Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)G
Posts
1
Comments
439
Joined
3 yr. ago

  • FYI: Ed Zitron is a PR expert. He has no background in engineering or finance.

    I'm not super interested in people's credentials (good or bad). I need for the actual substance of the words on the page to be well supported and well reasoned.

    Zitron does the work of actually gathering the public statements (across SEC filings, public disclosures, public or leaked documents) and crafting a narrative around those statements. He links to original source documents a lot. Other people should be doing the same, but for whatever reason not a lot of other people are.

    He needs an editor. His articles could be better organized, more tightly argued, and more focused in scope.

    I have some skepticism about many of the extrapolations that he makes from the facts, but on my read, his factual claims are mostly well supported. When he calls other people liars by showing those contradictions out in the open, I think those arguments stand for themselves regardless of what his background, credentials, or even motivations are. So I draw a line between his factual claims about the past and present and his predictions about the future.

    And that's the reason for this thread. He makes factual claims about the exponential rise in costs for these companies, and infers/extrapolates into the future with it, but I want to check whether those extrapolations actually fit the data we already can see. That's what I'm trying to learn by asking here.

    Of course, if you have specific examples of him making false statements about the past or present (no need to attribute intentionality to the speaker), I'd love to see those, too.

  • Thanks, this is great.

    I’ve found that very few people are asking this question. And when I ask people what they think is happening to these costs over time, their opinions vary wildly.

    I'm similarly baffled. How is it that this industry generates so much discussion, but nobody is asking this fundamental question, with an ecosystem of comments, discussions, critiques, and corrections on those analyses?

  • New technology has always been horribly inefficient, it’s only once more people see it does it start to get optimized.

    Well, I wonder if the frontier ends up looking like supersonic commercial flight (prohibitively expensive so that there wasn't enough of a market for consumers at the actual cost of providing the service): technology that continues to exist but never really gets used, because the alternatives that aren't as good are still much, much cheaper.

  • Who cares if the not all companies or investors make money?

    I care about the downstream effects on everyone else, of who else gets hurt in a crash.

  • MacOS ran out of cats at some point. Android ran out of desserts.

    Ubuntu had no problem rolling over with the letters of the alphabet, but I imagine some letters may pose issues at some point when you run out of identifiable animals that start with that letter. Although they were already going with a lot of obscure animals to begin with.

  • The compose key combinations are great because they're easier to remember, because the codes are grounded in some kind of relationship between the character and the keys used.

    Alt codes are just memorized combinations of numbers, and that's not as easy.

  • A 2018 MBP should be good for MacOS 15 Sequoia, which still runs updated Firefox. I'm still running Sonoma (the version before that) and I use Firefox as my primary browser.

  • Testing a bunch of linux distros on old intel macbooks has shown me that apple is really good with resource management on their vertically integrated hardware, even with greedy daemons like identityserverd or whatever it is, trolling through your drive cataloguing faces in your photos all the time, and the relentless indexing system, and telemetry.

    It's really amazing to me how little power MacOS uses in normal use, compared to running Linux on the same machine. The Asahi Linux project also has documented a ton of interesting bits of hardware that MacOS makes use of, pretty seamlessly, that they've gotta figure out.

  • Ah yeah. Plus apparently Android's default SELinux configuration blocks this separately, as well.

  • Android doesn't have su, which this proof of concept exploit requires. Although rooted Android does, so in theory malware written for rooted Android could escalate to root privileges.

    Also, the underlying vulnerabilities might be exploitable without su but I don't fully understand the AF_ALG and authencesn bug limits things, or what other executables can escalate privileges.

  • I'm not terrified because there's nothing to be afraid of. but there are dumb, evil little men creating these issues.

    Drunk drivers on the highway are terrifying, precisely because they're so bad at what they're doing, and are behind the controls of dangerous machines they shouldn't have been trusted with.

    The AI tech execs can hurt us, so it is concerning.

  • AI avatar man wants you to be afraid: "sleeper agents"! "backdoors"! "poisoned documents"! Terrifying!

    It is terrifying. People in positions of power have placed entirely too much trust in these machines that are this easily fooled. I'd argue that we shouldn't trust these machines as much as they are, but I don't think the rest of the world is listening enough to these warnings.

    I also worry about how broken search result rankings have gotten. For someone like me who doesn't use these AI products, it concerns me that actual search engines (which I do use) continue to get worse.

    Sure, there are lessons here for those who build and maintain LLMs, but everyone else should still be terrified at how the world is moving towards, rather than away, this nonsense.

  • It's really important for people to understand that E2EE cannot protect the message portions that aren't between the ends themselves. The best encryption in the world can't help you if the person you're talking to is an undercover cop, because that "end" can do with the plaintext whatever they want, including record/store/forward the plaintext of any messages they then encrypt and send, or any messages they receive and then decrypt.

    That's not a flaw of the E2EE protocol itself, but is a limit to the scope of protection that E2EE provides.

  • Here's the original reporting, instead of another website's summary of Bloomberg's actual report:

    https://www.bloomberg.com/news/articles/2026-04-28/us-ends-investigation-into-claims-whatsapp-chats-aren-t-private

    https://archive.is/sGE3e

    So it sounds like the agent was investigating allegations, from content moderation contractors, that Meta could access the contents of WhatsApp messages, and came to the conclusion that yes, Meta could.

    There are a few possibilities here.

    1. Meta does have full plain text access to all Whatsapp messages, but guards that access very closely. Although the clients seem to generate E2EE keys for each session, somehow they're leaking those keys to Meta's servers somewhere, and the closed source code sufficiently hides that so that there's no whistleblower or security researcher able to detect this definitively.
    2. Meta has a secret wiretap functionality where they can compromise the E2EE keys somehow, but uses it only for narrow cases. This helps keep the functionality secret, because security researchers and other reviewers may never see the functionality in action.
    3. Meta allows users to report objectionable content in the threads they're already part of. The reporting function either forwards the E2EE key itself, or all the plaintext data, that gives content moderators access to the underlying message contents. The contractor whistleblowers and the federal agent investigating these allegations simply got it wrong, and misunderstood the technical process of how the plaintext messages end up in the content moderator's possession.

    Meta claims that it's #3. They acknowledge they have plaintext access to messages when a party to the thread presses the report button.

    This unnamed federal agent believes it's #1, after 10 months of investigation, and sent out an email to other investigators that they should look into that possibility.

    I'm skeptical of #1, simply because I don't believe that conspiracies to keep that kind of stuff secret can be maintained. It's not just that there would be technically skilled whistleblowers who have actual access to the code (not the non-technical content moderator contractors who review the content), but a weakness in such an important and widely used protocol would attract all sorts of hackers, state sponsored or otherwise.

    But option #2 might explain everything we've seen so far. Full wiretap capability that is rarely used and very tightly controlled.

  • Anybody who believed that quantum computing posed a risk to symmetric encryption was fundamentally misunderstanding how encryption works and what quantum computing might be good at one day.

    Asymmetric cryptography is primarily used for the secure exchanging of symmetric keys: use a public/private key pair to exchange secure messages of what symmetric key to use for their session, and then both sides switch to the symmetric key for actual communication of a real payload.

    A public/private key pair is two keys that have some interesting mathematical relationship, such that it is easy to confirm that someone possesses the right private key using the public key or to encrypt something that only the correct private key can decrypt. And that mathematical relationship, relating to the product of two very large prime numbers, is at the core of modern asymmetric cryptography.

    Quantum computing may make number factorization much, much easier. So once a product of two large primes becomes possible to factor, the public/private key pairs might not be as secure anymore.

    But none of this has anything to do with symmetric encryption, or hash functions. Quantum doesn't move the needle on that particular math.

    The real risk, though, is for an adversary to eavesdrop on an encrypted key exchange (which uses asymmetric cryptography) and then the message itself (which uses symmetric cryptography) and then be able to take the two steps of getting the secret symmetric key from the intercepted key exchange over a compromised asymmetric protocol, and being able to decrypt the symmetric portion of the communication too.

  • This is actually a pretty common concern for businesses on dealing with whether and how to protect themselves when installing improvements, business-critical equipment, or other hard-to-move stuff on land or in a building without a long term lease in place.

    The tenant deals with it by either building out a portable infrastructure to where they can move their business quickly if need be, or by protecting themselves legally to where the landlord can't kick them out on a short notice, by negotiating a long term lease.

  • Yes, this has everything to do with AI, because this is an AI vendor locking out a customer from their ordinary workflow.

    At the same time, this is a generalizable example not limited to AI, where any form of vendor lock-in on a critical business function becomes a potential point of failure when the vendor drops the customer or stops working. It's true of a cloud provider, an email provider, an ISP, any software provider that can revoke access/authority, or even non-tech vendors like a landlord or a temp agency or an electric utility.

  • I think it's worth being clear about the scope of the rating. iFixit has always been about repairability defined by parts availability, and its ratings consider software restrictions only to the point where it interferes with the user experience when replacing parts to restore things to the original performance.

    Customizability (in software or otherwise) isn't part of the score. Durability/longevity isn't part of the score, either. Those are things that I want, too, but I can recognize those are outside the scope of what iFixit advocates for.

    I do have some concerns about the partnerships creating a conflict of interest, but sometimes that feedback loop is helpful for improving the product, where the maintainer of a standard also has a consulting business in helping others meet that standard. Ideally there's a wall between the two sides (advisors versus raters), but the mere fact that one company might do both things isn't that big of a deal in itself.

  • briefly released millions of tracks that were scraped from Spotify via BitTorrent.

    That's just an awkward sentence construction but it makes sense: they released track via Bittorrent. The tracks were scraped from Spotify.

    I sold my car that was purchased from a dealership via private party sale.

    I charged my laptop that normally accepts 100W via a 20W phone charger.

    I would've used a "which" phrase with commas to avoid the confusion, but the sentence as written is valid and makes sense.

  • You can reason from a few principles:

    • At its core, the math functions being optimized by these AI tools and their specialized hardware is that they can perform inference and pattern recognition at huge scales across enormous data sets.
    • Inferring a rule set for pattern also allows generation of new data that fits that pattern.
    • Some portion of human cognitive work falls within the general framework of finding patterns or finding new data that fits an old pattern.

    So when people start making claims about things with clear, objective definitions (a win condition in chess, the fastest route to take through a maze, a highest lossless compression algorithm for real world text), it's reasonable to believe that the current AI infrastructure can lead to breakthroughs on that front. So image recognition, voice recognition, and things like that were largely solved a decade ago. Text generation with clear and simple definitions of good or bad (simple summaries, basic code that accomplishes a clearly defined goal) is what LLMs have been doing well.

    On things that have much more fuzzy or even internally inconsistent definitions, the AI world gets much more controversial.

    But I happen to believe that finding and exploiting bugs or security vulnerabilities falls more into the well defined problem with well defined successes and failures. So I take it seriously when people claim that AI tools are helpful for developing certain exploits.