Forgot your password?
typodupeerror

Comment Re:Correct. And oh, no. (Score 1) 51

It's not. Full disk access is sticky. When you grant it, the app has it until you go into settings and revoke it.

You're interpreting it in the context of typing "sudo" on the command-line granting a one-time permission. And the original statement from Apple (after correcting the "every -> very" error in the summary) makes it clear that this is *not* what is being proposed, so if that was the original poster's intent, then it was incorrect.

The way I interpreted the original sentence — "They're going to make it like sudo where when you give permission to a program to write protected files once it has it forever after" — is that they're going to make it like the sudoers file, where you edit it to grant permission to a program to do something, and it permanently has the right to do that... which is exactly what happens when you grant full disk permission, just with a dialog box instead of editing a file.

That said, I'm not sure if that's how the original statement was intended to be interpreted. It was a bit confusing. :-)

Comment Re:Groundwork for censorship (Score 1) 103

Some would argue that censoring spam is bad due to free speech, once again, fuck your free speech as I don't want to associate with spammers. Security of body, should we put up with speech preaching violence?

Nope. And this is why I object to the phrase "censorship is bad". *Unreasonable* censorship is bad. But not all restraint on speech is bad.

Comment Re:Groundwork for censorship (Score 1) 103

Censorship is a problem when you are not free to express an idea.

The form of the idea can be limited without it being censorship: for example, you can't protest with a bullhorn in the middle of the night.

No, you're confusing the definition of censorship with what restraints on free speech are constitutional. You're defining the term based on legality in a specific jurisdiction. If you applied the same standard with a different jurisdiction — say what can legally be spoken in Iran — you would get a very different definition. This is why you cannot define censorship based on a specific legal standard. It must be defined in the abstract.

The general definition is that censorship is the suppression of expression by an authority. That expression could be a constitutionally protected idea, or it could be an advertisement for Taco Bell. It's still expression, and blocking it is still censorship.

Free speech doesn't mean everyone has to listen to you, it means the people who want to listen to you are able to. Youtube demonetizing a video is not censorship. Removing videos because they don't like the ideas in the videos is the worst kind of censorship, because they are trying to control you.

And again, you're using the U.S. definition of free speech to define censorship. These things are not synonymous. Nobody is talking about whether someone should have to listen to you. The fact that someone shut you up is still censorship. It may be *constitutionally allowable* censorship. It may even be *entirely* *reasonable* censorship. But it is still censorship.

Not all censorship is bad. Restraints on speech based on time, place, and manner restrictions can be entirely reasonable. They are still, at least in a purely abstract way, a form of censorship. Restraints on speech where your speech costs someone else money can also be entirely reasonable (e.g. spam, robodialers, etc.). But those decisions still represent censorship in the abstract. We simply choose to say that those types of restraints on speech are reasonable and necessary for a functioning society.

It's all about balancing rights — your right to swing your fist ends when it meets my nose, and all that. Censorship is generally justifiable when exercising your right to speech has the effect of violating someone else's rights. For example, if you call for violence and that violence happens, you can get thrown in jail, and your rights to free speech can be massively curtailed. This is, however, still censorship in a purely abstract sense.

Comment Re:Correct. And oh, no. (Score 1) 51

Yeah, "very". They're going to make it like sudo where when you give permission to a program to write protected files once it has it forever after.

No, wait, that isn't how it works, is it?

That's how it already works. But you can request the permission from the user with a pop-up. Presumably a "very explicit action" means going into the Settings app and turning it on by hand.

But that's going to do exactly nothing. The app will tell them that they have to do this, and the users, having no idea how dangerous it is to give an AI unrestricted access to their device, will do it anyway, and we'll be right back to where we are now. And the next step will be "See, we can't allow full disk access." And then macOS will cease to be usable.

The only reasonable choice is to flag Meta's software as malware for extending their full disk access to agents. Force them to implement a proper sandbox. Apple already gives them all the tools they need to do it right.

  • The main host app asks for full disk access, but functions without it, triggering an open file dialog to work around missing access when necessary. Most users will end up granting full disk access out of frustration, but that's okay because the agents themselves don't have that access. If possible, make it start out with a read-only full-disk entitlement, because otherwise, using it will be much harder.
  • Each agent runs in a separate agent runner process with a stricter sandbox.
  • The agent sandbox has an entitlement that grants read-only access to the entire disk (or, if the main host app's sandbox doesn't allow that, to every resource that the main host app has access to), and bans the use of the socket() system call.
  • AI agents can request read-write access to specific files or directories by asking the host app. The agent is encouraged to ask for access to an entire directory at once if it needs to write to multiple files in that directory.
  • The host app can pass in a security-scoped bookmark/URL to grant permission, but asks the user first unless the URL is part of an explicit list of allowlisted URLs that the user provided before beginning the task. Doing this expands the sandbox to allow writing to that file or to files in that directory. The SSB can be created programmatically or, if the main app also doesn't have access, through showing an Open File dialog.
  • One tool provides network access to specific hosts with no POST, all GET parameters filtered, and a low limit on URL length to mitigate exfiltration risk. This tool has an entitlement that allow socket access inside an environment where opening sockets is otherwise banned, and thus can be run directly by AI agents.
  • One tool provides broader network access with full upload capabilities. This tool lives outside the sandbox so that the AI agents cannot run it themselves — only ask the main host app to run it for them. Then:
    • The main host app requires the user to give permission to access a single hostname for either a single request (allow once) or a single task (always allow for this task).
    • If the user clicks the "Always allow sending data to example.com" button, the user is asked "Trust example.com for similar request parameters only" or "Trust fully".
    • If the user choose to trust similar request parameters only, then any additional GET parameters must be explicitly allowed each time.
  • The main host app passes each AI agent runner a new open socket connected to the AI service's server.
  • The AI service's server is configured to provide minimal or no network access from the server side.

This is how you protect privacy in an agentic environment.

Comment Re:We're probably going to find more (Score 4, Informative) 31

Deeply, deeply misleading comment.

First off, you're using a denominator fallacy. Yes, we have discovered over 200 types of HPV. Gardasil 9 targets 9 types, and numerically, yes, 9 / 200+ ~= 4-5%. But most of the 200 known types of HPV are rare and/or irrelevant (causing ordinary warts on fingers, knees, and feet, with extremely low odds of cancer). Only 40 types infect the mucosal/genital tract, and of those, only 12-14 are high risk. Gardasil 9 targets the 7 strains responsible for 90% of all cervical cancers, as well as types 6 and 11, that cause 90% of genital warts.

Secondly: cervical cancer indeed tends to happen in middle-aged women. But the disease itself is typically acquired in the teens or 20s. It's oncogenesis that takes decades to happen. Vaccination protects women of all ages.

I will however, admit that your claim that it "doesn't even target the HPV most likely to cause throat cancer in men" isn't misleading. Rather than being misleading, it's just simply false. HPV-associated oropharyngeal cancer is caused overwhelmingly by Type 16 (85-90% of all HPV-positive throat cancers). Even the original 4-variant Gardacil covered Type 16.

And, do I even need to add, that the claim that "Gardasil fatalities will have killed more teens than prevented deaths of women” is sheer unadulterated bullshit? There has been ZERO causal link found between Gardacil vaccination and death, by any major health organization (WHO, CDC, or EMA). This more stupid "I DiD mY oWn ReSeArCh" VAERS bullshit, where even a person dying in a car accident after getting vaccinated gets a report. VAERS isn't controlled. Stop pretending that it is. It flags signals for controlled research. It is not itself controlled research. Controlled research does not link Gardacil and death.

You know what the most common significant adverse reaction to Gardacil is? Vasocagal syncope. Sounds pretty terrifying, until you learn that that is "fainting from needle anxiety".

Check Falcaro et al, 2021, studying HPV vaccination in the UK - there's been an 87% reduction in cervical cancer rates and a 97% reduction in precancerous lesions. Australia is on track to effectively eliminate cervical cancer as a public health issue within a decade.
  vaccination coverage.

Also, do I even have to get into how stupid the notion of "get cancer, but then cure it" is? Cancer does damage. "Cures" do damage. Pain, infertility, disfigurement, etc. Your notion is "rely on some theoretical (deeply doubted by most researchers) notion of imminent magical perfect AI cancer cures" because of your ridiculous not-at-all-scientifically-backed antivax bullshit about a treatment that has been immensely effective and immensely safe.

Comment Re: We're probably going to find more (Score 1) 31

We have remnants of all sorts of viruses left around in our genome. My favourite example is parasitic wasps. They ended up evolving the ability to use viral genomes in their DNA as a weapon. Laying an egg inside another insect and having it mature in there is a big challenge, because their eggs' host's immune system starts attacking it. But it turned out to be advantageous for wasps to be infected, because they'd infect the host, hindering its immune system. The virus and wasp ended up coevolving, to the degree now that many parasitic wasps in effect produces virions on-demand, which do not harm the wasp, and instead serve only to suppress their eggs' host's immune system.

Comment Re:We're probably going to find more (Score 2) 31

And not just cancers. Look at the intro paragraphs to the Wikipedia article on Epstein-Barr, for example. It's like every year we discover a new link between it and some horrible disease. My mother has disabling neuropathy from Sjögrens; there's now some links between Sjögrens and EBV, and she has measured EBV reactivation.

In COVID, we discovered "Long COVID", and how disabling it was for victims. Not just Long COVID - e.g. obvious sequelae - but also a whole slew of other diseases (particularly cardiovascular and respiratory) have their probabilities shoot up dramatically in the six months post-infection, lesser increases after that. Yet as we started comparing it to other contageous diseases such as influenza, we started finding that even if SARS-CoV-2 is somewhat more at risk of causing debilitating sequelae (times how everyone was contracting it at once), influenza and other common viruses are also very capable of causing debilitating sequelae.

My father went from someone who was going on long hikes every day to prepare for hiking to Everest Base Camp to being unable to walk in a matter of days. He caught a virus on a plane, "got better", but then a couple weeks later, suddenly ended up in the hospital becoming rapidly paralyzed due to Guillain Barre. It nearly progressed to his lungs, but he was lucky to avoid intubation and to be an unusually-fast recovery case. Most aren't so lucky.

Just because you "got better" doesn't actually mean that you "got better". Pathogens deliberately disregulate your body in a vast range of ways (some in weird ways - for example, measles can cause your body to "forget" how to fight other infections that you were previously immune to!). Your innate immune system attacking them means deliberately doing damage to your body in the process. And the adaptive immune system runs the risk, with every infection, of accidentally learning to attack some part of your body instead. Even the very act of the immune system proliferating is itself a risk. Because of my mother's Sjögren's, the immune system was attacking her salivary glands. This led to extensive, nonstop lymphocyte propagation. Which in turn, led to MALT lymphoma. Your own immune system's activation can cause cancer.

It honestly shocked me that we went from all we learned during COVID to "pretending that nothing ever happened", just back to exactly how we were living before. No, we should absolutely not all be masking all the time. But can we at least clean our damned air, like we clean our water? Yes, if you're up close talking to someone, you should be able to get infected from them if they're sick; trying to prevent that is too difficult. But the person across the room should not be getting sick. You know what it reminds me so much of? The Broad Street cholera epidemic. It's well known that removing the handle from the Broad Street pump cured the infection, a victory for modern epidemiology and proving the hazards of contaminated water. But what's lesser known is the fact that as soon as the epidemic subsided, they put the handle right back on. People simply didn't want to think about the fact that their feces was leaking bacteria into their drinking water supply.

Also, to be clear: pathogens are not Pokémon: you do not need to catch them all. Yes, if there is no vaccine for a given common "mild" pathogen, it's usually good that children catch some variant of it once as a child, rather than first encountering it when they're 70 years old. But you do not need to catch every seasonal variant that goes around. Memory B and T cell immunity against severe outcomes is very durable. A virus shuffling up its receptor binding domain to evade immunity enough to cause a seasonal infection doesn't mean your body has to start over with learning how to not end up hospitalized from it.

Comment Re:Universities teaching the 'truth' (Score 4, Informative) 31

The human body is eminintly capable of controlling its internal pH. Arterial blood is maintained within a very precise pH range, 7.35 to 7.45. Bicarbonate buffers, protein buffers, and phosphate buffers react within seconds. Respiratory response (increased or decreased breathing rate, to adjust blood CO2 levels), in minutes. The renal system (pumping H+ to or from the urine, and generating or recovering bicarbonate) in hours or days. Food intake has essentially zero impact on pH. The stomach is always extreme, and food leaving it is immediately neutralized by sodium bicarbonate from the pancreas. Metabolism can generate free acids, but the amount is far less than the kidneys are capable of handling. You cannot make your blood more or less acidic with diet.

I hope this helps, and please learn to be more skeptical of what you read online.

Comment Re:kids these days ... (Score 0) 111

Fun reminder that with an AI agentic framework, pretty much any software can be readily disassembled and this sort of malicious behavior "fixed". Tasks that previously would have taken far too many man-hours to do, well, you can have a bot do it now.

Comment Re:LEDs for thee, not for me (Score 1) 110

, I'm talking about the massive, entirety of the electronics industry, all of which is required to make an LED bulb:

Yes, that's what life cycle assessment (LCA) figures include. It doesn't take 8-20 kWh merely to assemble a LED bulb, that's the energy for everything included.

And that's actually a lot of energy for such a small item. Even incandescents are relatively energy intensive to make for such a small item (glassmaking is energy intensive), and LEDs are 8-13 times as energy intensive to make. Just (A) not 25x as many, and (B) orders of magnitude off of being relevant compared to usage consumption.

Remember that this "every person driving every car" also applies to the usage electricity, which is by far the vast majority of the impact. Generating an extra 1,23 megawatt hours to power 25000 hours of incandescent instead of LED lighting involves massive numbers of people "driving their cars and mining". 1,23 megawatt hours of generation just is not even remotely comparable to the resources that go into manufacturing a small electronic device. Which should be obvious from the price alone.

And pretending that incandescents are made of rainbows while LEDs are made by Satan is just not fair. Incandescent bulbs rely on tungsten. Tungsten is only 50% more common than silver. Extracting tungsten from wolframite or scheelite requires open-pit and/or underground mining, then pressure digestion in hot sodium hydroxide, liquid-liquid extraction with organic solvents, & acid precipitation. Since you're throwing away 20-25 incandescent bulbs for every LED, you're demanding 25 glass envelopes (glass smelting), 25 brass threaded bases (copper mining), and 25 tungsten filaments. The number of components is less but the volume of them is far more. As is the energy required to make them.

As for "waste": a large portion of the world's electricity comes from fossil fuels. 1,23 megawatt hours of electricity leads to a ton of pollution, including things like lead arsenic and mercury, being emitted directly into the environment. Far more than anything you might be concerned about within a LED bulb if you were to outright incinerate the thing in open air and dump all its waste straight into the water. Which is, of course, not what actually happens. And it should be mentioned that that RoHS marking on the bulbs? That requires strict requirements on the maximum amounts of toxic elements that can even exist in the product. We're talking milligram quantities of gallium, indium, phosphorus, etc. It is simply incomparable to the emissions from power generation.

Re, health claims, I can only guess you're talking about blue light impacts on circadian rhythms, and that early LED bulbs tended to be "cold" / "daylight" color spectra, wherein most incandescents are "warm" spectra? But today you can buy fluorescent to literally any spectrum you want, so it's not particularly relevant. Or maybe you're talking about flicker? Again, it was often bad with old bulbs, but completely irrelevant to modern bulbs. If you mean something else, you're going to have to state what you mean.

Slashdot Top Deals

"Well, it don't make the sun shine, but at least it don't deepen the shit." -- Straiter Empy, in _Riddley_Walker_ by Russell Hoban

Working...