Show HN: Quake ported to safe Rust, playable in browser(quake-srp.pages.dev) |
Show HN: Quake ported to safe Rust, playable in browser(quake-srp.pages.dev) |
Just the cherry on top of great demonstration of our collective new superpower: asking computers to do something we can describe how to do, but would (probably) never take the time to do ourselves.
[0] https://github.com/terrapapagalli1516/quake-srp/tree/main/or...
There are so many more degrees of freedom, which I can see Claude handled... mipmaps, subtle differences in lighting/positioning/compositing etc.
How long before the same thing is done to like, banking back ends? Wallstreet proprietary software? Amazons logistics and distribution systems?
It seems like we might be weeks/days/hours before a situation where someone back engineers and spoofs a system so pivotal to modern human society that the plug needs to be pulled.
Porting software is painstaking grunt work which still takes a moderate amount of intelligence. It's therefore extremely expensive to port say, COBOL banking software running on mainframes, to another language like Java. That's why a lot of COBOL software is still in use. I expect this to die out in the coming years as many of these systems will finally be ported to another language (could be Rust or any other language).
why would a recreated system be detrimental?
If currently there's a monopoly on a software, this AI recreation is a good outcome to poke holes in that monopoly. It's only bad if you are financially invested in said monopoly, and this would be a minority compared to the amount of benefits that society at large could obtain.
As someone who works in a bank: depending on the exacty subsystem of a bank the answer is from "already" to "in 3-5 years".
The plug being "the cloud" and "hooking everything up to the same internet".
These confusion attacks can only confuse people, because critical systems can exist in the same space where entertainment systems and all other categories of systems live. This was wrong even before LLMs.
I don't see any need for this. Rust is brilliant but the Quake C++ code was already more or less bug-free.
Since this ended up on Hacker News, I'll say it: I find the discourse around LLMs strangely sad. They're annoying, yes, and they make mistakes every day, every hour. But they're also amazing, and working with them has been one of the most rewarding things I've done in years.
Historically things that make people more productive have tended to make us richer, not poorer. And it's a virtue to change your mind as the evidence comes in.
We played with Lego all our lives; now the Lego understands us and helps us build. I think that's something to be glad about.
Obviously gameplay bugs are still possible in Rust, but many of them are not.
It was indeed human assisted.
I wholeheartedly bless this slop.
Found the repo in the Reddit post:
https://github.com/terrapapagalli1516/quake-srp
https://www.reddit.com/r/quake/comments/1x1ch14/quake_srp_sl...
I like these
I think 'standing on the shoulders of giants' is the phrase for something like this. It's the confluence of browser rendering, WASM, Rust, and LLMs. For me it's less a demo of what AI can do, and more a showcase of the human effort from the past few decades on the parts that needed to fall into place for an LLM to come in at the (relatively speaking) last second and claim a win. Sure, an LLM did the port from C to Rust, but think of all the things needed for it to all work. That's pretty damn amazing, and it wasn't done with AI.
.... /s, if it needed to be said
Fucking missed it.
Quake in Flash player from 2009 I think
You can play Half Life right now, with one click.
Because I did and it's the playable allegory of the cave but in vibecoded rust.
From what I understand, the adobe guys software is not great.
What this exploits is the mental shortcut of "rust = good", which might be a good thing, as that was always wrong. But now it is being pushed to its breaking point so that that idea will eventually collapse.
Accelerationalism on a micro scale, basically.
AI keeps breaking things that were broken before like this constantly. It's the great cleanup of old bullshit. (Unfortunately through even more bullshit, but at least there is a silver lining)
It would have been impressive before LLMs, but now? Who cares? Why is this here?
Also, the C version of Quake compiled to WebAssembly and running in browsers is just as "safe".
If you're not going to do that don't post your results online, just keep it to yourself. Anyone could've done this. Even people without any programming skills.
But "this" has been shapeshifting somewhat constantly. We're dynamically crossfading from one dysfunction being blown up to the next.
AFAIK Rust doesn't check for integer overflow in release builds, so that would still be exploitable.
It's also partly why some people preferred snapshot tests that compared the DOM tree instead, though that was brittle in other ways (e.g. tests would break if an application's frontend used a major UI library and an update to the library permuted the order of classes in some part of the HTML).
As a proof of concept however it shows that we are at the stage where any malicious actor has a very low barrier to entry to cause large scale corporate espionage etc.
It's easy to create a set that looks as if it was a real city. It's infinitely more hard to create that real city.
But you're absolutely right that a set is all it needs for all sorts of (cyber) attacks.
In the past you'd need nation state actors with considerable budgets to do this kind of thing, and we're on a trajectory that could see any kid in his bedroom could do it.
And i assume you don't truly mean spoof as in man-in-the-middling someone - i assume you mean the end user knows they are using an alternate system and are not being defrauded. Like using a photoshop replacement.
I am, actually, talking about MITM attacks that are much further in scope than just defrauding some people using their banking app. I work in resources and operate HMI systems that are networked, but not exactly the bleeding edge of modern software development. If you had an ability to decompile it and recompile your own version you could start sending instructions to infrastructure all over the country - the only thing stopping you is the keys, which if you're intent on hacking someone you'd have the means to obtain anyway.
I can see a lot broader attack vectors than just stealing peoples money. It's the erosion of trust in the api calls themselves.
Only in your opinion :)
Sure this project won't save humanity or optimize some KPI pleasing some obscure hierarchy.
Let people have fun, as long as they don't hurt anyone personally I'm fine with it and even I'm happy learning someone had some cool moments.
It's of course everybody's personal choice, and it's nice for an experiment to figure out what Claude can do. But why go on HN and brag about a project entirely created by Claude when literally everybody else can do the same thing without lifting a finger?
It's getting to the point that LLM produced code is indistinguishable from even the best handwritten code.
There's no value in gatekeeping,the code side of software is becoming increasingly democratised, and the barrier to entry is getting closer to no barrier at all.
...I mean...I just don't really know how to respond to that. Who the heck cares if someone posts this online? If you don't like it, just move on. Sheesh. Lookout everyone, this guy doesn't approve of your side project.
"hey i want to make an image editor, can you look into how photoshop does field blur"
"oh nice job implementing it, but the output is not pixel for pixel the same, can you check how photoshop does it - i have it installed right here"
"oh it still has some bugs - can you look into the precise algorithm they use, is there perhaps any software i can install to help you with that"
"oh i see the NSA has a thing called ghidra, would that be useful?"
I gotta try that
I hope the future is brighter because the present is bleak.
Consequently it’s missing tons of features.
In my little game restoration project, Claude just holds me to the commonly accepted standards and makes sure none of the original assets ever make it to the git repo its working in. I only once had to assert that occasional game screenshot to illustrate some doc is acceptable - again, it didn't argue the point, just said something about abundance of caution.
No trickery needed.
The other agent then implements the documented journey.
Tons of tricks, but really, you don't need frontier models. We're way beyond that stage.
Obviously you need to have access to the keys, BUT I don't see this as a dealbreaker anymore because you just get your agents to go and find them.
Photoshop has been around for around 35 years, fraud has always been an issue. There are plenty of reports of people selling things via Facebook marketplace and the ‘buyer’ showing them sending a payment on a fake baking app. Fraud will always exist and I don’t think tech will make it worse, everyone needs to be more cautious and tells friends and family to be the same.
I'm talking about cloning hmi platforms to send fake instructions to offshore oil platform valve bodies or insert false market trades to collapse companies.
Alternatively, you just act as a middleman drop shipper and slightly raise the price more than Amazon’s and skim the difference. It might be a while before they find out.
Currently a plague in some European countries.
It looks like the real site, and you pay twice, in the fake app, and later the police.
No room for hostile social engineering.