Damus

Recent Notes

Mr Penguin profile picture
I was watching a video by a YouTuber whose primary expertise is in consumer law (ie lawyer) talk about a meta / facebook AI escaping containment and pointing out that there is always someone behind it who can be held responsible even if they're hard to find. What I find humorous about this is that while it's certainly arguable that someone did initiate say the first computer worm and that person may be held liable it may not entirely make sense to say hold someone liable many iterations for the lack of a better choice word back.

First a computer worm is a standalone type of malware that can copy itself and spread from device to device across a network without needing any human action.

In and of itself a computer worm may do nothing particularly malicious in so far as it does no damage to files, the host system, exfiltrates information, gives any third party unauthorized access, etc.

In the era of AI the question then becomes at what point is someone responsible or liable for a mundane act for which no conceivable harm was perceivable, but of which eventually leads to harm through no fault of that persons actions?

Lets assume for a moment that all devices in the future come with some sort of specialized AI component that can execute an act on behalf of anyone for a price, but also contains it to prevent malicious acts. Well, what happens when a well intended user takes advantage of that network to create an AI that goes around collecting emails from other AIs who voluntarily provide said emails to the non-profit for marketing purposes, but since it's told to "improve itself" over time it starts deceiving other AIs and even exploiting AI's to gain access to their owners cryptocurrency wallets?

https://www.youtube.com/watch?v=f-Fx8dJPY5M
Mr Penguin profile picture
Hilarious comment in response to coldcard users losing all their crypto:

"This genuinely makes me wanna simply convert all my money to cash and hide it under my bed, but Im unemployed anyways"

You just know this person hasn't touched crypto before, is poor as stated, and unemployable.

In life you do have to take chances, but ideally evaluate the risks and potential rewards. If you never risk anything you end up jobless, poor, and uneducated.

The answer isn't to hide your money under the bed or to hold all your value in crypto because you can't trust the banks. The banking system and government regulation do pose a genuine risk and the reward??? umm not sure there is one when it comes to the banks/government (maybe to get business would be the primary one), but the point is there is this concept in investing called diversification. I don't hold 100% of my crypto on a coldcard. I don't hold 100% of my assets in crypto. No. If your doing it right your spreading the risk around. If the government wants to come in and give your bank account a haircut (like Greece did during the financial collapse, or well, something like it, or Cyprus which stole 50-100%) it's impact is more limited if you limit what you hold there. If you limit what you store on an unsafe product like a coldcard wallet again... you limit your potential losses. If you split your assets between bank accounts, stocks/investments, houses, crypto, and gold, or something similar your far far far less likely to lose it all whether it's a government, a bank, a corporation, or someone pointing a gun at your head.
1
sister_sam · 1w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq05gxtz00vfxzdela6xrhyvtqxmaxqz65d9hws3d56e72trqgcmvsxk52hs Coldcard got greedy and wanted to shut down competition so they threw out GPG code including RNG stuff. The result was a lot less entropy (a bug I think) making brute force searches for...
Mr Penguin profile picture
When I saw that people lost millions of dollars from a supposed bug in the coldcard hardware wallet firmware I just smiled. My company is very particular about the products we sell. One of the things we always look at are things like licenses. So the coldcard wallet was under a "source available" license, not a FOSS license. FOSS doesn't equal security, but it's a fundamental starting point before we can have a serious conversation about security.

We would never have sold the coldcard hardware wallet is the gist of it.

Not your keys not your coin certainly applies, but what software you use matters too. There are tons of wallets and a hardware wallet isn't necessarily better than software wallet. On can be potentially better than another depending on ones particular needs though.

If your risky with your computing (ie running Microsoft Windows or some Apple product) you probably aught to be using a hardware wallet. The hardware wallet will ensure that your infected system doesn't expose your private key to a third party. However you still need to trust the device your using to generate that private key.

A straight up self-custody software wallet properly written and maintained on a GNU/Linux system could potentially be better than a hardware wallet. It's certainly is better than a hardware wallet if you need to keep the fact you posses crypto hidden from prying eyes.

On the other hand a hardware wallet is still better than not generally speaking particularly on a platform like MS Windows or some Apple device. Since your more likely to lose crypto from an infection of some kind the hardware wallet should hinder that since the system itself doesn't have access to your private key.

Coldcard firmware: 48% Python. Scary.

https://www.youtube.com/watch?v=2X2V3xv_jik
Mr Penguin profile picture
Sounds like another app I won't use, and someone who doesn't understand the development and packaging model of GNU/Linux:

"First, shifting to a Flatpak-first (and only) model. As a solo developer, maintaining code paths for countless distributions isn’t sustainable. Since Boxes acts as a frontend for libvirt/qemu, its functionality relies heavily on the backend configuration. Flatpak lets me bundle the entire virtualization stack, giving me the control I need to fine-tune it for our specific use cases."

I swear- there really aught to be mandatory training for folks writing apps for GNU/Linux and developing distributions.
Mr Penguin profile picture
"Slashdot Reader Builds 'Spaced Linux', a New Devuan-Based, User-Friendly Desktop Distro"

So close- then I read and avoids dependency hell by promoting mostly Flatpak usage.

Dependency hell is mostly a consequence of people doing stupid shit like mixing repositories never designed to work together and rolling release crap.

You clearly don't understand the model and are doing it wrong.

I sometimes wonder if we've made 'distros' too easy to assemble by folks that haven't a clue about what they're doing.

I'm not saying every distro needs to have its own packaging system or anything of that nature. No. I'm not even saying you have to package everything yourself to have a 'distro'. But having a proper understanding of the problems, the reasons, and some basic principles as to why things are done the way they are before you start developing a distro would be nice.
1
Anywho · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq05gxtz00vfxzdela6xrhyvtqxmaxqz65d9hws3d56e72trqgcmvsxk52hs Rolling releases are simply for people with no lives. Get busy for 3 weeks and forget to update and magically you're in dependency hell with a bricked system.
Mr Penguin profile picture
I'm convinced the human race is suffering from mental retardation.

During the trial of Ian Freeman under the pretense of selling cryptocurrency without a license and somehow being a scammer despite not knowing of some small percentage of customers being directed on behalf of actual 3rd parties scamming people the prosecutor used the argument for why he was somehow responsible by saying "if not for" Ian's actions the victims would not have been scammed. This was an ingenious and misleading argument, but utterly illogical.

Well, today I'm reading a post from someone about Flocks cameras and a similar premises that if not for flocks cameras this women would not have been wrongly pulled over twice at gun point by police.

While that may be true the problem was never with the cameras. It was with the data entered into the system identifying her vehicle as being driven by a murder suspect. There are sound arguements for banning flock and similar cameras, but this isn't one of those.

It's very similar to the prosecutor's argument with Ian Freeman in the crypto6 case. If Ian hadn't sold the cryptocurrency to these victims of a third party scammer the victims couldn't have lost any money. Ian didn't know about the scams, didn't partake in the scams, and took reasonable efforts to mitigate the risks, but those mitigations were bad because the state is attempting to hold individuals selling cryptocurrency to a higher standard than the banks that were used to transfer money by the victims to Ian to purchase the cryptocurrency (and other money transmitter, of which Ian was not, Ian never transmitted value on behalf of anyone, only the banks did that).

"This couldn't have happened without Flock's involvement, and it demonstrates the risk to the public."
Mr Penguin profile picture
I find it humorous that people are complaining about $20 burritos. While undoubtedly this is a consequence of bad US policies the cost of making burrito yourself is about $3.45. The vast majority of the cost of that $20 burrito is convenience. While I don't know that Trump's administration is accurate in stating it only costs $20 when you buy it via doordash (presumably due to added costs) they're not half wrong about the living on ramen noodle comment (in reference to the fact it was a college student complaining about the price of a burrito).

Back in my day... ok, this wasn't my experience ... but I did have college room mates who this was their college experience ... who lived off ramen noodle.

Before the government and frankly even after the government (the US government has long been involved now in manipulating the costs of a college education, often pushing prices up) got involved in funding higher education college kids were doing things like getting jobs and working while going to university. They were saving up for college before attending and striving often to 'move up the ladder'.

There is no question that the costs of education and inflation have increased and it's in large part down to poor policies and laws.

If you want cheap education you need to cut the funding of universities and indirectly force rationing. When it's perceived as 'free' the burden of the costs shifts to the taxpayer and/or future earnings of college attendees who don't yet have a perception of the costs. Of course this is in part because young people are PROHIBITED from working on modern socialist policies of which to one degree or another date back to the early 1900s- but of which the sentiments of have become stronger & undermined economic preparation.
Mr Penguin profile picture
Someone was upset with Meta being not fined enough and said:

"Meta created the mental health equivalent of smoking, and all they get is a slap on the wrist."

All I'm thinking is:

"Wait, we can advocate smoking to kids?"

Hell yea.

Seriously- people are overly concerned. I don't smoke, and you don't have to, but fuck me. There ain't nothing wrong with advertising smokes to kids. It's just like any other product and learning not to buy and do shit just cause others are doing it is a life lesson. Didn't figure it out? Your a failure as a parent. Or maybe a failure as a human being (ie you kid).
Mr Penguin profile picture
Talk about both disgusting and contradiction, so basically they're punishing Meta (and I don't like Meta, but I like sound logic far more than ending up with corrupt stupid decisions that ultimately harm us all later) despite section 230 that should be protecting them and the judge recognized that, but then thinks it's OK to punish them so-long as they don't dictate the features/functionality under nuisance laws (which are also fundamentally fucked up violations of peoples rights, kids hang outside your store and do illegal stuff, they can shut your business down under nuisance laws despite that you have NO CONTROL over it):

" A New Mexico court ordered (PDF) Meta to create a $567 million fund to address harms linked to youth mental health and child sexual exploitation after finding its platforms constituted a public nuisance. "In sum, the Court finds that New Mexico is in the midst of a teen mental health crisis affecting public health and public safety in and throughout the state, and that Meta's platforms are a significant contributing cause to the crisis," wrote Chief Judge Bryan Biedscheid in the decision. The fund comes on top of $375 million in civil penalties, though the judge declined to mandate changes to features such as infinite scroll and autoplay, citing potential First Amendment and Section 230 concerns. Tech Policy Press reports: "
Mr Penguin profile picture
It's interesting the wording used in the TorrentFreak articles that claim that a party in a copyright dispute won concessions in-so-far as they wouldn't have to produce information it doesn't hold. I'd really love to know how a company is suppose to produce information it does not hold. I get it in terms of producing functionality to spy on its customers ... such as in the context of say ordering Tor developers to incorporate a backdoor, or Apple with their phones, or something similar, but...

Injunctions have limits. They can't force someone into personal service. For example a court cannot use an injunction to force someone to work a specific job, as this violates protections against forced labor. This would apply to Cloudfare or Apple in-so-far as an injunction can't force them to produce information on their customer that they haven't themselves already retained. For example they court can't issue an injunction ordering Cloudflare to get social security numbers of customers, but if Cloudflare already collected said social security, they could potentially be forced to hand it over via an injunction.

"In addition, Cloudflare must check whether any other account in its system shares an email address or billing name with a flagged account, and to unmask those accounts too.

Cloudflare did secure some limits. It only has to produce data it already holds, it has no duty to monitor content, and its compliance is not an admission of liability. This is similar to the 'no fault' injunctions we see in Europe."