The Register Home Page

* Posts by doublelayer

11394 publicly visible posts • joined 22 Feb 2018

How the GNU C Compiler became the Clippy of cryptography

doublelayer Silver badge

For strings less than the hash length, the explicitly lengthened comparison is still faster. For something longer than the hash length, comparing hashes is both constant time and faster, except calculating the hashes to compare is not. That was also a simple example of a thing where optimization can introduce additional gaps, and since many sensitive comparisons already use hashing, not the biggest of them.

Linus Torvalds keeps his ‘fingers and toes’ rule by decreeing next Linux will be version 7.0

doublelayer Silver badge

Re: Frostbite ?

If you reject x.10 because it looks too much like x.1, why does x.11 not seem like it comes between x.1 and x.2? We have two choices: interpret a version number as a single decimal number or split at the . and interpret each component as an integer. Since there are three digits in the Linux version number, that seems the most logical option.

I remember when single arbitrary precision decimal numbers were more common as version numbers and it was a pain. Sometimes, people would release version 2.0, then a large change but not large enough to make it 3.0 (especially as this was also the day when upgrades to a new major number would usually cost money), so they'd jump straight to 2.5. Then they had to make a fix to something in that, so that was 2.6. Since bug fix added 0.1, the next small feature update would be 2.8 to distinguish it, and now there wasn't enough version number left for more than a bug fix release, so they started making 2.94 and 2.96. Semantic versions seem easier to manage properly.

Study confirms experience beats youthful enthusiasm

doublelayer Silver badge

Re: No s**t

Keeping in mind that experience comes from a lack of wisdom only for the people with enough ... I'm not sure what word so let's say intelligence, though that might be wrong, to learn something from it. Also, wisdom only grows when people learn from experience more than once.

People who have a lot of experience and learned from it are often the most wise and capable, but I've also known old people who decided that experience is boring and to stop bothering with that years ago. In the tech space, that meant people who would refuse to consider running Linux servers because, based on their experience from the late 1990s, that's not really a thing anyone of our size would bother with. In that place, the young people were better than the old ones just in the sense that the young people bothered to consider options. I've also met young workers who decided to get started on that plan early. Praising experience is great, but don't automatically assume that age or tenure at a job means there is experience.

Pakistan to test students for real-world skills before they graduate from IT degrees

doublelayer Silver badge

Re: Since when did a degree become a vocational qualification?

I think you've invented some history and decided what people think degrees are, getting both of them wrong. Degrees have long taught people more than just "tools to learn". Once, centuries ago, they might have focused entirely on logic and Greek, but A) we don't live in the 1600s anymore and B) they weren't that basic even then. Someone who obtained a chemistry degree a century ago both expected and got a lot of practical information about chemistry which did help them obtain a job in chemistry if they worked for one. It wasn't a coupon for a job, but it provided them skills that someone who studied something else didn't have unless they had done a lot on their own to learn it and, to get hired as a chemist, they would be expected to know and use those skills.

Undoubtedly there are people who believe that a degree should teach you all the skills you need for whatever job sounds most like the name of the course. These people are called children. Others realize that, as Feynman put it in the 1960s, "There’s two hundred years of the most rapidly developing batch of knowledge that there is. So much, in fact, that you might think that you can’t learn all of it in four years—and you can’t: you have to go to graduate school, too." But if people took a physics degree and only came out with an understanding of how they would go about repeating experiments to rediscover the laws of physics, they would have been cheated because the point of the degree is to learn many specific things that are relevant to further study or application. I don't know what Pakistani schools are teaching or what the Pakistani government wants to test people on, and as I said in another post, I expect this to go wrong in one of a few ways, but it is possible for a course to be bad by not being practical enough.

doublelayer Silver badge

Re: Why IT?

The focus on IT makes sense since they think that's a national priority, but it's not the first time that suggestion has been made about one or another course. I don't think it is likely to work though because this sounds like the skills will be about specific types of technology, or worse specific products, and those change enough that people who don't learn how to pick new ones up won't stay relevant for long.

Four horsemen of the AI-pocalypse line up capex bigger than Israel's GDP

doublelayer Silver badge

As I said, losing a million jobs would be painful if it happened quickly, but nobody said it would be wonderful. Even AI fans who think that could somehow happen don't all say it would be utopia, though the stupid ones sometimes do. Even if those million losses were packed into one month, that would probably mean a bad recession, but it wouldn't eliminate the economy by making it impossible for people to buy things which is what Doctor Syntax suggested would happen.

doublelayer Silver badge

We're talking about hypothetical consequences from events we know won't happen. Before we could start to estimate them, we'd need to decide or likely simply invent the conditions for that.

Most predictions from promoters of AI don't claim it will replace all or even most jobs, just certain subsets. If, somehow, that turned out to be possible, that wouldn't eliminate so many jobs that companies in general wouldn't have customers. It would be very hard for anyone whose job was lost, and quite possibly a net loss for the economy as a whole, but the economy as a whole wouldn't be paying for the AI, the people who hired the replaced workers would be, and they would probably enjoy some savings.

If a million people could be fired globally with an average saving of £100k, not an unreasonable figure for a few years of salary including some people above the average as frequently predicted, that would cover a £100B datacenter and AI investment expense, more than was actually spent in 2025. That doesn't cover everything that was promised, but most of that hasn't been built yet and might never be. A million lost jobs wouldn't be so many that nobody would be buying things anymore, especially when spread out over multiple continents. That would still be enough pain that we would all notice it to our detriment, especially if that number went higher, but it wouldn't do what you're suggesting.

doublelayer Silver badge

That depends on how we assume it works. If we assume that AI becomes competent and can successfully do lots of jobs cost-efficiently, then there's plenty of money to be spent and the DC makers will be able to cover their investments. If any of that isn't true, and none of it is, then the DC companies will have more problems.

Likely a couple DCs will survive by being bought up by hyperscalers who have already committed to using it, they move their GPU workload machines into them and use more CPU workload machines in their old DCs, and the rest fail. It's also likely that many fail without getting built in the first place. The big cloud providers do have a lot of money and they'll likely have to pay big chunks of that to get out of obligations they've signed up to without thinking it through.

doublelayer Silver badge

Re: Profits? We don't need no stinking net profits

You'd hope but you'd often not get what you hoped for. DCs ask for a lot of subsidies for these things and sometimes get them, but even when they don't, they sometimes make agreements, agreements that take the form of electricity supplier builds the infrastructure which the supplier prefers so it's done well and can be managed in the same way, the DC commits to buying a certain large amount of power at a certain price that would make that profitable, sometimes very profitable, for the supplier, the supplier announces this to reassure regulators and average customers that bills won't be affected. If AI makes tons of money, that happens. If the DC company goes bankrupt any time before five years after the DC is completed and starts operating, the electricity supplier gets the bill and has to do something to cover it.

It doesn't always work that way, there are some examples of builds where, if it fails, the DC company is on the hook. Unfortunately, that's far from the norm, and often when someone says the DC is paying for all the new build, they mean "in the future if everything goes well".

Containers, cloud, blockchain, AI – it's all the same old BS, says veteran Red Hatter

doublelayer Silver badge

There's not a lot of difference between SaaS and normal services. Dividing them into groups, especially if one group is bad and the other one neutral, is a fool's errand. Webmail can be software as a service since it includes a mail client, a spam filter, and various other things which you get from the provider instead of running your choice of software and configuration on a rented server.

Often when the SaaS conversation comes up, the relevant question is lock in. Does the provider have a copy of your data which you can't get back in usable form if you don't want to use their service anymore? That potential is present no matter what it is you rely on this place for. If they were running a completely normal mail server but refused to give you a copy of your email, then you'd still be locked in, whereas if it's a subscription office program but all your documents were easily downloaded in an open format, then you're not. The latter is the more likely to get the SaaS label because the thing being rented does include a lot more software, but that's not the cause of the problem here.

GitHub ponders kill switch for pull requests to stop AI slop

doublelayer Silver badge

Re: Wait, What?

I agree except for the bug fix part, so let's jump to that. I'm currently writing a bug fix PR to an open source project where I have not requested permission to do so. Here's why. The bug has already been reported a year ago. I found that out when I encountered the same one a couple weeks back and did my research to see if it was known. Nobody has done anything about it, including the debugging to find out why the software segfaults the way it does.

I want the bug fixed, so I've done a lot of the debugging to figure out why it does that and what you need to do to have it not do that and still run properly, because simply escaping before it would crash would still produce wrong results. Doing all that planning work is not much different from writing the code. If I only do 95% of the problem, write up a description, and ask someone to decide whether I or they do the last 5%, I'm giving them extra work and they might not bother since they haven't bothered to fix this in a year. There aren't a lot of maintainers and, while I've submitted PRs to this project before, I am not among the core team. If, instead, I implement the fix and test it, I can deliver them a report of why the bug exists and code that demonstrates that my report is correct. They can review that code and confirm that it does what I say it does. That's less work on their end and an easier way to determine whether I have a clue what I'm doing. If I only wrote the report, they have harder work to prove whether my report is correct about what's wrong because I might have failed to debug properly and made recommendations which would never work. That's why PRs are often given a lot more attention than issues alone and why most projects I'm aware of do not object to and often prefers people who create those without seeking explicit permission. If their PR conflicts with something else, maintainers will either request their assistance to merge them or will simply tell them that they need to rebase against the new changes and fix it.

doublelayer Silver badge

Re: Wait, What?

It depends how the public project wants to create fixes, but most I run, have contributed to, or have familiarity with don't do it that way exclusively. Users are free and encouraged to create issues, but issues are ways of reporting a problem which a maintainer will try to debug when they have time. Users who want to contribute can easily help by taking an issue, either one they've reported or one they found, fixing it, and sending code. That code then gets reviewed and either included directly or modified by the maintainers if it works. If it doesn't work, it gets ignored or its contributor informed of the problems and that gives you an idea of whether that person will be a useful contributor in the future. That process is used, not just in small projects, but in some truly massive ones as well.

The debugging to make the source change is a lot of work. Good contributors can be motivated enough to learn what the code is supposed to do and why it's doing it wrong, and if they do that they have saved the maintainers a lot of time because the maintainers just have to verify the debug summary is correct and do code reviews, but the maintainer doesn't know that is going to be the case before seeing that code. Good contributors would have done some checks to see if the bug had already been reported and, in your case, fixed, so they wouldn't have to. People contributing normally do a lot more work than you did. The methods you recommend don't tend to work for projects without a lot of maintainer time. Some examples:

"agree on who is going to do the work": If the maintainer has never met me before, they won't agree to let me do the work because they don't know if I can do it. Nor are they able to take on any task from their pool of few maintainers. They can't run it like a manager would because they don't have the ability to command.

"get agreement on the maintainer (or maintainers) on what that issue should cover and its acceptance criteria": That might happen. There are mailing lists for some projects where those things can be discussed, but that's more likely to happen for feature additions rather than fixes. If the fix breaks something, you don't need to have discussed it beforehand to not merge that until it's better and the partial code might be an easier starting point for the bug fix than no code.

doublelayer Silver badge

Re: It’s not looking good

It's all down to how much someone wants the product to be good. LLMs can produce some things which can save some time, as long as the person receiving them bothers to review, check, and fix everything in the output. If someone produces good output from an LLM, it's often hard to know whether they used it at all because they've eliminated bad phrasing, bugs, and everything else such a thing tends to produce with regularity, and if their first output was too useless to do that, they either tried different prompts until it did work or gave up and did that one manually. I don't use them much, but there are some people I know who decided they were useful and care enough about quality that they make something good.

The problem is all the people who don't care and therefore use raw output from their first prompt and the others who build the same model into larger workflows that automatically accepts output and uses it in the next step. They either don't know or don't care that the quality is unknown and likely bad, so they are happy that they've saved time.

In many ways, LLMs are like search engines. A good user of a search engine would try various searches and read lots of results to gain information, then give you the relevant information. A bad search engine user would put in one search, click the first result, and copy whatever it said. LLMs make the bad workflow faster and the results worse, which is one reason they're so obvious, but the human cause is pretty much the same.

doublelayer Silver badge

Re: Wait, What?

It allows anyone to request changes, not to merge them. It's not that unusual, as otherwise someone with a fix implemented would have to hunt for a way to get themselves approved to show it to you. That would probably involve finding a maintainer email, which is a lot more open to spam than opening a PR would. The other advantage of having the general public send a PR directly is that, if they start by emailing you to ask permission to send you code, you would probably have to say yes because you don't know whether the code they have is any good, but if they send a PR, you can see their code whenever is convenient and ignore it otherwise.

Sudo maintainer, handling utility for more than 30 years, is looking for support

doublelayer Silver badge

Re: superpowers not superuser

Actually, I think it is me they were accusing of not knowing what su does. Since they didn't specify what it does which I clearly don't understand, I'm none the wiser for what similarity it is supposed to have with sudo that makes it relevant. Therefore, I continue to think that it does a smaller number of things than the stuff sudo does meaning some people will want sudo because they want one or more of those.

doublelayer Silver badge

Re: superpowers not superuser

No, it didn't, specifically the "often used to confer only a limited set of magic privileges, for example to gain admin privilege for a particular service" part. Su does less than sudo. Sometimes, all you need or want is what su does. In that case, you don't use sudo and are fine. Sometimes, you don't even need what su does so you leave out both. But if you ever want slightly more than the one feature su provides, then you look for replacements, whether that's sudo, doas, sudoRS, or something else. Pretending that the feature you want is the only feature that exists doesn't help.

'The EU runs on Microsoft' – and Uncle Sam could turn it off, claims MEP

doublelayer Silver badge

Re: Reality bites

The problem is that your approach is easy when you have total control of everything. If you actually do have total control of everything, then it's close to the best approach. You probably don't. Liam's approach is better for the many situations where you might have that policy but not an infinite budget or complete permission to accept any pain, system outages, employee firings, etc that you frequently recommend. It's nice to dream that whatever change we want will be mandated by people who give us free rein to implement it in whatever way we think best regardless of the consequences, but I've never been given that power before and I don't think you will this time.

doublelayer Silver badge

Re: Reality bites

By the time someone decides they want to fire nuclear missiles, paper agreements and the economic or political leverage you're talking about no longer matter. If the US wanted to stop someone who was already determined to launch nukes, they would probably have to threaten military consequences. Your concerns might be more relevant in smaller-scale events, but if the question is whether the missiles would fire, the answer is yes, and if someone with the ability feels it's worth launching them, there's not a lot that can stop them.

doublelayer Silver badge

Re: Reality bites

The law may try to prevent it, and it would succeed in the sense that people don't sign support contracts with Pyongyang, not that North Korea has any interest in paying foreigners to maintain their software, but North Korea has all that open source code, same as anyone else, and they use it. They use KDE as their desktop environment and lots of components from Fedora, and the US does not try to punish the KDE community or IBM/Red Hat for that because neither did anything to help them. US law does not, nor could it likely succeed, try to enforce people keeping open source code from North Korea's maintainers.

AWS says you're on your own if media codec patent owners come knocking

doublelayer Silver badge

Re: At the risk of being fair to Amazon

Except that the software concerned was written by AWS, so they know what licenses apply to it more than the individual user does and clearly think that they don't have some of those licenses. It might be acceptable if AWS told users what licenses they would need, but they don't seem to have done that either. If I violate the license of a component I distribute in software I charge people for, the charge for the license violation will usually be directed to me, not the end user.

If your argument is the simpler "it's not illegal for Amazon to make the contract changes they have done", then you might be right, but it's an entirely useless counterargument for anything from the article or the comments thus far which consider whether it is ethical. You might also be wrong, because license terms on patented things are set by the patent-holders individually and often require licenses for the inclusion of their patent, so if Amazon is running code that violates that license, they may be culpable on their own whether or not their customers execute that part.

Microsoft engineer speedruns Raspberry Pi magic smoke in five minutes

doublelayer Silver badge

Re: He posted this?

I don't think he did connect that as a hotplug. He connected it backward, and the pins that accept lots of power are not the same when you do that, meaning the not hotplugged installation will still deliver power to the wrong place when it gets plugged in.

I don't know why he did it backward, but it's possible that whatever he was connecting wasn't one of those hats that's conveniently the same size and shape as the rest of the board so it's obvious. If you connect using a ribbon cable or to something which passes the GPIO through, then you have to be careful with the orientation.

Europe shrugs off tariffs, plots to end tech reliance on US

doublelayer Silver badge

Re: Meanwhile, back in the real world

I would hope that the people with the authority would understand the risks of the tech they're using too and, having known that, would come up with a clear plan of where they wanted to go which they could stick with. Experience hasn't led me to believe that those hopes will be rewarded. Politicians are not good at understanding tech, providing resources for tech improvements, or sticking with any plan for the years it would take to fully change something this large. That's why, even when people sound supportive, I still try to find ways to make the change as easy as possible so I have to ask them for less help, therefore if they end up not being that motivated, maybe I can still manage it.

doublelayer Silver badge

Re: The scope is not large enough

"One of the features of the US constitution is that it combines head of government and head of state."

How is that relevant? In most countries where that is not the case, the head of state is a ceremonial role with no power at all, and in many others, the head of state is a person with theoretical power which they don't use because it would be hideously authoritarian. This has come up before, and last time I asked for the last time the monarch of the UK used the power they have in opposition to the head of government. The last example I could come up with was the removal of the Australian PM in the 1970s, an act so unpopular it nearly got Australia to expel the monarch and become a republic with the new and the old PMs both supporting the republic plan. I contend that this separation has no effect on government power.

"In general countries with a PM or the like as head of government that position depends on being able to put together a Parliamentary majority"

And in countries with a presidential system, the president must win an electoral majority too which in many cases, though not now in the US, requires experience in government. The question is what can happen afterward, and parliaments have shown that dictators can manage to get their majority and use it, with Russia in the 2000s and Italy and Germany in their fascist periods being obvious examples of successful conversion from parliamentary democracies to authoritarian states.

"Lord Chancellor is a member of the government of the day but the rest of the judiciary as appointments on merit, not political appointees."

That is a good step and possibly one the US should adopt. I should point out though that the UK used the same system, one politician being able to nominate judges, until that was implemented in 2006. It's not the fundamental difference in structure you imply, and unlike in the US, where changing that would require a constitutional amendment but would then take another one if an aspiring dictator wanted to reverse it, the 2006 decision could be reversed much more easily if a UK parliamentary majority wanted to entrench themselves.

doublelayer Silver badge

Re: Meanwhile, back in the real world

The people who want the change need to be reminded that a lot of people don't understand why. If you run it and are in the position to demand what you have demanded, it works. If you're not, then you're seen as the person bringing the problem (cost of replacement, some software needs to be rewritten, known disruption to processes, potential additional disruption, etc) and the person advocating Microsoft has the solution (one more M365 annual payment and people keep going).

If you want the change to happen in a place you don't have total control of, you need to do a little more to point out why the change is necessary to people who don't have a full understanding and a lot more to show them how to fix it without breaking everything, because you don't often get to say that something's important enough that you can ignore the pain and expense of implementation. Perhaps the EU has enough people doing both of these that they can do that. Many of the previous attempts haven't. Your approach isn't going in a good direction.

doublelayer Silver badge

Re: The scope is not large enough

That is true, but you imply that other countries do have working protections. None does. The unfortunate part of democracy is that people who get elected can be stupid or evil. The unfortunate part of non-democracies is that people who take power are almost always evil and many of them are also stupid. Anything unethical the US is doing can be done again, even if they fix it in the middle. Anything unethical the US is doing can also be done by other countries, and depending on the size of that country and your country's reliance on it, it can have the same, smaller, or larger effect. Keep that in mind when deciding how to plan.

Let them eat Pi: RAM shortage bumps Raspberry prices as much as $60

doublelayer Silver badge

Re: PI is over.

What is the replacement you suggest? In my experience, most SBCs that are competitive on price and specs are not built for industrial stability; they get stuck with things like custom kernels which become maintenance problems, driver gaps which mean not everything works even years after they're released, or they're not always available which would be a big problem if you relied on them for a commercial product. Meanwhile, most of the things I know that are good for industrial uses are a lot more expensive, and while they tend to be better on software support, sometimes similar gaps show up.

There is plenty I don't like about the Raspberry Pi, but long-term software and hardware support is one of its strengths and, until now, they have been rather cheap.

doublelayer Silver badge

That's why there are so many people who lie about what AI does. If LLMs do what they actually do, then it becomes clear that it will never make anywhere near the money it promises to. But if LLMs can replace lots of people's jobs, then you could get a little less than what all those companies were giving those workers, and that could easily exceed the investment being made this year. It can't replace so many jobs, but if investors think it can, they'll keep paying until the end. Combine that with a lot of people who aren't investors but think it can replace jobs for some other reason* and you've got plenty of noise supporting investors' confidence that this is the perfect investment for the long-term investor because they think it's guaranteed to make massive profits and they have to wait a few years. That's also the perfect investment for the fraudster because now they have a few years to take as much as they can before it collapses.

* There seem to be several reasons for people to assume AI can do everything, even if they aren't personally investors in it. Some of them seem to be:

1. They want to have AI do their work, so AI must be able to do so so they're not being unprofessional.

2. They want to not have to do work at all, so if AI takes all the jobs and they need to set up something else, then AI must be capable of doing it.

3. They want to hate someone, and if AI took all the jobs, then the people making money off the AI would be easily despised. It seems like you could hate someone, even the same people, for better reasons, but still.

4. They want something to exist which doesn't, they don't think it would happen without AI, so if AI was able to make it, then they would get what they want. This is the vibe-coders' position, in my experience. People want a piece of software, nobody's writing it for them, so they are sure that the next run of the AI code generation will compile to the thing they imagined.

Microsoft's Sinofsky saw Surface fail coming – then hit up Epstein for advice on exit

doublelayer Silver badge

Re: Is that all?

I'm not sure how much I'd trust an internet wealth estimate, but even if it's correct, it's useful to consider that Microsoft stock has been a rather good investment to have been in between 2012 and 2025 (quite a bad one for 2026 so far). Microsoft stock worth $300M on New Year's Day 2026 would have been worth $16.88M on New Year's 2013. So if he's been investing in Microsoft since then, that payment might have been rather significant for him.

Notepad++ update service hijacked in targeted state-linked attack

doublelayer Silver badge

Since that whitelisting would have blocked the unrecognized updaters if you did it correctly, maybe it wasn't the tool you use they were criticizing but how you've chosen to configure it.

It's worth considering, for instance, that this wasn't something new in Notepad++ or something done to their servers. As far as we know, this vulnerability could only be exploited by a MITM attack that replaced the URL of the update binary which was then downloaded and executed. Your installation system, unless you messed up, wouldn't be vulnerable to that. But if you interpret this the way you have, then you can come to unrealistic ideas of how bad the problem was, how much it's the fault of the Notepad++ maintainers, and have a drastic conclusion. If people rely on this software and many do, then your drastic conclusion from an incorrect premise will cause problems for their work until they find a suitable replacement. Maybe you have arguments against that, but if you continue to assume that criticism was of the tool you used which it was not, you won't be making them.

Open-source AI is a global security nightmare waiting to happen, say researchers

doublelayer Silver badge

Re: FTFY

It's not hard to tell. Here's the code. It's under the MIT license. That's open source. The pricing page you linked doesn't contradict that, especially as what they charge for is:

1. Running models on hardware that isn't yours, which costs extra and has nothing to do with the right to see, modify, and distribute the software.

2. Storing models on their servers without making them public, which has nothing to do with [etc].

What's your evidence for distros being unwilling to touch Ollama? Arch has a package, Ubuntu has a Snap, there are probably others. Not that, if they didn't, it would indicate a problem with the license because frequent code changes making it a maintenance nightmare is the more likely reason.

AI security startup CEO posts a job. Deepfake candidate applies, inner turmoil ensues

doublelayer Silver badge

Re: Double standard?

"If you work remotely and there is a network problem, can you continue to do your job?"

Some of it, yes, because I have the code I'm developing on a local computer. We also take steps to keep my network functional because I will need it for other things. That won't help if the LLM service has an outage.

"If I have a particular set of skills, why should I not be able to build an AI agent perform those tasks. Then I can license (ie. receive a paycheck) those abilities to employers."

If you have the ability to make software that actually works, then you can. It's called selling that software to companies who should ask the same questions I've asked. Maybe you sell that for them to run, maybe you sell it and a support contract where you go and operate it for them too, but if you're going to do it ethically, you inform them how you're going to do what you promise. If your plan is to pretend to be an employee but use software they don't know about, you're taking a risk that might not work out well for you because the consequences for violating policies on software use can be more severe than just not doing a good job was. I'm not sure if that is your plan because you speak in generalities and argue against things we didn't say, so I don't know what you actually intend to do and little about your opinion other than you think AI can do a lot of things I've rarely seen it manage.

doublelayer Silver badge

My takeaway is quite different. It sounds like they knew this was a fake candidate from the start but wanted to see what that would be like, but since there's not much point in doing that except satisfying curiosity, they kept telling themselves that maybe they'd find a valid candidate in there even though they subconsciously, and probably consciously too, knew that wasn't going to happen.

I'm not sure I've correctly understood your suggestion for how to interview, but if I have it right, I don't think it's the best approach. You have to get a lot of information which means complex questions, but you don't want the interview to be challenging for that sake. You want the questions that elicit the most information, and difficulty doesn't do that. For example, one type of question I like in interviews is a really simple system design question where I ask the candidate to describe what they'd consider when writing some simple software. Good candidates show they're good by knowing a lot of the possible obstacles they should consider before tripping over them, design considerations that would change the approach, realities of the business process that might make a difference, etc. Throwing a hard question at them doesn't tell me if they're aware of those things and know what to do when they happen.

doublelayer Silver badge

Re: Double standard?

This rubbish argument again?

As I read that, my thought was "Does it matter that it's AI if it can do the job?"

Why do you assume it can do the job? And yes, even if that was the case, there's more involved. For example, can it do the job without sending data to an untrusted LLM-execution server? If there's a network problem, can it continue to do the job? Can it do the job without hallucinating important details? Can it be trusted to continue doing the job as well or improving rather than losing access to one model version and getting forcibly updated to another which handles all the prompts differently? We don't generally have to think about these questions because almost nothing passes a single one and you only need one failure for it to be unacceptable.

"Why is it that employers deploying AI systems to replace workers is ethical, but if an employee sets up an AI to do their work it's a scam?"

It might not be ethical and it might not be a scam, but there's a reason why employees don't generally get to outsource their work to someone or something else without permission, a fact that is not different when it's a program because of all those other factors I already mentioned. Also, most employees who have done this are doing it even though the AI they've chosen to use does not do the job correctly, which is why that's a scam. Employers who replace employees with AI have often done the same thing, and from the customer's perspective, that's also a scam because they're being promised functioning services but getting AI hallucinations, which is why many of the attempts have failed and been reversed.

doublelayer Silver badge

Re: Back to in-person application.

Okay, then in that version, we simplify it to which country has the most expensive possible intranational travel cost. Russia seems like the obvious first guess because it has the longest total distance to take someone from the east coast to the west, but I'm wondering if somewhere like Indonesia which has more inter-island travel difficulties might not be able to exceed that.

Back in reality, some businesses do actually agree to hire people from not their country, whether their countrymen approve or not. That even happens when the company doing the hiring is not so massive that they have a local office in almost every country. In that case, we still calculate the around-the-world cost because some people will have to consider paying it to implement our solution. It's not quite as simple as it sounds because, depending on what type of employee is being hired, the travel cost to salary ratio will be higher than assumed. If this becomes a problem, there is a market for a trustworthy local business whose job it is to bring candidates to an office where their identity is checked, they interview on known hardware, and other things that an in-person interview would want to establish. That has its possible problems too, but it can do a lot against the basic version which should reduce the number of impersonators involved.

doublelayer Silver badge

Re: Back to in-person application.

The solution being that the employer pays for the ticket after the candidate agrees to use it. The candidate should not be asked to pay anything for this process. Of course, there is the theoretical risk that the candidate then ignores the ticket or that the employer strands the candidate through a fake return ticket, but since nobody benefits if either of those happens, it probably won't happen very often when compared to the advance fee version.

'Hey! I'm chatting here!' Fugazi answers doom NYC's AI bot

doublelayer Silver badge

Re: Ok for businesses to take employees' tips

I think that is incorrect. That is what New York City claims to have done, and even if we assume that they really didn't, I don't know where you get your confidence that they could have. LLMs do not perfectly understand the text they're trained on, so even if you trained it only on the relevant laws, it can still get the answers wrong by random chance. The extra randomness and variability of unrestricted prompts makes this worse.

Take that summary I linked above about what New York state/city laws allow you to do with workers' tips, since that's the subject of the comment thread although I don't know why. Here are two sentences about tip pooling arrangements:

"Under New York labor law, employers are allowed to require their employees to share tips, but they cannot participate in the tip pools themselves."

"The key requirements are that: The pooling system is voluntary [...]"

What does that mean? Those appear to contradict each other, because the employer can require people to do something as long as the people can choose whether to do that thing voluntarily. If I'm an employee who doesn't want to be in a tip pool, the bot can show me the voluntary line, whereas if I'm an employee who does and hopes the employer will make that happen, the bot can tell me that it's fine to require it. The LLM is trying to respond to the prompt, and when the prompt assumes that something exists, the LLM generally looks for valid text that best satisfies that prompt and it doesn't have a full legal understanding. In legal fact, there's probably a definition of "voluntary" which is important here, but the bot doesn't know that because it doesn't know anything.

doublelayer Silver badge

Re: Ok for businesses to take employees' tips

It's both, but probably neither of them is specifically tilted in anyone's favor. It's quite possible that it would do the same thing by promising to an employee that something they want is definitely legal whether or not it actually is, but it might also be producing specifically incorrect information because of something in its training data which, being an LLM, it's incapable of encoding to the specific rules that the law requires. Laws about what employers of tipped workers can do are complex, and that's a summary from a non-governmental source. Being trained on the more absolute but less clearly-written law, regulation, and probably some court proceedings is not a situation an LLM can generally handle without making plenty up.

doublelayer Silver badge

Re: Ok for businesses to take employees' tips

That depends what sycophancy means, but we know what they meant when they said it, and what they meant isn't that big a diversion from the dictionary definition. A sycophant might have all sorts of reasons to flatter and support the object of their attentions, but the core part, the unquestioning and effusive agreement, is the important part. The output from an LLM being called sycophantic is often both of those things.

