jj4211

joined 3 years ago
[–] jj4211@lemmy.world 8 points 1 hour ago (1 children)

If you've seen a typical GenAI pull request, it's blatantly obvious. If it has been curated well, sure it's probably not feasible to know, but "slop" is easy to tell, and the target users have very slop contributions.

[–] jj4211@lemmy.world 11 points 1 hour ago

If you can tell it is AI generated, then it's going to be more trouble than it is worth.

Note "substantially" AI generated. If you've been paying attention to popular open source projects you've seen the sort of "contributions" and of course they should be dismissed.

If you have had generally good experience with GenAI, think not of your direct experience, but rather your experience with how others have used it, and that's more representative of the issues.

[–] jj4211@lemmy.world 25 points 1 day ago

One thing is that in early days they hadn't really sorted out the full potential of manipulating online interactions yet. So we got to enjoy connection with relatively less active manipulation.

[–] jj4211@lemmy.world 7 points 1 day ago (2 children)

Forget number 1s, what was your mother's maiden name?

[–] jj4211@lemmy.world 6 points 1 day ago

Really sucked after Michael Jackson did a knock off of one of his songs...

[–] jj4211@lemmy.world 4 points 1 day ago

If the school picked Hot for Teacher to play on behalf of the students that would be... Something.

[–] jj4211@lemmy.world 3 points 1 day ago

Yes, that's a very very basic negotiation strategy, anyone who has even heard of a car being sold knows that super basic thing.

However the Greenland situation is more like going to Walmart and demanding they give you a PS5 for free, and then Walmart saying "you can have it for $599" and then declaring "victory" because you never expected it for free, but you got the price you wanted. Except $599 is the list price and you didn't have to every make a stink about wanting it for free.

Trump was never that 'great' at this sort of thing, but his old age has eroded his ability to have any sort of filter that would facilitate even trying to play things close to the vest. What he says is what he thinks, more plainly than ever.

[–] jj4211@lemmy.world 1 points 1 day ago

I certainly think it's risky (it goes without saying that it is also wrong). With Venezuela, it seemed you had a regime and populace that, fundamentally, were maybe mildly disapproving of US, but the regime was, in their hearts, pretty comfortable with corrupt arrangements and the Trump administration fits right in with those arrangements. Even an interview with one of the folks the regime unjustly imprisoned seemed at peace with the regime being intact, with a fairly "this sort of corruption is just the way the world works" attitude toward the whole thing.

The Cuban people have endured decades of the US working to actively screw them over, and may be less 'pragmatic' about the best way forward even if it means accepting wrong being done and may be more ideologically engaged to recipricate, even if it is likely not going to be a 'win', but at least make the US hurt for what they do.

[–] jj4211@lemmy.world 3 points 1 day ago

In an ideal world, they would be using TLS with a properly set up CA even for internal.

In practice, I can't get most of them to do that, and instead they just click through the certificate warning and use it over https, but without certificate assurance.

So it's still over https, though a fair argument can be made that hardly matters if the certificates aren't validated, and browser ecosystem doesn't consider 'TOFU' a valid approach like it generally is for SSH.

Anyway, the point is that passkeys are 'security' by virtue of not ever divulging the secret on the line. They can't be sniffed, they can't be captured by phishing, they can't be retained for later use after a MITM. So the refusal to operate even with informed user consent means the user just uses a password, which is weak to all those things. In a scenario where it could provide the most mitigation is a scenario where the browsers refuse to let it try. Even the built in password manager will still auto-fill without certificate validation, one of the most risky places to be 'helpful'.

[–] jj4211@lemmy.world 7 points 1 day ago (4 children)

One complaint I have is browser insistence that a site must have a proper certificate to work at all.

I provide self hosted software with passkey support and probably over 90 percent of my users never set up property certificates due their private networks. So the passkey function is impossible for them.

Which means they must use passwords. Which are far worse in this scenario. The practical risk either way is arguably low for them, but to take a more mitm/phishing resistant technique and then force it to not work because mitm or phishing might be in play...

[–] jj4211@lemmy.world 4 points 1 day ago (3 children)

One complaint I have is browser insistence that a site must have a proper certificate to work at all.

I provide self hosted software with passkey support and probably over 90 percent of my users never set up property certificates due their private networks. So the passkey function is impossible for them.

Which means they must use passwords. Which are far worse in this scenario. The practical risk either way is arguably low for them, but to take a more mitm/phishing resistant technique and then force it to not work because mitm or phishing might be in play...

[–] jj4211@lemmy.world 2 points 1 day ago

If SQRL was adopted, then the popular manifestations would have just as much vendor lockin, with built in password managers hosting the master private key without export option.

Passkey is not inherently vendor lock in. It's mostly a consequence of password managers doing software passkeys and not making it reasonable to export private keys. It does have a mechanism a site can use to lock to "trusted vendors", but if a site does that, that is on them for being dickish.

view more: next ›