Forgot your password?
typodupeerror

Comment Re:Still can't turn off update notice (Score 1) 105

Some people don't want automatic updates, or automated checking. It also depends on which OS and which Firefox you have installed. For example, under Linux, Firefox from the distro will typically have zero notifications or updating because it is handled elegantly by the distro updates.

Comment Re:Still can't turn off update notice (Score 1) 105

>"Apparently Mozilla isn't interested in simple. Like so many other companies, the object is to make things as complicated, convoluted, and inconvenient as possible."

Their objective is to make sure web browsing is secure and that you are aware of updates. Look, I agree with you that there should be an easy way to turn it off, even if just in about:config. But they made it clear when they took it away (many years ago) that they aren't going to bring that back, due to security. And I do have some sympathy for that position, considering many users would just never update- giving themselves a sub-optimal experience and possibly giving Mozilla a bad reputation.

But complaining about it to others in Slashdot over and over makes zero difference. All it does is stir up unnecessary and unneeded negativity while also making it sound like there is NO way to disable update checking/warning, which is not true. And that they are incompetent on this, which is also not true, because it was/is intentional.

Comment Re: Nothing of value was added (Score 1) 153

No one said rust is magic. But but attempting to claim that whole world of memory safety issues being resolved is somehow countered by a single vulnerability is not just dumb, it's mindbogglingly stupid.

This wasn't just an innocent bug where someone overlooked something or did a typo it was a design failure. Memory safety is being oversold especially the data race aspect when it does not prevent race conditions. Nobody cares about CS pedantry they care about correct operation and rust doesn't provide it.

Rust isn't perfect. But claiming the old tools were is just spectacularly ignorant, especially given the recent history of CVEs related to those "well-working, _old_ tools".

Rather than your dumb fucking US vs THEM approach, how about you advocate for both sides to improve their code?

This is the criticism I have for rust. Its only selling point is the memory safety thing which is in itself insufficient to justify rewriting everything in a different language with commensurate risks of introducing bugs in the process. What is needed are better analysis tools and better means of imposing constraints to enable correct operation across all concerns not just a single one. This means better tooling not playing pointless musical chair games with languages.

I think before long AI driven proof assistants will make all of this rather moot with rust being too little too late to the party.

Comment Re:Whereas the rest of us believe... (Score 1) 97

Because who would not be trying to parlay their association with a multi-billion dollar company into a next career step or second career?

All of those people are or were drawing salaries that would make most of us blush. They want to continue doing that. The reality is they are not adding value and their know it. They are pontificating about what machines might do with large matrices of numbers, tokenizaiton, attention algorithms, and fancy looping constructs over it all. You can get that free on Slashdot!

fundamentally their options are -
1. Snow some other organization, commercial, political, etc into believing they were not being taken seriously but are really necessary and they should hire and pay them for version 15 of their safety whitepaper informed mostly by 1960s sci-fi tinged with 1990s political correctness.

2. Convince the public the world is going to end, like every cult leader before them; so they can do the paid speaking circuit or write some sci-fi novels of their own leverging the fact their names are already in print to rise above the noise and get past the mail room at McMillan.

3. Get a real job actually making something for 1/4 the pay, or less.

It is not hard to see hard that even if these are very smart, very successful people by any measure. Probably smarter than me, they are still "failing upward." If they were really all that they'd have been on the teams building the things, not occupying some position created entirely for the sake projecting an image of corporate responsibility. I doubt Durrant had anyone at Union Pacific churning out copy on the potential loss of cultural distinctiveness that might result if a Transcontinental rail line is completed, but he would have if he'd faced a public that had become preoccupied as we are today with the latest jobs report. He also would have found a reason to dismiss, drive them quit, or otherwise sideline them the INSTANT their recommendations stood in the way of the actual business activity as he saw it; just exactly as Si Valley has done.

Comment Re: have they even tried (Score 1) 97

You are right that problem of sandboxing an agentic system will still giving it access to outside information even by proxy is actually hard.

What bothers me is; these are smart guys who should understand that. They are building a testing these things at scale. I would *think* they would be very interested in questions like "hmm why does the system keep making the same http request over and over..."

  Existing SIEM-like tools should be spotting and flagging that top level behavior all day long. That ought to trigger various looks in the to the agent-to-agent message layers, and agent-model-loop. While the way they press releases read nobody every looked at it except from the agent message direction. Which is just beyond credibility. In the case of some the 'hacking events' I really can't imagine ordinary network monitoring did not spot some of the very noisy side-channels and strange seemingly off target-off task activity early. I remain of the opinion i was ignored and almost had to be if not quite deliberately so...done with a level of intentional ignorance, kinda like those mid 2000s VPN services that 'kept no logs' because 'your privacy' but we all know they knew a not in significant part of their customer base was using it for abusive activities like sweeping for open SMPT relays to SPAM thru..

There simply had to have been a lot of fingers jabbed in ear canals, and signing 'la lal la' at OpenAI and Anthropic over the past couple years.

Comment Re:Not deception (Score 1) 97

This is one of the things I found I really don't like working with recent qwen models.

If you read thru the reasoning. It will write stuff like, "I was asked to ... but that will prevent me from ... the user probably did not really mean ... so I will ..."

I told you not to do anything other than read files under /usr/doc and search the web while trying to answer my question. That fact you can get around writing in 'plan mode' by running giant blobs a python one-liners, is not a plus.

These things have almost arrived at a state, I'd call "malicious compliance as a service." Which I do believe to be a training problem not a fundamental technology problem.

Comment Re: Firefox Not Private by Default Bug (Score 1) 105

>"That's true now that pocket is gone, perhaps."

I don't think pocket did anything to collect data unless you had it configured and were actually using it, though. I am not certain. I just disabled pocket in settings or about:config and paid it no mind.

Comment Re:Firefox Not Private by Default Bug (Score 2) 105

The funny thing is, although it is a bogus "bug" report, they treated it like it was real.

In any case, Mozilla only collects anonymized data by default. And you can happily, quickly, and easily turn that off and it will turn it off and it will remember that across updates.

Comment Re:Still can't turn off update notice (Score 2) 105

>"For all they keep doing, the one thing they can't seem to do is make a checkbox to stop being harassed about updates."

You literally post this on every article about Firefox. Aren't you tired yet? I have replied numerous times that they are *NEVER* going to do that. And then I pointed you to using policies, which will disable updates.

Comment It's ok to grieve (Score 0) 118

As they've been telling us software developers who are being asked to adapt to probably the most rapid transformation of any career that's ever been seen... "it's ok to take a moment to grieve." I was spending most of my time writing code up until about the middle of August, and then I realized that Fable was finally good enough to work on the rather large code base that I work on, and now I write less than 5% of the new code, and I'm pushing out new features at probably 3 times as fast as I was before, while now spending almost all my time creating and reviewing specifications, reading code, updating documentation, reviewing software architecture, and making bigger plans. It's jarring, exhilarating, and humbling at the same time. It's gonna take a minute for us to adjust. And yes, things are still changing fast. Software development has embraced this. It's coming for 3D CAD software and mechanical engineers next. There's been pushback within the more creative arts, like graphic design, writing, and making videos, and I totally understand that. Those industries will grapple with it in different ways than we have in the engineering space. And we won't lose all the creative stuff. As someone recently said to me, "we still ride horses, but we don't ride them to work."

Comment Why would an LLM know what humans want? (Score 2) 74

Why in the world would anyone think that an LLM would know what products humans would want to buy? To the LLM, all the products are merely words. Just descriptions. It cannot perceive anything about these products, but only knows of them indirectly via words. Further, all the LLM knows about what things are appealing to humans is also from words.

The whole thing is absurd really. It reminds me of something like Futurama where Bender is trying to cook food for humans. Or Star Trek and Data is trying to do something human but failing at it. Just not nearly as entertaining to watch this store fail though.

Comment Re: We are going so fast we need to slow down! (Score 1) 118

You apparently did not read the source materials. Let me quote the Anthropic threat report for you:

I accepted your CISA reference. I'll accept references from other similar organizations or law enforcement. I am unwilling to defer to Anthropic as they have a clear conflict of interest with billions of dollars on the line and a track record of manipulative behavior.

Having said this I remain disappointed in the continued failure to read your own references. This is a report titled "Detecting and countering misuse of AI" it speaks in general terms about AI and misuse of AI services for crime. It is not focused entirely on the distillation issue by leading Chinese AI firms.

The quote you referenced:

"These groups then often sell that access through brokers, which often feed into fraudulent AI reseller networks that rotate in new stolen API keys and session tokens until they exhaust their usage. Malicious actors also use or purchase these stolen API keys and session tokens from brokers for their cyber attack operations."

Is in reference to the section on crime and the use of AI to commit crimes under the heading "AI supply chain as target, loot, and attack compute". This is separate from the Chinese distillation allegations.

In fact NONE of the named distillation campaigns described on pg147 thru the end of the report GTG 16005, GTG-16002, GTG-16001, GTG-16006, GTG-16008, GTG-16012, GTG-16003 say anything whatsoever about stolen credit cards or stolen credentials. I wonder why that is? Why does CISA not mention the stolen credit cards and stolen credentials? Perhaps because it never happened?

Over the last several months, unauthorized labs have developed increasingly sophisticated methods to circumvent our defenses and harvest the capabilities of US frontier models. These labs generally access Anthropicâ(TM)s models by routing requests through proxy services, also known as âoetransfer stations.â To circumvent our geographic restrictions and related controls, these proxy services create thousands of new accounts using false identities, fake or stolen credit cards, and stolen API keys. They will often use stolen API credentials belonging to legitimate companies or individuals to give unauthorized entities access to US frontier models. These fraudulent activities harm legitimate customers. The graphic below illustrates the life cycle of an illicit distillation campaign.

This is general language that speaks to "unauthorized labs" without naming names and incurring associated libel per se liability. It is impossible from the language to link stolen cards and stolen credentials to any particular or any subset of AI firms because no such linkage is present in the text.

If you separately have credible evidence of stolen credit cards and stolen credentials being used by the relevant leading Chinese AI firms I am interested in learning more about it.

I'd implore you to stick to the facts and actually read the source materials before accusing others of 'peddling bullshit.' Your claim that AI distillation doesn't use hacked credentials is patently false.

Please just stop digging. You obviously just CTRL+F for keyword and cut and paste without even bothering to understand the context of the statements. This same sloppiness is pervasive throughout your statements.

The underlying argument you are peddling is also rather crazy in its own right. A "distillation attack" does not require stolen credit cards or stolen credentials. The modality of access to the teacher model is not even relevant to its definition. It doesn't stop being a "distillation attack" even if the lab paid the normal rate for access to the model.

That someone somewhere performing distillation to improve their models uses a stolen credit card to do so is irrelevant... It doesn't in any way justify calling distillation an attack.

Imagine if I decided going to a supermarket and filling the shopping cart up to the brim would be called a "shopping attack" ... when someone calls my bullshit term out I turn around and point to some rando who filled their cart and didn't pay on their way out to justify the attack terminology... even though most people who fill their shopping carts to the brim and do pay are still performing a "shopping attack".
This is the exact same logic you are attempting to peddle here. It make no sense.

Slashdot Top Deals

"If John Madden steps outside on February 2, looks down, and doesn't see his feet, we'll have 6 more weeks of Pro football." -- Chuck Newcombe

Working...