molly-guard /mol´ee·gard/ n.
[University of Illinois] A shield to prevent tripping of some Big Red Switch by clumsy or ignorant hands. Originally used of the plexiglass covers improvised for the BRS on an IBM 4341 after a programmer's toddler daughter (named Molly) frobbed it twice in one day. Later generalized to covers over stop/reset switches on disk drives and networking equipment. In hardware catalogues, you'll see the much less interesting description “guarded button”.
There’s an enormous amount of liquidity in growth stocks, which means that you can use growth stocks to grow. You can buy other companies with shares, and shares are an endogenous substance that you make on the premises by typing zeros into a spreadsheet. Firms with growth stocks can grow by typing zeros, whereas firms that are mature, they have to use money if they want to grow, and you’re not allowed to make money on the premises. If you do, the Treasury Department shows up and takes you away in handcuffs. So you can see why firms would be very anxious to maintain the perception that they have room for growth even after they have 90 percent market shares.
That’s why those firms started promoting stories about how they were going to conquer imaginary markets. Imaginary markets have no agreed-upon valuation because you just made them up. Unless you can turn an imaginary market into a real market pretty quickly, you need to come up with another imaginary market and announce that this is the new imaginary market you’re going to conquer. It’s easier than you’d think because the capital markets have the object permanence of a toddler, and they would lose a game of peekaboo if they were drafted to play in the league. So you can say, “Oh, actually, it’s not metaverse. It’s crypto. It’s not crypto. It’s Web3. It’s not Web3. It’s something else.” And the markets will forgive you, provided you do it quickly enough. //
AI really appeals to a fantasy that I think all of us have to some extent but that powerful people really have, of a world without people in it—because hell really is other people. You can’t get stuff done without other people helping you. You can’t have romance without a romantic partner. You can’t have social media without people to socialize with. You can’t play a board game, or do a startup, or build a bridge, or build a house, or do politics without other people. And other people stubbornly refuse to organize everything they do to make you happy.
Particularly if you’re rich and powerful, it’s very galling. So AI is very attractive. //
If you combine those two things—the material necessity to have a growth narrative and the ideological attractiveness of a world without people—you get $1.4 trillion in CapEx for a sector that is turning over $50 billion a year and has to replace all of its assets every 24 to 30 months. //
Whereas the workers who hate it are workers who are being asked to produce more with AI at the expense of quality, at a higher speed, at the expense of their own wellbeing, and who understand that they’re being recruited to be what Dan Davies calls accountability sinks—to take the blame when the AI screws up their job. //
We hear plenty about the negative aspects of AI. What do you like about it?
Cory Doctorow: I have a couple of local models on my computer, which is just a framework laptop running Ubuntu. It doesn’t even have a GPU. I use Whisper to transcribe audio. I will sometimes want to cite something I’ve heard in a podcast and not remember where I heard it. One time, I just threw the last 30 hours of audio I’d listened to at Whisper, and it shot out verbatim logs that were good enough that when I searched the full text, I could find it. And it gave me time codes so I could check the transcript. That’s amazing.
The idea that I might someday have a computer full of audio and video files with full text indexing is great.
SplatMan_DK Ars Tribunus Angusticlavius
18y
8,304
Subscriptor++
Confy said:
Nutanix has Veeam support and HPE has Zerto support. I wonder what hypervisor Tesco chose.
Lot's of talk about this in the MSP chats around Europe (and I am a small MSP).
A very good bet is is KVM underneath a private-cloud stack that can handle 40K+ instances in 100+ locations in a fully automated fashion, using Infrastructure-as-code, and which includes baked-in options to run Kubernetes (the Tanzu subscription says so).
Who fits the bill:
Virtuozzo (very good VMWare replacement with K8S but too much proprietary stuff mixed in)
OCI (Oracle are also duchebags so unlikely)
Openstack vanilla (possible but unlikely given the focus on risk - managers want paid support)
RHSOSP (Red Hat OpenStack Platform - expensive but less than half the price of VMWare)
Canonical Charmed OpenStack (cheap and solid option - decent bet especially with Sunbeam for small local sites)
Apache Cloudstack (unlikely as few commercial options would provide support for "at a sprint" migration)
FishOS by Sardina (nice vanilla OpenStack with migration tool, support contract and remote ops but unlikely candidate due to small organizational size for Tescos taste)
Platform9 (cloud-based control plane for on-prem OpenStack and optimized for retail)
Theoretically fits the bill but with lots of re-work:
Rancher (K8S only - unlikely)
SUSE Harvester (Rancher but with KubeVirt VM capability - still unlikely but pretty cool and solid for a long term strategy)
Doesn't fit the bill:
Nutanix (supported by govtools; Veeam - but has good K8S)
HyperV (supported by govtools; Veeam - has no K8S)
Hyperscalers with cloud-only strategy; like Azure, AWS, GCP, Oracle Cloud (too expensive)
Proxmox (great for small shops - but finnicky and absolutely nowhere near Enterprise grade)
Other likely options (the MBA/C-suite approach):
Azure Hybrid environment with Azure Local for most workloads (on-prem) but some Hyperscaler mixed in; for example Azure. Migrating VMWare workloads is easy; doesn't save cost but keeps the few percentages of un-migratable legacy workloads spinning. Not everything in a hybrid environment is easily handled by Veeam and Zerto. But the bulk of VM instances would be covered. AKS on Azure Local for the K8S workloads for example; as well as various PaaS services.
The last option would often be the most appealing for the CIO, the CISO and the risk manager. It offers the easiest migration path - at least on paper. Price would be high but still significantly lower than inflated Broadcom prices; though the first few years of savings would be eaten by the accelerated transition costs.
Me, I'd go for Vanilla OpenStack and hire enough people to keep it running. The offering from Sardina is nice. It supports the accelerated transition requirement, and keeps the exit strategy clean and simple. It also ticks all the compliance boxes upper management wants because paid support is available.
Most vendor lock-in is with Microsoft or Nutanix. Least lock-in and easiest exit strategy is with Vanilla OpenStack, SUSE Harvester, Sardina FishOS, Canonical OpenStack.
Then again ... the suits in 40K+ employee companies rarely make the right tech-decisions. So who knows.
It will spill eventually. :)
voline Ars Scholae Palatinae
20y
853
fe3a8b63 said:
https://isaiprofitable.com/
Even if we ignore all other problems in regards to environment, pollution, water, electricity, etc. it still doesn't make sense.
It's just burning money to.... burn money to..... uh what? What's the goal. You ain't making money.
I think Signal CEO Meredith Whittaker had a good answer:
I’m going to give a sideways answer to this, which is that the venture capital business model needs to be understood as requiring hype. You can go back to the Netscape IPO, and that was the proof point that made venture capital the financial lifeblood of the tech industry.
Venture capital looks at valuations and growth, not necessarily at profit or revenue. So you don’t actually have to invest in technology that works, or that even makes a profit, you simply have to have a narrative that is compelling enough to float those valuations. So you see this repetitive and exhausting hype cycle as a feature in this industry. A couple of years ago, you would have been asking me about the metaverse, then last year, you would have asked me about Web3 and crypto, and for each of these inflection points there’s an Andreessen Horowitz manifesto.
It’s not simply that one piece of technology is overhyped, it’s that hype is a necessary ingredient of the current business ecosystem of the tech industry. We should examine how often the financial incentive for hype is rewarded without any real social returns, without any meaningful progress in technology, without these tools and services and worlds ever actually manifesting. That’s key to understanding the growing chasm between the narrative of techno-optimists and the reality of our tech-encumbered world.
— Meredith Whittaker, Signal CEO, to Derek Robertson. "5 Questions for Meredith Whittaker". Politico, 2023-12-01.
https://www.politico.com/newsletters/digital-future-daily/2023/12/01/5-questions-for-meredith-whittaker-00129677
But those customers don't count. They aren't real Apple customers, because they want to do things that benefit them, not Apple's shareholders. In other words: they're holding it wrong.
Law, not technology, is the true battlefield in the War on General Purpose Computing, a subject I've been raising the alarm about for decades now:
https://memex.craphound.com/2012/01/10/lockdown-the-coming-war-on-general-purpose-computing/
The fact that there's no technical way to enforce these restrictions means that the companies that benefit from them have to pitch their arguments to lawmakers, not customers. If you have something that works, you use it in your sales pitch, like Signal, whose actual, working security is a big part of its appeal to users.
If you have something that doesn't work, you use it in your lobbying pitch, like Apple, who justify their 30% ripoff app tax – which they can only charge because it's a felony to reverse-engineer your iPhone so you can use a different app store – by telling lawmakers that locking down their platform is essential to the security and privacy of iPhone owners:
https://pluralistic.net/2024/01/12/youre-holding-it-wrong/#if-dishwashers-were-iphones
Google lost a brutal antitrust case brought by Epic Games, makers of Fortnite:
https://pluralistic.net/2023/12/12/im-feeling-lucky/#hugger-mugger
Epic's suit contended that Google had violated antitrust law by creating exclusivity deals with carriers and device makers that locked Android users into Google's app store, which meant that Epic had to surrender 30% of its mobile earnings to Google.
Google lost that case – badly. It turns out that judges don't like it when you deliberately destroy evidence:
They say that when you find yourself in a hole, you should stop digging, but Google can't put down the shovel. After the court ordered Google to open up its app store, the company just ignored the order, which is a thing that judges hate even more than destroying evidence:
https://www.justice.gov/atr/case/epic-games-inc-v-google-llc
So it was that last month, Google found itself with just two weeks to comply with the open app store order, or else:
https://www.theverge.com/news/717440/google-epic-open-play-store-emergency-stay
Google was ordered to make it possible to install new app stores as apps, so you could go into Google Play, search for a different app store, and, with a single click, install it on your phone, and switch to getting your apps from that store, rather than Google's.
That's what's behind Google's new ban on "sideloading": this is a form of malicious compliance with the court orders stemming from its losses to Epic Games. In fact, it's not even malicious compliance – it's malicious noncompliance
Speaking to Ars in the wake of the controversy, Rosenbaum says he “learned a lesson” and is “going to be much more suspicious” and “reticent to trust” AI outputs going forward.
But he also can’t tear himself away from the tools. Rather amazingly, Rosenbaum is not interested in going back to the AI-free research process he used to write previous books.
“The idea of taking X years off [from AI] while it sorts itself out, and going back to, like, Microsoft Word … it’s just not in my nature,” he told Ars. “[AI] is magical. Because it connects, it knits together ideas and gives you pathways to think about things that you’re not going to come up with on your own.”
It’s also magical in another way: Like J.R.R. Tolkien’s One Ring, AI convinces many of those who use it that they can control its power properly. But can they?
May 15 marks one year since Governor Kathy Hochul enacted a “bell-to-bell” ban on personal phones in public schools, impacting almost a million children in K-12 public and charter schools across the state.
Teachers who spoke to The Post all say the ban has had an overwhelmingly postive impact on their schools.
“I think that the cell phone ban has been remarkable,” Dr. Jessica Chock-Goldman, director of clinical services at Bard High School Early College of Manhattan on the Lower East Side, told The Post. “I’ve been astounded by how much of a shift it has been.” //
But it’s not just in the classroom. When he walks by the cafeteria during lunch, it’s now full of energy.
“They’re talking with each other instead of just looking down at their phones,” he marveled. “Now they have to communicate, they have to socialize. They have to talk, find out how their day is going, what’s going on, what class do you have next, did you do last night’s homework?”
At Friday’s hearing of the Colorado Senate Business, Labor, and Technology committee, lawmakers voted unanimously to move Colorado state bill SB26-090—titled Exempt Critical Infrastructure from Right to Repair—out of committee and into the state senate and house for a vote.
The bill modifies Colorado’s Consumer Right to Repair Digital Electronic Equipment act, which was passed in 2024 and went into effect in January 2026. While the protections secured by that act are wide, the new SB26-090 bill aims to “exempt information technology equipment that is intended for use in critical infrastructure from Colorado’s consumer right to repair laws.” //
“I can point out at least five problems with the bill as drafted,” Gay Gordon-Byrne, the executive director at the Repair Association, said during the hearing. “The definition of critical infrastructure is completely inadequate. The definition that has been proposed in this bill is not even a definition.” //
Repair advocates also say that limiting this kind of repairability is the exact opposite of keeping devices secure. If something goes wrong with a critical piece of technology, the people using it need to fix it and not have to wait for manufacturer approval.
“There’s a general principle in cybersecurity that obscurity is not security,” iFixit CEO Kyle Wiens said in the hearing. “The money that’s behind the scenes, that’s what’s driving the bill.” //
DarthSlack Ars Legatus Legionis
12y
23,110
Subscriptor++
So critical infrastructure is, well, critical, right? Like you need it to keep working because if it stops you're in a world of hurt? So isn't that the stuff you really, really, really want to be able to repair when it breaks and not sitting on your ass waiting for some clownshoes to show up and charge you a small fortune to turn a screw or apply a patch?
IanRS
Bigger problems
In my work as a security architect I occasionally get asked by an assurer or auditor why I think running AWS infrastructure in just two availability zones without a second region is enough. The latest was just earlier this week. It shows that they do not understand risk/impact balance outside their own little box. I have to point out that if something can take out two geographically separated data centres simultaneously then the impact is not restricted just to their website, and they probably have bigger problems to worry about. Some of them accept this. Some still think another region would help.
20 hrs
Anonymous Coward
Re: Bigger problems
I worked for a small public sector body. An auditor once asked what would happen if both our main and DR sites went dark. I said if that happened, something very big & bad was happening and no-one was going to care about our organisation.
Auditor ticked their box as we had clearly considered the possibility and we had a plan. (Do nothing is still a plan!)
Would you rather have a smoke alarm that goes off 33% of the time you make toast, or one which never goes off when there's a fire ?
Re: 1/3 wrong of 60 is progress (?)
The problem is not with the "smoke alarm" it's with the fire engine.
1 day
MOH
Re: 1/3 wrong of 60 is progress (?)
When I'm making toast, I'm making toast.
I'm aware of what I'm doing and ensuring that the toast making doesn't escalate to a house fire.
If it does, that is fully on me.
I don't need a wonky security camera setting off a fire alarm for times a day because my dark brown slippers have vaguely the same shade as burnt toast and it blindly assumes a fire is in progress.
1 day
Yet Another Anonymous coward
Re: 1/3 wrong of 60 is progress (?)
But it could be useful if you're very confused and might be about to put marmalade on your slippers
The Federal Communications Commission yesterday announced it will no longer approve consumer-grade routers made outside of the US, citing a President Trump directive on reducing the use of foreign technology for national security reasons. The action will prevent foreign-made routers from being imported into or sold in the US.
Routers already approved for sale in the US can continue to be sold, and consumers can keep using any router they’ve previously obtained, the FCC said. But the FCC will not approve new device models made at least partly outside the US unless the Department of Defense or Department of Homeland Security determines that the router does not pose national security risks.
The prohibition applies to both US and foreign companies that produce routers outside the US. Foreign production includes “any major stage of the process through which the device is made, including manufacturing, assembly, design, and development.”
“This action means that new models of foreign-produced routers will no longer be eligible for marketing or sale in the US,” FCC Chairman Brendan Carr wrote on X.
A federal judge in Virginia ruled Tuesday that the City of Norfolk’s use of nearly 200 automated license plate readers (ALPRs) from Flock is constitutional and can continue, dismissing the entire case just days before a bench trial was set to begin.
The case, Schmidt v. City of Norfolk, was originally filed in October 2024 by two Virginians who claimed that their rights were violated when the Flock network of cameras captured their cars hundreds of times, calling the entire setup a “dragnet surveillance program.”
However, in a 51-page ruling, US District Court Judge Mark S. Davis disagreed, finding that the “…plaintiffs are unable to demonstrate that Defendants’ ALPR system is capable of tracking the whole of a person’s movements.” //
I intended to NOT drop what I was doing and just let the video play in the background. But after 1 minute, I dropped what I was doing to give the video my full attention. https://www.youtube.com/watch?v=vU1-uiUlHTo
See also "We’re All So F’d | NVIDIA x Palantir, Global Surveillance, 'Pre-Crime' Arrests, & AI." https://www.youtube.com/watch?v=5lYsO4k7OIY
Don't mess with the IT department guys. Although their office might look as messy as mine, they are a force not to be screwed with.
It all started one day with this guy, the origional Etherkiller, developed with a few misc parts to warn new users that the IT department is not to be messed with. You too can make one at home, connect the transmit pins of the RJ-45 to HOT on 110VAC and the recieve pins to Common. Modify to suit tase by varying pinout.
This led to some general discussion that this particular device really is in a class of devices, now called the "killers", which need to be made.
I’ve started only buying smart devices if there’s already an active community project to provide firmware and such should the company disappear or give up. If you want the convenience of “smart” devices, you have to compromise somewhere.
You can also buy devices that use open protocols like zwave, zigbee, or thread/matter. zwave is by far the best of the 3 because the certification requires that the devices properly implement the standard so any controller can manage any device, however that also makes it the most expensive and least flexible of the 3. For me stuff I care about long-term support for is zwave (thermostat, living room lights including wall controller), stuff that I'm less worried about having to possibly replace some day like motion detection or smart outlets can be zigbee, or Matter. Thread/Matter is starting to get to the point where the standard and interoperability testing is robust enough that I might consider it for my mission critical stuff in the near future.
As far as music, I've got 20 year old speakers hooked up to a 10 year old receiver that gets fed by the TV or anything plugged into it, thanks to HDMI ARC I don't have to worry about what TV I use or what device is plugged into it, downside of course is that the TV has to be turned on and tuned to the music source (not a big deal for my personal situation, others may not like the compromise).
And now, with that redesign having been functional and stable for a couple of years and a few billion page views (really!), we want to invite you all behind the curtain to peek at how we keep a major site like Ars online and functional. This article will be the first in a four-part series on how Ars Technica works—we’ll examine both the basic technology choices that power Ars and the software with which we hook everything together.
Reported in Nature this week, the study notes that audiovisual glitches break the illusion of a face-to-face meeting, damaging interpersonal judgments.
The authors argued that distorted faces, misaligned audio and visual cues, and choppy movements resulting from technical failures can create an "uncanniness, a strange, creepy or eerie feeling." //
Some might think the resources of the tech industry could eliminate such problems and their resulting impacts in the real world. But priorities seem to lie elsewhere.
The study's authors noted that older technologies like phone calls have fewer glitches now, but keep getting displaced by those that require more bandwidth. New conferencing methods such as 3D group functionality and VR will have even higher bandwidth demands.
Nephophobia, or cloud phobia, is an excessive or irrational fear of clouds that can evoke intense emotional responses and substantially impact an individual's overall well-being.
It’s always DNS
Amazon said the root cause of the outage was a software bug in software running the DynamoDB DNS management system. The system monitors the stability of load balancers by, among other things, periodically creating new DNS configurations for endpoints within the AWS network. A race condition is an error that makes a process dependent on the timing or sequence events that are variable and outside the developers’ control. The result can be unexpected behavior and potentially harmful failures.
In this case, the race condition resided in the DNS Enactor, a DynamoDB component that constantly updates domain lookup tables in individual AWS endpoints to optimize load balancing as conditions change. As the enactor operated, it “experienced unusually high delays needing to retry its update on several of the DNS endpoints.” While the enactor was playing catch-up, a second DynamoDB component, the DNS Planner, continued to generate new plans. Then, a separate DNS Enactor began to implement them.
The timing of these two enactors triggered the race condition, which ended up taking out the entire DynamoDB.
Aranya is an access governance and secure data exchange platform for organizations to control their critical data and services. Access governance is a mechanism to define, enforce, and maintain the set of rules and procedures to secure your system’s behaviors. Aranya gives you the ability to apply access controls over stored and shared resources all in one place.
Aranya enables you to safeguard sensitive information, maintain compliance, mitigate the risk of unauthorized data exposure, and grant appropriate access. Aranya’s decentralized platform allows you to define and enforce these sets of policies to secure and access your resources.
The platform provides a software toolkit for policy-driven access controls and secure data exchange. The software is deployed on endpoints, integrating into applications which require granular access controls over their data and services. Endpoints can entrust Aranya with their data protection and access controls so that other applications running on the endpoint need only to focus on using the data for their intended functionality. Aranya has configurable end-to-end encryption built into its core as a fundamental design principle.
A key discriminating attribute of Aranya is the decentralized, zero trust architecture. Through the integration of the software, access governance is implemented without the need for a connection back to centralized IT infrastructure. With Aranya’s decentralized architecture, if two endpoints are connected to each other, but not back to the cloud or centralized infrastructure, governance over data and applications will be synchronized between peers and further operations will continue uninterrupted.