• 0 Posts
  • 463 Comments
Joined 2 years ago
cake
Cake day: June 16th, 2023

help-circle

  • If you were being properly pendantic, you’d realize that the term AI has existed for fucking decades prior to the current LLM boom and even machine learning, and has regularly and repeatedly been used to describe the type of (comparatively) simple algorithms used to manage NPC actions in video games.

    You may also know that Valve recieved a shit ton of press praise for the complexity of the algorithms and tricks they used to give their NPCs life in a large number of their previous games. Simulating predator/prey dynamics in aliens, command structure in soldiers, and even making the appearance of troops communicating information audibly (both human soldiers and aliens having specific phrases and sounds for different situations) all in Half Life 1.

    With Half Life 2, they made a large stride pushing back against the uncanny valley through how they managed facial animations. They also made groundbreaking use of pathing nodes with different contexts which allowed NPCs to build off the communication and dynamically flank you (outside of the previously common scripted set pieces). Also some stuff that’s escaping me right now with player led platoons.

    In Left 4 Dead, they used one set of algorithms to direct the overall PvE match flow, a separate one to handle large groups of enemies as a group, and then even more to manage individual enemy entities when they were close enough to players. Again, groundbreaking for the time, with many PvE and horde defense games since adopting similar “director” algorithms.

    In every single aritcle written about this shit, the term AI was used. In articles about monsters in the original DOOM, the term AI was used.

    Effectively “it was our word first”.




  • being born into a little seed cash and enough comfort to go a while without working a straight job. As Julie says when someone repeats that Amazon was started in a garage: Ain’t no garages in the trailer park.

    We need look no further than the “hackathon,” that sad facsimile of the days when we were all learning the basics so fast that the world could be ours with just a day or two of focused effort. Hype up an exciting atmosphere, assemble some folks with so few attachments in life that they have time to spend all weekend at a hackathon, and this ritual will summon up the old gods. The hackathon is the proof that people believe this can work, and it is the proof that it doesn’t.



  • I’m not exactly calling bullshit, but I’ve worked almost the entire last decade in IT in a Windows environment that has a decent amount of RDP use and has grown from ~2000-4000 employees during that time.

    We’ve never encountered this as described. Whatever this situation that allows the cached password to persist indefinitely is, it is a situation that would need to be engineered by the attacker.


    From what I can tell, this “exploit” is just the standard NT password caching functionality that Windows has had for literal decades. Windows caches the last valid password used to log in, so if you lose your connection to your identity provider (AD or Entra) you can still log in with the last password confirmed to be valid.

    In AD environments, this is what allows you to log into your laptop at home before you connect to VPN. You can’t hit your work AD before you’re on the work network. It also causes some fun because if you changed your password at work but didn’t lock and unlock your computer with the new one, it might still have your old one cached for the login screen but need the new one for VPN. This was a fairly common support call (I’m out of direct user support now so I can’t easily see if it still is).

    Any situation where an old password would be valid indefinitely and a new one not recognized would require the machine to not be able to reach AD or Entra, but also to still be reachable by RDP… indefinitely. That’s definitely not impossible, but it’s one hell of an edge case to use the term “indefinitely” for.

    It’s annoying that there aren’t separate settings from “local logins with AD as the IDP” and “remote logins with RDP” or “logins with Entra”, but this feature is pretty damn critical for remote workers to be able to function and it is an intentional design choice as Microsoft states. Any potential workaround for a theoretical lack of this functionality is worse than the current state. Can’t rotate passwords on a local break glass account if the machine can’t reach your IDP, leaving effectively the same hole except with an account known to have elevated access.

    There’s no nefariousness here or lack of due dilligence. Labeling it as some horribly dangerous security hole with the amount of vagueness this article has is just misleading and clickbaity.


  • On paper, it’s one of the uses for AI image recognition. It could reduce the amount that needs human review drastically.

    In reality, Youtube’s partially automated system (to my knowledge the most robust one around) regularly flags highly stylized videogame violence as if it is real gore. It also has some very dumb workarounds like simply putting the violence more than 30 seconds into the video (which has concerning implications for its ability at filtering real gore).



  • Edit: missed the context. This was about Torvalds, not Tech Tips

    Theres a lot more problems than that. Both GamersNexus and Louis Rossman have made videos on it.

    Shady sponsor deals. Making huge mistakes when testing things from new small companies (one guy machining custom watercooler blocks), calling the device garbage because their own mistakes caused it not to work, refusing to return the prototype one they tested as they had agreed to, and then auctioning it off. Claiming all of that was just honest mistakes while making no efforts to make it right and doubling down on calling it shit. Many many cases of Linus just being an abusive bastard of a boss behind the scenes. Many cases of anonymous current and former employees talking about toxic workplace culture (coming from the top down), insane crunch, deadlines set too tight that cause issues in reviews.

    Regular smaller mistakes in their reviews and videos with no standard company policy on how they should go back and edit them to inform viewers of the mistake. Numerous cases where they acknowledge the mistake privafely but refuse to even add a pinned comment to the video.

    His team knew about the Honey extension, one of their sponsors, being a scam. It hijacked any links to online stores nd made them referal links to kick back money to Honey. While countless other youtubers made exposes about it he refused to say anything about it to his viewers and then had a tantrum on the podcast about how it was unfair to expect him and his team to say anything about it after he was called out.

    Every. Single. Time. When Linus is called out on this stuff in a large enough way, he throws a very public tantrum.

    At best, Linus is an overgrown child who is unfit to run a business of the size and clout his has.