A while ago I participated in security design for an open source foundation. (Security is not a specialty of mine, but I aspire to be competent enough for my role as a developer working in web dev and open source.) We attempted to design our processes to assure some level of defense against state-level threat actors despite assuming we could not keep them out of our network. The main goal was to ensure an audit trail in the event that our source repositories or release archives were compromised and changed.
HN user
rectang
So I went down the rabbit hole of the meaning of "champ", thinking it might mean something esoteric in the context of "champing at the bit" like "speaking the first line of the skit". But no, "champ" as a verb is just an alternative version of "chomp", or at least a word that differs very subtly from "chomp".
https://www.merriam-webster.com/dictionary/champing%20at%20t...
https://www.merriam-webster.com/dictionary/champ
The migration of "champing at the bit" to "chomping at the bit" is inevitable.
There don't seem to be many idioms like this, where the newer version is both semantically intuitive/meaningful and accepted by authorities. The closest is probably "hone in on", but the verb form of "home" as in "homing device" is still current, unlike the verb form of "champ". Another interesting one is the migration from "just deserts", using an archaic meaning of "desert" as in something deserved, to the modern form "just desserts". However there's much greater distance between "desserts" and the archaic meaning of "deserts" than between "chomp" and "champ".
It's not the same, but I still remember the first time I was served genmai cha (roasted rice tea) at a sushi restaurant. I loved it and inquired, the server was kind enough to show me the actual tea bag — it was Yamamotoyama. Available lots of places in the US, but I used to buy it at a Japanese grocery store.
lol wut “corporate”?
I don’t get the rest of your post either.
While it will take a while to review the subtleties of this license, I appreciate that out of the gate they are marketing it as "Source Available" rather than picking a stupid fight by calling it "Open Source".
Voter suppression strategy depends on statistical degradation of enfranchisement.
There is a small group for whom it is literally impossible to obtain supporting documentation — this is the group that you're focusing on, but to my mind it's not that important.
There is a much larger group for whom the difficulty of obtain supporting documentation makes them statistically less likely to obtain it — and this larger group is the one targeted by voter ID laws to suppress their votes.
Because voter suppression strategies will absolutely not be abandoned, we're on an inevitable path towards national IDs.
Should voter ID requirements (a la "SAVE America" act or similar) become law, constitutional prohibitions on poll taxes will lead towards every citizen getting an ID at no charge.
The goal should be to run up the score of the popular vote as much as possible even in the face of anti-democratic shenanigans like gerrymandering or statistical voter suppression, e.g. how the SAVE act would make it harder for women (who lean Democratic) to exercise their right to vote (because it will require more documents for people who have changed their last name to prove their identities).
Manipulating the election and perpetuating minority rule rather than responding to popular will has its limitations. We need to be prepared for a second civil rights movement.
Making it hard for politically inconvenient humans to vote is more straightforward than granting AI agents the right to vote.
To secure network effects for themselves. This is one of the reasons the ASF was founded.
https://httpd.apache.org/ABOUT_APACHE.html
We realize that it is often seen as an economic advantage for one company to "own" a market - in the software industry, that means to control tightly a particular conduit such that all others must pay for its use. This is typically done by "owning" the protocols through which companies conduct business, at the expense of all those other companies. To the extent that the protocols of the World Wide Web remain "unowned" by a single company, the Web will remain a level playing field for companies large and small. Thus, "ownership" of the protocols must be prevented.
Output is a separate issue from training. Courts will never decide that a identical copy spit out by an LLM is non-infringing simply because it went through an LLM stage. Copyright laundering is wishful thinking by tech folks.
License the training corpus and encourage copyright suits against outputs from models trained on unlicensed corpora.
More likely it will be taken as a plan for "how to win at any cost and then humanize yourself later".
AI is finding vulnerabilities in all kinds of software written by humans.
I'm aware — I've used LLMs to find vulnerabilities, myself. But it doesn't follow that because AI can find them that AI can find the optimal fix, because fixing vulnerabilities often involves tradeoffs.
Also, can we please have a civil discussion?
"Make my web app secure."
Even if the specific image being infringed were not in the corpus, it's possible that a court would return a judgment of copyright infringement.
Consider the case where someone deliberately prompts the AI to build a facsimile image and the AI does a creditable job after some tweaking.
As much as I like the Apple Passwords app, one of its downsides is that if I have my TOTP app on my iPhone, both passwords and TOTP live on the same device. So for many services I use Bitwarden for passwords.
Here is the relevant quote from _The Cathedral and the Bazaar_[1], which was given the name _Linus's Law_[2] in honor of Linus Torvalds:
Given enough eyeballs, all bugs are shallow.
[1] http://www.catb.org/~esr/writings/cathedral-bazaar/cathedral...
Client says "access denied"
Server says "here's everything"
hahahaha
Hire me (just kidding... unless?)
FIFA is a legendarily awful organization. In my weaker moments reading your piece I thought to myself how nice it would have been if someone more ruthless than you had been made an example of them.
RCV completely solves the “spoiler candidate” problem, which is a huge issue limiting choice and innovation in the two-party-dominated US. Approval Voting remains susceptible to spoilers.
In the US there are already people who complain that any election they lose must been “rigged”, including the current occupant of the White House. Choosing Approval Voting over RCV is not going to bring such people around; it’s rhetorical advantages are inconsequential.
Ranked Choice Voting makes it easier to vote for “less bad” candidates.
RCV also tends to work against polarization, since it rewards candidates who are at least acceptable to a broad swath of the electorate.
It may not be the “answer” for all that ails the American political system, but it would help.
ETA: Unlike many other reforms it's also doable within the constraints of the current constitutional order and is hard for SCOTUS to torpedo (though I suppose I shouldn't underestimate SCOTUS).
Does anybody run a local agent on a Mac using an outboard GPU?
Yes, and that demonstrates that developers are not immune. And so, developers who suspect they're being asked to do something illegal (but aren't sure) are going to act as sticklers who irritate enterprise architects until you take concrete action to reassure them.
Complain about them, denigrate them, upbraid them for performing analysis outside their primary expertise, fire and replace them.... none of that changes the incentive structure that shunts people in the implementation role towards conservatism out of a perceived need for self-preservation.
But here we're talking about developers being asked to implement decisions which they don't understand to be compliant.
Engineers are not shielded by their implementer role if they participate in illegal activity. James Robert Liang was a rank-and-file engineer for Volkswagen and he got jailed for his role the VW emissions scandal[1].
No matter how much an enterprise architect or compliance officer promises "it'll be fine" to the developer, the developer needs documented CYA. An enlightened organization would perhaps find ways to expedite that CYA documentation rather than demonizing programmers as a class.
[1] https://apnews.com/general-news-988ea2ae45694b37b320e68cefe3...
I am skeptical that developers who implement a non-compliant solution that gets a company in trouble get off scot-free.
If the company you work for actually had such a no-fault culture, I doubt you'd be criticizing programmers so aggressively for being sticklers, but would instead be trying to understand and account for the systemic factors (including human factors) behind their behavior.
In your world, do subordinates ever get scapegoated for bending the rules at a boss's behest?
Eventually there will be successful copyright lawsuits for derivative images produced by LLMs. Copyright laundering is an illusion.
There are lots of sites that provide images that somebody has claimed are public domain. But for significant use, you what you really need is provenance documentation.
These folks seem to be more up-front about the issue than many sites I’ve seen:
https://pdimagearchive.org/reusing-images/
On each image page we communicate to the best of our knowledge the rights status of both the underlying work and the digital copy of this work. We provide this information based on a basic knowledge of copyright law and what is communicated by the source institution — it is strictly meant as a guideline and it should not be taken as legal advice. We admit no responsibility for any untoward consequences that may arise through reuse of material featured on our site. If you are requiring certainty as to usage allowed for an image, then you are encouraged to check with the source institution and make your own investigations.
A great opportunity for selective enforcement!
I'm using VSCode dev containers, powered by Podman on a Mac. Most people would probably choose Docker over Podman but I'm weary of Docker and wanted to try something else. I would not consider myself an expert on containers but with the help of Claude I've been able to fight my way through various challenges:
* Persist a volume for Claude so that conversations don't get blown away with every container rebuild. An attacker may still be able to get a Claude token from me, which is something I'd like to tighten up in the future.
* Fix file permissions issues by running rootful inside the container. (The container process still runs on the host as an ordinary user. Since my threat model is "compromised dependency scanning for credentials in project dir and home dir" rather than "attacker escaping the container", I figured that was good enough to get started.)
* Work around architectural availability issues with precompiled PyPI libraries. This I punted on by choosing a different approach and eliminating the problematic dependency (by writing my hobbyist CAD 3d printing stuff using Blender extensions instead of CadQuery). I've gotten the impression that dependency compatibility with a container workflow is an ongoing challenge.
* Run a database in a docker-compose sidecar for integration testing.
For all the projects I'm containerizing I'm the solo dev with full control over the Git repo so I can make the call to add a `.devcontainer/devcontainer.json` config file. I haven't yet explored how to isolate projects I don't control.