Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror

Comment Re:Isn't this already present in some capacity? (Score 1) 130

Honestly, I don't think Microsoft really gives two shits about locking down tech-savvy at-home users - trying to figure out how to lock down home machines doesn't generate profit.

What they do care about is corporate site-licenses for 10s of thousands of installs with broad-facing support contracts - Fortune 500 companies are very interested in securing each machine, in order to not run untrusted applications. The trick is they also want the ability to control what gets trusted - I have no doubt Microsoft has the ability to privatize their AI for big users and tune it to their needs, at least if you have enough 0s on the purchase order. There is zero chance they will risk these contracts with anything resembling the word "mandatory". (Code signing isn't really a solution here either, as most companies don't have a mature internal process for signing/distribution/key management required to make it work at scale.)

Comment Re:no thx (Score 1) 130

That's the point of the AI - essentially the idea is gather metrics on what individuals choose to trust and use that to drive decisions on what to trust by default. The delicate bit is that has to be shaped by feedback on whether that trust was well-earned or not. The authors shape the AI to make it seem to favor metrics that suggest trustworthiness and disfavor untrustworthiness. The value of this approach is it works at scales that aren't feasible with human review... except it stands on uncertain fundamentals.

The key problem is any such tool will have both a true-positive and false-negative rate - so it becomes a back-and-forth game where malware authors try to mimic true-positives while Microsoft tries to minimize false-negatives. Unfortunately, AI as it exists today is mostly written for modelling behavior that is fundamentally cooperative - so while this offers some promise of counteracting naively written malware, there is no way to know whether it can be effective (or even outright dangerous) against well prepared, strategic adversaries.

My professional opinion is that AI has too many "maybes" and "guesses" to be valuable against human adversaries - virus authors have already proven to be up to the task of innovating against code scanning, it stands to reason they can learn to exploit AIs that lack actual intuition. This is boldly underlined by the research showing that AI tuning can be used against it if exposed - forcing Microsoft into the ugly position of uploading all software to the cloud for analysis or risking costly exposures.

Comment Re:A journey... (Score 1) 48

The problem is a lot of key advantages either come all at once or not at all - blacksmithing was around for thousands of years, but without the key ingredients like the Bessemer process, it simply couldn't scale to the extent require for industrialization.

Comment Re:I'm sticking to my guns (Score 1) 48

I care... but not that much.

The biggest problem in crypto is just getting people to care at all - look at the sheer scale of data breaches where internal connections/databases are completely unprotected. Unfortunately, that often means purposely setting the bars as low as we can without scaring off users - for instance, better to have users encrypting using only 3DES than nothing at all. This is closely coupled to integrating low-level crypto (e.g., AES) into high-level libraries accessible to typical developers (e.g., TLS 1.2) across a wide range of platforms and devices.

Today we're facing serious headwinds from national governments/corporations suggesting that it is better to leave people unprotected in order to better support surveillance. Add in a frustrating muddle of patented algorithms and copyrighted libraries and a lot of organizations are happy to make a token effort then drop the subject...

I'm simply not optimistic enough to expect quantum resistant algorithms to be widely adopted anytime soon - the unfortunate reality is that any adversary who can afford a quantum computer can already breach just about anyone for a whole lot less.

Comment Re:Theres other issues (Score 1) 58

The main problem with bitcoin as it exists today is you are very limited in what you can do with it if you don't have access to exchanges - no one is selling 100M luxury yachts or mansions for bitcoin. The reality is if you are on a sanctions list, you run a very real risk your bitcoin becomes radioactive and no one will touch it - worth less than the bits it is printed on.

Comment So much for privacy (Score 1) 294

The sole purpose of a social media app is to gather invasive data from users - things you can't typically access through a browser session (which is plenty invasive on its own). Considering the site is subject to the same laws as any other company, their lawyers are all but certain to avoid the same liability that comes with platforming extremist - this just provides a way to tap into some of that sweet Facebook money by exploiting a partisan fanbase.

Slashdot Top Deals

Were there fewer fools, knaves would starve. - Anonymous

Working...