they just wrote a paragraph about evil being easy, convenient and providing value, how the evilness of others legitimizes their own, how the inability to achieve absolute moral purity means that one small evil deed is indistinguishable from being evil all the time, discredited trying to avoid evil as stupid, claimed that only those who have unachievable moral purity should be allowed to lecture about ethics in favor of good, and literally gave a shout out to hell. I don't think property damage is what we need to worry about. Walk away slowly and do not accept any deals or whatabouts.
HN user
Jon_Lowtek
Our society has been hacked. Look around you: should it look like this? Don't let anyone tell you "it could be worse", demand it should be better! We need to patch. We can change everything, one system, one rule at a time. ~ Snowden
Social Media companies have actively and intentionally tried to make their products more addicting... now they have to face the very obvious consequences of that decision.
on desktop i had to click on the small black area between two pictures before scrolling with left/right arrows became possible ... very bad UX
The citizens of the USA need to modernize their concept of privacy. Defining it over private/public spaces comes from a time when mass surveillance was technologically unfeasible. Technology has changed, and so must the definition of privacy.
thought experiment: >> if they do not want their conversations in their living room recorded, parsed by automated language models running in our datacenters, and added to their permanent record, they shouldn't have a window to a public space that vibrates. All we are doing is being in a public space, spending billions of VC money to point laser microphones at all homes 24/7 collecting data that anyone in this public space could have collected. You can not outlaw that without outlawing 5 year old Timmy riding his tricycle down the sidewalk, because we are using his right to see the light from his lamp being reflected by the houses, to justify why our creepy business model isn't a violation of millions of peoples privacy. You can't have a reasonable expectation of privacy that allows little Timmy to see, but forbids our corporation to spy on everyone, not in america. We also send electromagnetic waves out on one side off your house and collect them on the other, so we can see you move inside your house. It is basically like ham radio, anyone could do it, little Timmy sends electromagnetic waves through your house when he talks to his friend on a walkie talkie. You think Timmy shouldn't be allowed to have a walkie-talkie? We just send them through all the homes, all the time, everywhere. No we are not on your property all our devices are in public spaces <<
The idea that, if a single piece of information could be collected by a human in a public space, then mass scale collection of that and similar information at all times and in all public spaces, for any purpose by a fully automated behemoth is fine, is insane.
The USA needs to amend its constitution to define the right to privacy in a way that declares mass surveillance and systematic profiling using non-consensual data gathering at scale illegal for being the nefarious violation of basic human rights that it is, before they completely loose what little privacy they have left when they hole up in their homes.
So your think that AI systems that pose a significant risk to basic human rights at scale, should not be subject to oversight and regulation, because that would be anti-human?
According to the "Huawei cyber security evaluation centre" (HCSEC) oversight boards annual report to the national security adviser of the United Kingdom (note: HCSEC was a joint lab between NSCS, GCHQ and Huawei with a lot of access to internal documentation and firmware source code and so on to check if they are telling the truth when they promised there is no backdoor for the chinese ministry of national security in the 5G equipment) their quality and basic security processes are so bad, that it is believable that all the vulnerabilities are unintentional. However they did improve in the years prior to being kicked out, so you are not wrong that it was somewhat of a bandwagon move following the us sanctions.
this is not a new issue: airbus has been the victim of corporate espionage supposedly by boeing with aid by the nsa in a well documented case in november 2011, and they are not the only victim of US government agency supported corporate espionage: investigations into the selector lists that ran in the cabinet noir at DE-CIX have shown that a large part of them were targeting european corporations. and that predates the cloud act of 2018, which made american infrastructure significantly less trustworthy.
typographic attacks against vision-language models are still a thing with more recent models like GPT4-V: https://arxiv.org/abs/2402.00626
the 24% increase has nothing to do with car size over time in europa.
Table 2 in the paper lists which cars where compared, and that 24% numbers is an average from comparing models where manufacturers offer EV and ICE variants.
"relatively clean" means 85% of PM2.5 is from non-exhaust sources, and 15% is from exhaust after catalytic conversion. In New York EV and ICE are pretty much on par when it comes to this category of pollution, as the additional weight increases non exhaust sources. Source: https://www.sciencedirect.com/science/article/abs/pii/S13522...
It is different in Africa, where catalytic converters are harvested for precious metals and cars are driven without them.
While that is the most common use case for CLAs, it is normally done by contributors granting a very permissive, but not exclusive, license to a legal entity like a company or foundation, in addition to the public license granted to everyone.
This is not that. This is not even a license. They want a full transfer of intellectual property ownership. Sure that enables them to use it in a commercial product, but it also enables them to sue if contributors contribute similarly to other projects. Obviously that would create a shit storm, and there is an exception with the public license, but riddle me this: can you legally make similar contributions to multiple projects that have this type of CLA?
Let us take a step back and instead look where such terms are more common: employment contracts.
has anyone tried the PoC for CVE-2025-12198 from that chinese site on a version more recent than rusty? It wants a signup with a mainland china phone number, and i only have a taiwanese fax machine.
The affected version 2.73rc6 is quite interesting, because it is from 2015, and it is not the version the relevant code was introduced in, that is even older (guessing 2.62). Why fuzz some random release candidate from ten years ago?
Even more interesting v2.77 from 2017 (commits 5614413 and 2282787 to be precise) changed the code and added an (++i == maxlen) check at the place that is being highlighted by CVE-2025-12198 as lacking an (i < maxlen) check. The commit message says it fixed a crash and thanks a friend for fuzzing the config file.
Now i am not well versed in heap smashing with C, so don't confuse my lack of skill with an expert opinion, but i have a hard time understanding how that check is circumvented in recent versions of the code. Any explanation would be welcome.
But more than that someone should verify if this PoC works in recent versions. As a prerequisite it should be shared internationally.
