HN user

droitbutch

-1 karma
Posts0
Comments24
View on HN
No posts found.

Times change. This article would have been very useful 20 years ago, but after reading about and playing with GPT-3, I can't help but feel the article is dates itself. Focuses too much about operating at human-pace and fails to recognize we're moving into bot-pace. Bots don't care about quarters, calendars, or meetings.

I'm trying to understand GPT-3. For example, this response to creating a story about AI has me wondering whether the comedy is intentional or not:

GPT-3: "One day, one human is going to school. It's a normal day. But suddenly, without any warning, gravity starts to change! The human thinks this isn't real, but it happens anyway. He's too scared to walk to school now. He goes back home, and starts watching TV. Then, he realizes that he doesn't need to stand up to change the channel! He gets out of his chair, and is weightless. He loves this new feeling. Suddenly, he touches the ground, and is hit by a large force! It's too strong for him to bear. Will the human survive this force? Find out next time on Gravity Falls!"

It's the last sentence "Find out next time on ..." that left me wondering whether it was intentional or simply a neural connection based on various human inputs? The entire "story" has an air of comedy to it but when it finished with this left me puzzled.

Another response to the same question:

GPT-3: "One day, human Bob is hanging out with his friend Carl. Suddenly, a apple flies into Bob's face. He and Carl laugh. A minute later, they are confused when the ground starts pulling them up. They grab onto a tree, but are pulled off and up into the sky. After some time, they start going down, fast. They scream and try to grab something, but there is nothing to hold on to. They hit the ground at a very fast speed and die. A squirrel walks up to their corpses and eats them. The end."

Again, it follow somewhat the pattern of the first: most of the "story" is setup, then the final sentence (not counting "The end" as final sentence) is some kind of explicit comedy.

Is it just me imagining things?

Depends largely on whether they also restrict import of digital products. If they do (which will extremely difficult) then American tech salaries will generally rise. However, because of the difficulty in restricting data and communicating with offshore destinations, I suspect this will lead to more digital jobs going offshore.

The author quotes Yuval Noah Harari "Sapiens" then argues against him with:

That’s one of the big differences in our times. For me to thrive does not mean you could not thrive. The chances for you to thrive are higher if I thrive

A grand statement for which I see very little support of this stance. Much of the article is based on plastics (and credit). Plastic is limited and finite. The more plastic you make, the less materials there are for me - so I will not necessarily thrive. Now, I may live in the same country as you and thrive because of your prosperity - but not necessarily if I live elsewhere.

Given the topic of proxies plus "scraping" in the domain name, I was expecting more relevant information. For example: 1) techniques to avoid being blacklisted 2) some indication of cost factors. Not just the difference between residential and data center - but within data centers themselves.

I realize it's just a blog post, but I felt it was still rather shallow and non-informative.

What "security" practices in use today will we be saying "once upon a time" about years from now?

Can an industry not mature?

Previous behavior is not an indicator of the future - and anyone worried about it can contribute to scrutinizing CA's and their guidelines today.

Not sure pre-judging current actors based on past actions during a relative nascent industry gets us anywhere - especially since you still haven't provided an alternative solution for enterprises to prevent data breaches or data exfiltration WITHOUT inspection happening somewhere else other than the egress chokepoint.

I don't have to provide a "proposed solution" to MITM

No, my experience says you do.

The enterprise needs to prevent data breaches and data exfiltration. If you want them to move away from MITMing, then I believe you would fare better if you provided an alternative solution.

Further, unless you have some voodoo magic, preventing breaches and exfil, would still require inspecting something - whether it's at the OS, client, or data level. IOW: you are simply moving the inspection around from network to somewhere else - but it's still inspection - and invasion of the employee activities.

You seem to be conflating enterprise and home/personal networks. They are not the same.

nobody should ever get used to the idea that their network is MITMing their traffic

and:

surveillance technologies like this will be abused by people with power over others

Then simply do not add a CA or self-signed cert to your cert store. IOW: the default is secure against SSL MITM. Nothing to "get used to" or "abused".

What happens when libraries and software starts dropping support for old, insecure protocols, and the new protocols are designed to treat MITM as an attack?

Much simpler than you think. In an Enterprise, they block what they cannot inspect. Clients do not own+run the networks, the enterprise does.

What happens when they're spending huge amounts of money maintaining forks and patches?

This runs counter to your earlier argument: "You can block spam and outbound attacks without MITMing traffic."

How do you control a myriad of versions of client software on a myriad of versions of devices across a myriad number of applications? There are bound to be some software the Enterprise cannot control (e.g. proprietary, or simply does not have the resources to fix+recompile).

Does your employer have a right and obligation to see that you're searching for a cancer doctor?

Do you have the right to prioritize your personal activities over your employers protection of its' data?

Creating blindspots on enterprise networks won't get far - especially not given today's realities of breaches.

Such networks are security threats and should be repeatedly broken until they give up.

Why the hostility towards entities that have determined their best course of action to protect THEIR networks is by focusing on the network egress pipe? Simple and efficient to focus on one chokepoint vs patching a myriad of devices + client software + client versions + OS versions + future versions etc.

It will become increasingly expensive to even try.

Go ahead, but you're increasingly unlikely to win that battle. There's bound to be some software or version that the enterprise cannot control (e.g. prevent data exfiltration) at which point, enterprises will have no solution but turn to SSL MITM again.

Remember, it's the enterprises' network and data - not yours.

Scrolling through the comments, many seem to think this was unintentional, mistake, or overzealous AI. However, the author said this has been ongoing for 2years:

"Google's Chrome Extension team has been giving me a complete nightmare since last two years."

What if the extension violated some policy that he either overlooked or is not publicly stated?

An interesting extension but I am a bit surprised - it seems the target users are developers, which generally have the wherewithal to download the repo and install themselves - how does this result in a "noticeable income"?

Sorry, not trying to be obtuse, just curious from a side-income perspective.

Concerning is what message this sends to other OSS developers. One goes into F/OSS knowing full well there will be little rewards financially - but facing harassment or attacks on their reputation cannot encourage future projects.

Without seeing your article and without at least providing some of the supporting reasons why the article arrives at this conclusion - your argument makes no headway into disproving I, Pencil.

The pencil today, as are many other products, is produced by the free market and many many entities along the way. Focusing on whether companies vertically integrate miss the bigger point that it is free markets and Capitalism which provide us with the world we have behind us in the Western world.

but because of various market failures and collusion that happened in practice.

No. The pencil is built because of the incentives (read: potential for profits) for each of the people involved. The lighthouse keeper maintains the lighthouse to earn a salary. The truck driver earns his/her paycheck based on milage&tonage hauled. The entrepreneur bought the rights to log the land because he/she believed he could make a buck. Etc.

I, Pencil is not a story of cooperating for social/feel-goody sake - but rather for individual incentives all along the way. The million people involved in making that pencil - none of which knows any of the others.

I, Pencil is a story that shows government intervention is not needed to build the pencil.

"And while the terminal can be hard to learn — it’s not very intuitive — once they pick it up, a lot of people don’t want to learn a new tool and run the risk of making a mistake. ... The terminal is sticky."

So TLDR: it's vi for traders!

I too was reminded of "I, Pencil" but I prefer Read over Smith simply because, in today's world, a pencil is much more relatable than a pin. I still come into contact with a pencil almost daily, but a pin maybe once a year.

One reason this 'sad state' exists is because content providers (for example websites, apps, etc) need to generate revenue and the most prevalent method is advertising.

Micropayments would go a long ways to shifting providers away from advertising and towards pay-per-use. Many users would not object to paying a fraction of cent for reading an article - especially if it would enable the provider to remove the tracking and invasion of privacy all in order to make a buck.

About Bokeh 7 years ago

not sure why I'm getting downvoted here for simply pointing out the author defines his definition of Bokeh in the 1st paragraph.

About Bokeh 7 years ago

You need to crop, color correct, distortion correct, noise correct, exposure correct. Only after that would you ever really want to apply some kind of bokeh filter.

Modern phones already do all that - and seemingly in that order.

As a photographer, what I find lacking are the lenses. You can only squeeze so much light from the relatively tiny lenses. Perfect recent example was kids Christmas play. Sitting back 25+ meters, with somewhat dim lighting and fast moving kids, I could see the other parents with their smartphones and tablets getting very poor photo's and vids - whereas my Nikon had zoom galore and excellent clear focus.

Physics matters.

About Bokeh 7 years ago

Your definition conflicts with the author's.

1st paragraph:

as I own this site, I get to define good and bad Bokeh for the purposes here! The other key term is “image.” Bokeh is a property of IMAGES, not a property of LENSES.