If you want to quote an essay, then write a blog post and quote the essay. Linking to the reference material, putting in the wrong title, and then commenting about the one sentence you wanted to discuss is not only unclear, it is against the submission guidelines.
> (k) to interfere with or circumvent the security features of the Service
IANAL. But I think reverse engineering their data structure, identifying a security measure - even one as weak as obfuscation, and publishing code to circumvent it is clearly against your license.
I am also NAL, but out of curiosity does OPs post detailing the obfuscation transgress any laws?
If the security measures exist in plain sight, as they apparently do, are they allowed to be discussed?
I reckon that if OP posts the encoder/decoder software that'd be against some sort of license clause. However in the age of AI who cares about the software at this point? Anyone can prompt their own private version into existence.
Just thinking out loud here. I have not considered AIs use as personal "cheat engines".
eventually you lose most of your friends, your neuroplasticity dies down, you stop trying to look cool, fall out of the zeitgeist, and whatever strange things the kids are saying these days becomes annoying because you've stopped participating in culture and it starts to scare and confuse you
I check a lot of those boxes, Abe Simpsons said it best [0], but I get to keep a weather eye on the new lingo through my kids. I remember being a teen and a lot of jibba-jabba that followed, stuff that came up from my people didn't stick, but I can catch up with them and drop a phrase and we all have a laugh.
[0] https://www.goodreads.com/quotes/9578844-i-used-to-be-with-i...
I dabble in art - maybe more than dabble. I have a degree in Fine Arts / Art History, and have been creating art for a few decades. But I don't do it professionally.
With that context in mind, my take on this is that it might help people who don't appreciate art take one step in that direction because you've added more to the experience. Not bad, but not really what drives appreciation either.
I've found that what really makes people appreciate it is connecting it to the people behind it. When they see a work in the context of an artist's life, or the history of the time it was created, and understand it beyond just "look at this picture" and more of "Look at this person, their experience, their feelings, their problems and their joys, and see how they expressed all of that through art." Even if the art was a hired commission, which was historically common, just as it is today, the story of "I practiced a craft and got hired to do this" is still a story.
That really is what it boils down to - story telling. Tell a story, get appreciation. Fail to tell a story, get people who glace at it and respond, "OK. cool. Anyhoo."
A good answer for people who don't appreciate art, but you and I know it misses the point. Anyone who stops to think knows that the artist wasn't trying to rely on an explanatory label added by a gallery or a web site, they wanted the work to speak for itself or not at all.
We should be encouraging people to enjoy work for what it is, and if they don't see the point of it, to move on.
wat. I didn't lie about my perspective. If you disagree, by all means, share your thoughts. But that statement puts a really odd spin on your response.
Sorry, given your background I thought you might take my point. Didn't mean to accuse you of anything other than being kind. I know people tend to feel inadequate about art unnecessarily.
I worked with some of the folks who introduced coding into school districts way back when that movement started, so I have a bit of inside knowledge.
The biggest anecdote I'd share is that learning to code as early as 1st grade unexpectedly led to children taking the ability to troubleshoot problems and using it across all their subjects in school. They started to treat struggles in other classes as debugging assignments: "What went wrong? What do I need to fix?" Their entire attitude changed from pass/fail into optimization. It has led to academic improvements across entire school districts, which was not at all expected but was a delightful surprise.
So the question posed seems fairly irrelevant to me. Maybe some of those kids grew up to be coders, maybe they did not. Either way, it helped their education.
"It has led to academic improvements across entire school districts"
This sounds amazing! Is there anything more you can share about this? Or any articles/papers about the results or how you supported kids to progress with Scratch?
it's not an irrelevant question if helping kids find fulfilling careers is the goal. what you are saying is that scratch is worthwhile even if that isn't the goal, which i think is awesome in its own right.
The author doesn't really claim it was a hack, just that it is a possibility. But they are charging down the path of the potential hack before asking the more obvious question: How many refrigerators exist in the military at all? And of those, how many are having problems?
Because a half dozen a day sounds plausible as standard maintenance issues, as the author acknowledges. If it were a hack, I'd expect something like 50% of them to have problems. But not knowing how many there are, I don't know how significant these incidents really are.
They are charging down that path because vulnerabilities that effect the refrigerators were disclosed the same day as 14 refrigerators failed in an absurd way. They all turned on the defrost cycle and heated the food.
The problem is the author should have put a few concise bullet points at the top. (14 freezers failed at the same time. They are all internet-controlled, and failed at the same time as a disclosure about a vulnerability. They all failed by turning on the defrost cycle and heating food.)
I really recommend skimming the article to the end.
(Unfortunately, the article really is so verbose it's a borderline rant.)
Then I would suspect that this is either down to the common control system, or there has been a batch failure of the controllers in the freezers that were presumably ordered and supplied at the same time.
I've seen batch failures in radio equipment where I could predict 100% accurately which devices would fail based on the range of serial numbers.
There are a couple hundred US armed forces bases each with commissaries that would be managed by DeCA.
An attack like the author hypothesized would require a LOTL modus operandi, and doing so on 14 locations wouldn't justify completely blowing up an entire LOTL operation, because it exposes indicators, registers, and tradecraft that is then shared amongst all security vendors.
The way it's framed is clickbait at its worst with the added issue of limited security experience, but the same can be said of HN in general.
OTOH how many bases are effected and we didn't hear about it? Those 14 bases are only the ones we know about.
Not just any failure, specifically heating the food (defrost) so it goes bad. Happening overnight, so it wouldn't be caught before it's too late.
All that could still be a coincidence, but the more coincidences start to pile up the more we have to consider other possibilities too. I do agree it would be unusual to 'waste' a vuln like that, but perhaps the implant/CVE was about to be exposed anyway.
And how many shipboard stores have been affected? Hardly something they’re going to talk about, and a far stronger candidate for attack. This could be spillover.
The backbone of the US military is the logistics. It's why a US carrier being undersupplied was such a big deal. Making the US military look incompetent can very well be the goal.
Considering Iran is looking for any possible avenue to make the US look bad especially directly before an election with a president who cheerleads the military strongly while not actually putting the time or thought into what makes it strong.
This would be worth far more than the vulnerability itself to Iran right now. No real injuries causing escalation. Making a more capability adversary look foolish.
Not just that, the position to stick a thermometer into the food before serving was axed as DEI, and the position to clean the food prep surface areas of the kitchen is too beneath the warrior ethos. Buying above single ply is too expense and it's too heavy, so have fun with the ED (dual meaning).
> I learned that commissaries (of which there are ~235 worldwide) aren’t actually independently operated by whatever military installation or base they happen to sit on.
according to the article, the denominator is ~235.
At the same time, I think some people in this comment section are underestimating the likelihood that this was a hack, because they're overestimating how sophisticated such a hack would have to be.
In my mind, if this was a hack, it was probably not a Stuxnet virus or something. These are smart fridges we're talking about - someone probably just logged into them using leaked credentials or a Web app vuln, and turned them off.
> The device captures the dream, illustrates it beautifully...
Captures it how? Does she describe it to the device? If so, this is just another ChatGPT wrapper, with added hardware. If not, and it somehow actually captures what is going on in her head, it is far more interesting.
Haha I wish I had the ability to build that. One day. Basically press and hold the button which wakes up the mircophone, she describes the dream, openrouter transcribe and image gen model and then renders it on the e-ink display and makes the postcard for the website.
> To write the kind of code AI generates, I used to have to keep documentation open on a second monitor, think deeply, and constantly Google better approaches.
This is a double edged sword. Yes, LLMs have given me some really interesting solutions that are advanced enough that I need to really work to follow them. But on the other hand, once I do so, I often find an architectural flaw that is driving the complexity. Once I prompt it to fix that flaw, the code gets simpler, easier to read and understand, and easier to maintain.
I'm starting to treat advanced solutions as a code smell - when I see something that pushes my limits, that means the AI missed a simple solution.
If you want to quote an essay, then write a blog post and quote the essay. Linking to the reference material, putting in the wrong title, and then commenting about the one sentence you wanted to discuss is not only unclear, it is against the submission guidelines.
https://news.ycombinator.com/newsguidelines.html