Vendors need to make it easier to verify the integrity of persistent firmware, in an offline fashion. It will dramatically increase the cost of persistence, which is the best way to put these thugs out of business.
2,010 karma · joined March 4, 2020
Vendors need to make it easier to verify the integrity of persistent firmware, in an offline fashion. It will dramatically increase the cost of persistence, which is the best way to put these thugs out of business.
You might want to question your own confidence once in a while. Unless you independently predicted rowhammer, spectre, and meltdown.
For what it's worth, the state very likely needs a warrant to use technologies capable of looking inside structures [1]. Not that the law applies to them, but hypothetically.
We also have PE firms, like the ones that controlled Solar Wind, dictating the level of security investment and dumping their positions when the bill for their negligence comes due. PE wizz-kids call that "optionality". They love optionality.
Congress should listen to Dan Geer and adopt product liability for closed-source software. They should also do something about PE control over the economy, they are doing serious damage.
Congress should probably just listen to Dan Geer and establish products liability for closed-source software. I feel like this might have turned up sooner if there was a git diff to read.
[1] https://blog.erratasec.com/2011/03/comodo-hacker-releases-hi...
[2] https://www.comodo.com/news/comodo-ceo-entrepreneur-of-the-y...
[1] https://scholarship.law.columbia.edu/cgi/viewcontent.cgi?art...
awk -F : '/\/home/ { print $1":"$3":"$4":"$6 } 'I think the popularity of Python for scripting is pretty good evidence that PG was dead wrong on the importance of brevity in programming languages. Further evidence can be found in Python's development of type hints.
"[We need] a set of guiding principles to inform the types of speech that should be permitted in digital town squares"
[1] https://foreignpolicy.com/2020/10/15/forget-counterterrorism...Agreed, Facebook is just exploiting weaknesses that already exist in American minds. Those problems exist elsewhere, but have not advanced as far.
There will be a silver lining in the Facebook case though. We're going to see a lot of emails and depositions that end the "Mark Zuckerberg is a uniquely competent person who earned an empire through ability" myth. That's good enough for me.
When broker-dealers (BD) say this, check their foot notes. The precise statement is something like "80% of market orders are filled with a price improvement relative the the NBBO at the time of execution." That is a super narrow definition of "better". It says nothing about limit order fill rates, improvement rates, or improvement magnitudes.
More importantly, it says nothing about the path of the NBBO midpoint. "Better" needs to be measured relative to the counterfactual where orders are not sent to the BD. The BDs that fill Robinhood orders are all associated with large systematic hedge funds. The hedge funds make directional bets and hold positions overnight, activities that move the NBBO midpoint. That is a seriously suspicious conflict of interest.
If the BD is benefiting from hedge fund research about short-term price movements (probably legal if disclosed to hedge fund LPs), it will harm Robinhood clients. If the hedge fund is benefiting from BD research about retail flows (probably illegal), it will harm Robinhood clients. The data only has to cross the corporate boundary once to be harmful.
The worst thing about this clear conflict is that the BD and hedge fund are the only ones presently capable of measuring that harm. Until the SEC undertakes a systematic analysis, it is inappropriate to call this a "conspiracy theory". The SEC doesn't even have the data it needs to study this question. Weird.
Even just annotating the table of contents from "Serious Cryptography", "Cryptography Engineering", etc. would be enormously useful for motivated hobbyists.
Probably hard to monetize, but it would be a great service to the community.
She would be in a totally different situation if she had a tape of Tesla's AGC threatening her friends through their immigration status. That is straight up mafia tactics.
Brings to mind this case [1].
Can you point to some industry literature that explains this?
If this is true, it is a lot more surprising that Intel is talking about going fabless. You build a lot of expertise by rolling the dice on new techniques that don't pan out on the first iteration. People wouldn't be so pessimistic about Boeing if they had just been overly aggressive in a new airframe design, rather than failing to safely mount new engines on an old design.
Yes, that would create some accounting overhead. But it's a small price to pay to keep Godzilla from eating the villagers' livestock.
Predatory pricing is just dumping. You sell something below cost until your competition goes out of business, then you either raise prices or hold prices constant but reduce quality (eg Amazon selling counterfeit books).
Bundling is requiring people to purchase A+B in combination. An example would be a gourmet ice-cream maker that is actually famous for chocolate but only sells 50% chocolate, 50% vanilla.
You can see this move as a combination of bundling and predatory pricing. Microsoft did this with Defender too. Their strategy is to starve nascent competitors for revenue in a niche area so they can never mount a direct attack on the core business.
The picture at the top of the confounding article gives it away. Those kinds of diagrams are common in "hierarchical Bayesian models" like LDA.
In the simple linear setting, they are the same thing. Teaching people the "confounding variable" concept in a general setting before teaching them about "omitted variable" in a linear setting is like teaching people about Riemannian manifolds before teaching them about vector spaces.
Correlation isn't a particularly useful concept outside of simple linear models.
Omitted variable bias tells it like it is. A bias in a regression coefficient that results from an incorrectly specified model.
y = x*b + e
b = cov(x,y)/var(x) = corr(x,y) * (std(y)/std(x))
It's too bad the article did not mention omitted variable bias. The two principal sources of spurious correlation are (1) measurement error, (2) omitted variable bias. It is much easier to grok omitted variable bias in the regression context, then pull it back to correlation with the scaling rule.