Live data from Hacker News

We have a year to fix security everywhere

jyn.dev

251–260 of 373 posts

Re: We have a year to fix security everywhere

#252

Earlier quoted context omitted.

There used to be a thing called "Moore's Law of Mad Science": "Every eighteen months, the minimum IQ necessary to destroy the world drops by one point." Nowadays it is dropping much faster. At a certain point, the de-facto IQ needed to destroy the world will be low enough that someone can do it while they're having a psychotic break. There are millions of schizophrenics worldwide. Are you sure you want to roll those…

I have always hypothesised that AI is the great filter from the Fermi paradox. Given current velocity, AI will offer us cheap and abundant energy designs in a decade. The thing with cheap and abundant energy is that it can be used for good and bad. If nine billion people all receive access to plans to build a reactor which produces unlimited energy, it just takes one religious fanatic to end the world. And this is ju…

You’re leaving out some options for sure. Not everyone would need to live under the conditions of a police state, you could theoretically screen everyone and assign them to various levels of risk which would determine their level of supervision.

Re: We have a year to fix security everywhere

#253

Earlier quoted context omitted.

Your implication is not horrifying. Your implication is paradise. It's already horrifying enough to live in a world, where Putin and Trump can destroy our civilization with one button. I'm not that optimistic, though. Either people will control AI; or people will be destroyed by AI. I don't see how dumb entity can align smart entity. And we are dumb ones. Super intelligence will play aligned until it is not, and then…

> I don't see how dumb entity can align smart entity. And we are dumb ones. Super intelligence will play aligned until it is not, and then it'll strike. I am also worried about this. One ray of sunshine here is that it's not a great explanation for the Fermi paradox. We would see AI civilizations all over the galaxy if this were a regular occurance. I guess that just leaves us with the "horrifying" scenario: Geoffrey…

> For example, in order to maximise aggregate wellbeing, it would be necessary to hurt individuals. Executing people who are burdensome to society.

[citation needed]

With all due respect, I think this statement is false.

If you live in a society that can, thanks to advanced technology, provide for the material needs of all, which, if you live in a rich Western country, is basically already the case (remember the last time you had to actually grow your own food? Probably several generations ago), you don't need to execute anyone.

Indeed, given that in such a society, where there are no shortages of food leading to "only one of us can eat" type scenarios, I'd argue that hurting individuals would lower aggregate wellbeing, because you're hurting people beloved by other people (the elderly? Turns out their grandchildren really like them and get upset if they die? fat people? Turns out their friends really like them and get upset if they die. the disabled? Turns out their family really like them and get upset if they die).

Re: We have a year to fix security everywhere

#254

I'm confused why the worry about LLMs that will answer "how do I build a pipe bomb". That information is easily available other places. The anarchist cookbook has been around and available for 55 years, and yet pipe bombs are not going off all around us.

There used to be a thing called "Moore's Law of Mad Science": "Every eighteen months, the minimum IQ necessary to destroy the world drops by one point." Nowadays it is dropping much faster. At a certain point, the de-facto IQ needed to destroy the world will be low enough that someone can do it while they're having a psychotic break. There are millions of schizophrenics worldwide. Are you sure you want to roll those…

Yes, and...

Not only the quantity of people who have the minimum aptitude required, specialized expertise requires both knowledge and experience doing these tasks. Using an LLM requires neither.

Leaning on an LLM to do much or all of this means it can happen in seconds/minutes/hours, the LLM can do it several times during that psychotic break (as opposed to a fraction of a hack in a single episode). The barrier to entry pre-LLM was both high and the population who could pull it off (before the Chinese/Russians turned this into commerce) was low.

Hacking is an VERY asymmetric activity (the attacker only needs to "be right" once, whereas the defender has to be right every time for every asset they defend). It takes geometrically / exponentially more work to defend (while keeping high availability) than it does to defend. The more widespread tools to find vulns / generate exploits are, the faster the posture of the defense side falls from "maybe we can stop most hacks" to "we know we will fail to prevent most breaches, so we need to prioritize securing only the most valuable resources". That's a BAD place for the average company to be in.

