https://cabforum.org/working-groups/server/baseline-requirem...
161 karma · joined February 7, 2025
https://cabforum.org/working-groups/server/baseline-requirem...
>100% agree, as with any important technology. But this is just a small curriculum change, just one more topic to cover in the lecture, and maybe a class.
Critically scrutinizing LLM output is just critical thinking skills, something universities should already teach.
Really, if the journalist wanted to cover the event without being noticed he could've done so undercover.
They also have this to say about AI:
>Computer tools, including artificial intelligence (AI), are making the work of translators and localization specialists more efficient. However, many of these jobs cannot be entirely automated because computers cannot yet produce work comparable to what human translators do in most cases.
https://www.bls.gov/ooh/media-and-communication/interpreters...
https://www.reuters.com/sustainability/climate-energy/rwe-ha...
In your scenario, yes it is bad if the attacker gets root on your computer, but sealing the key with the TPM means they can't retrieve the key itself. Where the TPM helps is preventing the attacker from establishing low level (kernel, bootloader, or firmware) persistence, since modifications of these components would change the TPM PCR measurements and result in a boot failure.
If the attacker is local and they reset the UEFI, the TPM PCRs are now different and as before, the disk encryption keys will not unseal.
It is also generally recommended to use a pin with TPM, which further complicates this scenario for the attacker because the TPM enforces rate limiting. As the other commenter mentioned, the physical access scenario is commonly a stolen laptop situation, where the attacker would not be in communication with the victim and probably wouldn't return the laptop.
https://wiki.archlinux.org/title/Trusted_Platform_Module#PCR...
Spoiler alert: This applies to all software. This is why security preaches defense in depth.
Additionally, total dose is only one part of the equation. Single Event Effects (SEE) also must be mitigated.
You can read NASA JPL's ASIC design guidance for a brief intro.
https://energy.ec.europa.eu/topics/infrastructure/high-level...
https://www.ree.es/en/ecological-transition/electricity-inte...
>I got the money back via chargeback in short time.
So as evidenced, you are protected by the fraud infrastructure. The bank ate the loss for the fraud and you were made whole. In the end, the banking system cares about fraud loss. And they are exceptionally good at finding the fraud. Making changes to the card payment system is extremely difficult, due to the vast scale of the systems, so without a very good justification that a particular change will move the needle on fraud rates, the banks will opt to not make the changes.
>The search committee hopes to hire someone next spring, with Cohn planning to remain at EFF for a transition period through early summer
https://www.eff.org/press/releases/executive-director-cindy-...
It always has been, it's just now the state actors are more and more active (and visibly so).