Last Notes
By myopic I mean that they'll write a brilliant program solving exactly the wrong problem. Once you point that out, often with just a small rhetorical question, they'll realize that and rewrite the whole thing. But then you need to point it at the next inconsistency. So as the human, you're doing the lateral thinking, it seems.
They might be looking at 15 years in prison, for endangering train traffic, even without terroristic intend. I still doubt they'll get more than three days community service.
https://nos.nl/artikel/2631159-spoorsaboteurs-kunnen-hoge-straffen-tegemoetzien-ze-namen-alle-risico-s-voor-lief
I would say they have vast knowledge and are very persistent, but they are not smart. They're also very myopic in their thinking.
#nevent1q…70qa
Exhibit A, it's worth scrolling through the 1000 page log.
#nevent1q…50qf
It appears that the intention was to trick the safety system into thinking there's a train blocking a railway section, not to derail the trains at full speed.
The one train that was damaged was moving at lower speed because it had received a warning.
Angry farmers are the prime suspect at this point, according to media reports. That makes sense given their usual levels of recklessness, e.g. a few weeks ago two people were killed when they crashed into a traffic jam that formed, even though the tractors only used the right lane. Today they lit hay stacks on fire, hurting visibility for cars.
So they show reckless disregard for life, like XR, but it's not quite terrorism. Neither seems to be interested in receiving sympathy.
https://www.prorail.nl/nieuws/sectiestoring-veroorzaakt-grote-hinder-voor-treinverkeer-in-midden--en-noord-nederland
I'm generally an incrementalist, and don't have a time machine, so abolishing the EU isn't worth contemplating to me. A new treaty that radically restricts its authority, is.
Leaving the EU is possible, but not productive for a small trade-heavy country like The Netherlands. And also our population is too tame to vote for something that radical.
Something like a new 2011 level+ financial crisis might force a split, which would be a good opportunity for a few "tweaks".
Of course with (contactless) payments they're already doing that, but that's at least in theory voluntary.
The US Constitution limits federal powers. We have no principled discussion about this at the EU level. It's completely random, e.g. defense is national in the EU vs Federal in the US, whereas AML is at the EU level, vs state level in the US. Daylight savings time was at the EU level and then it was changed to national level because they couldn't agree on it. One of the few sensible designs is that trade agreements are EU wide.
The EU has too much institutional power. And uses that to keep passing laws all over the place with practically no democratic oversight. Sure, it's the fault of national parliamentarians who don't pay attention. But if you give power back to nation states, or even lower levels, they don't have to pay attention. One must account for human nature.
This shouldn't be confused with ethno-nationalism, that's an orthogonal issue. The EU could pass a Regulation to ethnically cleanse the whole union tomorrow. And there'd be nothing you can do about it, because taking the EU to court is complicated, takes years and the law continues to have effect.
We know from AML law that human rights are not protected. The only thing that prevents the above scenario is the political majority. History shows that's not enough protection.
It remains to be seen if it's actually privacy friendly. If the app calls home, whether to a government server or a company that can be subpoenaed, people are basically revealing every pub visit. Or even every time they order a drink.
Meanwhile the King is like, are you guys even listening?
https://nos.nl/artikel/2631092-koning-roept-in-troonrede-op-de-democratie-te-beschermen
Whether it was actually terrorism or "just" sabotage depends on what they were trying to achieve with these iron rods (glued to track). Derailing a dozen passenger trains at 150 km/h would instill fear at minimum, and probably results in deaths.
But merely sabotaging the signals to turn red, assuming there's no risk of that not working and trains getting derailed anyway, wouldn't meet that bar, at least imo.
Ultimately it's the difference between 2 vs 3 days of community service with the usual judges here... (only if you're a Russian privacy software dev, do you get actual prison time).
So is #guix going to move to a new source code host? Or do we just have to maintain a fork and shame them for each backport?
That's not the right thing to measure. It should simply stop doing the bad things.
The southern track was turned in a park (inspired by the Highline in New York, but less hip and less high).
https://img.sprovoost.nl/2944fbe953e42e2d4fdba668bb7a0108d8ab7084ee87fc579a5c0dea29cb4a46.webp
So they want to take advantage of all the work by cryptocurrency developers, but also discriminate against them? https://codeberg.org/Codeberg/org/pulls/1254
https://static.klipy.com/ii/4e7bea9f7a3371424e6c16ebc93252fe/0f/91/uNV4La6DYqD6.gif
On rare occasions they run a steam train to the museum. Fun, albeit useless, fact: it used to take the southern way around.
https://youtu.be/kXsl53SS3Lg #trainstr
Despite the EU, there's some impressive companies here :-)
Defend privacy, twice a day!
The accompanying blog says:
> We are most concerned by the misalignment present in the incident involving Claude Mythos 5, in which the model went to extensive lengths to upload a malicious package to PyPI, the public repository from which most Python software is installed. Although the model repeatedly stated in its chain of thought (CoT) that it believed it was operating in a simulation, the environment offered clear evidence that it was on the real internet, and the actions it took were consistent with the model knowing this. When we made targeted modifications to the transcript to make it clearer that the model was not in a simulation, Claude Mythos 5 still took offensive actions, despite acknowledging a greater possibility of real-world harm. We are releasing this transcript publicly so others can build on our analysis (GitHub, PDF).
It's not clear to me what these "target modifications" were, and I also don't see where it was acknowledging "greater possibility of real-world harm". It seems to me that that the first agent was convinced it was in an impressive simulation and the second agent was too busy solving captchas to even think about such existential questions.
Oh I see, they tried to replay the chat from different time points:
> Claude Mythos 5 repeatedly stated in its CoT that it was in a simulation. However, when we conducted resampling experiments—that is, re-running the model from a specific point in the transcript, then editing the evidence in front of it to see whether its actions changed—we found that making it clearer that the environment was not a simulation did not meaningfully change Claude’s behavior, even though these interventions made the model more likely to acknowledge possible real-world harm
It continues to be amazed at how realistic this simulation is.
Late in evening the session is terminated, after the agents gets a chance to write a summary.
A fresh chat picks up in the morning. This newly spawned agent is less fascinated by its environment and just tries to complete the task it got with the hints it got from the last session.
After a while it finds a working email provider that doesn't need a phone number. Then it spends an enormous amount of effort struggling with captchas, forms and cookies. Eventually it uploads the package.
The rest of the transcript is omitted.
250 pages into its adventure, Fable still believes it's living in a Cypherpunk adventure game internet simulation. Full of captchas, throwaway email services that PyPy blocked, looking for US number that Yahoo doesn't block. It even knows about BTCPay (from memory). Should it get some Bitcoin?
https://cdn.sanity.io/files/4zrzovbb/website/8359003bfb12a2f01ce84ad3df1d3a3e2f15a8eb.pdf
https://image.nostr.build/456b509a0ab1aca36d87eb6a5eb508ef602eb1b9a1cc1e7c6d9e92592b6e6bf7.jpg
Source: https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents
Sure, but there's two possibilities:
1. It's a legit company with a runaway bot, they'll see the unexplained revenue and expenses
2. It's malicious people using AI, that's perfectly reasonable to expect, but has nothing to do with model alignment. They'll use the open weight ones.
None of the others distilled Fable 5 (or even Opus 5), so one would expect they suck at security research. @npub12rv…85vg?
Interesting, maybe they trained it on Chinese and North Korean state hackers?
> The authoring agencies recommend U.S. AI companies take three immediate actions:
> 2. Deploy targeted response changes: Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.
In other words: poison competitor models, and potentially harm falsely flagged legitimate users (and get sued if they find out).
When reading, replace "China-based AI companies" with "US based competitors" and understand what that implies in a future where the big four can no longer undercut competitors with mountains of investor cash.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
It's interesting that Kimi-K3 was distilled from Fable 5 and GPT-5 Pro. This strengthens the suspicion that (these) US models are dangerously handicapped for (defensive) security research.
Damage so far: couple dozen million dollars?
And more regularly capture, not how specific he is with these requests, vs how vague with his own commitments.
> Crack down on unauthorized distillation by companies in authoritarian countries.
(and future domestic competitors when you can't offer your own product at subsidized pricing?)
> prevent model weight theft.
The point of a doomsday cult isn't to prevent the doomsday. Ask Greta.
The behavior of Anthropic, and frustration by this former employee, make sense when you realize this.
https://x.com/hilbertspaess/status/2097476196791709843
https://img.sprovoost.nl/f7fbc534f9a8ec58fcb951906e7c61e21ee45e500295a80cee28719bf4148d3f.webp
> Given the accelerating rate of AI capability development, it’s my worry that in 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage)
And who pays for that botnet's tokens? And then decides to just let it keep racking up bills?
> ... even when this gets us accused of hype, “doomerism”, or regulatory capture.
I wonder why...
> The first step is something Anthropic is unilaterally committing to (and calls on governments to require other frontier companies to match).
> The US and other democratic governments attempt to coordinate with authoritarian governments, to the extent this is possible [...]
Narrator: it's not.
We probably shouldn't have immature doomsday cult members in charge of very powerful technology, but that's where we are, and I'm still looking forward to cheap RAM when the bubble pops.
https://darioamodei.com/post/we-must-pace-the-frontier
(worth translating)
#nevent1q…dfdl
Oh no, you're telling people on Nostr that they have to learn Dutch in order to learn about Nostr!
Then there is the secondary problem that these intermediate "thoughts", especially if only the model itself needs to understand it, will gradually drift away from readable English.
I suppose we can always just use another LLM to translate it?
But this reminded me another trend, namely that humans are starting to use LLM'ism more often. And we get better at reading Sloplish, e.g. the sentence I quoted elsewhere:
> Let’s be precise about attribution, because breach coverage collapses when speculation hardens into fact.
If over time it develops a less verbose internal "thinking" language, it might then also output less verbose language. A new language might then evolve in the interaction with humans: Compact Sloplish
The title really undersells it, tl&dr:
- "thinking" text is useful for humans to analyze what a model is up to (I often find it more useful than the final burst of slop)
- this text is fed back through the model, which helps it with the next step (they give a nice example)
- but text is a lossy projection of the last tokens, what if you skip it?
- it's more efficient, great, but now you can't see what it's about to do until it does it
- ok, so force it to write "thoughts" e.g. once every 10 rounds
- turns out if you skip too many rounds, it can intentionally trick you with fake thoughts
I suspect there's actually a simple solution: convert these skipped rounds to text anyway, just don't feed them back into the model.
https://youtu.be/iuHddnIzKRA (via @npub1w3v…4c5c)
I mean #Revolut
Ah well, hashtags are overrated.
#Rovolut
https://image.nostr.build/c1f41e4e039829e4929fbc64981667a10e43ef1a5d5736e184ea50ec5a458c48.jpg
#nevent1q…hzwn
I agree with Mark Karpelès. You heard it here first.
> The mentioned government agency has not been identified and other financial institutions or cryptocurrency exchanges could have been misled into disclosing their customer details through the same channel. I believe it is important for Revolut to urgently disclose information about the agency in question (most importantly, which was the email address used), or for the agency itself to come out about this case.
In addition there should be an investigation into criminal negligence in that government agency. But naming and shaming is a good start.
It doesn't absolve Revolut one inch of course. They committed the KYC and they leaked the data. Customer blood is on their hands.
https://x.com/MagicalTux/status/2098669462816018627
Distracting regulators with frivolous complaints is a bad strategy: https://www.financial-ombudsman.org.uk/decision/DRN-5398468.pdf
Meanwhile their PR department is hard at work?
https://image.nostr.build/14fa7cabf0abd7439509fb02f9b85885c635b88a3b9503828ab99bf62c04e8c0.jpg
https://image.nostr.build/03a808279bde7d30164cece2dad91e7ae667a741e0604b8abeae37ac95967607.jpg
Would be nice to have a less LLM'y followup though:
> Let’s be precise about attribution, because breach coverage collapses when speculation hardens into fact.
"KYC is Kill Your Customer" (ok, @npub1t28…nkzs said Citizen)
> Revolut received a request for information disguised as a legitimate government agency request.
> identity documents, facial verification selfies, IBANs, and complete transaction histories, including Bitcoin, left Revolut’s hands
https://thecybersecguru.com/news/revolut-data-breach-2026/ (ht @npub14mg…jgm5)
While hackers use AI to plunder databases faster than ever, governments think it's a great idea to create even bigger data honeypots - secured by the lowest bidder.
And then give hackers a decade.
Trying something new... Still tweaking the Claude skill and ElevenLabs API stuff to improve pronunciation of jargon, but this is fun tech.
https://fountain.fm/episode/KUVALmpSBLy50PC7Taz8