1,971 karma · joined April 10, 2017
To me F1 shall go back, remove all the crappy rules made in the last 20 years, return to pure gasoline V10 engines, no turbo, no hybrid, minimal electronic, no closed park, no limit in consumption of fuel, tires, etc, return to refueling during the race, and let the better pilot with the best car and the best team win.
These F1 is too sophisticated, at this point to me makes very little sense even racing, just race the car in a simulator at this point, everything is decided by the electronics and algorithms anyway, seeing talented pilots like Max Verstappen or Lewis Hamilton struggle to race because the electronics of the car doesn't let them show their potential, because they have to "save battery" or "save fuel" or "save tires", doesn't make a good show to me.
And we are talking about who knows how many tools that work with git built in the years, and this is also made it worse from the fact that most tools just invoke the git binary and capture its output instead of passing from a library.
I like more the solution proposed at the end of the article, do not change sha-1 but instead, if you are relying on git commit for security purposes (that was never the intended use) add another header to the git object with a sha-256, so that with the small expense of computing the hash twice you don't break 20 years of existing tools that make the assumption of the git commit being 40 character long.
Now, unless your AI gains access to the codes, and sends two robots in a bunker or nuclear submarine to insert the code and turn the keys to launch the missile, you can be modestly sure that no AI could launch a nuclear missile or nonsense like that.
I'm quite frankly more worried that some foolish president decides one day to launch a nuclear missile than an AI could do it.
Now that we return to the real world, the only thing AI could do is to attach systems that are connected to the internet (and critical systems are not), but let's be real, AI are not really that intelligent by themself, it's not that someday an AI could decide like in Matrix or Terminator to exterminate humans, because (at least now) AI have no consciousness and can't really decide what to do.
An human can of course use an AI to carry out cyberattacks, as he can do that also without AI like it's done since the internet exists, but it's an entirely different thing (a human using a tool, AI, to do damage VS the AI itself that decides by himself to destroy the human race).
A chatbot using an LLM of course not, it suffers from hallucinations, it may do what you want but there is a change it won't and you have to fight it to get the desired result.
Chatbots are far WORSE than traditional UI for everything. If some product has a chatbot functions it's the first thing I disable, if it's not possible to disable it, I avoid the product.
And GUI applications are typically preferred, at least for the normal people and not us nerds, to CLI applications, since you know people like moving a mouse and clicking on buttons (or tapping them on a touchscreen) that learning commands: a chatbot doesn't make the CLI experience less awful for the average user, and for the nerd user, he prefers to use the CLI directly (replace asking the chatbot with man or --help and you don't need to emit tons of CO2 and transmit your personal data to a datacenter on the other side of the world to do stuff you did with MS-DOS)
And if it wasn't for these apps (for example banking apps, since someone decided that it's now impossible to use your homebanking from a PC since it's not secure enough) I would already use a Nokia 3310.
If you trust TPM not to be backdoored... come on, you don't think the NSA or who else has put effort in getting a backdoor inside? They even tried to put one in Linux and it's documented, never the less in anything proprietary...
> It can just read the generated seed directly from user space without the program ever knowing about it.
Not that simple: it has to know exactly where in memory it's stored, and that requires understanding of the source code of the program that is encrypting data. That is not of course a simple task if someone wants to write a malware that just "steals" encrypted data from any software just by looking at the network traffic, like you would do if you compromise the RNG of the OS.
> clock_gettime() just reads a value that the kernel has set, so that's not particularly difficult to fake.
You can sample the call millions of time and understand if the value is truly random or there is a pattern. It's something detectable. Software like GPG that doesn't trust what the OS gives you already do that (as well as combining multiple entropy sources).
> It's fine if you use it as a strictly additional source of entropy, but then the whole argument that it is superior because it avoids syscalls goes out of the window, because you're doing strictly _more_ work.
Avoiding the syscall could have other benefits, not only performance. For example: a program making that syscall may be flagged by a possible backdoor as a process with something interesting in it, and thus a potential spyware may be interested in take, for example, the memory image of that program and send it to a remote system for it to be analyzed. The fact that the reading of the current time doesn't pass from a system calls means that it's not possible to identify that process as "some process that uses cryptography and thus has something interesting in it to hide".
We are fooling to me, there is no intelligence in these models, they just apply methods that were invented by humans without any consciousness on what they are doing.
Sure, Linux laptops are not "pretty", but I don't need a computer to be pretty, in fact I hope that someone starts to produce again laptops identical to old IBM thinkpads (not the insult to the brand that Lenovo is building) but with modern hardware, a computer that had every port you need on it, no adapter required, that you could have it fall from a ladder and not break, with removable battery, hard drive, with the trackpoint instead of those stupid trackpads, I want it even with a DVD burner fuck it. I don't care it to be small, I care it to be functional.
Sure an infected system may as well fake time values, but that is much more difficult and it's possible to detect from a userspace program. For example you mention to use getentroy, but on a compromised system you know how easy it is to change something that is implemented in a system library (e.g. libc) or even if you read /dev/random directly without passing from the libc how easy it's to make it read whatever you want?
To me that is not that bad implementation, in fact it's an implementation that is used in a lot of security software (including GPG, not as the sole source of course but as one of many).
The LLM *may* be used as a mere tool, that is something you ask question time to time, but shouldn't be the thing that makes the work that you should do. Because if we arrive at this point (hopefully never) at that point the CEO of the tech companies may as well say, why we still need developers? Let's fire all of them.
Fortunately they did not, because there is STILL VALUE in writing code by hand, understanding what it happens, what the code will do, etc. I hope this will not be a lost skill, or well, if it does good for me, because the same as nowadays things being able to repair electronic devices makes a ton of money (I've considered opening a repair shop) because there is no one still doing it, will do programmers that well, know how to program.
If you are an experienced programmer (not someone that did an online course and calls like this) with YEARS of experience in coding in multiple languages really, the only real limitation is the speed at which you can type on the keyboard, that is usually way faster than what the even good LLM is able to emit tokens.
This not considering token expense: if we see at the point of view of the company, it's way cheaper an experienced programmer, that in my country costs you 4000 a month tax included, than the tokens that an LLM would use to do the same job.
On top of that there is the environmental impact of all of this, and why they are almost making me not use my car because it's euro 5 and now there is euro 6, these AI companies are emitting tons of CO2 to do stuff that human beings can do with 1/1000 the energy that these AI companies use.
The problem of AI generated stuff (we see the problem of manifests, but I'm a software engineer and with computer programs it's exactly the same thing) is that they immediately look non-human, and our brain trained itself to detect, and thus get irritated by, AI generated content.
It looks fake, it hurts to see, it seems fine at first glance fine but it's not, everyone seems identical because the AI is not, despite of the name, creative, it just a hyper complex copy/paste machine, and obviously the result just looks copy/paste as well.
And unfortunately is something I start to see to family members/friends that are not tech experts when they ask me to setup them up a new phone... at least the passwords they would have written them in some notebook that they had at home, or always used the same for everything, but with passkey... and when you tell them that they lost access to their email, possibly the files backed up to Google Drive/Google Photos, etc they are surely not happy.
Also passkeys makes it difficult to get access to your account in an emergency scenario, what if I loose my phone and I'm not signed in to other devices? Maybe I've setup an SMS as a recovery method, but first I have to get to my phone company to request another SIM card, maybe I'm on vacation on the other side of the earth in vacation for 2 weeks, I'm locked out of my Google account, and from all accounts that uses the passkey as a sign-in method (including, for example, the account that I need to use to check in on my return flight, or my banking app that I need to pay stuff!)
Then I've decided that is worth either spending money on phones whose replacement parts doesn't cost half of the phone itself, or just buying the cheapest Xiaomi or similar chineese brand phone and when it breaks buy a new one or repair it (funny enough cheap phones are more repairable than expensive ones, so I usually repair them).
And if such AI does something wrong (which it does) no matter what they WILL REMOVE your app. Because they don't care about you. Sometimes the only way out is to publish the app again with another package identifier, because once they flagged it even if you remove all reference to the offending feature there is no way that they will accept it (it unfortunately happened, fortunately before releasing the app to the public so we could switch without affecting users).
In some sense I prefer Apple (and I say it as an Android user), you surely pay an annual fee to publish to the store, but if you have some issues you can open a ticket where a fucking real human will look into it and answer you, and explain what to to.
Having the option to also pay with credit card would be much more convenient to tourists, when I visited Japan I've had difficulties finding the right place to get a SUICA card (being that my Android phone didn't have Felica chip, as most phones sold outside Japan), and on top of that you almost everywhere need to charge it with only cash. And you can charge it only by 500 or 1000 yen at the time (depending on the machine), and of course tickets always have not round prices like 110 yen. And you have 500 yen of deposit for a card that probably costs to them 10 yen to manufacturer, unless you get the red SUICA card that you can get only in some special machines at the airport but with that you don't get back the unused credit when you leave (you can spend it at vending machine tough).
So the speed saving of a couple of ms of not having to pay by tapping your normal credit card is completely vanished by wasting time to charge that card.
BTW even if they don't want to put credit card POS on every station (I get it, it's expensive and they need to pay fees if someone uses a card, compared to cash) they could make a system that uses regular NFC (would be 100ms slower, who cares) at least for tourists so they can use it with a regular NFC card in their phone wallet that they can charge with an app without requiring a technology that only works in phone sold in Japan?
The digital version only works on iPhones, since Android phones sold outside Japan doesn't have the Felica chip, or if they have it (e.g. Google Pixel) is disabled in EU/US firmware because the manufacturer doesn't want to pay a fee for every phone to Sony for something 99.999% of people that will never travel to Japan would use.
Second a lot of people has still FTTC even if it has FTTH, mostly because FTTC offers a speed that is enough for most people (100Mbit/s) and upgrading may have costs (the installation of the fiber is at the expense of the ISP, but if you need to make modifications, such as put a pipe from your house to the street in which they will put the fiber, it's at your expense). In some cases even if fiber is present it's difficult/not possible to get it into your house (for example you live in a condo and the other tenants doesn't want to spend money to make the modifications that are needed to pass the wires).
In any case they have started to switch off copper (since it costs money to maintain an infrastructure that has decades), so either way customers will be forced to move to fiber or 5G network in the upcoming years. In any case a fault on a copper line is likely not to be repaired...
To me people that say that x86 is slow etc. never used an x86 processor with anything other than Windows. Yes, Windows is shit and laptops that run Windows are for the same reason shit. I get it. But on an x86 system you can run other OS, and, for example, a Linux distro with well tweaked power consumption parameters can get you even 3 days of battery life, or even more.
The point is that Windows keeps almost always the CPU above the minimum frequency, because it's full of useless background services, because programs are not well optimized for the hardware (to maximize backward compatibility they don't compile target x86_64 v3 for example and thus don't leverage on features and instructions available on new CPU or fall in the emulation case I've mentioned initially), and other reasons.
With a Linux distro you can keep the CPU at 600Mhz while web browsing, you can even turn off cores that you don't need, and the battery with this configuration surely lasts ages (at that point it becomes more predominant the consumption of other peripherals such as the display).
Apple wants to sell you a new system every couple of years, they don't want you to upgrade. They want you to throw it away the system completely and replace it (and they claim they are environmentally sustainable, btw) when in the PC world you would replace RAM, CPU, GPU, motherboard, maybe the SSD, but surely you can keep the power supply for decades, keep cooling fans, not talking about the chassis that could last 50 years because it's a just metal box.
They are a rip off these products, and I don't understand people that buys them.
BTW even when Apple did produce towers like Mac Pro they did so in a purposely non-standard way, such that you couldn't, for example, replace the PSU with a standard ATX one, the only standard components were really RAM, HDD, CD-ROM drive and in Intel models the CPU, and of course PCI expansion boards (sort of, because to work GPUs needed to have an Apple specific firmware in the old PowerPC models). You couldn't for example upgrade the motherboard, if you wanted to change the CPU to a new generation you also needed to buy a entirely new Mac with a new chassis, new PSU, etc even if what you had were perfectly fine.
To me there is no reason to update a PC if you don't use Windows or MacOS that forces you to purchase a new hardware to do the same things. Just look at Windows 11, full of useless AI features, weights a ton, and in the end it's probably faster a PC from 25 years ago with Windows XP.
Of course if you are a person that ships 20 packages you don't register a company to do so, nobody will, you just sell them privately (and the exception to sell things privately is quite high, in my country you can do it up to 5000 euros AT YEAR, after that you need to declare the income in your tax declaration but still you don't need to register a company if it's not your main income).