7/31/2026 at 6:28:17 AM
This is an important article. I hadn’t realized it was already getting this bad. Like a frog enjoying a nice warm bath ...> Most people do not switch their operating system or phone provider every week either. But even if you do not utilize that freedom, it matters because it changes the relationship you have with the provider and the provider has with you.
This is why it’s important to utilize your freedoms. Do NOT let yourself get locked into a particular ecosystem (this is why I’m building a phone app for OpenCode).
This article makes me reconsider using my recently acquired Codex sub in my home setup. I never liked that they hide the reasoning, but somehow overrode the cognitive dissonance because the performance is so good. But the inauditability is already a huge problem.
by solarkraft
7/31/2026 at 11:05:59 AM
People will keep hiding reasoning because it allows prompt injection https://arxiv.org/pdf/2603.12277, in addition to facilitating distillation (you don't pay the full cost of RL)by benob
7/31/2026 at 11:44:02 AM
Or they could store the reading traces and validate the user hasn’t edited them server-side? They could sign reasoning traces so they can’t be counterfeited?by rsfern
7/31/2026 at 5:06:52 PM
both openai and anthropic actually do this and let you as a harness store only the encrypted contents of thinking traces to be passed again on further turns but they only have the key to unencrypt it so its jibberish for final usershttps://developers.openai.com/cookbook/examples/responses_ap...
by tough
7/31/2026 at 2:36:55 PM
Why would the model bother to check signatures if it doesn’t check tags?by ses1984
7/31/2026 at 2:16:01 PM
The latter ("facilitating distillation") is a real concern from the labs I'm sure, but the first part I don't understand what you mean, or you misunderstand that paper, it's about "prompt injection" via manipulating the reasoning, not about the model reasoning by itself and somehow that leading to more prompt injections. They're quite literally maliciously rewriting the reasoning as the model reasons, not just showing it to the end-user, two very different things.by embedding-shape
7/31/2026 at 2:34:51 PM
Yeah, signing would prevent the paper's attack, but seeing the "raw reasoning" is helpful in figuring out what triggers refusals or (especially) what in the system prompt is guiding a specific refusal.Gemini (the web UI) used to show raw reasoning, or at least a more detailed summary of its reasoning, less than a year ago. Complete with markdown and weird spelling idiosyncracies, so I'd lead towards "real reasoning", but who knows. The reasoning block leaked the system prompt way more often than the response block did, and you could figure out why it would refuse a request through the reasoning, even if the response itself refused to elaborate. This is, presumably, why they stopped showing it. No loss for them, just prevents "pesky users" from low hanging fruit snooping.
(Gemma 4's reasoning and output remind me strongly of what I remember Gemini 2.5/3's reasoning to be, as an aside. I guess that's obvious, but Gemma 3 felt like a totally different model, while 4 feels very Gemini-ish.)
by spijdar
7/31/2026 at 2:57:47 PM
What matters for this injection strategy to work is to follow quite closely the style of the reasoning. It's particularly effective if you copy reasoning from the same context. If you cannot see the reasoning, you cannot duplicate it's style.That said, including instances of the attack in training is already a good countermeasure.
by benob
7/31/2026 at 11:34:15 AM
Token-based reasoning also seems like it would be inefficient, there’s no reason it has to be English or even human understandable.by jurgenburgen
7/31/2026 at 12:32:04 PM
There have been models trained for latent space reasoning. It has a lot of advantages but the big drawback is the reasoning is completely opaque.by UltraSane
7/31/2026 at 2:35:58 PM
What use is the reasoning if its unintelligible to a human?by skinfaxi
7/31/2026 at 5:41:30 PM
Even if it is intelligible, reasoning styles (and hence reasoning effectiveness) differ between models.For example, gpt-oss loves reasoning in the style of "I be caveman, hungry, need food, need coconut, will search coconut now, eat when find." Giving that to a model unaccustomed to that style could cause it to respond like that.
Reasoning interpretability helps debug why models fail (and some labs will give it to you if they trust you not to distill or be hacked), but there are also conflicting goals like token-efficiency, so interpretable reasoning doesn't always mean "pretty sentences".
by miki123211
8/1/2026 at 9:22:08 AM
Reasoning improves the output of the model. Originally it was a prompting method called chain of thought but later models were trained to do the reasoning steps without the human prompting for it. Being able to see the reasoning steps is just an accidental benefit.by jurgenburgen
7/31/2026 at 7:17:41 AM
>Like a frog enjoying a nice warm bath...Exactly :-)
Call me naive but I think dark patterns are a short term strategy for winning and I'm optimistic that in the long run they will be replaced with those that are more respectful and oriented to the greater good (granted, the long run might take more time than one hopes for).
Given that the pendulum can sometime swing back fast enough to be able leverage it, it might be a good time to focus on models that are both open weights and economically viable to run to build the next great thing.
by placebo
7/31/2026 at 8:19:13 AM
> [...] dark patterns are a short term strategy for winning and I'm optimistic that in the long run they will be replaced with those that are more respectful and oriented to the greater goodThis is definitely not the way most software has been going in the past decades. It's rather the opposite: Companies play friendly to obtain a user base, then start applying more and more dark patters to further increase their profit. Facebook, Evernote, Instagram, Komoot... The list goes on and on.
by blauditore
7/31/2026 at 10:14:42 AM
Also, see Android and iOS which have a monopoly on the mobile OS marketby pcthrowaway
7/31/2026 at 11:20:31 AM
Sorry about the nitpicking, but s/monopoly/duopoly/by falcor84
7/31/2026 at 12:16:45 PM
I don't think that's the economical definition of monopoly. It's not about 1 single actor owning the market but rather about unilateral change. Obviously a single actor owning 99.99% will be able to shape the market ... but also one owning a lot less, e.g. 30% if even if they don't collude with another actor owning e.g. 21%.by utopiah
7/31/2026 at 3:27:11 PM
what you are describing sounds like an oligopoly not a monopoly. A company cannot realize monopolistic benefits without > 50% control of a market. That's not to say there aren't benefits to a large market share, but they are different and we have different terms for them.by monknomo
7/31/2026 at 4:45:23 PM
US law sets the breakpoint for when a company is considered a monopoly at 30% of a market. It's never actually enforced, of course, but may be worth noting.by odo1242
8/3/2026 at 3:51:12 PM
[what does the ftc say about it?](https://www.ftc.gov/advice-guidance/competition-guidance/gui...) Courts do not require a literal monopoly before applying rules for single firm conduct; that term is used as shorthand for a firm with significant and durable market power — that is, the long term ability to raise price or exclude competitors. That is how that term is used here: a "monopolist" is a firm with significant and durable market power. Courts look at the firm's market share, but typically do not find monopoly power if the firm (or a group of firms acting in concert) has less than 50 percent of the sales of a particular product or service within a certain geographic area. Some courts have required much higher percentages. In addition, that leading position must be sustainable over time: if competitive forces or the entry of new firms could discipline the conduct of the leading firm, courts are unlikely to find that the firm has lasting market power.
by monknomo
8/2/2026 at 7:06:31 PM
>A company cannot realize monopolistic benefits without > 50% control of a market.I don't think that's true at all. Why 50% specifically? This is not about political votes or anything like that. It's about being the largest player by a margin, usually.
by blauditore
7/31/2026 at 11:31:24 AM
not nitpicking; huge difference between 0 and 1 competitorby chrisweekly
7/31/2026 at 12:06:23 PM
Huge difference while both are competing. But it’s a huge risk in a market with such high cost of entering. If either divests then it rapidly degrades.by jmathai
7/31/2026 at 9:01:47 AM
"Naive" is a big understatement.by cyclopeanutopia
7/31/2026 at 5:28:11 PM
I can’t think of any example in which it has gone like this, but some in which it has: The most prominent in my mind would be software transitioning from “of course you get the code so you can extend it yourself” to what we have today (please correct me if I’m wrong about this, I’ve only read about it).Users at large (individuals and companies alike) don’t care much about a freedom taken away when a product is a few % better than another, so the biggest player sees if they can get away with it. And once they do it, everyone else does too.
by solarkraft
7/31/2026 at 4:04:04 PM
As a frog I'm happy to report the water is comfortably warm today, the same as it was yesterday.by wren6991
7/31/2026 at 9:01:56 AM
> This article makes me reconsider using my recently acquired Codex sub in my home setup. I never liked that they hide the reasoning, but somehow overrode the cognitive dissonance because the performance is so good. But the inauditability is already a huge problem.Same, I dislike it so much I've acquired 96GB of VRAM to run local models, but sadly nothing so far, even with that amount of VRAM, comes even close to running Codex with GPT models. I really, really, really want local models to be ready, and things like Laguna S2.1 NVFP4 gets really close of almost being there, when it comes to coding specifically. But still feels like we have a long way to go for local models to be serious general purpose alternatives.
by embedding-shape
8/1/2026 at 1:43:50 PM
The open models are good! Even when hosted, they buy you a lot of portability.by solarkraft
7/31/2026 at 6:56:03 PM
At this point you should realize there are now tech executives that have 30 to 35 years of experience in all the dark patterns.Anything new is going to be an extremely rapid race to the bottom.
by AtlasBarfed
7/31/2026 at 9:16:00 AM
I am waiting for prices to get down and in the meanwhile I am gathering as much session data from claude/codex as possible so I can then later use them to fine tune open models. I've built my own session parser/archiver for this.by rkuska
7/31/2026 at 9:47:34 AM
Same. And I built a search tool for that repository of older sessions, so that I can search through those on all my machines. This helps me to be able to pick something up on a machine I did not originally start the convo on.by sdoering
7/31/2026 at 10:03:10 AM
It was with the transience of valuable agent session dialogue in mind that I built https://www.agentkanban.io - A key feature is context capture in the tasks which you create on the board and then progress in agent sessions. Supported agents are currently Claude and Github CoPilot in VS Code. All of your context is captured in the task and can be reloaded into new agent sessions at any point in the future. Tool use is intentionally discarded because it is proprietary in nature and therefore breaks the promise of session portability.by gb2d_hn
7/31/2026 at 7:16:29 AM
https://indieweb.org/POSSEThis is the way.
by theshrike79
7/31/2026 at 6:56:51 PM
This analogy doesn't make sense to me. Once I've had a conversation, it may be useful to refer back to it shortly afterwards, but typically the output is some code (or maybe a recipe or instructions for something or whatever). It's certainly important to me that I can use that code elsewhere. That's the thing that, to me, is analogous to being able to switch operating system and still access my files or use my favourite word processing program.But being able to decode the blobs that subagents returned in a conversation I've already forgotten about? That doesn't affect my ability to switch at all! I can't even imagine what trivial detail of an operating system this is analogous to. Maybe an undo buffer of a document that gets cleared on exit anyway?
I can still pass all my code, and any associated documentation, to any other agent at any time. What am I missing?
by quietbritishjim
7/31/2026 at 8:52:52 AM
You are building a phone app for open code?You mean like fossify phone or?
by tcfhgj
7/31/2026 at 1:38:32 PM
no he means he's locked him self into a bloated and slow react based terminal ui.waste of time. should be using pi mono
by NamlchakKhandro
8/1/2026 at 1:46:13 PM
No, it means that I’m building a fast alternative to the stock solid based web UI. Pi (isn’t the “mono” just about it being a monorepo?) has no features and no defined server-client API.by solarkraft
7/31/2026 at 6:36:57 AM
And yet people still go with Sign in with Google as the only login method.by agilek
7/31/2026 at 7:17:25 AM
I’ve actually started ignoring services where that’s the only login possibility.Sorry even if your platform is the greatest thing ever, but I’ll find a different tool. I’ve read one too many stories about Google (or Apple!) closing the entire account over some bullshit unnecessary reason like “fraudulent” gift card issues or whatever. I’m certain the affected people would’ve preferred to just pay back the amount in question instead of losing their entire Google Drive, or their 20 years of iCloud Photos or whatever.
by msdz
7/31/2026 at 8:03:18 AM
It's the only reason I want to replace Tailscale with something else or look into self-host when have a bit of time during my vacation. They only allow login through a third party, which is a big no for me.by n6242
7/31/2026 at 8:14:03 AM
Tbf to Tailscale they allow any OIDC provider[1]. I wish this was more normalised, then we could have one login everywhere regardless of who hosts it (even if it's yourself).[1] https://tailscale.com/docs/integrations/identity/custom-oidc
by corney91
7/31/2026 at 1:30:04 PM
While that isn't convenient is you don't want to use the public identity providers, it should make you think about what makes your identity on the Internet, and consider to have your own identity provider on a DNS domain you control.by dolmen
7/31/2026 at 9:48:03 AM
This is what headscale does, right? Manage private logins and keys for your tailnet from a vps? I haven't played with it but seems straightforwardby noduerme
7/31/2026 at 12:04:52 PM
I created my own AWS Cognito userpool just for tailscale. I recall the webfinger redirect was frustrating to get right but I refused to use Google/Apple as a gatekeeper to my own network so I had all the motivation to get it working.by zalebz
7/31/2026 at 8:09:21 AM
I think you can use a passkey now.by aidos
7/31/2026 at 9:03:47 AM
Only for people invited to the Tailnet. To create your own account, you still need a third party.by stavros
7/31/2026 at 11:34:28 AM
You can host your own identity provider. Authentik, Keycloak, authelia or Zitadel work.I don’t fully agree with tailscale’s decision to not want to be an identity provider but I understand it on some level. It simplifies their service greatly and the amount of asks for that will essentially have them build a full enterprise Entra-like solution that would be a constant maintain headache and they are not interested in that.
by eddythompson80
7/31/2026 at 1:35:27 PM
Beyond simplifying their service, it allows Tailscale to have reduced responsibilities (because of reduced collection of sensible data), and makes them a less interesting target for people wanting access to the data (wether illagally by hacking, or legally from government agencies). This probably makes them less attractive as targets for censorship.by dolmen
7/31/2026 at 6:51:21 AM
It’s odd, I just saw my first one of these today. Some former Figma person linked an AI site comp designer.I was going to give it a shot, but the only choice was a Google login.
So very weird.
by dd8601fn
7/31/2026 at 9:15:07 AM
It's not that weird. Building a modern accounts system is a lot of work and people don't like creating new accounts. So it's the path of least resistance for developers and users.by mike_hearn
7/31/2026 at 9:53:36 AM
It's not even that it's hard to build a modern account system. It's that if you put your site behind a private / custom account system, and you post a link to it on HN (for example), everyone and their mother complains that it's requiring an email address and password. But if you put the same site behind a Google auth, most people wouldn't think twice to click the button.by noduerme
7/31/2026 at 12:04:05 PM
I worked on the Google account system for a few years. I'd say it's a lot of work to beat it. Not necessarily "hard" for a team with the right skills, but certainly a lot of sweat, blood and tears.A modern account system is expected to have, in rough implementation order: email confirmations, password strength checks, password reset emails, forgot password flows (=advanced ID verification as otherwise this becomes a backdoor into accounts), user profiles (+avatar image upload/recompression/hosting), usernames independent of email addresses along with ability to change usernames later, password brute forcing blockers, bulk signup prevention (=solid bot detection), abuse controls (can easily become a team of people), 2FA (SMS), 2FA (authenticator apps), 2FA (backup codes), 2FA (voice calls), 2FA (passkeys), 2FA: recovery when both factors are lost, enterprise SSO integration (SAML), enterprise SSO (Active Directory), fast global signout support (much harder than it looks), cookie theft mitigations, heuristic online login risk analysis to catch cases where an attacker knows the right password via phishing, support for signing the user in to multiple domains, audit logging so users can review their own sign-in history, age verification and restriction support, and possibly support for being logged in to multiple accounts in a single browser session.
Oh, that all has to be HA, and the account system is the keys to the kingdom so the security requirements are the strictest of any part of your system.
You might say we don't need all of that, but expectations rise over time. Maybe 20 years ago you could get away with a simple account system and an automatic forgot password flow that just assumes the user still has access to their email. Maybe today you still can write a simple system, if you don't expect to have many users and are willing to implicitly delegate identity to webmail providers anyway (the moment you assume the user has access to a secure email account you're basically doing Sign In With Google anyway for 90% of users). But if you roll your own accounts, and then the user gets phished and someone logs in from an obviously suspicious place with the right password, they won't say "yes that's my fault" anymore, they'll say "Google could block that log in, why didn't you?" or maybe "Why didn't you support 2FA? It's your fault".
by mike_hearn
7/31/2026 at 2:43:07 PM
> A modern account system is expected to have, in rough implementation order: email confirmations, password strength checks, password reset emails, forgot password flows (=advanced ID verification as otherwise this becomes a backdoor into accounts), user profiles (+avatar image upload/recompression/hosting), usernames independent of email addresses along with ability to change usernames later, password brute forcing blockers, bulk signup prevention (=solid bot detection), abuse controls (can easily become a team of people), 2FA (SMS), 2FA (authenticator apps), 2FA (backup codes), 2FA (voice calls), 2FA (passkeys), 2FA: recovery when both factors are lost, enterprise SSO integration (SAML), enterprise SSO (Active Directory), fast global signout support (much harder than it looks), cookie theft mitigations, heuristic online login risk analysis to catch cases where an attacker knows the right password via phishing, support for signing the user in to multiple domains, audit logging so users can review their own sign-in history, age verification and restriction support, and possibly support for being logged in to multiple accounts in a single browser session.You don't need half of that. Even to this day, anthropic lets you log in by sending a code to your email. No password, no dealing with resets, no MFA. So yeah, you definitely don't need all of that.
by skinfaxi
7/31/2026 at 3:21:10 PM
That's what I said. If you're willing to implicitly rely on webmail provider's identity/auth systems then you can simplify - but that's not much different to just adding a Sign in with Google/Microsoft button. The identity is ultimately controlled by the email service and almost all users are on just two of those.by mike_hearn
7/31/2026 at 3:31:35 PM
What web auth system doesn't rely on a user having a secure inbox? It is vastly different from signing in with an IdP, since I can use my email address regardless of who my mail provider is.by skinfaxi
7/31/2026 at 1:18:20 PM
Thank you for this. The whole attitude of "it's just [complex thing we take for granted], how hard could it be?" is exhausting.by StilesCrisis
7/31/2026 at 2:01:54 PM
I dunno, I’d say it’s never been easier.If you’re building a paid service you’re probably already using cognito or supabase or something. That puts you a few clicks aways from 5+ other identity providers and normal accounts.
by dd8601fn
7/31/2026 at 7:19:06 AM
I am guessing that's because Sign in with Google is the least of the evil, as compared to other popular OAuth Sign-in options like Facebook, X...by wwind123
7/31/2026 at 9:04:24 AM
It's the least evil of the evil options? Why not use one of the good options then?by stavros
7/31/2026 at 1:56:22 PM
A password manager has an almost as efficient UXby ulrikrasmussen
7/31/2026 at 10:17:04 AM
Google is more evil than X or Meta by some assessmentsby pcthrowaway
7/31/2026 at 11:38:56 AM
It’s funny how the tides shift. I remember the more dominant online position in the early 2010s being “I don’t want to create yet-another-account for your website. Just let me sign in with my google account”. I’m with you thoughby eddythompson80
7/31/2026 at 11:04:44 AM
I guess the good aspect of sign in with Google is that it falls back nicely to sign-in via email which is very portable.by the_mitsuhiko
7/31/2026 at 7:02:15 AM
Because with the alternative they'll require you to "confirm your e-mail" instead of just picking a passwordby qurren
7/31/2026 at 7:06:40 AM
I'm actually more annoyed by having to pick passwords than confirming my email.by eru
7/31/2026 at 7:33:47 AM
I'm opposite. If my email goes down, or I do not have access to it, I cannot login. With passwords I still can.by mystifyingpoi
7/31/2026 at 10:52:13 AM
My email is with Google. They are less likely to go down than my password manager.by eru
7/31/2026 at 1:36:39 PM
Until one day your Google account gets locked with an automatically generated message that you violated an unspecified rule. Good luck getting contact to a human support.by Viliam1234
7/31/2026 at 4:37:22 PM
Well then you need a better password manager. Like a .kdbx file which is ~100% available, given enough copies I guess.by mystifyingpoi
7/31/2026 at 11:36:15 AM
Then what’s the point of it all? Just use Google login.by jurgenburgen
8/1/2026 at 12:31:21 AM
Yes, that's what I'm doing, when it's available.But it's not always an option, so a password manager is still a good idea.
by eru
7/31/2026 at 7:54:04 AM
Doesn't your password manager take care of that?by lucumo
7/31/2026 at 9:33:44 AM
It does. But I haven't properly synced it across all my devices, yet. I know, my fault.by eru
7/31/2026 at 12:36:17 PM
when in a rush I will put in gibberish instead going through the pw manager steps and rely on resetting the pw at a later timeby zalebz
7/31/2026 at 7:15:51 AM
Picking passwords is a job best left to password managers. You don't use a hand crank when riding an elevator, do you?by hotelsacher
7/31/2026 at 10:52:26 AM
I am using a password manager.by eru
7/31/2026 at 11:59:59 AM
Use a password manager to autogenerate them?by Geezus_42
7/31/2026 at 6:43:04 PM
Considering the two different people who fat finger my email address when signing up for services, I wish more systems required a validation step.Janet and Jake, I am sick of getting your stuff. Learn your actual email.
by 0cf8612b2e1e
7/31/2026 at 11:51:37 AM
> This is why it’s important to utilize your freedoms. Do NOT let yourself get locked into a particular ecosystem.I wish people would apply this same logic to governments.
by Geezus_42