Daily Shaarli

All links of one day in a single page.

February 26, 2023

Velocipedia on Behance

You might have noticed there’s something wrong with this bike. Or you might have not.

This bicycle is missing a very important part of its frame and it would immediately break if it actually existed and someone tried to ride it.

Let me explain everything from the beginning:
back in 2009 I began pestering friends and random strangers. I would walk up to them with a pen and a sheet of paper asking that they immediately draw me a men’s bicycle, by heart. Soon I found out that when confronted with this odd request most people have a very hard time remembering exactly how a bike is made. Some did get close, some actually nailed it perfectly, but most ended up drawing something that was pretty  far off from a regular men’s bicycle.

Little I knew this is actually a test that psychologists use to demonstrate how our brain sometimes tricks us into thinking we know something even though we don’t.
 
I collected hundreds of drawings, building up a collection that I think is very precious. There is an incredible diversity of new typologies emerging from these crowd-sourced and technically error-driven drawings. A single designer could not invent so many new bike designs in 100 lifetimes and this is why  I look at this collection in such awe.  //

In early 2016 I eventually decided it was my turn to take part in this project.

I decided my job was going to be presenting the potential and the beauty inside these sketches. I selected those that I found most interesting and genuine and diverse, then rendered them as if they were real. I became the executor of these two minute projects by people who were mainly non-designers and confirmed my suspicion: everyone, regardless his age and job, can come up with extraordinary, wild, new and at times brilliant inventions.

The James Webb Space Telescope discovers enormous distant galaxies that should not exist | Space
thumbnail

The James Webb Space Telescope discovers enormous distant galaxies that should not exist

By Tereza Pultarova published 4 days ago

Giant, mature galaxies seem to have filled the universe shortly after the Big Bang, and astronomers are puzzled.

Nobody expected them. They were not supposed to be there. And now, nobody can explain how they had formed.

Galaxies nearly as massive as the Milky Way and full of mature red stars seem to be dispersed in deep field images obtained by the James Webb Space Telescope (Webb or JWST) during its early observation campaign, and they are giving astronomers a headache.

These galaxies, described in a new study based on Webb's first data release, are so far away that they appear only as tiny reddish dots to the powerful telescope. By analyzing the light emitted by these galaxies, astronomers established that they were viewing them in our universe's infancy only 500 to 700 million years after the Big Bang.

936: Password Strength - explain xkcd

If you're confused, don't worry; you're in good company; even security "experts" don't understand the comic:

  • Bruce Schneier thinks that dictionary attacks make this method "obsolete", despite the comic assuming perfect knowledge of the user's dictionary from the get-go. He advocates his own low-entropy "first letters of common plain English phrases" method instead: Schneier original article and rebuttals: 1 2 3 4 5 6
  • Steve Gibson basically gets it, but calculates entropy incorrectly in order to promote his own method and upper-bound password-checking tool: Steve Gibson Security Now transcript and rebuttal
  • Computer security consultant Mark Burnett almost understands the comic, but then advocates adding numerals and other crud to make passphrases less memorable, which completely defeats the point (that it is human-friendly) in the first place: Analyzing the XKCD Passphrase Comic
  • Ken Grady incorrectly thinks that user-selected sentences like "I have really bright children" have the same entropy as randomly-selected words: Is Your Password Policy Stupid?
  • Diogo Mónica is correct that a truly random 8-character string is still stronger than a truly random 4-word string (52.4 vs 44), but doesn't understand that the words have to be truly random, not user-selected phrases like "let me in facebook": Password Security: Why the horse battery staple is not correct
  • Ken Munro confuses entropy with permutations and undermines his own argument that "correct horse battery staple" is weak due to dictionary attacks by giving an example "strong" password that still consists of English words. He also doesn't realize that using capital letters in predictable places (first letter of every word) only not increases password strength by a bit (figuratively and literally): CorrectHorseBatteryStaple isn’t a good password. Here’s why.
    Sigh. 🤦‍♂️
Putting Undetectable Backdoors in Machine Learning Models - Schneier on Security

We show how a malicious learner can plant an undetectable backdoor into a classifier. On the surface, such a backdoored classifier behaves normally, but in reality, the learner maintains a mechanism for changing the classification of any input, with only a slight perturbation. Importantly, without the appropriate “backdoor key,” the mechanism is hidden and cannot be detected by any computationally-bounded observer. We demonstrate two frameworks for planting undetectable backdoors, with incomparable guarantees.

First, we show how to plant a backdoor in any model, using digital signature schemes. The construction guarantees that given query access to the original model and the backdoored version, it is computationally infeasible to find even a single input where they differ. This property implies that the backdoored model has generalization error comparable with the original model. Moreover, even if the distinguisher can request backdoored inputs of its choice, they cannot backdoor a new input­ a property we call non-replicability. //

Turns out that securing ML systems is really hard.

zxcvbn tests

password testing

passwords - Is "the oft-cited XKCD scheme [...] no longer good advice"? - Information Security Stack Exchange

One of the reasons why I advocated for an XKCD-like scheme (before it got called that) in Toward Better Master Passwords back in 2011 is precisely because its strength does not rely on the attacker knowing what scheme you used. If I may quote myself

The great thing about Diceware is that we know exactly how secure it is even assuming that the attacker knows the system used. The security comes from the genuine randomness of rolling the dice. Using four or five words should be sufficient against the plausible attacks over the next few years given observed speed of password crackers [against 1Password Master Password]

What the XKCD comic does not effectively communicate is that the selection of words must be (uniformly) random. If you ask humans to pick words at random, you get a heavy bias for concrete nouns. Such biases can and will be exploited.

Secret crawlspace cryptomine discovered in routine inspection of MA high school | Ars Technica

The cryptomine’s operator was likely motivated to maximize cryptocurrency gains by negating the cost of operating the mine. Cryptomines notoriously run off an excess of electricity, with all the world’s cryptomines requiring more energy than the entire country of Australia, the White House reported last year. Where Cohasset is located in the Boston area, “electricity costs have exceeded the national average” by at least 48 percent over the past five years, the US Bureau of Labor Statistics reported.

Medical gas storage under NFPA 99

This covers the basics of medical gas storage and the requirements for health care spaces detailed in NFPA 99

Framework | Introducing the new and upgraded Framework Laptop

A thin, light,
high-performance 13.5” notebook

  • that’s designed to last
  • that’s totally upgradeable
  • that respects your right to repair
AnechoicMedia on Twitter: "What an incredible rabbit hole. Margaret Hamilton, awarded the Presidential Medal of Freedom for "[leading] the team that created the on-board flight software" for the Apollo missions, wasn't even hired until after the completed software had already flown to the moon in Apollo 8! https://t.co/xGICM7okcU" / Twitter

AnechoicMedia @AnechoicMedia_

What an incredible rabbit hole. Margaret Hamilton, awarded the Presidential Medal of Freedom for "[leading] the team that created the on-board flight software" for the Apollo missions, wasn't even hired until after the completed software had already flown to the moon in Apollo 8!