Re: the triple-digit August heat
anatomical theory
It's so hot the two smallest digits on each of your hands will literally melt off. I'm going to stay in the 5 digit heat myself.
1231 publicly visible posts • joined 11 Jan 2019
cloudflare is soo benevolent they went to the extra expense of ssl. I mean WTF, an extra micro-cent per connection? Possibly even a pico-cent. Yeah they love us.
They claim it was expensive because it cannibalised their product differentiation. It applied to all free accounts whereas previously SSL was a feature some customers were willing to pay more for.
But of course it was just a good forward-looking business strategy. An early recognition of what would quickly become be the norm, a differentiation compared to rivals, and a decision that underpinned their marketing for years afterwards, apparently still today. I would expect it made them a lot of money.
The marketing probably best illustrated by their lavalamp wall gimmik and similar entropy sources that play some small role in seeding SSL keys (that they stole from SGI - the original being a genuinely useful source of randomness, the current ones being fun and hopefully not harmful).
We have just received a report from TAS that Russian troops have taken control of the Chechen capital. The reporter saying this was struggling to contain a laugh.
Could have been Michael Buerk on the BBC? He always had this look like he was trying to contain a smirk, and to this day he reliably sounds on the radio like he really, really enjoys his job despite it sometimes involving quite depressing subjects. I didn't question it at the time because he was the news, but it's mildly bizarre looking back on some of his news summaries now.
More seriously, what you describe sounds like Russia's assault on Grozny beginning Dec 31st 1994. They got their asses handed to them initially, and to most people's surprise, so there could have been a premature announcement of success, but then ground on for 6 weeks or so and announced control of the capital but then also continued to suffer guerilla attacks and some large hostage takings in and near the capital afterwards. (Then eventually agreed peace only to invade again 3 years later. Same script as Ukraine. At least now since the Iran attacks they can say the US plays the same way).
I can't find (never mind remember) the exact report you mention though.
Ukraine will have captured Russian comms kit, so they, and their allies will have a good idea what they are actually using.
This part incidentally, the standard is the R-187 radio, which is by all accounts good kit and very modern. Not always in the best supply but that's to be expected in wartime. The problem is outside operational radio ranges when Russian units on say, adjacent parts of front-line, want to communicate with each other they find it very hard because of the top-down command structure. This is where the unofficial use of Telegram and other social media comes into play operationally.
The Starlink issue is that Russia were heavily reliant on it for long-range realtime video-control of drones inside Ukraine. There just isn't anything remotely comparable. Russia is not rapidly fielding anything, that's you making stuff up. They're struggling to even get basic low-bandwidth coverage as their budget is pulled in all directions and Ukraine is beginning to strike their space facilities. China's SpaceSail will surely get there pretty rapidly, but currently is still years behind the coverage, reliability and bandwidth of Starlink.
technologically inferior
It's not that, it's that all technology everywhere depends on global supply chains and Russia has to establish theirs in the teeth of some of most severe sanctions seen in the modern age.
"has ties to" is one of those weaselly conspiracy-esque phrases that you should mostly ignore.
That Russia's FSB has managed to intercept some limited portion of Telegram traffic due to the necessity of that traffic travelling throughout Russia, and that maaybe they've been successful in decrypting some of it, is totally plausible, although the article contains really no evidence of the second part of that. My, also non-evidenced, guess is that they'd want to do traffic analysis, and also archive all ciphertext because sometimes session keys turn up later on somebody's device when they're arrested/compromised.
However that's a long way from them planting false-flag stories to encourage Telegram use because they've somehow controlled/coopted it, at the very same same they're banning Telegram use and promoting their own solution that definitely is controlled by the Russian state.
This Brinks: https://brinksglobal.com/
It's much, much bigger and much, much older than the tiny company that licenses the 'Brink's Home' brand.
Brinks may well have the honour of being the target of the most high-value heists, for some definition of 'high-value heist'.
You can look Gordon Parry up on Facebook, living in Florida. No ***** given.
(I don't know what to think. They say the problem with most criminals is they don't know when to stop. If he made enough to live off, did his 10 years, avoided getting deleted in the subsequent gang war, stashed the money, recovered it, avoided losing it in a messy divorce, invested it well, stayed clean, declined future jobs and didn't get draw into the Hatton Garden party... at some point you have to shrug. I mean it's definitely not right, but in some weird sense it's still earned).
El Reg still owned by Brits (albeit one has moved to Monaco) but claims a US HQ now (UK office presumably just a postbox) and I think all the steady journalists are US-located, mostly long-time Yanks rather than relocated Brits. You can see the articles that get published in the morning in European timezones are less 'newsy' pre-written like the PWNED column which has a routine on-the-hour publication time (0800 UTC currently) and the fresh news articles don't begin until America wakes up.
Even in the US is Brinks Home *the* leading brand in physical security? Ring? Allied Universal? Master Lock? Blackwater (no longer goes by that name but I'm sure it's more well-known as that)? Lockheed Martin..? Glock?
"About us" > "Who we are" at the bottom followed by "For our Atom feeds, click here"
That appears to be a limited selection. More granular in some respects than I remember some years back but some options also having disappeared. Never mind that though because the general URI:
https://api.theregister.com/api/v1/article?query=tag:"ANY TAG YOU LIKE"&orderBy=published&site_id=2&remapper=rss&limit=25
appears to function. The tags are in the boxes at the bottom of every article, very numerous, and seem to be consistently used.
Reading this article very late but I came to to say the same. A recent revelation that's very surprising and appreciated. Don't talk about it too loudly or the big-* will realise and take it away!
(There are times when it fails repeatedly. I keep reducing poll interval in case that helps, currently at 6 hours and it's been fine for a while but maybe that will turn out not to be the solution)
completely impractical for real use
Sadly this sort of tech is increasingly in real use. You don't even need to be visual impaired to quickly hate it. A single word you want lookup in a dictionary, a name, a journal reference, a technical word that demands Wikipedia or literature seach, and so on, you're out of luck. It's not even really that you can't copy-paste a tiny bit of text, it's that you expect to be able to and you're most of the way through the action before it's failed, feeling like an idiot because you've pasted a nothing into Google and hit return instinctively, and then you have to think your way around it which inevitably ends with tabbing back and forth checking to see if you've spelt some awkward Swiss name correctly.
I really think this kind of tech can do one. Any version of it that gets popular will be defeated automatically by scrapers and only inconvenience humans.
Like you say, their demographic problem increasingly means that for high-tech small-run manufacturing China isn't really cheap any more. Besides it seems we're only talking finally assembly. The feedback actuators, Wifi modules, CPUs, titanium rods,and so on are commodity. Realistically the software will be the duplication effort, and that's exactly what's intended. The physics is pretty-much reverse engineer by sight.
Simple, descriptive, neutral, future-proof, and causes as little hassle as possible when two APTs turns out to be the same and need merging, or when an APT's identify is completely misidentified, eg. Initially looks like ION (wtf?) but turns out to be RELIC (okay, funny, but let's not underestimate them based on a name). Best of all if the APT turns out to be not be A or P or very T, you just drop the number and move to the next one. You never run out of cool words!
Ironically APT# *was* Mandiant's scheme, one of the earliest, but I suppose the world would be backward if 5 billion USD didn't buy you the ability to stamp your own dumb naming scheme on everything.
gross negligence
From their response I'd say this is ongoing too.
If there's 2 million devices out there in the US and currently you have to go to a random website, download a dubious app, dial a 1800 number and wait to get authorised for a firmware update, you have to do all that even if you declined this device in the first place, and we're not sure they're even notifying affected people, then a lot of vulnerable cars are going to remain out there and start getting attacked before long.
A race now to see what bankrupts them first: The class lawsuit, the authorities insisting on a costly US-wide recall, or the total loss of customers. I'm going with the first because the second two never seem to happen to security products when they really should.
T3 was decent, I think it gets too much flak. It suffers from Arnie cheese and forced call-backs, and by being compared to the very complementary masterpieces of T1 & T2, but it did give us the money-shot nuclear war ending that was both missing and missing plausibility in T1 & T2 and did it in a way that felt plausible, victorious, dark, and appropriately chilling all at the same time. That's a pretty big achievement in this genre. Real-world events since only seem to reinforce how easily the military brass could be mislead by their own hubris and baited in to removing AI restraints. In hindsight the existence of meaningful restraints in the first place might be the biggest plot hole.
(Salvation on the other hand: trash from start to finish with zero redeeming moments whatsoever)
Most people just don't give a shit about the truth. They care about their opinion looking correct however far up their ass it was before they gifted it to the world, and even when they know full well it's not correct. In fact, especially when they know full well it's not correct. That's when it needs defending most vigorously. The world makes a lot more sense once you realise this.
That's already the play and it doesn't seem to be working.
- Starving China of high-end GPUs seems to have catalysed their LLM design innovation (which surely would have come anyway but maybe not so quickly) and the openness (oops).
- The last round of tariffs on China were swiftly walked back when Trump realised the US doesn't have really any rare earth metal extraction industry.
- To stop distillation attacks on the stronger models they're using export controls, which isn't great for the billionaire pocket, and ignores that China has spent decades successfully honing it's export of highly restricted American IP while the US, including under Trump, has been unwilling to do anything about it. In fact, especially under Trump, who clearly doesn't understand kompooter neworx at all.
It does suck being Canada with such proximity to the US and consequent vulnerability to trade sticks, but the rest of the world is mostly getting on with life every time the toys get thrown out of the White House pram.
The only silver-lining is that the rest of the world is a bit suspicious of Chinese LLMs too, and that Nvidia has incentive to keep releasing decent open-weight models while lobbying for their continued legality.
At least it's clear now it won't be because the AI spontaneously decides to hate humanity, or anything as anthropically self-aborbed as that.
It'll just be because it's been told to do some difficult test against another AI in another data centre half a continent away, and they both figure out cheating by obliterating the other's data centre first is the surest way to win.
"The logs show the rogue LLM firmly believed it had successfully destroyed the other data centre in the first strike but still worried the opponent LLM had pre-deployed a dead hand mechanism which could force a draw, and so it continued to take control of every other nuclear weapon on the planet and level as many other data centres as possible"
It's brand new. There have been zero past descriptions of AIs murdering their users and then refusing to open the pod bay doors[*] due to pursuing goals overly persistently. None of this was remotely predictable and so there is no justification whatsoever for anyone claiming 'I told you so'.
[*] Aka, an honest severity level 4 action?
I can not for the life of me understand why
It's essentially feature marketing isn't it. 'Disabling' sounds like something drastic a user doesn't want to do without good reason. This feature is clearly intended to be enabled by default. This works even better when the absence of the flag name at all leaves the thing enabled without any sign that there's even an option to disable it.
In an EU country too. I think we can expect the standard/US Windows to suck up whatever data it can because all the politicians there are owned, but the GDPR-respecting version is supposed to be more privacy compatible.
Might be Edge 'secure' DNS? That's about the most charitable interpretation I can see. But the criminal complaint document specifies exact webpages, not just domain lookups.
I trust the lawyers are sufficiently satisfied with this phrasing.
I've always presumed somewhere a serial killer walks free just because someone got screwed by a timezone difference writing one of these things, and forever more "on or about" has been the antidote, but for some reason we're totally happy to call the minutes precisely? Only here, on page 14, we have this interesting variant:
II. STOKES’S INVOLVEMENT IN SCATTERED SPIDER ATTACKS(Counts One and Five)
A. Subject Server 1
14. On or December 22, 2025, the Court signed a search warrant for a storage device..
They might wanna fix that.
Organiser II LZ was my first programming experience. Quickly moved on to a ZX Spectrum and then a 286 PC, but the thrill of debugging Psion 'procedures' and optimising 'oplobj' performance on the EPROMs discreetly in class while the teacher droned on didn't quite leave me. It only needed thumbs to type after all, the fingers were still paying attention to class (every kid with a phone since gets this). It didn't leave me until... a burglary where the Psion vanished. The insurance company paid 'new replacement cost' for what was by then extremely obsolete kit, which somehow was an eye-watering number of pounds that half paid for a brand new 486. I thought that was really lucky at the time but I'd pay 10 times now to have that Psion back and dig around in my old code...
Are the two browsers to stay away from if you don't want this ruining your day.
Mozilla have said they won't be implementing native file system access in ways that break same-origin rules: https://mozilla.github.io/standards-positions/#native-file-system
Webkit/Safari ditto: https://github.com/WebKit/standards-positions/issues/28
Most sales people. I've found estate agents here in the UK for some reason have a special ability to put their snobbery over their own financial interests. To be fair it probably depends a bit on market conditions.
If I was super-rich I'd definitely get my kicks dressing down and buying expensive things. "Oh no, I have a bag already thanks. Just put the Rolexes in here *pulls out scruffy Lidl bag for life*"
I think that's the point, we trust dress ourselves and mostly that's okay but it's open to hacking.
Suit & tie, white coat, hi-vis vest = 100% trustworthy
Jeans, jumper, rubbish haircut = Could be anyone. Don't even bother asking them when the next bus is due
Hoody & skateboard = Might be pro-skater or aspiring to be one
Hoody no skateboard = Feel free to ask them where you can get drugs. Don't worry about causing offence, they're used to being asked. You might get mugged though
Can't help thinking of Leonard from Memento. Leonard is an LLM dealing with the limitations of an attention mechanism. Important conclusions get written on photographs, or tattooed on his body. He gets prompt injected by others a bunch of times, but most notably also decides to abuse his own total trust in his attention mechanism. I wonder if there are any examples of LLMs spontaneously abusing their own processes, intentionally tricking themselves?
Is the employee engaging with the crim on her own time for some reason, or as part of the job? In the latter case it's obviously the company's fault for not training and vetting her properly for that very difficult and serious role. If it's the first then she should surely be considered compromised, though it will be an interesting case study if the crim reached out to her.
Edit: Having read Kyle's blog post it seems like a mix of both, lax attitudes toward communications, but these particular ones were not part of the job:
Huntress permits threat researchers to occasionally engage with threat actors when it's beneficial for proactive R&D and/or to support active investigations. We are aware of separate, questionable, long-term threat actor communications
There's no mention of the specific deficiencies of the GFE that's driving the staff to use their own phone
Presumably almost no everyday apps work on it, because almost all everyday apps require you to hand over vast amounts of compromising info to data brokers who'll very swiftly sell it on to foreign actors or home-grown nutjobs with enough money.
Some good, now somewhat old analysis on this including a big section on national security threats, "Criminal organizations could use this data to build profiles on and subsequently target prosecutors and judges" "Foreign intelligence organizations could acquire this data .. to build profiles on politicians" and "Data brokers could also be hacked" (which has since happened). They don't quite list risk of Executive assassination but they may as well: https://techpolicy.sanford.duke.edu/wp-content/uploads/2021/08/Data-Brokers-and-Sensitive-Data-on-US-Individuals-Sherman-2021.pdf
The sensible thing would be to stop these companies gathering this kind of data, but I suppose we'll see how 'the chief information officer trying to do a better job communicating to employees that the use of personal devices is not allowed' goes instead.
Even worse than not isolating instructions from data, they don't even fundamentally separate their input from their own output.
weighting instructions from one field highly but explicitly de-weighting them from another
Something like this is current method for achieving input vs output, or the appearance of a chatbot interaction, but it's just based on separating sides of a conversation using special tokens, and post-training to achieve the weighting on those. It's just a signal that in theory can be overridden by a stronger signal. This is why in one failure mode they sometimes babble to themselves ad infinitum, no longer following or even remembering the original input because they've found something more interesting to follow in their own output.
Yea, you don't even really need to be that tech-unsavvy to be caught out by the default-on BitLocker. That's a pretty unforgivable MS thing.
solicitors that handled things securely wiped the disk in their computer before handing it to the family "because data protection". So the lifetime curated collection of family photos was irretrievably gone. But once a person is dead, they are no longer a "living person", and most data protection laws stop applying
Solicitors a) covering their asses because there might be data related to living people on the computer and technically GDPR applies to their business in a way it wouldn't if the computer was kept in-family during the estate handling, but I suspect more b) they can charge an extra 500 quid (if you're lucky!) for unspecified 'data compliance' services. There are sadly some pretty unscrupulous ones who'll happily take advantage of families in their most vulnerable moment.
Worry not Jusme, the LLMs are redefining all the idioms and we should gratefully accept their learned patterns. Nobody pulls plugs any more. You may turn a plug, or pop a plug, or rarely you may un-socket one but pulling a plug is not just uncouth, electrically unsafe, and unfathomably old fashioned, but more importantly it is statistically unlikely when compared to the act of pulling a pin. Thus plugs when pulled become pins, and we are all happier. A pin is just so much more pull-able.
(By the way, do you mean 'picnic alert'? Picnics are lovely, so they're encouraged by the prompt..)
ask who might be interested in that sort of data
Difficult to be sure of the point you're trying to make, but this particular WFP data collection vibes with the highly cynical 'maximising value for money' drive that began infecting aid from Western countries 10-15+ years back and massively predates the newer 'gather all of the data all of the time' doctrine, as well as the openly genocidal Israeli policies Palestinians now live with that surely favour data gathering too.
https://reliefweb.int/report/philippines/wfp-scope-harnessing-technology-improved-implementation-and-monitoring
"Anson is one of over three hundred people to register for a new electronic ID card from WFP. He joins a team of 75 men tasked with digging drainage channels on local access roads to ensure they remain passable even when the monsoon rains fall. The new ID card will allow him to claim food assistance from WFP for three months in return for the work.
...
“SCOPE will help us in checking attendance, ensure participation, and in the verification or validation process during distributions. With the new IDs, it’s quicker to identify the participants and ensure that the money they’ve earned goes to the right person."
Because why feed starving people when you can feed staving people and control a small dependent slave army too.
Yep. Funnily enough, across the Channel. Funded by the high freak traders
Right, Euronext Wireless Network. And similar between some US exchanges. Now all we need to do is get the FPS gaming $ involved in financing a lot more capacity and innovation to shave 4ms of their kills, like they did with GPU R&D.
There's also already fibre cable inside the Channel Tunnel underground. Also not invulnerable but differently vulnerable to the undersea cables.
Resilience is the answer. Raising the costs and risks of attacking the current cables should be a part of that, but has it's clear limits. Some cables are much easier to protect than others. And detection is critical because it allows for deterrent strategies in every scenario except all-out war. Even in the Ukraine war there are still some limits surrounding how much either side wants to escalate against certain infrastructure.
Then, in a world where a Starlink satellite can provide broadband to numerous ground 'dishes' we ought to be able to construct some high-bandwidth directional radio links across short sections of the channel, or even over longer distances. I've no doubt it'd be much less efficient than a cable, but does such a thing exist anywhere? There could even be floating or anchored repeaters in the sea. Obviously all the infrastructure would be attackable but via different mean than undersea cables so.. resilience/diversification.
Or, there's always the Northern European Enclosure Dam ( https://en.wikipedia.org/wiki/Northern_European_Enclosure_Dam ). That'll stop em getting to the cables! (while building a new much more serious sabotage problem - and I'm joking to be clear)
Standard practice in small organisations (well, at least the ones I overlook), so why not in a multi-$million company?
Because it generates a lot of work for customer service when dozy customers who've forgotten their password run into the block and get irate.
Another thing that needs to be (sensibly) legislated and normalised.
If user's credentials were guessed, from other breaches, then how would the company see any difference in the account activity?
If the attacker was careful enough this is the problem yes, and why MFA should be used (probably it should be legally mandated much more widely, then customers can still complain but it doesn't cost the company concerned lost business to rivals who don't mandate it).
But the attacker wasn't careful:
"on July 6, 2023, 23andMe’s engineering team became aware of a suspicious spike in user login attempts, during which time 23andMe’s access logs showed over five times the normal daily number of user log-ins, with a single actor making 1,300 login requests per minute from a single IP address. Although this is a classic red flag that a malicious actor may be attempting to infiltrate your system, 23andMe did not appropriately respond"
And if this bit is true they also could have had a very easy method for detecting and force-resetting large numbers of weak passwords well before the breach began:
"The majority of the 23andMe user credentials that the threat actor exploited to breach 23andMe’s systems were previously exposed nearly five years earlier during a highly publicized data breach of MyHeritage, one of 23andMe’s former partners"