Live data from Hacker News

Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers

theregister.com

341–350 of 382 posts

Re: Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers

#341

"I feel like making ’90s-style t-shirts with ‘fix this code’ on the front and ‘this shirt is a munition’ on the back.” I'd buy that shirt.

Reminds me the tv show “Hugo” that was taken off air because a kid said “f.ck this shit” while playing with a rotary phone, and still pisses a lot of people who couldn’t play the game afterwards.

Re: Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers

#342

this is basically trying to enforce security-by-obscurity, which is a terrible idea all around. it's just a model. the security issues still exist and are exploitable. and after staking the economy on AI, you can't really put a cap on intelligence. if models are not allowed to be better than Opus 4.8, then the whole investment structure is about to unravel. why invest billions and billions into AI if returns are arti…

Wow, it's starting to seem like the choice is essentially between an intelligence cap that pops the bubble, and an increasingly chaotic and unpredictable cybersecurity environment with major hacks and exploits left and right.

Re: Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers

#343

As an European, I really don't get where this strategy wants to take the USA to. It's pretty clear everyone is getting scared about changes like this that happen overnight, without clear reason and completely unpredictable. Business requires a stable environment, and Trump is making everything in his power to disrupt business stability. Ultimately, I see the rest of the world (especially Europe) relying less and less…

What European hardware would be used instead?

Re: Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers

#344

As an European, I really don't get where this strategy wants to take the USA to. It's pretty clear everyone is getting scared about changes like this that happen overnight, without clear reason and completely unpredictable. Business requires a stable environment, and Trump is making everything in his power to disrupt business stability. Ultimately, I see the rest of the world (especially Europe) relying less and less…

The divorce is already happening, House of El made a video yesterday summing up the alternate routes taken by European governments. https://youtu.be/KQ2ndCqRJDM?si=V1tT-TuGME4LoFki

Re: Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers

#345
What's more dangerous, a version that's capable of actually fixing bugs well because it can identify the bugs or a version that creates more bugs because it's "not dangerously powerful" and instead just obliterates the code.

Re: Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers

#346
post #83
post #41

Earlier quoted context omitted.

Can we retire the “seatbelts are useless because they can’t prevent every loss of life” approach to risk mitigation please? If the acceptance criteria is “would prevent every single past instance and every imaginable future instance”, then yes, no mitigation is every sufficient to address any problem in the world, so we might as well give up. But I don’t think that’s the right lens to use.

That depends on whether it's a issue of accidents or a "you have to get lucky every time, we only have to get lucky once" issue.

Death only has to get lucky once. Are you going to stop wearing seatbelts?

Re: Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers

#347

So the problem is not Fable's ability to exploit, but that they don't want people to have access to it's ability to patch vulnerabilties? Wow.

You can't really have one without the other..

I admit I hadn't really thought about that before (I don't work specifically in security), but I see your point.

But, so... the solution people think is limiting people's ability to discover and patch vulnerabilities, and hoping the black hats won't find a way anyway? This does not seem like a sustainable or feasible plan. It does, to be honest, make me wonder how much of the government's motivation is ensuring that they have access to vulnerabilities that remain unpatched.

Re: Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers

#348

Earlier quoted context omitted.

Many, many years ago I was asked to implement a filter like that for usernames. I said right away that it wasn't going to work well, but I did implement it. Next internal build, the CEO can't create an account. With his real name. It worked exactly to spec; I added a debug print and showed everyone the "bad word" it tripped on. The idea was promptly rethought. I feel like the AI did you a favour here.

Now I'm trying to figure out which word that would be, but yeah. That reminds me of a bug I fixed where my bosses boss found it, we did everything, my boss at the time forced us to deploy anything and call it fixed. Then someone else saw it half a year later, I finally figured out the root cause and fixed it (localStorage vs sessionStorage) and my boss was acting like he didn't know what I was talking about, but I co…

Two of my co-workers have the last names Dyck and Cox. I've seen others whose last name is literally Dick. And let's not forget the famous actor Dick Van Dyke who strikes out twice on most filters. I've heard several other names from other ethnicities that were straight up "slurs" by some people's standards. The only thing harder than matching a slur is deciding what words count as slurs.

Re: Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers

#349
post #329
post #282

Earlier quoted context omitted.

This is the same way you get people to do bad stuff as well. Make the task small enough so that the moral curvature of the topology is flat and even though they know it is a not-good part of a larger bad part they just shrug. Look at all the wonderful people we know who are working at Amazon and Meta? Corporatism has already jailbroken society.

I don't think people working at Amazon "know that it is a part of a larger bad", it's one of the most trusted American institutions. https://www.theargumentmag.com/p/why-everyone-loves-amazon

You really don't think know they are selling endless counterfeit products? Don't know they are taking part in massive return fraud against small sellers? You don't think they know they totally ignore sellers with problems even if their livelihood depends on it?

Re: Feds freaked over Fable 5 after 'fix this code', not jailbreak, say researchers

#350

this is basically trying to enforce security-by-obscurity, which is a terrible idea all around. it's just a model. the security issues still exist and are exploitable. and after staking the economy on AI, you can't really put a cap on intelligence. if models are not allowed to be better than Opus 4.8, then the whole investment structure is about to unravel. why invest billions and billions into AI if returns are arti…

Wow, it's starting to seem like the choice is essentially between an intelligence cap that pops the bubble, and an increasingly chaotic and unpredictable cybersecurity environment with major hacks and exploits left and right.

But those hacks and exploits have always existed. Just had to have the right people to find them / be sufficiently motivated.

The same models that can find these exploits can also help fix them, thus everyone will be better off.

Relying on the fact that nobody has found a security issue with a piece of software yet is not a great way to ensure safety

Post reply on HN