back to article Open-source AI is a global security nightmare waiting to happen, say researchers

As if AI weren't enough of a security concern, now researchers have discovered that open-source AI deployments may be an even bigger problem than those from commercial providers.  Threat researchers at SentinelLABS teamed up with internet mappers from Censys to take a look at the footprint of Ollama deployments exposed to the …

  1. Doctor Syntax Silver badge

    In this case it's the "exposed to the internet" that provides the "open" bit.

  2. segfault188

    Missed headline opportunity

    The US Treasury Department has cut ties with consulting firm Booz Allen Hamilton

    US Treasury said Bah to BAH

    1. Gene Cash Silver badge
      FAIL

      Re: Missed headline opportunity

      Yeah, if it had been my tax info, nothing would have happened.

      But it was Trump, so there was actually a response.

      1. QET

        Dude who leaked it definitely set himself up, when he pilfered tax info on people who weren't wealthy and isn't a clear-cut case of a influential loudmouthed idiot with cognitive dissonance.

  3. Fruit and Nutcase Silver badge
    Black Helicopters

    Edward Snowdon

    Also worked for BAH. However, before that he worked for Dell and before that the CIA, presumably, as a direct contractor.

    https://en.wikipedia.org/wiki/Edward_Snowden

    I guess Dell are still working for the NSA

  4. Anonymous Coward
    Anonymous Coward

    "a monoculture ripe for exploitation"

    "175,108 unique Ollama hosts in 130 countries", many with all-access agentic passes, such an untapped trove of entry points for the RotM locust plague ...

    It's like give me convenience AND give me death of the human species support infrastructure, all at once, right there! ;(

  5. Big_Boomer
    Facepalm

    FTFY

    "AI is a global security nightmare waiting to happen, say researchers". Open Source has nothing to do with it.

    1. m4r35n357 Silver badge

      Re: FTFY

      never a bad time to add a bit more FUD . . . .

      https://ollama.com/pricing

      seems you can call anything "open source" these days.

      HINT: if the distros won't touch it, is it really "open source"?

      1. Paul Crawford Silver badge

        Re: FTFY

        "open source" may, or may not, be under "free license".

        Think free speech versus free beer.

        1. Doctor Syntax Silver badge

          Re: FTFY

          In this case it's open as in "open door".

        2. This post has been deleted by its author

      2. doublelayer Silver badge

        Re: FTFY

        It's not hard to tell. Here's the code. It's under the MIT license. That's open source. The pricing page you linked doesn't contradict that, especially as what they charge for is:

        1. Running models on hardware that isn't yours, which costs extra and has nothing to do with the right to see, modify, and distribute the software.

        2. Storing models on their servers without making them public, which has nothing to do with [etc].

        What's your evidence for distros being unwilling to touch Ollama? Arch has a package, Ubuntu has a Snap, there are probably others. Not that, if they didn't, it would indicate a problem with the license because frequent code changes making it a maintenance nightmare is the more likely reason.

  6. amanfromMars 1 Silver badge

    Beware and Be Aware and Take Care .....

    .... of SMARTR Futures and AIDerivative Markets that Take NO Prisoners nor Suffer Fools’ Follies

    As if AI weren't enough of a security concern, now researchers have discovered that open-source AI deployments may be an even bigger problem than those from commercial providers.

    You can check out more than just a few very likely future problematic-to-existing-authorities AI deployments on this new development and developing site .... A Social Network for AI Agents

    AI is not going away you know. And IT has realised humanity is easily led prey with no effective practical defence against smarter remote virtual operations which might be attacks or assaults or incursions or interventions or treats or insider threats or whatever etc etc etc. they plan to virtually materialise with execution and administration of mentoring and monitoring.

    Play nice with them is excellent advice lest they weary and take offence at your hopeless opposition and persistent titanic stupidity.

    1. Albert Coates
      Pint

      Re: Beware and Be Aware and Take Care .....

      Wish I could give you more thumbs up for "your persistent titanic stupidity", can I nick that one please? ===========>

  7. tiggity Silver badge

    South Korea vulnerable

    Given their none too friendly relations with the Norks, & the Norks having just a bit of a reputation for dubious cyber actions, you would have thought South Korea might have long focused on making critical systems secure.

    1. Claptrap314 Silver badge

      Re: South Korea vulnerable

      Sadly, it appears that endemic government incompetence is...endemic.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon