Skip to content

Year: 2020

Links for 2020-01-20

Links for 2020-01-16

  • Snowboy Hotword Detection

    Open-source, Apache-license hotword detection library for homebrew IoT: 'Snowboy is an highly customizable hotword detection engine that is embedded real-time and is always listening (even when off-line) compatible with Raspberry Pi, (Ubuntu) Linux, and Mac OS X. Currently, Snowboy supports: all versions of Raspberry Pi (with Raspbian based on Debian Jessie 8.0) 64bit Mac OS X 64bit Ubuntu (12.04 and 14.04) iOS Android with ARMv7 CPUs Pine 64 with Debian Jessie 8.5 (3.10.102) Intel Edison with Ubilinux (Debian Wheezy 7.8)'

    (tags: audio iot hardware hotwords speech-recognition speech devices)

Links for 2020-01-15

  • Facebook Ad Library Showed Just How Unreliable Facebook’s Security System For Elections Is

    On Dec. 10, just two days before the United Kingdom went to the polls, some 74,000 political advertisements vanished from Facebook’s Ad Library, a website that serves as an archive of political and issue ads run on the platform. [....] Facebook has said it will not fact-check political ads or restrict the ability for campaigns to target people. Instead, it said it will provide transparency with tools like the Ad Library, the Ad Library report, and the Ad Library API, so the public, researchers, and journalists can monitor how elections play out on the platform. But that only works to the degree that those tools operate properly. It was only the news media’s reporting that brought the issue out into the open. “The fact that they could have an outage like this that went up to the day before an election, and they didn’t really publicly communicate,” Laura Edelson, a computer scientist at NYU whose work involves using the API, told BuzzFeed News, “that’s just not how you treat a security system. That’s what this is — this is a security system for elections.”

    (tags: facebook ads politics uk-politics transparency microtargeting social-media)

Links for 2020-01-14

  • How is computer programming different today than 20 years ago?

    Some good answers:

    A desktop software now means a web page bundled with a browser. You are not officially considered a programmer anymore until you attend a $2K conference and share a selfie from there. Code must run behind at least three levels of virtualization now. Code that runs on bare metal is unnecessarily performant. Running your code locally is something you rarely do. A tutorial isn’t really helpful if it’s not a video recording that takes orders of magnitude longer to understand than its text. Mobile devices can now show regular web pages, so no need to create a separate WAP page on a separate subdomain anymore. We create mobile pages on separate subdomains instead. We run programs on graphics cards now. Since we have much faster CPUs now, numerical calculations are done in Python which is much slower than Fortran. So numerical calculations basically take the same amount of time as they did 20 years ago. Storing passwords in plaintext is now frowned upon, but we do it anyway.
    There's also some serious answers, but I prefer these ones.

    (tags: evolution dev programming humour coding lols fortran history)

  • Record/Replay testing in Sorbet

    I do like record/replay tests. +1

    (tags: sorbet testing record-replay-testing unit-tests tests)

  • The Center Blows Itself Up: Care and Spite in the ‘Brexit Election’

    The center of British politics has become a smoldering pit. The country is now being governed by a hard-right government placed in power by its oldest citizens, in the face of the active hatred of its increasingly socialist-inclined youth. It’s fairly clear that for the Johnson team, Brexit was never anything but an electoral strategy, and that they don’t have the slightest idea how to translate it into economic prosperity. (It is an unacknowledged irony of the current situation that the people most likely to profit from the Brexit process are, precisely, lawyers—and, probably secondarily, accountants. For everyone else, it’s hard to imagine a scenario where they will improve their current situation, and quite easy to imagine Johnson being remembered as one of the most disastrous prime ministers in British history.)

    (tags: labour brexit uk politics tories boris-johnson jeremy-corbyn centrism)

Links for 2020-01-10

Links for 2020-01-09

  • "One of our office chairs turns off monitors"

    Crappy unshielded display cables are prone to electrostatic discharges from gas-lift office chairs... "we have also seen this issue connected to gas lift office chairs. When people stand or sit on gas lift chairs, they can generate an EMI spike which is picked up on the video cables, causing a loss of sync. If you have users complaining about displays randomly flickering it could actually be connected to people sitting on gas lift chairs. Again swapping video cables, especially for ones with magnetic ferrite ring on the cable, can eliminate this problem."

    (tags: chairs furniture funny hardware emi esd monitors twitter video)

  • Disinformation For Hire: How A New Breed Of PR Firms Is Selling Lies Online

    If disinformation in 2016 was characterized by Macedonian spammers pushing pro-Trump fake news and Russian trolls running rampant on platforms, 2020 is shaping up to be the year communications pros for hire provide sophisticated online propaganda operations to anyone willing to pay. Around the globe, politicians, parties, governments, and other clients hire what is known in the industry as “black PR” firms to spread lies and manipulate online discourse. A BuzzFeed News review — which looked at account takedowns by platforms that deactivated and investigations by security and research firms — found that since 2011, at least 27 online information operations have been partially or wholly attributed to PR or marketing firms. Of those, 19 occurred in 2019 alone.

    (tags: disinformation china propaganda pr disinfo social-media marketing)

  • How to monitor Golden signals in Kubernetes

    Most of this doc is Kubernetes specific, but this "golden signals" idea is interesting; basically, the four metrics of requests per second, average request latency, CPU usage on service fleet, errors per second. I would modify by adding the P99 or P99.9 request latency, and representing errors per second as a proportion of that period's request-per-second figure.

    (tags: kubernetes monitoring sysdig golden-data k8s golden-signals metrics latency errors)

  • Serving 100µs reads with 100% availability · Segment Blog

    Distributing read-only snapshotted SQLite databases to shared volumes works! nifty hack

    (tags: architecture databases performance sqlite segment ops docker)

  • Ironies of automation

    Wow, this is a great paper recommendation from Adrian Colyer - 'Ironies of automation', Bainbridge, Automatica, Vol. 19, No. 6, 1983.

    In an automated system, two roles are left to humans: monitoring that the automated system is operating correctly, and taking over control if it isn’t. An operator that doesn’t routinely operate the system will have atrophied skills if ever called on to take over. Unfortunately, physical skills deteriorate when they are not used, particularly the refinements of gain and timing. This means that a formerly experienced operator who has been monitoring an automated process may now be an inexeperienced one. Not only are the operator’s skills declining, but the situations when the operator will be called upon are by their very nature the most demanding ones where something is deemed to be going wrong. Thus what we really need in such a situation is a more, not a lesser skilled operator! To generate successful strategies for unusual situtations, an operator also needs good understanding of the process under control, and the current state of the system. The former understanding develops most effectively through use and feedback (which the operator may no longer be getting the regular opportunity for), the latter takes some time to assimilate.
    (via John Allspaw)

    (tags: via:allspaw automation software reliability debugging ops design failsafe failure human-interfaces ui ux outages)

  • Bellingcat's Online Investigation Toolkit - Google Docs

    'Welcome to Bellingcat’s freely available online open source investigation toolkit [...] The list includes satellite and mapping services, tools for verifying photos and videos, websites to archive web pages, and much more. The list is long, and may seem daunting. There are guides at the end of the document, highlighting the methods and use of these tools in further detail.' (via Damien)

    (tags: bellingcat osint mapping archival search image-search geo-search web fact-checking)

Links for 2020-01-08

  • Modin: Speed up your Pandas workflows by changing a single line of code

    The modin.pandas DataFrame is an extremely light-weight parallel DataFrame. Modin transparently distributes the data and computation so that all you need to do is continue using the pandas API as you were before installing Modin. Unlike other parallel DataFrame systems, Modin is an extremely light-weight, robust DataFrame. Because it is so light-weight, Modin provides speed-ups of up to 4x on a laptop with 4 physical cores. We have focused heavily on bridging the solutions between DataFrames for small data (e.g. pandas) and large data. Often data scientists require different tools for doing the same thing on different sizes of data. The DataFrame solutions that exist for 1KB do not scale to 1TB+, and the overheads of the solutions for 1TB+ are too costly for datasets in the 1KB range. With Modin, because of its light-weight, robust, and scalable nature, you get a fast DataFrame at small and large data. With preliminary cluster and out of core support, Modin is a DataFrame library with great single-node performance and high scalability in a cluster.

    (tags: data parallel python pandas dataframes modin data-science)

  • IAmA: Reddit's Own Vacuum Repair Tech

    some top tips on what to look for in a vacuum cleaner. Bottom line: bagless and stick vacuums are not the best

    (tags: reddit vacuum-cleaners shopping tips ama hoovers)

  • Buckle Up Twitter

    Listen up bitches, it’s time to learn incorrect things about someone you’ve never heard of:

    I am thinking of the response to February’s “Beau Brummell invented toxic masculinity” episode, in which the 19th-century English fancy man Beau Brummell, as infamous a dandy as one can be, was “taken down” in a grueling thread which neatly encapsulated all the worst qualities of Buckle Up Twitter: bewilderingly irate, laden with a combination of baroque linguistic flourishes and performatively subversive swearing, assumption of complete ignorance on the part of the audience, fondness for the word “gaslighting,” a powerful youth pastor-like eagerness to “meet people where they are,” high likelihood that it will be retweeted by people who refer to themselves as “Scolds” in their twitter bios, strong urge to lay the blame for the ills of the 21st century firmly at the foot of a basically random actor or event, total erasure of most things that have ever happened.

    (tags: twitter threads bores social-media funny)

  • Facial recognition for the public: Yandex

    not such much via, as from, Nelson:

    You can use Yandex Image Search right now as a pretty good facial recognition system for anyone who has labelled photos on the Web. I believe this is the first generally accessible facial recognition system with a large database. Yandex isn’t designed for this purpose. The trick is to upload photos cropped to a face and it’ll work more or less to find similar faces.
    this is really odd. Definitely seems like they designed the image similarity engine to support faces as a special case.

    (tags: privacy face-recognition yandex search similarity images web)

  • How "special register groups" invaded computer dictionaries for decades

    For some reason, a 1960 definition of [a computer's] "central processing unit" included "special register groups", an obscure feature from the Honeywell 800 mainframe. This definition was copied and changed for decades, even though it doesn't make sense. It appears that once something appears in an authoritative glossary, people will reuse it for decades, and obsolete terms may never die out.
    Additionally, the "main frame" was a Honeywell term for the large physical frame which held the CPU. History!

    (tags: computer computing language history etymology mainframe honeywell cpu dictionaries)

Links for 2020-01-07

  • massive Travelex outage

    The holiday money exchange site has been offline for the past 7 days, reportedly due to a ransomware infection, with 5GB of PII data exfiltrated

    (tags: travelex fail security exploits ransomware malware outages)

  • SHA-1 is a Shambles - First Chosen-Prefix Collision on SHA-1 and Application to the PGP Web of Trust

    Abstract: The SHA-1 hash function was designed in 1995 and has been widely used during two decades. A theoretical collision attack was first proposed in 2004 [WYY05], but due to its high complexity it was only implemented in practice in 2017, using a large GPU cluster [SBK+17]. More recently, an almost practical chosen-prefix collision attack against SHA-1 has been proposed [LP19]. This more powerful attack allows to build colliding messages with two arbitrary prefixes, which is much more threatening for real protocols. In this paper, we report the first practical implementation of this attack, and its impact on real-world security with a PGP/GnuPG impersonation attack. We managed to significantly reduce the complexity of collisions attack against SHA-1: on an Nvidia GTX 970, identical-prefix collisions can now be computed with a complexity of 261.2261.2 rather than 264.7264.7, and chosen-prefix collisions with a complexity of 263.4263.4 rather than 267.1267.1. When renting cheap GPUs, this translates to a cost of 11k US\$ for a collision, and 45k US\$ for a chosen-prefix collision, within the means of academic researchers. Our actual attack required two months of computations using 900 Nvidia GTX 1060 GPUs (we paid 75k US\$ because GPU prices were higher, and we wasted some time preparing the attack). Therefore, the same attacks that have been practical on MD5 since 2009 are now practical on SHA-1. In particular, chosen-prefix collisions can break signature schemes and handshake security in secure channel protocols (TLS, SSH). We strongly advise to remove SHA-1 from those type of applications as soon as possible. We exemplify our cryptanalysis by creating a pair of PGP/GnuPG keys with different identities, but colliding SHA-1 certificates. A SHA-1 certification of the first key can therefore be transferred to the second key, leading to a forgery. This proves that SHA-1 signatures now offers virtually no security in practice. The legacy branch of GnuPG still uses SHA-1 by default for identity certifications, but after notifying the authors, the modern branch now rejects SHA-1 signatures (the issue is tracked as CVE-2019-14855).
    (Via Tony Finch)

    (tags: via:fanf security sha sha-1 crypto hashes hashing pgp gpg collisions)

Links for 2020-01-06

  • Algorithms interviews: theory vs. practice

    Good critique of the current practice of using algorithm questions during tech interviews from Dan Luu

    At this point, we've gone through a few decades of programming interview fads, each one of which looks ridiculous in retrospect. Either we've finally found the real secret to interviewing effectively and have reasoned our way past whatever roadblocks were causing everybody in the past to use obviously bogus fad interview techniques, or we're in the middle of another fad, one which will seem equally ridiculous to people looking back a decade or two from now. Without knowing anything about the effectiveness of interviews, at a meta level, since the way people get interview techniques is the same (crib the high-level technique from the most prestigious company around), I think it would be pretty surprising if this wasn't a fad. I would be less surprised to discover that current techniques were not a fad if people were doing or referring to empirical research or had independently discovered what works.

    (tags: interviews interviewing hiring tech software jobs fads algorithms dan-luu)

  • Testing in Production: How we combined tests with monitoring

    The Guardian Digital team's write-up on their "test in prod" setup -- post-release monitoring through running integration test suites. We do the same in Swrve, calling our suites the "canary tests", and it works really well for us.

    (tags: testing monitoring ops devops the-guardian prod production releases)

  • Power Line Adapter noise interference

    oh dear, I use this model....

    About 3 weeks ago our neighbour installed power line adapters. The PLAs in question were branded TP-Link [....] How did I know that my neighbour had installed these? Well, the 50MHz band was immediately submerged under a wall of radio noise. Much tinkering with the Noise Blanker settings on the Icom IC-7300 allowed me to separate out two distinct types of noise - 1st a sound like a chicken clucking which was there 24 hours per day and - 2nd a wideband swoosh of white noise of varying strength which happened at certain times.

    (tags: noise rf wifi powerline networking home hardware radio)

  • City maps from tourists' feelings

    This is fascinating, and potentially quite useful -- although the great loft I stayed in in Antwerp is marked in a decidedly yellowish region :) (via Nelson)

    The aim of this project is to map tourists’ perceptions of different urban areas through data retrieved from vacation rental platform Airbnb. After their stay, Airbnb guests score their feeling about the neighbourhood using a star-based rating system. The aggregated rating of each Airbnb listing is publicly accessible, and given the widespread expansion of this platform, a large amount of data is available for the most visited cities. When overlaid on a map of the city, the data reveals interesting geographic patterns and exposes subjective perceptions on safety, upkeep or convenience. -- Beñat Arregi

    (tags: airbnb dataviz maps mapping via:nelson data tourism europe vacations holidays)

  • Home Automation Bargain Alerts thread at boards.ie

    in case I need to fill my house with IOT tat

    (tags: iot tat home-automation home gadgets bargains boards)