Want to wade into the snowy surf of the abyss? Have a sneer percolating in your system but not enough time/energy to make a whole post about it? Go forth and be mid: Welcome to the Stubsack, your first port of call for learning fresh Awful you’ll near-instantly regret.

Any awful.systems sub may be subsneered in this subthread, techtakes or no.

If your sneer seems higher quality than you thought, feel free to cut’n’paste it into its own post — there’s no quota for posting and the bar really isn’t that high.

The post Xitter web has spawned soo many “esoteric” right wing freaks, but there’s no appropriate sneer-space for them. I’m talking redscare-ish, reality challenged “culture critics” who write about everything but understand nothing. I’m talking about reply-guys who make the same 6 tweets about the same 3 subjects. They’re inescapable at this point, yet I don’t see them mocked (as much as they should be)

Like, there was one dude a while back who insisted that women couldn’t be surgeons because they didn’t believe in the moon or in stars? I think each and every one of these guys is uniquely fucked up and if I can’t escape them, I would love to sneer at them.

(December’s finally arrived, and the run-up to Christmas has begun. Credit and/or blame to David Gerard for starting this.)

      • froztbyte@awful.systems
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        (note: out-of-order to linked post for comment cohesion)

        Terminals are an invisible technology to most

        what a fucking sentence

        …that are hyper present in the everyday life of many in the tech industry.

        hyper? like this?

        But the terminal itself is boring, the real impact of Ghostty is going to be in libghostty and making all of this completely available for many use cases. My hope is that through building a broadly adopted shared underlayer of terminals around the industry we can do some really interesting things.

        oh good so the rentier bridgetroll wants to do just a monopoly play? that’s fine I’m sure. note: I don’t think there’s a more charitable reading of this. those shared underlayers already exist, in the form of decades of protocol and other development. many of them suck and I agree about trying to do better, but I (rather strongly) suspect hashi and I have very different ideas of what that looks like

        I’ve already addressed the belittling of the project I really find useful and care about. So let’s just move on to the financial class.

        Regardless of my financial ability to support this project, any project that financially survives (for or non-profit) at the whims of a single donor is an unhealthy project

        “uwu, think of the poor projects. yes sure I could throw $20m at this in some kind of funny trust and have it live forever but that wouldn’t allow me to evade the point so much!”

        I paid a 9-figure tax bill and also donated over 5% of my other stuff to charity this year

        “I’m not as bad as the other billionaires I promise

        • gerikson@awful.systems
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          I’m too fucking old to care about hipster terminals, so I had no idea ghostty was started by a (former) billionaire. If forced to choose a new terminal I will certainly take this fact into consideration.

    • swlabr@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      bring back rich people rolling their own submarines and getting crushed to death in the bathyal zone

    • istewart@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      ghosTTy is the username of a schizoposter on Something Awful who only shows up to post bitcoin price charts and get mocked into oblivion. I wonder if there’s any connection?

    • froztbyte@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      I took psychic damage by scrolling up and seeing promptsimon posting a real doozie:

      I have been enjoying hitting refresh on https://fuckthisurl/froztbyte-scrubbed-it-intentionally throughout today and watching the number grow - it’s nice to see a clear example of people donating to a new non-profit open source project.

      “oooh! look at the vanity project go! weeeee, isn’t having a famous face attached to it fun?” with exactly no reflection on the fucking daunting state of open source funding in multiple other domains and projects

    • flere-imsaho@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      all things aside, is current ghostty any good, or still an audiophile consolephile-ware?

      i’m generally reluctant to try something which reeks of intensive self-promotion, but few months ago i decided to finally see what’s the hype about, and, well, it’s a terminal emulator.

      wezterm does much more, and with a much cleaner ui, and it’s programmable, and the author doesn’t remind me that hashicorp is a thing that exists.

      • froztbyte@awful.systems
        link
        fedilink
        English
        arrow-up
        0
        ·
        8 days ago

        been giving it a whirl for a few weeks now and greatly enjoying it. one or two minor snags I still need to solve (such as back-kill-word not working in search, just haven’t looked into it yet) but otherwise fairly pleased

        and I no longer have to see the stupid iterm2 update nag every damn day

        config.keys and hot reload are nice

  • froztbyte@awful.systems
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    saw this elsewhere. the account itself appears to be a luckey stan account, but the next

    There’s more crust than air or sea or land… so a vehicle that moves through the crust of the earth is going to be a huge deal

    I have built working prototypes of this

    so are we talking mining, or The Core (2003)? it feels like he’s trying to pitch it as though it’s Tiberian Sun style subterrean APC, but I can’t be sure whether I’m reading into it

      • CinnasVerses@awful.systems
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        Cinnas

        The Rolling Stone article is a bit odd (it appears to tell the story of the ex-employee who created Miricult twice, the first time without names and the second naming the accuser) but I trust them that MIRI did pay the accuser. Rolling Stone are a serious news organization which can be sued.

        • GorillasAreForEating@awful.systems
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          2 months ago

          Yeah, I think Rolling Stone was worried about getting sued and omitted Helm’s name in the first draft (or something like that).

          I know who the alleged victim was, and I think there probably was a crime and blackmail payments but the alleged victim didn’t want to come forward for a number of reasons (among other things, he’s still part of the rationalist community and has faced a lot of harassment from the public after an unrelated newspaper article outed him as being trans). I’d also point out that the only person that miricult directly accused of statutory rape was one of Yudkowsky’s employees rather than Yudkowsky himself. That being said, the journalist who wrote the Rolling Stone article claims she got a copy of the police report Helm filed and only Yudkowsky was named.

          Even if miricult was total bullshit I’m confident that the alleged victim was lying about not being exploited by other rationalists; a few years later he and a couple of other people posted accounts of being sexually abused by a rationalist (unrelated to miricult) and it led to the abuser being ostracized from the rationalist community.

          Anyways I know a lot more about this but I’d rather not discuss the details on a publicly viewable forum to protect the privacy of the people involved.

          • CinnasVerses@awful.systems
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            I agree that its gross to discuss a lot of this in public, and that underage sex is often an ethical grey area. I had no idea that the person who accused BD of pushing him into substance use and extreme BDSM scenarios is also the person who allegedly had sex underage with a MIRI staffer while living in a Rationalist group home.

            • GorillasAreForEating@awful.systems
              link
              fedilink
              English
              arrow-up
              0
              ·
              2 months ago

              Ziz’s blog had posts that revealed his identity and mentioned some of the BD stuff, once I found them it was just a matter of putting two and two together, so to speak

      • Soyweiser@awful.systems
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        “Nah, salary stuff is private”, starting to think this sort of stuff is an idea introduced to protect capital and nobody else.

        • swlabr@awful.systems
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          I was teasing this out in my head to try come up with a good sneer. First thought: for an organisation that tries to appeal to EAs, you’d think that they would do a good job of being transparent about why so much money is being spent on someone with such low output. But immediate rebuttal: the whole point of the TESCREAL cult shit is that yud get free tuocs because he’s the chosen one to solve alignment.

          • Soyweiser@awful.systems
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            Was thinking more about how the radical, dont fall to biasses think for yourself and cone here to really learn to think (so we can stop the paperclipmachine and resurrect the dead) defend a half million dollars salary with a ‘thats private’.

            But that is the same conclusion. The prophet must be protected.

        • swlabr@awful.systems
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          I believe he was trying to explain why it looked like MIRI had paid money out to an alleged sexual abuser. The analogy was constructed something like this:

          1. A and B work at a company C
          2. A has conflict with B.
          3. C decides to fire B.
          4. unrelated to 1, 2, or 3, B has a wife D, who dies in mysterious circumstances, leading A to strongly believe that B killed D.
          5. The police, E, perform an investigation and decide not to pursue a case against B
          6. C pays out B’s severance, unrelated to 2, 4, or 5.

