Live data from Hacker News

Trusted access for the next era of cyber defense

openai.com

61–70 of 79 posts

Re: Trusted access for the next era of cyber defense

#61
post #43

I don't think they've added enough cyber. My cyber workflow demands more trusted access for cyber so that I can use these cyber-permissive models for my cybersecurity.

It's a source of minor, but persistent, annoyance that security people have tried to abscond with the prefix cyber, morphing it into a synonym for security. Having grown up reading cyberpunk novels about life in cyberspace, a passing interest in cybernetics (though not of the Sirius Cybernetics Corporation variety), it's frustrating to lose a 'this means computer or internet related' prefix.

As far as I can tell, using the word cyber to specifically and only talk about security has come from the kind of suits who take Gartner seriously.

I don't know any techies who use the term like that, unless they're in a role that interfaces with the suits.

Re: Trusted access for the next era of cyber defense

#62

It's important to keep perspective, the holes that everyone (including LLMs now) keep finding in pretty much everything are mostly the fault of running things with ambient authority, instead of using systems based on default deny, and capabilities. I used to think we were 20 years away from a shift to Capabilities based Operating Systems, which were ----> this Unfortunately, I think we're about to repeat history, and…

"Solve things" or actually do something useful, pick one.

If anything, maybe the security community can finally be arsed to consider ad-hoc delegation of authority as a core concept and a basic use case, because that's arguably the primary source of persistent user-level security issues in computing.

In real life, it's absolutely normal to ask random people on the fly to do something in your name, with your credentials - whether that's sending your kid with your credit card for a grocery run, asking spouse to do some bank transfers for you or set up a new computer for you, or asking a co-worker to operate some system. It's the other reason people write passwords on post-its: even without bullshit password strength rules (see xkcd://936), there's still a frequent need to share passwords with people.

Meanwhile, for the past decades, security community has been insisting on tying authority to individuals, and doing everything possible both technologically and socially to prevent authority delegation (except in top tier corporate systems, where this is technically supported, but in such convoluted, complex and broken ways that it may as well not exist - people will still resort to post-its in drawers).

Until this basic concept is recognized, I fear more broad security improvements will only result in more useful work being prevented from happening, and more people-years wasted as users figure out ways to defeat security measures so they can do their actual jobs.

Re: Trusted access for the next era of cyber defense

#63
post #8

>democratized access >partner with a limited set of organizations for more cyber-permissive models. I get where they're going with this, but still rather hilarious how they had to get a corporate speak expert pull of the mental gymnastics needed for the announcement

No need for corporate speak experts anymore, SOTA LLMs are more than capable of doing that job now.

Re: Trusted access for the next era of cyber defense

#64

It's important to keep perspective, the holes that everyone (including LLMs now) keep finding in pretty much everything are mostly the fault of running things with ambient authority, instead of using systems based on default deny, and capabilities. I used to think we were 20 years away from a shift to Capabilities based Operating Systems, which were ----> this Unfortunately, I think we're about to repeat history, and…

Many (maybe even most bugs) the ais are finding are memory safety errors, which is pretty clearly not "the fault of running things with ambient authority". The data is treated as untrusted, but due to a mistake can still do something it shouldn't.

Re: Trusted access for the next era of cyber defense

#65

Earlier quoted context omitted.

In the early days of socialization on the Internet it had a very different meaning!!

In my headcanon, I still read k8s as "network of cubes", as in Borg cubes, as Kubernetes itself is a poor man's Borg (as in the thing that Google runs on, named after Star Trek Borg, known for cube-shaped ships referred to as "Borg cubes"). The whole kyber thing sounds like an explanation after the fact, to detach from the Collective legacy.

Have they ever released the full internal Borg toolset and software ?

Re: Trusted access for the next era of cyber defense

#66

It's important to keep perspective, the holes that everyone (including LLMs now) keep finding in pretty much everything are mostly the fault of running things with ambient authority, instead of using systems based on default deny, and capabilities. I used to think we were 20 years away from a shift to Capabilities based Operating Systems, which were ----> this Unfortunately, I think we're about to repeat history, and…

"Solve things" or actually do something useful, pick one. If anything, maybe the security community can finally be arsed to consider ad-hoc delegation of authority as a core concept and a basic use case, because that's arguably the primary source of persistent user-level security issues in computing. In real life, it's absolutely normal to ask random people on the fly to do something in your name, with your credentia…

Are those really things people do all the time ? Not sure I would trust any kid with my credit card

Re: Trusted access for the next era of cyber defense

#67

Earlier quoted context omitted.

First, it looks like an "AI psychosis" paper. AI psychosis has been going through armchair philosophers the way crack was going through the low income neighborhoods back in the 80s. Second, it does not look relevant to the discussions in any way, fashion or form.

If I didn’t empirically prove it I would agree with you. Computation and semiotics are two fields that want nothing to do with each other. The SRT is through several stages of quantitative validation. For the first time in 150 years semiotics is not a philosophy. It is proven to have computational value. The SRT bolts onto any model and improves it. I’ll be sure to link you to the benchmarks when published. The relev…

Bold fucking claims for a "paper" that: makes an LLM with an awkward architectural tumor, and proves that it doesn't completely die on a purely synthetic task.

Further than most "AI psychosis" papers go, but still not in any way far.

And "makes these treasured black boxes irrelevant"?

With wild claims like this, either demo a generational improvement on a live model or GTFO.

Re: Trusted access for the next era of cyber defense

#68

Earlier quoted context omitted.

If I didn’t empirically prove it I would agree with you. Computation and semiotics are two fields that want nothing to do with each other. The SRT is through several stages of quantitative validation. For the first time in 150 years semiotics is not a philosophy. It is proven to have computational value. The SRT bolts onto any model and improves it. I’ll be sure to link you to the benchmarks when published. The relev…

Bold fucking claims for a "paper" that: makes an LLM with an awkward architectural tumor, and proves that it doesn't completely die on a purely synthetic task. Further than most "AI psychosis" papers go, but still not in any way far. And "makes these treasured black boxes irrelevant"? With wild claims like this, either demo a generational improvement on a live model or GTFO.

I’ve been here over a decade longer than you sport. No need to bully people out when you are only 8 months in. I will be updating here when the model is live. Expect no further engagement.

Re: Trusted access for the next era of cyber defense

#69
post #33

I don't think they've added enough cyber. My cyber workflow demands more trusted access for cyber so that I can use these cyber-permissive models for my cybersecurity.

you make fun of it but i kind of like that the security community has just embraced this kinda old school hokey term. its a short hand. leave them be.

[deleted]

Re: Trusted access for the next era of cyber defense

#70

Earlier quoted context omitted.

"Solve things" or actually do something useful, pick one. If anything, maybe the security community can finally be arsed to consider ad-hoc delegation of authority as a core concept and a basic use case, because that's arguably the primary source of persistent user-level security issues in computing. In real life, it's absolutely normal to ask random people on the fly to do something in your name, with your credentia…

Are those really things people do all the time ? Not sure I would trust any kid with my credit card

[deleted]
Post reply on HN