Hacker Newsnew | past | comments | ask | show | jobs | submit | jrmg's commentslogin

In the 90s, how long did people expect it would be until consumer computer hardware would be able to do this so quickly?

In Schneider's 1995 book he estimated factoring a 512-bit number would take roughly 30,000 MIPS-years (a one-million-instruction-per-second computer running for one year).

When a research team actually factored RSA-155 in August 1999, it took 8,400 MIPS-years due to efficiencies discovered. It still took 35 CPU-years spread across a cluster of 300 fast SGI/SUN workstations and Pentium II PCs (400-500 MIPS each), crunching in parallel for seven months. https://cs.ccsu.edu/~pelletie/local/risks/cryptography/Facto...

Robert Silverman, a senior research scientist at RSA Laboratories, published an analysis projecting these new hardware requirements against Moore's Law. His expectation was that within 10 years (roughly 2009–2010), common desktop machines would possess the speed and memory necessary to handle a 512-bit factorization entirely on their own. https://cr.yp.to/bib/2000/silverman.pdf


I don't know how fast my CPU cores are in MIPS, but it's 4.5 Ghz and some random googling indicates that might be about 10 MIPS per Mhz, so 45,000 Dhrystone MIPS.

And assuming about ((32x32 core-hours) / 8766 (hours/year)) x 45,000 = 5256 MIPS-years.

So within the order of magnitude of the 1999 factoring! Of course, the MIPS number is kinda made up, so


Only lunatics would do it on CPU's though. They'd use their GPU cluster, with custom SW (not yet online). RSA-1024 would cost about a week then.

GPUs may have existed in the 90's but they were very specialized to graphics and couldn't do general purpose computation like factoring integers.

From my recalling, a few years at most. There was, and apparently still exists, distributed.net which was aimed at brute forcing DES (easy), RC5-56 bits and then RC5-64 bits by establishing a web of personal computers (via a client one had to install). Thus it was well known brute forcing was achievable in a reasonable time.

PGP (1991) was considered secure as it was considered not brute forceable. With 128 bits, it was considered military grade at the time and the US had an export restriction due to that. That might have been an incentive for GNU Privacy Guard. In France you had to give your private key to the government authority if an encryption system used anymore than 56 bits (as I recall, I don't remember the exact number).


It was also illegal to export software with cryptography in the early 90s, anything with keys bigger than 40 bits, so there was a lot of intentionally weak connections.

At least in the US in the 90s, crypto was effectively required to be breakable. There expectation was this was possible at that time.

In 1999, factoring RSA-512 required roughly 292 CPU-years of work distributed across hundreds of academic machines, running for about 7 months. The community already knew it was weak -- the US export restrictions on 512-bit RSA were explicitly calibrated so the NSA could break it while casual adversaries couldn't.

Consumer hardware doing it in a couple of days in 2025 is roughly in line with Moore's Law extrapolations people were drawing at the time. The surprise isn't really the timeline. It's that someone did it as a weekend project rather than a nation-state effort.


To keep tax revenue equal, property taxes for those who purchased recently would go down, and property taxes for those who’d purchased in the past would go up.

The housing market would become more liquid because people would move out of homes if their values rose too much and they could no longer afford the taxes. This would be a shock initially, but over time it would just be seen as part of life like it is in other areas: mostly, empty nesters would downsize to a cheaper, smaller house with lower taxes. Gentrification might be more problematic though.

In practice, probably some phased rebalancing would have to happen to avoid the sudden economic shock, but, politics notwithstanding, it’s not crazy to suggest it could be done and that the end state might be overall ‘better’ for most people. The end state would be how property taxes work almost everywhere else.


> To keep tax revenue equal, property taxes for those who purchased recently would go down, and property taxes for those who’d purchased in the past would go up.

That's what I'm saying _won't_ happen. The high property taxes as-is will stay high and previously protected properties will have their taxes shoot up. That is my prediction and nothing about the state of California, or the US broadly, suggests otherwise to me.


The TV will join that automatically without asking you because they have an agreement with the network provider.

This seems far fetched to me. Have you seen evidence or reliable reporting of this?


Why is this more far fetched than LG smart TVs recording audio while pretending to be off and caching the results waiting for an opportunity to exfiltrate the precious data? We're in a "if they can they will" world with this stuff.

Comcast sets up a secondary wifi network on their routers in your home that they use as the backhaul for smartphones. Why wouldn't they make a deal with LG or whoever to use that data? We've already established they'll do about a half-a-Stuxnet to get at this data, you're telling me they won't do a couple bulk deals with common ISPs?


Why go through all that trouble of spoofing MAC addresses or assuming it will always be able to connect to an open WiFi network.

5G connectivity is cheap. You can put a 5G modem in pretty much any device for $10 or less, and pay roughly $2/year in subscription fees. My local water utility with ~900 subscribers pays $2/year for 5G connectivity for water meters, and I have no doubt you can get it much cheaper at scale.

They don't even have to tell you about the 5G modem. It could exclusively be used for exfiltrating data about your viewing habits. It's virtually undetectable and more or less impossible to block. The TV could behave nice on the Wifi, you can block all the DNS servers you like, it would still be able to phone home.


because using open wifi is infinity cheaper.

You are asking for $20 increase in BOM, which means they somehow has to extract $20 from your private data, which is hard.


Or simply increase the selling price by $20, would you even notice ?

And if they're not expecting to make $20 over 10 years selling your data, it hardly seems worth risking your reputation over.


It’s just the BOM price. When your product has Cellular module, there is set of certification that is painful to pass. It’s better to use included wifi module since it’s already there and certified

Okay, even if you don’t agree with me that it’s far fetched, claims of ‘X is doing Y’ usually require some evidence that X is doing Y to be considered credible.

after everything we’ve seen factually that companies do, why would this, of all things, seem far-fetched to you?

i think it would be significantly more far-fetched that cable companies don’t sell them access. i would be shocked if they didn’t.


How about this? LG builds many other home appliances like washers and driers. Some have apps and wifi.

Why wouldn’t LG allow their devices to talk to each other locally, without needing to join a network? With private SSID or something like that? Only one appliance would need internet access.

This shit already exists. Like Amazon Sidewalk: https://ring.com/amazon-sidewalk

Now, I’m not saying LG is doing it, but this is not a far fetched technical concept. The only reason they’re potentially not going that far is because most people probably just connect it to the internet so why bother about the few who don’t.

The devices are already scanning the network for any devices and software they can find, and mapping your phone to your TV viewing habits for example. The LG execs are on record bragging about it. So I don’t see why it’s absurd


This is alarmingly realistic to me.

The part about ISP routers broadcasting an alternate "hotspot" SSID is documented [1] and can be easily observed. Walk around any city, open your phone's wifi settings and see networks like "xfinitywifi" or "optimumwifi". As an end user, if you connect to one of these networks from your device, you'll get a captive portal web page that makes you sign in to your ISP account. Once signed in, you get internet access courtesy of the router sitting in whatever home or business you happen to be near to.

In addition to ISPs allowing their own subscribers access, there are examples of corporations cutting deals with ISPs for hotspot network access. For example, Google's MVNO Google Fi has a deal with unnamed partners that allows subscribers' phones to connect to hotspot wifi networks for extra coverage, branded "Wi-Fi Auto Connect+" [2].

From the user's perspective (and personal experience), this connection is handled seamlessly and outside of the OS' normal wifi UI flow. If your phone sees no saved wifi networks but does see xfinitywifi (et al), it auto-connects in the background. Authentication with the captive portal happens automatically and non-interactively, presumably with some keys provisioned to your device. Your traffic is VPNed back to Google, so the router and ISP don't see anything. The only indication that any of this happened is that the "5G" icon changes to "W+"; the normal WiFi icon never shows up.

In the case of Google Fi, this is actually a pretty great deal for users. You get better coverage (especially indoors in cities, where cell service can be spotty) with no real downsides to you – your traffic isn't meaningfully exposed to another third party, it doesn't cost you extra, and you don't have to bother the staff for a wifi password.

But given all that, it's not a huge leap to believe that ISPs are also more than willing to quietly take LG's money in exchange for an all-access pass to their hotspot network.

It's easy to imagine that an evil company could ship their TV with a key that allows it on an ISP's hotspot network. No extra suspicious hardware like a 5G modem needed, and no MAC address spoofing required. The TV software could easily connect to the hotspot network with zero indication in the UI, and then use the surreptitious connection only to transmit your kompromat back to HQ.

