[HN Gopher] Rabbit R1 source code [part 1]
___________________________________________________________________
Rabbit R1 source code [part 1]
Author : wibbily
Score : 292 points
Date : 2024-04-23 18:18 UTC (4 hours ago)
(HTM) web link (github.com)
(TXT) w3m dump (github.com)
| ado__dev wrote:
| Not surprised at all. This and the Humane Pin both seemed like a
| quick cash grab before phones integrated all the new AI goodness.
| I'm expecting we'll see that window close by the time I/O and
| WWDC wrap up this year, so they had to move fast.
| pnw wrote:
| A company founded in 2018 that raised over $200m is a "quick
| cash grab"?
| SheinhardtWigCo wrote:
| "Quick" as in being quick to exploit LLM hype.
|
| "Cash grab" as in Elizabeth Holmes grabbing $700m from
| Theranos investors.
| SheinhardtWigCo wrote:
| Their "keynote" just _screams_ shenanigans. It 's the most
| blatantly fake product demo I have ever seen.
|
| To take one example, at 14m30s, the CEO is shown using the
| device to book a trip to London. This is presented as a live
| demo, but it's clearly simulated.
|
| https://www.youtube.com/watch?v=22wlLy7hKP4
| imiric wrote:
| Playing devil's advocate, tech demos are often faked. From
| the famous "Hello" Mac introduction in 1984[1], to Google
| with their Gemini demo a few months ago.
|
| A certain degree of smoke and mirrors to generate hype around
| ground-breaking tech is the norm, not the exception. This
| doesn't necessarily mean that the product itself is a scam.
|
| [1]: https://www.folklore.org/Intro_Demo.html
| RockRobotRock wrote:
| To be fair, he doesn't "book" a trip to London in the
| presentation, he gets flight, hotel, and car rental
| information, which isn't that out there.
|
| But, he does imply that you _can_ book from the device, which
| is completely insane. How do you deal with flight selection
| with multiple layovers? Seat choices? DOBs? KTNs? Phone
| numbers? Frequent flyer number? Payment? Travel insurance?
| Disability accommodations?
|
| What could possibly be the overlap of people who travel
| enough that this is all worth setting up, who don't already
| have their own personal assistant?
| kmlx wrote:
| just the payment part is it's own universe of issues,
| friction, fraud, security etc etc etc
| hncel wrote:
| I don't think this is a fair characterization of Humane. I
| don't and haven't worked at Humane, but I did interview there
| and have some friends who work there now. They are notoriously
| secretive about their product (founders are ex-Apple, and they
| try to keep an Apple like secrecy culture) but I do know a bit
| about the evolution of the product.
|
| Humane was founded in 2018, well before ChatGPT was released in
| November 2022. If you look online you can find some articles
| about patent applications they made well before ChatGPT was
| released that give you an idea about their idea for the product
| at the time, e.g. https://9to5google.com/2022/01/07/humane-
| android-ar-wearable...
|
| Developing the hand tracking, laser projection system, voice
| recognition, etc. is very hard, especially considering the
| power constraints on the device. They spent years working on
| this and when LLMs hit the scene they realized that the
| original product idea was going to be severely lacking if they
| didn't integrate this technology. This caused a big internal
| pivot to more closely integrate with these LLMs. I'm not sure
| which they're using, presumably they're paying for GPT-4 access
| or something like that. It's understandable why they felt like
| they had to do this, and why it feels like a rushed
| integration. The bottom line is that they were way too
| optimistic with the hardware capabilities when they started
| working on the product, and the last minute rush to integrate
| with LLMs to at least improve the software capabilities to kind
| of close the gap is what we're left with. It's not a great
| situation, but I also think it's unfair to characterize it as a
| "cash grab".
| megaserg wrote:
| Secretiveness in a startup at that stage is not a good sign.
| See e.g. Theranos or Magic Leap.
| rodiger wrote:
| Cash grab from VCs is probably more accurate... I have zero
| doubt some incredible engineering has gone into their
| product.
|
| However, from what I can tell they were searching for a
| problem to solve instead of coming with a distinct,
| compelling, articulable vision of what they wanted to build
| fragmede wrote:
| the hardware is phenomenal, but it's tied down by bad
| software
| georgehill wrote:
| Why did they upload the code to some random site instead of
| GitHub?
|
| EDIT:
|
| > But let's call a spade a spade - this is a blatant lie. And
| we're about to expose it with the first partial release of the
| source code for its so-called "large action model".
|
| FYI, Text to Action is possible. I personally tested a couple of
| apps, but I don't think anything reliable exists like we humans.
|
| I would not disregard what they claim is completely false.
| paxys wrote:
| Because it will be taken down from Github.
| claytonjy wrote:
| to reduce the chances of GitHub taking it down, perhaps? not
| sure it'll help though
| no-dr-onboard wrote:
| It buys time for them. GitHub will have a lengthy internal
| discussion about DMCA takedown requests and the fact that the
| code isn't on their server. During this time it'll give the HN
| and reddit communities time to grab the link and redistribute.
| georgehill wrote:
| Understood!
|
| But zipped files are super fishy though. What if this repo is
| spreading malware?
| fwip wrote:
| Zip is just a tarball that Windows understands.
| dxbednarczyk wrote:
| Potentially due to the threat of DMCAs. Pixeldrain and Mega are
| widely used in piracy and sometimes leaks like these,
| considering they are not known for complying with them most of
| the time, unlike GitHub.
| rodiger wrote:
| At least it'll look nice on a shelf thanks to Teenage
| Engineering's good work :)
| WanderPanda wrote:
| TE might have their name really damaged by this. I wonder why
| they agreed to this colab in the first place
| micromacrofoot wrote:
| they were paid money in exchange for services
| BadHumans wrote:
| I don't think any fan of Teenage Engineering is no longer a
| fan because they were paid to design a product that flopped.
| serf wrote:
| why not? they clearly wanted to exploit AI hype in order to
| turn a profit, even if they did so indirectly. Why
| shouldn't that speak to their motives and trustworthiness?
|
| if Apple started churning out guns, landmines, snakeoil,
| cancer cures, NFTs, and magic-AIs their reputation would
| falter.
| wilsonnb3 wrote:
| Apple might be able to get away with all that, their
| reality distortion field is unmatched, but I agree that
| teenage engineering might actually take a reputation hit
| if they are too liberal with their outsourcing.
|
| Personally, the Vision Pro wasn't really my cup of tea
| but I will be standing in line on day one at my local
| Apple Store for the Landmine Pro.
| kevindamm wrote:
| Wait til you find out that the Vision Pro can detect the
| presence of Landmine Pro in your vicinity.
|
| It's all about that vertical integration.
| chambored wrote:
| I highly doubt that. TE has a strong reputation and their
| involvement in another company's product outside of their
| normal business won't impact their sales regardless of
| whether or not R1 is a flop or a ruse.
| talldayo wrote:
| Selling underpowered toys at eye-popping prices has been
| Teenage Engineering's modus-operandi since the beginning.
| After the OP-1 price hike (and subsequent re-release at an
| _even higher price_ ), I don't think their target audience
| cares past this point. You either buy TE stuff for the brand
| recognition or you own a bunch of Behringer gear because
| you're poor.
| vegadw wrote:
| Honestly, while I agree there's a massive price
| discrepancy, I don't know that I even see Behringer as the
| "lower end" option anymore. The lowest end is a laptop and
| pirated VSTs. Behringer pedals? Yeah, those are because
| you're poor (or just don't care, I guess?) but synths? The
| K2 is better built than the MS20 mini, the Wasp reissue
| doesn't have a good equivilent I know of, and their 303
| clone isn't any better or worse than the other similarly
| priced 303 options - and it's easily hackable.
|
| I mean, don't get me wrong, I still think Behringer as a
| company is doing bad things to the music land scape and
| that they've done some pretty horrendous IP theft and
| racist stuff, but I don't think "because you're poor" is
| right either.
|
| To the point though, yeah, no, TE absolutely won't get a
| black eye for this: Nobody cares, and hardly anyone but
| tech bros even know. It's no worse than their wooden choir
| thing.
| caseyy wrote:
| https://teenage.engineering/store/field-desk/
| talldayo wrote:
| I retract my previous statement. Indeed, toys are not the
| only expensive stuff they have for sale.
|
| Hey look down there! The computer-1 case is on sale for
| $149, down from $249. How much profit you still think
| they're making, considering it's a DIY kit of bendable
| sheet metal?
| noman-land wrote:
| While I agree this has been true of TE for most of their
| existence, their most recent $300 sampler bucks this trend
| considerably.
|
| https://teenage.engineering/store/ep-133/
|
| Neither that, nor this little AI cloud device are eye
| watering in price.
| neom wrote:
| People loooove to complain about TE pricing. OP-Z is
| $499, find me anything else that can sequence sound,
| video and DMX (on the go) like OP-Z can, there are
| exactly zero others. OP-1 for portable synths.... are
| people pulling a Deluge out on a flight? I've seen people
| compose a whole set with a OP-1, over 30 minutes, with
| nothing else... good luck doing that on a MC-101.
| talldayo wrote:
| I own a Pocket Operator, my head's not in the sand about
| their cheaper offerings. The Pocket Operators are cheap
| toys though, you cannot tell me with a straight face that
| it's about to prop up your next EP. It's a mass-produced
| calculator PCB they forgot to make a case for, and sell
| at insane markup.
|
| The same goes for the KO and indeed, the OP-Z. The OP-Z
| doesn't even have a screen, it has no business costing
| $499 for being a bunch of buttons with a USB-C plug.
|
| > find me anything else that can sequence sound, video
| and DMX (on the go) like OP-Z can
|
| How about the mandatory paired device it requires to
| sequence everything? That iPhone/iPad is certainly
| capable of doing that itself, alongside multiple things
| the OP-Z _can 't_. Nevermind how far you'd get with a
| $300 laptop and $200 DAW.
| j4ustin wrote:
| The Rabbit CEO is on the board of TE.
| slily wrote:
| This reminds me of how Playdate owners make it very obvious
| they don't use the thing in the way they retroactively justify
| their purchase by commenting on quirkiness or aesthetics at the
| expense of functionality or usability. I guess I get it but
| there's cheaper plastic toys out there.
| mulderc wrote:
| I don't think that is retroactive, people bought it because
| it was different and looks cool and is quirky. I think it is
| a very fun device and has some great games for it. It isn't
| for everyone but it is a cool device for people that
| appreciate what Panic is doing with it.
| kotaKat wrote:
| I bought it because I figured out it's gonna be some crummy
| little Mediatek thing underneath the skin (and it is) running
| some form of Android (and it is) so I'm just sitting back to
| hack it back to be a real communicator ;)
|
| EDIT: It's an MT6765 (Helios P35). It's got a known BootROM
| exploit. Won't be long until someone dumps it and cracks it
| open, though would be hilarious if a part2/part3 dump is just a
| factory stock ROM.
| aw4y wrote:
| I expect it (or at least I hope) to be really hackable.
| plugin-baby wrote:
| Based on how hackable their infra is?
| rvz wrote:
| Big if true.
|
| Could set back the AI device hype 5 years back after Humane
| getting exposed as another scam.
| jagger27 wrote:
| You already have the best AI hardware we'll see for a while in
| your hand.
| passion__desire wrote:
| I remember Mozilla was working on 3D web browsers. Could be
| new way to do things in Vision Pro? Is there any progress on
| that front?
| adlpz wrote:
| Any background on how the code got leaked? Insider? Hacked
| servers?
| jthnme wrote:
| Some will call it scam, some will call it MVP
| godelski wrote:
| If your product doesn't work anywhere near what your "live
| demo" shows, it's a scam.
|
| That's very different from "here's the product we envision and
| need money to build it."
|
| And just because others have scam demos (including Gemini) that
| doesn't make it okay. It makes it a race to the bottom (and is
| why I'm more upset about Gemini because big players are held to
| higher standards)
| ikurei wrote:
| In and of itself, the product might be a decent MVP to validate
| the idea or some aspects of the design.
|
| The problem is in how they've marketed. If you're taking
| people's money and giving them an MVP, you need to be upfront
| about it; if you aren't you're doing a bad thing.
| paxys wrote:
| Meh. I don't think they ever hid the fact that the device is
| basically a ChatGPT wrapper. As long as it can achieve what it
| advertises, who cares how the backend looks? At least it has the
| decency to charge a reasonably price ($200, rather than $700 +
| subscription like the Ai Pin).
| furyofantares wrote:
| > I don't think they ever hid the fact that the device is
| basically a ChatGPT wrapper.
|
| "Large Action Model"
| k8svet wrote:
| >As long as it can achieve what it advertises, who cares how
| the backend looks?
|
| so if I pump out enough advertising, you're going to give me
| the usernames, passwords, and active sessions for your accounts
| to me?
|
| I need to log out of this thread asap. I thought the defenses
| of Ai Pin were going to drive me nuts, I need to preserve some
| sanity. Has everyone lost their minds? Are tons of people here
| working for equally scummy, shoddy, if not scammy, startups?
| Seriously, what the hell.
| paxys wrote:
| > you're going to give me the usernames, passwords, and
| active sessions for your accounts to me?
|
| You give all of those to every smartphone maker. Why is this
| any different? Is there evidence that their handling is
| insecure?
| k8svet wrote:
| If I found out that Android was eavesdropping my Spotify
| credentials, I'd be just as stupified, yes.
|
| If I found that Android built in some Spotify integration
| that worked by stealing my active session cookies to do
| some backdoor integration with it, and billed it as some
| future AI smart service, I'd find it equally g-d absurd,
| yes.
|
| Do I think that me logging into the Spotify app, in
| Android, and it exchanging those credentials for an app-
| internal access token is the same as a server hijacking my
| session? No, not really, I don't.
|
| That's what's so damn brazen and shoddy about this. SPOTIFY
| HAS OAUTH.
| paxys wrote:
| I have no idea what you are trying to say. The device
| works by running apps for Spotify, Uber etc. in a VM and
| logging you into it. They say it right on their homepage.
| If you don't trust it, sure don't buy it. That's your own
| decision, but doesn't make them any more right or wrong.
| k8svet wrote:
| I'm saying it's shoddy, and scammy, and I can't believe
| anyone would lift a finger to defend this type of
| product, engineering, or actively training people to get
| phished. Hope that clarifies.
| ado__dev wrote:
| Yeah, I have a lot more faith that Google and Apple will
| properly secure my private data vs a random startup.
| madeofpalk wrote:
| Well, I actually don't. I only use hardware from companies
| that I have a semblance of trust in, and I certainly don't
| run around entering my Spotify or Uber password into other
| services.
| bogwog wrote:
| This is probably what it felt like to be alive during the
| peak of the "dotcom" craze I read about in historical
| literature.
| cogman10 wrote:
| Haven't you done that already?
|
| I mean this in all seriousness, have you used Oauth with
| google/facebook or the like to login and register with online
| services? Why not? Have you put passwords into a password
| manager? Why?
|
| Did you give Uber or Lift your credit card number? What if
| they were a scam?
|
| I say this also thinking rabbit R1 is a pointless product
| that based on hype that nobody should buy. However, I can see
| why people might think it reasonable to give their AI
| assistant a bunch of personal information. For the same
| reason people have trusted google with health data.
| k8svet wrote:
| > have you used Oauth with google/facebook or the like to
| login and register with online services?
|
| No, I don't use federated login _anywhere_. I can show you
| my Google account. The only place I 've compromised is
| Tailscale, and I plan to replace that imminently. And
| frankly I consider it lazy of them to not support email,
| especially since google.com accounts are single-tenant
| anyway. _And tailscale never sees my password, never has
| raw access to my entire damn account, etc, etc_.
|
| Also, besides, federated login or delegated access, sure,
| OAuth is great, I wouldn't have commented in this thread if
| they were using it. Typing my raw creds into a [redacted]
| VNC session is not comparable.
|
| >Did you give Uber or Lift your credit card number? What if
| they were a scam?
|
| I call my credit card company. They reverse the charge, and
| ding the merchant. My life goes on. Takes a shockingly
| small amount of time.
| skywhopper wrote:
| It can't achieve what it advertises, though. I mean, what even
| did it advertise? Voice transcription? Playlist management?
| Phones do these already. "Order me a pizza, whatever the most
| popular option is"? That's laughable. No one actually wants
| that.
| GaggiX wrote:
| We already know that the large action model would not be
| available at launch, but I wonder how well it does works as an AI
| assistant.
| godelski wrote:
| Please upload source in an unzipped format. If the concern is
| about GitHub taking it down, use an alternative. There's plenty
| and many other ways to distribute source in an uncompressed
| manner.
|
| Otherwise this is indistinguishable from a hack. How do I know
| these zips are secure? The mega and pixeldrain report different
| sizes. Rabbit is entirely about hype and a scam, how are we
| supposed to know this isn't the same nefarious ploy?
|
| I appreciate what's being done and think it's good to call out
| these scams (I've done so myself) but help by building some
| trust. We understand the need for anonymity but a nefarious actor
| could just as easily mascaraed as the same repo. And if you do
| need files downloaded, provide hashes.
|
| (Fwiw, xz, despite recent events, is great at compression and can
| help you reduce your bandwidth if needed)
| titaniumtown wrote:
| > (Fwiw, xz, despite recent events, is great at compression and
| can help you reduce your bandwidth if needed)
|
| zstd level 22 is even better in my experience
| nebulous1 wrote:
| What is the reason for it to be uncompressed?
| mimischi wrote:
| I suppose the risk of a 0-day in the compression format,
| given we're in the post-xz-era. Publishing the source code in
| clear text would alleviate such risk for the consumer
| godelski wrote:
| 1. I can read it on my phone or in my browser.
|
| 2. Why should I have to download text to __read text__?
|
| 3. We don't want to normalize unnecessary behavior that is
| something scammers and bad actors can easily take advantage
| of.
|
| While I don't believe the leak is nefarious or contains an
| exploit, normalizing a requirement to download files that can
| issue exploits -- when there are easy alternatives that make
| this unnecessary -- just helps create the exact type of
| environment that scammers thrive in. 3 is incredibly
| important. If we're going to call out scammers we shouldn't
| do it in a manner where we're enabling an environment for
| more scammers to thrive in. Doing what's done here just
| created a rich opportunity for hackers who can now post a
| "rabbit source code leak" and just provide people with a
| different link. Makes for easy picking. Uncompressed and
| readable code just makes this harder and easier for people to
| determine if something nefarious is going on.
| nebulous1 wrote:
| It's not a single file unless it's tar'd or compressed or
| whatever. It's completely normal to distribute software
| projects as some form of archive. This is doubly true for a
| "leak" like this where you want the single file to spread
| around.
|
| I agree that it would be nice to have it browsable online,
| like in a github repo or whatever, but that's a separate
| issue.
| godelski wrote:
| > It's completely normal to distribute software projects
| as some form of archive
|
| Again, I think you're missing my point
|
| >> normalizing a requirement to download files that can
| issue exploits -- when there are easy alternatives that
| make this unnecessary -- just helps create the exact type
| of environment that scammers thrive in
|
| Yes, it is "normal" and that is exactly the problem.
|
| Ask yourself this Is there a reasonable
| alternative? Is downloading necessary?
|
| I think you'll find that the answer to both is
| unambiguously "no." I think you'll also recognize that
| having the readable source __also__ unambiguously creates
| higher utility.
|
| So you don't need to explain to me that this stuff is
| normal because I already understand that (and am actively
| demonstrating a knowledge of this). I realize
| communication isn't always obvious, but if someone is
| telling you that you're missing the point of what they're
| saying, please consider that you might actually be
| missing the point rather than doubling down. Even if you
| aren't, someone telling you that indicates that somewhere
| there's a miscommunication, and that needs to be
| resolved.
| nebulous1 wrote:
| I would prefer that it is distributed as a zip. It allows
| me to easily get the entire file, and hash it to make
| sure it's the same file as other people are getting, and
| have an archive of it.
|
| I would also like to be able to browse it online, but
| this is a usability issue for strictly when I'm intending
| to read it in a browser alone.
|
| As to your final paragraphs referring to communication
| and me "explainig to you that this stuff is normal", you
| specifically said that "We don't want to normalize
| unnecessary behavior" which implies that you do not think
| it is already normalized. You're also implying that I
| should have altered my interpretation of your words when
| you said that I was missing your point, even though you
| didn't say I was missing your point until the same reply.
|
| In any case, I think I understand your POV regarding
| archives, and I disagree.
| godelski wrote:
| > I would prefer that it is distributed as a zip. It
| allows me to easily get the entire file, and hash it to
| make sure it's the same file as other people are getting,
| and have an archive of it.
|
| I mean hosting it on any GitHub alternative makes this
| possible too. We also get better archival because when
| things change, we can see. Considering this says "Part 1"
| I expect things to change. History tracking is better for
| archival.
|
| > you specifically said that "We don't want to normalize
| unnecessary behavior" which implies that you do not think
| it is already normalized.
|
| That's not accurate. Here's a counter example "We don't
| want to normalize clickbait headlines." Clickbait
| headlines are already normalized, that does not mean we
| want them to be nor does it mean we should accept them
| and not fight against them. I'm sure you can find many
| other similar examples.
| andrewflnr wrote:
| To me the question is, why would you put source code on
| github if you're _not_ going to make it uncompressed? What 's
| the point of using a source code hosting website if your
| payload is a link to an upload site? Pastebin sites have been
| around for years.
| godelski wrote:
| Exactly. Similar questions Why does a user
| need to download a file to achieve the goals? Does doing so
| provide added utility? Does obscurification provide
| some benefit? Does distribution in this manner help
| normalize environments which scammers take advantage of?
|
| I'd argue: - Don't make users download
| things they don't have to. - Serving in plain text
| gives higher utility as users can view it on any device
| (e.g. mobile. Am I the only one that reads repos on
| mobile?) - A GitHub alternative also provides the
| capacity to download an archived zip, thus achieving any
| benefits that aren't obscurification related - Git
| helps for better archiving as we can have a track record of
| commits and changes (this is labeled "Part 1"!) -
| Did no one else notice that there are ".github" directories
| with workflows? But there is no ".git" folder? I'd honestly
| like that... - While a zip itself is not an
| executable and not generally dangerous in of itself,
| scammers (hackers) do take advantage of such environments.
| Because you can... change a file extension. Or because a
| user may double click the zip to extract, but this will
| cause execution. Or idk, hackers are fucking smart and
| people are dumb.
|
| I'm a bit peeved that people feel the need to explain to me
| that a zip isn't nefarious in of itself, because that's not
| what I was concerned with (and that there's several such
| comments and we don't need to keep repeating the same
| comment...). My concern is with how such formatting is (as
| best as I can tell) not necessary, suboptimal, and
| normalizes practices that nefarious actors take advantage
| of. This topic is obviously hot, so I won't be surprised if
| there are "alternative links" that could just contain
| straight up maleware. Yeah, the user has to execute it, but
| people are dumb, lazy, and/or tired and there is a *
| _better*_ form of distribution that just doesn 't leave
| this script-kiddy style attack around. Like for fuck's
| sake, people at intelligence agencies plug in USBs they
| find on the ground...
| wibbily wrote:
| I've nothing to do with the leak itself, so can't help you
| there. But did check - both archives are identical, and contain
| a Node project that seems to match what is claimed. (Run it at
| your own risk.) $ md5sum lam.zip
| 3a78b14e1379ac5c059dbbe5660fca8a lam.zip
| godelski wrote:
| Thanks! I don't actually assume that the person is being
| nefarious, but I think it is also important to make sure that
| they understand these things. Especially if we're talking
| about scams.
|
| Scams take advantage of what is normalized, it is how they
| fly under the radar and bypass people's bullshit detectors.
| It's why a safety vest, hardhat, and a clipboard is the most
| covert disguise around. So one of the best ways to prevent
| scams is to normalize behavior that is harder to take
| advantage of! (same reason people fall for fake voice scams,
| because we're so used to distortion in calls anyways. A
| glitch poor voice can be difficult to distinguish from poor
| cell reception)
|
| As for the filesizes, I assume it is just the websites
| reporting incorrectly. Pixeldrain reports 188 MB compressed
| and 510 MB uncompressed. Mega reports 179.r MB. Pixeldrain at
| least shows all the files, which look to not have been
| cleaned up since they have things like .DS_Store. But at
| least the files are individually downloadable.
| fwip wrote:
| 179 MB if a megabyte is 1024^2 bytes, 188MB if it's 1000^2.
|
| Zip files aren't evil, just unzip them and look inside.
| godelski wrote:
| I think you're missing the point of my comment.
|
| The point of the comment and request is about not
| requiring technical knowledge and minimizing amount of
| necessary thinking. The point is about helping stop
| scammers in the first place!
|
| > 179 MB if a megabyte is 1024^2 bytes, 188MB if it's
| 1000^2.
|
| This is not entirely correct though because MB != MiB. Us
| on HN will probably know this but proper labeling helps
| prevent mistakes. The improper labeling requires us to
| think more when considering security, which is bad
| security (not that you shouldn't think, but I'm saying
| "don't set off alarms when you don't need to set off
| alarms")
| dns_snek wrote:
| > This is not entirely correct though because MB != MiB.
|
| The point the parent was making is that the file is
| 188026773 bytes long. One site represents that as 179 MB
| (base 1024) and the other one as 188 MB (base 1000). Your
| complaint is therefore with one of the websites and not
| with the uploader.
| kish_kush wrote:
| uncompressed and compressed have nothing to do with what you
| said. you can choose to run the code or not, but it doesn't
| have to do with the uncompressed thing.
| godelski wrote:
| You're missing the point. The point is to make it harder for
| scammers. Yes, I can safely extract files but on many systems
| if you double click a zip instead then there you go. Either
| way, it is always best to not download when you don't have
| to.
|
| The question here is "is there a reasonable alternative that
| doesn't require the user to download." The answer is
| unambiguously "yes" and unambiguously has higher utility.
| indrora wrote:
| a zip archive is not executable unless something has gone very
| wrong.
| godelski wrote:
| You're missing the point. As I've been explaining in other
| comments which have expressed the same thing as you have
| (please read to reduce noise and repetition), the point is
| about not normalizing environments which scammers can easily
| take advantage of. And clearly, the request has higher
| utility, so in either way, it is an advantage.
| meindnoch wrote:
| Bro, it's a zip file. It won't set your computer on fire.
| godelski wrote:
| Bro, no one claimed this.
| mrstone wrote:
| At the very least, here's a scan from Jotti.
|
| https://virusscan.jotti.org/en-US/filescanjob/svl9focwgt
| extr wrote:
| I really think this + the humane AI pin would be super
| interesting products if they made them hackable. The hardware is
| super cool, no problem if the software isn't there yet, it's not
| like they're being sold at Best Buy, I'm not worried about my mom
| acquiring one of these and getting her passwords leaked. Who
| cares if the auth flow is super hacky/insecure? Let us self host
| it! Let the community create more playwright scripts!
| roughly wrote:
| Humane is founded and populated by ex-Apple folks, so I
| wouldn't hold my breath.
|
| You're right, though - it's a bit weird because ostensibly the
| interface is via the GPT system and you've gotta work through
| those interactions (same problem Alexa had), but given how
| early both the platform and the product category are, they'd
| benefit big from letting early adopters build capabilities for
| them.
| harryp_peng wrote:
| Worst possible thing is that bozos learn the closed source
| model. The closed source model only worked because they had
| the Great SJ.
| 999900000999 wrote:
| Agreed.
|
| The Rabbit R1 looks like it would be the perfect device to play
| with.
|
| As is I just assumed Rabbit was sending off pictures and stuff
| to a Chat GPT API or something. I never assumed the models ran
| on device
| disconcision wrote:
| this exists!
|
| https://www.openinterpreter.com/
|
| even their hardware is (apparently) open-sourced
| spaceship__sun wrote:
| But how is an hardware version of a mic/speaker anything
| interesting? The humane AI pin, to which you wear and gets
| contextual data, is the only wearable of interest to hackers.
| vineyardmike wrote:
| If you want something fun and hackable look at these glasses:
|
| https://brilliant.xyz/products/frame
|
| They have shipped products before, and they include a bunch of
| code - _today_ on GitHub to start hacking with.
| phh wrote:
| > In reality, they're simply relying on several Playwright
| automation scripts to do the job for you, which is why they only
| support four apps: Spotify, Midjourney, Doordash, and UberEats.
|
| I think that part is mostly fine? I'd rather make give a LLM
| access to https://woob.tech to be my personal assistant while
| parsing 99% less noise, than have a LLM that parse and understand
| stupidly complicated web pages, and randomly fail at the task
| because the name of my doctor is bobby drop tables.
|
| That being said, it can be interesting to use LLMs to assist
| creating woob plugins.
| vunderba wrote:
| Midjourney does not have a public API and I'm pretty sure that
| automating a Midjourney account is against the TOS, so I
| wouldn't expect that functionality to last long.
| saltsaman wrote:
| The problem is that they claim to have developed a
| groundbreaking Large Action Model when in fact it's just a
| playwright wrapper
| ach9l wrote:
| you can't automate playwright without a decision making
| component in front of it, they are definitely using a
| transformer there. one could train a llama and make it
| perform triggers to playwright automations. you can even get
| deep into transformer tokenization and create action tokens
| and a formal grammar for your generation, build a parser on
| top of your predict function and have a "lam" working. the
| fact that they use playwright does not imply it is not
| generative ai. i'd say it is really hard to do those actions
| without a transformer involved
| Jonovono wrote:
| What NFT projects were they involved with?
| ugh123 wrote:
| /s?
|
| Underrated comment.
| itishappy wrote:
| > Sadly, this shouldn't come as a shock to anyone who's done
| minimal due diligence on the team. After all, they were still
| hawking NFTs just two years ago.
| tripletao wrote:
| No sarcasm,
|
| https://web.archive.org/web/20221203132009/https://gama.io/
| ipsum2 wrote:
| I implemented my own DIY version of Rabbit at a hackathon using
| Playwright and VNC. I feel extremely validated that they use the
| same things that I thought of.
| ugh123 wrote:
| If it can do what it claims to do, which is automate on top of
| existing apps by your voice, whats the difference? Seems
| innovative regardless of the tech underneath.
| amiantos wrote:
| I'm really into AI stuff but both the AI Pin and Rabbit R1
| underwhelm. They are products that don't need to exist if the
| problem they're solving was truly solvable right now, because the
| best place for that problem to be solved is already in our hands:
| our phones. But we're not all talking to AI assistants in our
| phones all day. Why? Because the technology isn't good enough to
| do it yet? Because people don't want to talk to digital
| assistants? Once the tech is good enough that it can motivate
| ordinary people to look silly talking to their phones outloud,
| it'll be on our phones and easy to use, and there will be no need
| for kitschy little handheld devices. No one wants to carry around
| another device.
|
| That said, smart glasses sound like a great idea to me, but I
| wear glasses all ay long, so I am extremely biased. I don't think
| most people want to voluntarily wear glasses to just put a
| computer on their face, so I wouldn't bet on glasses, either.
| Sorry, Zuck.
| azinman2 wrote:
| I don't know why I need to keep saying this, but the point of
| the pin is to replace phones. It's meant for you to have access
| to digital services while staying in the moment and avoiding a
| screen. Many ppl are addicted to their smartphones, so they
| propose something different.
|
| You can like and prefer a phone but it's their raison d'etre.
| imiric wrote:
| It wasn't that long ago that it wasn't socially acceptable to
| have phone conversations in public wearing Bluetooth ear
| pieces, whereas now we don't think twice about it. A few
| decades before that, the same thing with portable music players
| and headphones.
|
| Society adapts quickly to technology, but, as you say, the tech
| needs to be good first.
|
| I think we've reached that point with voice recognition and AI
| assistants. It's now a matter of time until someone connects
| the pieces into a functional and accessible product.
|
| The reason smartphones are not the devices to get us there is
| because they're not a good fit for this use case. Pulling out a
| rectangular slab with a huge screen out of your pocket every
| time you want to interact with a voice assistant is enough of a
| UX hurdle that most people won't do it, even if it would be
| socially acceptable. Even if this was in a watch form factor,
| which we'll surely see as well, just bringing your arm close to
| your face would get slightly annoying over time.
|
| So a light pebble device you can pin on your shirt or wear as a
| necklace seems like a good form factor for this. The Limitless
| Pendant is another recent contender, and seems like a better
| thought out product compared to the Humane Pin. These devices
| aim to be unobtrusive, and disappear into the background, yet
| still remain deeply integrated into our lives. This is what
| technology is trending towards. I reckon the smartphones of
| today will seem primitive in a few decades, replaced by
| seamless VR/AR in glasses and primarily voice-driven wearable
| tech. We're currently in this transitional period where
| companies are investing in high-risk products to see what
| sticks, but eventually someone will launch something that
| resonates. Just like Apple did for smartphones in 2007.
| mulderc wrote:
| Why wouldn't the device just be your ear buds connected to
| your phone?
|
| I already use siri all the time as I usually have my AirPods
| in and it works great. That seems like a much more likely
| device to access our digital assistance than some necklace or
| pin. Better yet, you could just pair it with your smartwatch
| and not even need the phone.
|
| I'm still deeply skeptical on voice driven tech as we have
| had that available and easy to use from various devices for
| over a decade now and it hasn't taken off for tons of
| reasons. I just am not going to have a conversation with my
| computer with others around.
| vineyardmike wrote:
| So I agree generally,
|
| BUT existing phone companies have an incentive to maintain the
| app-centric world that keeps their app stores profitable, and
| app companies have an incentive to lock you into their app to
| keep customer loyalty and be "more than an API".
|
| All that's to say, the Rabbit idea of manually scripting
| against apps to allow "business as usual" for all these
| individual parties who wouldn't want to collaborate fills a
| void that existing players don't have incentives to fill.
| eterpstra wrote:
| Maybe they hacked together something that can feasibly me
| marketed as an AI-assistant knowing that whatever they build now
| will get "steamrolled" by GPT-5 (Sam's words, not mine). When
| GPT-5 gets released, update the OS and it'll work as
| advertised... EZ-PZ!
| xori wrote:
| Not much here explicitly in the source code dump. A little
| insight into their worker node infra but no "secret sauce" imo.
| saltsaman wrote:
| Isn't the secret sauce just VNC with playwright? What more do
| you need to achieve 80% of what they are showcasing (basic
| doordash orders, spotify controls)?
| rhinoceraptor wrote:
| I can't find any purported auomation scripts for those
| services as claimed in the Github page. There is a reference
| to "cm-spotify-client" which seems to be some sort of custom
| integration code they've written, but other than that there
| is no reference to doordash, midjourney, or uber eats. This
| dump seems to just be the code/infrastructure to run
| chromium/playwright in kubernetes, wrapped in a Node API to
| accept commands, persist/hydrate browser state, etc.
| mafuyu wrote:
| Pretty much in-line with my expectations. I ordered one because I
| thought the design was neat, and I was interested in hacking
| around and flashing my own stuff onto it. The pricing was clearly
| at or below cost.
|
| Looking at just the concept (and ignoring execution), I don't
| really see the point of this thing? The whole thing is a feature
| that could exist on a smartphone. The dream of an AI agent that
| you can converse with to replace your smartphone could be
| compelling, but nowhere close to reality yet. Even then, the big
| smartphone OS companies are obviously better positioned for this.
| The smartphone is the hub for all your information, plus they
| have years of voice assistant, automation, and home IoT
| integration to build off of.
|
| Humane was silly because it was a smartwatch without any of the
| proper software support, but Rabbit is essentially doing the same
| but targeting a smartphone replacement. If you really want to
| break out and try to dethrone smartphone vendors, you'll have to
| come up with something more compelling than a worse user
| interface to a poorly made software platform. That's a software
| feature you're building.
|
| In some sense, I do think Rabbit had a better approach than
| Humane, though. Getting a bunch of low-priced "toy" devices into
| the market that are just a frontend to your server software could
| get you off the ground. The software needs to exist, though...
| animex wrote:
| I just couldn't fathom the big three phone platforms not
| implementing this on a device that we all have and is capable of
| same if-not better dynamic voice integration.
|
| At the very least, I hope products like the Rabbit spur these
| companies to start innovating again. Even if they are smoke &
| mirrors, the interest shows there's demand for these features.
|
| Site Note: I've noticed Google Home's voice assistant has
| declined over time -- it used to handle complex queries and now
| it can barely understand simple directions. It used to understand
| me perfectly in the noisiest environments and now it makes many
| transcribing errors.
| redserk wrote:
| Like in iOS with SiriKit?
|
| Blame app developers for prioritizing implementing less useful
| features.
|
| https://developer.apple.com/documentation/sirikit/
| Wowfunhappy wrote:
| The problem with Siri is their voice recognition sucks,
| especially compared to e.g. Whisper.
| iamleppert wrote:
| Who cares how its made if you can make a bag from it before
| anyone is the wiser? The point in all this stuff is to make bags
| of money, whatever way you can do that don't matter as long as
| you gettin the bread.
| vunderba wrote:
| One of the bizarre talking points in defense of the existence of
| rabbit was to get away from our phones. It's just completely
| inexplicable to me because it's not like it was ever intended to
| be a replacement, the only difference is congratulations you now
| have to lug around two separate brick shaped appliances wherever
| you go...
| stranded22 wrote:
| They gave 12 months perplexity pro with it - and I am already a
| subscriber. So, I basically paid a bit extra for another 12
| months and a rabbit r1 to play with.
|
| If it doesn't work how I want, I should be able to sell on whilst
| keeping the perplexity pro sub.
| anon115 wrote:
| LOL
| m3kw9 wrote:
| The UIUX isn't good, AI models are useless without good user
| experiences
| serf wrote:
| I never understood the appeal outside the cute form-factor, all
| of the demos were absolutely terrible.
|
| an aside : npr doesn't like the 'spade' comment, although I think
| the explanation is kind of iffy.[0]
|
| [0]:
| https://www.npr.org/sections/codeswitch/2013/09/19/224183763...
| latentcall wrote:
| I thought the idea of the Rabbit R1 was cool. I have a strong
| feeling this will end up like the Humane Pin, which is sad. I'm
| glad companies are trying something different.
|
| I'd love to be able to use my phone hands free without having to
| look at it, and interface with ChatGPT/Claude/whatever but I am
| not sure if it's possible? Siri works very poorly and is
| unreliable. I'd like to be able to use an LLM as a personal
| assistant. Set timers, call people, message people, but also be
| able to ask questions like the voice chat function in the ChatGPT
| app. Maybe one day!
| mulderc wrote:
| I must be a Siri unicorn but for setting timers, calling
| people, messaging people, controlling my smart home, adding
| things to my shared shopping list, adding items to my 3rd party
| task manager, controlling my music. It works great!
| NetOpWibby wrote:
| According to their CTO in the Discord[0]:
|
| > If someone spends enough time with the login minions they can
| extract these code. But these code are locked down and are
| sanitized. LAM lives elsewhere. This is someone looking at the
| rabbit hole not understanding how it works. And tries to be
| smart.
|
| [0]:
| https://cdn.discordapp.com/attachments/1185274946981732374/1...
| patleeman wrote:
| Can somebody translate this?
| floren wrote:
| "Shit, shit, shit, shit! Dissemble!"
| _heimdall wrote:
| The original claim in the code dump is that no ML tools are
| used at all and the tool is just leaning on Playwright to
| automate specific actions on a website.
|
| The CEO here is claiming that the ML code is being run
| outside this code base and that the original claim is being
| made by someone who doesn't know how the code works.
|
| The CEO's mention of sanitized code isn't as clear to me,
| that can mean different things. Compiled code can be
| considered sanitized since it likely isn't human readable,
| obfuscated code makes that harder, and removing some code all
| together would be the most effective. The problem with
| removing code all together is that you would still find code
| paths that just can't be executed at all, leaving some trail
| of what code was removed. That wouldn't leak any secrets
| obviously, but would support the argument that code has been
| removed and the codebase is being misread.
| threeseed wrote:
| I think it means to say that:
|
| 1) The got the code by bruteforcing the login credentials on
| device.
|
| 2) Server-side code is not accessible which is where the LAM
| runs.
___________________________________________________________________
(page generated 2024-04-23 23:01 UTC)