Hacker Newsnew | past | comments | ask | show | jobs | submit | 63's commentslogin

It's easy to blame the military and the higher-ups, after all they made this choice. But more relevant to HN, this couldn't have happened without technology professionals working for Palantir.

> A Palantir spokesperson told Bloomberg the company “is not responsible for the underlying data nor identifying intelligence deficiencies” and that there is no evidence its software was at fault.

If you work for Palantir, you are writing software that kills people. Software that, in this case, killed 123 children. What salary is worth that?

I encourage others who work in the public sector, whether directly or through a contractor, to read and internalize Don't Get Distracted by Caleb Hearth [0]. I think about it nearly every day.

[0] https://calebhearth.com/dont-get-distracted


>It's easy to blame the military and the higher-ups

My brother in Cthulu, they're the ones making the life or death decision that killed people, who else should be to blame?

>But more relevant to HN, this couldn't have happened without technology professionals working for Palantir.

If you wanna go the historical tech-tree scapegoat route then none of this would have happened if DARPA wouldn't have invented the internet, or if Thomas Edison wouldn't have invented the lightbulb, or if the fish haven't ventured onto land and evolve into us land mammal apes who invented sharpened sticks as murder objects.


Look, if Palantir had any redeeming qualities then I might agree with you. Unlike electricity which runs our computers, homes, cars, etc. What does Palantir do? It spies on people and helps governments to create "people we don't like" lists. In the absolute best case it's a "minority report" engine, but it's still just there to try and stop pre-crime (not crime).

This isn't the case where we are talking about a company doing anything socially good. It's simply there to help authoritarian governments.


Palantir only exists because government wants and funds these types of tools. If it Palantir wouldn't exist then another dozen companies with different names would exist that would create the same Torment Nexus for the government due to inexhaustible demand for such tools.

>It's simply there to help authoritarian governments.

The fact that you're so close yet so far away to figuring out who's to blame still boggles my mind.


Are you implying that the demand for these evil services absolves the suppliers from any moral responsibility? Simply because “if we don’t do this somebody else will”.

It’s an evil service and no matter who requests it or supplies it, doing so is an evil act.


>Are you implying that the demand for these evil services absolves the suppliers from any moral responsibility?

No, you are implying that. I'm saying that evil are (primarily) those who use it, not (just) those who make it. You can try to make whatever you want, if nobody will buy it to fund it, then you won't have money to make it, so your evil thign won't exist. Palantir only exists because governments are evil and willing to fund it to buy it and use it. If you want likes of Palantir to not exist then you need to hold your government accountable to not spend money on evil things.

Are gun makers evil and responsible whenever someone gets killed by a murderer, or are those who pull the trigger responsible for who they kill?


> Are gun makers evil and responsible whenever someone gets killed by a murderer, or are those who pull the trigger responsible?

Yes. There's a reason Remington decided to settle for $73M dollars with the sandyhook parents even though they didn't "pull the trigger" [1]. That's not a number you pick because you think you'll win the case.

[1] https://abcnews.com/US/sandy-hook-families-settle-remington-...


>There's a reason Remington decided to settle for $73M dollars with the sandyhook parents

It's only because of how the legal system works in the US(for better and for worse), with profit-seeking ambulance chasing lawyers, and where cases are decided on the emotions and societal moral panics of the people in the jury and the negative image such cases can cause to a brand, not if someone or a company is objectively right or wrong in the eyes of the law.

Meaning it's cheaper to pay people off even if they're legally wrong, than try to prove you are right but then deal with the bad publicity of the emotionally charged mob with pitchforks and torches who blames you for their kids dying and looks bad in the media.

Keep in mind parents of that time also blamed violent videogames like Doom for it, so it's not like they were right about who was to blame, they were just looking for retribution from anyone they could, aided by unscrupulous ambulance chasing lawyers looking to cash in on the drama that was feeding on the public's emotions amplified by the media also cashing in.

So highly mediatized and politically divisive/charged legal cases, are not (always) great examples of objectivity and righteousness of the US legal system.


Jury trials definitely have their flaws, but what would you propose as a better approach?

I absolutely knew you’d bring up guns and gun making but it’s not a valid comparison. If the gun companies were also involved in the actual shooting of people part that would work.

Palantir were in no way obliged or coerced into making an evil thing, they just decided being evil for money was ok.


>I absolutely knew you’d bring up guns and gun making but it’s not a valid comparison. If the gun companies were also involved in the actual shooting of people part that would work.

Do you have an argument on this that isn't child Redditor armchair level?

>Palantir were in no way obliged or coerced into making an evil thing, they just decided being evil for money was ok.

You keep beating it around the bush and avoiding to address the fact that if Palantir wouldn't do that, then dozens of other companies would.

You can't expect for society and especially for-profit businesses to run on morality in order for evil apps to never be made, but you need the government to do that by rule of law and force behavior of companies so that no Palantir ever exists.


Personal insults only weaken your argument.

Palantir could decline to build this and so could everybody.

If somebody proposed to you that you could have a lucrative contract in exchange for an intrusive system that provides a bedrock for authoritarianism, you are arguing it’s perfectly ok because if not you, somebody else will and that makes it OK.

It doesn’t.


>Palantir could decline to build this and so could everybody.

