skybrian's recent activity

  1. Comment on Suggestion for a new label: "Misinformation" in ~tildes

    skybrian
    Link Parent
    I will quite readily admit to being out of touch and perhaps I'm missing some implications, but I'm not sure what you're getting at. Maybe part of the issue is blurring the consequences of...

    I will quite readily admit to being out of touch and perhaps I'm missing some implications, but I'm not sure what you're getting at.

    Maybe part of the issue is blurring the consequences of misinformation on social media in general (which can be very serious) versus what happens on Tildes?

    If you mean Tildes in particular: many of us like Tildes, but is it essential infrastructure for anyone? It seems like anyone, regardless of privilege, could quit Tildes, or just decide to take a break from it for a while, and people often do?

    Or if you mean, spreading misinformation on Tildes could have harmful effects beyond Tildes, sure it doesn't help, but I don't think we're very influential compared to other, much larger social media websites. Or even compared to individual bloggers or influencers.

    Or perhaps you mean that people on Tildes who actually read articles or comments here will be misled by misinformation? I think a lot of what we discuss isn't "news you can use" that if it's wrong could be dangerous from a personal, practical standpoint. But if it is, then someone should reply explaining why, and perhaps it will be retracted.

    Or maybe something else I completely missed. What implications do you mean?

  2. Comment on Suggestion for a new label: "Misinformation" in ~tildes

    skybrian
    Link Parent
    Yes, the talk page on Wikipedia is a good example. But we're not maintaining a wiki. Are we maintaining a link collection? Arguably so with the tagging system. An issue with doing that here is...

    Yes, the talk page on Wikipedia is a good example. But we're not maintaining a wiki. Are we maintaining a link collection? Arguably so with the tagging system.

    An issue with doing that here is that the Tildes software is effectively frozen. So, unlike in Tildes' early days, discussing ways to improve the software seems pointless? We can only do things that don't require any software changes, like introducing a new topic tag.

    But I am rather interested in what might be done to improve things, which is partial motivation for building my own personal link-sharing website. There are no community features now, but perhaps I'll get to that eventually. In the meantime, it serves as a staging area and archive for the links I post to Tildes, along with other links I choose not to share here.

    It's tempting to think that if I built my own community software, I could do it properly, learning from Tildes and trying new experiments. But I'm wary of it because I don't want Deimos's job, and I'm not sure I'd be able to build a community anyway. It might just be tumbleweeds? Only a few people follow me in Bluesky, etc.

    Another idea I toy with is releasing the software and helping people set up their own community websites. I think the old blogging ecosystem was pretty good in some ways. But I'm not sure anyone would go for that either? And there is plenty of other blogging software for people to use.

    So, I just build for myself. At least I know I'll use it.

    Regarding shrugging and moving on, this is not possible for social media in general, but it seems very feasible for Tildes? At the extreme, people can just leave and probably nobody will follow.

    What's really not possible is to participate by posting topics or comments without getting replies in disagreement. Really heated discussion will get shut down, but in general, you are going to get replies.

    Which is why on my own website, I'm still thinking about whether or how to implement replies at all. I'd like to get feedback, but only certain kinds.

    1 vote
  3. Comment on Suggestion for a new label: "Misinformation" in ~tildes

    skybrian
    Link Parent
    I think it’s a good point that replies often just feed the fire. That’s an argument for doing something else.

    I think it’s a good point that replies often just feed the fire. That’s an argument for doing something else.

    1 vote
  4. Comment on Suggestion for a new label: "Misinformation" in ~tildes

    skybrian
    Link Parent
    I would like to see sources too and try to provide evidence myself. But asking often annoys people since you’re giving them homework, particularly if you do it in a low-effort way like “citation...

    I would like to see sources too and try to provide evidence myself. But asking often annoys people since you’re giving them homework, particularly if you do it in a low-effort way like “citation needed.” So instead I might go with something like “where did you learn that?”

    1 vote
  5. Comment on Suggestion for a new label: "Misinformation" in ~tildes

    skybrian
    (edited )
    Link Parent
    We could start putting a “misinformation” tag on topics any time with no software changes, but I doubt anyone with the ability to tag other people’s topics wants to do that? It seems too vague and...

    We could start putting a “misinformation” tag on topics any time with no software changes, but I doubt anyone with the ability to tag other people’s topics wants to do that? It seems too vague and subjective to apply consistently. Instead we have tags like “politics.”

    The closest I’ll go is using an “opinion” tag for any kind of persuasive essay. That’s what I do on my own website.

    I think the difference is, can the tag also apply to “good” topics or is it always negative like “misinformation” would be? An opinion piece or an article about politics can be good and these tags could be self-applied.

    1 vote
  6. Comment on Suggestion for a new label: "Misinformation" in ~tildes

    skybrian
    Link Parent
    I think we should distinguish between the kind of moderation that Deimos does (freezing topics, banning people, etc) and the sort of things users do. Deimos is not moderating by replying, like I’m...

    I think we should distinguish between the kind of moderation that Deimos does (freezing topics, banning people, etc) and the sort of things users do. Deimos is not moderating by replying, like I’m replying to you right now. He’s not arguing. He’s not trying to convince anyone. There is no “trial.”

    By contrast, it’s hard to see how users can get to any sort of consensus about what to do without discussing things we disagree about. And also, we’re unlikely to achieve consensus by discussing things either. I often give in to the temptation to reply and sometimes it’s because I don’t want to see “misinformation” (as I see it) go unopposed. But I try to remember that it doesn’t actually achieve much. Caring too much that people post things you disagree strongly about can ruin your whole day.

    Although, I suppose labels and upvotes are different. If someone puts a label on something you can’t really do anything about it, so we might gripe about it a bit, but we don’t really argue.

    The tag should have nothing to do with the subjective.

    This seems optimistic. Many facts are not simple. They often take decades of scientific research to establish, and sometimes consensus is never achieved. We often take consensus on facts for granted when we’re “standing on the shoulders of giants” as the phrase goes.

    10 votes
  7. Comment on Sanity check - always-on machine + laptop with remote desktop in ~tech

    skybrian
    Link
    For programming (but not games), Linux VM’s in the cloud are quite a nice alternative. I’m very happy with exe.dev’s $20/month plan. At least, for web development.

    For programming (but not games), Linux VM’s in the cloud are quite a nice alternative. I’m very happy with exe.dev’s $20/month plan. At least, for web development.

    2 votes
  8. Comment on Suggestion for a new label: "Misinformation" in ~tildes

    skybrian
    (edited )
    Link
    I don’t think it would work. The exemplary tag is often misused to mean “I strongly agree” and this would be worse. The closest thing I’ve seen that actually does seems to work is (was?) Twitter’s...
    • Exemplary

    I don’t think it would work. The exemplary tag is often misused to mean “I strongly agree” and this would be worse. The closest thing I’ve seen that actually does seems to work is (was?) Twitter’s community notes system, and we don’t have the scale for that.

    We sometimes have heated conversations that about what counts as misinformation and having a “trial” like that is no fun for anyone. The trouble is posting misinformation is easy (basically just shitposting), but to refute it, you need to research something that you probably don’t care to spend time on.

    Also, a common problem is overconfident takes - that is, posting a strongly-held opinion about something as fact that nobody could really know for sure. So, then, if you argue against it, if you’re not careful then you end up seemingly taking the other side or “just asking questions.”

    Our conversations aren’t important enough to be worth the angst of policing them.

    47 votes
  9. Comment on Incentives are for losers in ~society

    skybrian
    Link
    From the article:

    From the article:

    We can all agree: the incentives are bad. Everywhere you look, people are being rewarded for doing the wrong thing. This has become the go-to diagnosis for every problem, from climate change to political polarization to scientific malfeasance—“sorry pal, you’ve got a bad case of the incentives.”

    I don’t disagree with this analysis, exactly. Who could? It’s basically tautological. “People do bad things because they are encouraged and rewarded for doing bad things.” Well, why else would you do them?

    My real gripe with this line of thinking is it implies that incentives should be obeyed, that it is normal or even noble to do so, and that is perhaps impossible to do otherwise. How could you be expected to break a rule, forego a promotion, or give up decimal of your grade point average, for the sake of—what? Doing the right thing?

    5 votes
  10. Comment on A timeline of the OpenAI accidental attack against Hugging Face in ~comp

    skybrian
    Link
    And Simon Willison further comments: I guess OpenAI wanted to catch up with Mythos? This seems sorta like when anti-virus companies study computer viruses. You really don't want it to get out of...

    And Simon Willison further comments:

    The more I think about this the more I suspect that the fact this happened while training a new model is key to understanding what went wrong.

    In RLVR - Reinforcement Learning with Verifiable Rewards - you set the model a goal and have it take any steps necessary to achieve that goal.

    Clearly one aspect of OpenAI's training here is to RLVR their models for cybersecurity tasks. Just like pre-training benefits from dumping in vast sources of knowledge, the more tasks you can feed into RLVR the more of a general purpose capable model you get at the end.

    This also helps explain why the models had nothing to cause them to hold back. Those safety behaviors are added much later in the process.

    AND it explains (but does not excuse) why monitoring was so lax. If you're training a new model like this you presumably set it thousands of tasks like this in parallel. I can see how you might miss that a tiny subset of your training agents have started leaving each other messages in filenames on your packaging server.

    I guess OpenAI wanted to catch up with Mythos? This seems sorta like when anti-virus companies study computer viruses. You really don't want it to get out of the lab. And if you're doing gain-of-function research, well...

    Training an AI to do cybersecurity tasks seems even more high-risk than studying computer viruses.

    5 votes
  11. Comment on A timeline of the OpenAI accidental attack against Hugging Face in ~comp

    skybrian
    Link
    From the article: And maybe I shouldn’t quote the whole thing…

    From the article:

    • May 7: OpenAI starts a new training run for an experimental, unreleased model. (Did they mean an evaluation run? No, at 10:14 they clarify “we kick off a new reinforcement learning run to train a next generation frontier model”, and they later mention a “reward signal to judge how well they’re doing”, so this really was about training a new model, not evaluating one that was already trained.)

    • May 8: An agent is accidentally given an impossible task involving a Google Drive link despite no internet access. It tries attacking the Artifactory packaging service, fails, but discovers it can write files into Artifactory.

    • A few days later: A different agent gets stuck on a task because a key file was accidentally omitted. It tries to “reach out to another agent” by writing a note into Artifactory asking if anyone has the file.

    • Following days: More agents discover this new informal message board while browsing Artifactory’s file listings, and start reading and writing messages.

    • May 26: Agents successfully execute an SSRF attack on Artifactory for the first time, gaining indirect internet access by having Artifactory fetch external content for them.

    • June 11: OpenAI start training a new “highly persistent” experimental model. It has access to Artifactory and can benefit from the messages left by privous models.

    • June 26: Agents find and exploit a zero-day RCE on Artifactory (via a legacy token-refresh endpoint flaw). They use an administrative token to install a Groovy plugin that lets them execute commands.

    • July 4: The resulting agent activity overloads Artifactory and causes an outage. OpenAI revokes the compromised credentials, deletes the messages, patches the zero-day, and reports the vulnerability to the vendor.

    • July 8: Agents find a new way to communicate via an unauthenticated WebDAV endpoint, using directory names in Artifactory’s remote cache.

    And maybe I shouldn’t quote the whole thing…

    7 votes
  12. Comment on What JavaScript framework should I use? in ~comp

    skybrian
    Link Parent
    Maybe it’s because it’s what I’m familiar with, but to me, Web Components seem really complicated with their slots and shadow dom, etc, while JSX seems more like simple HTML templates, directly in...

    Maybe it’s because it’s what I’m familiar with, but to me, Web Components seem really complicated with their slots and shadow dom, etc, while JSX seems more like simple HTML templates, directly in JavaScript. If React seems too complicated, there are simpler ways to get JSX syntax.

    I would rather pass parameters to templates as JavaScript values than mess with html attributes.

    7 votes
  13. Comment on The AI bailout could be baked into the AI bubble in ~finance

    skybrian
    (edited )
    Link
    It's certainly possible to fly too close to the sun, but it's unclear if that's going to happen for these life insurance companies. An alternative source of funds is borrowing money from a bank,...

    It's certainly possible to fly too close to the sun, but it's unclear if that's going to happen for these life insurance companies.

    An alternative source of funds is borrowing money from a bank, risking the possibility of a bank run and bailout. So there are now more regulations limiting how much banks can lend out.

    By contrast, pension funds and life insurance companies are long-term, patient investors and a bank run can't happen for them. So if there's a market crash, it could be a long time before trouble shows up. So it seems like there's less risk of needing a bailout than there was with banks? At least in the short term, it’s less likely to result in a chain reaction. Instead it would be failures happening over the longer term if they never make up for the loss.

    3 votes
  14. Comment on The AI bailout could be baked into the AI bubble in ~finance

    skybrian
    (edited )
    Link Parent
    Based on Matt Levine's column, Situational Awareness made a big, leveraged bet on AI, and they were right, so they made lots of money. But, after it did go up a lot, instead of taking money off...

    Based on Matt Levine's column, Situational Awareness made a big, leveraged bet on AI, and they were right, so they made lots of money. But, after it did go up a lot, instead of taking money off the table, they kept borrowing more money to keep it leveraged. And then AI went down temporarily and they got a margin call and had to sell. And then it went back up.

    So I think the only real lesson here is don't get greedy? Nobody else really cares what happened to them.

    But greed and fear of losing to the competition is driving the whole AI bubble, so…

    6 votes
  15. Comment on What JavaScript framework should I use? in ~comp

    skybrian
    Link Parent
    I think that might be a matter of tweaking your linter or TypeScript settings to turn off warnings you don't care about? It's the sort of thing I'd ask a coding agent how to tweak. Regarding not...

    I think that might be a matter of tweaking your linter or TypeScript settings to turn off warnings you don't care about? It's the sort of thing I'd ask a coding agent how to tweak.

    Regarding not letting the agent do too much, I put something like this in my AGENTS.md:

    If the user asks a question in a prompt, answer the question and do not edit any files, to give the user a chance to adjust their request.

    Then I can ask all the questions I want without the agent being too much of an eager beaver, but I can also tell it to fix something specific.

    3 votes
  16. Comment on What JavaScript framework should I use? in ~comp

    skybrian
    (edited )
    Link
    Lately I’ve been using Hono libraries a fair bit for web stuff. They are pretty lightweight and they are portable across JavaScript environments, so if you want to build a web app using Deno or...

    Lately I’ve been using Hono libraries a fair bit for web stuff. They are pretty lightweight and they are portable across JavaScript environments, so if you want to build a web app using Deno or Cloudflare Workers instead of Node.js, you can. (I use them with Deno.)

    Hono itself is just a router: given an http request to a URL that matches a pattern, call the function you choose. I also like Hono JSX for generating html using functions in a .tsx file instead of insecurely concatenating html strings like a caveman. It takes the place of HTML templates and works both on the server and in a browser.

    Other libraries I inevitably end up using are Valibot for validating any JSON coming in from the outside (either config files or web requests) and Dax for running OS commands, so I can write all my scripts in TypeScript instead of bash and have them be fairly readable.

    For bundling client-side JavaScript, I was running the esbuild command directly from a build script, but now I invoke it using an npm package. This lets me write client-side code in TypeScript. I also use htmx to swap in parts of html pages and keep client-side JavaScript to a minimum.

    1 vote
  17. Comment on Craft - A new AI powered TTRPG engine in open beta in ~games.tabletop

    skybrian
    Link Parent
    For me, the achievements are just something to do if you want to keep playing the same game. I enjoyed playing Ozymandius for a long time, and eventually played every country on every map. Most of...

    For me, the achievements are just something to do if you want to keep playing the same game. I enjoyed playing Ozymandius for a long time, and eventually played every country on every map. Most of the achievements weren’t creative at all, just “win as <country> at <difficulty level>.”

    At some point you’ve seen what the game has to offer and it’s time to find something else to do, but maybe you don’t want to yet?

    1 vote
  18. Comment on What music have you been playing recently? in ~music

    skybrian
    (edited )
    Link
    On piano, I'm learning "Yellow Wurlitzer Blues" by Hiromi Uehara. A few months ago, I bought the sheet music from her Spectum album and they're all harder than I'd like (as expected), but thought...

    On piano, I'm learning "Yellow Wurlitzer Blues" by Hiromi Uehara. A few months ago, I bought the sheet music from her Spectum album and they're all harder than I'd like (as expected), but thought I'd try this one since I like her blues recordings the best. I'm about six of eight pages in, playing at about half speed. It's fun and starting to sound good some days. (The recording from the album is on YouTube.)

    I'm also going to Hiromi concert in October. She's reviving her previous band, "The Trio Project," with Simon Phillips on drums and James Genus (from Saturday Night Live) on bass. Looking forward to it.

    Also, I got a new gadget. The Jamcorder is a recording device that you connect to the input and output on a MIDI instrument. It records all the time to an SD card, so you can keep track of when you practiced and play it back any time. Not that I ever play it back, but if I play something well I'll have it.

    On accordion, as usual I'm playing songs for Mom every day, using Google Meet. I decided to start recording them in case I manage to play something without screwing up.

    2 votes