Forgot your password?
typodupeerror

Comment Re:Correct. And oh, no. (Score 1) 47

Yeah, "very". They're going to make it like sudo where when you give permission to a program to write protected files once it has it forever after.

No, wait, that isn't how it works, is it?

That's how it already works. But you can request the permission from the user with a pop-up. Presumably a "very explicit action" means going into the Settings app and turning it on by hand.

But that's going to do exactly nothing. The app will tell them that they have to do this, and the users, having no idea how dangerous it is to give an AI unrestricted access to their device, will do it anyway, and we'll be right back to where we are now. And the next step will be "See, we can't allow full disk access." And then macOS will cease to be usable.

The only reasonable choice is to flag Meta's software as malware for extending their full disk access to agents. Force them to implement a proper sandbox. Apple already gives them all the tools they need to do it right.

  • The main host app asks for full disk access, but functions without it, triggering an open file dialog to work around missing access when necessary. Most users will end up granting full disk access out of frustration, but that's okay because the agents themselves don't have that access. If possible, make it start out with a read-only full-disk entitlement, because otherwise, using it will be much harder.
  • Each agent runs in a separate agent runner process with a stricter sandbox.
  • The agent sandbox has an entitlement that grants read-only access to the entire disk (or, if the main host app's sandbox doesn't allow that, to every resource that the main host app has access to), and bans the use of the socket() system call.
  • AI agents can request read-write access to specific files or directories by asking the host app. The agent is encouraged to ask for access to an entire directory at once if it needs to write to multiple files in that directory.
  • The host app can pass in a security-scoped bookmark/URL to grant permission, but asks the user first unless the URL is part of an explicit list of allowlisted URLs that the user provided before beginning the task. Doing this expands the sandbox to allow writing to that file or to files in that directory. The SSB can be created programmatically or, if the main app also doesn't have access, through showing an Open File dialog.
  • One tool provides network access to specific hosts with no POST, all GET parameters filtered, and a low limit on URL length to mitigate exfiltration risk. This tool has an entitlement that allow socket access inside an environment where opening sockets is otherwise banned, and thus can be run directly by AI agents.
  • One tool provides broader network access with full upload capabilities. This tool lives outside the sandbox so that the AI agents cannot run it themselves — only ask the main host app to run it for them. Then:
    • The main host app requires the user to give permission to access a single hostname for either a single request (allow once) or a single task (always allow for this task).
    • If the user clicks the "Always allow sending data to example.com" button, the user is asked "Trust example.com for similar request parameters only" or "Trust fully".
    • If the user choose to trust similar request parameters only, then any additional GET parameters must be explicitly allowed each time.
  • The main host app passes each AI agent runner a new open socket connected to the AI service's server.
  • The AI service's server is configured to provide minimal or no network access from the server side.

This is how you protect privacy in an agentic environment.

Comment Re:Correct. And oh, no. (Score 1) 47

I hereby retract everything I just said. The entire post was based on a misunderstanding caused by Slashdot's editors adding a single extra letter.

  • Original: "very explicit user action."
  • Slashdot: "every explicit user action."

What a difference an 'e' makes. I was imagining every single file access causing a UAC dialog.

Yikes.

Well, no, I don't retract the last paragraph. They should still kick Meta's garbage agent off the platform until Meta can get security right.

Comment Re:Correct. And oh, no. (Score 3, Funny) 47

This looks like the final cell-phonification of the Mac. I'm bummed.

How do you figure that? From the Apple post: "Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. "

The word was *every*. *Every* explicit user action.

Oh, bloody hell. I just got rage-baited by incompetent Slashdot editors.

Good night. I'm done for the day.

Comment Re:Correct. And oh, no. (Score 1) 47

This looks like the final cell-phonification of the Mac. I'm bummed.

If this happens, this thirty-year Mac user will be leaving the platform. Full stop. So will just about everyone else within months to single-digit years.

This approach didn't work with Gatekeeper in Mac OS 7. It didn't work for Windows XP. It won't work for modern Mac OS, either. Here's why: CONSTANT PROMPTING MAKES SECURITY WORSE.

Prompting users over and over again to allow or deny actions makes security WORSE. Period. It means that users are constantly being nagged, and constantly having to decide whether an action is harmful or not. This rapidly (over the course of just minutes) turns into query burnout, and the user just clicks "Allow" for everything. And not only does it fail to meet its objective, but it also causes them to the same for every other dialog, including all of the other things Apple put in place to improve privacy and security. And now people are granting every app whatever access it asks for automatically without question, and every advantage that Apple has security-wise and privacy-wise evaporates instantaneously.

Continuous prompting NEVER makes security better. It ONLY makes security worse.

AND this would have a hopelessly deleterious effect on EVERYTHING that high-end users do, from running commands in Terminal (which would become completely unusable) to third-party backups, etc.

And that latter one would also be a major antitrust problem for Apple, which is to say that if they do this, they WILL get sued, and they WILL lose, because it is so clearly open-and-shut that this is not the correct solution for the problem, but that Apple stands to greatly benefit while their competitors are irreparably harmed.

What's described here would completely break the platform at a level that makes it a toy, no more useful than iOS, and completely unreasonable to use for any serious professional work, whether as a software engineer or a graphic designer. And it is pathetically absurd that they think this is a good idea. It makes me assume that none of the Apple security engineers I know are still around, because all of them would have flat out called you a moron for even suggesting something like this. They actually understood security at a more-than-superficial level. Someone proposing this "solution" clearly does not.

You can't fix sh**ty apps by making the platform objectively worse or making things that people legitimately need to do as painful as possible. The only way to fix sh**ty apps is by banning them from the App Store and flagging direct downloads as malware repeatedly until such time as they get their security model right. There are correct ways to sandbox things like agentic frameworks. This is about as far from the right way as you can get, as it does nothing to improve the security of the agentic setup, while catastrophically breaking overall platform usability and turning users into mindless "Allow" clickers.

Find another way. Kick Meta's horrific agentic tool off the platform until they can get security right.

Comment Re:Groundwork for censorship (Score 1) 99

Moderation is censorship by definition.

False.

Censorship means suppression of speech or expression by a governing authority. It can be prior restraint (blocking publication) or censorship after the fact (take-downs, bans, etc.).

In the strictest sense, you could maybe argue that soft moderation in the Slashdot style where people who want to see what has been moderated down doesn't qualify as censorship because there's a way around it, but the net impact is still that most of the potential audience doesn't see it, so that argument is on somewhat shaky ground.

At best, you can argue that moderation is not prior restraint censorship, but while prior restraint makes censorship way more likely to be a first amendment issue if the government is involved, it's not a requirement for something being censorship.

Comment Re:Pretty obvious (Score 0) 99

I don't know if the caption is true or not. But it sure convinced a lot of people. So how do you solve this problem?

You slow the initial spread of posts for long enough to throw AI at the problem and analyze the factual accuracy of every post, or at least every post that any user flags as misinformation or factually incorrect.

For posts that are obvious satire (e.g. from known satire sites, etc.), flag them with a clear "This post is satire" warning at the beginning of the post.

For posts that are just flat-out lies, mass cancel the post automatically:

  1. Prevent it from appearing in anyone else's feed or spreading.
  2. Fan out the ban scan to recognize similar posts from people who saw the original post, recursively cancel those.
  3. Backtrack to see if any posts that the original poster might have seen posted similar information from which the false post was derived, and recursively cancel those, including fan-out and backtracking from there, etc. until you have a complete graph of every post that appears to be derived from the lie.
  4. Bulk distribute a post to everyone who saw the original post, explaining what was untruthful and why the bot believes that it was untruthful, providing factual citations to refute the original post. You do this in bulk to everyone who saw the original post all at once, not through organic spread, making it faster to refute a lie than to spread it originally.

In your fact checking ban post, you make it possible for anyone who believes that the cancellation was unjustified to submit external citations as evidence of its accuracy. After 72 hours, all citations submitted by anyone who saw the fact checking ban post are deduplicated, consolidated, and sent to a hundred human reviewers. These reviewers vote to either: A. reinstate the original post, B. reinstate the original post with clarification at the beginning (this post is mostly correct except XXX, this post is satire and is not intended to be taken as truth, this post is an opinion piece that disagrees with broadly held scientific consensus and the evidence presented herein should be treated with skepticism unless proven correct by larger/stronger/more robust studies, etc.), or C. uphold the ban.

If a post is reinstated, every post flagged as a consequence of the original flagging is also reinstated in a similar fashion, with clarification if applicable.

In other words, make it easy for users to report that something is a lie, make the resulting fact checking be aggressive at immediately halting the spread of things that are clearly untruthful, and make corrections spread faster than the lies did originally.

The last critical piece is the ability for an individual user to choose whether to see posts that have been flagged as being lies. If they choose to repost something that is already flagged, it will be seen only by other people who have chosen to opt out of hiding factually erroneous posts, so the spread will be mostly limited to those who have already bought into one or more conspiracy theories, but that's still moderation rather than outright banning of the content. And people would be free to write new posts that point out that a post on a subject has been banned and telling people why they think it should not be banned. Of course, in most cases, that will paint the person as a nutter, but at least you'll know. :-)

Unfortunately, at some point, in the U.S., certain political groups decided that things that are contrary to established facts are "opinions" that cannot be questioned, rather than lies, so demanding factual accuracy will be seen by many as political bias, which is why this will probably never happen.

Comment Re:Different usage? (Score 1) 99

Maybe people shouldn't believe everything they see online, and learn how to research the candidate/incumbent themselves.

Any time I get a political ad, I read at least 3 sites (as diverse as possible) and average the overall "facts" that the sites say. Maybe candidates could switch from only bad-mouthing other candidates to the candidate just saying what they're campaigning on.

Any time I get a political ad, I assume that their position is questionable enough to require spamming me with ads, and therefore that I should probably do the opposite of what they're advertising.

Comment Re:Groundwork for censorship (Score 4, Insightful) 99

Censorship is bad. There are ways to moderate trolls, spam, and misinformation that don't involve censorship. We've seen that censorship serves to promote conspiracy theories (because it actually is a conspiracy.)

Moderation is censorship by definition. So no, there cannot be ways to moderate those things without censorship.

What you mean is that governments requiring companies to censor things is bad. And in general, I agree.

Corporate-driven censorship is also generally bad, where corporations censor things to protect their interests or boost their revenue without a legitimate public interest in mind.

The real problem is that social media does not give the public control over what they consume, and subjects us to increasingly low-quality garbage from increasingly distant voices in a desperate attempt to drive interaction in spite of a declining user base. And that effectively becomes corporate censorship, as the garbage drowns out the organic content from our friends that we actually went to the site to see. Yet it is by design. Sites like Facebook appear to completely ignore our "I don't want to see this" signals and continue to shovel this garbage. As a result, I go to Facebook an order of magnitude less often than I did ten years ago, but at the same time, I know that other people find the algorithmically driven shovelware to be compelling, and they're the ones being manipulated by this stuff.

With that said, I don't want government censorship. I want government to require social media to give control to users, to publicly disclose how their algorithms shape what users see, to allow independent audits to ensure that their algorithms are working for the public good rather than just for the corporate good, etc. We need more access to information, not less, but we also need to be able to filter what we see. Because if news media, etc. is not serving as a filter to show us the most important information and filter out unverified information and clear misinformation, then we need tools to help us moderate what we see, and maybe by sending those signals, also influence what our friends see and reduce the garbage a bit.

Comment Re:Is this true? (Score 3, Interesting) 99

The propagandists say that their competitors confuse people and they won't believe the propaganda anymore.

The Horror, the Horror.

The problem is that there are propagandists in the first place. Here's the way I see it:

  • Early 1980s: The 24-hour news cycle made people demand immediate access to news.
  • Mid-1980s through today: Low pay, media consolidation, newspaper closures, and mass layoffs made journalism an increasingly unattractive career, causing most of the best and brightest to leave the field or not enter it, resulting in a gradual decline in the news media's ability to lead interviews, call politicians on outright lies, etc.
  • 1987: Fairness doctrine eliminated, allowing the rise of biased talking head infotainment shows.
  • 1996: Fox News started broadcasting with the explicit intent to create a right-biased news source.
  • 2003: MSNBC took a leftward shift to counter Fox News.
  • 2009: Social media reached peak users, where gaining more eyes was impractical, so the only way to increase ad revenue was to increase screen time or increase ad count or both, and increasing ad count would reduce screen time in the absence of a mitigating factor, so sites began shifting from most recent posts from your friends to most clicked/viewed, resulting in the rise of clickbait.
  • 2013: The Russian government formed the Internet Research Agency, a.k.a. Glavset, a Russian company tasked with online propaganda, including disinformation and trolling campaigns on social media.
  • 2016 through 2022 or so: Social media began showing more and more content from people who are not your friends or friends of friends and groups that you have never joined in a desperate attempt to get more screen time out of a plateauing (and later declining) daily active user base.
  • 2022: A far-right-wing propagandist buys Twitter.
  • 2023: Glavset shut down, though it is generally assumed that other groups took up its mission.

The social media dates are based on Facebook. Other social media behaved similarly at around the same time, plus or minus a couple of years.

But ultimately, it's all about companies focusing on profit above all else, without the slightest bit of concern over the negative impact of their choices. And as long as social media companies — and media and news sources in general — are predominantly for-profit entities instead of nonprofit corporations, they will be at best marginally harmful to society, and at worst, massively so. The profit gained from using hype and propaganda and clickbait and massive amounts of slant to drive viewers/readers is simply too strong a motivation to overcome as long as the focus of an organization is making profit, rather than breaking even.

And yeah, social media is part of the problem, but the mainstream media abdicated their responsibility to inform the public at least a decade earlier, and arguably three decades earlier, creating the information vacuum that social media filled. And the fact that it's a lot harder to refute a lie than to publish the truth in the first place made social media's increasingly extreme amplification of troll campaigns incredibly harmful, but the public's tendency to repost whatever garbage they see and the ease with which people can repost things they see to broader and broader audience made that problem much, much worse.

So yes, traditional social media is a large net harm to the public as a whole. Instead of helping bring us together, it has largely driven us apart. We would be much better off if Facebook groups ceased to exist and became separate discussion forums like we had before. We would be much better off if public Facebook posts were banned going forward, requiring people to actually copy and paste before sharing other people's posts beyond the friends or followers of the original person, or at most, one hop away. We would be much better off if sites like Facebook were forced to allow us to disable algorithmic spam in our feeds, including all posts suggested from people that our friends follow, groups distantly related to groups that we're in, etc. And so on.

Comment You're mis-identifying the problem (Score 5, Informative) 75

The federal government has always (for at least several decades) used the threat of removing federal funding to force states to do things that they don't want to do. This is nothing new, and is not, as this summary implies, setting a dangerous precedent.

The difference is that normally, this is used to do things that add standards intended to make things better/safer for the general public or serve some legitimate public need.

This is being done to remove standards intended to protect the general public. As a general rule, states have always been allowed to have stricter laws than the federal government, just not more lax laws. Using the threat of removing federal funding to take away laws intended to protect the public's rights, reduce competition among content providers, and push the Internet more and more towards a content monopoly is doing the opposite of that.

It's not the federal government using the threat of withdrawing funding to push its agenda that is bad. It is the agenda itself that is bad. It is fundamentally antithetical to the rule of law, fundamentally contrary to the regulatory powers required to maintain a functioning capitalist system, and fundamentally contrary to the public interest. It is putting greedy corporations ahead of the American people.

Additionally, the executive branch taking such an action without authorization from Congress is also bad. The long history of doing this has, to my knowledge, been limited to the executive branch acting on laws passed by Congress that give them the authority to withhold funds for specific non-compliance reasons. Doing so in the absence of such laws is likely a violation of the separation of powers.

But unfortunately, the current administration has a long history of violating that separation of powers, doing various illegal acts, knowing full well that it will take months for the courts to strike down those acts, and that the damage will have been done by then, and using the threat of such illegal executive orders as a way to extort concessions out of states, government agencies, corporations, nonprofits, and individuals. And that right there — the repeated willful commission of unconstitutional acts for borderline felonious purposes — is a fundamental abrogation of their oath of office.

So the way I see it, there are only three ways to fix the problem:

A. Pass laws clarifying that Congress has exclusive power of the purse, and that the executive branch shall not retract funding to any state, any agency, or any individual for any reason unless the right to retract funding for that specific reason is explicitly codified in the relevant law as an executive power, and that this rule shall apply to all government agencies, without exception, superseding all previously assumed authority, and providing criminal liability for anyone acting in contravention of this law, with no statute of limitations. That way, federal agency heads who act on such executive orders will no longer be protected by any assumption of legality or constitutionality, and will risk future criminal charges if they act on an executive order that violates the separation of powers in this way.

B. Remove the people who are pushing this agenda, whether through the ballot box, through impeachment, or both.

C. Do both A and B.

Comment Re:Loss of pulse detection? (Score 1) 22

Let me know when all this heart rate monitoring can do loss-of-pulse detection and call emergency services if I have a heart attack.

I can't tell whether that's a joke, but the Google Pixel 3 smart watch has "recently" (June, 2025) received FDA clearance for "loss of pulse" feature. Seems like there would be a lot of false positives if the watch is either too tight or not tight enough, but maybe not.

Not a joke. I'm aware of that feature, and that's why I said it. No idea about false positives.

Slashdot Top Deals

Your code should be more efficient!

Working...