The issue with this broken argument you keep repeating is that it only works in a fantasy setting where the world only runs on morality, where countries could also decide to not have nuclear weapons and never got to war with each other and share resources fairly, and end world hunger and all that, while my argument is based on how things work in the real world which isn't run on morality but on rule of law enforced by force of violence, and such power corrupts, so the world is run in a corrupt fashion by powerful and corrupt people, meaning the existence of various Palantirs is virtually inevitable unless the voting population heavily protests to force the governments' hands.

>you are arguing it’s perfectly ok because if not you, somebody else will and that makes it OK.

No, I never said that. You're good at pretending to misunderstand things I never claim to have things to build arguments upon.


There are several things that make Palantir uniquely objectionable, though:

1) They're private-sector and have low hiring standards, which can lead to Boeing-esque quality control issues

2) They have every incentive to fleece US taxpayers, becoming another over-fattened rice-bowl defense contractor

3) Exporting Palantir products could create diplomatic crises and conflicts of interest undermining American security (see: NSO Group)

We can't ever avoid spyware since Google, Microsoft and Apple already built the perfect surveillance state a decade ago. But we can prevent taxpayers from being scammed, and reject the enshittification of the federal government's defense budget.


Would you hold that same line for individuals that built weapons, planes, bombs, etc in past wars?

Companies that make bombs aren't forced to (usually), and they also know there's only really one use for a bomb.


its clearly a democratically approved legal act though. If its as evil as you suggest, the better approach would be to convince your peers that its evil and thus should be made illegal

Again, absolving the company that built it and runs it. They weren’t coerced into doing so and must share the blame for the evil that was created.

Listen guys, i cannot be held responsible for how an evil government chooses to use my child torture machine, if I didn't make it someone else would have, you cannot blame me, I'm just great at building stuff and trying to put food on the table

I know, right? I'm not even sure if this is the biggest installation on Earth. If it's possible for us, it's possible for any number of private military contractors. I bet there's a similar capability in the hands of every advanced county on Earth. Anyway, shaddup, the focusing crystal's not calibrating right, and tomorrow I have present the targeting parameters to Dr. Evil.

Thank you for sharing the talk.

> I encourage others who work in the public sector, whether directly or through a contractor, to read and internalize Don't Get Distracted by Caleb Hearth.

I know a guy who works for well-known hardware company. He isn't a software dev, but close enough, works with Verilog on hardware design and verification. One day he tells me how he is working on video processing module and he doesn't know if that module will be part of surveillance system, missile guidance or nanny cam. It's possible that even middle management doesn't know more than him, and very likely the module will find uses in multiple products. He is a small cogs in a large machine, maybe his work will save a baby's life, maybe it will kill a person, he cannot know.


Well, at least there are definitely jobs in hardware and software where you can in fact be 100% sure what you build won't kill another person. Surveillance, Missile guidance, and nanny cams though? What, does he work for Honeywell or something?

Not Honeywell. In consumer market they are known only for storage and memory products, I didn't know they do anything else. Timing is also interesting because his regional management office is in Tel Aviv, so it could be just a conspiracy theory at his local office.

If I write healthcare software, and a doctor orders the wrong drug that kills the patient, am I responsible?

It depends. Did you write a bug that caused the wrong drug to get ordered? Did you design or implement an algorithm that recommends drugs, and the algorithm was a bad one? Did you design or implement a confusing UI flow that led to the doctor ordering the wrong drug?

If so, I'd say yes, you share some of the responsibility. Legally, I'm sure you'd be fine, but if that were me, I'd feel responsible.

The doctor of course is responsible too; they're the one who didn't double-check that it was an appropriate drug. But multiple people can share responsibility for a bad thing.


Legally, probably not...?

Whether you may/should feel responsible depends on how the software works, I guess. Did it automatically recommend some drug, somewhat confidently, with gray text on gray background saying "AI sometimes makes mistakes"?

So I think we should behave responsibly when making software, even more now with AI


Yeah but if I didn't write the software that killed 123 children, somebody else would've anyways!

At least I can donate some of my salary to progressive politicians! I don't, but I hypothetically could, which makes me a good person.


The govt is investing in the military whether you like it or not, there is a set amount of GDP going into the sector regardless of your moral choice.

Would you rather not have someone make good software that does not misidentify schools at sites? Or should we outsource this to worse engineers who don't care about morals and don't find this metric meaningful?


That's a reasonable argument, but I don't think I could make the decision to work on software that's designed to kill people. I consider myself a pretty good software developer, and yes, I could probably do a better job building software to help kill people than many others, but I don't think "if you don't do it, someone less capable will, and more innocent people will get killed" would sway me. I just don't want to be involved in that, and I'm lucky that I don't have to be.

Well you made a personal choice to stick your head in the sand to not have to deal with the hard emotions, and that's fine. But to then pass judgement on people who don't sounds a bit unfair given this.

You stuck your head in the sand on this one buddy but I'm going to build the safest god-damned child torture machine possible because if I won't some jackass will that gets a child more hurt than they need to, sorry I don't live in your fantasy world of rainbows and sprinkles.

The people sticking their head in the sand to avoid hard emotions are the ones writing the people-killing software.

Those who are aware of it, and choose not to, are the ones who have reckoned with those emotions and chosen not to participate in the killing of innocents.


The government is sending people to death camps whether you like it or not; there is a set number of non-Jews being sent there regardless of your moral choice.

Would you rather have someone make good software that does not misidentify non-Jews as Jews and send them to the death camps? Or should we outsource this to worse engineers who don't care about morals and don't find this distinction meaningful?


Of course it could have happened. You don't even need targeting for this to happen. You can drop bombs at random and kill whoever is unlucky enough to be in the wrong place. The US has a long history of doing it (Japan, Vietnam, ...).

So yeah, the military and whoever decided that a war was a good idea are to blame.

People working at Palantir are as much responsible for the killing of these 123 children than seatbelt manufacturers are responsible for the people who died because their product failed. That is, because they didn't do their job correctly, people died, definitely worth feeling bad about. However, should people stop working in seatbelt manufacturing because of it? Absolutely not, we need seatbelts, because without them, things would be worse.

Palantir, or whoever does target identification, is like the seatbelt of the reckless drivers of the militaries, who, for the lack of precise information, would just carpet bomb the place. It is not a hypothetical, it is how the US has worked before they had precision ammunition.

This is essentially a trolley problem. The war is the trolley, people who work for Palantir are the ones pulling levers. And if there is no one to pull the lever, the trolley is gong on a track with a lot of people on it.


Let's not forget the shareholders who invested in this company knowing what they do. That includes some of my colleagues. I told them that whoever created and named this company is clearly a psycho.

If you found this interesting, you may also be interested to hear about some related projects with similar goals/scopes: Miri[0], Kani[1], and Creusot[2]. There looks to be some significant overlap between Verus, Kani, and Creusot but I've not used any of them so I'll refrain from trying to differentiate them.

[0]https://github.com/rust-lang/miri

[1]https://github.com/model-checking/kani

[2]https://github.com/creusot-rs/creusot


Miri: proves pre-defined properties, no changes to code other than adding a few annotations

Kani: use in a test suite

Creusot: annotations

Verus: annotations or macro

The macro system looks very nice if it doesn't slow down the normal build.


AI tells me that code using the verus! macro everywhere would double in build time but if only used ocassionally the verus! macro would only increase build time by a few percent. The attribute annotation would basically be free, but there is a downside that loop invariants would be rejected by stable rustc.

A bit unfortunate that so many of the interesting bits were left to ai. I would've enjoyed some commentary on why the custom TLS implementation was necessary. Oh well.

Update: found this explanation in a comment at the top of the (surprisingly short) Go file in the linked repo:

The target client is Netscape Communicator 4.51 (both the 40-bit export build and the 128-bit US build) with its clock set to the year 2000.

Go's crypto/tls cannot help: it dropped SSLv3 in Go 1.14, never accepted the SSLv2-compatible ClientHello that Netscape 4 sends, and never had RC4-MD5 or the 40-bit export suites. So this file carries its own tiny SSLv3 server-side implementation on top of stdlib primitives (RSA PKCS#1 v1.5, RC4, DES, 3DES, MD5, SHA-1). The server key is 512-bit RSA so that export clients can encrypt the premaster secret to it directly, without a ServerKeyExchange.


(As the author of the post)

I've written and worked on a few TLS implementations, so it wasn't terribly interesting to me. And I have to go to work tomorrow and solve real, modern CA problems :)

But in short, I wanted to use Go, and it doesn't support SSLv3, the SSLv2 Client Hello, or the 40-bit RC4-MD5 export-grade cipher suites which I wanted to support too.

I was more shocked that I managed to get stock OpenSSL to issue a certificate that worked. There's a number of things that didn't work there, too. You can find my scars in mkcert.sh in the repo. Perhaps all of this is worthy of a follow-up post.

I could have tried to get some old server running instead, but I wouldn't have wanted to deploy that on the internet, even on an isolated Fly VM.


I bet all the certificate metadata shown in the „View a certificate“ popup window is vulnerable to cross-site scripting. Back then you probably wouldn’t get a <script> tag through a CA's review process and I found such a problem in Netscape's image „About page“ popup.


If it were vulnerable to XSS, why would you even want it properly signed by a CA? People almost never inspect the certificates of working websites, the only time they might look at it is when it fails validation.


I actually do like to view certificates of working sites, because it can be interesting to see what's listed in the Subject Alternative Names field. It can lead to some interesting observations about what sites are linked.


Netscape of this era predates the Subject Alternative Name :)


Strange seeing how people have such a hard time seeing others using AI and seem to want to complain about it instead of just, well, asking AI why something was likely done a way. It works both ways my dudes, experts don’t need to explain every last detail, prompt a bot with the context until you understand.

From my prospective, the outputs of a bot aren’t the interesting bits, it’s the input prompt that should warrant more attention.


I asked my AI for a rebuttal to your argument and it came up with some pretty good points.

Since inputs are more interesting than outputs I've included my prompt; you should submit it to your AI to see why you're wrong.

> I'm debating with someone online. Can you come up with a counter argument? Here's what they said: <QUOTE>


Probably because modern libraries dropped support for ancient insecure SSL. Backwards compatibility is really not a valued thing for that area.


A while back I helped a friend (read: dumped a bunch of compute power into it) brute force the SSL keys for Sega's "Phantasy Star Online" Dreamcast game.

They used a similar kind of custom (and flawed) TLS implementation in their game(s) which allowed signing new certificates after brute forcing.

The benefit to this is that users can now play these games without needing to burn a new CD with either the SSL certs swapped, or the code patched to dummy out the checks. A "retail CD" will simply work with private servers now.

I've also been on the other side of the fence, building a "retro internet" service [1] has meant trying to implement ancient SSL/TLS services for things and people that want to use them on the network.

Getting modern OpenSSL (aka what ships in Debian) to even accept these ciphers, let alone keys that short is an uphill battle. Understandably, they're disabled by default and (in Debian at least) the cipher support isn't even compiled into the binary! This requires building a custom OpenSSL to build Nginx against to serve ancient SSL.

Presumably for the OP this kind of work was either outside of their realm of knowledge, or simply "easier" to outsource to the slop machine. Though I hope the machine they're running their demo TLS implementation on is separated completely from their own network. Rolling your own crypto libraries is always a bad idea [2] and I doubt LLM's have "improved" that

[1] https://www.youtube.com/watch?v=cSJsGNIDjtc

[2] https://soatok.blog/2025/01/31/hell-is-overconfident-develop...


(I have next to zero knowledge of matters crypto)

“Presumably for the OP this kind of work was either outside of their realm of knowledge,”

Unnecessary? I don’t even follow the statement’s framing even if I validated the apparent nerdswipe tendency.


Wasn't intended as a "nerdswipe". Wrangling OpenSSL to actually work is a herculean task on a good day. Much less figuring out how to enable ancient crypto protocols within it

It's okay to "not know things". Computers are such an incredibly vast field that there's chunks of them that can simply be beyond some of us


> A while back I helped a friend (read: dumped a bunch of compute power into it) brute force the SSL keys for Sega's "Phantasy Star Online" Dreamcast game.

Is there anything published online about this? It looks like the Sylverant website still requires patching the game.

https://sylverant.net/connecting-to-sylverant/


I'm not sure why they aren't using it. His github repo is over here

https://github.com/patapancakes/dreamconstraint


“Rolling your own crypto libraries is always a bad idea”

Absolutes like this aren’t absolutely true.

It’s interesting because in a related comment, someone claimed that I was “rolling my own crypto” https://news.ycombinator.com/item?id=37368245

>>>a few odd coding decisions, such as rolling your own crypto (RNG)<<<

Let me give some context here. MaraDNS is a DNS server that’s been around for a very long time, since 2001. There has never been, in those 25 years, any security holes found having to do with the RNG code used by MaraDNS. MaraDNS originally used an AES variant for the RNG; when DJB found cache timing attacks a little over two decades ago, I revised the AES-based RNG code to minimize the impact of such impacts, making the code slower and more complicated. So, about two decades ago, I implemented a new RNG based on RadioGatún, an algorithm which isn’t vulnerable to cache timing attacks and, indeed, has no known attacks which break its cryptographic claims, even though those claims were made over two decades ago.

My code has been extensively audited by multiple AI-based security researchers, and while they found two minor issues with the DNS-over-TCP code in the recursive resolver, and a minor issue with the RFC8482 reply in the recursive resolver, no issues have ever been found with the RNG code in MaraDNS (except the issue with possible cache timing attacks I fixed myself after learning about them). [1]

In the same time period, OpenSSL has had a large number of security issues, security advisories, and so on. OpenSSL has had countless security holes and patches in the last two decades (Heartbleed, etc.); MaraDNS has had precisely 0 known issues with its RNG code in the same time period. If I had relied on OpenSSL to keep MaraDNS’s cryptography secure, it would had been exposed to many more attacks than it has, since the code I rolled myself ended up being far more secure than using the code in a third party library.

Point being, it is possible for someone to roll their own secure RNG. I wouldn’t do so in a corporate context, for the simple reason management often times puts unreasonable time constraints on developers, but for an open source project developed on my own timeline, it can be, in fact it has been very secure.

Also: I was never exposed to the Lastpass breach because, instead of using Lastpass, I rolled my own secure website password generator. [2]

[1] https://samboy.github.io/MaraDNS/webpage/security.html

[2] https://github.com/samboy/PassGen


Forget whether you "roll your own" or not, userspace RNGs are a bad idea. The advice to rely on getrandom or urandom is as much about the superior security properties of a kernel RNG as they are about whether you'll fuck up AES somehow.


Linux kernel crypto code has resulted in security issues, e.g. CVE-2026-31431.

The advantage of using a cryptographically secure stream cipher [1] is that we only need about 128-256 bits of good entropy to generate an arbitrary large number of secure random numbers, across multiple systems (e.g. MaraDNS has a native Windows port where /dev/urandom randomness is instead done with proprietary Windows API calls). It can even give us some level of protection on systems where the OS level random API is compromised: Some people are wary of RDRAND because they think Intel might actually use an insecure PRNG for the numbers, and Coldcard Bitcoin seed generators were compromised a little over a month ago because their version of /dev/urandom was completely insecure on some of their devices.

[1] Yes, libsodium supports them: https://libsodium.gitbook.io/doc/advanced/stream_ciphers


This is CopyFail. You just provided CopyFail as evidence in favor of userspace random number generators.


A read() on /dev/urandom on every packet isn't economical, so there's going to be some user space element to RNGion


I don't grant the premise that per-transaction urandom reads are likely a meaningful expense to begin with but on modern Linux getrandom is a vDSO anyways. Even before the vDSO, getrandom was fast.

The application domain where this tends to get brought up as a problem is in large-scale simulation. I have no opinion about whether getrandom is fast enough for simulation, but here we're talking about cryptographic random numbers, not simply high-quality random numbers. If you want to use something like PCG for your simulations I won't dunk on you.


In addition to the overhead of a /dev/urandom read(), since my programs run in a chroot() sandbox, there’s the possibility that the file descriptor to /dev/urandom will no longer function—since chroot() is not part of POSIX, there’s no rigorous standard on how chroot() is supposed to behave with a given operating system.

getrandom() is another possible solution, but the problem with getrandom() is that it’s also not part of the POSIX spec, and my program needs to compile in an anally POSIX compliant system: While my programs use chroot() and setgroups(), both of which aren’t part of the POSIX spec, it has a configure time option to disable both chroot() and setgroups() so everything will compile as long as the underlying system follows POSIX.

The reason for this strict compliance with POSIX is because the changes to the C compilers (gcc and clang) between 2022 and 2026 made previous versions of MaraDNS have issues compiling everything, and, indeed, with these C23 changes to C compilers, unpatched djbdns no longer even compiles with a modern compiler. I changed everything to work with the new C23 spec, then I changed the compile flags to compile with a strictly compliant C99 compiler, but to get that to work, I had to make the program strictly POSIX compliant (with the exceptions of chroot() and setgroups()).

This way, should MaraDNS not compile in the future (remember: The post-C23 changes broke a lot of programs that used to compile just fine), it’s a bug with the compiler not following C99 and/or POSIX, and not a bug with MaraDNS.

Hence, my homegrown secure pseudo random number generator, so I can make strong random numbers while remaining POSIX compliant (we seed the PRNG before entering the chroot() sandbox). Of course, /dev/urandom is also not part of POSIX, but it’s on pretty much any modern *NIX, and trying to open /dev/urandom is not going to raise compile-time errors.


I don't think trading resilience for POSIX compliance is a good call, and I don't think "strong random numbers" is at all the right way to think about this problem.


For what it's worth, this comment was better than the article...

When you outsource to the slop machine, you don't have anything interesting to say (usually).


The slop machine gives answers to your questions. It hallucinates so it's recommended to verify what it says. Shit in, shit out. If you have no idea whatsoever and can't use other sources to verify claims, well, get a different job I guess.


Why use the slop machine then, if you already know or precognize the answer?


Because you move faster.


Oh, I have *strong* opinions about the slop machine. But I try to temper them so I don't get buried by the usual "pro AI" mob

I will say that my projects have a "leading the pack" anti-AI policy [1]

[1] https://wiki.cursedsilicon.net/wiki/AI_Policy


[flagged]


This condescending psychiatrist meme implying hallucinatory nature of entities described by one's opponent has got to stop.


You must be new here then.


I don't recall doing any of that. But thanks for affirming my point? :)


Did I imply you did? I simply said I never see a "pro AI" mob, only an "anti AI" mob.


Let's flip it, then

Is the "anti AI mob" in the room with us right now? If not, why did you feel the need to lament it?


This entire comment section is almost entirely people bemoaning AI output, calling AI a "slop machine", and you posted your regressive religious screed against it as if it were something to be proud of, seemingly to the approval of others. nearly every comment section with AI involved is like this, and many comment sections where AI is not involved. It deserves pushback.


You seem to be representative of this mob - I merely said that the post was bad, and welcomed some actual commentary.

There's no need for pushback, there was no technical information realy shared in the OP (no work shown or explained).

And I think the fact that the work was done by the aforementioned slop machine is telling....

But how dare I point this out, time to grab the pitchforks... bemused smile


People are indeed proud of remaining humans and resisting becoming AI corp appendages that are lost in slop at their own expense. Get over it. Your pushback is exactly as religious.


Ah,

So. I (and one other person) disagreed with you visibly. Ergo you felt personally called out :)

Sounds like a bit of main character syndrome


Busy downvoting their initial comment, apparently.


When you're one of the people who finds TUIs inaccessible, "accessibility" isn't just a downside to be considered, it's table stakes. I think they're fine for one off toys for individuals and small groups, but if you're selling a product to the public, it ought to be accessible first and foremost.


That just means you have a potential userbase for an alternative for non-TUI people. If the market is that big, why not take it for yourself?


We should get rid of ramps and handicapped parking at grocery stores too. If it’s such a large market someone can start their own accessible grocery store…


When you purchase a new laptop, you can choose a different manufacturer who may have a more durable product. When you have a framework, you're forced to buy the same component from the same company that made it poorly in the first place, if it's even in stock.


When you buy a framework, you are not forced to buy the same component from framework. You are free to buy a new laptop like you would if your laptop from Dell failed.


You're always free to purchase a new laptop, though.


While that's true, I'd still rather replace a single component rather than turn a whole laptop into e-waste.


