umami_wasbi

joined 2 years ago
[–] [email protected] 2 points 19 hours ago* (last edited 12 hours ago) (1 children)

DLP broken? Didn't heard of that.

[–] [email protected] 3 points 20 hours ago (3 children)

I think he means something like challenge-response type of auth flow that while using user/pass, the password waa never sent to the server?

[–] [email protected] 1 points 3 days ago

True. It is just another avenue to label things.

[–] [email protected] 2 points 4 days ago* (last edited 4 days ago)

Please allow me to have a little bit of time deep thoughts and organize myself. It might take a while, but I will give you a response.

[–] [email protected] 2 points 4 days ago* (last edited 4 days ago)

And the lack of label just reinforced the confirmation bias.

[–] [email protected] 4 points 4 days ago* (last edited 4 days ago) (2 children)

The problem is you can't make a digital label that hard to circumvent. Much like a signature, you sign something you want to prove it is genuinely from you, but you won't sign something that's not from you while not signing things that are, especially in digital format. Digital signature can just be stripped out of the data. Watermarks on images can now patched with the help of inpainting models. Disclaimers in text can just be deleted. The default shouldn't be "This thing doesn't have an AI label so it would be written by human." The label itself it a slippery slope that helps misinformation spread faster and aid building alternate facts. Adding a label won't help people identify contents generated with ML models, but let them defer the identification to that mere label because it said so, or didn't.

Misinformation didn't spread fast simply because fascists obtained controls on medias. Just look at how China, Russia, and Iran launch misinformation campaigns. They didn't have to control those media, but some seed accounts that make sensational title that attracts people in more powerful position and recognition to spread it out. For more info on misinformation and disinformation, I recommend you watch Ryan McBeth's video on YT.

Yes, we need a way to identify what is and what not generated by ML models, but that should not be done by labeling ML contents.

[–] [email protected] 9 points 4 days ago* (last edited 4 days ago) (4 children)

Then what AI generated slop without label are to the plain eyes? That label just encourge the laziness of the brain as an "easy filter." Those slop without label just evelated itself to be somewhat real, becuase the label exist exploiting the laziness.

Before you said some AI slop are clearly identifiable, you can't rule out everyone can, and every piece are that identifiable. And for those images that looks a little unrealistic, just decrease the resolution to very grainy and hide those details. That will work 9 out of 10. You can't rule out that 0.1% content that pass sanity check can't do 99.9% damage.

After all, human are emotional creatures, and sansationism is real. The urge of share something emotional is why misinformation and disinformation are so common these days. People will overlook details when the urge hits.

Somethimes, labeling can do more harm than good. It just give a false sense.

[–] [email protected] 3 points 4 days ago (2 children)

That's a different thing. C2PA is proving a photo is came from a real camera, with all the editing trails. All in a cryptographic manner. This in the topic is trying to prove what not real is not real, by self claiming. You can add the watermark, remove it, add another watermark of another AI, or whatever you want. You can just forge it outright because I didn't see cryptographic proof like a digital sign is required.

Btw, the C2PA data can be stripped if you know how, just like any watermarks and digital signatures.

[–] [email protected] 41 points 4 days ago* (last edited 4 days ago) (6 children)

Think a layer deeper how can it misused to control naratives.

You read some wild allegation, no AI marks (they required to be visible), so must written by someone? Right? What if someone, even the government jumps out as said someone use an illiegal AI to generate the text? The questioning of the matter will suddently from verifying if the allegation decribed happened, to if it itself is real. The public sentiment will likely overwhelmed by "Is this fakenews?" or "Is the allegation true?" Compound that with trusted entities, discrediting anything become easier.

Give you a real example. Before Covid spread globally there was a Chinese whistleblower, worked in the hospital and get infected. He posted a video online about how bad it was, and quickly got taken down by the government. What if it happened today with the regulation in full force? Government can claim it is AI generated. The whistleblower doesn't exist. Nor the content is real. 3 days later, they arrested a guy, claiming he spread fakenews using AI. They already have a very efficient way to control naratives, and this piece of garbage just give them an express way.

You though that only a China thing? No, every entities including governments are watching, especially the self-claimed friend of Putin and Xi, and the absolute free speech lover. Don't think it is too far to reach you yet.

[–] [email protected] 24 points 4 days ago* (last edited 4 days ago) (2 children)

That's what they want. When people doing it locally, they can discredit anything as AI generated. The point isn't about enforability, but can it be a tool to control narative.

Edit: it doesn't matter if people actually generating locally, but if people can possibly doing it. As long as it is plausible, the argument stands and the loop completes.

[–] [email protected] 6 points 4 days ago* (last edited 4 days ago)

Lol. So everything and anything can just be AI generated fakenews.

[–] [email protected] 20 points 5 days ago* (last edited 5 days ago) (4 children)

Looking at linuxserver/jackett on Docker Hub, it seems it indeed update everyday.

 

I'm using Proton right now. Someone suggest I should get a Gmail instead for higher chance of success. Is that true? How risky is it for Google sanning those mails in terms of privacy?

107
Orbit by Mozilla (orbitbymozilla.com)
submitted 2 months ago* (last edited 2 months ago) by [email protected] to c/[email protected]
 

New Mozilla AI project. Put "trust" and "privacy" in the title and subtile but doesn't support locally hosted model.

Exists as an add-on today. Model is Mistral 7B hosted by Mozilla in GCP. Claims won't save data long term. Promises won't use personal information to train models and not share queries with Mistral or any other services.

Am I going to use it? No. Not without local model supported.

Note: the mobile version of the page is broken (lack of many content). Best to view the desktop version for complete details.

60
submitted 3 months ago* (last edited 3 months ago) by [email protected] to c/[email protected]
 

I heard a friend from my Chinese community that Samsung and Kioxia are reducing production of NAND chips to hike SSD price. Samsung and WD SSD in Amazon UK are quite sold out.

Can anyone confirm this?

EDIT: Related Chinese news from HKEPC https://www.hkepc.com/23015/%E5%82%B3%E4%B8%89%E6%98%9F%E9%8E%A7%E4%BF%A0_NAND_%E8%A8%88%E5%8A%83%E6%B8%9B%E7%94%A2_%E4%BB%A5%E9%98%BB%E6%AD%A2%E5%83%B9%E6%A0%BC%E4%B8%8B%E8%B7%8C___%E7%94%9A%E8%87%B3%E6%89%AD%E8%BD%89%E8%B6%A8%E5%8B%A2

EDIT 2: Add English source

Original title: Kioxia Reportedly Planning Production Cuts Amid NAND Flash Market Challenges

 

(Rant)

At somepoint, HSBC decided KDE Connect installed via F-Droid is less secure.

Photo of the HSBC UK app urging I install KDE Connect via GPlay or Galaxy Store

Then it decide non-whitelisted keyborads are a security risk. Only Gboard and Samsung Keyboard is confirmed within the whitelist.

Photo of the HSBC UK app telling me to switch input method citing security risk


I understand the point that risk can be introduce at various points, yet this is simply too much. Yeah there are people phone infected by malware but from Play Store. Not a single time I heard one ever happened on F-Droid distributed apps, at least not from the official repo. Also, I will put more trust on an open source keyboard than any proprietary keyboard.

Furthermore, I'm shocked that an app can read my app list, and current keyboard (introduced in Android 14). This just make building a profile much easier as I belive everyone almost have an unique set of apps they like. I don't think any apps need such functionality. Why the f it needs to care what input devices I uses? This make me worry more about untold (aka burried deep in Privacy Policy) data collection.

 

How come this wasn't getting more attention?

 

There are reports in Registar's comment section that Malaysia didn't only redirect DNS traffic, but took active measures to block VPN, and MITM DoH where Cloudflare's DoH returns local ISP certificate.

In fact, some ISPs like Maxis and Yes were already blocking VPN (I see a lot of complains on Lowyat.net about Maxis blocking VPN, and I was using Yes WiMax and experienced the blocking firsthand. I couldn't connect to PPTP endpoints and L2TP endpoints caused the modem to disconnect from the network and reboot).

They were outright trying a MITM redirect attack on those using DOH. Many reported error messages saying that Cloudflare's DOH server were practically returning the certificate for Telekom Malaysia's DNS servers.

Even with many new technologies, I ralized that I not as safe and free as I want to be, maybe you too.

 

If $70 +$10/mo can get me through all those annoying CAPCHAs, I will gladly pay. Of course, if cheaper or even free solutions exists, I will use it. My only requirement is it work 90%+ of the time.

1
submitted 7 months ago* (last edited 7 months ago) by [email protected] to c/[email protected]
 

I want to check if my Lenovo T480 is afftected by the recent PKFail, but have no idea how to extract the bios firmware for validation. Can someone detail the steps? Thanks.

42
submitted 8 months ago* (last edited 8 months ago) by [email protected] to c/[email protected]
 

Just wonder what if my mail server went offline for some periods, and the sending party couldn't deliver.

Will there be any consequences except I don't get the mail? I tried searching but they all in the perspective of a sender and get a bounce, rather the other way around.

21
submitted 8 months ago* (last edited 8 months ago) by [email protected] to c/[email protected]
 

Saw they have promotion £1/mo without setup when paid for a 12mo contract for the lowest end VPS. Anyone use it before?

Just planning to run frp on it. https://github.com/fatedier/frp

view more: next ›