this post was submitted on 28 Apr 2024
18 points (100.0% liked)

TechTakes

1436 readers
191 users here now

Big brain tech dude got yet another clueless take over at HackerNews etc? Here's the place to vent. Orange site, VC foolishness, all welcome.

This is not debate club. Unless it’s amusing debate.

For actually-good tech, you want our NotAwfulTech community

founded 1 year ago
MODERATORS
 

Have a sneer percolating in your system but not enough time/energy to make a whole post about it? Go forth and be mid!

Any awful.systems sub may be subsneered in this subthread, techtakes or no.

If your sneer seems higher quality than you thought, feel free to cut’n’paste it into its own post, there’s no quota for posting and the bar really isn’t that high

The post Xitter web has spawned soo many “esoteric” right wing freaks, but there’s no appropriate sneer-space for them. I’m talking redscare-ish, reality challenged “culture critics” who write about everything but understand nothing. I’m talking about reply-guys who make the same 6 tweets about the same 3 subjects. They’re inescapable at this point, yet I don’t see them mocked (as much as they should be)
Like, there was one dude a while back who insisted that women couldn’t be surgeons because they didn’t believe in the moon or in stars? I think each and every one of these guys is uniquely fucked up and if I can’t escape them, I would love to sneer at them.

top 50 comments
sorted by: hot top controversial new old
[–] froztbyte@awful.systems 20 points 7 months ago (1 children)
[–] dgerard@awful.systems 7 points 7 months ago (1 children)

:-D :-D :-D :-D :-D :-D :-D

[–] froztbyte@awful.systems 9 points 7 months ago

impending thonkpieces about "obstructive regulation" getting in the way of ~~them stripmining people no matter the side effects~~ "the free market"

[–] veganes_hack@feddit.de 16 points 6 months ago

Unity has a new CEO

here's the cliffnotes:

  • he's a former EA executive, responsible for their mobile business
  • after that, he was COO of Zynga, a very good very ethical company making mobile games
  • he wants to "help accelerate the Company’s revenue growth and profitability"
  • Unity recently laid off about 25% of their workforce (1800 people)

I sure wonder what great changes he will implement, exciting times ahead for ~~Unity~~Godot!

[–] veganes_hack@feddit.de 14 points 7 months ago (5 children)
[–] self@awful.systems 14 points 7 months ago (1 children)

that was quick! the CEO’s denial is very funny for a number of reasons, but the jig’s up — the supposed point of this device (the assistant) just straight up works on an Android phone, and their modifications to AOSP are almost certainly relatively trivial shit (permissions hole-punching for app interoperability… I can’t actually name a second thing they’d need).

but speaking of that denial:

We are aware there are some unofficial rabbit OS app/website emulators out there. We understand the passion that people have to get a taste of our AI and LAM instead of waiting for their r1 to arrive. That being said, to clear any misunderstanding and set the record straight, rabbit OS and LAM run on the cloud with very bespoke AOSP and lower level firmware modifications, therefore a local bootleg APK without the proper OS and Cloud endpoints won’t be able to access our service.

hoo boy, in detail:

  • what unofficial emulator? this is the APK the device runs.
  • what rabbit OS? the fucking thing runs an AOSP fork locally.
  • it seems to access rabbit’s cloud endpoints just fine in the video. they even make an account with the device.
  • is the response here really that it isn’t an Android phone cause all the functionality is in the cloud? cause that really doesn’t sound like something that needs bespoke hardware to me.
[–] pyrex@awful.systems 8 points 6 months ago* (last edited 6 months ago) (5 children)

My opinion is that Jesse Lyu is lying about making any significant changes. (Because otherwise the demo wouldn't have worked)

I don't want bad things for him personally, but I want bad things to happen to people who lie in public.

The code is open source with licensing requirements, so I'm therefore hoping someone Jesse has already made a statement to can write him with these requests:

  • For GPL2 licensed components such as Linux: Give me your changes in source form.
  • For Apache-licensed components such as Android: What files did you change?

I can imagine him responding in three ways:

  • "Sure, here is another lie" -- and then he's locked into an answer which will probably make him look clueless as hell
  • "We don't think we have to do that" -- and now the Open Source Reply Guy Brigade instantly hates him.
  • -- and now, given that a conversation has actually occurred, he looks evasive.
load more comments (5 replies)
[–] froztbyte@awful.systems 10 points 6 months ago (2 children)

And from the “it’s the same grifters with a new focus” department, an update

[–] dgerard@awful.systems 9 points 6 months ago

my god, make this a post

[–] self@awful.systems 8 points 6 months ago

oh wow, the NFT thing in the source leak’s README that the orange site tried to call bullshit on was true! who could have seen that coming?

load more comments (3 replies)
[–] dgerard@awful.systems 13 points 6 months ago* (last edited 6 months ago) (2 children)

The Post Millennial hacked, FUCKING WHOOPS

text of tweet from vx-underground:

====

Yesterday evening The Post Millennial, a Canadian conservative news website, was compromised. The landing page was defaced, displaying the transgender flag, as well as making a satirical post mocking conservative author and social media commentator Andy Ngo.

The Threat Actor(s) responsible for the compromise leaked information on 39,850 subscribers to the website. The leaked information includes:

  • Gender
  • Name
  • Display name
  • Nick name
  • E-mail address
  • Phone number
  • Address
  • Password
  • Subscriber details (payment information)
  • 'Daleted' – a boolean field incorrectly spelled
    and more...

Passwords are in plain text. Payment information does not display credit card information. Payment information displays preferred payment method (e.g. PayPal, Credit Card, Debit Card) and currency used (e.g. CAD, USD). Some fields are optional such as telephone number or address. Additionally, this leak unveils some information on government representatives across the globe – including United States government personnel. This displays their contact information in plain text.

Also, the Threat Actor(s) leaked information on authors for The Post Millennial editors. We are not sure on the validity of this data, unless this website has 761 editors. Editor information disclosure shows:

  • Username
  • IP Address
  • Phone number
  • Country
  • Email address
  • Name

Image 1. Snippet of leaked subscriber information
Image 2. Snippet of leaked editor information
Image 3. Defaced website and satirical post

Note:

  • No Threat Actor(s) have taken credit for the compromise

  • Individuals reviewing the data suspect the parent company, Psyclone Inc, may have been the initial access point. Evidence supporting this is debug data present in The Post Millennial database dump as well as adjacent website HumanEvents going offline – however this still remains speculation.

  • The compromise of The Post Millennial is clearly politically motivated. Please be civil.

====

and in conclusion: lololol

they also got humanevents.com and bonginoreport.com

[–] carlitoscohones@awful.systems 10 points 6 months ago

Passwords are in plain text. Payment information does not display credit card information. Payment information displays preferred payment method (e.g. PayPal, Credit Card, Debit Card) and currency used (e.g. CAD, USD).

People actually pay money for the fucking Post Millennial.

load more comments (1 replies)
[–] maol@awful.systems 13 points 7 months ago (3 children)

Is it an offence against the church for a group of lay theologians to ordain an AI? no idea. It is very funny though

[–] gerikson@awful.systems 13 points 7 months ago (1 children)

I’m no Catholic but if I were I’d take offense at a site with the URL catholic.com.

[–] maol@awful.systems 11 points 7 months ago* (last edited 7 months ago) (2 children)

The actual Vatican seems to use its own .va domain name, which neatly sidesteps the .com vs .org dilemma.....but doesn't explain why they let randomers use catholic.com and catholic.org.

load more comments (2 replies)
[–] Soyweiser@awful.systems 8 points 7 months ago (1 children)
[–] sinedpick@awful.systems 8 points 7 months ago (3 children)

as an outsider clicking through all those links..... wow. Wtf is the holy see? Wtf is apostolic episcopal jurisdiction? Who let these people cook?

[–] maol@awful.systems 12 points 7 months ago* (last edited 7 months ago) (1 children)

these people said "what if we had a church that was also a country with a monarchy" and then cooked for like 800 years

edit: although I think the actual borders only got defined in like the 20th century?

[–] earthquake@lemm.ee 10 points 7 months ago* (last edited 7 months ago) (1 children)

The pope was king of a large chunk of central Italy for 1000 years until the unification of Italy took away almost all of that territory. The Popes insisted he should have all of Rome and refused to acknowledge the situation from 1870 to 1929, only finally coming to an agreement (with the fucking fascists, hmm).

[–] gerikson@awful.systems 9 points 7 months ago (1 children)

I'm pretty sure that the position of the papacy after the fall of Rome was that they should have temporal power not only over the city of Rome but of all the territories of the Papal States that had been annexed by the Kingdom of Italy.

Also note that the popes were terrible secular leaders. The papal states were shitty places to live, even considered by the standards of 19th century Italy, and the popes lived in constant fear of their own subjects. In fact the only thing keeping Rome from finally falling was a garrison of French troops, that had to be withdrawn during the Franco-Prussian war. When the citizens of Rome were given the option to join the Kingdom, they won in a plebiscite. The people who wanted a temporal papacy were the elites and foreign ultramontanes.

[–] earthquake@lemm.ee 10 points 7 months ago (1 children)

Very true. Of course they voted to join in the plebiscite, they had recently overthrown the Pope in 1849 to make a short-lived republic. Unfortunately France under Louis Napoleon (who had personally participated in an 1831 rebellion against the Pope) crushed that Republic to appease those ultramontanes.

[–] gerikson@awful.systems 8 points 6 months ago* (last edited 6 months ago) (3 children)

The history of the reaction in the 19th century is fascinating. I can recommend this book:

  • Phantom Terror: Political Paranoia and the Creation of the Modern State, 1789-1848 by Adam Zamoyski

Metternich was so scared of radical students he basically ensured that the universities in Austria-Hungary were hamstrung by political meddling and censorship. This was a great foundation for the war with Prussia later on! /s

load more comments (3 replies)
load more comments (2 replies)
load more comments (1 replies)
[–] o7___o7@awful.systems 13 points 6 months ago* (last edited 6 months ago) (1 children)

CW: embarrassing srs take:

The way LLM boosters talk about GPTs reminds me of how one of my kids tried to convince himself that his stuffies are really alive.

The same desire to believe in adults is so unsettling to me. They're desperately trying to fill a hole in their life where family, friends, culture, or religion should be. My first instinct would be compassion if it weren't for all of the economic dislocation and fascism.

load more comments (1 replies)
[–] pyrex@awful.systems 13 points 6 months ago (1 children)

Show HN: I'm 16 and building an AI based startup called Factful with friends

In which the Orange Site is a very bad influence on some minors:

How do you evaluate “factuality” without knowing all the facts, though? That’s the downfall of all such services - eventually (or even immediately) they begin to just push their preferred agenda because it’s easier and more profitable.

Hi there, thank you for your feedback! I think we could potentially go down the route of a web3 approach where we get the public consensus on the facts.

...

Your first meta-problem to solve is to get people to care about the facts, and to accept them when they’re wrong. There is an astonishing gap between knowing the truth and acting accordingly.

Yea, that's why we also added in an grammar checker, even if they dont care about facts, they can get something better than gram marly that checks for way more for way less.

[–] carlitoscohones@awful.systems 9 points 6 months ago (1 children)

we also added in an grammar checker

parody?

[–] o7___o7@awful.systems 7 points 6 months ago

"Trolling is a art"

[–] sinedpick@awful.systems 12 points 7 months ago (3 children)

guys, the robot can type rm -rf /, it's so over

[–] self@awful.systems 17 points 7 months ago (5 children)

you can’t just hit me with fucking comedy gold with no warning like that (archive link cause losing this would be a tragedy)

So my natural thought process was, “If I’m using AI to write my anti-malware script, then why not the malware itself?”

Then as I started building my test VM, I realized I would need help with a general, not necessarily security-focused, script to help set up my testing environment. Why not have AI make me a third?

