Hacker Newsnew | past | comments | ask | show | jobs | submit | devy's commentslogin

Doubleword AI is conducting a classic textbook marketing trick called newsjacking.

Writing a detailed technical post behind the news of Kimi K3 and KDA algorithm with an audacious title like "You Could Have Invent Breakthrough It too" they are pre-filtering out the ones who couldn't comprehend with quick read (myself included) and attracting the ones who agreed with the blog post. At the end with a strong CTA to promoting their 10x cheapter open weight model AI inference and hiring too.

Good job Doubleword, I see what you are doing there.


“Kimi Delta Attention” because “Kimi K3 Delta Attention (oh that’s just our little internal name for it as a joke)” passes no sniff tests.

(HN titled updated from previous “You Could Have Come Up With Kimi Delta Attention” … gotta check if someone maintains an “Editing The Gray Lady” for HN, for title histories and derankings)

lol - co-founder of Doubleword here. honoured you think we have sophisticated enough marketing to 'newsjack'. What actually happened is my cofounder wrote it over the weekend because he's a mega-nerd and put it live yesterday. I hadn't even read it until I saw this hacker news thread lol

We're just a group of guys and gals who like inference!


The blogs from doubleword are indeed full precision. A great team doing a fantastic job.

So you think JetZero's blended-wing body (BWB) aircraft design will be killed by regulators? Why?

Btw, it will take hydrogen propulsion for their planes to be zero CO2 emission.


This is the original blog post where Terrence explained his thoughts where the ChatGPT conversation was originally referred from:

https://terrytao.wordpress.com/2026/07/21/a-digestion-of-the...


Docs full of emojis, this is another AI slop?!

Tangential note: there is already a community effort[1] to rewrite GNU commandline tools into Rust and Canonical shipped the rust version of the /bin/utils in Ubuntu 26.04 Resolute Raccoon by default[2] in their "oxidizing" initiative.[3]

PS: Linus Torvalds has confirmed that the existing Linux kernel will never be fully rewritten in Rust.[4] Let's see how well that statement age.

[1]: https://github.com/uutils/coreutils

[2]: https://canonical.com/blog/canonical-releases-ubuntu-26-04-l...

[3]: https://discourse.ubuntu.com/t/carefully-but-purposefully-ox...

[4]: https://news.ycombinator.com/item?id=41355731


As soon as Linus retires, there will be an initiative to rewrite the Linux kernel in Rust assisted by LLMs. Either that, or some company will fund a fork before that. Imagine, man pages full of emojis!


Linus is supportive of Rust and uses LLMs.

The reasons to not have a full-Rust Linux kernel are over more important, real engineering things. (Platform support being the big one.)


> Platform support being the big one.

And between rustc_codegen_gcc, projects like https://github.com/FractalFir/crustc, the ongoing addition of backends to LLVM and Rust, and the eventual removal of obsolete targets as hardware goes away, that's less and less of a problem.


I certainly don't think it'll be a barrier forever, for sure.


Since the Rust support in the kernel is not optional, it already has an impact on platform support, no? Or maybe they are using the gnu toolchain to avoid that?


Rust support in the kernel is still optional; it's currently only allowed in drivers, and drivers only use Rust if they can accept running only on current Rust targets (which is not a substantive limitation).

I expect Rust to eventually get used in the core kernel, or in drivers that everyone wants to use (e.g. some new bus or device on most new hardware), but I expect that by the time that happens the set of targets supported by the kernel and the set of targets supported by Rust (including through things like crustc and codegen_gcc) will have converged sufficiently.


The submission link should have been the original editorial piece at

https://www.thedeepview.com/articles/how-apple-s-decade-long...


Yep. The 4 Samsung SSD 990 PRO 4TB NVMe SSDs are $1100 apiece. Yikes!

https://www.samsung.com/us/memory-storage/nvme-ssd/990-pro-p...


> At this point the only OS with a consistent look and feel at all is Mac.

Apparently, NOT! Apple's controversial Liquid Glass UI disrupted their long-standing Human Interface Guidelines by prioritizing cinematic aesthetics (transparency, refractions, and blur) over core tenets like readability, contrast, and content deference. Critics highlight that transparent, light-bending panes frequently clash with underlying wallpapers or videos, causing text and buttons to become illegible. This is a HOT topic in recent WWDCs and amongst UI designers.[1]

[1] https://blog.prototypr.io/why-apples-liquid-glass-design-is-...


Gary Bernhardt's Wat lightning talk [1] was my favorite of all time.

It's only 2 years predates this talk in the title.

[1]: https://www.destroyallsoftware.com/talks/wat


AI and their armies of agents has been making the job search much much worse for both employers and employees - the reason is simply, spamming becomes extremely cheap and easy - sometimes it's literally one prompt away.

Find offline channels to connect with potential employers in person is your best bet, IMO. Good luck job search!


I can't believe promoting the QR code-based challenge as the agentic way of fraud defense. Having non-human readable data input is dangerous if somehow the QR code is comprised with a zero-day URL, it's game-over.

Note: I know QR code is ubiquitous these days, but still blinding scanning a QR code to go to accessing an URL is like running a binary downloaded from the internet.

Note2: yes, the `curl $URL | bash` installation approach is essentially just that, yet somehow became popular.


But a QR is a URL. If visiting a certain URL pwns your device, complain to whoever made the device or browser.

Not that I like this thing at all. But using a QR isn’t exactly why it sucks.


It's a URL that you can't read. It's literally exactly what we tell people to not do to be secure. LOOK AT THE FUCKING URL BEFORE YOU VISIT THE SITE.


No, we don't, or shouldn't ask people to check the URL itself, because of homonym attacks are a thing. Goal is to make sure that your credentials can't be compromised by surfing the wrong website (e.g. by using Passkeys instead of passwords).


IDK about how you scan them, but when I scan one with my camera, I see the top domain part (e.g. it would show 'ycombinator.com' for a link to this page) and have to tap that to open the link. So, that not only satisfies the "can look at" part, but also neutralizes some of the deceptive URL tricks like the ol' `google.com-secure-signin.php-sfd7sdfj.xyz/login.html`.


Whoever told you that is the same person that advocated complex password rules with montly resets and no repeats.


If you really think that's true, I have some QR codes for you to scan.


Please, share them.


Right! Let me check the URL before clicking the "confirm your account" link!

https://rt434.mjt.lu/lnk/GN2PVLyAIiUHuMqkGcjHkjkcRBtF/zJfB7p...

Oh wait, never mind. I guess I won't be signing up for electricity, then?

Also, the vast majority of people don't know that google.com and loginto-google.com aren't the same website, or that google.com.securesigning.net isn't real Google.

If your device gets busted by opening a URL, without any further confirmation or user interaction, your browser/camera app/third party app is broken.


What's the point of confirmation or user interaction, when nobody knows how to read a URL, and they just click the goddamn accept button?


The user doesn't need to know the exact URL to confirm an interaction they've just started.

The point of the confirmation is 10% account creation and 90% confirming that the user knows their own email address and can type it in correctly. That's actually more challenging to the wider audience than you might think.


> Oh wait, never mind. I guess I won't be signing up for electricity, then?

You ~~will~~ should be picking up your phone and calling the electrical company to confirm and to tell them their links are nonsense. Couldn't bother with AI agent on phone, or 60 min waiting queue to a human? Fuck it, don't pay the bill, figure it out later.


This advice sounds like nonsense. CS has neither knowledge of what layers of enterpriseware has wrapped their links, nor the domains that software uses, nor any control over those decisions by software engineering or marketing (or perhaps even more removed, some third-party electricity account management platform that they buy as a service).

You certainly could operate on policies like this, but I think most people prefer to spend their time differently instead of arguing with strangers who don't have any way to solve your problem.


Their customer support people don't know what I mean and they especially don't have any power to change this.

The problem isn't paying the bills (I can't recall the last time I ever needed to do that manually), the problem is that pretty much every service uses trackers and shorteners. The only way to opt out is to opt out of society.

Maybe I should, but this "read the link before you click" advice isn't just geared towards hardcore privacy advocates. It hasn't worked in ages. It also doesn't help that companies like Outlook rewrite links to make them redirect through their malware scanners as well.


2020s will be remembered as the decade when companies stopped behaving in a trustworthy way, and normalized scanning random QR codes, downloading random apps, uploading photos of your face or documents, all as strange convoluted "verification" procedures. Scammers will love this


Companies were doing this all along. The 2020s will be remembered as the decade when we realized, too late, that the world began ending in the 2010s.


Unregulated greed doesn't care if every user gets robbed and their identity stolen.


Whats to stop malicious actors (bad extensions, compromised cdn, etc.) from painting over the qr code or injecting their own? This is so incredibly terrible.


Doesn't have to even be that advanced, people get conditioned to stuff like reCAPTCHA and friends & Cloudflare's interstitial landing page (when "I'm under attack" mode is on) and they won't bat an eye. That's how we get people piping `curl | bash` into their terminal to "solve" fake challenges.

As a side note though, I recently have tried to turn CSP on a website I run and the amount of garbage I see in the reports is astonishing. There's some noise from things like OpenDNS intercepting YouTube or Social embeds for people using the work-friendly or family-friendly options, but the sheer amount of things attempting to phone home to random URLs and random extension scripts injecting ads into the site would astonish you. My mental model of "toolbar hell" from the Windows XP days being gone has completely shattered.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: