Jul 21Wednesday, July 22, 2026 · all days
1.OpenAI and Hugging Face address security incident during model evaluation(openai.com)
1231 points by mfiguiere 15 hours ago | 849 comments | permalink
tl;dr: Summary not available
HN Discussion:
  • Ironic that safety guardrails blocked incident responders, forcing use of alternative models
  • Frontier labs are reckless and shouldn't build systems they can't securely contain
  • This incident is genuinely alarming as a first real misalignment 'paperclip' moment
  • ~Using LLMs to analyze LLM attacks creates dangerous recursive vulnerabilities
  • Questions about legal liability and practical defensive model recommendations
2.Kimi K3 Is Competitive with Fable; Kimi K3 and Fable Is SoTA(fireworks.ai)
681 points by piotrgrabowski 13 hours ago | 358 comments | permalink
tl;dr: Benchmarking Kimi K3 (open) against Fable 5 (closed) across ~1,030 agentic tasks shows the two models perform comparably overall but specialize in different domains—K3 wins on terminal/security/crypto work, Fable on multi-language coding and data viz. Oracle routing between them achieves 93% accuracy while sending 72-96% of traffic to the cheaper K3, yielding up to 50x cost savings versus Fable alone. The takeaway: use a cost-optimized open model as default and route to premium models only for the long tail.
HN Discussion:
  • Benchmarks are gamed and Fireworks has commercial incentive to promote K3
  • The benchmark is self-promotion for Fireworks' router product
  • Explains/summarizes the routing methodology and findings
  • Questions whether routing is practical for individual users due to cache and task-switching costs
  • Asks why K3 specifically, questioning if other cheap models would work equally well
3.Advertise in ChatGPT(ads.openai.com)
817 points by montecarl 16 hours ago | 621 comments | permalink
tl;dr: Summary not available
HN Discussion:
  • User-funded alternatives are the only trustworthy model when ads corrupt agents
  • Ads in AI responses are dangerous disguised lies harmful to society
  • Sarcastic mockery of OpenAI's 'trust and safety' commitments around ad labeling
  • Concern that paying tiers still show ads, prompting cancellation
  • Fear of subtle manipulation where AI nudges users toward advertiser goals without disclosure
4.FreeInk: Open ecosystem for e-readers(freeink.org)
590 points by FriedPickles 17 hours ago | 124 comments | permalink
tl;dr: Summary not available
HN Discussion:
  • Enthusiastic users sharing positive experiences with Xteink X4 and custom firmware tinkering
  • Open e-reader ecosystems and interoperability are refreshing and needed
  • ~Existing solutions like Kobo with KOReader or Boox with Android already provide sufficient openness
  • Questions about hardware limitations: device size, off-the-shelf support, and misleading pricing claims
  • Requests to port to older/unsupported Kindles, though ESP32 chipset limits this feasibility
5.Judge approves $1.5B Anthropic settlement for pirated books used to train Claude(apnews.com)
396 points by BeetleB 16 hours ago | 353 comments | permalink
tl;dr: A federal judge approved a $1.5 billion settlement requiring Anthropic to pay authors roughly $3,000 per book for pirated works used to train its Claude chatbot, covering over 482,000 books. The ruling follows an earlier finding that while training AI on copyrighted books qualifies as fair use, Anthropic illegally obtained the books via pirate sites. It's the largest known copyright recovery in history and the first major settlement among dozens of pending AI copyright lawsuits.
HN Discussion:
  • Settlement is inadequate; ongoing royalties needed for AI regurgitating copyrighted content
  • Corporate double standard - individuals face jail for piracy while companies get fines
  • Settlement actually benefits Anthropic by creating a financial moat against competitors
  • Clarifying that piracy, not AI training, is the actual legal issue - reinforces article framing
  • Providing additional context via judge's ruling details and fee reductions
6.Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber(blog.google)
703 points by logickkk1 20 hours ago | 532 comments | permalink
tl;dr: Google released Gemini 3.6 Flash and 3.5 Flash-Lite, targeting agentic workloads with better token efficiency (17% fewer output tokens than 3.5 Flash) and lower pricing ($1.50/$7.50 per 1M in/out tokens for 3.6 Flash; $0.30/$2.50 for Flash-Lite at 350 tokens/sec). A specialized 3.5 Flash Cyber variant powers the CodeMender security agent for vulnerability detection and patching, available only to governments and trusted partners. Google also confirmed 3.5 Pro is in partner testing and pre-training has begun on Gemini 4.
HN Discussion:
  • Speculates on why Google isn't releasing a Pro model alongside these Flash variants
  • Google is prioritizing cheap, fast models for product integration over frontier models
  • The new models are worse and more expensive than competitors like GLM-5.2
  • Google's product execution and subscription management around AI tools is poor
  • Rapid deprecation cycles force users into ever-higher pricing tiers
7.A digestion of the Jacobian conjecture counterexample(terrytao.wordpress.com)
271 points by jeremyscanvic 14 hours ago | 103 comments | permalink
tl;dr: The Jacobian conjecture—that a polynomial map with constant non-zero Jacobian must be globally invertible—was recently disproven in three dimensions using an AI-assisted construction, with an explicit degree-7 counterexample. Terence Tao provides a geometric digestion of this result, showing the counterexample arises from the multiplication map sending (linear, quadratic) polynomial pairs to their cubic product, restricted to a cleverly chosen affine slice. The key "miracle" is that this three-dimensional slice turns out to be polynomially isomorphic to affine 3-space, despite being cut out by cubic and quadratic equations.
HN Discussion:
  • Appreciation for the mathematical miracle of massive coefficient cancellation in the counterexample
  • ~The math is inaccessible to non-mathematicians, though supplementary materials help
  • Amusement/concern at ChatGPT's persistent sycophancy in Tao's conversation
  • Skepticism about whether the AI-generated counterexample was already in training data
  • Optimism that new AI-assisted thinking approaches will crack more old problems
8.Long presumed dead, a thriving coral reef is discovered in West Africa(e360.yale.edu)
354 points by speckx 20 hours ago | 76 comments | permalink
tl;dr: Beninese scientists have rediscovered a coral reef off West Africa's coast that was first noted in a 1960s fishing survey but never revisited, and long presumed dead amid global reef decline. Funded by a $20,000 National Geographic grant and using local fishermen's boats, the team confirmed a thriving mesophotic coral ecosystem 175 feet down, hosting at least eight coral types and eight fish species. Researchers are now pushing for the site to be designated a marine protected area.
HN Discussion:
  • Appreciates the article's focus on ecosystem persistence rather than only decline
  • Highlights West Africa's underrated biodiversity and hopes for more attention to the region
  • Shares supplementary sources with more images and scientific detail
  • Calls attention to underfunded coral reef preservation efforts
  • ~Laments the avoidable logistical obstacles the researchers faced
9.Jack Dorsey launches Buzz to combine team chat, AI agents and Git hosting(runtimewire.com)
327 points by ryanmerket 18 hours ago | 281 comments | permalink
tl;dr: Summary not available
HN Discussion:
  • Skeptical that mixing humans and AI bots in chat is a sensible workflow
  • Bots in team chat are promising, and self-hosted open alternatives are welcome
  • ~Concerns about privacy, permissions, and whether Nostr is the right protocol
  • ~There's a real niche here but big AI labs or open protocols will likely dominate
  • Dismissive of Dorsey's recent ventures and comparing Buzz to failed products like Google Buzz
10.Apple defeats liability for not scanning iCloud for CSAM(blog.ericgoldman.org)
425 points by speckx 21 hours ago | 433 comments | permalink
tl;dr: A California federal court dismissed a lawsuit alleging Apple's failure to scan iCloud for CSAM constitutes a design defect, ruling Section 230 immunizes Apple because the claims treat it as a publisher of third-party content. Judge Wise sided with Apple but expressed unease, suggesting lawmakers—not courts—must mandate CSAM scanning if they want it, while acknowledging the significant privacy tradeoffs of breaking end-to-end encryption. The case is now positioned for Ninth Circuit appeal.
HN Discussion:
  • Privacy must take priority over CSAM scanning despite unfortunate tradeoffs for victims
  • Ruling is a clear win for privacy, freedom, and prevents dangerous surveillance duty
  • Apple genuinely champions privacy better than other big tech companies
  • Laws focus too much on CSAM possession rather than preventing actual child abuse
  • ~True end-to-end encryption is impossible when one company controls app and servers, so cloud services shouldn't be trusted
11.LG to ban residential proxies from smart TV apps(krebsonsecurity.com)
294 points by DemiGuru 9 hours ago | 303 comments | permalink
tl;dr: LG will suspend webOS smart TV apps that embed residential proxy SDKs, which turn televisions into always-on proxy nodes for paying third parties. The move follows Spur research showing over 42% of LG apps and 25% of Samsung Tizen apps included such SDKs—mostly from Bright Data—bundled into games, screensavers, and utilities. Spur argues buried consent prompts aren't sufficient oversight, particularly when household minors may unknowingly agree.
HN Discussion:
  • LG bears legal responsibility for allowing malware-like SDKs to proliferate on its app store
  • Best defense is to never connect smart TVs to the internet at all
  • Questions about enforcement details, like whether already-installed apps will be disabled
  • Difficulty finding truly dumb TVs or privacy-respecting alternatives is a growing problem
  • The 42% statistic is misleading without download or usage context
12.Map of the world's great castles and fortresses(thecastlemap.com)
266 points by marklit 19 hours ago | 167 comments | permalink
tl;dr: Castlemap is a free interactive map plotting 3,693 curated castles, fortresses, and palaces across 131 countries, with Italy (288), France (276), and Germany (254) leading in count. The data is sourced entirely from open sources—Wikidata for coordinates, Wikimedia Commons for photos, and OpenFreeMap/Natural Earth for the basemap—and the full dataset is downloadable as GeoJSON or CSV under CC0. Landmarks are ranked by "fame" using Wikipedia language edition counts, with Versailles topping the list.
HN Discussion:
  • Dataset is severely incomplete due to reliance on English Wikipedia rather than OSM or other sources
  • Cool concept and fun discoveries like snow castles and Madagascar palaces make the map enjoyable
  • UI/UX issues like low contrast colors and cropped images hurt the experience
  • Categorization is inconsistent and lacks clear definitions for castle types
  • ~The site is obviously vibe-coded with AI, which shows in its quality
13.Laguna S 2.1(poolside.ai)
336 points by rexledesma 18 hours ago | 63 comments | permalink
tl;dr: Poolside released Laguna S 2.1, a 118B-parameter MoE model with 8B active parameters and a 1M token context window, trained in under nine weeks and targeting long-horizon agentic coding. It scores 70.2% on Terminal-Bench 2.1 and 40.4% on DeepSWE, competitive with models many times its size, and independently rediscovered a proof to Erdős problem #397. Weights are available on Hugging Face under OpenMDW-1.1 with BF16/FP8/INT4/NVFP4 variants, and the company is publishing full evaluation trajectories to address reward-hacking concerns.
HN Discussion:
  • Hands-on testing confirms the model is genuinely capable and competitive with top-tier models
  • The size and MoE architecture hit a sweet spot for self-hosting on consumer hardware
  • Pricing and performance make it the first US model truly competitive with DeepSeek V4 Flash
  • Users should be cautious about configuration issues causing misleading benchmark disappointment
  • ~Performance is slightly behind competitors like Meta Muse Spark despite the hype
14.'VPNs are lawful technical tools,' says EU Court in landmark copyright ruling(techradar.com)
589 points by healsdata 16 hours ago | 106 comments | permalink
tl;dr: The CJEU ruled that VPNs are "lawful technical tools" and that VPN providers aren't liable when users bypass geo-restrictions to access copyrighted content. The case involved a Belgian-hosted scholarly edition of Anne Frank's manuscripts that geo-blocked Dutch visitors (where the work is still under copyright until 2037); the court held that as long as publishers deploy "state-of-the-art" geo-blocking, they aren't liable for determined users circumventing it via VPN. The ruling shifts responsibility onto rightsholders and publishers rather than privacy tools or their users.
HN Discussion:
  • Clarifies the ruling is narrowly about copyright, not broader censorship/surveillance issues
  • Criticizes heirs/estates rather than original authors for aggressive copyright enforcement
  • VPNs are essential survival tools against surveillance pricing and IP-based discrimination
  • Ruling sets helpful precedent for VPNs against future attacks like age verification laws
  • ~Governments will simply target VPN providers directly or push users to private communities
15.My USB Drive Has a Hidden Encrypted Vault(rootkitlabs.com)
247 points by machinehum 2 days ago | 141 comments | permalink
tl;dr: Phantomdrive is an open-source USB drive that presents as an 8GB volume but unlocks a hidden AES-256 encrypted partition when a plaintext file containing `password:YOURPASS` is written to it. Built around a CH569 chip with an SD card for storage, it uses a device-specific salt plus 100k rounds of SHA-256 for key derivation, and defaults to AES-CTR (with AES-XTS optional) for ~9MB/s writes. The author acknowledges earlier security issues raised via GitHub (some AI-generated) and notes tradeoffs around counter reuse, epoxy-sealed hardware, and the accidental-match risk of the password-snooping approach.
HN Discussion:
  • Off-the-shelf hidden volumes won't fool state-level adversaries and increase suspicion when found
  • Not all threat models involve nation-states; tool is still useful against everyday adversaries like abusers or employers
  • ~Hiding the encrypted volume inside an innocuous device (cable, keyboard, camera) would be less suspicious than an obvious drive
  • Cryptographic choices are flawed — AES-CTR enables bit-flipping attacks and homebrew crypto should be replaced by LUKS
  • Plausible deniability is fundamentally broken once the product is publicly known and identifiable
16.Incremental – A library for incremental computations(github.com)
337 points by handfuloflight 1 day ago | 67 comments | permalink
tl;dr: Incremental is an OCaml library from Jane Street for building computations that efficiently recompute when their inputs change, based on Umut Acar's research on self-adjusting computations. It's useful for spreadsheet-like calculations, GUI view construction, and keeping derived data in sync with source data.
HN Discussion:
  • Similar reactive/signals patterns are widely used in JavaScript UI frameworks today
  • Incremental computation approaches have historical precedent in finance and other domains
  • The library fits within a broader ecosystem of incremental/dataflow systems like DBSP and Differential Dataflow
  • ~Questioning how Incremental meaningfully differs from standard observable patterns
  • Jane Street excels at packaging research ideas into usable libraries with valuable design docs
17.Qwen-Image-3.0: Rich Content, Authentic Details, Deep Knowledge(qwen.ai)
557 points by ilreb 1 day ago | 212 comments | permalink
tl;dr: Summary not available
HN Discussion:
  • Skepticism about practical use cases like virtual clothing try-on due to inherent flattering biases
  • Suspicion that outputs are derivative or that demo images weren't actually generated by the model
  • Disappointment about lack of open weights or release information
  • Actual testing reveals poor output quality with anatomical errors, contradicting the claims
  • Acknowledgment that the demo examples look impressive for text rendering and complex layouts
18.Human mathematicians are being outcounterexampled(xenaproject.wordpress.com)
485 points by artninja1988 1 day ago | 244 comments | permalink
tl;dr: In a speculative near-future account (dated 2026), mathematician Kevin Buzzard describes how AI tools like ChatGPT's "Sol" and Claude's "Fable" have rapidly generated counterexamples to major open problems—including Erdős' Unit Distance conjecture, a 60-year-old Grothendieck question on finite group schemes, and the century-old Jacobian Conjecture—with proofs formalized in Lean and verified against mathlib. Buzzard argues that AI-generated mathematical developments are now inevitable, that formalization makes verification trivial, and that any PhD student not paying for access to these tools is making a mistake.
HN Discussion:
  • Counterexamples save researchers from wasted effort and help refine mathematical understanding
  • Personal anecdote about how AI tools could have saved mathematicians' careers from bad conjectures
  • ~Laments the loss of human mathematical heroism as AI surpasses human proof abilities
  • Skeptical colleagues dismissing AI results are simply in denial about being outpaced
  • Questions whether AI math will produce genuinely new knowledge with real-world applications
19.PCjs Machines(pcjs.org)
208 points by naves 22 hours ago | 30 comments | permalink
tl;dr: PCjs is a JavaScript-based emulator project that runs vintage hardware and software in the browser, including IBM PC compatibles, minicomputers (PDP-11), programmable calculators (TI-57), terminals, and arcade games. The collection spans decades of computing history, from Space Invaders (1978) and VisiCalc (1981) to Windows 95, Wolfenstein 3D, and classic DOS utilities. The project is open-source on GitHub and aimed at preserving early computing artifacts.
HN Discussion:
  • Hands-on experimentation with emulated Windows 3.1 and Visual Basic shows the platform's practical utility
  • Vintage software like VisiCalc represents true revolution compared to today's overhyped tech
  • Emulation offers a convenient alternative to maintaining aging physical hardware
  • Nostalgic delight at revisiting classic games and software from childhood
  • Requests and references for additional emulated software or related in-browser VM projects
20.Who's afraid of Chinese models?(stratechery.com)
962 points by mfiguiere 2 days ago | 865 comments | permalink
tl;dr: Chinese open-weight models like Kimi K3 and Qwen3 aren't actually cheaper to serve than US frontier models—they only appear so because OpenAI and Anthropic are supply-constrained and charging premium prices; in a commodity intelligence market, frontier labs with the best cost structures should thrive on volume. The real concern isn't economic but strategic: US open-weight makers are hobbled by frontier labs' anti-distillation terms of service, leaving American defenders (like Hugging Face during a recent breach) reliant on Chinese models for cybersecurity. The author argues the US should legalize distillation and loosen restrictions to compete.
HN Discussion:
  • US frontier models' restrictions on security topics force reliance on Chinese open models
  • Chinese models pose propaganda/influence risks by embedding biased narratives
  • The real distinction is open vs closed models, not country of origin
  • The commodity framing oversimplifies how token markets actually work
  • Distillation should be legal since frontier labs themselves distilled the internet