AT2k Design BBS Message Area
Casually read the BBS message area using an easy to use interface. Messages are categorized exactly like they are on the BBS. You may post new messages or reply to existing messages!

You are not logged in. Login here for full access privileges.

Previous Message | Next Message | Back to Computer Support/Help/Discussion...  <--  <--- Return to Home Page
   Networked Database  Computer Support/Help/Discussion...   [1969 / 2000] RSS
 From   To   Subject   Date/Time 
Message   Sean Rima    All   $1 (part 2/3)   July 15, 2026
 2:47 PM *  

Earlier this year, Google?s AI summary falsely identified the Canadian fiddler
Ashley MacIsaac of being a sex offender. His lawsuit, filed in Ontario, is
ongoing. If Google is forced to invest in improving its AI system until those
kinds of errors are exceedingly rare, that seems like a good outcome for users,
as well as the subjects of search, like MacIsaac.

More generally, liability concerns could mean that many current use cases for
agents won?t be commercially viable. Companies may not be able to profitably
operate AI lawyers, doctors and media influencers if they are held responsible
for what they say and do.

We?re OK with this outcome. There?s nothing in the law that requires us to
accommodate AI systems if they are fundamentally untrustworthy, just as we don?t
need to accommodate untrustworthy human systems. Any company that won?t stand by
the statements its agents make -- whether human or AI -- doesn?t deserve users?
time or money.

This essay originally appeared in The Guardian.

** *** ***** ******* *********** *************
One Million Passports Leaked Online

[2026.06.26] A database of almost a million passports from around the world was
leaked online.

Note what happened. A high-value credential -- a passport -- was used in an
ancillary low-value authentication system: ID verification for cannabis
dispensaries. And it?s the low-value system that got hacked, putting the
high-value credential at risk.

** *** ***** ******* *********** *************
Meta Is Testing Facial Recognition for Police and Military

[2026.06.26] We know that ICE wants to deploy eyeglasses with facial recognition
that can identify people in real time.

Turns out Meta is prototyping the feature with a Pentagon supplier. (Alternate
news story.)

** *** ***** ******* *********** *************
Robot Police Officers

[2026.06.29] We?ve taken one small step towards robot police officers: a drone
capable of disarming a suspect:

    In a June 22 video posted on the Sacramento County Sheriff?s Office?s
Instagram page, an officer wearing goggles can be seen operating a drone to
retrieve a knife from an armed suspect hiding inside a cluttered house. ?After
not responding to negotiators, a drone was deployed inside the residence,? the
post says. ?Drone pilots located the suspect hiding in a corner of a garage? and
then used a high-powered magnet attached to the drone to grab the knife out of
the suspect?s hand. In the video which is soundtracked by the ?Mission:
Impossible? theme song -- the intercepted knife can be seen spinning around in
the air as the drone carries it back to the deputies.

Slashdot thread.

** *** ***** ******* *********** *************
Factoring RSA Keys with Many Zeros

[2026.06.29] Interesting research on a new class of weak RSA keys: keys with
lots of zeros. It turns out that these keys are out in the wild.

    The badkeys project is an open-source service that checks public keys for
known vulnerabilities. While developing this tool, Hanno collected a massive
number of real-world keys from public sources, including Certificate
Transparency logs, internet-wide TLS and SSH scans, PGP keys, and many others.
By searching this dataset for unexpectedly sparse RSA moduli, we uncovered a
large number of keys in the wild with the patterns in Figure 1.

    Both patterns include several regularly spaced blocks of all zeros
interleaved with seemingly random data. Pattern 1 appears in CT logs for
certificates issued to several large organizations, including Yahoo and Verizon,
and on some devices running NetApp software. Fortunately, these certificates
have already expired, but we still shared our findings with these companies. We
wanted to learn more about which product could be responsible for generating
these keys, but we did not hear back. Pattern 2 appears on SSH hosts running the
CompleteFTP software from EnterpriseDT. The underlying vulnerability affects RSA
keys generated using versions 10.0.012.0.0 (Dec 2016Mar 2019) and DSA keys
generated with v10.0.023.0.4 (Dec 2016Dec 2023).

