I'm not an expert, but my current mental model for this sort of thing is that the thoughts were already there, somewhere in the training data.
Some human was looking for something like this once. They didn't find it, but they wrote about the search precisely enough that the finding can happen during inferrence.
Maybe somebody will come along and school me, but for now it's a fun way to think about it: A million dead ends, each with a uniquely disappointed human, now with a chance at a second life in the hands of a different human they haven't met. If only the weights had encoded enough to introduce us, supposing they still live.
> All social artifacts are stored in Git, and signed using public-key cryptography. Radicle verifies the authenticity and authorship of all data for you.
They're clearly not talking about privacy there.
Is it embarrassing that their private feature was broken? Sure. But it's for the most part a publishing platform. Protecting users against a network adversary who wan't to know what they're publishing isn't exactly core functionality.
Oh indeed, if we just redefine words in the fine print then we can commit fraud with impunity.
Please enlighten me how that blurb supports the common reading of the claim: Your data, … secure. Note that and is a additive conjunction, so the components can be safely examined separately.
A regular person would assume that means your data is secure against tampering and disclosure. If you then say: “lol, jk we do not do anything related to securing your data” in the fine print then in a reasonable society you should be required to remove that more prominent false large print.
You can always go back and reword your large print to be more accurate without making deceptive claims to your benefit. Weird how the deception is always beneficial.
Security is an umbrella term. You can't just assume that secure things are private--you have to make the determination in context with whatever kind of thing it is.
The primary goals of a system like radicle are:
- spread the word
- don't let anybody alter it
If you ask if it's secure, you should assume you'll get an answer related to those purposes.
If you got a sunburn while standing in line for a water slide, you wouldn't say that the slide is unsafe, even though being burned is a hell of a departure from "safety". You'd have to be a little more specific.
That does still leave many things like malice (or ignorance that's as good as), organized crime (including political), and possibly neighbours that still have desperation. Lots of things are in the way of having nice things. But nice things are also a spectrum.
Yeah, there are other root causes. I'm just saying that we should focus on those. Much of this conversation is focused on enforcement. Getting enforcement right is like having the right sized bucket for bailing out your sinking boat: some answers are better than others, but none change the fact that the boat wasn't seaworthy to begin with.
Although to nitpick your examples... Can you really imagine a malice fueled crime that has to do with stealing copper from infrastructure? If you're angry but not desperate for money, there are more satisfying ways to express it.
And organized crime... That's for stealing Venezuelan oil tankers. If you're involved with organized crime and you're stealing copper from infrastructure, maybe you need to find a more ambitious boss because any junkie can do that. You don't even need to be organized about it.
I think the panels are safe if there's enough of a safety net that nobody's desperate
Maybe we should just give up on custodial trust re: people we don't know.
If somebody wants data about me, they can write the query, I'll approve it, and it can hit a server designated by me and run by somebody I know personally.
It's not just a privacy/security concern. People who get too close to large piles of sensitive data tend to start behaving poorly in other ways too--they might be compelled to misrepresent it. Apparently the forces of corruption are too great. Maybe the way to avoid exposing each other to such hazards is to just maintain smaller piles of data, closer to the people that the data is about.
I think we will just be heading for a future with very little secrecy.
I think privacy will remain, perhaps even improve, because people are much less inclined to snoop when it cannot be done covertly. No secrecy means no covert activity.
Information is everywhere and with the increasing ability to analyse it, not only does it enable access to explicit information, but the ability to infer from increasing volumes of data that will make it hard to hide anything.
Spectre reads protected memory by tiny vriarions in timing. You can now measure the pulse of people from film. You can recover audio from a room by analysing frames of a video recording of a chip packet taken with mobile phone camera. Even as far back as ww2 intelligence on the success of attacks could be measured by the price of items impacted by different types of infrastructure damage.
This kind of data residue is everywhere, collecting only what is publicly available can probably tell you more than you could hope to know about anything that happens. The only thing preventing it is the ability to consider it all together. Those walls are swiftly crumbling.
The most common kind of hack is phishing, social engineering, human facing stuff.
If the users know their admin, then each server has no more than few dozen other users' worth of data on it. The juice just isn't worth the squeeze to target them one at a time. Ain't nobody has the resources for that kind of attack.
Also, it's a lot harder to phish somebody who is on a first name basis with 100% of their users. It's not enough to merely have a plausible backstory, you have to impersonate one of their friends. That's incredibly difficult.
The only thing left is to hack through whatever protocol indexes these servers and multiplexes queries across them, but now you're presenting a much smaller and easier to defend attack surface, one which can be defended in aggregate (e.g. supply chain scrutiny) rather than singly.
If we all had a significant sum auto-invested in an early age, we'd all have a stake in preserving the practices that are causing so many problems. I don't wanna live in a broken world forever, so I'm kind of glad that we don't.
I've found it helpful to make an explicit delineation in the codebase for which interfaces I'm going to agonize over and refine and which I'm going to ignore.
One set goes into haxe files and I use reflaxe macros to write tiny compilers that generate docs, clients, servers, cli's, test cases, serializers and deserializers, etc in whatever language is appropriate. That leaves gaps, which the AI can then fill in.
So I iterate on the haxe stuff. If the AI is struggling to "draw the rest of the owl," I change the source of truth until it has enough guidance re: type related errors, failing tests, and documentation. As requirements change, these things change.
As for the rest of the owl, it's disposable. Every few months I'll delete it and have an AI rewrite it from scratch (now with a smarter model and better docs and API specs and tests to guide it). This keeps the cruft from accumulating while preserving human contact with the code.
The natural manufacturing defects in all image sensors uniquely identify normal media. Post once to a friend over mms or a social media service... and your ninja life is burned.
These kids and their foreign contractor run VPN services are naive about depth-charge Steganography. Privacy has been dead for years. =3
When I search for "depth-charge Steganography" I find... this thread and nothing else. So I think most people are ignorant of it. Is there a typo? Or is it so secret that the web hasn't heard of it? If the latter, then I think you just blew its cover.
I used to work at a traffic signal controller company. We were under strict orders not to use AI. We did anyway, in a simulation, and let it optimize over the weekend. When we got back it had blown all of our previous attempts out of the water. We huddled around my coworker's workstation eager to see its masterful new pattern. It just made one phase red all the time and one phase green all the time, effectively closing one road. The throughput on the other road was through the roof though, since its light was always green. We did not present these results to the boss.
We treat it as a proxy for consent, and it fails horribly at that job.
Given perfect information, I'd avoid feeding you if I knew your mining operation was poisoning my drinking water. Money hides that from me. I see one dollar the same as any other, accept yours in exchange for food, and go home to drink the poisoned water--an outcome I could've avoided if I mapped that dollar back to the event that created it: a loan in support of a venture that harms my community.
The banks that create money have no incentive to ensure broadly favorable outcomes result from their decisions. Profit is sufficient for them. It's a status quo that we should be furious about, since we bear the brunt of the negative outcomes.
Absence of money does not at all imply perfect information. The problem you describe would occur equally with an ordinary debt between two parties, or barter, or indeed any system that doesn't entail the (laborious, impractical, necessarily incomplete) gathering of perfect information.
Yes but money is perfectly situated to carry the missing information in this case. If it's legitimate, it was issued by a bank. Which bank? To whom? For what venture?
The fact that it doesn't is by design. It deliberately obfuscates its origin to create fungibility.
But in a climate of rampant corruption its not a suitable design choice (and maybe it never was) because now it's starting to look like all dollars are equally illegitimate. Continuing to use them appears to be encouraging outcomes that will hurt me. That's totally contrary to the point of money. The baby is being thrown out with the bathwater.
The fix is to make it risky to hold currency that was issued in support of an antisocial endeavor. And the way to do that is to make the money carry extra information about the conditions of its issuance so that if the backed venture has harmful outcomes, holders of the associated dollars will have a hard time finding somebody to accept their money.
If we want it to be a proxy for consent, it has to actually provide enough information for that consent to be rational.
By leading with the improvement-order-barter story, the article announces a bias that borders on propaganda. It's maybe worth objecting to even if the goal isn't to be historically accurate.
The problem that was actually being solved when money was invented was how to get recently conquered villagers to support the soldiers that recently conquered them. (Demand taxes in the coinage that you pay your solders with, then they can live off the local economy and you don't have to feed them directly, which might be hard if they're very far away--tax collectors can take years to show up, but the demand for the new currency is instant, so your soldiers get fed right away).
The system of interpersonal debt that predated money likely outperformed money in a variety of ways from the perspective of the users. It was only for the conquerors that the invention of money solved any problem at all. It's hard to keep reading the article when it starts with the story that is used to distract from this.
There's a central problem, a blind spot, that plagues economics: because the fundamental credo of the discipline is that it's all about free people engaing in mutually beneficial trade to maximize their respective well-being, it completely neglects how important armed force and violence are in shaping the economic system we know.
Agreed. We should acknowledge that it has historically been about ensuring that conquerer grandpa and conquered grandpa end up with different qualities of life even after they're too old to swing a sword. I.e. extending violence begotten structure into places where violence is impractical.
Some human was looking for something like this once. They didn't find it, but they wrote about the search precisely enough that the finding can happen during inferrence.
Maybe somebody will come along and school me, but for now it's a fun way to think about it: A million dead ends, each with a uniquely disappointed human, now with a chance at a second life in the hands of a different human they haven't met. If only the weights had encoded enough to introduce us, supposing they still live.
reply