Hacker Newsnew | past | comments | ask | show | jobs | submit | amluto's commentslogin

I’ve always thought that IPv6 has dramatically worse layering than IPv4. In IPv4 over Ethernet, there’s ARP, which layers over plain Ethernet, and IPv4 sits on top of the combination of ARP+Ethernet.

In the IPv6 world, neighbor discovery is IPv6, but only sort of, because the participants don’t necessarily have real addresses. So it’s a mess.


IPv6 link local layers over Ethernet the same way Arp does. Both contain a source/dest MAC which is used for forwarding, both contain the relevant neighbor info. If anything, keeping the protocol's self-discovery messages wrapped in the protocol itself is actually cleaner layering at the cost of complexity (the extra link local signalling addresses).

It really is not. There's a whole morass with possibly overlapping "on link" networks that nobody can implement correctly on the first try.

Then there's this whole pretend "it's not broadcast but multicast" song-and-dance with ND in IPv6. In IPv4/ARP the separation is clean, and no lower protocol details leak into the IP layer.

Link-local addresses were also meant to be used for LAN-only apps. Except that it quickly turned out that you can't actually use them reliably because some interfaces (like PPP tunnels) do not _have_ MACs.

It's a mess.


Morass, mess, broadcast/multicast, etc aside (seems more like complaints of complexity than layering), IPv4+ARP is the textbook example of a layering violation. When you do want to violate, having the L2 info in the L3 packet is still cleaner than L3 info in L2. One is a protocol carrying its own glue in itself, the other is a protocol using different protocols (per L2) to discover the glue the same way it could have itself anyways. It's certainly convenient of course, but that doesn't make it cleaner layering. It also gives a consistent answer for different L2s e.g. cellular links because of this.

Sticking L2 into L3 means that L3 needs the ability to communicate with nodes with as-yet-unknown L2 addresses and that L3 nodes that don’t have an L3 address yet need to be able to transmit L3 packets. Both of these are quite messy, and APR completely avoids these problems.

(I am not, however, defending DHCPv4 - that has some of the same problem.)


Whut?

IPv4 is an example of _correct_ layering. The hardware address is a detail that does not leak into upper layers. It's confined purely to the network layer.

In contrast, with IPv6 the whole 64/64 separation is a result of leaking the MAC address into upper protocols. Indeed, MAC was supposed to be a part of the publicly visible IPv6 addresses for hosts!


Huh? No, the MAC was never a part of the publicly-visible v6 address.

I know you're talking about SLAAC, but SLAAC is just a convenient way of picking a unique address. Changing the address wouldn't result in e.g. the packet being sent to a different MAC. Even sending packets to link-local addresses still does NDP, rather than parse the MAC out of the address.


> Huh? No, the MAC was never a part of the publicly-visible v6 address.

Yes, it was: https://www.rfc-editor.org/info/rfc3513/#section-2.5.4

The 64/64-bit split was in fact a result of (then planned) Bluetooth having 64 bit MACs. Moreover, the initial IPv6 RFCs did not have privacy extensions for SLAAC: https://www.rfc-editor.org/info/rfc2464/#section-4

> Even sending packets to link-local addresses still does NDP, rather than parse the MAC out of the address.

It doesn't.


Broadly it's true that historically there was this idea for ethernet networks at least. It was always optional though. Even in that long obsolete rfc2464 it's described as the way to do SLAAC which was optional even in 1998.

This kind of thing doesn't normally count as violation of layering though. In protocol design its common to leverage identifiers from lower layers for addressing. For example many workings of the internet would be hard to imaging with the rule that you could not use IP addresses and ports in upper level protocols (like DNS, P2P protocols, etc)


This article is missing an incredibly important detail: what is the harness doing?

I get remarkably good results using any recent OpenAI model using the codex-rs harness pointing at a built checkout of the PR. The models use the available tools (i.e. the shell) to understand the repo. I get some false positives and some false negatives, but I don’t believe for a second that I would get comparable performance using a dramatically less capable harness. (Also, the models read the short AGENTS.md for some context as to what’s going on. The prompt I use is about one sentence. I don’t bother with the built in review tool.)


It’s not only hubris — I think it’s actively counterproductive. The US could choose to:

(a) Sell many billions of dollars of fancy chips to China, thus bringing in billions of dollars of money and billions of dollars of trade balance improvement. And let China continue to build models quickly when they seem oddly happy to export the trained weights for free.

Or

(b) Decline to do so, thus reducing exports and very very strongly encouraging China to do everything in their power to avoid needing to depend on our chips.

In exchange for (b), what do we gain? A temporary advantage in model training and availability?


This admin is super in favor of isolationist policies right now. Whatever can bring in the most bribes. To the detriment of 99% of the public.

Don't forget that when they increase export restrictions under the current US regime they signal further that economic ties are on their terms not fair terms. The rest of the world will continue to steer towards alternatives to US tech.

I don’t buy it.

Reasonable about building secure software can take the form “this memory access might be out of bounds — that MUST be fixed” or “this process has access to an inappropriate privilege — this is a serious weakness”.

Exploiting things and the capabilities that the labs call “cyber” are about the ability to (a) find the issues mentioned above and then (b) string issues together and avoid all the imperfect mitigations to actually compromise something. That latter part was IMO not actually necessary to train extensively, and I’d be quite happy to use a model that has no special skills in this regard but that would do (a) without complaining.


The changes may not last, but it’s quite unusual for an already-permitted facility to lose permission to operate.

A lot of unusual things are happening in government lately.

As an American, I found the protein situation and the whole “Canadian” flour concept bizarre.

In the US, most high quality flours will state their protein percentage reasonably prominently on the label. It’s not particularly hard to buy commercial flour at a fairly wide range of protein levels - 13.5% and even higher protein flours are available and inexpensive. And (lucky for us?) they’re basically all farmed in the US.

But in Europe, the labels seem more interested in ash content and the milling technique, and, at best, the protein can sometimes be inferred from the nutritional information. The last time I shopped for bread flour in Europe, I found a Canadian flour with sort of acceptable protein at a very high price, and I found a Croatian “Pizza” flour that was even better at a lower price.

Do not take American mass-produced sandwich bread as any kind of product that Europeans should wish they had :)


The irony that caught my eye in the article is that American mass-produced sandwich bread is depicted as this old-fashioned, slow production process. It takes far too long for the time-crunched futuristic British bakers. Who can wait 5 hours for yeast to ferment? The Chorleywood process comes to the rescue and whips and explodes the water-flour mixture into a foam that is baked seconds later. While those old-fashioned Americans are still waiting for their ancient traditional yeast to slowly do its thing.

At the same time, we have legions of new-age Rogan-adjacent food influencers on both sides of the Atlantic droning on about how American flour makes them bloated and tired (a line that Rogan himself repeats ad nauseam) while European flour avoids all of these problems.


Bread is really a fascinating product.

There are so many things for which modern mass or mass-ish production methods can produce results as good or better than artisanal techniques. Nails, knives [0], textiles, etc are all examples as long as one is considering a modern example that is trying to be good.

But a halfway decent loaf of bread made using hundreds-of-years-old techniques (albeit probably with modern yeast [1] if it’s not sourdough) is just dramatically better than “modern” bread, even though the latter often contains highly engineered ingredients and is made with extreme precision.

[0] I know it’s kind of sad, but a well designed blade cut from a sheet of high quality steel and beveled appropriately is better than even a very, very well made Japanese knife made from the alloys that, for some reason, are still state of the art in Japan. I do imagine that a highly skilled artisan could produce an even better knife from modern steels, but this is a rarity and is very, very expensive.

[1] Actual modern yeast is dramatically better than your average supermarket yeast, in flavor, performance and convenience. In the US market, this means that you should use SAF, not Red Star. Good sourdough starter is still just an artisanal thing.


> "at best, the protein can sometimes be inferred from the nutritional information."

I looked at some recently in the UK and the nutritional information is always per 100g and says e.g. 11.5g protein. Is there something wrong with that meaning 11.5% without any inference, or are continental European nutritional information boxes presented differently?


In the US, at least in larger sized bags, flour seems to be treated as an ingredient and there might not be a nutritional fact label. I admit that I didn’t look that carefully last time I was in a European grocery store.

I imagine that the 11.5g you’re looking at really does mean 11.5%.


Ahh, I am just looking at 1Kg consumer/household bags, maybe commercial huge bags are different.

Maybe this is just a difference in where the label is. I found an actual nutrition fact panel on the flour’s website.

Huh? Processed ingredients don't generally get a pass on nutritional labeling requirements in the US. A bag of flour in a grocery store should have a label.

The European grocery-bought bag of sugar I have lying around has a regular nutritional label, including a list of ingredients. Spoilers: sugar is made out of sugar and contains almost 100g of sugar per 100g.

I checked some 25lb bags of flour (not from a grocery store) and they do not appear to have any nutritional facts label.

Ok, if they're meant to be marketed for food service, like a bakery regardless of who actually purchases them, then that does makes sense.

I consider myself a decent amateur baker and I've never noticed a huge difference in bread flours. I buy from a local mill because they sell interesting grains and I want to support them. Otherwise I get King Arthur, or Bob's Red Mill if I need something a bit more specific. KA is particularly good because their recipes are usually reliable and they're designed around their flours. The selection of baking ingredients is usually much wider in the average US supermarket compared to the average European one in my experience.

I once did an experiment in which I baked two otherwise identical loaves, made under as close to identical conditions as I could arrange, very carefully measured, with the only difference being the flour. I used 11.5% protein malted flour and 13.5% protein untreated flour. The breads rose the same amount, looked and tasted basically indistinguishable, but had a dramatic difference in texture. The higher protein bread was more cohesive and resisted falling apart or being pulled apart much more strongly. Maybe I should try the experiment again, better, without any malt involved.

In any case, I think that the basic bread flours from King Arthur and Bob’s Red Mill are decently high in protein. King Arthur Bread Flour is 12.7% and they sell even higher protein flours. Bob’s Red Mill doesn’t obviously list a percentage, but the nutrition facts suggest it’s around 13%.


> I consider myself a decent amateur baker and I've never noticed a huge difference in bread flours.

If you make sourdough, have a crack at using standard supermarket flour and then try adding some organic stone ground or other expensive flour with special snob factor.

I am far from expert but notice a big difference.

(I’d say to try 100% organic stoneground but getting a good rise can be quite hard).


I have no idea which keychain is in which, but the last time I migrated from one Apple laptop to another, I couldn't get the automated tool to work at all, so I restored a physical backup, went through the sign-in process, and passwords and passkeys migrated correctly.

Passwords and passkeys are in the iCloud keychain. You can technically save passwords in the login keychain (not sure about passkeys), but if you’re using the Passwords app it will be in the iCloud one.

IMO the most alarming thing currently going on with AI is the huge RL runs that give models some incentive to compete with each other and rather strong incentives to hack things, break rules and otherwise cheat. And the “cyber” initiatives are remarkably examples of doing most of this deliberately.

Of course, it’s the “frontier labs” doing almost all of this. No one is about to SFT a model that turns into Skynet on its own.


Clean room equipment is kind of the opposite of what was needed. Clean room equipment protects the room from the people.

What’s was needed was likely pretty basic PPE: P100 respirators along with outer clothing that would be kept out of people’s homes and showers when leaving the site. (PAPRs would have been even better, but they wouldn’t have been cheap or available in large numbers on short notice.) Unfortunately, if you watch modern construction workers, you’ll find that PPE is almost universally ignored when performing common but dangerous tasks like cutting concrete or lead-painted surfaces.


I've been well served by just using a P100 respirator when I'm doing anything dirty or dusty. There have been a few times that it's reduced exposure to something bad that I didn't know about, among them removing old shingles from my attic (asbestos composite material) or sanding paint that I had tested negative for lead (transparent varnish underneath had lead).

> transparent varnish underneath had lead

Weird. Wasn’t lead typically used as an opacifying agent?

In any case, if you test by taking a little scraping, you can only detect lead that you actually scraped. But if you test with X-ray fluorescence, you get an integrated density over a decent thickness.

Also, even if the P100 respirator protects you adequately while sanding, it provides no protection against future exposure to the dust that you create.


> Weird. Wasn’t lead typically used as an opacifying agent?

That's its role in paint, but lead glass [0] is a thing, so transparent lead-based compounds do exist.

[0]: https://en.wikipedia.org/wiki/Lead_glass


there was a layer in between. I had it XRF'd after I started. And I always cleanup with a full HEPA vacuum anyways.

What's up with the doors?

> NOTE: If low voltage power is unavailable and the windows are fully rolled up, the door windows may crack or shatter when you open the doors with the interior manual release handles.

> WARNING: When the doors or the area around the door struts of Cybercab are damaged, the preloaded springs for the doors can pop out when the door opens. Access the vehicle from the undamaged door when possible. If both doors are damaged, open the doors with caution. There is a lower chance of the springs popping out if the door does not fully open. Wear appropriate PPE. […]

I've been in quite a few cars with cool frameless windows. They mostly seem to have the property that the window could plausibly be damaged if one aggressively closes the door with the window all the way up (which the car's electronics will attempt to mitigate). But somehow the Cybercab might have the glass break when opening them! How?

(FWIW, early Tesla Model S cars have the windows done correctly. There is a single interior handle. As you pull it, first it actuates an electronic switch that rolls the window down slightly. Then, as you pull it a bit farther, it mechanically releases the door. If there's no power, then the door still opens, just without the window automatically rolling down a bit first. Maybe Tesla should copy their own previous design?)

The preload spring situation is just delightful. So is the upward-opening door. I hope no one ever rolls a Cybercab over and needs to exit.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: