The Register Home Page

* Posts by doublelayer

11418 publicly visible posts • joined 22 Feb 2018

Not hot on bots, project names and shames AI-created open source software

doublelayer Silver badge

In their defense, they also accuse the editor of having a lot of AI features, albeit optional ones, and this does seem supported by the long list of "AI", "LLM", and "agentic" features prominently displayed. The creators of the list have decided that optional LLM features are bad enough to land you on the list as demonstrated by their first entry, Firefox, which you can also disable LLM features in and mostly wouldn't see them even if you didn't unless you specifically hunted them down. Whether we agree with that or not, that makes Zed compatible with their rules even though they do accuse them of LLM-written code with no evidence cited.

Less in their defense, they do have a pattern of accusing people of LLM usage with little evidence. For example, the entry below Zed is eSpeak NG, and the crimes they committed there include the use of copilot instructions. The evidence for that is an issue that was created in October saying "Set up Copilot instructions" but with no code linked to it. The other complaint is that Copilot reviewed a pull request, on GitHub, where Copilot is pushed all the time. These seem like flimsy reasons to add something to a list.

I disapprove of most LLM use, but I won't be joining this project. It seems to have extreme criteria for inclusion and to make little effort in distinguishing what happened and how important it was.

doublelayer Silver badge

Re: Mind where you put your money, if you can't afford to lose it

On what do you base your indictment of those harassing the original maintainers? Whether we like it or not, saying nasty things on public social media, including here, is not illegal. If you have specific examples of people who went further than that, which I admit I have not seen because I was unaware of this repository until I read this article, you might have a point. If it was merely that they were so noisy and vicious that they caused discomfort and, since they were LLM fans, almost certainly wrong, that's not criminal.

Similarly, we should consider that some online discussions surrounding this have accused people of using this list to harass the projects accused of using LLMs. Like the last group, I have not seen the alleged harassment firsthand, and you could not blame the fork of this project which specifically asks people to make their accusations respectfully (I don't know if the original did). The most important factor and the only one that could be criminal is what anyone actually said, but I would prefer that neither type of harassment occurred.

Fast Pair, loose security: Bluetooth accessories open to silent hijack

doublelayer Silver badge

Re: Not too sure what the problem is about

That is an underestimate of Bluetooth's security procedures. Bluetooth connections are encrypted, or at least almost all are because it's built into the spec. That is, contrary to Lisa's expectation, more than we can say for plenty of hardware on the market that used or uses unencrypted wireless transmissions. For example, I have one of those wireless keyboards that has a USB dongle and connects to that dongle almost immediately when switched on, but it's not encrypted. If you're in range, you can record what I type and you could send keyboard commands to the connected machine. If I used a Bluetooth keyboard instead, you couldn't do either of those things.

Connections can also be authenticated, and this exploit is relevant to that part. Some devices don't bother with that and do let whatever device announces itself connect, but many devices intend to authenticate the devices making connections with shared secret information and, if they do that properly, would withstand an external attempt to divert them.

doublelayer Silver badge

Re: Ship it!

"The idea that someone can stroll through a carriage with a magic antenna and silently re-pair dozens of earbuds is fantasy. If it were that easy, Bluetooth would have collapsed as a consumer technology years ago."

The lack of an attack does not disprove this for two independent reasons. For one thing, the exploit allowing some re-pairings was just made public and uses an extra piece of software which plenty of Bluetooth devices do not use. If this exploit did work, then it would only have become available to attackers somewhat recently, and then only if they independently discovered it. The fact that nobody attacked using this five years ago doesn't matter if the vulnerable software is newer than that.

The other reason is that, whether you can attack devices in bulk with this or not, most people don't have any reason to want to. What's the benefit in mass-hijacking headsets all over a train? It's a prank or vandalism at most, even if you can activate all the microphones you don't need to because you could just carry your own microphone to get the same useless audio. This would be of most use to a targeted attacker trying to go after one device, and that wouldn't necessarily have become public because it could be difficult to detect.

In practice, I think your conclusions are closer to correct in that a lot of devices I'm aware of won't accept pairing requests when they're already paired and, if I'm understanding the information on this vulnerability, that's still true of the hardware they are referring to. It seems like an attacker would need to make their attempt in the smallish gap between the user powering on their accessory and it connecting to their main device, and if the attacker succeeded, the user would likely become confused because they're not getting a connection. The user is most likely to turn the accessory off and on again, breaking the attacker's connection and if the attacker keeps intercepting it every time, they would think their accessory had stopped working properly. There are a few circumstances I can envision where it would work better, but the attacker would need to get quite lucky to find one. You still can't prove that from it not already having happened to our knowledge.

Moon hotel startup hopes you get lunar lunacy, drop $1M deposit for 2032 stay

doublelayer Silver badge

Re: I admire your trust in human nature

"That treaty has always been a dead letter. Tell me, what formal complaint has EVER been filed by one country against another under it?"

Canada, against the Soviet Union, for the contamination caused by Kosmos 954. The USSR paid, though not all they should have. So far, that's the only one, but it worked that time.

However, I wasn't arguing that some other country would make a claim against the US and the US would pay, since there's no logical claim to expect. I was arguing that the US would probably not jump to permitting this company to do whatever it wants because they don't see a benefit from it, this company can't do it, and this company will need approval from some government, almost certainly the US government, to launch their stuff.

doublelayer Silver badge

Re: Outer Space Treaty ?

Mostly the fact that this company only operates for its own purposes and doesn't have anywhere near the money to make any politician care about what it wants the rules to be. Several countries ignore provisions they don't care about, but usually for nationally significant projects like anti-satellite tests (China mostly but some others) and getting the first big LEO internet satellite constellation regardless of the risks (US) and getting the second such constellation (a few countries in a race) because, if I had to guess, they're assuming that someone will stop this but the first movers will get grandfathered in.

A hotel set up by people who don't have a clue how to do it or fund it isn't likely to be the same. I don't think any country is going to break the treaty for these guys' benefit.

doublelayer Silver badge

Then go and read the history of existing space law, because the answer is that those do still count, partially because launches are authorized by the government of the state. We don't have to argue about it.

doublelayer Silver badge

And please, “doesn’t have ownership rights”? Maybe you want to expand on that bald assertion, starting with explaining who has, and who hasn’t, “ownership rights” on the moon. And the basis for that claim.

Sure, if you need it. The basis is the Outer Space Treaty. Relevant portions of the summary read and their significance is:

"States shall be responsible for national space activities whether carried out by governmental or non-governmental entities": So they will need permission from at least one government, almost certainly the one that launches all their stuff, to do that, and

"States shall be liable for damage caused by their space objects": That permission is going to come with some big strings attached to prevent that liability from being invoked since their hotel runs a significant risk of contaminating the moon, and

"outer space is not subject to national appropriation by claim of sovereignty, by means of use or occupation, or by any other means": their ability to retain control and ownership of their hotel if they landed it isn't going to work the way they think it does.

Trump says Americans shouldn't 'pick up the tab' for AI datacenter grid upgrades

doublelayer Silver badge

Re: And

We don't agree on the important things. We agree on simple facts. There are larger conclusions that we draw differently from facts, some of which I would agree with you on and some of which I wouldn't. The difference in the parts that aren't reliable is extremely important and results in completely different next steps in research and policy ramifications for fusion power compared to wind and solar power, hence why pointing out that both do indeed have something unreliable is not a useful point.

I don't know why you post. If you do for the same reasons I do, to try to understand what others believe and, where I think their beliefs are harmful, it can be useful to understand where you differ with them. I think those you debate wind and solar with will also agree that wind stops blowing sometimes and that is a problem, and you could then skip ahead to how good or bad the current solutions are and future solutions will be, the point there's likely disagreement on. If you think that agreement that the sun sets and solar panels don't do much after that is concession, I think you're doomed to never convince people of your opinion no matter how correct it might be. If you have a different reason, then this advice is probably useless and I think we've gone as far as we can go with this.

doublelayer Silver badge

Re: And

"Amazingly when I point this out about relying on wind and solar on the grid it causes meltdowns."

That's because of something you're implying is a misunderstanding but I'm pretty sure you understand without me having to explain to you. The difference is that wind and solar are reliable in the sense that we know how to generate power when there is wind or sunshine, but they're not reliable in the sense that there's always wind or sunshine. The problem we have to solve is not how we turn this thing into electricity (we can improve efficiency with research though) but how we handle some times where we have a lot of it and some times where we don't. Fusion power is not reliable in that we don't know how to make it generate electricity, or rather we don't know how to do that without destroying the equipment we need to do it. That is a problem that fusion currently faces and wind and solar do not, and while we can focus on the downstream problems on the latter, fusion has to get the making energy come out of the process step first.

That is why fusion research could be worth it, because they have some chance of figuring that out, but people who think they can start producing facilities to do it industrially are jumping ahead. Either they're extremely optimistic or they're fraudsters. Either way, they're not going to succeed.

"I am sure people would disagree with some of your purchases and spending, but that is the great thing about freedom. We are not the same."

Of course, but that doesn't stop you saying things are bad when you believe it. Why should it stop others from doing so. It doesn't stop you making recommendations to prevent the things you think are bad in policy changes. Why should that be an argument against theirs?

doublelayer Silver badge

Re: And

"How do they figure out how to make one if they dont build them?"

You start with how you make fusion power that works reliably. Once you succeed, you find out how to build a machine to efficiently do that process at scale. You don't build the machine first in case you find that the way that fusion works doesn't fit inside the machine or needs something the machine won't let in.

"Is it not better the private individuals waste their money trying to achieve whatever especially if we are such a long way away from such a thing and that it costs so much for so little?"

I suppose if the other option is that the public has to pay for it, then yes, I prefer that private people do so. That doesn't mean it's a good thing, though, just that the less bad of the two funding options was chosen.

Bond, debt bond: Investors shaken, not stirred by Oracle’s borrowing spree sue Big Red

doublelayer Silver badge

Re: Realised losses?

I don't think you can define mark to market as "shady accounting". They are legally mandated to do that for things they intend to have available for liquidity. Their risky choices worked out badly, and if the laws had been different, maybe they would have avoided making those choices, but they didn't hide what they were doing.

But perhaps the better question is why your point, to the extent it is correct, has any significance whatsoever? People buy bonds, sometimes with the intent of selling them before they mature, sometimes without that intent but with the knowledge that they can if it eventually comes to it, and sometimes to hold them but being judged on their market value by a lender or a manager or a client, and all of those groups have a legal right to information about the plans of the company to which they're providing cash to evaluate the credit risk they're taking on. What does it matter that some subset of them might have had a plan which means they're not any worse off? Your post suggests that the bond sellers are a distinct group from the bond holders when they're not and that there's some difference between them that has any meaning here.

Lawmakers urge FTC to probe Trump Mobile over 'deceptive' marketing

doublelayer Silver badge

I think it's a way of making brand recognition pay out for them. If you know only the names of the main providers and go to their websites, you'll see only the expensive plans. If you're willing to pay that and don't do the research, then you buy one. Meanwhile, anyone who isn't willing and wants something cheaper does some research, finds the less advertised brand, and still ends up paying money to the same place. It's an efficient way of finding who doesn't mind spending extra money or doesn't realize there is a choice and getting more from them.

Just because Linus Torvalds vibe codes doesn't mean it's a good idea

doublelayer Silver badge

Re: Synthetic Take: Why Vibe Coding Isn’t “Just for Toys”

I couldn't, but then again I was reading it on the assumption that you intended to say something and, however you wrote it, I should try to understand you. I find that I can often recognize LLM output more reliably when there's a lot of unedited text, but not every time. That's not too surprising because it's intended to be similar to human writing, and usually the most obvious indicator of an LLM is that it's saying little with a lot of words.

This is how I feel about vibe coding as well. I don't care if you use an LLM to write a comment if you're doing that because it helps you phrase what you wanted to say. I do mind if you use it as a spambot, filling threads with things you don't bother to read and adjust to what you want to say. For similar reasons, if someone uses LLMs to generate code and makes sure that code works through thorough testing, fine with me. It's when they have the LLM spit out something then toss it at me for me to fix that I get angry.

Bankrupt scooter startup left one private key to rule them all

doublelayer Silver badge

Re: Never buy a device that doesn't work if the internet is down or the server is not responding.

True, manufacturers generally don't advertise that, but that doesn't mean it's hopeless. If you think that it might, for example because there's an app, you can ask them. If they lie, you can use that from anything from a return outside normal windows to a legal complaint. It's also something you can check after having bought something to know whether that can affect you later.

In a perfect world, there would be a requirement to disclose this. Since we don't have that yet, it is still something you can do before you feel the consequences.

Venezuela loses president, but gains empty Starlink internet offer

doublelayer Silver badge

Re: "under whatever administration emerges in Venezuela"

Many of the refineries in the southern US were built specifically to process Venezuelan petroleum and are optimized for that. A lot of them switched to processing Albertan petroleum which has similar characteristics when Venezuela and the US fell out and stopped the integrated production system that had previously existed. Multiple pipelines, notably the Keystone and controversial Keystone XL (not built) pipelines, were built or proposed specifically to link Canadian oil to those refineries because it was more efficient to build pipelines going most of the way across North America than to build refineries in or closer to Alberta.

doublelayer Silver badge

Yes, you continue to redirect to a point that nobody made. Nobody other than you has argued that the service might be a bad thing in itself, and you're not arguing that either, so it looks like that's a pointless question.

The part where you and the article author disagree is whether people will actually get those credits or whether Spacex is exaggerating or even lying about them. We don't know, because as you've agreed in this and other posts, it's not licensed for use in Venezuela, so anyone who is eligible to receive the credits is using the service against Venezuelan law and in violation of the Starlink agreement, with at least some users using it with an address outside Venezuela which would make them ineligible. So does anyone get the credits after all? It's not the most important question because it's trying to tell how honest a sales claim without sales is, except you keep jumping to defend it. This question can extend to various others, such as whether it's a good or bad thing that Starlink, with its benefits to its users, is ignoring many national regulators, some but not necessarily all of which are dictatorships. We could have that discussion and I'm sure you have an opinion, but it still wouldn't be a thing the article talked about since they focused on unclear and likely misleading sales claims.

doublelayer Silver badge

Re: Ground Stations?

I already described the inter-satellite option in my post, and I described why that isn't enough, because if a lot of Venezuelans signed up for this, they would saturate those links. The question is whether there are enough ground stations in Colombia that Venezuela's traffic can be handled without the need to install more which could take a while. A single user's speed test does not demonstrate that. I'm sure Starlink has plenty of analysis of this already and will deal with it if they ever properly expand into Venezuela.

doublelayer Silver badge

True, but unless they get a move on, that won't make the free credits available to anyone because those expire in less than a month. If Starlink gets fully licensed to operate on February 4th, then nobody gets to have those credits. I don't think Starlink is the primary goal of any of the people who are or claim to be in control of Venezuela, and licensing, even abnormally, takes a while.

Dutch cops cuff alleged AVCheck malware kingpin in Amsterdam

doublelayer Silver badge

Probably with sandboxed AVs, either running on offline (except for sending results to the service) and cleared so they couldn't report samples back or with connections to detect and block those reports. Some of it would be easy, but presumably the customers would buy the service for the ability to test against the AVs that are hard to circumvent.

Stop dragging feet on AI nudification ban, UK government told

doublelayer Silver badge

Re: Knickers in a twist?

I think that post was intended as an insult on their appearance. If so, it says a lot more about Long John Silver's personality than anything else.

Tories vow to boot under-16s off social media and ban phones in schools

doublelayer Silver badge

Re: Wealth vs income

"While he might know what I am saying his perspective is different which leads to discussion."

Except your discussion is being padded by arguments over what wealth means which slows it down to a crawl. You're not arguing most of this by saying that that doesn't technically count as wealth, nor by trying to sort everyone into "not privileged" and "privileged" buckets when the part they're talking about is a sliding scale and even a quantifiable one. You know that someone with wealthy parents who provide lots of things to their children has more opportunities than someone who lacks those. So do they. If you actually intend to discuss that and whether or not it has the effects they claim it does and you've claimed it doesn't, then discuss that rather than arguing endlessly about what to call it first.

doublelayer Silver badge

Re: Wealth vs income

This argument is pointless. You both know what each other are saying. Wealth consists of more than just money, and even if we decide that the access to money and other resources via parents doesn't count under a strict definition of "wealth" and we want to use that strict definition, then we find some other word to express the major difference we all know is what we're talking about and continue the discussion with that. "Privilege" seems to be commonly used, so maybe that. If you don't like it, don't bother explaining why that's the wrong word, suggest a word you think is adequate to refer to the different resources people have as a result of the circumstances of their birth and upbringing and chances are it will be suitable for the rest of the conversation.

What if Linux ran Windows… and meant it? Meet Loss32

doublelayer Silver badge

You're still making up more and more tortured arguments for why your dictionary game move was correct, which it still isn't. Compensation can and does mean payment in exchange for something, harm or not.

Similarly, you've made up on no evidence at all the claim that proprietary software consists primarily of others' code, which we both know applies to some things and very much doesn't apply to others. Surprisingly enough, the less work someone has put into their proprietary software, the less interested I am in buying it.

doublelayer Silver badge

Compensation doesn't mean what you think it means. It can mean payment for a harm, but it can also mean payment for a service. I used it in the second sense. Read as many dictionaries as you like until you recognize this is a legitimate use, because playing the dictionary game has never and will never work for your arguments. People understood me, and even if I had to change the word until you couldn't make your spurious argument, the statement would be the same and, if you wanted to argue against it, you would have to on its meaning rather than its phrasing.

doublelayer Silver badge

I assume "Linux" in your first line is a typo for "Netflix"? I don't think I agree with you. A lot of people rented video content before streaming took off and for the same reason that they use streaming now. You can buy DVDs for many shows but at a higher price than it costs to rent access to them. For something you like so much that you're planning to watch it over and over, that can make sense. A lot of entertainment that I or people I know watch is not in that camp. It would be a lot more expensive to buy permanent copies for everything someone views once than to rent access while watching then stop. I'm sure there are people who want to buy DVDs for something and aren't allowed to, but I don't think that's the limiting factor because a lot of the content that streamers have is easily available on DVD and people still subscribe to watch it.

doublelayer Silver badge

"You're confused that people are rewarded for their work? The people who pay for the full version are subsidizing your free version."

You have misunderstood. The decision was between a commercial piece of software which definitely has a feature or an open source and thus free* alternative that might, but it takes experimentation to find out what features it has and whether they work. I do start with the open option because it's free to check whether it can do what I want, though I'm fine going to a commercial option if it turns out the answer is no. If the open option does work and I use it a lot, I may donate to its authors because I believe writers of software, whether proprietary or open source, do deserve compensation for the value they create. The decision is almost never between two options created by the same people.

What I find confusing is people who hear that there is software that is probably able to do what they want and comes without the need for payment, data collection, etc, but nonetheless choose not to try it to see if it can work. For example, I've known people who were annoyed that the version of Microsoft Office they bought is no longer working and ask me to help find them a cheap replacement license. I suggest LibreOffice might be worth a try. If they tried it and it didn't do something they want or they found it hard to learn, fair enough, but when they don't bother and tell me to buy Microsoft Office, I don't understand why they couldn't give it a go. I still find them what they asked for, though.

* Theoretically there can be open source software that requests payment, but because of the license conditions, they can't stop people from removing that part so it's rare and easily ignored.

doublelayer Silver badge

You are entirely correct about the answer to that question, but that's not the set of options users generally get. Here are more likely questions, each of which users face individually for different programs or services:

1. Would you like to pay $x for a permanent license to this program or $x/4 per year? Users decide based on an assumption of how long they'll need this thing.

2. Would you like to pay $x/year for this software or nothing for a version that doesn't have all of the features but maybe it has enough to do what you want? The user decides based on their willingness to experiment rather than to buy the thing they know will work. As someone who always starts with the open option because it's free to see how well it works, I find those who choose the other option a little confusing, but I've seen plenty of them.

3. Would you like to pay $x/year for a service or set up your own server and configure and host it with some required system and network admin? The user chooses based on their knowledge of or willingness to learn terms like "firewall rules", "NAT circumvention", "log-based banning of malicious attempts", "sizing your VM for performance requirements", and things we underestimate the complexity of because they're the bread and butter of our jobs.

Brussels plots open source push to pry Europe off Big Tech

doublelayer Silver badge

Maybe that will be enough, though I doubt it. To answer your "what more should we be looking for" question, though, you should be looking at the problems the funds are being allocated to solve. Let's stick with the Threema example. The two areas that have gotten the most discussion are independence of government tech and industrial policy. What can Threema do to make itself useful in one or both of those areas and thus earn funding?

There's an answer I can see, but it doesn't work out very well for Threema as it stands right now. Right now, governments need messaging software for internal communications, and most of them are using Microsoft Teams, Google Meet, or Zoom just like most businesses. If they want to be independent, they'll want a replacement. The replacement would be in an excellent position to receive funding, but it's unlikely that the EU would fund all the open source message services instead of the one they picked and thus rely on the most. Threema, being mobile-only, is in a worse position than, for example, Jitsi. Ah, but Jitsi's largest contributor is US-based, so they're not in the EU. Not only would that not matter if the funds went to an EU contributor who could use the existing code, but that argument works against Threema which is also mostly maintained by a non-EU (Swiss) company. If they were set on the EU thing, that might give the cash to Nextcloud Talk, whose primary developers are in Germany. Any of those could be used for independence of communication software.

Any project hoping for funding is going to have to navigate stuff like this. Being open source and having a maintainer in Europe really won't be enough; it's not an infinite pot, nor is it intended for generally useful open source stuff.

doublelayer Silver badge

Under previous initiatives they're doing some things, but this article is about a new project, so it should come as no surprise that they're not supporting anyone with it yet since it doesn't yet exist.

Unfortunately for any project that could receive funding, they're going to have to be selected. That means that, even if I can find nothing bad to say about them, that won't be enough. They will need a compelling case to prove why they deserve to be in the small subset, and it is not my job to provide that case for them nor to find reasons to deny them. I know little about the service either to support or oppose it. If the list of arguments in its favor starts and ends with "it's under an open source license", that's not going to be a big enough list. Fortunately for supporters of any project, they can try adding to that list.

doublelayer Silver badge

Because, and this goes for every "they should fund [project]" suggestion, they're going to have limited funds and need to decide whether each possible service deserves them. Why is Threema a project of enough significance to be one of the few that gets funding? What service does it provide that would be instrumental to the governmental or industrial independence the EU is aiming for? If there is one, why is that the project that best provides it?

There are lots of open source projects. Even if we decide that anyone receiving money must be in the EU (not so good news for Threema given the Switzerland aspect), there are still too many to fund them all. If they're going for specific goals, limiting themselves to ones that have no non-EU organizations would be limiting because it would mean they are limiting themselves to a subset of open source software when the open source part means they could use the rest without the risks they're trying to avoid. You therefore need to make a better case for the inclusion of any specific project.

doublelayer Silver badge

Re: Why don't they...

Because they are trying to fix government's infrastructure, not every citizen's. Their initiative is around the availability of software they rely on to provide services that run for a lot of people and thus is not easy to replace at all and tends to take a long time when they want to. To make their problem harder, they're also trying to support the development of commercially viable open things which can be used in industrial areas as well, a similarly difficult enterprise without as much motivation as the governments currently have. Their goals are already ambitious.

That's hard enough without the expense of setting up shops few people would voluntarily go to. People can already install Linux themselves, and we could make it easier by producing documentation though the recent attempts have been widely criticized for not being much more user-friendly than existing docs. If getting people to know about the option is the tricky part, then an advertising campaign might be more effective or at least cheap enough that it's practical. And if helping unfamiliar users is useful, I know multiple Linux-focused groups who held Linux installation events to celebrate the end of Windows 10's normal support, but those I knew better, including the one I attended, didn't get too many interested users.

doublelayer Silver badge

Re: Paying for development

That is not a loophole nor is it hard to avoid paying a US company when you use the software. People who rent hardware can still rent hardware when running open source software and can design a managed service around open source software. To remove that right requires eliminating some of the rights that you get with open source. However, to run it without AWS in the middle requires one of two fiendishly difficult options:

1. Use a server you bought.

2. Rent it from someone who isn't AWS.

This is not what the EU has any trouble with. They have trouble with systems that don't exist in an open source manner or to which proprietary systems compare favorably. That's why they would want to get more software written which reduces the advantage that cloud providers or other companies they don't want to rely on have.

A wrapper around Elastic is not what gave AWS its market share, and reimplementing the features in that wrapper won't dethrone them. Incidentally, it's likely that whatever approach they use may use Amazon's OpenSearch fork instead of normal Elastic because that's the version you can deploy without getting Elastic's permission now they've abandoned their previous license.

Putinswap: France trades alleged ransomware crook for conflict researcher

doublelayer Silver badge

Is that so? Tell me, what "Russian resources" are the US and UK and France after right now? For that matter, which were they trying to get from 1950 to 1990? Your characterization is inaccurate in many ways, and not just the categorization of Russia as the victim in phrases such as "conflict for Russian resources". The object of the conflict was also quite different from what you're describing from both sides, because as George Orwell expressed, each of the largest powers was large enough on its own and certainly large enough including its sphere of influence to get the resources it wanted without needing to go elsewhere for a source. Many of the most active incidents between Russia and the United States have had nothing to do with resources but a lot more to do with countering one another or entrenching their previous positions of power.

Boffins probe commercial AI models, find an entire Harry Potter book

doublelayer Silver badge

Re: Can it improve the Harry Potter books?

I was not one of them, but I can see lots of possible reasons that probably account for it:

1. Misunderstanding of LLMs: "the language of the text was unimaginative and stereotypical -- the kind of language you expect from LLM homogenization. So no surprise that AI models can reproduce the text." That has nothing to do with why the LLMs can print it. They print it because the exact text was fed in and likely lots of times. They can also repeat famous books that are better written, whereas they cannot exactly print formulaic crap which was not provided to them so much or at all.

2. Perhaps some people read you as supportive of LLMs: "If the reproduction is only 95% copied, is that 5% better?" I assume you know that the 5% not copied directly is basically random mutation and the chances of this being an improvement are quite low, but if you didn't or people assume you didn't, they might see this as suggesting an LLM has capabilities it doesn't.

3. Maybe some people just disagree with your criticism of Harry Potter's writing. You weren't very specific, so I have no idea whether I would agree or not, and while it's likely we'd probably agree about the relative quality of some parts, we might disagree about how important it is because there are some types of writing I see as big crimes and some as completely normal, both of which are entirely subjective.

doublelayer Silver badge
doublelayer Silver badge

Re: Can it improve the Harry Potter books?

That would depend on your personal opinion of better. My guess is no, but there's no way for me to predict your taste nor to know what faults from the book you would like a rewrite to improve, likely a different set than if I made a list. If you're hoping that it can do that, you're more likely to get what you want if you prompt it to do a rewrite rather than hoping that faults in memorization that it's not supposed to be doing in the first place spontaneously improve the text. I don't think either approach will get you good results, but the former is slightly more likely than the latter to do so.

doublelayer Silver badge

Re: Hang on a minute…

Because they're trying the argument that it's only a crime if they print the copyrighted content, not when they used it without permission and on illegal copies. That's not how the law worked. It's not how the law works if you or I do it. So far, that is what courts and politicians have decided to let them do across multiple countries, so their spurious logic seems to be working for them so far.

Grok told to cover up as UK weighs action over AI 'undressing'

doublelayer Silver badge

Re: Grok complied

Is this a complaint about what words we use to describe actions software performs? Describing this as "complying" isn't really that unusual. LLMs can reject commands but are not great at filtering, and when their creators put less effort into trying, the attempts to avoid bad uses are even less effective than they generally are.

Help desk read irrelevant script, so techies found and fixed their own problem

doublelayer Silver badge

Re: Help Desks shouldn’t be necessary

That's fair enough for those support calls because the software has bugs and messed something up, but a lot of support calls aren't that in the first place. If people don't know how to use the software, that's at most a UI or training gap, neither of which is generally considered to be a QA problem unless they're very severe, and in many cases it's not even that. Another class is for people who have unusual requirements who have purchased ongoing access to people who can help solve their problems more quickly than building it all themselves, which is also not a thing related to software quality and is a perfectly normal support service to offer.

The Microsoft 365 Copilot app rebrand was bad, but there are far worse offenders

doublelayer Silver badge

No, partially because I don't find most LLM stuff very useful, but I think part of the problem is that I don't have a clue what the different products can do. I have had access to Office with Copilot and the generic Windows Copilot, but I don't know what things those particular Copilots can do compared to anything else, so that makes it rather hard for anyone in that position to know whether to use them.

UK regulators swarm X after Grok generated nudes from photos

doublelayer Silver badge

Re: Why Do People Still Use X - Twitter ???

RSS is the easy part: distribution. What I am suggesting is a design that makes it easier for a smaller team to post small messages without the assistance of web design, a problem I've seen people who didn't plan out their website run into. One reason why some places embraced social media was that it was easier to quickly announce something and get it posted than it was with a website not designed for such a thing because, when they were publishing a press release every month or so, they could afford to use a more complex process than when they're posting tiny updates every day or two. And as I said originally, that's not too hard either and should be done.

doublelayer Silver badge

Re: Why Do People Still Use X - Twitter ???

Government departments need a way to make public announcements rather than waiting for people to email them. My solution to that problem would be a widget on their website which can be updated more easily than larger changes, and that's a mostly realistic one, but it still needs to be implemented. Still, that should be a relatively cheap solution to the Twitter problem.

But politicians are different. You can have the opinion that they shouldn't use Twitter or any social media all you like, but they're not going to listen and from their perspective they shouldn't. Politicians want to be elected. Those with a public profile have that because they think enough voters want it, and they're probably right that there are more people who will follow them on social media than those like us who don't have an account at all. Like it or not, politicians can and will make personal decisions motivated by their own goals.

doublelayer Silver badge

Re: Why Do People Still Use X - Twitter ???

In the case of politicians or organizations, it's probably inertia and the network effect. Those aren't necessarily good reasons, but they make sense. Bluesky has 47M global users if you trust this counter, which is not a very high number if you're focused on a specific region. People are slow to change in any case.

Stalkerware slinger pleads guilty for selling snooper software to suspicious spouses

doublelayer Silver badge

Re: He should have joined Google or MS or Apple

"why is Google allowed to sell across state lines and not be prosecuted for mass snooping?"

Because they'll claim that you agreed to it in the terms which you had little choice about, whereas this software was installed without the permission of the owner or user of the device concerned. You would need stronger privacy legislation to deal with the former, the US doesn't have it, and those places that do have it tend to ignore their ability to enforce this stuff, matched by a little more attention to detail from the companies so it's less obvious that they're breaking those laws.

IBM's AI agent Bob easily duped to run malware, researchers show

doublelayer Silver badge

Re: If only there was a way to run a separate process...

"Just "review a site" is what I was responding to."

I admit that phrasing is ambiguous. The program is intended to take actions, not just review a site. Something intended to produce summaries wouldn't be told to find the installation code and execute it, but this is supposed to be an assistant and therefore was given more power which it can't safely use.

"Executing the output from the echo is level 2. The user has not been asked to clear that."

Of course. That's the vulnerability. And it's a bad one because the LLM only looks at the first word in the command, sees it's "echo", and decides that's fine. If it was calling exec to spawn processes, then it would only be an echo, but it's pasting strings into a terminal which means what it incorrectly identified as an echo is a chain of commands and it only checked the first one. That can be fixed by checking for redirection, splitting each of those in code, and running each by the checker. Above this vulnerability there are probably more because it is using an LLM or some manual parsing to decide whether any given string is safe and matches something the user agreed to which means there are lots of chances to pass the test with malicious commands. Detecting malicious strings from normal ones is hard enough without the randomness of an LLM trying to help.

There's undesirable behavior all over this because an LLM is being used for something it is incapable of. The problem is less to do with the LLM's inability to tell instructions from data, though that never helps, and more to do with the fact that they deliberately connected an LLM and a terminal (which can do this with just those two, and then added in the open internet just to add that extra spice of danger.

doublelayer Silver badge

Re: If only there was a way to run a separate process...

This is not buffer escape or unwitting execution. It's not even poisoning instructions, which is kind of like what you're describing*. It's programmatic copying and pasting text. The bot's being told to read documentation and glean instructions from it, then execute those if they're safe. No level of separation is going to prevent it from executing stuff in that. That makes it inherently dangerous and, since the checks intending to find malicious instructions and not run them are also LLM commands, dangerous in a way that's not easy to fix. The user is intentionally allowing a program to fetch and run things from untrusted locations and it goes about as well as you'd think it would.

* Poisoning instructions is when a user executes a prompt in an LLM like "Summarize this text", and the text contains other instructions which the LLM ends up executing. That can be argued as an example of what you're describing, although since the LLM has no concept of separate instructions and data, that's also difficult to prevent. That's not happening in this case because the only instructions the LLM is executing are those it was given. It just happens that the instructions it was given are foolhardy and the protections designed to block the biggest disasters aren't big enough (and likely can never be).

Gmail preparing to drop POP3 mail fetching

doublelayer Silver badge

Re: Thunderbird for the win

Are any of those things deleting your mail on their own just because? Because the only thing I've seen do that is mail set to automatically delete old mail after X days, and the way to fix the server is to go to the settings in the UI and turn it off. Other servers just don't bother. If you're dealing with a provider that turned on and now won't let you disable that feature, maybe switch to any of the ones you named or any self-hosted version, no code changes required, which won't.

doublelayer Silver badge

Re: Thunderbird for the win

"How many people realise all their private stuff is on "Someone else's Server"?"

I hope it's anyone who is choosing to use POP3, because all your private stuff is still on someone else's server. That's how email servers work unless you run them yourself. If you don't trust the someone else, you should be careful what you do with their server whether you use IMAP or POP3 to talk to it. Both protocols can be used to permanently erase mail from the server, but it was there in the first place, so if some server was being untrustworthy and keeping copies, they could do that as easily no matter which protocol was used.

doublelayer Silver badge

Re: Thunderbird for the win

I suppose if that's what you want, then that's the protocol for you. I don't understand why you want that and I know most others don't want that, which is why IMAP is the default for almost everybody. I was glad to leave POP3 behind decades ago because it would do the things you are describing. I had to either handle every email on the device that first saw it or delete every email from multiple computers because they couldn't sync the fact that I don't want to see this message anymore. Because I leave deleted mail in a folder, using IMAP also meant I did have a full archive of old mail rather than each machine's individual subsets of deleted mail.

With IMAP, there is a local file storing the state of your mail folders, but it will, unless you configure otherwise, update itself from the server's state. If your server is deleting things without your permission, it seems like fixing the server so it doesn't do that is the more effective strategy.