NaibofTabr

joined 3 years ago
[–] NaibofTabr@infosec.pub 1 points 1 week ago (1 children)

To each their own. I prefer having the ability to adjust things from 1 central source. I'm prone to losing remotes.

My preference is for devices to be as simple and reliable and end-user repairable as possible. I have an aversion to any kind of appliance that might be dependent on someone else to update software or maintain a network service to keep operational. No software dependence at all if possible, just a basic microcontroller and firmware. Again, there's nothing to this that needs to be any more advanced or complicated than the functions of a basic alarm clock like this:

Instead of setting off an alarm, we're activating the feeding mechanism. Dead simple. Hell, you could probably make this yourself by wiring the alarm from a clock like this to a motor that moves the feeding mechanism.

Also, how would you do such a remote. You would also need a screen for feedback etc, which puts you back at square 1.

Nah, there's no reason feeding times need to be any more granular than per-hour. You can show that with a 2x6 grid of 12 indicator LEDs, with a 13th AM/PM indicator. On lights indicate hours when feeding will activate. You could have that on both the remote and the feeder, cheap and easy. Maybe you have a 14th indicator that lights up if the food in the storage bin is low and needs refilling.

Also, a remote would be considerably more expensive than the extra cost of a ZigBee/Wifi enabled microcontroller.

Definitely not, because it's not fair to count the cost of only the link hardware on the feeder, you have to account for the cost of the rest of the smart home system to operate it. A remote like this is dirt cheap:

You're over thinking what this really needs to do. It's a timer that activates a switch, that's all.

[–] NaibofTabr@infosec.pub 3 points 1 week ago (3 children)

OK, add a simple remote control with buttons for adjusting the schedule and triggering a manual feed. No need for that to be any more complicated than a TV remote from the 90s. Keep it offline, no problem.

[–] NaibofTabr@infosec.pub 3 points 1 week ago

God forbid the user have to push a button on the device itself.

[–] NaibofTabr@infosec.pub 35 points 1 week ago (7 children)

Why in fuck would a device that activates a motor once or twice a day on a schedule need any kind of network connectivity? This is an ultra-dumb programmatic function, it shouldn't need any more compute power than an alarm clock. Why would you hook it up to a smart home anything?

It should be exactly this complicated:

Anything beyond that is like killing a housefly with a bazooka.

[–] NaibofTabr@infosec.pub 29 points 1 week ago

Or push ads, or gather data on users.

[–] NaibofTabr@infosec.pub 1 points 2 weeks ago

If the smugglers are even marginally competent they won't use their real personal information for the orders, nor the same fake information from one order to the next.

[–] NaibofTabr@infosec.pub 11 points 2 weeks ago (1 children)

But it's called an "agent"! Of course it has agency!

[–] NaibofTabr@infosec.pub 3 points 2 weeks ago* (last edited 2 weeks ago)

Oh absolutely, I think that is already happening, but it hasn't reached broad public awareness yet. Reddit has 20 years of momentum, it won't stop all at once.

I suspect the company is aware that user engagement is dropping, along with the quality of new content. Typical of most corporations, their response is to play defensive, to try to maximize the value of what they already have, to scratch and claw and squeeze every drop from the existing data and userbase. This will accelerate the decline, obviously, but when a company is in this state they consider any strategy besides protectionism to be too high a risk.

They will ruin themselves with cowardice, to be sure, but they're still coasting on momentum for the moment. They will continue making the same types of decisions, at an accelerating pace, as the desperation sets in.

[–] NaibofTabr@infosec.pub 42 points 2 weeks ago* (last edited 2 weeks ago) (9 children)

"Vhen rockets go up, who cares vhere zey come down? Zat's not my department!"

Sarcasm aside, you can buy these in dev kits on MicroCenter:

https://www.microcenter.com/product/691058/nvidia-jetson-orin-nano-super-developer-kit

Which means the components are pretty widely available. I'm not sure how you'd prevent someone from ordering a bunch to an in-between country and then shipping them on to Russia after.

[–] NaibofTabr@infosec.pub 44 points 2 weeks ago* (last edited 2 weeks ago)

Valve shares delivery-related information with CEVA so that it can ship Steam hardware in Europe, and it appears that this personal data is what was stolen. This personally identifiable information (PII) may include your name, address, country, phone number, email address, and the details of the products you ordered. CEVA stores customer data for up to 90 days after an order is assigned to them, which means that the data for lots of customers may have been leaked. Fortunately, payment information, Steam account details, authentication codes, and more are not stored at CEVA.

The leak was not from Valve but from the shipping company used to distribute their hardware in Europe. Your Steam account details are not leaked, but any information related to shipping probably is.

Following this breach and the subsequent exfiltration of data, Valve has asked customers to be wary of contact attempts from fraudulent entities who have taken hold of your leaked information and may use it to prove that they are genuine. Customers do not need to change their passwords, but they definitely should not share their account details with any person identifying them as a courier service for your hardware.

[–] NaibofTabr@infosec.pub 3 points 2 weeks ago (3 children)

Not like reddit is relevant these days.

Even within the lemmy user community people still occasionally refer to reddit because there isn't a better source for some things. Outside of lemmy, reddit is a household name alongside facebook, snapchat &etc; people who don't use it still know what it is. I think your conclusion is more aspirational than currently real.

[–] NaibofTabr@infosec.pub 10 points 2 weeks ago

Volume, and breadth of subject material. For language model purposes the specific content isn't really important, it's the wide variety of language samples from many sources, all in the same data format. You could get similar samples from other platforms, but you'd have to compile them from multiple sources and then standardize them somehow for input as training data.

view more: ‹ prev next ›