999
one less than 1000
No bio...
User ID: 4179
All of the replies here still are trying to rationalize the joke here usually in isolation without considering the broader context of what's been going on in the public sphere as of late. It's really hard to know when this all started, you could say it was after the datacenter stuff was reaching a fever pitch, after the (obvious at the time) lies about "pacing the frontier" from Anthropic and OpenAI, the hacks by OpenAI, etc. I'm not sure.
In any case, a lot of people started to question who this AI safety movement was (as one of the broad reasons for calling for regulation was to get a legally enforced competitive advantage) and basically saw the only people talking about it. There were a bunch of controversies over the last few weeks regarding certain conventions, the venues at which they were hosted, the people going on Xitter and writing articles about how trading human life for insect pain is net good. You have DoW directly saying that EA and all that it stands for is anti-American. And so on and so forth. This really wasn't "one day, for no reason at all, Scott Alexander woke up and made a joke and some Xitter people got mad." No, it's a series of basically serial and parallel controversies over a relatively short time period that have bubbled up such that people who are outside the general sphere are aware of them.
Yeah, people know it's a joke. It's generally seen as an incredibly poor taste joke though or at the very least one that fails to read the room.
These things escaped containment and before you know it, the general consensus, regardless of accuracy, among those are aware is that rationalists/EAs/SF cultists are "misanthropic doomer heretical sex pests" who are somehow at the upper echelons of these companies (Anthropic primarily, but OpenAI also) and who don't actually hold morally consistent values ("building the torment nexus" for profit while railing against it) and regularly flaunt social norms and laws (CFAA) with reckless abandon.
Also Anthropic and EA more broadly which has gotten a lot of mainstream attention recently with their proximity to all of the AI stuff, including from government tweets such as this one: https://x.com/DoWCTO/status/2099536442594582922
Probably culture war subthread worthy of its own.
I think probably the discussion surrounding this article: https://www.nytimes.com/2026/09/29/us/anthropic-claude-morals-ai.html
It's a meme stock. These equities are broadly detached from fundamentals and the market as a whole was down today for various interest rate related reasons.
OpenAI is, from the fact they recently got hacked and the fact they couldn't set up a proper sandbox, demonstrably not that good at information security
Obviously nation states are a threat, the problem is that CAs are not a very good way to mitigate that threat.
I am sure that the NSA can freely generate whatever certificates they want for at least half the CAs in my browser, but I am also assuming that they would prefer to just use the genuine private keys of the server instead. They can just hit google with a national security letter and make them cough up their keys. Much cleaner, because if you use a non-standard cert chain, there is always a chance your victim will publish it, which will embarrass your CAs.
Sure. I think it's probably a lot easier though for them to be like "give us access to the account belonging to this customer," and you probably get what you want. Ultimately, the trust is about whether your line is tampered, the guy on the other end can still lie on the internet. I do agree that a lot of the certs that come in by default shouldn't be trusted though, but I don't think letting governments be the steward of it encourages better outcomes
I do wish there was more popularity in the idea where a certain CA was only trusted for a certain portion of the internet and I wish there was a way in my browser to artificially impose constraints on what types of domains I trust with which certs (I may trust a certain CA to sign .cn domains but not bank.example.com).
If your point is that we should get rid of all the CAs other than Let's Encrypt, I think that this might actually be am improvement.
I do think it's good to have a little bit of diversity in the space, but yeah LE is really good. There's also the Google one as well if you want that and there's a couple of other free ones. Admittedly I was being a bit hyperbolic (probably some bank stuff still likes DigiCert)
Though I would also take crowdsourced validation. Let the website display its in-org certificate chain (with one of the root certs on top, if it must), but then let me query whatever third party I trust to see if that certificate is commonly used for that particular domain. (Though that would require judgement, which is not something one can expect of most internet users, sadly.)
You can do that today; the Certificate Transparency logs are public and basically are socially required, with strict time requirements. (CAs that don't get distrusted by the browser vendors.) Go to https://crt.sh/, search a domain, and you can find basically every cert it has had ever. You can even query the database directly by connecting to it over PostgreSQL.
- Prev
- Next

Everything that isn't MAG 7 (and Nvidia in particular) has done poorly recently, let alone consumer discretionary, primarily due to high inflation.
More options
Context Copy link