HNHacker News
TopNewBestAskShowJobs

127361

507 karma · joined October 30, 2023

I think nobody should be going to prison for looking at or storing any image on their computer. Or reading any book or text as well (some countries prosecute possession of certain written material).

Such actions are part of the private sphere, which the state has absolutely no business policing, unless e.g. you commit some violent crime or are diagnosed with a severe mental illness.

The state's policing of what we are allowed to read is a modern day witch hunt.

submissionscomments
127361··on Bluetooth keystroke-injection in Android, Linux, macOS and iOS
Even more scary: (launch child porn web site)
127361··on Don't Use Thorium Browser – If Installed, Remove It
And I got flagged for speaking out against this ridiculous moral orthodoxy. Good.

I'll just take my speech to another site, before I get banned from this Hacker News completely.

127361··on Don't Use Thorium Browser – If Installed, Remove It
Well it's dangerous to even check if it's true. Because doing so would be illegal, it would require downloading the browser. So you cannot even prove that it's really in there or not - or you risk breaking the law. This is sheer, utter madness. It is pure insanity. These crazy laws belong in the Middle Ages, not the 21st Century.
127361··on Don't Use Thorium Browser – If Installed, Remove It
The worst thing would be if some kind of virus or malware infected millions of computers or smartphones with such material. What would law enforcement do then? They can't arrest everyone under such strict liability pretenses. And it's not impossible for a state actor such as Russia to do this....
127361··on Don't Use Thorium Browser – If Installed, Remove It
So are you safe or are you going to be arrested for a thought crime? This stuff is straight out of dystopian fiction. What am I reading here, is it HN or Orwell's Nineteen Eight Four?
127361··on Don't Use Thorium Browser – If Installed, Remove It
That's absolutely so dangerous, so forking someone's repo on GitHub could potentially get you child porn charges? Insane. Fucking insane.
127361··on Don't Use Thorium Browser – If Installed, Remove It
There could be so many places where this is happening, and it's going undetected, until law enforcement happens to seize some unfortunate individual's computer and child porn is found on it.

Distributing or creating such material (with real children) is rightfully illegal. Possession with intent to distribute, as well. But absolutely not simple possession.

These crazy laws need to go, it's a modern 21st Century form of morality policing[1]. Such morality policing is not much more that primally driven primitive behavior, akin to which our tribal ancestors carried out, and coming from a part of our brain that is thousands of years old. It does not belong in a modern technologically based society. And the internet, with its fundamental lack of privacy, has enabled such morality policing on a shocking scale.

Such material can be easily generated locally with AI with no risk of detection by law enforcement, and planted into people's web browser caches or other temporary storage so easily. The government is basically giving any sophisticated hacker or state actor (e.g. Russia) a push-button way of destroying any political opponent with ease.

If you live in a Western country and criticize a Russian political figure too much, well the FSB (the successor to the KGB) is going to put child porn on your computer. They've already been caught doing precisely that. [2] So it's especially important in this current geopolitical situation we're in.

1. https://journals.sagepub.com/doi/abs/10.1177/135485652311936...

2. https://en.wikipedia.org/wiki/Kompromat#History

127361··on Mozilla expands extension support for Firefox for Android
And a chunk of Mozilla's funding going towards social justice related projects, as much of the organization has been co-opted by social justice types.

As was stated in the article[1], close to half a million dollars was spent on a social-justice related organization, the Mackenzie Mack Group.

“[Mckensie Mack Group] is a change management firm redefining innovation in the white-dominant change management industry.”

In the article it also says " While The Lunduke Journal does not like to delve too deeply into the Political Woods (tm), it should be questioned why so much money — possibly millions of dollars donated by individuals who thought they were supporting a web browser — is being funneled into highly political organizations that seem to have no involvement with the World Wide Web, Web Browsers, or any related standards. "

1. https://lunduke.locals.com/post/4387539/firefox-money-invest... "

127361··on Mozilla expands extension support for Firefox for Android
And the rest of the money going to social-justice and DEI inclusion related projects, as the whole organization has been co-opted by social justice types.
127361··on AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking
That already happened on Xilinx Zynq FPGAs, where an incorrect power supply sequence causes random writes to one of the internal buses, which overwrites various eFuses, even after they have been locked.

https://support.xilinx.com/s/question/0D52E00006hpKdKSAU/zyn...

I understand burning eFuses is necessary during production, but having them blowable when the device is operating normally could be compared to building disposable devices. One logic or software error and the device can be bricked permanently. That is a ridiculous state of affairs. What about single event upsets or some EMI induced glitch causing eFuse corruption?

The power for burning the important fuses should be off at all times during normal operation. And we can have a test pad to supply the VPP during production.

In the case of the AMD processors, a separate bank of fuses can be used to store diagnostic data for warranty returns, if necessary. If those get corrupted somehow, the device won't malfunction. But the important ones should not be possible to program after manufacturing, no matter what happens to the logical state of the hardware, period.

127361··on AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking
This will ruin the AMD brand, if Intel doesn't do such a thing, then people will start going with Intel instead.
127361··on AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking
I'm sure this is illegal and AMD should be prosecuted for it. The people who decided to implement these "security" measures should lose their jobs and/or face legal consequences for it.

If they did such a thing with car components, it would be shut down in no time. No different for computer parts.

Also a CPU that can be rendered permanently inoperable due to a software issue could be considered not fit for purpose and thus a defective product. Especially if it was intentionally designed this way - such that the CPU can self-cripple itself.

Maybe a legal firm would want to take up a class action against AMD for this potential product defect? Viruses and malware should not be able to physically destroy a CPU. There should be physical hardware protections against such destructive behaviour occurring due to a software induced logic error.

The PSP is not truly secure, someone should write a PSP eFuse bricker tool (Ryzenkill?) that can be run as a proof of concept to show the CPUs are defective, and then we can have a recall or free replacement of the CPU by AMD. I'll look into it myself - I need to ensure it's legal for me to write it from the country that I'm residing in right now. I personally have extensive experience hacking older AMD processors and GPUs through JTAG.

I'm sure it's still legal to provide a list of addresses and data writes that you need to perform to permanently brick the CPU?. I don't think that is classed as a "hacking tool". I can get t-shirts printed with it on, together with the words "AMD Ryzen CPU Self-Destruct Sequence". I don't think selling those would be illegal?

127361··on The Old Internet Is Dying, and Something Worse Is Being Born
Yes, air-gapped and the entire operating system is running off overlayfs + tmpfs, so no data persists after power off. There's also a problem with TEMPEST emanations from the computer's display - the problem is almost non-existent on mobile devices such as smartphones, which are very well shielded. So disable the modem physically, and run everything locally.

Of course the risk of targeted surveillance still exists, and nothing is going to stop a hidden camera from being placed in your home.

But in most cases there would be no reason to ever place the average person under such surveillance. So the bulk mass surveillance of the population would be hindered. And they won't be able to persecute people for reading or viewing certain things anymore. So that puts an end to the morality policing that has been enabled by the Internet.

127361··on The Old Internet Is Dying, and Something Worse Is Being Born
And the next big thing to look forward to is local AI. With both the models and the hardware getting better and better, that's the next big thing.

And it doesn't have any of the privacy downsides that the Internet has. You can do anything you want with it, total freedom.

No more law enforcement or intelligence agencies being able to monitor your every move. So you could say it's way better even than the old Internet.

127361··on The AI Trust Crisis
Likely a cognitive bias there, we pay selective attention to the topics we've been discussing previously, and likely remember when an ad comes up that's related. So yes, they're not listening to our microphones. It's just our selective attention and memory, instead.
127361··on The AI Trust Crisis
Yes and if we start chatting to a local AI model instead of searching on Google, that means we get an overall increase in privacy. So the new local AI era could actually be much more private than the previous Web era - an era in which we could have much more freedom.
127361··on Xorg being removed. What does this mean?
Mozilla took away native ALSA support and forced everyone to use PulseAudio, fortunately there are emulation libraries you can install to work around that.
127361··on AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking
You could write protect them by removing a resistor (R6T3) from the console's motherboard.

https://consolemods.org/wiki/Xbox_360:Disabling_the_eFuse_Bu... (see Method 2)

127361··on AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking
That's why we need open source chips, the same restrictions we had with proprietary software are now coming to hardware. Plenty of interesting things to do with FPGAs, and the community is even in the early stages of developing open source FPGAs now.

It was AMD with their PSP that pushed me into FPGAs and creating open source hardware, now that everything is getting locked down.

127361··on AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking
This practice should be made illegal, if it's not already.
127361··on AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking
I really don't like the idea of having field-programmable OTP memories in microprocessors. This shouldn't be possible, there should be a physical VPP pin (as in MediaTek SoCs), if you don't supply power to this then no fuses are blowable. Otherwise we're going to have ransomware physically brick CPUs if you do not pay up on time.

There's even worse possibilities, I think some hardware has ~1KB of executable OTP which can be programmed in that manner - so it may just be possible to implement some kind of backdoor that resides in the physical CPU. Maybe something only a state-level attacker could do.

For example, it could prevent CPU side-channel mitigations from ever working, somehow, e.g. by repeatedly writing to a private internal register to stealthily keep the CPU vulnerable. And few would ever know about it, because it's hidden in an on-chip security processor.

Personally I utterly hate all AMD chips which have a Platform Security Processor. Locking down your own property to prevent you from accessing it should be illegal.

There is a full Trustronic Trusted Execution Environment running in there, on both GPU and CPUs, I believe. For example the TEE firmware blob for a radeon GPU on Linux is "/lib/firmware/amdgpu/psp_13_0_7_sos.bin", with "sos" meaning Secure Operating System. And some of these firmware files are encrypted, so you can't reverse engineer them.

The moment some ARM SoC company such as Rockchip comes up with a chip that's within an order of magnitude in performance, then my AMD chip (EPYC) is going in the bin. After being smashed to pieces with a hammer, live on YouTube, with an explaination why. That might get AMD marketing to pay attention.

Update: Ampere Altra CPUs have seperate power pins for blowing eFuses, you can find it in the public datasheet here[1], on page 55, the supply pins are EFUSE_MFG_VDDQ1P8 and EFUSE_PCP_VDDQ1P8. It says tie to GND if unneeded.

Also they have a public datasheet for the chip. I wonder if we can buy unfused CPUs without secure boot enabled? Or is that the default state of the chip?

Could someone design a simple and cheap open-source motherboard for one of these processors, it's only a matter of time before the chips start turning up on Ebay? We will need more documentation from Ampere than just the datasheet, of course.

1. https://uawartifacts.blob.core.windows.net/upload-files/Altr...

127361··on IBM Diversity Efforts Targeted by Stephen Miller's Legal Group
So we need to address that one as well, so we can employ those who are brilliant technically but might not be so good at socializing. We urgently need something to counter the rise of China, so we are going to have to adapt as a society in order to compete globally.

In fact, hiring such people would be a step towards real diversity in the workplace, if we can find a way to fit them in somehow.

127361··on IBM Diversity Efforts Targeted by Stephen Miller's Legal Group
Also it would be in Russia and China's interest to promote these diversity agendas, in order to destabilize and weaken the West. I remember someone say these DEI agendas are a part of a "long march through the institutions" - something right out of China's playbook? If there's a real possibility of state actors promoting such agenads, then this is a serious national security issue.
127361··on IBM Diversity Efforts Targeted by Stephen Miller's Legal Group
If we're not hiring based on merit then we're destroying the country's global competitiveness against China.
127361··on Unveiling secrets of the ESP32: creating an open-source MAC layer
Feed through capacitors for power and use fiber for the rest?
127361··on Unveiling secrets of the ESP32: creating an open-source MAC layer
Some old Realtek switch chips featured a protocol called RRCP[1] where you could write to the hardware registers using a specific type of Ethernet frame. So I guess a CCP-designed backdoor would probably detect a specially encrypted WiFi packet and allow then internal memory of the device to be written/read over the air. The key would be hardwired into the chip, part of the random logic - so there will be no visible block to identify on visual inspection of the die.

Or more subtly they could insert (or just not fix) a bug which allows packet descriptors to be overwritten on reception of a certain malformed WiFi packet, e.g. too short or long, which makes it possible to overwrite regions of the device's memory and thus compromise it. A SDR might be required to transmit the malformed packet(s).

By the way, I wonder if modern Realtek switch chips might still support RRCP, and an undocumented EEPROM bit or strapping resistor might re-enable it?

1. https://en.wikipedia.org/wiki/Realtek_Remote_Control_Protoco...

127361··on Unveiling secrets of the ESP32: creating an open-source MAC layer
I think Espressif have or at least used to have their own in-house developed MAC and PHY, which is not publicly documented.

For the Bouffalo Lab and Beken WiFi SoCs we already have SVD files[1] for the WiFi MAC (and likely the PHY too). Thus we have nearly complete documentation for all chip registers and their bitfields. Both SoCs are based on CEVA RivieraWaves WiFi IP.

Also you might be able to use it as a SDR for the 2.4GHz band, there appears to be registers to send ADC data to on-chip SRAM. And USB 2.0 High Speed device functionality on some of the Bouffalo chips.

I was thinking of hacking it to use as a cheap uplink to the QO-100 amateur radio satellite, which uplinks in the 2.4GHz band. I think 100mW of power might be just enough for CW or some very narrowband PSK mode.

By the way, on the Bouffalo devices, watch out for the eFuse registers, they're not fully lockable and write protectable, one wrong register write and the whole chip itself can be bricked and stuck permanently in secure boot mode. It happened to me, and I'm going to try and work around it by glitching the clock input on boot, just at the right time, to disrupt the eFuse reading, just for the fun of it.

1. https://github.com/bouffalolab/bl_iot_sdk/blob/master/compon...

127361··on A16Z Funded AI Platform Generated Images That Could Be Categorized as CSAM
Down with this thinly veiled morality policing. Someone should make a read-only bootable USB flash drive OS, with all the AI models in it plus GPU drivers, etc. That way, people will be able to create anything they want with it and enforcement will be nearly impossible because everything runs locally and is lost on power off.
127361··on State of Mozilla
By the way, I have left the community and found something else to do after the introduction of these codes of conduct in open source. Over and done with it.
127361··on Firefox on the brink?
We'll see what happens after Manifest V3 becomes mandatory in Chrome. That might trigger an influx of users?
← PreviousPage 7 of 8Next →