-
The UK’s Online Safety Bill – allegedly the ‘safest place in the world to be online’ – ConnectFutures
This is not a terribly *bad* little blogpost by Connected Futures, however I do wish that they would not (like so many others) indulge in false dichotomy: Whose job is it to keep the online space safe? ‘Big Tech’ companies or government? https://connectfutures.org/resources/the-uks-online-safety-bill-allegedly-the-safest-place-in-the-world-to-be-online/ Unpopular as it may be amongst Governments who want to be seen…
-
Kevin A. Bryan on X: “NYT/OpenAI lawsuit completely misunderstands how LLMs work, and judges getting this wrong will do huge damage to AI. Basic point: LLMs DON’T “STORE” UNDERLYING TRAINING TEXT. It is impossible, the parameter size of GPT-3.5 or 4 is not enough to losslessly encode the training set”
I’m seeing lawyers and their peers in Civil Society saying stuff along the lines of: Ooh, the GPT4 bot is quoting entire NYT articles, and it’s leaving out stuff which reflects the NYT style guide which proves that it’s up to no good! …which is an understandable position to take if and only if GPT4…
-
PODCAST | Encrypting Facebook Messenger with Jon Millican and Timothy Buck
Facebook Messenger has finally been end-to-end encrypted, a couple of years after Mark Zuckerberg announced it! Plus Instagram DMs are trialing ephemeral E2EE DMs too! We invited on Jon Millican and Timothy Buck from Meta to discuss this major cross-platform endeavor, and how David Bowie fits into their personal Labyrinth. https://securitycryptographywhatever.com/2023/12/28/e2ee-fb-messenger/
-
Statement about the EU Cyber Resilience Act – Bits from Debian | …oh, this is glorious
The open source community suddenly discovers the “yes but we didn’t mean like that”-effect… https://bits.debian.org/2023/12/debian-statement-cyber-resillience-act.md.html
-
Something interesting to read: the history of iodised salt in Switzerland
Jonah Goodman · A National Evil https://www.lrb.co.uk/the-paper/v45/n23/jonah-goodman/a-national-evil
-
Okta says the quiet part out loud: the goal of (all) digital identity systems is to lock people in so that they are under control; “Lock in their loyalty,” indeed
Now: how about the European Union wanting digital national identity cards to be used to log into Facebook? Previously…
-
Am I alone in feeling that MITRE ATT&CK is essentially D&D roleplay for pentesters who can’t get the Devops team to implement ISO27001 and have just got bored?
Sarah: Alright, team, the Russian Bear is hitting us with spear-phishing. We need to fortify our email gateways. Ideas? John: Maybe implement multi-factor authentication across the board? DM: Roll for success of your MFA implementation. John rolls. DM: Great job! The Russian Bear is baffled by your strengthened defenses. Now, prepare for the Chinese Dragon.…
-
Am still bemused that when Apple undocumented hardware gets misused by the NSA people are all like “…it must be for testing” yet when I *personally* wrote one cookie-handling goof/bug on Facebook it spawned (1) conspiracy theories (2) academic white papers (3) newspaper headlines and (4) EU-wide lawsuits by Belgian privacy activists
The latter: https://securehomes.esat.kuleuven.be/~gacar/fb_tracking/ — I was not aware that I was supposed to add a new endpoint to a blocklist; as part of “lessons learned” the entire codebase was revised to use an allowlist for various forms of cookie-manipulation, instead.
-
Meet Joe Biden’s Favorite Hacker – The Messenger | …nice little biography of Dark Tangent
Also: quelle surprise: Moss no longer serves on the Homeland Security Advisory Council after failing “the political vetting that the Trump administration introduced,” he said, but two years ago, he joined the Cybersecurity and Infrastructure Security Agency (CISA)’s Cybersecurity Advisory Committee, where he leads a group that delivers policy advice from independent researchers, cyber threat…
-
Operation Triangulation: The last (hardware) mystery | …if this turns out to be an NSA-enabling backdoor, Apple’s security reputation will be toast
Our guess is that this unknown hardware feature was most likely intended to be used for debugging or testing purposes by Apple engineers or the factory, or that it was included by mistake. Because this feature is not used by the firmware, we have no idea how attackers would know how to use it. https://securelist.com/operation-triangulation-the-last-hardware-mystery/111669/