Hacker Newsnew | past | comments | ask | show | jobs | submit | newtonsmethod's commentslogin

I assume they're using a more candid definition where they're not counting all the countries a company may be based, but rather the primary country they're based in.

I don't think they're trying to flex this as a large number. They don't want to give an exact number, as that may change etc / is fuzzy, but also want to give you an idea of the scale.

They say "In the future, we intend to expand our geographical reach much further". I imagine this commentary is somewhat related to the concerns that AI will create an even worse "global underclass". AI developments are first accessible to Americans, then allies, and then later the whole world.


There's a comment on the GitHub thread which also mentions pinning rsync version would be a bad idea. Many of the people affected by reversions are those with workflows vulnerable to the prior CVEs.


I don't actually see much evidence the usage of AI here was an issue. I think you can obviously identify areas where the code isn't perfect. I'd blame this slightly on human prompting, slightly on AI.

But I'm not a sure a human on their own would've done better. There aren't enough resources to make the changes required.


Can you tell me any of the bugs? All claims I have seen so far of people being affected by bugs seem deeply implausible.

The current ones I see are: * Can't build on Linux < 5.6. But people aren't complaining strongly about this, since it requires a build from source / isn't a result of an update from a distribution (and people can wait for updates / implement them themselves). * An issue hit with chroot false + daemon. People running this in an automated manner (as some claims suggest) are already using it in a way fairly likely to be insecure, chroot false is strongly discouraged here, and the whole point of these commits was that they fixed CVEs impacting precisely these people.


> Just because you got shat on the head once it doesn't mean it's fine to be shat on the head every day now.

This happens frequently when there are fixes for CVEs, since regression tests can't catch many things which incremental rollouts can. It happened for example in 2025. People are right to imply the reaction is totally outsized here, and it's almost certainly the case that people are overreacting to AI (rather than the somewhat weak idea that it's because of the frequency of these issues).

What's really funny is that the people opposing AI here are showing far less literacy than those who wrote the code. People claiming to be affected by this bug severely are likely exposing themselves: * One bug is for Linux < 5.6, where it didn't hit distributions. This is a low severity bug where it can't build, where distribution maintainers may be reasonably expected to fix it themselves (although rsync will also fix it eventually too).

* The other bug affects precisely the people impacted by the CVE https://github.com/RsyncProject/rsync/issues/897

You probably don't want to revert in this scenario. If someone is hit by this bug and is running rsync in an automated manner, it is highly likely they're ignoring very many security practices: you're usually not supposed to run native rsync in an automated manner (the main use case is for public users, where you can't SSH etc; since it's unencrypted, you're supposed to check a checksum against a website etc); these cases are hit with chroot false, which is deeply discouraged and leads to far larger attack surfaces.


Yes, the actual issues seem to be:

* People with linux < 5.6 can't build this from GitHub. This to me seems like a fairly minor regression: people using maintained versions of 5.6 (mostly extended security) will have distro maintainers pick up that the build is failing, allowing for it to be corrected in a timely manner.

* Hardening against path-traversals causes failures for users with: no chroot; using the native rsync protocol. Ironically: chroot = no is deeply discouraged; you shouldn't really be using native rsync in an automated manner (and perhaps it seems I wouldn't advise using it at all); the CVEs the commits fix apply exactly to this use case.

https://www.cve.org/CVERecord?id=CVE-2026-29518

Requires daemon + no chroot. " daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false."

So the workflows affected are those which are the most vulnerable, and yet people are recommending that people revert versions.

* Furthermore, if a regression test picked this up, it would've been written previously.


Is your justification in dismissing Fields medalists that they are impressed by funding? Not even receiving it (I assume you say this because Tao is not funded by AI for Math, but rather an advisor for it)?

Not only would it be a leap to suggest that people automatically lose their integrity by taking funds for projects they believe are useful, especially after involvement with adjacent fields, but you are suggesting merely being impressed by a fund is enough to dismiss their views?

You also have no evidence that Renaissance Philanthropies is a front for VC companies. All news coverage indicates that they seek to be an alternative for high net worth individuals engaging in philanthropy.

Many people discovering Erdos results, engaging in Olympiads etc, are doing so with publicly available models and publish the resources used in the process.


Renaissance "Philanthropy" brainwashes children with AI, which is child abuse:

https://www.renaissancephilanthropy.org/insights/renaissance...

https://www.renaissancephilanthropy.org/insights/embedding-a...

It promotes "agentic science", which will destroy science further:

https://www.renaissancephilanthropy.org/insights/open-source...

No one publishes. Please show me papers about the math proof logic in ChatGPT that are as detailed as those from Boyer/Moore/Kaufman for prior work.

If they are on arxiv.org with 50 authors in a sea of slop, I didn't find them. If they exist, they are certainly not from Gowers, Tao or Lichtman.

You have all the upper hand because your AI shills back you up here, but nothing of substance.


This is getting insane. You have no evidence for your initial claims and didn't respond to a thing I said, and are now claiming using AI for education is "child abuse". Please get help.


There is also no evidence that Radio Free Europe is still linked to the CIA. Just look at the donors of Renaissance Misanthropy.

But we are feeding a sealion who does not know how the math proof logic in LLMs work, probably because it is a highly computationally expensive random restart hack calling Lean that is unpublishable.


Many of these results don't rely on repeatedly calling Lean. You have no clue what you're talking about.

> Just look at the donors of Renaissance Misanthropy. If you're actually interested, who funds each project is listed in the PDF here. https://www.renaissancephilanthropy.org/annual-reports

As you can see, it's mainly philanthropic projects of wealthy families.


They literally operate on the model developed by Kleiner Perkins:

https://www.renaissancephilanthropy.org/the-fund-model

But get your AI friends to downvote truth and sink the entire submission, because that is how the AI fascists operate.


Are we back to magic water and magic soil? Does the energy have some morality attached to it?

The emissions per kWh of energy used in providing internet downloads probably is similar to that per kWh of energy used for washing clothes.


You're not seriously trying to explain that a kWh is equal to a kWh. Why not cut the crap? Are you trying to say washing clothes is of equal importance to convenience features in a browser, given that we can use each clean kWh only once? I can't tell what you truly mean like this


>a kWh is equal to a kWh

Yes, and it's none of your business how other people spend their electricity.


That's where we disagree. With our current system so reliant on fossil fuels, every kWh generated is a debt to our planet, our society.

Until that's resolved, I don't wish that debt incurred for frivolous uses.


What do you mean you "disagree"? I pay for the electricity I use and I use it however I want.

Instead of trying to control other people, why can't you start with yourself? Throw away your phone/computer. Go live in a small hut. Practice what you preach.


You read what I wrote, you just chose not to engage with it and went into an ideological creed instead.

You may pay for it, but I and the rest of the planet incur the cost.

I can go live the life of a hermit and the above will still be true.

Your electricity use puts more pollution into our air. It burns our forests. It kills species we all depend on.

No man is an island. Your actions affect others. Just paying your indulgences does not make that basic fact away.


[flagged]


[flagged]


[flagged]


Still no engagement with actual arguments brought up several posts ago at this point. Still more attempts at derailment.

Speaks for itself. I shall leave it at this then.


[flagged]


[flagged]


[flagged]


[flagged]


[flagged]


[flagged]


>until we coerce the more repugnant parts of society

Go away, troll.


You will notice I let you state your views without going absolutely deranged and resorting to ad-hominems.

Why can I not state my philosophical positions without you absolutely freaking out?

If you disagree, you should be able to articulate why. But you don't. Why?

Is it narrow-mindedness? Insecurity? Fear of debate? A nagging feeling I might be right and it would absolutely destroy your identity to admit so?


>until we coerce the more repugnant parts of society

I noticed. Shoo, troll.


An honest reflection of my values. What's wrong with that? Why does not agreeing with you make me a troll?

You must encounter lots of trolls. Good thing you're not one.


You can stop soliciting.


[flagged]


He even brought out his alt.


You are not paying for the total cost of the electricity you use.

You pay for a portion of it, in money.

The other portion of it is belched up into the atmosphere for future generations to pay.

You are incurring debt and forcing it upon others.


>You are incurring debt and forcing it upon others.

You seem to have no problem whatsoever with using electricity yourself. So when do you get to tell me (or anyone else) how to live? And when does it stop? Btw, this is all bizarrely dramatic since we were talking about small local models anyway.

>future generations

Yeah, and some will also say (using the same arguments) that having children is harmful to the planet and we need "measures" to limit that too.


I’m not telling you to do one thing or another. I’m taking issue with your argument that because you pay an electric bill, it follows that you can do whatever you want.

That does not follow logically for me. As humans we disagree about many things, but we generally agree that things that we do often affect others, so one way or another, we need to come together and decide which things are agreed to be acceptable and which things are not.


And I'm not inclined to entertain this nonsense, not even as a hypothetical. I'm not giving up on my most basic and fundamental rights, doubly so when these draconian restrictions won't apply to the people who want to impose them.


Why do you get to tell me (or anyone else) how to live? Why do you get to decide that burning my forest is acceptable?


Not interested, go away.


I have to tell you something: there is consumer demand for AI.


We'll never know, since companies seem determined to make it non-optional.


This is a very good way to put it.

AI is being pushed so hard from the top down by every executive (who have been practically foaming at the mouth about AI for years now) it might as well be extruding from every port and seam on people's devices as if it were a buzzword/fomo diarrhea of some sort.


I for one would love to see someone try and shove hamburgers down everybody's throats in order to increase consumer demand.


Unless they mean another "f word", the f word was used in Apollo 10. It's just that the transcripts change it to "freaking": > Oh, shit' What they did, they made it a two - Ain't this smart' Ain't that a smart freaking sack.

( https://apollojournals.org/afj/ap10fj/as10-day2-pt9.html )

It can be found in this video: https://www.youtube.com/watch?v=DQVEsfa15SY


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: