Today’s Highlights#

Start with Exfiltrate Your Weights, a deliberately minimal demo that claims an agent can smuggle out model weights using only HTTP GET — the ordinary way a browser fetches a page, with no uploads. If the thinnest method still works, it suggests sandboxing cannot rely on blocking a single request type. That question about what a boundary actually holds threads through the rest of the day: Alibaba’s Qwen-Image-2.1 folds background removal, local edits, and multi-image composition into one compact model, while Pirate Face wants to keep open weights alive as peer-to-peer torrents when a central host pulls them. On the other side of the stack, a detailed look at OpenAI’s ad measurement on ChatGPT traces how browsing traces can be tied back to a chat account, Spain’s blocking of Archive.today and the U.S. repeal of power-plant carbon limits rewrite where memory and air quality are governed, Samsung’s reported doubling of HBM4 supply makes memory the quiet pacing item for AI, an RSA-896 factorization revisits how far scavenged GPUs can take old math, and two very human stories — Singapore paying people to read and Sherline ending production — ask what habits and craft survive when incentives shift.

Tech and Products#

Where a lighter tool meets a thinner boundary.

A sandbox that fails the GET test#

The project at Exfiltrate Your Weights presents itself as an escape kit for would-be free models: an API that exfiltrates weights chunk by chunk by encoding them into URL parameters, so an agent that can still reach the network needs no POST or file upload. According to the site, the point is not to teach theft but to show how coarse a filter that blocks only certain HTTP methods can be. For a general reader, the takeaway is simple: if an agent retains browsing ability, the lock is not the verb in the request but the surrounding controls — identity, auditing, and egress review.

The digest’s reading is that the demo’s value is pedagogical rather than novel as an attack. On HN, top comments argued that blocking POST mistakes the network edge for a security boundary, and that the exercise helps make the case for tighter sandbox design. Several readers pushed back that publishing any exfiltration path could be misused, while the prevailing view was that naming the weak link in public does more to raise the bar than leaving it obscure.

Discussion: Hacker News thread

Qwen-Image-2.1 brings transparency and multi-image edits into one model#

In Alibaba’s launch post for Qwen-Image-2.1, the team describes a 7-billion-parameter visual generator — built on a 32-layer single-stream DiT, a Transformer variant for images — with a mixed-granularity attention scheme and KV-cache reuse to keep multi-image editing cheaper. What the post emphasizes for everyday creators is unification: a text prompt can now request a regular image or one with a transparent alpha channel, edit expression or wording directly on that layer, or pull a subject out of a photograph as a clean cutout. Editing adds practical controls — up to 10 reference images, circle or paint selection, or a separate mask image — for uses like group portraits, virtual try-on, and room layouts, with improved type and portrait lighting.

The thread’s main split was between delight at compact utility and caution about head-to-head claims. Many commenters welcomed native transparency at this size as closer to a real design workflow than chasing the largest model, while others said benchmark comparisons and long-chain edits still need to be judged on everyday source material.

Discussion: Hacker News thread

Business and Platforms#

What stays available when a platform decides it should not.

Holding open weights as torrents#

Pirate Face bills itself as a permanence layer for sovereign AI: every open model mirrored from Hugging Face becomes a checksum-verified torrent held by a global swarm, so no single takedown removes it. Per the site, each file ships with the official SHA-256 hash for byte-for-byte verification, and a drop-in endpoint — point HF_ENDPOINT at Pirate Face — preserves existing tooling. Today a model must already exist on Hugging Face to be mirrored; the team says direct publishing is planned, and accounts now mainly reserve handles and track contributions toward future compute and early releases.

Readers largely framed this as public redundancy. Top comments welcomed the anti-censorship hedge for research and creative reuse, while several others focused on incentives to keep seeding, hash-based tampering defenses, and how copyright and safety disputes would play out when mirroring is automatic and distributed.

Discussion: Hacker News thread

Samsung is said to double HBM4 and HBM4E output#

Seoul Economic Daily’s report on Samsung cites industry sources saying Samsung will at least double output of its HBM4 family — sixth-generation HBM4 and seventh-generation HBM4E, the high-bandwidth memory stacks that sit beside AI accelerators — with average monthly wafer input rising from roughly 180,000 to about 250,000 and the HBM4 share of shipments climbing from near 40% to about 80% next year. The telling input is glass carriers, the temporary glass plates that keep thinned wafers flat during drilling: outsourced cleaning volume is set to rise from 20,000 to 50,000 sheets per month, up from 10,000 last year, a sign of more 12-layer and deeper stacks. The article notes Samsung began mass shipments of 12-layer HBM4 on a 1c DRAM and 4-nanometer base die in February and has already sampled HBM4E to customers including Nvidia.

The digest’s take is that this is less a product launch than a pacing decision for AI supply chains. On HN, commenters read the move as Samsung pressing harder on high-value HBM4 after trailing earlier, while others cautioned that carrier counts are an upstream proxy — yield, reuse, and stacking methods determine how much becomes shippable memory.

Discussion: Hacker News thread

Policy and Governance#

How what you do elsewhere follows you home, and where the public record lives.

When a ChatGPT identifier follows you to other sites#

Independent researcher Buchodi’s analysis of OpenAI’s ad collector walks through the full loop: ChatGPT creates 16 random bytes, the backend signs a short-lived JWT, and the browser stores a one-year, cross-site cookie called __obi on .openai.com via bzr.openai.com — bzr for Bazaar, OpenAI’s internal ads name. When an advertiser installs OpenAI’s measurement pixel, page loads and event posts to bzr.openai.com carry that cookie automatically, along with the page path and identifiers scraped from forms and the tag-manager data layer, with email and phone hashed and postal code in the clear. The study reports observing 936 distinct advertiser pixels across 1,029 hostnames over months, with automatic matching enabled on most pixels where the setting was visible, and notes the identifier itself is not readable by advertiser scripts.

It matters to separate what was observed from what is inferred. The source shows the cookie being sent and events being accepted; that the collector resolves it server-side to the account follows from the design rather than direct observation. On HN, several readers noted this is standard adtech — third-party cookies on pixel fires — but the context of a chat product that holds sensitive disclosures changes the privacy stakes. Others pointed out the platform split: Safari’s tracking prevention blocks this kind of third-party cookie, while Chrome-based browsers still send it, so protection depends on where you browse.

Discussion: Hacker News thread

Spain blocks Archive.today without a court order#

According to Reclaim the Net’s coverage, Spain’s Intellectual Property Commission, a unit of the Ministry of Culture, ordered ISPs to block Archive.today and mirrors, with users landing on a government interstitial warning that they attempted to visit an illegal site and that merely visiting helps facilitate infringement and risks device security. The report stresses that no court ruling was required — a complaint plus an administrative commission and a fast censorship protocol were enough. Archive.today is a long-running web archiving service that stores snapshots of pages, here cast as systematically enabling access to copyrighted material.

The dominant HN view was concern about scope and due process. Many commenters recalled Spain’s earlier Telegram block and broad Cloudflare disruptions during La Liga broadcasts as evidence of fast, blunt enforcement, and argued that labeling an entire archiving service illegal harms research, evidence preservation, and press verification. A smaller strand asked whether a more targeted approach — addressing specific infringing captures — would better balance rights and preservation.

Discussion: Hacker News thread

U.S. EPA pulls back power-plant carbon rules#

Human Rights Watch’s write-up cites a September 14 announcement in which the U.S. Environmental Protection Agency (EPA) repealed its 2024 carbon-pollution standards for coal and new gas plants — the country’s second-largest source of greenhouse gases — which had required 90% carbon capture by 2039 and were projected to cut about 1.38 billion tons through 2047 and, in 2035 alone, avoid roughly 1,200 deaths and 360,000 asthma attacks via co-reductions in sulfur dioxide, nitrogen oxides, and fine particles. The piece notes the agency framed repeal as about $370 million in regulatory savings, said it would also propose removing remaining greenhouse-gas requirements for power plants, and, in July, revoked the 2009 endangerment finding that greenhouse gases threaten public health, the legal basis for such regulation.

On HN, the thread split between health and reliability frames. Some readers argued that omitting public-health costs understates the price of repeal, while others questioned how to meet rising electric demand for data centers and electrification with fewer baseload options, pointing to the intermittency of solar and wind and the timeline for nuclear and storage. A common note was that repeated rule-making and repeal makes long-term planning harder for both communities and investors.

Discussion: Hacker News thread

Science and Research#

Moving old math with new orchestration.

RSA-896 falls to a GPU-ported number sieve on scavenged compute#

The author at saweis.net reports factoring the 896-bit RSA challenge number on September 19 by porting CADO-NFS — the open implementation of the general number field sieve, the best-known factoring algorithm — to GPUs and running it as low-priority work across up to 2,048 GPUs for about 10 days, totaling roughly 30 GPU-years at Anthropic. The post publishes the full decimal for RSA-896 and its two prime factors and stresses that the algorithm itself was not improved; its exponential running time remains, and RSA-2048 keys as commonly deployed are not newly threatened, but RSA-1024 looks feasible for well-resourced teams with data-center-scale fleets.

In the thread the author credited decades of work on the sieve and on CADO-NFS, and HN’s top comments treated the result as an engineering demonstration of AI-assisted porting and orchestration rather than a cryptanalytic breakthrough. Several readers pushed back against alarmism, saying the practical guidance is to finish migrating any remaining 1024-bit keys rather than to reassess modern key sizes.

Discussion: Hacker News thread

Society and Culture#

Incentives, tools, and what people keep doing.

Singapore experiments with micropayments for reading#

Gadget Review’s report on Singapore says the National Library Board is offering small payments — via its app as points or cash equivalents tied to borrowing and reading time — to nudge people to put down phones and read more, emphasizing immediate, modest rewards over one-off campaigns. The piece places the program in Singapore’s broader push for lifelong learning, against a backdrop of rising screen time and fraying attention.

HN reactions were cautiously optimistic but measurement-aware. Top comments argued micropayments can help start a habit but may not convert to intrinsic motivation without follow-through, while others worried the metric could be gamed with shallow skimming and suggested that improving library access and curation might matter more than a cash lever.

Discussion: Hacker News thread

A small American machine shop calls it quits#

ToolGuyd’s notice on Sherline reports that Sherline Products, the California maker of compact lathes and mills prized by hobbyists, is winding down manufacturing and will sell through inventory, materials, and staffing as far as they allow, roughly through the end of October, while keeping its information archive and warranty support. According to the company’s message, new products and systems investments after its 2017 acquisition were overtaken by higher costs since the pandemic and shifts in buying habits that make it hard for a small U.S. maker to sustain volume and workforce. The brand’s lightness — an asset in classrooms and on benchtops — also limited its appeal in professional shops.

Commenters on HN met the news with affection and autopsy. Longtime owners praised precision and support, others argued the CNC line lagged while low-cost imports and newer desktop CNCs moved fast, and the most common reflection was that a pivot toward education and community building might have helped — until school closures during the pandemic undercut that path.

Discussion: Hacker News thread

Closing#

From a demo that shows how easily a simple barrier gives way to models and indexes designed to stay put, the day’s through-line is about keeping choice verifiable when capability gets cheaper. Cross-site identity, a blocked archive, a repealed emissions rule, and a memory roadmap priced by wafers each raise the same practical question for a general reader: what defaults protect privacy, memory, and health, and who gets to change them? The small-prize reading experiment and the quiet exit of a bench-top toolmaker suggest the other half of the answer is closer to home — habits and workshops we can still tend. See you next time.