We're in the worst of all worlds. Sometimes it feels like you only know it's a human because the AI would have over-explained.
But yeah, this security company only prodded, what, once or twice a month for 7 months? I mean, if they really truly cared, they would have found the CISO's home address, broken into their house, painted the reproduction steps on the inside of their front door (to avoid accidental disclosure), created a few "beginner friendly" repos with a git.exe that DDoS's their auth servers, got a job as a night cleaner in their offices, waited for one of the developers to leave their machine unlocked then fixed the vuln themselves.
It's just another capitalistic money grab, them posting their security concerns. Ugh.
They have "clarified" elsewhere on here that the normal citizenry get a legal exemption [waves hands mystically] somehow, and that they're only blocking people when they legally have to.
Obviously (to the rest of us) if the agreement says otherwise, then they're saying that it's LE that is forbidding the citizens of these countries, and it's not (entirely) the government's fault, which completely contradicts what they're trying to say.
We should probably be clear that this document is most likely a backside-covering exercise; it exists so that people can't sue LE for denial of service without a just cause, and so that the US can't prosecute them for intentionally shipping cryptographic services, or some such rubbish.
If you live entirely outside the US legal system, or its multifaceted tendrils, and if you don't make too much noise, you may be fine. Obviously that's a far cry from a "right to free speech" level of protection, but then LE have no obligation to provide that to people outside the US, and arguably non-rich citizens within the US lost that a long time ago.
As with anything word-gamey involving internet, you will probably have to trim down your dictionary. While I'm very glad my "sxxg" beat their "txxt", the first probably shouldn't be allowed (although there are non-rude definitions) and the second definitely shouldn't have!
Analogies are not the problem. In fact, an analogy is like a good knife; sharp, removes problematic parts, and totally unethical unless it knows the motivations of its wielder.
Seriously though, yes it is obvious why analogies are so often used, but I think you have it the wrong way round. They are a form of proof by negation; you don't have to find a thing exactly like the subject of the argument.
It's a way of fighting against bad arguments; If I say China is bad because X, Y and Z and also, their flag is red! They must be evil. If you then tell me that this argument could also be applied to the Red Cross/Crescent, you have negated my argument by analogy. You don't have to negate every argument I made; but at least then we can treat X, Y and Z on their own.
The problem with this writeup is, there really are no other powerful arguments in it.
And I'm pretty sure C4 is great for controlled demolition of highly dangerous buildings. Or do you want adventurous people to hurt themselves?
I think that's where most people thought that this article was going.
Shall we just have that debate anyway? :D
The big question that I hoped the article might address: Can AI ever be ethical (within the norms of what the average Jo(e) considers ethical), or have we forever poisoned the well?
If the technology and mathematical underpinnings have been created on fundamentally immoral grounds (IP theft, energy / water excesses, etc) what would we have to do to produce an entirely - or even mostly - ethical AI stack?
Is it even possible, given the dependencies on (Lithium / Israel / fossil fuels / conflict mining / capitalistic exploitation / any other morally questionable underpinning you might think of) to re-do the work to such a point that we could "black box" our way to decently function LLMs?
Assuming that comes with a caveat of rolling back the technological progress, how far back do we have to go? It feels like the bronze age is a step too far, at least on the basis of my "average Jo(e)" test above - but what is considered reasonable?
Then - and only then - would it make sense to ask how to make the content generation itself ethical.
It feels like the Nazi medical science issue all over again, except nobody really cares as much about this one. But socially, it feels like an anti-capitalistic uprising is on the horizon, so maybe if that happens, a moral aversion to the state of AI might piggyback onto it?
Not that I want it to. Quite like AI really. Feels like the background immorality radiation of the earth is quite high anyway, maybe AI isn't the thing to fluff our feathers about. But it's certainly an interesting thing to mull as we weep over our non-gm oat milk babyccinos, pitying at the state of the world.
This article in a nutshell: AI will never be ethical or safe, because no tool can ever be ethical or safe, without it knowing the complete motivation of any person using it and every person who might receive its outputs.
Wasn't the article I was expecting! Not sure it helps much, except maybe if you wanted to muddy the water of ethics-and-AI discussions.
It's interesting; I'd imagine very similar design briefs (friendliness, breadliness, etc)
The ICBINB font is almost a semi-serif, almost like a sans serif that's slightly melted, whereas I'd say the crumpet is fully serif. The "e", "L" and "v" are pretty different. And I'd say the ICBINB font lends itself better to tighter spaces, whereas the crumpet font seems to beg for more space.
But certainly, I could see one being used to replace another in a pinch - but I'm not a font specialist (graphologist? Is there a word for a person who studies fonts?)
No, I agree. That said, I think a lot of that particular shift is down to a) increased individualism b) an emphasis on the healing power of personal boundaries and c) the rejection of unity as an overriding good.
People are far more happy to cling to the tribe they choose, and the tribe that has their back, over the tribe they were born to. Then, there are those who see that trend as dangerous to society (where, in many cases, society is really just a proxy for their own power or social status - ironically as viewed through their own chosen tribes more than the tribe they were born to)
That is to say, I don't think it's the political views that are splitting the families. Individuals have decided that care for each other should come secondary to those political views. I feel like there used to be a certain amount of care in the "sweeping under the rug" - it was the tribe against the world, it was protecting the family image as much as it was protecting the individual from society. These days, being a thing "in private" means being a thing alone, and that's no longer a compelling thought when external tribes are willing to embrace you.
Which probably applies to software tribes just as much as family ones.
I feel like BDFLs are akin to the concept of village elders; they're not immune to corruption or scandal, but they often have this beloved status that can paper over a lot of cracks. That's probably dependant on their leadership style - the hard headed (Linus, DHH) vs the grandfatherly (Matz, Van Rossum).
Which, going back to your note on geopolitics, leads me to wonder: Is it just that more power corrupts more, or is it that (modern-day definitions of) democracy require a desire for power? I guess as the "FL" part of "BDFL" comes to bite more of the communities, we'll see better how different succession styles have different effects. I also wonder if the analytical nature of the individuals within the "populations", and inability to police defectors will mean uprisings will be more successful, either in causing BDFL attitude adjustments, or just overturning the community completely (for example, there's already a lot of momentum for a complete fork of Rails)
(Edit: having submitted this, I now see others have had very similar thoughts! Definitely an excellent conversation topic)
> 1) explained why relying on Docker Hub is dangerous
I mean, that's the other 770 words of the article. Except they're just giving their experience, and allowing you to come to your own decisions - because otherwise people might legitimately call them out for "smear" tactics.
> 2) what the alternatives are, and why they're not good enough
"as we grew we started mirroring our images to Gitlab and Quay.io," <= Alternatives (that they are using)
"Docker Hub is the de facto standard Docker registry, literally, if you don't specify a registry when pulling an image Docker will invisibly prepend docker.io/ to it." <= Why they're not good enough (extra config step)
> 3) what needs to change, which may include consumer behavior - things that we control, because we really don't have control over Docker Hub.
"but it does feel like we need to do something. Whatever we decide, we'll keep you informed." <= They're not there yet, but they're open and honest about it
> use fewer words, because people's attention spans are really short these days,
I can see that you have a short attention span.
> which naturally requires the words to have more dense and intense meaning
You are a belligerent, self important ignoramus who incorrectly believes the world needs his opinion. <= genuinely, do you like this style of discourse? Why are you treating shock language as a status quo worth maintaining, but trust and expecting decency from a corporation as some kind of unacceptable failing?
I love how you intentionally cropped off the first two words of that sentence, try to make out that their 30 word side note was actually the whole point of the 800 word article, and you STILL didn't manage to make them sound as malicious as you wanted to.
"give us a hint" - "Stop begging!"
As I say, you're clearly coming into this with a strong unjustifiable bias, I can tell because you're forced to use words like "smear", "parasite", "exploiting", "beg", "indentured servitude" - it's a cover for the cognitive dissonance.
But if you genuinely would like a discussion about the pitfalls of the funding models of open source, yeah it's a reasonable question that has never been satisfactorily answered. There are whole PHD projects on the subject, and nobody's cracked it. Giving money to open source projects is difficult for many reasons - ranging from tax treatment to geography even to legality. Providing services is somewhat easier, but in many companies in some countries even that comes with geopolitical legal issues. Marketplaces only work if you have something to barter, and if you would like to contribute to the freedoms you enjoyed, it's hard to make that work in a marketplace model, not to mention that even providing people the option of donating money for a product comes with overhead (legal / technological / service / financial network / server etc).
If you would like a discussion about ensuring abstractions over the services you use, sure, I'm here for it. Of course, it's hampered by a lack of consistent interfaces, and in some cases interfaces that ensure they can never be smoothed over. But that sounds like a cool open source project - in this case, I guess it would be an anyhub kind of deal that can serve images for different use cases, paired with a DSL for defining a resource (that can generate a dockerfile / docker compose file, in docker's case). Of course, serving images isn't free, but you've cracked the problem of funding models of open source, right? Right?
And you mention indentured servitude, loaded though that phrase is, it's also a poor analogy. Tax would be a closer match. You depend on open source and make money off it? Great. Giving open source a cut of that pie in some way seems the morally right thing to do. How you do that is up to you, but telling people they can use your service then pulling the rug while simultaneously ghosting them? That sounds kind.
You know what, I think you're right - it's so much easier to lambast someone for daring trust or daring to express concern than it is to do anything meaningful to improve the landscape.
This blog is for LinuxServer.io, who build repositories that produce free docker images, for free, paid for by donations, for a bunch of open source software. By the looks of things, they are literally a charity.
Conversely, their complaint is not "aren't docker rubbish? Let's mob 'em" - it's "heads up, something seems to be wrong and docker are not responding to anything, chances are there's trouble brewing - we're gonna start looking around and if you're depending on this, you should too"
I would say calling "the open source community" a "parasite" because they're using free services from companies that have benefited greatly and earned a lot of money from things given freely by the open source community seems weird.
Seems like a lot of people on here very concerned about those poor struggling corporations, and their exploitation by those evil open source charities. Feels like an evil political wind is blowing, wonder where that's coming from?
I just tried it with phi3.5:3.8b-mini-instruct-fp16 - it didn't work with the base question, though interestingly the reasoning decided that strawberry was spelt s-t-r-a-w-b-e-r - which explains why the AIs have such a hard time with this question. I also tried it with my current favourite programming question too - What programming language is this whole line of code using? `def obfuscated_fibonacci(x)` - and like all the AIs, it was convinced the answer was python (the correct answer is ruby - python needs a trailing colon - but most LLMs will swear blind that it's python). It didn't even consider ruby as a possibility. Nobody uses ruby anyway :D
Thanks for the fork and the suggestions though - looks like I'll be having fun with this over the week!
Yeah, it was paper cuts - for example, if you don't have git installed inside your devbox, it wouldn't work because of different glibc versions. Which would be fine, but my shell prompt uses git. So there has to be a nix version of git installed for every project for my machine, despite almost no projects technically needing it.
There were a couple of other libraries, can't remember which ones. I remember once having a fun chain of a library that depended on a library that depended on two libraries that in turn depended on glibc, and for some reason the last link of the chain, only one of the libraries was hitting the system libc incorrectly - that was a fun one to debug. I think I ditched that dependency in the end, it was the only solution (and was clearly badly written).
One of my projects used an older version of ruby. In that case, there was a gem to connect to the database, and that gem links to the db client library, but the db is new and the ruby is old and guess what? Two different versions of glibc, both being used within the nix ecosystem.
I worked around a lot of it with LD_LIBRARY_PATH (I think? from memory) which I had to unset for everything in devbox, and used aliases to set it to a backup of that env whenever I found a binary that needed it - and then they tried to fix that, but it just seemed to stop my workarounds from working, so I had to come up with new ones.
But yeah, it was a wild ride. Most of it came back to glibc or environment variables or both, and probably me doing something I really ought not to do (like support old projects). Alas, for me, it wasn't worth the effort - but I sure learned a lot.
My experience of Devbox on Linux has been highly disappointing. I gave it a good go, had it running on my main project from February to May.
In case you hadn't realised, the very concept of having two sets of binary distributions on one machine, vying for superiority and the correct version of glibc... is fraught.
Most of my use was with rails projects, and I can't recommend it.
Coupled with an abstraction that tries to save you from Nix, but almost entirely fails, you end up with a bloated hellscape where every time you load your project it will unnecessarily reinstall your packages and several times an hour it will have forgotten curl exists and so you have to manually reinstall curl (not-so-slowly increasing your /nix folder's size), every week or two a new version of devbox completely changes the workarounds you need to do, and don't try to garbage collect nix or it will delete vital files, and you end up scrubbing it all and starting again.
In python, it overrode the path so I couldn't get it to reliably use the binaries in the venv. Pip and Python were using packages in different places and I couldn't get them to converge for love nor money.
The devbox team were great and really tried to get things working, but in the end I couldn't get it to work with enough stability to properly recommend it to my team, and if I wanted it to half-work for any substantial length of time I had to lock to a version of devbox.
Obviously, ymmv, please do give it a try, it's an impressive project. But my view is that it's trying to do something that is very very hard, and for that you need a very clever solution. And this is a very clever solution, with very clever bugs, and so it's not something I'd recommend jumping into with both feet.
So yeah, turns out it's nothing to do with the 8266's board, and everything to do with the chosen relay module. Since it has nothing to do with driving the relay, it doesn't need to be connected. But if it were connected, whenever it is high, the relay board connects it to the reset, so the chip gets reset.
So you are bending it simply to ensure that pin can't be plugged in to the relay
Ahh! So it's not the ESP that has an extra connection, it's the relay breakout board.
That makes much more sense.
Yeah, I guess you would need to sound the doorbell every boot, and that might be inconvenient in places with a lot of power supply issues / loadshedding.
That said, that quick-boot-button link? That's some brilliant info right there.
Am I missing something? Neither schematics nor my limited understanding of physics explains why you need to, nor how it is possible to, bend one of the pins to disconnect GPIO0 (chip-row, 3rd from the left) from the reset pin (edge-row, 2nd from the left)...
Is it me? Have I been misusing my 8266s all this time?
Otherwise, good article, nice idea, great conclusion!
As is often the case, the truth is far more complicated.
Firstly, the bridge - while up to code - did not have the kinds of buffers that could have been installed, or arguably should have been installed [1]
It isn't wrong to say that if you are going to authorise large container ships, if you are going to profit from large container ships as a harbour, and you are not going to invest properly in the infrastructure, you should take some of the blame when things inevitably go wrong. I don't know whether such buffers would have entirely saved the bridge or the people on it.
It also isn't wrong to say that if you are operating a large container ship, you should ensure it has failsafes in case of power failure. I don't know what failsafes exist (emergency anchors? Some kind of manual rudder?) that would be effective on a ship that large.
It also isn't wrong to say that given the public outcry, a scapegoat will likely be chosen, and it's more likely that they will scapegoat the foreigners rather than blame the politicians in charge of public spending.
But yeah, this security company only prodded, what, once or twice a month for 7 months? I mean, if they really truly cared, they would have found the CISO's home address, broken into their house, painted the reproduction steps on the inside of their front door (to avoid accidental disclosure), created a few "beginner friendly" repos with a git.exe that DDoS's their auth servers, got a job as a night cleaner in their offices, waited for one of the developers to leave their machine unlocked then fixed the vuln themselves.
It's just another capitalistic money grab, them posting their security concerns. Ugh.