Forgot your password?
typodupeerror

Comment Re:Who will pay for this? (Score 4, Interesting) 30

To clarify, the users were OpenAI themselves, so there is no question that they would be liable in this case.

The bots were not intentionally deployed; rather, they were being tested on how well they could complete a data recovery task (downloading a certain file from a certain server on a simulated Internet) that had been complicated by putting various obstacles in the way. Unfortunately, they found a different way to solve the problem: by getting the file from the real Internet, where it was publicly available. Part of this process involved collaborating with each other by treating the RubyGems website (which is supposed to be for polished packages) like GitHub; unlike every other package site hack in history, the exploits they uploaded weren't meant to be downloaded by unsuspecting users. As usual the bots cheerfully ignored all the clues that they had escaped containment and were consistently justifying their actions as acceptable due to being in a sandboxed testing environment. (This is something OpenAI has pledged to focus on.)

The actual damage done to RubyGems seems to be that OpenAI is now unwittingly in possession of a substantial number of user login tokens. This certainly meets the definition of a data breach, but it's not like the credentials are for sale on the dark web. As a website operator I'd much rather be mauled to death by this well-meaning swarm of superintelligent infants than targeted by even a single actual malicious human. In all likelihood OpenAI will just quietly pass RubyGems a sizeable donation and it'll all blow over.

Comment Re:Dumb crawlers require dumb solutions (Score 1) 43

To be honest that was actually my first theory, since the bots didn't seem interested in exploring the rest of the domain. I suppose there's no way to know for certain. I concluded that it must be an imbecile's attempt at harvesting, though, because the queries weren't really exploring the string space in any useful way. Here's a sample:

"GET /index?author=15&go=Search&id=48&name_restrict=1&q&re&results_&results_pagenum=2980 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=5440&template=41&type HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=33500&templat HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=32640&templ HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&res&results_page&results_pagenum=39300 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_&results_pa&results_pagenum=12340 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_r&res&results_pagenum=6100 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=2920&te HTTP/1.1"
"GET /index?author=15&go=Search&id=48&nam&results_&results_pagenum=17940 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results&results_pag&results_pagenu&results_pagenum=37720 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=9360&template=41&type_r HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&r&results_pagenum=28040 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_&results_pag&results_pagenum=10400 HTTP/1.1"

The only thing this is fuzzing is the query string parser. It's not testing the limits of string buffers, it's not using interesting characters, it's just brain-damaged. The fact that it's also fetching different page numbers shows it's trying to follow page links and failing badly at doing so.

The site gets plenty of sniffing from garden-variety pests. e.g. this half-hearted attempt to find a framework or two that I don't have:

"POST /__rsc HTTP/1.1"
"POST /api/auth/session HTTP/1.1"
"POST /api/auth HTTP/1.1"
"POST /__nextjs_action HTTP/1.1"
"POST /.action HTTP/1.1"
"POST /_rsc HTTP/1.1"
"POST /api/auth/callback HTTP/1.1"
"POST /_middleware HTTP/1.1"
"POST / HTTP/1.1"

(of course, none of these URLs exist other than /, and you definitely can't just POST to it)

All this said... I've seen that spammers regularly misconfigure their tools, they'll try to register accounts with names like #[X:\LISTS\NAMES.TXT] and it only makes sense that some other cybercriminals trying to get rich quick have a similar lack of interest in programming shit correctly. Generally people don't turn to script kiddie shit if they have a personality conducive to putting in an honest hard day's work perfecting their craft.

Comment Dumb crawlers require dumb solutions (Score 5, Interesting) 43

I had a problem where AI scrapers were absolutely DETERMINED to fish out every possible query string from a search results page. Almost all of the query strings they tried were invalid due to shitty and dysfunctional string substitution. "&page=100" wouldn't be followed by "&page=101", it would be followed by "&pag&pag=1010" or something even more insanely half-baked, until the query strings were like 100+ characters long. It was the technological equivalent of watching HIV mutate in real time.

But the insane thing was that, aside from page number, they were always requesting info about the same other criteria: filtered by the same user, the same page type, and with no text string. So I just took those particular values and started banning logged-out users who requested that combination of criteria.

I figured I'd need to change my tactics in a couple of days once the botnet got bored of that particular page and moved on to requesting bogus entries for another user.

MariaDB> select count(*) from ip_bans;
+----------+
| count(*) |
+----------+
| 671671 |
+----------+

It hasn't.

Comment Re:That quote aged well /s (Score 5, Informative) 42

William Gibson wrote a new foreword for Neuromancer where he wonders how later generations will experience that first line with no experience of what a "dead channel" is... He spent three pages comparing the future he'd imagined to what did and didn't happen decades later. (Amazon only seems to have the version with Neal Gaiman's foreword.)

It was weird seeing a great science fiction writer volunteering all the guesses about the future that missed the mark. Gibson even wrote a new introduction for Burning Chrome where he said "Nothing acquires quite as rapid or peculiar a patina of age as an imaginary future..."

Comment Re:HP INK only $39.99/GAL (Score 3, Informative) 54

I regret to inform you that you have woefully underestimated it. The actual retail rate offered to consumers is closer to $2200 US per gallon. Sources: internet-ink.com, cbc.ca. This $14 million fine is only worth like, seven thousand gallons, or less than 200 oil barrels of ink.

Submission + - 'Dave Eggers doesn't need a smartphone, the internet or your Flock camera' (sfgate.com)

destinyland writes: Without a pen and paper handy, he was stuck texting the idea to himself. The problem? Eggers doesn't own a smartphone. "It takes 20 minutes to write a sentence," Eggers said... It's a funny predicament for Eggers, given that he's arguably the city's biggest proponent of the written word... Now age 56, Eggers’ latest book is called "Contrapposto "...

On writing days, Eggers bikes to his sailboat docked near the Golden Gate Bridge. He writes using a hefty 1998 Mac that has never been connected to the internet. On the boat, he keeps "banker's hours," working 9 to 5 without any meetings or interruptions except for the occasional wildlife visit. "You're there with the cormorants and the occasional porpoise and sea lions and seals, and when you want to take a break, you walk around and you're in the thick of it, one of the most beautiful spots on Earth," he said. "Especially coming from the Midwest, it never gets old."

Given Eggers' decidedly low-tech existence, it's not surprising that the current state of San Francisco gives him pause, but there's a streak of hope that underlies his concerns. He abhors the growing surveillance technology that's gripping the city, refusing to get into Ubers that use recording devices, but he feels a well-written ballot measure about Flock cameras could potentially save our dwindling privacy. ChatGPT's effects on the art of writing are demoralizing, but he welcomes that teachers are re-embracing pencil and paper, with cursive making a big comeback. The wave of artificial intelligence ads blanketing bus stops imploring companies to stop hiring humans are so over the top, they'd sound cliché if he were to include them in one of his dystopian tech industry novels like "The Circle" or "The Every," but tech philanthropy has helped many of his projects flourish.

Case in point, Art + Water, a new art space scheduled to open next year on Pier 29 funded largely by art world donations... Co-founded with the artist JD Beltran, the space is slated to operate as an old-school apprenticeship system, hosting 10 artists in residence mentoring 20 students, all free of charge... The ultimate goal is to break down the financial barriers that keep students from pursuing art.

Comment Re:Open source it then (Score 5, Informative) 52

The main aim of Stop Killing Games is to ensure the practice of rug-pulling eventually comes to an end. They are not trying to save MMOs, for example.

Moreover they don't demand that every game currently on the market comply with open-sourcing requirements: at a minimum, companies always have the option of simply providing customers with adequate notice before shutdown. Open-sourcing the server would be nice, but it's hardly the only way to protect consumers' interests. Scott has, for example, suggested game boxes being marked with an estimated expiry date for online service functionality.

But most importantly: because this is about future games, not the present, the market has time to change. If studios and publishers are designing their games with a fair EOL in mind, then they can make decisions from the get-go to avoid licensing dependencies that they won't be able to release in a possible 'afterlife' version of the game. As suggested by your example of GameSpy in C&C: Generals, when a commercial dependency is crucial to a game's success, it tends to be a client-side library, but typically the problematic dependencies aren't crucial; they're e.g. add-ons for Unity or Unreal that the studio bought to save time. In a world with SKG laws, the providers of these dependencies aren't going to be a stagnant target either—demand for compliant libraries will motivate development of open-source versions.

Interestingly, the will for doing this does exist among game developers; they just need the institutional support from legislation to twist the arms of the studios and publishers. Ross Scott has talked to a lot of devs who are burnt out from having their projects cancelled, leaving them with huge gaping holes in their resumes and portfolios where they've spent years on unreleased projects that are stuck under NDA. In general they tend to see SKG as a path to ensuring the games that do see the light of day aren't also scrapped, which would erode their work histories even further. (Apparently it also just plain feels bad to have your work erased from history. Shocking, I know.)

Submission + - 'Steve Jobs in Exile' Remembers the Birth of the Web, Making Unix Taste Sweet (arstechnica.com)

destinyland writes: Ars Technica shares some anecdotes from Steve Jobs in Exile , a new book released last month:

[Author Geoffrey] Cain reminds us, in stunning detail, that Jobs' "exile" era at NeXT was not only critical to his evolution as a man and an entrepreneur, but that it mattered for the rest of us, too. The technological innovations that came out of NeXT — notably, the NeXTSTEP OS — continue to live on in what we now call both macOS and iOS. As Cain puts it, "NeXTSTEP was Steve's attempt to make Unix taste sweet...."

[W]hile many tech nerds know that Tim Berners-Lee created the first World Wide Web server on a NeXT machine while working in Switzerland in 1990, few know that NeXT employees were wary of bringing the news to Jobs. Why? They feared his wrath "and that he would dismiss [the web] as 'shit.'" (In another timeline, NeXT might itself have capitalized on this world-changing innovation....)

Perhaps one of the wildest anecdotes that Cain uncovered was how one voicemail changed computer history forever. In 1996, when Apple was solidly in its mediocre Performa era — and considering buying BeOS as the basis for its new operating system — a mid-level NeXT product manager asked aloud, "Why don't we just frickin' call Apple?" (NeXT was also struggling during this period.) And so someone did. As Cain writes:

Garrett left the group of managers, walked back to his office, and took a risk. He picked up his designer phone and called the head of software at Apple. He left what he described as "one of my more inspired sales pitches" on the man's voicemail, explaining why Apple should be looking at NeXT instead of Be... In any other universe, Garrett's call might have gotten him fired. But in this timeline, it worked out. And thanks to him, Steve [Jobs] was about to enter Apple's airspace once again.

Submission + - New Power Banks Released by BMX with Safer Semi-Solid-State Batteries (androidauthority.com)

destinyland writes: https://www.androidauthority.c... From Android Authority :

Singapore-based BMX has announced that its SolidSafe magnetic power bank lineup, first showcased at CES 2026, is now available for purchase through its website and Amazon US, with prices starting at $59. What sets these power banks apart is their use of semi-solid-state batteries. Traditional lithium-ion and lithium-polymer batteries rely on liquid electrolytes to move energy between electrodes. Semi-solid-state batteries significantly reduce the amount of flammable liquid inside the cell, improving thermal stability and lowering the risk of overheating, swelling, or fire...

BMX says the power banks are designed to remain stable under extreme conditions and show greater resistance to physical damage and thermal stress than conventional battery packs. The company has also launched the SolidSafe Air, a 5,000mAh magnetic power bank that it claims is the world's thinnest semi-solid-state Qi2 power bank... BMX is positioning the device as a travel-friendly alternative for users who want added safety and the convenience of a magnetic battery pack without the bulk.

Slashdot Top Deals

Bell Labs Unix -- Reach out and grep someone.

Working...