• 0 posts
  • 17 comments
Joined 3 years ago
Cake day: June 16th, 2023
  • Yeah, booking a flight is only difficult because I make it difficult by deciding about how I feel about cost versus layovers versus time of departure/arrival.

    For grocery shopping, I’m very specific in what I want, and it’s easiest just to pick them specifically. For a lot, I’d rather just go in person to the store to look over things. In fact, whenever I spend money I’m pretty specific in what I want and I don’t want something to “improve” things by letting me be more vague.

    As a point of comparison, fast food ordering. Apps and Kiosks were actually a step up for me, because it was easier and quicker for me to see what the options are and select precisely what I want. AI order taking would be a huge step backwards from there. Even when ordering from waitstaff at a restauraunt, I always like to have my finger clearly pointing to the menu for what I want to order.

  • This is absolutely a valid concern.

    There are various available solutions, but little incentive for landlords to bother. Either ev charger for every renters parking spot with some mechanism to lock it out (expensive) or a large pool of chargers that are shared, but you have to badge in and get it billed to you. The latter if too small barely helps and if too large will piss off gas vehicle tenants that hate the “wasted” space.

  • Have to dig into the nuance of this specific scenario.

    A new memory vendor would be a huge capital expense, and investors are generally a bit apprehensive about that.

    Further, it would be years before they could theoretically roll out product, a delay that investors would need to be awfully patient for under the best of circumstances. Further, we went through this dance in recent history, people thinking that the chip industry needed huge advancement and expansion of supply, only for demand to subside to normal before any of that expansion could even start.

    And the stated payoff? Lower margin product than competition. Not exactly exciting to tell your investors your whole game plan is to make less money than your competition.

    Then there’s the reality that this is not an innate direct demand of memory for the sake of memory, it is intrinsically linked to these big AI companies, leading to the big question: Is this a bubble that has a risk of popping? If so, then the market will go poof before you have a single item shipped.

    Even if broadly, you think the AI is viable, if any one company, especially OpenAI, gets left behind, the memory market could collapse. If not for Sam Altman’s very specific purchasing commitments, the memory pressure would probably be much more modest.

    Ok, fine, you are a ride or die believer in the durability of the AI boom and that every company is going to win. However, even if the AI companies do very well, what’s to say they will still have the same appetite for hardware by the time this new enterprise gets going? A pivot from aggressive training to exploiting more what they have done, or some breakthrough that dramatically takes down their bloated memory requirements. If you believe in the AI boom, then just directly investing in the AI companies is the safer bet.

    At the end of the day, an investor has a choice between being confident in the AI boom and investing directly in the AI companies, or being a bit less confident and investing in the memory vendors that are making bank now with a weaker, but still viable post-pop story. If you aren’t comfortable directly investing in the AI companies now, then you almost certainly aren’t comfortable with a long shot that only benefits if the AI boom keeps going exactly the way it has been going.

    Yes, effort is underway to do this in China, but it’s more about supply chain sovereignty than free market interests. It may have similar benefits, but here the free market is unlikely to be the impetus for increased supply in this scenario.

  • I’m trying to stay too anonymous, the paper is of super niche interest and the vulnerability comes down to a popular configuration being vulnerable, but a hardened configuration is possible, but requires randomizing some data that folks tend to leave non-random because it’s the lazier way to set that up and it wasn’t formerly recognized that the randomness of the data had security implications.

  • It’s not so new anymore, however, it is widely known as an “easy” way to a strong six-figure salary, so we have a lot of gold-rush mouth-breather idiots that never would have gotten into this in the first place if not for the dollar signs. Really started to turn south around the time dot-com inspired early career people to get in on the bubble.

  • I’ve met two sorts of dedicated cybersecurity experts:

    The sort that only understands how to click ‘scan’ in various tools and repeat output and browser error messages without understanding nuance. Had a fun incident where the nuance really mattered in interop with a popular product in my niche, company said we must not implement the interop because it was hopelessly insecure. When I pushed back on the nuance (folks behind the ‘vulnerable’ tech had way much more sway in the market than we did), got told I should really educate myself and read the paper on the vulnerability to understand that my proposol to workaround it was impossible. For one glorious moment in my career, I got to tell them to look at the paper again and specifically the author (I had written up the vulnerability in the first place). After a brief shock though, he still went back to even though I may have found it and explained in key detail, I still must not understand the implications…

    Then there’s those that understand and can engage in nuance, but will still say inaccurate stuff, because they’ve learned being accurate and precise with the lay person doesn’t work too well, and easier to just say “big scary” instead of explaining precisely the threat model and rationale. I will confess on a number of threads I have seen this happen and let it go without correction because correcting wouldn’t have changed the core of the material, but would make the discussion go on even longer and waste more time. I personally can’t bring myself to outright say the wrong things, but I do understand why it’s the more practical strategy sometimes.

  • In an ideal world, they would be using TLS with a properly set up CA even for internal.

    In practice, I can’t get most of them to do that, and instead they just click through the certificate warning and use it over https, but without certificate assurance.

    So it’s still over https, though a fair argument can be made that hardly matters if the certificates aren’t validated, and browser ecosystem doesn’t consider ‘TOFU’ a valid approach like it generally is for SSH.

    Anyway, the point is that passkeys are ‘security’ by virtue of not ever divulging the secret on the line. They can’t be sniffed, they can’t be captured by phishing, they can’t be retained for later use after a MITM. So the refusal to operate even with informed user consent means the user just uses a password, which is weak to all those things. In a scenario where it could provide the most mitigation is a scenario where the browsers refuse to let it try. Even the built in password manager will still auto-fill without certificate validation, one of the most risky places to be ‘helpful’.

  • One complaint I have is browser insistence that a site must have a proper certificate to work at all.

    I provide self hosted software with passkey support and probably over 90 percent of my users never set up property certificates due their private networks. So the passkey function is impossible for them.

    Which means they must use passwords. Which are far worse in this scenario. The practical risk either way is arguably low for them, but to take a more mitm/phishing resistant technique and then force it to not work because mitm or phishing might be in play…

  • One complaint I have is browser insistence that a site must have a proper certificate to work at all.

    I provide self hosted software with passkey support and probably over 90 percent of my users never set up property certificates due their private networks. So the passkey function is impossible for them.

    Which means they must use passwords. Which are far worse in this scenario. The practical risk either way is arguably low for them, but to take a more mitm/phishing resistant technique and then force it to not work because mitm or phishing might be in play…

  • If SQRL was adopted, then the popular manifestations would have just as much vendor lockin, with built in password managers hosting the master private key without export option.

    Passkey is not inherently vendor lock in. It’s mostly a consequence of password managers doing software passkeys and not making it reasonable to export private keys. It does have a mechanism a site can use to lock to “trusted vendors”, but if a site does that, that is on them for being dickish.

  • Heh, reminds me of an email thread. Someone stated a fairly straightforward, clear, and actionable course of action.

    Then someone followed up with a GenAI email basically trying to be a sycophant to the person who wrote the plan and agreeing with them.

    A VP did not get excited by the person that actually plainly declared what to do, but did announce that he was going to set up a meeting with the sycophant because he displayed so much insight, despite only repeating the first guy in a more confusing and buzzwordy way.

    The AI generates corpo-speak in a very exciting way that further exacerbates an existing problem of promoting the wrong people.

  • The problem in my experience isn’t as much the work forcing it, it is the people who are very enthusiastic because they didn’t know what to do and now they think the AI does it for them, but they still have bad ideas.

    Think of the person who has this “great app idea” but just needs a developer to write it. Well now these messes are having GenAI churn out… something. They don’t know if it works or not, but now all they need is someone to help finish off the “essentially done” work, or to accept the pull request the AI generated for your project.

    Similar story for the creative content like videos and text. These people were limited by not having enough care to bother to learn or invest the time, but they thought they had amazing ideas. Now we see their uninspired slop bright to life in painful time killing form. The ones that might use it as just an accelerator but care about the output are drowned out by the “prompt and it’s done” folks that just don’t care.

  • Another interesting thing to consider.

    To be clear, he is rich. But he’s not crazy crazy rich, like nowhere near billionaire status.

    With that in mind, his kernel is a key component of RedHat’s, SuSE’s and Canonical whole business, with at least two of those being multi billion dollar businesses.

    His kernel is a key component of Android phones, which represent over 50 billion a year in hardware spend, and a bunch of software money on top of that.

    His kernel is foundational to most hosting/cloud services with just mind blowing billions of revenue quarterly.

    It’s used in almost every embedded device on the planet, networking gear, set top boxes, thermostats, televisions, just nearly everything.

    People with a fraction of that sort of relevance are billionaires several times over. A number of billionaires owe much of their success to him. Yet he is not among their numbers.

    Now there’s more to things than just a kernel to be sure, but across the hundreds of billions of dollars made while running Linux, there was probably plenty of room for him to carve out a few billion for himself were he that sort of person, but he cares about the work more than gaming the dollars. I have a great deal of respect for that.

    Means that while he may not always be right, but I at least believe his assessments are sincere and not trying to drive some grift or cover some insecurity about being left behind.