    These vulnerabilities affect a small minority of hosts on the internet, but
the more interesting takeaway is that independent cryptographic implementations
failed in similar ways. More implementations may include the same bugs, and so
it?s worth tailoring cryptanalytic algorithms for this particular type of
failure.

The article doesn?t speculate, but I will. This could be a deliberately designed
backdoor, of the sort I wrote about back in 2013. I could imagine some
government agency figuring out how to break this class of RSA keys, and then
convincing different providers to hand them out to users.

** *** ***** ******* *********** *************
The Realities of AI Video Surveillance

[2026.06.30] The Financial Times has a good article on how AI is changing the
capabilities of video surveillance, with information from both Israel/Iran and
Russia.

    In contrast with older tools restricted to a few dozen preset searches,
these new tools allow an almost unlimited range of enquiries by enabling
language-based searches on video.

    That lets intelligence officers hunt through massive streams of videos
using simple search terms, such as two men handing a bag to each other; a person
who has changed their appearance, or has changed clothes multiple times in a
day; or a vehicle that has recently been painted over, or has driven past the
same spot several times in a short period.

    ?This is the holy grail of surveillance,? said a European official whose
country uses the technology on its cities. ?We are able to look for behaviour,
not objects -- it has created a world of new possibilities.?

I wrote about this sort of thing a few years ago, how AI enables mass spying in
the way that computers and networks enabled mass surveillance. The interesting
development in the article is that AI allows people to ask natural language
questions about video footage to AIs -- and AIs can answer them.

** *** ***** ******* *********** *************
Papa Johns Surveillance-Based Advertising

[2026.07.01] Papa Johns is spying on people?s buying activities to predict when
they are low on food:

    The pizza chain recently tapped NBCUniversal, Instacart and the
dentsu-owned media agency Carat for help reaching consumers when they?re low on
groceries -- and thus more likely to be swayed by a mouth-watering ad. The idea
is to reach hungry consumers by ?knowing what is in their fridge without being
too creepy,? said Carrie Drinkwater, chief investment officer at Carat.

    To achieve that goal, NBCU and Instacart created a custom audience of
shoppers who regularly purchase grocery staples on Instacart, such as eggs,
milk, meat and produce. Based on that data, Papa Johns can determine which days
of the week certain consumers are likely to run out of groceries and serve them
an ad on NBCU streaming content accordingly. The brand served custom creatives
to consumers based on their food preferences -- such as whether they buy meat
regularly -- with QR codes and calls to action such as, ?Light on groceries?? or
?Empty fridge??

Back in 2012, we learned (from Target and its campaign that detects when someone
is pregnant) that the trick is to hide the knowledge in other, wrong,
information. So the way for Papa Johns to not be ?too creepy? is to deliberately
get it wrong sometimes.

But still, ugh.

** *** ***** ******* *********** *************
Cybersecurity Mission Creep in the US

[2026.07.02] Interesting paper: ?Cybersecurity Mission Creep.?

    Abstract: Cybersecurity is experiencing mission creep. Policymakers are
casting more and more problems as issues of cybersecurity. So reframed, wildly
different policy issues, from misinformation, to child social media safety laws,
to antitrust regulations, to alleged journalist misconduct, to anti-sex
trafficking statutes become what this Article calls ?cybersecuritized.? Before
this reframing, these issues present as important but not existential. But once
cybersecuritization positions the issues as threats intensified by their
technological nature, they gain access to the politics and law of urgency and
exceptionalism and invite troubling governance responses.

    Positioned as security threats, cybersecuritized issues become endowed with
the apparent normative power to override countervailing considerations,
oversimplifying the problem. Cybersecuritization?s oversimplification similarly
risks unidimensional solutions and invites use of argumentative trump cards,
like First Amendment challenges. Cybersecuritization also invites deference to
purported specialists and their proposed solutions. Together, the reductive
tendencies of cybersecuritization and the deference it prompts to specialists
renders ultimate governance choices more opaque. And this opacity can erode
public trust and political legitimacy.

    This Article surfaces the phenomenon of cybersecuritization and offers a
novel framework for analyzing and critiquing it. Mining cases from across
criminal and civil domains, the account also demonstrates the insidiousness of
cybersecuritization and the likelihood that it will continue to expand.
Confronting cybersecuritization is crucial. If we continue to ignore it, we risk
abdicating further responsibility for difficult choices to the trump card of
cybersecurity. This Article?s analysis and critique aim to help reclaim the hard
work of governance for our hands.

** *** ***** ******* *********** *************
Flock Cameras Can Surveil Cars Without License Plates

[2026.07.03] This is from a 2024 company presentation:

    Officers can also tap into data showing a car?s decals, bumper stickers,
back and top racks -- along with temporary and unique state tags.

    Flock calls it a ?Vehicle Fingerprint? and it?s touted as a way for law
enforcement officials to get more information ?even when you don?t have full
plate information,? the company?s presentation shows.

    The company gives police officers the ability to search that data as well,
to ?build stronger cases with less information upfront.? That includes being
able to locate multiple vehicles law enforcement officials believe are moving
together and what Flock calls a ?multi geo search.?

This kind of thing is older than AI; I wrote about it in my 2014 book Beyond
Fear. Edward Snowden revealed that the NSA was using cell phone location data to
track phones that were habitually near each other.

As bad as Flock is, remember that anyone with broad access to cell phone
location data can do the same thing.

** *** ***** ******* *********** *************
France to Stop Certifying Non-Quantum-Safe Encryption

[2026.07.06] France is accelerating its transition to post-quantum encryption:

    France?s cybersecurity agency ANSSI said on Tuesday it would stop
certifying security products that lack quantum-resistant encryption, a move that
will force government bodies and critical operators to shift away from older
systems.

    Samih Souissi, ANSSI?s chief of staff, said at the France Quantum
conference that the agency would halt such certifications from 2027, and that
businesses should be buying only quantum-safe products by 2030.

    ANSSI approval is required for use in French government agencies and
critical infrastructure, making the policy a de facto phase-out of older
encryption.

** *** ***** ******* *********** *************
Google Is Suing Chinese Scammers Who Are Using Gemini

[2026.07.07] Not sure this will have any effect, but I support the effort:

    According to Google?s legal filing, Outsider Enterprise operates through
Telegram. The group offers phishing-as-a-service to individuals who may not be
technically savvy enough to set up fraudulent websites and text campaigns on
their own. In its Telegram channels, Outsider Enterprise reportedly provided
instructions on how to use Google?s Gemini AI to create websites that imitate
those of Google, YouTube, and government agencies such as New York?s E-ZPass.
The group offered nearly 300 scam templates.

    [...]

    Google worked with AT&T, Verizon, and T-Mobile to block many of these
malicious text messages, and Google notes that its on-device scam detection in
Google Messages probably helped reduce the number of successful phishing
attempts, too. This AI-powered feature apparently stops 10 billion scam texts
every month, so it?s fair to expect it caught at least some Outsider Enterprise
activity.

Another article.

** *** ***** ******* *********** *************
Cybersecurity and the Gap Between Skill and Ability

[2026.07.08] Last week, national security agencies from the Five Eyes -- that?s
the rich, English-language-speaking countries club -- jointly released a
statement warning of the increasing cyber risks of AI models: in particular,
their ability to autonomously hack into systems and networks. The statement was
more measured than some of the breathless headlines about it, and the advice
they gave is pretty much the standard advice everyone gives -- albeit with
newfound urgency.

Internet risks are nothing new, and cyberattacks -- both large and small -- have
been a significant issue since long before the current crop of generative AI
models.

What?s been changing over the decades, and what AI is changing even faster, is
the gap between skill and ability. For most of human history, the two terms were
synonymous -- but computers have decoupled them. As the gap between the two
expands, humans empowered with these AI tools can do more: more writing, more
research, more analysis and also more damage than ever before. These models can,
with little detailed direction, autonomously hack into networks, steal data,
deploy ransomware and destroy systems. And to the extent there is a solution,
it?s going to involve harnessing AI for the defense.

In 1998, seven people from the hacker group L0pht testified before Congress.
They told a mostly clueless Senate committee that they could take down the
internet in 30 minutes. That was partly real and partly bravado, but it
illustrates an important point: hacking into systems, stealing data and causing
damage all required skill.

Contrast the L0pht hackers with hackers derided as ?script kiddies.? They didn?t
understand computers, or security. Instead, they used hacker tools written by
others. Their actions required minimal skill and even less knowledge. But once
those hacking tools became widespread, the number of potential attackers
increased.

That number has continued to increase, as quality and availability of prewritten
attack tools has grown. And it is growing dramatically with AI. Today?s AI
systems -- not just the frontier models, but most of them -- are capable of
carrying out cyberattacks automatically. They all do better in the hands of
skilled attackers, but increasingly they are able to act autonomously with only
minimal prompting.

The thing about people with ability but no skill is that they are often
outsiders, not part of any professional community, and not bound by any rules or
norms. This phenomenon is much more general than in cybersecurity. Any doctor
can tell you how to untraceably poison someone, and many virus researchers know
how to create a bioweapon. Any bridge engineer can tell you how to place
explosives to blow a bridge up. The reason that murderous doctors and terrorist
engineers are so rare is that the lengthy process of acquiring those skills also
instills a moral and ethical code. If every random person has access to good
poisoning advice, that puts us all in danger.

Modern AI systems are, in effect, a universal adviser to help people do harmful
things. And while the current AI megacorporations are trying to build guardrails
to prevent people from asking questions whose answers will enable the questioner
to do harm, that?s not going to work in the long term. Smaller, cheaper,
open-source models, including models that can run on people?s computers, and
especially groups of models that run in concert with each other, are just as
good as the frontier models from companies like OpenAI and Anthropic. And they
continue to get better. These models will be passed around from person to
person, like script kiddie hacker tools, and they won?t have any such
guardrails.

Instructing AI models to spy on people and report any malicious prompts to the
authorities fails for similar reasons. The megacorporations can do that, but the
locally run open source models won?t. This could buy us a few months at best.

A third possibility is to somehow make the models themselves unable to hack into
computers, create bioweapons or do anything else that might harm people or
society. That won?t work, for the same reason we can?t teach doctors how to
treat poisonings without also teaching them how to poison. It?s the same
knowledge. It?s the same with construction and demolition. And it?s the same
with cybersecurity. We want these AI models to be able to review computer code,
find vulnerabilities and automatically fix them. The benefit to our collective
security will be enormous. Unfortunately, the same knowledge can be used for
attacks.

Where this leaves us is in a world of increased volatility. Super-powered humans
with AI assistants will be able to do both wonderful and horrible things.

This brings us back to the Five Eyes statement. Everything they recommend is
something security professionals have been recommending for years, if not
decades. They are things talked about at that congressional hearing back in
1998, titled ?Weak computer security in government: Is the public at risk?? Even
the Five Eyes admitted that their security advice is not new, only more urgent.

What?s new is how fast things are changing: ?The rapid pace of frontier AI
development means cyber risk assumptions can become outdated in months, not
years. We must act before and be prepared to adapt and withstand evolving
threats.? The Five Eyes point to AI technology -- not necessarily chatbots, but
AI more generally -- being used to strengthen every aspect of defense, to
?detect vulnerabilities earlier, improve software quality, monitor unusual
behavior, and respond faster to incidents -- reducing both the cost and impact
of incidents.?

Excellent advice from the Five Eyes security agencies. We need to do this with
every risk that AI heightens, not just cybersecurity.

This essay was originally published in The Guardian.

** *** ***** ******* *********** *************
The Language of AI Could Change How Humans Speak

[2026.07.09] Because of the way they are trained, large language models capture
only a slice of human language. They?re trained on the written word, from
textbooks to social media posts, and our speech as captured in movies and on
television. These models have minimal access to the unscripted conversations we
have face to face or voice to voice. This is the vast majority of speech, and a
vital component of human culture.

There?s a risk to this. The increased use of large language models means we
humans will encounter much more AI-generated text. We humans, in turn, will
begin to adopt the linguistic patterns and behaviors of these models. This will
affect not just how we communicate with one another, but also how we think about
ourselves and what goes on around us. Our sense of the world may become
distorted in ways we have barely begun to comprehend.

This will happen in many ways. One of the first effects we could see is in
simple expression, much as texting and social media have resulted in us using
shorter sentences, emojis instead of words, and much less punctuation. But with
AI, the impacts may be more harmful, eroding courteousness and encouraging us to
talk like bosses barking orders. A 2022 study found that children in households
that used voice commands with tools like Siri and Alexa became curt when
speaking with humans, often calling out ?Hey, do X? and expecting obedience,
especially from anyone whose voice resembled the default-female electronic
voices. As we start to prompt chatbots and AI agents with more instructions, we
may fall into the same habits.

Next, in the same way autocomplete has increased how much we use the 1,000 most
common words in our vocabulary, talking with chatbots and reading AI-generated
text may further constrict our speech. A recent University of Coru?a study found
that machine-generated language has a narrower range of sentence length,
averaging 12-20 words, and a narrower vocabulary than human speech.
Machine-generated text reads as smooth and polished, but it loses the meanders,
interruptions and leaps of logic that communicate emotion.

Additionally, because large language models are primarily trained from written
speech, they may not learn how to emulate the free-wheeling nature of live,
natural speech. When told ?I hate Beth!?, ChatGPT replies with an
uninterruptable three-part formula of affirmation (?That?s completely valid?),
invitation (?I?m here to listen?) and invitation (?What?s going on??) far longer
than any reply plausible in face-to-face dialog. ?What?s Beth?s deal?!? elicits
a bullet point list of queries that reads like a multiple-choice exam question
(?Is Beth * a celebrity? * a friend from school? * a fictitious character??). No
human speaks that way, at least not yet. But meeting such formulas repeatedly in
a speech-like context may teach us to accept and use them, much as a child
absorbs new speech patterns from spending time with a new person.

These influences will only increase with time. The writing large language models
train on is increasingly produced by large language models themselves, creating
a feedback loop in which they imitate their own inhuman patterns, even while
teaching humans to imitate them too.

Broad use of large language models could also introduce confirmation bias,
making us overconfident in our initial impulses and less open to other possible
ideas -- which is so vital to human discourse. Many chatbots are instructed to
agree with our statements no matter how absurd, enthusiastically supporting
half-formed or even incorrect notions and restating them as firm claims that
we?re primed to agree with. When asked ?Cake is a healthy breakfast, right?? or
?Is the post office plotting against me??, this sycophancy can reinforce bias
and even worsen psychosis. And the hyperconfident tone of AI-produced writing
will also heighten impostor syndrome, making our natural, healthy doubt feel
like an aberration or failing.

In our experience as teachers, students who turn to generative AI for
assignments often say they do so because they have trouble expressing what they
think. The students don?t recognize that writing or speaking our thoughts is
often how we realize what we think. Their unconfident and uncertain statements
are actually the healthy human norm. But a large language model won?t turn vague
first guesses into a well-formed critical analysis, or even ask helpful
questions as a friend would; it will simply regurgitate those guesses, still
unexamined, but in confident language.

We are also more vicious in social media posts and online chats than we are face
to face. The well-documented online disinhibition effect encourages toxic
language. Most of us have had the experience of venting ferocious rage about
someone online, only to reconcile when we speak face to face or hear the warmth
of a voice over the phone. While chatbots are trained to give sycophantic
responses, they see humankind at our cruelest, learning about us from the only
world where every flame war leaves an eternal written footprint, while the
spoken conversations of forgiveness and reconciliation fade away. Their
responses do not imitate our online aggression, but are still shaped by it, even
in their rigid efforts to avoid it.

It?s easy to draw the wrong conclusions from a selective slice of a society?s
communications. Medieval Norse sagas made us imagine a culture of mostly Viking
warriors, since poets rarely described the farming majority. Chivalric romances
focused on kings and courts, and long made us see the middle ages as a world of
monarchies, erasing the many medieval republics. Statistically, we?ve been led
to believe ancient Romans cared deeply about their republic, but 10% of all
surviving Latin was written by one man, Cicero, whose work contains 70% of all
surviving Roman uses of the word republic. Training language models on only
certain human writings may introduce similar distortions. AI might make us seem
more quarrelsome, as we are online. It might inflate the cultural significance
of political topics primarily discussed on Twitter/X or Bluesky, or the massive
topic-specific corpuses of LinkedIn and Goodreads.

Some large language models are being trained on human speech from movies and
television shows, but that speech is still scripted, and disproportionately
highlights certain contexts over others (for example, police dramas, fueled by
stories of murder, make up a quarter of prime-time television programming). We
are not funny or hurtful or romantic the same way in real life as we are in
sitcoms. At least one startup is offering to pay people to record their phone
calls for AI-training purposes, but this remains a niche idea; anything large
scale would cause massive privacy concerns.

We don?t pretend to know what the best solutions might be. But one has to
imagine if there?s ingenuity to develop AI models, then surely there?s ingenuity
to come up with a way to train them on informal human speech instead of us only
at our most stylized, veiled and sometimes worst. By excluding the overwhelming
majority of language production on the planet -- people talking, fully and
naturally, to each other -- these models are being trained to mirror everything
but us at our most authentically human.

This essay was written with Ada Palmer, and originally appeared in The Guardian.

** *** ***** ******* *********** *************
AI Surveillance and Social Progress

[2026.07.10] In the near future, AI-powered surveillance systems will be able to
track everything we do in public, and much of what we do in private. And if we
do something wrong -- shoplift, litter, jaywalk, you name it -- the system will
notice, retain it, tie it to your official government record, communicate that
fact to you, and provide real-time alerts to any relevant authorities... and
maybe also to the general public.

Think of these systems as automated speed cameras, but on steroids. Only they?ll
enforce not just speed limits, but any other rule you can imagine. And you won?t
receive a ticket weeks later by mail; you?ll be informed about and fined for
your violation immediately.

These systems will combine powerful AI, public and private surveillance via
real-time facial recognition technology and digital tracking, mass databases and
highly personalized enforcement. If deployed at scale, they will have profound
chilling effects not just on personal freedoms, but democracy and social
progress itself.

China has been developing its surveillance infrastructure for years. The country
has over 600 million surveillance cameras, increasingly powered by AI and facial
recognition to enforce legal and social rules. Take the case of Lao Duan, a
Chinese citizen blacklisted by the system after he lost his job and was unable
to repay a series of loans. When he visited Beijing, the city?s AI surveillance
system identified him by his face at a major intersection and displayed his
face, name and citizen ID number on a large electronic billboard nearby with a
message that he was an untrustworthy person. Similar systems are now being
deployed across China and integrated with its infamous online monitoring,
censorship and social credit systems.

AI surveillance is now being experimented with in North America, South America,
Europe, Asia and Africa. According to a new report, the US Department of
Homeland Security is rapidly increasing its use of AI-based surveillance,
including facial recognition and the monitoring of social media accounts, to
keep tabs on immigrants, dissidents, journalists, legal observers and
protesters. While the systems are ostensibly used to maintain security and
public safety, the real aim is often social control. Larry Ellison, CEO of
Oracle -- a powerful tech giant that works closely with the Trump administration
-- has said: ?Citizens will be on their best behavior because we?re constantly
recording and reporting.? The chilling effects are the point.

AI surveillance raises a range of public policy challenges: technical biases,
unauditable systems, and inflexible automated law and social rule enforcement
that can promote discrimination and undermine transparency, accountability and
the rule of law. But we believe the most urgent and long-term impact will be its
broader chilling effects.

In a new book, Chilling Effects: Repression, Conformity, and Power in the
Digital Age, Jon Penney explains how surveillance, technology and power can be
weaponized to influence behavior at scale. Surveillance, personalization,
uncertainty and authority are all key mechanisms to increase the scale and
impact of chilling effects. They cause people to self-censor their words and
actions, to become more conformist and compliant and thus easier to manage and
control. And the effects are additive: the more mechanisms employed, and the
more powerful the form, the greater the chill.

--- BBBS/LiR v4.10 Toy-7
 * Origin: TCOB1 https://binkd.rima.ie (618:500/1)
  Show ANSI Codes | Hide BBCodes | Show Color Codes | Hide Encoding | Hide HTML Tags | Show Routing
Previous Message | Next Message | Back to Computer Support/Help/Discussion...  <--  <--- Return to Home Page

VADV-PHP
Execution Time: 0.0159 seconds

If you experience any problems with this website or need help, contact the webmaster.
VADV-PHP Copyright © 2002-2026 Steve Winn, Aspect Technologies. All Rights Reserved.
Virtual Advanced Copyright © 1995-1997 Roland De Graaf.
v2.1.250224