Live data from Hacker News

We have a year to fix security everywhere

jyn.dev

271–280 of 371 posts

Re: We have a year to fix security everywhere

#272
post #22
post #15

[flagged]

Supply chain risks are essentially a solved problem. 1. Set a minimum age on dependencies: https://github.com/rust-lang/cargo/issues/15973 2. Scan all dependency code with AI Even if you don't do #2 yourself as long as anyone does in the age window you've set, you're protected. In the age of AI the "you can't read all dependency code" argument doesn't work anymore. On top of the above modern age argument, let's compa…

If I look at actual incidence involving memory safety issues compared to supply chain issues in general, it is the later which is much a higher risk to me.

And yes, there were successful supply chain attacks on Rust developers, even just recently: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on... despite this being a "solved" problem. I think this becomes worse with AI not better, while memory safety risks will probably get much less in other languages after possibly some higher rate for a while.

Re: We have a year to fix security everywhere

#273

Earlier quoted context omitted.

I have always hypothesised that AI is the great filter from the Fermi paradox. Given current velocity, AI will offer us cheap and abundant energy designs in a decade. The thing with cheap and abundant energy is that it can be used for good and bad. If nine billion people all receive access to plans to build a reactor which produces unlimited energy, it just takes one religious fanatic to end the world. And this is ju…

You’re leaving out some options for sure. Not everyone would need to live under the conditions of a police state, you could theoretically screen everyone and assign them to various levels of risk which would determine their level of supervision.

While true, I'm not sure this is much better. There are many genetic traits which are correlated with increased criminality, risk taking, obesity, heart disease, unemployment, etc. IQ in particular is the most well correlated metric we have for criminality, for example. This would imply that some people are just born with fewer freedoms. That's probably a good thing for society in aggregate, but something about this doesn't feel quite right.

Re: We have a year to fix security everywhere

#274

I'm confused why the worry about LLMs that will answer "how do I build a pipe bomb". That information is easily available other places. The anarchist cookbook has been around and available for 55 years, and yet pipe bombs are not going off all around us.

> I'm confused why the worry about LLMs that will answer "how do I build a pipe bomb".

The author too is confused, asserting that telling people how to build pipe bombs is malicious.

Re: We have a year to fix security everywhere

#275
post #130

Earlier quoted context omitted.

This is a very roundabout way of saying "Anyone not agreeing with me is simply not smart enough". Which might be true, sometimes, but also might not. And especially will not, if the distinction drawn is between blanket statement "worried about AI" and "not worried about AI".

It's not about being smart, it's about accounting for your own ignorance. >And especially will not, if the distinction drawn is between blanket statement "worried about AI" and "not worried about AI". I'm just describing the general pattern I see in cognitive tendencies. If you can think of a way to make the fundamental point about the limitations of our knowledge in a way that's still compelling but less antagonisti…

Perhaps the general pattern you see is not a "fundamental difference"? Could it be that you are also falling prey to the "all you see is all there is" cognitive bias?

Re: We have a year to fix security everywhere

#276

Earlier quoted context omitted.

There used to be a thing called "Moore's Law of Mad Science": "Every eighteen months, the minimum IQ necessary to destroy the world drops by one point." Nowadays it is dropping much faster. At a certain point, the de-facto IQ needed to destroy the world will be low enough that someone can do it while they're having a psychotic break. There are millions of schizophrenics worldwide. Are you sure you want to roll those…

I have always hypothesised that AI is the great filter from the Fermi paradox. Given current velocity, AI will offer us cheap and abundant energy designs in a decade. The thing with cheap and abundant energy is that it can be used for good and bad. If nine billion people all receive access to plans to build a reactor which produces unlimited energy, it just takes one religious fanatic to end the world. And this is ju…

> The thing with cheap and abundant energy is that it can be used for good and bad.

Yes, but the more important thing is the imbalance. So-called "AI" can be used far more effectively and efficiently for bad.

> I have come to the conclusion that we should not allow everyone access to unlimited intelligence.

You meant unlimited information, right?

Re: We have a year to fix security everywhere

#277

I'm confused why the worry about LLMs that will answer "how do I build a pipe bomb". That information is easily available other places. The anarchist cookbook has been around and available for 55 years, and yet pipe bombs are not going off all around us.

How many hacking incidents are police involved in. Any authorities really? Basically none. Hacking is already extremely prolific.

Re: We have a year to fix security everywhere

#279

Earlier quoted context omitted.

That's quite hypothetical. I imagine it would be easier to cure psychotic breaks. At least it will start to manifest at small scale.

If the recent HuggingFace attack is any indication, many people will respond to small-scale manifestations by insisting that they are marketing stunts.

We live in an age where we know the phrase "avoid it like the plague" actually means "50% of us will gleefully get and transmit the plague to mock the other half".

Re: We have a year to fix security everywhere

#280

Earlier quoted context omitted.

I have always hypothesised that AI is the great filter from the Fermi paradox. Given current velocity, AI will offer us cheap and abundant energy designs in a decade. The thing with cheap and abundant energy is that it can be used for good and bad. If nine billion people all receive access to plans to build a reactor which produces unlimited energy, it just takes one religious fanatic to end the world. And this is ju…

You’re leaving out some options for sure. Not everyone would need to live under the conditions of a police state, you could theoretically screen everyone and assign them to various levels of risk which would determine their level of supervision.

This is why utpoias are actually police state hellscapes. Who decides what risk means? Our current administration has declared that simply being anti-facist makes you a terorrist.
Post reply on HN