No, it doesn't have to be associated with the phone, and IMO you are better off not letting the big tech companies own your identity, which is effectively getting Apple or Google to store it in your phone for you ends up being. There are physical passkeys that feel like a door key in everyday use. You can attach them to your house key ring, and like house keys are near indestructible. Lookup the Yubikey 5 NFC.
The only downside is unlike a house key, you can't get a backup "cut". Copying a physical passkey currently isn't possible. If you lose it, you've lost access to all your logins. As the article says, their recommended workaround is to keep backup physical passkeys, and log all your passkeys (including the backups) into every site. Which is insane - very few people have the patience to do that.
The article is really a long rant about that one issue - there is currently no way to securely backup a physical passkey. Solve that, and all the other issues melt away.
> I purchased a "perpetual" license for Office 2019
My, memories are short. In 2008 Microsoft "Play for Sure" became play no more. Exactly the same stunt, 11 years before you bought that perpetual licence. Why anybody trusted the company after Play For Sure was a mystery to me.
And that was just the beginning. Then came Sony being ripped a new one, Azure being taken down by expired certs - twice in 6 months, critical certs signed with MD5 until it's so weak they were exploited, more recently China running rampant in hosted exchange scraping state secrets, GitHub with record down time, and Windows has become a dog slow ad platform. And yet today Microsoft makes the most revenue than any other software firm.
I dunno how they do it. After decades of treating their customers like shit, business has never been so good. They must have one mother of a sales team.
Also, the inability to have older software installed with newer software because of the installer type. e.g. Visio 2019 and Office 365 suite cannot coexist.
I heard the novel term "Golf Driven Development" the other day. Essentially it's where software/services aren't sold because people wanted or asked for them, they're sold because one CEO played golf with another CEO (with the express purpose of making this happen).
Salesforce, Microsoft, Atlassian, and co. are obviously sold on their merits.
FPTP isn't wonderful but for those of us looking on for outside the tolerance of gerrymander, deliberate disenfranchisement of some voters and letting corporations spend unlimited amounts of money on getting political outcomes ranks higher. FPTP is merely a bad choice. The others look more like a country deliberately eschewing democracy for something else.
That's wrong thing to try and understand. We don't have to accept anybody. As Howard said, "We will decide who comes to this country and the circumstances in which they come". And he achieved that. He also orchestrated the biggest proportional uptick in immigration the country has seen this or last century.
Immigration was never driven by people trying escaping India. The issue is our politicians invited them in with open arms. The irony is the very same politicians from the conservative side were pushing their "big Australia" agenda while at the same time noisily ranting against "illegal immigration" with emotive terms like "children overboard".
If you thought Howard was against immigration, you were sucked in by his outright deceptive tactics. He was the biggest immigration proponent I've seen in my lifetime. I'd give it a 50/50 chance of it working out the same way for One Nation. Their core supporters are rural and the elderly. Both are highly dependent on immigrant workers.
The right framing isn't "people escaping India", but rather how many and what type of immigrants the pollies want - because that is what determines what we get. Any politician who tells you otherwise is bullshitting you. Illegal immigration never made much of an impression on the real immigration figures.
He used LOC, and it isn't bad. Just this week I had a LLM do a small task, and it produced 500 LOC, every little detail beautifully abstracted out. But 500 LOC for such a simple change looked suspicious to me. As everything must pass human review, I re-wrote it to see what happened. The result was 100 LOC. No human wants to review 5 times a much code.
The issue really isn't "there is no good metric" - when I saw 100 LOC vs 500 LOC for the same thing there was no argument. The problem is Goodhart's Law. Whenever we use a metric use like LOC as a reward function for humans, the result is a disaster. I have no doubt that's true for LLM's too.
> if it takes humans a month to find out something has been happening at all,
That time is more reflective of the security posture of OpenAI than "humans" in general. Alibaba had a similar incident. Their internal networking team picked it up fairly quickly:
I get the impression OpenAI eat their own dog food when building their infrastructure, so they aren't completely across the unimportant messy details. It's entirely possible the configuration was generated and reviewed by AI's, so no human has ever set eyes on it. I suspect that hasn't been a huge issue (apart from the bit where OpenAI said the kubernetes configuration was overpermissioned) so far. It may become a big issue when the AI's creating those configurations see those message boards.
Anothropic is clearly no better, as they attacked three organisations, only noticing weeks later after the Hugging Face incident caused them to look at their logs.
We do have protocols for containing dangerous things - like the BSL-4 standard for bio labs. The irony is OpenAI and Anothropic have been hyping how powerful and dangerous their products for ages now in order to pump their IPO valuations. Apparently they weren't treating their own hype as serious. If they did, they would have detected these outbreaks when they happened, not a month or two later.
Right now, they are looking like opsec cowboys, probably vibe coding opsec cowboys.
Given the inequality in the USA, it would be more relevant to the rest of the world if he used the mode instead of the median. The mode is what most of the population gets to experience. In most OECD countries, the mode and median are a closer than the USA, so the median is a better approximation of the mode. Comparing the USA's median to their daily experience is a little misleading, the mode would be less so.
It definitely steers. For example if it suggests travel plans, the booking links it provides give Alphabet a cut.
As you say it was subtle, along the lines of "oh, if you are planning on going to the place you are researching, here are some helpful links to places you can stay". Subtle, in that it didn't get in the way of main result, so I didn't mind overly. Insidious, as I only noticed because I wondered why it was providing those particular links and looked them up. I can't see how you could ad-block them if I did object.
And worrying, because these unblockable sneaky ads are just a first foray coming from a company that prostitutes its own app store searches, by making the first and most obvious result utterly unrelated to to the search topic. Instead it's who paid them the most to be there. That behaviour is why everyone dumped Alta Vista when an alternative came along. Alternative Android app stores can't come soon enough.
They already skim off 15% of purchases which I'm sure makes their Android operation return a profit that makes other industries drool. Debasing their search to ad a tiny bit extra on top must by driven pure greed. Senseless, as I'm sure it will come back to bite them in the end.
It's not hard to test. Go to a page that demands PoW, change your IP and see what happens. I just did it. Spoiler: kernel.org asks for a new PoW.
If the source IP was an issue, you could do it other ways: for example, make the cookie rotate on every access, and insist there is a single stream of accesses.
The only downside is unlike a house key, you can't get a backup "cut". Copying a physical passkey currently isn't possible. If you lose it, you've lost access to all your logins. As the article says, their recommended workaround is to keep backup physical passkeys, and log all your passkeys (including the backups) into every site. Which is insane - very few people have the patience to do that.
The article is really a long rant about that one issue - there is currently no way to securely backup a physical passkey. Solve that, and all the other issues melt away.
reply