Like many others, I gave up on self hosting email when I realized Gmail and Outlook would always mark me as spam, if I even got delivered. DMARC and DKIM did nothing, I think the datacenter IP was just blacklisted. Ostensibly there are ways to get it unblacklisted but man what a pain the ass for the whole process.


I had some email bounced by gmail, had to hardcode the ip addresses in the SPF records.

I think gmail can just gradually bounce self-hosted email and people will give up and move to their service.


Maybe I'm an outlier, but personally if a friend used ai to make me a gift like in TFA, I'd be pretty offended. Using AI shows that you didn't care enough to even think about it on your own. When I see a business use obviously AI generated imagery, I think "I'll stay away from them, they clearly don't care enough to do things the right way." It's a sign of disrespect and a lack of care. I know my partner thinks similarly, as do most of our friends. I don't think creativity is going anywhere long term, though perhaps there will be an awkward adjustment period while older people catch up to the new social norms.


I wonder how many parents are looking forward to the day their kids can just talk to a computer and have an LLM produce all the works. That'll be something to proudly hang on the fridge, yeah?


This thread inspired me and I made this prompt for you:

“A comic of a kid and his father standing in the kitchen. The father is pinning a page to the fridge with a magnet while the kid stands there, proudly watching. The page is an image depicting a comic of a kid and his father standing in the kitchen as the father pins a page to the fridge with a magnet.”

Edit: I decided that without effort, a gift can fall a little flat. So I took the time to process the prompt for you. I hope you like it! https://ibb.co/PsdDjDLy


That was good for a laugh. And of course it is so typically AI. Superficially pretty incredible, and then you start to spot the errors. And they are the kind of errors only an LLM would make, not a human.

Also a pretty great demo of why original content creators hate LLMs for stealing all their work.


Who stole the fridge art, Billy?

NOT ME!


> if a friend used ai to make me a gift like in TFA, I'd be pretty offended

As would I. Not only would that demonstrate they don't care, but it would also indicate that this "friend" simply doesn't know me at all, and therefore is an acquaintance at best.


What if I used no AI in writing it i.e. it was all heartfelt but used AI to literally edit a video together? The author says

"Two videos, with different stories, shared so many similarities that most people thought they were roughly the same.

Same similar tone of voiceover with cadence. Same cutscenes of flying over empty beaches, and navigating forest trees and stars/universe, and same narrative: after years of evolution scientists have yet to discover the power of such love with a national geographic tone in both (one of the videos even started with that logo)."

Which to me, just means the manually done cutscenes was a waste of time? In fact in most situations pre-AI you'd foist this task on "that one friend" who's good with Movie Maker or hire a hobby videographer. Now I offload to AI, why is that bad?

I think having Claude wholesale write a wedding speech is obviously silly, but the rest doesn't seem so black and white, just more Ikea-fication of consumer art.


>Which to me, just means the manually done cutscenes was a waste of time? In fact in most situations pre-AI you'd foist this task on "that one friend" who's good with Movie Maker or hire a hobby videographer. Now I offload to AI, why is that bad?

Because there's no value in something that you offload to AI without effort.

If it's something that anyone could do, without skill, why would anyone be impressed by that?


> If it's something that anyone could do, without skill, why would anyone be impressed by that?

Gifts aren't supposed to be impressive. Nor is their value measured by effort or cost.

Nor does this reply answer their question of "is hiring a professional to to it any better?" It seems you would have to argue no, though.


"The person of our group that championed it used AI for the script/narrative"


If someone says "if a friend used ai to make me a gift like in TFA, I'd be pretty offended" and not spell out what TFA means and make me ask ai, I'll be shaking my head


On the gift scale, an AI thing is worse than an envelope with cash.


Ironically, I think that serves as an absurdist refutation of the argument. On the gift scale, the question is appropriateness, a measure of sacrifice, and a measure of thoughtfulness. Personally I'd find some kind of AI-personalised gift to be slightly less worse than buying me a Gift™ from a major chain store.


I remember the day when my dad gave me $100 in an envelope. One of the worst days of my life.


Best day was when my dad said he's good at Texas Hold'em, I said 1v1 me, I won, he said it's not realistic unless we play for $200, I agreed, I won again


If you don’t learn how to play every instrument, sing, and use your private plane to fly on location to film the music video then your soul ain’t even in it bro

I need millions spent, rainforests burned down, office complexes erected, ecosystems and lives ruined, layoffs - or it didn’t happen bro. It’s just AI


It's utterly mortifying. I would have been having an out-of-body experience if I was in attendance at such a wedding. If it had been my own wedding, I'd have been livid at the insult.


I can't even imagine doing this. It's not that hard to make a special video once you've collected the source material. It won't look professional at all, but nobody cares about that at a wedding.


I suspect the real threat wasn't the blacklisting so much as the possibility of lawsuits that could come after


I think broadly I'm in agreement that the censorship via blacklisting threats was unwarranted. That said, I also think we should keep in mind that this isn't some public forum made for adults to have discussions, it's a public block game server. I think it's more than reasonable to say that the average minecraft player is probably a child and one of the most popular servers being full of swastikas and racial slurs probably isn't good for children. Personally I think there was potential for some kind of middle ground, but I'm also not mourning the loss of the obsidian nazi builds too hard. The paradox of tolerance and all that. The vast majority of the anarchy spirit is still there, it's just slightly less edgy. It's hard to discuss in good faith because the advocates for lack of censorship here are largely people who want to spam the N word in chat all day or their unwitting allies. Ultimately, whatever the outcome (and I think the current outcome is at least /ok/), I've made peace with the possibility of losing minecraft as a medium for totally free speech. It's just a block game.


> I think it's more than reasonable to say that the average minecraft player is probably a child

That is almost certainly not true, especially for the Java version, which this server runs.


> I think it's more than reasonable to say that the average minecraft player is probably a child and one of the most popular servers being full of swastikas and racial slurs probably isn't good for children.

Maybe. They’ll encounter if eventually and if they are coddled too much they can’t handle it. I also think folks forget, or perhaps they were coddled, that kids already know about a lot of this stuff and when parents aren’t around say all the bad works and make very, very crude jokes. That’s what kids do. That’s what we did.


Sure, kids will encounter a lot of things, but there’s a difference between coddling and having conversations when the time is right (well, better - there’s rarely a correct time in any exact sense with kids).

Our kid is old enough now to have a good grasp on “world war 2 was bad, nazis are bad”, and if they were to hop on this server and then we have discussions surrounding ie the “obsidian swaztikas” mentioned above, I think it would go alright.

This kid is also smart, and emotionally aware, and actually a pretty cool dude. They can swear around us, and never in anger towards someone, and tbh they’ve said “oh shit” once while playing a game with us because they got spooked and last night during a run on Marathon they went “hey phatskat, I might use a swear word”. I asked what they wanted to say and why they were hesitant (since they know the rule that it’s ok generally), and they explained that swearing makes the “queasy” lol. A couple minutes later they went “ok, I’m gonna say it. Fuck yeah!”

All that is to say, I don’t feel like they’re coddled, and they also aren’t just going to grow up like I did in the Wild West of the 90’s internet. I saw a LOT of things I shouldn’t have, way too soon, and I also grew up in an environment where hiding that from my parents was the safest option. So yeah me and my friends swore and made off color jokes around each other because the adults would get mad, despite us learning a lot of the crude stuff from them and then Something Awful et al. In hiding it, I felt like the harder topics were absolutely not able to be broached with my parents, and looking back on it that sucks.

The way my partner and I are approaching it is to be up front and have the conversations we can at the kid’s level in a way that makes sense (eg age six: war bad, age ten: World War Two was a war about…).

There’s a middle ground between coddling and bootstraps, and it’s the kind of parenting I want to encourage others to do if they can.


You making the rest of the world foam padded because you don't want to control what your kid can access is gross. The rest of the world didn't have a kid. You did.


That’s a wild take tbh. In a different comment I did say that ideally the community would’ve taken action before MS had to step in. I don’t want to make the world “foam padded”, and in particular when it comes to fascism it should be stomped out wherever it appears, point blank. It’s a bummer that Microsoft came in and threatened to blacklist the server, and at the same time if you have a nazi in your bar and you don’t kick them out, you own a nazi bar.

Yes, my kids will run in to nazism in the wild, and I can’t control that, and if they ran into in a Minecraft server we’d talk about that and maybe even make an effort to clean it up ourselves - that’s what I think that community and frankly any community that doesn’t want to be a nazi community should do.


Having a Nazi in a bar doesn't make it Nazi bar. It creates a tendency to become a Nazi bar, which can be counteracted by other forces.

If that logic held water, having a communist in a bar would make it a communist bar, which is ludicrous.


That’s a false equivalence and imo disingenuous - Nazis are understood by the broad majority to be “bad”. We, the public, don’t want nazis around - period. If I go to a bar and there’s a handful of obvious nazis there, I’m leaving because said bar has said “we’re ok with Nazis” and that’s a Nazi bar.

Most communists don’t hold abhorrent beliefs such as “Jewish people should be eradicated” or “the world belongs to the aryan race”, but a Nazi is a Nazi, there’s no grey area there.


That presumes:

1) that said bar knows everyone's political mindset, including those which haven't been made public;

2) that said bar actually treats said Nazi with decency;

Also, most communists hold the belief that there must be a violent revolution and the opposition should be executed, specially those of the tankie variety.

Edit: I have noticed you switched the count of Nazis from singular to plural ("if you have a nazi in your bar" -> "If I go to a bar and there’s a handful of obvious nazis") while proposing I'm being disingenuous. This might not have mattered to you, but the prevalence of an ideology is very important to whether a bar "is a Nazi bar" or "happens to have a Nazi".


1) I did say “obvious Nazis”

2) letting a Nazi be at your bar is decency imo

3) “most” is doing some heavy lifting, and even so, you are showing the shades of communism. Nazism expresses an ideology of hate and racial superiority, it’s a completely different beast. (And yes I know that communism has been party to some ethnic cleansing such as in Stalinist Russia, however, that belief system of ethnic superiority is not inherent to communism)


1) fair enough, I was focusing on the original post;

2) disagree, the bar might be a pretty public place, so being allowed in is just the default; or they might have been personally allowed in, but is treated as the butt of jokes;

3) is it? "most" is pretty big group. If you take issue, we can replace it with "tankie". Also, does it really matter whether the motivations are racial or not? Mass murder is still mass murder, regardless of motivations.

