came to say this. it's the AI writing cadence, I can smell it from 1000ft:
- Lots of "The" headings
- Always "why it matters"
- Machine gun style cadence of short sentences
I hate that AI has stolen my emdashes and I can't use them without looking like slop. But I will die defending markdown as my preferred note taking format. They're not taking that away from me.
I felt like this with the word delve. Seemed like nobody had ever heard the word before, and that the only possible way it’d be written was if an llm did it - but it’s just a nice word.
Delve was used a lot in corporate writing. A lot of the so-called "whitepapers" that businesses like to publish to show how smart they are were ingested in training models.
Unfortunately, in a place like this, if a bunch of people falsely accuse you of being a slop spreader your karma drops like a rock.
Can you imagine how hard it is to start up a new Reddit account lately? Even in a small and isolated community of niche enthusiasts just getting to the point where your posts aren't auto-modded takes serious effort. One stray emdash and you can lose it.
Ask me how I know.
Oh yay, I'm in HN jail again. "You're posting too fast." Faster than once per 30 minutes? Sigh.
Just on HN alone I think I've seen roughly 3948538902748750897520938 mentions of emdashes when others were complaining about slop in the past 2 months. It might as well be the unofficial slop logo. Folks are treating it like a dead giveaway.
I feel like a school friend of mine has been taken from me.
I can't tell if my main source of hate there is the homogeneity itself, or that it's excessively marketing-flavored (fluffy and aggrandizing, mere inches from "our incredible journey..." at all times).
It shouldn't but often still is... and maybe a runbook like this is easier to handle than a script with possibly 1000 lines and not a single comment.
Of course, in your ideal world maybe nothing of this applies and you never have any incidents ;)
In addition contents of the presentation, in terms of timeline...
2018 (September): First undocumented MMIO-present CPU launched, Apple A12 Bionic SOC.
2021 (December): Early exploit chain infrastructure backuprabbit.com created 2021-12-15T18:33:19Z, cloudsponcer.com created 2021-12-17T16:33:50Z.
2022 (April): Later exploit chain infrastructure snoweeanalytics.com created 2022-04-20T15:09:17Z suggesting exploit weaponized by this date.
2023 (December): Approximate date of capture (working back from "half year" quoted analysis period + mid-2023 Apple reports.
The presenters also state that signs within the code reportedly suggested the origin APT group has used the same attack codebase for "10 years" (ie. since ~2013) and also uses it to attack MacOS laptops (with antivirus circumvention). The presenters note that the very "backdoor-like" signed debug functionality may have been included in the chips without Apple's knowledge, eg. by the GPU developer.
So... in less than 3.5 years since the first vulnerable chip hit the market, a series of undocumented debug MMIOs in the Apple CoreSight GPU requiring knowledge of a lengthy secret were successfully weaponized and exploited by an established APT group with a 10+ year history. Kaspersky are "not speculating" but IMHO this is unlikely to be anything but a major state actor.
Theory: I guess since Apple was handed ample evidence of ~40 self-doxxed APT-related AppleIDs, we can judge the identity using any follow-up national security type announcements from the US. If all is quiet it's probably the NSA.
It's not, it really isnt. Honestly just apply this mentality to one other scenario to test the waters. We should stop publishing yara rules because it flips our hand to the malware makers? It's nonsense to even say.
yeah, this basically confirms my experience and is also what annoys me so much. Not even investing 5s to read the first sentence of the profile... just wasting time for every one.