Hacker Newsnew | past | comments | ask | show | jobs | submit | bnj's commentslogin

I’ve been following the development of the drivers license sharing system from Apple where different fields can be selected; are there any implementations of PKI based identification systems where multiple certificates can be generated and revoked when compromised?

I’ve often thought that replacing the US social security number with a more robust root key makes for a fun thought experiment. Hard to imagine how such a system could securely serve so many people but passports with embedded chips seem to be doing okay.


Not in the US. Several EU countries have PKI systems integrated with identity documents that let the requester to ask for age (for example) and then only age is supplied. But their PKI systems are for the whole ID document.

As for the passport, the key/PIN you need to authenticate to the chip are printed on the page with the photo. Otherwise "hackers" can only determine nationality of passport. The standard is ICAO 9303.

https://www.icao.int/publications/doc-series/doc-9303

SSN was never intended for identification. My original card, issued in the 1970s was clearly marked "not for identification". In the original numbering system, the first 3 digits identified the office/area where the card/number was issued and the next 2 digits identified the filing cabinet. 700s were set aside for railroad workers (until 1963) because the legislators did not want railroad workers to be included in social security.

https://secure.ssa.gov/poms.nsf/lnx/0110225045


LLMs have enormous capacity for supporting a person who is motivated to learn and wants individualized support and instruction. That doesn’t describe all students and there’s no reason why seat time in the classroom should be used that way - students can still use an LLM to help them learn if they’re motivated to do that, but not during class.


I guess this is another angle on why they are interested in watermarking the generated content


Great, how are we supposed to use those websites now? No wonder web is breaking down


I'm choosing to read this as an option for people who want to put forward a serious attestation that the writing is not generated by AI, and are looking for ways to make that pledge tangible and give it a level of authority that feels more significant than "I promise" by getting that event-stream sent and signed. In that light, it seems like a useful offering!

I think it's important to consider the risks/rewards/benefits. There's definitely a sense in my circle of contacts that if a work is seen as purely human then it's somehow better and more authentic, and annecdotally, it's also possible to win points by taking something created with the help of AI and passing it off as your own independent work. Like social credit, there's a sense that you'll seem smarter than you feel yourself to be.

With that in mind, absolutely any technical solution to detect AI or attest to human authorship will be abused. The only context that a solution like this one supports is one where there isn't a risk or reward, the author just sincerely wants you to know that it's human-produced.

Plenty of people, after all, produce a draft with AI, then type it all out again editing and refining and updating as they go, and then ask an AI to look at the result and make suggestions, and then go back and make the changes they agree with. Such a workflow would be deemed human by semoi - so it's lucky that there's no point in lying about it.


That’s what a brain is


Why do companies bother with the Chinese wall technique, then?


Maybe but your brain is not running 24/7 capable of outputting thousand if not millions of tokens per hour, all while having ingested nearly the entire internet.

If yours do that, maybe we can redefine what copyrighting and patenting means for humans


This whole incident reads like OpenAI want their Fable moment


Except instead of being banned they'll be charged under the CFAA.


I’ve been wanting to get better acquainted with local inference but I don’t have the hardware, which has made me think about something I haven’t seen discussed, which is local collaboratives. The economics makes it seem like a group of people joining together to run good hardware and an open model might make sense, but I haven’t seen anything like this mentioned. Have I been missing it?

I think it would be pretty neat to launch a service helping people who wanted to participate in something like that locate one another.


The reason you don't see more of this is because everyone does the math, realizes it's not a good deal, and then gives up on the idea.

There's a post at the top of /r/localllama about this exact math right now: https://www.reddit.com/r/LocalLLaMA/comments/1ubrcwj/tokenom...

TL;DR: Running GLM 5.2 is going to cost about $20K minimum, and that's going to be painfully slow compared to the cloud hosted versions. Even the estimates where the server is computing tokens 24/7 you can't break even for several years.

The only reason to run locally is if complete data privacy is your top concern. You pay a high premium for that.


If you invest the minimum to run the model, obviously that's more expensive per-token than investing the optimum to get the best price/performance tradeoff (which for GLM 5.2 is at least five times that figure)

If you can bring the load to run the model on close to optimal hardware 24/7 with multiple concurrent requests, and have reasonably cheap power and AC, you would break even in a reasonable timespan. Which won't happen unless you are self-hosting for a medium-sized company. I guess you could sell your spare capacity to get better utilization ... and we've reinvented hosted inference


I mean sure, I’d you’re attempting to run the biggest possible models, it’s going to require a stupid amount of compute? I thought we all knew this?

The appeal to me is that we can run that, but we can also run smaller models on your laptop _and it’s functional!_ I can run DeepSeek v4 flash and a qwen 3.6 on my laptop! Thats crazy good.


.. conversely, all the cloud LLMs are being subsidized by their investors in addition to massive economies of scale.


It is false to say that all cloud LLMs are subsidized. The open weights models are hosted through numerous third party providers on OpenRouter that are operating as hosting businesses. They aren’t spending investor money to provide tokens for you at below-cost rates. They’re operating as hosting businesses.


economies of scale are enough to explain the entire price difference. Running 8 concurrent requests at 100 token/s on $100k hardware is a lot cheaper than running one concurrent request at 20 token/s on $20k hardware


There are plenty of providers of open models that offer very affordable rates. Generally, I recommend looking at OpenRouter since they track various metrics for the various providers.



Open models hosted in Cloud???


AWS Bedrock hosts Gemma 4 31B and this is The Best Deal – hands down. Try it. Vertex also has Gemma 4 MoE version. Not "lobotomised" by quants. There are also GLM (latest) and Qwen / DS (but these two are not latest versions)


I appreciate this distinction. The are multiple senses of SOTA and one that has been taking on greater mindshare is as a synonym of “the best available”. By rebasing on SOTA as generally available and understood versus cutting edge, which has limited distribution and leads the way, we expand the vocabulary we have available to describe what’s going on. Thanks.


> We are not collecting more than we need

Why does anthropic need more than a credit card for paying subscribers?


Issuer country is not a very good proxy for nationality, I suppose.


Wouldn't this also be true of government issued ID's? There's nothing preventing a non-US national from having a drivers license...

Maybe I just don't understand the definitions?


I am working on the assumption that the ID is used to check against some database or other via some state-provided route.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: