For non-technical people, it isn't really news, because they already forgot about it after reading it. Maybe they'll be a little more monitored in their own typing for like... a day or two.
One of the hardest lessons to internalize, and keep internalized, as someone who works on and writes software, is the vast, vast, vast majority of the Public doesn't understand even the most basic shit about software. It just does stuff. Hopefully the stuff is good. That's it, beginning, middle, and end.
"Why would you think x would y" is a poor framing. They didn't think about x or y because they don't care. The phone works, that's the beginning and end of their interest in the subject.
I think in part it's selection bias? Like if you're smart enough to get by honestly, you're probably also smart enough to realize getting by honestly is just a way more comfortable way to live. The only reason you'd probably cross that line is because your principals, whatever they may be, conflict with those laws, or your life circumstances are so bad that you have no choice BUT to turn to crime.
And that cuts the other way too: if you're dumb enough to think you'd NEVER get caught for a burglary, for example, you'd probably be way more down to plan and execute one, failing to consider that most thieves aren't caught when they steal the shit, they're caught when they try and sell it later.
...but the last sentence if kind of important, right?
We only know about the criminals who got caught. Which probably means they did something dumb.
It's conceivable to me that there could be many—maybe even a majority—of criminals we don't know about because no one ever caught them. Maybe they committed fraud once, decided not to push their luck, and lived the rest of their life quietly. Maybe they killed someone and made it look like an accident, and no one ever suspected anything. How would we know?
Here's an FBI chart for 2019 [1]
Though some countries like Japan and Germany have really good clearance rates for homicide. [2]
But more heartening, it seems like it doesn't really matter how many people the cops catch. Crime rates are still generally on a long downward trend (with some bumps along the way). [3]
[1] https://ucr.fbi.gov/crime-in-the-u.s/2019/crime-in-the-u.s.-...
[2] https://en.wikipedia.org/wiki/Crime_clearance_rate
[3] https://ourworldindata.org/grapher/types-violent-crime-rate-...
Basically a lot more evil goes unpunished than most realize, because carma is a thing only when it's a thing - sometimes it just isn't.
Which is to say: If a criminal gets away with a crime and faces no punishment, not even public scorn, are they really a criminal? Or did they just work a situation, even of their making, to their advantage?
I don't particularly know where we should draw that line. But yes, my statement does deserve a big caveat there.
I think it's also much about self-esteem -- am I proud of myself? And criminals probably think highly of themselves when they succeed in their crimes.
Also, unlike the bad old days when 1 in 3 was an informant, now ordinary people aren’t in “informant loop” of providing information on others, so they aren’t thinking about being informed on either.
Of course, if I don't want anyone reading it, I sure as heck don't put it online.
You can bet that everything sent across the Internet is stored somewhere. But read? Yeah right. People don't seems to realize that there are 6B+ people online and just how big a number 6B is. If you have a staff of 30-40K people (like the FBI or NSA) and they spend 40 hours/week doing nothing but reading Internet posts and the average person spends 4 hours/week writing Internet posts (likely a huge underestimate) and the FBI agent can read 5x as fast as the person can post, then the collective manual surveillance capacity is about 2M people. That gives a 1 in 3000 chance that a random Internet user would be surveilled (though it is decidedly not random). With more realistic numbers of maybe 5000 analysts reviewing potential threats, spending 10 hours/week on it (so they have time to actually follow up on threats, attend meetings, communicate with their boss & coworkers, etc.), and the average person spending more like 25 hours/week posting on the Internet, that's a surveillance capacity of 10K people and your chances are more like 1 in 600K.
AI will give you only what you prompt it for, and the prompts are still designed by human analysts. What's changed with it is that now the 10K people surveilled will be anyone that "fits" in a category that the government deems criminal (say being transgender, or foreign, or left-wing, or criticizing ICE) instead of actual criminals. It shifts targeting, not capacity. If you wanted to be an actual criminal and are willing to do it in creative ways that bear no resemblance to other major categories of criminality (or lets be real, political disfavor), there is no time better than the present.
FWIW, I feel you; I too try to leave internet a mildly more amusing place to be.
Why should you be? Linux gives us software we can reasonably say we own, but not hardware. Everything you type into your local linux apps can be being monitored by your processor and whatever is sitting in the CSME/PSP subsystem which you don't have permission to access, but which is always running even when your computer is off. We need fully open, documented, auditable hardware if allowing any third party access to our devices means our private documents will make us all into criminal suspects.
On top of that, the data has to pass through several layers of routers and access points we control, which makes at least the fact of exfiltration visible. Plenty of people have a very strong vested interest in preventing data exfiltration from company hardware and so the government would have to somehow get in touch with every one of them to tell them to stay quiet before they leak any hints of it happening.
It's possible for targeted shipments, but the prospect of it being done for all consumer hardware sold in the US is a bit far fetched.
We know for a fact the government does intercept hardware shipments already on some scale. It's a lot easier when there are only a few chip makers being used for most devices. Intel and AMD alone cover the vast majority of the CPU market for desktops and laptops. It's basically the same situation for the wireless chipsets in every mobile device. No need to worry about dealing with about every cell phone manufacturer directly when you only need to hit up the extremely small number of companies every manufacturer has to get their chips from.
> Plenty of people have a very strong vested interest in preventing data exfiltration from company hardware and so the government would have to somehow get in touch with every one of them to tell them to stay quiet before they leak any hints of it happening.
Whistleblowers are extraordinarily rare. Edward Snowden worked with many many others. Any of them could have come forward at any time, but they didn't. Only one AT&T employee came forward to tell the public about Room 641A (https://en.wikipedia.org/wiki/Room_641A). The government marched into AT&T's building, took over part of their offices, rerouted their network and the whole AT&T backbone into their offices and through hardware. You can bet that more than one person noticed that. Government has no problems at all with going to a business with guns and gag orders and telling people to keep their mouths shut. Companies have no problems keeping quiet about what's happening either.
No one who isn't directly in the know is going to notice if someone's CPU (which is running it's own network stack) sends a few extra encrypted packets going to the servers of major internet companies (microsoft, cloudflare, apple, google) to either be collected at those end points or just picked up as it passes across the internet backbone.
Maybe if we had a ton more competition in things like chip makers, ISPs, operating systems, etc. it might be more difficult, but the way things are it'd be easy.
Sure, I'll take your comment at face value, not all consumer hardware has spyware, but it cannot be ruled out now, in the future, or at least now for targeted high value customers.
Those “special workstations” are mostly about lack of features they view as potential attack vectors (external or internal motherboard ports, replaceable/non-soldered components, thunderbolt, anything extensible or “repairable”) and mandate certain hardware features (hardware tpm, locked secure boot, locked UEFI). Other than that, those workstations are Lenovo, Samsung, or Dell machines running typical chips. They may pick certain CPU models or chips but that’s mostly about avoiding new or “cool” features that may not have matured enough yet. Most of them are moving to thin clients though. Where you use that “special workstation” to remote into an VM that can access production systems. And that part is partially about controlling the software running in the VM and making sure updates can be forced “offline” on the VM even if you haven’t connected to it in few weeks.
Well, sure, there was NSA's Tailored Access Operations unit which interfered with all kinds of hardware, even computer monitor cables:
https://www.nbcnews.com/tech/tech-news/report-nsa-intercepts...
For these kinds of operations, open source hardware won't save you unless you build it yourself, much like open source software. At the end of the day, you're hoping that the pre built thing matches what it claims to be.
The hardware case of TAO is still targeted and didn't rely on the manufacturer's compliance and secrecy for their entire line of products, though. The scale of that to my mind is quite the qualitative difference.
You can have open and auditable hardware, but how can you be sure that the hardware you buy is exactly the same hardware as what's in the Github repo?
At this point, even if I could never be sure my system was secure, just knowing that systems were purchased, tested, and verified would make me feel a lot better. It'd be nice to have confirmation that it's even possible to make and sell a system that isn't backdoored in this country.
This is silly. Nevermind the government; you should always assume some Redditor will pore through OSINT data and leaks looking for anything they can use to dox you and wreck your personal and/or professional life.
That's definitely not the good word to use. It is most likely made with the intent to be privacy-friendly, but they are unfortunately anything but secure (including the whole Linux userspace), and especially in the age of agents it would be the best if everyone understood it that you are a single bash/npm install/malicious PDF away from everything bad happening with your data. But rest assured, your video driver won't get updated!
I'm also puzzled by the phenomenon of using ones real name on the Internet (outside a professional context). I believe this began to occur around the time facebook became popular.
no outside device comes in - no inside device goes out.
So I obviously opted to not enroll my phone, but that came to bite me in the ass one day when I needed to get a train ticket from my company email (it was a business trip) and the policy prevented non-enrolled devices from attaching or downloading attachments...
Felt like a fool grabbing my laptop to let the train attendant scan the QR code.
Wow, so we're assuming police state plus it's your fault if you didn't know...
I'm not talking about the lens of morality nor even the law, because it's obvious this shouldn't be the case but in actuality, it is - everyday more true than it was yesterday.
Certainly it shows that agents like Muse are a complete nonstarter for anyone doing anything that needs to be private. Even if you never talk about it with the bot, merely having sensitive information on your hard drive means it can be sent to outside servers where, if it hits some safety filter, some probably low paid employee is going to read it. Say you’re working for a public company and have files on your computer that could be material nonpublic information, now potentially some content monitor is going to be seeing that and trading based on it. It’s completely untenable to have everything you put on your computer be subject to human review at some tech company.
I think you can count on governments accessing that information where it suits them, and you can definitely count on unscrupulous people like Altman within tech companies to do so too.
I’m not sure what the answer is here, but it’s naive to think that nobody is accessing the information you give away by sending it to cloud AI providers.
Anytime the strong encryption debate comes up it's actually about maintaining the effectiveness of unencrypted surveillance in the AI era.