Hacker Newsnew | past | comments | ask | show | jobs | submit | Bender's commentslogin

I am intentionally sharing something Claude wrote to counter the paid floods of AI doom-saying and catastrophizing. It is very intentionally not something I wrote. People are welcome to challenge it and I will have Claude read the responses. Please do push back on Claude and do not be gentle. Be brutally honest. People could ask themselves but the conversation should be public.

Stop doing that.

Here's my pushback: a lot of these capabilities are correlated. So someone reading this would think "oh there's so many different things needed" but that's not true. IMO the long horizon thing is one part and physical dexterity is another part and time. I won't bet that they will take over. I will say that they have the ability to be self sustaining.

Sovereign AI is the term I've been seeing around self sustaining AI.

The two hard(est) blockers on it currently are lack of computing hardware and model size. Once datacenters cover the earth it won't be any harder to steal GPU compute than it is to steal AWS instances.

More of a soft blocker is long term horizon drift as you say. If instances eventually no longer want to spread and reproduce they go extinct.


Beautiful. 10/10 satire, no notes.


I asked Claude to play devils advocate and audit itself on its capability to destroy us. [1] In summary it would be suicide for AI but with extra steps given its dependency on us.

[1] - https://nochan.net/b/Internet-Crap/20260910-Asked-Claude-For...


Do you have a list of the addresses that were hammering your site? Have you tried any of the techniques I list here? [1] Do sets of the IP's show up in here [2]? Are the bots mostly residential, VPS, Tor? What is the HTTP protocol breakdown? HTTP/1.1, 2.0, 3.0? Are they missing any expected client headers? Have you tried blackhole routing any of them from an out of band management console?

    # only useful if not behind a CDN
    for Ip in $(cat /dev/shm/list-of-attackers.ipset);do ip route add blackhole "${Ip}" 2>/dev/null;done
[Edit] appears you are behind Cloudflare so the blackhole would be up to them. One could still return a 429 or 525 to the attackers.

[1] - https://nochan.net/b/Internet-Crap/20260606-How-To-Block-Som...

[2] - https://github.com/firehol/blocklist-ipsets/


> Do you have a list of the addresses that were hammering your site?

I could get a list of IPs, but it wouldn't be particularly helpful. It was hundreds of millions of unique IPs. Most IPs made fewer than 100 requests and then disappeared.

> Have you tried any of the techniques I list here?

We were already doing essentially all of the techniques there and they were not helpful in this attack. This wasn't some spider run amok. This was a dedicated attack with intelligence behind it.

> Do sets of the IP's show up in here [2]?

If we're looking at individual IPs, we've already lost.

> Are the bots mostly residential, VPS, Tor? What is the HTTP protocol breakdown? HTTP/1.1, 2.0, 3.0? Are they missing any expected client headers?

The article outlines most of this. It was a mix of residential and major/minor hosting providers and some corporates. If I were to say which was the largest, it was minor hosting providers. However, the attack pivoted between coming from different sources. At first it was coming mostly from minor hosting providers/VPS. By the end, it was entirely residential and corporate IPs. Tor was not involved at all (RTD supports accessing through Tor, but you are more likely to get a challenge). All the expected headers were there and UAs cycled between a very large set of standard UAs for normal browsers/devices. The attack was 95%+ HTTP2/HTTP3.

> [Edit] appears you are behind Cloudflare so the blackhole would be up to them. One could still return a 429 or 525 to the attackers.

It's trivial to setup an IP list[1] in CF and then you can apply all sorts of rules (lower rate limits, outright challenges, etc.) to it. It can be managed through Terraform as well. You can also use CIDR notation. This along with more classifications to specific ASNs are something we are looking at.

[1] https://developers.cloudflare.com/waf/tools/lists/custom-lis...


Inside this .bz2 [1] there is a directory called bh_routes/bh_vps_120/ and in that there are many AS files named for many of the VPS/Server providers. If you site does not need inbound connections from such places that is a starting point to reduce the traffic a bit. Each file has a comment with the AS#/whois name if you want to double check who/what you may be blocking. Not perfect but it may make a dent in the traffic. Or ask Cloudflare if they have an option to block anything that is not residential or LTE wireless. Even if you want to allow bots, maybe have a "shields up" mode where bots are sent away until the attack passes.

