HN user

vayup

234 karma
Posts0
Comments48
View on HN
No posts found.

They've got, ballpark, $5t to $10t to make back in the next 5 years, or the hardware buildouts will start getting written down.

Depreciation and write-offs are about accounting models. Hardware will still be running after five years and still be making money. They may not be as efficient as the new hardware, but they will still be making real money even though they are valued at $0 in the books.

The strongest arugument made is that hybrid is more complex, more work and therefore more risky.

As someone who has been implementing such systems for 20 years, I don't buy this. In my mind, it's equivalent to saying "Seatbelts add complexity to the safety system, and it's more work. So let's get rid of it."

In this argument, the benefits of hybrid/seatbelts are not factored in adequately.

You are absolutely right that it is easy to rule out obviously bad choices, such as 3 of 3. However, determining the actual quorum to use is a qualitative risk analysis exercise.

Considering that this is an election for a professional organization with thousands of members, I am going to go out on a limb and say that it should be easily possible to assemble a group of 5 people that the community/board trusts woudn't largely collude to break their privacy. If I were in the room, I would have advocated for 3 of 5 quorum.

But the lifecycle of the key is only a few months. That limits the availability risk a little bit, so I can be convinced to support a 2 of 3 quorum, if others feel strongly that the incremental privacy risk introduced by 3 of 5 quorum is unacceptable.

Few lessons to relearn here:

- Availability is a security requirement. "Availability" of critical assets just as important as "Confidentiality". While this seems like a truism, it is not uncommon to come across system designs, or even NSA/NIST specifications/points-of-view, that contradict this principle.

- Security is more than cryptography. Most secure systems fail or get compromised, not due to cryptanalytic attacks, but due to implementation and OPSEC issues.

Lastly, I am disappointed that IACR is publicly framing the root cause as an "unfortunate human mistake", and thereby throwing a distinguished member of the community under the bus. This is a system design issue; no critical system should have 3 of 3 quorum requirement. Devices die. Backups fail. People quit. People forget. People die. Anyone who has worked with computers or people know that this is what they do sometimes.

IACR's system design should have accounted for this. I wish IACR took accountability for the system design failure. I am glad that IACR is addressing this "human mistake" by making a "system design change" to 2 of 3 quorum.

Spot on. Defending simplicity takes a lot of energy and commitment. It is not sexy. It is a thankless job. But doing it well takes a lot of skill, skill that is often disparaged by many communities as "political non sense"[1]. It is not a surprise that free software world has this problem.

But it is not a uniquely free software world problem. It is there in the industry as well. But the marketplace serves as a reality check, and kills egregious cases.

[1] Granted, "Political non sense" is a dual-purpose skill. In our context, it can be used both for "defending simplicity", as well as "resisting meaningful progress". It's not easy to tell the difference.

A definition of AGI 9 months ago

Precisely defining what "Intelligence" is will get us 95% of the way in defining "Artificial General Intelligence". I don't think we are there yet.

Some of the stuff that was extracted from the unencrypted traffic in the link:

- T-Mobile backhaul: Users' SMS, voice call contents and internet traffic content in plain text.

- AT&T Mexico cellular backhaul: Raw user internet traffic

- TelMex VOIP on satellite backhaul: Plaintext voice calls

- U.S. military: SIP traffic exposing ship names

- Mexico government and military: Unencrypted intra-government traffic

- Walmart Mexico: Unencrypted corporate emails, plaintext credentials to inventory management systems, inventory records transferred and updated using FTP

This is insane!

While it is important to work on futuristic threats such as Quantum cryptanalysis, backdoors in standardized cryptographic protocols, etc. - the unfortunate reality is that the vast majority of real-world attacks happen because basic protection is not enabled. Good reminder not take our eyes off the basics.

now Google has stopped providing device trees for the newer ones which I therefore won't buy

Yeah, that sucks. I don't know if they made any official statement on that. I hope they will continue releasing device trees. It's a feather in their cap that the best mobile device to use for de-Googling so far was a Pixel device (with alt OSes). I hope they won't lose that distinction.

Dare I say it, I think we're being too harsh on Google here.

When you own a massively successful consumer product like Android, which is foundational to users' lives, you have an obligation to your users to keep them safe*. Sometimes you will have to choose between protecting users who don't know what they are doing at the expense of limiting users who know what they are doing. In this case, they have chosen to err on the side of the former.

I get it. It's OK to not like this development, especially if you use a lot of sideloaded apps. However, if you call this "anti-consumer", then perhaps you and Google have different notions of who the consumers are.

All said and done, Android/Pixel is still the most open mobile platform. Users are still free to install other AOSP-based OSes such as Graphene OS, which have no such restrictions on sideloading.

PS: I'm a former Google employee. I don't think I am a Google shill. I worked on mobile security, but I was not involved on this matter.

* I am using "safety" as a catch all for privacy and security as well.

With VoiceBuddy:

- You can just focus on the content and speak naturally. It is extremely smart in applying punctuation and formatting.

- You don't need expensive Microphones to get good accuracy. The crappy microphone that comes with your laptop should be good enough.

For me Dragon was pretty much unusable without expensive microphone setup. And even then, it needed constant intervention for punctuation and formatting.

Here's an example of what I mean. In these tests, I just spoke the words, I did not dictate any punctuation. Mistakes annotated by ~

VoiceBuddy (with microphone built into my cheap Logitech Webcam): The color of animals is by no means a matter of choice. It depends on many considerations, but in the majority of the cases tends to protect the animal from danger by rendering it less conspicuous. Perhaps it may be said that if coloring is mainly protective, there are to be but few brightly colored animals. There are, however, not a few cases in which vivid colors are themselves protective. The kingfisher itself, though so brightly colored, is by no means easy to see. The blue harmonizes with the water and the bird, as it darts along the stream, and looks almost like a flash of sunlight.

Dragon 15.6(with the same microphone), unusable due to recognition errors: ~the color of ~monuments~ is by no means a matter of choice~ ~it depends on many considerations~ but in the majority of the cases tends to protect the animals from danger by rendering it less conspicuous~ ~perhaps it may be ~saidthat~ if coloring is mainly protective~ ~and~ ~not~ to be but few brightly colored animals~ ~there are~ however~ not a few cases in which ~we~ ~would~ colors ~of~ themselves protective~ ~the kingfisher itself~ though so brightly colored~ is by no means easy to see~ ~the blue harmonizes with the water ~the~ bird~ as it darts along the stream~ and looks almost like a flash of sunlight~

Dragon 15.6 (with $220 high-end microphone setup - Sennheiser): The color of animals is by no means a matter of choice. It depends on many considerations~ but in the majority of the cases tends to protect the animals from danger by rendering it less conspicuous~ ~perhaps it may be ~saidthat~ if coloring is mainly protective~ there are to be but few brightly colored animals~ ~there are, however~ not a few cases in which we would colors are themselves protective~ ~the kingfisher itself, though~, so brightly colored~ is by no means easy to see~ ~the blue harmonizes with the water and the ~board~~ as it darts along the stream~ and looks almost like a flash of sunlight~

There is a whole lot of commerical products built out of what we consider hobby projects (Adruino, Raspberry Pi). Eg: digital displays, industrial equipment controllers etc. All of this is clubbed under the nebulous IoT moniker.

My take: Qualcomm hopes to leverage Adriano adoption to expand their IoT share, and also to grow Adruino's footprint to include more smart IoT devices using Qualcomm's chipsets (Eg: Robotics)

A lot of folks are arguing that the real problem is that they refused to use US cloud providers. No, that's not the issue. It's a perfectly reasonable choice to build your own storage infrastructure if it is needed.

But the problem is they sacrificed "Availability" in pursuit of security and privacy. Losing your data to natural and man-made disasters is one of the biggest risks facing any storage infrastructure. Any system that cannot protect your data against those should never be deployed.

"The Interior Ministry explained that while most systems at the Daejeon data center are backed up daily to separate equipment within the same center and to a physically remote backup facility, the G-Drive’s structure did not allow for external backups."

This is not a surprise to them. They had knowingly accepted the risk of infrastructure being destroyed by natural and man-made disasters. I mean, WTF!