• 8 Posts
  • 789 Comments
Joined 3 years ago
cake
Cake day: June 25th, 2023

help-circle





  • Please do, you’re point for the work all over the world (China may be already lost, or not, depending on how well you do), London likely too. Also, please, sustained (go nuts on Samhain though, keen symbolism) but after Flock, there will be subtler versions, expecting you to lose momentum and just fade. They will be detectable, vulnerable.

    Want to know why all the AI (GPU) centres are being built? Deliberately or not they will be used to process camera feeds (why let that compute go to waste).

    The tree of freedom is watered in the blood of patriots. Well actually, get the other side to bleed, or preferably convert, good cause and all. The principle of being bloody serious about it when oligarchs (or upper class British) have control still stands. Step forth, the only thing you have to lose is a future of climate fire. And possibly next weeks meals, but history is replete with cases where that paid off (or not, bloody anarchist truth tendencies)



  • But if you use AI to find issues, then investigate the issue, reproduce it, document it, etc, then you’ve got something meaningful that someone can do something with.

    In principle that is sound, but LLMs can’t do that, yet, if ever. Sounds like anthropomorphism. The ‘hallucination’ thing is intrinsic. What you can do is point it at easily verifiable problems like searching for security flaws, and then verify them. Whether that’s cost effective in wasted energy and human time is still an open question, especially as token cost ramps up pre IPO.







  • Distrobox is not an isolated environment

    True, you’ll note I didn’t say it is sandboxed or isolated, but it is a different environment. Paths that point to normal things like /usr etc. will be in the distrobox environment. That said, unless you use a custom home for the distrobox (you should anyway), your home directory is hosed. At this point I expect the malware to not be distrobox aware and use things like distrobox-host-exec, that may change.

    A VM is absolutely a better approach, if significantly more frictional.


  • If possible do it in a distrobox and down networking before running, yes that won’t stop the curl | sh in the install, but at least you can blow it away without hurting your main install and it will likely infect only the distrobox. Bonus points for an immutable main OS.

    As the whole supply chain attack vector gets more sophisticated, and probably subtler in effect, these are going to be harder and harder to spot and likely start making it into main repos. Keep sharp people.

    Not real fun for a linuxmemes post, but I think it needs saying.