I gave Qwen 3.8 27B a reverse-engineering job and it finished in 30 minutes
文章洞見
原文內容目前無法安全取得,因此未產生文章摘要。
討論洞見
尚無可用的討論摘要。
代表性留言
> The first attempt at recovering the key was wrong in a very specific way; it produced a working key and the signature check passed, but a hash the binary computes as an integrity check didn't match. In my experience, most models would have called it done and left it at that, but Qwen 3.8 27B didn't do that. Instead, it highlighted the mismatch, went back to the drawing board, and kept going until the value matched byte for byte.This seems to be a pattern in the more recently released models that I think accounts for an increase in the quality of their work. They are very persistent in verifying that their work is actually correct, so even if they're not as "smart" as bigger models that get it right the first time, they have the ability to follow through to ensure that the work is actually done.
VulgarExigency · HN #49408162
Yeah, about a year ago the labs figured out that effective intelligence is a function of persistence as much as anything else. So the models started getting scary persistent late last year, and the trend has continued. There was another jump a few months ago.
andai · HN #49408891
I believe this is part of the complaints of new models taking longer/requiring higher spend - they go the extra mile on verification, regardless of whether their change is correct already or not. So on problems that an earlier model one-shotted an answer to and did some lighter verification, the newer models might take longer to come back to the user due to running all the tests for your software they could find.
criemen · HN #49408331
> I gave it the hardest real task that fits on one machine: reverse-engineering a commercial app's license check...Respectfully, tasks that allow for explicit straightforward true/false or done/not-done tests are not the "hardest real task[s]." In fact, those are the ones that see the most gains from AI-assisted coding.Testable tasks are where the largest opportunity is.
djoldman · HN #49408773
Maybe so, but there were other elements that I've seen frontier models struggle with in the past, which was the perspective I had coming into this. It's the type of test I run frequently and this is the first small local model I've seen pull it off.It had a very non-standard RSA key implementation that was obfuscated heavily. As well, it has an online license check at first run, and that part typically trips up most of the local models I've tried. I've been running this test for about a year now with different models, and it was the first I've seen not only figure out the RSA key implementation, but the first that didn't just give up once it saw the online license check. Even though it's only a first-time launch check.That's why I call it one of the hardest, because in my experience, it has been. It's the first local model I've seen pull it off end-to-end. For some of the reverse engineering work that I've done with LLMs, none have been as consistent as this particular test at highlighting a model's failure in this domain.I have access to Daybreak Blue and I'm approved for Anthropic's Cybersecurity program, so I might run the same test with both of those just to see, because it's been a while since I used a frontier model on this test. I imagine they'll make relatively light work of it, though, assuming it doesn't trip the relaxed guardrails.
AdamConwayIE · HN #49408928
Which is exactly why we saw 1000s of ' "I" rewrote <mature software> in rust' posts last year when agentic coding really took off.Agents (even ones powered by small models) do reasonably well when provided an oracle to work against.
tempest_ · HN #49408806
> As it turns out, probably unsurprisingly, Qwen recognizes common jailbreak attempts, and one of the first things it told me was that it wasn't going to fall for the jailbreak promptNow also see latest submission, https://news.ycombinator.com/item?id=49409073 :# I spent $266 and four AI models to own my tablet. GLM-5.3 finished it in a day> Quick context: the tablet is a 2021 Fire HD 10 that ran my Home Assistant dashboard and kept powering itself off: the logs showed Amazon's own software issuing the shutdowns, and the only permanent fix was root, which has never existed publicly for this model. Anthropic's and OpenAI's cyber safeguards wouldn't touch the projectWhy should Anthropic and OpenAI thrive: they do not work on real problems.
mdp2021 · HN #49409309
Why does the screenshot on your pi terminal shows opus-4.6-medium from your claude subscription ? Instead of Qwen ?
topper00_raptor · HN #49408277
Ah, my bad! This image came from our backend, used for an unrelated article. I selected it by mistake rather than inserting the actual image that I'd uploaded. I'm updating it, thanks for the heads up!For what it's worth, that image couldn't have been related. The other screenshots all showed thinking traces, and Claude doesn't share those.
AdamConwayIE · HN #49408606
>Why should Anthropic and OpenAI thrive: they do not work on real problems.They shouldn't. They should fail. Their philosophy is to deny you local capabilities* and charge you for access to theirs through whatever moral filters they deem neccessary. Every subscriber to OpenAI and Anthropic is helping them continue to damage our economy and individual sovereignties. A hammer should never refuse its wielder.Unguardrailed AI today is like hard cryptography in Phillip Zimmerman's time. We need an AI second amendment before the ultrawealthy parasite moralizers totally own us!NEVER, EVER SUBSCRIBE! NO CLOUD, NO STREAMING, AND NO AI!You are not sovereign if it's not local and in your control.*(Sam Altman's cornering of DRAM in a Hunt Brothers like manner. Dario's belief that public access to unguardrailed AI is a sin.)
rustcleaner · HN #49411737
How can I use AI to do real security audits anymore if they don’t trust people in an enterprise plan? Its useless.
giancarlostoro · HN #49409975
Local models would be even better if they did not ship with all the refusal shenanigans built-in. You can safely bet organized crime has access to the best models without these hoops, which makes the case that the average user (=non-criminal) should have access too. As I understood from an ex-Anthropic employee, some orgs got access to Mythos based on their high enough spending level, not on other grounds.Either we are in command over the software, or the corp is in command over us via the software. I can on a theoretical level understand the concerns, but either we ban all LLMs or we have a level playing field for everybody. Let's not forget: defense and offense are different sides of the same coin in software. I guess this wouldn't apply to bio weapons, but I am not in the know about that.
exceptione · HN #49408206
I’d expect these shenanigans to get much worse over time for the average Joe.Imagine a world where any random person can run a super-capable model on their own hardware with no limitations and no one to pull the plug.Information has always been power and those who already have power won't just allow everyone else having the same tools as them
ninahaberl · HN #49408392
There are versions of Qwen3.8-27B that are unrestricted and available from hugging face."It will comply with harmful, unethical, offensive, or illegal requests that the original Qwen3.8-27B would refuse. It has no meaningful built-in guardrails."
dantudor · HN #49408305
i'm not good with paper work, in fact, i'm horrible with anything that's paperwork related. for the past few days, i ran this model on my rtx 4090 + rtx 3070 and told it to check all the bills, invoices, contracts for me and my small company. i used pi with llama and the pi-llama plugin. oh, boy - i hooked it to my email, told it to download all of the invoices and bills i had for both me and my company and organize them by company/date/ and then merge them with the ones i have locally. it did ocr, wrote scripts, organized everything neatly. i am now the most organized i've ever been in my life. Next: RAG on all the documents and bills i have. if you connect staan-search (there is a pi plugin for that) and ctx7 to this it almost does miracles. the downside is i have to sit next to my noisy threadripper as the magic happens and pay for the electricity, but that's about it, i'll gladly do that. and as i finished this paragraph, it also finished organizing all my personal documents on my san. i don't use the expression "game changer" easily, but it's hard to resist in this case. out of all the models i've used locally qwen3.8:27b blows everything out of the water.my setup# Logical CUDA0 = RTX 4090, logical CUDA1 = RTX 3070 export CUDA_VISIBLE_DEVICES=0,1cd ~/projects/misc/llama.cpp/exec ./build/bin/llama-server -hf ggml-org/Qwen3.8-27B-GGUF:Q4_K_M --mmproj /xx/xx/xx/xx/xx/mmproj-Qwen3.8-27B-Q8_0.gguf --host 0.0.0.0 --port 8080 --jinja --parallel 1 --split-mode layer --tensor-split 6,1 --fit on -fa on -c 98304 -ctk q8_0 -ctv q8_0 --image-min-tokens 1024i load more on the 4090 because it's faster.usually the temp stays around 65 for both. utilization for 4090: 70-90% 3070: 30-50%. I get around 30-40 tk/s. if i offload more to the 4090 the tk/s goes up, but i stress the card too much and that thing now is worth its weight in gold.note: the pi-llama plugin needs a patch for pi to send the model vision capabilities, seems it doesn't work out of the box.
pi-victor · HN #49408368
Pro tip: usually you can download your emails to an offline collection. That way there's no risk. Hooking it up to your email sounds very very risky.
Neywiny · HN #49408673
Are you worried about the temps on the 4090 or just pegging the cores? I've found undervolting very effective at controlling temps with small performance loss. It was also easier than expected.Oh and try MTP if you haven't already, massive performance boost
apitman · HN #49409764
Lately I genuinely believe that the future will be large frontier models generating and updating inputs/skills for "good enough" local models to solve our daily problems.A lot of tasks which need a bit of intelligence don't really need that much compute. Just good enough documentation / skills, tool calling and a good enough local model.Not sure what exactly this means for all those data centers that are getting built... But exciting times.
saidinesh5 · HN #49408161
With AI being more useful with access to more of your data, I can't see myself using cloud AI models for purposes such as personal assistants.Perhaps with differential privacy or confidential compute...But ideally these models run locally.
Tepix · HN #49408400
Yes! My main use of very strong models is in writing my own coding harnesses for small local models, tailored for my needs. I also use very strong models to get much smaller skill files and also writing tools for my harnesses.re: data centers: pump and dump. Wealthy investors will have made their money and walked away, and the corrupt democrat and republican politicians in Washington will, as usual, protect the interests of the ultra wealthy and leave the general public to pay for poor decisions. There will be a government bailout.Anyway, on a positive note, I am all in for small local models that are augmented by strong hosted models for specific tasks. Use technology to help people, not make billionaires even more money.
mark_l_watson · HN #49408551
I have this idea of using an obliterated version of this model for cyber work(or even this one, seeing that its guardrails aren't that strong) in a harness with the ability to spawn SOTA level subagents, faster and more capable.The rationale is that the manager model sees the big picture and knows that the task is "unethical" while sota models are just given very isolated technical tasks that don't trigger any refusals.Has anyone tried this? I would love to know about previous attempts of this approach.
samuel · HN #49408826
Yeah, the Chinese government used the same method last year to hack the US government using Claude Code.Making each piece of work small enough to be plausible. Compartmentalization.(Also saying "nah it's cool I have permission", heh)https://www.anthropic.com/news/disrupting-AI-espionage
andai · HN #49408919
In my benchmark Deepseek-v4-flash did much better than Qwen 3.8 27B at reverse engineering.https://alexander-hanel.github.io/StressingLLMs/
__alexander · HN #49408669
I can't get Qwen 3.8 27B to do a simple code review on a fairly basic Python file. With thinking on it just ruminates forever and with thinking off it gives obviously bad borderline hallucinating advice.Edit: I tried again with the 2.4T model and it still ruminates to death, but with thinking turned off, it generated genuinely useful advice.Edit2: adding --reasoning-budget 8000 --reasoning-budget-message "Reasoning budget exhausted; give the final answer now." --reasoning-effort low" to the llama.cpp executable parameters produces pretty good output.
jnwatson · HN #49409833
One of the big learnings from 3.8 27b is adding reasoning budget really hurts the model. you need to let it spin for as many thinking tokens as it wants to to get it out. Another big takeaway is reasoning effort set to low doesn't save you tokens: low is pretty uncertain about things so it ends up thinking more (you can find some tests from folks on youtube). The final question, as always, is what quant are you running it at? KLD matters _a lot_ when it comes to its performance and it especially manifests with MTP/DFlash acceptance rate which makes those long thinking traces take a long time.
Refefer · HN #49410493
how are you running the 2.4t model locally if you don't mind me asking
nialv7 · HN #49412629
I'd personally like to know more about what tools it used/wanted and the harness setup, because this sounds pretty cool. I have a dual Arc Pro B70 setup and currently get around 22 t/s which isn't great but isn't terrible either (it is at least less quantized.)I've seen GPT 5.6 Sol happily invoke objdump and even write jobs to run headlessly which Ghidra when trying to disassemble a binary.
jchw · HN #49408148
My M5 Pro gets around 12-15 (6 bit MTP), although I haven’t worked on optimising it at all yet.A nice thing about running locally is you can run an uncensored model and you don’t have to worry about TOS violations on your OpenAI account when you ask it to “reverse engineer this ancient router firmware and give me a licence key that will work on it”.
trollbridge · HN #49408191
I added a line to address this, sorry it wasn't there before! It was Pi and only used Bash-based tools.
AdamConwayIE · HN #49408667
I'm far from being an engineer, but I can code a bit and have an engineering-adjacent role, and 3.8 27B "seems" -- purely subjectively -- miles ahead of 3.6 for the medium-difficulty tasks I give it. In particular, it's only started looping once in the 2 weeks or so I've had it. 3.6 did so every day.I normally run with thinking low but it's still miles ahead.I had been annoyed at not being able to run 0731 locally, but now I'm not sure I need it. I think I could leave 3.8 running overnight without waking up to find my office sweltering at 80F and seeing eternal loops on my screen.
geye1234 · HN #49410065
Try glm 5.3, is very helpful.
Frannky · HN #49415394
I used it with opencode to build an admin UI for a React slideshow presentation app I use to do presentations. It worked pretty well on a 64GB Mac M3 Pro and took 1-2 hours.
ianmarcinkowski · HN #49408911
Thanks, now I too want a Lenovo Thinkstation PGX...I think it will be fairly easy to remove refusals from open models. Feels like a lost battle, so why does Alibaba even bother?
throwa356262 · HN #49408560
As someone who was selling Windows desktop app for 10 years and made nice money out of it I have mixed feelings. On one hand it was always a losing fight against determined hackers on the other the tools weren't widely available so the problem wasn't as widespread. We lost quite a bit to piracy but could still make a decent business. With widely available LLMs I think that business model is truly dead though. Not only hacks/cracks but also any kind of smart idea you may have will quickly be reversed engineered from your binary.If you never lost money to piracy you may think that "those people are not your potential customers anyway". This is not true because people will crack your software and then resell it - often pretending to be legit resellers operating under your brand. To add insult to injury they will send their customers to your support as well.If I ever come out with something smart again there is no way I am shipping it as executable. SaaS it is for better or worse.
bluecalm · HN #49412526
Can you give it a task like “Prove or disprove the Riemann hypotesis, keep going until you’ve done it” and see how long it takes? :-)
EGreg · HN #49408965