and so tend to do things in large batches. There probably are other use-cases that could be more suitable though.

Might be worth chucking that thought into Astra, especially if someone springs the $$$ money for it?


This would be rad.

> the bummer is that all this "work" is just wasted cycles

There's probably an overlap with people who think anubis is a good idea and those who think we should be doing more to battle climate change.

The two views are not compatible though.


It's wild how many people happily jump on this DRM train now that they are hoping to gain from it.

Well, there was CoinHive which did this exact thing 6-7 years ago, but that system got abused a bit much

PoW was originally anti-spam technology.

Both CarPlay and Android Auto are second screens to your phone... they're just "Airplay" streaming a simpler interface.

being done by No Such Agency.

it's fair to say they do and have for ages... it's not that hard to assume a well trusted TLS cert is under their control.

What does having a "well trusted TLS cert" enable for them in this case, exactly?

Having a magical cert doesn't mean you can just intercept everything.


On the contrary, it lets you MITM encrypted communications by swapping the website's original certificate for the "well trusted TLS cert"

No, it doesn't. HSTS and other methods prevent this from happening.

HSTS doesn't protect you from this at all. It only requires HTTPS, which a spoofed-but-trusted cert passes just fine.

No mainstream browser (or any browser?) is doing cert pinning.

What "other methods" are there that are deployed and actually in use?


Transparency logs. It's mandatory for a cert to be in CT logs for browsers to trust it. Those are public, if this was happening, someone would have noticed already.

someone had to swap out the tape drive in Room 641A.

careful, boomers have selective memory... the 80's was some sort of fever dream


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: