Showing posts with label Arrogance. Show all posts
Showing posts with label Arrogance. Show all posts

2026-03-23

A DeCSS shirt for the late 2020s

So, I see a lot of wittering and gnashing of teeth about online age verification laws. Both in general and specifically as the apply to Linux, BSD, and other open source operating environments. I want to talk about some practical issues around what technology will have to emerge to make them "work" and how easily even moderately technologically aware people can, to be blunt, screw the laws over.

And I want to propose a new fashion that might, just, catch on in the next few years.

What is going on

A few juristictions (including Brazil and California) have passed legislation pertaining to online age reporting and many other jurisdiction seem to be following suit.

Allegedly these are intended—as so many, many bad ideas have been in the past—to Protect The Childred (tm).

They're not going to work any better than content labeling of music, the v-chip, or video game content rating (just to name a few) did1. I recall a time when every stand-up comedian seemed to have a bit about how parents would have to get their seven-year-olds to program the v-chip just like the kid was the one who set up the VCR. But hey, we have to do something and this is something so obviously we have to do this. Not that I'm depressed by how predicatable all this is or anything.

Why it's weird for open source

There are a few of things going on here. One is structural, one is philosophical, and under all that is brute technological fact.

Structural

While Windows, MacOS, IOS, ChromeOS, and Android2 are controlled by large coorporate entities that decide what their customers get to install, Linux, BSD, and other open source operating system are, in principle, fully under control of the individual installing them. The weasle words are in there because few people build out their system from raw parts: they mostly use a distribution, which does have a central point of control (though many offer much more customization that the you get from Apple or MicroSoft).

This is not a funcdametal issue; the kernel and or the encrustation of supporting code could feasibly (I won't say "easily" because I'm not the one programming it) be altered to support the requirements of the laws. And those changes could be incorporated in upcoming distribution releases and make their way out to the mass of users.

But it's not like there is one place to go to try to enforce this decision. Or even ten places. Keep in mind that even if some major distribution (perhaps Ubuntu) were to comply nothing stops a downstream re-packager (say Elementary) from removing, disabling or defanging that support. More on that later.

By the way, there are litteraly scores of distributions originating on all the inhabited continents and from various points in Oceana.

Philosophical

As a generic term "open source" covers a lot of ground, but central to the that nebulous mass broadly known as the open-source/free-software movement we find Creative Common, the Open Source Iniitive, and the Free Software Foundation all of which of are organizations with some money, rather more precisely specified definitions, and some very strong opinions on matters of software control and human flourishing. And they're not the only ones. In fact the space is just crawling with various NGOs that provide legal support, lobbying services, publicity, and (obviously) software packaging.

The whole "the government is telling you how to build your software" thing isn't going down well. You may expect resistance at many levels. Anyone else own a DeCSS shirt?

The foundational reality of Open Source

Programmers program. In one sense that's a tautology, but it has profound implications.

Before delving into what it means for this issue, let's just talk about what it means for organizational cyber security. My employer has recently gone through a series of IT security exercises in an effort to lock down all the possible cyber threats. And they have a problem: what programers do on a day to day basis is indistinguishable from a large class of threats. We create new executables not known to the system and run them. Often dozens of times a day. And that is unavoidable: you can't have the benefits of what programmers do without having the relative chaos of programmers at work.

Similarly, you can't have open source and still be confident that everyone is running the nannyware you insist on. Remember that I said a downstream distributor could strip-out or neuter a reporting facility installed by an upstream provider? Well, in principle every single user is a downstream provider with that same capability. Worse, capable programers can provide tools to enable less capable people to perform the necessary modifications. Indeed, Ageless Linux is already pushing back against early complinace efforts on the part of systemd (the dominant, but often derided, init system on major Linux distros).

Legal aside

I think the intent is that anyone modifying the softawre is the "Provider" that the government enforcers can go after, but if that's just a couple of techy parents who don't want their machine identifying their minor childern to the wider internet, there is a "parent's rights" argument to hang a political and legal challange on.

But ... talk to an actual lawyer in your actual jurisdiction with actual expertese on the legal system you actually might be picked on by before counting on that kind of thing. K?

Speculation on implementation and countermeasures

From ten kilometer altitude, communication between a user's machine and a software store or other endpoint that might want to use a age signal can take one of two forms, and one of them is harder than the other for actual installed systems. You see, one machine has to initiate the conversation, and if that's the store's server, then many home and corporate firewalls will drop the packets on the floor.3 For that reason I suspect the industry will settle on a strategy where the user machine asks the server for a one-off token, hands that to a local age-reporting API which cryptographically mixes it with the answer, and the mixed data is then relayed back to the server for decoding. There are other things they could try, but they're all pretty fragile.

Anyway, on Linux the bit that builds the reply would either be built into the kernel itself or in a kernel module, but either way a savy user will be able to disable them. Then they just substitute a dummy system that respects the protocol, but always returns a least-interesting answer to every query (Yeah, this user is of age. Trust me.).

What Ageless does is more than that: it removes the infrastructure and storage that could be used to respond, which is a good thing, but the above is enough to stop making meaningful responses. And I'll bet a bottle of scotch that the dummy responder can be constructed with code that will fit on a t-shirt.

Intent

I'll write the thing as soon as the spec is available (or grab someone else's if it's avilable, because I'm not stuck about this sort of thing). And then I'll be printing shirts. And maybe hoodies, too. You never know.


1 Which is to say that (a) the kinds of parents who take the trouble to monitor their kids' media consumption will have another tool while other kinds will completely ignore it and (b) the kids will not only find ways around the tech, they'll use the system to advise them where the "good" content is.

2 Android is a little weird, because while Google (whatever name they're going by now) controls the system, many devices ship with manufacture customized versions. But it is still the case that there is a corporate entity for the government to go after.

3 And maybe report them to an intrusion detection system, but that's not really relevant here.

2026-02-02

Hey, ya wanna help?

Here's the thing about smart phones: you cannot reasonably prop them between your shoulder and you ear. Not only will you get an instant muscle cramp (and probably scoliosis within minutes if you persisted), but the thing won't actually stay there. In that respect they really, deeply suck.

But whatever. Price you pay for the benefits of the form factor. Or whatever.

That said, this has a consequence: if someone calls and (a) you don't feel you can skip it, (b) you still need to have both hands for something (anything) other than the phone, and (c) you don't currently have your buds in then you must, in short order:

  1. answer the call
  2. switch to speaker
  3. prop the phone somewhere

Presumably the people who write the UI for these things have this experience, too.

But recently with my phone, when I tap to answer, the UI goes through some flashy, battery-draining, nonsensical animation which results in the hang-up control landing right where the change-the-audio-button was a moment before. I have no words.

Random musings

If you found yourself in the same room as whatever self-satisfied twit is responsible for foisting "liquid glass" on us and asked the two nearest other iPhone users if they wanted to help administer a swirly, what do you think the odds would be?

I put them over 2/3, personally.

2026-01-30

The limits of manipulations for "their own good"

It's OK, because Duggee has his gas-lighting badge!

It's an endless question for parents about their children, isn't it? How much pressure and distortion can I, legitimately, use to teach them things,1 to buy a little space, and so on? Some, I suppose, but it must be an ever moving target as the kiddo grows, develops, and just gets better at seeing through our BS. We try to keep in mind that the kiddo must one day stride forth to meet the world with her own skills, opinions, and point of view. We'd like that to go pretty well, so the scaffolding must be dismantled and some kind of model of good-person-in-a-hard-world needs to be offered.

I'll just get right on that.2

But, wait! There's more! My wife and I are smack is the middle of the sandwich, so it's also applies to interactions with our elders. And the answer to that, too, will be an evolving thing. Right now it's just one set, but there is every reason to suspect the others will need support sooner or later. So that's a whole different take on the same kind of questions.


1 In my prior, professional life, it even had a name: "lies to children".

2I wonder who in their right mind would sign off on our being parents in the first place?

2023-07-04

More registration bullshit

I ordered something online last month (hardly an uncommon occurance). The vender shipped it and gave me a tracking link which I've been checking periodically. As of July 22nd, the tracking website lists it's status as

Shipment Received, Package Acceptance Pending [name of my town]
and it claims it will be delieverd by the very next 7pm. Every time I look it's coming by the next 7pm. For nearly two weeks, now.

Now, I have to say that "Acceptance Pending" is mildly worrying,1 but the ongoing lack of progress is a bigger deal. A few of days ago (when the status hadn't changed2 for eight days) I ran out a patience and decided to get a human being involved. I don't think that's unreasonable, do you?

Anyway, you might expect there to be some kind of link or button explcitly for escalating a case to a person. There isn't. Presumably that's a behavior engineering thing: if you make it too easy to escalate, people will avail themselves of the option enough to cost you real money. Disappointing but not terribly surprising.

So try drilling down both from the tracking page and from the home page.

The tracking pop-up does offer to let me log into the system so that I can see my "full shipment progress",3 but I have to give them lots of personal data to do that. Why? Why is knowing my name and where I'm recieving package not enough, huh?

The "Contact Us" part of the home page has a varienty of toll-free numebrs to use t oget put in a queue to talk to one of their call centers, which I suppose is what I'm going to have to do.


1 Did they lose the package between pulling it off the truck and sorting it for local delivery? Is the box more dmaged them they're comfortable with? Something else?

2 Except for updating the project deliever date every day to keep it at the next 7pm, of course.

3 That offer is on the "Shippment Progress" tab of the tracking pop-up. I guess it's really a Partial Shipping Progress tab. Or something.

2021-11-02

Holding back the schadenfreude

Today my news feed included yet another article about the terrible plight of hiring managers these days. The poor dears are being left high and dry by job seekers who don't care about their wasted time and don't feel the need to offer their victims even the common courtesy of a phone call or email. Or even a text message. Such unprofessional behavior! Who could credit it?

Or something like that.

I am aghast In theory. But not in reality.

You see I conducted professional job searches in 2004-5, 2007-8, 2012-13, and 2017-18; making somewhere between 250 and 300 applications in total. Consequently I have a reasonable statistical basis on which to make some observation of what "professional, business behavior" associated with hiring situations has actually turned into over the last decade and a half. Albeit, based on my memories rather than good records. You've been warned.

First a few observations about the large scale context:

  • The vast majority of those applications were made via email or on-line form. I can't recall sending a single hard-copy packet in the last two job searches.
  • The prevalence of on-line forms over "send us these documents in a format we understand" grew steadily through the period and was total dominant by the end.
  • It is obvious (occasionally even explicit) that many of these systems use some kind of automated filtering to save the hiring managers from needing to look at all the applications.1

Before we go on, I should mention that I've sat on hiring committees. I've sat in bed next to my loving spouse pouring over a slush pile of packets sorting out those that should never have been sent from those that at least come close to having the background we asked for. The next week I was working over a subset of them to select a set of promising prospects for deeper investigation.2 I've called references. I've sat through two rounds of telephone interviews and hosted the in-person appearances. I've debated the pros and cons of the multiple interviewees who were almost but not quite the candidate we wanted, each with their own strengths and weaknesses.

I know how painful, labor intensive, and demoralizing it can be to be on the hiring end of these things.

That said, I want to focus on a particular feature of the hiring system we've developed in these glittering first decades of the twenty-first century: in many, many cases the system is designed solely for the convenience of the hiring manager at the cost of the job seeker. First I have to register with a portal to start the process. Including, of course username3, password4, and recovery questions. No, you won't be able to re-use any of that; every employer has their own portal. Then not only should I upload my carefully formatted resume (or CV), cover letter, and other documents but I also need to copy the data therein to an endless series of web forms.5 Then I get to answer a set of true/false or multiple choice questions to confirm that I have the minimum requirements for the job.6,7 Then I'm lucky even to get an automated email confirming that the system received my application8 and even more lucky to receive further communications if I don't get called for an interview.9

Total time screwing around in the web interface: 30-60 minutes. Exclusive of (a) finding the prospect, (b) any research on the company you care to do, and (c) any customization of your packet materials you care to do.

The "painful, labor intensive, and demoralizing" bit I experienced when trying to hire was never a patch on what it was like to be a job seeker.

And there are three key points here. First, no one on the other end gives a fig how well this system works for the job seeker. Your blood, sweat, or tears are of no consequence to them. Second, while people are looking for a "fit" they care more about being able to identify a reasonable fit than about finding the perfect (or even a great) fit if it means more work to do it. And finally, the last fifteen plus years have been spent normalizing the idea that one side of this negotiation is allowed to drop the other side without a word. Some folks just imagined that only one side would ever exercise the option.

Ghosting your partner in this interactions is the standard of professional business behavior in the hiring game. Because a significant fraction of hiring managers have been working hard to make it so for decades.

Now, it's just possible that the people interviewed for these articles are the compassionate few who insisted on maintaining polite, if automated, contact with applicants up to the point that the position closed with those hopefuls still outside the door.10 It could be, but I doubt it.

I started this post with the intention of writing a sly observation on the reversal of fortunes. But somewhere along the way it turned into a bit of a rant. It seems I may have a little residual anger. Something on order of a coal-seem fire, perhaps. And I'm sure I'm not the only one.

In any case, schadenfreude is an ugly emotion and I try not to indulge, but sometimes it's very tempting.


1 And let's face it: those filters are utter trash. Natural language processing has come a notable way since the early 1990s but it is still better characterized as "artificial unintelligence" than AI. If you write it by hand you use word and phrase matching, and if you hand it over ot a ML system you get a more finely weighted word and phrase matching system. Either of which suck at seeing transferable skills and related experience. You can try to fix that with some kind of mapping systems but only if you can accurately anticipate what related experience and transferable skills will appear in your application pool. And of course, if you care to spend the not inconsiderable amount of money turning such predictions into work code would require.

2 I'm positive, both as a job seeker and a hiring committee member, that good candidates get screened at this step.

3 But not that one, it's already taken.

4 But not that one, it has characters we don't allow. Or doesn't have a character from this class. Or doesn't have characters from enough classes. Or whatever.

5 Occasionally the system tries to pre-populate the forms for you by parsing the documents you uploaded. I presume this works OK if you upload in Word format (but why would you upload something like that in an editable format?!?) and use a popular template.

6 Always after you've done all the other work.

7 Which means these things are hard fails with no chance for intelligent consideration of the other factors. A friend who chaired the IT security committee at a major public university and gave talks at major security conferences was ruled out of a position in IT security because he didn't have a master's degree. Of course, you could lie to the computer, but how will the hiring manager feel about that?

8 I'd guess this was roughly 50% of systems in my earliest search reported here and had dropped to less than 25% by my latest one.

9 A few systems do make it possible for you to log back in to track the progress of your applications. For those you actually have to hold on to that username/password pair you made.

10 I even had a handful of personal emails telling me I hadn't been selected back in the noughties. One person took the time to write what looked like a personalized encouraging message. Nothing like that in the teens, however.

2020-08-05

Your messaging isn't reaching the virus

I talked a bit in a previous post about how nerds mostly don't rule the world. One of the big issues is that we think that we live in a world of facts, but most of humanity lives in a world of opinions masquerading as facts. And if enough people believe them then for political purposes they are facts. Politicians get their way in large messure by controlling the way people understand things; spin doctoring works at least some of the time. Which is why message control looms large in the minds of politicians.

But there are some things you can't message your way out of.

When you hear politicians complaining that too much testing is the problem you know they're locked in a mindset where messaging is more important to them than reality. They aren't making any progress in asserting their view of things because of the relentless drumbeat of daily figures, so rather than addressing the hard problem they try to just get rid of the reporting. Rather like the Ravenous Bugblatter Beast of Trall; which is to say "Daft as a bush".


Consdier, if you will, what we could do with enough data.

If we could test everyone all at once, we would have a very powerful tool for isolating the virus. Given that we can't do that, if we could at least test everyone who had been in contact with known carriers we would have nearly as good a grip, which is the point of contact tracing (note how quickly South Korea contained their initial outbreak as an example).

What we can actually accomplish is a lot less powerful, and without some help from the population at large it may not be enough to choke off the transmission, but asking for less data is the best way to guarantee that we don't stop this thing.

2020-06-06

Bureaucracies and Language

Bureaucracies, by their nature, need to make precisely deliniated distinctions and they need to distill those distinctions down to sinlge words (for use in reports, questionaires, statistics and so on). Where existing usage does not support exactly the distinction they need they simply assign the denotation they need to an existing word (effectively re-defining it or at least imposing artifical precision on a word that cared some natuural ambiguity).

To chose an example that came up in the public conversation in the US following Hurricane Katrina, the UN defines "refugee" more closely that most dictionaries because they need to distinguish people diplaced over national border from those who are seeking refuge inside the country where their legal situation is well established. This insistance that the word only applies to those whove crossed national borders is stronger than the original organic use of the word.

This last week we learned that the US National Parks Service defines "tear gas" to exclude pepper bombs. I'm not sure what (if any) purpose is served by this distinction, but it certainly isn't one in general use. It's purely a bureaucratic denotation.

As I indicaed above, I understand that such distinctions may serve a purpose for the agency that makes them, but I feel quite strongly that there is no obligation for actual flesh and blood humans to give a damn. Real people should use words with their real meanings and should feel free to laugh at any jobsworth1 who sugggests that their organization's internal usage is more correct than the general population's.


1 A word I'd forgotten about until I saw it in a opinion peice from a British paper this week.

2020-04-09

Didn't get the survey

Ah. I see that the promised surveys have been sent out to Stack Exchange moderators who stepped down during the recent unpleasantness.

I didn't get one. But then they haven't gotten around to removing my diamond, either. I suppose that's because I didn't make use of any official channels to tell them about my decision, but that's their problem.

I mean, my resignation post on the Physics meta was featured and got more than 80 votes, I changed my username to indicate my new status, and I posted a few comments on the mother meta and Stack Overflow meta, and one of those said explicitly that I'd left.

I know some staff members saw them.

I conclude that the organization is either trying to pretend that some of this stuff didn't really happen or just doesn't give a fig about most of the network.



Aside: I'm sure the "Arrogance" tag applies. But is it for me or for them?

2020-02-05

Upgrade woes and another thing to walk away from

I finally let my MacBook Pro upgrade to Catalina a couple of days ago and got a rude surprise.

Some arrogant snot at Apple (I know, not exactly an uncommon breed over there) thought it would be a good idea to make the Desktop and Download folder special.  As in most application aren't allowed to touch them. Apparently this is a "security" measure.

Now, you can manually assign permission to applications you want to have access.

But I do most of my work from the command line (everyone thinks a Mac is just a convenient Unix box, right?), which is to say that I use dozens of different "small sharp tools" (i.e. applications) that aren't on Apple's blessed list. Who wants to add them all by hand? And especially who wants to discover another one you need to add right in the middle of your next tricky operation?

And I store active projects in folders on the Desktop, so this affect stuff I use all the time.
There are probably children out there holding down spacebar to stay warm in the winter! YOUR UPDATE MURDERS CHILDREN.
Used by permission of the creator Randall Munroe
I guess I'll spend a little time installing Linux on that spare laptop this weekend. I'm told that Elementary OS often just works (though my first attempt was thwarted by the TPM).