Hacker Newsnew | past | comments | ask | show | jobs | submit | archi42's commentslogin

Zzzzz, we should have gotten security right a few decades ago. But security costs money and isn't a flashy feature to attract new customers, or cuts into your margin if you're a "real" business producing stuff or offering some service. Or whatever the decision makers in Berlin were thinking when they ignored security.

Yeah, we would still see hacks, but we would see less of them if security wasn't optional.

Maybe the AI craze helps by forcing more decision makes to see security as imperative, and by giving us another powerful tool for our tool box.

N.b.: I work in the security industry, our customers obviously want to improve their security. We've been seeing an uptick in awareness, but that's mostly due to NIS2 and other legislative efforts. Those force them to do something. AI is a curiosity for small talk to many of them.


A large number of places will buy a new firewall every 5 years, or pay their fortinet renewal and check "Security: Done!" without any kind of analysis.

I was contracted in to a place to do among other things cyber security insurance audits, and they asked me to stop doing them because I refused to lie to their insurer. "Wait but if we only score 20 / 300 that makes us look kind of bad" uh huh.


> pay their fortinet renewal and check "Security: Done!" without any kind of analysis.

there exists objective measure of security, which would be some sort of hacks/breaches per period. If customers cared about it (and i assume they do), they would choose companies that have less breaches over others with higher counts, normalized on cost differences.

Therefore, if companies didnt actually try to fix their security but instead just checked boxes, they would get breached more often, resulting in customer losses.

The only thing stopping this from actually occurring is the lack of mandatory regulatory reporting of it. So this is where gov't needs to step in and mandate disclosure etc.


Breaches don’t happen often enough to be a useful metric. Most smaller companies are never breached, despite having basically zero security.


The number of breaches would have to be honestly reported for that idea to work. None of the security firms would want to do that; least of all the lowest quartile of them.


> would have to be honestly reported for that idea to work.

and why does this idea work for accounting audits, but not for security? As long as regulations for companies exist, they would necessarily follow it, and this would lead to reporting of security breaches just like companies would have to report their financials honestly.


Accounting is generally both easier to do correctly and easier to verify than security practices, unfortunately


We're talking about reporting breaches, not giving yourself some sort of abstract security score


And how do you know if you have been breached if you (negligently, in my opinion) have no audit logging, multiple principals sharing the same account, and no anomaly tracking? Does a breach only happen if the attacker brags openly about it?

The difference with accounting is that, relatively speaking and certainly within this context, few businesses are cash businesses. Your bank is keeping at least a basic audit log of money coming in and out of the corporate bank account. Your payment processor is keeping at least a basic audit log of who paid you and how much. You won't make your auditors happy if they're the only documents you have, but they're at least something to be handed over in an audit that pretty much every software business will have. Cybersecurity? By default, nothing is collected.


forensic accounting and audits also require a paper trail.

So if you have no logging and such, you will have already failed regulatory reporting standards - just like you would fail an accounting audit if you have no paper trail of where your money went!


On the more legal side of services was the original last.fm - as a pupil/student I spend days/hours discovering new music there. Not only due to automatic recommendations, but a lot of time by browsing other people's listening habits - just like browsing the music collection of someone else on soulseek.


Wait a few years, and we're all gaming on decomissioned data center GPUs ;-)


Old datacenter GPUs could game, but new ones can only do OpenCL/CUDA/ROCm etc. and have no display out. Im using an MI50 right now and I would wish newer datacenter cards could also be used for everything like them.


Ah, I'm aware of the physical limitations (including cooling), but I was under impression that these days we had a good handle on rendering on one device and doing the video output on another (at the expense of some latency). Obviously I never tried that with a datacenter GPU.


If you could render fully in OpenCL and output it via another device it would probably work. But they dont have ROPS so they cant do traditional video rendering. Even something like Blender where you would use it for calculations and not for display/video doesnt work without software emulating hardware features related to textures.


It's a 100" telescope... from 1917. To summarize Wikipedia for you (my words, not a genai): While it was used by famous people like Hubble it isn't used for scientific work anymore. Some adaptics optics stuff happened in the 1990s, but I suppose that was just to test the system on a telescope that wasn't in active use anymore. In 2014 it "began its new life as the world's largest telescope dedicated to public use".

So I'd say it's a good use as any ;-)

https://en.wikipedia.org/wiki/Mount_Wilson_Observatory#100-i...


It still works pretty well in the IR band. I know that one from experience due to storm damage to our roof ;-)

A leak only turns invisible if the water has the exact same temperature as the wall and there is no meaningful evaporation happening (as that cools the affected area).

Of course don't let me stop you from actively probing your all using RF. Though also there you might have good chances with IR, since wet $stuff should behave differently than dry $stuff ;-)


Ugh, we have BSH [Bosch Siemens Group] appliances with wifi, but ours add actual features and don't artificially lock any. Both dryer and washing machine: Remote start, start when energy is cheap, notifications when done or on issues. The dryer can automatically select the program based on the last washing machine program. For the washing machine program I can use the phone to select what I put in there, and it picks a program for me.

However, I can also use the dials much like I did with our old appliances. There is nothing locked out and we actually used them offline for a few weeks (tbh I didn't try setting the finish time using the appliances' controls).

In Jeff's case that's obviously not the case, but there are still options from BSH. As with everything, one has to be careful in what they buy these days. Don't interpret this as victim blaming: I hate that we have to be careful with these traps.

Edit: There are of course alternative manufacturers, but BSH ist a known quantity regarding quality. And when it comes to cloud stuff I trust them a little bit more than other manufacturers; they're actually the only smart thing we own that's not blocked in my OpnSense.


That's actually a use case that I imagine could work well, if done well. Especially in fully integrated systems like GMail or our corporate Exchange, when the LLM can access enough data to produce meaningful suggestions.

IMHO the UX problem is, as the article points out in so many words, shoving AI slop down our collective throats as if we were geese waiting to be fattened.


Yeah, that was one of features that made me try Plex a long time ago.

And that's why these days, I run Jellyfin on a VPS for watch parties (similar situation as yours), while sticking with Plex for family use.


It's dumb the apps don't remember that, but I think it's not nice that you're being downvoted for neutrally pointing out a workaround.


The article addresses this:

> Rules that ask people not to use LLMs are ignored and almost impossible to enforce in open online events.

It's quite sad to see CTFs dying. I never had the time do seriously participate in CTFs, but I always respected those who did, as well as the people organizing these events.


> Rules that ask people not to use LLMs are ignored and almost impossible to enforce in open online events.

That's such a non-reason. If your competition cannot enforce the rules of the competition, then what's the point? Does the CTFs specifically need to be 'open'?


I don't get your reasoning? You're agreeing with the author but are not?

The author argues that open CTFs are done for because of rampant cheating. You're agreeing with that, don't you?

The title is "AI has broken the open CTF format". If the format is "open CTF" then it is very specifically open.

As to your second question: Yeah, I believe having open CTFs was a good idea.


ah my bad. You're right, the author specifically states 'OPEN CTFs'. I think that keyword slipped my mind by the time I was at the end of the article.

So my question then becomes, what will realistically be lost if CTFs move to a form that requires teams and individuals to sign up?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: