This is the reason I switched probably mor than a year or two ago. YouTube remains a cat and mouse game. Strange things with those forks is that they always add some more streaming sources Mike BkliBili but keep the old stuft. Actually soundcloud only works very limited lately.
Wouldnt call it regulatory blood lust at the moment. I think the competitive situation that is however solely focussed in performance at any cost and not at compliance at all is forcing AI labs to play with fire. The risk for them is an even bigger regulatory backlash. Totally different industry : Chinese ebike manufacturers are currently pushing the rules for motor strength to the max due to competition. What will likely happen is stricter regulation of max support and motor power if there are incidents. Particularly there will be more regulatory fragmentation with little common denominator. This will hurt the whole industry's growth. In this industry it kind of still works as an agreement of non-Chinese manufacturers.
Interestingly Russia I think itself presented its 2012 law as modeled on the American Foreign Agents Registration Act at the time. A bit worrying is that the US DoJ starts to create also a bit of the same chilling effect speaking about “Liability for Unregistered Foreign Agents". Don't get me wrong: there is huge differences in freedom of speech and I do not say this is the beginning of the end. But it seems at least intellectually interesting to draw comparisons.
Can someone explain to me how such self-awareness can be forced into the model. I mean I guess the pre training data could contain all sorts of stuff. How reliable are those hacks. I know that a lot of open weight models answer that they are Claude in the absence of a system prompt. I find destillation not that much of a plausible explanation as typically claude would probably not mention that it is Claude all the time. I find it rather plausible that a foreig. system prompt made it into pre-training. But again: I have no clue how much care is given by models to leave traces for destillation (for closed weights) or post training (for open weights).
Cool, I actually applied for a diploma thesis for doing the PIC 16 port around 2004. Raphael Neider actually was quicker then me, so he maintained the port for our lab at the Uni Karlsruhe (i am still in the same lab). We needed the port because was needed to allow people to compile our OS for our sensor nodes at the time. Still did a lot of testing of the PIC 16 port at the time because my thesis was about implementing a filesystem and a REST like API for the nodes.
A lot of neural engine, particularly in the embedded domain (ARM/RISC MCUs) have the same problem. Designing other models means on top of this means a lot of profiling to get convolution blocks right to get good speedups. (We optimized this in the past e.g. using Neural Architecture Search on super networks)
One of the reasons I haven't switched to Graphene is this kind of drama. I wish there was more middle ground. I don't think the post is in any way constructive and will lead to fairphone to consider adding a secure element.
I don't see their post as 'drama' or nonconstructive at all. It's simply a list of well-founded criticisms of Fairphone's extremely lax position on security that is incompatible with Graphene's. If being critiqued for it doesn't lead to them considering adding a secure element, that's a problem on Fairphone's side imo.
The core criticism to the vendor is the missing security element. This is a fair point.
However, calling out on e/OS in the same post, seems to me very counter-productive. We need more OS vendors and less infighting. Calling all custom ROMs insecure and claiming to be the only one is IMHO 'drama'. Particular there are contributions of me microG that are helpful if you want to de-Google ones phone. Graphene has a different approach: fair. People will use GrapheneOS if they share their goals.
Fairphone is about sustainability and a bit about not supporting major tech like Google. I don't think this hurts. In an ideal world we could have both. But sustainability seems to be a non-goal of GrapheneOS.
I think in this context it's fair to call out /e/.
In some ways /e/ and GOS are trying to achieve different things (/e/ is not hardened and does not claim to be), but /e/ is severely lacking security wise compared to AOSP.
This [0] is, in my opinion, a fair review that mentions many of the issues. That Fairphone is ok with these is telling about their position on privacy and security.
> Calling all custom ROMs insecure and claiming to be the only one is IMHO 'drama'.
No, what it is is true. microG lets you de-Google a phone, but the resulting phone is provably less secure. If stating the truth causes "drama", the problem isn't the person or entity saying the true thing. If that truth shakes people, if it upsets them, they should look into the problem that truth has revealed (not created, as truth isn't something that exists only after someone speaks it) rather than blame those who are speaking it.
Can you provide evidence that GrapheneOS is less secure than LineageOS or other custom ROMs? Because GrapheneOS (and even leaked documentation from commercial adversarial phone hacking tools) provide a hell of a lot of evidence that it is, in fact, considerably more secure than just about every other phone OS in existence.
I am not saying that what they say is wrong. However, this is about current phones. If your goal is supporting aftermarket phones the case looks very different. It is the only way to get a decent level of security. The problem is IMHO how graphene communicates. It is mixing tons of different things to always make their communication more 'bold'. Then they complain about people complaining about their communication style. It is my personal choice, but I accept less security while not having to care about GrapheneOS announcements. I value their work in a similar way that I value WikiLeaks.
What I've seen (that doesn't outwardly appear astroturfed) is largely people getting their feelings hurt because of an opinion they've expressed about the qualities of project they're involved in, or just a user/fan of. Their dislike of the Linux kernel or the relative insecurity of desktop Linux projects in general tends to piss people off, even though the negative points they make are invariably detailed and well communicated.
Because of that, instead of refuting the actual argument being made, discussion always swings towards their tone.
What it is, exactly, that is objectionable? Are there personal attacks being made? Yeah. Towards the GrapheneOS developers. It's something I've seen for myself and if you get into these threads on HN early, you can see how the comment deletions pile up. When they say they are the target of organized disinfo and targeted attacks by malignant third parties, it's pretty easy to believe them. It is in the best interests of many, many very powerful people that GrapheneOS is destroyed.
No one who takes infosec seriously cares about GOS' PR filling their communication with tummy rubs and head pats. Infosec is a nightmare, adversaries are everywhere, all anyone should want to know is whatever is as close to the truth as possible.
To be honest, I am happy that a somewhat influential account is raising these issues. I have tried to explain for probably two decades now that the Linux desktop has poor security and the Linux kernel has issues. But somehow a significant portion of the Linux community lives with the delusion that the Linux desktop is the most secure OS. The whole idea that a vulnerability in some image parser that their Mastodon client uses could give an attacker access to their full user account, simply doesn't occur to them.
I want the open source desktop to succeed, but we can only make progress if we accept that there are a lot of security, UX, and UI issues and start tackling them.
When they say they are the target of organized disinfo and targeted attacks by malignant third parties, it's pretty easy to believe them. It is in the best interests of many, many very powerful people that GrapheneOS is destroyed.
Yeah. There it's clear that there is a lot of organized disinformation, probably by government actors and certainly by other open source and phone vendors that try to sell privacy/eurowashed phones (one Volla astroturfer outed themselves accidentally on Mastodon by sharing information only an employee could know).
While many things might be legal (or hasn't been ruled clearly illegal yet) /under different jurisdictions, we are still in the process of figuring out what we accept as ethical. As the output of models can't be easily copyrighted, destillation is equally disputed. Particularly if the primary model interaction was not destillation (as in this case) IMHO it will be legally quite difficult to restrict secondary use for training. In the end we have to find a legislation and probably even international treaties that account for the fact that classical copyright is beginning to become an obsolete concept.
reply