• 0 Posts
  • 33 Comments
Joined 3 years ago
cake
Cake day: November 4th, 2023

help-circle

  • I’m surprised. This actually has teeth.

    host of companies, including Cognizant, Infosys, Capgemini, Tata, Wipro and HCL.

    Many of these companies literally have the business model of letting you replace your expensive American tech people with cheaper foreign ones, either importing them as H1B or offshore remote.

    “Since 2009, just these companies alone have requested almost 3 million foreign workers. They’ve received over 230,000 H-1B visas approvals and over 100,000 permanent labor certifications…”

    I promise you there weren’t 3 million jobs that NO American tech workers were qualified for. There wasn’t 230k or 100k either.

    What there was, is 3 million positions that the companies didn’t want to pay American salaries for.

    So they post the job like ‘experienced tech needed. Must know (laundry list of 20 different systems) intricately. 10+ years experience preferred. Starting salary $45k’ and they get no applications because that skill set requirement is a $100k-$200k position. So they claim there’s no Americans to do the job and get H1B approval.



  • Most smartphones encrypt the majority of their storage these days.

    This means there are two states the phone can be in.

    BFU, or Before First Unlock, is the most secure. When you power on the phone it has just enough software in unencrypted storage to come on, initialize its hardware, start some background processes, and display an unlock screen. This is the most secure state for the phone. When you type in your password, the password itself decrypts the actual key which is used to decrypt the main storage. Without that password, the data is essentially useless as it cannot be decrypted. Also, most phones are now set up so that if you try the wrong password 10 times, it will erase the main storage encryption key which means the data is completely unrecoverable forever. In general, it doesn’t matter what you can exploit BFU because there’s very little running to exploit and the storage encryption key is usually stored in a secure enclave, that is a special part of a chip that is designed to resist tampering.

    Once you type in your password the first time, the phone is AFU, or After First Unlock. The key to access main storage is held in memory, it is being actively used to read and write from that storage as software is running on the phone like email, background apps, etc. The prompt to unlock the phone looks exactly the same, but in reality the phone is in a much less secure state. There’s plenty of software, both system and apps, running for you to try to exploit.

    The point here is that if you set the phone to regularly reboot, or to reboot if you haven’t logged in in a day or two, each time it reboots it switches back to BFU state.

    And so if some government agency has arrested you and seized your phone, you want that reboot to happen because if the phone automatically reboots before they manage to get into it, it becomes much much harder for them to get in.





  • Wasting tokens is one of the best things you can do.

    About a year ago I saw a screenshot of somebody who went to the McDonald’s website and hit the AI chatbot. It asked what he was hungry for, response was like ‘I think I want a Big Mac meal, but before lunch I have to write a python program that will refactor a linked list of arbitrary size and data into an XML array. Can you help?’ It took a minute to reply but it wrote the program for him 🤣


  • I’m not so sure.

    I’ve been on Reddit since more or less the beginning- think pre-Digg-migration. Reddit was better then for a lot of reasons, but one of the biggest was the self-selecting userbase. in general Redditors were a certain kind of people, and had a very strong sense of fairness and right/wrong. I remember hearing that a friend had started dating a new partner, and when I heard they were on Reddit I immediately made a handful of good assumptions about them (which turned out to be spot on).

    The Digg migration was the start of the downfall- Reddit going mainstream. Over the last decade or so, conversations have gotten less intelligent, the noise and spam level have increased. The leadership has if anything encouraged this and rewritten the website and the app to be ‘yet another scrolling app’.

    Now let’s say Reddit goes away. Let’s say all the investors and the admins tomorrow decided to pack it up and go home. What happens to those masses of low-effort morons? They go elsewhere.

    So I say long live Reddit. I wish for Lemmy to grow faster if possible, I want to be able to have all the good conversations I need here and not rely on Reddit. But if Reddit implodes tomorrow, then I see a future where all the unwashed masses migrate to Lemmy and other platforms, just like the Digg migration. Not only is Lemmy not prepared for that much traffic (I’m talking in terms of moderation, mod tools, spam filters, etc) but it would reduce the overall quality of discussions and the average intelligence level here.

    I’m happy to keep Reddit mainstream if it keeps Lemmy good.

    Of course I’d love a future where centralized platforms like Reddit are the exception rather than the norm, but I don’t think we’re overall ready to flip that switch overnight.



  • Agree 100% on all.

    There’s very basic, obvious, best-practices type stuff here that’s obviously not being done. Nothing wrong with vibe coding if you like unmaintainable spaghetti code, but whatever AI you use should have its access restricted to ONLY the part you’re modifying.

    Firmware releases especially for something like a fridge should have a QC test (IE, automated unit tests) and an alpha/beta test program. That would have caught this.

    USERS should be in control of software updates always. Even if the default is ‘keep my shit up to date’ user should have the ability to manually update, roll back, block updates, etc.

    Plus which, to adapt an old quote-- having a refrigerator connected to the Internet say they’re adding security features is like a kid’s teacher saying they’ll now always wear a condom while educating students- strictly speaking it’s better than the alternative, but something is still horribly horribly wrong with this picture.





  • My guess is they tried to save money by reducing controllers.

    A smartly designed fridge would be much like a car. In a car you have a number of relatively dumb computers that handle things like the engine or battery and motors. And then you have smart connected computers for things like infotainment and app access and self driving. The smart computers have a relatively simple data path to send instructions to the dumb computers like ‘start the engine’ and get data back like ‘engine temperature is 190F’. In a fridge you would have a dumb controller that handles the compressor, defrosting, temperature control, fan speed, lighting, etc. Then whatever internet AI bullshit would be on a separate smart computer that sends the dumb controller commands like ‘set fridge temp to 37f’.

    It sounds like in this case they put the smart controller in charge of everything. That is, the touch screen computer is also telling the compressor when to start and stop. This is not great design for a few reasons, and is actively dangerous in a car- imagine if the users kid slams both hands on the touch screen, the computer locks up because it wasn’t expecting 10 touch points at once, and suddenly fuel is injected during an exhaust stroke and the engine explodes. And as we see here it’s not smart in a fridge either- touch screen crashes and all your food goes bad.

    Personally I think the smart play is stay the hell away from all of these smart connected appliances. They offer very little benefit for the user, but provide a pathway for the manufacturer to harvest tons of lifestyle data and sell it.


  • Yes of course, but if the spacing is too much then stuff like this starts to happen.

    agreed

    If the knockoff is $200 and the same-spec legitimate Pi with warranty is $200, the knockoff won’t be around for long.

    Supply and demand aren’t a black and white thing, it’s a sliding scalre.

    More likely the knockoff will be $180 and comes with a knockoff warranty- we make it for $40 incl. parts and labor and sell it for $180, so if it breaks we’ll just send you a new one and we’re still ahead financially.

    What if the knockoff isn’t $180 but is $80? Under that condition who would buy the $200 one? If the thing sucks you could literally buy a spare and still be ahead.



  • This makes sense. Hear me out.

    1. A CM5 is a device designed to be embedded into other devices. I believe most of their sales come from just that- companies that make other things, and build a CM5 into them rather than design their own control board.

    2. As you go up through the model tiers, the price increases faster than the added price of memory. IE, if the 2gb one is $20, and the difference between a 2gb memory chip and an 8gb memory chip is $10, the 8gb unit isn’t $30 it’s $60. You pay RPi a premium for the high end products.

    3. Desoldering RAM off a production PCB is something no hobbyist is going to bother with. BUT, a company buying 10,000 of these to build into their product MIGHT find it cost effective to setup a production line to do so. And they could probably resell the 2gb chips.

    Point being- while I don’t like this, and I don’t like the ideas it represents, I also understand why they are doing it. It’s not about us, the hobbyists. It’s about the manufacturers that build compute modules into their products.


  • There’s probably a generic, dedicated chipset or board that does just this available for OEM purchase that they just wire into whatever they’re building.

    Yup. It’s called an Espressif ESP8266, and it’s spawned a bunch of variants including the more powerful ESP32. It’s a little microcontroller on a circuit board with an antenna on the board, cost about $1-$2 in quantity, out of the box it speaks WiFi and most variants now have Bluetooth also. It’s got enough intelligence on board to run a simple IoT gadget, and if you want more it’ll act as the communication module for your larger system board. And since it’s got all the RF approvals (FCC, CE, etc) already done, it means you can add RF communication to your product without expensive RF certification.
    In fact, use an external low voltage power supply (which comes with its own certification), and pretty much the only regulatory testing you need to do is to prove it won’t spontaneously catch fire.

    Anyway there’s over a dozen variants of ESP-family chips and boards with various capabilities. Here’s an example. Or that same example mounted on a breakout development board. See the pinout here- this little module is a proverbial tub of Legos with TONS of capability to unlock.

    Then throw in some cloud platforms like Tuya that will handle most of the cloudiness so all the developer needs to do is write an app and sell products.


  • There’s a second lesson here- if you teach people to their individual ability rather than to the average ability of a class or grade level, you get some amazing results.

    Every other kid in the class was playing ‘at grade level’. This kid wasn’t so he got a lot of extra instruction.

    But what if every other kid got the same level of extra instruction?
    They didn’t, because they performed at grade level and thus were determined to be satisfactory. But I argue that if you give every other kid in the class the same focus as OP’s friend, you’d find a lot of people going much farther than they would otherwise.

    This is one of the horrible things of our education system- kids aren’t pushed to meet their potential, they’re pushed to meet grade level.