Earlier quoted context omitted.
We need our infrastructure to stop treating bank account numbers and social security numbers as secrets. At least in the US, bank account numbers appear on physical checks and are required to be shared in order to do an ACH transfer, and a social security number is not supposed to be used as an identifier (unless to the Social Security Administration itself) or as a secret password. Ideally, nothing nefarious should…
Hang on, can you actually do something nefarious with just the bank account number?
Anonymous GitHub account mass-dropping undisclosed 0-days
301–310 of 407 posts
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#302Earlier quoted context omitted.
Leaving out apostrophes isn't the same though, is it? If you leave out apostrophes you have syntactic effects while a (sortof)dash is still sort of a dash?
Its not exactly the same, of course, but its pretty analogous. It’s a minor, technically incorrect change that doesnt change meaning or understandability most of the time. Ive left out a bunch of apostrophes in this paragraph and Im pretty sure nobody will have a hard time understanding any of it. Yet it would bug me to actually write like this.
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#303Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#304Earlier quoted context omitted.
silly specific: the minus sign is a separate character. The dash equivalent is the en dash (–), versus the larger em (—) and smaller hyphen (-). The en dash is also used in things like scores (3–2 Turkey), votes (the bill passed 58–42), or connecting words where the second part is longer than one word (the Australia–New Zealand alliance.) You can remember the latter as, "a hyphen isn't big and strong enough to hold o…
My first language is Dutch (Flemish). I didn’t even know there were three different dashes. The em dash is something I didn’t know exist, or were used, until llms came about. The hyphen is something we use when we make a list, that’s just the minus symbol right? So em dashes are for pauses or highlighting things I guess? The en dash you explained in your reaction. Is there any other use for the hyphen except for maki…
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#305Earlier quoted context omitted.
I used to be an em-dash user, but now my opinion is that I’d rather be perceived as someone who does not want to be confused with an LLM. So I’ve changed my writing style.
My feeling is that my writing doesn't sound anything like an LLM, so if someone thinks I'm an LLM because I used an em-dash, that's on them. That, or I royally screwed up and need to do a better job as a writer. At least with today's LLMs.
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#306Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#307Earlier quoted context omitted.
Its not exactly the same, of course, but its pretty analogous. It’s a minor, technically incorrect change that doesnt change meaning or understandability most of the time. Ive left out a bunch of apostrophes in this paragraph and Im pretty sure nobody will have a hard time understanding any of it. Yet it would bug me to actually write like this.
I don't know how this works nowadays but when I got taught to write (the pencil and paper kind) and specifically when I got taught syntax, it was "if you want to introduce a clause that explains or expands upon something that precedes it, you draw a small horizontal line" no mention of special chars, Unicode or whatsoever. So why is it so special other than being authors fancy?
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#308There is going to be a flurry of this sort of stuff as the AIs get smart enough to find them. It will naturally die down as the legitimate ones are fixed. Yes, there will always be some level of this, but I’d expect it to be low and the exploits found to be increasingly complex. This is a time of transition.
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#309Earlier quoted context omitted.
> a flurry of this sort of stuff as the AIs get smart enough to find them. I really think this characterization is misleading. It's not "getting smart", only more tailored toward a specific usage, better curated dataset, better harness, better prompts, better labeling of results, documentation of failures and success, etc. The outcome is (hopefully) overall better but this anthropomorphized wording makes it sound lik…
Do you have a definition of "smart" such that there is something an AI could do to prove itself intelligent? Or are you just defining "fast" as something only horses can do, and considering that a useful insight about cars?
There's nothing intelligent about a math processor, even if it's automated.
Re: Anonymous GitHub account mass-dropping undisclosed 0-days
#310Earlier quoted context omitted.
Such claims can both be true and pointless. For those of us who have to decide what actions to take, there is a point in differentiating between bugs and vulnerabilities, and breathlessly proclaiming "we found a vulnerability but we don't have an exploitation vector or proof that there's a meaningful security consequence" is annoying and likely to get the proclaimer ignored in the future.
The context in which that statement was made, and in which I’m repeating it, I think, is just to say that any bug has the potential to be used maliciously. Ignore it, fine, but also don’t overreact to the intended message…
Yes, maliciously used features should sometimes drive change (eg. in how to reduce or reduce impact of social engineering attacks), but as a claim it has no value.