The weights themselves aren't stolen. The claim is that Chinese companies are using VPNs and proxies to buy massive amounts of Claude Pro and Codex subscription accounts, and then selling usage on those subscriptions as cheap white-label LLM API usage.
While selling that LLM API usage, they then capture all the prompts, outputs, and intermediate thinking the LLM does, and then sell those logs to the companies making open-weight models. The open-weight model developers then train on those logs to 'distill' a model.
Imagine making this argument with a straight face in any other industry:
"The claim is that Japanese car companies are buying Ford vehicles, and then leasing them to American consumers at cut-rate prices. In return for the cheap cars, the customers are letting the Japanese observe their driving behavior, studying how they use their F-150 and then the Japanese car companies are applying that data to design new vehicles that will directly replace Ford!"
I wasn't arguing against the practice, I was clarifying that the weights of these models are not being stolen, and explaining what these companies do to create their models.
For those wondering, the AI Max 395 has around 256GB/s of memory bandwidth, whereas this new 495 has 273GB/s. So a very modest improvement in bandwidth.
It doesn't work that way. AMD said they simply couldn't do it. It wasn't about taking some modest performance hit, it was that they couldn't make the chip function with modular memory due to signal integrity problems.
Why not put a big fat Ryzen 9 chip in it? Most people use their computer for browsing the web, playing some games, doing some spreadsheets. A standard CPU would have been more than powerful enough for that and the Desktop would be more repairable.
It's not really about performance, it's about signal integrity. AMD said that even with LPCAMM2, you just wouldn't be able to send a clean enough signal from all these different memory channels to the chip, and they insisted on a soldered design because they just couldn't make anything else work.
Technically it's not wrong to say it's about performance in the sense that if you clocked the RAM slow enough you probably could maintain signal integrity, but we're not talking some small hit to performance here, it'd probably be more like a multi-generational drop in memory bandwidth.
KeepassXC is free, open source, and supports passkeys. You can locally store your encrypted password vault wherever you like, and transport it between devices using physical media if you like (or self host your own personal storage synchronization server and sync your passkeys between devices like that).
No need to be a part of an 'ecosystem' to use a password manager or passkeys.
You can sync your vault between devices, but what's the point if the clients on those devices don't support passkeys? As far as I know, no KeePass app on Android has mature passkey support. That's not even mentioning more niche cases, like what if I want to log into a website in a browser on my TV? The cool thing about passwords is that they work on any device.
Also, remember when one of the maintainers of the passkey standard warned that KeePassXC users would get blocked by relying parties [0]? Would you allow tech companies to determine what password manager you are allowed to use?
Passkeys do *not* do that. I use 1Password to manage my passkeys and they are all synced across all my authenticated devices where I installed 1Password.
Perhaps they should’ve said platforms. Because if you wanted to migrate those passkeys off your password manager and into a different platform like Apple Pass or Google how is that accomplished?
There's a protocol, FIDO Credential Exchange Protocol (CXP) which is currently at proposed standard status. It is supported by Apple and Google and some third party password managers (1Password, Bitwarden, and Dashlane). (1Password is kind of annoying though as its CXP export only supports exporting everything. There is no way as far as I can tell to export just a single item yet).
Once 1Password supports proper single export when I make a new passkey I'll store it there and later export it to Apple.
Meanwhile I simply make two passkeys. I've only run into I think two sites that supported passkeys but would not let me make two.
On most sites making a second passkey is as simply as going to your security settings, finding the passkey settings there, hitting the "add another passkey" link, and pointing your phone at the QR code it shows, and then on those phone choosing the password manager that you did not use for the first passkey.
in the ios password app you can tap on the button to export data to other app. it will show you the list of installed apps that can import them. works with passwords and passkeys.
I moved all of them from my iphone to a selfhosted bitwarden in two minutes.
I'm surprised selfhosted services would be allowed in that list. Isn't there the "risk" that you can then extract the raw key from your selfhosted instance?
"The automated query can be based on:
* Identity information included in the application or in travel documents, such as name, date of
birth, national ID number, and/or
* the fingerprint of an individual."
Sounds like they could send requests to that computer system just based on publicly available information on a person like name and date of birth, even if the person never applied for a visa or tried to enter the US.
Well, a national ID number isnt usually publicly available info, even if it can be obtained by the US government through illicit means.
But yeah, it does sound that way, but certainly not clear cut to me what the situation is. I.e. does the agreement involve clauses about what to do if this is abused? Do we have a way to detect if theyre using this on non-travellers? Etc.
I wrote a system for a medical lab decades ago and IIRC I did actually have to change some RRN's manually. It's been a while so I'm not 100% sure, but I do think the changes were due to switching gender.
With a population of 12M and life expectancy of 80 years (give or take), probably not, as that needs ~400 newborns a day to maintain, and the birth rate is probably well below that, like in most Western countries.
Back-of-the-napkin math supports that, but baby births aren’t uniformly distributed. Well, anyway, I’m sure they thought about it. Thanks for explaining how I got my Belgian ID number!
It's not clear how it is supposed to work in detail. But it sounds like it could be implemented in a way that makes illegitimate queries possible. It doesn't sound like they want to really ensure that you can catch those.
I played with Estonia’s e-residency and they use asymmetric cryptography for everything so the ID is public but does nothing without the corresponding private key.
In most German cities (and even many villages), district heating is a rather common utility offering. There's pipes everywhere to move around the hot water to people's homes, and the water is typically heated by the waste heat from gas plants and waste heat from factories (though increasingly being supplemented with giant heat pumps).
This isnt some novel thing in Germany, selling excess heat from some energy intensive commercial proccess is pretty standard. The local district heating operator probably took care of almost all the infrastructure for them.
Wero has no such requirement. The bank that you use to interoperate with Wero might require Google Play Integrity though.
reply