Wednesday, September 23, 2026

Modern Slavery

What is the essence of slavery?

I think the most fundamental motivation for slavery is the desire to have goods or services as cheaply as possible, without concern for the rights, dignity and well being of those producing them.

When people work to produce goods or services, they should be compensated enough that they do that work and give up the products willingly. They should not be forced to do the work without compensation or against their will and the products of their work should not be taken from them against their will.

This gives rise to the most morally objectionable aspect of slavery: taking away the liberty of others, to force them to do work against their will. This typically entails effective imprisonment, physical and emotional abuse and an almost complete lack of compensation for the work done, beyond the minimum necessary for the workers to survive to do the work, and sometimes not even that much.

Some few people might find pleasure in abusing others but the vast majority who benefit from slavery do it merely for the benefit of having goods or services at a lower cost than possible when they are produced by people living freely, with dignity, health and security, and producing them willingly, for compensation.

Of course, everyone wants more for less. It is a natural desire. What separates those benefiting from slavery is the willingness to ignore the abuse of others.

One might be more or less removed from the direct abuse of others. One might be directly involved in the physical coercion of them to work. Or one might trade with people who are. Or with people who trade with people who are. Or ever more removed. But if, ultimately, the goods or services are produced, in whole or in part, by people who are coerced to work against their will and without reasonable compensation, then one is benefiting from and therefore participating in slavery.

Our society is structured to obscure the existence of slavery and its contribution to the goods and services that are available. Long supply chains obscure the ultimate sources, more of less deliberately. This allows people who would not knowingly participate in slavery to benefit from it. And this motivates efforts to expose slavery, so that others might choose not to participate in it.

Beyond merely exposing slavery, there are laws to make slavery illegal. These take many forms. Some refer explicitly to slavery. Others bar the means of physical or emotional coercion essential to slavery. Laws restricting hours of work and setting minimum wages also contribute to the prevention of slavery, as do the many laws protecting basic human rights.

Theft is typically treated as something distinct and different from slavery. Slavery is forcing someone to do work and taking the products of that forced work without compensation. Theft doesn't entail forcing someone to do work, merely taking the products of work after the fact, without forcing the work. But the end result is very similar: people work and the product of their work is taken from them against their will, without the compensation that would make them do the work and give up the products willingly.

It seems to me that theft is just a more subtle and devious means of slavery. It avoids some of the physical and emotional coercion, which is good to avoid, but it has all the other adverse consequences of slavery.

Thinking of theft and modern slavery, it seems to me that one of the biggest transfers of wealth in human history is the taking of almost all the artifacts of our culture for the training of LLMs, without compensation to the creators. This is deemed not to be theft, by those in power and benefiting from the transfer. But for the vast majority of creators, their products were taken against their will and without compensation: the essence of theft.

And as for coercion to work against ones will, one means to make others do this without direct physical coercion is to remove all alternatives. If one isn't allowed to raise or grow food and there are no stores except the company store, one will buy food at the company store, regardless of the price. Even if that makes one perpetually indebted to the company. The force, in this case, isn't up front as in traditional slavery, but it comes later, if one tries to stop working and leave the company town without paying off the debt: then law enforcement intervenes. So it isn't physical coercion that leads to slavery, but rather the threat of physical coercion: just one slight step removed. Like theft, this avoids the direct use of physical coercion that is the essence of slavery, but has all the other immoral consequences.

The so-called 'AI' industry entails two aspects of slavery: theft of the products of work, without compensation to the workers; and removal of any alternative but to work in conditions equivalent to slavery, by way of unfair competition. The industry is giving away the outputs of the LLM systems at far below cost, in order to compete with real people working productively and creatively, leaving them no alternative but to work in abject poverty to gain a few scraps of food.

It surprises me, therefore, that there isn't more vocal opposition to the 'AI' industry from those advocating against modern slavery. It is a morally repugnant abuse of human rights, morality and basic dignity, in progress at a massive scale, and should be opposed.

It is less direct that a sweatshop with imprisoned slaves, but it is so pervasive that it is almost inescapable. And, thus far, there is very little attention to the immorality of it. Not no attention, but not nearly enough. Many people discuss LLMs and so-called 'AI' merely on the basis of effectiveness as a tools for producing an immediate result in comparison with other means of producing the same result,  without consideration of its broader effects on people, society and the environment: without consideration of the theft of the products of people's work without compensation or the elimination of alternatives to working in slave-like conditions.

Saturday, September 19, 2026

Some thoughts about LLMs

I'm not an LLM developer, mathematician or computer scientist with deep insight into how LLMs work and what they are capable of.

I am not a lawyer with thorough knowledge of the law, its applications and impacts.

I have used LLMs, out of curiosity and as required for work.

LLMs are not perfect: they sometimes produce utter nonsense with good local consistency but overall lacking in self-consistency and consistency with reality. Often the output is not correlated with the input in any way that is useful to a person living the the real world and wanting help to deal with it. Not long ago, the outputs were predominantly nonsense. As time goes by, such faults in the output are less noticeable and less impactful, but they still exist. It remains foolish to depend on the outputs of LLMs for anything that matters in the real world (e.g. health, legal or business issues, social or political issues, relationships, etc.) without thoroughly vetting the outputs.

LLMs often produce useful outputs: the outputs are not devoid of truth or useful information. They are able to analyze, manipulate and produce computer software source code, often very effectively. They sometimes provide true information in response to questions. They sometimes correlate information from disparate sources to synthesize a summary or describe a pattern that might otherwise be difficult to discover. However, the usefulness is impaired by having to fact check everything, in cases where correctness matters.

The companies developing LLMs have been allowed to take copies of a large part of humanities cultural artifacts, to use them to train their LLMs with very little compensation to the creators or owners of the intellectual property rights in those artifacts. As far as I know, in the vast majority of cases, with no compensation at all. In a few cases, courts have forced them to provide some little compensation. I am not aware of any cases where they have provided compensation willingly, on their own initiative.

I understand that the legal justification for the companies developing LLMs being allowed to take and consume copies of artifacts not in the public domain is that the LLMs are transformative and therefore use of the artifacts is 'fair use'.

I do not understand how it is transformative, 'fair use' for these companies to take and use copies of protected works without permission or compensation but it is not equivalently 'fair use' if I or others take copies to similarly consume them - to learn from them - to train ourselves. 

Surely if I read a book, blog post, media company article or any other written work, or listen to an audio recording or watch a video recording, to become aware of the content, then my learning is also transformative. Whatever the internal representation of it in my mind, it is not a mere copy of the original. Whatever I might say or do subsequently, it is not an exact copy of the original, but transformed by my broader experience, abilities and limitations. Even if I tried, I couldn't create an exact copy of anything.

If I take a copy of a physics text book or article without compensation to the copyright holder, to read and learn from it, it is deemed theft.

If an LLM developer takes a copy of a physics text book or article without compensation to the copyright holder, to train their LLM, it is deemed 'fair use'.

The inconsistency is striking. I think the obvious difference is that the companies developing LLMs have billions of dollars to bribe and manipulate politicians and courts, while I and others like me do not.

I do not think there is anything fundamentally different in what we are doing, from a moral perspective, and there should be no difference from a legal perspective. Taking copies of protected works to consume them for whatever benefits doing so might provide should be treated the same, regardless of who is doing it.

I think the different treatments by the courts is a manifestation of fundamental injustice, largely resulting from the difference in power and influence of the extremely wealthy companies developing LLMs, compared to individuals.

LLMs are not useless. They can produce valuable outputs. This has already been proven. They have improved greatly in recent years and there is little reason to expect that they are already the best they can be or that there is no more possibility of learning to use them better.

None the less, it remains uncertain whether the benefit of using them will exceed the cost of producing and operating them and the adverse impacts of using them.

To the extent that LLMs are powerful tools, they can be used for good or for evil. There are harms associated with using them that is inherent in the use of them. This includes the consumption of resources to develop, build and operate them, for example. These costs and harms are not trivial. There is enormous energy consumption, at a time when climate change is already a serious problem. There is disruption to the balance of supply and demand of many goods and services. There is disruption in the economy on a massive scale, including the displacement of humans from their means of earning a living in our capitalist society. But I think the far greater harm is the harm that has and will come from evil people using the for evil purposes and selfish people using them for selfish purposes, to the detriment of others and society as a whole.

At the level of society as a whole, the greatest impact of the companies that develop LLMs and the LLMs themselves, thus far, seems to be to have greatly increased the already excessive concentration of wealth and power in the hands of a very few people. I think the short term and long term impact of such concentration of wealth and power is a net harm to society. Worse, that it is harmful to the vast majority of people and benefits only a very few who already enjoy the benefits of such extreme wealth that they have no legitimate moral need for any more.

Further, the use of LLMs is somewhat akin to slavery: the work of others taken for oneself, without any compensation - those others essentially made to work for free. Not by physically restraining or punishing them, but by unfairly competing with them, giving them no alternative. Many people have long wanted to benefit from the work of others without having to respect their rights or compensate them with a living wage. This desire is not new. LLMs are just a new mechanism to remove oneself from the direct oppression but still benefit from it. Like buying goods made in a sweatshop where slaves work or trading with a country or industry where slavery is common. But knowingly participating in such activities makes one complicit in the oppression and abuse. It is morally reprehensible.

I expect that the risks associated with the development and operation of LLM systems will be externalized by the companies developing and operating them. The risks will be transferred, through the financial institutions and governments, to the majority of ordinary people, who have no knowledge of the risks nor control of the decisions that will determine the outcomes. This will happen, for example, by institutional investors investing funds from pension funds, insurance funds, mutual funds, etc. on a massive scale: providing the companies with billions or even trillions of dollars, freeing the wealthy initial investors from risk and losses.

I expect many of the companies developing LLMs will fail, going bankrupt or bought out for very low prices. In the end, there will be a further concentration of wealth and power: an effective monopoly, or perhaps a duopoly or oligopoly: very few companies, not truly independent. controlling the market to extract maximum wealth and power from it. Externalizing losses and internalizing profits for the wealthy owners.

These companies or the people who use the LLMs they produce, might produce great benefits, some of which will be broadly distributed through society. New and better software, medicines, medical treatments and other products and services of all sorts. But I am skeptical that these benefits will be greater than the costs and harm done, in the foreseeable future.

The disruption will continue for decades and generations. Ultimately, if more efficient LLM systems are developed, new power sources are developed and the environments is not degraded to the point of being unlivable, LLMs might produce net benefits that could be broadly distributed throughout society. But I don't think a fair, equitable and generally beneficial distribution is likely. 

I don't think the companies developing LLMs will willingly share any of the benefits. They are, after all, capitalistic and operated by narcissistic sociopaths. Despite the legal definition in some jurisdictions, companies are not people. They do not behave like people. They do not have the morality, empathy or compassion of people. Rather, they are amoral, bureaucratic systems for extracting wealth with minimal risk, cost and responsibility. If a person behaved similarly, we would call that person a sociopath.

As always, the challenge is to negotiate an equitable distribution of the benefits of our culture, technology and work, that motivates people to be productive, cooperative members of society while allowing as much freedom as possible for different people to live according to their preferences and priorities. To mitigate and regulate conflicts sufficiently to avoid violence. To hold people accountable for their actions, including rewards for their good actions and punishment for their bad or harmful actions. 

This is made particularly difficult by different people having different values and therefore different ideas about what is good or bad, harmful or beneficial.

Society will never be peaceful. There will forever be conflict.

 

I like Yanis' take on the dangers of AI: "Is AI dangerous? Of course it is dangerous. All new tech is dangerous, because it reveals: how terribly humans are treating other humans. That has happened since time immemorial."

Monday, April 13, 2026

Windows 11 error message rant

I was given an incorrect security key for a WiFi network.

I tried to connect WiFi but the attempt failed. 

All Windows 11 indicated was 'Unable to connect to this network' - no indication that authentication had failed.

I followed advice for debugging WiFi problems: disabling and re-enabling WiFi, Forgetting the WiFi connection, rebooting Windows 11 and the router, disabling and re-enabling the WiFi device.

An utter waste of time.

If Windows 11 had indicated 'Authentication failed' instead of 'Unable to connect to this network', it would have been a quick fix.

My mistake was to assume that since Windows 11 didn't report an authentication failure, that authentication had not failed. Silly me! 

Why is it so hard from Microsoft to provide useful error messages?

'Unable to connect to this network' provides no actionable information other than what I already know: the WiFi isn't connected. 

Monday, March 16, 2026

Python PEP Caution

I didn't realize until today that Python PEP documents are not static. For example, look at PEP 366. This PEP document was modified many times, from May 1 2007 when it was first created until February 1 2025 when it was last changed. It began as a txt document with history from May 1 2007 to September 16 2022, then was changed to an rst document with history from September 10 2023 to February 1 2025.

Why is this an issue?

Because, when you read a post that references a PEP, unless they provide a copy of the PEP they were referring to, or the commit of the version they are referring to, you can't be certain what they were reading.

While most of the changes don't change the essence of the PEP, some do. You can't know without investigating them all. In the case of PEP 366, substantial changes were made until February 2 2009, after which changes were mostly changes to metadata, formatting and links to referenced resources.

To make matters worse, substantial changes are made even after the status of a PEP has been updated to Finished or Final.

Compare this to the IETF management of RFCs. RFCs are published and don't change substantially. Only metadata is changed to indicate if there are errata or when the RFC is superseded. Corrections are published in separate errata documents. More substantial changes are published in new RFCs that clarify or supersede the original RFC but don't change the RFC.

Tuesday, March 10, 2026

YouTube alternatives?

Bruce understands the fundamental problem with YouTube, and proposes an alternative: PeerTube, combined with portals to make it easier to find content: multiple portals. The biggest issues will be the monetization,  liability for illegal content, if a node proxies access for others, and security. The big players (YouTube, Meta, Apple, etc.) can have competition de-banked, which would disrupt monetization. Governments are increasing the restrictions and liabilities imposed on content providers.

Friday, March 6, 2026

AI in Firefox

I don't want a browser with inbuilt AI and a configuration switch to disable it: a switch which might inadvertently or maliciously be set to enable the AI features.

An addon that provides the AI features would be better: I could choose not to install the addon and to enable the AI features, an attacker would have to breach security to the extent they could install and enable the addon. At that point, they probably already have access to all my data anyway.

AI systems are, at the current state of the art, fundamentally unreliable and insecure. See, for example AI Agent, AI Spy.

Mozilla has decided that it will build AI features into Firefox. Therefore, I am forced to seek an alternative to the browser I have used preferentially for decades.

Nothing is forever and it is time for change, but not the change Mozilla intends.

It does make me wonder who funds Mozilla and what their real objectives are. 

Monday, March 2, 2026

Configuring WireGuard VPN client on Debian 13/trixie Linux

I am having difficulty configuring a WireGuard VPN client on my laptop running Debian 13/trixie Linux with XFCE desktop and NetworkManager managing network connections, to connect to the WireGuard VPN server I have configured on my router running OpenWrt.

I installed the wireguard package with: sudo apt install wireguard

I installed dbus-x11 package with: sudo apt install dbus-x11

The dbus-x11 package provides dbus-launch. At one point in my trials I was running nm-connection-editor as root (as some posts suggest this is necessary for it to write configuration to /etc/NetworkManager) and got an error indicating dbus-launch was not found. Installing dbus-x11 resolved this.

I tried configuring the VPN client by opening 'Configure VPN...' from the network icon in the XFCE panel (presented by the Status Tray Plugin of the panel). This appears to run nm-connection-editor, which can also be run from the command line.

This opens a window with title 'Network Connections' and two lists of connections: Wi-Fi and WireGuard. I clicked the '+' icon at bottom left and a new window appeared: Choose a Connection Type. I chose WireGuard and clicked Create.

This opens a window with title 'Editing WireGuard Connection 1'. The default connection name is 'WireGuard Connection 1'. I changed this to 'wg0'.

I completed the form on the WireGuard tab, including a peer with details of the WireGuard server on my router. It all seemed simple, except that  when adding the peer I was unable to enter the preshared key until I realized that the icon at the right of the field value text box is clickable and brings up a menu of options, the default being: The password is not required. With the default setting, the input textbox is disabled. 

But the connection didn't work. When I re-opened it in the connection editor, I found that sometimes the Preshared key input of the peer configuration was blank and sometimes the Private key input of the connection was blank. There were no pop-up errors or indications that the connection didn't work, but the connection wasn't created and the checkbox beside the VPN name in the pop-up from the network icon in the XFCE panel wasn't checked.

Eventually I found that when I tried to bring up the connection, there logs from NetworkManager in syslog, including:

2026-03-02T10:25:50.614594+13:00 tpt590 NetworkManager[849]: <warn>  [1772400350.6144] device (wg0): No agents were available for this request.
2026-03-02T10:25:50.614731+13:00 tpt590 NetworkManager[849]: <info>  [1772400350.6145] device (wg0): state change: need-auth -> failed (reason 'no-secrets', managed-type: 'full') 

When I added or edited the peer, I could enter the Preshared key after selecting 'Store the password only for this user' or 'Store the password for all users'. I could save the peer configuration then immediately reopen it for edit and all settings remained. But if I saved the connection then reopened it then opened the peer for editing, the Preshared key value was gone. And sometimes the Private key value of the connection was gone. It isn't obvious to me when the Private key value is cleared. Often, but not always, when I open the connection in the connection editor, the Private key value is gone - reverted to blank, though my selection for only this user or all users remains.

If I edited the connection and the Private key was present, then edited the peer and added the Preshared key and saved the peer but didn't save the connection (i.e. the connection editor was still open), then I was able to bring up the connection and the error about missing key did not appear. But as soon as I saved the connection, the Preshared key was lost and I was unable to bring up the connection. 

The WireGuard site does not provide documentation for the NetworkManager nm-connection-editor.  At least, not that I could find.

I don't know what package provides the functionality for editing WireGuard connections: whether it is part of XFCE, NetworkManager, WireGuard or some other. The forms I see are a bit different from what I see in posts about GNOME connection editor, which makes me think it might be desktop specific. It clearly relates to NetworkManager: the configuration editor is launched by running 'nm-connection-editor', but I suspect there is a plugin provided for WireGuard. Thus far, I don't even know where to ask: there are multiple forums for each of these components.

I am able to configure a client using the 'wg-quick' script and a configuration file I wrote by hand. Or by using the ip and wg commands directly. Bringing up the connection this way results in some configuration in  /run/NetworkManager/system-connections, but none of the keys are in the generated file.

I don't know if I'm missing some package or using the connection editor incorrectly or if it is actually misbehaving. Maybe the keys are supposed to disappear from the connection editor. I see some suggestions that they are stored by some sort of agent. But I haven't yet found any helpful documentation about this.

Update: 

I have found source code for nm-connection-editor and it includes modules for WireGuard. I have also found posts that assert that support for WireGuard is built in to NetworkManager: that the wirreguard package and wg command are not required.

I have also found that importing the WireGuard configuration that worked with 'wg-quick' into NetworkManager with the command:

sudo nmcli connection import type wireguard file ./vpntest.conf 

creates a connection file in /etc/NetworkManager/system-connections that can be brought up and down from nm-applet, which runs from the network icon in XFCE panel.

This creates a configuration similar to what I created using nm-connection-editor, except that all the keys are present.

I am still undecided where there is a bug in nm-connection-editor or I am using it incorrectly, to cause it to lose the Private key and/or Preshared key. I see implications that a key/secret store may be used to store them. But the keys are sometimes lost with no error message, which is very unhelpful even if, technically, it is not a nm-connection-editor bug that causes it.

For the moment, I will ignore nm-connection-editor and use 'nmcli connection import' to create configurations. Or edit the files manually, now that I have a working example.

FWIW, the working configuration in /etc/NetworkManager/system-connections is:

 

[connection]
id=vpntest
uuid=0fb0c5dd-9494-4854-b0a9-33659c21d5c1
type=wireguard
interface-name=vpntest

[wireguard]
private-key=REDACTED

[wireguard-peer.q0wK24nJWvlC+pZQ6wzGzsaqiI41vONaf8wtXjG7xzA=]
endpoint=64.246.80.42:51820
preshared-key=REDACTED
preshared-key-flags=0
persistent-keepalive=25
allowed-ips=192.168.1.234/32;

[ipv4]
address1=192.168.9.2/24
method=manual

[ipv6]
addr-gen-mode=default
method=disabled

[proxy]

 

The redacted keys are as created by 'wg genkey'

 

Labels