this post was submitted on 27 Jan 2025
27 points (100.0% liked)

TechTakes

1583 readers
405 users here now

Big brain tech dude got yet another clueless take over at HackerNews etc? Here's the place to vent. Orange site, VC foolishness, all welcome.

This is not debate club. Unless it’s amusing debate.

For actually-good tech, you want our NotAwfulTech community

founded 2 years ago
MODERATORS
 

Need to let loose a primal scream without collecting footnotes first? Have a sneer percolating in your system but not enough time/energy to make a whole post about it? Go forth and be mid: Welcome to the Stubsack, your first port of call for learning fresh Awful you’ll near-instantly regret.

Any awful.systems sub may be subsneered in this subthread, techtakes or no.

If your sneer seems higher quality than you thought, feel free to cut’n’paste it into its own post — there’s no quota for posting and the bar really isn’t that high.

The post Xitter web has spawned soo many “esoteric” right wing freaks, but there’s no appropriate sneer-space for them. I’m talking redscare-ish, reality challenged “culture critics” who write about everything but understand nothing. I’m talking about reply-guys who make the same 6 tweets about the same 3 subjects. They’re inescapable at this point, yet I don’t see them mocked (as much as they should be)

Like, there was one dude a while back who insisted that women couldn’t be surgeons because they didn’t believe in the moon or in stars? I think each and every one of these guys is uniquely fucked up and if I can’t escape them, I would love to sneer at them.

(Semi-obligatory thanks to @dgerard for starting this.)

(page 2) 50 comments
sorted by: hot top controversial new old
[–] [email protected] 12 points 2 days ago* (last edited 2 days ago) (6 children)

I’m not going to link Andy Ngo but random rationalist transwomen are being accused of terror sympathy…and Aella is doing this ‘leopards ate my face’ dance.

edit: it was @jessi_cata who tipped Ngo off of all people.

[–] [email protected] 7 points 1 day ago (2 children)

Ok you brought aella up so now I can post this:

Heard this song for the first time the other day and it reminded me of aella.

side note: what’s a good way to post links to music that isn’t youtube?

load more comments (2 replies)
[–] [email protected] 9 points 2 days ago (1 children)

i don't think it's the first time i see jessicata acting like a total piece of shit in her completely emotionless way and it's incredibly creepy. she doesn't even seem to be aware of the harm she can cause.

[–] [email protected] 8 points 2 days ago

I was kinda picking up on that ugh.

Ngo is going on Newsmax tonight to do his thing in front of the masses.

load more comments (4 replies)
[–] [email protected] 18 points 2 days ago* (last edited 2 days ago)

you can get banned on facebook now for linking to distrowatch https://www.tomshardware.com/software/linux/facebook-flags-linux-topics-as-cybersecurity-threats-posts-and-users-being-blocked and from distrowatch https://distrowatch.com/weekly.php?issue=20250127#sitenews

but it's not as bad as you think, it's slightly worse. it's not only distrowatch and linux groups got banned too

[–] [email protected] 13 points 2 days ago (1 children)

And on a less downbeat and significantly more puerile note, Dan Fixes Coin Ops makes a nice analogy for companies integrating ai into their product.

https://retro.social/@ifixcoinops/112847573063473767

[–] [email protected] 10 points 2 days ago (1 children)

that thread is a work of genius and answers what the next tech boom needs to be

~~dicks in mousetraps~~ I MEAN whatever wastes electricity most, preferably with Nvidia cards

[–] [email protected] 7 points 2 days ago

I do actually have a mechanism for using the sharp edges of NVidia cards for ~~dick~~ mouse trapping purposes. And we could - hypothetically - use the extraneous power inputs to mine Bitcoin or something, maximizing efficiency!

[–] [email protected] 11 points 2 days ago (1 children)

Hey, did you know of you own an old forum full of interesting posts from back in the day when humans wrote stuff, you can just attach ai bots to dead accounts and have them post backdated slop for, uh, reasons?

https://hallofdreams.org/posts/physicsforums/

[–] [email protected] 10 points 2 days ago (1 children)

this was mentioned in last week's thread

what I don't get is why the admins chose to both backdate the entries and re-use poster's handles. If they'd just tried to "close" open questions using GenAI with the current date and a robot user it would still be shit but not quite as deceptive

[–] [email protected] 7 points 2 days ago

The whole thing is just weirdly incompetent. Maybe they just had everything configured wrong and accidentally deployed sone throwaway tests to production? I could almost see it as a way to poison scrapers, given that there are some odd visibility settings on the slop posts, though the owner’s shiftiness and dubious explanations suggest it wasn’t anything so worthy.

[–] [email protected] 18 points 3 days ago (1 children)
[–] [email protected] 6 points 2 days ago

gives a hell of a kicker to the numbers I found

[–] [email protected] 9 points 2 days ago (1 children)

This is from 2023 but when debugging an xfce issue this week I came across this forum post: https://forum.xfce.org/viewtopic.php?id=16835

The user is competent enough to use xfce with Debian, but too incompetent to understand debug symbols is not a violation of privacy.

[–] [email protected] 13 points 2 days ago (1 children)

I get being privacy conscious and that sharing crash dumps and logs you don't really understand yourself can be scary. Making demands of urgent free tech support from strangers is just rude, though.

load more comments (1 replies)
[–] [email protected] 15 points 3 days ago (2 children)

Live: Chinese AI bot DeepSeek sparks US market turmoil, wiping $500bn off major tech firm

Shares for leading US chip-maker Nvidia dropped more than 15% after the emergence of DeepSeek, a low-cost Chinese AI bot.

https://www.bbc.com/news/live/cjr85l2e4l4t

lmao

[–] [email protected] 17 points 3 days ago (2 children)

Folks around here told me AI wasn't dangerous 😰 ; fellas I just witnessed a rogue Chinese AI do 1 trillion dollars of damage to the US stock market 😭 /s

load more comments (2 replies)
[–] [email protected] 10 points 3 days ago (1 children)

Is it too early to hope that this is the beginning of the end of the bubble?

Also, does someone know why broadcom was also hit so hard? Is it because they make various networking-related chips used in datacenter infrastructure?

[–] [email protected] 8 points 2 days ago

When hedge funds decide to flip the switch on something the reaction never looks rational. Meta was green today ffs.

[–] [email protected] 12 points 3 days ago (3 children)
[–] [email protected] 12 points 2 days ago (2 children)
[–] [email protected] 20 points 2 days ago (2 children)

Pouring one out for the local-news reporters who have to figure out what the fuck "timeless decision theory" could possibly mean.

[–] [email protected] 14 points 2 days ago* (last edited 2 days ago)

Taylor said the group believes in timeless decision theory, a Rationalist belief suggesting that human decisions and their effects are mathematically quantifiable.

Seems like they gave up early if they don't bring up how it was developed specifically for deals with the (acausal, robotic) devil, and also awfully nice of them to keep Yud's name out of it.

edit: Also in lieu of explanation they link to the wikipedia page on rationalism as a philosophical movement which of course has fuck all to do with the bay area bayes cargo cult, despite it having a small mention there, with most of the Talk: page being about how it really shouldn't.

[–] [email protected] 6 points 2 days ago

I kicked them a donation just for that

[–] [email protected] 9 points 2 days ago

This is a good article, thanks for posting.

[–] [email protected] 10 points 2 days ago (2 children)

They're probably talking about Ziz's group. The double homicide in Pennsylvania is likely the murder of Jamie Zajko's parents referenced in this LW post, and the Vallejo county homicide is the landlord they had a fatal altercation with and who was killed recently.

[–] [email protected] 6 points 2 days ago* (last edited 2 days ago) (1 children)

landlord was ~~killed~~ stabbed in 2022, but recently they killed ~~someone who shot one of zizians back then~~ him

wait nah i fucked up

In November of 2022, three associates of Ziz (Somnulence “Somni” Logencia, Emma Borhanian, and someone going by the alias “Suri Dao”) got into a violent conflict with their landlord in Vallejo, California, according to court records and news reports. Somni stabbed the landlord in the back with a sword, and the landlord shot Somni and Emma. Emma died, and Somni and Suri were arrested. Ziz and Gwen were seen by police at the scene, alive.

landlord's name is curtis lind. this is about 2022 incident:

Early that morning, several of the tenants asked Lind to come out of his trailer home to help them with an issue, but instead “jumped him with a bunch of knives and swords, apparently with the intent of chopping him up and dissolving him in a bath of chemicals, which they had prepared,” Young said.

https://openvallejo.org/2025/01/27/man-killed-in-vallejo-was-main-witness-in-upcoming-murder-trial/

[–] [email protected] 7 points 2 days ago* (last edited 2 days ago) (1 children)

No no that's right, landlord shot one of them to death and got a sword put through him but he survived. He was stabbed again recently and died.

[–] [email protected] 4 points 2 days ago

noted, edited

load more comments (1 replies)
[–] [email protected] 9 points 3 days ago (1 children)

excuse me, what the fuck is this

[–] [email protected] 7 points 3 days ago (2 children)

Either Baader-Meinhoff or Manson family, not sure which.

[–] [email protected] 6 points 2 days ago

i don't think that RAF dropped acid but in revolutionary way

[–] [email protected] 7 points 3 days ago (1 children)

Also Andy Ngo has now picked this up and its being spun as a purely trans terror cell thing.

[–] [email protected] 12 points 2 days ago
[–] [email protected] 12 points 3 days ago* (last edited 3 days ago) (4 children)

Me: Oh boy, I can't wait to see what my favorite thinkers of the EA movement will come up with this week :)

Text from Geoff: "Morally stigmatize AI developers so they considered as socially repulsive as Nazi pedophiles. A mass campaign of moral stigmatization would be more effective than any amount of regulation. "

Another rationalist W: don't gather empirical evidence that AI will soon usurp / exterminate humanity. Instead as the chief authorities of morality, engage in societal blackmail to anyone who's ever heard the words TensorFlow.

[–] [email protected] 7 points 2 days ago

engage in societal blackmail to anyone who’s ever heard the words TensorFlow.

no no wait this is geoff's stopped clock moment

[–] [email protected] 19 points 3 days ago

dude missed that Trump won and the people in power are Nazi pedophiles

load more comments (2 replies)
[–] [email protected] 2 points 2 days ago* (last edited 2 days ago) (3 children)

Spent the last week playing with some security shit (thinking about a career change, since it looks like I will be mastering out of my PhD program) and fuck me everything about hardening your personal devices is exhausting. We are nowhere close to accessible privacy and security in our computers. The best solution right now may be "buy a Macbook and learn MacOS", which is so depressing.

Still deciding on a web browser. Used to be I could recommend Firefox because Righteous-Opposition-to-Google, but that doesn't really track anymore with Mozilla's behavior. Now I guess I would recommend Chrome, but it feels so gross (and I am unsure about things like Ungoogled-Chromium, for security reasons).

the basic laptop hardening

  • Install Fedora Silverblue
    • Be sure to set a good LUKS password
  • Set a BIOS password and disable USB booting
  • Rebase to secureblue
  • Follow the Post Install Readme
    • I personally couldn't figure out how to set the GRUB password. I will probably get around to it eventually.

As far as passwords, the only password I have to memorize is the one to my Bitwarden vault. Everything else is stored in Bitwarden. The passwords (except for my phone PIN) are 16 characters if I ever need to type them in manually (e.g. LUKS password), whereas passwords that will always be copy-pasted are 128 characters. I am looking into integrating a yubikey, but am leaning towards "fuck that shit, why would anyone actually want to use this?" If anyone here has comments on this (am I missing an obvious pitfall? do yubikeys suck as much as it looks like they suck?) I would be happy to hear them.

Anyway tl;dr is I spent the last week hardening all my devices and it sucks. In some cases it was a complete waste of time (my Steam Deck does not appear to have a way to set a password in the BIOS). In other cases (e.g. my Framework), it was probably worth it but a deeply terrible experience.

[–] [email protected] 6 points 1 day ago* (last edited 1 day ago) (1 children)

Last time I tried it, ungoogled chromium had some issues with yubikeys (see https://ungoogled-software.github.io/ungoogled-chromium-wiki/faq#how-to-get-fido-u2f-security-keys-to-work-in-google-sign-in) which I don’t think have been fixed yet. That was enough to be a deal breaker for me.

do yubikeys suck as much as it looks like they suck?

Without knowing why you think they suck, it’s hard to say. I like having unphishable uncopyable credentials, and it irritates me that they aren’t more widely supported. On my desktop or laptop, they’re less irritating than TOTP, for example, which is neither unphishable nor uncopyable but much more widely used.

whereas passwords that will always be copy-pasted are 128 characters

Whilst there isn’t really such a thing as “too secure”, it is the case that things like passwords are not infinitely scaleable. Something like yescrypt produces 256-bit hashes (iirc) so there’s simply no space to squish all that extra entropy you’re providing into the output… it might not be any more secure than a password a quarter of its length (or less!).

128 bits of entropy is already impractical to brute force, even if you ignore the fact that modern password hashes like yescrypt and argon2 are particularly challenging to attack even if your password has low entropy.

[–] [email protected] 3 points 1 day ago (1 children)

Without knowing why you think they suck, it’s hard to say. I like having unphishable uncopyable credentials, and it irritates me that they aren’t more widely supported. On my desktop or laptop, they’re less irritating than TOTP, for example, which is neither unphishable nor uncopyable but much more widely used.

I've come around a bit since posting yesterday (after looking into the various hardware key options, like OnlyKey). The biggest issue I have is that the firmware cannot be updated (which I realize is somewhat a matter of taste regarding your threat model). Other than that, it's the added complexity of "use this physical device" and the concern I had about recovering accounts if I lost the Yubikey. Their page on spare devices does not inspire confidence.

Whilst there isn’t really such a thing as “too secure”, it is the case that things like passwords are not infinitely scaleable. Something like yescrypt produces 256-bit hashes (iirc) so there’s simply no space to squish all that extra entropy you’re providing into the output… it might not be any more secure than a password a quarter of its length (or less!).

128 bits of entropy is already impractical to brute force, even if you ignore the fact that modern password hashes like yescrypt and argon2 are particularly challenging to attack even if your password has low entropy.

Fair point! I chose 128 because it's the maximum allowed in Bitwarden (if it's going to be copy-pasted anyway, who cares). Assuming I didn't fuck up basic math, the entropy of a passphrase of length n selected uniformly at random from characters in A is given by nlog|A|, so to reach 128 bits of entropy with 70 chars (lower + upper + digits + special) requires a passphrase of length 21.

load more comments (1 replies)
[–] [email protected] 9 points 2 days ago* (last edited 2 days ago) (1 children)

The best solution right now may be “buy a Macbook and learn MacOS”, which is so depressing.

Depends on whether you include "my personal data is sent to the manufacturer of the computer against my wishes" in your threat model... Apple does many good things for security, and I wish PC hardware makers would take security-related things even just nearly as seriously as them. But I can't trust Apple anymore either.

(Explanation: the whole iCloud syncing stuff is such a buggy mess. I don't want it, I don't need it, so I want it off. But I guess Apple just doesn't test enough how well it works when you turn it off, maybe they can't imagine someone not wanting it. The problem is, iCloud sync settings don't stay off. Settings randomly turn themselves back on, e.g. during OS updates, and upload data before you even notice it. I'm not claiming that's intentional, I assume it's just bugs. But I've observed such bugs again and again in the past 9 years, and I've had enough. Still have a Macbook around, but I use it very rarely these days, only when I need some piece of software on MacOS that has no suitable Linux equivalent.)

While a PC+Linux setup can avoid the specific issue of "don't randomly upload my data somewhere", the setup of it all can be a mess, as you say. And then security is still limited by buggy hardware and BIOS/firmware that is frequently full of security holes. The state of computers is depressing indeed (in so many ways, security just being one of them)...

[–] [email protected] 7 points 2 days ago

A note to the effect of:

You have basically no control over how Apple handles your data. When iOS users opted out of data collection, Apple still collected the data, they just didn't allow third-party access to it.

is a good idea if I ever do recommend a Mac.

[–] [email protected] 7 points 2 days ago (1 children)

I don't think I could ever recommend chromium-based browsers due to the MV3 switch. Does ungoogled-chromium do any patching to get around this? If not I think FF is the only sane option still.

[–] [email protected] 4 points 2 days ago

I believe ungoogled-chromium does have MV2 support. Unfortunately, there are still real security concerns with Firefox. The good news is that Trivalent (a hardened version of Chromium developed by the Secureblue folks) has ad/content blocking built in. I am still mostly using Firefox, but the small amount that I have used Trivalent has been good.

[–] [email protected] 18 points 3 days ago (1 children)

I screenshot this the other day and forgot to post it. Well, enjoy.]

[–] [email protected] 10 points 3 days ago

i wonder which endocrine systems are disrupted by not having your head sufficiently stuffed into a toilet before being old enough to type words into nazitter dot com

[–] [email protected] 10 points 3 days ago

Spotted in the Wild:

load more comments
view more: ‹ prev next ›