• 0 Posts
  • 231 Comments
Joined 3 years ago
cake
Cake day: June 30th, 2023

help-circle
  • I’m disappointed that it took seeing that ad for so many people to realize what should have been obvious: ring, along with teslas, and any voice assistant listening devices, or any other cloud-based tech that monitors video, audio, or even other data, can be used to set up an unprecedented surveillance network. Phones are a part of it, too, at the very least as tracking beacons, assuming the mics and cameras aren’t being tapped more often than that little activity dot indicates.

    There’s a reason why the venn diagram of people who really understand tech and people who are enthusiastic about most new tech in the last decade and a bit aren’t the same circle. The Snowden revelations weren’t surprising on the “what they are capable of” side of things, though there had been hope before they came out that they weren’t crossing the lines that tech would have easily allowed them to. Just like when zuck bragged about the information fb users just gave him, that wasn’t all new but there was an unspoken (and perhaps naive) rule that admins should respect their users’ privacy.

    When I was on the webteam for a gaming community, it would have been trivial to set up the login page to also store all user/password/email combos in a location none of the other team would be likely to notice. We hashed the password in the db, but I could change the source code to do whatever. Even if it was hashed on the client, I could have added a temporary unhashed field and get all the plaintext credentials to check who uses the same password for their email. I didn’t because I respected our users, but from then on just assumed that any site admin could see my credentials and never reuse passwords.

    That also applies to Lemmy, btw. At the very least, you shouldn’t use the same password for you email and anything else (though also be aware emails are just sent as plaintext to a bunch of servers while being routed to your email provider).





  • Yeah, windows came from a different era where if you’re seeing a new exe, it’s because you put a disk in the drive and explicitly navigated to it. Speaking of which, this isn’t even the first time that convenience ended up opening up a wide security hole because they handled CDs differently and added an autoplay feature that would check the disk for autorun.exe and just run it if autorun was enabled. I started disabling it after word about sony’s rootkits got out but have been appalled to see it enabled by default still ever since then.

    I was one of the few that appreciated UAC when it was there and kept it on one of the stricter settings. I’d rather my PC ask than assume, but people bitched about it so they weakened it and eventually just got rid of it entirely I think?

    Though a permissions setup would be even better. I didn’t like that UAC was an all or nothing prompt, plus it didn’t give any details about what a program wanted to do. Are you asking because this program is trying to create a new directory in program files or because it wants to replace system32 dlls with its own versions?

    It’s an area even Linux can improve in (though probably depends on flavour). I like the android permissions model, where there’s various actions and you can allow or deny categories (though GrapheneOS does it even better by also sandboxing everything). I’d love to see something like that for my desktop, where apps are free to save files but can’t touch files that aren’t their own unless an explicit share is set up, where I might want one app to have network access and no disk access and another to have the opposite. I’d love to be at a state where I could just run any executable from the internet because I know that my OS won’t let it fuck anything up other than its own address space. Hell, could even dedicate a core to monitoring apps to detect if one breaks out of its sandbox without my explicit permission (while the OS also doesn’t use that to enforce the desires of other developers over my own).



  • Can you elaborate a bit on how notepad following a link can result in running arbitrary code? Cause it sounds more like a second vulnerability is involved, because a text editor following a link still shouldn’t result in running whatever code is on the other side of the link.

    Though it is a privacy issue on its own, just like a tracking pixel or images in emails.

    I’m also curious what the actual use case is for having a link that notepad automatically follows on load in markdown. Or why they got rid of wordpad (their default rich text editor) and put it into notepad (their plain text editor), ruining one of the reliable things about notepad: it would just show you the actual bytes of the file, whether it was text or not, kinda like a poor man’s hex editor (just without the hex).

    Makes me wonder if eventually opening an html file in notepad will make it render it like a browser. “Back in my day, we edited html in notepad instead of browsed it!”



  • Over time, the more common mistakes would be integrated into the tree. If some people feel indigestion as a headache, then there will be a probability that “headache” is caused by “indigestion” and questions to try to get the user to differentiate between the two.

    And it would be a supplement to doctors rather than a replacement. Early questions could be handled by the users themselves, but at some point a nurse or doctor will take over and just use it as a diagnosis helper.


  • (Assuming you meant “you” instead of “I” for the 3rd word)

    Yeah, it fits more with the older definition of AI from before NNs took the spotlight, when it meant more of a normal program that acted intelligent.

    The learning part is being able to add new branches or leaf nodes to the tree, where the program isn’t learning on its own but is improving based on the expeirences of the users.

    It could also be encoded as a series of probability multiplications instead of a tree, where it checks on whatever issue has the highest probability using the checks/questions that are cheapest to ask but afffect the probability the most.

    Which could then be encoded as a NN because they are both just a series of matrix multiplications that a NN can approximate to an arbitrary %, based on the NN parameters. Also, NNs are proven to be able to approximate any continuous function that takes some number of dimensions of real numbers if given enough neurons and connections, which means they can exactly represent any disctete function (which a decision tree is).

    It’s an open question still, but it’s possible that the equivalence goes both ways, as in a NN can represent a decision tree and a decision tree can approximate any NN. So the actual divide between the two is blurrier than you might expect.

    Which is also why I’ll always be skeptical that NNs on their own can give rise to true artificial intelligence (though there’s also a part of me that wonders if we can be represented by a complex enough decision tree or series of matrix multiplications).



  • Yeah, if you turn off randomization based on the same prompts, you can still end up with variation based on differences in the prompt wording. And who knows what false correlations it overfitted to in the training data. Like one wording might bias it towards picking medhealth data while another wording might make it more likely to use 4chan data. Not sure if these models are trained on general internet data, but even if it’s just trained on medical encyclopedias, wording might bias it towards or away from cancers, or how severe it estimates it to be.


  • Funny because medical diagnosis is actually one of the areas where AI can be great, just not fucking LLMs. It’s not even really AI, but a decision tree that asks about what symptoms are present and missing, eventually getting to the point where a doctor or nurse is required to do evaluations or tests to keep moving through the flowchart until you get to a leaf, where you either have a diagnosis (and ways to confirm/rule it out) or something new (at least to the system).

    Problem is that this kind of a system would need to be built up by doctors, though they could probably get a lot of it there using journaling and some algorithm to convert the journals into the decision tree.

    The end result would be a system that can start triage at the user’s home to help determine urgency of a medical visit (like is this a get to the ER ASAP, go to a walk-in or family doctor in the next week, it’s ok if you can’t get an appointment for a month, or just stay at home monitoring it and seek medical help if x, y, z happens), then it can give that info to the HCW you work next with for them to recheck things non-doctors often get wrong and then pick up from there. Plus it helps doctors be more consistent, informs them when symptoms match things they aren’t familiar with, and makes it harder to excuse incompetence or apathy leading to a “just get rid of them” response.

    Instead people are trying to make AI doctors out of word correlation engines, like the Hardee boys following a clue of random word associations (except reality isn’t written to make them right in the end because that’s funny like in South Park).



  • Also, every single name that gets released is a name that Trump was ok with releasing. From my pov, it just turns it into a more effective blackmail tool. He’s not afraid of what’s in the files. If it was going to ruin him, it would have already done so.

    Instead it just shows others who know they are in the files that a) he’s one of them (if they didn’t already know), b) that he can protect them, c) he isn’t protecting everyone in the files just because of point a.

    Hate to be realizing this, but I think everyone who thought the release of the Epstein files would help anything got played. Just like everyone who thought the Mueller investigation would threaten his first term or result in making a second term impossible.



  • Yeah, for a while I was looking for any benefits to moving from win 10 to 11. 7 to 10 had kernel and scheduler improvements, for example.

    Only ones I could find were the virtual desktop support (though I had an alternative desktop back in the XP or Vista days that supported that, so not really groundbreaking), and WSL, which I didn’t have any use cases for.

    Other than that, it was just shit I didn’t want. Copilot, recall, more UI changes that don’t really add anything (on my work laptop where I didn’t have a choice, first thing I did was go into the UI options and undo as much as I could). One of the things I used to like about windows was that it wasn’t a mac, but the UI changes look like that’s their inspiration. The inspired folks porbably all left already.



  • I had an upgrade plan for my PC that involved a step up to a 4k monitor, but when the time came, it was hard enough just finding a 4k monitor with decent specs that I stopped to really think about whether I would really benefit from it. I already knew I didn’t need it, but I realized that I wouldn’t even really gain anything from it. I already used the UI scaling with the one 4k monitor I had at work, so that was a wash. And for games, I didn’t really have any times when I wished the resolution was higher than the 1440p I was already using, but I did have times when I wished it would generate the frames faster or more consistently.

    Part of the change was a new GPU to handle 4k better (they were supposed to justify each other), but I ended up just getting an ultrawide 1440p monitor instead.

    I don’t think I’ll ever bother with higher than 4k for TV or 1440p for PC.