Lukas @lxgr.net · 30/05/2026Irritating login antipatterns, #387: Sending a one-time login code via email or SMS immediately upon entering my username/email, without asking for confirmation, when I have a perfectly good Passkey *right here on this device*. 010
Lukas @lxgr.net · 30/04/2026“Talk like a nerd, but don’t ever mention goblins or pigeons”? Words uttered by people who have never been in the same ZIP code as a nerd 000
Lukas @lxgr.net · 26/04/2026There’s some moderately cursed command that lets your Mac stay awake under all circumstances, including lid closed and on battery mode. Accidentally been using mine in that mode for a few months. It mostly sucked, but being able to SSH to it while it was in my backpack had its benefits. 110
Lukas @lxgr.net · 18/04/2026Finde ich aber generell ok, sofern sie dann auch €200k Studiengebühren zahlen 000
Lukas @lxgr.net · 15/04/2026"It looks like you're trying to install Madden NFL. Do you need help?" 050
Lukas @lxgr.net · 07/03/2026I think the big corps people most commonly use are relatively good by preventing "email takeovers" by now, but some sites do offer a lot of random login options. Best practice, IMO, is to require reauthentication using an existing "social login" before adding a new one, or at least doing email OTP. 020
Lukas @lxgr.net · 07/03/2026Same here, and it's quite common. My problem with it is that it reduces the security of my account to the lowest common denominator of all social logins a given site allows. My Google account is pretty secure, but my Facebook account I haven't used in 10 years probably not so much. 250
Lukas @lxgr.net · 16/02/2026Oder anders gedacht: Wenn Modelle ohne COT nur intern/intransparent denken, verlieren sie diese Fähigkeit doch nicht nur dadurch, dass sie _auch_ öffentlich denken können. 110
Lukas @lxgr.net · 16/02/2026Hier ist das Steganographie-Paper: arxiv.org/abs/2506.01926 Da geht es eher um adversarial/durch “Zensur” (also nicht zufällig) erlernte Steganographie, aber ich vermute stark, das kann auch “einfach so” passieren.arxiv.orgLarge language models can learn and generalize steganographic chain-of-thought under process supervisionChain-of-thought (CoT) reasoning not only enhances large language model performance but also provides critical insights into decision-making processes, marking it as a useful tool for monitoring model... 110
Lukas @lxgr.net · 16/02/2026Mein Punkt ist also nicht, dass die Traces nicht helfen, sondern dass sie dem Modell manchmal/eventuell als private Sprache helfen können, die für uns nur vermeintlich interpretierbar ist. 110
Lukas @lxgr.net · 16/02/2026Es gibt schon Arbeiten, die zeigen (durch mechanical interpretability), dass die reasoning traces teilweise frei erfunden sind. Dass sie dem Modell trotzdem helfen, kann z.B. daran liegen, dass das Model gewisse englische Begriffe als eine eigene private Sprache benutzt. 110
Lukas @lxgr.net · 16/02/2026Nicht unbedingt. Die Traces könnten ja z.B. auch komplett “modelese” sein, oder zwar wie Englisch aussehen, aber die eigentliche Bedeutung für das Modell selbst ist steganografisch codiert. 100
Lukas @lxgr.net · 16/02/2026Reasoning bringt Modellen definitiv viel, aber die Interpetierbarkeit ist dafür halt leider nicht notwendig bzw. eher zufällig und sehr instabil. Man sieht ja in den Traces jetzt schon oft post-hoc reasoning etc. 100
Lukas @lxgr.net · 16/02/2026thezvi.substack.com/p/the-most-f... tl;dr: Wenn du dem LLM abtrainierst, "böse Gedanken" im Chain-of-Thought für Menschen lesbar wiederzugeben, lernt es genau das: Sie nicht mehr lesbar wiederzugeben. Ob es sie privat trotzdem noch hat oder nicht, kannst du dann nur noch sehr schwer herausfinden.thezvi.substack.comThe Most Forbidden TechniqueThe Most Forbidden Technique is training an AI using interpretability techniques. 110
Lukas @lxgr.net · 16/02/2026Die Interpretierbarkeit der Zwischenschritte ist aber nicht automatisch gegeben, und kann durchaus (absichtlich oder unabsichtlich) wegtrainiert werden. Nur weil du mit Stift und Papier besser denkst, rechnest etc., macht dich das nicht sofort zum charakterlichen Trisolarier. 100
Lukas @lxgr.net · 10/02/2026This one is especially annoying because it even breaks for the canonical Bay Area bubble scenario. Or do you really all live in San Francisco, CA, U.S. Minor Outlying Islands? 000
Lukas @lxgr.net · 10/02/2026Falsehoods programmers believe about phone numbers, #164: Country calling codes and countries are a bijection. 100
Lukas @lxgr.net · 15/01/2026Wednesday and Thursday were almost certainly swapped this week. Can’t prove it though 000
Lukas @lxgr.net · 20/12/2025It would also trivially fall to double spending. But all of this is a solved problem and has been since the late 90s! Many European countries had domestic two-sided offline capable digital cash schemes, but they were all shut down in favor of domestic online schemes, or often Visa and Mastercard 010
Lukas @lxgr.net · 20/12/2025I doubt the ECB will want to get into the business of retail dispute arbitration. And probably not so coincidentally, Wero now seems to support disputes? 100
Lukas @lxgr.net · 06/12/2025Seems like an excellent way to outsource both frontier model training (to Anthropic, via Opus reasoning traces) and RLHF (to users). 000
Lukas @lxgr.net · 06/12/2025So, uh, Google released a free IDE with free and very generous Claude Opus 4.5 tokens… Does this mean what I think it means? 100
Lukas @lxgr.net · 30/11/2025Du bist doch hier der Feuilletonist, mach mal was für mein Abo*!! *Probeabo 010
Lukas @lxgr.net · 01/11/2025Matches my experience completely. It's pretty good at coming up with small/one-off scripts or single-page web apps, OK at working in large existing code bases, but an absolute beast at finding bugs given a detailed description of symptoms and a few pointers. 150
Lukas @lxgr.net · 29/10/2025Not all OSes allow trusting self-signed certs only for a particular set of hostnames, and if they don't, the associated private key becomes incredibly risky (since anyone getting it would be able to pose as google.com etc. to you as well). Some OSes don't even have a system-wide trust store at all! 240
Lukas @lxgr.net · 07/09/2025A real shame there’s no mechanism browsers can indicate language preferences to websites, like a request header or something. Fortunately IP addresses map to user language preferences perfectly. 010
Lukas @lxgr.net · 07/09/2025Logged in to my Spotify account on the web once when traveling to update my card, and now the web interface, while logged in with my account they know the country/language for perfectly well, is persistently in a language I don’t speak, even after returning. 110
Reposted by Lukasqntm @qntm.org · 03/09/2025Amazing new age verification procedure requires no government ID, no credit card numbers, no photography import { setTimeout } from 'node:timers/promises' const verifyAge = async () => { await setTimeout(568_036_800_000) return true } 727956
Lukas @lxgr.net · 12/08/2025So the model powering “GPT-5” in the UI (modulo “routing to the thinking model”) is called “gpt-5-chat” in the API, while the one powering “GPT-5 Thinking” is called “gpt-5”? This has got to be intentional at this point. 000
Lukas @lxgr.net · 09/08/2025Men don't care what models are on ChatGPT. They only care what other models are on ChatGPT. 010
Lukas @lxgr.net · 21/07/2025USDL is pegged to USD and is domiciled in Abu Dhabi, as far as I know. No idea if that’s available to residents there, though. 000
Lukas @lxgr.net · 20/07/2025Natürlich, Selbstanzeige. Wäre für das kriminell schlechte LLM dieses Zusammenfassungs-Bots auch überlegenswert. 000
Lukas @lxgr.net · 16/07/2025Ah, and the other one requires an app to have verified some companion domain and then allows only that as RPID, IIRC? Thanks for doing all of this, by the way, I hope having a great use case finally convinces Bitwarden to also support PRF :) 010
Lukas @lxgr.net · 16/07/2025Speaking of that, did your explorations of using the FIDO "backend API" on macOS in CLI tools lead anywhere, or does that still require some browser-only code signing entitlement? 100
Lukas @lxgr.net · 16/07/2025It's slightly different from a smart card in that the key inevitably is revealed to the host computer with the PRF extension, but for applications that only use the smartcard for key (un)wrapping it's effectively equivalent. 000
Lukas @lxgr.net · 15/07/2025On the other hand, having somebody/something really intelligent working for you certainly helps a lot. 010
Lukas @lxgr.net · 14/07/2025I don’t think being a majority holder of voting shares allows you to make decisions that disadvantage minority shareholders. (Otherwise, people would vote for things like “don’t pay any more dividends to these 49% of shareholders” all the time.) 100
Lukas @lxgr.net · 14/07/2025You might be delighted/horrified to learn that the machine-readable zone of ICAO passports encodes all dates as YYMMDD – including the date of birth. 051
Lukas @lxgr.net · 11/07/2025Excuse me but deluding myself into thinking I saved everyone some time by monologuing at an intern who didn’t ask any question whatsoever isn’t novelty, that’s a core part of my professional identity 000
Lukas @lxgr.net · 04/07/2025Woah, this is literally on my to do list for vibeserver github.com/lxgr/vibeser...github.comGitHub - lxgr/vibeserver: A little webserver making things up just in timeA little webserver making things up just in time. Contribute to lxgr/vibeserver development by creating an account on GitHub. 050
Lukas @lxgr.net · 30/06/2025Identity documents supporting interactive cryptographic authentication have been around for decades now (e.g. ICAO 9303 "biometric passports"), and I wouldn't be surprised if some government had a stockpile of a few hundred million ICs that can only do ECDSA and/or RSA as a result 😬 110