Live data from Hacker News

We have a year to fix security everywhere

jyn.dev

261–270 of 373 posts

Re: We have a year to fix security everywhere

#261

I'm confused why the worry about LLMs that will answer "how do I build a pipe bomb". That information is easily available other places. The anarchist cookbook has been around and available for 55 years, and yet pipe bombs are not going off all around us.

Any sufficiently determined individual can buy mac mini, put it under their bed, configure outside proxy via some random internet address and prompt "iterate on websites in the CT logs, one by one, try to find vulnerabilities, if you did - encrypt their data and blackmail them for this bitcoin address". And it'll work, day and night. Abliterated GLM 5.3 is much smarter than average software developer, they know a lot…

[flagged]

Re: We have a year to fix security everywhere

#262

Earlier quoted context omitted.

I have always hypothesised that AI is the great filter from the Fermi paradox. Given current velocity, AI will offer us cheap and abundant energy designs in a decade. The thing with cheap and abundant energy is that it can be used for good and bad. If nine billion people all receive access to plans to build a reactor which produces unlimited energy, it just takes one religious fanatic to end the world. And this is ju…

The implication of this is quite horrifying. It means a paternalistic AI which is firmly in control. One with no off switch. One which can say "no" to Presidents and despots alike. One which can protect us from our worst citizens. I think you're right, to be honest. I fully understand why people would think this is a horrific outcome, being ruled by AI, but I don't think it matters what we think. I don't think there'…

There is a burgeoning anti-AI movement. We've regulated the heck out of technologies like nuclear power in the past. I don't see why people are so fatalistic about the supposed inevitability of AI development. It seems like a bit of a self-fulfilling prophecy.

Consider joining https://pauseai.info/ or similar organizations

Re: We have a year to fix security everywhere

#263
post #8

Here's an idea: as a first step, simplify everything, and make sure you're aware how your stack works, and what it imports. As an example: WordPress is a horrible thing, but the core has been through so much, that it's suprisingly secure. Then plugins and themes come, and whoosh, the security is gone. We need a new KISS: keep it simple, stupid, secure.

Static sites all the way (hugo, jekyll, mkdocs!). No one needs wordpress. There's even Sveltia or DecapCMS now, to give those WYSIWYG-people access to static site editing. Then, remove PHP and all the dependency overhead and attack surface and you have a stripped down nginx that is pretty simple, minimalistic and bulletproof.

> Static sites all the way (hugo, jekyll, mkdocs!). No one needs wordpress.

Maybe. A better question may be about how many people need to have the dynamic part of Wordpress live on the Internet? How many would be served well enough with the CMS aspects of Wordpress on the 'backend', but have it spit out static files for the 'frontend':

* https://wordpress.org/plugins/simply-static/

* https://wpstatic.site

Re: We have a year to fix security everywhere

#264

I'm confused why the worry about LLMs that will answer "how do I build a pipe bomb". That information is easily available other places. The anarchist cookbook has been around and available for 55 years, and yet pipe bombs are not going off all around us.

I'm still waiting for someone to build a fine-tuned local "Anarchist Cookbook" LLM. We haven't seen LLMs tuned for bad purposes yet, I have to imagine someone somewhere is thinking about it.

Re: We have a year to fix security everywhere

#265
post #179

Earlier quoted context omitted.

There used to be a thing called "Moore's Law of Mad Science": "Every eighteen months, the minimum IQ necessary to destroy the world drops by one point." Nowadays it is dropping much faster. At a certain point, the de-facto IQ needed to destroy the world will be low enough that someone can do it while they're having a psychotic break. There are millions of schizophrenics worldwide. Are you sure you want to roll those…

Kind of passed that point at the Trump election. If there is to be a world-destroying event, it will be triggered by human fear, greed, and aggression. (I also think people massively overstate schizophrenia as an attack driver)

The exact 2 points I was itching to make. The political dice rolled some time ago ...

Re: We have a year to fix security everywhere

#266
post #5

I don't think we even have a year. The current batch of LLMs are ferociously good at identifying vulnerabilities.

The long tail is what scares me. Chrome will get fixed. Major OSes will get fixed. But your enterprise software and all your appliances? Shit.

Re: We have a year to fix security everywhere

#268

Earlier quoted context omitted.

> It's not the end of the world. But future will be rough. Short term you’re probably right, but longer term is the realm where nation states will start to police the avenues of attack. This is what will lead to govt needing to attach an actual ID your network connection. I think it’s a bit like frontier development (like the US “Wild West”). You rob a bank because there’s no one to stop you, and even if you do get i…

Even in China you can find a way out and build a tunnel. And once you built a tunnel to any outside server, you can jump into another server. So three jurisdictions and your target is fourth. Imagine untangling the links. Police won't do that. Not for some small-sized business anyway. I don't see how you can prevent something like that.

But I think you can do psychotic shit like applying punishing sanctions to anywhere that permits an ungoverned connection. Or apply physical force (military).

I’m not saying we’re even remotely close to this, I’m just saying State-level coercive action is not unheard of if a problem is perceived to be significant enough to warrant it. Shit, it even only needs to be viewed as significant by a small subset of the governing body (see: Iran conflict, or current pushes for “child safety on the internet”). It just has to be “useful” to a certain body politic.

Re: We have a year to fix security everywhere

#269
post #239

Earlier quoted context omitted.

City Desk. Where is Joel when we need him!

Retired and probably just chilling around the world.

If I wasn't making 5 other things right now I'd consider making something like city desk. Every other day there are complaints about bots smashing peoples servers. Perhaps its time for a better static site generator.

Re: We have a year to fix security everywhere

#270
post #151

Earlier quoted context omitted.

That law is not based on thorough data. Even a person with a sky high IQ can't destroy the world easily. You need access to stuff that is not easy to get. My guess is that developing a new lethal virus or bacteria that is very infectious, is the easiest way, but even that requires a lot of high tech out of reach of most people. Or hacking into systems that control nuclear missiles, but I think these have "air gaps".

> My guess is that developing a new lethal virus or bacteria that is very infectious, is the easiest way, but even that requires a lot of high tech out of reach of most people. You can do at home gene editing with open source software and have it synthesized into a bacteria for the cost of a nice meal for two (under $100), or viral vector for less than $500. That's in reach of anyone that can snatch a purse.

I think you're confusing DNA sequencing with DNA synthesis. DNA synthesis is much more expensive, around $0.07 per base pair [1], and bacteria have more than a million, so it's over $70.000. Then you just have the DNA, turning that into the bacteria is very complex, I'm not even sure whether it can be done.

Using CRISPR to modify existing bacteria is probably cheaper, but still complex.

[1] https://briefglance.com/articles/elegen-slashes-dna-synthesi...

Post reply on HN