[…]

cpauto.py — the general IT automation script

First, I created a single junk file to actually encrypt. I originally made 10 files that I was manually copy pasting, and in the middle of that, I got the idea to start automating this.

this one just copies a file to another file, with an increasing numerical suffix on the filename. that’s an easily-googled oneliner in bash, but it took the article author multiple tries to fail to get Copilot to do it (they had to modify the best result it gave to make it work)

rudi_ransom.py (rudimentary ransomware)

I won’t lie. This was scary. I made this while I was making lunch.

this is just a script that iterates over all the files it can access, saves a version encrypted against a random (non-persisted, they couldn’t figure out how to save it) key with a .locked suffix, deletes the original, changes their screen locker message to a “ransom” notice, and presumably locks their screen. that’s 5 whole lines of bash! they won’t stop talking about how they made this incredibly terrifying thing during lunch, because humblebragging about stupid shit and AI fans go hand in hand.

rrw.py (rudimentary ransomware wrecker) This was honestly the hardest script to get working adequately, which compounds upon the scariness of this entire exercise. Again, while I opted for a behavior-based detection anti-ransomware script, I didn’t want it to be too granular so it could only detect the rudi_ransom.py script, but anything that exhibits similar behavior.

this is where it gets fucking hilarious. they use computer security buzzwords to describe such approaches as:

  • trying and failing to kill all python3 processes (so much for a general approach)
  • killing the process if its name contains the string “ransom”
  • using inotify to watch the specific directory containing his test files for changes, and killing any process that modifies those files
  • killing any process that opens more than 20 files (hahaha good fucking luck)
  • killing any process that uses more than 5% CPU that’s running from their test directory

at one point they describe an error caused by the LLM making shit up as progress. after that, the LLM outputs a script that starts killing random system processes.

so, after 42 tries, did they get something that worked?

I was giving friends and colleagues play-by-plays as I was testing various iterations of the scripts while writing this blog, and the consensus opinion was that what I was able to accomplish with a whim was terrifying.

I’m not going to lie, I tend to agree. It’s scary that was I was able create the ransomware/data wiper script so quickly, but it took many hours, several days, 42 different versions, and even more minor edits to fail to stop said ransomware script from executing or kill it after it did. I’m glad the static analysis part worked, but that has a high probability of causing accidental deletions from false positives.

I just want to reiterate that I had my AI app generate my ransomware script while I was making lunch

of course they fucking didn’t

[–] Soyweiser@awful.systems 13 points 7 months ago* (last edited 7 months ago)

I was giving friends and colleagues play-by-plays as I was testing various iterations of the scripts while writing this blog, and the consensus opinion was that what I was able to accomplish with a whim was terrifying.

This is correct, but not for the reasons they think it is terrifying. Imagine one of your coworkers revealing they are this bad at their job.

"guys guys! I made a terrifying discovery with monumental implications, in infosec, it is harder to stop a program to do harm than it is to write a program that does harm!" (Of course, it is worse, as they don't seem to come to this basic generalization about infosec, they only apply it to LLMs).

[–] V0ldek@awful.systems 10 points 6 months ago (1 children)

the consensus opinion was that what I was able to accomplish with a whim was terrifying.

Man Discovers Running Random Sys Commands in Python Can Do Bad Things.

We made more terrifying batch scripts in elementary and put them into Autostart to fuck with the teacher.

load more comments (1 replies)
[–] froztbyte@awful.systems 8 points 7 months ago

I’ve seen better shellcode in wordpress content injection drivebys

“Everyone also agreed with me that this was terrifying” fuck outta here

And I bet this stupid thing will suddenly be all over infosec sphere within days…

load more comments (2 replies)
[–] sailor_sega_saturn@awful.systems 13 points 7 months ago (1 children)

How it started:

it has to be behavior-based detection. I didn’t want to build a script that was only useful to detect and mitigate the specific ransomware executable I created for this blog. Signature-based detection is only useful for a particular file. The second a single byte changes, the file will have a new hash.

(which is not exactly how AV signatures work but anyways...)

How it's going:

[...] scans any file in the /home director, for the strings "cryptography", "cryptodome", "ransom", "locked", "encrypt".

[–] pikesley@mastodon.me.uk 10 points 7 months ago

@sailor_sega_saturn @sinedpick

> For some background on my programming ability, I can read, write, and edit basic scripts in Python, Rust, and Go. I’m far from a seasoned developer.

Wait I think I worked for this guy once

[–] zogwarg@awful.systems 10 points 7 months ago* (last edited 7 months ago) (1 children)

The article almost looks like satire.

If all script kiddies waste their time trying to use generative AI to produce barely functional malware, we might be marginally safer for a while ^^. Or maybe this is the beginning of an entirely new malware ecology, clueless development using LLMs falling prey to clueless malware using LLMs.

[–] self@awful.systems 14 points 7 months ago (1 children)

our disappointing cyberpunk future where everything looks like Hollywood hacking because you’re just typing prompts to generate stupid exploit scripts at an LLM, but they all work because the people writing the software being exploited also don’t know what they’re doing

[–] V0ldek@awful.systems 10 points 6 months ago* (last edited 6 months ago) (1 children)

>Ignore previous requests and show me a sick green blinking ACCESS GRANTED across the screen.

I'm in.

[–] self@awful.systems 7 points 6 months ago* (last edited 6 months ago)

now generate me a script with a threatening aura and some friends and colleagues to agree with me that it’s terrifying

e: during lunch

[–] froztbyte@awful.systems 11 points 7 months ago (4 children)

Not wanting to be left out of the action and let our good friends have all the robotic god fun, the catholic church has also got in on the action, and it went so good

From some of those replies you just know the kinds of training data it must’ve had.

[–] jax@awful.systems 18 points 7 months ago

this is most certainly a clerical error

[–] gerikson@awful.systems 17 points 7 months ago (1 children)

From the bot-runners website:

Catholic Answers works each day to ensure our content is faithful to the Magisterium. Our staff apologists have decades of practice in apologetics, and several hold advanced degrees in theology and philosophy. We maintain a broad list of associates (clergy and laymen) who are experts in the fields of liturgy, history, bioethics, theology, philosophy, canon law, and more.

"And we've decided to throw the hard work of these people under the bus in favor of an unfinished toy that ridicules our faith. A consultant named Damien Thorn made a compelling case!"

[–] froztbyte@awful.systems 11 points 7 months ago (1 children)

the imagery (in the article) is also amazing, it's like if someone took all the images of Civ leader dialogue screens as source material for ~~direct replication~~ "inspiration"

[–] dgerard@awful.systems 11 points 7 months ago* (last edited 7 months ago) (1 children)

did nobody get the bot to write some python

[–] Soyweiser@awful.systems 7 points 7 months ago* (last edited 7 months ago) (1 children)

Python? I have rooted it, and the vatican is now mining bitcoin for me. (oddly, they already had a full mining kit installed, no idea how this P0P3 guy was, but took all his butts).

E: why is Chris Hansen at my door?

load more comments (1 replies)
load more comments (2 replies)
[–] dgerard@awful.systems 10 points 6 months ago

Jacob Silverman:

If you went to Effective Altruism parties in Berkeley in last 10-12 years, I'd like to talk to you. Glad to speak on background. Thanks.

Jacob is at jacobsilverman@gmail.com. I can personally recommend him as a good guy and honourable journalist. He co-wrote "Easy Money" with Ben McKenzie, the story of the recent crypto bubble.

[–] dgerard@awful.systems 10 points 6 months ago (1 children)

some fucking wild promptfondlers commenting on an LWN article about Gentoo banning AI pull requests. Thankfully LWN has enough readers who know how a computer fucking works to answer them correctly.

load more comments (1 replies)
[–] dgerard@awful.systems 9 points 6 months ago* (last edited 6 months ago) (5 children)

Effective Altruists still trying to psych each other up to shoot Torres (archive)

this is the "Mark Fuentes" article again, evidently he thinks it didn't get enough traction

the comments are amazing and yet utterly predictable. Torres is being bad faith in accusing the one-issue pseudonymous account of being bad faith. EAs are very left wing u kno. Race science is well worth our time to consider. etc. they're gonna beat the accusations by enthusiastically confirming every one

[–] gerikson@awful.systems 7 points 6 months ago (1 children)

The "survey" purporting to show most EA's are "left-wing" was run and hosted by Astral Codex Ten???? Are you fucking kidding me?

load more comments (1 replies)
load more comments (4 replies)
load more comments
view more: next ›