Forgot your password?
typodupeerror

Comment Re: A buggy whip in every EV! (Score 1) 196

I loved Art Bell. He'd just tell the perpetual motion machine loons "you can't do that, it violates the laws of thermodynamics, show me or GTFO." George Noory, the last thing I remember about listening to his show, he had the head of some medical examiner's office on, and conducted a normal interview, and then at the end, "have you ever seen anything that looked like an attack by a vampire or werewolf?" You could hear the guest rolling her eyes, and she said "we... Don't see a lot of that."

Comment Re: Seems like a business opportunity (Score 2) 44

Quite. Invoking a self-destruct mode within sight of whatever cop wants the data is a Bad Idea. There's room to argue whether this is how it ought to be, but this is currently how it is. Don't wipe your phone after being asked to hand it over, unless you KNOW it contains data that will get you (or others you care about) in more trouble than a 'destruction of evidence' charge, or unless you want to make an expensive stand on principle. There are legitimate folks who live in that gray area: political dissidents under hostile regimes, some whistleblowers and journalists, abortion patients in societies where it's "health care" on one side of an arbitrary line and "murder" on the other, etc.

Might get away with it if the destruction doesn't follow from a specific action taken after access has been demanded, such as:
1) configuring a 'wipe after n bad passwords' setting
2) setting a duress-wipe code and writing it on a post-it, but not entering it, hoping the cops try it
3) setting a duress code/fingerprint that reboots but doesn't wipe -- that makes recovery much harder, but under the current framework, this might lead to a legal battle over whether crypto keys in RAM are "evidence" subject to "destruction."

I'd rather enjoy reading the court proceedings over any of those options, but I'd not enjoy it enough to be party to said proceedings.

GrapheneOS has an 'idle reboot' function like the iOS feature at issue here, and it's unknown whether there are any similar vulnerabilities in that. People should probably turn it on, it's more likely to protect than to harm.

I think probably the best advice is, for those worried about non-criminal personal data while traveling, take a travel phone and access your data over a VPN when it's safe. For criminals, maybe leave your phone home while doing crimes and don't store evidence on it.

Comment Re:Minimal hardware requirements. (Score 1) 100

Someone told me once that the hardware in there is this mediocre Android dev board with a little additional panopticon gear bolted onto it. So yeah, definitely in the "Free phones handed out in front of Walgreens" territory.

Not sure what would be the utility of running that sort of software on an individual endpoint machine, there's already much better malware intended to run on those. But it does point out the ease with which a sufficiently motivated actor can roll out an impressive surveillance grid with cheap (or was cheap before the AI bubble) off-the-shelf hardware.

Comment Re:Single key encryption? (Score 1) 100

Did we really expect more from the company that also left a lot of its devices searching for WiFi APs with predictable SSIDs and passwords, then offering an ADB port? Or, for those that weren't actively connectable, requiring pushing the exposed power button on the back with a stick to make them connectable?

Startup culture, move fast, break things -- preferably someone else's things.

Comment Re:These companies need to bring charges (Score 1) 125

Probably some of that, but it's also pretty hard to prosecute someone for a specific act absent evidence that they intended that act to occur. There's a whole family of "negligent X" crimes, but those tend to target specific outcomes ("that person is injured/dead because you were negligent"), and I don't think there are any negligent hacking statutes on the books.

Doing a hack manually is clearly prosecutable. Writing and invoking a script to do the same hack automatically is clearly prosecutable. Specifically directing an AI agent to perform an action that the person giving the command knows to be criminal is probably prosecutable under innocent-instrumentality doctrine. Telling the agent "get me a copy of the latest Toy Story" leading to the agent hacking Pixar and downloading pre-release video, less so.

I think the closest analogy in these cases would be either vicious-dog prosecutions ("you knew your dog was dangerous, you frequently brag in public about how vicious your dog is, you failed to contain it properly, it injured someone") or corporate-officer responsibility ("As CEO, you may not have issued the order to store the food in the rat-infested warehouse, but you had a duty to ensure that didn't happen, and you knowingly allowed it to happen.")

Certainly can't prosecute the model for hacking Acme when it was told to pen-test EvilCorp, and under current law, I don't think we can prosecute the creator or the person who gave the "Get me EvilCorp's R&D files by any means necessary" order for the actual hacking of Acme. And I think the vicarious-liability laws on the books are deliberately pretty narrow, to avoid them being used for all sorts of BS prosecutions. Might be able to get a vicious-dog conviction for sandboxing the known-dangerous agent by removing the default route and hoping it doesn't notice.

We'll probably need new laws for this. For now, if anything, it'll probably be civil litigation along the lines of negligent supervision -- given that the big AI companies are currently privately held, civil penalties might actually even hit almost the right people. Once they're public, it'll be pension funds and 401k's bearing the penalties for their corporate malfeasance, at least criminal law catches up with the concept of non-conscious agents that are capable of forming functional intentions, possessing "knowledge" of which targets are permitted and which not, and selecting actions against out-of-scope targets anyway.

Submission + - US Military Disables Ad Trackers on Devices to Protect Troops (reuters.com) 1

DeanonymizedCoward writes: Reuters reports that the US Military is disabling ad tracking on devices, to prevent adversaries from buying publicly-available tracking data to assist in targeting troops. Military officials say that they have disabled trackers on a variety of computers and mobile devices, according to letters released on Friday by Sen. Ron Wyden, and following reports that commercially-available tracking data has been used to target troops in the Middle East.

This effort comes amid attempts by the military to impose tighter restrictions on use of personal devices in the field, and after it was reported that videos posted publicly by troops abroad have also been used by adversaries to target military facilities.

Wyden said in a statement that it was clear that the military's efforts "have not been effective at neutralizing this threat." U.S. Representative Pat Harrigan, a North Carolina Republican, said that U.S. enemies "should not be able to pull out a credit card and buy information that helps them track American troops."

Rep. Harrigan remains silent as to the larger question of whether the general public should be able to pull out a credit card and buy information that helps them track anyone they please.

Comment Re: humble opinion (Score 1) 61

Probably some combination of "they don't want to clutter the UI with options and data most users don't care about" and "they don't want you to see the amount of system resources consumed by telemetry, advertising, 'on-device AI,' and other shit you didn't ask for."

That said, I don't really see this particular change as "pushing AI" on anyone -- just an evolution in the types of hardware and workloads commonly encountered, with a corresponding evolution in tooling.

Comment Re: Screw the jellyfish, tell me about the racoon! (Score 1) 27

Unfortunately for the Raccoon Mafia's XP score, it looks like this is a relatively small town utility counting individual customers as separate outages.

I had seven power outages in my living room the other day when I tried to run the air conditioner and the iron at the same time.

Comment Re: Retention Periods? (Score 1) 33

We're sorry, but we are unable to answer any questions about the searches you asked about. All data and metadata pertaining to those searches has been deleted in keeping with our terms of service, and now exists only in hardcopy form in Officer Manley's stalker binder. We wish we could be more helpful.

Comment Re:They will just take over the state governments (Score 1) 132

And then override the locals. Every time they want to do something people don't want that's how they do it. They have a name for it they call it government small enough to drown in a bathtub.

They're reportedly already doing that. The 404 Podcast recently interviewed an ex-Flock employee, who said that some municipal PD had completely bypassed the normal city-council funds approval process and signed the city up for a Flock contract using forfeiture funds.

Guillotines for everyone involved, and laws that all forfeiture funds go directly into a public ledger with absolute transparency on what they're used for. Or just get rid of civil forfeiture as an adjunct to criminal prosecution entirely.

Slashdot Top Deals

Remember, UNIX spelled backwards is XINU. -- Mt.

Working...