1,713 karma · joined October 28, 2021
I doubt it will discourage the true large-scale bad actors for whom Wikipedia is only a tiny subset of what they are trying to download, and are sufficiently well-resourced that they can't be bothered to special-case it.
It'll be interesting to see how this plays out.
I think the most interesting thing here is that it shows that the companies doing these crawls simply don't care who they hurt, as they actively take measures to prevent their victims from stopping them by using multiple IP addresses, snowshoe crawling, evading fingerprinting, and so on.
For Wikipedia, there's a solution served up to them on a plate. But they simply can't be bothered to take it.
And this in turn shows the overall moral standards of those companies - it's the wild west out there, where the weak go to the wall, and those inflicting the damage know what they're doing, and just don't care. Sociopaths.
The mitigations in the cited article are good too, but they don't replace the need for safer languages.
The nice thing about this approach is that the LLMs don't need to be flawless for it to work, as the formal analysis / unit testing will keep their errors at bay - they just need to be good enough to eventually output something that passes the tests.
"These four types of integrity, do not establish memory safety, but merely attempt to contain the effects of its absence; therefore, attackers will still be able to change software behavior by corrupting memory."
and the paper then goes on to say, about Apple's implementation of the cited techniques:
"This intuition is borne out by experience: in part as a result of Apple’s deployment of these defenses since 2019, the incidence of RCE attacks on Apple client software has decreased significantly—despite strong attack pressure—and the market value of such attacks risen sharply."
"Decreased significantly" is not "eliminated"; indeed, you could paraphrase this as "the combination of these techniques has already been shown to be insufficient for security guarantees".
Which is not to say that these mitigations are a bad idea; but I think their benefits are significantly over-sold in the paper.
Human civilization is now so totally dependent on fragile, buggy software, and active threats against that software increasing so rapidly, that we will look back on this era as we do on the eras of exploding steam engines, collapsing medieval cathedrals, cities that were built out of flammable materials, or earthquake-unsafe buildings in fault zones.
This doesn't mean that safer C++ isn't a good idea; but it's also clear that C++ is unlikely ever to become a safe language; it's too riddled with holes, and the codebase built on those holes too vast, for all the problems to be fixed.
But it's promising work, shows the treatment seems at least to be safe, and more research will no doubt follow to clarify this.
https://www.med.keio.ac.jp/gcoe-stemcell/english/member/okan...
A tiny bit of hardwired dedicated logic integrated into the camera module would be more than adequate to do this - just gating of either the digital I/O or the power to the camera, and a pulse-stretcher so the LED goes on for at least a few seconds each time to prevent an attack by rapidly flicking the camera logic on and off.
A similar circuit for the microphone with a different-coloured physical LED - not just a software-controlled dot on the screen - would be a good idea too.
Banking is critical national infrastructure. If online banking were to stop working for any considereable time, the result would be economic chaos, and right now the online banking services of most of the major banks are going down regularly, and concurrently, to the point where the mainstream media are reporting it.
Outages like this should be incredibly rare, and certainly not both frequent and concurrent across the big-nine banks.
It's all happening in plain sight, but outside of some trade press reports, no-one seems to be discussing it within the tech community. DDoS? Nation-state level hacking? Wide-area data centre or telecoms network failures? Repeated failure of some unacknowledged single point of failure? Or something else?
It's clear that even the Treasury Committee don't know, or they wouldn't be sending these letters to the banks' management.
Whatever it is, the banks seem to be keeping it a secret, and security-through-obscurity is generally a very bad idea. I understand keeping problems secret for short periods to allow fixes, but this has now been going on for months. Something is very wrong.
https://committees.parliament.uk/publications/46590/document...
https://www.openbanking.org.uk/glossary/cma-9/
Unless this is all chance, and IT reliability and/or security is falling apart across the entire British banking sector independently, which seems increasingly unlikely, something is going on. But what?
But this isn't the first time something like this has happened, and simultaneous outages like this are not something that is likely to happen by chance. This report is only part of the visible problem; this is happening to other banks as well on a regular basis (see below).
If it's not chance, either external attacks have occurred against several different banking groups at once (Lloyds, TSB, Halifax and BoS are all one group, but Halifax, Nationwide, First Direct and Barclays are not), or a substantial fraction of the entire British banking industry has a single point of failure somewhere.
Whichever it is, the banks and their regulators are keeping very quiet about it.
More reporting:
https://www.theregister.com/2025/02/28/payday_from_hell_as_s...
https://www.independent.co.uk/tech/lloyds-bank-down-not-work...
Transparency logs are of course better because they make it much easier for rogue CAs to be caught rapidly, but it's not a reason to abandon CAA until transparency log checking is universal, not just in browsers, but across the whole PKI ecosystem.
Interestingly, all the banks seem to have the exact same notice on their websites about this. (See https://www.theregister.com/2025/02/28/payday_from_hell_as_s... )
None of the reporting on this seems to report a cause for what might be behind this. A concerted DDoS campaign? Failure of some shared common facility? Nation-state-level hacking?
None of the reporting on this seems to report a cause for what might be behind this. A concerted DDoS campaign? Failure of some shared common facility? Nation-state-level hacking?