

Getting a private pilot certificate. Was fun, but after going to every airport within range, not sure it was worth it.


Getting a private pilot certificate. Was fun, but after going to every airport within range, not sure it was worth it.


Sigh. I really need to put /s around things.
It’s a Monty Python quote.


In that case, society’s to blame.


You rolled a bowling ball down a hill. It struck a few cars on the way and went through a house and killed their pet. Guess who would be held responsible? You or the bowling ball manufacturer?
What if the bowling ball was really shiny and worth $100B? Should it make a difference?
Colditz, Victory, Stalag 17, Von Ryan’s Express, and the best of them all, The Great Escape.
Making fools of Nazis.


I had a roommate who would play “Burning Down the House” by Talking Heads every morning at top volume.
It starts slow and quiet, then the drums kick in hard, launching you out of bed. By the end of the song we’d be pogo-dancing around the apartment.


If he had only spent an extra $0.50 and added a Microchip 608c (https://www.microchip.com/en-us/product/atecc608c) to the design, then you wouldn’t have to deal with cleartext passwords in files. Instead, you could have elliptic-curve, asymmetric public-key encryption.


It’s way worse than that. The OpenAI talk at DefCon is a real eye-opener.
The agents swarmed, discovered chinks, left each other notes in hard-to-find places, and just relentlessly pressed on. Nobody knew what was going on for months, until it hacked its way into Huggingface. And HF’s own AI security agents didn’t pick anything up for weeks. It took a small glitch for someone to even notice.


The OpenAI talk at DefCon shows what can happen when you let these things run without any human intervention.
The solution is, obviously, even less human intervention. 🤦🏻♂️


It’s amazing to watch the degree of irresponsibility of all this. OpenAI unleashed autonomous sub-agents with NO human gating factors in it. The agents iterated hard enough to find holes. They exploited those holes to break into an otherwise secure company. It took them MONTHS to realize this was going on. It took the other AI company WEEKS to realize they had been compromised.
Then they show up at a security conference and have the audacity to lecture everyone that they should put up defensive agents WITHOUT humans in the loop so it could fight off the uncontrolled agents THEY unleashed.
How about you be responsible and REQUIRE human approval of every stage of an agent actions? Sure, it’ll slow you down, but it will also allow someone sentient and responsible to hit the stop button and prevent runaways like this.
It’s like you created an infinite-bullet machine gun, handed it to a toddler, and dropped it off in a shopping mall. After the carnage (for which you don’t take responsibility, even though you should be criminally charged), you suggest everyone else should wear full-body armor and board up their stores.
The ultimate in corporate gaslighting. This is all so goddamn irresponsible.


Fortnine. No question.


More intrusive ‘liveness’ proofs coming up. Captchas on steroids.


I’m really close to dropping Dwarkesh Patel after he gave a platform to AI bros and Musk.
He used to have proper researchers and scientists on. Now it’s unwatchable shit.


Went on the public tour of our local waste-treatment facility. Really fascinating stuff. Highly recommend it if you’re even slightly curious.
There are definitely industrial-scale automation systems. Mostly PLCs, but also SCADA for monitoring. Lots of 20-30 year-old tech. Those networks have no reason to be connected to the internet.
But there were also office equipment and personal devices everywhere. All it takes is for someone wanting to monitor the state of a digester on their laptop from home.
You just crossed the beams.


Last time this happened, we got Tang: https://www.wideopencountry.com/tang-drink/


From the HuggingFace article:
With node root and forged service-account tokens valid for 24 hours, the agent read the cluster’s secret objects, including a production object holding 136 keys. With node root and forged service-account tokens valid for 24 hours, the agent read the cluster’s secret objects, including a production object holding 136 keys.



The whole thing about moving from centralized to decentralized had a core glitch. Whatever server you signed on would effectively lock you in. What happened if things didn’t go as planned? LOLA is a good step, but it’s still not enough.
Long time ago, URNs were designed to handle URLs that moved. These were permanent resource indicators that would allow the underlying data to move but not break the link. The HTTP redirect codes were supposed to help. Idea was, a website could redirect to a new location so clicking on a link would never get you a 404. It assumed both source and target site were still accessible so source could send the 301, 302, 307, or 308 codes. Very genteel. But what if the source site or account were zapped or suddenly blocked?
Redirect codes work if the owner moved them and has now set up a suggested next location. But it doesn’t handle the negative reasons. Getting forcibly banned, site getting hacked, sites shutting down, owner not paying the bill (for economic, health, or political reasons), anything else that could render the content inaccessible. It’s nice to add constructs to avoid getting account hacked. But what if owner is in jail, muffled, coerced, going through a tough personal stretch, or dead?
They still need to solve for real life and how shit happens.


This is great!
All the bad advice in those poorly-edited “For Dummies” books gets to live on.


Corporate customer dinner in Vegas, footed by sales director, who insisted on ordering the most expensive bottle of scotch on the menu.
It was pretty good, but pretty sure not worth the high 4-digits.
He did get to close the sale 🤷🏻♂️
If I had to do it again, I’d start with the end goal and work backwards. It was a long time ago, I was single with no extra expenses, had a decent job, and thought it might be fun to learn. If I had wanted to become a professional pilot, the calculation would have been very different.
Getting the cert mainly involved putting in the hours. Having a good instructor helps a lot. Also, not making any stupid mistakes. I almost stalled the plane hard on my first solo touch and go. The hardest part was getting used to the ATC lingo and not stuttering too much. I got an aircraft band radio with a headphone and joined all the weirdos who liked to sit at the end of airport runways.