Sign in

Lukas

@lxgr.net
42 followers 62 following 227 posts
PostsRepliesMedia
Lukas @lxgr.net · 30/05/2026
Irritating login antipatterns, #387: Sending a one-time login code via email or SMS immediately upon entering my username/email, without asking for confirmation, when I have a perfectly good Passkey *right here on this device*.
010
Lukas @lxgr.net · 15/05/2026
More than enough against classical attackers in any case.
000
Lukas @lxgr.net · 07/05/2026
"Man bites dog" at this point
000
Lukas @lxgr.net · 30/04/2026
“Talk like a nerd, but don’t ever mention goblins or pigeons”? Words uttered by people who have never been in the same ZIP code as a nerd
000
Lukas @lxgr.net · 29/04/2026
Why would they nerf goblin mode!?
000
Lukas @lxgr.net · 26/04/2026
There’s some moderately cursed command that lets your Mac stay awake under all circumstances, including lid closed and on battery mode. Accidentally been using mine in that mode for a few months. It mostly sucked, but being able to SSH to it while it was in my backpack had its benefits.
110
Lukas @lxgr.net · 18/04/2026
Finde ich aber generell ok, sofern sie dann auch €200k Studiengebühren zahlen
000
Lukas @lxgr.net · 18/04/2026
Wann Einweg-Becherpfand!!
100
Lukas @lxgr.net · 15/04/2026
"It looks like you're trying to install Madden NFL. Do you need help?"
Microsoft Clippy
050
Lukas @lxgr.net · 07/03/2026
I think the big corps people most commonly use are relatively good by preventing "email takeovers" by now, but some sites do offer a lot of random login options. Best practice, IMO, is to require reauthentication using an existing "social login" before adding a new one, or at least doing email OTP.
020
Lukas @lxgr.net · 07/03/2026
Same here, and it's quite common. My problem with it is that it reduces the security of my account to the lowest common denominator of all social logins a given site allows. My Google account is pretty secure, but my Facebook account I haven't used in 10 years probably not so much.
250
Reposted by Lukas
AtomD @atomd.bsky.social · 02/03/2026
02310
Lukas @lxgr.net · 16/02/2026
Oder anders gedacht: Wenn Modelle ohne COT nur intern/intransparent denken, verlieren sie diese Fähigkeit doch nicht nur dadurch, dass sie _auch_ öffentlich denken können.
110
Lukas @lxgr.net · 16/02/2026
Hier ist das Steganographie-Paper: arxiv.org/abs/2506.01926 Da geht es eher um adversarial/durch “Zensur” (also nicht zufällig) erlernte Steganographie, aber ich vermute stark, das kann auch “einfach so” passieren.
arxiv.org
Large language models can learn and generalize steganographic chain-of-thought under process supervision
Chain-of-thought (CoT) reasoning not only enhances large language model performance but also provides critical insights into decision-making processes, marking it as a useful tool for monitoring model...
110
Lukas @lxgr.net · 16/02/2026
Mein Punkt ist also nicht, dass die Traces nicht helfen, sondern dass sie dem Modell manchmal/eventuell als private Sprache helfen können, die für uns nur vermeintlich interpretierbar ist.
110
Lukas @lxgr.net · 16/02/2026
Es gibt schon Arbeiten, die zeigen (durch mechanical interpretability), dass die reasoning traces teilweise frei erfunden sind. Dass sie dem Modell trotzdem helfen, kann z.B. daran liegen, dass das Model gewisse englische Begriffe als eine eigene private Sprache benutzt.
110
Lukas @lxgr.net · 16/02/2026
Nicht unbedingt. Die Traces könnten ja z.B. auch komplett “modelese” sein, oder zwar wie Englisch aussehen, aber die eigentliche Bedeutung für das Modell selbst ist steganografisch codiert.
100
Lukas @lxgr.net · 16/02/2026
Reasoning bringt Modellen definitiv viel, aber die Interpetierbarkeit ist dafür halt leider nicht notwendig bzw. eher zufällig und sehr instabil. Man sieht ja in den Traces jetzt schon oft post-hoc reasoning etc.
100
Lukas @lxgr.net · 16/02/2026
thezvi.substack.com/p/the-most-f... tl;dr: Wenn du dem LLM abtrainierst, "böse Gedanken" im Chain-of-Thought für Menschen lesbar wiederzugeben, lernt es genau das: Sie nicht mehr lesbar wiederzugeben. Ob es sie privat trotzdem noch hat oder nicht, kannst du dann nur noch sehr schwer herausfinden.
thezvi.substack.com
The Most Forbidden Technique
The Most Forbidden Technique is training an AI using interpretability techniques.
110
Lukas @lxgr.net · 16/02/2026
Die Interpretierbarkeit der Zwischenschritte ist aber nicht automatisch gegeben, und kann durchaus (absichtlich oder unabsichtlich) wegtrainiert werden. Nur weil du mit Stift und Papier besser denkst, rechnest etc., macht dich das nicht sofort zum charakterlichen Trisolarier.
100
Lukas @lxgr.net · 10/02/2026
This one is especially annoying because it even breaks for the canonical Bay Area bubble scenario. Or do you really all live in San Francisco, CA, U.S. Minor Outlying Islands?
000
Lukas @lxgr.net · 10/02/2026
Falsehoods programmers believe about phone numbers, #164: Country calling codes and countries are a bijection.
