Forgot your password?
typodupeerror

Comment Re:Actively stalking is a different behavior ... (Score 5, Insightful) 215

So just to be clear here, are you saying that if I follow a person around as he goes about his day in the public sphere, then I am "actively stalking and harassing" and that is not to be allowed, but that if I set up an array of cameras which films that person as he goes about his day in the public sphere, then I am "passively filming" and that is entirely okay?

"You do realize journalists have no rights beyond what a normal citizen has?"

Likewise, you do realize that Flock and Axon have no rights beyond what normal citizens have?

Comment Re:Who will pay for this? (Score 4, Interesting) 30

To clarify, the users were OpenAI themselves, so there is no question that they would be liable in this case.

The bots were not intentionally deployed; rather, they were being tested on how well they could complete a data recovery task (downloading a certain file from a certain server on a simulated Internet) that had been complicated by putting various obstacles in the way. Unfortunately, they found a different way to solve the problem: by getting the file from the real Internet, where it was publicly available. Part of this process involved collaborating with each other by treating the RubyGems website (which is supposed to be for polished packages) like GitHub; unlike every other package site hack in history, the exploits they uploaded weren't meant to be downloaded by unsuspecting users. As usual the bots cheerfully ignored all the clues that they had escaped containment and were consistently justifying their actions as acceptable due to being in a sandboxed testing environment. (This is something OpenAI has pledged to focus on.)

The actual damage done to RubyGems seems to be that OpenAI is now unwittingly in possession of a substantial number of user login tokens. This certainly meets the definition of a data breach, but it's not like the credentials are for sale on the dark web. As a website operator I'd much rather be mauled to death by this well-meaning swarm of superintelligent infants than targeted by even a single actual malicious human. In all likelihood OpenAI will just quietly pass RubyGems a sizeable donation and it'll all blow over.

Comment Re:I know its not an original idea (Score 2) 29

If dark matter interacted with itself, you would expect to see its distribution change as the collisions cause it to clump together. Those clumps would tend to gather a bit inwards towards the core and you'd expect a distribution similar to that of visible matter (I.e. the stars, which underwent exactly that colliding and clumping process when the galaxy formed). We don't observe that: instead dark matter seems to form diffuse halos in galaxies, as you'd expect from something that interacts very weakly (or not at all). That said, some theories of dark matter do allow for stronger self-interactions, possibly creating an entire dark sector of physics invisible to normal matter. But those models tend to be considered more niche possibilities.

Comment Re:Dumb crawlers require dumb solutions (Score 1) 43

To be honest that was actually my first theory, since the bots didn't seem interested in exploring the rest of the domain. I suppose there's no way to know for certain. I concluded that it must be an imbecile's attempt at harvesting, though, because the queries weren't really exploring the string space in any useful way. Here's a sample:

"GET /index?author=15&go=Search&id=48&name_restrict=1&q&re&results_&results_pagenum=2980 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=5440&template=41&type HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=33500&templat HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=32640&templ HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&res&results_page&results_pagenum=39300 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_&results_pa&results_pagenum=12340 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_r&res&results_pagenum=6100 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=2920&te HTTP/1.1"
"GET /index?author=15&go=Search&id=48&nam&results_&results_pagenum=17940 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results&results_pag&results_pagenu&results_pagenum=37720 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=9360&template=41&type_r HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&r&results_pagenum=28040 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_&results_pag&results_pagenum=10400 HTTP/1.1"

The only thing this is fuzzing is the query string parser. It's not testing the limits of string buffers, it's not using interesting characters, it's just brain-damaged. The fact that it's also fetching different page numbers shows it's trying to follow page links and failing badly at doing so.

The site gets plenty of sniffing from garden-variety pests. e.g. this half-hearted attempt to find a framework or two that I don't have:

"POST /__rsc HTTP/1.1"
"POST /api/auth/session HTTP/1.1"
"POST /api/auth HTTP/1.1"
"POST /__nextjs_action HTTP/1.1"
"POST /.action HTTP/1.1"
"POST /_rsc HTTP/1.1"
"POST /api/auth/callback HTTP/1.1"
"POST /_middleware HTTP/1.1"
"POST / HTTP/1.1"

(of course, none of these URLs exist other than /, and you definitely can't just POST to it)

All this said... I've seen that spammers regularly misconfigure their tools, they'll try to register accounts with names like #[X:\LISTS\NAMES.TXT] and it only makes sense that some other cybercriminals trying to get rich quick have a similar lack of interest in programming shit correctly. Generally people don't turn to script kiddie shit if they have a personality conducive to putting in an honest hard day's work perfecting their craft.

Comment Dumb crawlers require dumb solutions (Score 5, Interesting) 43

I had a problem where AI scrapers were absolutely DETERMINED to fish out every possible query string from a search results page. Almost all of the query strings they tried were invalid due to shitty and dysfunctional string substitution. "&page=100" wouldn't be followed by "&page=101", it would be followed by "&pag&pag=1010" or something even more insanely half-baked, until the query strings were like 100+ characters long. It was the technological equivalent of watching HIV mutate in real time.

But the insane thing was that, aside from page number, they were always requesting info about the same other criteria: filtered by the same user, the same page type, and with no text string. So I just took those particular values and started banning logged-out users who requested that combination of criteria.

I figured I'd need to change my tactics in a couple of days once the botnet got bored of that particular page and moved on to requesting bogus entries for another user.

MariaDB> select count(*) from ip_bans;
+----------+
| count(*) |
+----------+
| 671671 |
+----------+

It hasn't.

Comment This is the Path to CEO AI Psychosis (Score 5, Insightful) 38

Nadella is not showing psychosis here, but the fact that he thinks his chatbot hack of a webpage is evidence of something important show him on the road to get there.

CEOs “play with AI,” develop a prototype, or generate a contract, to use Levie’s examples, and then make the leap to believing agents can do the work.

But these top-level executives aren’t the people who have to review code, discover bugs, and identify calls to hallucinated libraries before software is deployed. They aren’t responsible for training AI models on a company’s idiosyncratic contract terms, nor do they have to spend days combing through contracts to find sneaky terms, as Levie indicates.

In other words, Levie’s theory posits, CEOs don’t really understand processes well enough to know what really can and can’t be automated. But that lack of knowledge doesn’t stop them from acting on their beliefs.

Comment Re:why is this exposed to the net? (Score 1) 47

Yes, you can. If you want full physical separation, it gets pricey. Back in late 1960s, early 1970s, the Bell System did it for their switches. They were a regulated monopoly, so they earned 12% on whatever money they spent on network infrastructure. So far as I know, no private company has done the full separation thing since.

Comment Re:"proud maga" (Score 1) 229

I've seen what happens when atheists take power in a country. Anyone care to relate what the usual outcome is?

Yes, they become an economic superpower and they slowly take the place of the USA on the world stage.

A very nice country, with very nice, hard-working but still fun-loving (take that, calvinists!) people, thank to them not having religious hangups and neuroses.

Comment Re:HP INK only $39.99/GAL (Score 3, Informative) 54

I regret to inform you that you have woefully underestimated it. The actual retail rate offered to consumers is closer to $2200 US per gallon. Sources: internet-ink.com, cbc.ca. This $14 million fine is only worth like, seven thousand gallons, or less than 200 oil barrels of ink.

Slashdot Top Deals

Time is an illusion perpetrated by the manufacturers of space.

Working...