nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 1 participants
- 30631 messages
[CFP] ITC35 PhD Workshop - Travel Grants Available
by Martino Trevisan
[Apologies if you receive multiple copies of this mail]
**ITC35 PhD Workshop, co-located with the *35th International
Teletraffic Congress
“/Network Traffic Engineering in the TLC networks of the future/”*
*Wednesday, October 4, 2023, Turin*
*Website: https://itc35.itc-conference.org/*
/_*CALL FOR PRESENTATIONS*_/
/Re-thinking fundamental networking functions, their modeling and their
performance evaluation in the framework of the evolving Internet and
cellular networks, in the era of cloud and content providers, is a
target for the ITC community. The PhD workshop aims at fostering
contributions and fresh ideas from young researchers, pursuing their PhD
or having just completed their PhD. Discussion of their PhD ideas and
progress, proposition of research challenges and directions is welcome
during a dedicated workshop./
/_*TRAVEL GRANTS
*_/
The International Advisory Committee (IAC) of the ITC has decided to
offer a number of _/*travel grants*/_ (STG) that will be available to
support full-time students for attending ITC 35th. The amount of each
grant is *EUR 600* that can be used to cover student travel expenses
related to attending ITC 35th conference, such as student registration
fee, airline ticket, and hotel accommodation expenses./_*
*_/
/_*SUBMISSION INSTRUCTIONS
*_/
With respect to the presentation to be given during the Workshop, two
contribution formats are solicited:
* more *mature* research works, in the form of a long presentation (up
to 20 min each);
* short *in-progress* research work discussion, with a short
presentation (up to 10 min each).
Correspondingly, Authors proposing a long presentation are invited to
submit an *extended abstract* (max 3 pages plus references, using the
same format as for regular contributions to the main conference).
Extended abstracts will be *published* along with conference
proceedings. The best contribution will be invited for submission as a
full paper to be *fast-track* reviewed for potential publication in a
journal (to be determined).
Authors proposing a short presentation are solicited to submit a title,
list of Authors and a short abstract (up to 400 words), to help set up
the workshop program.
*Contribution should be sent in PDF format via email to:*
* *Andrea Baiocchi:* andrea.baiocchi(a)uniroma1.it
* *Lea Skorin-Kapov: *Lea.Skorin-Kapov(a)fer.hr
/_*IMPORTANT DATES*_/*
*
* <https://itc35.itc-conference.org/> *Submission deadline*: August
10, 2023 (Extended)
* *Notification of acceptance:* August 20, 2023 (Extended)
* *Submission of camera-ready extended abstracts:* September 16, 2023
(Extended)
Camera-ready versions should be uploaded as indicated with respect to
camera-ready instructions
/_*WORKSHOP CHAIRS*_/*
*
* *Andrea Baiocchi*, University of Rome, Italy
* *Lea Skorin-Kapov*, University of Zagreb, Croatia
For any questions do not hesitate to contact the conference organization
under***itc35_oc(a)tlc.polito.it*
/Best Regards,/
/*ITC 35 *//Organizing Team/
July 11, 2023
New Trans-Atlantic Data Privacy Framework largely a copy of "Privacy Shield". noyb will challenge the decision.
by Alberto Cammozzo
Conformità ottenuta tramite ingegneria semantica del termine
'proportionate'.
<https://noyb.eu/en/european-commission-gives-eu-us-data-transfers-third-rou…>
Third attempt of the European Commission to get a stable agreement on
EU-US data transfers will be likely back at the Court of Justice (CJEU)
in a matter of months. The allegedly "new" Trans-Atlantic Data Privacy
Framework is largely a copy of the failed "Privacy Shield". Despite the
European Commission's public relations efforts, there is little change
in US law or the approach taken by the EU. The fundamental problem with
FISA 702 was not addressed by the US, as the US still takes the view
that only US persons are worthy of constitutional rights.
Comparison of the change in US law since 2014:
*
o "Old" PPD-28 (2014)
<https://obamawhitehouse.archives.gov/the-press-office/2014/01/17/presidenti…>
o "New" EO 14086, replacing PPD-28 (2022)
<https://www.govinfo.gov/content/pkg/FR-2022-10-14/pdf/2022-22531.pdf>
* Comparison with previous public relation efforts:
o "Rebuilding Trust in EU-US Data Flows" and the "Umbrella" from
2013
<https://eur-lex.europa.eu/resource.html?uri=cellar:4d874331-784a-11e3-b889-…>
o Press Statement on the "Privacy Shield" from 2016
<https://ec.europa.eu/commission/presscorner/detail/en/IP_16_2461>
o Media FAQs on the "Privacy Shield" from 2016
<https://ec.europa.eu/commission/presscorner/detail/en/MEMO_16_2462>
o Single Page "Agreement in Principle" between Biden and von der
Leyen from 2022
<https://ec.europa.eu/commission/presscorner/api/files/attachment/872132/Tra…>
* European Commission Draft Adequacy Decision (December 2022)
<https://noyb.eu/en/European Commission Draft Adequacy Decision
(December 2022)>
*Background.* In 2013 Edward Snowden disclosed that the US government
used "big tech" companies and programs like "PRISM
<https://en.wikipedia.org/wiki/PRISM>" or "Upstream
<https://en.wikipedia.org/wiki/Upstream_collection>" under FISA 702
<https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act_of_1978…>
and EO 12.333 <https://en.wikipedia.org/wiki/Executive_Order_12333> to
spy on the rest of the world without the need for probable cause or
judicial approval. This was not limited to crime or terrorism, but also
included espionage on "partners" of the US. Since a 1995 EU law,
personal data may generally not be sent outside of the EU unless there
is a "essentially equivalent" protection in the destination country. The
US industry heavily relied on a European Commission Decision called
"Safe Harbor" that declared the US "essentially equivalent" in 2000. The
CJEU has annulled the Commission Decision in C-362/14 ("Schrems I")
<https://curia.europa.eu/juris/liste.jsf?nat=or&mat=or&pcs=Oor&jur=C%2CT%2CF…>
in 2015, given the vase US surveillance laws. In 2016 the European
Commission has passed largely the same Decision on EU-US Data Transfers
again, under the new name "Privacy Shield", which was invalidated by the
CJEU in C-311/18 ("Schrems II")
<https://curia.europa.eu/juris/liste.jsf?nat=or&mat=or&pcs=Oor&jur=C%2CT%2CF…>
in 2020 largely on the same grounds.
*Ursula's and Joe's "Magic" Tricks. *After the annulment of the "Privacy
Shield" the negotiations between the EU and the US saw little progress.
The US insisted that EU data would stay subject to US mass surveillance
and "non-US" persons will /not /have the same protections as US persons.
After little movement for more than 1.5 years, the US has reportedly
used the war in Ukraine to put pressure on the EU on sharing personal
data
<https://www.politico.eu/article/us-eyes-breakthrough-on-data-dispute-with-e…>.
Soon thereafter, Joe Biden and Ursula von der Leyen met on 25 March
2022. The same day, the two have suddenly "solved" what the lawyers were
unable to solve and presented an "agreement in principle
<https://ec.europa.eu/commission/presscorner/api/files/attachment/872132/Tra…>",
a one pager which in essence contained two "tricks" that should calm the
public:
* /First/, the CJEU found that*FISA 702 bulk surveillance being not
"proportionate"* within the meaning of Article 52 of the EU's
Charter of Fundamental Rights (CFR). The "new" US Executive Order
14086
<https://www.govinfo.gov/content/pkg/FR-2022-10-14/pdf/2022-22531.pdf>
(which is largely equivalent to PPD-28 from 2014
<https://obamawhitehouse.archives.gov/the-press-office/2014/01/17/presidenti…>)
would now include the word "proportionate". The "trick" here: *the
US will attribute another meaning to the word "proportionate" than
the CJEU*. EO 14086 declares FISA 702 bulk surveillance to be
"proportionate" under an undisclosed "US understanding" of the word
and contrary to the two findings by the CJEU. This way the EU and
the US were able to claim that they agreed on the same word
("proportionate") - even when there is no agreement on the meaning
of the word.
* /Secondly/, the CJEU found that *redress via the Privacy Shield
"Ombudsperson"* was not even remotely complying with Article 47
CFR**- even when the Ombudsperson was hailed by the Commission
public relations in 2016 as an "/independent/" form of "/redress in
the area of national security/"
<https://ec.europa.eu/commission/presscorner/detail/en/MEMO_16_2462>.
The "trick" on redress: the Ombudsperson mechanism was*renamed and
split to a Civil Liberties Protection Officer (CLPO) and a so-called
"Court"* (which is not a court, but a partly independent executive
body). While there are some minor improvements over the
Ombudsperson, the individual will not have any direct interaction
with the new bodies (they will have to send a complaint to an EU
data protection authority and not be heard by the US) and they will
give the exact same response as the previous "Ombudsperson". Under
EO 14086 the CLPO and the Court must in any case respond by saying:
"/Without confirming or denying that the complainant was subject to
United States signals intelligence activities, the review either did
not identify any covered violations or the Data Protection Review
Court issued a determination requiring appropriate remediation/"
(see here <https://www.federalregister.gov/d/2022-22531/p-107>). The
"judgment" of this "Court" is therefore known even before a case is
brought. There are many additional problem with the mechanism, that
will largely ensure that complaints will not even be admitted. It
seems unthinkable that the Court of Justice would accept this as
"judicial redress" under Article 47 CFR.
* /Finally/, the*US has refused to reform FISA 702* to give non-US
persons reasonable privacy protections. There is agreement on both
sides of the Atlantic that FISA 702 and EO 12.333 violate
fundamental rights under the 4th Amendment in the US and Articles 7,
8 and 47 CFR in the EU - but the US continues to insist that non-US
persons do not have constitutional rights in the US - hence a
violation of their right to privacy is not covered by the 4th Amendment.
* *FISA 702 will have to be prolonged by the end of 2023*, given that
there is a "sunset clause" in US law. This would have been the
perfect opportunity to improve US law, but given the new deal with
the EU, there will be little reason for the US to reform FISA 702.
Overall the new "Trans-Atlantic Data Privacy Framework" is a copy of
Privacy Shield (from 2016), which in turn was a copy of "Safe Harbor"
(from 2000). Given that this approach has failed twice before, there was
no legal basis for the change of course - only logic of having a deal
was political.
Max Schrems, chair of /noyb/: "/They say the definition of insanity is
doing the same thing over and over again and expecting a different
result. Just like 'Privacy Shield' the latest deal is not based on
material changes, but by political interests. Once again the current
Commission seems to think that the mess will be the next Commission's
problem. FISA 702 needs to be prolonged by the US this year, but with
the announcement of the new deal the EU has lost any power to get a
reform of FISA 702."/
*Fool me Thrice? *Already in the wake of the Snowden disclosures in
2013, the European Commission announced that it will "rebuild" trust
<https://eur-lex.europa.eu/resource.html?uri=cellar:4d874331-784a-11e3-b889-…>
and "/make Safe Harbor safer/" and come up with an "/umbrella
agreement/".**In 2016 journalists were told that
<https://ec.europa.eu/commission/presscorner/detail/en/MEMO_16_2462> the
"Privacy Shield" would mean that /"for the first time, the US has given
the EU written assurance",/ that there would be /"clear limitations,
safeguards and oversight mechanisms" /and even/"no indiscriminate mass
surveillance". /None of these claims and systems has prove stable when
put before the CJEU. In the current version of the Commission's public
relations efforts, the same (ever-repeating) claims are entertained.
Max Schrems: "/We now had 'Harbors', 'Umbrellas', 'Shields' and
'Frameworks' - but no substantial change in US surveillance law. The
press statements of today are almost a literal copy of the once from the
past 23 years. Just announcing that something is 'new', 'robust' or
'effective' does not cut it before the Court of Justice. We would need
changes in US surveillance law to make this work - and we simply don't
have it./"
*CJEU challenge ready to be filed. *Anyone who's personal data will be
transferred under the new deal can bring a challenge with Data
Protection Authorities or Courts. /noyb /has prepared various procedural
options to bring the new deal back before the CJEU. We expect the new
system to be implemented by the first companies within the next months,
which will open the path towards a challenge by a person who's data is
transferred under the new instrument. It is not unlikely that a
challenge would reach the CJEU by the end of 2023 or beginning of 2024.
The CJEU would then even have the option to suspend the "Framework" for
the time of the procedure. A final decision by the CJEU would be likely
by 2024 or 2025. No matter if such a challenge will be successful, this
will bring clarity to the "Trans-Atlantic Data Privacy Framework" within
about two years.
Max Schrems:/"We have various options for a challenge already in the
drawer, although we are sick and tired of this legal ping-pong. We
currently expect this to be back at the Court of Justice by the
beginning of next year. The Court of Justice could then even suspend the
new deal while it is reviewing the substance of it. For the sake of
legal certainty and the rule of law we will then get an answer if the
Commission's tiny improvements were enough or not./ /For the past 23
years all EU-US deals were declared invalid retroactively, making all
past data transfers by business illegal - we seem to just add another
two years of this ping-pong now./"
*EU Commission shows little care for rule of law and citizens' privacy.
*This third attempt to pass largely the same unlawful decision also
raises questions as to the larger role of the European Commission being
the guardian of the EU treaties. Instead of upholding the 'rule of law'
the Commission simply passes an invalid decision over and over again,
despite clear rulings by the CJEU. Despite large outrage after the
Snowden disclosures in the EU and repeated calls by the European
Parliament to take action, the Commission seems to give the diplomatic
relations with the US and business pressure on both side of the Atlantic
the priority over the rights of Europeans and the requirements of EU law.
Max Schrems: "/The Commission is meant to be the 'guardian of the
treaties' and the defender or the 'rule of law'. It loves that role when
it comes to Member States violating EU law. Now the Commission itself
simply ignores the Court of Justice for the third time./"
July 11, 2023
Re: [nexa] relatività della rete in azione (was Re: Rant against centralising e-mail in big-tech silos, and breaking the internet in the process)
by Antonio
> Non mi è chiara la "fonte" dell'informazione sui € 330.000 + IVA.
> Qual'e'? E' "ufficiale"?
https://www.unipi.it/index.php/gare/item/24390-procedura-negoziata-ai-sensi…
July 10, 2023
Re: [nexa] relatività della rete in azione (was Re: Rant against centralising e-mail in big-tech silos, and breaking the internet in the process)
by Damiano Verzulli
Non mi è chiara la "fonte" dell'informazione sui € 330.000 + IVA.
Qual'e'? E' "ufficiale"?
Il paragrafo (senza riferimenti al costo), invece, è un estratto del
"bilancio" (pagg. 126 e 127) che è gia' circolato in lista [1]
Bye,
DV
[1] https://server-nexa.polito.it/pipermail/nexa/2023-July/051221.html
Il 10/07/23 15:35, Antonio ha scritto:
>> il bilancio 2022 dell'UNI Pisa ...
> "Green Data Center di Ateneo
> Nel corso dell’esercizio sono stati effettuati investimenti per l’acquisto di nuovi server per l’espansione della
> infrastruttura di AI per il Calcolo Scientifico per far fronte alle richieste di risorse per GPU computing da parte
> di gruppi di dottorandi e gruppi di ricerca in ambito AI/ML e HPC con acceleratori, aumentando in modo
> significativo la potenza di calcolo, in particolare è stato acquistato un server MultiGpU DGX H100 640 GB P4387
> che ha consentito l’aumento significativo della potenza di calcolo"
>
> Un "giocattolino" da 330.000 euro + IVA, con una potenza di 32 petaFLOPS che consuma 10.2kW ... [1]
> Mi aspetto grandi cose dall'UniPI se è vero che, come ha scritto il prof. Attardi qui in lista qualche mese fa, "queste tecnologie rimangono appannaggio di pochi e rendono più difficile ad altri ricercatori di restare al passo".
>
> A.
>
> [1] https://nvdam.widen.net/s/kpwzdwrwbv/ai-for-enterprise-dgx-h100-datasheet-n…
>
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
--
Damiano Verzulli
e-mail: damiano(a)verzulli.it
---
possible?ok:while(!possible){open_mindedness++}
---
"...I realized that free software would not generate the kind of
income that was needed. Maybe in USA or Europe, you may be able
to get a well paying job as a free software developer, but not
here [in Africa]..." -- Guido Sohne - 1973-2008
http://ole.kenic.or.ke/pipermail/skunkworks/2008-April/005989.html
July 10, 2023
Re: [nexa] relatività della rete in azione (was Re: Rant against centralising e-mail in big-tech silos, and breaking the internet in the process)
by Antonio
> il bilancio 2022 dell'UNI Pisa ...
"Green Data Center di Ateneo
Nel corso dell’esercizio sono stati effettuati investimenti per l’acquisto di nuovi server per l’espansione della
infrastruttura di AI per il Calcolo Scientifico per far fronte alle richieste di risorse per GPU computing da parte
di gruppi di dottorandi e gruppi di ricerca in ambito AI/ML e HPC con acceleratori, aumentando in modo
significativo la potenza di calcolo, in particolare è stato acquistato un server MultiGpU DGX H100 640 GB P4387
che ha consentito l’aumento significativo della potenza di calcolo"
Un "giocattolino" da 330.000 euro + IVA, con una potenza di 32 petaFLOPS che consuma 10.2kW ... [1]
Mi aspetto grandi cose dall'UniPI se è vero che, come ha scritto il prof. Attardi qui in lista qualche mese fa, "queste tecnologie rimangono appannaggio di pochi e rendono più difficile ad altri ricercatori di restare al passo".
A.
[1] https://nvdam.widen.net/s/kpwzdwrwbv/ai-for-enterprise-dgx-h100-datasheet-n…
July 10, 2023
Mercoledì di Nexa del 12 luglio 2023, ore 17.00 | Aperitivo insieme al MixTo, Corso Castelfidardo, 34/A
by Nexa Media
Gentilissime, gentilissimi,
Vi segnaliamo che l'incontro di *mercoledì 12 luglio*,
dedicato alla riflessione condivisa sull'anno accademico trascorso
e al brindisi per salutarci in vista della pausa estiva,
si terrà al *MixTo, in Corso Castelfidardo, 34/A*, a Torino, dalle
*17.00* in avanti.
Ricordiamo che per questo incontro non sarà prevista la modalità di
partecipazione online.
Vi chiederemmo anche la cortesia di farci sapere, tra oggi e domani, chi
vorrà partecipare,
così da segnalare al locale scelto il numero indicativo di persone presenti.
Per maggiori
informazioni:https://nexa.polito.it/mercoledi-brindisi-chiusura-anno-accademico
Cordiali saluti,
--
Anita Botta
Communication Manager
Nexa Center for Internet & Society
Politecnico di Torino – DAUIN
Corso Duca degli Abruzzi, 24 - 10129 Torino
web: https://nexa.polito.it/
mail: anita.botta(a)polito.it
tel: 011 090 7219
July 10, 2023
Facebook is the "true employer" of its content moderators in Kenya – not Sama, its outsourcing company
by Antonio
Titolo delle (buona) notizia: Huge ruling in Kenyan court threatens global model of outsourced content moderation – and says that Facebook is the "true employer" of its key safety workers
Link: https://www.foxglove.org.uk/2023/06/06/kenyan-court-ruling-outsourced-conte…
I "moderatori di contenuti" sono persone come Kauna Malgwi:
"Kauna Malgwi, 29, is among the former Sama workers whose lives are in limbo right now. A trained clinical psychologist, Malgwi worked at Sama for four years, starting in 2019. Her job involved reviewing and flagging content that violated Facebook’s guidelines. She would typically start her day at 7 a.m., sifting through thousands of posts daily, many of which contained disturbing content such as videos depicting murders, road accidents, rape, beheadings, and suicides. She earned around $600 per month. Five months after losing her job, Malgwi told Rest of World, she continues to struggle with mental health issues from the moderation work." [1]
Sama è una delle tante outsourcing company che al primo problema con l'opinione pubblica chiude (o cambia committente) e licenzia tutti.
Altri riferimenti alla "Content Moderators Union" qui [2][3].
Antonio
[1] https://restofworld.org/2023/meta-content-moderators-kenya-fired-unionize/
[2] https://africasolutionsmediahub.org/2023/05/01/workers-at-facebook-tiktok-a…
[3] https://superrr.net/2023/05/10/Report-Content-Moderators-Summit-Kenya.html
July 10, 2023
The AI Dividend: a _modest_ proposal by Bruce Schneier and Barath Raghavan
by 380°
Buongiorno,
«Aò: "Big Data is the new oil"; perché nun famo come 'aamo fatto pe'
l'Alaska?!?»
https://www.schneier.com/blog/archives/2023/07/the-ai-dividend.html
«The AI Dividend»
aka
«Artificial Intelligence Can’t Work Without Our Data - We should all be paid for it»
Date: 2023.06.29
--8<---------------cut here---------------start------------->8---
For four decades, Alaskans have opened their mailboxes to find checks
waiting for them, their cut of the black gold beneath their feet. This
is Alaska’s Permanent Fund, funded by the state’s oil revenues and paid
to every Alaskan each year. We’re now in a different sort of resource
rush, with companies peddling bits instead of oil: generative AI.
Everyone is talking about these new AI technologies—like ChatGPT—and AI
companies are touting their awesome power. But they aren’t talking about
how that power comes from all of us. Without all of our writings and
photos that AI companies are using to train their models, they would
have nothing to sell. Big Tech companies are currently taking the work
of the American people, without our knowledge and consent, without
licensing it, and are pocketing the proceeds.
You are owed profits for your data that powers today’s AI, and we have a
way to make that happen. We call it the AI Dividend.
Our proposal is simple, and harkens back to the Alaskan plan. When Big
Tech companies produce output from generative AI that was trained on
public data, they would pay a tiny licensing fee, by the word or pixel
or relevant unit of data. Those fees would go into the AI Dividend
fund. Every few months, the Commerce Department would send out the
entirety of the fund, split equally, to every resident
nationwide. That’s it.
[...] The bottom line for Big Tech is that if their AI model was created
using public data, they have to pay into the fund. If you’re an
American, you get paid from the fund.
Under this plan, hobbyists and American small businesses would be exempt
from fees. Only Big Tech companies—those with substantial revenue—would
be required to pay into the fund. [...]
Using today’s numbers, here’s what it would look like. The licensing fee
could be small, starting at $0.001 per word generated by AI. A similar
type of fee would be applied to other categories of generative AI
outputs, such as images. That’s not a lot, but it adds up. Since most of
Big Tech has started integrating generative AI into products, these fees
would mean an annual dividend payment of a couple hundred dollars per
person.
The idea of paying you for your data [isn’t new], and some companies
have tried to do it themselves for users who opted in. And the idea of
the public being repaid for use of their resources goes back to well
before Alaska’s oil fund. But generative AI is different: It uses data
from all of us whether we like it or not, it’s ubiquitous, and it’s
potentially immensely valuable. It would cost Big Tech companies a
fortune to create a synthetic equivalent to our data from scratch, and
synthetic data would almost certainly result in worse output. They can’t
create good AI without us.
Our plan would apply to generative AI used in the US. It also only
issues a dividend to Americans. Other countries can create their own
versions, applying a similar fee to AI used within their borders. Just
like an American company collects VAT for services sold in Europe, but
not here, each country can independently manage their AI policy.
Don’t get us wrong; this isn’t an attempt to strangle this nascent
technology. Generative AI has interesting, valuable, and possibly
transformative uses, and this policy is aligned with that future. Even
with the fees of the AI Dividend, generative AI will be cheap and will
only get cheaper as technology improves. There are also risks—[both
every day and esoteric]—posed by AI, and the government may need to
develop policies to remedy any harms that arise.
Our plan can’t make sure there are no downsides to the development of
AI, but it would ensure that all Americans will share in the
upsides—particularly since this new technology isn’t possible without
our contribution.
This essay was written with Barath Raghavan, and [previously appeared]
on Politico.com.
[isn’t new]
<https://www.nytimes.com/interactive/2019/09/23/opinion/data-privacy-jaron-l…>
[both every day and esoteric]
<https://www.wired.com/story/large-language-model-phishing-scams/>
[previously appeared]
<https://www.politico.com/news/magazine/2023/06/29/ai-pay-americans-data-001…>
--8<---------------cut here---------------end--------------->8---
Tralasciando _ogni_ considerazione di storia più o meno contemporanea in
merito all'Alaska e gli interi USA *e* _ogni_ considerazione in merito
alla fiscalità applicata alle multinazionali...
...in rigoroso ordine di importanza:
Neanche un accenno al fatto che una grossa quantità dei dati ingollati
da quei sistemi di machine learning non sono stati prodotti da cittadini
statunitensi, molti dati addirittura sono precedenti ai primi
insediamenti dei coloni nelle americhe... ma ogni bit, ogni pixel, deve
contribuire al WAWOIF (We are Americans and We Owe It Fund)
Neanche un accenno al fatto che la _stragrande_ quantità di /quei/ dati
sono **personali** - molti di cittadini EU, raccolti in violazione del
GDPR, ma che gliè frega a loro - e sono impiegati precisamente per
profilare e schedare le persone.
Neanche un accenno ai lavoratori para-schiavizzati che sono
indispensabili per "taggare" le tonnellate di dati ingollate dai sistemi
di machine learning delle multinazionali che questa proposta vorrebbe
tassare, lavoratori che quelle stesse multinazionali remunerano con
cifre scandalose e fregandosene dei loro diritti ("non siamo noi, sono i
governi dei rispettivi paesi a doverci pensare"); quel lavoro
semplicemente non è contemplato, quel lavoratori **non esistono**. Per
non parlare della qualità di quel lavoro di "tagging".
Saluti, 380°
--
380° (Giovanni Biscuolo public alter ego)
«Noi, incompetenti come siamo,
non abbiamo alcun titolo per suggerire alcunché»
Disinformation flourishes because many people care deeply about injustice
but very few check the facts. Ask me about <https://stallmansupport.org>.
July 8, 2023
[CDT:L5] [CDT:L6] AI as Sensemaking for Public Comments
by 380°
Buongiorno,
https://www.schneier.com/blog/archives/2023/06/ai-as-sensemaking-for-public…
«AI as Sensemaking for Public Comments»
June 20, 2023 - by Bruce Schneier and Nathan Sanders
pubblicato anche qui:
https://theconversation.com/ai-could-shore-up-democracy-heres-one-way-207278
con il più "modesto" titolo
«AI could shore up democracy – here’s one way»
--8<---------------cut here---------------start------------->8---
[...]
Many groups have started demonstrating the potential [beneficial] uses
of AI for governance. A key constructive-use case for AI in democratic
processes is to serve as [discussion moderator] and [consensus builder].
To help democracy [scale better] in the face of growing, increasingly
interconnected populations—as well as the wide availability of AI
language tools that can generate reams of text at the click of a
button—the US will need to leverage AI’s capability to rapidly digest,
interpret and summarize [this content].
There are two different ways to approach the use of generative AI to
improve civic participation and governance. Each is likely to lead to
drastically different experience for public policy advocates and other
people trying to have their voice heard in a future system where AI
chatbots are both the dominant readers and writers of public comment.
For example, consider individual letters to a representative, or
comments as part of a regulatory rulemaking process. In both cases, we
the people are telling the government what we think and want.
For more than [half a century], agencies have been using human power to
read through all the comments received, and to generate summaries and
responses of their major themes. To be sure, digital technology has
helped.
In 2021, the Council of Federal Chief Data Officers [recommended
modernizing] the comment review process by implementing natural language
processing tools for removing duplicates and clustering similar comments
in processes governmentwide. These tools are simplistic by the standards
of 2023 AI. They work by assessing the semantic similarity of comments
based on metrics like word frequency (How often did you say
“personhood”?) and clustering similar comments and giving reviewers a
sense of what topic they relate to.
Think of this approach as collapsing public opinion. They take a big,
hairy mass of comments from thousands of people and condense them into a
tidy set of essential reading that generally suffices to represent the
broad themes of community feedback. This is far easier for a small
agency staff or legislative office to handle than it would be for
staffers to actually read through that many individual perspectives.
But what’s lost in this collapsing is individuality, personality, and
relationships. The reviewer of the condensed comments may miss the
personal circumstances that led so many commenters to write in with a
common point of view, and may overlook the arguments and anecdotes that
might be the most persuasive content of the testimony.
Most importantly, the reviewers may miss out on the opportunity to
recognize committed and knowledgeable advocates, whether interest groups
or individuals, who could have long-term, productive relationships with
the agency.
These drawbacks have real ramifications for the potential efficacy of
those thousands of individual messages, undermining what all those
people were doing it for. Still, practicality tips the balance toward of
some kind of summarization approach. A passionate letter of advocacy
doesn’t hold any value if regulators or legislators simply don’t have
time to read it.
