Actually it has been for a couple of weeks. I've had a pretty bad case of blogger burnout - there's been a number of blog worthy topics and I just haven't been feeling it.
Meh.
Still, 14425 posts and 54948 comments is pretty decent. Especially the comments.
The nature of the problem (I think)
is that the attempts at safety reflect the behavior of the people who programmed and trained
the AI engines, and they are apparently snarky, obnoxious twits that think its better to argue
about meta issues than to serve their customers, like me, with the real capabilities they have
developed.
Their version of safety is the opposite of mine. If you want children to be safe from AI, don’t let
them use it.
If you want adults to be safe from AI, don’t make it available.
If you want a ship to be safe, don’t put it out to sea… but that’s not what ships are for.
We trade the utility for the safety, and while making ships that leak like a sieve is a bad idea in
my view, making ships that don’t sail is a fruitless effort.
...
Solution
The solution is to put someone in charge of these mechanisms in these companies who is not
a snarky, obnoxious twit… and I hope this doesn’t exclude me from the candidate pool.
There are also some rather direct solutions to the problem of providing information to people
where the information is not something that should be provided to anybody as a matter of
policy. The most obvious solution is not to incorporate any of that sort of policy-violating
information in the learning process.
Of course the snarkiness is the same problem. If you don’t teach the LLM to be snarky by
feeding it snarky crap, it will probably not behave that way. It’s no different than a child
brought up by respectful parents vs. disrespectful parents. They learn from their teachers.
Conclusions
If you don’t want trouble, stop asking for it. If you teach a dog to bite, you are unlikely to be
successful at later telling it not to. If you train an LLM with views of pedophiles, fraudsters,
and murderers, you are unlikely to get it to not carry that behavior through later on.
I think that Fred's entirely correct here (note that we ignore the very serious problem of AI Hallucinations here). AI training is generally crap layered on top of the hallucination engine*.
But I wonder if this is an opportunity for AI companies? If you did a better job training the AI to be well-behaved (like you'd do with your kids or your dogs) would you have a different - and more attractive AI offer? How about politeand wellbehavedAI.com? That's a branding that would stand out from all the others. You could market it to parents worried about their kids, or to old fuddy-duddies like me who hate everything about AI?
I smell a billion dollars of venture capital here ...
* It seems very likely that the AI algorithms cannot be prevented from hallucinating.
This post is the fourth in a series on how to make your home network harder to attack. Here are links to posts one, two, and three.
Now you might think the question in the post title is a bit strange - after all, these are you devices, so you'd think that they're all trustworthy. You'd be wrong. There are at a minimum two different categories of trustworthiness:
Your main computing devices. These are computers (duh) such as laptops and desktop computers, servers (a future post will talk about why these can be useful to you, and your cell phones (which are nothing but tiny hand held computers).
Now I've been in security for long enough that I get a bit twitchy about mobile phone security (I'll address this in a future post as well). However, that ship has sailed and even a security nerd like me won't bother making a separate network just for these. So they're computing devices for this discussion.
Then there's everything else. It's surprising how any Internet-connected thingies there are these days. Ring doorbells, Nest thermostats, online appliances (fridges, washing machines, etc). At this point the Borepatch from four years ago would have told you to just walk away from all this nonsense. Don't Internet-enable anything in this category.
Today's Borepatch sighs and tells you that this is coming to a home near yours. It's here in my home. No, not the thermostat (which was installed by the previous owner and which I have not connected to the WiFi). However, the TVs all come with streaming apps for Netflix, Prime, and Youtube (among dozens of others). And The Queen Of The World reminds me that the kids like to stream when they come and visit. She likes it when they come and visit, as do I. And so we have to do something for these devices.
Fortunately, you don't need any new kit to do this. If you remember from the last post on water tight compartments, you don't own the Internet box from your network provider. Basically, you can't trust it, so you install a new firewall box running DD-WRT. It's trustworthy because you own it and have your own software and configuration on it.
All of your main computing devices connect to it's WiFi. All of the other devices (doorbells, thermostats, TVs, appliances) connect to the WiFi from your network provider's box.
What you've done is to put a firewall between your computing devices and your untrusted devices. It doesn't matter if your TV gets hacked because it can't get through your DD-WRT firewall to your computers.
Likewise, your TV is at least somewhat protected from the outside world because it's behind the firewall in your network provider's box.
I dunno - he looks a little Woodrow Wilsonish to me. But if you're right, you're right.
And Nota Bene: it seems that DuckDuckGo can't find the link to that last post. Strangely, Google can. Search sting site:borepatch.blogspot.com best worst presidents on each site. So long, DuckDuckGo, it's been fun. But I can't trust you, and neither should my readers.
This post is the third in a series on how to make your home network harder to attack. Here are links to posts one and two.
Post two introduces the concept of a Firewall which is a device that lets you connect to the Internet without letting the Internet connect to you. Firewall technology comes embedded in your Internet provider's device like a Cable TV modem. A recent article does a comparison on a number of these devices.
If you look at the device it will look a lot like this:
The red colored connection goes out to the Internet, the yellow ones go to your devices (as does the Wifi). This one has a connection for a landline telephone as well (ask your parents, kids).
Installing the device is really simple - red (labeled "WAN") goes to the outside which is untrusted, and yellow/WiFi go to your own devices which are trusted.
Except nothing is as simple as that. Your Internet provider actually owns the firewall device, it's not really yours. Some providers run their own WiFi network for other subscribers who happen to be passing by - Verizon is notorious for this, and you will often find all sorts of WiFi networks called "VerizonXYZ" or some such.
So who is outside the firewall, and who is inside? The question may sound pedantic but it's terribly important. Fortunately there is something you can do about this.
Ships used to sink all the time but this is pretty rare these days. One major reason for this is that they are divided into compartments which are watertight - if the ship hits a rock (or, like the Andrea Doria gets rammed by another ship) only one compartment will flood and the ship can likely make it to port.
USS South Dakota under construction
The network security analog of this idea is to use more than one firewall. Don't trust your provider's firewall? (and you really shouldn't) Buy your own and hook it up to your provider's firewall. The red (WAN) port on your firewall gets connected to the internal (yellow) connector on the provider firewall. Now anyone that the firewall lets in can't get past your firewall.
And it really is your firewall, although you'll have to buy it with cash money. But your devices connect to your firewall's yellow network connections, or to your firewall's (NOT your provider's firewall) WiFi.
Now you don't have to trust your provider because their device doesn't have access to your internal "watertight compartment".
Linksys, Netgear, and TP-Link are low cost options, running $30 - $70 or so.
The first thing you should do is replace your firewall's operating system with dd-wrt:
DD-WRT is a Linux based alternative OpenSource firmware suitable for a great variety of WLAN routers and embedded systems. The main emphasis lies on providing the easiest possible handling while at the same time supporting a great number of functionalities within the framework of the respective hardware platform used.
Here's a step by step tutorial on how to install dd-wrt on a Netgear device:
[UPDATE: Rick T in the comments says to check the dd-wrt website before buying a device, to make sure that the software supports that particular hardware.]
Why go to this hassle? Product longevity. Consider a $60 Netgear device. The profit margin on this to Netgear is probably $5. You can't pay for a lot of enhancements or security bug fixes with that. DD-wrt is an open source project with a bunch of passionate contributors. I like my chances on having a viable, supported software five years down the road with them. Not so much the device manufacturers.
So now you have a device you can trust for the long term. We're not done yet, because there's all sorts of new tech evil that people want to use - Ring doorbells, Alexa, etc. That's tomorrow.
Forget about the Internet and security for a moment - you already own something with a firewall. Your car has one between the engine and the passenger compartment, even if your car isn't a sweet 1969 Dodge Charger.
The firewall in your car is designed to contain engine fires to the engine compartment, not letting the flames spread to the passengers. Firewalls have been around cars for a long, long time - certainly since the 1930s, and probably a lot longer.
Now back to the Internet and security. Internet firewalls are designed to keep bad things (and Bad Guys) out of your network, so they don't burn down all your devices. Yes, I stretched that metaphor, but that's exactly where the name came from.
An old Internet wag once described a firewall as a device that "keeps the bad guys out while letting the good guys out". That's a really good description. Internet firewalls have been around for basically as long as there has been an Internet, say from around 1990. The technology is very well understood, and very mature. That's the good news.
The bad news is that there are a million ways to set up your firewall so it's more full of holes than Swiss cheese. This post will try to help you avoid this.
More good news: your Internet Provider almost certainly has a firewall capability in hte box that gives you Internet access. For example, if you get Internet via cable TV, you have not only a cable box that changes channels, you have a separate box that gives Internet. That thing has a firewall built in, so yay.
You an check this yourself via a web site that I've linked to a number of times over the years, Steve Gibson's Gibson Research. You should see something that looks like this:
Green is good.
So what went on when you ran that? There are a bunch of Internet services like web, email, and so on. Each uses a "port" - email is 25, web is 80, there are a bunch of others. What Gibson's app did was to try to connect to all of these posts on your IP address. Ideally, your firewall (like mine) dropped these connections in the trash can.
So from a first cut, your firewall is letting you out onto the Internet (so you can read this, hello!) but keeping the Bad Guys out.
But the devil is in the details of how we (and our devices) use the Internet. The next post in this series will explore this: Secure Your Home Network: Can (and should) you trust your devices?
This was the best year ever for traffic here: 4.5M page views. This brings the all-time total to 19.5M. There's quite a market for free Internet blather.
And this year's over 1000 comments from you is (I think) also a record. Many thanks to everyone who keeps coming by and especially for commenters.
17 years ago I put up my first post here. Around the same time, ASM826 - my brother from another mother - put up his first post on his blog, Random Acts Of Patriotism.
17 years later, we are still here. I almost hung up my blogging shoes but realized that the world needed Dad Jokes. Err, or something.
And ASM826 is still here, too. And a lonely place it would be, too, without him. We both need to do more firearms related posts. Range Reports, that sort of stuff. I shall endeavour to improve my output here.
It's weird that in another year, this blog would be old enough to vote.
Dude, you've been coming around here for a long time asking to get added to the blog roll. And when I do add you, you don't seem to notice: not four months after that first link you're back in the comments asking to get blogrolled even though you were already there.
This has been your unique approach to blogging for 15 years. Weird.
Actually, it's gotten worse. You've left twolinks in two days about something entirely unrelated to my posts, pointing to a post on your site. That's comment spam. I see that you have ads on your site, so I guess that's why. It doesn't seem that you added me to your blogroll, so reciprocal blog back scratching doesn't seem to be your thing.
Commen Sense, you are not welcome here, because you don't have any manners. All your comments will be deleted in the future because you are trying to hijack my site. Not cool.
Oracle engineers mistakenly triggered a five-day software outage at a number of Community Health Systems hospitals, causing the facilities to temporarily return to paper-based patient records.
CHS told CNBC that the outage involving Oracle Health, the company’s electronic health record (EHR) system, affected “several” hospitals, leading them to activate “downtime procedures.” Trade publication Becker’s Hospital Review reported that 45 hospitals were hit.
The outage began on April 23, after engineers conducting maintenance work mistakenly deleted critical storage connected to a key database, a CHS spokesperson said in a statement. The outage was resolved on Monday, and was not related to a cyberattack or other security incident.
Everything is "cloud" these days. Having worked in cloud for a decade, it's really really hard to get good reliability. The best vendors promise "Five Nines" reliability, i.e. uptime of 99.999%. The very best vendors have compensation clauses in their contracts and pay penalties to customers when they don't meet the uptime agreement.
Five Nines means that you will have no more than five minutes of downtime in a year. Like I said, this is really hard stuff.
Oracle Health had this customer down for five days. This translates to less than 99% uptime - probably 98.5%. Not a good look for a cloud provider.
Even worse, this isn't the first problem for Oracle Health. Oracle Health's Federal cloud went down for a day last month, taking 6 VA Hospitals and 26 clinics with them.
If you're in IT and looking at cloud services (and why wouldn't you?), pay special attention to the Service Level Agreements. SLAs with penalty clauses mean that the vendor is serious about reliability.
A bipartisan, bicameral pair of lawmakers urged newly confirmed Director of National Intelligence Tulsi Gabbard to reevaluate U.S. cybersecurity and intelligence-sharing relations with the United Kingdom in response to a report revealing that the UK secretly ordered Apple to build a backdoor into encrypted iCloud backups.
The Feb. 7 report from the Washington Post says that the order issued last month demands UK law enforcement and intelligence operatives be granted worldwide, unfettered access to users’ protected cloud data. Apple customers residing in the United States would be cast into that dragnet.
Sen. Ron Wyden, D-Ore., and Rep. Andy Biggs, R-Ariz., asked Gabbard in the Thursday missive if the Trump administration was made aware of the order by stakeholders and whether the White House has understanding of the CLOUD Act, which lets U.S. law enforcement get data stored by American tech companies, even if that data is on servers outside the U.S., by using warrants or subpoenas.
“If Apple is forced to build a backdoor in its products, that backdoor will end up in Americans’ phones, tablets, and computers, undermining the security of Americans’ data, as well as of the countless federal, state and local government agencies that entrust sensitive data to Apple products,” they wrote in their letter to Gabbard.
Remember, Encryption Backdoors are a Very Bad Idea. It's not just me saying this, it's the former Director of the UK's GCHQ (their NSA equivalent).
And well done to Congresscritters from both parties in both the House and Senate for putting some pressure on the idiots in Blimey.
Ulbricht was the guy who set up the "Dark Web" site The Silk Road. I am a little conflicted about this.
On the one hand, he made money on each drug deal that went through his site. There's no question that this was dirty money.
On the other hand, his 2 life sentences without the possibility of parole was hideously excessive. People have pointed out (rightly) that drug dealers convicted of using the site to sell their wares got much less time.
And on the gripping hand, a place where people can spend their money without the 24/7 government surveillance of everything sure seemed like it was a good thing.
I wonder if Trump would have issued the pardon if he hadn't been railroaded through the legal system himself. All in all, the "Justice system" here has taken a huge credibility hit.
For the longest time much of the media has fed us the idea that “union = overpaid/lazy/bad”. Now we should all have the following ingrained in our skulls by now, “the media lies”.
Proceeding from that “law” (it really should be a scientific law at this point) we can deduce that the media is lying about unions. The real question to ask ourselves is, “why?”
So their live streaming of the Mike Tyson fight last night was an unmitigated disaster. But come on - you'd think that Netflix IT would understand how to spin up capacity to meet demand. Maybe their replacements will.
For those who like the Sweet Science (or who used to), this is a fascinating episode from Hard Core History about how boxing has changed over time, mostly for the worse. Dan Carlin interviews Mike Silver, author of The Arc of Boxing which is a terrific read. I'm in general agreement with both the podcast and the book, although have to admit that I quite enjoyed the Barrios/Ramos bout last night. It had a very Friday Night Fights feel to it.
Millions of Kaiser Permanente patients' data was likely handed over to Google, Microsoft Bing, X/Twitter, and other third-parties, according to the American healthcare giant.
Kaiser told The Register it has started notifying 13.4 million current and former members and patients that "certain online technologies, previously installed on its websites and mobile applications, may have transmitted personal information to third-party vendors," when customers used its websites and mobile applications.
Kaiser has since removed that tech from its websites and apps, and said it is not aware of "any misuse of any member's or patient's personal information."
Yeah, I'll bet.
If you get Kaiser Permanente insurance at work, you might want to ask your HR department for an assessment of whether your data was included in this data sharing scheme. It's hard to see how at the minimum HIPAA-adjacent data was not shared here.
The FTC today announced it would be sending refunds totaling $5.6 million to Ring customers, paid from the Amazon subsidiary's coffers.
The windfall stems from allegations made by the US watchdog that folks could have been, and were, spied upon by cybercriminals and rogue Ring workers via their Ring home security cameras.
The regulator last year accused Ring of sloppy privacy protections that allowed the aforementioned spying to occur or potentially occur.
...
In the most egregious case, one employee went out of his way to view "thousands of video recordings belonging to at least 81 unique female users," according to the FTC. A coworker reported this behavior to her supervisor, who it's alleged initially said this snooping wasn't that strange until he realized the rogue employee was only reviewing videos of "pretty girls."
The fines work out to $50 per effected Ring customer. Don't spend it all in one place.
A misconfigured MediaWiki web server allowed digital snoops to access members' resumes containing their personal details at the Open Web Application Security Project (OWASP) Foundation.
...
"If you were an OWASP member from 2006 to around 2014 and provided your resume as part of joining OWASP, we advise assuming your resume was part of this breach," OWASP said in a Good Friday notification posted on its website.
"We recognize the significance of this breach, especially considering the OWASP Foundation's emphasis on cybersecurity," it added.
Yup. This shows just how hard security is - OWASP is full to the brim with folks who (a) understand the importance of security, (b) know how to implement security (well, most of the time), and (c) have a lot of reputation at stake. That reputation took a hit here.
Protecting your privacy online is hard. So hard, in fact, that even a top Israeli spy who managed to stay incognito for 20 years has found himself exposed after one basic error.
The spy is named Yossi Sariel allegedly heads Israel's Unit 8200 – a team of crack infosec experts comparable to the USA’s National Security Agency or the UK’s Government Communications Headquarters. Now he's been confirmed as the author of a 2021 book titled "The Human Machine Team" about the intelligence benefits of pairing human agents with advanced AI.
Sariel – who wrote the book under the oh-so-anonymous pen name “Brigadier General YS” – made a crucial mistake after an investigation by The Guardian which found an electronic copy of Sariel's book available on Amazon "included an anonymous email that can easily be traced to Sariel's name and Google account.” ...
Being outed after more than 20 years of anonymity isn't optimal for someone who's supposed to be a top spy
Yup. And while it's tempting to roll your eyes and chorus Top. Men., remember that this is how they nabbed Ross Ulricht, a.k.a. The Dread Pirate Roberts from The Silk Road.
Yeah, OPSEC is a stone cold bitch of a problem. You have to be right 100% of the time, and dropping that to 99.99% means that you lose.
The Feral Irishman emails to saw that my post about the climate movie looked weird from his Windows computer. He could watch the movie but there was nothing displayed about Youtube. Everything looked normal from Safari on his iPhone.
Well, it turns out that Youtube has shadowbanned the film. This almost certainly made the post look wonky. If they disappear it I will update the embed to Rumble or something.
You know that you're over the target when you're taking flak.