AmbitiousProcess

joined 1 year ago

all android devices have been using file based disk encryption since several Android versions now.

All Android devices are supposed to support it, but not all do. (or at least, not all do effectively without compromising the cryptographic root of trust by not implementing proper hardware security chips)

I'll grant it to you on the scopes, PIN changes, etc, but realistically I just don't think anyone can justify GrapheneOS being something that should be supported on Fairphone given how absolutely desolate the phone looks with regard to any attempt at all to hardware security.

[–] AmbitiousProcess@piefed.social 15 points 5 days ago (4 children)

It really depends on what security level you want out of a phone

It does, but that's exactly my point. GrapheneOS will provide you essentially no more security than any other alternative Android operating system, should it have to operate on a Fairphone with all those features not supported by a Fairphone stripped away.

Unless Fairphone adds more hardware security features that are standard on most other phones, and highly supported on Pixels, installing a heavily crippled GrapheneOS on a Fairphone would get you essentially none of the benefits of GrapheneOS in the first place.

[–] AmbitiousProcess@piefed.social 86 points 5 days ago (13 children)

Entirely lacking disk encryption for typical users due to not having a secure element is a pretty major flaw.

It's also missing hardware accelerated virtualization which is necessary for much of GrapheneOS's sandboxing, has weak security for other keys in the OS keystore, is missing hardware memory tagging which makes it much easier for apps to use overflow attacks, doesn't have proper verified boot support once a custom alternative OS is flashed, and leaves exposed debugging APIs even when the phone is locked.

This breaks:

  • Secure app spawning
  • Memory corruption protection
  • Integer overflow protection
  • Most of Graphene's kernel hardening
  • Much of Graphene's attack surface reduction abilities
  • Hardware-based attestation and security monitoring
  • Quick tile protection pre-unlock
  • Debugging access prevention
  • Verified Boot
  • The security of your PIN against any automated attack

At that point, GrapheneOS can't physically provide you essentially any security anymore.

[–] AmbitiousProcess@piefed.social 68 points 5 days ago (15 children)

It wasn't just the update cycle either, it's that they don't have the physical hardware chips to support Graphene's minimum requirements for security, which would severely weaken any benefits you actually get from GrapheneOS.

Especially given it has a similar effect to how spam emails are often deliberately bad so they just don't waste their time with people that waste some of their time before wising up. If you only get the most easily duped people in the first place, that's a lot less time wasted.

With LLMs, you're explicitly targeting people that are less likely to strongly ideologically object to things (like LLMs, or genocide funding) on moral grounds, you're getting the people that are willing to just get a quick answer without having to look into it deeply, and you're getting the people who's sole goal it is to flood the web with any SEO-optimized slop they can with the least effort possible.

LLMs self select for people not willing to put in cognitive effort, that are easily influenced and less careful about fact-checking things.

[–] AmbitiousProcess@piefed.social 1 points 1 week ago (5 children)

Two is many?

And no, if you think spellcheck and language translators are slop, then unfortunately for you, a sizeable chunk of all written content ever created on the internet has been "slop" since far before LLMs even existed.

Regardless, I think it's clear at this point you don't give a fuck and just want to be angry, so I'll stop and hopefully you won't burst a blood vessel or something.

Please calm down.

[–] AmbitiousProcess@piefed.social 1 points 1 week ago (7 children)

"the use of LLMs to generate or rewrite article content is prohibited"

"[LLM generated] edits to existing pages may be reverted without review, and pages where the editor is the only significant contributor may be nominated for a special proposed deletion process"

Does that seem like condoning slop to you?

Again, there are only two highly limited exceptions: spellcheck (whaddaya know, the thing who's entire purpose is to predict likely words is good at being a thesaurus and grammar checker.), and translation (you must be skilled in both used languages, re-check every source and its claims, and read through the entire article for hallucinations while crosschecking with the original document's other language version)

This is why I stated earlier that you seem to just want something to be mad about. Wikipedia is just only allowing LLMs to be used for cases they already allowed with non-LLM tools prior, that LLMs are also more typically reliable in, while mandating extensive human review.

You are getting angry and calling me a dumbass because Wikipedia allows the narrow functions of something performing the exact same functions as spellcheck or Google Translate 💀

[–] AmbitiousProcess@piefed.social 6 points 2 weeks ago (9 children)

unlike you I don’t condone slop

Quote where I condoned slop. Oh you can't? That's so crazy, it's almost as if I didn't.

maybe don’t die on the hill trying to defend it in my proximity

Sending you links to the actual policies instead of just relying on your made up assertions of what the policies are is dying on a hill? You're the one dying on a hill you made up lol

And btw my link was also a direct link to Wikimedia, the nonprofit who owns Wikipedia.

You linked to a blog post by Wikimedia that's over a year old. I linked to current Wikipedia policies.

Which do you think is more reflective of the organization's current stance:

  • A single blog post written by two people over a year ago
  • Multiple guideline and meta consensus documents cooperatively developed by hundreds of editors, and currently enacted as policy across all of Wikipedia.
[–] AmbitiousProcess@piefed.social 6 points 2 weeks ago (12 children)

(From the Meta-wiki page on the topic)

"Our use of AI will allow editors to focus more on what they want to accomplish, not how to technically achieve it."

"we cannot significantly support editors with AI for both content generation and content integrity at the same time. We made a decision to first prioritize using AI to support editors to assure content integrity."

"generative AI in particular offers a promising solution for automated mentoring and guidance of newcomers"

"we should prioritize using AI to support knowledge integrity and increase the moderator's capacity to maintain Wikipedia’s quality"

(From the most current page regarding AI use policy on Wikipedia and the LLM Writing Guide)

"the use of LLMs to generate or rewrite article content is prohibited"

This is categorically an outright refusal to allow LLMs as a method of simply generating content. The only exceptions are for language translation (with many caveats), and for minor grammar corrections.

i.e. the shit you could do with a tool like Google Translate or Grammarly/LanguageTool/Word Spellcheck/etc, just done via a different mechanism, with anything past that being outright prohibited.

Also, it is punished, via the same means any transgression on Wikipedia is. See: https://en.wikipedia.org/wiki/Wikipedia:Disruptive_editing#Persistent_LLM_use and https://en.wikipedia.org/wiki/Wikipedia:Disruptive_editing#Dealing_with_disruptive_editors

Do you even edit Wikipedia? Have you had to rewrite or remove LLM content and put warnings on people's talk page? Have you reviewed the live changes feed to repeatedly see LLM-generated content getting removed? Or do you just want something to complain about while ignoring what actually happens on Wikipedia because you don't seem to even have read a single meta or guidelines page on the topic?

[–] AmbitiousProcess@piefed.social 16 points 2 weeks ago

Exactly this. They are guaranteed to get scraped regardless. Ask any question of an AI model and the first 'source' it cites is almost always Wikipedia. (assuming it's not like a super technical in-depth question)

Might as well save on server overhead costs and get paid while doing it instead of trying (and failing) to block every possible scraper.

[–] AmbitiousProcess@piefed.social 8 points 2 weeks ago (14 children)

People choosing to post slop edits on Wikipedia means Wikipedia itself is supportive of AI?

Besides, I've regularly seen AI generated content get labeled as LLM-generated (and marked for cleanup/removal), removed AI content myself, and seen editors revert obvious AI slop content within a minute of the edit being made. AI is absolutely not something Wikipedia or most of its editors support.

[–] AmbitiousProcess@piefed.social 38 points 3 weeks ago (1 children)

Yep. If you want to record everything going on from your POV, strap a GoPro to your head and see if people's moods change about it. If they clearly don't want that, they don't want the "convenient" hidden cameras either. Simple as that.

view more: next ›