Forgot your password?
typodupeerror

Comment Re:Going to get worse before it gets better (Score 5, Insightful) 60

Most maddening for open source projects is the number of false positives exacerbated by multiple people trying to 'help' by running effectively the same security audit as a bunch of other people have done and trying to open issues that are duplicate...

Huge pain in the ass dealing with contributions from people who don't understand enough to analyze their LLMs "findings" and just pass them through "in case they are helpful".

Might be nice once the fad of "everyone contribute by running duplicate reviews" subsides though.

Comment Re:Great news (Score 2) 60

Note that this isn't even new to AI, the kernel has always been a flood of CVEs. The AI spotlight puts a bigger spotlight on it, but it has been a mess.

The real problem is that the average security team is mismanaged and forced to use terrible tools that report on yet fail to reconcile the status of the CVEs on behalf of the user and instead drives the team to have to figure out how to take care of it themselves.

Some twisted security mindset of going direct with CVEs as 'the most thorough vendor neutral approach' without instead leveraging distribution security advisories. So you end up with a security tool claiming you have thousands of security issues on an up-to-the-minute patched instance of the latest enterprise linux distribution because they backport and tools don't understand the version numbers.

Comment CVE management is just broken... (Score 1) 60

In the industry, so many security teams mandating CVE management software that is absolutely stupid and pushes off all the hard bits to the user.

It sees 6.12.0-211.34.1.el10_2... Well... none of that makes sense so it just assumes that it's just plain 6.12.0 and demands the user reconcile the reality. Now the security vendor *could* maybe integrate with the major linux distributions advisories... But no, more CVEs is better, when you demo that your product finds hundreds of CVEs, that just proves it is being thorough as far as upper management is concerned.

They offer up sound guidance here, skip direct CVE management and lean on your distributor. If you are doing CVEs direct, at *least* use the patched files to cross-reference against your build to see if it even in theory could matter. However the problem is the business of the security industry doesn't prioritize those, and so we have stupid tools inflicted on people, and pushing back against those tools carries a stink of "must not care about security then".

Comment Re:Great news (Score 2) 60

Depends on the number of realistically 'false positives'.

I've known a few people who find the kernel CVEs particularly unreasonable as they tend to aggressively assume security implications. If they grant a CVE to a 'mere bug', no one is going to get too grumpy over that specific item. If someone believes they have a vulnerability and do not see a CVE, then people get riled up. So some feel the kernel is just granting CVEs to avoid pushing back.

The other headache is the monolithic nature of the project. "Linux" covers just everything. A potential security issue in a device never seen outside of PA-RISC systems 20 years ago? It's a "Linux" issue, so every x86 system will be flagged as 'affected' by security software that cannot deal with nuance

Of course, we are here mainly because the kernel team largely recognizes the practice of trying to apply only security updates while avoiding 'only bug' fixes as pretty insane. So err on the side of caution make CVEs extra unmanageable because realistically it was a pretty crappy strategy for such a complex project anyway.

Broadly speaking, CVEs are usually pretty bogus, but a small percentage are very real and critical issues. You can't use the 'score' to really measure this either, it's not very good in the first place, and for example I saw the exact same issue in a C library and a python binding for that C library, and for whatever reason they graded the C library as 'minor' and python binding for that library 'critical', despite the python binding being nothing but a ctypes wrapper around the c library...

The Almighty Buck

Apple Partners With Klarna To Offer iPhones, Macs On a Subscription Basis (computerworld.com) 43

Apple is reportedly launching a Klarna financing deal that will let U.S. customers spread the cost of devices over up to three years, pushing the company closer to a hardware-as-a-service model. "The only thing you don't get under the new arrangement is AppleCare, for which you'll allegedly need to pay extra," notes Computerworld. From the report: The introduction of the scheme gives consumers a way to purchase the company's popular high-end devices when they are introduced -- no doubt,at higher cost -- this fall. [...] A combination of changed customer habits and external threat means the stars are now aligned for hardware-as-a-service models. "Reframing a device as a low monthly payment protects that [upgrade] cadence and allows Apple to start marketing their products as device-as-a-service to consumers, which no other vendor was ever able to do," [IDC analyst Francisco Jeronimo] wrote to me.

There is a one-more-thing aspect to this: the products are effectively being leased, a new approach that will give Apple a stronger grip on EOL devices, helping it grab more of them for refurbishment, resale, and recycling. Over time, this will give the company a much stronger grip on the lucrative second-user market that exists around Apple equipment, even while for almost every consumer product we find the life we want is something we can rent, but probably can't afford to own.

The other solid reason to take a partnership approach is risk management. Apple had intended to develop its own buy-now, pay-later scheme via Apple Pay Later, but abandoned that plan as it became riskier with rising bank rates. "Also, by backing the program with Klarna rather than reviving the in-house subscription plan it shelved in 2024, Apple captures the demand upside without taking the credit risk onto its own balance sheet," Jeronimo said.
"Apple Upgrade lands at precisely the moment Apple needs it," Jeronimo wrote in a note seen by Computerworld. "Having just pushed Mac and iPad prices up on the back of the memory shortage, with iPhone increases widely expected in September -- as well as the new iPhone foldable expected at $2,500 -- Apple's real risk is that rising prices even further can impact the upgrade cycle."

Comment Re:Why only boys? (Score 1) 58

Here's a little more detail.

Researchers a few years back ran tests. ADHDers and neurotypicals were asked to harvest berries and edible plants.

Neurotypicals tended to over-harvest and damage bushes to the point where recovery would be slow if possible at all, and tended to pick areas clean, wiping out local populations of edible plants.

ADHDers tended to move relatively quickly from area to area, harvesting a decent amount from each area but not excessively. The quantities tended to be at the sort of level that have long been established as a good balance, such that plants and populations would tend to actually do better the following year. Not only that, but they tended to gather more.

https://www.psychologytoday.co...

Crofts and small farms rapidly went to three-stage and four-stage crop rotation, but different fields would be with different crops. This meant that the failure of a single crop would be much less of a survival thing.

You'd see fields with a mutitude of diverse crops, because diversity was critical. Failure was highly likely, so you localised it. Failure in one area had no meaningful impact overall. Things like the Irish potato famine and the parsnip failures across France in the 1700s were relatively rare in history. Likewise, when industrialisation wiped out cottage industries, farms that had been very successful suddenly went bankrupt and mass starvation was common. The ability to task-switch and have a large number of small projects going was essential to life at the edges.

You're absolutely right, more ADHD would have indeed curbed the excesses. The industrial revolution caused huge problems by trying to do too much with too little diversity. Which eventually destroyed the economies built around the early mills, because the markets were too easy to undermine. There was no capacity to switch. But during the IR, the obsession with coal meant nobody really looked at alternative fuels or alternative activities. Economies became tightly constricted, which was devastating when it came to global warming, but equally devastating when it came to distributing metal-devouring bacteria (which did enormous damage to infrastructure) and radioactive particles (old mill areas are still unusually radioactive).

More ADHD wouldn't have eliminated the problem, but it would have diversified the solutions and would have diversified the markets, resulting in a much more robust, much healthier marketplace and a much more robust, much healthier population.

Comment Re:Why only boys? (Score 1) 58

Uh, no. As in, 100% of gatherers would be ADHD. IF they weren't, you'd be extinct within the year. 20% of the hunters would also be ADHD, because over-harvesting was also going to wipe out your food source. 100% of your explorers would be ADHD, 100% of your experimenters would be AuDHD.

ADHD was essential to survival. If you didn't want to die out, you stuck the neurotypical outside so that the wolves and other nasties actually hunting (tigers wouldn't be present) would get them. Neurotypicals were the main threat to survival.

Comment Re: Automate me away... (Score 1) 90

Nothing you said precludes a bubble pop and investment problem, even if taken at face value. The fact that you are getting rate limited doesn't mean there isn't a bubble. That doesn't speak to the economics, how the demand is distributed, and whether or not that demand is durable as hype levels out.

As the post said, there may be "right" AI companies but there are certainly "wrong" AI companies and investors don't really know which is which and trillions of dollars are at stake with what will turn out to be the wrong companies. Some of the "wrong" AI companies are just stuff on top of the same provider you are using, so you are rate limited because they are also selling to less robust companies and when that less robust company goes poof, your rate limiting concerns may go away. Or your org is one of the less robust companies.

In the year 2000, plenty of folks got real strong value of the internet. But the bubble still popped and the markets dropped 40%. Hosting providers that were hugely constrained by the overwhelming demand at the time suddenly had capacity to spare. People continued to get value from the internet, but that was of little solace to folks whose livelihood was tied to one of the "wrong" internet companies of the day.

Comment Re:Automate me away... (Score 1) 90

For some, *maybe*, but keep in mind:

I have met a fair number of folks making $200k+ who were supremely underwhelming. They would have a very narrow wheelhouse and *only* do things within that, single language, single framework, stuff like that. Even then, you ask them to do something that they can't find an example of online already and they would be lost. We had a scenario where work hired a few of these folks to replace the front-end work that our 'full stack' team had been doing, because we had more money and we should develop it 'properly'. They started from scratch, had a fairly basic tutorial-fodder front end and customers complained about loss of features and the front-end team rejected as "impossible with new framework, so won't be done". Meaning they couldn't find anyone who did that on stack overflow, and the old UI wasn't written with Angular so they decided it was not applicable. AI may well supersede such folks fine.

For a fair number of these companies, if the realization comes that AI couldn't replace the personnel they thought it could, then the bubble is likely popping and taking some of these companies with it. If not completely, having to scale back offerings. AI isn't going away, so the people in the above example can't celebrate too much, but the realization that it won't replace the entirety of white-collar work will be crushing financially.

Even assuming they can and want the talent back, they may see their position as strong with all those other unemployed/underemployed developers out there, so they may not relent to an exorbitant consultant rate. It *can* work and work long term if things line up right. For example they begrudgingly get gouged on what they think is short term then realize they can't just bandaid it and let the consultant go. But it's far from guaranteed.

Slashdot Top Deals

Memories of you remind me of you. -- Karl Lehenbauer

Working...