Live data from Hacker News

Disrupting malicious uses of AI by state-affiliated threat actors

openai.com

21–30 of 94 posts

Re: Disrupting malicious uses of AI by state-affiliated threat actors

#21
post #6

Fuck openai, I'm a security researcher and if you dare ask it about anything Windows related it tells you to screw off. Linux? Fine. But ask about some undocumented Windows behavior and it says it can't. Ask it about patchguard internals as a reference? Tells you it can't assist. Absolutely crazy, I can understand asking it to write straight up malware, oh wait, it does that no issue! Lord help you if you want to use…

Yeah, fuck OpenAI. The amount of censoring done by them in the name of "alignment" is fucking crazy

Re: Disrupting malicious uses of AI by state-affiliated threat actors

#22
post #6

Fuck openai, I'm a security researcher and if you dare ask it about anything Windows related it tells you to screw off. Linux? Fine. But ask about some undocumented Windows behavior and it says it can't. Ask it about patchguard internals as a reference? Tells you it can't assist. Absolutely crazy, I can understand asking it to write straight up malware, oh wait, it does that no issue! Lord help you if you want to use…

It’s silly that they do that. I doubt it matters, though. In my experience, querying ChatGPT for factual information like that is a mistake. It isn’t reliably accurate enough.

Re: Disrupting malicious uses of AI by state-affiliated threat actors

#23
post #16

Looking over the specifics, the striking thing about this to me is that it seems like these supposedly-sophisticated covert operatives are just going to ChatGPT (or similar) and basically asking "how do I make good malware?"

[flagged]

Agreed on some points, but you're really understating the case for Russian interference in 2016. Study Guccifer 2.0

Re: Disrupting malicious uses of AI by state-affiliated threat actors

#24
post #16

Looking over the specifics, the striking thing about this to me is that it seems like these supposedly-sophisticated covert operatives are just going to ChatGPT (or similar) and basically asking "how do I make good malware?"

[flagged]

Well said, fellow systemd enjoyer

Re: Disrupting malicious uses of AI by state-affiliated threat actors

#25
post #16

Looking over the specifics, the striking thing about this to me is that it seems like these supposedly-sophisticated covert operatives are just going to ChatGPT (or similar) and basically asking "how do I make good malware?"

[flagged]

> "Russia influenced the 2016 election" = some guy with a distant relationship to the Russian govt bought some really crappy Facebook ads in Florida.

I'm not sure this is true. I'd highly recommend reading the Muller report. It provides a lot of detailed, specific, evidence of direct communication with the Russian government.

Re: Disrupting malicious uses of AI by state-affiliated threat actors

#27
post #18

If this is the case, there must be a serious competency crisis in foreign intelligence agencies. It’s trivial to run your own local model.

> It’s trivial to run your own local model With what GPUs?

They don't seem to be having much trouble securing consumer oriented GPUs, which can do a lot of the work.

Re: Disrupting malicious uses of AI by state-affiliated threat actors

#28
post #12

> two China-affiliated threat actors known as Charcoal Typhoon and Salmon Typhoon; the Iran-affiliated threat actor known as Crimson Sandstorm; the North Korea-affiliated actor known as Emerald Sleet; and the Russia-affiliated actor known as Forest Blizzard. I wonder who came up with those. The pattern is similar to the UK's https://en.wikipedia.org/wiki/Rainbow_Code , which makes me suspect that the threat actor att…

How Microsoft names threat actors → https://learn.microsoft.com/en-us/microsoft-365/security/def...

Microsoft shifts to a new threat actor naming taxonomy → https://www.microsoft.com/en-us/security/blog/2023/04/18/mic...

Re: Disrupting malicious uses of AI by state-affiliated threat actors

#29
post #18

If this is the case, there must be a serious competency crisis in foreign intelligence agencies. It’s trivial to run your own local model.

> It’s trivial to run your own local model With what GPUs?

Ones they ship to countries that haven't signed the American export-control regime, e.g. Singapore and then send off to China.

Re: Disrupting malicious uses of AI by state-affiliated threat actors

#30
post #12

> two China-affiliated threat actors known as Charcoal Typhoon and Salmon Typhoon; the Iran-affiliated threat actor known as Crimson Sandstorm; the North Korea-affiliated actor known as Emerald Sleet; and the Russia-affiliated actor known as Forest Blizzard. I wonder who came up with those. The pattern is similar to the UK's https://en.wikipedia.org/wiki/Rainbow_Code , which makes me suspect that the threat actor att…

I am not a hacker nor security expert, so take this with a grain of salt. As I see it, there's one of two (general) ways a group will get a name:

1) The group themselves declares it (like Anonymous). Which means they need to explicitly leave their name somewhere.

2) The name is given by someone from the outside, such as the US.

I suspect 2 is quite common. I wouldn't expect most state level hackers leaving calling cards on systems. In fact, probably not most hackers at any level. It really seems like if state level actors were leaving calling cards that this would instead be misdirection rather than a tag. So I would not be surprised if they ended up getting US style naming schemes because it would be US (or other Westerners) identifying these people the same way you'd identify people by the style of actions and how they write. I know you can probably look at code from coworkers and know who wrote specific parts. Think like what you see in a movie with serial killers (or even real life). How do you know it is the same killer? Style.

I mean you could also get the name if you infiltrated the other country and then intimately studied their groups. The name of their group internally. But then you'd probably translate it. Still probably not a great idea to give that name out publicly though because then you could be hinting at how you obtained that information because different parts of the organization may refer to the same group by different names (specifically to do this. Military groups often run disinformation internally in secret channels).

Edit: guessmyname left a link to showing Microsoft names these.

https://www.microsoft.com/en-us/security/blog/2023/04/18/mic...

https://news.ycombinator.com/item?id=39372339

Post reply on HN