This weekly roundup thread is intended for all culture war posts. 'Culture war' is vaguely defined, but it basically means controversial issues that fall along set tribal lines. Arguments over culture war issues generate a lot of heat and little light, and few deeply entrenched people ever change their minds. This thread is for voicing opinions and analyzing the state of the discussion while trying to optimize for light over heat.
Optimistically, we think that engaging with people you disagree with is worth your time, and so is being nice! Pessimistically, there are many dynamics that can lead discussions on Culture War topics to become unproductive. There's a human tendency to divide along tribal lines, praising your ingroup and vilifying your outgroup - and if you think you find it easy to criticize your ingroup, then it may be that your outgroup is not who you think it is. Extremists with opposing positions can feed off each other, highlighting each other's worst points to justify their own angry rhetoric, which becomes in turn a new example of bad behavior for the other side to highlight.
We would like to avoid these negative dynamics. Accordingly, we ask that you do not use this thread for waging the Culture War. Examples of waging the Culture War:
-
Shaming.
-
Attempting to 'build consensus' or enforce ideological conformity.
-
Making sweeping generalizations to vilify a group you dislike.
-
Recruiting for a cause.
-
Posting links that could be summarized as 'Boo outgroup!' Basically, if your content is 'Can you believe what Those People did this week?' then you should either refrain from posting, or do some very patient work to contextualize and/or steel-man the relevant viewpoint.
In general, you should argue to understand, not to win. This thread is not territory to be claimed by one group or another; indeed, the aim is to have many different viewpoints represented here. Thus, we also ask that you follow some guidelines:
-
Speak plainly. Avoid sarcasm and mockery. When disagreeing with someone, state your objections explicitly.
-
Be as precise and charitable as you can. Don't paraphrase unflatteringly.
-
Don't imply that someone said something they did not say, even if you think it follows from what they said.
-
Write like everyone is reading and you want them to be included in the discussion.
On an ad hoc basis, the mods will try to compile a list of the best posts/comments from the previous week, posted in Quality Contribution threads and archived at /r/TheThread. You may nominate a comment for this list by clicking on 'report' at the bottom of the post and typing 'Actually a quality contribution' as the report reason.

Jump in the discussion.
No email address required.
Notes -
Australian boys make spreadsheet of girls attractiveness, national media, federal minister and state premier rush to condemn them. I'm pretty surprised this got any media attention, doesn't it seem trivial? This all happened on some discord server, it's not like they were parading it around. Does anyone think this would happen in their country?
I can't see how 'unrapeable' could possibly be a threat. Saying someone is vulnerable could be a threat, calling someone invulnerable is not... OK it's very rude, suspend the ringleaders - do police need to be involved? There's a certain level of hysteria here, you get the sense that the male principal fears for his job unless he takes this as seriously as humanly possible.
It would be pretty crushing to be labelled unrapeable or 'get out' by your male peers, though I don't see how a counsellor could help.
Context: Australian media and govt have been panicking about male-on-female violence for a few weeks now. We recently had a mass stabbing by a mentally ill man, who targeted mostly women. Accordingly, male on female violence has increased statistically and the government has thrown a lot of money at various NGOs.
Additionally, there has been a lot of concern about Tate corrupting the minds of the youth. So this lets the media hit two talking points at the same time.
A related matter - youtuber argues that ranking women's attractiveness upsets the Byzantine system of female intrasexual competition, where every queen is praised as a 10/10 regardless of ugliness. I found the video pretty decent albeit a few minutes longer than it needed to be. It features the infamous Gorlock the Destroyer claiming to be a 10/10 (sarcastically?), which does make you think. There might be something to it - ranking women by attractiveness seems more dangerous than one might naively imagine.
In the male-dominated patriarchal society of the distant past, accusing men of being bastards or having incorrect lineage was a very serious matter. Legitimacy and preventing cuckoldry was deeply important to men, it informed the whole structure of European politics, inheritance and succession. Perhaps in the emerging future it's female sexual dynamics that will take priority and we'll see more of this kind of thing.
Premier (woman): "This pattern of violence against women — not only does the act of violence have to stop, but these displays of disrespecting women. Like, it's just disgraceful."
Lèse-majesté: an offence or defamation against the dignity of a ruling head of state or of the state itself.
Calling a specific subsection of women unrapeable is a pretty clear implication that you consider other subsections acceptable to rape. https://en.wikipedia.org/wiki/Exception_that_proves_the_rule#Proving_the_existence_of_the_rule
It's not rocket science. Sure, it would't hold up in a decent court, but "acktchyually I said I wouldn't even rape her, why are you upset" isn't fooling anyone.
Calling dog-kidney pie "inedible" is a clear implication that you consider other preparations of dog meat acceptable to eat.
They're children. Maybe some children somewhere are capable of rape, but treating a group of posh high school boys as if they were seriously contemplating violent rape is laughable on the part of the Australian establishment.
Well if you had a ranked tier list of dog meat preparations, of which 'inedible' was the lowest rung, that would pretty clearly indicate that those above that rank were edible. In fact it would be necessarily true, as anything that wasn't edible would by definition be in the inedible tier.
"Unrapeable" could just as easily mean "they're so ugly even a rapist wouldn't bother," as it could "they're so ugly I wouldn't rape them". There's not really an equivalent for "inedible", so the comparison is lacking.
Please stick to a single account.
I have multiple? I lost track.
Understood, carry on.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
You can treat them as if they'd made an overly spicy joke, and they'll wear it as a mark of pride. Or you can put them through the wringer so they'll think better next time. I don't think the second option is more laughable.
I'm not too sure it works like that.
It does. Force works for everything, if you can apply enough force. Treat someone who makes a joke as if they're a violent criminal, and they will think making jokes makes you a violent criminal. Brainwashing works.
More options
Context Copy link
More options
Context Copy link
Think better of what? Edgy offensive teenage jokes? Is this something you think society can or should stomp out?
Obviously they do. Like how is this even a question at this point? By revealed preferences they care about it more than murder. Look at the reaction to the frat bro who dared make fun of a lizzo cosplayer vs the literal Hamas militia.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
The argument was incomplete. It's not the use of unrapeable in isolation that's making the threat. It's the contrast between that section and the other sections. If you made a tier list of food, put dog-kidney pie in "inedible" and all the other dog meats in the other not-inedible sections, it would imply you consider other preparations of dog meat acceptable to eat.
To draw up a situation where the courts would find someone at fault for doing like this, consider a Mafia boss writing a list containing categories like "deal with soon" and "not to be killed" and handing it to a made man. Then, a few weeks later, some of the people under "deal with soon" are dead. This would be evidence connecting the boss to the crime, even though the literal interpretation of the list is that it never listed anyone to be killed, only those to not be killed.
The reason it should fail is because the threat is non-credible, and being done in private, couldn't have been used to coerce anyone.
More options
Context Copy link
More options
Context Copy link
Not at all; it's an implication that you consider other subsections vulnerable to rape, that is, desirable. "Unrapeable" says "not even with zero effort or consequences would she get any".
If you're rating on a spectrum, you get "I would put effort into getting laid with this person" as the higher tier, but then there's a tier of "sure, would fuck if an opportunity arose". That's the "rape" tier; it's not saying you want to engage in rape, but that rape is the obvious-to-come-to-mind situation in which their attractiveness would overcome the thus-lowered effort barrier. If there was a rapist in the room, they would rape this person. They would not rape the lower tier - unrapeable - because it would be actively unenjoyable, net negative even if free. "Thanks, I'd rather masturbate."
A less edgy schoolyard way to phrase the same thing is "would pay to fuck", "would fuck if you paid me" and "not even if you paid me."
We can rephrase this in this context simply as "unable to induce an erection".
More options
Context Copy link
More options
Context Copy link
I think there's an interesting "The Dress" style divide in how this statement is perceived that's basically determined by your belief about whether these boys would rape someone [if they could get away with it]. There's probably a genuine divide between a large number of men who wouldn't and can't conceive that the median man would, and a large number of men who would and can't conceive that the median man sincerely wouldn't, and they are prevented from sizing up each other in part by the circumstance that signalling needs create large sets of those who are in one group but claim to be in the other.
Depending on whether you are a believer that rape is widely accepted (and here the belief about others really seems to matter more than whether you would do it yourself), "unrapeable" sounds either like "I wouldn't take this one for free" (but I would take the others for free - free stuff is good!) or "this wouldn't get stolen if it were left out" (it's not like I'm a thief, but it's so bad that it's beneath even outgroup bad people like thieves).
(I tried and failed to find a realistic instance of something like "the dogs wouldn't eat you if you were thrown to them" being used as an insult, so I have to settle for the weaker point that a hypothetical insult of that type would not be taken as an endorsement of cannibalism.)
More options
Context Copy link
What does "clear" mean here? Reliable? Or subjectively persuasive?
I also think you're probably wrong about the semantics. "Raping Jane is impossible because she's so ugly" doesn't ordinarily imply that "Raping Sally is permissible because she's attractive." That's conflating two different types of modality: moral permissibility and practical possibility.
More options
Context Copy link
"Unrapeable" doesn't mean "morally unacceptable to rape". It means "unattractive even to rapists". The implication is that the others on the list would be attractive to rapists, but not that the writer would rape them personally.
More options
Context Copy link
More options
Context Copy link
Women carry around a nagging anxiety that their own existential authenticity is always in doubt; there is an unresolvable neurosis over the possibility of being reduced to a mere biological function. The fear is that all the rhetoric about girl bosses and shatter-prone glass ceilings and a more egalitarian future really is, at the end of the day, just rhetoric, no matter how many Emmy Noethers and Angela Merkels and Jane Austens dot the pages of our history books.
A man may be a scoundrel and an outcast and a criminal, but at least these are proper symbolic roles - they require the attribution of human agency. If your identity is fully coextensive with the biological function of reproduction, then the worry is that this makes one more object than human - more like the scaffolding that supports the stage, rather than a proper player in the drama.
This is why the threat of "objectification" carries such a sharp sting. I would be so bold as to speculate that this is, in some sense, a trans-historical feature of femininity as such - the division between the human as rational agent and the human as embodied biological organism almost demands a group of people who fall on the wrong side of the divide - and therefore cannot be assuaged by any amount of empirical evidence that women are in fact capable of leading much the same types of lives and engaging in the same sorts of intellectual pursuits as men are.
More options
Context Copy link
School children ranking each other on attractiveness is nothing new. Not sure about Australia but here in the states ranking people based on attractiveness made it's way around the news as well previously. As the article points out, this had been happening for as long as people can remember and many people have had personal experiences going across both sexes. Heck, even I had the misfortune of finding out what some girls rated my attractiveness back during high school.
It's just yet another opportunity to bash on men and to push the women are victim narrative that seems to become ever more prevalent.
Interestingly enough /r/TwoXChromosome had a thread on that news and most responses seem responsible: https://old.reddit.com/r/TwoXChromosomes/comments/b68zn2/teen_boys_rated_their_female_classmates_based_on/
The responses that seem to say the attractive rating between teens is problematic are actually downvoted.
That being said, this was 5 years ago. I wonder if the average user/demographic has shifted enough that the responses would be different today. There is another post on /r/melbourne about the exact article you linked to: https://old.reddit.com/r/melbourne/comments/1ckq7hp/private_school_boys_suspended_after_absolutely/
It's a different subreddit so I would expect TwoXChromosome to be more sympathetic to the girls, yet the responses on this more recent story seem to be more full of outrage.
There was also a similar though more serious scandal in California back in 1993 around the so-called Spur Posse.
More options
Context Copy link
Melbourne is rather leftist and conformist by Australian standards, it's reasonable that they're more feminist than US feminists.
This came up during "the voice" referendum too, which proved to Australian reddit that they live in an irredeemably white supremacist dystopia. It's actually more off the deep end than most of the US city subs.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
They are going to use the tragedy to push through vaguely linked changes that they wanted to do anyway. The UK saw the same pattern happen when the government used the murder of David Amess by an Islamist to push laws seeking to censor social media even though this is completely unrelated to the circumstances of the murder.
The majority of murder victims in Australia (and most if not all other countries) are male. But men are treated as disposable, so that doesn't matter.
More options
Context Copy link
I think that the issue with "unrapeable" is that it is not a tag that was applied to all of the classmates, the implication being 'the primary thing that keeps us from raping people (apart from strategic concerns regarding law enforcement) is people being ugly'.
If the boys had rated their classmates on a scale of one to ten, this would still be in poor taste imho (as it would be if the genders were reversed, like in that South Park episode), but probably not make national news.
Also, the one-dimensional scale of female attractiveness is certainly an oversimplification. Looking at porn categories, I think it is safe to say that while there is a common axis of attractiveness, there is is also a lot of variation in preference among men.
Finally, your physical attractiveness should mostly matter in so far as your goal is to bang all your classmates or find a partner who prefers a high status mate to underline their own status among their peers, neither of which sound like very worthwhile goals.
...
More options
Context Copy link
We ought to interpret “unrapeable” more charitably as “even a driven (evil/damned) rapist would pass up the opportunity because of how ugly she is”. There is no indication that the boys have formed some some crypto-pro-rapist organization which hides their aspirations by including the word “unrapeable”. That is too uncharitable to consider. It’s like, if I say I wouldn’t eat your cooking even if I’m starving, I am not making a positive value claim about the state of being starved.
In the feminist mindset, rape is an expression of power, not an act of lust, and hence it is quite disconnected with a woman's attractiveness.
You know I used to think this was nonsense (along with its stronger and more generalized form, "sex for men is about power rather than lust"), but the more time I spend thinking about the way that different men conceive of and relate to sex, the more I start to think there's some truth for it.
If you look at any of the "redpilled manosphere" guys - Rollo, Andrew Tate, Fresh & Fit, anyone in that milieu - I think it's clear that they view women first and foremost as an economic resource to be managed and optimized, and the pleasure that they derive from their own status as an "alpha" is more central than the pleasure that they derive from the woman's body itself. In fact a man completely losing himself in the thrall of pleasure while in the presence of a woman would be viewed with suspicion - he's a simp, he's unmanly, he doesn't know how to control himself, etc.
I think it's true of how some men think of sexually relating to women. Also some women: a lot of romance novels are explicitly about emotionally subjugating a powerful man, with a "he gets down on his knees and begs" scene being a very common trope of the genre. Not so much "civilizing a bad boy into a mature man" as "having control over a bad boy".
IIRC, romance novels are disproportionately read by middle-aged women and AFAIK Tatism appeals to low status/young men. Two of the bottom feeder groups of their respective sexes, who fantasise about debased devotion of a partner in the absence of perceived opportunities for healthy romantic fulfillment. The equivalent submissive pathologies are femdom pornography for men and rape fantasies for women, both of which seem to be largely a matter of despair at forming a mutually loving connection.
More options
Context Copy link
More options
Context Copy link
Yeah but like, they're wrong.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
Why is it in bad taste for men to rate women's attractiveness?
It has been my experience that if you show (straight) men a group of women (across anything from a IRL social situation to just a set of headshots), they can pretty reliably sort them quickly by their own metrics of attractiveness. The rankings probably won't be identical, and they could change with interaction, but I bet at any given point most men, even those not looking for partners, are at least aware of who they find the most attractive woman in any given room.
But it's also generally verboten to discuss the rankings themselves in mixed contexts, and even most of the time in male spaces. But I have occasionally been party to discussion of rankings of celebrities. I would be curious of (straight) women think similarly, but I have no real information to go on.
I think your last paragraph gets to the heart of the matter. Attractiveness is tied very tightly to status, particularly for women. When men are ranking women's attractiveness, their rankings are pretty close to openly articulating the status rankings of the women in question - ranking someone last in a group is basically the same thing as just outright saying, "I think she's a loser and not worthy of the same respect as the other women". When this is done with people are members of a near-group (or worse still, a friend-group), it's a fairly aggressive action to take. On the flip side, this is why ranking celebrities can be fun even in a mixed-gender group - no one has to be personally invested in it in the same way. Of course, everyone basically knows where they stand anyway, but it's rude to say it outright! If you had a group of guys where one buddy was unathletic and low-income, everyone in the room would know he's low status, but it's still a dick move to explicitly point it out.
This gets at the heart of it. It's not that it's unusual to rate people by attractiveness, as everyone does that implicitly if not outright explicitly. But people still don't like that it occurs, and some people will be rated lower which when combined with humanity's natural "MUST PROTECT WOMEN" impulse creates situations like this, where an entire country explodes at the very normal behavior of some random adolescent boys.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
One of the cringiest faux pas of my lifetime was rating every single female classmate in my 7th grade yearbook. Which was then found and passed around.
There was something deeply distasteful about a mid bro such as myself a) exhibiting how thirsty I was for some of my female friends b) quantitatively showing how unattractive I found others. Even for children this was a bit of a bridge too far, I didn't recover socially from it until 9th grade.
Since then I've migrated to a more progressive, binary system in which women are either a 1 or a 0. There's not as much fidelity but it leads to richer conversations about attractiveness anyway.
It is funny, though, how when it comes to ranking attractiveness women are so vicious and unrealistic compared to men.
I also have a far less charitable reading of "unrapeable" than OP - I think it's obvious that it means someone is too ugly to rape. This is still just dumb kids getting together to say stupid and hateful shit because they have underdeveloped EQ. This has been happening since forever, and it's not a sign of some endemic issue in Australian society. Fuck Marry Kill is a classic game.
More options
Context Copy link
It is bad taste for any group whose primary purpose is not a dating pool to systematically rate the hotness of that pool, no matter the gender.
These lists tend to become common knowledge, and some people will end up on the bottom part of the list or being rated an average of 1.3 out of ten (but people -- especially people going through puberty -- might also be uncomfortable being rated really high). If the victim had actually asked to be rated, this would be different, but in all likelihood, they do not prefer an supposedly objective (it's a number! numbers don't lie!) rating of their hotness to become common knowledge.
The outcome of these lists is not so different from writing "X is an ugly pig" on the blackboard. As that is bullying, I would classify creating such lists as at least likely to lead to bullying.
Men like discussing who is hot. There is no expectation that everything you say in a private or semi-private space becomes public. Your argument becomes close to saying that ranking any human attribute is in bad taste, because someone ends up at the bottom, which is bullying.
People discussing whether you're hot (or ugly) does not make you a victim.
It's been awhile since I was in elementary school, back in the previous century, but even that far back, the whole "self esteem" program we were subjected to pretty much endorsed something like this — you're great just the way you are, nobody is better or worse than anyone else, everybody's equally special in their own way ("which is another way of saying nobody is," to quote Dash Parr), everybody gets a participation trophy.
It's the "equity" mindset, the moral axiom that fairness demands equal outcomes for everyone; the same thinking that, when applied to identity groups, creates our "disparate impact" regime. And to many of its defenders, whether it's true, or even if it's a "noble lie," it's the only thing holding back horrific oppression. After all, you know who else once thought some people were better than others, back in mid-century Germany?
More options
Context Copy link
I think the bad-tasteness of it depends on the group size. Three people can keep a secret (if two of them are dead) and all that. If three boys want to spend their time fantasizing about their classmates, that is very different than if three quarters of the class participate in the ranking, in my mind. (I don't know what the participation rate for that spreadsheet thing was, I am trying to make a general point.)
I don't think having rankings is necessarily bad taste. I am fine with men ranking porn stars (or participants of a dating show) by their hotness, or athletes by their speeds, or competitive eaters by how many burgers they can eat, or students by how well they did on their last math test (even though I would prefer to just tell everyone their outcome and the overall statistics in that case). In all these cases, the ranking is kind of relevant to the job. Don't want to be judged by your genitals? Then don't become a porn star.
I agree that not every inappropriate ranking implies bullying and victimization. If the bottom of the list gets rated a 4/10, the whole endeavor would still be slightly ill-advised, but victim-free. (Some feminists might disagree with me here, whatever.) If half the class coordinates to agree on an 1/10 rating for one classmate especially based on politics and this strongly influences how they subsequently treat them, that would be bullying.
More options
Context Copy link
More options
Context Copy link
Writing "X is an ugly pig" on the blackboard is writing it where X is likely to see it. The list was private and only exposed to the public by the authorities.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
You don't think many teenage girls rank male classmates?
I remember ranking boys in terms of cuteness (albeit ordinally rather than quantitatively) being a repeat conversation among some girls from age about 11 onwards. How else can you work out which boys you can date without getting bullied?
More options
Context Copy link
More options
Context Copy link
Another aspect of Australian life in which feminist ideology is given an outsized influence is this list of video games banned there, which doesn't cover even all cases of questionable Australian censorship authorities decisions. Atelier Totori was in other jurisdictions given at most a T rating, was in Australia rated as 18+, with the justification famously being "High Impact Sexual Violence". Some are RC'd due Australia's drug prohibition extending to fiction, but others for depiction of apperence of minor sexuality. Determination of who "appears to be, a child under 18" is subjective and fraught with many issues including racial bias, as a 25 old Anglo is on average more visually and vocally distinct from a 15 year old Anglo, than a 25 year old East Asian is from a 15 year old East Asian. Anime artstyle compounds this problem as it has less age indicators than a realistic one, meaning that if one determined to get a game or anime banned, it is harder to find evidence characters are of age.
Hilariously there have even been cases of works of art intended to viewed by women, such as "otome" games, deemed to be offensive to what is thought to be an interest of women as a class, Refused Classification and thus banned.
Further evidence of its feminist alignment is the censorship of materials of adult materials, featuring confirmed adults, if by some arbitrary criterion they are deemed to look too young. Why is this evidence? Because men do but women do not place a premium on youthful features.
As for the alleged mass murder of women epidemic in Australia: in 2022 and 2023 (ignore the irrelevant graph which depicts only a subset of homicides, look at the table) 168 men and 72 women were murdered there. "World Ends, Women Most Affected" doesn't capture the extent of pro-women bias in what is deemed relevant by the media, at least this (obviously ficticious) headline implies both men and women were harmed in equal measure, the present scare takes the less victimized gender and makes it the primary victim.
You’ve blocked me, so I don’t expect a response, but how is not wanting underaged girls depicted sexually in video games a “feminist” thing?
Think back 10, 20, and 30 years and recall that this has a never been a partisan issue, let alone a predominantly leftist demand.
That's the motte.
You don't want women to get raped as a result of wearing immodest clothing, do you?
I'm confused -- whose stance are you attacking?
I'm illustrating the motte-and-bailey by analogy.
"I don't want CP in video games" is the motte. "This particular censorship is desirable, at a minimum" is the bailey.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
It absolutely is a leftist demand, but it only applies to things that aren't western. Anime style can only be attractive to people who are pedophiles. Therefore anyone attempting to be attractive in anime style is appealing to pedophiles. When I think back 10-20-30 years nobody would give a shit about this at all. Sailor Moon would be re-edited for American audiences now with more modest clothing and all sexual innuendo changed to say "pickles... .. ... farthead" or whatever they change many modern japanese translations to say.
Because it doesn't matter it's just a videogame or an anime and only children watch those and if you watch or play them you're a child and probably a pedophile if you enjoy anything not western.
This is a huge vibe I get from literally anyone trying to crusade against "underaged girls" being exploited in the videogames. Of course they'd never say that but every other aspect of their political and cultural bent is left, they just happen to also think that underage anime girls presents some kind of major moral issue because they're fighting pedophiles.
Not many people gave a shit about trying to censor American Beauty and those that did certainly aren't the same people that give a shit about a 100% more tame anime visual novel coming out now that will get rejected from steam while "Hitler rapes all the milfs" will be sold without problem. A japanese visual novel will get rejected from steam for an underage girl wearing a towel for a scene but a western visual novel about underage siblings engaging in incest and cannibalism, that's fine, the art style isn't even anime. Or even outside of mainly sexual content something like the Witcher or Cyberpunk is fine for twitch but I can guarantee if the characters were anime-looking it would be banned, or maybe if they were simply produced outside of the western-okay-to-be-sexual sphere and anime-looking is just a happenstance.
Sure there are some hardliners that don't want any sexuality in anything and will side with the crusaders but the crusaders are faux fighting pedophilia and they're almost entirely left wing. Why? I don't know in either case but the only people that I've encountered that care and are happy when steam bans a visual novel that has like a two second scene of an "underage" girl in her underwear are all left wing, to the point that it's most of their commentary on reddit dedicated to it.
Looking at actual legal policy passed by politicians, the principle piece of legislation seems to be the PROTECT Act, which, among many other things
Okay fine, but that act includes lots of other provisions. Fine, how about the previous Child Pornography Prevention Act of 1996? I literally cannot find a record of a vote (if that sounds impossible, please, somebody show me up). I can, however, find the court case that ruled it unconstitutional.
The majority had 3 Republican justices (Kennedy, Stevens, Souter), and 2 Democrat (Ginsburg, Breyer), and one concurrence (Thomas (R)).
I find these examples more convincing than your vibes and lived experience, so I'll reiterate: being against virtual child pornography sees bipartisan support.
You're arguing about something that nobody was even asking about. The people that care about "underage" character in videogames have nothing to do with court cases. I honestly don't even understand how you even make that connection with what I said and someone talking about Australian games that are classified "poorly" or refused classification and court cases/laws from the United States. I'll trust my vibes over your info that is not about anything either I or the above comment were talking about.
Yes, I consider actual legislation passed to be more relevant than your vibes, simply because I never consider vibes relevant. A poll demonstrating that Republicans think virtual child pornography should be legal would certainly be even better.
Yes, the fact that I'm citing American legislation is off topic to what some@ was talking about, but it's perfectly on topic as a response to your comment, which discussed American audiences, an American film, and generic redditors, but never mentioned Australia.
To be clear, I wasn't passing on "vibes" that was your word I repeated and should have put quotes around. I was telling you that people interested in this moral crusade are left leaning based on my experience. Though, now, I entirely understand why that other person blocked you because you argue in bad faith by continually misrepresenting others' words to "win" an argument. No, the legislation that deals with child pornography has absolutely nothing to do with videogames that may or may not portray a child or child-looking adults as having anything sexually related at all as being the equivalent of pornography. Nobody is actually talking about pornography but you because you don't understand what we're talking about or are actually trying to misrepresent what we're talking about. The entire crux here is shit like "that anime girl's 17 and wearing thigh high boots, this is clearly sexualizing minors" even people that want to stamp this stuff out don't actually refer to it as pornography.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
If you’re talking about ‘ The Coffin of Andy and Leyley’, then the two title characters aren’t minors. They’re both in their twenties.
So, are 99% of the "underage" anime girls.
Maybe you're thinking of some particular subset that I'm not, but not that I've seen? Anime loves high-school, so a lot of characters are 16-18, and a fair number are 13-15 too. Reddit famously once (temporarily) banned subreddit mod holofan4life for posting a picture of Kaguya from the romantic-comedy Kaguya-sama in a bikini. (Presumably for "sexualizing minors" either because she's 16 at the beginning of the show or because her breasts aren't big enough.) Outside the school settings ages still tend to be pretty young and often feel like they were chosen at random, Yoko Littner is canonically 14, though it's not mentioned in the show. I'm less familiar with videogames but I think a lot of visual novels have school settings, and the characters in the aforementioned Atelier Totori range from 13-17.
Of course, the same is true for whole swaths of western media, like the teen sex comedy genre of movies, or teen dramas, both of which can have outright sex-scenes without anyone of note screaming about how that makes them "child porn". Some media from SJW-adjacent people will engage in the ridiculous business of deliberately writing characters to be 18+ because they believe it would otherwise be immoral to depict them sexually, but it's still not a mainstream taboo. Now, I think SJWs would probably go after those if they could get away with it (and probably have something to do with there being less teen sex comedies nowadays, though mostly for other reasons), but they're too obviously mainstream to act like they're doing something weird. Anime-style media is an easier target because any free-floating feeling of weirdness can be converted into talk about how something feels "creepy" for "sexualizing minors", without consciously thinking about how the same standards would apply to western media that doesn't feel "creepy".
My experience with this, mainly, are games that are refused from steam without explanation. This happens every few months and sometimes the people in them are children in a towel or underwear but sometimes there's absolutely no one underage in them at all. The tinfoil theory is there's someone that approves games on steam that thinks all anime games are pedophilic in nature. Maybe that's true or not there are quite a few people that are always commenting about how happy they are that steam is trying to put a stop to this stuff and they're always "SJW" when I look at their profiles. They do seem to think that even when the age is changed that it is simply a fig leaf like the little girl who is a 500 year old dragon. Which, to me, suggests that it doesn't matter what their age actually is because they think something drawn underage is underage. Though how they can tell the difference between a 17 and 18 year old anime girl is unknown to me.
Yes, I've heard about examples like that as well where the characters aren't even underage and there isn't even any real justification for calling them underage, and obviously they are a particularly telling example of the censor's mindset. (I'm reminded of how Patreon will periodically go after anime-style porn, like this pornographic animation of Hex Maniac, based on criteria that would include anything in an anime art style.) But I wouldn't call those cases the vast majority, a lot of censored visual novels are high-school romances and the like. It's just that standard is unjustifiable as well.
More options
Context Copy link
Per one of the VN translation companies, there does seem to be one particular reviewer ("Mary") who is disproportionately involved in visual novels that get rejected.
This arbitrariness in the enforcement of the acceptance guidelines combines with Steam's policy of not allowing edited re-submissions means that the process for publishing or translating an 18+ game on Steam looks like this:
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
It’s not a game where they have a warning “all these characters are over 18” despite being set in highschool.
Not only is their age stated during the course of the story, they are shown being spoken to as if they’re adults by their own parents. When they visit their parent’s home, the mum makes it clear she doesn’t either of them to move back in.
Their design IMO doesn’t strike me as appearing obviously underage. Based on the art style they look like young adults to me.
Yeah, and it shouldn't matter either way. If you think it's important to tease apart the minutiae of this example in defense of something that is clearly not pornography then I'll take this conversational detour as an agreement that people deciding that things need to be censored or banned based on a passing familiarity with the content should be ignored.
More options
Context Copy link
In non-Anglo countries people leave their nest later. In Poland, on average, if the mum expected they would back in, it would merely mean they are under 27.4. A test which expects such autonomy from characters to consider them adults, would have a high false negative rate when applied to media not produced in the Anglo cultural milieu.
This ties to my point that "perceived to be a minor" is culturally dependent and subjective.
Huh? The point is that they’d have to at least be legal adults for the mum to be saying that. The reason the mum wants them to fuck off is cause the daughter is a fucking psycho who the mum doesn't want to be around. It doesn’t really matter if they come from a culture where they normally kick their kids out at 18 or 30.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
You are unfamiliar with Sailor Moon censorship. And they actually did edit the art during the transformation sequences.
More options
Context Copy link
More options
Context Copy link
I admit to having never played Atelier Totori and have only played about 10 minutes of Atelier Sophie, but I'd be very surprised if any Atelier game had "high impact sexual violence"...
More options
Context Copy link
More options
Context Copy link
From the article, it is clear that the rate of both men and women being murdered by intimate partners has decreased by a factor of about two since the 1990s.
To be sure, of the 0.45 Non-Indigenous women killed per 100k, 0.32 are killed by an intimate partner, who is very likely to be male. I am not sure what could be done about that, though. Encourage more women to join gangs so that they are more likely to be killed in gang warfare, like presumably the males (for whom the murder rate is twice as high, but only with a small fraction being perpetrated by intimate partners)?
In general, the price we pay for freedom is that sometimes people elect to do bad stuff with it. In theory, we could save a few women's lives by outlawing heterosexual relationships or locking up all men. In practice, that would not be worth it on a QALY basis.
If being murdered is among the ten leading causes of death, then we could consider talking about an epidemic. Traffic deaths are between four and five per 100k. We should roughly care five times as much about that than we care about murders (which should still not be a lot).
Also, Indigenous women are murdered at six times the rate of their non-Indigenous peers!!111 Should the intersectionist woke crowd be all over that fact?
More options
Context Copy link
More options
Context Copy link
The response and escalation of this whole thing is completely disproportionate and seems to be part of the recent 'Violence against Women' moral panic.
Frankly I find it pretty disgusting that the politicians and media have used this to get some easy free points at the expense of minors. Meanwhile kids are running around stabbing people and it doesn't draw the same level of vitriol that these boys did for their poor choice of category names for their ranking system.
Edit: Two of the boys have now been expelled. Can't really blame the principal once it exploded in national media, but I think this should have been a suspension at worst.
More options
Context Copy link
My annoyance with some of the other issues here aside, what exactly do they imagine is to be done about the supposed epidemic of women being targeted for violence by men? Is there really a generalized belief that the problem is insufficient scolding or insufficient laws targeting this variety of crime? Men killing women seems to have basically two main categories - partner violence and random violence from serial killers or impulsive psychopaths. The latter variety is about as looked down on and prosecuted as reasonably possible and the only thing you can really do to go even farther is being quicker to lock up psychopaths and never let them out of institutions. Partner violence could maybe be addressed by being quicker to lock up men found guilty of these sorts of violence. I quite literally cannot imagine that a more scold-heavy culture would improve either of these.
If you want to lock up obviously violent men, that's fine, the broader right will probably be happy to work with you on that. Be prepared for the usual socioeconomic splits though - this is mostly not actually a problem of posh teenagers snapping and killing their girlfriends. If you're not willing to lock up violent people, there is pretty much nothing else that's going to have any meaningful effect.
Their response, if you could get down to the heart of the matter, would be: the thought that everything is stuck like this forever, that nothing will ever change, is too much to bear. So we have to believe that more education and more feminism and more shaming will fix all the problems, for the sake of our own sanity.
More options
Context Copy link
It's classic anxiety behaviour. When one is worried about X, but doing something about X seems hopeless, then worry about Y instead, provided Y seems X-ish and it seems like progress on Y is more optimistic. Politicians are under pressure to do something about women being murdered. This is something, and it's "kinda about" women being murdered, or at least violence against women, or at least implied violence against women, or at least violent words about women, or at least nasty words about women. By the supposed transitivity of "aboutness", that's about women being murdered.
More options
Context Copy link
It makes sense if you hold to the belief in strict blank-slateism.
More options
Context Copy link
More options
Context Copy link
I would wager that the point of this story is to shame Australian men in such a way that they fear male camaraderie. The story creates a fearful negative association with male solidarity, as when men get together they often discuss women. If men in a Western country decided to form male-only groups, this poses a problem to feminism — which then poses a problem to globalism and progressivism. The act of men getting together to judge women would greatly reduce feminism, promiscuity, all sorts of things, which may be seen as problematic.
Anyway, if Australia wanted to tackle gender violence, they need to do something about their aboriginal problem, because they are “32x more likely to be hospitalized due to family violence”. Next they would want to study their Somalian population, and possibly reduce all migration from that country. After that, eliminating alcohol culture would be the best big step.
The Australian govt is great at doing things with Indigenous issues, there's no shortage of activity! Only results fail. We shuffle the welfare system around from time to time. Cashless to non-cashless benefits and back again, trying to lower the drunkenness and violence. Every so often we put down a youth curfew in horrible places like Alice Springs and the Northern Territory. When the Right was feeling brave they tried a big crackdown. When Left were feeling brave, they tried for a referendum to enshrine indigenous legal bodies in the constitution. Nothing worked, though I'm sure many public sector jobs were created.
https://en.wikipedia.org/wiki/Northern_Territory_National_Emergency_Response
https://en.wikipedia.org/wiki/2023_Australian_Indigenous_Voice_referendum
More options
Context Copy link
More options
Context Copy link
No. It implies that any girl rated higher on the list might receive consideration for rape by someone.
(But in reality, it's just used because "fuck" has lost all its sting, so "unfuckable" is no longer edgy enough)
More options
Context Copy link
If the major objective of a system is to protect the interests of the powerful people that lead the system, then it is logical to say that a feminist society exists to protect the interests of women, and that means protecting them from one of the worst sins, the attack against the faux-equalitarian women's morality system.
It is all longhouse, all way down.
More options
Context Copy link
Adolescent boys doing something awful and insensitive(and it was) is not a major news story, so I think this is being promoted to fit the narrative.
We see the same thing in the US with anything that can be spun as anti black or police brutality.
More options
Context Copy link
Fun fact - women are way way more critical of other women's appearance than men. In men's category waist, normal weight, clear skin - and you are stable 7. I had some of my female circle declare a 20 year old, tall, blonde, cute, normal weight, nice ass, blue eyed, B-C cup that I was interested in as completely unattractive because of her - wait for it - slightly bigger than average nose. She was also very nice/polite and smart.
And they will tell me that we are objectifying women. Yeah right.
That’s partially because women are more neurotic and partially because they’re competing for men. Men can be pretty harsh on each other and themselves if they’re neurotic and insecure about attracting women, see incel forums obsessing over shoulder to hip ratios and canthal tilt and jawline mewing and cheekbones.
Like men, women often misjudge what the other sex is attracted to (for example most men prefer women who have thicker hourglass bodies, like Sydney Sweeney or Christina Hendricks, to rail thin models, and most women prefer a guy with lower bf% to a roided beefcake type), but I don’t think most women are delusional enough to think a 20 year old skinny tall blue-eyed blonde woman unattractive to men.
Since "low bf%" and "roided beefcake" are not mutually exclusive, this is an interesting view into the female view of men.
By roided I don’t just mean bodybuilder physique, I also mean the distended stomach, like what Joe Rogan has which people say is a result of steroid use. Muscles help but they’re not a significant factor as long as he’s neither skinny fat nor actual fat. Henry Cavill is hot because he’s tall and has a great face, if he had the physique of a runner or something it would make minimal difference, that was my point.
I don't think this is true. He's got a large, wide frame that he'd continue to have even if he had a runner's physique, and women like large frames. If he was about a foot wide in the shoulders nobody would think he's attractive.
John Hamm is a good example of this. He's a handsome guy and looks good in a suit because he's got a large frame. His actual physique is similar to a sack of potatoes, but it just doesn't matter (yes, it never even began for framecels).
Yeah I agree, broad shoulders are important too.
More options
Context Copy link
Both Hamm and Cavill are "face attractive" hall of famers, as well.
I agree with everything said about frame size. Add in above average height (that mythical 6' barrier). With those basic ingredients, your next step is building a social status and generally signalling competence and potential (good career, respected by beers, etc.) There are interesting memes that float around the gym-bro internet (these are my people) the hint at the enduring loneliness even after years of "looksmaxxing." Lots of this is tongue-in-cheek, however, the hinted at truth is that, beyond a basic level of fitness, you hit diminishing returns quickly save for those women who really geek out over biceps or something. Especially as you round 30, you need to have all of the "longer term" attributes going as well - career, social life, etc.
But then there are the likes of Cavill and Hamm. These dudes won the genetic lottery. Hamm is notorious for his dad bod. But his face is so epically GOAT'ed (as the kids say) that I think he's largely responsible for the phenomenon of women saying they like dad bods. Think about it - it's not so much a woman saying she wants a dad bod as saying "If he looks like John Hamm, I don't care about him going to the gym." Pretty girl privilege is real, but I also believe that four-standard-deviations-of-handsome privilege is also real for men. I mean, that's the whole plot of John Hamm on 30 rock
This is a better stated version of what I was trying to say.
More options
Context Copy link
you know what they say: in America, first you get the frame, then you get the respect of your beers, then you get the women.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
The pot bellies are a result of HGH abuse.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
To be fair, canthal tilt is a really big deal (and yes mine is that of a god).
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
Why is this more offensive than ranking people according to academic or athletic ability? Why is this considered offensive, but describing an individual woman's attractiveness is not? Why is putting multiple women onto a single list to compare them worse?
I find this somewhat baffling. There are numerous references to violence against women and sexual assault in the article as though the connection, which I cannot identify, were totally obvious. As fast as I can see, this list is totally innocent and their right to freedom of speech gives them the right to do this.
Because all animals are equal but some are more equal than others.
Australia recognizes no such right. Also, the people who made the list are generally recognized as subhumans [due to their age], so nobody's expecting them to have rights in the first place- the hysterics are because lists like that are hard evidence the brainwashing campaigns were ineffective.
Don't all countries with legal systems based on the English common law have freedom of speech?
English law doesn't even recognize that concept; the US's notion of protecting it was a reaction to it being non-existent.
Later nations gesture vaguely at the concept, but if it's in their law, it's always explicitly prefaced with "unless we really don't want to".
English law does recognize the concept, since it’s part of the ECHR which is British law. But the ECHR does caveat hate speech, dangerous speech and so on.
Yes, that's what "no right to free speech" means.
Sure, but that isn’t no understanding of free expression, it’s just a different one. For most of the history of the US states had various laws banning various kinds of speech, so did the federal government during the wars. Absolute free speech is a 20th century interpretation of the first amendment.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
That's not true. There was a debate in the US over even including the bill of rights because those rights were considered to already exist and it was worried that including it would imply rights not listed did not exist.
In Canada, our Charter of Rights explicitly lists "freedom of expression", but there was also a law passed earlier recognizing an already existing "freedom of speech" and there are court rulings stating that this already existed as a quasi-constitutional right emerging from English common law.
S. 1 of the CCRF is the explicit "everything after this section is functionally meaningless" part. It's difficult to miss, being at the top and all. And if that wasn't enough, there's S. 33 (which normally gets used for provincial vs. federal slapfights).
Well, given how they treat the rights that are listed...
What I'm saying is not true is your assertion that the US's notion of protecting freedom of speech was a reaction to it being non-existent.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
In Australia we have 18C. Speech is free so long as you're not racist. Plus we have pretty aggressive anti-defamation laws.
https://en.wikipedia.org/wiki/Section_18C_of_the_Racial_Discrimination_Act_1975
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
Same reason why women can denigrate men based on their height but men can't judge a woman based on her weight, even though one is a mutable characteristic and the other is immutable.
For a woman, a lot of her social status and worth does stem from her appearance. To insult a woman's appearance, or to even rank her lower relative to her peers in terms of attractiveness, is to denigrate her very existence. Their looks determine who they get to date, who becomes friends with them, and how people treat them. A woman's academic or athletic ability relative to her peers is not as important since women aren't competing with each other on the basis of academics or athletics, especially when it comes to the dating market. Also, women are more neurotic and take these things more personally than a man would. A man that complains women call him ugly would be labeled a loser and an incel. A woman complaining is a victim that needs protection, and being a victim (only for women and minorities) gives you social brownie points nowadays.
Notice it's not really men pushing against this sort of ranking, it's mostly women. The only men that do are male feminists or men who have to criticize in lieu of reputation harm.
More options
Context Copy link
What’s different in this instance is the systemization of it. Sure, everybody knows men find women varying levels of attractive, but I think keeping a logbook of all the women you know and their rating would generally be considered ‘freak behavior’. (Think of Don Giovanni.)
There are many things that are not inherently bad, but signal some maladaption, and they often involve specifically codifying vague norms. If you found out a friend keeps a ranked spreadsheet of everybody he knows, and writes down his judgements of all their actions, that would be understandably off putting. Sure, it’s something we all do unconsciously, but the very act of making it explicit causes problems.
The connection to sexual violence likely comes from the ‘unrapable’ label. It’s clearly implying that the boys are contemplating the ‘rape-ability’ of their classmates. Even if it is an edgy joke, it’s absolutely unacceptable from a school’s (and likely parents’) perspective. The same spreadsheet ranking them from 1-10 would still warrant action by the school, but likely wouldn’t reach national news levels.
Like what? I agree that it's weird, but I don't see anything wrong with it.
Because it prevents you from having a normal social connection. That type of thing is best mediated through interpersonal contact, because that’s how we evolved to deal with it.
It’s one of the reasons people behave radically differently online than they would in person.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
I'm not sure it's as complicated as that. Observing girls from a distance and sexually commenting on them is pretty archetypical "creep" behaviour in most people's minds. You could remove the ranking element - these guys could have been compiling a list of all the girls who they fantasise over and dream of naked - and the reaction would still probably have been "eww" from most of the girls involved (unless the guys were particularly good-looking or had high social status). Throw in the concept of some of these girls being "un/rapable", the dominance of progressive ideology in schools and the media, how easily this can be framed in terms of the widespread panic about the influence of people like Tate, and maybe a slow news week, and I'm not surprised this event got picked up in the media.
I think you're getting at an important point. People don't like to think that others are doing things to them mentally. We make a compromise - don't make your thoughts other people's problems. If you want to masturbate to a classmate, you can't be stopped, just don't tell them you did that.
Of course, the pronoun/trans thing is a deliberate and willful violation of that compromise.
(That the faction most supportive of breaking that compromise in that way is apoplectic when anyone else does it is... illustrative.)
The appropriate analogy would be "don't tell a trans person you don't think they're the gender they claim to be", not "don't tell people their evaluation of your sex doesn't match what you say it is".
No, this is more "you can think you're [opposite gender] in your own head/in private, but there's no valid reason to do that in public outside of wanting to make it someone else's problem".
Going out and screaming "it's ma'am" in people's faces and insisting that "because I think I'm a woman, that means I get to be classed as one in their sporting events" are, in my opinion, central examples of "making your thoughts other peoples' problems", and is as intentionally destructive/disruptive as publicly announcing you're using hot-or-not on people when they interact with you. (Same thing with casual racism/sexism/ageism, come to think of it.)
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
Wasn't this how Facebook was conceived initially?
More options
Context Copy link
More options
Context Copy link
If the weather seemed especially treif/haram this weekend, it is probably due to all these flying pigs. The guardian published an article on antisemitism in the US student protests which actually tries to be somewhat balanced.
They acknowledge that there have been unambiguous incidents of antisemitism.
Then there are gems like this:
Of course, if issue one is "a work of literature containing rape" and issue two is "an Israeli student encountering protesters who say stuff like 'Zionists don’t deserve to live', I have my own ideas which of these I would classify as "making one feel uncomfortable" versus "making one feel genuinely unsafe".
I think that this illustrates nicely how most of the protesters are in it for the signaling value. This is not uncommon, after all, many things we do are mostly for the signaling value. My own position that Israel should do more to minimize civilian casualties while they crush Hamas is probably something a majority of US voters could get behind, but boy is it lackluster from a signaling point of view. A student protester expressing this opinion would not get any respect for their bravery from their peers. On the other hand, calling for an intifada might be utterly devastating to the aims of the protests, but it will earn the one expressing it a lot of respect for being so brave and likely get them laid.
While I am sure that there is some antisemitism, I'm annoyed by this being the standard for whether people that are trespassing, camping illegally, detaining others illegally, and so on are worthy of condemnation. I really don't even care whether what the mostly peaceful protestors are on about, whether I agree with them just doesn't actually play into whether I want them to knock off the nonsense. If you're trying to camp in a park, cops should show up and inform you that you that you're not allowed to do that. If you insist on doing it anyway, they should arrest you and remove your stuff from the park. The idea that the basics of evenly enforced law are up to whether the scofflaws are antisemitic or not is absurd (and plainly anti-constitutional).
I'm honestly getting sick of hearing the word 'antisemitic' as if this is some major moral standard that matters. It is honestly starting to make me...anti-semitic.
I'm a Catholic. If I were to imagine s/anti-semitism/anti-Catholicism/ for all of these things I keep hearing from official government sources, or from the news media (but I repeat myself, hey, oh!) it would just make me laugh. Imagine Karine Jean Pierre starting off her daily press briefing by talking about the "concerning rise of Anti-Catholic sentiment in The United States" or how "Anti Catholicism is never acceptable" or can you imagine the congress passing a law condeming "anti Catholicism" or changing some educational standard to make it so that public schools were required to teach students that Mary was born without original sin?
You know something funny happening in my neighborhood: there is some kind of Jewish center here for students. Since October 7th[1], there has been a police officer posted outside of this building every day, seemingly 24 hours a day. And yet, my house, 2 blocks away, routinely has things stolen from the yard, has had people attempt to break into it, etc. My Church, a few blocks away again from this Jewish student center, has had to put up a large fence, and get our own security to watch over things during mass. What the hell is going on here?
This stuff is ridiculous to me. Yes, don't hate the Jews for being Jewish, but also...you can absolutely criticize anybody for anything; this is America. This is one of our founding ideas.
[1]: I hate having to constantly say this, but October 7th was probably the most horrific thing I have ever seen. Just maximally horrible and brutal. I get why the Israelis want revenge for this. I just don't think I should have anything to do with it, and don't think I should be funding it.
To understand why "antisemitic" is an issue, you first have to understand that whether a protest is acceptable has little to do with the particular tactics of the protestors. Within a very broad range, protests for acceptable causes are acceptable even if they are disruptive or out-and-out violent, while protests for unacceptable causes are unacceptable if the slightest excuse can be ginned up. The argument over "antisemitism" is an argument over whether these protests are in the first class or the second.
More options
Context Copy link
I see where you're coming from, but the history of anti-Catholic animus in the United States isn't short: you could point to reactions to Irish and Italian immigration, or more recently Hispanics. The Klan was, among many other things, anti-Catholic. Things like arson of churches (some Catholic) isn't unheard of even today.
And I say this as not-a-Catholic. On the other hand, we largely seem to have overcome this bias, and few seem worried about Biden's allegiance to the Papacy. This is probably for the better, and IMO a good model of what real integration looks like: I haven't seen any third generation Irish immigrants try to claim victimhood on the basis of Catholicism, which is probably better for society as a whole.
More options
Context Copy link
And if you lived in Northern Ireland or somewhere else where Anti-Catholic sentiment resolved into both government and private action against your faith and Catholics? Or perhaps even 60 years ago in the US.
The reason it makes you laugh is because you haven't (presumably) lived somewhere where that sentiment creates action. And indeed, as part of our move away from that, we did have to say mandate a specific percentage of Catholic officers in the police, and increase funding for integrated faith schools and the like. The US is pretty well integrated when it comes to Catholics vs Protestants, but this is a fairly modern occurrence.
Just because the idea of Anti-Catholicism makes you laugh, doesn't mean that it can't be a problem if it actually occurred. Even just 20 years ago my brother marrying a Catholic was a huge scandal in my extended family. And my uncle still needles her about cannibalism, from time to time, though these days only when he is drunk, because my brother will kick him out.
Now there certainly can be an argument that the fear of anti-semitism in the US is overblown but I would caution against underestimating just how much sectarian problems Catholics can face.
How many Catholic Churches were burned in Canada in the last 4 years?
AI search says 33 odd churches, CBC says 24 of those are confirmed arson, and approx. half were Catholic. So 12 or so by the look of it.
Hope that helps!
That seems substantial to me!
Without the context of how common arson is generally it may or may not be substantial. Plus we'd have to know the relative ratio of Catholic churches to other churches in order to know if half those being targeted means Catholic churches are at greater risk than churches generally (so Catholics are being targeted specifically for being Catholic).
More options
Context Copy link
More options
Context Copy link
Maybe don't trust Gemini with that question
https://tnc.news/2024/02/12/a-map-of-every-church-burnt-or-vandalized-since-the-residential-school-announcements4/
Note that "100 Christian churches in Canada have been vandalized, burned down or desecrated" is a different measure than number of churches burned down. Your source lists around 50 churches that with a fire or arson attack. Of those it lists around 27 as destroyed or razed, with another few have no description of the severity.
My count only covered those burned down. 33 looks to actually be consistent with your source as well using that metric.
So perhaps adjust your trust in the AI counting somewhat?
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
For a few years now my state has had a bill to do away with priest penitent privilege. They don’t have the votes yet, but they’re close.
Does that law not equally apply to Protestants? I haven't needed it, but I seem to recall hearing that it did in my jurisdiction a while back.
Very few Protestants do confession. Fewer still treat it as an inviolable sacrament that demands excommunication for those that violate the confessional seal.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
Sure, anticatholicism is not a particularly serious problem in the modern USA, but neither is antisemitism- I think that’s his point.
Yeah my point is that he is probably a little too blase, about anti-Catholicism, history shows it can spill out quickly. Which is why I would certainly endorse the US being aware of that. It wasn't too long ago where it was actually open. As I said when we were talking about Christian nationalism, I think there is an underlying wedge there that can get worse.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
I think you’re underrating the possibility of this being paid for by some kind of Jewish organization- off duty and uniformed police officers are common high end security and Jewish organizations are both wealthy and paranoid.
My Catholic Church has police presence during Mass because we pay for it. I really don’t think that this is a religious prejudice.
In at least some cases, those are being paid for by the federal government through the Nonprofit Security Grant Program.
More options
Context Copy link
The nonprofit security grant program (NSGP) almost entirely goes to Jewish groups, including Synagogues. Jewish groups have recently lobbied for massive increases in these grants, which have been $275-305 million the past couple of years due to the lobbying by Jewish groups.
I also wrote a post about the ADL's "Day of Hate" hoax which directly coincided with a successful lobbying effort by ADL and other Jewish groups to massive increase the funding for that program.
That security outside the Jewish community center mentioned by OP is almost certainly paid for by DHS and American taxpayers.
NGO corruption and special interests is not the same thing as what’s implied; at least theoretically the first Baptist church of wherever could get access to the NSGP, it’s just that Jews are better at skimming from the government by, like, a lot. The local government didn’t decide that the ‘Jewish student center’ is more important to protect than the Catholic Church, the ‘Jewish student center’ hired an off duty police officer with grant money that got laundered to it.
It’s politically convenient for both sides to pretend that largely nonexistent antisemitism is a major problem, but that doesn’t mean the government chooses Jews as winners over everyone else.
We do not know that at all. I'm sure there are a lot of Christian churches who would like handouts from the Federal government, you think they are just leaving money laying on the floor by not filling out applications?
Jews lobby for federal funds that almost entirely go to Jewish organizations, that is absolutely the government choosing Jews as winners over everyone else.
More options
Context Copy link
More options
Context Copy link
From wiki:
This seems like an odd thing to do if the whole thing is a Jewish scam.
More options
Context Copy link
More options
Context Copy link
Synagogues in Australia do this - I believe the guards are mostly volunteers who are trained on the synagogue's own payroll.
In the past I found it a bit odd, since noticeably mosques and gurdwaras don't do this, despite Muslims and Sikhs also being religious groups that are widely hated, and which are actually more publicly identifiable than Jews due to their headscarves and turbans, but since October 7 I have re-evaluated a little and am more understanding of Jews feeling a need for special security.
I suspect socio-economic factors also play a role - Australian Jews are on average wealthier than Muslims or Sikhs, and thus more able to pay for security. It's also possible that the fact that Jews are indistinguishable in everyday life makes synagogues more vulnerable to random attacks, not less. If I want to attack a Muslim or Sikh, it's relatively easy to identify one on the street and then attack them when they're most vulnerable. (To be fair, most attacks on Sikhs are a result of people mistaking them for Muslims - actual anti-Sikh sentiment is quite rare.) However, if I want to attack a Jew, I need to go to a bit more effort to identify who's Jewish, and observing people going to synagogue is a good way to do that.
Eh, there was the mosque in Christchurch, NZ. That didn't have a cop out front, did it?
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
Don't worry, The FBI will happily send one of its friendly agents to 'protect' your Catholic service - no invitation necessary!
Tradcaths are extremely overrepresented on the far right which does on occasion advocate for political violence. Seems very cringe for the GOP to spend years being completely fine with the FBI spending billions infiltrating random mosques and then get upset when they target extremist tradcaths who openly advocate for violent revolution online. Obviously it isn’t any substantial percentage of tradcaths, but the same is true for Muslim extremists.
Where?
If you are going to seriously compare even the rhetoric being put out by Traditional Catholics and Fundamentalist Muslims, you really need to back it up with something.
It wasn’t even close to the same level, though. The FBI has hundreds, possibly a couple thousand people full time on Muslim extremism in the US; meanwhile they made a couple of reports and had a few agents look into the tradcaths. That’s not the same investment at all.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
IIRC the actual plan was to send FBI agents to infiltrate tradcath communities and hope they would squeal on other far right wingers, not something based on the idea that tradcaths were going to start a race war themselves. It’s hard not to notice that FBI agents would likely stand out quite a bit less among broadly middle class and socially conservative suburbanite tradcaths than among, say, prison Nazis or deep rural militia types.
My community’s source in the DHS tells us that this plan failed because the agents just kept going native.
"This Jesus feller's got a few good goddamn points! Oh - sorry"
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
I think the word is even worse than you think; it's not just that it's being overused, it's that it's so wrong.
What does 'Semitic' mean? It's a linguistic term for referring to people who spoke Semitic tongues. If Hamas is anti-Semitic then they might as well be called a "self-hating" group, since Arabic comes from the same Semitic family of culture as Hebrew.
What does "Anti" mean? It means to oppose something; but to oppose doesn't mean "a wish to destroy each and every single one of it's advocates". It's why it's so obtuse and disingenuous to use the term "anti-trans" to refer to someone who opposes any of the trans lobby's social and institutional takeovers; since the term "anti-semite" is the biggest culprit of "antis", you're basically implicitly putting someone who thinks male serial rapists who all the sudden identify themselves as female shouldn't be in women's prison in the same camp as someone saying "We should lock all transgender people into death camps and exterminate them until none are left alive, and hunt down all those who got away to the end of the world".
Gustavo Perednik, famous historian of Judaism and philosopher (who I met once!), uses the term "judeophobia" to describe this feeling, which is better because at least the targeted group is being accurately represented, but I still think it comes short; fear isn't the root of what we're talking about here. Guys who rub their hands on their shoulders after shaking them with someone gay can be called homophobic since he can be understood as being afraid of them; someone who wishes to place restrictions of homosexual behaviour on public places, put gay people into ghettos and make conversion therapy compulsory (or worse) isn't being homophobic since he isn't operating out of fear, but disgust and hatred.
The only "marginalized" group who's had the dubious luck to have the correct term for people who despise them are women: misogyny (ironically, they are also a group who despite all their oppression have never been a victim of genocide! "Women, can't live with them..."). Some times it can be over used (oppressing women of the "keep them in the kitchen" variety isn't misogynistic; raping, murdering them and treating them live slaves of the opposite sex is), but if you want to imply hatred or disgust of something, that's the correct prefix: "miso". Hence, the prefix "miso" should be used to describe someone/something that holds a group of people in contempt.
The result being: a force like Hamas, who wishes the genocide of Jews, should be described as miso-Judaic or having miso-Jewry at it's core. I think anti-judaic is a ludicrous label to place on someone chanting "They've got tanks, we've got hang gliders, glory to all the resistance fighters": it's a valid way of describing someone who mows the lawn on Sabbat while rubbing it in its Rabbi neighbour face, or someone who doesn't stop making dumb jokes about its co-worker's yarmulke because he can't stand it, but I think it comes short of describing in accurate dimensions the feeling harboured by Nazism/Islamic supremacism.
More options
Context Copy link
More options
Context Copy link
I think there is a world of a difference between camping illegally and detaining others.
Believing in the rule of the law does not imply believing that every law should be rigorously enforced all the time. Just like I don't think you should go after every kid's lemonade stand for lack of a business licence, I also think that universities should have some leeway in deciding which of their student groups they tolerate having protest camps on campus.
I think as long as it is not the government deciding that would not be unconstitutional.
For example, a university might tolerate a protest camp to Save The Whales (as long as they do not single out Japanese students or something) but might decide not to tolerate a protest camp about God Hates Fags.
So the amount of antisemitism and especially the attitude towards Jewish students might matter a lot to the universities -- who I imagine are doing damage control. The question for them is if it is worse PR to call the police to dissolve the camp or to continue to tolerate it and thus to some degree be endorsing the messages they spread.
But it does imply that if every laws was rigorously enforced all the time, they should be written in such a way that isn't blatantly oppressive if taken to that logical-by-words-on-paper conclusion.
Otherwise you get
anarchotyrannyrule by law where we just ban everything and selectively enforce against political enemies, which is what we have right now.More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
With respect, it's more than just a signal. It's also staking out a coordination point for like-minded people to rally around and to pool efforts/resources. That coordination and massing of support, in turn, unlocks the ability to pressure weakly-allied parties into line, and intimidate enemies.
More options
Context Copy link
Interestingly this statement is said by a pro-palestine student protestor. The previous time I heard this sentiment was from conservatives criticizing universities for being too left-leaning/left-biased. The question is, would this student be just as supportive if someone came to their school to push far-right talking points? The difference between the two is that one side has far too many proponents of its idea explicitly calling for the death/genocide of another group and the other side gets their views and ideas framed as violence and calls for genocide. Also, in my opinion, the universities have been far too tolerant of one but not the other.
It's only tolerance if you tolerate the intolerable. It's only freedom of speech if you support the speech of those you disagree with the most. At the same time, is it morally/ethically inconsistent to choose to hold people up to their own standards?
It's pretty common for the leftists to take rightist talking points and throw them back, often in situations where they don't really apply. It's not that surprising they'll also use them against other leftists.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
The "S" in IoT stands for Secure
Boy, looong ago now, I broached the topic of security standards for techno-mabobs. At that time, I mentioned that the UK was considering some legislative proposals on the matter. I can't find the comment where I described what I viewed as the core driver of the tension over the topic - the culture of tech folks. That is, they are so used to the 90s consensus that software is gee wiz magic that is pure and sanctified, is the solution to world peace and all of life's problems, and can never possibly be the cause of anything bad, ever. The 90s conclusion was that government absolutely can. not. touch it. Hands off. No regulation whatsoever. No liability whatsoever. No matter what happens, they must have an absolute immunity stronger than even the strongest version that Donald Trump could have ever dreamed of claiming.
Justifications for this view have shifted, but I've always felt they've had a flavor of, "We can't be regulated! We're
autistsartists! We make unique snowflake masterpieces! We have to move fast and break stuff! If we're ever held accountable for breaking anything, even for the most egregious of practices, then the entire economy will grind to a halt!" Whelp, after years of incident after incident exploiting the IoT-of-Least-Resistance, including things like ransomware takedowns of major corporate networks and huge botnets of smart refrigerators, we're about to see how true that really is.Hitting the wire last week, the UK has dropped regulation for smart devices that are sold there. In my original comments five years ago, they were proposing three items; I had only asked for one (the most incredibly basic one - don't have every bloody device have the same default password). I really feel like it's a case of, "If you resist and throw enough of a shitfit over the really simple stuff, it's going to come back around in a much stronger way that you really won't like." The full document of "Baseline Requirements" speaks to fourteen items:
● No universal default passwords
● Implement a means to manage reports of vulnerabilities
● Keep software updated
● Securely store sensitive security parameters
● Communicate securely
● Minimize exposed attack surfaces
● Ensure software integrity
● Ensure that personal data is secure
● Make systems resilient to outages
● Examine system telemetry data
● Make it easy for users to delete user data
● Make installation and maintenance of devices easy
● Validate input data
● Data protection provisions for consumer IoT
Each area is broken down into one or more specifics. There's a helpful table on page 32, detailing whether the requirement is Mandatory, Recommended, and/or Conditional. This is important to know, because a bunch of them are truly just recommendations, but even many of the ones that are Capital M Mandatory are also Conditional, which is actually displaying quite a sense of care about the diversity of devices and possible situations. For example, they acknowledge things like "constrained devices", which is a "device which has physical limitations in either the ability to process data, the ability to communicate data, the ability to store data or the ability to interact with the user, due to restrictions that arise from its intended use". Here, they give some explicit examples, like "The device cannot have its software updated due to storage limitations, resulting in hardware replacement or network isolation being the only options to manage a security vulnerability."
I think this truly is a culture war between the culture of technokings and the culture of They Can't Keep Getting Away With This, and no culture war offensive ever comes without a counteroffensive. Will major corporations, either American or Chinese, bow the knee? Will they pull out of the UK in a weird, polar opposite anti-security stance to the position that has led other companies to pull products like Signal/Telegram from countries that threatened to make them less secure? The UK may be the sixth largest economy in the world by GDP, but that's still only about 4%. Will they go full tizzy and make separate products, where the secure versions go to the UK and the less secure versions go elsewhere? If they don't pull out and don't make different versions, than everyone in the world just got a huge security upgrayyyed. If they don't pull out and make different versions, other countries have a green light to mandate that they should also get the good stuff. So, if they're even thinking about pulling out, they've gotta rally the troops, punish any defectors, and really make the UK feel blockaded as a warning shot to the rest of the world.
My guess is that they'll bow the knee and just do this stuff for everyone. It's pretty much all stuff that everyone has known that they should be doing for quite a while now. Will it cost a little extra? Sure. Will they have to deal with some annoyed developers who feel constrained by law, as basically every other industry ever does, and eventually have to bring their culture into the Industrial Age? Sure. I doubt that having to pay $9 for a smart plug instead of $6 is going to change much about the economics of wiz bang gizmos... but it just might be a step toward not having newspapers filled with nightmare exploits causing millions in damage... at least not every week.
The cost of compliance -- which is to say, the reams of paperwork and signoffs necessary -- will make this impractical for startups. The large companies making this stuff will do it -- eventually, with the UK getting delayed releases. The Chinese knockoffs will continue to be sold unlawfully, and a lot of new stuff just won't appear in the UK at all.
Sneer all you want (I guess you're a Real Engineer), but I think a big reason bits have continued to grow while everything else has stagnated is the regulators haven't caught up with the bits yet.
My read is that they literally just need to fill in that table that I mentioned on page 32. That's not a lot of reams.
I am most decidedly not a Real Engineer.
Like I mentioned, we will see if the economy of bits will grind to a halt... or if they'll take the couple days necessary to not have a default password and to write "Yes, we don't have a default password" in the table on page 32. Perhaps you could formulate your prediction in numerical terms? Maybe something about growth rates in the tech sector over the next ten years? Maybe something about stock prices and how they'll reflect this immense stagnation? Or maybe an explanation for why the market hasn't already priced this in and had a massive drop in valuations in the past week in response to oppressive new regulation?
I don't think the "detail" required is going to fit in that table. So it's going to be a reference to some much longer document which explains each item, in language understandable to regulators. And then all this will have to be reviewed by a lawyer specializing in UK regulations. And every time a change is made to the device, the document will have to be audited to ensure there's still compliance.
Of course just this one document isn't going to do much, aside from make new IoT devices less available in the UK and other countries adopting it as mandatory. The more regulation in more countries, the more the works get gummed up.
The good news is that it reads like they're expecting that companies will just publish this document on their website along with other support documentation. So, it won't be long until we get to see some and find out whose prediction is closer to accurate. As for the prediction of availability, would you like to predict anything specific about companies pulling out of the UK market?
If it's really so easy there won't be any problems. But I'm pretty sure, given the absolute glee expressed in your original post, you know it isn't.
I don't follow your line of reasoning. Can you speak plainly, please?
Your original post expresses considerable contempt for "tech folks" and demonstrates absolute joy for us having regulation "dropped" on us "in a much stronger way that you really won't like." This really doesn't fit with an idea that you think the regulations will be anything like easy or simple to follow -- rather, you actually think they will be difficult and painful to follow and are joyfully anticipating the pain it will cause.
Yeah, regulation sucks. It's terrible that in the "real" engineering professions, you need a minimum 10 years of experience before you're allowed to do anything more than turn the crank on well-tested models to determine if some very slight variation of an existing thing meets all the requirements, and then fill in all the boxes on the paperwork to maintain traceability. Doing that has high costs; applying those costs to the software industry as a whole will cause it to stagnate.
This does not follow. It's just a non sequitur. It can be easy and simple to follow, but incredibly grating to the personality of "artists". They don't like coloring inside the lines, even if it's easy and simple to follow.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
I don't think you understand how this works if you think that this is the only necessary step once this becomes an obligation by law.
Since this is a potential liability, someone will have to be responsible for filling that form, and they'll also have to have sufficient means to enforce that the form is true. That person is most likely a lawyer and not technical themselves, which means they'll have to rely on auditors, which means not only that you'll have to pay money to get those audits done, you'll also have to find a company that will do them on the tech stack that you are running and is familiar with the intricacies of the particular legislation you're trying to abide by.
And once the bureaucratic machine gets started like this it doesn't stop, standards will get more complex, there will be people whose whole job is to ensure that they are followed and the costs will balloon accordingly.
Compliance is a huge industry. If following the law was that simple, it would not be.
Like Bastiat says, there is what is seen and what isn't seen.
What is seen is the valuation of established companies that have compliance departments and who'll be able to integrate regulation with a marginal cost change they can pass on to the consumer. What isn't seen is how much harder it is or will be to get funding for a startup that designs novel appliances because the costs to enter the market are now higher.
Weird. I hear about that from my friends in literally every other industry ever. They still seem capable of operating.
I'm always sympathetic to concerns of regulatory capture putting barriers to entry in front of small businesses. Totally agree that this is the single strongest argument against these types of requirements. I just doubt that these particular requirements are that onerous. Plenty of smaller shops that actually care about not being a security clusterfuck already do these kinds of things, and you can do most of them without too much difficulty as a hobbyist. In any event, if you're a start up that can't figure out how to not have a default password on all your devices, I actually kind of don't want you selling stuff, anyway.
Where is the innovation in any other industry over the past decades exactly? You know, since they brought these in.
How expensive is it to build a bridge now, versus a hundred years ago, adjusted for inflation? "capable of operating", what a joke.
As Kulak is fond of saying, the reason we don't have flying cars isn't that they haven't been invented, it's that they've been made illegal. They were commonly flown (and shot down) by teenagers in the 1910s.
This is the tired same equivocation that motivates all such regulatory barriers. I complain about having to fill forms, you retort about the justifications for the form existing as if I didn't also have such a concern.
There are other answers to the problems of humanity than increasing the size of the bureaucracy. Just no other that fits into managerialism.
Let's go with a simple one - the shale fracking revolution in the oil/gas industry. But nobody is actually going to go counting these things, because no one really has any sort of consistent argument for which sorts of regulations stifle innovation. Again, I totally realize that they do sometimes, in some ways. But what sort of massive innovation is going to be stifled by requiring devices to not have default passwords? Like, surely we can agree on that one. We could at least leave open arguments for other requirements, and I would welcome a wide-ranging debate on them. But if we're stuck with just theoretical arguments, totally disconnected from any specifics, in a way that can't capture basic truths like, "Being forced to not have default passwords is not a significant barrier to innovation," then we're not going to get anywhere.
Ok, so you also have a concern about default passwords. What are you going to do about your concern?
That is a fair one, but It's also a very good example of just what I'm saying. I was part of the few people on the quite unpopular side of the oil industry here in Europe in the 10s when it was banned, for the same reason I'm on this side of this issue now.
If the UK wants to make such regulations it will reap the same sort of benefits: no toxic chemical pollution or chinese crap botnets, but also no innovation in these respective sectors.
It's a choice.
You can not like that enforcing common sense rules to an industry through state mandates is a barrier to innovation all you want. It's not going to stop being true. The debate is only on the magnitude of the effect.
I don't buy chinese crap that spies on you, I tell people not to buy chinese crap that spies on you and I shame people who do so in my social circles.
Hell, I've spent years of my life writing symbolic execution software used specifically to make edge devices secure, some of which you may be using right now. What have you done?
So, will you then make a prediction along the lines of what I asked for in the OP? Are you predicting that tech companies will pull out of the UK rather than either upgrayyyeding their security practices for the world market or going with a dual product (one version that doesn't make absurdly basic mistakes for the UK market and one that does make those mistakes for the world market)?
And I claimed that being forced to not have default passwords will have an incredibly low magnitude effect on innovation. Do you actually disagree with this, or do we agree?
I do the same, but clearly that is not changing much about the world. Have you succeeded in changing the world through your evangelism?
Then I'm sure you will be pleased that this work won't be going to waste by someone shaving a few cents off of the cost of your product by putting a default password on it. Honestly, hearing this, I'm really not sure what your concern is. Is it that your company's "We're Actually Secure" marketing is going to be slightly less effective, now that the floor has been raised? Did you really think that such marketing was really of all that much value in the first place? @The_Nybbler thinks that it's completely a waste and that no one would spend one red cent more for your secure product. Do you think he's wrong?
More options
Context Copy link
More options
Context Copy link
Since we are talking about the UK, shale fracking is illegal there. Hardly a revolution.
Irrelevant. Obviously, people can choose to regulate something specific away. The question is whether there has been "any" innovation in "any" other industry (that is, the non-bits ones that have more regulation). Unless you're claiming that the US has no regulation on the oil/gas industry, the shale revolution, which literally has changed the world at a geopolitical scale, is a huge counterexample.
But there are many others. Space X. Ozempic. Etc. It's really hilarious to have all the huge techno-optimists, who think that AI and tech more broadly is going to revolutionize literally everything, and at the same time, they imagine that the tiniest amount of regulation on fucking light bulbs will grind literally everything to a halt.
More options
Context Copy link
More options
Context Copy link
This isn't exactly a revolution. The tech behind shale fracking was known for quite some time, it just wasn't put to use because the costs associated with it meant that it was uneconomical. It wasn't a major shift or technological advance that unlocked shale, but an increase in the cost of energy and a lot of financial chicanery that made it competitive with traditional fuel sources. There's a very plausible case to be made that the technology is ultimately a loser, and that the environmental damage it causes in the long run will be more expensive than the economic value derived from the crap fuels you get out of it.
More options
Context Copy link
More options
Context Copy link
what do you mean by this? A homemade airplane isn't the same as a flying car. I guess it could work if you live in a very rural, but the problem with airplanes is that you need a long runway both to takeoff and land, plus clear airspace. That makes them impractical for anyone living in a city. A flying car could theoretically fit in your garage, take off/land vertically, and fly carefully enough to avoid collisions in the sky.
A Sopwith Camel fits in a garage and can take off and land on a piece of uneven land 300m long. And that's with 1910s technology. Central Park is 13 times longer.
The reason we have long runways for planes these days is because they are optimized for speed and drag, not lift. Which means they have weak landing gear and swept wings.
We had flying cars, we have the technology, they're just illegal to operate.
See also the autogyro/gyroplane/gyrocopter, developed in the 1920s, which can use 75-foot (25-meter) runways.
More options
Context Copy link
300m long is more than three football fields! That is an absurd amount of space for anyone in a city, where we fight over parking spaces that are about 3 meters long. The one @ToaKraka linked sounds better, but 75m is still way too much space for most people. You also need enough space in the sky for othem to fly without running into someone else, which can happen at any angle in three dimensions. It could work for a select few, but... we already have that, with private planes and helicopters.
Besides, if we're going this route, why not bring back zeppelins? The Empire State Building was designed with a spire so zeppelins could dock on top, as were several other buildings of the time.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
Sure, and Harrison Bergeron could walk with a junkyard's worth of scrap metal stuck to him. It's a handicap, not necessarily a fatal one (though sometimes it is).
More options
Context Copy link
In the specific case of the UK, most industries are not doing well, I believe in part due to a regulatory environment that makes it very hard for anyone to do anything.
More options
Context Copy link
Eh... they vary a lot, both on context and use case. Requiring secure storage for persistent storage of security parameters (5.4-1) makes sense and has trivial cost for applications like a network storage device, but it'd break a lot of assumptions on FRAM-heavy low-power devices, and that rule notably isn't conditional or a mere recommendation -- perhaps they didn't think about FRAM, or other persistent memory, but I wouldn't bet against UK compliance checks taking that as an excuse. Making security-focused unique IDs tamper-resistant (5.4-2) isn't too bad on a device with a real MAC (though not costless; there are benefits to software-changeable settings here), but for the more ultra-small or ultra-disposable equipment that's largely going to mandate more and more of program flash be devoted to encryption keys (unless you want to decrypt something on discrete flash every time you're doing an update check). Mandating a network update happen over a trusted relationship (5.3-10) and be timely (5.3-6) and be automatic (5.3-4) isn't too bad for a situation like deploying a bunch of wifi access points or phones, as much as I hate 99% of implementations work, but it's an absolute mess for wide deployment public LoRaWAN devices, and a mess for things like CAN- or LIN-networked embedded devices.
Others vary heavily on interpretation. Mandating that "For constrained devices that cannot have their software updated, the product should be isolable and the hardware replaceable" (5.3-15) could mean almost nothing, or it could require vendors to commit to support any optional part of a product until they retire an entire series. And these all definitely kill EPROM devices that it covers -- I'd expect this ends up with a ton of explicit or implicit exceptions, mostly around the "On devices with several microcontrollers (e.g. one for communication and one for the application) some of them might not be updateable", but it's not really obvious from the text.
That gets worse if they start dialing Mandatory-Conditional or Recommended rules into plain Mandatory ones down the road, and a lot of the text suggests that they're planning it:
In particular, SecureBoot (5.7-1), hardware memory access controls (5.6-8), and guaranteeing cryptographic updates for the life cycle of the product (5.5-3) mean throwing out a lot of existing microcontrollers, microprocessors, and often related code. It's clearly intended for big GHz+ microprocessors, but there's a lot of new (mmu'd!) chips that don't have this capabilities. SecureBoot there's some arguable conclusions for some of the bigger devices, like throwing a ATECC608 after a PIC, but a) I'm not sure if that actually complies with the recommendation, and b) no, god, no. Hardware memory access controls... maybe ESP32 memory protect would cover it (though they're software-settable, though the software settings are code-private?). Wherever these hit, a lot of chips aren't going to pass it, and businesses focused around them are going to have to toss inventory and code -- there's just too much of this stuff that isn't portable.
A number are probably gonna have to start now on the off chance that it happens in a couple years.
Now this is the type of response I was hoping for! Actually engaging with the substance!
Perhaps they'll issue a clarification, but from the note in this section, I think someone could read this as "memory"; it has "memory" right in the name! In general, I do expect there to be some clarifications along these lines as folks like you bring up additional concerns.
This one is conditional, and I imagine ultra-small or ultra-disposable devices won't qualify in the first place.
Same here; conditional. We'd at least have to get down to the level of thinking about each of the devices you've mentioned in terms of the conditions.
Notice how they define isolable:
In the section describing the rule, they continue:
I think I would interpret this as, sure, you need to support any part of a product until you tell the customer that you're not supporting it anymore, and the type of support can vary.
Yeah, I have a feeling that these aren't going to pop into the Mandatory category for a while. The real good news is that concerns are really of the type, "Will they at some point make these Mandatory, when it is still too soon?" Because pre-rule-dropping, I imagine the worry would have been of the type, "Will they make this stuff Mandatory now?" And, they, uh, didn't. I think this document shows a pretty decent level of care in getting some of the really basic stuff right and showing the industry the direction they'd like to go in the future. There's no telling at this point whether it'll all actually go that way; one has to imagine that there are differing worlds where it seems more/less plausible to upgrayyyed these Recommendatations into Mandatory.
Whereas this one, I think is fine, given their explanation:
How easy is that? You don't even have to update it at all. But if you do, then at least make sure your shit isn't trivially broken, at least so long as you're telling the customer that you're still supporting it.
Maybe, but so does CMOS RAM, and that's a central example of where you probably do want this rule to apply, and it's (usually) more volatile than FRAM. 5.4-1 to my read isn't about access modes or media type, but about storage volatility, and that makes some amount of sense for certain attack vectors -- you don't want someone reading cloud passwords by probing random SPI flash, as weird as that particular threat is.
But it also makes a lot of design spaces for low-power devices goofy, in ways that don't make sense. There's probably a class of low-power device where it's a really critical security problem is someone delid the main processors and inspects individual FRAM cells during a toggle-off state, but 99% of the time even if someone could hijack a session id from that it's less big of a deal than having access to the board to start with.
Yeah, but the condition is only that applies where ever "a hard-coded unique per device identity is used for security purposes". I think that includes virtually every LoRaWan (DevEUI) and probably every LoRa device, for one common example, but also technically at least most Bluetooth implementations. There's other places where it's a good idea to use hard-coded unique identities per device for security purposes even where it doesn't 'matter', and that's largely going to result in people just dealing with stupid hacks instead to avoid triggering the requirement whenever possible.
Yeah, but the conditions for 5.3-4 is "an update mechanism is implemented", 5.3-6 "an update mechanism is implemented" and "the device supports automatic updates and/or update notifications", and 5.3-10 that "updates are delivered over a network interface" and "an update mechanism is implemented". These are fine when you're talking a full web-UI/app-equipped device, but twenty sensors on a LIN line that can be updated still hit the requirement for 5.3-4, which is on its own a requirement for automatic updates so you now hit 5.3-6. Then you're trying to figure out how 5.3-10 works for devices that don't have user interfaces (and may not have user physical access!), and now you're either stuck tossing an authentication layer on your LIN, implementing a cryptographic security function for comms on said LIN, or spamming users with update notifications like they were running Arch Linux.
Eh...
Let's take the example of a lightning switches attached to a base station, as a fairly common home automation setup where the switches and adapters are... not actually a central case of the constrained device model (they have wall power!) but are at least arguably close. If you build one of these, you're probably going to support a wide variety of light bulb sockets and switch types, but not all of those are going to make sense over the longer term -- maybe a socket type falls out of popularity, or a new lightbulb tech drops that doesn't play well with dimmer circuits, or a vendor you partner with stops selling a product that makes that particular device make sense.
By the text, is a lighting hub "isolable and hardware replaceable" if the vendor doesn't want to sell every attachment for the hub's life cycle? Removing one attached device doesn't make the attached device 'isolable', because turning on and off that light is its core feature. Nor is removing the entire hub from the internet, since there's no sane way to call that a "self-contained environment with other devices if and only if the integrity of devices within that environment can be ensured", when the especially if the entire reason to pop them off the internet has to do with their ability to communicate securely with the local hub. Would it be hardware replaceable is the only hardware replacement doesn't actually fit into the same socket, just because something attaches to the same hub?
Yes, in practice your interpretation is the sane one, and hopefully it's probably going to end up as the sort of asterisk that just confuses people, like vendors just putting out generic 'support may stop without notice for some devices' clauses. But at best that turns the requirement into aspirational text instead of the actual policy.
I think the interpretation of that standard is closer to page 45-46 here, if not on the exact same timelines, and that quickly turns into an eWaste and version hop mandate for a lot of stuff pretty quickly in order to theoretically prevent the plausibility of certain attack classes, rather than blocking trivial ones. But even for its steelman of "don't use WPA2-only chips in new products", I think it's still costly even if well-intended, and a lot of those costs don't make a ton of sense. There's a number of chips and equipment that can't connect on WPA3 at all, and even where it's something that can be implemented in software that doesn't mean it's exactly easy.
More broadly, though, it seems like overbroad application of a rule. A presumption toward encrypting everything makes sense when it's free or nearly-free, but there are a lot of entire devices where it's just not that relevant. If your equipment does literally nothing but relay temperature and humidity values over ISM bands, you might want some amount of authentication to prevent spoofing, but it's really not that big a deal if someone can listen in. And there's a lot of IoT stuff that goes into that category.
There's some parts of the rules that motion around this -- 5.5-1's "Appropriateness of security controls and the use of best practice cryptography is dependent on many factors including the usage context" or the exceptions for ARP, DHCP, DNS, ICMP, and NTP in 5.5-5 -- but again that turns the requirement into aspirational text.
Fair enough. Hopefully the worst case is that this ends up not being covered, even though it should be.
I think I can agree that there may be tradeoffs here for some devices.
I think these would almost certainly just be classified as "constrained devices", and they also give alternate mechanisms for valid trust relations, which I think will be what the automakers go for. They'll do the verification at a different step and say that the lack of physical or other access is what ensures that presence on the network is sufficient.
I think you're right that some portion of this is aspirational text, but I think it's along the lines of, "If you can just put some reason down on the table for why this should be considered aspirational text, then you're probably fine," and the only people who are at risk are the people who are doing the clearly and obviously boneheaded stuff. Like, I don't think it's going to be hard for the maker of a device that does nothing but relay temperature and humidity values over ISM bands to just say, "It's a constrained device; can't do any of that fancy stuff; pretty much no way in anyway," and we can all mostly go home happy. If we start having major corporate networks brought down by botnets of temperature monitors (uh, how?), then perhaps folks will have to figure out how to make it more than aspirational text.
In any event, thanks a bunch for really thinking through edge cases for a wide variety of really specialized and, for lack of a better term, really constrained devices.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
I've thought about this a lot in trying to bootstrap something in the bio space. Even if I moved to Prospera tomorrow to escape the oppressive FDA, the CapEx required to get something off the ground is absurd. Simplest of animal studies is 10k a pop for really simple studies and more like 50-100k for the real disease relevant models, renting a single lab bench a month for myself is ~3.5-5k (maybe cheaper now that the biotech market has cratered), basic reagents run from a few thousand/month to 10s of thousands depending on what you're doing. Anything with human cells necessarily requires a bunch of infrastructure to do cell culture. There's also very few projects that lend themselves to producing an MVP and moving some units to fund more R&D; these are all decades-long slogs.
I joined a bunch of DIYbio mailing lists, discords and slack groups and the kinds of projects they do are just sad. More fit for high school ed than tackling any real problem.
The fact that you can buy a nice desktop for a few thousand and hack away in a fetid, windowless apartment for a few months or years to build a functional product seems to uniquely support innovation and, most importantly, give aggressive young founders a chance to lead a company. I'm interested to see whether the shift to training giant, prohibitively expensive AI models will lead to the same dynamics we see in biotech.
More options
Context Copy link
Presumably bits continue to grow because you can throw more bits faster these days, compared to 5 years ago. That seems like a field that hasn’t stagnated.
More options
Context Copy link
More options
Context Copy link
I think a big problem that has come up for IOT products is that they’re much more common than they were in the 1990s and are often connected to critical infrastructure either for private homes or to cameras inside the home. It might not have mattered how hack able a system attached to a dorm refrigerator is when it counts the beers removed and orders more. It’s not a well known system in 1998, and even if someone got into it, the worst that you could do is either change the program to never order beer, or maybe order a lot of beer. Attach the same system to 100,000 homes and have it use your credit card to order food from Amazon and you have a lot of actual damage you can do. You can steal credit cards. You can order stuff and have the address changed to your address. You can muck with whatever system it’s using to order from Amazon. Connect an automated door lock on a dorm room that can be opened by smartphone isn’t as dangerous as the same system on the doors of a business or government building.
More options
Context Copy link
As a topic expert (despite myself, embedded is both fun and hell) I did not want and continue not to want any government standardization of software because:
Just make IoT doodad manufacturers liable for bad things that happen with them and the problem will sort itself out, no state intervention with the potential for universal surveillance and totalitarian control needed.
The real reasons people want to do this shit are economic and strategic, they don't like that the Chinese are beating everyone at the doodad game and want protectionism through the backdoor. It's the same reason you can't easily buy American ETFs in the EU, because they don't care to include the handful of made up documents that are mandated by law at the advice of European financial institutions that enjoy proximity to the rule makers.
Let us not mince words: nobody gives a shit about the end user here. This whole game of being "regulatory leaders" only works if the major players of the industry you are regulating actually want to help you prevent further competition.
You can have protectionism and regulation if you want, but you can't get that and innovation. You have to choose.
This is a very common opinion, but if you delegate the assignment of liability to the court, then you will get even more problems about state overreach.
Consider the following scenario: A consumer buys some smart lights for their house. The smart lights are hacked, and hacker uses these smart lights as a proxy to launch ransom-ware attacks against hospitals. The hospitals are collectively "forced" to pay $100 million in ransom to continue their operations. Who is liable in this case? The consumer who didn't put the smart lights behind a firewall? The hospitals who had employees fall for phishing emails? Or the IOT company for not updating the security of their devices? If you don't have legislation defining what makes someone liable, then unaccountable judges will be forced to legislate from the bench about who is liable and who is not. If you don't like the decision, then you can't just vote them out of office the same way you can with legislators.
Of course the problem of codifying responsibility doesn't magically dissolve if we oppose someone doing it.
Most of the issues raised by your hypothetical can be resolved by the content of the contract signed by the parties.
The only crucial thing that isn't there is what the standard for being negligent about your security is, and while I get the argument that it's easier to resolve if codified by politicians, I actually think it's fuzzy and contextual enough that it is better left to the courts.
I also am under no such delusion as to believe that I could vote legislators out of doing the bidding of the interests that pay for all of their campaigns. Judges might at least accidentally stumble upon some good sense and integrity. Politicians are constitutionally incapable of such things.
I do not want to live in a word where people buying a $10 device from walmart have to sign a contract.
That's too bad, because you already live in one.
I too hate that we don't distinguish strongly enough between computers bolted onto appliances and regular appliances. It's confusing. But when your fridge is actually a computer with a delivery service that happens to come with a free fridge, we have to deal with the complexities of the former, not the latter.
More options
Context Copy link
To some extent we do live in that world already: your $10 electronic device from Walmart probably already has a click wrap license that you have to accept to use the product. The validity of those is perhaps subject to question, but they aren't, to my knowledge in the US, categorically invalid.
Funny you mention clickwrap, because this whole topic reminds me of Ross Scott's campaign on stopping the destruction of live-service-type games, and the legal precedents in the US that basically give consumers no rights over software publishers.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
Just cap the liability costs at 10x the costs of the device. This should be enough to get vendors to take security seriously without having to worry about black swan outcomes.
Also, a hospital getting attacked by ransomware should obviously not only be liable for the ransom they elected to pay, but be fined on top of that if it turned out that any patient files were accessible to attackers.
More options
Context Copy link
More options
Context Copy link
How about a government funded Red Team who's raison d'etre is taking out insecure household devices? Could be a nice cyber-warfare bootcamp; I can certainly think of worse uses for government funds. The problem with letting the market take its course is that IoT devices are a low-value target for black hattery -- classic case for governments protecting the commons!
Isn't this the reason the NSA is supposed to exist on paper too?
Security for devices for the defense industry is one of those reasons, but I think household devices would be mostly outside their purview.
More options
Context Copy link
More options
Context Copy link
The government isn't going to find the security holes and report them; they're going to find the security holes, report a couple, and save the rest for their own use.
More options
Context Copy link
I actually kind of like the idea of this; you wake up one day, your doodad has been pwned, and the screen on it says "if you are seeing this, please call [govt. number]."
Govt. number: DO NOT REDEEM THE CARD SIR. You think that idea would be to a net benefit of the normies?
More options
Context Copy link
More options
Context Copy link
I think this is a great idea, though I'm sure China and Russia are doing it already.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
I understand the worry some people have towards IoT devices, and I like a lot of the rules in that document, but ultimately the issue rests with the users. The issue is the idea that network devices, outside of standard end user devices like a computers and phones (and even then), can be secure by default, without thought. At this point, people need to be responsabilized with regards to their network security, and you can't mandate away all the ways that someone can shoot themselves in the foot with consumer devices.
Users need to learn to keep shit behind their firewall, in their home network, and access it via VPN if they need to access it remotely. They should learn to NOT ask for cloud services where they are not strictly necessary.
Sure, I'm a professional and it may sound like wishful thinking that users will learn to do this or hire professionals. But there's a lot of stuff inside a home I wouldn't do, like plumbing and electricity. We don't mandate that plumbing fixtures be impossible to fuck up. And while we have standardized power outlets, everything other than plugging in something, to do with electricity inside a home expects some degree of expertise.
Totally get where you're coming from. However, the last paragraph has I think the most important bit:
Most IoT devices are billed as, "You just plug it in, and it just works!" No one anywhere is standing at a store, looking at the baby monitors, seeing that one of the options lets them listen to it from their phone, and thinking, "Ya know, I really better not think about buying this and plugging it in unless I become an expert in network security." Just how no one stands in a store looking at toasters, thinking, "Ya know, I better not think about buying this and plugging it in unless I become an expert electrician." Like, should people learn more about network security and how their electrical system works? Yeah, sure. But while the breaker boxes in the store might have some sort of warning on them or cultural expectation saying that they mayyyyyybe shouldn't buy it and try to install it on their own without any expertise while the toaster doesn't have anything of the sort, nobody's internet devices have any such warning or cultural expectation. Even effin' routers, people just buy the box and plug the box in; it's easy! It's magic! Best case, they have the guy from the ISP show up to plug in the modem and the router, but he's not going to be fiddling with the security settings for them, either. Everyone is perfectly happy just letting it seem like plug-and-play magic.
I mean ideally people should be aware of the issues around network security to the point of being able to make reasonable decisions on whether a given networking device is safe to use much like they do every day with other devices and vehicles and activities. No one looking at a lot full of cars doesn’t make sure the car has airbags and seatbelts and antilock brakes. That’s not a super deep understanding of automotive technology, it’s pretty basic. And in home network security I think you should know enough to look for the basic security features. I wouldn’t buy a networked baby monitor that didn’t have at minimum password protection and encryption. I’m not an expert but I know enough to know that unencrypted information can be viewed by anyone with the appropriate receiver and that a device not protected by a fairly strong password is open to hacking. I think people are treating PNP devices differently than they treat other similar devices. It’s not that they are incapable of due diligence, it’s that they see computer devices and the systems around them as too complex to understand. They aren’t.
Since they're all mandated now, no one bothers. And when they weren't, people indeed chose cars without them. But those are a different issue; those are safety, and what we're talking about with IoT devices is security. Think door locks and immobilizers, not airbags and seat belts.
I also suspect that even someone who intentionally chose a car based on it having airbags and seatbelts would be incompetent at deciding which cars had better airbags and seatbelts and which cars had worse airbags and seatbelts.
More options
Context Copy link
I think it’s a distinction without much of a difference. Security in IOT is safety from crime and hacking and so on. The point being that because of the fact that people learned about those features and why they were important, people did due diligence on making sure that those features were in the cars they bought. Sure some poorer people had to do without airbags in the early 1990s, but that was a cost issue.
I still think that it’s better to educate and demand due filling simply because the law moves much too slowly to keep up with technology and even then people making the rules often have no idea what the dangers are or how the things being regulated actually work. Having an octogenarian who has trouble with emails try to anticipate the issues of an IOT camera in your kids bedroom isn’t going to work well. Teaching parents to make sure their devices have strong password protection, good encryption, and virus protection is easier and would keep up with the field.
More options
Context Copy link
More options
Context Copy link
In the negligent users defense, users checking for features like "password protection and encryption" is more the source of the issue than the solution. Network security is a process, not a feature. I feel safer putting up a camera with no encryption and password protection that serve a standard video feed on the network than one that requires a cloud service with SSL, password, 2FA, etc... to function. The former would be forbidden to talk to anything outside of my internal network, and there would also be restriction to what it can talk inside the network. Security features are a very distant concern after proper access control. But cloud services I just have to trust. If you take the most secure device and give the whole planet a surface to attack it, it's a matter of when, not of if, it can be cracked. To its credit, the document does address some of this, but what happens when the company decides to discontinue the product line and deprioritize security updates on the cloud services for their baby monitor? The document does say they have to precommit to a support period, but there's support and Support.
Even then people can and do learn. And I don’t see why people assume that computer and network issues are that much more complicated to learn than any other security or safety concerns for anything else you might do or use. People can be taught this stuff. We managed to learn electrical safety and gas safety and safe driving and thousands of other problems that came along with new technology.
Well, that's because you trust yourself to get out of anything you get yourself into.
The problem with learning how to use computers is that, quite literally, everything's behind glass. The efforts to ameliorate this in the early '90s (and to a point, why early versions of iOS had the design language they did) were all attempts at solving this problem, and the reason the more famous ones failed (specifically Microsoft Bob) was because this problem is intractable outside of maybe VR- it's just side-grading from one "this is all behind glass, weirdly artificial, and I'm not truly in control of this machine's states" to "that, but at least it looks like a house".
With other forces of nature, such as electricity, gas, driving, etc., you're interacting with a physical thing. Human beings are exceptionally good at manipulating and understanding physical things- for electricity, you can physically guarantee that the current isn't going to go anywhere but where the wires conduct it. Same thing with driving (or at least, before we stuck shitty tablets in the dash).
Take away the state they're supposed to be directly manipulating, though, and make it both abstract and only accessible through a very specific set of fragmented language? And make it clear that (just like how people claim drivers would be better if there was a gigantic spike sticking out of the steering wheel) there are a bunch of [metaphorical, but sometimes very literal] loaded guns sitting inside the box? I don't blame anyone who hasn't had time/motivation to practice that in a safe environment for giving up pre-emptively.
(And the industry has done itself no favors- yes, there is an undo button, but the contexts in which it is useful and the powers it has within those contexts are not obvious even though with a plain-English reading they should be. Plus, now you have mobile-first design, which has to hide that functionality as a limitation of the user interface if it even has it at all... and every redesign that's made without actually proving it out, which UX designers love to do for some reason, chips away at the established knowledge base of a user little by little until there's nothing left.)
I don't think it's that people are unwilling or unable- though there are certainly plenty of men and women who very blatantly refuse to use their eyes- but there's no obvious observable demonstration of "input A results in desired state 1", and that's coupled with "input B-Z results in undesired states 2 through 2000 and there's no easy way to go back to before making that input". So yes, "basic stupidity" is a thing that keeps people from understanding these devices, but I don't think it's the primary cause.
Speaking of physical interfaces... you ever seen what PLC programming interfaces look like? Ladder logic is arguably the most intuitive programming environment ever invented and most software developers have no idea it exists; its entire design goal is to make it as obvious as possible what input will result in what output. The only real thing you have to deal with there is the logic; more advanced things like functions become much more obvious when you can physically [or at least, as close to physically as possible- in this case, tracing a line with your eyes or finger] see what's happening and why.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
Let's say you were in charge of fixing this from the advertising side of things. What warnings would you add to this device so that even tech-illiterate users understand the risks of e.g. connecting this baby monitor up to the internet? Simple stuff you can fit on a pop-up or side of the box, because the user isn't reading the 100-page manual that probably already warns about this.
A big part of why you can just hand a toaster to someone with no further explanation is that people actually do know a lot about electricity and household appliances and can avoid the biggest problems. Nobody's dumping a live toaster into the sink to clean it.
Manufacturers should probably take this lower level of knowledge into account, but it's not as easy as "just make the device idiot-proof, like toasters!"
I don't believe any user manuals actually warn about any of these things. The manufacturers simply do not care about security, because they don't have to, be it built-in, in manuals, or in advertisements.
Totally and completely agreed. I started off saying that one way we could fix this is to do something extremely simple, like banning default passwords. No manufacturer is going to put on their box whether they have a default password or not, so many consumers aren't going to know.
There has been some efforts in the US to create a Cyber Trust mark, where that is an indication that they have been built to some sort of standards (that aren't that far off from these regulations). This is a plausible approach, though we likely won't see whether it would have been effective (are consumers going to be paying close attention for this mark on a box full of ten other certification marks?), because they're probably just all going to bring their devices up to the UK standard. Could have been an approach, though.
More options
Context Copy link
I guess manufacturers are in a tough position there because the lower level of knowledge means that quite uncomfortable things have to be put on the packaging. They can get away with putting the warnings in the 100 page manual for the toaster; it would put off buyers if the toaster they were looking at proeminently displayed "This toasted WILL kill you if you plug it in and take it for a bath!". Similarly, a baby monitor whose box said something like "Unless properly secured, this monitor can allow strangers to connect and listen in or talk to your child" will find itself selling less than the one that omits it.
I suppose the best move is to spin it as a feature. Put it proudly on the box! "Crowdsource your child's safety with the default password mode!"
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
I am not sure that government providing long detailed lists of how to do security is going to help anyone.
My solution would be to simply make vendors liable for damages caused by security flaws of their devices, up to say 10 times the sticker price. Or impose a fine per vulnerable unit per day. An authentication bypass for a cloud-enabled webcam might cost 10% per day it is known for an exploit which allows recording if the fact that the camera is recording is visible from an LED, or 30% if the camera-on LED can be bypassed.
In Germany, the BSI is a federal agency tasked with enhancing computer security (except for when they are tasked with breaking computer security). The gist I get from German IT blogger fefe is that most of their security recommendations serve more to cover the backside of the company than actually prevent incidents. 'We were running two different anti-virus programs plus a Cisco Firewall, and our Windows+ActiveDirectory network was still compromised by ransomware. This simply shows the immense criminal energy of our attackers, we are the victims here!"
Again, laws should not try to specify the process, they should specify the outcomes. In this case, minimizing the time a device is exploitable.
In practice, this will mean Tivotization. Personally, I am following the philosophy of "if you did not install the operating system, it is not your device". Owning a mobile phone is a lot of hassle. First you pick a vendor which supports OEM unlocks at all, then you find out that their dreadful unlocking process does not actually work, send the phone back, order a phone from a different vendor, request the unlock code, wait a week and finally unlock it. Give me a PC with a legacy boot option or a RasPi any day instead.
On the other hand, if it is no longer possible to sell Rasbian in the UK, I will consider that a win. "Let us just put a default user+password usable via fucking ssh on the image, YOLO" is so far from any responsible security mindset that I can hardly fathom it.
This sounds like the role NIST plays in the US. But those are also contractually enforced on companies doing business with the government.
More options
Context Copy link
I suspect 1x the sticker price would be more than sufficient if it happened reliably.
More options
Context Copy link
I'd put in a caveat there, that it's your device if it's not meant to be a general-purpose computer and the software isn't blocking you from doing stuff that you want to do with it.
Smart hotplates that turn themselves off when you boil anything uncovered are an example of meeting condition 1 but not 2. A dumbphone which lets you do normal dumbphone things meets both.
More options
Context Copy link
More options
Context Copy link
I genuinely cannot think of a single "smart" device that has made my life better but it's easy to think of a ton that have made my life a little bit worse. This isn't a privacy or security thing. The devices are genuinely pointless and annoying. We recently unplugged our Alexa because it was pointless and annoying. There was probably a week where I could come up with contrived tasks for it to help with so I could pretend it wasn't completely stupid. I'm tired of tech people telling me I need this or that and making it impossible to find a house in the Bay Area with a normal boring thermostat. It's an immense treat that the used grill I just bought has no electronics built in.
The best argument for IoT devices was that they were a lot cheaper than normal devices because a VC was spending some pension fund's money to "build market share."
I'm convinced a lot of it is malinvestment due to loose monetary policy. If we weren't in ZIRP for years, those VCs would have to fund stuff that actually has a chance of turning a profit rather than something that just sounds like a good idea.
There are legit IoT things that are useful but they don't really fit into the kitchen-widget-but-with-computer framework. Smart grids, automotive communications, logistics, medical, agriculture; there's lots of actual applications of cheap networked MCUs that people don't think about and rely on every day. Your car's backup camera was probably sold to the investors as "IoT" at some point.
But somehow "IoT" came to mean either gimmicky chinese lightbulbs or kitchen appliances that make you pay a subscription. Probably because you have to use fancy buzzwords to make people swallow that crap.
More options
Context Copy link
I like Alexa in the kitchen only, then I can set timers, play music, get recipes and the like while I am wrists deep in a turkey. Just saves a bit of time is all.
That's about it.
Both wrists in there?
Fucking savage, man!
You should see me injecting butter under the skin..My wife thinks I could give BBLs down in Mexico.
More options
Context Copy link
Mr. Bean knows how it's really done.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
I can turn off my thermostat from bed if I forgot to do it before turning in
I can have my lamp gradually turn on and brighten before I need to wake up, which is nicer than the alarm
More options
Context Copy link
The smartphone map features are genuinely useful and I use them all the time to figure out what bus I need to take where, for example.
More options
Context Copy link
I hate IoT shit, but being able to close/open garage doors without the receiver when leaving the house without a car, set my thermostat to vacation mode, monitor my dogs, etc., have been beneficial enough for me not to rip out the haphazard automation put in the house by the previous owner.
Still cannot believe Google just gave up on Nest tooling and decided to leave home automation to a dozen Chinesium applications instead. It's embarrassing.
More options
Context Copy link
More options
Context Copy link
I'd expect it's more likely that the UK just gets flooded with more CE crap, while the bottom end of the domestic or near-business market lifts its skirt up over the floodwaters, same as the rest of the EU user privacy data stuff. Sorry if that's cynical, but the last time I went to the UK a coworker got zapped because none of the three-prong power adapters he'd locally-purchased actually had connections between the input and output ground plugs.
Some of these restrictions, even some of the good ones, aren't that readily implemented. SecureBoot is only a recommendation, which is good, given that even a lot of mid-range microprocessors don't support it, nevermind the microcontroller world where it's gfl. I've got two projects I'm running now (STM32F103Cx- and Nuvoton NUC980) that don't support it at all, and these aren't exactly ancient PICs. Same, maybe even worse, for the recommendation for memory access controls. Mandating a default-off mode for any debug interface is understandable from a Serious IT Perspective, but it also makes a lot of stuff e-waste in a wide variety of circumstances, and makes a lot of useful prosumer and enthusiast concepts unavailable.
More broadly, this reads a bit like it was written by a mid-studies electrical engineering student, for better or worse. There's a lot of good recommendations, but trying to make a clear distinction between IoT and 'constrained' devices as a simple binary... it's bad enough trying to split microcontrollers from microprocessors, but from a quick read this reg would put harder restrictions on an ESP32 lighting controller than solar-powered NVR system.
On net, it's probably not bad to have a document people can look at, even if they end up shrugging on actual implementations at points, but it's frustrating.
More options
Context Copy link
In related UK news, the head of Cybersecurity for the treasury earns... 57K Pounds or 12% of comparable positions in business: https://twitter.com/jontafkasi/status/1641193954778697728?s=46
Just the other day the MoD was hacked: https://www.independent.co.uk/news/uk/home-news/china-mod-uk-hack-data-breach-b2540489.html
I don't think they're solving their cyber problems any time soon. Joke country.
More options
Context Copy link
Humans are part of the Internet of Things.
I'm not going to use this as an argument to say that we should or shouldn't be having the elites lock down these devices more. But we should be very careful and aware. Most people see a greater distinction between human and non-human devices than actually exists.
As a result they have a huge blindspot. The average citizen thinks that it is possible to create new technologies for controlling machines without creating new technologies for controlling people. But this is not the case, because we are living on the same Fractal Godelian Battlefield as our devices.
More options
Context Copy link
More options
Context Copy link