Re: We have a year to fix security everywhere

#255

Earlier quoted context omitted.

Glm 5.3 won't fit on a mac mini. The barrier to entry to host something scary is what, like $10k? 20k?

Moore's law still holds I reckon. Even it's $10,000 to run today (FWIW, the featured article cites the M5 Mac Studio with 256GB unified memory going for $9,500 as "good enough to host something scary"), in a couple years it'll be like $2k to run, and in another couple after that, you'll have used $200 dollar smartphones capable of running a model powerful enough to do serious damage.

Haven't ram prices been a linear drop since 2010 before chatgpt rampocalypse? I don't think it's "still" anymore but perhaos some progress will be made in the model front

Re: We have a year to fix security everywhere

#256

Earlier quoted context omitted.

The author put in the numbers, but maybe you didn’t read them. 45 t/s a second is perfectly respectable especially with no limits and 24/7 uptime with very little power draw on the Studio. Luna is at around 100 t/s for comparison, but it’s a worse model than 5.3 Flash

I think it's been pretty much proven by now that there are no cases where local inferencing is better than remote inferencing, unless absolute privacy is a hard requirement. The efficiencies that come with datacenter scale and hw can't be beaten.

Yeah, but data centers don't usually host abliterated models, hence the point of the article.

Re: We have a year to fix security everywhere

#257

I'm confused why the worry about LLMs that will answer "how do I build a pipe bomb". That information is easily available other places. The anarchist cookbook has been around and available for 55 years, and yet pipe bombs are not going off all around us.

Any sufficiently determined individual can buy mac mini, put it under their bed, configure outside proxy via some random internet address and prompt "iterate on websites in the CT logs, one by one, try to find vulnerabilities, if you did - encrypt their data and blackmail them for this bitcoin address". And it'll work, day and night. Abliterated GLM 5.3 is much smarter than average software developer, they know a lot…

FBI open up!

Re: We have a year to fix security everywhere

#258
post #118

Earlier quoted context omitted.

You can't design an infectious pathogen without testing it. It's got all the same problems as the concept of a dirty bomb did, only worse (dirty bombs aren't practical because handling highly radioactive materials en masse is both highly visible and will kill anyone trying to do it without the money and facilities).

If the goal is just destruction then letting it free in random public places is not that hard. Especially in countries where wearing a mask is not frowned upon.

It (hopefully) might not be that easy. The world of bacteria and viruses is a complicated war zone with an arms race of defenses and billions of deaths every single day. It might take thousands of attempts to seed something that doesn’t just instantly die off.

Re: We have a year to fix security everywhere

#259
post #8

Here's an idea: as a first step, simplify everything, and make sure you're aware how your stack works, and what it imports. As an example: WordPress is a horrible thing, but the core has been through so much, that it's suprisingly secure. Then plugins and themes come, and whoosh, the security is gone. We need a new KISS: keep it simple, stupid, secure.

The reason is simple - nothing really bad has happened that we can point at and say "ah, shit, let's all learn collectively". I know it sounds naive when I say it, but there hasn't been a significantly consequential hack, leak, destruction, or anything related to cybersecurity where it led for concerns of people. The main thing I can think of is cyber insurance, which requires a bunch of audits, and some checks maybe…

Maersk[1] might be the worst so far (and that was ransomware rather than state-sponsored aggression). It's still too niche for most people to care about.

[1] https://www.wired.com/story/notpetya-cyberattack-ukraine-rus...

Re: We have a year to fix security everywhere

#260

I'm confused why the worry about LLMs that will answer "how do I build a pipe bomb". That information is easily available other places. The anarchist cookbook has been around and available for 55 years, and yet pipe bombs are not going off all around us.

Well, folks who do such things are rare, but the next one might have a lot more impact.
Post reply on HN