HN user

undecisive

1,337 karma
Posts6
Comments317
View on HN

We're in the worst of all worlds. Sometimes it feels like you only know it's a human because the AI would have over-explained.

But yeah, this security company only prodded, what, once or twice a month for 7 months? I mean, if they really truly cared, they would have found the CISO's home address, broken into their house, painted the reproduction steps on the inside of their front door (to avoid accidental disclosure), created a few "beginner friendly" repos with a git.exe that DDoS's their auth servers, got a job as a night cleaner in their offices, waited for one of the developers to leave their machine unlocked then fixed the vuln themselves.

It's just another capitalistic money grab, them posting their security concerns. Ugh.

They have "clarified" elsewhere on here that the normal citizenry get a legal exemption [waves hands mystically] somehow, and that they're only blocking people when they legally have to.

Obviously (to the rest of us) if the agreement says otherwise, then they're saying that it's LE that is forbidding the citizens of these countries, and it's not (entirely) the government's fault, which completely contradicts what they're trying to say.

We should probably be clear that this document is most likely a backside-covering exercise; it exists so that people can't sue LE for denial of service without a just cause, and so that the US can't prosecute them for intentionally shipping cryptographic services, or some such rubbish.

If you live entirely outside the US legal system, or its multifaceted tendrils, and if you don't make too much noise, you may be fine. Obviously that's a far cry from a "right to free speech" level of protection, but then LE have no obligation to provide that to people outside the US, and arguably non-rich citizens within the US lost that a long time ago.

As with anything word-gamey involving internet, you will probably have to trim down your dictionary. While I'm very glad my "sxxg" beat their "txxt", the first probably shouldn't be allowed (although there are non-rude definitions) and the second definitely shouldn't have!

Still, a very fun game, well made.

Analogies are not the problem. In fact, an analogy is like a good knife; sharp, removes problematic parts, and totally unethical unless it knows the motivations of its wielder.

Seriously though, yes it is obvious why analogies are so often used, but I think you have it the wrong way round. They are a form of proof by negation; you don't have to find a thing exactly like the subject of the argument.

It's a way of fighting against bad arguments; If I say China is bad because X, Y and Z and also, their flag is red! They must be evil. If you then tell me that this argument could also be applied to the Red Cross/Crescent, you have negated my argument by analogy. You don't have to negate every argument I made; but at least then we can treat X, Y and Z on their own.

The problem with this writeup is, there really are no other powerful arguments in it.

And I'm pretty sure C4 is great for controlled demolition of highly dangerous buildings. Or do you want adventurous people to hurt themselves?

I think that's where most people thought that this article was going.

Shall we just have that debate anyway? :D

The big question that I hoped the article might address: Can AI ever be ethical (within the norms of what the average Jo(e) considers ethical), or have we forever poisoned the well?

If the technology and mathematical underpinnings have been created on fundamentally immoral grounds (IP theft, energy / water excesses, etc) what would we have to do to produce an entirely - or even mostly - ethical AI stack?

Is it even possible, given the dependencies on (Lithium / Israel / fossil fuels / conflict mining / capitalistic exploitation / any other morally questionable underpinning you might think of) to re-do the work to such a point that we could "black box" our way to decently function LLMs?

Assuming that comes with a caveat of rolling back the technological progress, how far back do we have to go? It feels like the bronze age is a step too far, at least on the basis of my "average Jo(e)" test above - but what is considered reasonable?

Then - and only then - would it make sense to ask how to make the content generation itself ethical.

It feels like the Nazi medical science issue all over again, except nobody really cares as much about this one. But socially, it feels like an anti-capitalistic uprising is on the horizon, so maybe if that happens, a moral aversion to the state of AI might piggyback onto it?

Not that I want it to. Quite like AI really. Feels like the background immorality radiation of the earth is quite high anyway, maybe AI isn't the thing to fluff our feathers about. But it's certainly an interesting thing to mull as we weep over our non-gm oat milk babyccinos, pitying at the state of the world.

(I'm really an upbeat person, honest...)

This article in a nutshell: AI will never be ethical or safe, because no tool can ever be ethical or safe, without it knowing the complete motivation of any person using it and every person who might receive its outputs.

Wasn't the article I was expecting! Not sure it helps much, except maybe if you wanted to muddy the water of ethics-and-AI discussions.

It's interesting; I'd imagine very similar design briefs (friendliness, breadliness, etc)

The ICBINB font is almost a semi-serif, almost like a sans serif that's slightly melted, whereas I'd say the crumpet is fully serif. The "e", "L" and "v" are pretty different. And I'd say the ICBINB font lends itself better to tighter spaces, whereas the crumpet font seems to beg for more space.

But certainly, I could see one being used to replace another in a pinch - but I'm not a font specialist (graphologist? Is there a word for a person who studies fonts?)

No, I agree. That said, I think a lot of that particular shift is down to a) increased individualism b) an emphasis on the healing power of personal boundaries and c) the rejection of unity as an overriding good.

People are far more happy to cling to the tribe they choose, and the tribe that has their back, over the tribe they were born to. Then, there are those who see that trend as dangerous to society (where, in many cases, society is really just a proxy for their own power or social status - ironically as viewed through their own chosen tribes more than the tribe they were born to)

That is to say, I don't think it's the political views that are splitting the families. Individuals have decided that care for each other should come secondary to those political views. I feel like there used to be a certain amount of care in the "sweeping under the rug" - it was the tribe against the world, it was protecting the family image as much as it was protecting the individual from society. These days, being a thing "in private" means being a thing alone, and that's no longer a compelling thought when external tribes are willing to embrace you.

Which probably applies to software tribes just as much as family ones.

Yeah, certainly tickles a few neurons.

I feel like BDFLs are akin to the concept of village elders; they're not immune to corruption or scandal, but they often have this beloved status that can paper over a lot of cracks. That's probably dependant on their leadership style - the hard headed (Linus, DHH) vs the grandfatherly (Matz, Van Rossum).

Which, going back to your note on geopolitics, leads me to wonder: Is it just that more power corrupts more, or is it that (modern-day definitions of) democracy require a desire for power? I guess as the "FL" part of "BDFL" comes to bite more of the communities, we'll see better how different succession styles have different effects. I also wonder if the analytical nature of the individuals within the "populations", and inability to police defectors will mean uprisings will be more successful, either in causing BDFL attitude adjustments, or just overturning the community completely (for example, there's already a lot of momentum for a complete fork of Rails)

(Edit: having submitted this, I now see others have had very similar thoughts! Definitely an excellent conversation topic)

1) explained why relying on Docker Hub is dangerous

I mean, that's the other 770 words of the article. Except they're just giving their experience, and allowing you to come to your own decisions - because otherwise people might legitimately call them out for "smear" tactics.

2) what the alternatives are, and why they're not good enough

"as we grew we started mirroring our images to Gitlab and Quay.io," <= Alternatives (that they are using)

"Docker Hub is the de facto standard Docker registry, literally, if you don't specify a registry when pulling an image Docker will invisibly prepend docker.io/ to it." <= Why they're not good enough (extra config step)

3) what needs to change, which may include consumer behavior - things that we control, because we really don't have control over Docker Hub.

"but it does feel like we need to do something. Whatever we decide, we'll keep you informed." <= They're not there yet, but they're open and honest about it

use fewer words, because people's attention spans are really short these days,

I can see that you have a short attention span.

which naturally requires the words to have more dense and intense meaning

You are a belligerent, self important ignoramus who incorrectly believes the world needs his opinion. <= genuinely, do you like this style of discourse? Why are you treating shock language as a status quo worth maintaining, but trust and expecting decency from a corporation as some kind of unacceptable failing?

I love how you intentionally cropped off the first two words of that sentence, try to make out that their 30 word side note was actually the whole point of the 800 word article, and you STILL didn't manage to make them sound as malicious as you wanted to.

"give us a hint" - "Stop begging!"

As I say, you're clearly coming into this with a strong unjustifiable bias, I can tell because you're forced to use words like "smear", "parasite", "exploiting", "beg", "indentured servitude" - it's a cover for the cognitive dissonance.

But if you genuinely would like a discussion about the pitfalls of the funding models of open source, yeah it's a reasonable question that has never been satisfactorily answered. There are whole PHD projects on the subject, and nobody's cracked it. Giving money to open source projects is difficult for many reasons - ranging from tax treatment to geography even to legality. Providing services is somewhat easier, but in many companies in some countries even that comes with geopolitical legal issues. Marketplaces only work if you have something to barter, and if you would like to contribute to the freedoms you enjoyed, it's hard to make that work in a marketplace model, not to mention that even providing people the option of donating money for a product comes with overhead (legal / technological / service / financial network / server etc).

If you would like a discussion about ensuring abstractions over the services you use, sure, I'm here for it. Of course, it's hampered by a lack of consistent interfaces, and in some cases interfaces that ensure they can never be smoothed over. But that sounds like a cool open source project - in this case, I guess it would be an anyhub kind of deal that can serve images for different use cases, paired with a DSL for defining a resource (that can generate a dockerfile / docker compose file, in docker's case). Of course, serving images isn't free, but you've cracked the problem of funding models of open source, right? Right?

And you mention indentured servitude, loaded though that phrase is, it's also a poor analogy. Tax would be a closer match. You depend on open source and make money off it? Great. Giving open source a cut of that pie in some way seems the morally right thing to do. How you do that is up to you, but telling people they can use your service then pulling the rug while simultaneously ghosting them? That sounds kind.

You know what, I think you're right - it's so much easier to lambast someone for daring trust or daring to express concern than it is to do anything meaningful to improve the landscape.

Here's a tiny bit of missing context.

This blog is for LinuxServer.io, who build repositories that produce free docker images, for free, paid for by donations, for a bunch of open source software. By the looks of things, they are literally a charity.

Conversely, their complaint is not "aren't docker rubbish? Let's mob 'em" - it's "heads up, something seems to be wrong and docker are not responding to anything, chances are there's trouble brewing - we're gonna start looking around and if you're depending on this, you should too"

I would say calling "the open source community" a "parasite" because they're using free services from companies that have benefited greatly and earned a lot of money from things given freely by the open source community seems weird.

Seems like a lot of people on here very concerned about those poor struggling corporations, and their exploitation by those evil open source charities. Feels like an evil political wind is blowing, wonder where that's coming from?

I just tried it with phi3.5:3.8b-mini-instruct-fp16 - it didn't work with the base question, though interestingly the reasoning decided that strawberry was spelt s-t-r-a-w-b-e-r - which explains why the AIs have such a hard time with this question. I also tried it with my current favourite programming question too - What programming language is this whole line of code using? `def obfuscated_fibonacci(x)` - and like all the AIs, it was convinced the answer was python (the correct answer is ruby - python needs a trailing colon - but most LLMs will swear blind that it's python). It didn't even consider ruby as a possibility. Nobody uses ruby anyway :D

Thanks for the fork and the suggestions though - looks like I'll be having fun with this over the week!

Yeah, it was paper cuts - for example, if you don't have git installed inside your devbox, it wouldn't work because of different glibc versions. Which would be fine, but my shell prompt uses git. So there has to be a nix version of git installed for every project for my machine, despite almost no projects technically needing it.

There were a couple of other libraries, can't remember which ones. I remember once having a fun chain of a library that depended on a library that depended on two libraries that in turn depended on glibc, and for some reason the last link of the chain, only one of the libraries was hitting the system libc incorrectly - that was a fun one to debug. I think I ditched that dependency in the end, it was the only solution (and was clearly badly written).

One of my projects used an older version of ruby. In that case, there was a gem to connect to the database, and that gem links to the db client library, but the db is new and the ruby is old and guess what? Two different versions of glibc, both being used within the nix ecosystem.

I worked around a lot of it with LD_LIBRARY_PATH (I think? from memory) which I had to unset for everything in devbox, and used aliases to set it to a backup of that env whenever I found a binary that needed it - and then they tried to fix that, but it just seemed to stop my workarounds from working, so I had to come up with new ones.

But yeah, it was a wild ride. Most of it came back to glibc or environment variables or both, and probably me doing something I really ought not to do (like support old projects). Alas, for me, it wasn't worth the effort - but I sure learned a lot.

My experience of Devbox on Linux has been highly disappointing. I gave it a good go, had it running on my main project from February to May.

In case you hadn't realised, the very concept of having two sets of binary distributions on one machine, vying for superiority and the correct version of glibc... is fraught.

Most of my use was with rails projects, and I can't recommend it.

Coupled with an abstraction that tries to save you from Nix, but almost entirely fails, you end up with a bloated hellscape where every time you load your project it will unnecessarily reinstall your packages and several times an hour it will have forgotten curl exists and so you have to manually reinstall curl (not-so-slowly increasing your /nix folder's size), every week or two a new version of devbox completely changes the workarounds you need to do, and don't try to garbage collect nix or it will delete vital files, and you end up scrubbing it all and starting again.

In python, it overrode the path so I couldn't get it to reliably use the binaries in the venv. Pip and Python were using packages in different places and I couldn't get them to converge for love nor money.

The devbox team were great and really tried to get things working, but in the end I couldn't get it to work with enough stability to properly recommend it to my team, and if I wanted it to half-work for any substantial length of time I had to lock to a version of devbox.

Obviously, ymmv, please do give it a try, it's an impressive project. But my view is that it's trying to do something that is very very hard, and for that you need a very clever solution. And this is a very clever solution, with very clever bugs, and so it's not something I'd recommend jumping into with both feet.

Cunningham's law baiting - I love it!

So yeah, turns out it's nothing to do with the 8266's board, and everything to do with the chosen relay module. Since it has nothing to do with driving the relay, it doesn't need to be connected. But if it were connected, whenever it is high, the relay board connects it to the reset, so the chip gets reset.

So you are bending it simply to ensure that pin can't be plugged in to the relay

Ahh! So it's not the ESP that has an extra connection, it's the relay breakout board.

That makes much more sense.

Yeah, I guess you would need to sound the doorbell every boot, and that might be inconvenient in places with a lot of power supply issues / loadshedding.

That said, that quick-boot-button link? That's some brilliant info right there.

Am I missing something? Neither schematics nor my limited understanding of physics explains why you need to, nor how it is possible to, bend one of the pins to disconnect GPIO0 (chip-row, 3rd from the left) from the reset pin (edge-row, 2nd from the left)...

Is it me? Have I been misusing my 8266s all this time?

Otherwise, good article, nice idea, great conclusion!

As is often the case, the truth is far more complicated.

Firstly, the bridge - while up to code - did not have the kinds of buffers that could have been installed, or arguably should have been installed [1]

It isn't wrong to say that if you are going to authorise large container ships, if you are going to profit from large container ships as a harbour, and you are not going to invest properly in the infrastructure, you should take some of the blame when things inevitably go wrong. I don't know whether such buffers would have entirely saved the bridge or the people on it.

It also isn't wrong to say that if you are operating a large container ship, you should ensure it has failsafes in case of power failure. I don't know what failsafes exist (emergency anchors? Some kind of manual rudder?) that would be effective on a ship that large.

It also isn't wrong to say that given the public outcry, a scapegoat will likely be chosen, and it's more likely that they will scapegoat the foreigners rather than blame the politicians in charge of public spending.

[1] https://www.theguardian.com/us-news/2024/mar/26/baltimore-br...

--libcurl 2 years ago

TIL - I have never used make without a Makefile! Thank you!

--libcurl 2 years ago

To compile it you'll need to tell it to link to libcurl, e.g. with -lcurl on gcc:

    curl https://ifconfig.me --libcurl ip_fetcher.c 
    # Output: your ip address, and a file ip_fetcher.c

    gcc -o ip_fetcher ip_fetcher.c -lcurl
    # Output: no errors, just a file ip_fetcher

    ./ip_fetcher
    # Output: your ip address
(I'm sure most people are saying "no duh" right now, but I'm probably not the only one on here who doesn't write C code every day!)

Colonialist: To my mind, it was the 's' on the phrase "primitive peoples". In other words, it is implying that people in our "civilized" society suffer from this, but those more primitive peoples outside of our society may be exempt - simply because they do uncivilized things that our civilized ladies wouldn't dream of.

Classist: Because of course, that's bunkum. Because even in 1960's "civilized" american society, maybe the upper class lady would keep herself "in confinement" but that doesn't mean that the majority of women would or could.

So no, I wouldn't say it's anti-classist.

(Note: I had presumed that George Blonsky was a doctor - but no, apparently he was a "mining engineer". I suspect he would have been reasonably well educated, but maybe not if he thought spinning pregnant women around to expel their babies was a good idea. So I don't know - maybe the classism was accidental. But it's definitely there.)

In the case of a woman who has a fully developed muscular system and has had ample physical exertion all through the pregnancy, as is common with all more primitive peoples, nature provides all the necessary equipment and power to have a normal and quick delivery. This is not the case, however, with more civilized Women who often do not have the opportunity to develop the muscles needed in confinement.

Ignoring the depressingly-predictable classist/colonialist tone, it's interesting to note that modern medicine recommends things like pelvic floor exercises to help with childbirth, primarily to prevent unwanted urination during childbirth and incontinence afterwards it seems.

But this observation - if correct - might lead us to conclude that certain types of exercise help the actual act of childbirth more than others.

Do we know if this has been corroborated / debunked? I'm wondering if there are any agencies out there with specific recommendations for those who are trying for a baby, for exercises that are actually proven to make childbirth quicker or less painful?

Sure.

So I discussed this situation generically, because the specific situation doesn't really matter given the question asked. And no, I said it was impolite - but I totally understand that impolite is a big step up from toxic.

The bigger issue is, and maybe this doesn't apply here, but creating a situation where there may be a legal copyright claim to be made simply gives the a-hole more leverage over you, which is exactly what you don't want, if even the mention of his username is triggering.

(I won't point out that you mentioned his username 10 times in your blog post!)

So weigh up the risk/reward. If he's done a DMCA, and you've batted it back, the next step is legal proceedings. A license is exactly that - a license, it never assigns ownership. If I remember correctly, AGPL3 has protections so that he cannot revoke the license on a whim - unless you break the AGPL3 license.

You will never own the copyright to that file, no matter how much you desperately want to, no matter how many times you change the file, no matter if you remove his name, no matter how much you feel like you've paid in dealing with him being a dick. If he can make a case that the file you have is not significantly different in nature to the one he wrote, he still owns that file.

Toxic people will be toxic, but never get into a pissing fight with a skunk.

IANAL, but I think it comes down to your interpretation of section 4:

You may convey verbatim copies of the Program's source code as you

receive it, in any medium, provided that you conspicuously and

appropriately publish on each copy an appropriate copyright notice;

keep intact all notices stating that this License and any

non-permissive terms added in accord with section 7 apply to the code;

keep intact all notices of the absence of any warranty; and give all

recipients a copy of this License along with the Program.

So by removing the copyright notice from "each copy" of the "convey"ed source code, I think you could argue they violated this.

But as others have argued, even if you don't believe that this section forbids it, the polite thing to do would be to either a) get permission to remove the copyright notices, or at the very least b) create a file (e.g. CONTRIBUTORS.md, or a section of the readme) and place the copyright information in there. Saying "Ooh, we don't like X's name at the top of the file, it's too ugly" without any attempt to maintain some acknowledgement might not be a violation, but certainly isn't within the spirit of the AGPL, the main point of which is to "(1) assert copyright on the software".

Yeah, it's awkwardly worded. I must have read the same sentence 3 times before I realised what it was saying. Looking at the latest version of the TOS, the new company is operating under the name "ManyCam ULC"

No, Visicom is the old owner, as per the quote in the original post:

“ManyCam is now under new ownership. […] Visicom Media stands by the Lifetime customers and will continue to support them by arranging with the new owner for a total of two years of free subscription."

Yeah. Lots of red flags in that EULA, including bits that don't seem to make any sense:

"You agree any legal dispute involving ManyCam services and software must take place in the state or federal courts in Montreal, Quebec."

and

"You consent to exclusive jurisdiction and venue in Montreal, Quebec and waive the defense of forum non convenience."

and yet

"If a U.S. court finds any part of this license agreement unenforceable then the remainder of the agreement will continue intact and in full force and effect."

Basically, it's your typical "We have rights, you have no rights" kind of contract. If the OP had even briefly scanned that "agreement" (and let's face it, most of us don't) I'm sure they would have realised that their "lifetime" license had no legs.

Poor Tim. (There's a very British joke for you.)

The post tries to recognise that it's not as easy as this:

you try to help them level up: pay for classes, conferences, and/or books; connect them with mentors or coaches; figure out if something’s in the way and remove the blocker.

The reason the post can't come up with an answer is that there isn't one that we like.

Because at a simplistic level, it's a blocker. Maybe they have the knowledge, but not the experience. Maybe they have the experience, but not the organisation skills to make use of the experience. Maybe they have the organisation skills, but not the discipline to use them. Maybe they have the discipline, but not the discernment to know how to keep or retrieve good useful notes. Maybe Tim's just a bit dim.

Once we know what that blocker actually is, maybe - just maybe - we can find a way to overcome it or mitigate it.

But it's hard - because however nice Tim is, every fibre of his being wants to smooth over the cracks in his ability. The nagging pain that fuels his impostor syndrome doesn't want to be found - he wants to blend in, he doesn't want to be embarrassed or called out. And even if he tries his hardest to open up to his equally nice boss, he may not be able to articulate why he gets himself into hot water. He might not even know himself what the blocker is. (Unknown unknowns, and all that.)

Traditional corporate wisdom would have Tim "fail upwards", because by the time his "blocker" is noticed, it's easier than firing him. As much as we hate this good fortune that seems to reward the incompetent, it quite often works and ends up being in the best interest of the company; the skills that are missing from a "worker" are probably not needed in a manager, and being a people-person at heart who trust his reports... well, that may make him a far better manager than many of his peers.

It's not a nice answer, but it's an answer that unfortunately seems proven to work.