Consultation documents and published feedback: https://ec.europa.eu/info/law/better-regulation/have-your-sa...
The documents link the DMA page on the EC website: https://digital-markets-act.ec.europa.eu/consultation-first-...
Interestingly there is no published filing by Apple, yet, and the consultation is closed for two days. Maybe they filed late and publishing the feedback takes time, due to the EC reading it before putting it on their website. Or quite possibly Apple did not actually file anything as part of the official process and is instead publishing their opinion on their blog.
i only cited it as a side note for the upper bound. the more conservative estimate of the scientific service of the Bundestag still shows that your claim of zero subsidies is made up and unsubstantiated. Discrediting the radical other position and ignoring the center positions does not make your own radical claims true. I can give another source: "Aufstieg und Krise der deutschen Atomwirtschaft 1945-1975" by historian Prof. Dr. Joachim Radkau. However that one you have to get from a library, it describes in detail how the nuclear industry in germany was build and what role and subsidies the government provided.
For example in Germany, nuclear production was never subsidized at all.
Except financing research and development, guaranteeing loans to reduce default risk and interest rates, capping liabilities to enable insureability at lower rates by guaranteeing to fix damages in case of critical failures with public money, financing and organizing emergency civil protection measures, as well as waste disposal, granting massive tax cuts, doing the diplomatic leg work to import uranium and protecting its transport with the police, all and all summing up public spending on making nuclear energy in germany to 169,4 billion euros according to the scientific service of the Bundestag (Document Number WD 5 - 3000 - 090/21), with the more green leaning FOES calculating 304 billion. And on top of that it is estimated that another 100 billion in public money will be needed to fix up long term waste disposal sites morsleben and asse.
... well except from those few hundred billion euros they barely ever subsidize it at all.
i have not checked every service affected in Nepal, but i would assume most of them require a user account, which includes agreeing to a contract that establishes a b2c relation. Such a relationship does not necessarily require payment, and is not at all comparable to calling someone.
The EU is not a single mind, it is many party democracy. Yes there are forces in it that have been pushing for "lawful interception" for some time now. And they have always failed to ban E2E-encryption.
In the USA there exist similar forces who also introduced bills with similar ideas multiple times in the last decade. One of those is currently in congress.
Having direct business to consumer relations with the people of a country is doing business in that country, even if the multinational corporation claims otherwise
there is a difference between "russian" and "russian speaking" that is quite important to many eastern europeans that do not wish to be part of some kreml lead lingua-nation.
a rich and fascinating history. If i may recommend a wikipedia article: "Cabinet Noir", which includes: "by the 1700s, cryptanalysis was becoming industrialized"
Read the USAs "Communications Assistance for Law Enforcement Act" of 1994, it may change your mind. An FBI document from 2021 foiad by the property of the people org shows the FBI abilities to get information from encrypted messengers, which, simplified, shows that end2end encrypted services run by american corporations have backdoors for the american government. Which surprises no one, except patriots who never heard of the patriot act of 2001.
Little known fact: GDPR replaced the Data Protection Directive (95/46/EC) from 1995 which itself replaced the Convention for the Protection of Individuals with Regard to Automatic Processing of Personal Data, written in 1981. Now if you compare these three, there is enough details to get an undergrads degree in law, but on the high level the tenor did not change much. Those who were struggling in 2018 to meet GDPR criteria before the grace period of two years ended were most likely not struggling with details, but in blatant violation of almost 40 year old rules. Well one of the details probably mattered: the fines went up considerably.
Transferring data to non-eu countries is not by itself a violation, if there are provisions in place to ensure that the basic human rights concerning data privacy of european citizens are respected. The actual problem is that those are missing.
> I didn't believe in the premise that if someone doesn't pay their parent, that it means the child doesn't care about them. I don't understand why the respondent said that vicious straw man,
Children who emotionally care about their parents but are financially unable to assist are rarely going to say
go fuck yourself you greedy selfish bastard
i did not build that strawman, you did, i just set it on fire
And if you directly want a piece of the investment from the children, as people got in the old days, well then go fuck yourself you greedy selfish bastard
consider the following: if your children don't care about you, the societal structure of capitalism may not be the primary reason.
To put it in words close to finance: it is not an early cash investment in daycare and food, but lifelong kin work, that is rewarded with emotional bonds and long term dividends.
Living together in multi-generational homes facilitates kin work, there i agree, but it is not a strictly necessary requirement.
There are also other effects at work, especially psychological. Many adults don't grasp that their elders have increased demands, because they are used to see them in a providing role. They understand it on a abstract and logical level, it is so obvious and well known, but to truly understand it on a personal level is far more difficult. In the same way people growing older often try to stay in this providing role as long as possible, as they for many years defined themselves through it.
There comes a time in life when easter invitations switch direction. If you live together on a farm, this changes gradually.
most expensive bug of all time that crashed a whole rocket
being valued at $ 370 million in 1996 that bug was recently dwarved by crowd strikes multi-billion-dollar disaster in 2024
and vice versa the later seems inauthentic, off-putting and weird to the former
France is also outsourcing parts of the fuel reenrichment process to Tomsk in Russia
GitHubs privacy policy towards end users says they collect usage information and telemetry, among other data. So you host a project comparing ToS on GitHub and Microsoft collects information about anyone viewing the project, who referred them, their browser fingerprint and much more. This usage data might, depending on technical design, even enable them to collect fingerprints on features like opening the comment trees of specific contract clause.
It is not only a privacy issue, "certified by entrenched gatekeeper mega-corporation" is a nightmare for user freedom. The first ones who will be impacted are the minority who root their devices and compile their own software, but in the long run there are detrimental effects of a monopoly at the gate, like the ease to implement surveillance, censorship and drm, that will apply to everyone.