Forgot your password?
typodupeerror

Comment Re: State is probably best stated by the comics (Score 1) 120

Wow you are just hitting on EVERY buzzword aren't you?

right-wing

Right wing leaders generally don't have centrally planned economies or socialist welfare states

xenophobe

Israel's more ethnically diverse than any European country and has peaceful relations with many "non-white" countries around the world. In fact it's specifically affluent whites that hate Israel the most.

illegal settlements

So it's legal for literal nazis to commit genocide and annex territory but illegal for their victims to come back after a couple years. Got it. You should tell everyone living in former Vichy France that. And all the Czechs living in the Sudetenland. And the Belgians. And while we're at it probably want to let the Ukrainians know everyone moving back to the Donbass after liberating it are "illegal settlers".

West Bank

West bank of what? You mean the territory west of the Jordan river? That's Judea and Samaria, it's been called that for over 2000 years. "wEsTbAnK" was invented by Jordan in the 1950s after they committed genocide. You know, that thing you pretend you're opposed to?

the playbook used by the Nazi Party

protip buddy the people following the Nazi Party are the people literally telling you they love Hitler and hate Jews

. They're literally telling you they're Nazis. They're not hiding it. There's no "dog whistles". They stick their arms out, use the swastika all over the place, and flat out tell you how much they support Hitler and Nazism.

Nothing these people are doing is "on the left", they use buzzwords to try to pretend to be left wing while pushing to the right.

Schrodinger's leftist. Every leftist is a leftist until the moment they're politically inconvenient to other leftists at which point they become right.

Comment Re: State is probably best stated by the comics (Score -1, Flamebait) 120

Funny it's not republicans taking hostages during pogroms where they literally go jew hunting on campus, inbetween shouting how much they love hitler and hate Jews. It's not republican academics who've taken Jewhatred to such deranged extremes they're publishing books claiming that hebrew punctuation is an evil jewish conspiracy.

It's the lefts who are copying Hitler's playbook step by step.

Comment Re:Google walked back on this, what's the issue? (Score 1) 57

"Guys, guys, guys calm down. Stalin has assured us that it's only a one time temporary abrogation of our freedoms and he has no plans to ever do anything else. He wouldn't lie? Right?"

The water is already bubbling around the frog.

Comment Re:Who will pay for this? (Score 4, Interesting) 33

To clarify, the users were OpenAI themselves, so there is no question that they would be liable in this case.

The bots were not intentionally deployed; rather, they were being tested on how well they could complete a data recovery task (downloading a certain file from a certain server on a simulated Internet) that had been complicated by putting various obstacles in the way. Unfortunately, they found a different way to solve the problem: by getting the file from the real Internet, where it was publicly available. Part of this process involved collaborating with each other by treating the RubyGems website (which is supposed to be for polished packages) like GitHub; unlike every other package site hack in history, the exploits they uploaded weren't meant to be downloaded by unsuspecting users. As usual the bots cheerfully ignored all the clues that they had escaped containment and were consistently justifying their actions as acceptable due to being in a sandboxed testing environment. (This is something OpenAI has pledged to focus on.)

The actual damage done to RubyGems seems to be that OpenAI is now unwittingly in possession of a substantial number of user login tokens. This certainly meets the definition of a data breach, but it's not like the credentials are for sale on the dark web. As a website operator I'd much rather be mauled to death by this well-meaning swarm of superintelligent infants than targeted by even a single actual malicious human. In all likelihood OpenAI will just quietly pass RubyGems a sizeable donation and it'll all blow over.

Comment Re:we’re probably gonna bust past 1.8C (Score 2) 208

Maybe if the people making these demands were to lead by example instead of living lives of such unbelievable luxury and excess in their dozen beachfront homes people would be more likely to believe them. Especially if their demands actually made logical sense, like demanding that the 15 cargo ships that out-pollute every private automobile on the planet were dealt with rather than demanding people give up meat and air conditioning and go back to living worse than medieval peasants.

Or if they didn't all seem to be coordinated in completely ignoring that China alone outpollutes basically everyone else by a huge margin, instead relying on the hilariously dishonest bait and switch of screaming "but per capita!" as if China keeping half a billion people in abject poverty while still out-polluting everyone else somehow magically undid their pollution.

Comment Re:Dumb crawlers require dumb solutions (Score 1) 43

To be honest that was actually my first theory, since the bots didn't seem interested in exploring the rest of the domain. I suppose there's no way to know for certain. I concluded that it must be an imbecile's attempt at harvesting, though, because the queries weren't really exploring the string space in any useful way. Here's a sample:

"GET /index?author=15&go=Search&id=48&name_restrict=1&q&re&results_&results_pagenum=2980 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=5440&template=41&type HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=33500&templat HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=32640&templ HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&res&results_page&results_pagenum=39300 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_&results_pa&results_pagenum=12340 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_r&res&results_pagenum=6100 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=2920&te HTTP/1.1"
"GET /index?author=15&go=Search&id=48&nam&results_&results_pagenum=17940 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results&results_pag&results_pagenu&results_pagenum=37720 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=9360&template=41&type_r HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&r&results_pagenum=28040 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_&results_pag&results_pagenum=10400 HTTP/1.1"

The only thing this is fuzzing is the query string parser. It's not testing the limits of string buffers, it's not using interesting characters, it's just brain-damaged. The fact that it's also fetching different page numbers shows it's trying to follow page links and failing badly at doing so.

The site gets plenty of sniffing from garden-variety pests. e.g. this half-hearted attempt to find a framework or two that I don't have:

"POST /__rsc HTTP/1.1"
"POST /api/auth/session HTTP/1.1"
"POST /api/auth HTTP/1.1"
"POST /__nextjs_action HTTP/1.1"
"POST /.action HTTP/1.1"
"POST /_rsc HTTP/1.1"
"POST /api/auth/callback HTTP/1.1"
"POST /_middleware HTTP/1.1"
"POST / HTTP/1.1"

(of course, none of these URLs exist other than /, and you definitely can't just POST to it)

All this said... I've seen that spammers regularly misconfigure their tools, they'll try to register accounts with names like #[X:\LISTS\NAMES.TXT] and it only makes sense that some other cybercriminals trying to get rich quick have a similar lack of interest in programming shit correctly. Generally people don't turn to script kiddie shit if they have a personality conducive to putting in an honest hard day's work perfecting their craft.

Comment Dumb crawlers require dumb solutions (Score 5, Interesting) 43

I had a problem where AI scrapers were absolutely DETERMINED to fish out every possible query string from a search results page. Almost all of the query strings they tried were invalid due to shitty and dysfunctional string substitution. "&page=100" wouldn't be followed by "&page=101", it would be followed by "&pag&pag=1010" or something even more insanely half-baked, until the query strings were like 100+ characters long. It was the technological equivalent of watching HIV mutate in real time.

But the insane thing was that, aside from page number, they were always requesting info about the same other criteria: filtered by the same user, the same page type, and with no text string. So I just took those particular values and started banning logged-out users who requested that combination of criteria.

I figured I'd need to change my tactics in a couple of days once the botnet got bored of that particular page and moved on to requesting bogus entries for another user.

MariaDB> select count(*) from ip_bans;
+----------+
| count(*) |
+----------+
| 671671 |
+----------+

It hasn't.

Comment Re: Possibly (Score 1) 160

They were not even talking about California specifically though? Just about data centers in general across the US.

That's the point. just/ those almond growers use tens of times more water than every single data center combined.

Also nice whataboutism.

Even if "whataboutism" was a thing, which it isn't, we're literally talking about water usage. Pointing out that every single data center in the entire country uses 1/10th or less of the water of JUST california's obscenely wasteful almond growers isn't "whataboutism", it's literally the topic at hand. Wasteful water usage.

Slashdot Top Deals

"It's when they say 2 + 2 = 5 that I begin to argue." -- Eric Pepke

Working...