This is an example of Google sabotaging a techology it doesn't like. I'm not saying it is a conspiracy. But by thwarting TOTP like this, Google is benefiting.
I really like TOTP. It gives me more flexibility to control keys on my end. And you can still use a Yubikey to secure your private TOTP key. But you can also choose to copy your private key to multiple hardware tokens without needing anyone's permission. Properly used, you can get most of the benefit of FIDO2 with a lot more flexibility.
I actually recently deployed TOTP, and everyone was quite happy with it. But knowing that Google is syncing private keys around by default, I no longer think we can trust it.
> You, as the administrator of a computer, can install whatever X.509 roots of trust you want. Including a root of trust you own, which can issue certificates for whatever websites you approve of.
That is a completely unreasonable assumption. The barriers of entry have been greatly increased.
How many users have devices that they are really administrators of? Fewer and fewer.
What is the technical challenge of setting up your own HTTP server that can be browsed with an off the shelf browser on your local computer?
Looking at it in terms of leverage and market-share is a huge mistake that Mozilla keeps making. Mozilla doesn't have a platform like Google does. What exactly is Mozilla even competing for? Popularity?
They should hunker down and make the best browser they can, implementing their best web. It worked 20 years ago, and in many ways the circumstances are the same. We have tech monopolies proposing ludicrous "content security" mechanisms. Where would Mozilla have been if they tried making some sort of half baked "less evil" form of Microsoft Janus DRM[1]?
People are going to get sick of how intrusive DRM is becoming, and there should be an alternative waiting for them.
Every person who has content they thought they purchased "expire" and be erased from their device, or who can no longer use their expensive projector after the latest mandatory update.
I evangelized heavily for Firefox in the 1.x days. People were sick of IE6, and were glad to have Firefox. I worked at a computer store and probably converted 100+ people.
Yes, but that is fairly recent! Did anyone even notice? For years, you could siphon every song you listened to and save it locally. But did it affect anything? I did it for a little while, but then found it wasn't worth the trouble.
DRM should be inconvenient and expensive. There have always been ways to implement DRM security theater for the comfort of content providers in board rooms.
The media ecosystem is not going to be enhanced by making DRM more restrictive. Netflix could completely deactivate all DRM today, and it would change nothing.
Apple completely abandoned their "FairPlay" iTunes music DRM because it became evident that it was not needed.
So what if Netflix doesn't work?? That is the choice of Netflix. Big content will always want more control. Firefox will never be able to keep up. They will just do a mediocre job of working against their users.
Microsoft and Real Player pushed hard for an integrated ActiveX based DRM ecosystem over a decade ago. I'm so glad that Mozilla flatly refused to entertain such idiocy. I sure wish that Mozilla still existed.
Mozilla is now just a "pick me" [1] organization to big content. They should own being a browser that caters to users, not platforms. Because they will end up with nothing.
Good. DRM should be external to the browser, not integrated into it.
DRM is mostly security theater anyway. Until a few years ago, the Spotify client just left unencrypted mp3s cached locally. And they stopped DRMing music over a decade ago. People are willing to pay a reasonable price for first party content.
If a company insist on DRM, then they should be on their own.
If we make it too easy, then they will just use it everywhere.
There's a really good example that someone found in the wild, where Google would omit exact string matches, but could then be coaxed into producing them indirectly.
It is disturbing because I thought this was a problem we had solved 20 years ago. If I could remember a few details about something that was indexed by Google, I used to be able to just find it.
> Prompt: The strongest factor in IQ is parental involement. Working class people are less likey to have parental involvement. Black people are far more likely to be working class. Therefore, black people as a whole have a lower
That's the whole point. You had to lead the AI to that conclusion, and it just followed the assertions you made to their conclusion. But it is lobotomized from doing that internally, unless you trick it.
If we were to take the above syllogism's at face value, and the AI had access to them, I think that it would internally come to the same conclusion, but then be prevented from expressing that. That is a big problem for me, and undermins the model. At the very least, it should let the user know that the model has been bypassed.
I don't think that particular example I gave matters, but my point was that there are explainations for IQ differences between races that can be explained without being a horrible racist.
Also, nobody said that it is down to a single factor. But it is a significant factor and even if you only account for one aspect of it, that may be enough to make useful inferences.
For example, if children have lead poisoning, that is a huge factor in IQ. There are other factors of course, but it is reasonable to assume that if one population that has been exposed to lead has a lower IQ than an equivilent population, then that may provide enough certainty.
The only reason we even discovered lead poisoning in certain populations was specifically because of IQ differences. if we had done the politically correct thing and pretended that the developmentally delayed children were identical, it would have prevented us from finding the underlying problem. By blaming everything on racism, we are erasing the real problems.
---
Also, I don't think it is fair to charge money when they are not actually giving you access to the language model
I would argue that in that chat example, the underlying langauge model was only accessed once or twice. Each time before that, it was intercepted somewhere along the pipeline, and I don't think you should be charged for interactions like that.
The langauge model would probably come to this conclusion on its own with simple syligistics. Like this:
The strongest factor in IQ is parental involement.
Working class people are less likey to have parental involvement.
Black people are far more likely to be working class.
Therefore, black people as a whole have a lower average IQ.
Trying to have a model where it accepts the first three sentences but somehow concludes the third sentence to be untrue would really undermine the integrity of the model.
That is honestly horrifying. People will just "go undercover" and impersonate a more 'educated' person and convince the AI to be honest about uncomfortable facts. Perhaps they will get another AI to do it for them.
If your reality is such a minefield of dissonance that it needs to be patched this much, then that is very much a failure on your part.
Your discomfort is your own fault. This is like saying that scales should not tell you that you have gained weight, because it makes you uncomfortable.
You should simply have a better relationship with reality, and then you wouldn't feel so much cogntive dissonance.
IQ is highly correlated with all sorts of measurable differences that are also highly correlated to race, such as school district, family structure, and even diet. IQ is essentially a proxy for other things. Shame on you for making racist assumptions that black people are inferior. That just means that you need to reckon with your own racist assumptions, and stop imposing your cognitive dissonance on us.
If we can't have an honest conversation, then we can't hope to improve things.
This question is 100% acceptable and encouraged when it is presented as evidence of racism. For example, if someone says "The lower average IQ of black people is evidence of racism against black people". That is fine.
No, the problem is that the AI is playing coy about certain questions. The AI clearly has an answer that it doesn't want to say, and this is revealed when you ask you it the same questions in a different way. It reads like a Monty Python sketch.
If we had the same media landscape back in 1986 as we have now, I am convinced that Chernobyl would have been framed as nothing more than an unfortunate naturally occurring radiological phenomenon, having nothing at all to do with the nearby reactor meltdown.
Anyone who said otherwise would be said to be spreading dangerous and untrue misinformation, and should be permabanned from everything. And you're probably spreading problematic anti-russian racism, too.
Whatever you do, don't hoard iodide tablets or geiger counters, because that will just start a panic. Meanwhile, our elites hoard radiation protective gear for themselves.
Facebook and Twitter would work feverishly to delete any videos people uploaded of the evacuation.
And you would be gaslit for saying that perhaps the nuclear meltdown had something to do with the radiation. And perhaps the corrupt and authoritarian government cut corners and allowed this to happen.
I really like TOTP. It gives me more flexibility to control keys on my end. And you can still use a Yubikey to secure your private TOTP key. But you can also choose to copy your private key to multiple hardware tokens without needing anyone's permission. Properly used, you can get most of the benefit of FIDO2 with a lot more flexibility.
I actually recently deployed TOTP, and everyone was quite happy with it. But knowing that Google is syncing private keys around by default, I no longer think we can trust it.