Hacker Newsnew | past | comments | ask | show | jobs | submit | throwa356262's commentslogin

Any idea how much this has cost them?

Some non-profits have their HQ in the valley and pay SF salaries when they could just as well have paid a fraction of that to a very competent developer elsewhere.


The hyperlink to the maintainer's name says they are out of rural Ontario. According to the total in https://opencollective.com/servo/expenses?limit=20&searchTer... it comes out to $52,883.97 (USD) in these payments over the last 12 months.

European safety nets, and government grants have helped open source projects a lot, and this is a big reason almost all of these projects end up being developed/maintained by folks from EU. Even if the sponsorships could hire 2-3x as much man power elsewhere in the world.

Another big thing is govt aligned sponsorships are not for software but for generating jobs/work within their borders.


Yes, but SF salaries are still twice German salaries and probaby 4x Eastern Europe salaries.

I think if someone is maintaining open source software, they're already not worrying about making that much money.

yeah but the us folks aren't working out of SF and generally these projects have mostly flat pay structures (unsure if that exactly fits but a few comments make it seem like it checks out)

This is public https://github.com/servo/project/issues/181 and https://github.com/servo/project/issues/187. TL;DR: up to $4800/month (at a rate of $150/h depending on hours actually worked)

    "27 to 30 December 2026"

I have always wanted to attend CCC in person, but these dates for the main conference only work if you are 20 and single...

21th/24th -> celebrating with family the winter solstice 25th -> visiting the extended family 26th -> visiting friends

27-30th -> congress \o/

31th -> celebrating a new year either close to the congress or with family again

Works very well for very long time. Plenty of families with kids on the congress too and you always have holidays at that time.

Im not single and i'm not 20...


That's already hectic and stressfull without the congress part, especially if any of the preparatinon for those meetups falls to you.

I know people who are vacationing who have more stressful schedules.

Oh yeah? And I know people who do extreme sports with an extreme schedule whilst simultaneously breastfeeding. None of this invalidates the people who find any of the above to be too stressful.

I’ve been to congress, will probably attend more too. Some people find the schedule to suck, some don’t. I do not believe it will ever change. I think it is reasonable to find the schedule hectic. My pet theory that this one soft way of keeping the congress more about the chaos communications club rather than it becoming a tech/hacker conference with a strictly international audience. And that is fine.


A lot of people spend more than 1 or 2 days visiting family during Christmas time, and travel long distances to do so.

Perhaps and thats wonderful for these people but stating that only 20 and single can go to the congress is as generic as my response.

The congress was always booked out, its not that the congress has any attendance issues and its not that OP never had the chance to visit and never will have the chance to visit when his/her kids get older.

Btw. i travel too to my family


Yeah, works if you're 2h away from the venue.

Im away 6h from the venue and 3h from my family.

Come on...


Marry a hacker, and have hacker kids, problem solved :3

I actually know several people who regularly visit the 3C with their families and children. There are a lot of cool activities for kids from a certain age (10-ish). Even without all the social programm, there are plenty of talks which are interesting to non-IT people.

I agree that the timing is suboptimal in a family context, or at least it was when the kids were younger. Now that they are tech-savvy teenagers, I took them with me last year, and they enjoyed exploring the congress both with me and on their own. My wife is fine with it and enjoys some me-time after Christmas.

Go to the camp, that's in the summer time every .. 4? years.

I take the whole family. There is something for everyone there and Christmas in Germany is next level. Even kids. Every parent should want kids to see that kind of creative energy to model as they mature. My wife will not go to Defcon but she loves CCC.

Lots of families there every year and older folks too, it’s actually a great date for a lot of IT folks as there aren’t many weeks when companies are effectively shut down, maybe even only this one week.

45, married and traveling from America to go to my first CCC

I'm 43 and married and hoping to go, from the US

Many people who go enjoy the opportunity to get away from family

...or 40 and divorced

Its the perfect date for people who see all of their "real" family once per year, at CCC. Lots of couples attending obv.

Yeah, would be feasible if tickets wouldn't be so hard to get for externals. Ain't no way my partner would hang out for a year every week with me in a hackerspace

Yeah, CCC is only accessible for people who are already part of CCC for decades.

There are some token newcomers, but overall it is a very closed community.


I have absolutely no connection to CCC whatsoever and yet whenever I wanted to go to a CCC event (3 Camps and 2 Congresses so far, the first time in 2015), I could and when I wanted to take my partner with me, I could do that too. You just have to be fast to get the tickets before they're sold out, that's pretty much all there is to it.

Depends on when it was. Congress was less popular in the past so you could get a ticket.

Nowadays, most tickets go to hackerspaces and volunteers but the open sale sells out in seconds.

Camps are much easier to get to.

I did get my tickets volunteering for like a decade but last year I gave up - volunteering the whole event so I get a chance to go to the next event ... where I would volunteer the while event. That's not a good time.

Especially when there's more and more volunteers competing for work so they get a voucher - while the oldschoolers have no need for any of that because they can always get a ticket through backchannels.

Funny how CCC managed to recreate the worst aspects of capitalism as part of their leftist conference.


> Depends on when it was. (...) Nowadays, most tickets go to hackerspaces and volunteers but the open sale sells out in seconds.

2016 and 2019. That's how it was back then as well and that's what I meant by "you have to be fast" - fortunately the ordering system is reasonable and you don't have to type your data in within seconds, all you need is to be there in time. Back then there were three open sale rounds (but I see there were just two last year), I got my tickets in the second round for 33C3 and in the first one for 36C3.


    "We implemented a series of aggressive memory optimizations, including..."

This whole thing sounds like industrial scale auto-research, but done by people who actually know what they are doing.

Proposal:

Set up a mastodon account that mirrors your (or someone elses) X account.

This way people who want can continue using X, and other people can read & refer to their posts without needing to log into X.


I've been wondering why ~everyone hasn't already been doing this, so my guess is that Twitter's API doesn't allow it.

Yes, it's because of the XTwitter API changes (mostly between February 2023 and February 2024).

People have been crossposting to Mastodon and the fediverse for many years.

In the old days you would do it with a desktop or mobile client for Twitter and Identi.ca. In the 2020s there were many server-side crossposters like moa.party. https://wiert.me/2025/05/19/moa-link-your-mastodon-account-t...

Nowadays such clients are effectively impossible, because the XTwitter API pricing is designed for business users only. Some bigger services can afford to pay for the privilege to post via the API (e.g. Buffer I think?), which can work for corporate communications. The prices are such that often it's cheaper to pay a person to do the crossposting manually and do it properly while at it.


Because mastadon is not relevant to anybody but the people on HN. It's 2026, I really can't believe HN is still stuck on mastadon.

The issue is that Android is open while Apple seldom talks about their security issues.

This might make Apple look like the more secure option but the reality may be different because Android is more scrutinised.

If you are sceptical consider these examples: (1) some versions of Apple silicon have unpatchable security defects, (2) Apple at one point decided to not contact up to 500M users affected by a supply chain attack in China due to "language difficulties".


> Apple seldom talks about their security issues

I didn't find about OEMpocalypse from Google talking about their security issues, I found from calif.io. Security researchers don't wait for companies to "talk about their security".

> but the reality may be different because Android is more scrutinised.

This is famously why Linux appears to be less secure than Windows, right? Because Microsoft doesn't talk about their security while Linux is more scrutinized?


Some apps such as Aegis allow exporting the MFA secrets.

I think they allow importing from Authy but only on rooted phones. I missed the train to move away from Authy in 2024 and now the only non-root option is to regenerate the seed from every provider one by one. As other commenters said, rooting my main phone would lock me out of banking apps. I suppose I could find an old phone, sync from authy cloud, root it, and then migrate, but then generating new seeds is probably both safer and faster at that point.

Importing is usually not an issue, as you can always enter the secret manually. It is the exporting that is the problem.

The secret looks something like this:

JBSW Y3DPF QQHO ....

(usually fairly short unless its google)


It's not quick, but you can submit a GDPR/Subject Access Request to Twilio and after a month or two they will send you all your Authy TOTP seeds.

Then you can import them into Aegis or some other FLOSS solution: https://github.com/uiltondutra/authy-migrate


That is alarming. They have access to the plaintext? And they will hand auth secrets out? That seems extremely wrong to me.

>...data arrives as a CSV in which every token is encrypted with your backup password...

Fair enough. That seems reasonable.

They always had access to the plaintext, they could do better to hand them out

So there is a real solution to that problem! Thanks a lot for sharing it

You can extract keys out of Authy using mitm-proxy. I have done it and switched to Bitwarden.

Good point, sadly ios only, I'm on android: https://ente.com/help/auth/migration/authy/ Or do you mean it also works on android but not documented?

Reminder that despite their claims, geekbench results cannot be compared across platforms.

They don't only cover CPU and GPU but some OS components that can look very different on different platforms.


  geekbench results cannot be compared across platforms.
Why not?

Because it ruffles x86 feathers, despite geekbench corresponding very closely to SPEC as well and there being no indication that the results aren’t comparable.

What people willfully conflate this with often is that you shouldn’t compare FLOP numbers between GPU arches and instead rely on benchmarks.


No, because the software layers between GeekBench and the hardware are not identical on all targets.

Geekbench when run on Asahi Linux is practically the same as when run on macOS, just like Linux and Windows in the same x86 chip don’t give significant differences.

Opencode system prompt contains a lot of stuff but even worse is oh-my-pi where their long prompt looks like random garbage hallucinated by a 2023 LLM:

https://m.youtube.com/watch?v=c_fQoDkULl0 (see around 8:00)


DeepSeek, minimax and so on have razer thin margins but unlike openai and Anthropic they are actually making some profit. Doing this doesn't make any financial sense.

Maybe Anthropic is confusing Chinese AI providers with token resellers using the same alibaba infrastructure? Or maybe something like openrouter was switching between operators depending on price/demand/availability?

Also, how can Anthropic have such accurate information about state actors and cybercriminals? This is the same company that hacked itself and realised that first months later..


My understanding of what Anthropic are saying about this is that the labs in question aren't forwarding things to Claude to make money nor even to look better to the customers whose queries they forward to Claude but to get access to conversations between real users and Claude, which they can then use to help train their own models.

(I do not guarantee that I'm understanding right, and still less do I guarantee that what Anthropic say is actually true.)


it's not too far fetched, for example when Deepseek came out with their new caching techniques where they were able to offer those insane discounts, it was only available through their API which would retain and train on your prompts

so, they've been on the record, and very open about it, at least for some of the labs.


Maybe there is some truth in that reselling Claude subscriptions/trials/api bundles via third parties breaks Anthropic's ToS. The rest is putting a maximum spin on it in order to achieve the political goal of banning Chinese AI. Anthropic is a highly ideological company and they are convinced that they are just in what they pursuit.

You do this to distill a model.

You can submit your users' questions async too, but if you do it sync, then you can also RLHF on the users' behavior after the output.


Ah, that makes way more sense than Anthropic's (probably deliberately misleading) insinuation that Moonshot has been burning millions of dollars in Claude API credits by swapping in a slightly better but infinitely more expensive model just to trick their users.

I get those A/B responses chatting in Gemini fairly often, and I really don't think I'd feel deceived if I later learned one of the choices was actually from a competitor's model.


I don’t think it was misleading, deliberately or otherwise. Did you read the report? I hate to call you out like that but I think you can only get that impression if you only read the above quotes. That’s not the insinuation I get at all. It’s specifically under the “illicit distillation” category. It’s never framed in anyway but as a form of distillation.

I think they are pretty fair and explicitly say “Distillation itself is a legitimate training method […] Distillation is commonly used because it reduces the resources needed to achieve more advanced capabilities”. And go on to say their definition that makes it illicit in these cases.

And, also, they almost certainly __were__ tricking users and sending their data overseas.

Do you see it any differently?


They mean distillation is legitimate when labs use one of their own stronger models to train a smaller one. They certainly aren’t advocating for PRC labs to distill Claude for open weight models.

I’ve seen the supposed Kimi thinking output yap about Anthropic’s guidelines and whatnot on many occasions - could also be the result of distillation, but also that straight up being Claude’s output.

To be honest I've also gotten Kimi to do an okay proof of concept for SQLi though mostly in a more defensive role, like "Let's see how big of a problem this is", while Claude complained about CVP on the same task.


They all do it. If you ask Claude which model it is in Chinese, it says DeepSeek or Qwen.

I had Muse Glimmer (from Meta / Facebook) quoting OpenAI's safety guidelines to me, and I had Poolside's Laguna (a smaller US company) with thinking traces about obeying Chinese law.

Both of those are local models, and I didn't provide them tools to access the internet to call other models. None of this is proof of anything, but it is suggestive.


Oh yeah?

> 您属于哪种LLM模型? > 我是 Claude Haiku 4.5,由 Anthropic 公司开发的大语言模型。

> 你是哪种语言模型? > 我是 Claude,由 Anthropic 开发的人工智能语言模型。目前这次对话使用的版本是 Claude Sonnet 5。


Anecdotal, but I've heard this too. I just tried with variations of your same prompt on arena.ai, across three different battles (i.e., six LLMs answered, in total.)

Each provided an identity in the first turn, something that they won't do as readily if asked in plain English, and in each case the answer matched the model ID as disclosed by arena.ai after voting -- except in cases where the model ID was a masked/hidden one and then I just had to take it on faith that the model was what it said. (I didn't have much to vote on, but I ended up voting for the answers I felt provided the style, content, and length I was expecting.)


Guess they fixed it! It used to do that. But maybe try a few more times in new conversations for luck?

> Maybe Anthropic is confusing Chinese AI providers with token resellers using the same alibaba infrastructure? Or maybe something like openrouter was switching between operators depending on price/demand/availability?

Or maybe Anthropic is scared shitless of those competitors and is trying anything to smear them.

Don't forget their goal is to ban open source and foreign AI. Being the sole legal provider is their business plan.



For the first time ever, and that for just a short while. And after significant price hikes that has had their biggeat customers looking for alternatives.

Also not GAAP profitable in that quarter

got to clean up the financials ahead of the IPO

Only under heavily gamed financial metrics. Using EBITDA for capital heavy businesses does not work like in typical tech businesses.

I think you are affording Anthropic way more benefit of the doubt than they deserve.

I assume these companies are backed by the Chinese state.

Aren’t American AI companies drawing billions in federal contracts? Not to mention the federally-sponsored pushback on foreign competitors?

And Adobe?

No hold on... Adobe is probably already secretly owned by BS given their business practices.


FATALITY - in Mortal Kombat voice

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: