Maybe I'm misremembering, but for example my esphome proxies in HA will show nothing for ages at night while my phone isn't being interacted with.
If the phone is lost, it's probably not super awake lol
52 karma · joined February 20, 2022
Maybe I'm misremembering, but for example my esphome proxies in HA will show nothing for ages at night while my phone isn't being interacted with.
If the phone is lost, it's probably not super awake lol
I get how there is risk associated with a supply chain attack, but what are you going to do when you don't understand a vulnerability and need to fix it?
Most problems aren't impossible to solve of course, but those who've been working with a codebase for a long time probably have a more intimate knowledge of how it works.
Not sure where I'm really going with this other than I fully understand opsec, the hacker mindset, cyber security, etc, but I've never really cared to stay private because I wanted to be known. Now that I'm likely as good as I'll ever be, it doesn't really matter lol. If someone finds something I said in poor taste, I'll apologize and hopefully have learned from it and move on.
What Open ai offers currently can't really compete with search - I understand the data it's being fed gets newer and newer, but it's not really real time like the search engines are. Indexing and presenting data is so different than NLM. Even if it is fed data that's new it's going to have to infer a lot because of a lack of history. It might be able to summarize recent events I guess. Way dumbed down here, but I consider chatgpt like a really smart encyclopedia that can search fast and stay in context across "searches."
If you meant Google, that's sort of what I'm saying - they wouldn't release something that could blow open ai out of the water. But I suspect what open ai offers as a product is something Google could've built long ago, or maybe did and couldn't figure out how to monetize it. They've instead invested in ai to make their products and services better, not as much to offer ai as a service.
What I meant by bard not working out so great was that Google quickly dusted off or slammed together some shenanigans to be relevant, even though what openai is doing doesn't appear to be a part of their master plan.
As much as it pains me to say this, I don't think the real money is in making this a service, or "the product." I think the real money is in using AI internally as a puzzle piece of your backend - ie. the secret sauce behind xyz product.
I'm being very narrow here, but you can only do so much integrating what openai has built into your products - eventually "everything" providing data from the same model brings "everything" to the same level. In contrast if you train and create your own models to make xyz do something specific, nobody knows how it was done, or it surely makes it a lot harder to kang.
I have zero proof, but I suspect Google for instance has models that would literally obliterate what openai has shown capability wise. They're probably not necessarily language models though. Again, nothing to stand on here but I doubt their search and analytics for example are driven by hard coded algorithms these days.
Bard may have been released sort of as a "psh, we've been there done that" when in reality they didn't, because they never planned to make the models they were/are working on "publicly" available to use. It makes me wonder if this is how Google has lead for some long with some areas - now openai sort of screwed it up for everyone by making it a service that can be integrated / adopted by nearly anyone.
The only people I guess that are really going to know are the devs working for these big orgs, and I'm sure that lock and key knowledge.
Just because phishing is common, doesn't make it sophisticated.
I'm not dumb, I just never looked at the lyrics I guess? IDK, it was a life changing moment I'll tell you that much.
It's not great, there's certainly a way to secure it, but like many other solutions - stuff it in a storage bucket with a "random" url is "good enough" in the eyes of the platform.
While there's definitely a method of securing the access to the uploaded content to those who should have access, it's often not implemented that way since your uploaded content would be statistically improbable to "guess" and even more improbable to tie it back to you.
I came off a little direct, straight up saying it was not a vulnerability without context. While I still stand by it not being a vuln from a sec perspective, it's definitely not great.
What do you do for a living?
This isn't going to come off nicely, but your assumption that it needs a full rewrite, is in my eyes a bigger problem than the current mess itself.
The "very junior" devs who are "resistant" to change are potentially like that in your view for a reason. Because of the cluster they deal with I suspect the resistance is more they spend most of their time doing it XYZ way because that's the way they know how to get it done without it taking even more time.
What it sounds like to me is that this business could utilize someone at the table who can can understand the past, current, and future business - and can tie those requirements in with the current environment with perhaps "modernizing" mixed in there.
I have equipment I own in two colos - for other things. It made way more sense when I was selling VPN access to lease everything.
Most importantly, this boast Azure is making falls flat on its face unless they own everything. Even if they "own the servers" they're likely still colocated, being provided network hand-off, etc. ¯\_(ツ)_/¯