It's usually not possible to prove that something was put in deliberately and maliciously, so that puts the bar very high. We know it for sure in some of the supply chain attacks, and should assume that other kinds of bugs are being introduced by malicious actors across the board, rather than to risk downplaying the issues to "just blunders".
HN user
UweSchmidt
Freelance test automation engineer from Germany.
www.korrektesoftware.de
Maybe it's time to take a closer look at reality and correct this meme, which might casually blur the issue and deflect responsibility?
Looking at the IT security landscape we see every layer, every product category if not every product itself riddled with issues at one point or another. At the same time the incentives to put those security issues in are huge, and we know attackers work systematic, creative and persistent to introduce those weak points.
Security is hard and many bugs certainly happen due to mistakes, but I wouldn't assume that all of those security mishaps stem from an endless series of blunders from "stupid" programmers.
So I would go with “Never attribute to ignorance that which is adequately explained by malice.”
It doesn't look like they put AI into vim like Microsoft into Notepad. Someone used an outside AI to code something with vimscript, what do you expect? I'll be worried if they mess with even the smallest bit of established muscle memory of any vim user, but a separate language (probably a dead end) and apparently some new diff options don't seem too terrible.
Even more important would be the purple hyperlinks (or any other distinct style) for those links that you've already visited.
That's just a basic financial credit score, and you can easily rent without one (even though some financial accountability is probably reasonable to balance the strong renter protection laws here). What's so nefarious about it?
My AI suggests a few existing algorithms to tackle the problem of comparing two sound curves - maybe this one is not too hard?
I'll check out that app when it's ready, good luck!
Accuracy indicators for rushing and dragging are very useful, but equally interesting would be an indicator that checks for a consistent peaks, so every note is played with equal volume. A dream would be if your app can detect differences in sound (fingernails occasionally scratching the string, fretbuzz).
Is there any way to get notified when your app is done, or do you have a name for it already so we can search for it in a couple weeks?
Ah, the good old Internet Libertarian.
If only free and enlightened individuals could, through their choices in a market in which everything is allowed, spawn such a diverse set of solutions, or allow true self-help, that every need is met...
...rather than everything consolidating under a few big players who leave few realistic alternatives, who confront users and customers with conflicting and hard to identify or quantify problems. There might just be 3 unreconcilable goals like:
- not allowing Google/Chrome to own the internet outright - have privacy for oneself and others who don't "opt out" - have a browser that is established enough to work on most websites
and you can't tell me what browser to use.
The same issue is present almost everywhere you look: All products have such massive permutations of health, energy, waste, sustainability, ethicical and economical parameters that making a decision is almost impossible for any well-informed individual, let alone for enough people to steer change in any meaningful way.
If you maintaing this sort of "Libertarian" view, make sure you're not inadvertendly serve the interest of corporations that would like to not be criticized nor regulated.
My mental model of a browser is the same as of any tool, as a hammer, purely defined by its technical capabilities to do a job, like to display a website and offer basic functionality like for saving a bookmark.
The very idea of an entity called "we", an anonymous and ever-changing cast of people managing "responsible defaults" and "simple tools to manage your data" and communicating it on their terms, making me try and keep up, is alien to this idea. They lay their hands on our data; want to know how exactly? Follow several links to this page:
https://www.mozilla.org/en-US/privacy/firefox/#notice
The page in its tone trivializes the entire deal and is just another EULA and as such could just as well be presented in a small textbox in all-caps. It's more than the average user will ever read, and way too vague anyway.
"Be informed about what data we process about you, why and who it’s shared with (that’s this Notice!)" they say, but
...how about you show the entire dataset compiled about any user with information who is using it and for what exactly (excluding truly secret law enforcement requests). Everyone involved would be mortified with shame.
I think in general, no major liability issue will come up:
- if everyone is doing it, you can't really fault anyone
- on some level we are, or will be, kinda dependent on that AI and opting out will probably be made unpleasant via dark patterns as usual
- no pushback to every piece of software, including at the operating system level, slurping all the keystrokes and data, let alone the data that's already in the cloud - big tech knows everything about us but to my surprise no major public leak has happened, i.e. one where you really can see your neighbor's private data without buying leaked data from someone on the dark web or wherever
- things are moving too fast, and you don't know if you can afford to have your programmers not use tomorrow's AI, for example, so your "bans" will have to be soft etc., this limits the potential pushback and outrage
My comment has not suggested that there were no legitimate cases for using more memory.
It's too easy, and happening too often on HN these days, to reply with a low-effort contrarian statement without engaging with the central point of the argument.
While we're bashing economics, something I truly miss is that no new high level economic systems are being discussed prominently. As important as fusion in physics or cancer treatment in medicine, we badly need to explore and discuss something beyond the heavily ideologized systems of capitalism, communism and feed this to politics to communicate these potential options to the voters. Say, https://en.wikipedia.org/wiki/Georgism, which is old and half forgotten. It appears as economics is kind of muted, students and professors beholden to an ideology themselves or feeling the need to appease potential employers who are usually politicized institutions with no room for intellectual curiosity. What else remains in terms of practical economics besides determining the inflation rate (oops, that one is also politicized)?
Is that generally how unused memory is used, and will this kind of "cache" be released if another application truly needs it to load actually vital things?
"unused memory is wasted memory" is a meme, technically true from a narrow point of view, but leading to bloat and encouraging bad practices. A little bit of care could shave off orders of magnitude of memory use, as well as performance, which could ultimately allow for cheaper computers, sustainable use of legacy hardware and keeping performance reserve for actual use. In reality, I the idea of increased efficiency by using more memory ultimately leads to software requiring that memory that used to be optional, and software not playing nice with other programs that also need space. Of course even with the idea to have everything ready in memory, software is not generally snappy these days, neither in starting up and loading even from fast SSDs and during trivial UI tasks. Performance and efficiency is also generally not something that programmers regularly seem to consider the way real Mechanical-, Civil-, or Electrical Engineers would when designing systems.
I accept trade-offs concerning development effort and time-to-market, however the phrase "Unused memory is wasted memory" does not seem appropriate for a developer who's proud if their work.
Little friday rant, sorry :-)
As usual it comes down to the increasing individualism, that rejects any overarching societal guidance in favour of judgement-free self-expression ("body positivity"). This removes any collective bargaining or collective action (some of which I proposed in my parent comment) and exposes the individual to systemic risks (food industry making people fat, medical industry giving them a pill to feel better), unless the individual is equipped with enough of Bourdieu's social capital to navigate the pervasive health risks of the modern food supply. Allowing this minefield in place is also a convenient way to maintain class, leaving the unwashed masses hampered by health issues (like diabetes), reduced cognitive function and less attractiveness.
It appears that sentiments that downplay or dispute the health risks are growing in large social media bubbles, with strong effects on the real world. Efforts to push back on serving unhealthy food are undermined, doctors discouraged from discussing weight with their patients as a personal and sensitive issue; overweight models validate unhealthy body compositions. This surely has to please the food industry, which is as culpable as the tobacco industry in harming peoples health.
I would propose a concerted effort through mandatory levels of food quality that is served to the public (e.g. schools, hospitals), funded by a higher tax on sugary atrocities, limits on sale of sugary food and drinks to children, and an outright ban on any substance designed to create cravings.
Open source is not a gift economy, and is in fact a different, and long established social contract. Never has this misplaced metaphor been used to describe open source, nor do the contributers demand any return that amounts to an "entitlement to future gifts".
Is it though? Microsoft .NET has telemetry that you always have to opt out always. Dark patterns like this setting not sticking but being overridden after an update, and of course the shell command that you kinda have to google each time, where you set a parameter to "1" and get no verification that you have indeed successfully disabled telemetry come with the territory (of software vendors not respecting the user much)
Let's do a less science then, but rigorous and throrough. Or find more funding.
But surely let's have a "hard-line stance" on not drowning in BS?
If you get an answer outside of what you expected, reevaluate your approach, fix your study and redo it all, probably with a new set of participants.
If you can't do science, don't call it science.
You used to find amazing information on the internet back then. It is quite likely that someone else had already worked on a similar topic and blogged about it in a very searchable way. Without good search that kind of online culture died out.
While we do have a video tutorial culture that exceeds what we had back then in many ways, and to be fair that technically happened under Google's umbrella (Youtube), destroying search and with it a lot of the open internet, will not only be Google's downfall, it's also a silent tragedy.
Actually, measured by what a global online population could have achieved, with human information truly at anyone's fingertips, with infinite communities forming all over the place instead of in non-searchable Discord and monoculture Reddit ... this might be one of the main tragedies ever.
You appear to be in favour of said Guild trying to change the cultural expectation for more copyrights, now extending to human movement. Needless to say this evokes the image of corporations like Disney ending up with those copyrights and going after people doing the zoomer dance long after the Mickey Mouse copyright will have expired. Are those worries warranted?
"Throwing the baby out with the bathwater" means trying too hard to do something good but accidently overdoing it!?
Just to make sure we're not accidentally giving Google a break, Google+ ended in 2019, if they cared for search at all they would have brought back this feature.
When I learned about Rails a long time ago I thought the idea of MVC, scaffolding, creating the database, code and frontend that works, i.e. a basic application was genius, but hasn't quite caught on it seems.
Communities for RoR or Microsoft MVC could have created templates for all kinds of applications, and parameters with best-practice implementations of useful stuff like "jwt webtoken" could have been added and maybe implemented to work across different application templates?
Maybe there are good reasons why this is not feasible on a fundamental, technical level, but maybe that's just a path not travelled, as the open source spirit fizzled out and people tried for their own unicorn app.
What's overlooked is that today's workforce is not ruled by a cadre of hardcore company people any more. Work from home is generally enjoyed on every level of the hierarchy. Likewise, even your boss's boss will have a family and share childcare responsibilities, which creates strong demands for flexibility and autonomy that are hard to argue against. This means, leadership doesn't want to, and can't really enforce return-to-office all that well.
So, unless I am missing something big, heavy-handed measures mandated from the CEO ultimately won't change modern workplace culture.
(If you like WFH though please do your part: Be productive and communicative from home and argue against return-to-office at any occasion to the full extent of your influence within the organization)
All right, there are certainly other major forces affecting western societies and various scenarios could play out in the future. Let's put our weight behind the movements that would lead to some positive outcomes...
I do see it happening naturally; the very idea that an UBI idea is floating around is a product of the wealth and automation we enjoy. It's a realization that sets in on a broad front, from bullshit jobs, to new generations of products that are not improving much or even regressing, environmental concerns that discourage producing more, massive government budgets squandered ("why not give it to the people who need it?"), and COVID giving people a pause in their respective hamster wheels.
Imagine a technological reset and/or war: Under those circumstances one could still argue for a socialist system of work, but not for people doing nothing getting UBI.
Everything you say may be true, but is orthogonal.
I do think social benefits are expanding in the USA also, more and more people find it viable to be a NEET. The wealth gap will surely widen; this implicit UBI is certainly not communism in any way. Truth is, today western societies can afford to provide the basics for everyone, so ultimately withholding in order to keep the masses in the jobs is not tenable.
"The future is already here – it's just not evenly distributed."
There won't be the big UBI day, where we make the big switch globally. It's a creeping expansion of social benefits and transfer payments and an easing of work conditions. Some people will somehow stay in the unpleasant jobs, by inertia or the unfairness of a class system or, increasingly, by wages that compensate for the trouble. People will drop out of individual job categories and certain businesses become unsustainable; society will adapt around it, with automation or higher prices.
The conclusion for the individual is to not tough it out in a shitty job, instead look for opportunities where companies will pay a contractor or company to do work that used to be done conventionally in-house for a wage. Also, and I hesitate going that route, don't see the redistribution opportunities as shameful handouts, but rather as an income stream that will make up a larger and larger pie of the economy.
Interesting point about the GDPR; I will soften my point to mean that lawmakers have started (late) to regulate data retention / deletion and the rights of users in general and that might be a trend for the future.
However I would like to avoid the impression that with the description of the technical status quo the topic is settled. To do so I would go back to my previous point: Imagine some truly illegal pictures are in that cold storage backup, and one day you might have to restore that data. (Since aparently the user's wish to delete data is not quite as respected as certain other hard legal requirements regarding content)
What solutions to mitigate the situation could a company, or backup tool/web framework etc. reasonably come up with? Maybe check the restored data against a list of hashes/IDs of to-be-deleted-data?