The general response available is going after whatever mechanism is used to make money. I do not use 4chan, so I don't know how it works, but simple searches suggest they have ads. If they run advertisements in the UK, paid for by UK advertisers, that is money that can be taken by UK authorities before it can be transferred away. As long as they either are or are willing to operate without any revenue from UK users, they can mostly ignore complaints and let the UK handle it.
Posts by doublelayer
11420 publicly visible posts • joined 22 Feb 2018
Page:
- ← Prev
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- 36
- 37
- 38
- 39
- 40
- 41
- 42
- 43
- 44
- 45
- 46
- 47
- 48
- 49
- 50
- 51
- 52
- 53
- 54
- 55
- 56
- 57
- 58
- 59
- 60
- 61
- 62
- 63
- 64
- 65
- 66
- 67
- 68
- 69
- 70
- 71
- 72
- 73
- 74
- 75
- 76
- 77
- 78
- 79
- 80
- 81
- 82
- 83
- 84
- 85
- 86
- 87
- 88
- 89
- 90
- 91
- 92
- 93
- 94
- 95
- 96
- 97
- 98
- 99
- 100
- 101
- 102
- 103
- 104
- 105
- 106
- 107
- 108
- 109
- 110
- 111
- 112
- 113
- 114
- 115
- 116
- 117
- 118
- 119
- 120
- 121
- 122
- 123
- 124
- 125
- 126
- 127
- 128
- 129
- 130
- 131
- 132
- 133
- 134
- 135
- 136
- 137
- 138
- 139
- 140
- 141
- 142
- 143
- 144
- 145
- 146
- 147
- 148
- 149
- 150
- 151
- 152
- 153
- 154
- 155
- 156
- 157
- 158
- 159
- 160
- 161
- 162
- 163
- 164
- 165
- 166
- 167
- 168
- 169
- 170
- 171
- 172
- 173
- 174
- 175
- 176
- 177
- 178
- 179
- 180
- 181
- 182
- 183
- 184
- 185
- 186
- 187
- 188
- 189
- 190
- 191
- 192
- 193
- 194
- 195
- 196
- 197
- 198
- 199
- 200
- 201
- 202
- 203
- 204
- 205
- 206
- 207
- 208
- 209
- 210
- 211
- 212
- 213
- 214
- 215
- 216
- 217
- 218
- 219
- 220
- 221
- 222
- 223
- 224
- 225
- 226
- 227
- 228
- 229
- Next →
Ofcom fines 4chan £20K and counting for pretending UK's Online Safety Act doesn't exist
Techies tossed appliance that had no power cord, but turned out to power their company
I'm still not entirely certain what that actually means, because my first reading, admittedly one I'm not very certain of, was that this was a new policy after the failure rather than the status quo beforehand. If that was the rule all the way through, that just brings up more questions, questions like why did they have access if they were explicitly not allowed to go there, who was informed or approved the cost-saving plan, and all sorts of other things the article doesn't say. Sure, if we assume that the answer was they were explicitly forbidden from entering it, nobody asked for permission, they cheerfully ignored the rule, then yes, the firing decision was completely right, but that's assuming an unlikely set of circumstances based on no evidence at all, the same way that it would be justified to fire them if they entered the datacenter by breaking the window but we have no reason to think they did.
If, for example, the rule that you're not allowed to go in there was not stated beforehand but someone hastily added it later, then I do not think it is justified to fire someone for breaking it. If this plan had been run by others who had approved, it wouldn't be justified. I don't know whether any of those happened, but neither do you have proof of any of the conditions that justify your opinion.
Re: Data Center Access
Why do you assume any of the following:
1. that this facility was anything like those. There are lots of colos that don't have critical infrastructure security levels where the client provides people with credentials to access their area. There's still security, but generally not make an appointment weeks in advance level.
2. that the people entering didn't have the required credentials. They hosted servers there, these people can recognize and probably installed them, this sounds like the kind of people who would have access.
3. that they didn't follow the procedures. Even if assumption 1 is correct and thus that they couldn't have had general access credentials, they clearly planned to visit and decommission. They would have had the time to make that appointment. If they were not allowed to do that, it's equally if not more likely that the person who has to answer for it is the one who signed off their appointment or the one who didn't need to but should have been gating that access. Assuming, of course, that there was any policy requiring that be gated.
I assume you've got a set of assumptions about the circumstances here. We all must to some extent because the only facts are those in the article, and theoretically any of those could be lies too. However, the defenses and attacks I'm seeing are fundamentally differences in accepted facts like did anyone above the boss authorize this decommissioning operation? I've seen comments deciding that's a clear yes and a clear no, and my own defense is a more moderate I don't know on the boss, but the employee covered in the article had sufficient reason to believe that it was because his boss said so and would be the path by which the information would be delivered.
When you confidently assert what you would have done, consider whether your answer would be different if the unstated circumstances were the opposite of what you're assuming. If you would fire both of them no matter whether there was authorization from above, whether anything was documented, whether there was system monitoring, whether there was a logical purpose for that equipment, fair enough. I would not agree, because people decommissioning equipment with permission and on orders removing something that shouldn't have been there is enough for me to take their side if that's how the facts ended up. If you're making that decision based on guesses, you should at least tell us what guesses you're basing it on.
"He went on an unauthorized, and not known about visit to the data center that wasn't in any way time critical."
Unauthorized by whom? Because it was authorized by his boss who is the person who generally communicates authorization for projects assigned to someone, and you have absolutely no information suggesting that the boss didn't receive authorization and a command to do this.
And not time sensitive? It sounds like it could be. Depending on the colo contract, a lot of them sell space in long-term contracts, meaning that if that was coming up for renewal, the situation is to reduce space now or pay for it for some large amount of time to come. That's the definition of time sensitive.
Microsoft warns of 'payroll pirate' crew looting US university salaries
Re: Exploiting adversary-in-the-middle (AITM) technique
They do which is why, before messing with the MFA, the attackers were gaining control over the email. That way, they can delete the message so the user never sees it. They'll be deleting other messages warning the user about new payment accounts and allocations too. Some may also use that control to send things from that email if that helps in their scam.
Re: I think I see the problem
I think you have a faulty macro that's been littering [MICROSOFT] through your messages. If all of those were intentional, can you tell me how HR emails or the act of hiding or deleting those is a Microsoft thing? Do they have a patent on email filters, because if so I'm worried about the legal notifications about the ones I'm running in Thunderbird (personal) and GSuite (work). So far, my company's HR department hasn't outsourced to Microsoft. How much do you think they charge?
You've also guessed Microsoft Authenticator even though the only actual MFA provider named in the article is non-Microsoft Duo and assumed Microsoft is providing the SSO when it might or might not be, especially as Microsoft SSO is not so common when some parts of the network might be using non-Microsoft operating systems. But hey, one out of four with Exchange.
RondoDox botnet fires 'exploit shotgun' at nearly every router and internet-connected home device
Re: Is there a 'generic thing' that can mitigate most of it?
UPNP is probably a lot of it because people don't know to turn it off and some things people buy won't work without either having it enabled or knowing how to administer a network. Take those IP cameras people were complaining about earlier. With such a thing, there are three general options. Here they are, along with the experience of the nontechnical person wanting to view the outside of their house when they are not in the house:
1. The IP camera that sends a data stream to a device of your choosing. The user doesn't know how to set up the server to send the images, so they can't see anything unless they're on their local network.
2. The IP camera with a basic UPNP and DDNS component built in. The camera gets installed, you add the address to your phone, and you can see the camera from wherever you are as long as the network's up.
3. The camera that connects to a remote service like the seven different lines Amazon's got. You can access your footage but only through the app you're already signed into. Also they have access to everything and misuse it in many ways.
For us, the ideal option if we're going to have such a thing is 1, and we can figure out how to either direct the traffic to a server of our choice or VPN into our home network to see it. The average buyer can't use that one so ends up with one of the others. Manufacturers that don't want to maintain a mobile app and cloud system won't build with number 3, and since most customers won't use things with option 1, they mostly land with option 2. Then they stop development as soon as the products are on sale and they become targets for botnets.
Hundreds of millions of business PCs are still on Windows 10 as D-Day nears
Scale can determine how much you care, but it isn't currently and, in my opinion, probably shouldn't be relevant to what the law is. We can't decide that there's a regulation that stops this because the problem's big; there still isn't. That could be a good reason for some politicians to make a law when they didn't care before, but the first step would be to try to make them care.
If you do, I think it's important to decide what you think that law needs to be. You need to define how the responsibility works, how long updates need to be for, how you would restrict them, etc. For example, I think that smartphones and computers both last a long time, so I'm still more annoyed at Android's short lifetimes than I am with Windows's which are at least twice as long and often more, although I'm quite annoyed with both. Both have similar scales, with hundreds of millions of Android phones losing security updates each year. Yet we don't see complaints about those, probably because that's always happened whereas Windows is getting this all at once. If we're passing a law, we need to decide whether those two get the same regulation or if they should be treated differently, and if it's the latter we need to define what makes the difference. These details are important if you don't want a gap in the law making it possible for this to happen again. If you are mandating updates, you have to decide the conditions when it is justifiable for updates to end. That is why I brought up the technical perspective because, when I decide about the updates for stuff I build, my reason for cutting them off is nearly always technical and that is the most justifiable reason in my mind.
A lot of your reasoning boils down to you considering this problem a really big one, so the rules should be different. I agree with you that this is a really big change, but the regulations don't change with the size of things going down because, as I said in another comment, there's no regulation about this in the first place, the closest you can get is consumer protection, and consumer protection doesn't cover this anyway because it has been too long since Windows 10 was released to be covered under most of it.
Let's also consider what that regulation can be. If you concede or even just ignore for a bit that regulators can't regulate without a law giving them the power and the reasoning, what would we want that new law to say so they can do it? It will probably be too late for Windows 10, but we can write it for the next time. My problem is that I can think of a lot of laws that cover something like this but Windows wouldn't be included. For example, one of the things I think we can argue against is the nontechnical obsolescence of technical things. For example, when Apple cuts off a Mac model because that's the end, I don't consider that legitimate if they've got another model with the same or worse hardware which gets to update. We could make that illegal. That would not affect Windows 10 because those restrictions are technical ones. I don't think they are good ones, but they are quite normal technical requirements. If you write code which only works with a TPM 2.0 chip, it is reasonable to require that you have one to run it. To cover this, we would have to do something a lot blunter like simply announcing that an operating system must have support for twenty years, no exceptions, which while possible as a law, has a lot of downsides that a more nuanced one would not.
In order for regulators to act, there would need to be regulation. There isn't. That is why Android devices have always expired earlier than that, why Chrome OS death dates were shorter than that until Google's latest change made them about equal, why Macs get seven years before the Mac OS updates stop. Microsoft has, before this, been an outlier for long update lifetimes. Perhaps because of this, the people who would have to make the regulations haven't done it, and without them, regulators can't do anything about it.
BOFH: Recover a database from five years ago? It's as easy as flicking a switch
Re: Or just use the backup data?
This sounds more like tax evasion, illegal production of fraudulent data sent for tax assessment, than tax avoidance, legal choices designed to get the best outcome from the tax laws. I can't tell how they were using those figures, but if they were changing things retroactively, it probably wasn't a good sign.
I'm not sure the tax level has much to do with it. There will always be people who don't want to pay any taxes and are willing to break the law to pay less, so tax evasion will never disappear. Tax law is often written specifically to give people incentives for taking some actions or penalize them for others, so tax avoidance is exactly how they're structuring it. As long as tax law is so complex, there will be gaps that people use to legally save even though that wasn't the original goal. Theoretically, if taxation was reduced so much that nobody was paying almost anything, then the reward for avoiding what was left might be so small that nobody bothered to do it, but you would probably have to decrease taxation to near zero to accomplish that.
Re: Or just use the backup data?
"I would have thought the UK would have something along the lines of AU's general anti·avoidance provision which would presumably render the distinction academic."
Australia's regulation applies to corporations more than individuals, whereas the article's comment suggests that it was individuals who were still in control who did things for their own personal taxes. Most countries don't have something like Australia's provision because Australia is going for the very vague approach of trying to guess whether you might have done something to pay less taxes and saying that's not acceptable which makes it very hard to do anything at all with attention to taxes without possibly coming under that. That might eventually cause Australia some grief in the courts because judges often take a dim view of a citizen being punished for complying with the letter of the law because of a vague spirit-based provision, but that's yet to be determined. A lot of anti-avoidance steps in other countries have taken the harder to make but easier to enforce steps of finding things people used to do as avoidance and deciding that they're no longer allowed and will count as evasion henceforth.
Humans flunk the Turing test for voices as bots get chattier
Re: Turing test this is not
When, in either of my comments, did I say anything at all about an educated person? The only words at all related were in my first comment and read "instead of intelligence". You may recognize that "instead" as indicating that this test is not about intelligence. Being able to synthesize a human voice means nothing related to education or intelligence, and the programs that can do it are neither educated or intelligent; they're making a sound file following mathematical rules.
The utility of the test has nothing to do with machine intelligence. It has to do with human capacity to determine the difference between a computer-generated and human voice. We care, not because a computer is going to use that capability for its own goals. If it does, that will be a different program that doesn't currently exist. The risk is that a human will use these for malicious goals, which is why it can be helpful to know how good their tools are. I do not know why you decided I was talking about comparisons to educated people since my only two points were a) there are a lot of similarities between this test and a Turing test in methodology and b) this kind of test is worth doing occasionally.
Re: Turing test this is not
By same purpose, I mean that it is also testing a computer program and a human at the same task with the purpose of determining whether a separate judge human can tell the difference between the two attempts and correctly match the attempter with its performance. That is, in fact, quite similar in operation and intent. To be the original Turing test, the task would have to be the same and it is not, but you're acting like it's a lot more different than it is. That is not a big class of tests, and whenever the question of "human or computer" comes up, Turing test is a frequent category to put it in. You may also conclude that captchas are unicorns as well, but that T is supposed to stand for "Turing test".
Re: Turing test this is not
True, this isn't the original Turing test, but it has the same purpose with a different category. It's still comparing a human and a computer with the intent of testing whether a human can tell the difference, but instead of intelligence, this is testing speech naturalness because that can be important too.
The price is wrong! California goes Bob Barker on algorithmic price rigging
Re: I think they'll have problems with this one.
The argument is that users of this software are effectively a cartel, but the reason they haven't been included under cartel legislation so far is that it makes a weird form of cartel because the participants aren't collaborating actively; the computer is collaborating for them without telling them the details. Cartel legislation usually requires that participants actively form one. That is why this law was written to explicitly add this rather than trying to make the case that it already counted.
AI has had zero effect on jobs so far, says Yale study
That is a very positive view of AI's capabilities and effects. I agree with a lot of your basis, but I don't think your conclusions are realistic because current AI does almost none of what you're giving it credit for and even idealized sci-fi AI wouldn't necessarily do what you're describing.
Lots of examples probably wouldn't be helpful here, so let's just take one, the one where the AI promotes people meritocratically because it's immune to social things. Yes, there are indeed managers who promote based on personal interaction which is faulty, but there are a lot of managers who promote using the same logic you're suggesting for the AI. Those are not good managers. One common type of promotion structure, experienced by a lot of people, is that you get promoted on good metrics. If your job happens to involve something with a convenient number and something that doesn't, you do the big number thing and neglect the other, because at the end of a period, the managers will look at the numbers and only make the decision on that. Maybe that means you focus on number of helpdesk requests completed or number of positive customer survey results or number of sales contracts signed this quarter or lines of code written. What is common across all of those is that they're not the most important part to the team or the business who would probably prefer harder to measure metrics like least user unhappiness with the IT setup or maximum customer happiness or number of sales likely soon even if they are a month out of this quarter or most progress on having the application complete. It means the most difficult stuff, which is often the most important stuff, gets deprioritized, whereas a good manager during promotion is one who recognizes how much effort has been put in and what the results of that effort have been whether or not it can be measured. Your AI system sounds like the metrics boss.
From their funding statement:
The Budget Lab is funded by Arnold Ventures, the California Community Foundation, Ford Foundation, Heising-Simons Foundation, NEO Philanthropy, Peter G. Peterson Foundation, and Yagan Family Foundation.
I'm sure those are OpenAI by the back door. Of course, given how excitedly OpenAI is announcing that it actually is replacing workers because they're hinging their dubiously likely success on convincing businesses that they can replace workers if you pay them enough, they would actually be more likely to want to promote a study saying that lots of people have been replaced. So maybe we should be investigating Stanford's financial backers instead.
Or, in reality, we should probably check the methodologies and data between these studies to figure out what their differences are, keeping in mind that neither of them will have the full picture since there is no central register of why jobs were terminated or, in fact, which jobs really were terminated. How many people got fired because AI could do it? How many got fired because the bosses think AI can do it, but it can't? How many got fired because someone needed to be, but the CEO figured saying that AI was being used would sound better in the report? Neither you nor I can know, and neither can Yale or Stanford, but I have a feeling they've both done a lot more than either of us to try to have some actual research behind their conclusions.
This is your brain on bots: AI interaction may hurt students more than it helps
Re: Peak enshittification
Probably the one from the article saying that 85% of teachers surveyed said they used AI. Although it didn't say what the teachers were doing with it, that's a lot of people and there are basically only two things that seem likely: making class materials or processing student responses. Processing doesn't necessarily mean doing all the grading with it, but it could still be dangerous as examples have demonstrated where teachers used an LLM to guess whether a student's essay was LLM-written, a method which definitely does not work. I think their view is hyperbolic and may be incorrect, but if a large set of teachers are using LLMs, I would want to know in detail what they were doing with them because there are a lot of bad options there.
Python releases version 3.14 – with cautious free-threaded support
Re: Must be specified with a command such as python3.14t...
I think the limiting factor is that you can't really know what's around. I could write a script in any language of my choosing that searches your machine for the dependencies I want, chooses between the available versions for the optimal set, and then runs with those, but if you put them in a weird place or just don't have them, that script is still going to fail. The solution you're describing sounds a lot like that script, but a more professional version that is better at guessing where different versions of things might be. If you haven't updated your Python version for a while and only have 3.7 but I need at least 3.10, the launcher won't fix it, but my program can by checking against sys.version_info at startup before it does anything too new as long as it's acceptable for the user to find or install the later version when they are told the script won't run.
For complex projects, this is mostly solved by either putting it in a package which has dependency requirements (the Linux approach mostly) or just packaging all my dependencies and bringing them along with me (the classic Windows and Mac OS approach and various packaged application formats for Linux that don't require as many different distro-specific packages). Neither approach is really that hard for a developer to do, but it takes some effort and a lot of small scripts don't get very much effort in the areas of documentation or packaging.
London cops unplug iPhone crime ring said to nick 40% of city's mobiles
Qualcomm solders Arduino to its edge AI ambitions, debuts Raspberry Pi rival
Re: Seriously?
Are you drawing a difference between the original board as built by Arduino and the relevant chips running the same software? I'm not sure there is such a difference since the code you're worried about will be present in either case. Either way, there are people building and selling products with both approaches. The same way that people build products with a full Raspberry Pi in them, some people decided to prototype using an Arduino board and build the production version by just doing that a lot more times, and people take code, including unreliable or bad code, and put it into products all the time.
Re: No doubt many Arduino enthusiasts will be alarmed
DS999 was not asking about the differences between this board specifically and a Raspberry Pi. The article makes it clear that these are more similar. They were asking about the previous ones because they were contrasted in the article. The comparison made by Zolco answered that question correctly; previous Arduinos were microcontroller-operated devices with either code on bare metal or small RTOS software, whereas the Raspberry Pi is a computer with an application-class ARM processor intended to run a full operating system, almost always Linux.
There are a lot of differences determining when you would prefer one over the other, with access to Linux tools and raw compute being an advantage of the Pi, power consumption and low overhead being advantages for the Arduino, and various others depending on what hardware you intend to drive from it. Qualcomm is now banking on people wanting both and their board providing both. We will see how it goes.
AI: The ultimate slacker's dream come true
Re: Empowerment
That would be nice, and I encourage people to try. There will inevitably be parts of education which can't be enjoyable because it's trying to teach a needed skill and some needed skills are unpleasant. There are also some students who aren't driven to learn things but want that credential, and no matter how enjoyable it is for someone who is motivated, any amount of work isn't going to attract them. I think a lot of educators are trying to make their courses more engaging and that this is a laudable attempt. Any teacher who decides that being interesting is beneath them is making a mistake. However, a teacher finding that they can't make the important content interesting to everybody should choose content over engagement and students who don't care to live with some boredom are going to have larger problems later on.
Re: Empowerment
One reason is that there's only so much you can fit into even a long in-room exam. If you're doing serious research, writing a substantial program, building and testing some equipment, or many other things, you can't manage it in three hours with a paper and something to write with. A lot of the skills that we are trying to teach are exactly that kind of thing. Coursework is intended to be more representative of how the skills they're trying to learn are going to be used which makes it less likely that someone will end up learning what is easily tested and nothing more. Unfortunately, it means that those who aren't trying to learn have more opportunities to cheat.
Techie found an error message so rude the CEO of IBM apologized for it
Re: Bah!
I think the implication is that the asterisks were in the original message, possibly to evade something scanning the code for certain words. I'm not sure when the first such tool was created, but I've seen a bunch of those things with their own lists of words you're not supposed to put in comments or messages at various companies, sometimes with prohibitions that don't make sense and nobody can give an explanation for.
Struggling to heat your home? How about 500 Raspberry Pi units?
Re: A hacker's dream
Not so useful, especially as the hacker would have no guarantee that the people buying compute from that box are doing anything they care about. Network traffic into the box can be encrypted using keys that get set before it is installed. To mess with the computers directly, they have to open up the box full of oil and start pulling modules off which sounds like a messy, easily botched, and relatively detectable action.
Re: Most stupid use of RPs from A to Z
The alternative is using a computer that consumes the same amount of power, thus producing the same amount of heat, but gets more computing done using it. That might make for a more expensive box, but depending on which version of the module they're using, they're already spending $22.5k-$65k on Pis alone (not sure how much of a bulk discount you can get on those). If the computer was faster, they could make more money selling its performance to people who want compute, whereas tasks are going to have to be tailored for Pi performance to work on this. You can get either much more single-threaded performance from X64 or much more parallel performance from GPUs.
The price difference might not be that high after all. That lower bound of $22.5k is for 500 base modules with 2 GB ram and no storage. No storage could probably work with images pulled from something else at boot time, but that RAM is probably going to limit the tasks. True, in total there's a terabyte of RAM in that box, but it's too split up for anything memory hungry to use it that way and it will be partially taken up with 500 separate running kernels. They've probably opted for more RAM in their modules, increasing the price.
AI chatbots that butter you up make you worse at conflict, study finds
Not really. Asking it might help occasionally, but it can be wrong twice and often is, and if it disagrees with itself then you're back to where you were before; you have no clear information and have to go back and learn what employment law actually is. Fortunately, there are a lot of sources to find this data if you're interested enough in the outcome of the case you're filing about your job to do that homework.
Especially when it gets it wrong and says you have rights that only apply in a different country because it is not capable of understanding such differences, you go and confidently assert your mistaken rights, and you lose your case when maybe, if you used actual law you read about yourself, you could have won it. But as long as you go into it with the assumption that you must have a case and the AI will tell you what it is, the AI will tell you that you're absolutely right about both things and that will, well, make you worse at one specific conflict you were resting a lot on.
Hacking contest kerfuffle over copied rules pits Wiz against ZDI
College student went on a destructive rampage, then confessed to ChatGPT, cops say
Re: How long?
This wasn't one of them. The AI didn't, nor is an AI company claiming, detect the crime and notify the police. The police identified this beforehand and found written text on a phone they were handed even though the criminal didn't have to*. The AI did nothing at all other than write about the consequences of vandalism, probably incorrectly given it's a local crime and there are lots of different jurisdictions who may have different sentencing requirements and sublevels.
* This being the US, the police don't have the legal right to compel access to the contents of a device. Had the student locked the device with a code and declined to provide the code, they could have prevented having that log in the evidence pile, at least unless the police went to OpenAI with a warrant which they probably wouldn't need to bother doing. In some other countries including the UK and Canada, the police can demand access and punish you if they don't get it. From their statements, they asked for access and were given it, meaning the student was adding one more to a pile of stupidities. It probably wouldn't have made much of a difference if they had given the student had already been located.
Windows 10 refuses to go gentle into that good night
Re: I wouldn't hold your breath...
What should they have learned? Because there was a major difference between those and the 10 to 11 switch. When XP and 7 ended support, you could update the machines to another version of Windows without replacing the hardware. If it was 7 to 10, they probably ran just as fast if not faster because some resource improvements were made during that period (I'm not sure where 8 fell in relation to those because I, like everyone else, took one look at the initial version of 8 and decided I could skip this one because 7 had many years of support left). If it was XP to 7, the machines probably felt slow if they were from the early 2000s, because modern computers were substantially faster, especially if you were waiting until the last moment of free support in 2014. If you thought they were good enough, you could still use them. That is no longer the case.
What businesses learned with the expiration of those updates is that Microsoft eventually stops supporting an operating system, but not that hardware is forcefully ejected.
Re: Did anyone else...
I didn't, but you can find a history of which updates were installed at which times. Given the general frequency they come through, if there was one big update, tracking it down is probably as simple as finding the only thing that installed on that day. You can then find details about what was in the update using its identification number.
Curl project, swamped with AI slop, finds not all AI is bad
My policy on LLMs which I can't make binding on anybody else is that I don't really care if you use them as long as your output is good enough. My experience with others' use is that a lot of people who use them don't care about this and send out the output with little or no review. My experience with my own use is that, except in very specific areas, they aren't helping me produce better output or similar-quality output faster, so I'm not a heavy user. Some things I can do easily and the LLMs require more work to clean up, some things are hard and the LLMs do incorrectly, and some things are things I can't verify because I don't have the experience and I don't trust the LLMs to do it without review. Only a few tasks are hard for me to do, quick enough for me to verify, and the LLMs can do them enough of the time to be worth bothering.
Tile trackers are a stalker's dream, say Georgia Tech researchers
Re: Tile
These things work in two directions: use your phone to find the tag, or use the tag to find your phone. I suppose the complainant was thinking about the latter option, even though the former is probably the more common. Evidently, neither is acceptable; we are simply never to lose anything which is a great plan if you can do it.
Taiwan gets chippy about US request it shifts manufacturing
Re: Pretend I am a Martian.
The philosophy isn't automatically wrong. It's perfectly logical for Apple, for instance, not to go into the semiconductor manufacturing business. Someone else can fab their designs and, since those people will be constantly innovating on improving their manufacturing techniques, Apple benefits along with any other customers from improvements there. While Apple has a lot of cash and could conceivably manage that in house, they don't need to.
On a national level, though, there's a lot more reason to consider certain industries valuable enough that they're encouraged, the way that Taiwan decided to do that with semiconductor manufacturing and most other countries didn't bother with, except the US starting two years ago, except when that got abruptly canceled by decree this year. A country can't do that with everything unless they have lots of money and are willing to spend it all and waste a good portion of it, but they can focus and specifically target some types of things to their benefit.
Re: Do you feel lucky?
Given the history of geopolitics, I think that, if China thinks the US will respond militarily, it will dissuade them from attempting that, based on the fact that it has done for several decades. I also think they probably don't think the US will respond militarily and they're probably right about that. A lot of things get started because country A thinks country C will not react if they do something to country B, whether or not that ends up being the case. That is why coherent and stable foreign policy tends to be beneficial; maybe you don't mean it this time, but if you mostly meant it the last times, people might believe you and act accordingly. I don't think many countries are bothering with that anymore, the US foremost among them.
Re: Pretend I am a Martian.
In principle, nothing. In practice, it's easier for TSMC to do it because they've spent a long time learning how. Apple designs chips but doesn't manufacture them, so they would make mistakes that TSMC made in 2002 and now designs around. That means a TSMC-run effort is going to have a quicker trip from the first brick to profitability. It's not just them, as other companies have some experience and could also manage it, but look mostly at those who already manufacture because they're going to have the easiest time avoiding mistakes. As Intel demonstrated, that's not a guarantee that they will succeed and failures can be very costly.
Microsoft moves to the uncanny valley with creepy Copilot avatars that stare at you and say your name
You're right, it won't, due to all the normal deliberate noise to make it not emit the same output to a certain prompt. What it also won't do is give you the actual weather unless it's integrated with an external source of data, and if it has, you could get the actual weather report by going there directly.
Judge dismisses Arm's last legal claim against Qualcomm in licensing spat
You say that as if any part of the chain could quickly replace ARM with RISC-V. They can't. Qualcomm can't make similarly fast chips with it; they would need to spend a lot of time designing them, which they don't have experience with. They couldn't just buy someone else who knows how to do that; the existing designers are good, but not that good. The people who buy ARM chips couldn't just pivot to RISC-V because the software they want to run on it doesn't support it. The people who write the software can't just recompile for that quickly. Any change of that nature would take a long time.
Which is why ARM thought they could get away with this. If people are really going to switch to RISC-V, then this is the peak of ARM's power because they can't switch for some time even if they tried their hardest. If people are not trying to switch, then ARM is even more powerful at the moment. This is still true now; if ARM canceled Qualcomm's license now, both would suffer, but Qualcomm would probably suffer more because somebody's got to sell CPUs for smartphones and they're still going to be ARM-based because the existing RISC-V chips are nowhere near fast enough and Android's ejected RISC-V from the main project until it settles down more, to say nothing of the many other ARM-only systems people spend lots of money building.
Oracle will have to borrow at least $25B a year to fund AI fantasy, says analyst
Re: does that mean
No, that's not what those numbers mean. If OpenAI tried to host that many GPUs in house, they would end up having to build all the same stuff that Oracle is going to build, and it would probably cost them more because they couldn't easily sell unused capacity to someone else.
Oracle has some money they can spend on building these, especially if you include payments that OpenAI is to give them during the project. That assumes, of course, that OpenAI is able to come up with those payments which they probably aren't, but that's a completely separate problem. That money is included, and since some of it is coming from OpenAI, OpenAI could not count it as savings.
Greg Kroah-Hartman explains the Cyber Resilience Act for open source developers
Re: Explain the Basis of Article-Claimed Non-EU Jurisdiction!
I have to guess at what you mean by that comment. Do you mean that people don't sell FOSS, therefore that the previous comment doesn't apply to it? Because it's really not that simple. Is there a donation button on the project site? Congratulations, that's monetization, even if nobody's ever donated. You're covered. Did you need to have some system to coordinate things between multiple contributors so you set up a project website, even if it's an informal group of people? For example, did you ever write something like "Copyright 2025 [project] Group" above your open source license? That's organization. You're covered.
As the article says, you're not covered if it's just you, developing something for no reward and putting it up somewhere. There are several projects that work like that, but so many more who have had even the smallest amount of either of the things that qualify for the CRA.
Re: Theory vs real world
Exactly. In practice, I have a feeling we'll be fine because open source authors won't be the primary targets, nor will anything be automatic enough to sweep them up. From the letter, the situation is not so rosy as described in the article. The Linux Foundation and Mozilla can easily comply; they've got hundreds or thousands of employees and millions in the bank. The same thing applies to any small project with a single maintainer or perhaps worse, two part-time maintainers who don't have an agreement on which of them is in charge. They've got to do the same things and can face the same penalties.
Re: I wonder..............
How does it make it any easier to bring charges against them? If you know they wrote the software, you have all sorts of charges over developing a tool for crime and at least accessory charges in any time that was run. If you don't have proof they wrote it, CRA violations don't apply. If they're trying the argument that the code they wrote was never run anywhere, so theoretically you can't charge them with computer misuse, then CRA charges also don't apply because it only counts if it was obtained by someone in the EU as a product, though fortunately for us that argument is unlikely to work on the actual charges. Not to mention that, by the letter of the law, the parties that could have been harmed by the CRA charges are most likely to be other criminals who deployed the malware rather than the victims.
This law does nothing to help catch ransomware criminals and is so pointless as an additional charge that nobody's likely to bother with. Additional charges tend to fall into one of two categories:
1. It's another severe thing which increases the sentences, therefore giving criminals an incentive to cooperate. That doesn't apply, because the sentences on ransomware tend to be much higher than any CRA violation would be.
2. If they're found not guilty on the big charges, they might be found guilty on the small one at least. That's definitely not going to happen because the kind of proof you need to show a CRA violation is the same as that needed to prove complicity.
Google's dev registration plan 'will end the F-Droid project'
Re: Users should have the right to run whatever software they want on a computer they own
It's not entirely clear. It's possible that local installation of unsigned apps over ADB will still be supported, but it's also quite possible that you will have to register with Google. They have stated they intend to waive the rather small fee for this process, but it still means identity verification to Google's satisfaction before you can distribute anything and periodic checks or your permission will be removed.
The sweetest slice of Pi: Raspberry Pi 500+ sports mechanical keys, 16GB, and built-in SSD
Re: The distinctly long-in-the-tooth Pi Zero 2
I'm not sure it's a great fit for the educational part of the market. For people like us, both professionals and hobbyists, who already have at least some experience with this area, setting up the Pico toolchain isn't very hard. It's not going to be so easy for a student getting some early experience with a board. There isn't anywhere near as many hardware peripherals for the Pico as were created by many suppliers for normal Pis, meaning more parts of a system have to be built from scratch, and neither is it as easy to get prewritten software to run because there are three different recommended environments for the Pico and code written for one won't run in another.
The Pi Zero has the advantage that nearly everything written for a larger Pi will run on it. That includes hardware control but it also includes OS and software components. If a student wants to build something that controls hardware but also connects to the internet, either for very remote control or to take action based on data retrieved, it's going to be easier on a Zero when they have the full set of Linux tools to rely on rather than a Pico W where they get WiFi and have to build everything else themselves. For example, connecting a Pi to a VPN involves installing and configuring the VPN client, of which there are multiple open source ones with clear online instructions, which will teach the user some things about how networks are built. Connecting a Pico to a VPN involves writing the client yourself, almost certainly failing because you'll use a lot of RAM unless you already know quite well how the cryptographic part and the networking part work. I might be able to do that. The average student won't. A VPN isn't that unusual a component because it's a safer way to connect something for access outside the local network, so there are many things that rely on it, for example if you want to monitor the aquarium from school.
The Pico is a useful product and I'm glad that they made one, but if education is still a significant goal, I think the Zero is a lot more important. I'm not sure how much they're still focused on education though, so they may have different priorities.
Page:
- ← Prev
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- 36
- 37
- 38
- 39
- 40
- 41
- 42
- 43
- 44
- 45
- 46
- 47
- 48
- 49
- 50
- 51
- 52
- 53
- 54
- 55
- 56
- 57
- 58
- 59
- 60
- 61
- 62
- 63
- 64
- 65
- 66
- 67
- 68
- 69
- 70
- 71
- 72
- 73
- 74
- 75
- 76
- 77
- 78
- 79
- 80
- 81
- 82
- 83
- 84
- 85
- 86
- 87
- 88
- 89
- 90
- 91
- 92
- 93
- 94
- 95
- 96
- 97
- 98
- 99
- 100
- 101
- 102
- 103
- 104
- 105
- 106
- 107
- 108
- 109
- 110
- 111
- 112
- 113
- 114
- 115
- 116
- 117
- 118
- 119
- 120
- 121
- 122
- 123
- 124
- 125
- 126
- 127
- 128
- 129
- 130
- 131
- 132
- 133
- 134
- 135
- 136
- 137
- 138
- 139
- 140
- 141
- 142
- 143
- 144
- 145
- 146
- 147
- 148
- 149
- 150
- 151
- 152
- 153
- 154
- 155
- 156
- 157
- 158
- 159
- 160
- 161
- 162
- 163
- 164
- 165
- 166
- 167
- 168
- 169
- 170
- 171
- 172
- 173
- 174
- 175
- 176
- 177
- 178
- 179
- 180
- 181
- 182
- 183
- 184
- 185
- 186
- 187
- 188
- 189
- 190
- 191
- 192
- 193
- 194
- 195
- 196
- 197
- 198
- 199
- 200
- 201
- 202
- 203
- 204
- 205
- 206
- 207
- 208
- 209
- 210
- 211
- 212
- 213
- 214
- 215
- 216
- 217
- 218
- 219
- 220
- 221
- 222
- 223
- 224
- 225
- 226
- 227
- 228
- 229
- Next →