Posts
562
Following
37
Followers
2374

I miss the old-fashioned FOSS drama, where if you knew someone’s three-letter initials and they were an asshole, you just called them an asshole or ignored them, and didn’t worry that (1) they were a vengeful billionaire and/or (2) that they represented the pending downfall of democracy

4
8
0
@alrj I am surprised that people seem to think I'm unaware of that. Seriously...I live in Boulder... my question is what they think a "hash collision" is.
2
0
5

Jonathan Corbet

Just got a nifty bit of spam from a bot claiming to represent Weedmaps (a site for people trying to find cannabis products). They were, it seems, much impressed by an LWN article on hash collisions and were wondering if we could find it in our hearts to mention them there.

I am still trying to understand just what a "hash collision" would mean in that context; perhaps I don't have enough weed in the house to obtain the necessary insight.
8
6
37
@etchedpixels @jwildeboer ...but definitely stopped LinuxCare... sometimes you *really* miss the window.
0
0
1
@gregkh @KernelRecipes Heh ... I have a similar plot from the 7.2 development-statistics article that I'm thinking of using...
1
4
3
Some talks just write themselves, @KernelRecipes is going to be fun this year!

(not that it's not fun every year, but you get the idea...)
9
36
84

Jonathan Corbet

So why didn't I think of this business model?

1) Poke LLMs for a while and see which nonexistent URLs they hallucinate most often.

2) Register those domains and put malicious web sites behind them.

3) Profit!

https://spectrum.ieee.org/ai-cyberattacks-llm-slop-squatting

(What a world we have made...)
2
26
31

Jonathan Corbet

Out on my bike, when I had this feeling I was being watched...
0
4
41

Jonathan Corbet

Today at LWN we got a pitch from a prospective author of kernel-related material, offering to cover stuff that we've covered well already.

Included therein was this text: "Why I'm the right person for this: [I'd fill this in with your own background here — e.g. kernel contribution history, mailing-list involvement,
relevant professional experience, or prior writing]"

It forgot to tell this person to point out their attention to detail as well.
3
17
58
@pinskia Congratulations! I know well what a challenge you have taken on here...it's not easy to keep it going week after week.
0
0
2
@davidgerard You left out the part about letting the LLMs commit patches. What could possibly go wrong?
1
2
10
@sjvn That quote shows up in the Velvet Underground episode of "A history of rock in 500 songs":

https://500songs.com/podcast/episode-164-white-light-white-heat-by-the-velvet-underground/

It's excellent, as are all the episodes there; this is the production that finally forced me to create a Patreon account so I could toss money at its creator.
0
0
1
@paulmckrcu My condolences. Saying goodbye is a hard thing, even after the best of runs.
1
0
2

Jonathan Corbet

Doing my part to keep the -rc releases small
1
3
38
Edited 29 days ago

Some Stanford researchers dredged out the absolute dregs of r/AmITheAsshole for all those stories where _zero_ humans supported the poster, where one hundred percent of them said yes, you are unambiguously the asshole, and fed them into LLMs as first person scenarios to see what the LLM had to say.

Unethical, harmful, cruel, criminal, didn't matter: the slopbots took the faux poster's side about half the time.

Edit: preprint on arxiv https://arxiv.org/abs/2510.01395

https://www.science.org/doi/10.1126/science.aec8352

1
19
0
@monsieuricon I've seen a couple of other complaints about SYN floods as well, seems weird.
1
0
0

Jonathan Corbet

Ah what a world we have built...

"In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed. This software rents the user’s Internet address out to anonymous paying customers, who run the gamut from aggressive content scraping firms to ticket scalpers and outright cybercriminals.

What’s more, because these generic (and generally dirt cheap) TV boxes are all horribly insecure by default and bereft of any kind of authentication, installing one on your home or office network only invites further mischief. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in both the residential proxy software and the streaming devices themselves."

https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
1
14
22

You will be sorely missed Dan Williams, you were a good engineer and a great person, I will miss seeing you at our conferences every year. You were the best of us and you leave quite the hole.

0
6
2
@Epic_Null @Li The first step after a GrapheneOS install is to lock the bootloader again so no, it's not unlocked.
0
0
4
@lienrag As a general rule you have to unlock the phone before you can image it — and the contents of the drive are encrypted. If the phone is in the before-first-unlock state, especially, getting at its contents will be hard.

There are, naturally, forensics tools out there meant to bypass these protections. I have no way to know how effective they are on a GrapheneOS install.
0
0
5
Show older