Hacker Newsnew | past | comments | ask | show | jobs | submit | Xelbair's commentslogin

The issue is that it is a procgen game, with separate systems that rarely interact with each other and you never get an actual emergent gameplay.

No matter the biome, no matter the planet you just tick check-boxes which systems are enabled or not, but their combinations do not give you anything special back.

No matter what environment is generated you play in very similar way.

Elite: Dangerous suffers from the exactly the same issue. There's tons of interesting systems, yet you will do one thing of your choosing, that will play in the same way all the time. Like a theme park, while the game promises you a simulation.


Real answer was always no.

Tailwind is just conceptually bunch of css inline styles repackaged as classes for performance boost. It was always just shifting complexity around, but offered an immediate perception of productivity gain, because you could just make a quick edit here and there.


EU and EC have been made as a resistant to populism by design, the end result is that we citizens can't change anything, and decisions are arbitrarily made behind closed doors.

The amount of layers between your vote, and the elected official that matters is just too big to have any form of accountability, especially when you couple it with national issues.

I'm frankly less concerned about populism, but more concerned about sheer disregard of opinions of citizens.


Not that they don't disregard some of my opinions too, but I am quite worried about the opinions of some of the other citizens.

The worst thing might be that it is kind (or close to) a best possible average (can't assess honestly). When I talk with many (mostly opinionated) people, at various ends of various positions (left, right, ecology, industry, security, etc.) I can't imagine any leadership that would make a significant portion of the EU citizens happy.

Now, the historical solution was to make things so worse to calm down all the crazy ideas (mostly implying war or revolution) and make people focus on the basics, let's see how it goes around this time.


Or maybe it's impossible to satisfy desires of such culturally diverse populace as EU citizens.

Which makes current model, and federated model impossible and/or prone to crumbling. Problems of Germany are different than one Spain faces, and France, and Poland etc.


Which why originally much more was decided by consensus and if there is no consensus then simply every country can do their own way. I feel like a lot of things actually reached a local optimum in the 90s in our approach to improve things, we left that.


because it is a perfect tool for all governments to 'wash' unpopular political bills that would be a political suicide in local politics.

You're asking the group profiting from current arrangement to change it.


Including EC, and MEP themselves.


>One of the biggest problems that I have in the EU is that it's almost federated

I would argue it's even worse, because with properly designed federated system you get checks and balances to some extent.

There are parts of EU that have almost zero oversight.


Can you elaborate more? When you say "checks and balances" do you mean explicit legal mechanisms or implicit mechanisms like Tiebout-style foot voting? For the latter areas with "almost zero oversight" seem advantages. Also, can you give an example of these low-oversight places and how it manifests? I'm thankful even for some pointers in what to search for.


One example is the effective prohibition on spraying pesticides by air, including drone. Drones allow lower pesticide use than current, legal practices


Oh, so "parts of the EU" wasn't about geographic areas but policy areas? But this sounds like more regulation, not checks and balances either. Are you replying to the right comment?


Late response as i rarely check HN replies.

European Commission is so disjoined from electorate through many layers of elections, that it can disregard it completely - practically citizens have no input on EC's body. Any legislation originates from there which makes it even worse.

Only guarantee of EC doing their job is their Oath, and vote of no confidence is basically impossible to call, nor there's a way to initiate one from citizens side via for example a referendum. There are no consequences for not following the Oath at all so corrupt EC can easily push things that are favorable for bigger voting blocks, while screwing everyone else and get away with it.

The only measure that citizens have to actually affect EU turned out to be worthless(as SKG initiative has shown) - as Citizens Initiative is not binding at all, and can be disregarded.

EU itself creates a system of double loyalty for every politician - do they pursue national interest or do they jump ship to European ones(including appointed positions)? This erodes national systems of check and balances.

European initiatives are impossible to control nor audit form member state PoV, and it's even worse from citizen PoV. And there's no mechanism to counteract bureaucratic bloat growth, nor rampant lobbying.

European Council is used as a way to launder unpopular legislations and push it onto all member states - like chat control.

Most of the times none of those legislations have been a part of internal political campaigns - and even if they were, they were such in only single member state. There was zero input from citizens, even in forms of voting for their own government.

President of European Parliament can act against parliament itself, again with no mechanism for any consequences(ie best example is pushing chat control vote just before summer vacation this year)

Whole institution of EU after Lisbon Treaty was made with assumption that every member state will pursue their own best interests, MEPs will pursue their own best national interests too. But sadly this created system in which it is difficult to purge any form of corruption(both embezzlement/criminal, pursuing personal interests or being purely ideologically driven without consideration of practicality).

This was done to create resistance to populism, but in practice created system that's extremely resistant to purging corruption.

It doesn't help that EU itself is a very top-down organization. Not in form of dictatorship - it's far from that - but in form of committee driven changes by unelected civil servants that operate like a black box.

and one last thing, not related to checks and balances - EU itself moves at glacial pace and is resistant to change by design - which would be perfectly fine for just a Trade Union. Unfortunately it leads to it both not reacting in time, and pushing initiatives that are already outdated.


Yeah, this in between state is really frustrating. I hope we will see a push towards more federalization, but that’s unlikely


It’s unlikely because smaller member states wouldn’t want that as they’d be outvoted by bigger members and thus forced to implement laws that might not even make sense in those (smaller) countries.


It’s unlikely for a lot of reasons, but that’s not one of them given we don’t know what a federalized EU would look like.


We had a federation around here called Yugoslavia and we saw how it played out. Forcing different nations to agree on everything down to things that are basically cultural preferences never worked well. Regulations, bureaucracy and laws are often based on cultural preferences. The EU tries to find a common baseline but still leaves a lot to each member state to avoid this problem.


Lots of federations exists and work perfectly well… including Germany, Switzerland, Canada, Brazil, the US, and more


At least two of the countries on that list are quite obviously not working well.


and at least few of them are extremely similar culturally


That's why federations have a Senate where all states get equal representation.


Then the bigger member states will say that they’re contributing so much more but get very little voting power etc. It’s not an easy problem to solve, hence the current indirect system.


I don't see federalism ever working - you have thousand of years of grudges within EU that you would have to overcome, plus gigantic cultural differences that lead to completely different ways of life.

Trade union is more likely honestly.


Isn't the whole problem that it is impossible to determine if content is AI or not? Doesn't this make it impossible to prove under 'innocent untill proven guilty' unless you're really blatant about it?

And isn't this easy to sidestep via plausible deniability and using middleman outside of EU borders?

So bad actors, especially ones outside of EU, can just continue to operate as is and ones within can just outsource the 'bad' work outside.

AI disclosure makes sense, but it should be a short list in standardized label format.ie AI used for code, assets, text, etc.

The problem is what we(as society )try to sidestep: is to have content creators(including major traditional media) be held responsible for content they provide.


I'd say that for now LLM-generated content is detectable, still at least. But anyway, "proven guilty" doesn't work as many people seem to believe. Often, if not most of the times, courts deal with cases with no full direct information which 100% prove guilt or its absence. If enough pieces of general picture suggest something, it usually considered proven.

In the same way a suspect may be declared guilty when e.g. there were reasonable expectation to double check a published image, a possibility to do it, obvious benefits from spreading fakes. Even if that image is genuinely looking convincing.

Probably, eventually somebody will try to use it to silence real whistleblowing. And it's unclear how this will work at all with expected advancements of generation capabilities. But I believe there's a public demand for such law.

I expect pretense of uncertainty to be used to get around: "we got this video from unknown source and we are not sure if it's AI-generated, but look like how this politician f*cks a pig"


> I'd say that for now LLM-generated content is detectable, still at least.

It’s really not, if someone spends a little bit of time to make something look human. For comments, literally say to your agent “write in the style of the HN user broken-kebab”, and it will pass pretty much any sniff test

(Cool nickname btw)


it's not about having 98% confidence. but 100% irrefutable proof.

You can go to reddit and cherry pick coments, that are made before LLMs, that have that exact LLM style.


Can you elaborate? I'm not sure I'm getting what is the point here. As I said, legal system rarely deals with 100%, it's not a requirement to make a law enforceable. Not telling the particular law is good or bad, just that "you can't certainly distiguish between human and LLM output" is not a strong argument against it. The conflict emerges when e.g. you are attributed words you have never said, or presented in a fake video, and there ways to argue about such cases in court other than just trying to analyze bit-by-bit, or doing histograms.


Simple - you need to assign blame, and you need to do it in a fair way.

Any assingement of blame of using unauthorized LLM generated content could be shifted to external contractor(preferably outside of EU's jurisdiction) where you yourself had no awareness of it. Contract of course explicitly forbids LLM content and requires labeling.

This is and extremely basic loophole that gives enough plausible deniability to any sane publisher/content farm.

Now you need to prove they were aware of LLM content being generated, as they cannot rely on LLM content detection methods due to high amount of false positives.

Even easier if you publish content from people writing under pseudonyms/anonymously. It devolves into he said she said kind of situation, and burden of proof is on accusers side.

Basically depending on enforcement this system either:

- only punishes small players that cannot afford to setup such chain

- is used as an arbitrary excuse to shut some outlets if the system is corrupt


Thanks, now I see. No, that's not how it works. If a legislation designates you as responsible, you can outsource compliance implementation, but not the responsibility itself. Banks can hire external companies to verify operations wrt embargoes, but if relevant authority found a violation, the most probable outcome will be penalty againt bank, not contractor. Moreover, at any time a bank may be ordered to demonstrate that they organized the whole process in such a way that they have substantial reasons to believe it works as required according to the current best practices (whatever it means), and be fined if they don't. Laws are quite often stupid, but placing blame is a honed process, and when the letters say they will kick your balls if anything, it's not easy to avoid this. Possibly we even will see publishers overrecation (as it observed in banking where clients or operations often blocked for no strong reason) and human content will be marked as LLM-produced, or "possibly LLM-produced" if they are given such option. Your concern about disadvantage to smaller players is not without reason as legally complicated environments often have such effect, but to be sure one needs to study the whole thing deeper. E.g. there could be exceptions for individuals/small companies.


Does it require innocent until proven guilty? Other standards. Not familiar with most EU countries, but common law countries have a balance of probabilities for civil cases.


It's impossible to determine whether a killing is a murder or not. We still do it. And it's easy to sidestep by doing the murder outside the country.


>It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.

Then who should? Government, where each implementation strips away rights to privacy - which in some countries, including mine, are a constitutional right? Where it expands powers of government to track everyone's activity online - and remember we're one election away from total policy shift(just like with latest US elections)?

Free market? The profitable solution is, depending on environment - either ignore the problem(profit from ads served to children, no extra work necessary), or strip away all privacy (to filter out bots and get paid more per ad).

The sad reality is that "parent should take responsibility" is least bad option available, and takes into the account individual development of a child.

Even creation of a highly regulated child only internet creates more problems - as now that becomes a highly profitable target for bad actors(both individual abusers, and companies trying to serve ads)


Let's also not forget that many of the problems this supposedly solves are not even specific to children. The attention economy is bad for everyone.


In principle, it is possible to make a privacy-preserving age check.

Site/app asks "≥18?", device generates a UUID specifically for that [app/domain + device], the device passes that UUID to government database along with the "≥18?" question and the ID card info but not the app/domain, government database gives the answer and signs just the UUID and the answer and doesn't include any ID card info.

Government doesn't know what you're looking at, website doesn't know your ID.

(There's probably also better ways to do all this, I'm not a cryptographer and I expect that will be obvious from this comment to people who are).


In reality, the ones making such check will want extra capabilities 'just in case' as we observe now, or just go for simpler solution because it's cheaper.

How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from.

It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points.

Even in countries in which this requires a subpoena, agencies break the law frequently and don't get punished.

Legal systems aren't computer systems. This isn't a technical problem but a social/political one.


> How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from.

True, but as this problem exists without any ID at all*, I don't see how the addition of the ID cards makes any difference?

> It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points.

This is why I specified a "UUID specifically for that [app/domain + device]". Can't aggregate when each app/domain gets a different signed UUID.

> Legal systems aren't computer systems. This isn't a technical problem but a social/political one.

While true, the reverse also applies: computer systems are not legal systems.

I think many lawmakers' ignorance of this is to the detriment of everyone.

In this case, the social/political problem is: we want to stop kids accessing age-inappropriate material.

The options-space for doing this appears to be:

(0) give up

(1) require parents to limit their kids' behaviour (to which I say: "Have you met a kid? Do you remember being one?")

(2) require websites to age-rank appropriately (to which I say in a sarcastic tone of voice: "Gee, that worked soooooo well for GDPR")

(3) require operating systems to intermediate. Will this suck? Yes. Will it be buggy? Also yes. Will there be false positives and false negatives? Yes to both. Will it be a constant fight as kids keep finding loopholes? Indeed.

But you know what else? All that psych testing Facebook have used for evil, can also catch bugs and loopholes faster than kids can figure them out. A school full of kids can beat their parents at the security game because they have more time to spend on finding exploits than the parents have to spend keeping up, the reverse is true of the difference between kids and Google LLC etc.

It doesn't need to be perfect, the kids aren't a computer program.

What does need to be held to a high standard is making sure the OSes don't leak all over the place.

* to be specific, the Investigatory Powers Act 2016 is one of two reasons I left the UK, just look at how over-broad the "Internet connection records without a warrant" list is https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016#...


> All that psych testing Facebook have used for evil, can also catch bugs and loopholes faster than kids can figure them out

What would be the incentive for meta to deploy that against their own self interests?

> Will it be a constant fight as kids keep finding loopholes? Indeed.

Good thing there are no other issues we as a species face. Let’s burn resources on a sysphian task because what else were we going to do with them…


> What would be the incentive for meta to deploy that against their own self interests?

The normal method is passing laws. That's kinda the point of laws.

Zuckerberg may be arrogant as hell, think he can bully governments into bending over backwards for him, governments have guns and get to arrest (and have in the past arrested) anyone local who does what Zuckerberg says instead of what the laws say when they are in conflict.

> Good thing there are no other issues we as a species face. Let’s burn resources on a sysphian task because what else were we going to do with them…

Hardly. This is more like gardening. It matters much less if kids get a few days of messing around where they're not ment to be, than if it's continuous.

And ultimately, if you want to run a business without spending money on legally required actions, you're in the wrong business, nobody should shed tears for you.


> Zuckerberg may be arrogant as hell, think he can bully governments into bending over backwards for him, governments have guns and get to arrest (and have in the past arrested) anyone local who does what Zuckerberg says instead of what the laws say when they are in conflict.

In an ideal world. Personal experience has shown that isn't the case with him.


>The options-space for doing this appears to be:

(0) give up

...

(n) waste resources

yeah, i think current state is good enough, might as well slap regulation and ban any form of targetted ads.


I'd be on board with banning micro-targeted ads, and more broadly any use of psychology to induce similar states as regulated exogenous drugs equivalent to the simple language descriptions of US Schedule I, II, and III.

However, the issues are rather broader than showing ads to kids who have no money to spend on whatever is being advertised.


This can’t work because it creates a market for people that have an ID that cleared gates to lease/borrow to those that can’t.


It cannot work *perfectly*, but unlike most crypto stuff, it doesn't have to (at least, that part doesn't need to). It's a social/political problem, not a technical one.

The goal doesn't even need to be to make a completely perfect, impossible to circumvent, barrier for all minors; all this needs to do is just make it equally difficult for a minor to get adult (for whatever definition thereof) content online as it is to get tobacco or alcohol or gambling in real life, the hard part being to do so without compromising privacy, privacy being the bit which has to be done perfectly.


> (for whatever definition thereof)

See, that's why this can't be solved technically.

Pornhub has a decent amount of sexual health material on it so there's an argument to be made for allowing teens access to at least parts of it.

> privacy being the bit which has to be done perfectly.

> It cannot work perfectly

So we agree that this is going to end poorly?


> See, that's why this can't be solved technically.

Which "this"? There's multiple things here. I'm suggesting one specific "this" (anonymous age verification) in response to another "this" (the internet is not suitable for all ages).

> Pornhub has a decent amount of sexual health material on it so there's an argument to be made for allowing teens access to at least parts of it.

There's more content on the internet than any human can consume in a lifetime, so the presence of age-appropriate stuff as a subset of some website is no more relevant than how the intro to a porn film ("there's something wrong with my fridge, it's sooooo hot", though I am thinking of a beer commercial parodying this) is not itself 18 or R18 or whatever your local certification is called.

> So we agree that this is going to end poorly?

On the contrary, literally all the rest of my comment after that quote is cut explain why we *do not agree* about this.


And the verification systems rushing at us are immune to this?


> Government doesn't know what you're looking at, website doesn't know your ID.

But then the government knows your location at any point of time and how often you use websites requiring the age check. Also, if your device is configured to do it automatically, a child can also follow this verification.


Google and Verizon sell that data to the government right now. The US's official position is that buying info they aren't legally allowed to collect is perfectly fine, as if you were given a privacy right in the constitution only to enable an info broker economy, and not because of the obvious and understood harms of the government having whatever info about you they want.

If you want the US government to not know something about you, unfortunately there's a lot of changes that need to happen, including entirely new political parties and making changes to the Supreme Court, and popular support for taking the privacy rights you already have much more seriously.


> But then the government knows your location at any point of time and how often you use websites requiring the age check.

Not as described. There's no location info in that path, and the signed statement of that UUID passing the age check does not need to be re-signed because I've not given any consideration to expiry.

(Should I consider expiry? It's not like people age backwards?)

