Comment Re:Just wait a cotton pickin' minute. (Score 4, Funny) 47
He came to my apartment the other day to upgrade my Linux. So he didn't visit your machine? How did you offend him?
He came to my apartment the other day to upgrade my Linux. So he didn't visit your machine? How did you offend him?
We have duplicated code into a new language and removed all synergy effects by sharing a code base with the rest of the community. Hurray!
Maybe one day we can have bi-directional LLM-based translators that allow features and bug fixes to perculate back and forth forks
Where do the lists created by fail2ban and reaction ultimately go? I understand that these are local, but would it make sense to make a karma server where people can look up whether an IP is likely untrustworthy? Such a karma list may help prioritize traffic and help ISPs/providers identify that they are infected.
With the number of available and vulnerable IoT devices and the number of motivated hacker groups supercharged with LLMs, shouldn't a lot of company and government secrets get revealed these days? Perhaps news organisations have a bottleneck being underfunded to go through leaked material?
This is good long-term, but what fraction of routers, smartphones, IOT devices, cameras, cluster servers,
We can bet that black hats iterate through all accessible devices and try to gain access. They might patch flaws to avoid others getting in, but will keep a backdoor for themselves. So it will be extremely hard to tell. We do not have something like brickerbot to turn unpatched devices noticeable.
The moral of the story is that it is easier and easier for police and intelligence services to quickly get meaningful information out of hard disks, including passwords and files in a personal workflow / storage structure (or lack of structure). LLMs might piece this together and be targeted. Security analysts would be faster and ignore noise better, but what is shown here might scale to millions of citizens.
The response of "User-Agent is not authentication" is a strawman response to "Unofficial clients should not use our servers". They used it as identification of clients, not authentication. Would the developers be happier if they had used an API key for the web interaction, but package that fixed API key into the app? Would that be "authentication" and thus better to them? It's the same effect, and the open source clone would copy it too.
Same discussion as 30 years ago with open source clones of messaging apps such as ICQ. The open source client pretends, on those days through reverse engineering, to be the official client. Ultimately, it was okay then, because it was beneficial for the operators to have a larger network of users who can talk to each other. Does this dynamic apply here?
If hammering is an issue, randomly drop with 429 95% of requests. Then as an alternative, allow people to buy an API key for 1000 downloads costing 1€.
Then patient individuals can always download for free. Big companies / CI / AI will want to pay or make their own mirror.
Rebecca Watson is a quite famous skeptic, and a former co-host of the Skeptics Guide to the Universe podcast. Since Dawkins is also in these circles, not too crazy to bring her up.
The class of bugs for PipeFail can be prevented in principle with X^W, which is implemented in PaX, Exec Shield, and some SELinux configs.
Is any distribution that comes with these in the default installation protected against these exploits? If not, what is missing in terms of mitigation protections against this class of bugs?
Either you get faster and faster at it, or 2026 is the year we work on pen and paper until the storm is over...
W^X? As implemented in PaX, Exec Shield, SELinux. Which all Linux distros have and no Linux user ever uninstalls or disables. Or something.
The restructuring may be legal in itself and viewed in isolation, but if there was an investment with a (written or oral) understanding of being for an open source company, the metamorphosis of OpenAI may still break that investment contract. Probably the fair thing would have been to give back the investment at that point with interest, or settle the matter in another way.
> Putting a hardware guy in charge of Apple might help the company return to its roots as a hardware-first company.
Steve Jobs and Steve Wozniak founded the company, but the hardware guy was not in charge. It would be closer to the roots to put a salesperson or designer in charge? And I mean design in the computer science sense, a tool matching a purpose.
Some feel weird when people say please and thank you when interacting with chat bots. If what TFA says is true, I am curious whether norms of politeness (or lack thereof) in chat bots, treating them as disposable, emotionless tools could also leak from chat bot interactions into human interactions. It seems plausible that humans cannot maintain a clear mental separation.
Decaffeinated coffee? Just Say No.