Same experience as quoted - I used to use it. Once you have it 'trained' it's good to know the bad stuff is not getting through but it's a pain to maintain and for every new site you visit it takes experimentation to get the right setup.
You really want to share the pain of setup with other privacy people which is how ublock works with its lists I think.
...[the group] has claimed responsibility for similar DDoS attacks on the likes of eBay's Japan and US divisions, as well as BlueSky in just the past month alone.
Why the group is targeting London-based Canonical remains unclear and no reason was given via its Telegram channel. It is presumably because Ubuntu is one of the most popular Linux distros.
For example, the Anthropic-claimed 181 Firefox exploits ran with the browser sandbox turned off and the FreeBSD exploit transcript "shows substantial human guidance, not autonomy."
Additionally, the "'thousands of severe vulnerabilities' extrapolates from 198 manually reviewed reports. The Linux kernel bug was found by Opus 4.6, the public model, not Mythos," Devansh said.
Another researcher, Davi Ottenheimer, pointed out that the security section (Section 3, pages 47-53) of Anthropic's 244-page documentation "contains no count of zero-days at all. With no CVE list, no CVSS distribution, no severity bucket, no disclosure timeline, no vendor-confirmed-novel table, no false-positive rate."
Ottenheimer likens it to "the ending of the Wizard of Oz, a sorry disappointment about a model weaponizing two bugs that a different model found, in software the vendor had already patched, in a test environment with the browser sandbox and defense-in-depth mitigations stripped out."
He's talking about a physical object, something you have on your desk that you can pick up and prove your identity to the person on the other end of the video call.
Reminds me of the 'totems' in Inception, except they were to prove to yourself you were not in a dream.
I assume they hope that their added license condition of an 'obligation to retain the original product logo' is a 'reasonable...author attribution' (AGPL section 7b). Hmm.
They invite the FSF to judge:
If FSF determines that our license and project align with AGPLv3, we will continue as an open-source initiative. However, if the decision goes against us, we are ready to consider other options.
The danger being raised with the licensing is that you can't license something if you're not considered to be the author. There are growing examples of courts and lawmakers determining AI output to be public domain:
The US Supreme Court recently refused to reconsider Thaler v. Perlmutter, in which the plaintiff sought to overturn a lower court decision that he could not copyright an AI-generated image. This is an area of ongoing concern among the defenders of copyleft because many open source projects incorporate some level of AI assistance. It's unclear how much AI involvement in coding would dilute the human contribution to the extent that a court would disallow a copyright claim.
This is an evolving, global situation and hard to know what to do right now. I think what you've got is fine though - you've made it clear your intention is to license with AGPL. It's just that depending on the jurisdiction it might be public domain instead.
This is another reason to be clear about the use of AI in the README so your users can make an informed decision.
Interesting, some effort required to keep it on track:
Claude can be very persistent when it really wants to do something. I’ve seen Claude run the contents of a make command when make itself is blocked, or write a Python script to edit a file it’s been told it can’t edit. But hooks at least offer better enforcement than prompting alone.
Ten years after the launch of qmail 1.0, and at a time when more than a million of the Internet’s SMTP servers ran either qmail or netqmail, only four known bugs had been found in the qmail 1.0 releases, and no security issues.
Wow that's bad. The original idea of standing up, I understand, was to keep the meeting short through physical discomfort and only speak of blockers to progress or ask for help. It is not meant to report status, which can make people feel like they have to continually justify themselves and their work.
The contention is that Mattermost say it's licensed under AGPL but then they add conditions which are incompatible with that license. So it seems they want to give appearance of AGPL but not give the actual rights that come with it. So therefore it's not AGPL.
Errors in command substitution e.g. $(cat file) are ignored by 'set -e', one example of its confusing nature. It does not force you to all handle errors, just some errors and which ones depends on the code you write.
Same experience as quoted - I used to use it. Once you have it 'trained' it's good to know the bad stuff is not getting through but it's a pain to maintain and for every new site you visit it takes experimentation to get the right setup.
You really want to share the pain of setup with other privacy people which is how ublock works with its lists I think.