Forgot your password?
typodupeerror

Comment Re:TPM Suspicion Intensifies (Score 1) 64

It's all been over since we got processors with microcode, which could have something like a TPM in them. I'm not saying all of them do or anything like that, only that any of them could.

If you really want a computer you can trust, you're going to have to get vintage about it.

Comment Re:Correct. And oh, no. (Score 1) 38

I hereby retract everything I just said. The entire post was based on a misunderstanding caused by Slashdot's editors adding a single extra letter.

  • Original: "very explicit user action."
  • Slashdot: "every explicit user action."

What a difference an 'e' makes. I was imagining every single file access causing a UAC dialog.

Yikes.

Well, no, I don't retract the last paragraph. They should still kick Meta's garbage agent off the platform until Meta can get security right.

Comment Re:Correct. And oh, no. (Score 2) 38

This looks like the final cell-phonification of the Mac. I'm bummed.

How do you figure that? From the Apple post: "Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. "

The word was *every*. *Every* explicit user action.

Oh, bloody hell. I just got rage-baited by incompetent Slashdot editors.

Good night. I'm done for the day.

Comment Re:Correct. And oh, no. (Score 1) 38

This looks like the final cell-phonification of the Mac. I'm bummed.

If this happens, this thirty-year Mac user will be leaving the platform. Full stop. So will just about everyone else within months to single-digit years.

This approach didn't work with Gatekeeper in Mac OS 7. It didn't work for Windows XP. It won't work for modern Mac OS, either. Here's why: CONSTANT PROMPTING MAKES SECURITY WORSE.

Prompting users over and over again to allow or deny actions makes security WORSE. Period. It means that users are constantly being nagged, and constantly having to decide whether an action is harmful or not. This rapidly (over the course of just minutes) turns into query burnout, and the user just clicks "Allow" for everything. And not only does it fail to meet its objective, but it also causes them to the same for every other dialog, including all of the other things Apple put in place to improve privacy and security. And now people are granting every app whatever access it asks for automatically without question, and every advantage that Apple has security-wise and privacy-wise evaporates instantaneously.

Continuous prompting NEVER makes security better. It ONLY makes security worse.

AND this would have a hopelessly deleterious effect on EVERYTHING that high-end users do, from running commands in Terminal (which would become completely unusable) to third-party backups, etc.

And that latter one would also be a major antitrust problem for Apple, which is to say that if they do this, they WILL get sued, and they WILL lose, because it is so clearly open-and-shut that this is not the correct solution for the problem, but that Apple stands to greatly benefit while their competitors are irreparably harmed.

What's described here would completely break the platform at a level that makes it a toy, no more useful than iOS, and completely unreasonable to use for any serious professional work, whether as a software engineer or a graphic designer. And it is pathetically absurd that they think this is a good idea. It makes me assume that none of the Apple security engineers I know are still around, because all of them would have flat out called you a moron for even suggesting something like this. They actually understood security at a more-than-superficial level. Someone proposing this "solution" clearly does not.

You can't fix sh**ty apps by making the platform objectively worse or making things that people legitimately need to do as painful as possible. The only way to fix sh**ty apps is by banning them from the App Store and flagging direct downloads as malware repeatedly until such time as they get their security model right. There are correct ways to sandbox things like agentic frameworks. This is about as far from the right way as you can get, as it does nothing to improve the security of the agentic setup, while catastrophically breaking overall platform usability and turning users into mindless "Allow" clickers.

Find another way. Kick Meta's horrific agentic tool off the platform until they can get security right.

Comment Re:Groundwork for censorship (Score 1) 87

Moderation is censorship by definition.

False.

Censorship means suppression of speech or expression by a governing authority. It can be prior restraint (blocking publication) or censorship after the fact (take-downs, bans, etc.).

In the strictest sense, you could maybe argue that soft moderation in the Slashdot style where people who want to see what has been moderated down doesn't qualify as censorship because there's a way around it, but the net impact is still that most of the potential audience doesn't see it, so that argument is on somewhat shaky ground.

At best, you can argue that moderation is not prior restraint censorship, but while prior restraint makes censorship way more likely to be a first amendment issue if the government is involved, it's not a requirement for something being censorship.

Comment Re:What is the use when you have mail? (Score 1) 49

Why only waste time occasionally when technology will help you waste time constantly?

This is not a joke - some of my coworkers set up a Teams channel specifically for talking about dogs, cats, and babies. I have stayed out of it - like you, if I want human interaction I go visit the front office or generally walk around the building (or, on WFH days, go play fetch with the dogs for a few minutes). Plus, I need to get actual work done and having that channel ping constantly would not help.

And, when I REALLY want to kill time, there's always Slashdot...

Comment Re:Constructive responses anyone? (Score 2) 49

Why isn't EU sponsoring specific features and fixes it needs?

Or assign some of their own developers to submit pull requests.

Or hire *some Europeans* who are unemployed because their war is killing industry.

Let's hear from their project manager instead of faceless wankers and the people responsible for sales.

Slashdot Top Deals

"It ain't so much the things we don't know that get us in trouble. It's the things we know that ain't so." -- Artemus Ward aka Charles Farrar Brown

Working...