th3raid0r

joined 11 months ago
MODERATOR OF
[–] th3raid0r@programming.dev 4 points 1 month ago (1 children)

The real kicker is that I'm fairly sure we aren't really using them at any real scale - if we do it's to demo our product within the context of AI development. So if anything, they get a lot of free press when we do that. If they're gonna throw a fit over it, I'm sure we can work with some other "AI" company (that's what they bill themselves as) that wants the free marketing. Heck, I can't imagine the anaconda ecosystem working out if they keep threatening the developers that enrich that ecosystem.

[–] th3raid0r@programming.dev 4 points 1 month ago* (last edited 1 month ago) (1 children)

Yes, I am aware.

I'm more asking if others are getting a wide spread of threatening messages across the org - even if they don't regularly use conda/anaconda.

It's like everyone glossed over "I don't use it in my job at all, and neither do my teammates" bit.

[–] th3raid0r@programming.dev 13 points 1 month ago

Send the emails to your company’s legal team. It’s not your fight.

Already did, and agreed. I also asked the legal team if they could ask Anaconda.com to stop contacting me and threatening me personally. We shall see what happens.

[–] th3raid0r@programming.dev 8 points 1 month ago

I'm not here to discuss the nuances of a startup versus medium sized company. Suffice it to say that much of the organization still views itself as a startup. Even though yes, you are right, it's a medium sized organization.

[–] th3raid0r@programming.dev 15 points 1 month ago (3 children)

Sure. I can agree that my company would be liable. But the company isn't mine. I just work here. And my team doesn't use any conda stuff at all.

Essentially, I am being personally threatened of a lawsuit even though I have no ability to make a licensing or purchase decision.

That just doesn't sit right with me.

 

As in title, my company is seeing a huge uptick in abusive messages from Anaconda.com seeking licensing revenue.

They're hitting many people across the org with legal threats - many with zero control of whether a person uses conda or not. I don't use it in my job at all, and neither do my teammates.

FWIW - we're a small-ish growing startup that just recently crossed the 200 employee line. Our product is a database often used for AI and there are many packages within the Anaconda ecosystem that are owned by us, not them. So I don't know why they'd be hounding us for licensing since the primary reason we'd use conda is to contribute to conda - not consume it.

It's starting the conversation of needing to drop conda support for future releases. If they're going to be this utterly vile, then why would we spend the effort packaging for them?

It's gotten so bad that I've made FTC complaints over this. I'm tired of the near daily threats for something I have zero control over.

If anyone else is experiencing this, I highly recommend reporting the abusive comms to the FTC here - https://reportfraud.ftc.gov/ - also forward the emails to your HR/Legal team so they know to contact the state AG.

[–] th3raid0r@programming.dev 4 points 6 months ago* (last edited 6 months ago)

TPMs can be extracted with physical access

Sure, but IIRC, they'd still need my PIN (for TPM+PIN through cryptenroll). I don't think it's possible to do TPM backed encryption without a PIN on Linux.

EDIT: Oh wait, you can... Why anyone would is beyond me though.

[–] th3raid0r@programming.dev 2 points 6 months ago* (last edited 6 months ago) (1 children)

This sounds like a lenovo machine. Or something with a similar MOK enrollment process.

I forget the exact process, but I recall needing to reset the secureboot keys in "install mode" or something, then it would allow me to perform the MOK enrollment. If secureboot is greyed out in the BIOS it is never linux's fault. That's a manufacturer issue.

Apparently, some models of Lenovo don't even enable MOK enrolment and lock it down entirely. Meaning that you'd need to sign with Microsofts keys, not your own. The only way to do this is to be a high-up microsoft employee OR use a pre-provided SHIM from the distribution.

https://wiki.archlinux.org/title/Unified_Extensible_Firmware_Interface/Secure_Boot#Using_a_signed_boot_loader

For that case, Ubuntu and Fedora are better because, per the Ubuntu documentation they do this by default.

On Ubuntu, all pre-built binaries intended to be loaded as part of the boot process, with the exception of the initrd image, are signed by Canonical's UEFI certificate, which itself is implicitly trusted by being embedded in the shim loader, itself signed by Microsoft.

Once you have secureboot working on Ubuntu or Fedora, you could likely follow these steps to enable TPM+PIN - https://wiki.archlinux.org/title/Systemd-cryptenroll#Trusted_Platform_Module

There might be some differences as far as kernel module loading and ensuring you're using the right tooling for your distro, but most importantly, the bones of the process are the same.

OH! And if you aren't getting the secureboot option in the installer UI, that could be due to booting the install media in "legacy" or "MBR" mode. Gotta ensure it's in UEFI mode.

EDIT: One more important bit, you'll need to be using the latest nvidia drivers with the nvidia-open modules. Otherwise you'll need to additionally sign your driver blobs and taint your kernel. Nvidia-Open is finally "default" as of the latest driver, but this might differ on a per-distro basis.

[–] th3raid0r@programming.dev 6 points 6 months ago

Yeah, no kidding. The same systemd that enables the very things OP is trying to enable...

systemdboot + sbctl + systemd-cryptenroll and voila. TPM backed disk encryption with a PIN or FIDO2 token.

AFAIK this should be doable in Ubuntu, it just requires some command-line-fu.

Last I heard the Fedora installer was aiming to better support this type of thing - not so sure about Ubuntu.

[–] th3raid0r@programming.dev 1 points 7 months ago

Hahah, good luck. Proton Drive is really terrible. I can't even upload a single 1GB file through the service.

[–] th3raid0r@programming.dev 6 points 7 months ago

Well, I mean, most corps trying to shoehorn AI into things are using Cloud implementations of the various "AI" solutions.

What, pay for our own datacenter? Nah.

Just import openai and add "the AI" that way. 🤦‍♂️

 

A coworker send me this fantastic piece on getting linux to boot off of google drive (and s3). Definitely a fun read!

(I'm not the author of this article)

[–] th3raid0r@programming.dev 3 points 8 months ago (1 children)

Fair, and I think I'd have gone that direction if it wasn't a slack channel where everyone was invited to, and then questioned if they decided to leave. It was also a very noisy channel where it was disrupting my work.

I didn't just throw this into some channel in which I wasn't invited or anything. I actually felt like I wasn't allowed to leave, which is why other NDs privately thanked me afterwards.

I can ignore the ignorable, but if you're going to hunt me down if I ignore it (like they were doing), then I needed to speak up in order for it to stop.

Typically I do just what you've described, just kinda ignore it.

 

Let's discuss able-ism in our industry.

For me, I mostly experience it whenever marketing has a "genius" idea that everyone should be little mini-marketers on social media. Essentially, they wanted us to make a lot more noise on social media and do cold outreach in our network. I was in no mood to exploit what little friends I have on social media. Not to mention the fact that I'm really no good at this stuff, and it's likely to backfire.

I put my foot down on that one - called the initiative ableist right in their "party" channel. And stated that if my participation was an issue, then I'd like to request non-participation as a reasonable accomodation for my autism.

Not sure that was good for my career though. Despite getting many DM's expressing thanks for standing up. I'm pretty sure higher ups will just think I'm "not a team player".

So did it work? Yes, but also there may be other consequences to my direct nature that I haven't seen yet.

 

As in description, we need art!

I'm awful at art and don't want to use DALLE/Midjourney if I can avoid it.

So yeah, if anyone has a good banner image or icon image in mind, DM me!

 

After not getting what I needed out of a "managing up" post, I decided to create this community. Essentially the problem is that often we need to solve a social problem that others might deem "trivial". And when folks deem it trivial, they fail to provide anything except encouraging words.

This community will try to bridge that gap.

NTs / Allistics are very welcome, BUT they must understand that we need details, we need patience, and we need kindness around matters of business politics and office socializing.

view more: next ›