home.social

#trustbutverify — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #trustbutverify, aggregated by home.social.

fetched live
  1. Google's defense for false AI Overviews: Nobody should blindly trust AI output anyway. And they're right. A German court agreed nobody should trust it, then held Google liable for it regardless.

    However, the court found that your product only has value if people trust it. You can't sell a tool that answers with confidence and then tell a judge the answers shouldn't be believed.

    Two things from the ruling of note:

    1. Search engines get liability protection because surfacing third-party links is unavoidable. The court said AI summaries are optional. Nobody needs them to search the web, so they don't get the same level of protection.

    2. Google's AI Overviews on the current Gemini model are wrong about 9% of the time and attach bad source links 56% of the time. Most people never click through to check. Trust, but verify!

    Put that together, and a tool like this produces millions of wrong answers a day, and almost nobody verifies them. Which they should. I keep coming back to accountability, companies, and individuals. Someone decided to ship a feature that makes confident, original claims about real businesses and didn't fix them quickly when they were wrong. Additionally, it's up to the end user to always verify the claims. However, the court called it the company's own speech and liability.

    If you're adding AI features to your product, the lesson is simple. You own what your tool says. The disclaimer won't save you.

    arstechnica.com/tech-policy/20

    #AI #RiskManagement #Cybersecurity #TrustButVerify

  2. Google's defense for false AI Overviews: Nobody should blindly trust AI output anyway. And they're right. A German court agreed nobody should trust it, then held Google liable for it regardless.

    However, the court found that your product only has value if people trust it. You can't sell a tool that answers with confidence and then tell a judge the answers shouldn't be believed.

    Two things from the ruling of note:

    1. Search engines get liability protection because surfacing third-party links is unavoidable. The court said AI summaries are optional. Nobody needs them to search the web, so they don't get the same level of protection.

    2. Google's AI Overviews on the current Gemini model are wrong about 9% of the time and attach bad source links 56% of the time. Most people never click through to check. Trust, but verify!

    Put that together, and a tool like this produces millions of wrong answers a day, and almost nobody verifies them. Which they should. I keep coming back to accountability, companies, and individuals. Someone decided to ship a feature that makes confident, original claims about real businesses and didn't fix them quickly when they were wrong. Additionally, it's up to the end user to always verify the claims. However, the court called it the company's own speech and liability.

    If you're adding AI features to your product, the lesson is simple. You own what your tool says. The disclaimer won't save you.

    arstechnica.com/tech-policy/20

    #AI #RiskManagement #Cybersecurity #TrustButVerify

  3. We are drowning in information.
    But starving for truth.
    The line between journalism, propaganda, and entertainment has disappeared.
    One headline says "ceasefire". Another says "rearming".
    Both cite "anonymous officials".
    How do you decide who to trust?
    I don't have an easy answer.
    But asking the question is already a start.

    #MediaLiteracy #InformationWar #TrustButVerify #Politics

  4. We are drowning in information.
    But starving for truth.
    The line between journalism, propaganda, and entertainment has disappeared.
    One headline says "ceasefire". Another says "rearming".
    Both cite "anonymous officials".
    How do you decide who to trust?
    I don't have an easy answer.
    But asking the question is already a start.

    #MediaLiteracy #InformationWar #TrustButVerify #Politics

  5. Trump’s Iran MOU: A Tangled Web of Trust and Skepticism

    Learn about the Trump Iran MOU, why it causes skepticism, and how it relates to digital wallets and legal trusts. Affected: US citizens interested in foreign policy.

    #TrumpMOU, #IranDeal, #ForeignPolicy, #TrustButVerify, #InternationalRelations

    newsletter.tf/trump-iran-mou-t

  6. The Trump Iran MOU involves intense scrutiny, similar to how digital wallets require verification before transactions. This is a much higher level of caution than usual.

    #TrumpMOU, #IranDeal, #ForeignPolicy, #TrustButVerify, #InternationalRelations
    newsletter.tf/trump-iran-mou-t

  7. @astian @FibroJedi

    Comparing your official roadmap to "thoughts in school" and suggesting I am "thinking like an 18-year-old" is quite the deflection. Privacy and security auditing are not about "growth phases," they are about verifiable facts.

    The Facts:
    Your blog still markets "Integrated AI" as a feature. Leaving it up "for transparency" while telling critics it's "old" is a contradiction.

    You claim a proprietary index and Open Source status, yet your FAQ admits the code isn't public.

    "Trust me bro, I have changed" is not a security model.

    If you have truly improved, prove it by releasing the source code so the community can audit your privacy and "No-AI" claims. Until then, it's just a proprietary system.

    #TrustButVerify #Privacy #Linux #NoAI

  8. @astian @FibroJedi

    Comparing your official roadmap to "thoughts in school" and suggesting I am "thinking like an 18-year-old" is quite the deflection. Privacy and security auditing are not about "growth phases," they are about verifiable facts.

    The Facts:
    Your blog still markets "Integrated AI" as a feature. Leaving it up "for transparency" while telling critics it's "old" is a contradiction.

    You claim a proprietary index and Open Source status, yet your FAQ admits the code isn't public.

    "Trust me bro, I have changed" is not a security model.

    If you have truly improved, prove it by releasing the source code so the community can audit your privacy and "No-AI" claims. Until then, it's just a proprietary system.

    #TrustButVerify #Privacy #Linux #NoAI

  9. AI Search: Yes, absolutely, 100%, go for it 🔥
    Reality: Feature not available in your region, browser, planet, or lifetime.

    Feels less like 'artificial intelligence' and more like 'confident hallucination as a service' 😌 #AI #UXFail #TrustButVerify

  10. AI Search: Yes, absolutely, 100%, go for it 🔥
    Reality: Feature not available in your region, browser, planet, or lifetime.

    Feels less like 'artificial intelligence' and more like 'confident hallucination as a service' 😌 #AI #UXFail #TrustButVerify

  11. Palo Alto: “LOL, we fixed 24 vulns in a random Tuesday update with no CVE alert. Why are you panicking?”

    security.paloaltonetworks.com/

    • No alerts
    • No heads-up

    Just a stealth patch buried in the advisory feed.

    The stats:

    • 24 total CVEs
    • 11 High, 11 Medium
    • 100% discovered externally
    • Average patch delay: 4 FUCKING years for high severity

    All bundled into one advisory.
    Welcome to the Patch Gacha Machine:
    Spin once, fix 24 vulnerabilities (maybe).

    PAN CVEs age like wine… and compromise like whiskey.

    #PANOS #CyberSecurity #CVEs #PatchAndPray #SilentFixes #PSIRTFail #MemeSec #BlueTeamLife #TrustButVerify

  12. Palo Alto: “LOL, we fixed 24 vulns in a random Tuesday update with no CVE alert. Why are you panicking?”

    security.paloaltonetworks.com/

    • No alerts
    • No heads-up

    Just a stealth patch buried in the advisory feed.

    The stats:

    • 24 total CVEs
    • 11 High, 11 Medium
    • 100% discovered externally
    • Average patch delay: 4 FUCKING years for high severity

    All bundled into one advisory.
    Welcome to the Patch Gacha Machine:
    Spin once, fix 24 vulnerabilities (maybe).

    PAN CVEs age like wine… and compromise like whiskey.

    #PANOS #CyberSecurity #CVEs #PatchAndPray #SilentFixes #PSIRTFail #MemeSec #BlueTeamLife #TrustButVerify

  13. Ah yes, another startup solving the trust crisis in AI by... naming it louder. NeuralTrust's "Echo Chamber" sounds less like a security model and more like what happens when a product team feeds back its own pitch deck for 6 months. 🔁🤖 #AI #TrustButVerify

  14. Ah yes, another startup solving the trust crisis in AI by... naming it louder. NeuralTrust's "Echo Chamber" sounds less like a security model and more like what happens when a product team feeds back its own pitch deck for 6 months. 🔁🤖 #AI #TrustButVerify

  15. 😬 A cautionary tale for recent grads: A Utah law clerk was fired after using ChatGPT to draft a court filing that included fake legal citations — the first AI-generated “hallucination” officially sanctioned by a Utah court.

    🧑‍⚖️ Judge: Lawyers have a duty to review filings
    📉 Law firm: Fired the clerk + added an AI policy
    📱 Broader lesson: Overreliance on AI can harm your credibility
    🎓 Professors report students increasingly trust AI without verifying

    This signals a shift: AI use is no longer optional — but knowing how to check its output is critical.

    #AI #LegalTech #ChatGPT #WorkplaceEthics #ProfessionalDevelopment #TrustButVerify
    arstechnica.com/tech-policy/20

  16. 😬 A cautionary tale for recent grads: A Utah law clerk was fired after using ChatGPT to draft a court filing that included fake legal citations — the first AI-generated “hallucination” officially sanctioned by a Utah court.

    🧑‍⚖️ Judge: Lawyers have a duty to review filings
    📉 Law firm: Fired the clerk + added an AI policy
    📱 Broader lesson: Overreliance on AI can harm your credibility
    🎓 Professors report students increasingly trust AI without verifying

    This signals a shift: AI use is no longer optional — but knowing how to check its output is critical.

    #AI #LegalTech #ChatGPT #WorkplaceEthics #ProfessionalDevelopment #TrustButVerify
    arstechnica.com/tech-policy/20

  17. Just a few days back we were discussing hbom is tricky coz once we try to read in we are going to tamper warantties and today @bunnie.org Released https://bunnie.org/iris hoping this changes the landscape
    #hbom #trustbutverify

  18. Just a few days back we were discussing hbom is tricky coz once we try to read in we are going to tamper warantties and today @bunnie.org Released https://bunnie.org/iris hoping this changes the landscape
    #hbom #trustbutverify

  19. Buying a dog from a breeder in NY.

    We've been in discussions via phone calls and texts and pictures and videos for 6+ months.

    Called the credit union to wire transfer payment (this is a stupid expensive dog, I admit that).

    PLEASED as punch that they asked me no less than 3 times if I was SURE I trusted the seller, really wanted to wire the money, had a confirmed transaction, etc.

    I'm sure we sounded like the average overseas-magic-puppy-farm victim, and fit the SCAM pattern so well, it was really pleasing to see the CU taking all the precautions to make sure I'm not a victim.

    #trustButVerify #scams #wishMeLuck

  20. Buying a dog from a breeder in NY.

    We've been in discussions via phone calls and texts and pictures and videos for 6+ months.

    Called the credit union to wire transfer payment (this is a stupid expensive dog, I admit that).

    PLEASED as punch that they asked me no less than 3 times if I was SURE I trusted the seller, really wanted to wire the money, had a confirmed transaction, etc.

    I'm sure we sounded like the average overseas-magic-puppy-farm victim, and fit the SCAM pattern so well, it was really pleasing to see the CU taking all the precautions to make sure I'm not a victim.

    #trustButVerify #scams #wishMeLuck

  21. One of the Mastodon posts "gaining traction" today is a screencap of a post containing a screencap of another post containing an unsourced assertion about Musk.

    Can we all please stop doing that?

    #TrustButVerify #FactCheck #rumors
  22. 🦩 LIVING ON THE EDGE... literally!
    (@rnbwkat made me do it!)

    Just your favorite security flamingo casually ziplining across the Panama City skyline at Cielo rooftop bar! Talk about taking "elevated privileges" to a whole new level!

    Pro tip: When you're suspended 40 floors up, you REALLY learn to trust your security harness. Just like how you should trust but verify your security controls!

    Gotta say, the view of the Pacific is even more spectacular when you're zooming through the air. Though I did have to tuck my feathers in - nobody wants a wind-swept flamingo crash landing at the bar!

    Remember friends:

    - Sometimes you have to step (or zip!) out of your comfort zone to get the best perspective on things.
    - Just make sure your safety checks are in place first!
    #SkyHighSasha #PanamaAdventures #TrustButVerify #cybersecurity

  23. Yo! Everyone, listen up for a second.

    I know everyone is trying to help out and spread helpful information, but when the information contains an email or phone number, let's verify.

    This post kolektiva.social/@MikeDunnAuth

    It has a phone number only for the state of Washington. When I called, they said they were already overrun by out-of-state calls.

    This is effectively a DDoS attack. Their website is also down. I'm not sure if this is a deliberate attack to weaken the immigration services in Washington, maybe it's the next place trump is planning (Speculation, worth looking at.).

    It's not hard to verify. It should be second nature for all the IT/InfoSec people here.

    #TrustButVerify

  24. Yo! Everyone, listen up for a second.

    I know everyone is trying to help out and spread helpful information, but when the information contains an email or phone number, let's verify.

    This post kolektiva.social/@MikeDunnAuth

    It has a phone number only for the state of Washington. When I called, they said they were already overrun by out-of-state calls.

    This is effectively a DDoS attack. Their website is also down. I'm not sure if this is a deliberate attack to weaken the immigration services in Washington, maybe it's the next place trump is planning (Speculation, worth looking at.).

    It's not hard to verify. It should be second nature for all the IT/InfoSec people here.

    #TrustButVerify

  25. @henry The BBC article shown here does not mention AI. The post says that the company blamed a human for a copy-and-paste error using an older post.

    bbc.co.uk/news/articles/czd531

    #TrustButVerify

  26. @henry The BBC article shown here does not mention AI. The post says that the company blamed a human for a copy-and-paste error using an older post.

    bbc.co.uk/news/articles/czd531

    #TrustButVerify

  27. Happy (very punctual) . Today we're talking about some changes we are making in light of the . tldr; the Trusted Contributors program will be doing a bit more . Read more about Trusted Contributors at puppet.com/ecosystem/contribut or download the scanner module at forge.puppet.com/puppetlabs/xz and check your infrastructure today.

  28. Happy (very punctual) #FiveMinuteFriday. Today we're talking about some changes we are making in light of the #XZBackdoor. tldr; the Trusted Contributors program will be doing a bit more #TrustButVerify. Read more about Trusted Contributors at puppet.com/ecosystem/contribut or download the scanner module at forge.puppet.com/puppetlabs/xz and check your infrastructure today.

  29. @f00fc7c8
    I think #verification on #Mastodon does a lot more than "literally nothing." It proves that the person writing these toots is the same person writing those blog articles on my website, and those code repositories on my #GitHub profile.

    Now, the real question: Is that kind of verification actually valuable? For a relatively obscure guy like me, whose influence extends only as far as his own personal and professional networks, not extremely. But there's always a non-zero risk that someone out there will attempt to deceive someone I know by pretending to be me. I never want that to happen to anyone, especially those in my personal and professional networks, so I'm just doing what I can to establish a known baseline of my identity. #TrustButVerify

  30. @f00fc7c8
    I think on does a lot more than "literally nothing." It proves that the person writing these toots is the same person writing those blog articles on my website, and those code repositories on my profile.

    Now, the real question: Is that kind of verification actually valuable? For a relatively obscure guy like me, whose influence extends only as far as his own personal and professional networks, not extremely. But there's always a non-zero risk that someone out there will attempt to deceive someone I know by pretending to be me. I never want that to happen to anyone, especially those in my personal and professional networks, so I'm just doing what I can to establish a known baseline of my identity.

  31. CW: Police Shootings, US News Media, Open Data

    @databae Awesome to see this project get additional attention!

    #OpenData has inherent #transparency, and allowing your audience to #TrustButVerify as well as keeping the platform #OpenSource is powerful. Love it 👏

  32. Do you know if you can trust GPS? I have a proper antenna mounted on my roof and position captured with a survey gps. This is connected to a gps sending data to gpsd, calculating horizontal and vertical error, and feeding it to influxdb. There i can easily graph and create alerts. #trustbutverify #collectyourowndata

  33. Do you know if you can trust GPS? I have a proper antenna mounted on my roof and position captured with a survey gps. This is connected to a gps sending data to gpsd, calculating horizontal and vertical error, and feeding it to influxdb. There i can easily graph and create alerts. #trustbutverify #collectyourowndata

  34. CW: raspberry pi, cop talk. Good cop, bad cop, ugly cop, zombie cop.

    @tillianisafox Ooooh, this? Absolutely.

    You think I had to put my #trust in them? Mostly, just manned the radio or got outdoors with these people. Maybe as much trust as to be sure they won't fuck me over in one way or another.

    But it really showed when they actually gave a fuck about it and not just messed around our collective job (I can tell you stories about this).

    #TrustButVerify

  35. 🌊 #PSA: OK folks, fasten your seat belts for the next surge.

    ⚠️ Do NOT trust random new accounts to be who they say they are, unless they have a profile green check mark linked to a site you can verify externally is legitimate. This goes for people or organizations or software tools, whatever.

    ℹ️ Moreover, do not trust random people (especially new people) on here claiming to vouch for the legitimacy of other accounts. Especially those who can't be verified as described above.

    #TrustButVerify

  36. Teachable moment. How @georgetakei can show who he is:

    Tweet/post/link from a page he owns pointing to his account here:

    {blah blah some dying bird site dot com}/GeorgeTakei/status/1592998831524044801

    Add the HTML to a website he owns so that a check mark appears next to it in Mastodon:
    barrd.dev/article/add-a-verifi

    #TrustButVerify
    #Security
    #GeorgeTakei

  37. Teachable moment. How @georgetakei can show who he is:

    Tweet/post/link from a page he owns pointing to his account here:

    {blah blah some dying bird site dot com}/GeorgeTakei/status/1592998831524044801

    Add the HTML to a website he owns so that a check mark appears next to it in Mastodon:
    barrd.dev/article/add-a-verifi

    #TrustButVerify
    #Security
    #GeorgeTakei

  38. So, I may have gotten ahead of myself. I boosted something before doing my research.

    When picking a #mastodon server, or trusting advice on a #DisabilityAccommodation, or reading a journal article, check who funded the work, check credentials, check for potential conflicts of interest (disclosed or not), and make the best decision you can.

    What does the individual potentially gain from having this server? What does the author potentially gain from these findings? #Disability #TrustButVerify

  39. So, I may have gotten ahead of myself. I boosted something before doing my research.

    When picking a #mastodon server, or trusting advice on a #DisabilityAccommodation, or reading a journal article, check who funded the work, check credentials, check for potential conflicts of interest (disclosed or not), and make the best decision you can.

    What does the individual potentially gain from having this server? What does the author potentially gain from these findings? #Disability #TrustButVerify