When I read about these things I always think about some of the writing of @pluralistic on graceful failure modes. A product (system) is not defined by its success but by how good or poorly it fails. I've been teaching students that not considering (poor) failure modes is a huge liability.
It really frustrates me that most banks and credit card sites have either no #2FA or only offer SMS-based 2FA. Do people know of banks that offer 2FA via TOTP,/authenticator app, passkey, or hardware #authenticator (e.g. #Yubikey)? The only US financial sites I've seen claim this are Bank of America, Vanguard, USAA, and Schwab. (For the purposes of this discussion, I'm excluding crypto-related sites.)
Tomorrow is my last lecture for both my astro courses. I always end my astronomy classes with The Pale Blue Dot speech, and I'll be pretty impressed with myself if I manage to get through it without crying tomorrow. It seems to get even harder every year. https://www.youtube.com/watch?v=GO5FwsblpT8
"There is no better demonstration of the folly of human conceits than this distant image...it underscores our responsibility to deal more kindly with one another, and to preserve and cherish the Pale Blue Dot."
FBI releases PSA warning about all the ways that cybercriminals are using AI to commit fraud on a larger scale and to increase the success of their scams. The advisory warns about deepfaked videos and voice calls, as well as AI generated profile images to impersonate people.
Among their recommendations:
-Create a secret word or phrase with your family to verify their identity.
-Look for subtle imperfections in images and videos, such as distorted hands or feet, unrealistic teeth or eyes, indistinct or irregular faces, unrealistic accessories such as glasses or jewelry, inaccurate shadows, watermarks, lag time, voice matching, and unrealistic movements.
-Listen closely to the tone and word choice to distinguish between a legitimate phone call from a loved one and an AI-generated vocal cloning.
-If possible, limit online content of your image or voice, make social media accounts private, and limit followers to people you know to minimize fraudsters' capabilities to use generative AI software to create fraudulent identities for social engineering.
-Verify the identity of the person calling you by hanging up the phone, researching the contact of the bank or organization purporting to call you, and call the phone number directly.
-Never share sensitive information with people you have met only online or over the phone.
-Do not send money, gift cards, cryptocurrency, or other assets to people you do not know or have met only online or over the phone.
From now on, every time there is a new proposal to backdoor e2ee apps, we're just going to point to this, right?
If you love Richard Feynman you've got to watch this video...
... where Angela Collier will ruthlessly dissect the mythology he built around himself. You probably won't agree with everything she says, and you may hate some of it, but it will still be thought-provoking.
I didn't know about what she calls "Feynman bros": lazy male students who read Surely You Must Be Joking, Mr. Feynman! and try to adopt the flashy womanizing persona he depicts there, instead of working hard on physics. I can easily believe they exist. So if you know a youngster who likes physics, don't give them that book. Instead do what my uncle did: give them The Feynman Lectures on Physics.
I didn't know these books and indeed every book 'by Feynman' was actually written by his Caltech colleague Robert Leighton or his son Ralph Leighton based on audiotapes of lectures or conversations. I still don't know how much of a role Feynman had in crafting these concoctions.
I *did* know that he once flew into a rage and tried to choke his second wife.
I did not know he was good with children, eagerly answering letters from them, etc. It's nice that Collier points out this good side.
I *did* notice, from his anecdotes, that he put a huge amount of work into trying to seem like a manly man rather than a nerd.
I didn't fully notice that almost none of his anecdotes feature the famous physicists he worked with at the Manhattan Project. Collier points out that this leaves him free to make things up.
I think she overlooks how he eagerly *points out* that he used tricks to seem smart. He explains the tricks to show they're not so hard.
I could go on....
(1/2)
While transfer students represent one of the most diverse student groups on campus, they usually don't ever get the chance to become a scientist.
Why? Because lab RAships are so massively competitive, acquired in the early years on campus, and limited, our most diverse (and often most deserving, hard-working and incredible) students are systematically less likely and able to access those positions.
Big migration from Microsoft Office to #LibreOffice: The northern German state of Schleswig-Holstein is migrating 30,000 PCs. Learn more in this video from our recent conference: https://peertube.opencloud.lu/w/rUh7VLPkmkruarXHKeNGqG #foss #opensource #freesoftware
Raw milk producer optimistic after being shut down for bird flu detection
A second lot of milk was recalled after testing of retail products came back positive.
https://arstechnica.com/health/2024/12/raw-milk-producer-optimistic-after-being-shut-down-for-bird-flu-detection/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social
The Code for Science Symposium (#FSKomp24) starts in Hannover!
Over the next 3 days, we’ll dive into the future of software competence in research.
I’m particularly excited about the conversations on publishing research software- can’t wait to learn and connect with brilliant minds!
Let’s make research more open and reproducible with publishing our data and code!
Mornin’. Didn’t realise a formal #introduction was de rigueur on here - my bad. I’m the Bee Guy - the founder of the first and only native wild bee sanctuary on the planet - The Bee Sanctuary of Ireland. Not for profit social enterprise 24/7 365 advocating for our native wild bees. Not about honey bees - they’re fine. Only on here for the #bees & #planet. Heart on my sleeve, head in the stars, feet in a muddy puddle. Big plans. Need your support. Thoughtful brave disruption. Language matters.1/n
An Apple employee is suing the tech giant to limit access to employee personal devices.
According to the suit, Apple employees who use personal devices for work must allow Apple to install software that grants Apple access to search anything stored on the device or iCloud. The suit says Apple can monitor staff even when they're off duty.
If the employee wins, it could be another win against "bossware" surveillance.
This is one of my favourite dialogs in all of Linux. What application? Who is asking for this information and why? Stop asking questions and give me your secrets.
It’s amazing how it is 2024 and - consistently - our front-line security interfaces still train people to do and accept the very wrongest things.
Hello World :)
I am pleased to present you a small project that I have been working on these last weeks:
MARL (Mastodon Archive Reader Lite) is a small web app that allows you to explore in detail the content of your Mastodon posts archive, including attached files (images, videos, sounds), and with different search options.
Boosts welcome!
(More info in the post below )
A Cumulative Culture Theory of Developer Problem-Solving: new preprint
As Bluesky grows in popularity among real users, it likewise grows in popularity among those who operate fake accounts for myriad purposes. Here's an article about a network of fake Bluesky accounts with identical biographies.
https://conspirator0.substack.com/p/bogus-accounts-in-the-blue-skies
It seems like #Signal accounts have to be recreated after some amount of activity; I know several people who had used Signal a year ago or so, but then recently my client said I'd need to invite them and they said that they seemed to need to setup their account again. Is this behavior actually documented and/or explained somewhere? I couldn't seem to find anything authoritative on a quick search. #lazyweb
Anyone have any experience dumping Audible? I've already gotten rid of my amazon prime, and I'm working at getting my job to do the same (I have some supportive co-workers so I think it will work, this is the best way to do the same at you job. Find your allies then work together but not in an obvious way to get your company to stop ordering there.)
Anyway I thought getting rid of audible today would be a nice way to feel like I'm a part of the big Amazon Black Friday strike. 1/
why pipes sometimes get "stuck": buffering https://jvns.ca/blog/2024/11/29/why-pipes-get-stuck-buffering/
Moved to Mathstodon.xyz
Theoretical physicist by training (PhD in quantum open systems/quantum information), University lecturer for a bit, and currently paying the bills as an engineer working in optical communication (implementation) and quantum communication (concepts), though still pursuing a little science on the side. I'm interested in physics and math, of course, but I enjoy learning about really any area of science, philosophy, and many other academic areas as well. My biggest other interest is hiking and generally being out in nature.