• 1 Post
  • 211 Comments
Joined 1 year ago
cake
Cake day: June 11th, 2023

help-circle
  • You can vote from overseas in whatever location was your last permanent US residence.
    People in DC get to vote for president because a special law was passed giving them electoral votes.

    People in Puerto Rico have a US permeant residence that doesn’t let them vote for president, so they can’t legally vote from a different jurisdiction.
    One of the proposals that’s come up occasionally is to make a similar law for Puerto Rico as we did for DC, but there’s never enough consensus on any plan to go forward, up until relatively recently.



  • ricecake@sh.itjust.workstoScience Memes@mander.xyzGet good.
    link
    fedilink
    English
    arrow-up
    9
    ·
    10 days ago

    I thought the universal part was the tone and cadence people use when talking to small children, and not the actual words or grammar changes.

    It’s why you can listen to a recording of a language you don’t know and tell if they’re talking to a baby, but there are also cultures that essentially don’t talk to them at all until they have language.




  • Most modern plans for eradication involve creating a virus that handles it, rather than a pesticide.
    Have the virus introduce a gene that takes a few generations of breeding in the impacted population before it starts to debilitate or sterilize the mosquitoes. That way your virus can start to kill the population even as it spreads to areas that were missed.


  • All of our best data on the impact says that it really wouldn’t matter. Sometimes a species is a linchpin for the ecosystem, and sometimes it isn’t.

    Sucks for mosquitoes, but there’s a very real chance that we’ll smallpox them, and the biggest concern will be our confidence that the virus we use doesn’t impact other species unintentionally.


  • if you technically pull people out of poverty by outsourcing to the lowest paying, least labor regulated parts of the world, is the fact that extreme poverty went away in those areas even a good thing?

    Yes. Your prospects of a healthy life increase when going from not being able to provide for yourself to being barely able to provide for yourself by working in fantastically poor conditions.

    If a sweatshop didn’t provide more worker value than extreme poverty, people just wouldn’t work there.

    The bare minimum of improvements is still an improvement, and that we should strive for better than the bare minimum doesn’t make the bare minimum worthless to the people who got it.



  • Oh, certainly. But common language has a term for high latency already, it’s just not speed related. Everyone knows about a laggy connection on a phone or video call.

    Fun fact: TCP has some implicit design considerations around the maximum cost of packet retransmission on a viable link that only works on roughly local planetary scale.
    When NASA started to get out to Mars with the space Internet, they needed to tweak tcp to fit retransmission being proportionally much more expensive and let connections live longer before being “broken”.



  • Yes, to a degree. A VPN protects you from an attacker on the same WiFi network as you and that’s about it.

    Most assaults on your privacy don’t happen like that, and for the most part the attacks that do happen like that are stopped by the website using https and proper modern security.
    The benefit of the VPN is that it puts some of that protection under your control, but only as far as your VPN provider.

    A VPN is about as much protection from most cyber attacks as a gun is.

    They’re not a security tool, they’re a networking tool. They let you do some network stuff securely, and done correctly they can protect from some things, but the point of them is “this looks like a small, simple LAN, but it’s not”.

    It’s much easier to package and sell network tools than security tools, and they’re much more accepted by users, since security tools have a tendency to say “no” a lot, particularly when you might be doing something dumb,and users hate being told no, particularly when they’re doing something dumb.




  • Depends on the vendor for the specifics. In general, they don’t protect against an attacker who has gained persistent privileged access to the machine, only against theft.
    Since the key either can’t leave the tpm or is useless without it (some tpms have one key that it can never return, and will generate a new key and return it encrypted with it’s internal key. This means you get protection but don’t need to worry about storage on the chip), the attacker needs to remain undetected on the server as long as they want to use it, which is difficult for anyone less sophisticated than an advanced persistent threat.

    The Apple system, to its credit, does a degree of user and application validation to use the keys. Generally good for security, but it makes it so if you want to share a key between users you probably won’t be using the secure enclave.

    Most of the trust checks end up being the tpm proving itself to the remote service that’s checking the service. For example, when you use your phones biometrics to log into a website, part of that handshake is the tpm on the phone proving that it’s made by a company to a spec validated by the standards to be secure in the way it’s claiming.


  • Package signing is used to make sure you only get packages from sources you trust.
    Every Linux distro does it and it’s why if you add a new source for packages you get asked to accept a key signature.

    For a long time, the keys used for signing were just files on disk, and you protected them by protecting the server they were on, but they were technically able to be stolen and used to sign malicious packages.

    Some advanced in chip design and cost reductions later, we now have what is often called a “secure enclave”, “trusted platform module”, or a general provider for a non-exportable key.
    It’s a little chip that holds or manages a cryptographic key such that it can’t (or is exceptionally difficult) to get the signing key off the chip or extract it, making it nearly impossible to steal the key without actually physically stealing the server, which is much easier to prevent by putting it in a room with doors, and impossible to do without detection, making a forged package vastly less likely.

    There are services that exist that provide the infrastructure needed to do this, but they cost money and it takes time and money to build it into your system in a way that’s reliable and doesn’t lock you to a vendor if you ever need to switch for whatever reason.

    So I believe this is valve picking up the bill to move archs package infrastructure security up to the top tier.
    It was fine before, but that upgrade is expensive for a volunteer and donation based project and cheap for a high profile company that might legitimately be worried about their use of arch on physical hardware increasing the threat interest.


  • Most voters don’t have a business and never will.

    The value of a net new business is that it creates more jobs and economic activity.
    Most people benefit from more jobs to either work at or drive up labor demand.
    Per that school of economic thought, incentivizing a new business adds more activity to the market and more opportunity for people to find ways to innovate, provide value and become profitable.
    Giving money to an existing struggling business is subsidizing a businesses that’s already demonstrated that it’s not working.

    However, we’re both putting too much into it. The goal is to say $50k for small business, because people like a business friendly atmosphere.
    Trump gets credit for giving tax cuts to businesses for stock buyback, which only helps investors. The goal is to court people who want pro business policies without literal handouts to corporations.