Forgot your password?
typodupeerror

Comment Re:Integral layer of the Trusted-Computing/DRM sta (Score 1) 34

Every time people hear what it actually involves is outrage and opposition, at least all the way back to when Intel first announced that they wanted to hardcode identity numbers inside CPUs in 1999. But the corporations involved have been relentless, and have sunk countless billions of dollars steadily forcing it forwards, and building front organizations to obfuscate and whitewash it.

With Windows 11, Microsoft was finally able to FORCE Trusted computing hardware into every new computer. Not just every new Windows computer, but every computer.

Every new Intel PC CPU has built in Trusted Computing enforcement hardware. Every new AMD PC CPU has built in Trusted Computing enforcement hardware. Every new ARM PC CPU has built in Trusted Computing enforcement hardware. The only processor lines that DON'T have it are the microcontrollers.

There are some unlocked smartphones available, but as far as I can determine it's literally impossible to buy a smartphone that doesn't have hardware trusted computing built in.

I specified that enforcing Trusted Computing at the internet access level is still a long term goal, they couldn't get away with it today. However they are well on the way to success. Virtually all new hardware supporting trusted computing, all the front groups rolling out standards and systems, and as it gets incorporated into things everyone is going to increasingly running into situations where they get locked out of stuff if they're not Trusted Computing compliant. Streaming already restricts you to the worst quality if you're not compliant, and it's only going to get worse as pre-Win11 computers fade out and as more things require it.

Comment Re:Dual purpose age-bracket signal :o (Score 1) 129

I'd hardly call exact date of birth "low information content".

And yes this does reveal exact date of birth, regardless of the bullshit obfuscation that it supposedly only reports age range. The server simply tracks the reported result every time the user connects, and on some specific day the result CHANGES to announce their date of birth.

-

Comment Integral layer of the Trusted-Computing/DRM stack (Score 1) 34

This is based on SLSA (Supply-chain Levels for Software Artifacts), brought to you by the same fuckers making Trusted Computing and the TMP (Trusted Platform Module). It's part of the same shitstack to prohibit you from altering your software and to lock you out of your own files, and to send spy reports out over the internet so you can be cut off if you "fail" the Trusted Computing check.

The software can use a TPM's (Trusted Platform Module) Sealing function to encrypt your data such that it's impossible to access your own data if the software is modified. It can then pass control over that data only to software updates that carry a signed security certificate from Broadcom (or any other company using this system).

It is no longer open source, your system no longer works as you can no longer access your Sealed data if you change so much as a single letter of the code. Even recompile unaltered code won't work, unless you magically manage to get your build environment absolutely identical to the company's build environment and get byte-for-byte output. Even that may be impossible with the newer levels of non-deterministic compiler optimizations.

Also, with TMP's Remote Attestation feature can be used to transmit your machine's software configuration over the internet, so that you can be cut off if your system doesn't match Broadcom (or other company's) cryptographically signed certificate.

And then of course there's Network Access Control (NAC) / Trusted Network Connect (TNC). In the long term, the goal is for ISPs to use NAC/TNC to interrogate your computer for Trusted Computing compliance, and deny you any internet access whatsoever if your machine isn't compliant. Software with this sort of "security" certificate would pass inspection, while any attempt to alter the code would be detected as "tampering". You then get "quarantined". What "quarantine" means is that you are denied internet access - with the exception that you do get very restricted access which can only be used to download the approved software to "fix" your computer into Trusted Computing compliance.

Comment Re:First and foremost... (Score 1) 121

The problem with this argument, from the shop's point of view, is that the UK is in the middle of a shoplifting epidemic. The policing resources simply aren't there to deal with small scale (or even flagrant and much larger scale) shoplifting. It now seems to be rare for police officers to attend reports of shoplifting at all. And so effectively shoplifting becomes legalised, which is obviously hurting the big chain stores financially and potentially devastating for smaller shops.

Shops are trying to find some way to respond to this to protect themselves. They typically tell staff, even security staff, not to get physical with shoplifters as they walk out, not least because the risk of something worse happening and the business becoming liable for it is significant. But then the shoplifters know this and some of them will just walk in and openly empty a shelf into a bag and walk out again without paying because they know no-one will try to stop them.

Shops also know that our court system is completely overwhelmed at the moment and there is little chance of bringing any successful civil action to recover damages from shoplifters who aren't even being arrested by the police and put through the criminal justice system.

So what do they have left? Basically, they're trying to spot the "usual suspects" and refuse them entry in the first place, which is a less risky proposition in terms of potential for physical violence and quite effective because a lot of shoplifting is done by the same people, or they're trying to make it more physically difficult to steal goods, for example by using locking systems or keeping high value items behind counters where customers can't just pick them up. But these systems aren't perfect, far from it, and what we're discussing here today is one of the significant problems.

Obviously this kind of technology can have very bad consequences, as we see here. I don't think it should be used if it's not highly reliable, given the potential harm done in cases where it gets something wrong. But I do have some sympathy with the shops who are looking for something -- anything -- to reduce the threat they're facing because the rule of law has failed in retail settings.

Comment Re:I initially dismissed the idea of agents (Score 1) 54

I don't think I could have been more wrong.

On the contrary, I think most of your comment is as relevant as ever. A carefully designed UI is still better for almost any specific task than what "agents" will produce. It will probably be more efficient to describe what you want precisely enough to get it right. It will not be undermined by problems like non-repeatability, non-determinism and hallucinations that are inherent in LLM-backed agents.

Agents can be quite effective at getting something that seems about right, as long as you don't care too much about the details. And of course they get there much quicker than doing it manually as a human. This is useful for some tasks, and why they have become popular.

Unfortunately, it turns out that for many of the things we really care about, "about right" doesn't cut it. Right now, today, the software industry is already being overwhelmed by AI slop. It's hard to believe, but it's still only been a few months since agentic development processes arrived on the scene. And yet after just those few months of management trying to replace real developers with agents, we can see the slow-motion train wreck happening right before our eyes. And in return, where are the new applications that radically improve on what we had before thanks to all this added "productivity"? If this tech is going to change the world as the AI tech bros and the sycophantic CxOs kneeling at their feet would have us believe, where's my flying car?

Comment Re:Zoom Should Not Be Trusted (Score 1) 12

It's silly that a browser sandbox is better than any native sandbox available.

It is. The fact that our dominant desktop operating systems are still using security models from last century is probably the #2 disaster of modern tech security, coming in just behind so much software with potential security implications still being written in languages like C and C++ at #1. And the understandable yet still deeply regrettable reason for both disasters is the same: momentum.

Comment Re:Zoom Should Not Be Trusted (Score 1) 12

I normally connect to all online conference calls via their web UIs. At least then it takes both a screw-up in the communications system and a screw-up in a browser security sandbox that is independently developed to allow something like an RCE or data leakage vulnerability to be exploited.

People have called me crazy for not wanting to install native apps from the likes of Microsoft, Google and Zoom in the modern era of remote working, but every now and then, there's another story like this one that reminds me why I am extremely careful about what native software I install on anything these days.

Comment Re:Ouch (Score 1) 72

You always shoot first and ask questions later?

No, I read the details explicitly quoted at the start of the discussion and responded to them.

Are you saying that this episode has not in fact resulted in (a) unplanned software being installed on end devices that will (b) automatically read data that is stored on those devices without the proper approvals? Either of those things alone can easily become a compliance problem if you operate in a regulated environment, whether or not things ultimately go any further on this occasion.

Comment Ouch (Score 4, Insightful) 72

It was obnoxious enough when Microsoft started pushing this kind of unwanted "feature" on home users, then small businesses and professionals on Pro editions. There are real legal and regulatory concerns over this kind of change that businesses have to take seriously. If they've screwed up so badly that even their large corporate customers have been hit by the same thing and there isn't even a good way to undo the damage at the moment, this could lead to meaningful lawsuits from their customers and/or interventions by regulators.

Comment Re:From the article it's just browser fingerprinti (Score 2) 87

I suspect GP's point is that every malware blocker in every browser is likely to treat this kind of script as hostile, except for Chrome because Google are currently nerfing the ability for blockers to intercept hostile scripts in one of the most blatantly user-hostile changes they've ever made.

If Apple play along with Safari then every other browser and its malware blocking plugins are about to be toast in a huge retrograde step for Internet privacy. But not even Cloudflare is going to get away with blocking every iOS device if Apple continues to allow blockers to intercept this kind of script.

Did anyone mention recently that simultaneously controlling both the most popular web browser and several of the most popular ad-supported web properties might be a little anticompetitive, and that it's about time that Google was broken up? It's probably time for that drum to start beating a bit louder again.

Comment Valleygirl accent (Score 1) 40

I know it's really trivial, bordering on petty, but please oh please give her a different accent. She says "okay" so much, and the Valleygirl accent is never heard so pronounced as obviously as in that word that I really want any other accent. Mid Atlantic, Southern, Cascadian, Midwest, Irish, please anything other than Valleygirl.

Comment Re:Why not? (Score 1) 139

Side mirrors almost always leave a large blind spot directly behind and close to the vehicle. There's a reason that when firefighters are reversing their appliances they always have at least one of the crew physically get out and watch the area behind the vehicle.

Even a rear window and rear view mirror almost always leave a significant blind spot low and close behind the vehicle, which is why reversing cameras became a thing. When they're done well, they really are significantly safer, as well as sometimes making it a lot more reliable for most people to park the vehicle in difficult spaces.

Comment Re:What's "eye-like focal length"? (Score 1) 139

One of the modern innovations I really would like to have is full AR on my windscreen. I want unexpected hazards highlighted in real time, particularly those that are more easily detectable by non-visual sensors, like big potholes or animals obscured by vegetation near the side of a country road. I want the actual driving line I need to take to follow my planned route through complex junctions overlaid slightly on my view of the road ahead. I want light amplification for night driving, ideally combined with some other technology that can reduce the glare from oncoming headlights to prevent dazzle.

Although I only want all of this if (a) it's implemented well and (b) any additional data it uses is reliably up-to-date and (c) there's an emergency shut-off that instantly clears everything off the windscreen in case anything goes wrong.

Slashdot Top Deals

Science is to computer science as hydrodynamics is to plumbing.

Working...