Hacker Newsnew | past | comments | ask | show | jobs | submit | lightyrs's commentslogin

Really interesting deep-dive reverse engineering of Din Sync (Sync 24)

» Have there been any mistakes in signature verification for this letter?

» We are aware of two mistakes in our efforts to verify the signatures in the form so far. One person who was not an employee of OpenAI or Google found a bug in our verification system and signed falsely under the name "You guys are letting China Win". This was noticed and fixed in under 10 minutes, and the verification system was improved to prevent mistakes like this from happening again. We also had two people submit twice in a way that our automatic de-duplication didn't catch. We do periodic checks for this. Because of anonymity considerations, all signatures are manually reviewed by one fallible human. We do our best to make sure we catch and correct any mistakes, but we are not perfect and will probably make mistakes. We will log those mistakes here as we find them.


This was really fun. Nice job.


Interested to know what's changed (if anything) in the two years since this was written.


for one thing the ingress nginx is retiring[1], so they're probably revsiting alternatives, maybe even the service meshes for the new gateway api.

1: https://kubernetes.io/blog/2026/01/29/ingress-nginx-statemen...


Last night I was blocked from HBOMAX (or whatever brand they go by these days) for being on a VPN. That was the first time I've ever encountered something like that on HBOMAX. I wonder if there is some coordinating event here.


Did the error condition actually call out "VPN use" ? Did the HBO UI actually call out, by that term, a VPN ?

... or were you simply using a VPN and that's the most likely culprit for a general failure of the service ?

Genuinely curious ...


Having it spelled out as "Are you on a VPN?" on streaming services is pretty common these days. I guess with the popularity of consumer VPNs that term isn't just a technical one any more.


They specifically used "VPN" in the error message but I can't remember the exact text of the whole message.


I made several attempts to try to get it to generate something more esoteric. Here is a story about a computer falling in love with a potato chip who becomes a sentient meth addict.

https://g.co/gemini/share/598cc68832a9


I don't get it but I'm not sure I'm supposed to.

    life + death = mortality
    life - death = lifestyle

    drug + time = occasion
    drug - time = narcotic

    art + artist + money = creativity
    art + artist - money = muse

    happiness + politics = contentment
    happiness + art      = gladness
    happiness + money    = joy
    happiness + love     = joy


    Life + death = mortality  
is pretty good IMO, it is a nice blend of the concepts in an intuitive manner. I don’t really get

   drug + time = occasion
But

   drug - time = narcotic
Is kind of interesting; one definition of narcotic is

> a drug (such as opium or morphine) that in moderate doses dulls the senses, relieves pain, and induces profound sleep but in excessive doses causes stupor, coma, or convulsions

https://www.merriam-webster.com/dictionary/narcotic

So we can see some element of losing time in that type of drug. I guess? Maybe I’m anthropomorphizing a bit.


Does the system you’re querying ‘get it’? From the answers it doesn’t seem to understand these words or their relations. Once in a while it’ll hit on something that seems to make sense.


Having kids is an excellent solution to this feeling. Besides occupying any time you used to have for unnecessary work, they have an uncanny ability to remind you just how little you actually control. However you get to the end of the OCD tunnel, the journey is often very worthwhile.


I am a father of two, and I could not have penned that any better.


I really enjoyed this. I try to run my team similarly.

Where I disagree slightly is vendors. If the need filled by the vendor is well-defined and low-complexity, sure, I'll go for it. Otherwise, I'm doing it in-house nine times out of ten.

Where this starts to get tricky is when some worthy competitors emerge, utilizing your foundation to scale quicker and more effectively. Then you might wish you had hired more people earlier. But overall, I think starting from this perspective is a lot safer than the opposite.


> It did not reduce student drug use. In face, it backfired and taught kids about interesting drugs that they probably wouldn't have found learned about otherwise.

I will never forget the day in fifth grade when a DARE representative came to our class with a briefcase full of samples of esoteric (to me at least) drugs. The way they were presented made them extremely appealing to me, similar to perusing the choices at a high-end candy store. I don't know for sure if this had any effect on me but I strongly suspect that it did.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: