Live data from Hacker News

We have a year to fix security everywhere

jyn.dev

371–373 of 373 posts

Re: We have a year to fix security everywhere

#371

Earlier quoted context omitted.

You wouldn’t talk about ransomware like that for precisely the reasons you’d described: it’s a poorly defined open ended problem. You should tackle security in the same way you’d tackle any other kind of engineering initiative in IT. You break the problem down to identifiable tasks that can be easily marked as completed or not required (eg like developers track work in a KANBAN or sprint). So to take your ransomware…

Isn't that just sidestepping the issue? Setting up backups isn't a security task, it's just normal IT which businesses do indeed spend on because there are clear goals and predictable budgets. But just being able to restore data isn't the same thing as not getting ransomware. As you say, you can't define the latter as a goal exactly because it's a security goal, and so will turn into an infinitely long checklist of t…

> Isn't that just sidestepping the issue?

No. It’s addressing the risks of the issue.

> Setting up backups isn't a security task, it's just normal IT which businesses do indeed spend on because there are clear goals and predictable budgets.

All IT security issues are just normal IT.

And the processes I described are how you get clear goals and budgets.

> But just being able to restore data isn't the same thing as not getting ransomware.

The backups are an example. It’s not an exhaustive list of countermeasures.

My point is “not getting ransomware” is a vague and undefined goal like “improve performance”, “add monitoring”, “improve UX”, etc. Any initiative in IT needs to have clearly defined objectives that can be broken down and marked as completed when done. It doesn’t matter if that initiative is software development, UI design or security.

> As you say, you can't define the latter as a goal exactly because it's a security goal, and so will turn into an infinitely long checklist of things you could potentially do with no guarantee of payoff.

Exactly. And that’s why my examples are not sidestepping the issue. They’re just definable subtasks around the risk you’ve identified.

Re: We have a year to fix security everywhere

#372

Earlier quoted context omitted.

It would be much harder to deny it if any of you were capable of describing the risks. The current discussion is a national-scale Handwavium mine.

If these systems allow anyone with an internet access or a few grands to run an open model to obtain the necessary information to e.g. build a bomb, spread an infectious agent, hack water or electrical infrastructures, I think that creates significant threats to the population.

These systems don't enable that. Building a bomb, spreading a bioweapon and hacking water/electrical misconfigurations are all trivially possible without AI. Courtesy to Unibomber, Aum Shinrikyo and the IRGC, respectively, for teaching society this.

In any case, how would AI regulation prevent any of these things? Shouldn't we instead focus on limiting access to bomb/bioweapon precursors and securing vulnerable endpoints, since that is the solution that saves lives regardless of how AI disseminates? Regulating AI is expressly dangerous, if it expands that societal blind spot. It'd be like regulating red mercury.

Re: We have a year to fix security everywhere

#373
post #359

Earlier quoted context omitted.

Well that's funny, because you were making some pretty blanket statements upstream about how they "never" do this and "always" do that. And yet your experience seems extremely limited and niche, by your own admission. Maybe you should experiment a little more. I think you will quickly learn that your previous impression is wrong. The days of them being merely some sort of jumped up autocomplete are years gone.

Look, I know you believe in the Mystical GPU Sky Fairy, but AI is not in any sense "intelligent". It doesn't think. It's a pattern-matching system like an Eliza bot with a huge corpus to draw from. It is not thinking. It cannot think. It cannot create.

None of that has anything to do with anything either of us said to you, and is also well outside of how people are expected to converse here.
Post reply on HN