Still, I feel like you are missing my main point. Having a Nazi, even if an obvious one, isn't enough for a bar to be nazified. It might be the trigger for that, but it might not. I argue that this "nazification process", which mirrors the "degeneration" process in libertarian literature, isn't a binary thing that should be treated this reductively.


I disagree on the “nazification” point, your main point, because fascism is the kind of insidious thing that can’t be allowed a foothold. To your point 2, even if the Nazis were allowed in to be the butt jokes, it’s still allowing them in and tolerating them.

If an establishment is aware of Nazis in their ranks and they aren’t condemning them, then they’re supporting them by way of not removing them. It’s the paradox of tolerance at play.

I don’t want to really derail into different aspects of communism, just want to say that most communists I’ve met or been exposed to only believe in violent revolution if peaceful revolution isn’t an option. Again, this isn’t, to me, an equivalent to the violent beliefs of Nazism.


I have to disagree on fascism being this insidious bogeyman. While I agree that they ought to be fought against, IMO this is reaching into red scare territory (which is fitting, given that both share a really close ideological root).

I also disagree that merely keeping a Nazi in your establishment is support for Nazism. Simply not removing a Nazi is no more than not removing a person, it doesn't speak whether the ideology will actually take root.

The paradox of intolerance, in its original form written by Karl Popper, is about discussions. In this context, intolerants are people who forego argumentation. Kicking a person, Nazi or not, who has been acting peacefully and has been engaging in argumentation isn't "intolerance against intolerance", it's intolerance proper. You may argue that you are trying to prevent a future situation with this, but unless it is a 100% guaranteed (which I argue it isn't), it's just plain intolerance.

Finally, bear in mind that there are more equivalences in beliefs than you think. Mein Kampf didn't speak anything about Jew mass murder (and it still happened), and most (as in, the ones you see "marxist-leninist" in their profile) socialists admit that a nonviolent approach is basically impossible. In the end, both ideologies share the willingness to dehumanize and murder their opposition (and for similar reasons, Nazi-brand racial hatred derives from the same core idea).


> Finally, bear in mind that there are more equivalences in beliefs than you think. Mein Kampf didn't speak anything about Jew mass murder (and it still happened), and most (as in, the ones you see "marxist-leninist" in their profile) socialists admit that a nonviolent approach is basically impossible. In the end, both ideologies share the willingness to dehumanize and murder their opposition (and for similar reasons, Nazi-brand racial hatred derives from the same core idea).

Spot on. It's interesting to me that we've failed to stomp out communist sympathies but I guess we didn't stomp out Nazi sympathies either.

Both are authoritarian ideologies that are incompatible with free expression, free trade, and free peoples. Yet people openly talk about being communists despite the above and despite the fact that tens of millions of dead precisely because of communist ideologies and failed economic policies. To claim that fascism and specifically Naziism is an insidious boogeyman means you should also claim the same about communism. Curious how some/many folks don't or don't seem to understand that.


Tbf, communism is indeed more broad than Hitler's Nazism, from pre-marxists to Proudhon ancoms (although a similar comment may be made about the common sense definition of Fascism), hence I changed scope towards traditional Marxist-Leninists.


It's more broad but I don't think that changes anything with respect to the destructiveness and need to stamp out the ideology. Nazism is just a flavor of either authoritarianism or maybe just a flavor of a broader racial/cultural superiority ideology. Typically in the west we reject the whole tree and not just some of the branches. I apply the same argument to communism. And you can certainly find more charitable interpretations where maybe some freedoms are still present, but you can do the same thing racial or cultural superiority ideologies or similar.


its sad ppl cant run their own servers without companies interfering. Was never an issue on games like CS. sure there was a lot of toxic ones but also rly nice ones. you cant moderate human nature. hiding it does no one any good either.


I don't understand why you're being downvoted for this. Microsoft should not be moderating privately-run servers.

Sure, on the realms or whatever they're called or whatever servers Microsoft do operate, fair game and good idea. But if I'm running a Minecraft server on my homelab it should be my decision what behaviour is acceptable within that server.


It's a case of some people making it worse for everyone. If people behaved on the server, MS wouldn't have intervened, which then wouldn't have made 2b2t cave on a what feels like a core ideal. It may only have chipped a corner of that ideal, but it still stings.

That said, I think it is inevitable for any anarchist server that gets large enough to end up in this exact situation. MS wasn't going to let one of the biggest and most famous servers of its most popular game be filled with swastikas. Even less so when it's so popular with kids.

In a funnier world, 2b2t would have said 'no', but I have a feeling MS would escalate, and that whatever email or whatever the admins got probably implied as much, so maybe that world wouldn't be funnier after all.


> That said, I think it is inevitable for any anarchist server that gets large enough to end up in this exact situation.

Agree, and I think it’s the community’s responsibility to decide what is and isn’t tolerable - even within anarchy. Forget MS, the (imo) proper response should have been the community actively choosing to deface and destroy the nazi stuff, or outright ban it from the moment it became a thing.

This topic touches on a lot of the themes in [How to Radicalize a Normie](https://youtu.be/P55t6eryY3g).


I agree that it's worth reading the original source and encourage all to do so. My takeaway however was that the majority had a much stronger body of evidence than the dissenters.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: