Live data from Hacker News

From PGP to Mythos: a brief history of export controls that didn't stop anyone

techcrunch.com

51–60 of 75 posts

Re: From PGP to Mythos: a brief history of export controls that didn't stop anyone

#51

Trump's export controls to China seem to be having the exact opposite effect as intended, and are (as a less befuddled mind might have anticipated!) actually accelerating their technical advance. Huawei is a good case in point, about to have a 100% domestic replacement for NVIDIA chips (& CUDA stack), not reliant on TSMC, ASML, Samsung, SK Hynix... Initially Huawei's Ascend AI chips had used HBM memory from Samsung a…

> but GLM-5.2 coming 11 weeks later, scores 48%, about on par with GPT 5.5. What's next ?! It depends how good the US labs get at stopping distillation of their models.

So the Chinese can land a rover on Mars, are beating us back to the Moon, but can't figure out how to generate some reasoning data to train on - that's your theory ?!

Re: From PGP to Mythos: a brief history of export controls that didn't stop anyone

#52

Earlier quoted context omitted.

> Mythos is a service you buy from a US company, not source code you can procure from anywhere and compile on your own weren't chinese labs training on US Ai outputs? a looot of ai power is in correct data to train for - that's pretty much like inviting workers to your factories, they won't take machines with them, but will see and consume all the processes

I doubt that it has ever been possible to obtain enough output tokens from OpenAI or Anthropic to be useful for training other LLMs. In any case, had that been possible in the beginning, it stopped being possible long ago, because any suspicious accounts would be banned and the cost would be prohibitive even if they were not banned. On the other hand, anyone can train new LLMs using the open weights Chinese LLMs, or…

> and the cost would be prohibitive

The government of the Peoples Republic of China provides massive subsidies and incentives for R&D. The cost is absolutely not prohibitive, it's not even a factor. You are massively underestimating how much capital is involved in both countries respective industries. 500 billion on indirect compute? 好!

Re: From PGP to Mythos: a brief history of export controls that didn't stop anyone

#53
post #19

There's no effective way of enforcing export controls on local software like PGP etc. Whatever they say someone will leak it. It is possible to shutdown access to hosted services, as happened with Fable, but it can't really be done selectively. The US government wanted to allow it for US nationals only but Anthropic couldn't do that and so shut it down for everyone. Even if they did tie Claude accounts to nationality…

They can restrict it to US citizens only: just do KYC and enforce it. Any citizen exporting ITAR capabilities would be committing a felony.

I think it is inevitable that more capable models will require export controls, KYC, background checks, verification of credentials, etc. Even if you don’t buy Anthropic’s marketing of their current models, there is a future where models are capable of developing chemical weapons, biological weapons, cyber weapons, etc. which are genuine security threats governments will care about controlling and preventing. Maybe this prevents big commercial labs from developing more capable models until they figure out appropriate safeguards, but this is a good thing, a world where you can ask an LLM for an airborne rabies genome and it will simply produce it for you is not a world we should want to live in.

Re: From PGP to Mythos: a brief history of export controls that didn't stop anyone

#55
post #19

There's no effective way of enforcing export controls on local software like PGP etc. Whatever they say someone will leak it. It is possible to shutdown access to hosted services, as happened with Fable, but it can't really be done selectively. The US government wanted to allow it for US nationals only but Anthropic couldn't do that and so shut it down for everyone. Even if they did tie Claude accounts to nationality…

They can restrict it to US citizens only: just do KYC and enforce it. Any citizen exporting ITAR capabilities would be committing a felony. I think it is inevitable that more capable models will require export controls, KYC, background checks, verification of credentials, etc. Even if you don’t buy Anthropic’s marketing of their current models, there is a future where models are capable of developing chemical weapons…

Identity theft is a thing. And if you gate a desirable commodity behind an identity it will become even more of a thing. There are 100's of millions of identities to steal.

Re: From PGP to Mythos: a brief history of export controls that didn't stop anyone

#56

Earlier quoted context omitted.

> Mythos is a service you buy from a US company, not source code you can procure from anywhere and compile on your own weren't chinese labs training on US Ai outputs? a looot of ai power is in correct data to train for - that's pretty much like inviting workers to your factories, they won't take machines with them, but will see and consume all the processes

I doubt that it has ever been possible to obtain enough output tokens from OpenAI or Anthropic to be useful for training other LLMs. In any case, had that been possible in the beginning, it stopped being possible long ago, because any suspicious accounts would be banned and the cost would be prohibitive even if they were not banned. On the other hand, anyone can train new LLMs using the open weights Chinese LLMs, or…

There’s a hugely widespread business model where criminals steal people’s API keys, then sell people (mainly in China) access to models through their proxies for lower prices, and then of course save all this data and sell it to Chinese labs for distillation.

Re: From PGP to Mythos: a brief history of export controls that didn't stop anyone

#57
post #19

There's no effective way of enforcing export controls on local software like PGP etc. Whatever they say someone will leak it. It is possible to shutdown access to hosted services, as happened with Fable, but it can't really be done selectively. The US government wanted to allow it for US nationals only but Anthropic couldn't do that and so shut it down for everyone. Even if they did tie Claude accounts to nationality…

They can restrict it to US citizens only: just do KYC and enforce it. Any citizen exporting ITAR capabilities would be committing a felony. I think it is inevitable that more capable models will require export controls, KYC, background checks, verification of credentials, etc. Even if you don’t buy Anthropic’s marketing of their current models, there is a future where models are capable of developing chemical weapons…

If a model is really capable of that type of stuff (creating biological weapons etc) the problem isn't solved by export controls - I'm sure there are plenty of home grown US terrorist organisations that would like that capablility and wouldn't be subject to such controls.

Yes governments can, and probably should, restrict some things completely to all those outside of official government institutions but once something is public in one country it is effectively, even if not legally, public in all countries.

But for "physical" things like biological, chemical or nuclear weapons the know how / information part, that AI can "help" with is far from the complete picture. Articles have already been published on how to make a nuclear bomb. The knowledge isn't really the blocker that's more access to the required materiels and equipment. However in the cyber space then yes AI could indeed give the "bad guys" much more capability.

Re: From PGP to Mythos: a brief history of export controls that didn't stop anyone

#58

Earlier quoted context omitted.

> but GLM-5.2 coming 11 weeks later, scores 48%, about on par with GPT 5.5. What's next ?! It depends how good the US labs get at stopping distillation of their models.

So the Chinese can land a rover on Mars, are beating us back to the Moon, but can't figure out how to generate some reasoning data to train on - that's your theory ?!

I suspect there's just a bit of training data on the other side of the Great Firewall that western companies can't access.

Re: From PGP to Mythos: a brief history of export controls that didn't stop anyone

#59
post #5

It's a very brief history: it consists of three examples, only one of which isn't in the title. And the middle one is arguably a success story because the government did stop a bunch of spyware vendors it particularly disliked. That they turn a blind eye to some others is not really a policy failure, it's a deliberate political choice. The obvious difference between PGP and Mythos is that Mythos is a service you buy…

I want to put this charitably, but you come out swinging by saying this is "over hyped"... You clearly don't work in a role dealing with attacks from these models. They've changed the game, and for the worse. Capabilities that used to be available only to nation-state attackers are legitimately commodified, or nearly so.

> You clearly don't work in a role dealing with attacks from these models.

I do. And from my perspective, most people in tech do.

> these models [have] changed the game, and for the worse.

Yes. Also for the better.

> Capabilities that used to be available only to nation-state attackers

We (unhelpfully) draw a tight line around nation-state attackers. We don't perceive them as part of the relentless tendency of the powerful - to leverage tech against everyone they can. Particularly us.

> Capabilities ... are legitimately commodified,

Sure. Models will keep increasing in ability. The only choice is whether they're limited for the powerful to use against us - or if that power extends to us, to help us keep the powerful in check.

Re: From PGP to Mythos: a brief history of export controls that didn't stop anyone

#60
post #19

There's no effective way of enforcing export controls on local software like PGP etc. Whatever they say someone will leak it. It is possible to shutdown access to hosted services, as happened with Fable, but it can't really be done selectively. The US government wanted to allow it for US nationals only but Anthropic couldn't do that and so shut it down for everyone. Even if they did tie Claude accounts to nationality…

You could quite effectively set up access to Fable with know-your-customer, attested clients/workstations, and then inspection of what the session is actually used for to detect out-of-country use. It's not impossible.

If they had said only governemnt and a few other approved institutions can use it then yes that could work.

But they didn't say that. They said "only US citizens". Once something is available to hundreds of millions of people there will be leaks like it or not. Some accidental and some voluntary.

And even if it could be done it wouldn't solve the purported security issue anyway. Does anyone believe there are no criminals or terrorists with US nationality?

Post reply on HN