Unsure how federation does this. Moving to eviltoast.org instance if anyone cares to find me there.
so... you do want face verification for online interactions?
edit: In-person, for a "regulated" substance - it seems reasonable to require that proof be checked as part of policy, regardless of appearance. There's no storage (in most cases) and the cashier is the only one who looks at the ID and they are supposed to do it to keep their job. The only place I've seen recently where your ID is actually tracked is stuff like sudafed, where buying too much makes you a potential meth maker.
Online, the rule has been "trust me, bro" forever. There's no person testing you, aside from maybe a paywall to ensure you have a credit card as an age check. Steam is doing the online equivalent of minimal validation and minimal retention that the booze store is.
This is hardly OMGVALVE.
No shit. I now work from home, but my last cubicle was half that size and had no walls. That's a god damn luxury cube!
Not just the primaries! My city is pretty purple. We tend to vote republican by a slim majority in larger races (think 51/49), but in the mayor and city council race that just happened, the republican mayor won at like 66/33. Vote every chance or you cede your power to the people who do.
The fix is to start local. Bob's right: that school PTO experience will be on the candidate's bio when they run for mayor, even if they are the karen-est karen, and it will sway a few people. That (R) mayor has power over a huge amount of how the city is run and many of the things people are locally unhappy with are a direct result of them electing a rich asshole. If we elect Dems locally, we might be able to sway people to our side when the situation gets better under our leadership.
We individuals have the power but it's got a bit of a lag-time to it. Become informed about how the DNC structure works (best done by joining your local precinct, even if you do nothing more than joining a few meetings). The precincts vote for who runs the county, the counties vote for who runs the state, the states vote for the nation and it's all based on head-count of participants: a large precinct by population might only have a relative few people engaged and will not have as large an impact when voting in upstream elections. If we're mad at DNC leadership or the options we have for congress/president, the fix is to ensure people at the precinct-level are the right ones.
This comment is a direct response to anyone saying "both sides", "dem's are still corporate shills", or similar defeatist comments. The "spineless dems" currently have power at the top of the party, but we can fix that. It will take work. It will require time, and that time will be hard to justify with little immediate result. This is the battle we need to fight right now, though. It just needs to be constant and not only complaining online and voting every 2-4 years.
While I believe that this is accurate, as a broad stroke and specifically of the DNC itself, any individual democratic politician is not necessarily corrupt and playing a foil. Especially as you get more and more local.
Don't let cynicism prevent you from voting for a local candidate for mayor or city council, for example. It'll take time to see if Mamdani is what he claims to be, but it's not unreasonable for someone who is mad at the current situation to run for office with a real intent to improve things.
The way we fix things is by getting the local orgs to throw their weight around. Those precinct orgs get votes in the district and district vote in state and state vote nationally. If you're mad right now or were mad in 2020, then get involved. Find your local democratic organization and become the change. Under our Representative Democracy, we don't always directly elect our leadership, but we do get to elect the people that elect the people that elect the people... Gotta start at the bottom and ensure that first step has our values in mind. Right now, too many people only get involved every 2-4 years and are mad at the results.
"President" and "Senator" are important titles, but so is "County Chair". Doing this and pushing the Democratic party further left will be more effective than sending a protest vote for a third party every 4 years, but you can do both.
I'm happy you provided a few examples. This is good for anyone else reading along.
Equifax in 2017: Penalty was, let's assume the worst case, 700$M. The company in 2017 made 3.3$B, and I'd assume that was after the penalty, but even if it wasn't, that was a penalty of 27% of revenue. That actually seems like it would hurt.
TSB in 2022: Fined ~48.6£M by two separate agencies. TSB made 183.5£M in revenue in 2022, still unclear if that was pre- or post- penalty, but this probably actually hurt.
Uber in 2018: your link suggests Uber avoided any legal discovery that might have exposed their wrongdoing. There are no numbers in the linked article and a search suggest the numbers are not public. Fuck that. A woman was killed by an AI driven car and the family deserves respect and privacy, but uber DOES NOT. Because it's not a public record, I can't tell how much they paid out for the death of the victim, and since uber is one of those modern venture-capital-loss-leader companies, this is hard to respond to.
I'm out of time -- and won't likely be able to finish before the weekend, so trying to wrap up -- and Boeing seems complicated and I'm more familiar with Crowdstrike and I know they fucked up. In both cases, I'm not sure how much of a penalty they paid out relative to income.
I'll cede the point: There are some companies who have paid a price for making mistakes. When you're talking companies, though, the only metric is money-paid/money-earned. I would really like there to be criminal penalties for leadership who chase profit over safety, so there's a bit of 'wishful thinking' in my worldview. If you kill someone as a human being (or 300 persons, Boeing), you end up with years in prison, but company just pays 25% of it's profit that year instead.
I still think Cassandra is right, and that more often than not, software companies are not held responsible for their mistakes. And I think your other premise, that 'if software is better at something' carries a lot: Software is good at explicit computation, such as math, but is historically incapable of empathy (a significant part of the original topic... I don't want to be a number in a cost/benefit calculation). I don't want software replacing a human in the loop.
Back to my example of a flock camera telling the police that a stolen car was identified... the software was just wrong. The police department didn't admit any wrongdoing and maaaaybe at some point the victim will be compensated for their suffering, but I expect flock will not be on the hook for that. It will be the police department, which is funded by taxpayers.
Reading your comments outside this thread, I think we would agree on a great many things and have interesting conversations. I didn't intend to come across as snide, condescending or arrogant. You made the initial point, cassandra challenged you and I agreed with them, so I joined where they seemed not to.
The "bizarre emotion reaction" is probably that I despise AI and want it nowhere near any decision-making capability. I think that as we embed "AI" in software, we will find that real people are put at more risk and that software companies will be able to deflect blame when things go wrong.
The burden of proof is on you. Show me one example of a company being held liable (really liable, not a settlement/fine for a fraction of the money they made) for a software mistake that hurt people.
The reality is that a company can make X dollars with software that makes mistakes, and then pay X/100 dollars when that hurts people and goes to court. That's not a punishment, that's a cost of business. And the company pays that fine and the humans who mode those decisions are shielded from further repercussions.
When you said:
the idea that the software vendor could not be held liable is farcical
We need YOU to back that up. The rest of us have seen it never be accurate.
And it gets worse when the software vendor is a step removed: See flock cameras making big mistakes. Software decided that this car was stolen, but it was wrong. The police intimidated an innocent civilian because the software was wrong. Not only were the police not held accountable, Flock was never even in the picture.
It seemed somewhat topical to me. Google's censorship is the same trend of enshittification that Yar is talking about.
There are tons of other comments talking about the censorship issue. Using this moment to plug open source software is not unreasonable.
We can learn a few things from the French. They seem to have good ideas about how to protest for sure.
A question: How do you think you get to the point where the quiet majority feels confident enough to show up in force? To 'disrupt the system'?
We Americans, by our own devices, have become a very insular people. We have social media, which puts us all in our little bubbles and cellphones, which distract us from the actual people around us. We sit in despair about rising prices and the tragedies inflicted on ourselves or our neighbors, our world. We watch our rights get eroded.
These protests are a symbol that we are not alone. That there are others out there that are also mad. These protests burst the bubble that technology has trapped us in. Read through the comments with this in mind: How many people were surprised at the turnout being larger than expected. And for each of those, there's a comment indicating it could be larger. As we come to terms with how many allies we have, we gain collective power. Sure, we have it now, but we're not willing to wield it yet. Building the confidence that you will be one among many is the key to wielding that power. Ten people protesting will be intimidated by the local police. Ten thousand will intimidate the police instead. Ten million will intimidate the government.
I write actual responses to throwaway comments all the time. I don't do this for Auli or Fresh, I do this for those that might agree with you on the surface. This protest was not intended to make immediate change. It was intended to build pressure, to unite the people and to show support for the cause. When we show up and make a scene, we provide a shield for those who are not as willing to be in front to join in. When they join in, we grow and are able to pull in even more. Every thumbs-up from a car is someone who is on our side, but due to life commitments or fear did not attend... this time.
Edit: Followup: If you want faster change... do it. What's your idea? Build a movement and implement or shut the fuck up. You might find that it's hard to find other people willing to risk their safety and arrest to block a street, or to risk losing their job to strike with only a few people involved. When we have the numbers to make the system fear what we could do, we will win, even if we never have to do it.
I'm going to expand on TrickDacy's comment:
Every both sideser is either extraordinarily lazy or a closeted right winger
and instead state: It is OKAY to be mad at democratic politicians. Especially the spineless ones we have an abundance of right now. And there is certainly some rage we can all aim at the DNC as an organization, which appears to be trying to hamstring any actually progressive candidates.
But there really isn't a competition in the race for 'who is most evil' between D and R. One side is at least appearing to fight for worker rights, healthcare, equality, peace and other progressive/liberal goals. The other side is actively dismantling the government... like actively and they told us they were going to. There's no both sides here.
So, by 'closeted right winger', what I think Trick means is that anyone boldly claiming 'both sides' falls into one of a few categories:
- lazy: Doesn't "do politics" and gets their news from tiktok, fox, cnn, their buddy at work, and doesn't put in the critical thinking to make their own decisions. "Both Sides" lets them get away with not caring enough and just moving on with life.
- gullible: Believes they are thinking critically, but are swayed by media, social or conventional, into thinking that all politicians are shit, and if one is corrupt then they all are.
- malicious: Knows they are being disingenuous, but knows the other categories exist. If they claim 'both sides' are doing something, then when one side actually gets caught doing it, the public just kinda shrugs it off. This also depresses voter turnout in general, because of the lazy group.
So. What is your purpose in your post. Are you lazy, and just know that democrats also suck, but want to sound smart on the internet? Are you gullible, and really think that democrats would be just as bad if they had power? Or are you malicious, and trying to make the people that would otherwise "do politics" give up and become lazy?
If you are not trying to make people give up, STOP. There is no both sides. There is the fascist, authoritarian, oligarchic, billionaire side, and then there are the people. If you want to make a real difference and move the needle, then the time is now, but it's not in a forum post saying 'both sides are bad.' It's going to be in your local democratic organization, trying to find candidates to run for local or regional offices and then supporting them. The people THERE are definitely on our side, since they are just us. And if we can build strong networks THERE, then we can push people into the national stage who will also fight for us.
The democrats who act like republicans need a strong local network to primary them. Be the change you want to see.
Thanks for your reply, and I can still see how it might work.
I'm curious if you have any resources that do some end-to-end examples. This is where I struggle. If I have an atomic piece of code I need and I can maybe get it started with a LLM and finish it by hand, but anything larger seems to just always fail. So far the best video I found to try a start-to-finish demo was this: https://www.youtube.com/watch?v=8AWEPx5cHWQ
He spends plenty of time describing the tools and how to use them, but when we get to the actual work, we spend 20 minutes telling the LLM that it's doing stuff wrong. There's eventually a prototype, but to get there he had to alternate between 'I still can't jump' and 'here's the new error.' He eventually modified code himself, so even getting a 'mario clone' running requires an actual developer and the final result was underwhelming at best.
For me, a 'game' is this tiny product that could be a viable unit. It doesn't need to talk to other services, it just needs to react to user input. I want to see a speed-run of someone using LLMs to make a game that is playable. It doesn't need to be "fun", but the video above only got to the 'player can jump and gets game over if hitting enemy' stage. How much extra effort would it take to make the background not flat blue? Is there a win condition? How to refactor this so that the level is not hard-coded? Multiple enemy types? Shoot a fireball that bounces? Power Ups? And does doing any of those break jump functionality again? How much time do I have to spend telling the LLM that the fireball still goes through the floor and doesn't kill an enemy when it hits them?
I could imagine that if the LLM was handed a well described design document and technical spec that it could do better, but I have yet to see that demonstrated. Given what it produces for people publishing tutorials online, I would never let it handle anything business critical.
The video is an hour long, and spends about 20 minutes in the middle actually working on the project. I probably couldn't do better, but I've mostly forgotten my javascript and HTML canvas. If kaboom.js was my focus, though, I imagine I could knock out what he did in well under 20 minutes and have a better architected design that handled the above questions.
I've, luckily, not yet been mandated that I embed AI into my pseudo-developer role, but they are asking.
I think this is what will kill vibe coding, but not before there's significant damage done. Junior developers will be let go and senior devs will be told they have to use these tools instead and to be twice as efficient. At some point enough major companies will have had data breaches through AI-generated code that they all go back to using people, but there will be tons of vulnerable code everywhere. And letting Cursor touch your codebase for a year, even with oversight, will make it really tricky to find all the places it subtly fucked up.
I have 3 questions, and I'm coming from a heavily AI-skeptic position, but am open:
- Do you believe that providing all that context, describing the existing patterns, creating an implementation plan, etc, allows the AI to both write better code and faster than if you just did it yourself? To me, this just seems like you have to re-write your technical documentation in prose each time you want to do something. You are saying this is better than 'Do XYZ', but how much twiddling of your existing codebase do you need to do before an AI can understand the business context of it? I don't currently do development on an existing codebase, but every time I try to get these tools to do something fairly simple from scratch, they just flail. Maybe I'm just not spending the hours to build my AI-parsable functional spec. Every time I've tried this, asking something as simple as (and paraphrased for brevity) "write an Asteroids clone using JavaScript and HTML 5 Canvas" results in a full failure, even with multiple retries chasing errors. I wrote something like that a few years ago to learn Javascript and it took me a day-ish to get something that mostly worked.
- Speaking of that context. Are you running your models locally, or do you have some cloud service? If you give your entire codebase to a 3rd party as context, how much of your company's secret sauce have you disclosed? I'd imagine most sane companies are doing something to make their models local, but we see regular news articles about how ChatGPT is training on user input and leaking sensitive data if you ask it nicely and I can't imagine all the pro-AI CEOs are aware of the risks here.
- How much pen-testing time are you spending on this code, error handling, edge cases, race conditions, data sanitation? An experienced dev understands these things innately, having fixed these kinds of issues in the past and knows the anti-patterns and how to avoid them. In all seriousness, I think this is going to be the thing that actually kills AI vibe coding, but it won't be fast enough. There will be tons of new exploits in what used to be solidly safe places. Your new web front-end? It has a really simple SQL injection attack. Your phone app? You can tell it your username is admin'joe@google.com and it'll let you order stuff for free since you're an admin.
I see a place for AI-generated code, for instant functions that do something blending simple and complex. "Hey claude, write a function to take a string and split it at the end of every sentence containing an uppercase A". I had to write weird functions like that constantly as a sysadmin, and transforming data seems like a thing an AI could help me accelerate. I just don't see that working on a larger scale, though, or trusting an AI enough to allow it to integrate a new function like that into an existing codebase.
I'd wager that the votes are irrelevant. Stock overflow is generously <50% good code and is mostly people saying 'this code doesn't work -- why?' and that is the corpus these models were trained on.
I've yet to see something like a vibe coding livestream where something got done. I can only find a lot of 'tutorials' that tell how to set up tools. Anyone want to provide one?
I could.. possibly.. imagine a place where someone took quality code from a variety of sources and generate a model that was specific to a single language, and that model was able to generate good code, but I don't think we have that.
Vibe coders: Even if your code works and seems to be a success, do you know why it works, how it works? Does it handle edge cases you didn't include in your prompt? Does it expose the database to someone smarter than the LLM? Does it grant an attacker access to the computer it's running on, if they are smarter than the LLM? Have you asked your LLM how many 'r's are in strawberry?
At the very least, we will have a cyber-security crisis due to vibe coding; especially since there seems to be a high likelihood of HR and Finance vibe coders who think they can do the traditional IT/Dev work without understanding what they are doing and how to do it safely.
This is my fear. It's still possible, barely, to buy a dumb TV. When my current fridge/dishwasher/stove/etc dies in a few years, will there even be a dumb version? Will it cost 5x the price of a spyware version? How about my thermostat. HVAC? Car? And will attempting to disable any of this spyware land me in prison?
Right now, uninformed/unaware/stupid people are affected by this. Pretty soon, everyone will be, or they will have to forego things we consider to be necessities now, like refrigeration and cell phones or be rich enough to buy the privacy-focused models.
I can't immediately find it, but I just saw another post about a new privacy-focused cellphone with a huge price tag. The established manufacturers have a cost advantage. Samsung et al. can easily make a new fridge with fewer consumer rights, but a new company will have to spend tons of capital to make a factory to put out a comparable product; and they won't have the advantage of selling your data to subsidize the price.
Privacy is and will become more-so a commodity unless we fight for it.
This was an interesting article. I'm not a service provider, nor in the EU, so I have little personal exposure to this change. I like the customer freedom it will probably provide me as splash damage, though.
The thing I really want to call out is the tone of the article: "This thing we relied on is going away. Instead of gnashing your teeth and being mad, here's how to leverage it to make your offering more attractive than your competition."
- JumpDeleted
Permanently Deleted
That new hire might eat resources, but they actually learn from their mistakes and gain experience. If you can't hold on to them once they have experience, that's a you problem. Be more capitalist and compete for their supply of talent; if you are not willing to pay for the real human, then you can have a shitty AI that will never grow beyond a 'new hire.'
The future problem, though, is that without the experience of being a junior dev, where do you think senior devs come from? Can't fix crappy code if all you know how to do is engineer prompts to a new hire.
"For want of a nail," no one knew how to do anything in 2030. Doctors were AI, Programmers were AI, Artists were AI, Teachers were AI, Students were AI, Politicians were AI. Humanity suffered and the world suffocated under the energy requirements of doing everything poorly.
I fully agree: Companies and their leadership should be held accountable when they cut corners and disregard customer data security. The ideal solution would be that a company is required to not store any information beyond what is required to provide the service, a la GDPR, but with a much stricter limit. I would put "marketing" outside that boundary. As a youtube user, you need literally nothing, maybe a username and password to retain history and inferred preferences, but trying to collect info about me should be punished. If your company can't survive without targeted content, your company should not survive.
In bygone days, your car's manufacturer didn't know anything about you and we still bought cars. Not to start a whole new thread, but this ties in to right-to-repair and subscriptions for features as well. I did not buy a license to the car, I bought the fucking car; a license to use the car is called a lease.
I understand what you are saying, and what you want... but admitting fault publicly is a huge liability, as they have then stated it was their negligence that caused the issue. (bear with me and read this wall of text -- or skip to the last paragraph)
I've worked in the Sec Ops space, and it's an arms race all the time. There are tools to help identify issues and breaches quickly, but the attack surface is just not something that can be managed 100%. Even if you know there is a problem, you probably have to send an issue to a developer team to update their dependency and then they might need to change their code as well and get a code review approved and get a window to promote to production. A Zero-Day vulnerability is not something you can anticipate.
You've seen the XKCD of the software stack where a tiny peg is propping up the whole thing? The same idea applies to security, but the tiny peg is a supply chain attack where some dependency is either vulnerable, or attacked by malicious actors and through that gain access to your environment.
Maybe your developers leverage WidgetX1Z library for their app, and the WidgetX1Z library just updated with a change-log that looks reasonable, but the new code has a backdoor that allows an attacker to compromise your developers computer. They now have a foothold in your environment even with rigorous controls. I've yet to meet a developer who didn't need, or at least want, full admin rights on their box. You now have an attacker with local admin inside your network. They might trip alarms, but by then the damage might be done and they were able to harvest the dev database of user accounts and send it back home. That dev database was probably a time-delayed copy of prod, so that the developer could be entirely sure there were no negative impacts of their changes.
I'm not saying this is what happened to Plex, but the idea that modern companies even CAN fully control the data they have is crazy. Unless you are doing full code reviews of all third-party libraries and changes or writing everything in-house (which would be insane), with infallible review, you cannot fully protect against a breach. And even then I'm not sure.
The real threat here is what data do companies collect about us? If all they have is a username, password and company-specific data, then the impact of a breach is not that big -- you, as a consumer, should not re-use a password. When they collect tons of other information about us such as age, race, location, gender, sex, orientation, habits, preferences, contacts, partners, politics, etc, then those details become available for anyone willing to pay. We should use breach notifications like this to push for stronger data laws that prevent companies from collecting, storing, buying or selling personal data about their customers. It is literally impossible for a company to fully protect that information, so it should not be allowed.
- JumpDeleted
Permanently Deleted
not a locksmith, but...
One of those candidates for 'worst memorable phrase in history' is the old "duct-tape for things that move and shouldn't and wd-40 for things that should move and don't".
WD-40 isn't a lubricant. It often works to get something un-stuck, but then you need to still clean and lubricate the parts to keep it working.
I hear that. My local ABC store doesn't scan my ID, though I don't see a future where they don't eventually scan every time; and my local grocery store scans occasionally, but not always.
I can't just not buy age-verified products, though, because sometimes it's cold medicine or a prescription. **
Back to the original thread, this is not a Discord problem, this is a privacy problem. We need to push back on data capture in general and tell legislators that privacy is important to all people, even those who buy booze.
* could we make little sneaky stickers that obfuscate the barcode enough to prevent it scanning? The cashier would likely revert to visual inspection without the data retention: face matches photo, age is good, override.