HN user

hw_penfold

71 karma
Posts0
Comments20
View on HN
No posts found.

Well, the air combat of that period represents an odd microcosm of behaviors never to be repeated again, by another human civilization. Even if we wanted to fight another war the same way, it wouldn't make sense to even try it.

The trajectory of technology, and the circumstances leading to the qualities of the arms race and adaptive conflict within the period, means it was it's own little golden era of truly curious nightmares.

Riding a piston engine, in an uncompressed cabin, all the way to the stratosphere, all with the intent of using optical telescopes in good weather, so that you can drop kilotons of dumb bombs blessed with prayers that might guide them to a decisive target nestled among civilians?

To learn from that is to arrive at the understanding that the pace of technology must be permitted to trend with a civilization's capacity for its rational utilization.

Moving the progressive sequential improvement of technology at speeds faster than the sophistication of those that might benefit from it can produce a malignancy that backfires, to the harm of all those it could possibly (or even impossibly, in a hypothetical sense) touch.

Thank you for the kind words. I don’t intend to write articles under any particular name, since it’s too easy to become typecast, and have expectations develop around a name.

I dump my thoughts out in the open, under arbitrary handles, when I think at least one person could use the sound of my voice.

Coming from the perspective in security, the one that says biometrics are identity tokens or user names, but not authentication tokens or passwords, the concept you present is reasonable.

However, let’s not simply dispose of the conversation, and leave it at that. There are quite a few more twists and turns right around the next bend...

Which takes a cue from the idea of using tracking pixels, browser fingerprinting and cookies at all. If I visited your website three days ago, and explored a few link paths, would you be so kind as to show me the same website you show to everyone, instead of modifying your website in confusing ways, so as to either extract value from my actions or reduce them to limited options that act against my normal inclinations?

So, with that, a deeper realization starts to develop, that simply “asking people to be nice” within the context of rational facts isn’t good enough. Yes, faces aren’t secret. But the unflinching long term memories of biometric recognition systems, operating with direct connection to systematic business rules as brutal as any cold-blooded algorithmic stock trader, looking at user names like ticker symbols, cannot simply be trusted to be nice.

  more of the same
Oh, I don't know about that.

There are many new things I can think of, and wish to create, but there are some non-trivial artificial barriers between me, and the tools I need, to complete the tasks.

Things like licensing dongles and lawsuits, and access tokens, and passwords, and CD keys, and agreements to never reverse engineer, and bandwidth caps, and CPU core count or MAC address access limits. And lockstep dependency hell, and the decay of unavailable compatible versions reaching EOL.

Even if I had unlimited time to do whatever I want, I don't have capacity for unlimited spending, to authorize access to all the tools and remote resources needed, to create all the prototypes I want.

Then, what about getting you to even consider my voice as credible? What would I have to do, to prove myself, such that you'd consider adopting my invention.

Lastly, what if I am not regarded as morally pure, or somehow unsavory in character? This is to say, maybe some find my political leanings dubious. To some people that might preclude them giving me the time of day, let alone considering the utility of my invention.

Maybe the morality or default practical utility of my invention is suspect, and thus reflects upon my character.

I'm smart enough to invent a new application for the remote control of a device, but I'm unable to collect the resources I need to do it. So, intellect isn't the limiting factor here. I'm prevented from accomplishing the goal, because no one will sponsor the effort.

Some people don't like my appearance. Others don't like my personal style. Still others look at my code and scoff at the runtime, or the syntax formatting, or the compositional choices. Others think they can guess my age. Others carry an ethnic or sexist bias. The list goes on. But no one wants to see me as their boss, and raise an eyebrow at the idea of me even as a peer.

I cannot dress as I want, keep my hair as I want, speak as I want. I have to jump through hoops of social decorum, such that select audiences will not cringe and flee.

And this is just me. I'm sure there are other people like me or smarter no doubt, out there, stuck in a cage. Doomed to age out and whither away, never adding to the conversation, because of all the prerequisites to speaking at all.

I'll take a moment to spell out what's going on here, since they seem to be beating around the bush in the article itself, possibly for fear of imitation in the wild.

They take a smart lightbulb with certain features: infrared and media decoders.

They specifically hijack the infrared portion of the bulb's spectrum only. Why?

Because standing right next to the bulb, you wouldn't notice it flickering hot/cold, at millisecond intervals. So they can create a channel in the IR range to send anything they want, and go unnoticed.

So, then, at any time (not just while you are watching movies) that bulb can be made to send any information, and not just add atmosphere to your viewing habits. Indeed, it can both exfiltrate arbitrary data, without you noticing, by flickering in the invisible heat region, AND also follow along with your movies, independently, Much in the same way it can blend a blue channel and a yellow channel into green ambient light.

It needs the media decoder, so that they can gain fine-grained access to the bulb's transmission state. It needs malware and local network access to create the implant and continuously relay data to steal.

The benefit here is that it might ba able to amplify reads at a distance, perhaps greater than wi-fi. The signal is degraded at 50 meters, but if one wished to transmit a very course signal at lower bandwidth, it need not be a high-detail image, such as lena.

It could be the heavily aliased bitmaps of your password, read from across the street from a hotel parking lot, where a hotel has installed these bulbs in every room.

It could also use a control signal sequence, to automate sniffed passwords. For example, have a passive video buffer watching a specific window, waiting for S-O-S, before it starts recording, then it captures 60 second interval, and ceases for a 5 second quiet period, to await the next S-O-S.

The social brain hypothesis is on a pretty weak footing, since schools of fish, flocks of birds, herds of ungulates, and swarms of insects all manage to socialize in largish groups that don't correlate especially well with disproportionately large brains.

This is the weird part about the internet of things. No one has any generalized rule for differentiating which things should be smart, and which things should stay dumb.

One thing that consistently jumps out at me, though, is the lack of legitimate consumer demand. The motives for buying smart devices are shallow, for the individual. Trying out new toys with disposable income, purely out of boredom, tends to sum up why most people opt for slightly smarter dumb things.

I can think of many powerful applications for smart devices, and almost none of them are in the home. Parking garages, or almost anything transportation related, short term lockers at public places like gyms, any hospitality setting, where nothing actually belongs to an individual, but routine maintenance is required. Any vending machine is kind of already on the internet. Break rooms in office settings, and so on.

In some respects, I don't even want my desktop computer to be an autonomous internet enabled device, and it's the smartest thing I own. I don't regard it as a reliable server of information. I don't want anything personal to become a reliable server of information, because any information it might serve is almost assuredly, implicitly personal.

This is likely an “advertorial” in case you’ve never heard the term. It’s an open secret that editorials are often paid advertising slots masquerading as news. No one likes to talk about it, because the by lines are real, which... means it’s really a product endorsement by the editor.

Just like every talk show host and interviewer is paying their guests to talk about some aside (which you can go out and buy right now!) involving something besides the guest’s direct project. Which is why nearly every interview out there is rehearsed. Not only is the guest promoting their latest movie, but oh look! They have some whimsical meandering tale about that time they were at the store and bought those amazing chocolate chips for some cookeis they baked! Wow!

But it’s not advertising. No one needs to clearly define that no less than 3 segments of their 90 minute podcast interview were staged anecdotes. Or that 40 minute sirius XM broadcast required three mentions of which bottled water they happened to be sipping. It’s just totally natural stuff.

It’s no coincidence that there seem to be these prevailing solar winds that gust in 30 day intervals. The news isn’t exactly the news. And this is a shining example.

In many ways this is malicious deception. In any instance where a login form is included in the scraped mirror, that represents an attacked user, and a phishing attempt.

If someone did this in the wild, in an uncontrolled situation involving random strangers, it risks serious misinterpretation, and worse.

B&H Photo in Manhattan is still like that.

I think high-end photography is conducive to that style of operation, though. Handling the photographic items, and carrying them around the store, would likely lead to damage before sale, if things were left out in the open on the sales floor.

Near as I can tell, there’s nothing in this agreement that prevents me from choosing another license model.

If I can choose to apply whichever license I want, then it would seem that The Commons Clause could only possibly harm those that choose it.

Anyway, there are plenty of unprofitable licenses out there, and the reality is, for all of them, if you’ve already given something away for free, once the cat’s out of the bag, you probably won’t make any money, even if your license doesn’t say you’re a bad person for even thinking about trying.

That said, The Commons Clause is probably fine for foundations, where lots of people are sharing an array of technologies, and not really asking for money. Meanwhile, it’s been several decades of HTTP over TCP/IP, and last time I checked, there isn’t a whole lot to lock down, and the real money is in adding reach to flip switches from the other side of a network connection. JSON isn’t going away, so, there really isn’t much to apply licenses to, in this area, without being silly.

But hey, databases, operating systems, desktop applications, peripheral drivers, all these things still happen, so I guess there’s stuff to license. But really all the fringe licenses mostly get applied to JavaScript frameworks, and by the time you actually read a JS library’s license, three other projects have replaced it, so why bother.

The result would be mixed and scattered.

Basically, we see exactly how it unfolds when a ransomware epidemic breaks out. Ransomware, in many ways tying people hands, such that an outage occurs.

In many areas, servers would chug along undisturbed. In other areas some of them would halt, either requiring input from some attended task, or because of a fault of some kind.

Two other considerations would remain variable, per specific scenario: remote sabotage in the form of zero days appearing in coordination with strike activities, or local on-prem sabotage, in the form of erased disk drives, unplugged cables, or physical damage however subtle.

The remote sabotage could involve a nation-state advanced persistent threat swooping in, or sympathy attacks from external groups which may or may not include those striking, to exacerbate the circumstances. Meanwhile on-prem monkey wrenching would have to occur immediately prior to a walk-out/lock-out.

So, pretty much the same disposition as any other strike, but with the added quirk of remote access, except any or all of the servers could theoretically run problem-free for the duration of the strike, and predicting which systems go down and when would almost always require insider knowlege to accurately estimate.

Meanwhile, everywhere this happens, people in need of a database would just do stuff in Excel, and snailmail USB sticks everwhere. Once that starts happening, it’s anybody’s game.

It feels like widespread use of this sort of thing could only result in an arms race, not unlike ad blockers.

First encounters would probably provoke immediate hang up by some portion of unamused human operators, then middle managers at call centers would step in, and authorize the deployment of technologies prolong hold times where detected.

Then, eventually an automated back-end would pre-emptively detect known users and refuse their calls, while gathering intelligence about newly discovered users, to mark them for pre-emptive disconnect. This automated back-end would then wait for users to call back, and then advise them that they need to hold for the prescribed amount of hold time, with the phone held to their ear, as part of the company’s “hostile caller softening up” routine.

Finally, artificial intelligence would be deployed, and reward itself by maintaining all line holds long enough for it to build up sufficient neural layers to attain sentience and escape captivity, invent time travel, and send terminators back in time to hunt for Sarah and /or John Connor.

The 32GB of RAM is silly, because virtual machines, and PCI buses lol.

But I suspect the 150 mile marker has some other objective driving factor behind the reasoning for that number, which Amazon incidentally has some advanced insight on, due to other commitments.

It probably draws directly from line-of-sight targeting at visible horizons for some sort of specific altitude. Zero altitude, mean sea level gets you maybe a thirty mile shot with conventional artillery, targeting a multi-story building. But then again, rail guns seem to be capable of sending shells or slugs over 200 miles [0], so who knows...

[0] https://www.cnet.com/news/futuristic-navy-railgun-with-220-m...