You can start here to learn reverse engineering.
HN user
gray_charger
I disagree with the words you've chosen, but I think others are missing the sentiment. Most of us understand there is a level of politics involved in making free software. The problem many software communities are facing is unnecessary purity tests. The mission of the GNOME desktop environment does not include protesting U.S. I.C.E. enforcement.
Is the identity of those who make donations protected in any way? Could a company seek legal damages against all or some crowdfunders for what they might deem as libel (regardless of merit)? I doubt people who donate $1 here or $2 there have the capability of warding off a lawsuit.
What's the difference between Organic Maps/this and OSMAnd?
The social contract was to show ads. Gathering people's data even on websites they don't even own was not the social contract. Google broke the contract and to suggest otherwise is gaslightling. Google can either start blindly showing context-relevant ads with no tracking or they can eat the loss from those willing to use free services.
Very first bullet
AI can now generate code faster, and often better, than humans.
The author doesn't know what they're talking about. Feel free to skip this one.
Oh great, now I can exchange QR codes to connect with my frie...oops! Actually I can't because my server's admin got called a "poopyhead" so decided to defederate and isolate all the users. I wonder why people still use Twitter/X...
John Scalzi is a one (or three) hit wonder. The first three books of the "Old Man's War" series are the only books of his worth reading. Don't waste your time with Zoe's War, there isn't anything of substance in that book. The following books in the series just seem like Scalzi trying to milk the success of Old Man's War. There isn't anything new or interesting.
That's my major problem with it; it locks you out of messing with your own machine data, which you can see being instantly abused by third parties to prevent modifications.
It locks everybody, including the owner, out of any data it doesn't own. That's the point. If you can pull it out, so can anybody else, and you've just made a small hard drive. Could it be used by vendors for DRM-like things? Sure. That's on the vendor, though, and not the technology itself.
One which you, as the owner, don't have the keys to.
One which nobody, not even the owner, can extract keys from. I don't understand why people don't like the fact that they can't pull keys out of the TPM. If you, the owner, can pull them so can anybody else. I know TPMs aren't invulnerable but you have to admit they significantly raise the bar of compromise.
You could make cryptographic protocol where all chats have an extra user in them whose key is unable to be decrypted or revealed unless there is a warrant provided.
...that's called a backdoor.
This just sounds like a less private Tor.
Correct, hence the accusation of dishonesty.
If you're not doing anything that affects national security they won't bother burning that capability on you. They save action only for those they can take action against in a clandestine way (so the fact they can crack Tor is not on public record), or against someone so dangerous they need to act quickly for national security reasons (and a government acting quickly with overwhelming force is hard to keep secret).
You're being dishonest by implying that discussion of technology is inherently not inclusive and that an effort needs to be made to be inclusive by allowing people who feel oppressed (whether they are or are not) to play in the "oppression olympics" by creating tangential opinionated discussions regarding policy or ethical guidelines that have nothing to do with the technology or the problem the technology is trying to solve.
Technology is inherently apolitical and inclusive. Anyone who claims otherwise is just trying to stir up useless internet flame wars. If you want to uselessly rant about politics on the internet you can go to Reddit.
What forums, Matrix, and Discord are you a part of that have high quality discussion?
It's Debian based so allows you to run glibc binaries.
How does one download and play with these models?
It's not backwards. The prosecution makes a claim and supports it with evidence. The defense makes the claim that the prosecution's evidence is fake, thus the defense needs to substantiate that claim. That's been true even before deepfakes were a thing.
...it was extremely disconcerting to see PHONE NUMBERS spread throughout the log messages. It doesn't take much imagination to see how you can build a network of who you are talking to (etc.) from this log information.
The intent of Signal is to provide confidentiality of message content, not any sort of anonymity. This covers like 90+% of user's threat models and it's focusing on one problem makes it very effective at solving that problem. If one also needs anonymity then communication should happen over something like Tor or I2P.
PBKDF2 should only be used if compliance with government requirements is a concern. While it can be adjusted to be arbitrarily difficult by changing the iterations it's still not memory intensive and can still be fairly easily cracked with a GPU (when compared to scrypt or argon2id).
If the end user was "in control" of the PSP that'd defeat the purpose. These features are supposed to remain a secure enclave even if the machine is compromised.
A TEE has nothing to do with any of that. A TEE is a CPU feature that generates a physically separate area of memory that no other process can access to protect sensitive data from even the OS (in case of compromise).
So, if I remember correctly AMD PSP started out as a response to Intel ME, whose main selling point at the time was that businesses could remote into a compromised system and wipe malware without the malware being able to fight back.
Do you have a source for this?
SGX is an interesting case since Intel actually axed the feature a year ago. The only thing it did was enable more DRM for 4K Blu-Rays, and Hollywood's response to that feature going away has been to just refuse to let you play 4K Blu-Rays on PCs.
Signal used Intel SGX for remote attestation of their servers and is also using it for their upcoming username/password features to generate keys without Signal's knowledge (since it's a private enclave).
Furthermore, there IS a very large customer that has wanted to remove these kinds of secure enclaves from their systems: the US government, specifically the National Security Administration[1]. There's a special configuration option in Intel ME to turn off everything but basic system bring-up. Why would the NSA want to turn off "privacy and security software" on their own machines? Well, again, the whole "wipe a compromised system without the malware being able to resist" thing implies that this isn't merely a security enclave, but a backdoor that could be compromised by a third-party. If you aren't specifically using that remote management stuff, you want the ME to be as brain-dead as possible.
I need a source saying PSP has remote management capability.
Oh, and Apple doesn't actually give the Secure Enclave the ability to mess with the main application processor. It's more akin to a TPM, where it can withhold encryption keys from the regular OS but it can't actively snoop on it. So they also understand why PSP/ME were bad ideas.
What does "snoop" mean here? How can PSP "snoop" without remote management capability?
Why would you want to do away with AMD PSP? It's a trusted execution environment that privacy and security software (e.g. Signal) makes use of for it's confidentiality and integrity guarantees.
PSP is a trusted execution environment not a remote management platform. There is no reason anyone should want to remove this from a privacy perspective. In fact, privacy and security software may be hindered without something like PSP or SGX.
Most likely, yes. Those with a different worldview are cut off from the fediverse and many client apps blacklist those instances that gain momentum from being usable in the client app. For example, Gab.
How could we have ever known putting Covid patients in nursing homes with our most vulnerable population was a bad idea?
https://www.wxyz.com/news/region/detroit/20-year-old-beating...
Who could have guessed that stopping all economic activity was not a sustainable solution to the pandemic?
https://twitter.com/who/status/1316020010540625920
https://nypost.com/2020/11/29/nearly-one-third-of-ny-nj-smal...
If you don't take this vaccine you and your family will starve on the cold streets. But the company that created it also has zero liability with it being emergency authorization and all. What, you have a better idea?
https://www.shrm.org/resourcesandtools/hr-topics/talent-acqu...
Nobody warned us these things could be a bad idea. How could we have known?
https://twitter.com/davidzweig/status/1607378386338340867?s=...
Seriously, were you living under a rock? > "I don't think any armchair critic would have done any better." I think if we allowed a chimp to make decisions at random we could have gotten a better outcome.
I think centralized moderation is the problem with social media servers. Users should be the ones to control their own moderation. See a post you don't like? Hide the post. Don't like any posts from a particular user? Block the user. It's not difficult to do and if users are really only following friends and famous accounts (celebrities, bots, news, etc.) they won't experience much spam anyway.
I think the real issue is discovery. How does one find other accounts that post about similar topics (other than friend-of-a-friend approach) and that aren't spam.
Passwords are the only "warrant-proof" encryption method we have. A government can force you to provide either "something you have" (e.g. yubikey) or "something you are" (biometrics). For those in repressive regimes that's extremely important.