At least Cowbee has sources 🤷
At least Cowbee has sources 🤷


It’s wild to post something like this, and say things like “This impacts at least some operating systems or distributions,” without indicating at all which ones you’re having the experience with.


Just so I understand properly, you are being barred from attending class until you agree to no longer walkout of class in support of your principles? 🤔
Anyway, my (very limited) understanding of First Amendment protections for high school students is that they exist, but are not as strong as for college students or adults generally. The relevant landmark decision is from Tinker vs Des Moines, which basically says the administration can indeed infringe on students’ First Amendment rights if the exercise of those rights results in a “substantial disruption.” I imagine how difficult or easy it is for the administration to argue that a planned walkout results in a “substantial disruption” varies regionally, but is probably easier now in the current environment than it ever has been historically. That said, the case also did assert that “silent” protests like the wearing of armbands is not a “substantial disruption,” so perhaps there are still things you can pursue without fear of persecution.
Either way, I would like to echo the sentiments of respect and admiration for you and all you have done already, sympathy for what you have and had to endure, and hope for you now and in the future.
I’d say your reading is pretty much correct. I don’t know how much SSD variance would really impact things, but the extent to which it does would have to do with however the neural network was trained. The more robustly that model is able to discern what is and is not running based on the SSD analyses, the more plausible and reliable this attack is. I think that’s where the bulk of the “techno-babble” aspect comes into play.
The reported attack is really messed up from a privacy perspective, but I also think it’s not EXTREMELY viable in reality, due to the mentioned constraints (in particular the large file size requirement). There are two aspects here: 1. a web browser can snoop SSD behavior (❗), 2. if you run that data through an appropriately trained model, perhaps the sky’s the limit (☹️).
The wackest part is that a web browser can analyze SSD behavior. That’s just messed up. The fact that nerds were then like “yo, let’s train an ML model on this to tell what the user is doing on their computer” is also nuts, of course, but obviously that threat is mitigated presuming nefarious actors aren’t given carte blanche access to one’s hard drive behavior in the first place. It also seems plausible that you could maybe break such a model by running a program specifically designed to disguise SSD usage, not to mention other isolation approaches already referenced in the article.
But so yeah, being able to snoop on SSD activity is insane. Training a model on that activity is where it gets more techno-babbley, but they also showed it can at least be done on an M2. There’s no reason to think it couldn’t similarly be done for other systems, OSes, applications, and configurations, but of course the wider they cast that net, the trickier it likely is to viably train the model(s).