<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Thu, 16 Apr 2026 23:58:45 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>TechSNAP - Episodes Tagged with “Machine Learning”</title>
    <link>https://techsnap.systems/tags/machine%20learning</link>
    <pubDate>Fri, 27 Dec 2019 00:15:00 -0800</pubDate>
    <description>Systems, Network, and Administration Podcast. Every two weeks TechSNAP covers the stories that impact those of us in the tech industry, and all of us that follow it. Every episode we dedicate a portion of the show to answer audience questions, discuss best practices, and solving your problems.
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>Systems, Network, and Administration Podcast. </itunes:subtitle>
    <itunes:author>Jupiter Broadcasting</itunes:author>
    <itunes:summary>Systems, Network, and Administration Podcast. Every two weeks TechSNAP covers the stories that impact those of us in the tech industry, and all of us that follow it. Every episode we dedicate a portion of the show to answer audience questions, discuss best practices, and solving your problems.
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/9/95197d05-40d6-4e68-8e0b-2f586ce8dc55/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:owner>
      <itunes:name>Jupiter Broadcasting</itunes:name>
      <itunes:email>chris@jupiterbroadcasting.com</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<item>
  <title>419: Nebulous Networking</title>
  <link>https://techsnap.systems/419</link>
  <guid isPermaLink="false">9a06579c-89cb-4562-a2bc-09199c6790f5</guid>
  <pubDate>Fri, 27 Dec 2019 00:15:00 -0800</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/95197d05-40d6-4e68-8e0b-2f586ce8dc55/9a06579c-89cb-4562-a2bc-09199c6790f5.mp3" length="24506008" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>From classifying cats to colorizing old photos we share our top tips and tools for starting your machine learning journey. Plus, learn why Nebula is our favorite new VPN technology, and how it can help simplify and secure your network.</itunes:subtitle>
  <itunes:duration>33:33</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/9/95197d05-40d6-4e68-8e0b-2f586ce8dc55/cover.jpg?v=4"/>
  <description>From classifying cats to colorizing old photos we share our top tips and tools for starting your machine learning journey. Plus, learn why Nebula is our favorite new VPN technology, and how it can help simplify and secure your network. 
</description>
  <itunes:keywords>VPN,Nebula, Slack, Ryan Huber, WireGuard,mesh network,mesh VPN,mesh networking,networking,security,security groups,UDP, AT,NAT busting,UDP hole-punching,cloud,system administration,firewall, lighthouse, encryption, Noise Protocol Framework, cryptography, overlay network, flat network, virtual network, DeOldify,Jupyter notebook, Machine Learning, Artificial Intelligence, neural networks, Plinko, pachinko, ImageNet,  GPU, Google Colab, Colab, DevOps, TechSNAP, Jupiter Broadcasting,</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>From classifying cats to colorizing old photos we share our top tips and tools for starting your machine learning journey. Plus, learn why Nebula is our favorite new VPN technology, and how it can help simplify and secure your network.</p><p>Links:</p><ul><li><a title="Introducing Nebula, the open source global overlay network from Slack" rel="nofollow" href="https://slack.engineering/introducing-nebula-the-open-source-global-overlay-network-from-slack-884110a5579">Introducing Nebula, the open source global overlay network from Slack</a></li><li><a title="nebula: A scalable overlay networking tool with a focus on performance, simplicity and security" rel="nofollow" href="https://github.com/slackhq/nebula">nebula: A scalable overlay networking tool with a focus on performance, simplicity and security</a></li><li><a title="Nebula VPN routes between hosts privately, flexibly, and efficiently" rel="nofollow" href="https://arstechnica.com/gadgets/2019/12/nebula-vpn-routes-between-hosts-privately-flexibly-and-efficiently/">Nebula VPN routes between hosts privately, flexibly, and efficiently</a></li><li><a title="How to set up your own Nebula mesh VPN, step by step" rel="nofollow" href="https://arstechnica.com/gadgets/2019/12/how-to-set-up-your-own-nebula-mesh-vpn-step-by-step/">How to set up your own Nebula mesh VPN, step by step</a></li><li><a title="LINUX Unplugged 329: Flat Network Truthers" rel="nofollow" href="https://linuxunplugged.com/329">LINUX Unplugged 329: Flat Network Truthers</a></li><li><a title="Cloudy with a chance of neurons: The tools that make neural networks work" rel="nofollow" href="https://arstechnica.com/gadgets/2019/12/so-you-want-to-build-a-neural-network-the-cloud-can-help-with-that/">Cloudy with a chance of neurons: The tools that make neural networks work</a></li><li><a title="Welcome To Colaboratory" rel="nofollow" href="https://colab.research.google.com/notebooks/welcome.ipynb">Welcome To Colaboratory</a></li><li><a title="ImageColorizer Notebook" rel="nofollow" href="https://colab.research.google.com/github/jantic/DeOldify/blob/master/ImageColorizerColab.ipynb">ImageColorizer Notebook</a></li><li><a title="DeOldify: A Deep Learning based project for colorizing and restoring old images (and video!)" rel="nofollow" href="https://github.com/jantic/DeOldify">DeOldify: A Deep Learning based project for colorizing and restoring old images (and video!)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>From classifying cats to colorizing old photos we share our top tips and tools for starting your machine learning journey. Plus, learn why Nebula is our favorite new VPN technology, and how it can help simplify and secure your network.</p><p>Links:</p><ul><li><a title="Introducing Nebula, the open source global overlay network from Slack" rel="nofollow" href="https://slack.engineering/introducing-nebula-the-open-source-global-overlay-network-from-slack-884110a5579">Introducing Nebula, the open source global overlay network from Slack</a></li><li><a title="nebula: A scalable overlay networking tool with a focus on performance, simplicity and security" rel="nofollow" href="https://github.com/slackhq/nebula">nebula: A scalable overlay networking tool with a focus on performance, simplicity and security</a></li><li><a title="Nebula VPN routes between hosts privately, flexibly, and efficiently" rel="nofollow" href="https://arstechnica.com/gadgets/2019/12/nebula-vpn-routes-between-hosts-privately-flexibly-and-efficiently/">Nebula VPN routes between hosts privately, flexibly, and efficiently</a></li><li><a title="How to set up your own Nebula mesh VPN, step by step" rel="nofollow" href="https://arstechnica.com/gadgets/2019/12/how-to-set-up-your-own-nebula-mesh-vpn-step-by-step/">How to set up your own Nebula mesh VPN, step by step</a></li><li><a title="LINUX Unplugged 329: Flat Network Truthers" rel="nofollow" href="https://linuxunplugged.com/329">LINUX Unplugged 329: Flat Network Truthers</a></li><li><a title="Cloudy with a chance of neurons: The tools that make neural networks work" rel="nofollow" href="https://arstechnica.com/gadgets/2019/12/so-you-want-to-build-a-neural-network-the-cloud-can-help-with-that/">Cloudy with a chance of neurons: The tools that make neural networks work</a></li><li><a title="Welcome To Colaboratory" rel="nofollow" href="https://colab.research.google.com/notebooks/welcome.ipynb">Welcome To Colaboratory</a></li><li><a title="ImageColorizer Notebook" rel="nofollow" href="https://colab.research.google.com/github/jantic/DeOldify/blob/master/ImageColorizerColab.ipynb">ImageColorizer Notebook</a></li><li><a title="DeOldify: A Deep Learning based project for colorizing and restoring old images (and video!)" rel="nofollow" href="https://github.com/jantic/DeOldify">DeOldify: A Deep Learning based project for colorizing and restoring old images (and video!)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>417: Machine Learning Magic</title>
  <link>https://techsnap.systems/417</link>
  <guid isPermaLink="false">88c620a6-0b1c-4698-aac4-ac757b632286</guid>
  <pubDate>Fri, 29 Nov 2019 00:15:00 -0800</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/95197d05-40d6-4e68-8e0b-2f586ce8dc55/88c620a6-0b1c-4698-aac4-ac757b632286.mp3" length="19052274" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>We explore the rapid adoption of machine learning, its impact on computer architecture, and how to avoid AI snake oil.</itunes:subtitle>
  <itunes:duration>26:27</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/9/95197d05-40d6-4e68-8e0b-2f586ce8dc55/cover.jpg?v=4"/>
  <description>We explore the rapid adoption of machine learning, its impact on computer architecture, and how to avoid AI snake oil.
Plus so-so SSD security, and a new wireless protocol that works best where the Wi-Fi sucks. 
</description>
  <itunes:keywords>OFNP,wireless,wifi,On-Off Noise Power Communication,LORA,WiFi 6,Ubiquiti ,Unifi,Amplifi,Amplifi Alien,mesh wifi,router,home networking,networking,wireless,ethernet,ASUS,AiMesh,OFDMA,Orthogonal Frequency-Division Multiple Access,SmallNetBuilder,Tim Higgins,SSD,storage,IEEE,encryption,cryptography,hardware encryption,BitLocker,LUKS,DBAN,hard disk,hard drive,storage,solid state,Secure Erase,ATA,security,machine learning,AI,artificial intelligence,artificial general intelligence,training,neural network,inference,drunkard's walk,Nvidia,Tesla V100,Matrix multiplication,linear algebra,supercomputers,NPU,TPU,Google,Jeffrey Dean,CPU,GPU,Chip Design,Deep Learning,Intel AVX512,Deep Learning Boost,OpenVINO,ResNet,i9-10980XE,Arvind Narayanan,AIExpert, DevOps, TechSNAP, Jupiter Broadcasting</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We explore the rapid adoption of machine learning, its impact on computer architecture, and how to avoid AI snake oil.</p>

<p>Plus so-so SSD security, and a new wireless protocol that works best where the Wi-Fi sucks.</p><p>Links:</p><ul><li><a title="“Where the Wi-Fi sucks” is where a new wireless protocol does its magic" rel="nofollow" href="https://arstechnica.com/gadgets/2019/11/where-the-wi-fi-sucks-is-where-a-new-wireless-protocol-does-its-magic/">“Where the Wi-Fi sucks” is where a new wireless protocol does its magic</a></li><li><a title="Ubiquiti’s new “Amplifi Alien” is a mesh-capable Wi-Fi 6 router" rel="nofollow" href="https://arstechnica.com/gadgets/2019/11/ubiquitis-new-amplifi-alien-is-a-mesh-capable-wi-fi-6-router/">Ubiquiti’s new “Amplifi Alien” is a mesh-capable Wi-Fi 6 router</a></li><li><a title="Self-encrypting deception: weaknesses in the encryption of solid state drives" rel="nofollow" href="https://www.ieee-security.org/TC/SP2019/papers/310.pdf">Self-encrypting deception: weaknesses in the encryption of solid state drives</a></li><li><a title="Securely erase a solid-state drive" rel="nofollow" href="https://kb.iu.edu/d/aiut">Securely erase a solid-state drive</a></li><li><a title="Solid state drive/Memory cell clearing - ArchWiki" rel="nofollow" href="https://wiki.archlinux.org/index.php/Solid_state_drive/Memory_cell_clearing">Solid state drive/Memory cell clearing - ArchWiki</a></li><li><a title="The Deep Learning Revolution and Its Implications for Computer Architecture and Chip Design" rel="nofollow" href="https://arxiv.org/abs/1911.05289">The Deep Learning Revolution and Its Implications for Computer Architecture and Chip Design</a></li><li><a title="Intel Core i9-10980XE—a step forward for AI, a step back for everything else" rel="nofollow" href="https://arstechnica.com/gadgets/2019/11/intel-core-i9-10980xe-a-step-forward-for-ai-a-step-back-for-everything-else/">Intel Core i9-10980XE—a step forward for AI, a step back for everything else</a></li><li><a title="How to recognize AI snake oil" rel="nofollow" href="https://www.cs.princeton.edu/~arvindn/talks/MIT-STS-AI-snakeoil.pdf">How to recognize AI snake oil</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We explore the rapid adoption of machine learning, its impact on computer architecture, and how to avoid AI snake oil.</p>

<p>Plus so-so SSD security, and a new wireless protocol that works best where the Wi-Fi sucks.</p><p>Links:</p><ul><li><a title="“Where the Wi-Fi sucks” is where a new wireless protocol does its magic" rel="nofollow" href="https://arstechnica.com/gadgets/2019/11/where-the-wi-fi-sucks-is-where-a-new-wireless-protocol-does-its-magic/">“Where the Wi-Fi sucks” is where a new wireless protocol does its magic</a></li><li><a title="Ubiquiti’s new “Amplifi Alien” is a mesh-capable Wi-Fi 6 router" rel="nofollow" href="https://arstechnica.com/gadgets/2019/11/ubiquitis-new-amplifi-alien-is-a-mesh-capable-wi-fi-6-router/">Ubiquiti’s new “Amplifi Alien” is a mesh-capable Wi-Fi 6 router</a></li><li><a title="Self-encrypting deception: weaknesses in the encryption of solid state drives" rel="nofollow" href="https://www.ieee-security.org/TC/SP2019/papers/310.pdf">Self-encrypting deception: weaknesses in the encryption of solid state drives</a></li><li><a title="Securely erase a solid-state drive" rel="nofollow" href="https://kb.iu.edu/d/aiut">Securely erase a solid-state drive</a></li><li><a title="Solid state drive/Memory cell clearing - ArchWiki" rel="nofollow" href="https://wiki.archlinux.org/index.php/Solid_state_drive/Memory_cell_clearing">Solid state drive/Memory cell clearing - ArchWiki</a></li><li><a title="The Deep Learning Revolution and Its Implications for Computer Architecture and Chip Design" rel="nofollow" href="https://arxiv.org/abs/1911.05289">The Deep Learning Revolution and Its Implications for Computer Architecture and Chip Design</a></li><li><a title="Intel Core i9-10980XE—a step forward for AI, a step back for everything else" rel="nofollow" href="https://arstechnica.com/gadgets/2019/11/intel-core-i9-10980xe-a-step-forward-for-ai-a-step-back-for-everything-else/">Intel Core i9-10980XE—a step forward for AI, a step back for everything else</a></li><li><a title="How to recognize AI snake oil" rel="nofollow" href="https://www.cs.princeton.edu/~arvindn/talks/MIT-STS-AI-snakeoil.pdf">How to recognize AI snake oil</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>408: Apollo's ARC</title>
  <link>https://techsnap.systems/408</link>
  <guid isPermaLink="false">2577b50c-e740-46c8-a75b-14f074cb812a</guid>
  <pubDate>Fri, 26 Jul 2019 00:15:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/95197d05-40d6-4e68-8e0b-2f586ce8dc55/2577b50c-e740-46c8-a75b-14f074cb812a.mp3" length="25365234" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>We take a look at the amazing abilities of the Apollo Guidance Computer and Jim breaks down everything you need to know about the ZFS ARC.</itunes:subtitle>
  <itunes:duration>35:13</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/9/95197d05-40d6-4e68-8e0b-2f586ce8dc55/cover.jpg?v=4"/>
  <description>We take a look at the amazing abilities of the Apollo Guidance Computer and Jim breaks down everything you need to know about the ZFS ARC. 
Plus an update on ZoL SIMD acceleration, your feedback, and an interesting new neuromorphic system from Intel. 
</description>
  <itunes:keywords>virtualization, openzfs, zfs, kvm, qemu, vhd, qcow, qcow2, ARC, memory, page cache, caching, ZFS on Linux, ZoL, SIMD, floating point, fpu, apollo, apollo anniversary, nasa, retro computing, magnetic core, core rope, AGC, apollo guidance computer, intel, dancing demon, kernel module, loihi, neuromorphic computing, text adventure, punch cards, Margaret Hamilton, neural networks, machine learning, ai, pohoiki, snapshots, sysadmin, trs-80, cloud, Chris Siebenmann,  DevOps, TechSNAP</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We take a look at the amazing abilities of the Apollo Guidance Computer and Jim breaks down everything you need to know about the ZFS ARC. </p>

<p>Plus an update on ZoL SIMD acceleration, your feedback, and an interesting new neuromorphic system from Intel.</p><p>Links:</p><ul><li><a title="ZFS On Linux Has Figured Out A Way To Restore SIMD Support On Linux 5.0+" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=ZFS-On-Linux-Restoring-SIMD">ZFS On Linux Has Figured Out A Way To Restore SIMD Support On Linux 5.0+</a> &mdash; Those running ZFS On Linux (ZoL) on post-5.0 (and pre-5.0 supported LTS releases) have seen big performance hits to the ZFS encryption performance in particular. That came due to upstream breaking an interface used by ZFS On Linux and admittedly not caring about ZoL due to it being an out-of-tree user. But now several kernel releases later, a workaround has been devised. </li><li><a title="ZFS On Linux Runs Into A Snag With Linux 5.0" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=ZFS-On-Linux-5.0-Problem">ZFS On Linux Runs Into A Snag With Linux 5.0</a></li><li><a title="NixOS Takes Action After 1.2GB/s ZFS Encryption Speed Drops To 200MB/s With Linux 5.0+" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=NixOS-Linux-5.0-ZFS-FPU-Drop">NixOS Takes Action After 1.2GB/s ZFS Encryption Speed Drops To 200MB/s With Linux 5.0+</a> &mdash;  A NixOS developer reports that the functions no longer exported by Linux 5.0+ and previously used by ZoL for AVX/AES-NI support end up dropping the ZFS data-set encryption performance to 200MB/s where as pre-5.0 kernels ran around 1.2GB/s</li><li><a title="Linux 5.0 compat: SIMD compatibility · zfsonlinux/zfs@e5db313" rel="nofollow" href="https://github.com/zfsonlinux/zfs/commit/e5db31349484e5e859c7a942eb15b98d68ce5b4d">Linux 5.0 compat: SIMD compatibility · zfsonlinux/zfs@e5db313</a> &mdash; Restore the SIMD optimization for 4.19.38 LTS, 4.14.120 LTS,
and 5.0 and newer kernels.  This is accomplished by leveraging
the fact that by definition dedicated kernel threads never need
to concern themselves with saving and restoring the user FPU state.
Therefore, they may use the FPU as long as we can guarantee user
tasks always restore their FPU state before context switching back
to user space.</li><li><a title="no SIMD acceleration · Issue #8793 · zfsonlinux/zfs" rel="nofollow" href="https://github.com/zfsonlinux/zfs/issues/8793">no SIMD acceleration · Issue #8793 · zfsonlinux/zfs</a> &mdash; 4.14.x, 4.19.x, 5.x all have no SIMD acceleration, it is like a turtle. very slow.

</li><li><a title="Chris&#39;s Wiki :: ZFS on Linux still has annoying issues with ARC size" rel="nofollow" href="https://utcc.utoronto.ca/~cks/space/blog/linux/ZFSOnLinuxARCShrinkage">Chris's Wiki :: ZFS on Linux still has annoying issues with ARC size</a> &mdash; One of the frustrating things about operating ZFS on Linux is that the ARC size is critical but ZFS's auto-tuning of it is opaque and apparently prone to malfunctions, where your ARC will mysteriously shrink drastically and then stick there.
</li><li><a title="Software woven into wire, Core rope and the Apollo Guidance Computer" rel="nofollow" href="http://www.righto.com/2019/07/software-woven-into-wire-core-rope-and.html">Software woven into wire, Core rope and the Apollo Guidance Computer</a> &mdash; One of the first computers to use integrated circuits, the Apollo Guidance Computer was lightweight enough and small enough to fly in space. An unusual feature that contributed to its small size was core rope memory, a technique of physically weaving software into high-density storage.</li><li><a title="Virtual Apollo Guidance Computer (AGC) software" rel="nofollow" href="https://github.com/virtualagc/virtualagc">Virtual Apollo Guidance Computer (AGC) software</a> &mdash; Since you are looking at this README file, you are in the "master" branch of the repository, which contains source-code transcriptions of the original Project Apollo software for the Apollo Guidance Computer (AGC) and Abort Guidance System (AGS), as well as our software for emulating the AGC, AGS, and some of their peripheral devices (such as the display-keyboard unit, or DSKY).</li><li><a title="The Underappreciated Power of the Apollo Computer - The Atlantic" rel="nofollow" href="https://www.theatlantic.com/science/archive/2019/07/underappreciated-power-apollo-computer/594121/">The Underappreciated Power of the Apollo Computer - The Atlantic</a> &mdash; Without the computers on board the Apollo spacecraft, there would have been no moon landing, no triumphant first step, no high-water mark for human space travel. A pilot could never have navigated the way to the moon, as if a spaceship were simply a more powerful airplane. The calculations required to make in-flight adjustments and the complexity of the thrust controls outstripped human capacities.</li><li><a title="Brains scale better than CPUs. So Intel is building brains | Ars Technica" rel="nofollow" href="https://arstechnica.com/science/2019/07/brains-scale-better-than-cpus-so-intel-is-building-brains/">Brains scale better than CPUs. So Intel is building brains | Ars Technica</a> &mdash; Neuromorphic engineering—building machines that mimic the function of organic brains in hardware as well as software—is becoming more and more prominent. The field has progressed rapidly, from conceptual beginnings in the late 1980s to experimental field programmable neural arrays in 2006, early memristor-powered device proposals in 2012, IBM's TrueNorth NPU in 2014, and Intel's Loihi neuromorphic processor in 2017. Yesterday, Intel broke a little more new ground with the debut of a larger-scale neuromorphic system, Pohoiki Beach, which integrates 64 of its Loihi chips.
</li><li><a title="Dancing Demon - YouTube" rel="nofollow" href="https://www.youtube.com/watch?v=6CCJFQ_bP0E">Dancing Demon - YouTube</a> &mdash; Written in 1979 by Leo Christopherson for the Radio Shack TRS-80 Model I computer. This is the best game ever for at that time.</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We take a look at the amazing abilities of the Apollo Guidance Computer and Jim breaks down everything you need to know about the ZFS ARC. </p>

<p>Plus an update on ZoL SIMD acceleration, your feedback, and an interesting new neuromorphic system from Intel.</p><p>Links:</p><ul><li><a title="ZFS On Linux Has Figured Out A Way To Restore SIMD Support On Linux 5.0+" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=ZFS-On-Linux-Restoring-SIMD">ZFS On Linux Has Figured Out A Way To Restore SIMD Support On Linux 5.0+</a> &mdash; Those running ZFS On Linux (ZoL) on post-5.0 (and pre-5.0 supported LTS releases) have seen big performance hits to the ZFS encryption performance in particular. That came due to upstream breaking an interface used by ZFS On Linux and admittedly not caring about ZoL due to it being an out-of-tree user. But now several kernel releases later, a workaround has been devised. </li><li><a title="ZFS On Linux Runs Into A Snag With Linux 5.0" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=ZFS-On-Linux-5.0-Problem">ZFS On Linux Runs Into A Snag With Linux 5.0</a></li><li><a title="NixOS Takes Action After 1.2GB/s ZFS Encryption Speed Drops To 200MB/s With Linux 5.0+" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=NixOS-Linux-5.0-ZFS-FPU-Drop">NixOS Takes Action After 1.2GB/s ZFS Encryption Speed Drops To 200MB/s With Linux 5.0+</a> &mdash;  A NixOS developer reports that the functions no longer exported by Linux 5.0+ and previously used by ZoL for AVX/AES-NI support end up dropping the ZFS data-set encryption performance to 200MB/s where as pre-5.0 kernels ran around 1.2GB/s</li><li><a title="Linux 5.0 compat: SIMD compatibility · zfsonlinux/zfs@e5db313" rel="nofollow" href="https://github.com/zfsonlinux/zfs/commit/e5db31349484e5e859c7a942eb15b98d68ce5b4d">Linux 5.0 compat: SIMD compatibility · zfsonlinux/zfs@e5db313</a> &mdash; Restore the SIMD optimization for 4.19.38 LTS, 4.14.120 LTS,
and 5.0 and newer kernels.  This is accomplished by leveraging
the fact that by definition dedicated kernel threads never need
to concern themselves with saving and restoring the user FPU state.
Therefore, they may use the FPU as long as we can guarantee user
tasks always restore their FPU state before context switching back
to user space.</li><li><a title="no SIMD acceleration · Issue #8793 · zfsonlinux/zfs" rel="nofollow" href="https://github.com/zfsonlinux/zfs/issues/8793">no SIMD acceleration · Issue #8793 · zfsonlinux/zfs</a> &mdash; 4.14.x, 4.19.x, 5.x all have no SIMD acceleration, it is like a turtle. very slow.

</li><li><a title="Chris&#39;s Wiki :: ZFS on Linux still has annoying issues with ARC size" rel="nofollow" href="https://utcc.utoronto.ca/~cks/space/blog/linux/ZFSOnLinuxARCShrinkage">Chris's Wiki :: ZFS on Linux still has annoying issues with ARC size</a> &mdash; One of the frustrating things about operating ZFS on Linux is that the ARC size is critical but ZFS's auto-tuning of it is opaque and apparently prone to malfunctions, where your ARC will mysteriously shrink drastically and then stick there.
</li><li><a title="Software woven into wire, Core rope and the Apollo Guidance Computer" rel="nofollow" href="http://www.righto.com/2019/07/software-woven-into-wire-core-rope-and.html">Software woven into wire, Core rope and the Apollo Guidance Computer</a> &mdash; One of the first computers to use integrated circuits, the Apollo Guidance Computer was lightweight enough and small enough to fly in space. An unusual feature that contributed to its small size was core rope memory, a technique of physically weaving software into high-density storage.</li><li><a title="Virtual Apollo Guidance Computer (AGC) software" rel="nofollow" href="https://github.com/virtualagc/virtualagc">Virtual Apollo Guidance Computer (AGC) software</a> &mdash; Since you are looking at this README file, you are in the "master" branch of the repository, which contains source-code transcriptions of the original Project Apollo software for the Apollo Guidance Computer (AGC) and Abort Guidance System (AGS), as well as our software for emulating the AGC, AGS, and some of their peripheral devices (such as the display-keyboard unit, or DSKY).</li><li><a title="The Underappreciated Power of the Apollo Computer - The Atlantic" rel="nofollow" href="https://www.theatlantic.com/science/archive/2019/07/underappreciated-power-apollo-computer/594121/">The Underappreciated Power of the Apollo Computer - The Atlantic</a> &mdash; Without the computers on board the Apollo spacecraft, there would have been no moon landing, no triumphant first step, no high-water mark for human space travel. A pilot could never have navigated the way to the moon, as if a spaceship were simply a more powerful airplane. The calculations required to make in-flight adjustments and the complexity of the thrust controls outstripped human capacities.</li><li><a title="Brains scale better than CPUs. So Intel is building brains | Ars Technica" rel="nofollow" href="https://arstechnica.com/science/2019/07/brains-scale-better-than-cpus-so-intel-is-building-brains/">Brains scale better than CPUs. So Intel is building brains | Ars Technica</a> &mdash; Neuromorphic engineering—building machines that mimic the function of organic brains in hardware as well as software—is becoming more and more prominent. The field has progressed rapidly, from conceptual beginnings in the late 1980s to experimental field programmable neural arrays in 2006, early memristor-powered device proposals in 2012, IBM's TrueNorth NPU in 2014, and Intel's Loihi neuromorphic processor in 2017. Yesterday, Intel broke a little more new ground with the debut of a larger-scale neuromorphic system, Pohoiki Beach, which integrates 64 of its Loihi chips.
</li><li><a title="Dancing Demon - YouTube" rel="nofollow" href="https://www.youtube.com/watch?v=6CCJFQ_bP0E">Dancing Demon - YouTube</a> &mdash; Written in 1979 by Leo Christopherson for the Radio Shack TRS-80 Model I computer. This is the best game ever for at that time.</li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>400: Supply Chain Attacks</title>
  <link>https://techsnap.systems/400</link>
  <guid isPermaLink="false">c46ae690-b668-4708-a781-8e923bc4baf4</guid>
  <pubDate>Thu, 28 Mar 2019 20:15:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/95197d05-40d6-4e68-8e0b-2f586ce8dc55/c46ae690-b668-4708-a781-8e923bc4baf4.mp3" length="23436770" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>We break down the ASUS Live Update backdoor and explore why these kinds of supply chain attacks are on the rise.</itunes:subtitle>
  <itunes:duration>32:33</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/9/95197d05-40d6-4e68-8e0b-2f586ce8dc55/cover.jpg?v=4"/>
  <description>We break down the ASUS Live Update backdoor and explore why these kinds of supply chain attacks are on the rise.
Plus an update from the linux vendor firmware service, your feedback, and more! 
</description>
  <itunes:keywords>ASUS, ASUS Malware, ShadowHammer, ASUS Live Update firmware, shadowpad, cccleaner, badusb, ssd firmware, microcontroller, reflections on trusting trust, compiler, c runtime, UEFI, BIOS, intel management engine, machine learning, unsupervised learning, malware, backdoor, command and control server, mac address, windows, linux, linux vendor firmware service, fwupd, package managers, node, npm, python, pypi, ken thompson, supply chain, supply chain attacks, gigabyte, hardware manufacturers, SysAdmin podcast, DevOps, TechSNAP</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We break down the ASUS Live Update backdoor and explore why these kinds of supply chain attacks are on the rise.</p>

<p>Plus an update from the linux vendor firmware service, your feedback, and more!</p><p>Links:</p><ul><li><a title="Joren Verspeurt on Twitter" rel="nofollow" href="https://twitter.com/JorenYuuji/status/1109040022341275648">Joren Verspeurt on Twitter</a> &mdash; The explanation you gave for unsupervised wasn't correct, that was just using a net that was trained in a supervised way. Unsupervised learning doesn't involve labels at all. A good example: clustering. You say "there are x clusters" and it learns a way of grouping similar items.</li><li><a title="Hackers Hijacked ASUS Software Updates to Install Backdoors on Thousands of Computers" rel="nofollow" href="https://motherboard.vice.com/en_us/article/pan9wn/hackers-hijacked-asus-software-updates-to-install-backdoors-on-thousands-of-computers">Hackers Hijacked ASUS Software Updates to Install Backdoors on Thousands of Computers</a> &mdash; The researchers estimate half a million Windows machines received the malicious backdoor through the ASUS update server, although the attackers appear to have been targeting only about 600 of those systems.</li><li><a title="Malicious updates for ASUS laptops" rel="nofollow" href="https://www.kaspersky.com/blog/shadow-hammer-teaser/26149/">Malicious updates for ASUS laptops</a> &mdash; A threat actor modified the ASUS Live Update Utility, which delivers BIOS, UEFI, and software updates to ASUS laptops and desktops, added a back door to the utility, and then distributed it to users through official channels.</li><li><a title="Asus Live Update Patch Now Availabile" rel="nofollow" href="https://www.theregister.co.uk/2019/03/26/asus_live_update_patch/">Asus Live Update Patch Now Availabile</a> &mdash; Asus has emitted a non-spyware-riddled version of Live Update for people to install on its notebooks, which includes extra security features to hopefully detect any future tampering.</li><li><a title="ASUS response to the recent media reports regarding ASUS Live Update tool attack by Advanced Persistent Threat (APT) groups" rel="nofollow" href="https://www.asus.com/News/hqfgVUyZ6uyAyJe1">ASUS response to the recent media reports regarding ASUS Live Update tool attack by Advanced Persistent Threat (APT) groups</a> &mdash; ASUS has also implemented a fix in the latest version (ver. 3.6.8) of the Live Update software, introduced multiple security verification mechanisms to prevent any malicious manipulation in the form of software updates or other means, and implemented an enhanced end-to-end encryption mechanism. At the same time, we have also updated and strengthened our server-to-end-user software architecture to prevent similar attacks from happening in the future.</li><li><a title="The Messy Truth About Infiltrating Computer Supply Chains" rel="nofollow" href="https://theintercept.com/2019/01/24/computer-supply-chain-attacks/">The Messy Truth About Infiltrating Computer Supply Chains</a> &mdash; The Defense Intelligence Agency believed that China’s capability at exploiting the BIOS “reflects a qualitative leap forward in exploitation that is difficult to detect”</li><li><a title="Inside the Unnerving CCleaner Supply Chain Attack" rel="nofollow" href="https://www.wired.com/story/inside-the-unnerving-supply-chain-attack-that-corrupted-ccleaner/">Inside the Unnerving CCleaner Supply Chain Attack</a> &mdash; Security researchers at Cisco Talos and Morphisec made a worst nightmare-type disclosure: the ubiquitous computer cleanup tool CCleaner had been compromised by hackers for more than a month. The software updates users were downloading from CCleaner owner Avast—a security company itself—had been tainted with a malware backdoor. The incident exposed millions of computers and reinforced the threat of so-called digital supply chain attacks, situations where trusted, widely distributed software is actually infected by malicious code.</li><li><a title="ShadowPad: How Attackers hide Backdoor in Software used by Hundreds of Large Companies around the World" rel="nofollow" href="https://www.kaspersky.com/about/press-releases/2017_shadowpad-how-attackers-hide-backdoor-in-software-used-by-hundreds-of-large-companies-around-the-world">ShadowPad: How Attackers hide Backdoor in Software used by Hundreds of Large Companies around the World</a> &mdash; ShadowPad is an example of how dangerous and wide-scale a successful supply-chain attack can be. Given the opportunities for reach and data collection it gives to the attackers, most likely it will be reproduced again and again with some other widely used software component. </li><li><a title="Gaming industry still in the scope of attackers in Asia" rel="nofollow" href="https://www.welivesecurity.com/2019/03/11/gaming-industry-scope-attackers-asia/">Gaming industry still in the scope of attackers in Asia</a> &mdash; Yet again, new supply-chain attacks recently caught the attention of ESET Researchers. This time, two games and one gaming platform application were compromised to include a backdoor.</li><li><a title="Microsoft Security Intelligence Report Volume 24 is now available" rel="nofollow" href="https://www.microsoft.com/security/blog/2019/02/28/microsoft-security-intelligence-report-volume-24-is-now-available/">Microsoft Security Intelligence Report Volume 24 is now available</a> &mdash; Software supply chain attacks are another trend that Microsoft has been tracking for several years. One supply chain tactic used by attackers is to incorporate a compromised component into a legitimate application or update package, which then is distributed to the users via the software. These attacks can be very difficult to detect because they take advantage of the trust that users have in their software vendors. The report includes several examples, including the Dofoil campaign, which illustrates how wide-reaching these types of attacks are and what we are doing to prevent and respond to them.</li><li><a title="Microsoft Security Intelligence Report Volume 24" rel="nofollow" href="https://clouddamcdnprodep.azureedge.net/gdc/gdcVAOQd7/original">Microsoft Security Intelligence Report Volume 24</a></li><li><a title="Supply Chain Attacks Spiked 78 Percent in 2018" rel="nofollow" href="https://www.nextgov.com/cybersecurity/2019/02/supply-chain-attacks-spiked-78-percent-2018-cyber-researchers-found/154996/">Supply Chain Attacks Spiked 78 Percent in 2018</a></li><li><a title="Supply Chain Security: A Talk by Bunnie Huang" rel="nofollow" href="https://www.bunniestudios.com/blog/?p=5519">Supply Chain Security: A Talk by Bunnie Huang</a> &mdash; I recently gave an invited talk about supply chain security at BlueHat IL 2019. I was a bit surprised at the level of interest it received, so I thought I’d share it here for people who might have missed it.</li><li><a title="Attack inception: Compromised supply chain within a supply chain poses new risk" rel="nofollow" href="https://www.microsoft.com/security/blog/2018/07/26/attack-inception-compromised-supply-chain-within-a-supply-chain-poses-new-risks/">Attack inception: Compromised supply chain within a supply chain poses new risk</a> &mdash; The plot twist: The app vendor’s systems were unaffected. The compromise was traceable instead to a second software vendor that hosted additional packages used by the app during installation. This turned out be an interesting and unique case of an attack involving “the supply chain of the supply chain”.</li><li><a title="Supply Chain Attacks and Secure Software Updates" rel="nofollow" href="https://paragonie.com/blog/2017/09/supply-chain-attacks-and-secure-software-updates">Supply Chain Attacks and Secure Software Updates</a> &mdash; In general, a supply chain attack involves first hacking a trusted third party who provides a product or service to your target, and then using your newly acquired, privileged position to compromise your intended target.</li><li><a title="Bad USB, Very Bad USB" rel="nofollow" href="https://lmgsecurity.com/bad-usb-very-bad-usb/">Bad USB, Very Bad USB</a> &mdash; The best defense for this type of attack is to only use devices that do not have reprogrammable firmware. Outside of this, it is important to only use USB drives that you trust completely, because after plugging in an untrusted device, you will never know if there is an invisible threat running on your computer.</li><li><a title="Reflections on Trusting Trust by Ken Thompson" rel="nofollow" href="https://dl.acm.org/citation.cfm?id=358210">Reflections on Trusting Trust by Ken Thompson</a></li><li><a title="LVFS Project Announcement - The Linux Foundation" rel="nofollow" href="https://www.linuxfoundation.org/blog/2019/03/lvfs-project-announcement/">LVFS Project Announcement - The Linux Foundation</a> &mdash; The Linux Foundation welcomes the Linux Vendor Firmware Service (LVFS) as a new project. LVFS is a secure website that allows hardware vendors to upload firmware updates. It’s used by all major Linux distributions to provide metadata for clients, such as fwupdmgr, GNOME Software and KDE Discover.</li><li><a title="LVFS: Vendor Status" rel="nofollow" href="https://fwupd.org/vendorlist">LVFS: Vendor Status</a></li><li><a title="Two new supply-chain attacks come to light in less than a week" rel="nofollow" href="https://arstechnica.com/information-technology/2018/10/two-new-supply-chain-attacks-come-to-light-in-less-than-a-week/">Two new supply-chain attacks come to light in less than a week</a> &mdash; Called “Colourama,” the package looked similar to Colorama, which is one of the top-20 most-downloaded legitimate modules in the Python repository. The doppelgänger Colourama package contained most of the legitimate functions of the legitimate module, with one significant difference: Colourama added code that, when run on Windows servers, installed a Visual Basic script.</li><li><a title="Malicious code found in npm package event-stream downloaded 8 million times in the past 2.5 months" rel="nofollow" href="https://snyk.io/blog/malicious-code-found-in-npm-package-event-stream/">Malicious code found in npm package event-stream downloaded 8 million times in the past 2.5 months</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We break down the ASUS Live Update backdoor and explore why these kinds of supply chain attacks are on the rise.</p>

<p>Plus an update from the linux vendor firmware service, your feedback, and more!</p><p>Links:</p><ul><li><a title="Joren Verspeurt on Twitter" rel="nofollow" href="https://twitter.com/JorenYuuji/status/1109040022341275648">Joren Verspeurt on Twitter</a> &mdash; The explanation you gave for unsupervised wasn't correct, that was just using a net that was trained in a supervised way. Unsupervised learning doesn't involve labels at all. A good example: clustering. You say "there are x clusters" and it learns a way of grouping similar items.</li><li><a title="Hackers Hijacked ASUS Software Updates to Install Backdoors on Thousands of Computers" rel="nofollow" href="https://motherboard.vice.com/en_us/article/pan9wn/hackers-hijacked-asus-software-updates-to-install-backdoors-on-thousands-of-computers">Hackers Hijacked ASUS Software Updates to Install Backdoors on Thousands of Computers</a> &mdash; The researchers estimate half a million Windows machines received the malicious backdoor through the ASUS update server, although the attackers appear to have been targeting only about 600 of those systems.</li><li><a title="Malicious updates for ASUS laptops" rel="nofollow" href="https://www.kaspersky.com/blog/shadow-hammer-teaser/26149/">Malicious updates for ASUS laptops</a> &mdash; A threat actor modified the ASUS Live Update Utility, which delivers BIOS, UEFI, and software updates to ASUS laptops and desktops, added a back door to the utility, and then distributed it to users through official channels.</li><li><a title="Asus Live Update Patch Now Availabile" rel="nofollow" href="https://www.theregister.co.uk/2019/03/26/asus_live_update_patch/">Asus Live Update Patch Now Availabile</a> &mdash; Asus has emitted a non-spyware-riddled version of Live Update for people to install on its notebooks, which includes extra security features to hopefully detect any future tampering.</li><li><a title="ASUS response to the recent media reports regarding ASUS Live Update tool attack by Advanced Persistent Threat (APT) groups" rel="nofollow" href="https://www.asus.com/News/hqfgVUyZ6uyAyJe1">ASUS response to the recent media reports regarding ASUS Live Update tool attack by Advanced Persistent Threat (APT) groups</a> &mdash; ASUS has also implemented a fix in the latest version (ver. 3.6.8) of the Live Update software, introduced multiple security verification mechanisms to prevent any malicious manipulation in the form of software updates or other means, and implemented an enhanced end-to-end encryption mechanism. At the same time, we have also updated and strengthened our server-to-end-user software architecture to prevent similar attacks from happening in the future.</li><li><a title="The Messy Truth About Infiltrating Computer Supply Chains" rel="nofollow" href="https://theintercept.com/2019/01/24/computer-supply-chain-attacks/">The Messy Truth About Infiltrating Computer Supply Chains</a> &mdash; The Defense Intelligence Agency believed that China’s capability at exploiting the BIOS “reflects a qualitative leap forward in exploitation that is difficult to detect”</li><li><a title="Inside the Unnerving CCleaner Supply Chain Attack" rel="nofollow" href="https://www.wired.com/story/inside-the-unnerving-supply-chain-attack-that-corrupted-ccleaner/">Inside the Unnerving CCleaner Supply Chain Attack</a> &mdash; Security researchers at Cisco Talos and Morphisec made a worst nightmare-type disclosure: the ubiquitous computer cleanup tool CCleaner had been compromised by hackers for more than a month. The software updates users were downloading from CCleaner owner Avast—a security company itself—had been tainted with a malware backdoor. The incident exposed millions of computers and reinforced the threat of so-called digital supply chain attacks, situations where trusted, widely distributed software is actually infected by malicious code.</li><li><a title="ShadowPad: How Attackers hide Backdoor in Software used by Hundreds of Large Companies around the World" rel="nofollow" href="https://www.kaspersky.com/about/press-releases/2017_shadowpad-how-attackers-hide-backdoor-in-software-used-by-hundreds-of-large-companies-around-the-world">ShadowPad: How Attackers hide Backdoor in Software used by Hundreds of Large Companies around the World</a> &mdash; ShadowPad is an example of how dangerous and wide-scale a successful supply-chain attack can be. Given the opportunities for reach and data collection it gives to the attackers, most likely it will be reproduced again and again with some other widely used software component. </li><li><a title="Gaming industry still in the scope of attackers in Asia" rel="nofollow" href="https://www.welivesecurity.com/2019/03/11/gaming-industry-scope-attackers-asia/">Gaming industry still in the scope of attackers in Asia</a> &mdash; Yet again, new supply-chain attacks recently caught the attention of ESET Researchers. This time, two games and one gaming platform application were compromised to include a backdoor.</li><li><a title="Microsoft Security Intelligence Report Volume 24 is now available" rel="nofollow" href="https://www.microsoft.com/security/blog/2019/02/28/microsoft-security-intelligence-report-volume-24-is-now-available/">Microsoft Security Intelligence Report Volume 24 is now available</a> &mdash; Software supply chain attacks are another trend that Microsoft has been tracking for several years. One supply chain tactic used by attackers is to incorporate a compromised component into a legitimate application or update package, which then is distributed to the users via the software. These attacks can be very difficult to detect because they take advantage of the trust that users have in their software vendors. The report includes several examples, including the Dofoil campaign, which illustrates how wide-reaching these types of attacks are and what we are doing to prevent and respond to them.</li><li><a title="Microsoft Security Intelligence Report Volume 24" rel="nofollow" href="https://clouddamcdnprodep.azureedge.net/gdc/gdcVAOQd7/original">Microsoft Security Intelligence Report Volume 24</a></li><li><a title="Supply Chain Attacks Spiked 78 Percent in 2018" rel="nofollow" href="https://www.nextgov.com/cybersecurity/2019/02/supply-chain-attacks-spiked-78-percent-2018-cyber-researchers-found/154996/">Supply Chain Attacks Spiked 78 Percent in 2018</a></li><li><a title="Supply Chain Security: A Talk by Bunnie Huang" rel="nofollow" href="https://www.bunniestudios.com/blog/?p=5519">Supply Chain Security: A Talk by Bunnie Huang</a> &mdash; I recently gave an invited talk about supply chain security at BlueHat IL 2019. I was a bit surprised at the level of interest it received, so I thought I’d share it here for people who might have missed it.</li><li><a title="Attack inception: Compromised supply chain within a supply chain poses new risk" rel="nofollow" href="https://www.microsoft.com/security/blog/2018/07/26/attack-inception-compromised-supply-chain-within-a-supply-chain-poses-new-risks/">Attack inception: Compromised supply chain within a supply chain poses new risk</a> &mdash; The plot twist: The app vendor’s systems were unaffected. The compromise was traceable instead to a second software vendor that hosted additional packages used by the app during installation. This turned out be an interesting and unique case of an attack involving “the supply chain of the supply chain”.</li><li><a title="Supply Chain Attacks and Secure Software Updates" rel="nofollow" href="https://paragonie.com/blog/2017/09/supply-chain-attacks-and-secure-software-updates">Supply Chain Attacks and Secure Software Updates</a> &mdash; In general, a supply chain attack involves first hacking a trusted third party who provides a product or service to your target, and then using your newly acquired, privileged position to compromise your intended target.</li><li><a title="Bad USB, Very Bad USB" rel="nofollow" href="https://lmgsecurity.com/bad-usb-very-bad-usb/">Bad USB, Very Bad USB</a> &mdash; The best defense for this type of attack is to only use devices that do not have reprogrammable firmware. Outside of this, it is important to only use USB drives that you trust completely, because after plugging in an untrusted device, you will never know if there is an invisible threat running on your computer.</li><li><a title="Reflections on Trusting Trust by Ken Thompson" rel="nofollow" href="https://dl.acm.org/citation.cfm?id=358210">Reflections on Trusting Trust by Ken Thompson</a></li><li><a title="LVFS Project Announcement - The Linux Foundation" rel="nofollow" href="https://www.linuxfoundation.org/blog/2019/03/lvfs-project-announcement/">LVFS Project Announcement - The Linux Foundation</a> &mdash; The Linux Foundation welcomes the Linux Vendor Firmware Service (LVFS) as a new project. LVFS is a secure website that allows hardware vendors to upload firmware updates. It’s used by all major Linux distributions to provide metadata for clients, such as fwupdmgr, GNOME Software and KDE Discover.</li><li><a title="LVFS: Vendor Status" rel="nofollow" href="https://fwupd.org/vendorlist">LVFS: Vendor Status</a></li><li><a title="Two new supply-chain attacks come to light in less than a week" rel="nofollow" href="https://arstechnica.com/information-technology/2018/10/two-new-supply-chain-attacks-come-to-light-in-less-than-a-week/">Two new supply-chain attacks come to light in less than a week</a> &mdash; Called “Colourama,” the package looked similar to Colorama, which is one of the top-20 most-downloaded legitimate modules in the Python repository. The doppelgänger Colourama package contained most of the legitimate functions of the legitimate module, with one significant difference: Colourama added code that, when run on Windows servers, installed a Visual Basic script.</li><li><a title="Malicious code found in npm package event-stream downloaded 8 million times in the past 2.5 months" rel="nofollow" href="https://snyk.io/blog/malicious-code-found-in-npm-package-event-stream/">Malicious code found in npm package event-stream downloaded 8 million times in the past 2.5 months</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>399: Ethics in AI</title>
  <link>https://techsnap.systems/399</link>
  <guid isPermaLink="false">6a9e036e-abe5-4b0c-b727-2d3dab34ce1d</guid>
  <pubDate>Fri, 15 Mar 2019 19:30:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/95197d05-40d6-4e68-8e0b-2f586ce8dc55/6a9e036e-abe5-4b0c-b727-2d3dab34ce1d.mp3" length="27942893" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>Machine learning promises to change many industries, but with these changes come dangerous new risks. Join Jim and Wes as they explore some of the surprising ways bias can creep in and the serious consequences of ignoring these problems.</itunes:subtitle>
  <itunes:duration>38:48</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/9/95197d05-40d6-4e68-8e0b-2f586ce8dc55/cover.jpg?v=4"/>
  <description>Machine learning promises to change many industries, but with these changes come dangerous new risks. Join Jim and Wes as they explore some of the surprising ways bias can creep in and the serious consequences of ignoring these problems. 
</description>
  <itunes:keywords>machine learning, AI, expert systems, supervised learning, unsupervised learning, neural networks, bias, racism, zo, tay, reinforcement learning, python, algorithms, programming, data, privacy, server builds, plaintext offenders, CivicPlus, passwords, computer vision, natural language processing, classification, GloVe, word2vec, scikit-learn, Robyn Speer, ConceptNet, SysAdmin podcast, DevOps, TechSNAP, chatbot</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Machine learning promises to change many industries, but with these changes come dangerous new risks. Join Jim and Wes as they explore some of the surprising ways bias can creep in and the serious consequences of ignoring these problems.</p><p>Links:</p><ul><li><a title="Microsoft’s neo-Nazi sexbot was a great lesson for makers of AI assistants" rel="nofollow" href="https://www.technologyreview.com/s/610634/microsofts-neo-nazi-sexbot-was-a-great-lesson-for-makers-of-ai-assistants/">Microsoft’s neo-Nazi sexbot was a great lesson for makers of AI assistants</a> &mdash; What started out as an entertaining social experiment—get regular people to talk to a chatbot so it could learn while they, hopefully, had fun—became a nightmare for Tay’s creators. Users soon figured out how to make Tay say awful things. Microsoft took the chatbot offline after less than a day.</li><li><a title="Microsoft&#39;s Zo chatbot is a politically correct version of her sister Tay—except she’s much, much worse" rel="nofollow" href="https://qz.com/1340990/microsofts-politically-correct-chat-bot-is-even-worse-than-its-racist-one/">Microsoft's Zo chatbot is a politically correct version of her sister Tay—except she’s much, much worse</a> &mdash; A few months after Tay’s disastrous debut, Microsoft quietly released Zo, a second English-language chatbot available on Messenger, Kik, Skype, Twitter, and Groupme.</li><li><a title="How to make a racist AI without really trying | ConceptNet blog" rel="nofollow" href="http://blog.conceptnet.io/posts/2017/how-to-make-a-racist-ai-without-really-trying/">How to make a racist AI without really trying | ConceptNet blog</a> &mdash; Some people expect that fighting algorithmic racism is going to come with some sort of trade-off. There’s no trade-off here. You can have data that’s better and less racist. You can have data that’s better because it’s less racist. There was never anything “accurate” about the overt racism that word2vec and GloVe learned.</li><li><a title="Microsoft warned investors that biased or flawed AI could hurt the company’s image" rel="nofollow" href="https://qz.com/1542377/microsoft-warned-investors-that-biased-or-flawed-ai-could-hurt-the-companys-image/">Microsoft warned investors that biased or flawed AI could hurt the company’s image</a> &mdash; Notably, this addition comes after a research paper by MIT Media Lab graduate researcher Joy Buolamwini showed in February 2018 that Microsoft’s facial recognition algorithm’s was less accurate for women and people of color. In response, Microsoft updated its facial recognition models, and wrote a blog post about how it was addressing bias in its software.</li><li><a title="AI bias: It is the responsibility of humans to ensure fairness" rel="nofollow" href="https://www.information-age.com/ai-bias-123479217/">AI bias: It is the responsibility of humans to ensure fairness</a> &mdash; Amazon recently pulled the plug on its experimental AI-powered recruitment engine when it was discovered that the machine learning technology behind it was exhibiting bias against female applicants.</li><li><a title="California Police Using AI Program That Tells Them Where to Patrol, Critics Say It May Just Reinforce Racial Bias" rel="nofollow" href="https://www.newsweek.com/california-police-artificial-intelligence-predictive-policing-predpol-santa-1358508">California Police Using AI Program That Tells Them Where to Patrol, Critics Say It May Just Reinforce Racial Bias</a> &mdash; “The potential for bias to creep into the deployment of the tools is enormous. Simply put, the devil is in the data,” Vincent Southerland, executive director of the Center on Race, Inequality, and the Law at NYU School of Law, wrote for the American Civil Liberties Union last year.

</li><li><a title="A.I. Could Worsen Health Disparities" rel="nofollow" href="https://www.nytimes.com/2019/01/31/opinion/ai-bias-healthcare.html">A.I. Could Worsen Health Disparities</a> &mdash; A recent study found that some facial recognition programs incorrectly classify less than 1 percent of light-skinned men but more than one-third of dark-skinned women. What happens when we rely on such algorithms to diagnose melanoma on light versus dark skin?</li><li><a title="Responsible AI Practices" rel="nofollow" href="https://ai.google/education/responsible-ai-practices">Responsible AI Practices</a> &mdash; These questions are far from solved, and in fact are active areas of research and development. Google is committed to making progress in the responsible development of AI and to sharing knowledge, research, tools, datasets, and other resources with the larger community. Below we share some of our current work and recommended practices.</li><li><a title="The Ars Technica System Guide, Winter 2019: The one about the servers" rel="nofollow" href="https://arstechnica.com/gadgets/2019/03/the-ars-technica-system-guide-winter-2019-the-one-about-the-servers/">The Ars Technica System Guide, Winter 2019: The one about the servers</a> &mdash; The Winter 2019 Ars System Guide has returned to its roots: showing readers three real-world system builds we like at this precise moment in time. Instead of general performance desktops, this time around we're going to focus specifically on building some servers.</li><li><a title="Introduction to Python Development at Linux Academy" rel="nofollow" href="https://linuxacademy.com/devops/training/course/name/intro-to-python-development?utm_source=social&amp;utm_medium=twitter&amp;utm_campaign=2019_aprilcourselaunch">Introduction to Python Development at Linux Academy</a> &mdash; This course is designed to teach you how to program using Python. We'll cover the building blocks of the language, programming design fundamentals, how to use the standard library, third-party packages, and how to create Python projects. In the end, you should have a grasp of how to program.</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Machine learning promises to change many industries, but with these changes come dangerous new risks. Join Jim and Wes as they explore some of the surprising ways bias can creep in and the serious consequences of ignoring these problems.</p><p>Links:</p><ul><li><a title="Microsoft’s neo-Nazi sexbot was a great lesson for makers of AI assistants" rel="nofollow" href="https://www.technologyreview.com/s/610634/microsofts-neo-nazi-sexbot-was-a-great-lesson-for-makers-of-ai-assistants/">Microsoft’s neo-Nazi sexbot was a great lesson for makers of AI assistants</a> &mdash; What started out as an entertaining social experiment—get regular people to talk to a chatbot so it could learn while they, hopefully, had fun—became a nightmare for Tay’s creators. Users soon figured out how to make Tay say awful things. Microsoft took the chatbot offline after less than a day.</li><li><a title="Microsoft&#39;s Zo chatbot is a politically correct version of her sister Tay—except she’s much, much worse" rel="nofollow" href="https://qz.com/1340990/microsofts-politically-correct-chat-bot-is-even-worse-than-its-racist-one/">Microsoft's Zo chatbot is a politically correct version of her sister Tay—except she’s much, much worse</a> &mdash; A few months after Tay’s disastrous debut, Microsoft quietly released Zo, a second English-language chatbot available on Messenger, Kik, Skype, Twitter, and Groupme.</li><li><a title="How to make a racist AI without really trying | ConceptNet blog" rel="nofollow" href="http://blog.conceptnet.io/posts/2017/how-to-make-a-racist-ai-without-really-trying/">How to make a racist AI without really trying | ConceptNet blog</a> &mdash; Some people expect that fighting algorithmic racism is going to come with some sort of trade-off. There’s no trade-off here. You can have data that’s better and less racist. You can have data that’s better because it’s less racist. There was never anything “accurate” about the overt racism that word2vec and GloVe learned.</li><li><a title="Microsoft warned investors that biased or flawed AI could hurt the company’s image" rel="nofollow" href="https://qz.com/1542377/microsoft-warned-investors-that-biased-or-flawed-ai-could-hurt-the-companys-image/">Microsoft warned investors that biased or flawed AI could hurt the company’s image</a> &mdash; Notably, this addition comes after a research paper by MIT Media Lab graduate researcher Joy Buolamwini showed in February 2018 that Microsoft’s facial recognition algorithm’s was less accurate for women and people of color. In response, Microsoft updated its facial recognition models, and wrote a blog post about how it was addressing bias in its software.</li><li><a title="AI bias: It is the responsibility of humans to ensure fairness" rel="nofollow" href="https://www.information-age.com/ai-bias-123479217/">AI bias: It is the responsibility of humans to ensure fairness</a> &mdash; Amazon recently pulled the plug on its experimental AI-powered recruitment engine when it was discovered that the machine learning technology behind it was exhibiting bias against female applicants.</li><li><a title="California Police Using AI Program That Tells Them Where to Patrol, Critics Say It May Just Reinforce Racial Bias" rel="nofollow" href="https://www.newsweek.com/california-police-artificial-intelligence-predictive-policing-predpol-santa-1358508">California Police Using AI Program That Tells Them Where to Patrol, Critics Say It May Just Reinforce Racial Bias</a> &mdash; “The potential for bias to creep into the deployment of the tools is enormous. Simply put, the devil is in the data,” Vincent Southerland, executive director of the Center on Race, Inequality, and the Law at NYU School of Law, wrote for the American Civil Liberties Union last year.

</li><li><a title="A.I. Could Worsen Health Disparities" rel="nofollow" href="https://www.nytimes.com/2019/01/31/opinion/ai-bias-healthcare.html">A.I. Could Worsen Health Disparities</a> &mdash; A recent study found that some facial recognition programs incorrectly classify less than 1 percent of light-skinned men but more than one-third of dark-skinned women. What happens when we rely on such algorithms to diagnose melanoma on light versus dark skin?</li><li><a title="Responsible AI Practices" rel="nofollow" href="https://ai.google/education/responsible-ai-practices">Responsible AI Practices</a> &mdash; These questions are far from solved, and in fact are active areas of research and development. Google is committed to making progress in the responsible development of AI and to sharing knowledge, research, tools, datasets, and other resources with the larger community. Below we share some of our current work and recommended practices.</li><li><a title="The Ars Technica System Guide, Winter 2019: The one about the servers" rel="nofollow" href="https://arstechnica.com/gadgets/2019/03/the-ars-technica-system-guide-winter-2019-the-one-about-the-servers/">The Ars Technica System Guide, Winter 2019: The one about the servers</a> &mdash; The Winter 2019 Ars System Guide has returned to its roots: showing readers three real-world system builds we like at this precise moment in time. Instead of general performance desktops, this time around we're going to focus specifically on building some servers.</li><li><a title="Introduction to Python Development at Linux Academy" rel="nofollow" href="https://linuxacademy.com/devops/training/course/name/intro-to-python-development?utm_source=social&amp;utm_medium=twitter&amp;utm_campaign=2019_aprilcourselaunch">Introduction to Python Development at Linux Academy</a> &mdash; This course is designed to teach you how to program using Python. We'll cover the building blocks of the language, programming design fundamentals, how to use the standard library, third-party packages, and how to create Python projects. In the end, you should have a grasp of how to program.</li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