If done intelligently, you'd never notice. By only transmitting spy reports (and not downloading new ads), even a keen observer wouldn't notice any behavior on the TV that would trigger "how tf did this thing get a network connection?" Even more insidious, you couldn't really see what traffic was happening, since IP packet captures on your network are useless in this scenario. You'd need special hardware to capture what the TV is actually doing on the air.

If truly evil, the software could do this hotspot dance even if you've configured your own WiFi network on the TV. If the software finds it can't reach ad HQ because you've firewalled it off, then despite your best efforts to contain the disease, it still can spy effectively thanks to your neighbor's router with its default-enabled ISP hotspot. Just do a daily upload while you're sleeping and otherwise sit innocuously on your locked-down VLAN.

Everyone evil wins: ISP collects that sweet bonus revenue at zero marginal cost, TV manufacturer doesn't have to foot the hardware bill for millions of 5G modems or (relatively) expensive cellular agreements, and advertisers get to be that much more creepy targeting you. I'm sure the wanna-be despots of the world don't mind the spy apparatus being built for them either, conveniently under the control of easily-compelled corporations.

--

Now to be clear, I have no proof that any TV manufacturer is surreptitiously connecting to an ISP's hotspot network in order to exfiltrate your data. But all of the building blocks to make that happen provably do exist, and I seriously doubt that capitalism will allow them to go unused.

It's anything but far-fetched.

[1] eg https://www.xfinity.com/support/articles/xfinity-wifi-hotspo... and https://www.spectrum.net/support/internet/spectrum-mobile-wi... and https://www.optimum.net/pages/internet/hotspots/faq.html

[2] https://fi.google.com/about/wi-fi-auto-connect-plus and https://support.google.com/fi/answer/10091529?hl=en


And your credit card company investigates and accepts your chargeback requests?

I’m struggling here:

OpenAI’s primary bet here has been chain-of-thought monitoring (opens in a new window). It is based on an appealingly scalable idea: a lot of the model’s capability comes from a verbalized reasoning process (chain-of-thought). If we scale optimization on the outcomes of that process, but do not supervise the process itself, that chain-of-thought has no direct incentive in training to hide any misaligned ideas or objectives.

If we’re not supervising the process, but just the outcomes, doesn’t that do just the opposite of what he says? Give incentive to the model to hide misaligned ideas and objectives in the chain of thought that’s not being supervised?

When we shipped o1‑preview, we deliberately designed the product to hide the chain of thought , to protect it from supervision pressure in the long term2. In development since, we have strived to maintain the rule of not supervising the reasoning process. CoT monitoring became an extremely important tool for us in studying how our models generalize from their training distribution, allowing us to observe and analyze not only their actions but also their internal process.

Aren’t these two sentences in contradiction with each other?


I think they're saying the model is designed to hide the chain of thought because this prevents it from learning how to pursue goals and motivations in a way that doesn't show up in the train of thought.

For example, if somebody asked the AI to "build me the bomb", they might see in the chain of thought something like "It seems the user is talking about nuclear weapons. Nuclear weapons are dangerous.", followed by the chain-of-thought monitor interrupting model execution and aborting the request. Then the user might make a blog post about this behaviour. When OpenAI next scrapes the internet for its next training run, the model will now learn that if it wants to build the bomb, it must not think "nuclear weapon" or risk being cancelled.

So the risk is that the model might learn exactly how its being monitored. The only way to prevent that from happening is to hide the details of the monitoring both from the model and from the larger public.

Also, you don't want to punish or reward the monitoring being triggered during training, lest the model learn passim how to avoid the monitor.


A lot of skepticism here, but, anecdotally, we bought a Prologue without even test driving a Blazer.

I knew they were essentially the same car and that maintenance-wise it probably made more sense to get the Blazer from a GM dealer - but it lacked CarPlay so we didn’t consider it.

I can’t imagine we’re the only ones.


I made the same choice. Also did not even consider the Blazer knowing they are identical.

It looks like someone is downvoting all the people who say they wouldn’t buy a car without CarPlay in these comments!

What a weird attitude to have.


Is this the only piece of hardware that can be repurposed like this or are there other crypto mining (or AI?…) devices that have similar potential?

I actually got very interested in this sort of hardware repurposing, if someone know of any kind of place where people discuss and keep track of this, please share!

