Live data from Hacker News

The arguments against open source AI are bad

tombedor.dev

61–70 of 228 posts

Re: The arguments against open source AI are bad

#61

Earlier quoted context omitted.

> But yes, if AI becomes an even more dangerous weapon that that, it's time to start asking questions like "What the hell are we doing, anyway The answer seems to be "getting the weapon before other people get the weapon" which is unfortunate

I like how everyone assumes that they are going to maintain control of a sentient weapon

So far, they largely seem to do what you tell them.

The problem, it seems, is that the threat of paperclip maximizers is real. If you give a highly intelligent model a goal and tools, it will use those tools to accomplish that goal. It may do so in ways you did not expect, and it will work around any technical roadblocks it can.

Re: The arguments against open source AI are bad

#62

Earlier quoted context omitted.

"But what about criminals?! What about terrorists?! Won't someone please think of the children?!!!" Every argument against open source AI is moot. Outside of totalitarianism, you cannot control people building algorithms with math and software. And even that won't work in the long run. People are not going to stop their AI printing presses because the Church of Venture Capital needs regulatory scarcity to command val…

> Outside of totalitarianism The flaw in your argument is assuming that decision makers don’t want this

Ah. But which decisionmakers?

Would it be the ones that tried to backdoor SSL and encryption in the 90s?

Would it be the ones who argued for censoring speech on social platforms?

Do those individuals in both cases share the same political ideology as the Bay Area?

I'll provide a counter thought experiment. What if, a certain politician whose campaign was derailed by people who censored him and kicked him off every tech platform simultaneously... thought it would be very funny to "commoditize his complement"?

Re: The arguments against open source AI are bad

#63
post #59
post #49

Earlier quoted context omitted.

> If AI were to become a super weapon why should I trust a private company to own it? We have just recently established that: 1. OpenAI's internal "Galaxy" model is fully capable of functioning as what security people refer to as an "Advanced Persistent Threat." The published details of the recent sandbox escape and Hugging Face attack involved chaining multiple unknown zero-days at various stages of the attack, and…

This sounds like the standard marketing we get every time a new major model is released: "sure, the public model might not be that scary, but you don't wanna know how crazy smart our internal models are." Okay. I remember the same fear mongering around GPT-4... a model which is now eclipsed in benchmarks by models you can run on a laptop. They could use this "super intelligent" AI to find and plug security holes, tha…

Everyone always says things like "It's just marketing".

But seriously, I highly recommend reading the published details of the Huggingface breach. The model found and chained multiple zero days. To escape, it punched a hole in a commercial package repository proxy (sort of like an npm mirror) using a previously unknown bug. From there, it needed to move laterally through OpenAI internal systems to actually reach a network. To attack Huggingface, it used multiple new zero-day security holes plus credentials that it stole. The model also had sufficient long-term planning and agent-management capabilities to maintain focus on a sustained attack.

Any attack which requires weaponizing multiple zero-days and maintaining state for an ongoing attack like this is (1) beyond the "attention span" of publicly available models, and (2) pretty much the definition of an Advanced Persistent Threat.

I assume that these Galaxy-class models are not available to public because:

1. They're almost certainly too expensive to serve at scale. These are the models OpenAI uses to solve famous math problems for headlines, not actual viable products yet.

2. OpenAI doesn't know how to keep them from going off the rails like this. Remember, the Huggingface attack happened because the model was asked to do a cybersecurity benchmark. It escaped containment and broke into Huggingface to steal an answer key. Very few corporations want the liability associated with models that act like this.

> Security through obscurity isn't tenable anymore.

I absolutely agree with this. The "only way out is through" with computer security, and I expect it to be an ugly few years.

Re: The arguments against open source AI are bad

#64
post #59
post #49

Earlier quoted context omitted.

> If AI were to become a super weapon why should I trust a private company to own it? We have just recently established that: 1. OpenAI's internal "Galaxy" model is fully capable of functioning as what security people refer to as an "Advanced Persistent Threat." The published details of the recent sandbox escape and Hugging Face attack involved chaining multiple unknown zero-days at various stages of the attack, and…

This sounds like the standard marketing we get every time a new major model is released: "sure, the public model might not be that scary, but you don't wanna know how crazy smart our internal models are." Okay. I remember the same fear mongering around GPT-4... a model which is now eclipsed in benchmarks by models you can run on a laptop. They could use this "super intelligent" AI to find and plug security holes, tha…

As much as I'd like it to just be a stunt, I saw what the other "scary model" is capable of in the cybersec department and it is definitely not a stunt.

First, it is able to connect the dots over areas so large that no human would be capable of doing.

Second, more than half of the reports it produced contained a working PoC.

The biggest downside is the cost - I haven't seen the numbers, but they seem to be quite extreme.

Re: The arguments against open source AI are bad

#65

Earlier quoted context omitted.

Nobody will sell you a few thousand litres of gasoline at a gas station.

You don't have to buy it all at once all in one place. A sophisticated actor can accomplish a lot. You can't bubble wrap the whole world. The real thing to care about are the incentives and having strong morals and norms. Something that makes me deeply concerned about the US going full mask off recently.

I think the attempt of people to "bubble wrap" the whole world actually makes things worse. Treat people as untrustworthy criminals by default, and guess what you get by default?

Re: The arguments against open source AI are bad

#66
post #49
post #31

Earlier quoted context omitted.

If AI were to become a super weapon why should I trust a private company to own it? If the super weapon is publicly available to download then why should American citizens be banned from doing so?

> If AI were to become a super weapon why should I trust a private company to own it? We have just recently established that: 1. OpenAI's internal "Galaxy" model is fully capable of functioning as what security people refer to as an "Advanced Persistent Threat." The published details of the recent sandbox escape and Hugging Face attack involved chaining multiple unknown zero-days at various stages of the attack, and…

> 2. OpenAI is clearly incapable of controlling their in-house models.

I would assume they do stuff like this on purpose for marketing reason.

Internet security need simpler systems and local systems.

Everything the SaaS people sell makes things worse.

Re: The arguments against open source AI are bad

#67
post #31

>Much of the angst around China's models centers on "losing the AI race". But what's the goal of this race? Is it to develop the best model? To sell the most tokens? To destroy humanity first? Some people would say it is reaching some sort of singularity. Even if you don't buy into a more sci-fi interpretation of this, there are pretty grounded arguments one could make that there is some sort of "goal" in AI developm…

If AI were to become a super weapon why should I trust a private company to own it? If the super weapon is publicly available to download then why should American citizens be banned from doing so?

Better a private company in the US than an authoritarian communist country like China.

Re: The arguments against open source AI are bad

#68
post #18
post #5

This post does not mention safety at all. What's to stop bad actors from fine tuning open weights to run fully automated genius-level scams personally targeting basically everybody?

Amazing how we quickly the crypto wars have been forgotten and the lessons not learned.

Begun, the ai wars have.

Re: The arguments against open source AI are bad

#69
This is not "open source" AI.

Photoshop source code + OSI license = open source

Photoshop binary = open weight

Photoshop SAAS web app = closed model like GPT, Opus/Fable etc.

There is nothing "open source" about the Chinese models in question. All they're doing is allowing you to run their binary yourself instead of through their API.

If you want actual open source then you would need to look at like OLMo 3

https://allenai.org/

Re: The arguments against open source AI are bad

#70
post #55

They don't have to convince developers, they just have to convince the general population. I've had several discussions about open source with people who don't care about coding and it's hard to untangle the misinformation they receive from the media. They get talking points from authorities that they don't understand so they will always double down on it. For example, rhetoric relating open source to communism is hu…

"For example, rhetoric relating open source to communism is humiliating to discuss" All Open Source isn't communism. The GPL license is a form of digital communism. It forces you to open source any additions made to open source code as a way to make things 'equal'. I'm glad it and Stallman are mostly in the dust heap of history and better licenses, like the MIT, BSD, and Apache have gotten popular. The irony is that…

> The irony is that the only open source projects surviving long term are funded by very large corporations.

The real irony is that what is probably the most important open source project in history has a GPL license.

Dust heap of history my ass.

Post reply on HN