Hacker Newsnew | past | comments | ask | show | jobs | submit | spydum's commentslogin

nielsen's ACR method is embedded into millions of devices and vendors. No need for a microphone, it's processing the audio signal being sent out. A microphone would be a wasted conversion..

(your car infotainment also likely has nielsen tech in it most likely, as they bought arbitron and gracenote)


Notably, the TV was caught making audio recordings and transcripts of conversations, and sending them to LG, independently of all this.

For some reason makes me think about replicators, and I found this article: https://columbusunderground.com/next-abundance-ds1/

There is plenty of others, but the idea of being post-scarcity of information creation/software seems akin to how Star Trek had replicators. They used them for sure, but there was still people who wanted to cook/create by hand, as an expression.


Exactly, go look at Lucid/Tesla and a few others for examples of how the car is a brick without the manufacturers sekret unlock codes and calibration software. If they decide not to help, you are out of luck.

Ah but you didn't buy the car, you bought a license to drive the car. You know, like CD or Playstation game.

Until some kind anon hopefully leaks it...

isn't this just malicious compliance? not clear how this would violate GPLv2?


Yeah, I agree. While this is a terrible move IMHO, from my superficial reading of the GPLv2 it doesn't really constitute a violation: the license imposes that the source be distributed to anyone who asks, potentially even charge a fee to cover its distribution costs, but it doesn't require that development happen in the open.


GPL not defining a time limit to comply also doesn't mean there isn't a reasonable limit on compliance time. Google is more than capable of quickly complying. It comes down to whether a judge would think what they're doing is reasonable and we don't think they would.

The software also isn't in the preferred form for modification. The build system which runs Git commands and doesn't work as intended without it. You have to make a Git repository for it to work and there's meant to be a separate one for each separate component. It spews out errors.


I mean, the only way to test this is to require of Google here to release the source code. And then look at how a court will evaluate it. For instance, what if Google never sends the source code? What if they claim that no request made it in? Though I guess this can be ensured, e. g. via letter that is registered being sent and then looking at Google's response to it.

So right now I think we all probably do not know. Google MIGHT refuse to release the source code, but it could release it - we don't know yet. Someone has to test that.


> For instance, what if Google never sends the source code? What if they claim that no request made it in?

That would be a violation of the license terms. All Google has done so far is, apparently, to make it hella annoying to access the source code (but not impossible).


My guess is that all their code is in their monorepo (google3), and they don't want to set up a tool to sync it to a public git repo, so the easiest way is just to have someone create a tarball on demand.


But google already built a tool to do exactly that: https://github.com/google/copybara


That was mostly Bayesian probability filters, followed by SPF and more recently DKIM.. Maybe you could consider the Bayesian filter databases being trained as ML, but I feel it's a far way from our typical AI/LLM surge


> but I feel it's a far way from our typical AI/LLM surge

I think they are about the same.

Both work about as well as autocorrect


less than 10 years ago I worked for an AI company that sold Naive Bayes classifiers as a service. so I would call it AI


Yet another instance of when something from the field of AI actually works, it stops being called AI.


I have bad news if you think banks are the pinnacle of cyber security practices...

Maybe some rare few are, but by and large they generally stink.

They tend to give that impression because they hire tons of auditors and panjandrum, to hassle their suppliers, but internally they are winging it like the rest of us.


The difference is that at bigger banks at least, they tend to throw more money at the problem. They'll have defense in depth with e.g. DMZs, proxies for ingress and egress, locked down workstations and browsers, etc., and a different team for each one of those domains.

So while the actual "on the ground" picture may look suboptimal at any given point, overall it does make for security that in practice is much better than average.

This is reflected in the actual security compromise statistics. Your money in a bank is a lot safer than, say, your credit card deals on file with many retailers.


Does panjandrum mean chaotic rocketry, flahy but worthless in the end?


this is all fine and good, if you are okay broadcasting your internal hostnames. I suppose it's a trade off some might make.


There's one way around that which is requesting a wildcard cert, but then that has its own rammifications


There's really two ways, the other is to manage your own CA. But it seems like every browser/piece of software/etc out there is hell bent on making that as difficult as possible. It'd also be nice if it was easier to scope a certificate authority to a specific domain, but support for that is pretty patchy which is functionally the same as no support at all. And that's not to mention software that ignores the system certificate store. Or how tedious and nonstandardized it can be to get a trusted certificate store in a Docker container in cases where you have services that need to trust each other. Or how annoying it is to install your own trusted CA on devices (though, step-cli does help a lot at least on normal computers... phones however...). On and on and on, the barriers to what should be the obvious solution are extremely high.


If scoping were actually viable, public CAs could also sign your private intermediate CA with a name constraint and it would be trusted everywhere.


Kind of reminds me of https://lists.debian.org/debian-security-announce/2008/msg00...

Interesting they could not figure out pattern 1? Wonder if there is any additional metadata to point at a vendor or provider..


My best guess would be some kind of netapp product, as we saw some self-signed certs on hosts that identified as netapp. But netapp didn't answer, and we got either no or no useful feedback from any of the certificate owners. So we ended up being unable to figure that out.

I'll probably share a list in some way soon and will try to ask the wider cryptographic and TLS community if anyone can figure it out.


Hanno - we may have communicated before some years ago, but am more than happy to offer any help I can (if some of our customers are/were affected, happy to reach out and see if they can give you more answers as to which products). nick (at) sectigo (dot) com


Fully agree, the only downside is without a SOC2 you will be asked to fill out an insane 200+ questionnaire. Good news is you have all these great LLM tools you can do this work for you, and just check it over.


In my industry they still ask for the questionnaire even if you have a SOC2 report!


Yeah, I get this even with SOC2 Type 2 & ISO 27001 ... the requests never stop.


Just say no. Serious.


That all depends on the balance of power ...


We are replacing those with AI agents anyways. It'll be AI agents all the way down!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: