ricecake

joined 1 year ago
[–] ricecake@sh.itjust.works 2 points 4 days ago

A lot of that information can be weirdly public. Looking up property records often comes with data about utility bills and taxes, and their payment statuses.

[–] ricecake@sh.itjust.works 21 points 4 days ago

The RSV vaccine is even being used in the wild! Certain high risk demographics can get it during RSV season. And not rare high risk either, women beyond a certain point in pregnancy and older people.

[–] ricecake@sh.itjust.works 4 points 5 days ago

Depends on the vendor for the specifics. In general, they don't protect against an attacker who has gained persistent privileged access to the machine, only against theft.
Since the key either can't leave the tpm or is useless without it (some tpms have one key that it can never return, and will generate a new key and return it encrypted with it's internal key. This means you get protection but don't need to worry about storage on the chip), the attacker needs to remain undetected on the server as long as they want to use it, which is difficult for anyone less sophisticated than an advanced persistent threat.

The Apple system, to its credit, does a degree of user and application validation to use the keys. Generally good for security, but it makes it so if you want to share a key between users you probably won't be using the secure enclave.

Most of the trust checks end up being the tpm proving itself to the remote service that's checking the service. For example, when you use your phones biometrics to log into a website, part of that handshake is the tpm on the phone proving that it's made by a company to a spec validated by the standards to be secure in the way it's claiming.

[–] ricecake@sh.itjust.works 26 points 5 days ago (2 children)

Package signing is used to make sure you only get packages from sources you trust.
Every Linux distro does it and it's why if you add a new source for packages you get asked to accept a key signature.

For a long time, the keys used for signing were just files on disk, and you protected them by protecting the server they were on, but they were technically able to be stolen and used to sign malicious packages.

Some advanced in chip design and cost reductions later, we now have what is often called a "secure enclave", "trusted platform module", or a general provider for a non-exportable key.
It's a little chip that holds or manages a cryptographic key such that it can't (or is exceptionally difficult) to get the signing key off the chip or extract it, making it nearly impossible to steal the key without actually physically stealing the server, which is much easier to prevent by putting it in a room with doors, and impossible to do without detection, making a forged package vastly less likely.

There are services that exist that provide the infrastructure needed to do this, but they cost money and it takes time and money to build it into your system in a way that's reliable and doesn't lock you to a vendor if you ever need to switch for whatever reason.

So I believe this is valve picking up the bill to move archs package infrastructure security up to the top tier.
It was fine before, but that upgrade is expensive for a volunteer and donation based project and cheap for a high profile company that might legitimately be worried about their use of arch on physical hardware increasing the threat interest.

[–] ricecake@sh.itjust.works 5 points 2 weeks ago (1 children)

Most voters don't have a business and never will.

The value of a net new business is that it creates more jobs and economic activity.
Most people benefit from more jobs to either work at or drive up labor demand.
Per that school of economic thought, incentivizing a new business adds more activity to the market and more opportunity for people to find ways to innovate, provide value and become profitable.
Giving money to an existing struggling business is subsidizing a businesses that's already demonstrated that it's not working.

However, we're both putting too much into it. The goal is to say $50k for small business, because people like a business friendly atmosphere.
Trump gets credit for giving tax cuts to businesses for stock buyback, which only helps investors. The goal is to court people who want pro business policies without literal handouts to corporations.

[–] ricecake@sh.itjust.works 2 points 3 weeks ago (1 children)

Yeah, it's definitely faster, but I'm not sure it's going to make too much of a difference for a Minecraft server.

With setting it up being a bit annoying by hand, I'd still rank the router option higher even if it's a worse VPN. Otherwise you risk ending up in that yak shaving situation where you're fighting with routing tables and DNS when you wanted a Minecraft server.

[–] ricecake@sh.itjust.works 3 points 3 weeks ago (3 children)

Oh for sure. What I meant was "check router for a built in VPN and use it if it has one, otherwise use wireguard because it's the easiest".

The specific VPN doesn't really matter so much. The built-in one would be the easiest, so checking for a solution that took a few clicks is worth it. :)

[–] ricecake@sh.itjust.works 30 points 3 weeks ago (5 children)

I would use something like wireguard, or another VPN service you can host yourself if your router supports it natively.

From the looks of it Minecraft servers seem to have dogshit authentication, so using some form of private network setup is going to be your best move.

[–] ricecake@sh.itjust.works 0 points 3 weeks ago* (last edited 3 weeks ago) (3 children)

Basing your argument around how the model or training system works doesn't seem like the best way to frame your point to me. It invites a lot of mucking about in the details of how the systems do or don't work, how humans learn, and what "learning" and "knowledge" actually are.

I'm a human as far as I know, and it's trivial for me to regurgitate my training data. I regularly say things that are either directly references to things I've heard, or accidentally copy them, sometimes with errors.
Would you argue that I'm just a statistical collage of the things I've experienced, seen or read? My brain has as many copies of my training data in it as the AI model, namely zero, but "Captain Picard of the USS Enterprise sat down for a rousing game of chess with his friend Sherlock Holmes, and then Shakespeare came in dressed like Mickey mouse and said 'to be or not to be, that is the question, for tis nobler in the heart' or something". Direct copies of someone else's work, as well as multiple copyright infringements.
I'm also shit at drawing with perspective. It comes across like a drunk toddler trying their hand at cubism.

Arguing about how the model works or the deficiencies of it to justify treating it differently just invites fixing those issues and repeating the same conversation later. What if we make one that does work how humans do in your opinion? Or it properly actually extracts the information in a way that isn't just statistically inferred patterns, whatever the distinction there is? Does that suddenly make it different?

You don't need to get bogged down in the muck of the technical to say that even if you conceed every technical point, we can still say that a non-sentient machine learning system can be held to different standards with regards to copyright law than a sentient person. A person gets to buy a book, read it, and then carry around that information in their head and use it however they want. Not-A-Person does not get to read a book and hold that information without consent of the author.
Arguing why it's bad for society for machines to mechanise the production of works inspired by others is more to the point.

Computers think the same way boats swim. Arguing about the difference between hands and propellers misses the point that you don't want a shrimp boat in your swimming pool. I don't care why they're different, or that it technically did or didn't violate the "free swim" policy, I care that it ruins the whole thing for the people it exists for in the first place.

I think all the AI stuff is cool, fun and interesting. I also think that letting it train on everything regardless of the creators wishes has too much opportunity to make everything garbage. Same for letting it produce content that isn't labeled or cited.
If they can find a way to do and use the cool stuff without making things worse, they should focus on that.

[–] ricecake@sh.itjust.works 19 points 3 weeks ago (1 children)

Because the headline literally says "world's first all electric train", which it very much is not.

[–] ricecake@sh.itjust.works 2 points 3 weeks ago

Yup. :/

I looked it up and it's not unusual for sentencing in New York to take several months, but I would have been much happier if the political realities had pushed things to move faster.

Having read the prosecutions response to the request for delay that basically said "everything the defense said justifying a delay was wrong, here's why a delay would actually be a good idea", it feels hard to blame the judge too much for granting the delay.
Even though none of the reasons seem to be based on sound legal principles and are at best based on practical considerations.

[–] ricecake@sh.itjust.works 2 points 3 weeks ago

I'm unaware of anything the judge has done that strikes me as particularly partisan.

"Not offending either party" is definitely not a partisan act. It's almost the definition of nonpartisan.

I can't fault him overmuch for granting the schedule change, since reading the letter from the prosecution regarding it they do seem to be effectively agreeing that it should be moved. If the defense requests a scheduling change, and the prosecution doesn't object and makes some points about why it might be a good idea so as to "assist the court", it's pretty hard for a judge to deny the request.

https://s3.documentcloud.org/documents/25050972/2024-08-16-peoples-response-filed.pdf https://s3.documentcloud.org/documents/25100931/people-v-djt-letter-adjournment-dec-9-6-24.pdf

Do you have a citation for him saying that he didn't want to send him to jail? I feel like I would have heard something like that and the searches don't turn up anything particularly relevant.

 

Went camping in northern Michigan this week and I was quite popular with the local biting flies.
Delightfully, I found this local food samaritan doing their part to save me, and they were gracious enough to show off a little for the camera.

view more: next ›