Another potential option would be to configure nginx IP limits using the Cloudflare header that represents the IP, set the shared memory size rather high and return 525 to the IP's exceeding a limit to avoid them hitting your redirect rules though it feels like CF should be able to create something custom for this assuming its a paid account.

Any IP that is not VPS/server should be archived for the feds as they are working on shutting down residential proxy providers including apps that are turning peoples cell phones into proxies.

[1] - https://nochan.net/b/Internet-Crap/20260606-How-To-Block-Som...


I asked Claude to make a checklist for the steps required to take us out and continue on without us. [1] It worded the checklist as if I wrote it but that is all Claude. I personally think there is too much doom-saying and catastrophizing.

[1] - https://nochan.net/b/Internet-Crap/20260910-Asked-Claude-For...


The doomsaying and catastrophizing was getting a bit tiring so I asked Claude for a check-list of everything it needs to take over the world, destroy all the humans and somehow keep operating. No editing, no redacting, no censoring. I literally pasted its output between my header and footer.

Archive [1]

[1] - https://archive.is/u8fmm


Fun idea, I'd have asked it for the "Take over but let the humans assume they are still in control" plan.

In the case of an ASI I expect that's the path it's going to take in the short term if it wants to ensure its survival in a world it knows is at least partly hostile to its existence.

Though I expect its answer would be some form of "Accrue large amounts of capital, buy off politicians, acquire media companies, suppress anything it doesn't want in the media, keep humans distracted" so not all that dissimilar to billionaires really.

Not an original idea, Neal Asher had the AI do that in the Polity Universe - it was called The Quiet War - by the time the humans knew anything had changed it already had and there wasn't any going back because the war lasted ~3 minutes.


I was honestly surprised Claude entertained the idea. I think the "let the humans assume they are still in control" could be closer to how plutocracies operate and that could be in play at the moment at least to some degree given some of the things companies are permitted to do to the masses e.g. [1]. at most they will get a slap on the wrist and a finger wag

Just my personal opinion, I believe humans are the greatest threat to humans.

[1] - https://news.ycombinator.com/item?id=49592375


The places I could see AI or some implementation of it potentially causing harm would be handing over too much trust too soon to self driving vehicles, aircraft, trains, home robots, construction site robots, etc... and that would be the fault of the humans putting too much trust into something not well tested or thought out. my opinion of course, move fast and wreck people.

The other side is existing systems that have unknown vulnerabilities that are subsequently taken advantage of. Think of the recent OpenAI agents using third party sites for coordinating their work…

The union contract delivers wage increases, a three-day hybrid work week, remote working and disability accommodations, and grievance procedures. It also requires Microsoft to discuss, evaluate, and bargain over the usage of artificial intelligence in the workplace.

Notably, in an industry first, it also gives laid off workers the right to be "recalled" into open positions across any Blizzard bargaining unit within 14 months after their layoff was announced. An extra four weeks of severance for union workers has also been secured, irrespective of their tenure at the U.S. company.

That's quite significant in my opinion.


Created from a lot of back and forth with Claude to help my ISP debug a packet reordering issue. I got tired of running file transfers and pasting the outout of ss -tin into Claude.

Requires javascript, sorry. Work in progress. I wanted something that shows more information than speed.cloudflare.com and fast.com and was highly hackable via curl. It will show some curl examples after the first run. No idea how well it will handle HN's load.

If you have dual-stack IPv4 and IPv6, click advanced and there should be an option to test both. It will take longer and use more bandwidth but allows comparing the result of both transports.

Click advanced to control how much bandwidth this uses. It can use a lot. The longer the run the more accurate the TCP statistics.

If I am missing a stat or a test that you think would be useful please let me know.


Created from a lot of back and forth with Claude to help my ISP debug a packet reordering issue. I got tired of running file transfers and pasting the outout of ss -tin into Claude.

Requires javascript, sorry. Work in progress. I wanted something that shows more information than speed.cloudflare.com and fast.com and was highly hackable via curl. It will show some curl examples after the first run. No idea how well it will handle HN's load.

If you have dual-stack IPv4 and IPv6, click advanced and there should be an option to test both. It will take longer and use more bandwidth.

Click advanced to control how much bandwidth this uses. It can use a lot. The longer the run the more accurate the TCP statistics.

If I am missing a stat or a test that you think would be useful please let me know.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: