[-] Mikina@programming.dev 21 points 2 weeks ago

Oh no, the technology that is literally just a glorified text prediction that gives you random guesses about what word comes next, based on what was in the text you trained it on, can not scale to have an independent reasoning?

Color me surprised, who would have thought?

[-] Mikina@programming.dev 19 points 3 months ago* (last edited 3 months ago)

While I'm all for holding CS accountable for what happened, thisis not the way how to do it and to whom they should be accountable. If there's any lawsuit, it should come from the customers who have been affected by the outage, not some fucking investors and shareholders that probably kept pressuring CS for the last several years to reduce costs and increase revenue, that are now scrambling to avoid consequences of their endless greed ruining companies they don't care about by forcing endless growth at all costs and doing as much as they can to prevent internal investments, because that's not what makes the line go up.

Fuck them. I hope they loose and have to eat their losses + expensive lawsuit. If CS would be able to actually invest their revenue internally, instead of it feeding pockets of greedy investors who give literaly zero fucks about the product or the service, this may not have happened.

I saw that happen at the cybersecurity company I was working at, when we got acquired by investors. Several milion of profit after costs suddenly wasn't enough, and we had to reduce already non-existent internal projects or investments, that we have already been lacking to be able to do our job properly.

[-] Mikina@programming.dev 21 points 3 months ago

A random account on FB, with only like one or two mutual friends and a name and profile picture both being reference to Tim Burton's movies has messaged me because of a photo of me on a local old school goth festival. We started talking and hit it off pretty well, and eventually decided to meet. No-one of my friends knew who she was, I never saw any of her real pictures or had any indication whether I'm being scammed, catfished, or who the hell it is, other than her mentioning that she was part of the local goth scene several years ago, before I started participating.

We decided to eventually meet before another party, and I went in half expecting I'll just get a funny catfish story out of it, but I like collecting funny stories so why not. And she promised to bring alcohol, so all I was risking was one awkward afternoon I'd spend getting drunk with someone.

We both arrived already tipsy, and I was met at the train station with a really nice looking girl carrying three bottles of mead, which we've managed to drink on the way to the party. It was amazing experience and we hit it off immediately and it was basically love at first sight. Both of us could hold our drinks well, and we got to the party pretty drunk but nowhere near too drunk - I can drink a lot and be OK (not that I do it too often), and it's rare when I meet someone who can keep up with me.

When we arrived, it turned out that half of the people already knows her, because she indeed was part of the scene around five years before my time, before she got into a really bad relationship she couldn't get out of due to mortage for several years, cutting contact, but she changed her nickname so no one realized it was her I was talking about. She just got out of the relationship by moving out within a day because she found out he was cheating on her, and few months after that randomly decided to message me, because she saw me on photos with her highschool classmate - who was also my best friend who got me in the scene several years before that (I'm around 6 years younger than both of them), and her friend convinced her to just give it a try and message me.

We've been together for almost 6 years, moved together four years ago, and we've eventually started DJing and hosting our own goth parties, among other things, while also helping local promoters with their events. All in all, it's good, but it was a pretty random luck that we've met.

[-] Mikina@programming.dev 21 points 4 months ago

I see a lot of hate ITT on kernel-level EDRs, which I wouldn't say they deserve. Sure, for your own use, an AV is sufficient and you don't need an EDR, but they make a world of difference. I work in cybersecurity doing Red Teamings, so my job is mostly about bypassing such solutions and making malware/actions within the network that avoids being detected by it as much as possible, and ever since EDRs started getting popular, my job got several leagues harder.

The advantage of EDRs in comparison to AVs is that they can catch 0-days. AV will just look for signatures, a known pieces or snippets of malware code. EDR, on the other hand, looks for sequences of actions a process does, by scanning memory, logs and hooking syscalls. So, if for example you would make an entirely custom program that allocates memory as Read-Write-Execute, then load a crypto dll, unencrypt something into such memory, and then call a thread spawn syscall to spawn a thread on another process that runs it, and EDR would correlate such actions and get suspicious, while for regular AV, the code would probably look ok. Some EDRs even watch network packets and can catch suspicious communication, such as port scanning, large data extraction, or C2 communication.

Sure, in an ideal world, you would have users that never run malware, and network that is impenetrable. But you still get at avarage few % of people running random binaries that came from phishing attempts, or around 50% people that fall for vishing attacks in your company. Having an EDR increases your chances to avoid such attack almost exponentionally, and I would say that the advantage it gives to EDRs that they are kernel-level is well worth it.

I'm not defending CrowdStrike, they did mess up to the point where I bet that the amount of damages they caused worldwide is nowhere near the amount damages all cyberattacks they prevented would cause in total. But hating on kernel-level EDRs in general isn't warranted here.

Kernel-level anti-cheat, on the other hand, can go burn in hell, and I hope that something similar will eventually happen with one of them. Fuck kernel level anti-cheats.

[-] Mikina@programming.dev 21 points 5 months ago

Has anyone managed to figure out how to opt out?

I tried using the link from an email, but that landed me in generic contact us page, and when I selected that I want to opt out, they just said that the will contact me, and never did.

[-] Mikina@programming.dev 21 points 7 months ago* (last edited 7 months ago)

Down the Rabbit Hole for EVE Online is absolutely amazing. I've played the game here and there for quite a long time, and it's one of my favourite experiences, that is however really hard to put into words.

That game is weird. I still can't explain why it's one of the best games I've played, but I always keep returning to it and love consuming content about it from time to time. And this document is amazing in explaining how extremely unique and cool the game is in it's metagame and the stories it generates. The game has it's problems, but I still think it's one of the most unique lifestyles in gaming, that nothing ever comes close to. It's the only MMORPG that's actually literally roleplay, that basically forces you to roleplay without you even realizing it. Sure, you may not speak in character, but the fleet doctrines, logistics, corp organization, propaganda, corp-politics and everything around it people do - that's literally roleplaying.

Another one would be B-Movie: Lust & Sound in West-Berlin 1979-1989. This document is really really hard for me to watch, because it's a subculture that was always really important to me, to the point where I help with event promotions and DJ at local 80s goth/synthpop events and it's my main hobby. But, since I'm now in my 20s, I've missed it. The way internet transformed music subcultures is terrible, especially so the alternative ones, but music consumption in general - sure, it's really amazing to have every almbum ever in the palm of your hand, but there's just so many that I don't know any. If I talk to anyone who started with music with the one MC tape, and each new relleas was something hard to get that you actually treassured, I really envy their relationship with music. And that's something that's almost impossible to build in this day and age.

The fact that I'll never get to experience the scene as it was in the 80s is one of the saddest things for me, and this documentary shows it in really genuine and amazing way.

And then there's The Social Dillema, about the dangers of social networks. A word of warning from people who worked at large social network companies and left because the way they exploit users got too much for them, and now they are trying to spread the word. I really recommend this for everyone, it's eye openning and really terrifying. It was one of the first impulses that got me heavy into privacy, and it everyone should see it at least once.

[-] Mikina@programming.dev 20 points 7 months ago* (last edited 7 months ago)

If you don't use Discord for voice much, Matrix has a pretty solid bridges you can use.

Hosting your own Matrix server is suprisingly way easier than I though - got a VM on hertzner for like 5$ a month, and there is an Ansible script that takes care of the setup for you. It's also one of those rare cases where someone made an Ansible script that actually works, instead of you getting stuck in dependency-hell (seriously, fuck npm. Not a single docker or ansible tool that has used it ever worked for me out of the box. Python can get simillarly annoying).

They have a pretty easy to follow guide, and the whole setup took me like 20 minutes. I only edited a few options in config.yml (mostly to add Messenger and Discord bridge), and ran the ansible, and it worked at first try.

So I could at least ditch both messenger and discord apps from my PC and phone, without having to convince anyone to quit their poison - with only issue being that you can't use Discord voice. And that the messenger bridge is still unreliable sometimes, but those are still minor inconviniences in comparison to my deep-seated hate for Meta.

Of course - Meta still gets my chat data and content, same as Discord. But at least they don't get anything else from my phone or PC.

[-] Mikina@programming.dev 21 points 10 months ago

This is unfortunately not true - AI has been a defined term for several years, maybe even decades by now. It's a whole field of study in Computer Science about different algorithms, including stuff like Expert Systems, agents based on FSM or Behavior Trees, and more. Only subset of AI algorithms require learning.

As a side-note, it must suck to be an AI CS student in this day and age. Searching for anything AI related on the internet now sucks, if you want to get to anything not directly related to LLMs. I'd hate to have to study for exams in this environment...

I hate it when CS terms become buzzwords... It makes academic learning so much harder, without providing anything positive to the subject. Only low-effort articles trying to explain subject matter they barely understand, usually mixing terms that have been exactly defined with unrelated stuff, making it super hard to find actually useful information. And the AI is the worst offender so far, being a game developer who needs to research AI Agents for games, it's attrocious. I have to sort through so many "I've used AI to make this game..." articles and YT videos, to the point it's basically not possible to find anything relevant to AI I'm interrested it...

[-] Mikina@programming.dev 19 points 10 months ago

I 100% agree! Am a pretty new user of Nobara as a daily driver, switched like a month ago (I did have extensive CLI experience with Linux servers, along with Kali VM for work), and I've only realized what DE actually is only a week ago, because no one mentioned how important choice it is - it was usually just a note, that wasn't given enough importance.

So please, if you're ever recommending any linux distro to somenone who's asking, please include a short paragraph about what DE is and how importnant choice it actually is, and that they should not ignore it. I hated Gnome, and KDE feels so much better (only found about it when reinstalling broken first Fedora install to Nobara), but I didn't know I can switch or that there was that choice in the first place - I though KDE vs Gome is a back-end thing, similar to X11 vs Wayland. It's not, but people don't usually explain it when recommending distributions.

[-] Mikina@programming.dev 19 points 10 months ago* (last edited 10 months ago)

I'd recommend Tyranny. Its a CRPG, where you play as an envoy of basically villains that are sweeping through the world, conquering almost everything. Most of the choices are pretty difficult, because from what I remember its usually "bad or different bad", without it being clear what's going to be worse. Because you're an envoy for a dictator with the power to literally wipe an entire continent with a single sentence, you can't just go " fuck this, I'm gonna ignore the orders and do good", and balancing the long term and short term consequences makes every decision pretty difficult.

For example, if you get an order to "capture this fortress within few days or I'll wipe the entire island", any small war-crime now may be the long term good option, if it helps you capture it in time, and helping the soldier asking you to help find his wife nearby may be lost time you can't be sure you can afford.

[-] Mikina@programming.dev 19 points 1 year ago

I love this quote, it exactly sums up my sentiments.

I'm actually looking forward to it, because it will finally force me to go cold turkey on so many bullshit websites I don't need in my life anyway, which I was never able to do on my own, because the addiction simply is there. But not as strong ans my hatred of fingerprinting and advertisements.

[-] Mikina@programming.dev 22 points 1 year ago

They’d essentially have to by hand arrest every single node that participated to the source

I may be wrong on this, but I think that's exactly the risk associated with hosting TOR Exit nodes.

If they bust a darknet server, for example one hosting child pornography, they sometimes end up with logs of every IP that was accessing the said node. IP of every exit node that someone used to route their traffic. And they do investigate, and it will affect your life, even if you are not doing anything illegal - and even that line is pretty blurry in some of the countries.

If that IP is yours, you will get a visit from police. Being accused of anything in regards to child pornography is not a laughing matter. From what I've heard, they may take all of your electronics, you will get interogated and you have to prove beyond doubt that you did not know that someone is using your computer - the exit node - for such activites. In some countries, merely enabling someone to distribute or access child porn - which is exactly what an exit node is doing - is illegal. And while TOR has been in the public knowledge for pretty long time, you may get a judge who has never heard about TOR and has to research it for your case. And in addition to that, you are now literally investigated of distributing child porn. If someone finds that out, it will ruin your reputation and history has shown that being accused of something is enough for many people, no matter the result. Good luck explaining to your grandmother how does TOR work, or to HR at your company why you are being investigated for child porn distribution or why they confiscated your company laptop.

That's why there is so many warnings on never using your home IP for exit nodes - and that's exactly what would happen in Veilid.

In general, running an exit node from your home Internet connection is not recommended, unless you are prepared for increased attention to your home. In the USA, there have been no equipment seizures due to Tor exits, but there have been phone calls and visits. In other countries, people have had all their home computing equipment seized for running an exit from their home internet connection.

So, it esentially boils down to who is handling the investigation of your case. The police can either accept that it's an exit node and a waste of time and leave you alone, or they can make your life a living hell if they choose to.

view more: ‹ prev next ›

Mikina

joined 1 year ago