Mix Redux

Sep. 19th, 2025 08:51 pm
billroper: (Default)
[personal profile] billroper
Gretchen and I went out and gave an extremely cruel truck test to the current mix for the "Amy & Me" album.

Mostly things are ok. I'm going to go down to the studio, make another small round of adjustments tomorrow, and see if I'm done.

Being done would be a good choice. :)

Electrical, Rain

Sep. 19th, 2025 01:46 pm
ranunculus: (Default)
[personal profile] ranunculus
In order to finish my shop dust collection setup the last cord, the one going to the actual dust collector, needed to be hooked up.  For safety I turned off the entire garage/5th wheel panel.  Then disconnected all the wires going into the garage, pulled them out of the panel and tried to pull in one set of new wires.  Tried being the operative word.   I could NOT get them through the conduit.  Partway, yes, all the way, no.  I left the mess for the night. 
This morning I went back to work.  Eventually I remembered that -somewhere- there is an old fish-tape.  Fish tapes are long, slender, flexible, metal things. They are the right combination of not very bendable, but just enough to push through corners.  The fish tape got through on the second try.  That is to say it got through all but the last 1 foot of conduit.   It came out at a box just above the electrical panel.   I pulled the wire that far and then started trying to get it through the last foot.  I couldn't use the fish tape, there was a bend that was too sharp for it to go around.  I could get the wires to 1 inch from the end, where the stubbornly caught on a tiny ledge.  Took me more than an hour to finally, finally get the end off that ledge and out.  Whew!   All the wires are now re-connected.  Unfortunately I need one tiny part, for the box in the rafters, to finish the whole job, but at least power is restored to everything else. 
It rained last night, the very outer edges of tropical storm Mario.  We got almost 2  1/10ths of an inch. Enough to damp down the dust, which is very nice.  It is still cloudy and cool today at 2pm.  Makes it feel even more like fall. 

Bad News From Alpha Centauri A…

Sep. 19th, 2025 10:21 am
james_davis_nicoll: (Default)
[personal profile] james_davis_nicoll


There's a planet in the habitable zone... but not an Earthlike planet.

Bad News From Alpha Centauri A…

Sabrena Swept Away by Karuna Riazi

Sep. 19th, 2025 10:14 am
james_davis_nicoll: (Default)
[personal profile] james_davis_nicoll


Sabrena's life is full of struggles already. The last thing she needs is an other-worldly adventure. Life is, alas, not considerate of a teen's preferences.

Sabrena Swept Away by Karuna Riazi

Surveying the Global Spyware Market

Sep. 19th, 2025 11:01 am
[syndicated profile] bruce_schneier_feed

Posted by Bruce Schneier

The Atlantic Council has published its second annual report: “Mythical Beasts: Diving into the depths of the global spyware market.”

Too much good detail to summarize, but here are two items:

First, the authors found that the number of US-based investors in spyware has notably increased in the past year, when compared with the sample size of the spyware market captured in the first Mythical Beasts project. In the first edition, the United States was the second-largest investor in the spyware market, following Israel. In that edition, twelve investors were observed to be domiciled within the United States—­whereas in this second edition, twenty new US-based investors were observed investing in the spyware industry in 2024. This indicates a significant increase of US-based investments in spyware in 2024, catapulting the United States to being the largest investor in this sample of the spyware market. This is significant in scale, as US-based investment from 2023 to 2024 largely outpaced that of other major investing countries observed in the first dataset, including Italy, Israel, and the United Kingdom. It is also significant in the disparity it points to ­the visible enforcement gap between the flow of US dollars and US policy initiatives. Despite numerous US policy actions, such as the addition of spyware vendors on the Entity List, and the broader global leadership role that the United States has played through imposing sanctions and diplomatic engagement, US investments continue to fund the very entities that US policymakers are making an effort to combat.

Second, the authors elaborated on the central role that resellers and brokers play in the spyware market, while being a notably under-researched set of actors. These entities act as intermediaries, obscuring the connections between vendors, suppliers, and buyers. Oftentimes, intermediaries connect vendors to new regional markets. Their presence in the dataset is almost assuredly underrepresented given the opaque nature of brokers and resellers, making corporate structures and jurisdictional arbitrage more complex and challenging to disentangle. While their uptick in the second edition of the Mythical Beasts project may be the result of a wider, more extensive data-collection effort, there is less reporting on resellers and brokers, and these entities are not systematically understood. As observed in the first report, the activities of these suppliers and brokers represent a critical information gap for advocates of a more effective policy rooted in national security and human rights. These discoveries help bring into sharper focus the state of the spyware market and the wider cyber-proliferation space, and reaffirm the need to research and surface these actors that otherwise undermine the transparency and accountability efforts by state and non-state actors as they relate to the spyware market.

Really good work. Read the whole thing.

Push the Button, Max!

Sep. 18th, 2025 09:34 pm
billroper: (Default)
[personal profile] billroper
The dog training lesson was canceled tonight (sadly, because the instructor was sick, which is a shame in general and more of a shame because she seems to be a really nice person). This gave me the opportunity to shoot down to the studio and touch up the mixes.

I then gave them the *briefest* of possible reviews while on the way out and back to pick up Chinese food for dinner. Two of the mixes are failures and need to be touched up again, but I know in which directions. The other 21 mixes have not failed yet. :)

Tomorrow, I will listen to the whole thing in more detail. And we'll see how many other mixes fail.
[syndicated profile] bruce_schneier_feed

Posted by Bruce Schneier

This is a nice piece of research: “Mind the Gap: Time-of-Check to Time-of-Use Vulnerabilities in LLM-Enabled Agents“.:

Abstract: Large Language Model (LLM)-enabled agents are rapidly emerging across a wide range of applications, but their deployment introduces vulnerabilities with security implications. While prior work has examined prompt-based attacks (e.g., prompt injection) and data-oriented threats (e.g., data exfiltration), time-of-check to time-of-use (TOCTOU) remain largely unexplored in this context. TOCTOU arises when an agent validates external state (e.g., a file or API response) that is later modified before use, enabling practical attacks such as malicious configuration swaps or payload injection. In this work, we present the first study of TOCTOU vulnerabilities in LLM-enabled agents. We introduce TOCTOU-Bench, a benchmark with 66 realistic user tasks designed to evaluate this class of vulnerabilities. As countermeasures, we adapt detection and mitigation techniques from systems security to this setting and propose prompt rewriting, state integrity monitoring, and tool-fusing. Our study highlights challenges unique to agentic workflows, where we achieve up to 25% detection accuracy using automated detection methods, a 3% decrease in vulnerable plan generation, and a 95% reduction in the attack window. When combining all three approaches, we reduce the TOCTOU vulnerabilities from an executed trajectory from 12% to 8%. Our findings open a new research direction at the intersection of AI safety and systems security.

Treading Water

Sep. 17th, 2025 09:06 pm
billroper: (Default)
[personal profile] billroper
The mixes for the "Amy & Me" album are almost done. The vocals are now properly adjusted, but I'm not happy with the relative levels of the fiddle and guitar vs. the vocals, so I need to go down and take another run at the songs. Unfortunately, this takes time and time has been in short supply.

On Friday and Saturday, I was going to and from Ball State for Parents Day. This was a priority interrupt. :)

Sunday, I reworked and tested the mixes, realized where some of the problems were and started experimenting with some different approaches.

Monday, I had a Windycon meeting.

Tuesday, I went back into the studio and touched up all of the mixes.

Wednesday, I tested the mixes in the car and found them wanting. Tonight, there was another Windycon meeting.

Thursday night is the dog training class, so there will be no mixing on Thursday.

I expect that I can get this cleaned up on Saturday and off to the duplicator by Monday morning.

Assuming that nothing else happens...

Extraction Zones and similar lingo

Sep. 17th, 2025 07:33 pm
selki: (Diagram)
[personal profile] selki
I mentioned Ray Nayler's phrase "extraction zones" in my last post. Here are some podcast episodes I've listened to in the last few months that have alerted me to similar evocative turns of phrase:
  • *It Could Happen Here*: Neoliberalism Part 3: Where Is Paul Volker (Dec. 2021): In part 3 of our series on Neoliberalism we look at the coup in Chile, the Volker shock, the collapse of the G77, Venezuela's failed industrialization campaign and the conversion of the Third World into debt colonies.
  • *The Outlaw Ocean*: Waves of Extraction (October 2022):  It's the podcast and episode titles that grabbed my attention, but the episode description is A trip to Gambia to learn how fishmeal is meant to slow the depletion of fish from the seas but is actually accelerating the problem.
  • *A Matter of Degrees*: The Tongass: A Way Forward for the Forest (Mar. 2023): Marina and Richard describe the boom-and-bust extractive economy of the past [in Alaska].

I do listen to some fiction and review podcasts, not only history/analysis. :-)

Water Update

Sep. 17th, 2025 09:33 am
ranunculus: (Default)
[personal profile] ranunculus
This morning the tanks were half full, which is respectable for this time of year.  However, the water at the house was still trickling out of the faucet indicating there was virtually no pressure.  I opened the faucet at the base of Tank Hill, which is about 40 vertical feet below the tanks.  The water ran out with a distinct lack of enthusiasm. Water flow was even more anemic at the faucet on the hillside.  The faucet at the garden, which is lower than the one at the base of Tank Hill, ran reasonably freely, but not the way it should have.  I got out the new hatchet and hammered open the valve for the 2 inch Fire Hose pipe.  A LOT of water poured out. The flow from the garden faucet increased.   After a minute or so I hammered closed the 2 inch valve, closed all the faucets, got a bale of hay from the Iris Barn and came back to the house.  Low and behold water comes flowing easily out of the faucets.  I'm still not entirely happy with the pressure, but further "blowing out" of the water pipes can wait till the tanks are full and the garden is watered.  For now I can at least take a shower!  My guess is that dirt has accumulated in the bottom of tank 1 and partially blocked the flow of water down the hill. This is a real problem because there is no effective AND safe way to clean the tanks.  It is possible to climb into the tanks and bucket out dirt (dirty water) but doing that requires a supplied air source.  No one installed a "cleanout" valve for the tanks so there isn't any way to drain them and clean them.  On top of all of that there is no way to isolate one tank from the others so cleaning can be done without draining everything. If I drain everything there will be no water for a couple of days while the tanks refill.  So it has been about 20 years since the tanks were cleaned last. Plenty of dirt and tiny stones get washed down from the springs despite my best efforts.   As soon as I've finished paying for the new stove I'll hire someone to help re-plumb the tanks and fix this issue.  Maybe next spring when the springs are running fast and the tanks aren't doubling as  a source for water in case of a fire. 
james_davis_nicoll: (Default)
[personal profile] james_davis_nicoll


The Central Plaza Mansion tower offers palatial 900 square foot apartments for a mere ¥35,000,000. It is a deal too good for the Kano family to turn down... although they should have.


The Graveyard Apartment by Mariko Koike

Hacking Electronic Safes

Sep. 17th, 2025 11:05 am
[syndicated profile] bruce_schneier_feed

Posted by Bruce Schneier

Vulnerabilities in electronic safes that use Securam Prologic locks:

While both their techniques represent glaring security vulnerabilities, Omo says it’s the one that exploits a feature intended as a legitimate unlock method for locksmiths that’s the more widespread and dangerous. “This attack is something where, if you had a safe with this kind of lock, I could literally pull up the code right now with no specialized hardware, nothing,” Omo says. “All of a sudden, based on our testing, it seems like people can get into almost any Securam Prologic lock in the world.”

[…]

Omo and Rowley say they informed Securam about both their safe-opening techniques in spring of last year, but have until now kept their existence secret because of legal threats from the company. “We will refer this matter to our counsel for trade libel if you choose the route of public announcement or disclosure,” a Securam representative wrote to the two researchers ahead of last year’s Defcon, where they first planned to present their research.

Only after obtaining pro bono legal representation from the Electronic Frontier Foundation’s Coders’ Rights Project did the pair decide to follow through with their plan to speak about Securam’s vulnerabilities at Defcon. Omo and Rowley say they’re even now being careful not to disclose enough technical detail to help others replicate their techniques, while still trying to offer a warning to safe owners about two different vulnerabilities that exist in many of their devices.

The company says that it plans on updating its locks by the end of the year, but have no plans to patch any locks already sold.

Water. Sigh

Sep. 16th, 2025 09:58 pm
ranunculus: (Default)
[personal profile] ranunculus
I left a hose on yesterday.  It completely drained the water tanks.  Water is only trickling out of the faucets in the house.  Tomorrow I need to go up and look at the springs to see if I can improve water flow as the tanks are filling very slowly.  Of course it is September and it hasn't really rained since early April so I should expect some slowdown. 
Went to a lovely talk about Irish Birds this evening. Was modestly inspired to consider going to the north end of Ireland someday.  

About That New Guitar

Sep. 16th, 2025 06:09 pm
billroper: (Default)
[personal profile] billroper
So last month I got a new guitar, but I couldn't talk about it much then other than to say that I had gotten it. That is because this particular model had not yet been announced.

Today, Taylor Guitars announced it. It is a Gold Label 514e Super Auditorium model with spruce top and mahogany sides.

It is a very pretty guitar. And it plays well too. :)
mrissa: (Default)
[personal profile] mrissa
 Guess what I’ve been up to? Yes! It’s a novella! It’s the story of an ex-harpy, her harpy ex-girlfriend, and some extremely opinionated weaponry. Pastries! Operettas! Complicated friendships! All in one conveniently sized volume (or file)!

Seriously, very excited, friends.


 

Spread Me by Sarah Gailey

Sep. 16th, 2025 09:09 am
james_davis_nicoll: (Default)
[personal profile] james_davis_nicoll


If not friend, why friend-shaped?

Spread Me by Sarah Gailey

February 2025

S M T W T F S
      1
2345678
9101112131415
16171819 202122
232425262728 

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Sep. 20th, 2025 11:58 am
Powered by Dreamwidth Studios