100
Lukas @lxgr.net · 15/01/2026
Wednesday and Thursday were almost certainly swapped this week. Can’t prove it though
000
Lukas @lxgr.net · 20/12/2025
It would also trivially fall to double spending. But all of this is a solved problem and has been since the late 90s! Many European countries had domestic two-sided offline capable digital cash schemes, but they were all shut down in favor of domestic online schemes, or often Visa and Mastercard
010
Lukas @lxgr.net · 20/12/2025
I doubt the ECB will want to get into the business of retail dispute arbitration. And probably not so coincidentally, Wero now seems to support disputes?
100
Lukas @lxgr.net · 08/12/2025
@greg is this true
000
Lukas @lxgr.net · 06/12/2025
Seems like an excellent way to outsource both frontier model training (to Anthropic, via Opus reasoning traces) and RLHF (to users).
000
Lukas @lxgr.net · 06/12/2025
So, uh, Google released a free IDE with free and very generous Claude Opus 4.5 tokens… Does this mean what I think it means?
100
Lukas @lxgr.net · 30/11/2025
Du bist doch hier der Feuilletonist, mach mal was für mein Abo*!! *Probeabo
010
Lukas @lxgr.net · 01/11/2025
Matches my experience completely. It's pretty good at coming up with small/one-off scripts or single-page web apps, OK at working in large existing code bases, but an absolute beast at finding bugs given a detailed description of symptoms and a few pointers.
150
Lukas @lxgr.net · 29/10/2025
Not all OSes allow trusting self-signed certs only for a particular set of hostnames, and if they don't, the associated private key becomes incredibly risky (since anyone getting it would be able to pose as google.com etc. to you as well). Some OSes don't even have a system-wide trust store at all!
240
Lukas @lxgr.net · 07/09/2025
A real shame there’s no mechanism browsers can indicate language preferences to websites, like a request header or something. Fortunately IP addresses map to user language preferences perfectly.
010
Lukas @lxgr.net · 07/09/2025
Logged in to my Spotify account on the web once when traveling to update my card, and now the web interface, while logged in with my account they know the country/language for perfectly well, is persistently in a language I don’t speak, even after returning.
110
Reposted by Lukas
qntm @qntm.org · 03/09/2025
Amazing new age verification procedure requires no government ID, no credit card numbers, no photography import { setTimeout } from 'node:timers/promises' const verifyAge = async () => { await setTimeout(568_036_800_000) return true }
727956
Lukas @lxgr.net · 12/08/2025
So the model powering “GPT-5” in the UI (modulo “routing to the thinking model”) is called “gpt-5-chat” in the API, while the one powering “GPT-5 Thinking” is called “gpt-5”? This has got to be intentional at this point.
000
Lukas @lxgr.net · 09/08/2025
Men don't care what models are on ChatGPT. They only care what other models are on ChatGPT.
010
Lukas @lxgr.net · 21/07/2025
USDL is pegged to USD and is domiciled in Abu Dhabi, as far as I know. No idea if that’s available to residents there, though.
000
Lukas @lxgr.net · 20/07/2025
Natürlich, Selbstanzeige. Wäre für das kriminell schlechte LLM dieses Zusammenfassungs-Bots auch überlegenswert.
000
Lukas @lxgr.net · 16/07/2025
Ah, and the other one requires an app to have verified some companion domain and then allows only that as RPID, IIRC? Thanks for doing all of this, by the way, I hope having a great use case finally convinces Bitwarden to also support PRF :)
010
Lukas @lxgr.net · 16/07/2025
Speaking of that, did your explorations of using the FIDO "backend API" on macOS in CLI tools lead anywhere, or does that still require some browser-only code signing entitlement?
100
Lukas @lxgr.net · 16/07/2025
It's slightly different from a smart card in that the key inevitably is revealed to the host computer with the PRF extension, but for applications that only use the smartcard for key (un)wrapping it's effectively equivalent.
000
Lukas @lxgr.net · 15/07/2025
On the other hand, having somebody/something really intelligent working for you certainly helps a lot.
010
Lukas @lxgr.net · 14/07/2025
I don’t think being a majority holder of voting shares allows you to make decisions that disadvantage minority shareholders. (Otherwise, people would vote for things like “don’t pay any more dividends to these 49% of shareholders” all the time.)
100
Lukas @lxgr.net · 14/07/2025
You might be delighted/horrified to learn that the machine-readable zone of ICAO passports encodes all dates as YYMMDD – including the date of birth.
051
Lukas @lxgr.net · 11/07/2025
> new Date("📅") Invalid Date *monocle drop*
050
Lukas @lxgr.net · 11/07/2025
Excuse me but deluding myself into thinking I saved everyone some time by monologuing at an intern who didn’t ask any question whatsoever isn’t novelty, that’s a core part of my professional identity
000
Lukas @lxgr.net · 08/07/2025
Please contain me
100
Lukas @lxgr.net · 04/07/2025
Woah, this is literally on my to do list for vibeserver github.com/lxgr/vibeser...
github.com
GitHub - lxgr/vibeserver: A little webserver making things up just in time
A little webserver making things up just in time. Contribute to lxgr/vibeserver development by creating an account on GitHub.
050
Lukas @lxgr.net · 01/07/2025
I am become Parrot, the repeater of words
000
Lukas @lxgr.net · 30/06/2025
Identity documents supporting interactive cryptographic authentication have been around for decades now (e.g. ICAO 9303 "biometric passports"), and I wouldn't be surprised if some government had a stockpile of a few hundred million ICs that can only do ECDSA and/or RSA as a result 😬
110