Hacker Newsnew | past | comments | ask | show | jobs | submit | phuff's commentslogin

I wondered about this because I used a keyboard to do it. But then I thought maybe krick used mobile and there's no onscreen keyboard. But then I realized that krick said mouse skills and so is probably on a desktop. I think maybe just some graphical indicator that you can type would be helpful for first time users.


No, I did try to type, but nothing happened. I seem to remember I did check that I had English layout turned on, but maybe I actually didn't. Really cannot guess any better than that what might have been the problem.

Anyway, doesn't matter, it was totally my mistake, everything works for me as well as for everyone else.


Maybe there was some kind of focus issue your first time, where the browser wasn't sending the keystrokes to the page.


> I don't think this rule is universal.

Counterpoint: Most workplaces would be best served by a team of developers who help up level each other without causing morale issues when knowledge gaps, which everyone has, inevitably show up.

This type of environment is the best for software development organizations specifically because most software development shops that have more than one person working on a codebase or system or set of systems have already reached the point where no single person can keep the whole thing in their head at once.

Maybe that person really worked in an environment where they didn't have to think about pointer arithmetic. Reframing closing knowledge gaps as a beneficial and necessary part of a healthy development system makes it so when somebody doesn't know something and needs help they are willing to get it quickly. And that they will talk about knowledge gaps openly so they can be filled with the collective pool of the organization .

Shutting that down even by just "narc-ing" on the person just makes it that much harder when others need to know something they don't to get a job done, slowing down the system over time.


I definitely agree that kindness as a default is never a bad choice. There does come a time when a skill deficit becomes too much of a drag to the team and a sign of irresponsibility on the part of the practitioner, but it's the exception.


> [C]onsumers, on the other hand, are mostly looking to waste time, which is why attention- harvesting advertising is the only software business model that works at scale for consumer services.

I came here to talk about this, like some other commenters did, too :) I think that this _is_ a predominant view amongst most of Silicon Valley but I think it's kind of a local maxima view... Easy to agree with, easy to see that it's a functional idea, but... people... (i.e. consumers) do lots more than just waste time on their phones even though I bet that's a huge amount of what people are doing across the US right now.

I guess the thing that _is_ true about this nugget is the "at scale" part. It's hard to find things _at scale_ that people would pay for on a phone. So the phone sort of falls back into this easy to monetize thing via advertising. But I think people (qua consumers) probably can clearly be a sustainable market for way more than attention harvesting (or dopamine fracking!) but it requires a lot more effort to think of things that you can build a market out of there. So people sort of lazy-back into attention harvesting via ads.


I think that this is an attack on the understanding of the LLM _potentially_ but it doesn't seem like it's likely to standup to legal scrutiny?

Seems like this is pretty clearly a case of fraudulent misrepresentation (https://www.law.cornell.edu/wex/fraudulent_misrepresentation) which kinda nullifies the contract, if I understand correctly:

  Fraudulent misrepresentation is a tort claim, typically arising in the field of contract law, that occurs when a defendant makes a intentional or reckless misrepresentation of fact or opinion with the intention to coerce a party into action or inaction on the basis of that misrepresentation.
  To determine whether fraudulent misrepresentation occurred, the court will look for six factors:
    A representation was made
    The representation was false 
    That when made, the defendant knew that the representation was false or that the defendant made the statement recklessly without knowledge of its truth
    That the fraudulent misrepresentation was made with the intention that the plaintiff rely on it
    That the plaintiff did rely on the fraudulent misrepresentation
    That the plaintiff suffered harm as a result of the fraudulent misrepresentation
  Like most claims under contract law, the standard remedy for fraudulent misrepresentation is damages.


That would be an open question in every jurisdiction. There wasn't really a representation here, but it might be something more like the doctrine of "mistake". It's also not clear "your honor I never read the contract but my LLM told me it was okay to sign" is a great argument either. Doubly-true for your $1,500/hour law firm duped by something like this.

[Edit: by "nullify" you probably mean "void" or "voidable" which are remedies in equity, and the "never read it" argument carries even more burden there. As the citation notes the traditional remedy for contract issues is damages (i.e., cash payment).]


The LLM part is confusing people.

You can remove the LLM from the story and see how the trick would be a legal problem even with only humans involved: If you put an extra clause in a contract in white font that says “Oh and also if you agree to this you owe me $1,000” because you want to selectively hide it from reviewers but benefit from the text, no court is going to look kindly on you.


That’s not really a good analogy. (For blind people maybe. That is addressed in the legal accompanying post.) Here, only automation systems are actually vulnerable. The text on the screen is the same as print which is what the party signs.


The trick is this:

The white text is not visible to humans, and therefore not binding as part of the contract. But if lawyers use LLMs to assess the contract in part of the negotiation process, the LLM will be confused by the contract's contents.

You could - for example - say the contract is for $10000. Then use unicode tricks to make any LLM reading it think the contract is only for $1000. The LLM will say this is good value, and not worth negotiating hard over. The human signs.

Would anyone notice? Would a judge care? A human signed the contract. If they didn't do proper due diligence, its their own fault.


I would be surprised if a judge looks favorably on such shenanigans.


It would surprise me if the judge of such a case did not tell both sides off. Both fraud and negligence are problems.


You would be surprised, then.

If one party is intentionally misleading the other and employing technology to do it, they are the villain.

The law doesn’t “both sides” these issues and cancel bad behavior out because the other side didn’t notice something.


No, it doesn't "cancel out", but courts (not law) absolutely do "both sides" issues.

Rebukes for "winning" sides of a suit are relatively common.

For example, here's a case in Australia where the defence are criticised for over-reliance on AI, where the defendant was still found innocent by reason of insanity. [0] Most of the ruling is criticisms for the "winning" party.

[0] https://www.9news.com.au/national/judge-sprays-lawyers-for-f...


If they notice. Again, a printed version of the contract that is signed has no evidence of the attack. The attack is on getting your legal LLM to hallucinate specific things of what you are signing.

I doubt a judge will look favorable on people saying "but my LLM said it was 1k"... cause they are known to hallucinate.


Sabotaging due diligence, even if that diligence is performed with unreliable tools, is probably not legally great. What if the attack was against plain text search, so that a computer search for a phrase turns up zero results, but the phrase is still there, legible to a human? (E.g. as an embedded picture, or some font hackery)


> The white text is not visible to humans, and therefore not binding as part of the contract.

Using font tricks doesn’t make part of a contract not legally binding.

Intentionally tricking an LLM doesn’t make the other party immune to the consequences of intentionally misleading the other party.


Your point on LLM not beeing needed is right. Trying to put it in other contexts, what about writing a full contract on a sheet with a pencil, then erase everything and print the final revised version on the same sheet with a printer.

If the other party somehow relies on scanning the physically etched version of the contract and not the printer ink laid on top to digitize the contract, would you be legally responsible for their automated process misreading the document ?


This is a great bug report! I am not a kernel expert by any means even though I have read some about it... 10+ years ago. And I was able to follow along and see what was going on.

It does make me scared for what other dangers lurk since this was a really bad one and it was so little work to find.

Also of note: so many security issues lately have been done using AI. This report makes me think two things:

1. Expertise is still immensely valuable, the more niche, the more valuable.

2. There are lots of niches still where AI doesn't dominate...


I present an alternate etymology for homelab. Instead of "lab" as experimentation space, think of it as lab: place for doing work. Away back in the day we didn't have laptops to work on university CS classes.

So you had to go to the lab to find a computer beefy enough to do your work on.

It's not a home "lab for experimentation.".

It's a home "lab for getting work done."


The title of the original article is a little misleading. It's _website_ visitor tracking and it looks like it's really just advertising analytics... That's maybe bad but it's also the same as like... 98% of all other websites.


That's really pretty much everything, google knows you may think you have breast cancer -- email, gender, age, visit pages, etc. Certain sites and information classes/types are not just like the rest of 98%.


The title is totally misleading. It very much implies that hospitals are giving data about visitors to the hospital, which would be incredibly egregious.

Tracking website visitors is bad, but is something I 100% expect. If others aren't expecting this, that's a serious problem. People should absolutely be warned when it happens (or, better, laws should exist to prevent it from happening).

But web visitor tracking is not nearly as sensitive as tracking visitors to the hospitals (or any other health care provider premises) themselves.

I avoid the data leakage for sensitive things like health care by never using websites related to those things. I know that people often forget this, but at least in the US, using a website to interact with health care providers is not actually mandatory.


> I avoid the data leakage for sensitive things like health care by never using websites related to those things. I know that people often forget this, but at least in the US, using a website to interact with health care providers is not actually mandatory.

It is not mandatory but is made extremely onerous. I can get on the web site, authenticate while tracked, enter my request, or I can call an automated maze, get repeatedly dropped, talked to a ChatGPT knock-off, get dropped again, and maybe I get a human to answer my request. Then, I get an email asking if I am satisified with the service.


Interesting. I have to admit, I've never had a problem talking to doctor's offices or the hospitals in my area by phone. No onerous phone trees (just a simple initial menu), no voice robots, and usually only a short wait to talk to a human.

I need to stop complaining about my hospital. Apparently, this is one area where they're above the grade. But even if my phone experience was like yours, I'd still use the phone instead of the web site due to privacy concerns.

In the end, as with all privacy/security issues, there's an inherent tradeoff between convenience and security. Everyone has a different place on that spectrum where they're most comfortable. But at least we can choose how much of a tradeoff we're willing to engage in.


Website visitor information is still really sensitive. If you book an HIV test online, you probably don't want Google and Facebook to know that.


[flagged]


Imagine you stated online that you don't like the fact that your Uber ride data is being sold to Facebook. Then imagine someone said, "If you don't like theZuck or Googs knowing where whereabouts and who you are visiting, just walk when you need to go somewhere." Hopefully you'll realize why you are being down-voted.


Just because you think it is okay to continue to feed the beast is not my issue. I can spare the -4 points to engage the discussion.

I also don't use Uber because I don't support their history even if they might no longer behave that way now. You don't have to walk just because you don't use Uber. There are other ways to get around. The fact that you feel this way just means to me that you've drunk too much of the Kool-aid.

Society has become lazy/complacent with the status quo, and does not want to put forth the effort to fight for the rights that they so freely complain about on web forums. Yes, things can be more convenient if you are willing to accept the true costs. Things can be more difficult when you choose to not accept the true costs. Just because they are more difficult does not mean it is impossible.


Your reply is not only a non sequitur, the claims you make about me are factually wrong. I have never had a facebook account, nor instagram, nor twitter, and I've never taken an uber. But you claim I've overdosed on the kool-aid.

My point was you are very cavalier about how easy it is for people avoid what is structurally difficult to avoid. For instance, rather than going to the website to look up information, one should go to the hospital and ask someone in person.

You should also have some empathy for people who have no idea that a hospital might sell their information.


About 98% of hospitals has committed some form of medical malpractice. The major problem is when people start accepting this as acceptable behavior. There are multiple places where sharing information with advertisers should be greatly restricted, including hospital, lawyers, priests and so on. Government institutions like police emergency information centers should also avoid sharing data with advertisers, especially if that information get transported over the border.

Yes, people do bad decisions all the time. Hospitals are not perfect and mistakes happens. They should however not continue doing mistakes that harms patients.


Most hospital or medical websites do require some sort of authentication to access PHI.

The tracking is continued post authentication, making the identity to PHI significantly stronger.


Don’t people go to a website to find their specific doctor, department, or treatment options?


How many of these websites remember to completely disable analytics on the sensitive logged-in portions of the site? Completely disable doesn’t mean “an intern once logged in to the analytics provider’s config page and asked them to, pretty please, not log certain pages, and no one ever re-checks that config.” The analytics script should straight-up not be present on the sensitive URLs.

(Frankly, the script should not be present at all on the sensitive origin. Ever heard of fetch or service workers or any other same-origin mechanism of collecting data?)


ADHD (and many other psychological struggles) can be managed with practice and good habits and time. You seem to have a desire to change (evidenced by posting here) which is a great signal you are in a place to make changes in life. If you want, you can learn now how to make changes in your life to work with your ADHD and learn to manage it's effects, thereby being more successful than you would have been leaving it undiagnosed and poorly understood. This is a great position to be in! You know are in a position to learn the skills you need to manage the ADHD.

Additionally, you seem to have diagnosed yourself as having a skill deficit with interviewing. This is also a great position to be in. If you want to work on interviewing, which based on your message it sounds like is your weak skill, then invest time (and maybe money) in practicing that skill with the added understanding you have (and skills you are building) about your managing your ADHD.

One way to think about this is to treat interviewing as a separate skill set; there really are lots of online resources that teach you to interview these days. Practice interviewing as a separate skill set.

You can invest in this skill with money; leetcode and other sites really package this as a service. The benefit to you is not that they will grant you a job offer; it's that they will grant you the opportunity to practice in low stakes environments. There are also places online that are pairing people for interview practice.

You can also reach out to people you have worked with previously and say: I want to practice interviewing; would you spend 30 minutes with me doing a mock interview? People love to help each other.

At the same time continue to invest in managing and understanding your ADHD by working with professionals to develop those skills. Combine the two and some time and you can do this.

You'll get this. Hang in there! Feel free to email me if you would like to talk more.


You can see it in cost explorer if you break down by one of the spend types. Went and checked it: group by usage type and then filter for service: RDS and you can see your io usage broken out in plain baa cost explorer.


Lovely, thank you!


Regardless of the interpretation of these maps, these do seem to show the power of a good tool built for the free market.

Here you have an app on everybody's phone that is such a useful tool that the government isn't even thinking to turn off in the middle of a war even when it's providing real time intelligence in the open about what is happening on the ground.

This seems like a great example of how openness in technology can overwhelm even one of the least Democratic governments through transparent infrastructure.

I bet when they were building Google maps back in the early/mid 2000s they never thought their tool would be used for real time tactical war reporting on civilian and troop movement.


Back in Feb'22 the first non-classified sign of Russian offensive were traffic jams at 3AM on all roads toward borders.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: