Hacker Newsnew | past | comments | ask | show | jobs | submit | nullc's commentslogin

Youtube's bitcoin doubler scams are a great example of this... they run essentially the same videos over and over again, usually Elon Musk, Michael Saylor, or Steve Wozniak, occasionally Warren Buffet and a few others-- with some ticker or scroll telling people about a special promotion where whatever bitcoin you send them will be sent back doubled.

It takes basically nothing to reliably identify these videos. They're extremely heavily promoted with ads running on other videos. Google does nothing with them when reported. Google does not proactively remove them. And because, contrary to the documentation, youtube doesn't pull the verified flag from a channel when its name is changed, these scams go out on channels that look like official sources for the celebrities in them (they steal some random verified channel then change its name to SpaceX (official) or Microstrategy or whatever).

Google even got sued unsuccessfully by Woz and some of the scam victims-- and their response was pound the "S230 is an absolute shield for externally provided material" table and continue to do nothing about the fraud except rake in money from pedaling it. They haven't even fixed the verified flag issue.

(Shades of the same conduct were seen in the old viacom v. youtube case, -- users were reporting copyright infringements so they took away the button.)

I have sympathy for the S230 shield and consider it very important-- but the law is the absolute worst we're allowed to be. They are free to do better (and the CDA shield was designed to assure they can moderate without picking up liability).

Google's conduct is irresponsible, unethical, and may well cost us this important legal protection because if society's choice is liability for hosts OR the biggest and wealthiest companies do nothing while raking in money from even the most flagrant scams we're going to eventually choose liability with dire consequences for free speech.

It's especially ironic that the smaller sites and forums (like HN) would be hit especially hard by a narrowing of S230, but these forms reliably work hard to remove the worse abuse-- and are seldom the source of anything that truly offends the senses at least not for long. Companies like google that don't are ones that are so wealthy and powerful that they're almost intractable to litigate against even without S230 like protection. Loss of it would hurt them gravely but it would hurt everyone smaller more.


Has someone qualified that removing the wireless hardware leaves the device functional?

This would be a nice public service for gamers nexus that happened to buy a lot of these devices. :P

I can say from experience in several devices (but not an LG TV) that removing dedicated bluetooth chipsets so far has left devices functional. ... but some things implement their bluetooth as part of the ESP32 that is the whole kit and kaboodle, so you can't remove it.

As to why someone would remove these components -- in addition to the explicit spying LG is doing, there are companies dragnet collecting BTLE device identifiers <> gps collecting, including collecting them via phone apps. This means that if you have any BTLE devices that are frequently with you or otherwise connected to your identity it may be possible for a threat actor to determine your location(s) from largely unregulated commercial databases.

I don't use BTLE at all, so this 'functionality' is a pure risk to me.


Depends on how you use your computer. If you're mostly a developer/analysis terminal jockey with some browsing-- Qubes is a tremendous upgrade even if you don't care at all about the security properties:

The normal qube model of template OS vms + ephemeral app overlays makes it a cinch to troubleshoot complex issues because you can scribble all over the VM (e.g. go ahead, monkey patch your system LIBC if you want!) and all those changes will be gone when you restart the VM. Once you do find a solution you like, you can apply it cleanly and intentionally to the template. If all you were doing was a one-off, then no need to go make it permanent. Not sure if the latest Fedora upgrade is going to break stuff you care about? Install and switch to it one appvm at a time. Something breaks, file a bug and switch that one back until its fixed.

I've had friends screwing around with AI agents get their systems really screwed up because running the agent in a VM was work and requires maintenance. .. in qubes its just the natural way to run it, a few clicks and you're good to go. And the maintenance overhead of running in a VM is mostly non-existent.

If you ever use VPNs for privacy or to access protected networks-- Qubes is a big upgrade: You can run multiple VPN network VMs and then pick on an AppQube by AppQube basis which network they use. Then you don't have to worry about malware from your reddit browsing VM (or your Erotic MLP fanfic) going out over your employer's network or your banking going out via some Norwegian anonmization proxy that might spy on your traffic or cause your bank to instantly block your account. You can accomplish this without qubes but in qubes its particularly easy (and easy to get right): Every VM that has network access has it provided by another VM. Configure the networking how you like in that service VM and then pick what uses it.

When I say 'developer' above I don't mean to suggest that Qubes is particularly hard to use-- as I know significantly less technical people who use it without issue. But its non-security/privacy advantages are most significant if you're doing experimentation with the computer's configuration.

However if you're doing stuff that is Video heavy-- particularly gaming, and to a lesser extent CAD, video editing, etc. Qubes really brutally hurts video performance. It can be somewhat offset by running on higher end hardware (and then getting performance of a few year older system). Even just watching youtube videos is obvious impacted.

Similarly, it dents battery life. This is addressable via additional batteries given that now laptops are usbc powered and 100wh external batteries are readily available. But this is something of a lifestyle question.

Even before the AI-apocalypse I considered qubes to be non-negotiable on laptops-- there are just far far far too many browser RCE vulnerabilities to consider anything less for any computer that isn't a total security write-off.

Previously if I followed a link to a sus site and had my browser crash (maybe even the day before a RCE-in-the-wild was announced). I'd have some rationally justified paranoia that my whole computer might be compromised. Now, I can close the app VM (or-- better-- toss the disposable, which I try to use for most browsing) and know that even if they exploited the browser they'd have to have a VM escape of some kind too to do me any lasting damage.

The highest security stuff still ought to be on isolated hardware, of course. But using a multipurpose computer without qubes is unsafe at any speed, worse than driving without a seatbelt.


You make a very compelling argument. I've been thinking of at least trying it out before, but have been leaning towards it more and more over the years. A couple of questions though, if I could bother you with them?

How is remoting performance e.g. via VNC/RDP or particularly via Moonlight+Sunshine (intended for gaming and such)?

And how programmable is the configuration of Qubes? I like the idea of NixOS for example, but given how comparatively little activity there is in the actual nix rather than the packages, and across so few developers, I worry what would happen if someone got hit by a bus or something. But I still like programmatically configuring computers over manual monkey patches, because I have the memory of a gold fish. :p


> But using a multipurpose computer without qubes is unsafe at any speed, worse than driving without a seatbelt.

Could you elaborate on the odds of death and permanent disability occurring through use of unsecured general purpose computers? Because if not using qubes has the same risk profile as not wearing seatbelts I might feel like taking some measures


Reason 1492835 to use Qubes OS.

Also reason 35892384242892 to not use proprietary software, especially proprietary software with network access.


I mean I agree with you, but the real world just wants to get work done.

Outsource trust more carefully.

Turns out a lot of people can be mentally ill and delusional at once-- especially when there is a vector to turn their sickness into both profit and an instrument of control.

Every mass genocide in the history of humanity has followed logic like yours. People don't kill millions of humans because they want to do harm-- they do so because they think they are doing the ultimate good a good so great that is justifies the loss of life.

If AI ever does cause serious direct harm to humanity it will be because of logic like this.


What an absolutely hopeless and pessimistic world view. And you are absolutely wrong. What's caused genocide is listening to a group or control center that believes They Are The Right Ones. I said something akin to "wouldn't it be nice to see Anthropic post results of putting this into a simulation gym of redistribution of wealth? What does Astra's secret model do when it's asked that question?" Me stating it'd be nice to see an oligarch lose something for once instead of a group of civilians somehow offends you even in spirit.

So you're willing to burn the world to let them control an entire global supply of water and energy and political change and climate destruction, and won't even entertain the idea of "huh, maybe this is good enough to actually help people in aggregate already."

What a terrible way to twist my words. You're willing to pretend that millions aren't going to die because of the excesses of one person, but not to pretend what it would be like to see Robin Hood win in a digital experiment chamber.

No wonder people hate technology in 2026.

edit: what makes me more sad is seeing your credentials in technology and science. You look at the stars, read voraciously, share your science discoveries, and somehow you call my logic of "I wonder what the models say about what might work" genocidal? If you can't separate "I am want to control a populous to do what I want because I can convince them what's good for me is good for them" and "this machine is able to compute potentials that humans can't that may or may not lead to at least some version of a better world," I have no idea what hope I have.


edit: what makes me more sad is seeing your credentials in technology and science.

Nothing else has ever helped with the things you're bewailing.


Ever wonder why those CDNs are "free"?

No, but I am now! Why?

Control.

And i thought it was profit.

No, I don't actually. It's part of their lock-in and market capture like any other large digital business. The only ones that don't do it, can't.

> Anthropic and OpenAI were founded by people who wanted to use AI to do good

I think Anthropic was founded by people who wanted to control how other people get to use AI, and define doing so as the highest good possible. Much like the good intent of german's national socialists in applying the latest evolutionary science...


It's a fitting name.

Medical safety is generally unlikely to make the product less safe. AI "safety" is one of the most significant sources of potential harm from AI.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: