The Register Home Page

* Posts by doublelayer

11394 publicly visible posts • joined 22 Feb 2018

Nextcloud cries foul over Google Play Store app rejection

doublelayer Silver badge

You're right that it's a global requirement, and wrong about everything else. It's a global requirement so it depowers Android applications, making them store as much data as possible in the /data/data folder that users can't access, and user-installed apps can't access, but you know what can access it? That's right, Google sync software and Google backup software, installed and running as root. Now, why do you think they put in that requirement. It's not enough to just tell us that they did. If there's no actual security benefit, then that answer is not good enough. They aren't going after Nextcloud here. They're going after a bunch of different apps, of which Nextcloud is only one. They've taken similar steps to reduce access to users' data through any mechanism other than OEM-installed system apps, for example deprecating ADB backup without replacement.

But maybe this is Nextcloud's problem because they should be using some more secure method. Let's see what other applications use. There are convenient privacy reports that show the permissions apps use. Dropbox has READ_EXTERNAL_STORAGE and WRITE_EXTERNAL_STORAGE, the ones that implement access to all files. OneDrive, Box.com, Amazon Drive (write only for some reason), all have these permissions. But maybe these are just all lazy companies. What does Google use? Google Drive uses exactly the same permissions to do it.

I don't think Google is targeting Nextcloud here. I think Google is trying to target everybody, but if they did the same thing to the big players like Microsoft or Dropbox that they're doing to the small ones, they might get some real legal attention. But if you think this is totally normal, you can explain why Microsoft, who has thousands of programmers at their disposal and updated their OneDrive app lots of times since Android 11 was released, gets to use these.

US, China agree to roll back tariffs – but only for 90 days

doublelayer Silver badge

The reasons differ depending on whose reason you're thinking about. Trump's reason is because he is into mercantilism. That says that exporting is good because you get money from other people and thus have more money, and importing is bad because you give money to other people and thus have less money. It doesn't work because it fails to recognize that there's a lot of stuff with value that isn't money.

His supporters probably have a bunch of different reasons, and some of them like the mercantilism idea too. The other important one, though, is many people who have, either in reality or in their perceptions, lost a quality of life they once had or expected. People who expected that there would be easily-obtained and well-paid employment and found that these were not as simple as they expected are unhappy with their current situation. In some cases, that decline is real, whereas in others, they're actually able to obtain work that compares well in compensation and difficulty to their previous options, but they would prefer it to be easier and are under the misconception that it was better at some previous point. Various other factors, such as the increased prices of expensive things like houses and education have exacerbated this problem. Politicians, searching for a simpler explanation for this situation than the many realities of economic, technological, demographic, and geographic change, have decided that manufacturing in China is a convenient thing to blame it on, because it was at least part of the answer, so it can be stated as the whole answer. Therefore, anything you do that hurts China would have to be pushing the US back to the ideal times of the past where their lives would be better.

US Copyright Office found AI companies sometimes breach copyright. Next day its boss was fired

doublelayer Silver badge

Tell you what. Try that argument in a court. When you are convicted, that will prove how much your opinion matters when there is a law that says these things.

There is code I want to use. I have access to it; somebody posted it. It is copyrighted to a company who has not released it as open source. Guess what will happen if I try to use it for commercial purposes? Maybe they won't notice, in which case I'm fine. Maybe they will, in which case I can be sued. The fact that it's online, whether they intended it or someone posted it illegally (it's unclear) makes no difference at all. no matter how much I might want that to make a difference, it doesn't. Your opinion doesn't matter because this is about facts.

doublelayer Silver badge

No, and if the license sneakily says you're not allowed to read it after you've read it, that's a reasonable excuse. But this is not that. This is being allowed to copy and use it as you like, which is when you have to look for the license. If you didn't know that, this is your official notice. Not everything you can read is free for unlimited and unrestricted use.

Unending ransomware attacks are a symptom, not the sickness

doublelayer Silver badge

Re: Make the management legally liable

It's weird to see calls to make someone legally liable in the same comment where you suggest that you'd ignore a known attack. You do know that, if you got what you asked for, you're the person those bricks would fall on, right? Of course, you could be lucky: the liability might mean that more resources get assigned to security and then you don't have an attack to ignore. If you're unlucky, and your managers don't invest the resources, and you don't ignore the attack, then they will get the punishment for the problem. If they continue to ignore issues, you follow your stated procedure, then they have the perfect scapegoat because you're the incompetent who saw the evidence and promptly went home.

It isn't feasible for the stricter liability policy to only affect management. For example, if management provides tons of resources, hire new people, buy any software you like, overtime is easy, and some IT employee deliberately doesn't use them, then that employee is responsible for failures and would receive the consequences. A law that doesn't make that happen is obviously unjust and would not be passed. This means that, if you have such a law, the aftermath of an attack becomes a race for a scapegoat, a race you will only win if you are very professional despite your limits. Some people would approve of this, as it will at least encourage people to be vigilant to avoid personal consequences. Others recommend against it, using a similar logic to the no-blame investigations used in aviation to focus most of the energy on avoiding recurrences. Some others would be fine with blaming, but they would also argue against this because management generally has an advantage in the scapegoat search than the employees, since it's much easier for them to look for mistakes from the underlings than it is for the employees to get evidence of management's decisions. Arguing for strict consequences, but only on people who aren't you, is an unworkable and dangerous alternative.

If Google is forced to give up Chrome, what happens next?

doublelayer Silver badge

Because the problem is not any search engine owning any browser, but the most dominant search engine owning the most dominant browser. It being owned by Yahoo isn't going to matter because, outside Japan, nobody uses Yahoo search. Until Yahoo becomes the largest search engine by market share, they wouldn't be a concern under antitrust law.

doublelayer Silver badge

Re: Solving the wrong problem

Because a court can't do that. Making targeted advertising illegal requires a law to be passed by legislators who aren't interested in doing that because, should one of them suggest it, they would be buried in letters from interested businesses explaining how that would cost them four trillion dollars per hour and require them to fire every employee they have. Their colleagues would not have much interest in helping get that law passed when ignoring it would be the much easier solution and many of them believe the prognostications of doom and therefore oppose it. The selling Chrome option is an option because it's permitted by laws that have already been passed. If you can convince US politicians to pass that law, your problem will be solved, but you can't, nor can you convince any other countries' politicians to do it. The closest law we have to that is GDPR, which is enforced so halfheartedly that it has little effect, and the one you're proposing is an order of magnitude more drastic.

doublelayer Silver badge

Re: Think

The theory would be that their ad business makes a bunch of money by selling ads and the rest of their business makes a bunch of money by having places for ads to go. If they were separate, then Google (services) would still make most of what they used to make and would sell ad placement to the highest bidder among advertising networks, and Google (ads) would make money by being one of those networks with a lot of customers.

Some parts of Google would work just fine under this arrangement, for example search. Some parts wouldn't but could be kept or spun off as somewhat profitable enterprises of their own. Some things would crash and burn because they don't have enough places to insert ads to make all their money that way and they've been attached to Google (data collection) instead, or they just never made any profit but nobody noticed because all the rest did.

doublelayer Silver badge

Chrome being sold to some types of others might make Google even more desperate to pay Mozilla. If it's sold to someone who will replace Google with a different search engine, then Google will lose search revenue and will want more browsers to default to them. I think Google would prioritize selling it to someone who doesn't run a competing search engine and will keep Google due to popular demand, but maybe they won't get the choice.

doublelayer Silver badge

Re: Where's the standalone value?

It's the data and the users. You can grab and sell the browsing history of a couple billion people [warning, this is illegal, but nobody will stop you] and send the users to places of your choosing. As long as the places you're sending them are other search engines or ad sites and not malware, you'll get away with it. That's why it's worth so much. Of course, companies will probably overvalue how much you can make by doing that, but if Google has to sell it, they'll find the one that values it highest, whether they know what they're talking about or not. If it's not, as it probably will be because I'd bet on OpenAI having the highest bid*, that's the buyer's problem.

* OpenAI is used to having billions at their disposal which the backers don't mind them throwing into the shredder. Most other companies at least sometimes have to justify spending decisions. I'm not sure how long they can continue to find credulous investors, but some of them might see a Chrome purchase as a way to get even more users, because historically, a lot of startups have benefited a lot by throwing their product in front of millions of people and getting more customers this time. Some investors have not realized that the economics of AI-driven businesses are a bit different.

37signals is completing its on-prem move, deleting its AWS account to save millions

doublelayer Silver badge

Re: "Someone Else's Computer" is nonsense

The problem with that analogy is that, for a lot of the time, if you build equity in a house, you can sell it for more than you paid for it, and in many of the cases where that didn't apply, it was at least worth the same amount. After you've paid for a server, it decreases in value until you can't sell it at all and the remaining value is just continuing to operate it until it breaks. Owning a house means that, at the end of the process, you have an asset that someone else will probably buy. Even if you smashed up the house, someone will probably buy the land to build a new house on it. At the end of a server's life, you have some scrap metal and need to buy a replacement.

Renting might still be more expensive, but not necessarily. There are two other things you need to consider in your comparison. One is the different things you get when renting and owning. Renting means the power, space, and some types of hardware maintenance are included. Make sure to include those costs for owning the server when you compare them. The rental option may come with extra costs too. For instance, you're probably paying for data transfer by the gigabyte whereas you may not have any metering on your local connection. Add that one too. In many of these cases, those prices are not identical to what the other side would be paying so you can't eliminate them with the logic that "you're paying them either way". If you're paying indirectly for electricity usage which the cloud provider has optimized for because they run lots of electrical equipment and don't want to pay too much, they may have lower costs than you would. If you've got a lot of traffic to send, their bandwidth pricing might be an order of magnitude more than it costs you to rent usage of a sufficiently wide pipe. You have to know what the numbers are and only then can you compare them. No shortcut will give you that power.

doublelayer Silver badge

Re: "Someone Else's Computer" is nonsense

The context is clear. They were not saying that cloud is better because it actually provides that. They said that avoiding cloud doesn't provide it either, thus that the decision of which one to use shouldn't rely on incorrect assumptions that one will compensate you if it breaks and the other won't.

doublelayer Silver badge

Re: In six months...

"I spent 45 years in the onperm space as a server/database consultant to very large organizations"

Evidently much more professional ones than I've seen because several of the things you've never seen are not so rare in my much shorter experience, also on prem though cloud users got them too. For example, some of the stuff you've never seen:

"storage (say S3 buckets) being left wide open for the world to steal from cause wide open was the default config": I work in security. People leaving things open that they shouldn't because unauthenticated was on by default is really common. Where the server is makes no difference. That's down to config. People are often lazy with configs and it's often a problem.

"customers thinking XXX service meant remote failover but it didnt": Definitely seen it. People who thought that they had built redundancy into their system but they didn't happens whether you're using cloud services or not. Cloud services provide some tools that you have to build yourself for on prem, but it doesn't save you if you don't know how they work and what you have to do to use them properly.

"The BIG difference is your on perm team CARES about the systems they manage... cloud teams not so much.": You just made that up. I've dealt with on prem teams who didn't care, cloud teams who didn't care, dev ops teams that didn't care, managers who didn't care, and occasionally each of those things that did care. What they were doing was not a good indication of whether they would care about it. You can manage cloud services and care about them staying up and functional. You can manage your own servers incompetently. Your allegation that either of those doesn't happen is obviously wrong.

Curl project founder snaps over deluge of time-sucking AI slop bug reports

doublelayer Silver badge

Re: It's the spam effect

No, your downvotes are because nothing related to this has anything to do with advertising. The article and most comments are talking about spam security reports. Those are not adverts. The comment you replied to got closer to adverts, since it was talking about spam email. Yes, those are adverts, but banning all advertising wouldn't do a thing about it because the spam is already not allowed and the spammers are doing it anyway. Thus, whatever we may think about advertising, it isn't relevant.

Also, you have followed your typical pattern and gone too extreme on the negativity. I don't like advertising either, hence why I have a multilayer blocker in place to filter out as much as I can. There's a difference between that and justifying making it illegal, let alone making it illegal and actually enforcing that law to block it. It's much harder to justify that, but I'm not going to bother arguing on either side since you've not tried to do so either. You just called for it without providing reasoning.

doublelayer Silver badge

Re: It's the bug bounty

In addition to the points others have raised, there are two theories for why paying works better than just having an unpaid reporting mechanism, one of which I believe and the other I don't.

The good reason: it convinces people to look for security problems. There are people who will work actively to try to find a problem if they can get paid, whereas if they're working for free, you may only get reports they stumble on by accident. It can be quite cheap, because if they don't find anything, you don't have to pay them. I have not tested this, but I certainly have seen more reports sent when payment was offered, even if many of them were crap.

The less convincing reason: fears that the bad guys will pay for a vulnerability, so profit-oriented people will sell it to them unless they can make money by reporting it. I don't buy this. All of the parts of that are true, but I don't think bug bounty programs make a difference to any one of them. A criminal group will spend more for a good vulnerability than any bug bounty program will pay out. Most people who find one would be unwilling to sell to criminals because they don't like criminals. Most who would be willing don't know how to find them. Those who are willing and able have other reasons to choose not to, such as not having a reliable way of trading their vulnerability for cash when, if they send the details up front, the criminals don't have to pay because they have the vuln now, and if they don't send enough details, the criminals don't pay because they're not sure the thing is real. Someone who can get through all of those hoops will probably not bother trying to see if the company will outbid here.

doublelayer Silver badge

Re: Sorry to nitpick, but...

AI filters for AI text have been tried for a long time and the answer is usually no. You can make a model that takes a guess, and in many cases, that guess will be reliable, but that's all it will ever be. If people realize you're doing it, they can easily make the guess less correct. For example, comparing real bug reports to AI-generated ones, there's often a significant stylistic difference between the two* so I can assume which are which, but if I am a spammer after a bounty, I can customize my prompt to make the AI write its text less professionally and more laconically, and then it will look more like the human-written ones.

* People write bounties in a lot of forms, but they are often writing more informally, meaning more acronyms, a little less jargon, and slightly worse grammar, than the ones LLMs often produce. They are also written more formally, including the reverse of all three of those differences, than human-written ones that turn out to be crap. I can often guess based on the style how likely one is to be useful, but I have to read and test it anyway because the well-written one could be from someone who just likes to speak formally when they're sending a message to someone they don't know and the one with worse grammar might be someone who isn't a proficient speaker of the language they're writing the report in. All you could do with an AI is try to sort them so the useful ones are higher in the stack.

Nip chip smugglers by building trackers into GPUs, US Senator suggests

doublelayer Silver badge

Re: I'm sure...

Most of the time, the locations they track would be pretty obvious datacenters because the denied chips are mostly only viable inside custom servers. The idea is stupid and probably not as feasible as the article, let alone the politician, thinks it is, because there's no magic tracker that would work the way the politician thinks and serial number tracking doesn't do much after the chip's been shipped somewhere else. If they did make a tracker, it wouldn't be good or helpful, but neither would it cause the problems I think you're implying since most places with a bunch of GPUs in them are already findable.

People find amazing ways to break computers. Cats are even more creative

doublelayer Silver badge

Re: Cats and keyboards

A cat I had was very polite about keyboards for some reason. She would walk across my desk to get my attention, but she would always nicely circle around the keyboard rather than tread on a key. However, she had a different experience with another type of keyboard. When she was exploring after a move, she was very interested in a piano and, I think, wanted to look inside it. Several times, she would jump onto the piano, but because I'd left the lid up, the piano would make a noise whenever she stepped on the keyboard. I was going to put down the lid and try to keep her off, but fortunately, she seemed to interpret the piano's noises as a warning, jumped down whenever it made one, and quickly concluded that she would leave the piano alone as it clearly didn't approve of her visits.

BOFH: HR tries to think appy thoughts

doublelayer Silver badge

Re: "HR tries to think appy thoughts"

No, it's the same one, named Stephen, all the way through. I challenge you to find a single example of either of the events you've claimed. You will find a couple attempts by the PFY to leave, which are often reversed in that article or a couple episodes later, and you'll find two attempts by the PFY to replace the BOFH by fire (literally). The challenge isn't serious, as I'm quite confident you won't find it, but you'll read a lot of BOFH stories if you attempt it which is reward enough.

PowerSchool paid thieves to delete stolen student, teacher data. Looks like crooks lied

doublelayer Silver badge

Re: What I do not see here

One reason you're not seeing that is that it's not a great solution. The solution I and others have proposed in comments is a bit similar: make paying ransoms illegal, and then you can basically do the same thing you want to do to them if they pay one.

Your solution is a lot more drastic and puts the CEO and CIO in a position they can't manage, meaning that you can't implement or enforce that. The CIO, or CSO if they have one, is responsible for trying to prevent and respond to incidents, but that doesn't give them total power to prevent them from happening. You can investigate them for negligence in some cases, but deliberately not all cases, because they are not all-powerful. For instance, if a criminal robs an employee at knifepoint of their work laptop and forces them to log in, that's not something worth arresting the CIO over. The same is true if some employee clicks on a phishing link and installs some malware. A successful ransomware attack is a bigger breech, meaning more likely that it's negligence on the part of the employees or management, but it's still not a guarantee of anything. I'd like you to consider whether it would be fair if we through the book at you if tech you're responsible for was involved in an incident, with or without your manager included? A lot of people who want senior management to face serious consequences don't extend that downward even when there are significant problems there as well. That would never fly, because when the CIO is facing prison time, they'd find reasons why someone else should be going instead and some of the time, those reasons would be accurate.

doublelayer Silver badge

Re: Money Laundering

"money laundering is the act of obscuring or obfuscating the destination or source of money."

No, quite the opposite. Money laundering is the act of providing incorrect information about the source or destination of money and specifically applies when that money is, directly or indirectly, from a criminal source. As the Crown Prosecution Service describes it:

Money laundering is defined in the POCA as “the process by which the proceeds of crime are converted into assets which appear to have a legitimate origin, so that they can be retained permanently or recycled into further criminal enterprises”.

You have it backwards. There are many situations where a business transferring funds to someone they don't know is entirely legitimate. For example, if a business buys items from people for cash, they do not have an obligation to identify those people before paying them. They can claim that as an expense on their records. Sadly, paying a ransom is similarly allowed, hence why the UK police haven't descended on anyone who has and extracted massive fines.

doublelayer Silver badge

Some of the larger groups did indeed build up a brand name so they could get more payments, but ransomware has long had lots of people infecting with badly written encrypters that wouldn't decrypt or went with the whole infinite extortion loop. Unfortunately, that didn't happen often enough to convince people that paying didn't help. I'm not sure this example will prove any different. While there are people who can hope that their problem will go away for one short bit of pain, people will pay ransoms. I think we will have to prevent them from paying to make a meaningful dent in the problem.

doublelayer Silver badge

Re: Money Laundering

I'm afraid you were probably mistaken when you explained that, because paying a ransom is not money laundering. It is a bad idea, unethical, possibly illegal depending on your jurisdiction, and should be made illegal where it isn't now, but even when it is, it's not because of money laundering laws which have nothing to do with the money until the criminals have it and want to do something with it. Similarly, it has nothing to do with know your customer laws because:

1. If KYC laws don't apply to whatever type of business you run, they don't affect you. A lot of businesses don't have those regulations in any case.

2. If they do apply to the type of business you run, they require you to identify those who buy services from you, not ones you pay for their services, illegal or otherwise.

If you were a financial institution and you decided to pay the criminals by opening an account for them and depositing funds, KYC applies. If you are or did almost anything else, they don't. If you actually get to choose between these two options, please pick the former in the hopes that the criminals are stupid and will identify themselves to get access to the funds, making them easier to catch. Paying ransoms is legal in a lot of places, including the auditing and tax implications. It is so legal that cyber insurance companies have specialized in doing it, while if it was illegal they'd be storehouses of perpetrators ripe for law enforcement action. I would like to make paying those ransoms illegal so that this stops, but that hasn't happened yet.

If you think using these incorrect legal arguments is helpful in convincing companies not to pay ransoms, I think you're using the wrong path. We have many examples like this article demonstrating how paying doesn't mean the business gets anything, whether the promise is destroying the data or helping with recovery. We can point to PR downsides of even a successful ransom payment which reduce trust. We can point out the consequences to others of propping up a criminal industry. All three of these options has a major advantage which yours lacks: when they call in a lawyer to review the plan, the lawyer won't be able to say "they misunderstood the laws and this actually isn't a problem".

You'll never guess which mobile browser is the worst for data collection

doublelayer Silver badge

The linked report gives those lists. The article doesn't quote the lists for all the apps because that would take up a lot of space and isn't of much interest. The problem, as several people have noted, is that those lists don't contain a lot of information. When it says "collects contact details", does that mean that it will remember phone numbers if you enter them into a form or that it finds everything about you and sends it to the company for later misuse? Either way, can you disable it or do you have to accept it? When is the data shared, with whom, and with what terms? None of that is in the lists you can find in the report, meaning that counting them is pretty close to the amount of information you can find by doing this.

doublelayer Silver badge

Re: Targeted ads

"I have pondered recently about how bad the "i hate your adverts so I am never touching your company again with a bargepole" is, or isn't, for advertisers to persist in ramming their wares into your eyeballs at every opportunity."

We don't know, but more importantly, they don't know. I have a feeling though that that has almost no effect. I don't react like you do to advertisements*. I do my best to avoid them and ignore the rest, but I don't record the ones that get through that filter either to intentionally patronize their business or to punish them. In many cases, an advertisement that you're going to respond that way to is one of the many completely useless ones, ones for products you have no interest in anyway or ones where you have no choice**. Also, most of the people who are as averse to advertisements as you are would be blocking most of them, meaning that most advertisers don't feel the effects of your animosity anyway and wouldn't be able to categorize you into that group if they wanted to.

* The exception is when I get the same advertisement over and over again. The main place I notice this is on podcasts, which I listen to several of. In many ways, podcasts work the way I'd like advertising to: they're run by an individual, there's not much tracking of the downloader to try to target an ad at, and there are only a few attempts at centralized advertising networks for them. Unfortunately, that sometimes means that they don't get many advertisers so you just hear the same one over and over. Even then, I don't automatically develop a grudge against the advertiser. In a couple cases, I have built up a grudge against an advertisement or even a product, but I think those grudges are based on real defects with those rather than just having the advert repeated.

** Sometimes, a product is either the only option or clearly the best one, meaning that grudges against the company are kind of meaningless if you know you want to buy one. My ISP ran some annoying ads, but I need an ISP, this one has better prices and contract terms than the alternatives, so I ignore the ads which I'd be subject to regardless and buy their service anyway.

doublelayer Silver badge

Re: I use Brave

I rate the "turn it off in the settings" arguments based on how feasible it is to do. For example, some of the things I find annoying in Windows are easily turned off in the settings and don't come back, so those don't bother me very much, but other ones either move around, require registry hacks to turn off, or aren't configurable at all. I take those ones much more seriously. I don't know how Brave works, mostly because I'm satisfied with Firefox as it is now and because there seemed to be a longish list of things I didn't want. I probably can turn them off, but why bother when my existing browser doesn't have them in the first place?

Linux kernel to drop 486 and early 586 support

doublelayer Silver badge

Re: junk like the Celeron

Why is having a massive profit margin dishonest marketing? Annoying I get. Choosing to buy someone else's product that's reasonably priced, definitely. But if the answer is that their product is actually better, they can make it cheaply, and they're choosing not to let you buy it cheaply, that's just normal. The same reason that I would probably have accepted a lower salary when my current employer hired me, but they offered a certain number and I accepted it or even negotiated it up. It's how everything works and they aren't lying when they say that this is how much you have to pay to get one of these things.

doublelayer Silver badge

In addition to all the comments about what will still be supported, there's also a lot more choices for embedded systems processors which support Linux just fine. There are probably many cases where an old design does require a 486-compatible chip, but most embedded devices can work as well if not better with a different processor that's running a different ISA with more features, lower power requirements, and because everyone's using them, much cheaper.

doublelayer Silver badge

Re: Hubble Telescope.......

True, but they implied that the presence of that chip inside the telescope was relevant, which it isn't because it doesn't run Linux, and it wouldn't be even if it did run Linux unless they were pushing kernel updates which, for something that's really hard to fix if it ever didn't like a kernel update, they wouldn't be doing. Nor is it relevant for any machine with one of these CPUs unless the users of that machine have actually been updating the kernel version. There are indeed a lot of old machines with these processors in them. Almost all of the ones I've seen are running old software on the old hardware. Linux 6.12's the last LTS version with support? Some of these things are still running 2.6 kernels and the more updated ones are running 4.x ones. If you're running a 486 with a 6.x kernel, I challenge you to explain why, and only then will I start to worry about dropping support for it. If people haven't updated before when they could have, then I won't be bothered about cutting off the stream of updates they didn't use anyway.

Pentagon declares war on 'outdated' software buying, opens fire on open source

doublelayer Silver badge

Re: Enlighten Us !

You won't be able to determine the security of software based on location of the developer. Your country, as well as every other, contains evil people who will intentionally subvert security procedures and incompetent people who will break things by accident. This is why you have to analyze what you're running to some extent, which is indeed difficult. If they decide that doing that with open source software is too hard, they can write everything they run themselves, which will be expensive and means a lot of things they'd get by default with open source they will have to pay for, but maybe it will provide better results. Alternatively, they can use the fact that lots of people should be analyzing open source software when they're running it to distribute the costs of doing this across many organizations running the same stuff, which does happen some of the time already. Alternatively, they can do what most institutions have done so far, they can just not bother to analyze what they're running and hope for the best. Hoping to do it based on nationality guarantees that you'll get bad results while some clueless person thinks they've figured it out.

Top sci-fi convention gets an earful from authors after using AI to screen panelists

doublelayer Silver badge

Re: Detector triggered...

I'm less confident about this, mostly because this is a very public apology. Those will have been written and rewritten about a dozen times before they're released. LLMs could have been used, but you could get the same effect by just shopping around the statement to anyone trying to make sure it contains the right amount of contrition, explanation, and buck-passing. I also have a filter which works most of the time when the human-written text was written in one go and at most self-edited. I wouldn't have confidence in my filter on stuff written by a group of humans who are trying not to anger anyone.

Commodore OS 3 is the loudest Linux yet

doublelayer Silver badge

Re: Sell a usb stick?

Why would you pay for that? I think the optical media by mail service was mostly for people who didn't have a network connection fast enough to download those quickly, but most users can now download a normal distribution overnight or this monster in a couple days, and many can shorten that to a normal one in half an hour and this in four. Most users who would have trouble creating the USB disk themselves would also have trouble using Linux or knowing it existed. What would the convenience element be here compared to just downloading and writing it to a disk you already have?

Redis 'returns' to open source with AGPL license

doublelayer Silver badge

Re: "People moan because it wasn't the open source license they like"

The problem is that, to know whether something is open source, we need a clear definition of what that means. The OSI is not the only place that has a definition, nor do they really get a monopoly on the term. However, I tend not to accept someone else's idea of what it means unless they can provide their own unambiguous definition and apply it consistently. Often, when someone does that, I don't find their alternate definition as convincing or persuasive as the OSI's, which I mostly agree with. This is not for any reverence for the OSI itself. I never check whether the OSI has stamped their seal of approval on a license, and I disagree with them on a lot of things, notably their AI licensing thing which I think is completely wrong. The definition they're using, however, is pretty good.

Most of the faux-open licenses use vagueness to imply that it's basically the same and rely on "it doesn't affect you" to distract from problems. I have a problem with both of those things. A lot of them have their category of people who get extra restrictions if they use the software, a category based on vague conditions like "commercial use", or, in the case of the SSPL, "as part of a service". The licenses do this because the authors want to apply it to certain people, often cloud services. However, it's easy to argue that everything is part of a service unless it's running offline and only used by me personally and everything is commercial use if there's any possibility of money being involved, for example if there's a donation button on the site, even if nobody's ever clicked it. Even if it's only against AWS and Azure today, someone who wants cash could easily change their mind about those terms tomorrow. In all the cases I'm complaining about*, there is already a precedent for this because they just changed their licensing already, so changing their interpretation of "service" is a much smaller change which could cause problems for everyone. That is not a small difference from the AGPL.

* I do not object to someone who writes something from scratch and wants to license it under one of these from the start. I object when someone made their software open source then switches to it, mostly because they are taking the contributions of others to do it, and in some cases, preventing others from using their own contributions without forking.

doublelayer Silver badge

Re: "People moan because it wasn't the open source license they like"

The SSPL is neither free software nor open source. The SSPL license explicitly violates parts of the OSI's definition* and arguably removes one or two of the four freedoms that are core to the FSF's philosophy**. That's why we have a problem with it. Oh, and it's deliberately doing this to be impossible to comply with so that you pay the copyright owner to get out of it, meaning that they're not even doing this for ideological reasons. The other license they used, the RSAL, is even farther from open.

* The OSD is quite clear. The SSPL clearly does not qualify because it violates rule 9 and, to a lesser extent, rule 6. The text explains how with sufficient clarity that I don't have to go into more details.

** I will go into more details about the four freedoms of the FSF's definition, though. They are not as clearly defined, but the way they have been applied makes it clear that the SSPL removes freedom number zero, the freedom to run the software as you want to. Normal free software licenses impose terms on those who make derivative works from them, whether those are slight modifications or massive additions, but they don't do that on anyone who installs it. The SSPL does. Depending on exactly what you want to do with it, those terms may not be important, but unlike actual free software licenses, they're still there. The nondiscrimination element that is so explicit in the OSD may not appear to be there, but it is often included in freedom number zero, itself considered so obvious a requirement that the FSF didn't think it needed to be listed for a while. Of course, we could argue about how much this matters, I think it does, and you might not, but what's more clear is whether the organizations concerned think so. They do, which is why neither of them support the SSPL.

doublelayer Silver badge

Re: AGPL

Instead of trying to see this as an argument and picking a side, consider the pragmatic point they're talking about. If you run a project with users and you change the license of that project, some users will face legal consequences, which may reduce your user count even among those who don't object to the new one. This is something for creators of projects to think about when deciding what they want to do with their licensing. Often, if they choose one license and stick with it, they are more popular than if they change it. That is even true for things that start out as proprietary. Many, including me, are completely fine with proprietary code but much less happy about open source code that suddenly switches to proprietary.

doublelayer Silver badge

Re: AGPL

I am not a lawyer, so you are free to ignore me, but in case you or anyone else wants to know the answer, here it is:

You're using Redis under the AGPL3 with the conditions you described. Here's what you have to do.

1. Your code: nothing. It interacts with Redis through its normal channels. You don't need to change licenses or distribute it.

2. Redis code: if you changed it and made a custom version of Redis, you have to distribute that to anyone who wants and you have to use the AGPL3 to do so.

3. Attribution: Somewhere in an about screen or documentation, you have to say you're using Redis which is AGPL3 licensed and refer people to copies of those, but you can use Redis-hosted versions.

Feel free to get a lawyer to verify this. They cost more, though.

Altman's eyeball-scanning biometric blockchain orbs officially come to America

doublelayer Silver badge

Re: Proof-of-personhood

In almost all cases, the users' desire for anonymity is more important than other users' desire to know who everyone is or the frequent desire of companies to be able to sell that data. There are very few exceptions. Nothing you listed is among them.

Open Document Format turns 20, but Microsoft Office still reigns supreme

doublelayer Silver badge

Re: Succes

I think the only major office suite that doesn't (as far as I know) have support for it is Apple iWork. That's not a big surprise since iWork is very insistent on not liking any format except its own; it'll let you export to formats that other software can read, but it does make sure to complain about it if you routinely use it. When I used it, DOCX and XLSX were supported formats, but ODT and ODS were not.

doublelayer Silver badge

Re: That UK Gov Manadate thing

It's probably a lingering effect of the delay in meaningful support. Microsoft Office has had some kind of support for ODF for a very long time, but it's only since Office 2021 that it didn't come with some footnotes like Windows only or separate conversion process. Meanwhile, Office is one of those things that people don't upgrade very often because they don't see what changes they could need, and they're usually right. The combination means that someone who wanted to use Microsoft Office might still think that ODT files would not work so well if they tried, even though it has been fine and probably would be even if they're on an earlier version.

doublelayer Silver badge

Re: That UK Gov Manadate thing

I'm sure that some universities or schools do mandate that students use Office to create their Office format documents, but most just specify that they have to be in that format. I used LibreOffice to make them, and nobody ever complained about that, probably because they had no way of knowing I had but also because, as long as it opens in whatever they chose to use, they were happy.

Open source AI hiring bots favor men, leave women hanging by the phone

doublelayer Silver badge

Re: Now you know why LLMs are popular

No, they want to sell it. Some of them do a little hand waving to try to pretend that their model isn't biased, but as I said in my original comment, they've usually just made the bias results more random because removing bias is hard when the underlying technology is intentionally randomly generating results. VCs probably don't use AI to filter the companies they're investing in because they understand how fallible it is, but they're perfectly happy to sell it as useful to everyone else.

HR departments, meanwhile, adopt it because it saves time. Instead of doing their job, they shove all the candidates into the software. Are they trying to make sure that only some preferred group gets hired? No, they're trying to get their job done faster because it won't matter to them if they ignore a great candidate because the LLM didn't like the format of their resume. The bias in these programs is almost impossible to remove, and sadly the people who would have the best ability to reject it are the ones who benefit by using it (all the resumes reviewed in an hour, let's take the rest of the day off) and not the ones who suffer the consequences (having to work with the random choice the program spat out).

doublelayer Silver badge

Re: Now you know why LLMs are popular

I don't think so. A deliberate bigot doesn't need AI. They can discriminate on an industrial scale, and they can ensure that their acceptance rate hits their ideal 0% rather than the AI's 10-37%. I think the AI is more likely to be used by people who are clueless and lazy, so lazy they haven't read this or the, by conservative estimate, 754 articles on this subject all of which have indicated that AI recruiting applications have every bias in the book and some that we didn't know about yet. This will perpetuate all those biases again, and when more modern data is fed back into the AI, it will amplify them, but I don't think any of that will be deliberate.

Sadly, the only other category trying to do anything to fix this are the AI writers who do read these studies who want to find a way to have their AI not discriminate. Much nicer than the original bigots, but it really means adding in some extra prompts which change what the bias is but not whether there is one.

Disney Slack attack wasn't Russian protesters, just a Cali dude with malware

doublelayer Silver badge

Definition from 18 USC § 1030(e)(2)

the term “protected computer” means a computer— (A) exclusively for the use of a financial institution or the United States Government, or, in the case of a computer not exclusively for such use, used by or for a financial institution or the United States Government and the conduct constituting the offense affects that use by or for the financial institution or the Government; (B) which is used in or affecting interstate or foreign commerce or communication, including a computer located outside the United States that is used in a manner that affects interstate or foreign commerce or communication of the United States; or (C) that— (i) is part of a voting system; and (ii) (I) is used for the management, support, or administration of a Federal election; or (II) has moved in or otherwise affects interstate or foreign commerce;

As far as I can tell, it means any computer that is used by any business or government that operates across state lines, plus a couple more specific categories that are already included in that one. US law doesn't allow federal governments to deal with things like that that happen exclusively inside one state, so it can be simplified even further to "a computer the federal government is allowed to charge you with a crime about". None of this seems to be related to any real or notional protection, so there doesn't seem to be any such concept in the law as an "unprotected computer".

How Amazon red-teamed Alexa+ to keep your kids from ordering 50 pizzas

doublelayer Silver badge

Re: Interesting

No, that wasn't it. It was a specific compiler whose included libraries were triggering something in the AV. Unsigned binaries coming out of GCC were just fine by it. Unfortunately, binaries from GCC wouldn't do what we needed; only that compiler was supported.

doublelayer Silver badge

Re: A 100% way

Out of curiosity, do you mean the voice age verification thing which I spent three sentences explaining how it would a) annoy everyone and b) not fix the problem? If it was, can I suggest a rereading until you understand the core point, which was specifically that technological patches will never fix the problem, only hide it from the initial glance? It seems strange that you're critiquing the comment by assuming I said the opposite of what I said.

doublelayer Silver badge

Re: Interesting

"I would think it would be better to have overly active fraud detection than not enough"

In most cases, you're right, but overly active fraud detection can have some significant problems too. I've had online payment systems go totally haywire when the payment wasn't even declined yet; my card simply wanted additional verification of the charge, then approved once it got it. In the meantime, the payment system gave up on me and canceled the order, so I had paid them without completing my order. I ordered a second time which worked, and the situation got cleaned up without too much chaos, but that could cause problems for some groups of people, for example if the transaction was large, they didn't have a lot of cash on hand, and the payments were on a statement before one was removed. It's probably easier to err on the side of caution when I haven't had to experience the effects of frequently incorrect caution. If it was happening to me a lot, I too might want them to dial it down a bit.

I'm reminded of a piece of antivirus software that decided that the output of a certain compiler was malware. I couldn't run any code I compiled because every time I ran it, the file would either be quarantined when it was created or deleted when I tried to execute it. I screwed with the compiler to fix the antivirus's inaccurate judgement, but it probably would have been easy to convince me to remove the antivirus software when I had been fighting with it for a while (work computer, so for better or worse, I couldn't remove the antivirus).

doublelayer Silver badge

Re: What am I missing here?

The problem is that it's the security on the device that makes the transaction, not the card to pay for it. If I can secure my card, but that device can charge to it, which it needs to have if I'm using it to make other transactions, then the security I added to the card isn't going to help.

While we're at it, I have cards with the default level of security and there don't seem to be a lot of options to change that level. There's no interface that lets me put a cap on number of pizzas I could order at once. There's an opaque fraud detection algorithm which has fortunately never gone off by mistake but admittedly I don't spend much money and a slightly less opaque location tracking algorithm, neither of which can be turned off anyway. The next security level I have is "card locked except for recognized monthly bills". Those are the only two levels I'm aware of that let the card work at all, and since only one of them lets me buy anything I haven't purchased on a schedule for several months, on that one I must remain. I'm not sure what you're recommending is a feasible option for people who have any payment cards.

doublelayer Silver badge

Re: Interesting

Doing that changes how long you have to retry the situation, not whether it works in the first place. If the system rejected the order out of hand, it wouldn't work a day in advance either. I assume there is a mechanism for verifying that a user is permitted to conduct the action for the ones that have been filtered, so I doubt it's as problematic as the financial fraud detection examples it's being compared to.

Your graphics card's so fat, it's got its own gravity alert

doublelayer Silver badge

I think they were saying that you can't play many games on that spec to disagree with the previous commenter, and they were referring to the age of the PlayStation 4 which the previous commenter said was good enough for their uses. It sounds like you may be in closer agreement.

Chris Krebs loses Global Entry membership amid Trump feud

doublelayer Silver badge

Re: Too much probing

He had a security clearance before it was unjustly taken away. You get at least as much probing to get that. I suppose that, by the time he had already done it for doing security work for the government, it didn't matter so might as well get the benefits. Such things often mean that the government, and especially the military, have trouble finding all the people they want to work there. That goes for most governments, but the US one complains frequently about how they don't have enough people to do the computer work they want.