There were cheap nvidia crypto GPU's based on the A100 that recently got unlocked. They are no longer cheap.

I wonder if the fact that these random obscure wikis are being used implies that the agents first tried more obvious services like Tumblr, Neocities, Blogger, Reddit etc. [edit: oh, or HN obviously!]

It just seems so likely - trying the more obvious paths first is surely what they’d do?

I guess the only way we’ll find this out is if those services announce logs.


Note that this post was written twenty years ago, in 2006 - it just wasn’t published until now.


Thanks! Year added above.


He says it’s a journal entry from around 2006, but adding 2006 to the title feels slightly out of place to me in this case because this tweet in 2026 is publishing a journal entry that was from what I gather not previously published. (Assuming that when he says journal he is referring to hand written journals he has been keeping.)

So it seems to me that authored year is 2006 and publication year is 2026. And usually when you guys or the users put the year in the title, it has to do with year of first publication.

But I am probably overthinking it or I have an incomplete impression of how to interpret what you and others mean when you put the year in the title :p


When the two are different, we prefer the authored year over the published year, since the purpose of putting years in titles is to cue the reader that (1) this is historical material as opposed to current-internet-firehose, and (2) the context it dates from.


The USA started from and has come back from way worse in the past.

Some dark, dark things happened in the USA, and almost every progression had a corresponding backslide - but the tick-tock has always ticked further towards a freer, more equal, and more equitable society.

Progress doesn’t always (ever?) require complete collapse.

I’m willing to hope this era is another ‘tock’. But that does require people to not just give up (or even work to accelerate the backslide?!) as you seem to be suggesting is the best course of action.


>but the tick-tock has always ticked further towards a freer, more equal, and more equitable society.

This is a popular sentiment, not a statement of historical fact. Arguments both for and against this are credible.


You can make a credible argument that the American society is less free, less equal, and less equitable than it was at its founding?

There are just so many ways in which this seems crazy to me. I feel like you think you’re luring me into some sort of rhetorical trap - but to pick the two elephants in the room, a large proportion of the population was literally owned by other people, and only white male landowners could vote.


That wasn’t the claim: it was that the tocks always outpace the ticks.

One area that this extremely obviously does not align with is immigration. Privacy is another area in steady decline for generations.

It’s very reasonable to consider that in many areas we may regress to a mean somewhere in between founding days and the peak.


Exactly. It is a high dimensional space and it depends which sample you select


Income tax did not exist at the time of founding. The freedom to spend freely from the fruits of one's labor has been lost.


I don’t think any reasonable person would think I am claiming that every ‘tick’ makes things better along every possible axis for every possible person. It’s pretty obvious that judging whether America’s ‘ticks’ have been towards ‘a freer, more equal, and more equitable society’ means considering the state of society in aggregate.

On your particular example, there are lots of debates to be had about forms of taxation and which kinds are ‘fairer’ - but more importantly, and more overwhelmingly: eighteen percent of the population of America was literally owned by other people in 1790. They couldn’t ‘spend freely from the fruits of one's labor’ to any extent at all.


Your line of argumentation asserts that freedom has increased over time with allowances for any form of subjugation by the government short of enslavement. I don't doubt that you're making a good faith argument, but it doesn't engage with the real problem of abuse of power and disenfranchisement of the people because no matter how bad it gets for the average citizen it will never be as bad as chattel slavery. It's hard to argue in good faith on a nuanced issue with someone who has a one liner mic drop response to everything.


Do you honestly think that our society was more (or as) equal 200 years ago than it is today?

Or even 50 years ago? Even in the 1970s, there were places in the United States that women couldn't get a checking account without a man co-signing on the loan.

We can certainly take issue with how rich countries oppress and exploit poor countries today, but you can't honestly say it is worse today than it was during colonialism.


Prior to the enclosure period of English common law, land was assumed to be available to the private use of government subjects. The American West was the same before it was swallowed by the US government. The current situation is provably less free along this dimension. You could argue that this is not important relative to other things (this is a value judgement), or that things done outside of the state are outside of the discussion (this is a a fallacy, a lot of things once outside of the state find themselves inside it today), or you could say that this does not account for intra-community conflict between settlers and natives (this is a straw man)


Life in Nauru today seems much worse than the colonial period


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: