Live data from Hacker News

AI browser extensions are a security nightmare

kolide.com

41–50 of 129 posts

Re: AI browser extensions are a security nightmare

#42

Earlier quoted context omitted.

I’m hesitant to even call this moving the goal posts. Intelligence has never been solidly defined even within humans (see: IQ debate; book smart vs street smart; idiot savants). It’s unsurprising that creating machines that seem to do some stuff very intelligently and some other things not very intelligently at all is causing some discontent with regard to our language. I see a whole lot more gnashing of teeth about…

> I’m hesitant to even call this moving the goal posts. Intelligence has never been solidly defined even within humans (see: IQ debate; book smart vs street smart; idiot savants). > It’s unsurprising that creating machines that seem to do some stuff very intelligently and some other things not very intelligently at all is causing some discontent with regard to our language. I think I agree about the language. I don’t…

Conceptually Speaking you can reduce it down to Intelligence and strip out the Artificial Label.

So know the question is what is Intelligence. Our standardized testing Model tells us passing tests that Humans cannot would be considered intelligent.

Then add back in artificial to complete the equation.

Commercially the Term Ai Means nothing thanks to years of Machine Learning being labeled such. It's arbitrary and relays more to Group Think to avoid approaching that Intelligence is a Scalar Value and not a Binary Construct.

Re: AI browser extensions are a security nightmare

#43
post #2

> Yes, large language models (LLMs) are not actually AI in that they are not actually intelligent, but we’re going to use the common nomenclature here. I'm sorry for the off-topic comment, but why do I keep seeing this? What am I missing here – is it that some people define intelligence as >= human, or that LLM are not intelligence because they're *just* statistical models?

I say that large language models are not intelligent because of the way they fail to do things. In particular, they fail in such a way as to indicate they have no mental model of the things they parrot. If you give them a simple, but very unusual, coding problem, they will confidently give you an incorrect solution even though they seem to understand programming when dealing with things similar to their training data.

An intelligent thing should easily generalize in these situations but LLMs fail to. I use GPT4 every day and I frequently encounter this kind of thing.

Re: AI browser extensions are a security nightmare

#44

Earlier quoted context omitted.

> LLM are not intelligence because they're just statistical models This is exactly it for me.

Its interesting to see what it thinks about some ideas, like I ask, what 5 companies are best at marketing. My goal here is to be hypercritical of the companies it says because they are masters at manipulation. GPT3.5 was awful and confused advertising and marketing. GPT4 was perfect (Apple, Nike, Coke, Amazon, P&G) As much as chatgpt doesnt want to give you answers because the fuzziness, it has the ability to make j…

Does it have the ability or is it just generating text similar to what it has seen before? The two things are very different.

Re: AI browser extensions are a security nightmare

#45
post #14

Earlier quoted context omitted.

> LLM are not intelligence because they're just statistical models This is exactly it for me.

Are you intelligent or just a bunch of cells? Given that I can query it for all sorts of information that I don’t know, I would consider LLMs to, at the very least, contain and present intelligence…artificially.

I can query Wikipedia or IMDB for all sorts of information I don't know. I wouldn't consider the search box of either site to be "intelligent", so I don't know "query it for all sorts of information" is a generally good rubric for intelligence.

Re: AI browser extensions are a security nightmare

#46
post #42

Earlier quoted context omitted.

> I’m hesitant to even call this moving the goal posts. Intelligence has never been solidly defined even within humans (see: IQ debate; book smart vs street smart; idiot savants). > It’s unsurprising that creating machines that seem to do some stuff very intelligently and some other things not very intelligently at all is causing some discontent with regard to our language. I think I agree about the language. I don’t…

Conceptually Speaking you can reduce it down to Intelligence and strip out the Artificial Label. So know the question is what is Intelligence. Our standardized testing Model tells us passing tests that Humans cannot would be considered intelligent. Then add back in artificial to complete the equation. Commercially the Term Ai Means nothing thanks to years of Machine Learning being labeled such. It's arbitrary and rel…

[deleted]

Re: AI browser extensions are a security nightmare

#47
post #2

> Yes, large language models (LLMs) are not actually AI in that they are not actually intelligent, but we’re going to use the common nomenclature here. I'm sorry for the off-topic comment, but why do I keep seeing this? What am I missing here – is it that some people define intelligence as >= human, or that LLM are not intelligence because they're *just* statistical models?

It's a way for the author to distinguish himself as one who is neither a purveyor of, nor fooled by, the magic, grift, and cringy sci-fi fantasizing that currently comprises the majority of AI discussion. Currently, most mentions of AI, outside of a proper technical discussion, are coming from crypto-tier grifters and starry-eyed suckers. Even further, a lot of discussions from otherwise technical people are sci-fi-t…

In my field it's accepted (by some) that you write "AI" for your grant proposal and say "ML" when you talk to colleagues and want to be taken seriously.

It feels a bit wrong to me, because as you say it's arguably a grift, in this case on the taxpayer who funds science grants. More charitably it might just be the applicant admitting that they have no idea what they are doing, and the funding agency seeing this as a good chance to explore the unknown. Still, unless the field is AI research (mine isn't) it seems like funding agencies should giving money to people who understand their tools.

Re: AI browser extensions are a security nightmare

#48
post #17

Earlier quoted context omitted.

How would you allow changing page contents with a narrow permission?

I also have a Chrome extension that needs access to page content on all pages, for the purpose of making text easier to read. I could see distinguishing between extensions that in any way exfiltrate data from the pages you view, versus extensions that process the DOM and do something locally, but never send the data anywhere. This requires a bit closer vetting than Google currently does, I think. To demonstrate that…

There are hundreds of thousands of extensions, and none of them make Google any money. Hard to see how they could justify any serious manual review.

Re: AI browser extensions are a security nightmare

#49
post #47

Earlier quoted context omitted.

It's a way for the author to distinguish himself as one who is neither a purveyor of, nor fooled by, the magic, grift, and cringy sci-fi fantasizing that currently comprises the majority of AI discussion. Currently, most mentions of AI, outside of a proper technical discussion, are coming from crypto-tier grifters and starry-eyed suckers. Even further, a lot of discussions from otherwise technical people are sci-fi-t…

In my field it's accepted (by some) that you write "AI" for your grant proposal and say "ML" when you talk to colleagues and want to be taken seriously. It feels a bit wrong to me, because as you say it's arguably a grift, in this case on the taxpayer who funds science grants. More charitably it might just be the applicant admitting that they have no idea what they are doing, and the funding agency seeing this as a g…

Most people outside of academia understand AI to include way more than just ML. People refer to the bots in video games as AI and they are probably a few hundred lines of straightforward code.

I don't think there is anything wrong with using the colloquial definition of the term when communicating with funding agencies/the public.

Re: AI browser extensions are a security nightmare

#50

Earlier quoted context omitted.

Its interesting to see what it thinks about some ideas, like I ask, what 5 companies are best at marketing. My goal here is to be hypercritical of the companies it says because they are masters at manipulation. GPT3.5 was awful and confused advertising and marketing. GPT4 was perfect (Apple, Nike, Coke, Amazon, P&G) As much as chatgpt doesnt want to give you answers because the fuzziness, it has the ability to make j…

Does it have the ability or is it just generating text similar to what it has seen before? The two things are very different.

In this examples, it likely took that those companies are often praised about their marketing in the same sentence marketing is mentioned.

LLMs don't repeat text its seen before, it links words/tokens/phrases that are related. Its prediction, but the prediction isnt just copypasting a previous webpage.

Have you use chatgpt yet? I wouldn't delay. Heck you are here on HN, you basically have a responsibility to test it.

Post reply on HN