Euro firms must ditch Uncle Sam's clouds and go EU-native

doublelayer Silver badge

Re: What about the CDN

I think they're a smaller part of the problem. The most sensitive data and operations, the things that would cause the most chaos in the nightmare scenario, don't need to go through CDNs and most of them probably don't. Internal data on government, industrial, or infrastructural systems generally doesn't need to use a CDN because copies of it aren't being transmitted in bulk. CDNs are a much bigger thing for public-facing services, and the consequences of those going down tends to be smaller. CDNs are also often easier to switch at short notice. Therefore, though it might make sense for a company outside the US to build a competitive product for people to switch to, it's probably not something that needs a lot of effort or funding when compared to building a new set of productivity software or a place to operate lots of processes.

doublelayer Silver badge

Re: Sorry you don't get to "both sides" Trump's authoritorian governance

Judges should restrict action if and only if that action is already against current laws, but when that is the case, they absolutely should because that is their job. If a government wants to do something and the law says they can't, then it shouldn't and usually can't wait for the next election for voters to decide, from the few options available, whether they'll end up supporting it. If the government wants to do that, they have to change the law. If they don't, then judges have the power and the responsibility to stop the unlawful actions, reverse their consequences, and forbid those actions from being repeated, and if those judges are not obeyed, the rule of law has broken down.

doublelayer Silver badge

Re: It is unfortunate, but true

So, if I'm understanding your argument correctly, controlling it for 45 years, until they were forcibly expelled, is totally fine? Not counting those parts of Ukraine and Georgia they still control by force and Belarus they control by propping up a friendly dictator? They didn't go home immediately, they didn't go home without firing shots, they did none of the things you're incorrectly giving them credit for, and therefore any points you might have had that aren't completely fictional have been hidden under your clear attempt at ignoring obvious history.

Dow Chemical says AI is the element behind 4,500 job cuts

doublelayer Silver badge

Re: "The jury is still out when it comes to determining how much job loss AI is causing."

I would need some information about how many of the jobs that someone said was/will be replaced by AI were 1) actually lost rather than a "maybe this person will be replaced soon"; 2) actually had an AI program used in place of the former employee rather than the job being ended altogether or given to a different person; 3) actually done by what they're suggesting by AI, meaning a mostly automated program rather than someone realizing that they had a person doing a mechanical task and writing a normal, deterministic program to do it; 4) actually done successfully for a long time, rather than the AI plan going horribly awry and people being re-hired to go back to human work (of which there have been repeated incidents); and 5) implemented with the financial flexibility to continue to use their current approach at the increasing compute costs of LLMs. Do you have that number? The people who have parts of it seem unwilling to give me that level of detail.

I've seen plenty of things that didn't meet these requirements. Many of them were also sold as having met them. I've seen stuff that wasn't AI sold as AI. I've seen people promise they're going to replace workers any day now and then they just didn't. I've seen AI workflows that are going to save us lots of time which took longer. I've seen normal job cuts which, to make sound better to the investors, they sold as AI when it really wasn't. How much more evidence do you have, because I don't have enough yet.

If you're one of the 16,000 Amazon employees getting laid off, read this

doublelayer Silver badge

Re: Universal Basic Income

I think you would. Budgeting this out depends on a lot of things like what work you're doing on the 150 days and where you're living, but I think there are many people who could live a much higher standard of living than a peasant while not working half the year. The problem is that we don't compare our standard of living to peasants from 900 years ago, so it wouldn't feel good. For example, you would probably still have and afford some indoor heating and hot water. Those feel like relatively basic things to us, though to a peasant, they wouldn't be. You would have access to a lot more quantity and variety of food, something peasants did not get. Even something as simple and cheap as a few light bulbs means a lot less time spent making candles, to say nothing of getting the stuff you need to make candles, to say nothing of the convenience of light at the touch of a switch, to say nothing of the significant reduction in the risk of fire. But until we think about that and compare them to a situation we've likely never had to experience for long, they're just light bulbs, beneath our notice and certainly no luxury since they're all over the place.

If we calculate it out, though, we're more likely to see and think about the list of things we either have or have a chance at getting which we would have to give up for the 22 weeks of holidays this gets us. That's logical because those are the two alternatives that are realistically available to us, but it means we underestimate how much a peasant would enjoy the basic standard of living we can obtain if they got time machined into it.

doublelayer Silver badge

Re: Universal Basic Income

You have comprehension issues. For example, when I said that "none of it [the money] might be yours", that was not an insinuation of your wealth. As I noted about myself, they have people working on investments I have none of my money in, so none of that money is mine because mine is in a different fund. Or, if you invested your money in another bank, then it also might not be yours unless those banks invest in each other. You interpreted that as something it wasn't, much like you are doing with the employees you don't bother to understand.

I don't know what everyone at your council are doing. You could find out if you wanted. The fact that you only consider the people doing physical labor which you can see indicates that listing the many tasks that some of those people are certainly doing is a waste of time since you already know enough to know that plenty of things are done by your council and they need people to implement those. There may be people who don't do much in that building, but you've made it clear that you have either no knowledge or no care for the many things that account for some or all of them.

doublelayer Silver badge

Re: Universal Basic Income

Just because you don't know what someone is doing isn't sufficient evidence that they're doing nothing. Companies with only one public number might still have hundreds of customer service people behind that number, and even those companies who decide not to have one still have employees to do the things other than customer service.

As for what the people in the Commonwealth Bank buildings are doing, I can explain that. They are trying to take money and turn it into other money, even though none of it might be yours. For example, they operate private equity and commodities trading funds, both of which require a lot of people to do a lot of analysis to determine whether they think something will make money or not. You might not invest in either of those. I don't. Lots of people do, and even more large organizations do, and those investors are willing to pay for people to do that analysis if they trust them, and that's why there are people who work on financial services. You don't go into the buildings and talk to those people because they're not directly interacting with you, but if they disappeared tomorrow, you would notice eventually. Depending on your specific situation, you might notice in a variety of ways and not necessarily negatively, although there is a good chance it would be negatively.

doublelayer Silver badge

Re: Universal Basic Income

"Peasants only worked 150 days a year"

That is completely wrong. What that data you're summarizing actually says is that peasants had to work approximately 150 days a year to afford rent, and that specific number is called out as being in a time of notably high wages. What did they rent? Land, which they had to farm for the food they ate themselves as opposed to the food they farmed on those 150 days for others. We can do exactly the same calculation today. Take your annual cost of housing, divide it by your hourly wage rate. That's how much you have to work this year if you ignore the same things you're ignoring to use that incorrect argument.

If you have a point, making an incorrect claim to defend it doesn't help. Not that this claim would be a great defense even if it was true, because you probably can work 150 days a year if you're willing to live like a peasant would at that time, by which I mean poor-quality and small housing, no education for children, little access to luxuries, and relying on your community's willingness and ability to help you whenever something goes wrong. Then again, you probably have an opinion you're trying to express which is unrelated to historical personal economics, so maybe we should skip to that.

Tesla revenue falls for first time as Musk bets big on robots and autonomy

doublelayer Silver badge

Re: Cars - like phones

Depending on where you live, there might not be so many cars available whenever you want to use one, and people who live in that kind of place tend to have more cars. Also, depending on how often you need to travel somewhere, getting a taxi, even now when rideshare apps make them somewhat cheaper, might end up being more expensive. If you live next to convenient public transport, that reduces the number of times you need one and therefore the total expense, but keep in mind how many places don't have a complete public transport system, even places right next to cities that do.

No one talking about a datacenter could be a sign one is coming

doublelayer Silver badge

Re: "We won't tell the public anything

This company doesn't build DCs in the UK, but others do and will. Tactics used here may be used in identical or comparable ways during that build process. Comments you already read question whether they can do exactly the same thing because the EIA process doesn't apply to something of that scale or whether it does after all and they have a different regulation they need to work around. Things that happen in the US can affect you, you know.

Microsoft 365 outage drags on for nearly 10 hours during bad night for North American infra

doublelayer Silver badge

Re: When MS365 & Azure go down, GWS & GCP stay up

The problem with that is that, even if all your statements are true, you've put no effort into proving them. You just state them as unquestionable fact when proving them, even with complete access to all Google and Microsoft's data, would still be tricky. I'm not telling you that Azure is better than Google Cloud, but I am saying that you have not proven any of your claims to that effect and you seemingly aren't trying to.

For example, only one group's attempt at a comparison assigns Google Cloud the lowest uptime percentage of the big three, although Azure had the highest number of incidents of some type, and we would have to interrogate how they arrived at their statistic which probably includes deciding how to weigh different types of downtime since it's almost never everything down worldwide. Claims like "literally magnitudes more reliable" require evidence. Since you haven't tried to provide the numbers you claim to have, let's look at a list of large outages in 2025. Microsoft scores 2: an Azure outage on October 29 and a Teams outage on December 19. Google has a Cloud outage on June 12, a Workspace outage on July 18, a Meet outage on September 8, another on September 26, and a Workspace outage on November 12. That doesn't match your statistics. Your claims are subjective under the best of conditions and your arguments are not the best of conditions for them. Either of those sources of outage data can be wrong or have bad methodology, as can your statistics, but we can't even look at yours because we only have vague and exaggerated personal conclusions.

doublelayer Silver badge

Re: Confusion Was Rife...

We're talking about Office365, the product for organizations. Pretty much everyone using that has it attached to their own domain. But yes, if you're one of those people who uses a something.onmicrosoft.com email domain, it's not so easy. The next time I see that from anyone other than a spammer, which will also be the first time, I'll let you know. For the rest of 365 users, your objection does not apply.