Skip Navigation

Posts
97
Comments
1,922
Joined
2 yr. ago

  • exactly, it’s not a problem that’s unique to the web. I’d argue that as an execution environment, the browser has properties that make it slightly easier to catch this class of attack (though as you said, we’re in halting problem territory so there’s no universal check for this kind of thing):

    • there’s browser plugins (for Firefox at least, I don’t care about chrome) that alert you if the JavaScript you’ve been sent has changed and provide some tools to evaluate what specifically changed
    • you can examine JS memory in depth with a variety of tools, all of which come with the browser
    • you get a running log of network requests
    • as our intrepid cypherpunk visitor noted, you can mitmproxy it if you really want to? they seem to think it’ll be too late to do anything by then but like, losing your keys to an SLA doesn’t instantly dissolve you in a vat of acid or anything. they’ve still left forensic evidence of an attack in your browser’s cache and the potential for you to catch it and make a terrible lot of noise about it, and they really didn’t need to — Proton’s security is compromised enough by entirely silent server-side cleartext leaks, metadata logging (they turn it on silently on law enforcement requests; their no-logs policy is a legal no-op), and other evil fuckery

    and I do have to emphasize that last bit. I’m not here to praise Proton, I’m here to bury it correctly. if the worst thing you’ve got to say about proton is that an SLA could request a custom JS exploit be sent to your browser, then it’s probably still a perfectly fine service to use if you’re just chatting with your grandma and your drug dealer, depending on your threat model. I’d argue that Proton isn’t suitable for anybody, because the class of attacks they’ve enabled allow for quiet mass surveillance, rather than the motivated (and loud) targeted kind.

  • and for the users at home playing the drinking game: of course this weird fuck’s been giving dangerously bad advice on privacy lemmy, why wouldn’t he be

    I ain’t gonna dig any deeper to find out if privacy Typhoid Mary over here has a uniquely bad gpg setup he loves but if anyone does: that’s another shot

    e: also lol @ coming into TechTakes with an account named after the fucking cypherpunks mailing list

  • How many of their users do you think are sufficiently paranoid?

    for fucking Proton of all things? come the fuck off it.

    the rest of your post is wrong, but in a really boring way? like, you get that there’s a bunch of ways to catch this shit but want me to do the labor of proving that it’s possible for some reason? no, fuck off, go cosplay as a privacy expert elsewhere.

  • that’s utterly trivial for a sufficiently paranoid user’s browser to detect, and damning for proton if it is (not to mention, pushing hostile JavaScript doesn’t work for users on the imap bridge or using mobile apps they update via methods that can’t easily be tracked like Obtainium on Android)

    the mechanisms proton uses to exfiltrate encrypted data and get their users arrested are far more subtle and deniable than that basic shit. specifically, they’ve been silently overcomplying with law enforcement data requests for years, which has led to documented arrests of activists, and all of their LLM features represent a significant data leak, as all of them are implemented in a way that sends cleartext to proton’s servers while maintaining the illusion that the feature is more secure than it is.

    I wouldn’t be at all surprised if they were doing more evil shit than the above, but I would be very surprised if any of it were in the form of JavaScript that the user could, you know, deobfuscate and read

  • ah right, you only care about vague consolidation in the tech industry, but will take the industry’s word at their self-reported energy usage (while they build massive datacenters and construct or reopen polluting energy sources, all specifically to scale out LLMs) and don’t care about the models being fed massive amounts of plagiarized work at great cost to independent website operators, both of which are mechanisms by which LLMs are being used as a weapon with which to consolidate the tech industry under the rule of a handful of ethically bankrupt billionaires. but it’s ok, Claude Code is a massive improvement over the garbage that came before it — and it’s still a steaming pile of shit! but I’m sure going to bat for this absolute bullshit won’t have any negative consequences at all.

    how about you fuck off, bootlicker.

  • 404media posted an article absolutely dunking on the idea of pivoting to AI, as one does:

    media executives still see AI as a business opportunity and a shiny object that they can tell investors and their staffs that they are very bullish on. They have to say this, I guess, because everything else they have tried hasn’t worked

  • I was hoping they’d get interesting so I didn’t jump on banning them, but holy shit did they ever take so much space in the thread to say fucking nothing. now I’m pruning hopefully just enough so viewers can get a taste of how much horseshit they were spewing without being tempted to take up more space continuing any of it.

  • you noticed that debate wasn’t allowed here and then turned an entire thread into a pointless fucking debate. thanks for that. fuck off.

  • it can’t be that stupid, you must be donating wrong

  • wait til you find out what the ml does stand for, it’s a real trip (and it sure as fuck ain’t Mali)

  • holy fuck please learn when to shut the fuck up

  • programmers learned what N means in statistics and immediately realized that “this N is too small” is a cool shortcut to sounding smart without reading the study, its goals, or its conclusions. and you can use it every time N is smaller than the human population on earth!

  • the reason why we’re calling AI a bubble isn’t because we think the people illegally running gas generators to power their datacenters have suddenly grown a conscience

    we’re calling it a bubble because just like with NFTs, there’s no use case for LLMs or generative AI that stands up to even mild scrutiny, but the people funneling money into this crap don’t seem to have noticed yet

  • what the numbers show is that nobody gives a shit. nobody’s paying for LLMs and nobody’s running the models locally either, because none of it has a use case. masturbating in public about how invested you are in your special local model changes none of this.

  • no, you fuckers wandered into an anti-AI community and started jacking off about local models

  • Please calm down.

    for some reason this has gotten people very worked up

    Seriously I don’t know what I said that is so controversial or hard to understand.

    I don’t know why it’s controversial here.

    imagine coming into a conversation with people you don’t fucking know, taking a swing and a miss at one of them, and then telling the other parties in the conversation that they need to calm down — about racism.

    the rest of your horseshit post is just you restating your original point. we fucking got it. and since you missed ours, here it is one more time:

    race science isn’t real. we’re under no obligation to use terms invented by racists that describe nothing. if we’re feeling particularly categorical about our racists on a given day, or pointing out that one is using the guise of race science? sure, use the term if you want.

    tone policing people who want to call a racist a racist ain’t fucking it. what in the fuck do you think you added to this conversation? what does anyone gain from your sage advice that “X is Y but Y isn’t X” when the other poster didn’t say that Y is X but instead that Y doesn’t exist?

    so yeah no I’m not calm, go fuck yourself. we don’t need anyone tone policing conversations about racism in favor of the god damn racists

  • MoreWrite @awful.systems

    an introduction to gibberish.awful.systems

    important instance shit @awful.systems

    update: email, backups, and writefreely

    TechTakes @awful.systems

    On “Safe” C++: An Odyssey of Sneers

    TechTakes @awful.systems

    Any Technology Indistinguishable From Magic is Hiding Something

    important instance shit @awful.systems

    infra: email notifications might be a bit spotty

    TechTakes @awful.systems

    the Humane AI Pin is fucked

    TechTakes @awful.systems

    Nvidia caught ingesting as much of YouTube as possible

    TechTakes @awful.systems

    404media: Leaked Documents Show Nvidia Scraping ‘A Human Lifetime’ of Videos Per Day to Train AI

    TechTakes @awful.systems

    Andreessen Horowitz and the uwuness of little technofascism

    FreeAssembly @awful.systems

    Lix: a Nix evaluator fork focused on correctness and doing right by its community

    FreeAssembly @awful.systems

    an open letter to the NixOS foundation

    TechTakes @awful.systems

    the tea protocol is still predictably a gigantic source of PR spam

    FreeAssembly @awful.systems

    thread your Philthy feature requests

    FreeAssembly @awful.systems

    ask me questions about awful.systems or NixOS!

    FreeAssembly @awful.systems

    the r/SneerClub archive welcomes contributions

    FreeAssembly @awful.systems

    Philthy, the awful.systems fork of Lemmy, is seeking contributors

    FreeAssembly @awful.systems

    welcome to FreeAssembly: a non-toxic collaborative community

    TechTakes @awful.systems

    Amazon’s 'Just Walk Out' grocery stores are dead

    important instance shit @awful.systems

    flag any spam you see from lemmy.world (or elsewhere)

    NotAwfulTech @awful.systems

    the Amaranth hardware description language