Forgot your password?
typodupeerror

Comment Re:Integral layer of the Trusted-Computing/DRM sta (Score 1) 34

Every time people hear what it actually involves is outrage and opposition, at least all the way back to when Intel first announced that they wanted to hardcode identity numbers inside CPUs in 1999. But the corporations involved have been relentless, and have sunk countless billions of dollars steadily forcing it forwards, and building front organizations to obfuscate and whitewash it.

With Windows 11, Microsoft was finally able to FORCE Trusted computing hardware into every new computer. Not just every new Windows computer, but every computer.

Every new Intel PC CPU has built in Trusted Computing enforcement hardware. Every new AMD PC CPU has built in Trusted Computing enforcement hardware. Every new ARM PC CPU has built in Trusted Computing enforcement hardware. The only processor lines that DON'T have it are the microcontrollers.

There are some unlocked smartphones available, but as far as I can determine it's literally impossible to buy a smartphone that doesn't have hardware trusted computing built in.

I specified that enforcing Trusted Computing at the internet access level is still a long term goal, they couldn't get away with it today. However they are well on the way to success. Virtually all new hardware supporting trusted computing, all the front groups rolling out standards and systems, and as it gets incorporated into things everyone is going to increasingly running into situations where they get locked out of stuff if they're not Trusted Computing compliant. Streaming already restricts you to the worst quality if you're not compliant, and it's only going to get worse as pre-Win11 computers fade out and as more things require it.

Comment Re:Dual purpose age-bracket signal :o (Score 1) 129

I'd hardly call exact date of birth "low information content".

And yes this does reveal exact date of birth, regardless of the bullshit obfuscation that it supposedly only reports age range. The server simply tracks the reported result every time the user connects, and on some specific day the result CHANGES to announce their date of birth.

-

Comment Integral layer of the Trusted-Computing/DRM stack (Score 1) 34

This is based on SLSA (Supply-chain Levels for Software Artifacts), brought to you by the same fuckers making Trusted Computing and the TMP (Trusted Platform Module). It's part of the same shitstack to prohibit you from altering your software and to lock you out of your own files, and to send spy reports out over the internet so you can be cut off if you "fail" the Trusted Computing check.

The software can use a TPM's (Trusted Platform Module) Sealing function to encrypt your data such that it's impossible to access your own data if the software is modified. It can then pass control over that data only to software updates that carry a signed security certificate from Broadcom (or any other company using this system).

It is no longer open source, your system no longer works as you can no longer access your Sealed data if you change so much as a single letter of the code. Even recompile unaltered code won't work, unless you magically manage to get your build environment absolutely identical to the company's build environment and get byte-for-byte output. Even that may be impossible with the newer levels of non-deterministic compiler optimizations.

Also, with TMP's Remote Attestation feature can be used to transmit your machine's software configuration over the internet, so that you can be cut off if your system doesn't match Broadcom (or other company's) cryptographically signed certificate.

And then of course there's Network Access Control (NAC) / Trusted Network Connect (TNC). In the long term, the goal is for ISPs to use NAC/TNC to interrogate your computer for Trusted Computing compliance, and deny you any internet access whatsoever if your machine isn't compliant. Software with this sort of "security" certificate would pass inspection, while any attempt to alter the code would be detected as "tampering". You then get "quarantined". What "quarantine" means is that you are denied internet access - with the exception that you do get very restricted access which can only be used to download the approved software to "fix" your computer into Trusted Computing compliance.

Comment Re: Standing on the shoulders of giants (Score 1) 115

Writing music (or any other creative endeavor) is not just about mimicking learned patterns, but about experimenting until you create something actually new. Models are recombining patterns using deep learning, which can give the appearance of novelty without actually being genuine creations, unless there's adequate guidance and shaping by a human. The problem is that there is a way that real inspiration and innovation *feel* which becomes delocalized when the cognitive labor is mostly offloaded to a model and thus hard to recognize, especially if you don't actually have experience doing the creative act yourself. So people who don't know how to write music will make slop, and even experienced artists could end up with stuff that is mostly slop if they're not paying very careful attention.

Plus the social value of creativity is based on recognition of the effort involved in creating novel things; many people appreciate art because it reflects human experience and human effort, which can get muddled or lost with generative AI.

I have been writing music and studying computing since childhood and studying some machine learning since I was a teen, three decades ago. I don't think all generative AI is useless or offensive (though the resource overconsumption with the LLMs-in-everything fad is a serious problem, and I do believe there is a type of expected-usage violation / consent problem with many AI vendor training sets and products). The disagreements about deep learning and generative AI (exaggerated by a bubble-driven profit motive, unfortunately) will take work to solve because new social contract concepts will have to gradually be explored and tested over the coming years by billions of humans until a general consensus is reached on what fair use now means and how intellectual "property" ethics are navigated.

I think people are asserting a lot of things which amount to gazing into a crystal ball around these topics, but there are at least two things which I feel pretty sure of based on my experience: the human creative process is much more complicated than LLM/GAN training+prompting, and actual human creativity has value which a machine is unlikely to replicate effectively at least anytime soon â" though simulacra of creativity pass enough of a capitalist sniff test to make money, detracting from the livelihoods of artists already dealing with the nightmarish economic calculus of trying to make creative things while paying the bills in the contemporary era.

Of course, litigative copyright scalping companies don't add any value to society either and are effectively just another type of nuisance; Round Hill looks to be a hedge fund manager's project to make money off others' labor without actually facilitating human creativity. Cue the infamous "I believe everyone involved in this story should die" Norm Macdonald line... (which is much more applicable here than the original transphobic "joke"!)

Comment Re:Yeah, pretty much this. (Score 0) 194

This is a love tap, fists will be thrown later. One thing can and should be done, we need to start adding aerosols into the atmosphere, the higher the better. Adding Na compounds to jet fuels would introduce just enough aerosols in order to start reflecting a tiny amount more of solar radiation than what makes it to the surface of the planet. 1-2% reflection is all we need to start reducing the temperatures. Of-course we will have to keep doing it until we figure out a more permanent solution.

Comment sideloading control and 3rd party stores (Score 2) 38

Google is now adding more rules to make sideloading more difficult while Apple never provided a way to sideload an app in the first place. People need to be able to build and load their own apps without permission from the OS manufacturer, a phone is a computer with specialized hardware, we do have ability to build and run apps on our own hardware.

Comment Yes. (Score 1) 63

Flock is not a single police officer standing on a street corner. Flock is a network of continuous data collection from every perspective on every road and intersection. Flock is not a camera, it is an AI system that follows you precisely everywhere, it is a data dump without a court order. There is expectation that a police officer will NOT follow you everywhere without a court order just because he is paid from taxes and has nothing better to do, this is stalking.

Comment Re:Governments don't have the right (Score 5, Interesting) 132

Wrong, it's a slight of hand. This is not about individual cameras, this is about the network that uses all cameras together to follow you no matter what you do, no matter where you go, people shouldn't have a government that follows their every step by using AI and networked devices. If this was about individual cameras you would have a point, it is not, it is unreasonable to allow a government to exist that creates a panopticon of this scale, citizens shouldn't feel like they are inside a prison and the warden is watching.

Comment Re:"dismantle safety protections on Google Play" (Score 1) 69

Hi, I came across this thread and it's something which has raised a lot of concerns for me since Google's announcement. There's a discussion of how it hurts the open-source ecosystem at https://www.reddit.com/r/selfh... and Google's announcement is at https://android-developers.goo...

I like the idea of writing free, open source utilities for others to use. Users having to jump through even more hoops to sideload, or me having to pay money and reveal my identity to Google, get in the way of this --- especially if one of the things I've thought about is e.g. writing a tool to help LGBTQ+ people find locations where they can be reasonably safe in the current US geopolitical climate. That is exactly the sort of utility where the DoJ would make claims I'm some sort of subversive "antifa threat" and demand Google release my identity to them for harassment. Plus, the time where that utility would be most useful -- if someone suddenly has to go someplace unfamiliar on short notice (e.g. getting a call that a relative who lives a few hundred miles away in MAGA territory is getting emergency surgery), having to wait 24 hours to sideload the app if you don't have sideloading currently unlocked, just to find out which rest stops are safe to stop at or not on your drive, would be incredibly unfortunate!

I'm not saying improving app security is a bad thing, and at least Google didn't pull a "We Own Everything And There Is No Way Out Of Our Grip" like they could have, but the options they provide are not nearly good enough. It seems like they only thought about (1) average uninformed users who install things randomly, (2) big commercial developers [who still can get compromised and end up pushing malware, or might even include malware intentionally: just look at LG's McAfee situation, the infamous Sony BMG CD rootkits, etc etc], (3) independent developers who have identity documents Google is willing to recognize [what about the identity document fiascos going on right now with Ukrainian towns Russia is occupying? what about areas occupied in the Middle East by various regimes? what about the way cops confiscate homeless peoples' belongings including ID cards, but you need an ID card to get your belongings back?] plus extra cash [and $25 USD is a lot in some impoverished places, limiting the ability of people in such places to help themselves by becoming app developers], (4) students and hobbyists who only need to share their app with a small group of testers [limiting your ability to test scalability!], and (5) power users who are patient. If you don't fit into the scenarios they planned for, you might be out of luck. And I recognize that the vast majority of legitimate use cases do fall into those above categories, but there are legitimate use cases which don't. They could have at least had a series of open community fora to get feedback on other use cases and plan additional options, but they did not.

It's great that they thought about a few different use cases, at least. But that's not nearly enough!

Could I find an ally to register as the "developer" and publish such an app? Sure, but is that how it *should* be? I would now be dependent on someone else to manage the Play Store listing, which limits my ability to build. Could I spread the word to people who might need such an app that they should unlock sideloading indefinitely just in case? Sure, but maybe that creates new risks for them (and -- what if the option to unlock sideloading indefinitely gets taken away at some future point? Google gets to dictate all the changes here, and users have little recourse if they disagree with the specifics of the implementation)

I just want the guaranteed ability to say "hey, what about XYZ situation, which I or a friend have personal experience with? can you provide a way to handle that?" but I don't. There's no form to fill out to request some sort of special accommodation for an unusual situation, and there probably should be. When you have billions of users, planning for the needs of 99.99% of them still hangs hundreds of thousands of users out to dry. I know trying to accommodate more edge cases isn't as profitable, and having a large enough support team to hear people out when they have an unusual need requires a ton of extra staffing, but smartphone usage has become a critical utility rather than a luxury in much of the world. Google has an immense amount of power over numerous aspects of the lives of all sorts of different people, and if they want to continue to make money from that situation, they need to be prepared to deal with the complexities of it all.

Slashdot Top Deals

Riches cover a multitude of woes. -- Menander

Working...