> Also, if your device is configured to do it automatically, a child can also follow this verification.

Yes, if that device has been associated with a government ID and also the government ID signing process fails to make use the things we've already got on-device like how my phone reads my fingerprint to know I'm me and can store copies of some forms of government ID (in some places but not where I live, Apple Wallet apparently only supports some US states, Japan, Greece, and UAE).


> Not as described. There's no location info in that path

Ip address and general time of day will tell you a lot about location. Not street level, but country or state level.

> UUID passing the age check does not need to be re-signed because I've not given any consideration to expiry.

So as soon as any one uuid is leaked, it becomes plausible for any child to bypass the gates until the uuid is manually revoked?


> So as soon as any one uuid is leaked, it becomes plausible for any child to bypass the gates until the uuid is manually revoked?

How? Phones are already locked down pretty hard. Anything like this would need to be in something secured at the OS level just to stop signatures getting leaked between apps.

If you're thinking "kid roots device, replaces OS entirely", that's not the problem of the manufacturer of the OS that just got deleted.


> How? Phones are already locked down pretty hard

But never well enough, it seems.

If you can't revoke the token then I'll just sell mine to whomever needs it.

Kids will beg/borrow/steal their parents / older siblings ... etc.

The "harden the device, bake in controls that are difficult to circumvent and managed by not-the-primary-device-user" approach is _very_ similar to DRM. All that does is punish the innocent.

I have never once had VLC tell me that the mkv file I just opened can't be played because I'm not in the right region or because my screen is too old to support encryption. I have had family learn the hard way that DRM is not in their best interest, though. Now they just ask me for the movie on a pen drive when I visit next :).


> But never well enough, it seems.

"Never well enough" for stopping teens (and pre-teens) installing access tokens?

Has any adolescent in history ever managed to so much as spoof someone else's session cookie *on their phone*? And if so, when? If this is a flaw which comes up once every five iOS versions or whatever, who cares?

> Kids will beg/borrow/steal their parents / older siblings ... etc.

They occasionally get alcohol, too, despite restrictions. The point is to *mostly* stop them.

And it's not like the payment systems have not already solved the same problem.

> All that does is punish the innocent.

Which is literally something I'm trying to solve with my suggestion up-thread: here's a way to do age attestation that doesn't need to punish anyone.


> Phones are already locked down pretty hard.

Which is not how it should be done at all. Outsourcing your security to a big brother leads to all kinds of problems like planned obsolescence and spying.


> Outsourcing your security to a big brother leads to all kinds of problems like planned obsolescence and spying.

But, won't somebody think of the children!

_sigh_.


This is thinking of the adults though.


Which would be fine, if it was just a trade union like originally designed. I really love the original idea of EU. I could even get behind more federation style, although trade union is vastly preferable for me - but I do understand people pushing for it.

Yet EU has overstepped that ages ago, and you can see that with SKG recently. The only tool we, as citizens, have to actually try to affect EC is effectively useless. EC can be wined and dined by lobbyists, including outside of official recorded proceedings(!) and can just ignore you.

Not to mention a lot of other systems in EU were made with idea that countries would operate for their own best interest, and that interest was aligned for every member state:

- Shared energy market, which was crashed by Germany ideologically decommissioning nuclear power plants in middle of energy crisis.

- Free movement of people within Schengen area - which is crashed by countries taking mass of immigrants which they think they need(i don't live there so i won't judge), but then they can move around whole of the area - including the countries with vastly stricter regulations for migration.

- Digital euro as a backdoor to enforce transition to euro across the whole area, limiting the ways in which member states can dictate their own monetary policy. Digital euro must be accepted by all vendors across EU - even in the countries not using euro at all.

And that's ignoring slippery slope towards CDBC with expiration date.

- erosion of free speech and constant doublethink language, and noticing flaws in EU is undemocratic/euroskeptical(biggest sin possible) - even if it comes from "how to improve EU" point of view. or even if one points out that EU itself isn't democratic.

- double loyalty in case of politicians where there's a conflict between national and European interest. Do you pursue national benefit, or do you go against it in such cases and hop onto EU track - where there are plenty of unelected positions?

and also double loyalty in case of EC members - they should pursue good of all EU by their own charter, but there's no punishment nor anything systemic to discourage them from abusing their power and pursuing national interests.

All of those are minor or major flaws that slowly fracture EU. And by this point I don't think the system can be reformed.


the problem is that EU has no way for citizens/voters to actually purge those bad individuals.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: