> At the time, DoorDash’s campaign contributions in the run-up to the 2025 mayoral election were considered unusually large — it made a single $1 million gift to a super PAC that, at the time, was the largest donation in the race
I was recently job searching and roughly 50% of all jobs ghosted me. Just an automated email and then... silence. And when applying via LinkedIn only ~5% of companies even opened my application.
I can believe that your company has a good reason for keeping the job up, but I also know that some job ads are black holes were no one bothers to do the bare minimum including taking the posting down. I have no idea how to differentiate one from the other.
50% is a pretty damn good response rate! I wouldn't complain about that.
It's not surprising about LinkedIn. They've made applying for jobs too easy so there's too much noise. I wouldn't bother applying for jobs there. LinkedIn is great for recruiters though - just put some effort into your profile, set it to "looking for work", and then reply to interesting recruiter spam. That's how I got my last 3 jobs.
Not a meme but rather news. The FBI has recently updated their hiring guidelines and, among other things, they've removed "bestiality" from the list of reason that automatically disqualify an applicant.
Their argument is that, for instance, people who have been coerced into bestiality against their will may want to join the FBI to prevent other people from suffering the same fate but are automatically disqualified from doing so.
For a tongue-in-cheek version you can check late night shows from last week.
> Their argument is that, for instance, people who have been coerced into bestiality against their will may want to join the FBI to prevent other people from suffering the same fate but are automatically disqualified from doing so.
Wait, that implies they equaled being forced into bestiality as being into bestiality? It's like refusing all thieves and their victims.
Yes, HuggingFace was audited by a third-party. But said third-party wrote that they had to use unreliable AI in their conclusions (page 26) because they had six days to analyse 1300 (page 70) chains of thought and 70000 messages.
> OpenAI was founded to develop safe AI.
If that were the case, then they would have followed their own report saying not to release GPT-3. Or, if they were following their own founding principles, they wouldn't have stopped releasing models due to (in their own words) the challenging market.
I believe there is a bit of hype on both sides, with the labs operating from the mindset of "never let a good crisis go waste".
It is a crisis and the risk of A(G)I is real. But almost all this while in the history of automation, we have blamed implementation of automation when things go wrong. Instead of attributing morality, intent and so many other things that we do with LLMs.
Without having to go in to the philosophical validity of these concepts applied to AI, I feel it's much more useful to focus on the implementation of automation here as well - what risks were opened, how was the env hardened, what was the observability like - how was it being observed anyway, and more.
Done poorly, that can be catastrophic enough. But that sounds mundane. And does not help the hype.
If "the server has a memory safety bug that allows a malicious client to overflow some buffer and overwrite, for instance, the contents of the cgi_bin_path variable", then why is this a data-only attack? Instill need to overflow a buffer the "traditional" way.
The boundaries are a _little bit_ vague of course. Traditional attacks transition from "data" (the buffer) to a reality where all control is handed to the attacker (ROP, traditional executable stack pivots, etc.)
The attacker controls what's executed, and stitches side-effects together to achieve the desired attack. This also starts with "data" but ends with "instructions of the attacker's choosing doing what the attacker wants".
In a data-flow attack (which _still_ has some characteristics of the former), the attacker does _not_ have the ability to pick-and-choose what gets executed, even in the final stages of their attack. They _still_ need to overflow the buffer, and put some other data in some other registers, but their attack _never_ gets to the point where they pick the next instruction.
Likely, at the end of the exploit, arbitrary code execution or privilege escalation has been unlocked. But the exploit chain itself doesn't go through a stage of arbitrary execution (either through ROP, or executable stack). That's how I like to distinguish anyway.
Perhaps this is a good use case for AI? I'm sure it's trivial to write an AI system that reads AI text and replaces AI-generated text with AI-generated, non-AI-looking text.
To quote one of my teachers, "you may read the Constitution and think it's all obvious, that it's like writing a law that says people need air to live. The problem is, if you don't explicitly write it down someone may actually try to steal the air".
I didn't need someone to tell me that FIFA is full of ads. But studies like this provide a precise, measurable target to work with.
From this article [1] published by the European Commission:
> The 3 € fee is applied per declared item, where ‘item’ means each unit of a product that is declared on a separate line. Specifically, the Commission defines "item" as one or more goods in a consignment sharing the same tariff classification, description and, where applicable, origin.
Now, the type of declaration matters [2] - if you're filling an H1 (standard customs) then you pay per item but if you're filling an H6 (postal declaration) or an H7 (Courier or low-value consignment declaration) then you pay per category. So anyone saying that it's always one or the other is, at the very least, oversimplifying.
So in theory, that would be fine as well. In reality though, the categories aren't coarse like "electronic component", they're more like "resistor, 10K, 1/4W, carbon film".
A major factor is that the companies pushing for this technology are spending significant resources into making sure your consent isn't relevant. From this article [1] about Meta and smart glasses:
> Five years ago, Facebook shut down the facial recognition system for tagging people in photos on its social network, saying it wanted to find “the right balance” for a technology that raises privacy and legal concerns. Now it wants to bring facial recognition back.
> (…) The Silicon Valley company has been conferring since early last year about how to release a feature that carries “safety and privacy risks,” according to an internal document viewed by The New York Times. (…) Meta’s internal memo said the political tumult in the United States was good timing for the feature’s release.
> “We will launch during a dynamic political environment where many civil society groups that we would expect to attack us would have their resources focused on other concerns,” according to the document from Meta’s Reality Labs, which works on hardware including smart glasses.
> We will launch during a dynamic political environment where many civil society groups that we would expect to attack us would have their resources focused on other concerns
And if there's no dynamic political environment or fitting concerns to steal focus at hand, we'll sure as hell fund their creation.
> At the time, DoorDash’s campaign contributions in the run-up to the 2025 mayoral election were considered unusually large — it made a single $1 million gift to a super PAC that, at the time, was the largest donation in the race
reply