Suramya's Blog : Welcome to my crazy life…

September 28, 2024

My Limit for suspension of belief: black hole inside a person allows time travel

Filed under: My Thoughts — Suramya @ 10:58 AM

Watching movies or shows requires a certain amount of suspension of belief especially if it is a Sci-Fi or Fantasy movie. Most of the time this is fairly easy to do and makes for a fun watch or read. However, there are instances where no matter how much you try to suspend your belief it just doesn’t make sense and you are unable to watch the movie or show. Omni Loop is one such movie for me.

The movie sounded quite interesting as it is about time travel and I was looking forward to it, but once I started watching the movie within the first 5 mins I had to stop it as I couldn’t take it anymore. So, what happened in the first 5 mins that so annoyed me you might ask? The main character in the movie is a quantum physicist who is dying. The movie starts off with a doctor telling a lady that the the main character is dying because and I quote: she has a black hole growing in her chest. When I heard it I thought I must have been mistaken, because if there is a blackhole anywhere near a person they would be sucked inside it in micro-seconds.

A Black hole is a cosmic body of extremely intense gravity from which nothing, not even light, can escape. This means that they suck in any matter around them and incidentally that is how we can see them because of their enormous gravitational fields on nearby matter. We also have what are called mini-Black holes each with a mass that is only equal to or less than an asteroid. When the Large Hadron Collider went online folks were worried that it could create large numbers of mini black holes each of which could cause significant damage to earth before they dissipated.

If a black hole somehow managed to get lodged in someone’s chest (even a mini one), the gravitation forces would pull them apart and the weight would be so much that they wouldn’t be able to move even if they did manage to survive this somehow. The worst part was that this wasn’t shown as something that was unusual or rare. The doctor treated it the same way that they would have a tumor growing inside a person. If they had made it sound like a mystery that current science couldn’t explain maybe I would have continued to watch the movie but with the plot the way it was I just couldn’t continue to watch it.

– Suramya

September 27, 2024

Office retreat from hell: Worker rescued after being allegedly left stranded on Colorado mountain by colleagues

Filed under: My Thoughts — Suramya @ 10:37 AM

I know at times folks at work don’t get along and that can become quite an issue for HR & Managers etc to solve. But I don’t think I can imagine this scenario happening in any of the companies that I have worked with in my 24 years of corporate experience. A group of 15 coworkers were on an office hiking retreat where they were scaling a 14,230-foot mountain. Which sounds like a fun team building exercise till it went horribly wrong.

14 of the 15 people managed to scale the peak successfully and then instead of waiting for the 15th person to complete as is required by common-sense, courtesy and team building they left the person near the peak to attempt the climb alone. One of the first rules that was drilled into our heads when I did my mountaineering course was that no one is left behind. Even if the last person is taking forever to finish the climb we had to wait till they completed before we could leave/start back. This is a basic safety rule so that people don’t have to go through what this guy did.

The lone employee made it to the summit at 11:30 a.m., but when he tried to descend, “he became disoriented,” according to rescue officials.
Making matters worse, his colleagues descending the mountain ahead of him inexplicably collected belongings left in a boulder field to mark the path down, officials said.

“In his initial attempts to descend, he found himself in the steep boulder and scree field on the northeast slopes toward Shavano Lake,” according to officials.

The man, whose name and company were not released, used his cellphone to pin-drop his location to his co-workers, who informed him that he was on the wrong route and instructed him to hike back up to the summit to get to the correct trail down, officials said.

Just before 4 p.m. local time on Friday, he sent another location pin-drop to his colleagues that he was near the correct trail.

“Shortly after that message, a strong storm passed through the area with freezing rain and high winds, and he again became disoriented, losing his cell phone signal as well,” rescue officials said.

When his colleagues didn’t hear from him, they reported him missing to Chaffee County Search and Rescue at 9 p.m., some eight-and-a-half hours after he started his descent, officials said.

To make matters worse, they waited 8 1/2 hours before reporting him as missing. It was pure luck that he survived the trip and serious charges should be laid against each of the 14 folks who didn’t think twice before leaving him at the top of a mountain.

I really want to find out the company these folks are from so that I can ensure I never work there. This shows how bad or cutthroat/toxic the office environment is as they just left him up there.

Source: abcnews: Office retreat gone awry: Worker rescued after allegedly left stranded on Colorado mountain by colleagues

– Suramya

September 26, 2024

Python in Excel launched for all Office 365 Business and Enterprise users

Filed under: Computer Security,Computer Software,My Thoughts,Tech Related — Suramya @ 10:35 PM

Excel is both a blessing and a bane for companies. Because of its capabilities folks have created formulas/macros/scripts/functions etc in Excel that allows them to generate data that is used to take major financial decisions with real world impact. But that capability also makes it an ideal vector for infiltrating an organization using Macros or scripts in Excel files to compromise systems.

Back in Aug 2023, Microsoft first announced that they are going to support running Python inside an Excel file. After that there was no major talk about it so I had hoped this meant that they had abandoned the project, but sadly I was mistaken. Redmond announced the official release of Python in Excel for Windows users of Microsoft 365 Business and Enterprise in a blog post. The post has a lot of details on the new capabilities this gives to power users and frankly I can see why folks are excited about it. But from a security and version control point of view this is a disaster waiting to happen.

There is a new learning series available for free for 30 days on LinkedIn that incorporates numerous examples, tutorials, and tips on how to best leverage Python in Excel.

Included in the Excel for Python release is a large language model integration that will allow Excel users to ask the Copilot to build scripts for them with plain language commands.

Microsoft partnered with data science tool maker Anaconda to develop the Python-Excel integration. As we’ve previously reported, data can move effortlessly between the two platforms using a few custom-defined functions.

This two-way function sending is a key part of security – Microsoft states Python processes Excel data without revealing the user’s identity, and all Python code runs in a secure, isolated environment, only accessing libraries approved by Anaconda​.

As with all the stuff MS has released recently, this also has LLM Integration but is on a very restricted list. The service is available to all Office 365 users with a valid Enterprise or Business Microsoft 365 subscription on the Current Channel.

Source: The Register: Python in Excel is here, but only for certain Windows users

– Suramya

September 12, 2024

Applicant self filter themselves out because company staff uses Pronouns in mail

Filed under: My Thoughts — Suramya @ 2:15 PM

The following screenshot of an email was shared over at Mastodon by @drahardja and I think the company dodged a bullet with this person. In my experience people who complain about pronouns are the ones who are most likely to be misogynistic and difficult to work with.

Hi After seeing that your signature includes pronouns, I've made the quick decision this company isn't for me, as I don't justify mental iliness or play the pronoun game, and I don't want to be involved with a company that does. Please remove me from the potential candidate list.

Hi After seeing that your signature includes pronouns, I’ve made the quick decision this company isn’t for me, as I don’t justify mental iliness or play the pronoun game, and I don’t want to be involved with a company that does. Please remove me from the potential candidate list.

I don’t have my pronouns in my mail signature but I do have it in the company directory and in Zoom. Having them there helps a lot because it removes ambiguity. My name has often been mistaken for being a girls name which has in the past led to some hilarious confusion and if others have their pronouns in the mail/directory I know the ‘Kris’ I am dealing with is a lady instead of a guy as I had assumed which ensures I don’t shoot myself in the foot when I meet them.

Also, calling this ‘mental illness’ is not cool. Being kind and inclusive is not an illness or weakness. If you watch or listen to these so called ‘alpha males’ who claim to be the peak of manliness you will soon realize that they are whiny scared little boys who are afraid of everything. Anything they don’t understand or like is unmanly or beta behavior. At one time I was thinking about doing a post making fun of them but then decided I have better things to do with my life.

In any case, long story short: Be kind, be inclusive and don’t be scared of the ‘other’.

– Suramya

September 5, 2024

I want this Sky Alarm

Filed under: Astronomy / Space,My Thoughts — Suramya @ 12:41 PM

I really want this Sky Alarm, although that being said since I am in Bangalore 90% of the time it will happen that I would step outside and find the sky completely covered by Clouds.

Cool Space Thing happening. Go outside and look up
Cool Space Thing happening. Go outside and look up (via XKCD)

Thinking about it a little more, it might be a fun project to create. The data can be pulled from some of the astronomy sites that track predictable events (eclipses/meteor showers etc). The tricky part would be to get information for events that are last min, such as Aurora sightings etc.

Something to think about for when I get some free time.

– Suramya

September 4, 2024

Guys is not a gender neutral term

Filed under: My Thoughts — Suramya @ 12:37 PM

Gender neutral language is difficult at first because we are not used to it, but as you start using gender neutral terms things over time it starts feeling natural. For me the most difficult word to stop using was ‘guys’ and it took me a while to stop using it. Even now I still end up using it every once in a while accidentally but it is something I work on. For those who keep telling everyone that it is a gender neutral term, the following screenshot that popped up in my feed says it best.


It is rude but it makes the point beautifully. ‘Guys’ is not a gender neutral term and it never was. Just that people are so used to using it and didn’t want to change that it became sort of accepted.

Language is powerful and important. It can build communities and connections or it can break connections. For example, if you have a mixed gender group and are calling everyone guys you are indirectly telling the non male population that they are not part of the team or not important enough to be recognized. This is not to show that you are ‘woke’ or whatever but just basic human courtesy.

You should always use the correct language when interacting with others and believe me it does get noticed.

– Suramya

August 31, 2024

NASA has a site that uses LandSat images to spell a given name

Filed under: Astronomy / Space,Interesting Sites,My Thoughts — Suramya @ 8:30 PM

NASA satellites take a lot of photos of earth and they are available online to view but that doesn’t make it fun to look at them. So they have a site that spells out your name using landsat imagery. Which is a pretty cool way to showcase the images. You can try it out at the You Name in Landsat site.

Here’s how my name looks:

Suramya: Spelled using landsat images
Suramya: Spelled using landsat images

Hovering the cursor on each image gives you the name and location of the geological/geographical image used.

Source: Mastodon.world: @davidho

– Suramya

August 27, 2024

MIT Researchers publish AI risk database exposing 700+ ways AI can be risky

Filed under: Artificial Intelligence,Computer Software,My Thoughts — Suramya @ 10:44 AM

AI (or rather what is call AI right now), is not really intelligent but it does have a lot of risks associated with using it. We all know about the Deep Fakes and the hallucinations etc but those are not the only risks of using generative AI. The researchers at MIT have cataloged the over 700 risks of using generative AI.

The risks posed by Artificial Intelligence (AI) are of considerable concern to academics, auditors, policymakers, AI companies, and the public. However, a lack of shared understanding of AI risks can impede our ability to comprehensively discuss, research, and react to them. This paper addresses this gap by creating an AI Risk Repository to serve as a common frame of reference.

This comprises a living database of 777 risks extracted from 43 taxonomies, which can be filtered based on two overarching taxonomies and easily accessed, modified, and updated via our website and online spreadsheets. We construct our Repository with a systematic review of taxonomies and other structured classifications of AI risk followed by an expert consultation. We develop our taxonomies of AI risk using a best-fit framework synthesis. Our high-level Causal Taxonomy of AI Risks classifies each risk by its causal factors (1) Entity: Human, AI; (2) Intentionality: Intentional, Unintentional; and (3) Timing: Pre-deployment; Post-deployment. Our mid-level Domain Taxonomy of AI Risks classifies risks into seven AI risk domains: (1) Discrimination & toxicity, (2) Privacy & security, (3) Misinformation, (4) Malicious actors & misuse, (5) Human-computer interaction, (6) Socioeconomic & environmental, and (7) AI system safety, failures, & limitations. These are further divided into 23 subdomains. The AI Risk Repository is, to our knowledge, the first attempt to rigorously curate, analyze, and extract AI risk frameworks into a publicly accessible, comprehensive, extensible, and categorized risk database. This creates a foundation for a more coordinated, coherent, and complete approach to defining, auditing, and managing the risks posed by AI systems.

They have published a paper on it: The AI Risk Repository: A Comprehensive Meta-Review, Database, and Taxonomy of Risks From Artificial Intelligence that you should check out. They have also made their entire database available to copy for free as well.

Check it out if you have some free time.

Source: Boingboing.net: MIT’s AI risk database exposes 700+ ways AI could ruin your life.

– Suramya

August 22, 2024

Correct Pronunciation of SAP

Filed under: Humor,My Thoughts — Suramya @ 8:05 PM

Saw this sign while stuck in Bangalore traffic and it made me laugh. I mean, how annoyed do you have to be about the miss pronunciation of the name to take actual billboards out to correct people.


We are SAP (es-ay-pea)

– Suramya

August 21, 2024

First three Post-Quantum Encryption Algorithms released by NIST

Filed under: Computer Security,My Thoughts,Quantum Computing — Suramya @ 8:30 PM

NIST has been reviewing algorithms as part the the PQC (Post Quantum Cryptography) Standardization process for over 8 years now and they have released the first three standards for post-quantum cryptography. These standards will allow systems to protect their data and communications with encryption that are not vulnerable to Quantum Computers. Current standards and tools rely on complex math problems that are difficult or impossible to solve using conventional computers but are vulnerable to a sufficiently capable quantum computer which would be able to process potential solutions very quickly.

The new standards are designed for two essential tasks for which encryption is typically used: general encryption, used to protect information exchanged across a public network; and digital signatures, used for identity authentication. NIST announced its selection of four algorithms — CRYSTALS-Kyber, CRYSTALS-Dilithium, Sphincs+ and FALCON — slated for standardization in 2022 and released draft versions of three of these standards in 2023. The fourth draft standard based on FALCON is planned for late 2024.

While there have been no substantive changes made to the standards since the draft versions, NIST has changed the algorithms’ names to specify the versions that appear in the three finalized standards, which are:

  • Federal Information Processing Standard (FIPS) 203, intended as the primary standard for general encryption. Among its advantages are comparatively small encryption keys that two parties can exchange easily, as well as its speed of operation. The standard is based on the CRYSTALS-Kyber algorithm, which has been renamed ML-KEM, short for Module-Lattice-Based Key-Encapsulation Mechanism.
  • FIPS 204, intended as the primary standard for protecting digital signatures. The standard uses the CRYSTALS-Dilithium algorithm, which has been renamed ML-DSA, short for Module-Lattice-Based Digital Signature Algorithm.
  • FIPS 205, also designed for digital signatures. The standard employs the Sphincs+ algorithm, which has been renamed SLH-DSA, short for Stateless Hash-Based Digital Signature Algorithm. The standard is based on a different math approach than ML-DSA, and it is intended as a backup method in case ML-DSA proves vulnerable.

Similarly, when the draft FIPS 206 standard built around FALCON is released, the algorithm will be dubbed FN-DSA, short for FFT (fast-Fourier transform) over NTRU-Lattice-Based Digital Signature Algorithm.

This is a significant step in ensuring our data and systems are protected against threats that are on the horizon. The Register has a good article on this topic (NIST finalizes trio of post-quantum encryption standards) that I highly recommend you check out.

Sources:
* Mastodon.social
* Schneier.com: NIST Releases First Post-Quantum Encryption Algorithms

« Newer PostsOlder Posts »

Powered by WordPress