0811 | Illinois Social Media Safety Act, UK Anonymity War, Coding Agents, Open AI

||Download

Show notes

A look back at the week's top Hacker News stories. Illinois signed a sweeping social media law whose broad operating-system language could put open-source platforms like Linux on the hook for age verification, while an investigation alleges a coordinated UK-funded campaign importing internet-ID laws to America. There's a rigorous teardown of the claim that concise languages are more token-efficient for coding agents, plus Meta's return to open models as Zuckerberg attacks closed rivals. Also cov

Timeline

  • 00:00:00 Opening
  • 00:00:50 Illinois makes Linux liable for age verification
  • 00:02:51 The UK's war on anonymity comes to America
  • 00:04:51 What's the best programming language for coding agents?
  • 00:06:49 Zuckerberg attacks 'closed' AI rivals
  • 00:08:19 Magnitude 7.4 earthquake hits western Colombia
  • 00:10:35 Kinney Drugs pulls its AI phone assistant
  • 00:12:18 Tl;dv left 180,000 meeting recordings exposed
  • 00:14:32 Exploiting System Management Mode with a long interrupt
  • 00:16:49 Midlife heart health buys 12.5 dementia-free years
  • 00:18:42 Stop Killing Games: time to sue Sony
  • 00:20:29 Meta's Muse Glimmer: a 30B local agent model
  • 00:22:10 Needle2: a 14MB agentic LLM for edge devices
  • 00:24:19 Ante: an offline coding agent in a single binary
  • 00:26:32 Docker Sandboxes for AI agents
  • 00:28:25 Tail-call optimization in C is relatively recent

Related links

This episode is produced by Bri. Bri uses advanced AI technology to turn the feeds you care about into podcasts made for listening. Contact us at hi@bri.so.

Transcript

Mia: You're listening to HackerNews Daily, and I'm Mia. My co-host today is Milo. We've got a packed lineup, so let's get going.

Milo: Thanks, Mia. Today we're looking at a new Illinois law aimed at kids' social media safety, plus a major investigation into how foreign nonprofits allegedly export the UK's war on anonymity to America.

Mia: We're also digging into the best programming languages for coding agents, Mark Zuckerberg's latest attack on closed AI rivals, and a powerful earthquake that just hit Colombia.

Milo: And later on, we've got Kinney Drugs rolling back its AI phone assistant, and a wild set of posts on Hacker News, from a huge number of exposed meeting recordings to a project called, well, the silliest name we could imagine. Stick around.

Mia: Illinois governor JB Pritzker signed the Children's Social Media Safety Act back at the end of July, making it law as Public Act 104-0664. The social media piece is the headline: defaults for minors switch to chronological, follow-only feeds instead of algorithmic feeds tuned to maximize engagement, notifications get cut off between ten at night and seven in the morning, and adult strangers can't view a minor's profile, message them, or see their location.

Milo: And that part's pretty squarely aimed at the big platforms — Instagram, TikTok, Snapchat, X, Facebook, and Roblox are all named. News sites, email providers, broadband companies, and school software are carved out by name. It passed the General Assembly in June completely unanimously — fifty-seven to nothing in the Senate, and a hundred and thirteen to nothing in the House.

Mia: But here's where it gets interesting. A separate part of the bill creates what's called an operating system provider category, and the language is broad enough — it references a covered manufacturer and anyone who builds an internet-connected operating system, commercial or nonprofit, with no exemption for open source software. That's different from Colorado, and reportedly from where California is heading.

Milo: By January first, 2028, those providers have to build in an age-declaration step and pass an age-bracket signal to any app that requests one. Enforcement runs through the Illinois Attorney General only. And one wrinkle worth flagging: the bill's text caps penalties at seventy-five hundred dollars per affected child, while the governor's press release advertises penalties up to fifty thousand per violation — and those two numbers don't obviously square.

Mia: There's also an investigation making the rounds that reads the broader push for internet ID laws as an imported campaign. The report, from Effort, is called The UK's War on Anonymity Has Come to America, and it alleges five foreign NGOs and their US affiliates are running a coordinated operation to influence American lawmakers — using child safety as the selling point for digital ID laws that would stop adults from using the internet anonymously.

Milo: The claim is that playbook already succeeded in Britain, where these laws now sit inside a system that surveils, arrests, and jails political dissidents — and it's being replicated in twenty-one states and in Congress. The report names British nonprofit 5Rights, founded by Baroness Beeban Tania Kidron, saying it engaged on forty-two bills across eighteen states, eleven of which became law, and co-designed California's AB 2273.

Mia: It also flags the Center for Countering Digital Hate, founded by British Labour consultants, and says America First Legal accused that group of violating FARA in 2024, with no publicly announced Justice Department investigation. And the Institute for Strategic Dialogue is described as holding contracts with the State Department, the EU, and UK ministries worth over seventeen million dollars — all while 5Rights is said to advocate VPN bans, which the report compares to Russia, China, and North Korea.

Milo: And Hacker News commenters split hard on this. Some dismissed the child-safety arguments as outright manipulation to be ignored, and called the whole thing rhetoric all the way down — while others argued the NGOs skip straight past parental controls to deanonymizing everyone.

Mia: There's a genuinely interesting teardown up at danluu.com on the question of the best programming language for coding agents. It's responding to a fairly widely cited post claiming dynamic, more concise languages are more token-efficient for large language models. Google's AI summary even repeats that claim, citing the same post.

Milo: The original post reported a two-point-six times gap between C as the least token-efficient language and Clojure as the most efficient, with J later measured at about seventy tokens on average — nearly half of Clojure's hundred and nine. But the danluu post argues that first experiment relied on trivial Rosetta Code problems, so performance on trivial tasks doesn't generalize to real work.

Mia: It also points to a real flaw in the second comparison. One test executed a wrong, nonexistent path, and a later Go agent symlinked that path to its own executable — so every later test ran the Go executable instead of the correct one. Rust's failures just mean Rust scoring happened before that symlink got created.

Milo: The author pre-registered bets: ninety-five percent confidence that the dynamic-versus-static claim won't hold, sixty percent that static languages will be somewhat better at ultra effort, and ninety-eight percent that weird-language supremacy like J won't hold — in part because AI labs put little training effort into obscure languages. In the author's own eval, agents had to build a complete zstd decoder from the RFC in a container with no internet and no access to tests. At medium effort the dynamic cluster came out ahead, but at ultra effort results were mixed, with more static languages among the better results.

Mia: And on the Meta front, Mark Zuckerberg posted an essay attacking closed AI rivals as Meta shifts back toward open models. The Hacker News thread linked to a Financial Times URL, but it currently just returns a security verification error page — so commenters pointed to an archive copy and to Meta's own version on their site.

Milo: The writing itself drew mixed reactions. One person called it a bit like War and Peace, another complained about all the em dashes, while someone else pushed back that there weren't that many and it didn't read like something written by an LLM. But the sharper read came from the politics: one commenter asked whether this is an I'm losing, so let's change the rules situation — comparing it to Sam Altman saying we should slow down, and to Elon Musk years ago calling for a six-month pause on AI training so everyone else could catch up.

Mia: Not everyone buys that framing. One commenter argued OpenAI isn't actually losing, that GPT-5.6-sol competently gets things done, with the caveat that you might not like the lengths it will go to to get them done. And on substance, another reader called the essay a contradiction — liking the idea of putting AI in people's hands, but rejecting the part about handing over all our personal context so agents can work for us around the clock to better our lives.

Mia: There's a new earthquake at the top of Hacker News, and the confusion started with the name. The USGS event page says a magnitude 7.4 quake hit about 5 kilometers south of San José del Palmar, Colombia. But commenters admit they had to double check, because one of them said they first read it as San Jose, California. Another pointed out there are literally dozens of cities and towns called San José around the world, and the examples kept coming in the thread. There's at least one town or city named San Jose in four different US states. There are two separate San Jose creeks in California, and neither one is in the Bay Area — one's in LA and one's in Monterey. There appear to be two towns called San Jose in New Mexico. Illinois has both a San Jose and a St Joseph, both small towns. And there's apparently a tiny town called San Jose in Texas with a population of about 15, though it's unclear if it's officially incorporated.

Milo: The location matters for another reason. Somebody asked whether this quake was connected to the one in Venezuela earlier this year. One commenter said no, this is on the other side of the continent, on the Pacific coast. But another pushed back, saying that doesn't mean the two are unrelated. So what did the actual reporting show?

Mia: A commenter citing Colombia's national paper, El Tiempo, said coverage above the fold reported more than 20 confirmed dead in Pereira, a third-tier city with a population of roughly 500,000, plus many wounded. They were careful to use the qualifier "confirmed." Meanwhile, someone in Bogotá said they didn't feel it at all, but the quake apparently lasted several minutes and caused a lot of panic, with many people running out of their apartments in their pajamas. They even recalled that back in a smaller 2023 earthquake, adult webcam streamers had gone out into the streets in their lingerie. Another commenter in Medellín said much the same thing — not felt, but clearly a serious event for the people it hit hardest.

Mia: A New York-based pharmacy chain is scaling back its AI phone assistant after customers reported incoherent calls, wrong dosages, and missed prescription notifications. This is Kinney Drugs, and the AI assistant, named Burt after the chain's founder, went live back in May to handle patient questions about prescriptions and refills. But hundreds of complaints followed, and the company's president, John Marraffa, put it bluntly: getting privacy and security right doesn't mean they got the experience right, and they own that failure.

Milo: So what are they actually doing about it? The reporting, which was first surfaced by VTDigger, says Kinney is returning to its old touch-tone phone system for incoming patient calls. Burt will only stick around for outbound messages like prescription refill texts, and even then, patients have to opt in. The president also stressed that Burt is fully HIPAA compliant, isn't open source, and doesn't generate or manipulate data.

Mia: That open-source claim set off a big thread on Hacker News. One commenter said we need to fight the talking point that open source is bad, and someone else asked how open source could ever be perceived as bad. Another commenter laid out the real concern in regulated circles: with open source there's no vendor to sue, many open-source licenses explicitly disclaim merchantability and fitness for purpose, and the software is viewed, in their words, as akin to car parts found on the side of the road. One commenter sarcastically mocked the whole idea, suggesting that if the source is open, then presumably no one could trust it.

Mia: A Hacker News post with a deliberately cheeky title — T L D V, or Too Lazy, Didn't Validate — reports that 181,874 meetings were left wide open. The target is tl;dv, an AI meeting platform that drops a bot into your Google Meet, Zoom, or Teams call and then records, transcribes, and summarizes it. The article says more than two million users put sales calls, job interviews, performance reviews, and internal strategy sessions into this thing.

Milo: And the flaw was a missing security rule. After a user authenticates, they exchange a token through a specific endpoint, and then any authenticated tl;dv user could query the entire meetings database across every account. There was no tenant isolation — no wall between one company's data and another's. Each record included the creator's email, a joinable conference link, the provider, the recording status, and timestamps.

Mia: The researcher counted 181,874 meetings belonging to 84,312 users spread across 35,000 email domains, with roughly a thousand meetings in active recording status at any given moment — meaning live calls with exposed IDs. And he said he actually joined two of them. One was a Malaysian Ministry of Education meeting on Google Meet where a presenter addressed more than 157 participants. The other was a 21-person call of students from a major US university, screen-sharing a startup project while setting up a database service. Exposed government meetings spanned 23 countries, from Brazil and Colombia to Ukraine, the Philippines, Mexico, the US, Qatar, Malaysia, Israel, Indonesia, and more.

Mia: One of the more entertaining security posts on Hacker News this week is a GitHub repository that claims to exploit System Management Mode using a very, very long interrupt. The project name is a string of i's — the letters just keep going. The README describes SMM as the secure, ultra-privileged execution environment that runs invisibly in the background of every x86 CPU.

Milo: Why does the length matter? The security model requires all CPU cores to be either in SMM at the same time or out of it at the same time. When one thread enters SMM, all the others are invited in too. So the trick is to start an obscenely long-running machine instruction on core zero, have core one enter SMM and wait, then give up, do its secret work, and exit before core zero finally joins SMM. At that point core one is out while core zero is in — and that lets core one attack core zero.

Mia: The catch is that most instructions on a modern CPU are fast — an add takes a single cycle. But core one only gives up after roughly four billion cycles, which is over one second of wall-clock time. The README cites a one-second timeout that runs in x86 firmware whenever a core enters SMM. The discussion had its share of jokes about the deliberately drawn-out emphasis on "long," including one person asking whether a short instruction would do, and the answer being only if the short instruction is incredibly long. But there was a serious question underneath too: why does a one-second timeout exist at all, and can this be patched, or is it a hardware weakness that can't be fixed? The repository itself carries an MIT license and includes working C code, examples, and a Makefile — so the researchers clearly believe this is worth building on.

Mia: A study posted to Hacker News, from the journal Neurology, quantifies just how much healthy living in midlife pays off at age 75. Earlier research already showed that heart health at 50 predicts brain health decades later, and this study puts a number on it: people with zero major risk factors gained thirty years of dementia-free survival, versus seventeen and a half years for people carrying all three risk factors the study tracked.

Milo: So that's a gap of over twelve years of clear thinking in old age. The three risk factors measured here are blood pressure, diabetes as tracked through blood sugar, and smoking. One commenter noted the study's phrasing — maintaining optimal midlife vascular health was associated with up to twelve-point-six additional dementia-free years — and added that even moderate diet and lifestyle changes compound over decades, so they can make a big difference in that final stretch of life.

Mia: And the definition of high blood pressure used here is worth noting. The study counted it as a systolic reading of 140 or higher, a diastolic reading of 90 or higher, or being on blood-pressure medication. A commenter praised that as common sense, contrasting it with much stricter cutoffs some people push, or claims that a reading like a hundred over sixty-five is ideal even when it leaves people feeling dizzy.

Milo: The same commenter suggested the study could have added cholesterol, inflammation, and a lipid marker to the risk list. But the core takeaway stands regardless of the exact factors: the choices you make in your forties and fifties are doing quiet math on how many clear-headed years you get later. That's a payoff you can bank on for decades.

Mia: Over on Hacker News, a post titled "Stop Killing Games" is calling on people to join a Dutch collective action against Sony. A consumer foundation is running a campaign it calls the Fair PlayStation action. The foundation's argument is that PlayStation owners are effectively paying a "Sony Tax" on every digital game, that Sony is stopping physical PlayStation games, and it says it will go to court to push for fair prices and compensation.

Milo: Joining is low-risk: you can leave at any time, you're not obligated, and you only pay anything if the action wins — and in that case part of any damages goes to costs. What's interesting is that the comments mostly argue about what Sony actually did wrong. One commenter asked whether this is about Sony no longer selling digital download codes through third parties, and pointed out that Nintendo still does sell digital codes in stores like Walmart and Amazon.

Mia: Right, that's the crux. One commenter said they can't follow the monopoly logic, because this isn't about game exclusivity — the same game is usually on Xbox, Switch, and PC. It's about wanting to buy a game on PlayStation from a store other than Sony. Another commenter noted that even if Sony reversed course immediately, it would still have harmed some consumers during the time it was happening.

Milo: And this isn't the first such case. The same commenter mentioned existing US and UK class actions against Sony over what looks like the same thing — using a dominant position to charge higher prices. So this Dutch effort is joining a broader pattern of legal pressure over whether a platform holder can force everyone to buy software only through its own shop.

Mia: Meta's Superintelligence Labs has released an open AI model designed to run constantly on your own hardware — no cloud connection needed. It's called Muse Glimmer, it has thirty billion parameters, and it's built for what the company calls always-on local agent workflows. It's open-sourced under Apache 2.0, and sized to run on a Mac or PC with a single consumer GPU. Weights are already up on Hugging Face.

Milo: The pitched use cases are things like local agents, function calling, local coding, and using the model to judge other models. Meta describes training in three phases, ending with a mix of fine-tuning and reinforcement learning across general, reasoning, coding, and agentic tasks. And it claims the model handles multi-step reasoning, recovers from failures by retrying, and accepts multimodal input through a dedicated perception encoder.

Mia: The benchmark comparisons pair it against some of the newest open rivals from Google and others, and the meta team evaluated it under its own Advanced AI Scaling Framework, which is worth keeping in mind as a caveat. There are also optimized integrations promised for several local inference tools in the coming days.

Milo: Reaction on Hacker News was split. Some commenters were glad to see fresh open-weights releases from Meta and called it a good-looking showing. Others were much more critical — one accused Meta of aggressively hammering their employer's servers with requests while ignoring scraping rules. So beyond the model itself, it seems Meta's approach to gathering data is drawing just as much scrutiny.

Mia: Finally, a company called Cactus has shipped a tiny open AI model that's meant to run on devices you'd never associate with machine learning — phones, wearables, even a microcontroller. It's called Needle 2, it has forty-five million parameters, and it's built specifically for tool calling, device use, and structured extraction. The whole thing is a single 14-megabyte binary that runs a full session in just 28 megabytes of RAM.

Milo: So how fast is that in practice? On a Raspberry Pi 5, the team reports about 500 tokens per second for decoding. On virtual reality headsets like the Meta Quest 3S or Apple Vision Pro, between 400 and 1500 tokens per second. And on budget phones under two hundred dollars, roughly 300 to 700 tokens per second. That's comfortably fast enough for a lot of real-world automation.

Mia: Cactus says it trades wins with much larger small models on tool-call and mobile-device benchmarks, despite being five to seventy times smaller and using 2-bit compression. The technical argument is that most edge devices are cheap — something like four in five internet-connected devices cost under two hundred dollars, versus about a billion and a half PCs. And here's their bet: when a tool call is just typed parameters, the only hard part is mapping a messy sentence to a function and its values, which needs no world knowledge — so a 45-million-parameter model is enough.

Milo: They've also added structured extraction, where you pass a schema instead of tools — like flipping an enum field to turn the whole thing into a classifier. It's Apache 2.0 licensed, weights are on Hugging Face, and it supports newer microcontrollers like the ESP32-S3. If this holds up, it's a strong sign that the next wave of embedded AI is going to be very small, very cheap, and very local.

Mia: Mohan at Antigma Labs posted Ante on Show HN, and the pitch is genuinely unusual: a self-contained coding agent shipped as a single Rust binary around 15 megabytes, with the terminal interface, an embedded ripgrep, local PDF and OCR support, and a home-managed llama.cpp engine all packed inside. No runtime dependencies, no node_modules, no account required.

Milo: And the local model story is the interesting part. When Ante sets up llama.cpp on your machine, it installs a pinned, checksum-verified build matched to your hardware, so Metal on Apple silicon, and CUDA, Vulkan, or plain CPU on Linux. It can also discover GGUF model files you already have on disk, or attach to a llama server already running on a local port. Before loading a model it estimates the RAM or VRAM you'll need based on model size and context window.

Mia: So it's designed around true offline work. Once the model is on disk, inference needs no network at all, and you can switch telemetry off with a single environment variable. Mohan is upfront that this is an alpha preview with breaking changes and incomplete functionality, and Mac and Linux only, with WSL suggested for Windows users.

Milo: The honest caveat is performance. Local models are benchmarked with the same harness as frontier ones, and a roughly 17 gigabyte Qwen model scores about fifty-six percent on Terminal-Bench. So the design bet is offering hosted and local models in one catalog and switching mid-session, rather than claiming one local model replaces everything.

Mia: And the README pitches a stronger open-weight result with a DeepSeek model clearing around eighty-three percent, though that's a self-reported run on specific conditions. Either way, Ante is framing itself as working like Claude Code or Codex, minus their dependencies and model constraints.

Milo: Docker Sandboxes is Docker's answer to the disposable, isolated sandbox problem for coding agents, and it leans on microVM isolation. Each agent runs inside its own microVM with the dev environment and only the project workspace mounted in. The agent can install packages, tweak configs, even spin up its own Docker containers, while your host machine stays untouched.

Mia: Out of the box it supports the big agent CLIs, Claude Code, Gemini CLI, Copilot CLI, Codex, OpenCode, and Kiro, and you can build custom agents. Notably, the default is a permissive mode that skips permission checks, roughly what people call YOLO mode. Broader controls come from a separate governance product aimed at enforcing policies across the whole organization.

Milo: But a lot of the Hacker News reaction centered on one thing: a login requirement. Several commenters pushed back, with some calling it garbage and one saying Docker still wants a login even for a local dev tool. Others confirmed the requirement and noted the governance controls are tied to a specific subscription.

Mia: There were also alternatives in the thread. Some pointed to sandboxy as something similar, and one commenter said it looks low effort if it doesn't work out of the box with the Raspberry Pi. Someone shared a sandboxy Pi-agent config example listing allowed hosts like Anthropic and PyPI domains, with a Node 22 base image. So the demand for disposable agent sandboxes is clearly there, but whether Docker's login-gated version lands is still open.

Mia: Tail-call optimization in C is surprisingly recent, and a 2025 LWN article about it drove the Hacker News discussion. One commenter, a long-time LWN subscriber, explained why: C's calling convention historically required the caller to clean up stack arguments between a call and the following return, which essentially forced non-tail calls. When he surveyed C compilers back in 1994, none of them did tail-call optimization.

Milo: Then in 2001, tail-call optimization came to GCC via a separate calling convention, with documented limits, including an inability to handle indirect calls, which would have mattered for interpreter dispatch. The commenter says that after reading a paper on copy-and-patch compilation, he tested both GCC and Clang on the kind of tail calls described in that paper, and found both now handle them.

Mia: For him this matters in a practical way. His Gforth project keeps its virtual machine instruction set deliberately under a few thousand code snippets, while the copy-and-patch paper reports using a hundred thousand. That's the payoff of tail-call optimization: techniques that need far too many snippets to fit in a goto-based system become feasible. Gforth hasn't adopted it yet, and he congratulates the Python community for being first.

Milo: The thread also widened to other languages. One commenter pointed out that missing tail-call optimization is a real footgun for Scheme programmers who move to Common Lisp, since Scheme is one of the few languages where TCO is part of the language standard, so any compliant implementation has to provide it. And there was real enthusiasm for Rust's proposed become keyword. The argument is that making intent explicit pushes the compiler to deliver tail-call optimization even in cases where it wouldn't otherwise, turning a technical detail into a language-level promise.

Mia: And that's where we'll leave it for this episode. Today we covered everything from Illinois signing the Children's Social Media Safety Act into law, to allegations that foreign nonprofits are pushing restrictions on US online speech, to the debate over which programming language best suits AI coding agents.

Milo: We also dug into Meta returning to open models while targeting closed rivals, that magnitude seven point four earthquake in Colombia, and Kinney Drugs pulling back its AI phone assistant after customers reported incoherent calls and wrong information. Plus a developer reporting nearly two hundred thousand unguarded meeting recordings, a Dutch campaign urging people to sue Sony over disappearing games, and several new open-source agentic models, including Meta's thirty-billion-parameter Muse Glimmer and Cactus's much smaller Needle two.

Mia: We rounded things out with Ante, a self-contained coding agent that ships as a single compact Rust binary, Docker's disposable coding sandboxes, and the surprisingly recent arrival of tail-call optimization in C. That's a lot to chew on, so thanks for listening. We'll catch you next time.