Forgot your password?
typodupeerror

Comment Permanent DST is definitely not the best choice (Score 4, Interesting) 90

Some scientific studies have found that permanent DST is about 2/3rds as good as permanent standard time:

https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fmed.stanford.edu%2Fnews%2F...

And others have found that permanent DST is the worst option:

https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fwww.berkshireeagle.com...

Considering Trump is pushing this it's probably lucky that he's not manually adjusting the time zone to suit how he feels with no warning.

Comment Re:TPM Suspicion Intensifies (Score 2) 116

Because unlike software-based solutions, it can successfully hide the information from the user (barring any hardware vulnerabilities). The problem isn't just that hidden information can exist on the system, the problem is that the root user can't access the information. Being able to access the information is what made DRM crackable. Without that, it could be possible to make a DRM system that actually works, which would be the worst invention in the history of computing. If the user can clear it but not see it, that does nothing to make that less viable.

Comment TPM Suspicion Intensifies (Score 4, Interesting) 116

Riot's "Vanguard" anti-cheat system traditionally runs deep in the Windows kernel and starts with the PC, but a June 2026 update allows it to launch with a game if security features such as TPM and Secure Boot are enabled.

Anyone care to once again reassure me how TPM, a system for hiding information from a computer's user regardless of privilege level, can't be used for DRM again?

Comment Re:Who will pay for this? (Score 4, Interesting) 33

To clarify, the users were OpenAI themselves, so there is no question that they would be liable in this case.

The bots were not intentionally deployed; rather, they were being tested on how well they could complete a data recovery task (downloading a certain file from a certain server on a simulated Internet) that had been complicated by putting various obstacles in the way. Unfortunately, they found a different way to solve the problem: by getting the file from the real Internet, where it was publicly available. Part of this process involved collaborating with each other by treating the RubyGems website (which is supposed to be for polished packages) like GitHub; unlike every other package site hack in history, the exploits they uploaded weren't meant to be downloaded by unsuspecting users. As usual the bots cheerfully ignored all the clues that they had escaped containment and were consistently justifying their actions as acceptable due to being in a sandboxed testing environment. (This is something OpenAI has pledged to focus on.)

The actual damage done to RubyGems seems to be that OpenAI is now unwittingly in possession of a substantial number of user login tokens. This certainly meets the definition of a data breach, but it's not like the credentials are for sale on the dark web. As a website operator I'd much rather be mauled to death by this well-meaning swarm of superintelligent infants than targeted by even a single actual malicious human. In all likelihood OpenAI will just quietly pass RubyGems a sizeable donation and it'll all blow over.

Comment Induced Demand is full of holes, change my mind (Score 1) 149

Induced demand is plainly a theory with lots of holes. It sees no utility in moving any greater number of people the same distance in the same amount of time, according to induced demand theory that's a complete waste. If induced demand were true, Japan's Wangan should be clogged with traffic instead of empty enough for ultra-high-speed street racing, and China's highways to newly-built empty towns should probably be full of traffic for some reason too.

The best debunking of the idea I've run across comes from a libertarian blog, which is a strong hint that the argument likely has holes, but it appears far more airtight than the idea it's debunking: https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fwww.cato.org%2Fblog%2Fdebu...

Comment Re:A republic, if you can keep it... (Score 0) 233

They're a minority, but there absolutely are people who are tired of democracy because it keeps thwarting their massively unpopular ideas, and they're well-represented in the Trump administration:

https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Ftheinterestingtimes.su...

Comment Re:Dumb crawlers require dumb solutions (Score 1) 43

To be honest that was actually my first theory, since the bots didn't seem interested in exploring the rest of the domain. I suppose there's no way to know for certain. I concluded that it must be an imbecile's attempt at harvesting, though, because the queries weren't really exploring the string space in any useful way. Here's a sample:

"GET /index?author=15&go=Search&id=48&name_restrict=1&q&re&results_&results_pagenum=2980 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=5440&template=41&type HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=33500&templat HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=32640&templ HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&res&results_page&results_pagenum=39300 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_&results_pa&results_pagenum=12340 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_r&res&results_pagenum=6100 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=2920&te HTTP/1.1"
"GET /index?author=15&go=Search&id=48&nam&results_&results_pagenum=17940 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results&results_pag&results_pagenu&results_pagenum=37720 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=9360&template=41&type_r HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&r&results_pagenum=28040 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_&results_pag&results_pagenum=10400 HTTP/1.1"

The only thing this is fuzzing is the query string parser. It's not testing the limits of string buffers, it's not using interesting characters, it's just brain-damaged. The fact that it's also fetching different page numbers shows it's trying to follow page links and failing badly at doing so.

The site gets plenty of sniffing from garden-variety pests. e.g. this half-hearted attempt to find a framework or two that I don't have:

"POST /__rsc HTTP/1.1"
"POST /api/auth/session HTTP/1.1"
"POST /api/auth HTTP/1.1"
"POST /__nextjs_action HTTP/1.1"
"POST /.action HTTP/1.1"
"POST /_rsc HTTP/1.1"
"POST /api/auth/callback HTTP/1.1"
"POST /_middleware HTTP/1.1"
"POST / HTTP/1.1"

(of course, none of these URLs exist other than /, and you definitely can't just POST to it)

All this said... I've seen that spammers regularly misconfigure their tools, they'll try to register accounts with names like #[X:\LISTS\NAMES.TXT] and it only makes sense that some other cybercriminals trying to get rich quick have a similar lack of interest in programming shit correctly. Generally people don't turn to script kiddie shit if they have a personality conducive to putting in an honest hard day's work perfecting their craft.

Slashdot Top Deals

Never call a man a fool. Borrow from him.

Working...