I sympathize with the sentiment but the suggested/implied guidance to fix bugs is wrong.
The overall game is increasing costs to exploit so much that attackers give up.
Fixing 10 most obvious bugs, just very slightly increases costs, they would just a few more tokens to find another bug.
As someone said "I had infinite bugs, I fixed 1000, I still have infinite bugs".
To significantly increase exploit costs software/security has -1 years to do:
- Defense in Depth
- Sandbox everything
- Zero trust
- Canary tokens
- Split data from code (lol)
- App Whitelisting
- Reduce attack surface
- Etc.
In other words, the only path is investing heavily on the "game changers" we have already discovered... but we are too cheap/lazy/coward/incompetent to apply.
And if we feel specially brave, changing the liability laws regarding software. Open Source & Proprietary code is so crappy because no gets jailed or fined when one of its dumb decisions results in millions of people have their data stolen.
> For apps distributed via alternative app marketplaces or the web, Apple will charge a 5 percent Core Technology Commission.
Would it better a payment commission (free apps do not pay but apple takes a cut on everything) or would it better to an installment fee (pay X euros per installation but no commission cut for Apple) ?
Well everything depends on the fee/commission values but after I put the pitch fork down I was left wondering...
If you connect the dots of the earlier MCP Client/Server docs you understand that your desktop AI tool was also a MCP Server. This MCP Server provided the tools like "search files", "alter files", "open file".
It's was simpler to design/implement the AI tool if these interactions had state. When this was generalized to internet interactions this no longer made sense and was gradually cleaned up.
I think at the same time, the AI tool "protocol" to interact with the local system moved away from MCP model.
I think the copyright and license question is one of the elephants in the room that hasn't had a satisfying conclusion. It's very important to have a clear idea of this for the open source movement.
> Also they are anti EU and NATO. Lot of astroturfing here.
At the same time, that big advertising and crony politicians are fighting to impose digital ID for all internet communications... one of the strongest privacy advocates is being attacked with non-sense.
The overall game is increasing costs to exploit so much that attackers give up. Fixing 10 most obvious bugs, just very slightly increases costs, they would just a few more tokens to find another bug.
As someone said "I had infinite bugs, I fixed 1000, I still have infinite bugs".
To significantly increase exploit costs software/security has -1 years to do:
- Defense in Depth - Sandbox everything - Zero trust - Canary tokens - Split data from code (lol) - App Whitelisting - Reduce attack surface - Etc.
In other words, the only path is investing heavily on the "game changers" we have already discovered... but we are too cheap/lazy/coward/incompetent to apply.
And if we feel specially brave, changing the liability laws regarding software. Open Source & Proprietary code is so crappy because no gets jailed or fined when one of its dumb decisions results in millions of people have their data stolen.