Hacker Newsnew | past | comments | ask | show | jobs | submit | Tepix's commentslogin

Keep a close eye on abliterated and "heretic" open weight models. They will be outlawed first.

Agree. I took a look at these last few months, did a write-up: https://languageops.com/blog/ai-safety-pdoom-local-vs-fronti... and I don't know if I agree or not on outlawing completely, but I think an age restriction *at least* like for alcohol, firearms and driving would be not unwise.

Make sure they ban books with dangerous knowledge too.

The hardware requirements are already quite restrictive

Oh no, some run on iPhones

It is not feasible. They never made much of an inroad against torrents and that is a much easier target than abliterated models. As the linked website shows; the process to abliterate a model can be as simple as

pip install -U heretic-llm && heretic Qwen/Qwen3.5-4B

let alone people just putting the weights up in a torrent. All assuming that someone even tried to ban abliterated models.


The torrents you are talking about are outlawed. Whether enforcement is working or not is another issue.

Like they've outlawed drugs? Illegal weapons? Hacking?

I'm not sure what is your point. It reads as defeatism to me but I'm not sure.

Could you elaborate? Do you find it good or bad? What actions can be taken?


Hes of the mind that american fascism will hold together long enough to be competent decesion makers

Good.

If you think closed source software/binaries only is bad, wait until you see how awful the state of the art is with a clear-as-mud bucket of matrix weights.

We know it's possible to train an LLM to secretly respond to certain trigger phrases, and last I checked these could only be detected with the assistance of whoever chose those phrases.

The trigger condition for such backdoors is not something anyone can do a systematic brute-force check for, for the same reason we had to invent LLMs in order to do natural language processing: combinatorial explosion.

Passing around open weight models from known sources is already asking you to trust those sources; because of how difficult this is to do correctly even without deliberately inserting such things, we still don't know if China has already put such trigger conditions into their models despite headlines such as these: https://venturebeat.com/security/deepseek-injects-50-more-se...

Regardless of if it was deliberate or not, we don't know if we caught all of these misbehaviours. We don't know how to.

And note, I'm not saying "and therefore you should trust the Big Name Models". If open weight models score 2/100 in this context, closed ones score 1/100.


I thought you were doing a PR to add an 11th space.

Nah, for ≥11 spaces we should fan out to a GPT-6 Astra agent. On light reasoning of course, lest we be wasteful.

600b-a27b doesn’t sound enticing. Also with the higher number of active parameters compared to GLM 5.3 flash and DeepSeek V4/4.1 flash, I don’t see how they want to be more efficient at inference.

I believe with tailscale you don’t have to trust a 3rd party with your cleartext traffic

But you do seem to get to host a https version of your app in case you need features locked behind secure context.

That can't be right. If they're hosting on a different DNS they have an absolute need to MITM ssl/tls traffic. Can't work otherwise.

So cloudflare sees your plaintext. Btw: tailscale does not (but ssl errors and warnings are unavoidable)


They see all the traffic in cleartext. Plus you have to trust them not to maliciously alter your traffic. As a US company, their options may be limited if they are coerced by their government to do so.

Just use TLS / mTLS over the tunnel, no?

Suggestion: Every time someone uses nitter, the post in question is copied over to Mastodon and subsequent accesses just redirect to the copied post. That way you can interact with the copy on Mastodon.

Was just looking over the Safari 27 release notes¹, which is part of macOS 27, and noticed this:

Web Driver

New Features

- Allow your agent to connect to a Safari browser for development and debugging via the Safari MCP server. (176038457)

Related (From July 1st)

Introducing the Safari MCP server for web developers

https://webkit.org/blog/18136/introducing-the-safari-mcp-ser...

So that's interesting. On the other hand, looks like WebXR support for Safari will never come.

---

¹ https://developer.apple.com/documentation/safari-release-not...


I've been using the Safari MCP in a "grocery agent" tool I built. It takes the weekly menu my wife puts together, turns it into a shopping list, and then uses Safari to add things to the shopping cart on Walmart's website. It's pretty solid, I like it more than the Chrome dev protocol I had been using before Safari.

How are you getting around bot detection shutting you out? I tried exactly this but for stop and shop.

I've actually never had it trip any bot detection, captchas, or anything like that, and haven't built anything into it for evading detection. If I had to guess, it's because I make sure to manually sign in to my Walmart account before it begins adding things to the cart.

This is the case for me too. If I try to automate sign in, it trips bot detection. But if I manually sign in then let the agent rip, I'm fine.

Not on macOS but have my own browser extension basically doing the same with Firefox, for use with agents.

It's using a clone of my real Firefox profile, and can "ping" me if it encounters a page that needs my human input, like a login page (as I don't give it access to my password manager) or captcha page. Although sometimes it "bypasses" the captcha page by itself, even though I've instructed it not to...


i ended up having to hot swap in an abliterated model just to solve the captchas and then move on.

Unfortunately, not well suited for stealth use cases for personal automation. Here's a comparison to an mcp tool that allows driving your live safari via osascript:

[1]: https://github.com/achiya-automation/safari-mcp#vs-apples-of...



Given that Safari needs the most debugging and automation tooling for Safari was hardest to come by, this is a welcome change. I wonder if it works with pages on a connected iPhone though? Anyone tried it? Because debugging on iOS Safari is the most maddening. (No, responsive design mode doesn't cut it, iOS Safari has its own special bugs that don't manifest in desktop Safari merely emulating a phone viewport.)

This MCP server for Safari is pretty neat. I think I'm going to start automatting some tasks for our corporate websites.

It's really powerful. I have been using it in Chrome for a while.

This is how to enable: chrome://inspect/#remote-debugging


True WebXR for the Apple ecosystem will never come. At least that’s what I’m assuming given their behavior so far

> On the other hand, looks like WebXR support for Safari will never come.

Thanks for checking. What a mess. I'm so sick of the workarounds that have to make.


Time to dig up 386bsd

here you go: https://archive.org/details/386BSD1.0

probably faster downloading it than searching around in the attic ;-)


Sounds interesting. Clever name, too. And open source. I’ll check it out.

Remember that story a week ago „everything I own, owned“? That’s one way.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: