Facebook sucks, Future AMD GPUs could be GREAT! - WAN Show Apr.13 2018

  • Published on Apr 14, 2018
    Timestamps courtesy of JJMC89.
    00:07:20 - Facebook users aren't changing privacy settings, despite uproar
    00:20:45 - AMD Navi
    00:29:17 - Google-branded 4K Android TV dongle
    00:34:17 - Floatplane
    00:38:17 - Sponsor: Symless
    00:39:59 - Sponsor: be quiet!
    00:41:22 - Sponsor: Squarespace
    00:42:25 - WebAuthn
    00:51:24 - Ransomware asks you to play PUBG
    00:43:11 - FTC staff warns companies that it is illegal to condition warranty coverage on the use of specified parts or services
    00:54:37 - Apple's HomePod isn't the hot seller it wanted
    01:03:33 - New Gmail confidential mode
    Some of your points seemed a bit vague, and maybe some ppl may miss the underlying point with the Facebook regulation topic, but I fully understand, and it needs to be addressed because in its current state it is affecting some ppls lives in a very negative way. Honestly, with the way things are now with such regulations in place, can actually have the reverse effect, which is doing more harm then good. This is such a tough topic for me, and I really hope we can come up with a good solution for it. This is one of my favorite WAN Shows by far now that I fully understand LMG’s intentions.

    1:02:55 I agree it'll happen eventually, but I'm with Luke, I'd prefer it not constantly report back to the cloud, which is the path we are on.

    19:20 - Yeah, the argument that "my mom is dumb so we need total regulation and fines and taxes and prison sentences for everyone because she is too dumb to either not share private data or at least mark them as private. I want her to stay stupid but also be allowed to the non-stupid people society."

    the whole goal shouldn't be to regulate individual people. You should establish a certain level of ethical standards. And then you police those. Personal information on an advertising standpoint is inconsequential. We are all sentient and can determine what is a good reality and what is bad. The real concern is governmental involvement. If you hate a politician that gets elected, you should never feel the repercussions of that. But if you view sunglasses a lot, it is pretty harmless to be presented with a ton of advertisements about that.

    It's how you look at it, im glad even people that don't care about their privacy still stands up for it

    I know this is an old episode, but weighting in on the regulation matter anyways... the answer is probably what Europe will be doing with GDPR.
    It's something that, if government and regulatory bodies back then had the vision lots of people on the security sector and overall privacy advocates had, we would not have to be going through it arguably too late - because you know, what was leaked, is still being leaked, and will be leaked until something even more serious happen, is already gone.
    I've been saying this for years now, but it's basically guaranteed that everyone probably already has a dossier stored in several companies servers, plus some shady places on the dark web, ready for exploitation.
    Kinda like climate change effects. We will be severely impacted by it, and perhaps it's already too late... so doing something about it now it's kinda remedial. Perhaps so that future generations won't have their data entirely leaked and whatnot.
    But GDPR is arguably some steps ahead on the matter. Even then, we'll have to evolve it with the entire idea of privacy at some point.
    And like you guys said, blockchain might be part of the tools we'll be using in the future for that.
    Perhaps the next privacy oriented social network will have to find a way of handling user information without the company behind it actually seeing any of it. Much like you have encrypted messaging systems, e-mail services and search engines where the companies behind cannot have access to any of the private content, a social network with the same model also could be divised.
    Of course, a whole ton of problems emerge from that. How to monetize, how to censor, how to have some level of access and control, etc etc. There are potentially more downsides than advantages, but we could get to a point where it meets the standards and expectations of most people.
    There are several levels of struggle and contradictions happening right now that will eventually have to be decided - hard questions that needs addressing.
    For instance, at the same time the government made a whole deal of Facebook's data collection and improper usage, we're talking about the same government with politicians that advocates for mass surveillance, encryption backdoors and a whole string of other crap that, you know, would provide companies like Cambridge Analytica or even political parties with the same sort of ammunition. Not to mention leaks, hacks and whatnot.
    I bet you that at the same time some politicians were there vociferating against Zuck, at least some of them were thinking about having all that data for themselves for several reasons - future elections, to find terrorists and predict attacks in an easier way, to understand their voters better, etc etc.
    Can't eat the cake and also have it.

    So, tell me guys, is Linus an equal opportunity employer ? I only ask because the guys I see on his show are mostly very much pretty boys....does he employ any semi-ugly nerds with ultra mad skills ?..or does just have the one, you know as like a token so he can defend any questions relating to the whole deal ?..I honestly do wonder, because I'd bet most of his audience really don't give an electronic sausage if his crew are handsome or not, his audience are mostly straight males....

    I just realized Luke hates steemit.com because it is a platform that allows content creators a place to upload their content to that gets them paid.....a total threat to FloatPlane. The service that it provides actually competes in the same exact field. A mechanism to pay content creators and a place to view the content. Problem is whereas you may have to pay for FloatPlane as a consumer on steemit people who consume the content get paid to upvote comment and interact on the platform. Luke is cool guy I like him. I just have to make the argument which may seem small but huge......... Why would I pay to see content when I can get paid to see content. Love LTT I've thought highly of FloatPlane until I just had this realization. Yes lots of people do pay and donate extra to their favorite content creators and there is a market for that. I just wonder if Luke honestly has made the connection that steemit may actually compete for a slice of FloatPlane Market.

    I used Steemit to earn a few grand in crypto and buy stuff off Newegg.com with it. Its totally legit chill cool place. Not exactly social media though. More like blogging to a blockchain. I know this isn't the best way to plug it to LTT but to overlook steemit as a serious platform is a huge mistake for many. I also had a slow start due to the wtf is this effect being new to crypto. I'm just some random guy on there my current value is over $2000 I've spent around $500 worth since I've started. NO INVESTMENT NEEDED. I am in no hooked up with this steemit. I am just a nobody user on the platform. I've mostly posted my original memes and game streaming. Thats it.

    There are a lot of people out there who won't buy an NVidia product, whether it's cheap (only cheap if bitcoin collapses).. or if it's not. This $250 1080 is something that will sell like wildfire. Many have cards in need of replacing, and wouldn't be caught dead paying $800 for a 1080 or $1200 for a 1080ti, whether they could afford to or not. Besides this, that GPP or whatever it's called has just added to the disgust some of us have for this company. NVidia, Dell and even Intel are on this "sht list" of mine. Intel may have CPUs for $400 now that are decent, but take AMD out of the picture and Intel adds at least one digit to all of their SKUs. To hell with those greedy companies.

    Sharing on FB should be entirely opt-in, not opt-out. This would need to be forced by the government, since FB *IS* selling this data and won't stop on their own. They're addicted to money.

    I don't know what the regulation answer is, but I do know that if companies were actually and properly punished for fucking up, this would be less of a problem.
    Right now, any fines that *are* in place are just a cost of doing business, rather than a penalty.

    Could we get a revisit of the auth topic when Luke has had a chance to actually read the spec. It answers all of his concerns and is actually really interesting.

    13:45 Here is where you're wrong. In the early 2000's, most social media networks had XMPP gateways that enabled cross social media messaging. XMPP still exists but after Facebook dropped it to solidify it's lead over AOL and mySpace, most companies have shut those down. The technology is still here, and still used, although it's far more niche now.
    Mandating social networks maintain and interoperability standard could go a long way towards making the life of new entrants to the market easier. And it wouldn't be an unheard of thing either - for example Intel is currently forced by the FTC to support PCI-e(for ~10 years) because of an anti-competition lawsuit it lost to AMD.
    16:14 It's called Diaspora and it's been around for a decade now... diasporafoundation.org/

    Most websites are beginning to integrate SAML ( tools.ietf.org/html/rfc7522 ) and/or OAuth ( tools.ietf.org/html/rfc6749 ) plugins such that users can initiate authentication with external authentication providers. While this may seem like over complication, it provides SIGNIFICANT risk reduction to an individual and organization such that they have taken legitimate measures to protect their valuable data.
    phishing is an issue, as is brute forcing. Note however that biometrics are not significantly more complicated to brute-force in concept, because a finger-print reader does not take your actual legitimate finger-print to validate (which is not reproducable), instead it sends key measurements which the algorithm being used deems as discrete to the server to identify a specific person. Note that this data is all 0s and 1s, so the practicality/strength of this legitimizing factor is only as strong as the size of the data set (dependent on the sensitivity of the sensor). As all biometric information is encapsulated into binary, and likely hashed it is still specifically a single set of data, and is likely a (relatively) small quantity, such that it is definitely repeatable, it is just a measure of probability as to IF it will be reproduced, either willingly or not.

    The thing with the general authentication is that it the authentication/authorization code the site receives would probably be linked to the domain, so the paypol.com phishing domain would receive a code that would not work for paypal.com.
    Steve Gibson (grc.com, SecurityNow podcast) is building an authentication mechanism (SQRL) that's definitely worth checking out and which is probably close to WebAuthn.
    BTW, Authn comes from the acronyms for Authentication (auth'n) and Authorization (auth'z).

