HN user

hackermatic

603 karma

She/her. Web application security and typewriter repair.

Posts14
Comments128
View on HN

There's at least one company that straight-up reverses a pacifistic cultural reference: a Ukrainian autonomous weapons company called The Fourth Law, as in Asimov's Three Laws of Robotics to prevent humans from coming to harm.

Apart from my own thoughts on the Ukraine war and autonomous weapons, that name makes me feel like the company's founders either haven't engaged with the moral questions of their technology, or want to mock them.

I've run into one government website that required email addresses to come from gmail.com, outlook.com, or another common domain, and several websites that won't let you change your email address once registered. It also makes it really confusing if someone needs to share Google Docs with you. So I've moved as much as I can off of Google, but some stuff will linger forever.

I hope commenters will dig into the author's citations' data, in line with HN's discussion guidelines, instead of just expressing a negative opinion about the thrust of the article. The quantifiable impact of genAI on code productivity is an important research question, and very much an open question subject to bias from all the players in the space -- especially once you factor in quality, maintainability, and bugs or revisions over time.

The GitClear whitepaper that Marcus cites tries to account for some of these factors, but they're biased by selling their own code quality tools. Likewise, GitHub's whitepapers (and subsequent marketing) tend to study the perception of productivity and quality by developers, and other fuzzy factors like the suggestion acceptance rate -- but not bug rate or the durability of accepted suggestions over time. (I think perceived productivity and enjoyment of one's job are also important values, but they're not what these products are being sold on.)

As counterintuitive as it seems, that was my experience living in one of those neighborhoods and visiting others over several years. A handful of small stores on one block or corner every half-mile really doesn't induce that much traffic. It's an entirely different scale from a commercial district or even a car-oriented strip mall.

I think people in the US overestimate how much upzoning "has to" affect most neighborhoods, especially infill development or removing default single-family home zoning. I used to live in Minneapolis, which has lots of century-old duplexes and fourplexes mixed in with single-family homes on similar lot sizes. Traffic, activity/noise, appearance, and overall "niceness" were almost the same as on single-family-only blocks -- but the bump in density supported lots of corner stores and restaurants in walking distance that made people want to live there or visit the neighborhood for the day.

Part of the apprehension might be caused by the difficulty of rezoning itself. The only people with the determination and money to get a zoning variance are big developers who need a big building to make it worthwhile. That's how you get 50- or 100-unit apartments going up in single-family neighborhoods, and a "missing middle" of density and affordability.

Honestly, yeah -- it's not a cheat code, it's facing two sets of pressures from discrimination, not seeing many like you in your field, what you deal with outside of the workplace, etc. And it helped me to see how many people before me succeeded regardless of all that; learning about Lynn Conway ~15 years ago was really important to me.

Local hosting/processing is a good thought, but it only helps in limited circumstances, because partners you haven't separated from yet are likely to have physical access to your devices.

It's one of the big criticisms of Microsoft Recall: the database is locally generated and encrypted at rest, but practically, any user in the same home with device access can probably access it, and bypass any efforts you've made to delete your browsing history or messages.

Remember that abusers are often controlling and suspicious, so disabling Recall, denying them access to your devices, or changing your passwords is enough to set them off because you appear to be hiding something (maybe making plans to leave or report them).

Plausible deniability can be an important feature for activists and regular people alike. You can't always predict when a relationship goes south like this, or get out of it as soon as it does, or afford and hide a burner phone.

One of my friends remarks (edit) that tech companies should have a social worker and a public defender on staff for threat modeling these things.

I don't think the Big Three record labels will want to stop this, even if it's massive copyright infringement, because it's not a threat to their business model. Labels create a whole ecosystem around a limited set of artists through marketing and tastemaking, then capture multiple revenue streams (streaming, licensing) for the few artists who people mostly play and pay for. They aggressively persuade musicians to sign away the rights, so the labels control the terms of payment, and they work together with a tiny group of companies in streaming/radio/etc. who have the same self-interest.

Everything outside that structure is an afterthought. The occasional indie hit songs and labels have failed to upend the music industry power structure for a century (they tend to get acquired if they get big enough). Tons of people making songs mostly for themselves will only dilute the power of smaller players.

The labels will probably extract some licensing fees off the stolen copyrighted training data, but they famously don't care about their musicians earning a livelihood.

Edit: Other commenters report that Android will silently re-enable cell data under various conditions, so this isn't a surefire solution, either.

The Grugq created a tool for this a decade ago (sadly unmaintained): https://github.com/grugq/portal as part of a presentation about operational security for hackers. It's a great watch if you're interested in how various (in)famous hackers thought they were secure and got busted anyway. https://www.youtube.com/watch?v=9XaYdCdwiWU

People have been anecdotally reporting and investigating similar problems since at least last year[0], and it's entirely possible that changes to improve one aspect of a model could make it much worse at other aspects without careful regression testing and gradual rollout. I think models intended to solve every problem make it very hard to guarantee they can solve any particular problem reliably over time.

Imagine if a million developers simultaneously got much worse at their jobs!

[0] https://arstechnica.com/information-technology/2023/07/is-ch...

I encourage people to look for a variety of opinions on this bill -- and its various parts -- so you can better figure out which parts you actually want to keep, change, or remove, and give your legislators that specific feedback.

Alliance for the Future is a lobby group of effective accelerationists who endorse some of Marc Andreesen and Peter Thiel's views in their manifesto, and based on that plus this article, they seem to oppose the bill entirely.

A place to start for a breakdown of what's in the bill is the Context Fund analysis that AFTF links to. That analysis cites similar critiques from EFF, the Software & Information Industry Association, and others. All of these are from the perspective of voting against or substantially changing the bill.

I haven't found "pro bill" opinions as easily, but I haven't been plugged into the conversations around this, so I'm missing anything that doesn't appear on the first few pages of Google or DDG.

It's always a bad time to be an actor, between long hours, low pay, and a culture of abuse, but this will definitely make it worse. My writer and artist friends are already despondent from genAI -- it was rare to be able to make art full-time, and even the full-timers were barely making enough money to live. Even people writing and drawing for marketing were not exactly getting rich.

I think this will lead to a further hollowing-out of who can afford to be an actor or artist, and we will miss their creativity and perspective in ways we won't even realize. Similarly, so much art benefits from being a group endeavor instead of someone's solo project -- imagine if George Lucas had created Star Wars entirely on his own.

Even the newly empowered creators will have to fight to be noticed amid a deluge of carelessly generated spam and sludge. It will be like those weird YouTube Kids videos, but everywhere (or at least like indie and mobile games are now). I think the effect will be that many people turn to big brands known for quality, many people don't care that much, and there will be a massive doughnut hole in between.

People and governments really need to start asking if the results of the current generation of FAANG-size LLMs are worth the costs, in additional chips, power, and cooling water -- especially in locations that are constrained for any of those resources. Are we getting ten times better Google results for ten times more energy? I don't think so.

Because, as the article goes on to say, the problem isn't that genAI repeats copyrighted material. Rather, its automation and massive scale upends the labor incentives that copyright is intended to provide, in a way that a human synthesizing knowledge from multiple sources can't.

In other words, it doesn't really matter whether ChatGPT or Bing Chat or DALL-E are tweaked so that they no longer violate the letter of copyright law, if they deprive -- at scale -- all their data sources of the views, recognition, and revenue that incentivize them to go gather and produce this valuable data in the first place. Why bother researching and writing an article if you're never going to get any pageviews for it, because Google places your main point atop the search results page?

The marketing company is owned by Cox, an ISP, cable, phone, and general media conglomerate. This capability is apparently already active and being sold.

The full article title is: "Marketing Company Claims That It Actually Is Listening to Your Phone and Smart Speakers to Target Ads"

I wish they documented the sanitization logic beyond that it's optimized for JWTs -- there are so many other session token formats and naming conventions that I would have to test this tool for each site captured instead of making a blanket recommendation to use it.

I've seen very few chargers with prominent signage, visible from a major road (the ones in supermarket parking lots usually can't be seen until you're there), or next to existing gas stations. I also haven't seen any entertainment media showing someone plugging in or unplugging their EV, whether through product placement or organic scriptwriting.

How else, in America, will the non-enthusiasts realize that owning an EV could be a practical option, even an ordinary one?