There is another approach. In addition to collapsing testimony through
summarization, government staff can use modern AI techniques to explode
it. They can automatically recover and recognize a distinctive argument
from one piece of testimony that does not exist in the thousands of
other testimonies received. They can discover the kinds of constituent
stories and experiences that legislators love to repeat at hearings,
town halls and campaign events. This approach can sustain the potential
impact of individual public comment to shape legislation even as the
volumes of testimony may rise exponentially.
In computing, there is a rich history of that type of automation task in
what is called [outlier detection]. Traditional methods generally
involve finding a simple model that explains most of the data in
question, like a set of topics that well describe the vast majority of
submitted comments. But then they go a step further by isolating those
data points that fall outside the mold—comments that don’t use arguments
that fit into the neat little clusters.
State-of-the-art AI language models aren’t necessary for identifying
outliers in text document data sets, but using them could bring a
greater degree of sophistication and flexibility to this procedure. AI
language models can be tasked to identify novel perspectives within a
large body of text through prompting alone. You simply need to tell the
AI to [find them].
In the absence of that ability to extract distinctive comments,
lawmakers and regulators have no choice but to prioritize on other
factors. If there is nothing better, “[who donated the most to our
campaign]” or “[which company employs the most of my former staffers]”
become reasonable metrics for prioritizing public comments. AI can help
elected representatives do much better.
If Americans want AI to help revitalize the country’s ailing democracy,
they need to think about how to align the incentives of elected leaders
with those of individuals. Right now, as much as 90% of constituent
communications are [mass emails] organized by advocacy groups, and they
go largely ignored by staffers. People are channeling their passions
into a vast digital warehouses where algorithms box up their expressions
so they don’t have to be read. As a result, the incentive for citizens
and advocacy groups is to fill that box up to the brim, so someone will
notice it’s overflowing.
A talented, knowledgeable, engaged citizen should be able to articulate
their ideas and share their personal experiences and distinctive points
of view in a way that they can be both included with everyone else’s
comments where they contribute to summarization and recognized
individually among the other comments. An effective comment
summarization process would extricate those unique points of view from
the pile and put them into lawmakers’ hands.
--8<---------------cut here---------------end--------------->8---
[beneficial]
<https://www.nytimes.com/2023/04/05/opinion/artificial-intelligence-democrac…>
[discussion moderator]
<https://www.npr.org/2023/03/05/1161192417/a-new-ai-tool-can-moderate-your-t…>
[consensus builder] <https://arxiv.org/abs/2211.15006>
[scale better] <https://cyberscoop.com/rethinking-democracy-ai/>
[this content] <https://www.brookings.edu/research/robotic-rulemaking/>
[half a century] <https://core.ac.uk/download/pdf/144232278.pdf>
[recommended modernizing]
<https://resources.data.gov/resources/cdoc_comment_analysis/>
[outlier detection]
<https://scikit-learn.org/stable/modules/outlier_detection.html>
[find them]
<https://andrewmayneblog.wordpress.com/2021/04/18/the-gpt-3-zero-shot-approa…>
[who donated the most to our campaign]
<https://doi.org/10.1111/lsq.12266>
[which company employs the most of my former staffers]
<https://doi.org/10.1086/698931>
[mass emails] <https://www.congressfoundation.org/news/blog/1637>
--
380° (Giovanni Biscuolo public alter ego)
«Noi, incompetenti come siamo,
non abbiamo alcun titolo per suggerire alcunché»
Disinformation flourishes because many people care deeply about injustice
but very few check the facts. Ask me about <https://stallmansupport.org>.
July 8, 2023
anatomia di uno zero-day: il caso dell'ultimo baco di WebKit (Safari et al)
by 380°
Buongiorno,
grazie al DSA 5449-1 [1] ricevuto via email scopro che:
--8<---------------cut here---------------start------------->8---
The following vulnerabilities have been discovered in the WebKitGTK
web engine:
CVE-2023-32439
An anonymous researcher discovered that processing maliciously
crafted web content may lead to arbitrary code execution. Apple is
aware of a report that this issue may have been actively
exploited.
--8<---------------cut here---------------end--------------->8---
Per chi non lo sapesse WebKit è **software libero** ed è la "web engine"
(la libreria software che interpreta e visualizza il contenuto delle
pagine web) usata da moltissimi browser: Safari, quelli di iOS e iPadOS,
Gnome Web ma anche su console Playstation, Nintendo e televisori con
WebOS [2].
La notizia era già stata data sotto forma di _propaganda_ /un tanto al
chilo/ da diversi giornali "generalisti" nazionali [3] e non, senza dare
il benché minimo riferimento (nemmeno in successivi articoli di
aggiornamento, AFAIU) ai report tecnici che descrivono il problema.
Il baco riportato sopra fa parte di una serie di vulnerabilità descritte
come zero-day in questo interessante articolo di The Hacker News:
https://thehackernews.com/2023/06/zero-day-alert-apple-releases-patches.html
«Zero-Day Alert: Apple Releases Patches for Actively Exploited Flaws in
iOS, macOS, and Safari»
--8<---------------cut here---------------start------------->8---
[...]
This includes a pair of zero-days that have been weaponized in a mobile
surveillance campaign called Operation Triangulation
[https://thehackernews.com/2023/06/new-zero-click-hack-targets-ios-users.html]
that has been active since 2019. The exact threat actor behind the
activity is not known.
* CVE-2023-32434 - An integer overflow vulnerability in the Kernel that
could be exploited by a malicious app to execute arbitrary code with
kernel privileges.
* CVE-2023-32435 - A memory corruption vulnerability in WebKit that
could lead to arbitrary code execution when processing specially
crafted web content.
The iPhone maker said it's aware that the two issues "may have been
actively exploited against versions of iOS released before iOS 15.7,"
crediting Kaspersky researchers Georgy Kucherin, Leonid Bezvershenko,
and Boris Larin for reporting them.
The advisory comes as the Russian cybersecurity vendor dissected the
spyware implant used in the zero-click attack campaign targeting iOS
devices via iMessages [...]
The sophisticated implant, called TriangleDB
[https://thehackernews.com/2023/06/new-report-exposes-operation.html]
operates solely in the memory, leaving no traces of the activity
following a device reboot. It also comes with diverse data collection
and tracking capabilities.
This includes "interacting with the device's file system (including file
creation, modification, exfiltration, and removal), managing processes
(listing and termination), extracting keychain items to gather victim
credentials, and monitoring the victim's geolocation, among others."
[...] Also patched by Apple is a third zero-day CVE-2023-32439, which
has been reported anonymously and could result in arbitrary code
execution when processing malicious web content.
The actively exploited flaw, described as a type confusion issue, has
been addressed with improved checks.
--8<---------------cut here---------------end--------------->8---
La pagina dedicata al CVE-2023-3249 dal NIST [4] riporta alcuni link di
riferimento a "release notes" di aggiornamento emesse da Apple, alcune
delle quali [5] indicano che il bug sul sistema di bug tracking di
WebKit è il numero 256567:
https://bugs.webkit.org/show_bug.cgi?id=256567
«EnumeratorNextUpdateIndexAndMode and HasIndexedProperty should have
different heap location kinds»
--8<---------------cut here---------------start------------->8---
Status: RESOLVED FIXED
Alias: CVE-2023-32439
Product: WebKit
Component: JavaScriptCore (show other bugs)
Version: WebKit Nightly Build
Hardware: Unspecified Unspecified
Importance: P2 Normal
Assignee: Yijia Huang
URL:
Keywords: InRadar
Depends on:
Blocks:
Reported: 2023-05-09 18:26 PDT by Yijia Huang
Modified: 2023-06-22 08:44 PDT (History)
CC List: 2 users (show)
--8<---------------cut here---------------end--------------->8---
Il tipo di bug viene definito "type confusion" in [4] :-D
Il bug è quindi relativo al sottosistema che interpreta i Javascript (ma
dai?!?), viene classificato come di importanza normale mentre il NIS nel
CVE gli da un "base score" di 8.8 (su 10).
La descrizione del bug credo sia stata redatta per eliminare ogni
riferimento all'**anonimo** che ha segnalato il baco, strano perché di
solito queste cose "fanno curriculum" :-O
Il bug è stato risolto con il commit 52fe95e580 [6] il 10 Maggio
scorso (zero-day what?).
Tutti i nostri dispositivi sono letteralmente dei colabrodo, parlo di
quelli di cui almeno si può verificare la corrispondeza tra sorgente e
binario; il resto sono ovviamente irrimediabilmente compromessi.
É stata una svista o un sapiente hack?
Qualcuno™ lo sapeva e ha fatto finta di niente per anni?
Saluti, 380°
[1] Debian Security Advisory, non ancora pubblicato via web qui:
https://www.debian.org/security/2023/
[2] https://en.wikipedia.org/wiki/WebKit
[3] presi a caso:
Il Fatto Quotidiano: https://archive.is/HX7aL
Il Tempo: https://archive.is/2PloD
Punto Informatico:
https://web.archive.org/web/20230707111337/https://www.punto-informatico.it…
non ho avuto tempo di consultare i FAT checkers
[4] https://nvd.nist.gov/vuln/detail/CVE-2023-32439
[5] queste:
https://support.apple.com/en-us/HT213813
https://support.apple.com/en-us/HT213814
https://support.apple.com/en-us/HT213816
[6] https://github.com/WebKit/WebKit/commit/52fe95e5805c735cc1fa4d6200fcaa1912e…
--
380° (Giovanni Biscuolo public alter ego)
«Noi, incompetenti come siamo,
non abbiamo alcun titolo per suggerire alcunché»
Disinformation flourishes because many people care deeply about injustice
but very few check the facts. Ask me about <https://stallmansupport.org>.
July 7, 2023