          Don’t blame me or how I remembered this if this doesn’t make sense.

          • Architeuthis@awful.systems
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            Additionally he said something to the effect of I don’t blame you for not knowing this, it wasn’t effectively communicated to the media like it’s no big deal, which isn’t really helping to beat the allegations of don’t ask don’t tell policies about SA in rat related orgs.

            • swlabr@awful.systems
              link
              fedilink
              English
              arrow-up
              0
              ·
              2 months ago

              Can confirm. This was like if the pope walked into an r/atheism meetup and showed his texts saying “dw bro, I’ll just move you to a different diocese, btw this totally isn’t about the allegations wink wink”

  • Seminar2250@awful.systems
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    something i was thinking about yesterday: so many people i respect used to respect have admitted to using llms as a search engine. even after i explain the seven problems with using a chatbot this way:

    1. wrong tool for the job
    2. bad tool
    3. are you fucking serious?
    4. environmental impact
    5. ethics of how the data was gathered/curated to generate[1] the model
    6. privacy policy of these companies is a nightmare
    7. seriously what is wrong with you

    they continue to do it. the ease of use, together with the valid syntax output by the llm, seem to short-circuit something in the end-user’s brain.

    anyway, in the same way that some vibe-coded bullshit will end up exploding down the line, i wonder whether the use of llms as a search engine is going to have some similar unintended consequences — “oh, yeah, sorry boss, the ai told me that mr. robot was pretty accurate, idk why all of our secrets got leaked. i watched the entire series.”

    additionally, i wonder about the timing. will we see sporadic incidents of shit exploding, or will there be a cascade of chickens coming home to roost?


    1. they call this “training” but i try to avoid anthropomorphising chatbots ↩︎

    • megaman@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      At work, i watched my boss google something, see the “ai overview” and then say “who knows if this is right”, and then read it and then close the tab.

      It made me think about how this is how like a rumor or something happens. Even in a good case, they read the text with some scepticism but then 2 days later they forgot where they heard it and so they say they think whatever it was is right.

    • Amoeba_Girl@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Sadly web search, and the web in general, have enshittified so much that asking ChatGPT can be a much more reliable and quicker way to find information. I don’t excuse it for anything that you could easily find on wikipedia, but it’s useful for queries such as “what’s the name of that free indie game from the 00s that was just a boss rush no you fucking idiot not any of this shit it was a game maker thing with retro pixel style or whatever ugh” where web search is utterly useless. It’s a frustrating situation, because of course in an ideal world chatbots don’t exist and information on the web is not drowned in a sea of predatory bullshit, reliable web indexes and directories exist and you can easily ask other people on non-predatory platforms. In the meanwhile I don’t want to blame the average (non-tech-evangelist, non-responsibility-having) user for being funnelled into this crap. At worst they’re victims like all of us.

      Oh yeah and the game’s Banana Nababa by the way.

    • jonhendry@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      “they call this “training” but i try to avoid anthropomorphising chatbots”

      You can train animals, you can train a plant, you can train your hair. So it’s not really anthropomorphising.

    • ________@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Is there any search engine that isn’t pushing an “AI mode” of sorts? Some are more sneaky or give option to “opt out” like duckduckgo, but this all feels temporary until it is the only option.

      I have found it strange how many people will say “I asked chatgpt” with the same normalcy as “googling” was.

    • o7___o7@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Yes i know the kid in the omelas hole gets tortured each time i use the woe engine to generate an email. Is that so wrong?

      • swlabr@awful.systems
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        hi hi I am budweiser jabrony please join my new famous and good website ‘tapering incorrectness dot com’ where we speculate about which OSI layers have the most consciousness (zero is not a valid amount of consciousness) also give money and prima nocta. thanks

      • Soyweiser@awful.systems
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        Tcp/ip knew what it did, with its authoritarian desire to see packets in order. Reject authority embrace UDP!

        • bitofhope@awful.systems
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          Well that and “core”. I could consider social media and even chatbots parts of internet infrastructure, but they both depend on a framework of underlying protocols and their implementation details. Without social media or chatbots the internet would still be the internet, which is not the case for, say, the Internet Protocol.

          • YourNetworkIsHaunted@awful.systems
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            Also I would contend they’re misusing “infrastructure”. Social media and chat bots are kinds of services that are provided over the internet, but they aren’t a part of the infrastructure itself anymore than the world’s largest ball of twine is part of the infrastructure of the Interstate Highway System.

            • froztbyte@awful.systems
              link
              fedilink
              English
              arrow-up
              0
              ·
              2 months ago

              Heh yeah, “infrastructure” in the same way that moneyed bayfuckers are “builders”

              It is also a useful study in just how little they fucking by get about how anything works, and what models of reasoning they apply to what they perceive. Depressing, but useful

              • YourNetworkIsHaunted@awful.systems
                link
                fedilink
                English
                arrow-up
                0
                ·
                2 months ago

                It legitimately feels like at least half of these jokers have the same attitude towards IT and project management that sovereign citizens do to the law. SovCits don’t understand the law as a coherent series of rules and principles applied through established procedures etc, they just see a bunch of people who say magic words that they don’t entirely understand and file weird paperwork that doesn’t make sense and then end up getting given a bunch of money or going to prison or whatever. It’s a literal cargo cult version of the legal system, with the slight hiccup that the rest of the world is trying to actually function.

                Similarly, the Silicon Valley Business Idiot set sees the tech industry as one where people say the right things and make the buttons look pretty and sometimes they get bestowed reality-warping sums of money. The financial system is sufficiently divorced from reality that the market doesn’t punish the SVBIs for their cargo cult understanding of technology, but this does explain a lot of the discourse and the way people like Thiel, Andreesen, and Altman talk about their work and why the actual products are so shite to use.

    • BlueMonday1984@awful.systemsOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      the article headline: “Chatbots are now rivaling social networks as a core layer of internet infrastructure”

      Counterpoint: “vibe coding” is rotting internet infrastructure from the inside, AI scrapers are destroying the commons through large-scale theft, chatbots are drowning everything else through nonstop lying

    • nfultz@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      He came by campus last spring and did a reading, very solid and surprisingly well-attended talk.

    • Soyweiser@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Always thought she should have stuck to acting.

      (I know, Hayek just always reminds me of how people put his quotes over Hayeks image, and people just get really mad at her, and not at him. Always wonder if people would have been just as mad if it was Friedrichs image and not Salmas due to the sexism aspect).

      • swlabr@awful.systems
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        Yud’s whole project is a pipeline intended to create zizians, if you believe that Yud is serious about his alignment beliefs. If he isn’t serious then it’s just an unfortunate consequence that he is not trying to address in any meaningful way.

        • blakestacey@awful.systems
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          A belief system that inculates the believer into thinking that the work is the most important duty a human can perform, while also isolating them behind impenetrable pseudo-intellectual esoterica, while also funneling them into economic precarity… sounds like a recipe for delicious brownies trouble.

          • blakestacey@awful.systems
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            Growing up in Alabama, I didn’t have the vocabulary to express it, but I definitely had the feeling when meeting some people, “Given the bullshit you alreasy buy, there is nothing in principle stopping you from going full fash.” I get the same feeling now from Yuddites: “There is nothing in principle stopping you from going full Zizian.”

        • sc_griffith@awful.systems
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          fortunately, yud clarified everything in his recent post concerning the zizians, which indicated that… uh, hmm, that we should use a prediction market to determine whether it’s moral to sell LSD to children. maybe he got off track a little

    • BioMan@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Is it better for these people to be collected in one place under the singularity cult, or dispersed into all the other religions, cults, and conspiracy theories that they would ordinarily be pulled into?

    • BigMuffN69@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Most insane part about this is after he assaulted the treasurer(?) of his foundation trying to siphon funds for an apparent terror act, the naive chuckle fucks still went and said “we dont think his violent tendencies are an indication he might do something violent”

      Like idk maybe update on the fact he just sent one of his own to the hospital??

  • scruiser@awful.systems
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Another day, another instance of rationalists struggling to comprehend how they’ve been played by the LLM companies: https://www.lesswrong.com/posts/5aKRshJzhojqfbRyo/unless-its-governance-changes-anthropic-is-untrustworthy

    A very long, detailed post, elaborating very extensively the many ways Anthropic has played the AI doomers, promising AI safety but behaving like all the other frontier LLM companies, including blocking any and all regulation. The top responses are all tone policing and such denying it in a half-assed way that doesn’t really engage with the fact the Anthropic has lied and broken “AI safety commitments” to rationalist/lesswrongers/EA shamelessly and repeatedly:

    https://www.lesswrong.com/posts/5aKRshJzhojqfbRyo/unless-its-governance-changes-anthropic-is-untrustworthy?commentId=tBTMWrTejHPHyhTpQ

    I feel confused about how to engage with this post. I agree that there’s a bunch of evidence here that Anthropic has done various shady things, which I do think should be collected in one place. On the other hand, I keep seeing aggressive critiques from Mikhail that I think are low-quality (more context below), and I expect that a bunch of this post is “spun” in uncharitable ways.

    https://www.lesswrong.com/posts/5aKRshJzhojqfbRyo/unless-its-governance-changes-anthropic-is-untrustworthy?commentId=CogFiu9crBC32Zjdp

    I think it’s sort of a type error to refer to Anthropic as something that one could trust or not. Anthropic is a company which has a bunch of executives, employees, board members, LTBT members, external contractors, investors, etc, all of whom have influence over different things the company does.

    I would find this all hilarious, except a lot of the regulation and some of the “AI safety commitments” would also address real ethical concerns.

    • gerikson@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      This would be worrying if there was any risk at all that the stuff Anthropic is pumping out is an existential threat to humanity. There isn’t so this is just rats learning how the world works outside the blog bubble.

      • scruiser@awful.systems
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        I mean, I assume the bigger the pump the bubble the bigger the burst, but at this point the rationalists aren’t really so relevant anymore, they served their role in early incubation.

    • lagrangeinterpolator@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      If rationalists could benefit from just one piece of advice, it would be: actions speak louder than words. Right now, I don’t think they understand that, given their penchant for 10k word blog posts.

      One non-AI example of this is the most expensive fireworks show in history, I mean, the SpaceX Starship program. So far, they have had 11 or 12 test flights (I don’t care to count the exact number by this point), and not a single one of them has delivered anything into orbit. Fans generally tend to cling on to a few parlor tricks like the “chopstick” stuff. They seem to have forgotten that their goal was to land people on the moon. This goal had already been accomplished over 50 years ago with the 11th flight of the Apollo program.

      I saw this coming from their very first Starship test flight. They destroyed the launchpad as soon as the rocket lifted off, with massive chunks of concrete flying hundreds of feet into the air. The rocket itself lost control and exploded 4 minutes later. But by far the most damning part was when the camera cut to the SpaceX employees wildly cheering. Later on there were countless spin articles about how this test flight was successful because they collected so much data.

      I chose to believe the evidence in front of my eyes over the talking points about how SpaceX was decades ahead of everyone else, SpaceX is a leader in cheap reusable spacecraft, iterative development is great, etc. Now, I choose to look at the actions of the AI companies, and I can easily see that they do not have any ethics. Meanwhile, the rationalists are hypnotized by the Anthropic critihype blog posts about how their AI is dangerous.

      • rook@awful.systems
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        I chose to believe the evidence in front of my eyes over the talking points about how SpaceX was decades ahead of everyone else, SpaceX is a leader in cheap reusable spacecraft, iterative development is great, etc.

        I suspect that part of the problem is that there is company in there that’s doing a pretty amazing job of reusable rocketry at lower prices than everyone else under the guidance of a skilled leader who is also technically competent, except that leader is gwynne shotwell who is ultimately beholden to an idiot manchild who wants his flying cybertruck just the way he imagines it, and cannot be gainsayed.

  • blakestacey@awful.systems
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Dr. Casey Fiesler reports,

    I was poking around Google Scholar for publications about the relationship between chatbots and wellness. Oh how useful: a systematic literature review! Let’s dig into the findings.

    […]

    Did you guess “that paper does not actually exist”?

    Did you also guess that NOT A SINGLE PAPER IN THEIR REFERENCES APPEARS TO EXIST? […] When I was searching in various places to confirm that those citations were fabricated, Google’s AI overview just kept the con going.

    Jill Walker Rettberg in the comments:

    There’s a peer reviewed published paper in AI & Society called Cognitive Imperialism and Artificial Intelligence which is clearly mostly AI-generated. Citations are real but almost all irrelevant. I emailed the editors weeks ago but it’s still up there and getting cited.

  • blakestacey@awful.systems
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    From Lila Byock:

    A 4th grader was assigned to design a book cover for Pippi Longstocking using Adobe for Education.

    The result is, in technical terms, four pictures of a schoolgirl waifu in fetishwear.

    • froztbyte@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      The result is, in technical terms, four pictures of a schoolgirl waifu in fetishwear.

      I try to avoid having to even see the outputs of these fucking systems, but you just made me realize that there’s going to be more than a few of them that will “leak” (read: preferentially deliver, by way of training focus) the kinks of its particular owner. I mean it’s already happening for the textual replies on twitter, soothing felon’s ever so bruised ego. the chance of it not Shipping beyond that is pretty damn zero :|

      god I hate all of this

    • nfultz@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      It’s the McMindfulness guy, nice to see that he is still kicking around.

      In Empire of AI, she shows how CEO Sam Altman cloaks monopoly ambitions in humanitarian language—his soft-spoken, monkish image (gosh, little Sammy even practices mindfulness!)

      lol ofc he does

    • swlabr@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      I like this. Kinda wish it was either 10x longer and explained things a bit, or 10x shorter and was more shitposty. Still, good

    • Seminar2250@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      https://awful.systems/post/5776862/8966942 😭

      also this guy is a bit of a doofus, e.g. https://bugs.launchpad.net/calibre/+bug/853934, where he is a dick to someone reporting a bug, and https://bugs.launchpad.net/calibre/+bug/885027, where someone points out that you can execute anything as root because of a security issue, and he argues like a total shithead

      You mean that a program designed to let an unprivileged user
      mount/unmount/eject anything he wants has a security flaw because it allows
      him to mount/unmount/eject anything he wants? I’m shocked.

      Implement a system that allows an appilcation to mount/unmount/eject USB
      devices connected to the system securely, then make sure that system is
      universally adopted on every linux install in the universe. Once you’ve done that, feel free to
      re-open this ticket.

      i would not invite this person to my birthday

      • Sailor Sega Saturn@awful.systems
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        I was vaguely aware of the calibre vulnerabilities but this is the first I’ve actually read the thread and it’s wild.

        There were like 11 or so Proof of Concept exploits over the course of that bug? And he was just kicking and screaming the whole time about how fine his mount-stuff-anywhere-as-root (!!?) code was.

        I’m always fascinated when people are so close to getting something-- like in that first paragraph you quoted. In any normal software project you could just put that paragraph as the bug report and the owners would take is seriously rather than use it as an excuse for why their software has to be insecure.

    • flaviat@awful.systems
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Does this mean calibre’s use case is a digital equivalent of a shelf of books you never read?