Mafia technique
Nice data centre you have there, it would be a shame if anything happened to it.
Sign here to join our protection plan.
OpenAI has gathered more than 100 of the world's biggest tech and infosec companies to warn that cyber defense is in trouble - a reassuring development given quite a few of them helped build the technology involved. The open letter has more than 100 names attached to it, including many of the companies with the most to gain – or …
This post has been deleted by its author
Except “not using it” in this instance doesn’t help you, because the other people using it are still going to break your network with.
So actually (and annoyingly) you kind of have to use it to test your own systems before someone nefarious does.
And the AI companies are fully aware of this.
I think that it's possible to design a system which requires an actual human in the interface with the outside world, and that would fix the AI problem. People just haven't been creative enough to figure it out yet. I suspect that's coming. AI to fight AI is a fool's errand. That just ends up being an arms race. Being human is different from being AI. Distinguishing them is doable, if a bit time consuming.
Lets see.
Companies spend their money on AI 'just because'. They don't see an ROI. They lose their technical talent. Money they SHOULD have spent on replacing their ancient systems that are susceptible to attack is instead given to the companies that exasperated the problem in the first place.
I don't know of any company where they've used AI to test for vulnerabilities and use that data to plan upgrades - they've only used it as a pretense to get rid of people.
with a tax on AI. Double win, could deflate the bubble a bit since that cuts into profit and they'd get to pay for the mess they created.
With the money, we could hire people(maybe the ones being laid off now) to actually look after the control systems in person and disconnect them from the cesspool created by AI.
Now now, we don't want to discourage bri'ish biznis and be anti-growth and all that! So have a tax on AI's carbon emissions, no matter where in the world it is emitted.
i.e. if a British user calls an AI query that causes 1kg of CO2 to be sent up a smoke stack in Arizona, a tax should be due from the AI company (who may in turn pass it on to the user)
If they want to avoid that tax, then they ruddy well better build solar-powered datacentres (in locations that are in sunshine when the demand peaks occur) !
(of course they would never do that, because even in somewhere like Morocco, sunshine is less than half of the day, so they would need to spend twice as much on datacentres, plus the solar arrays)
None of these hacks are impressive on any technical level. It’s organizations embracing the most pathetic slop imaginable and calling it a system. Does anybody really think that Hugging Face is anything other than some slopcoded monstrosity? The TeamPCP exploits, while amazing fun to watch, started with GitHub running shell scripts containing unsanitized variables, in 2026. What could possibly go wrong?
Silicon Valley rose on the back of “move fast and break things,” made a mountain of money, and built us with a world full of broken shit. And then the overwhelming majority of IT departments looked at this mess and said “hold our beers.”
Now forgive me for pointing out the f'ing obvious but a lot of these systems should never have been put online in the first place. The only reason some were was to save money.
The ones that had no choice but to go online should have spent the money to make them secure or made access as small as possible and limited what could be done from online.
This is the problem with capitalism. It's all about profits. Can we do this to make more money by cutting workers? Sure but not one asks the question of consequence. Same goes for can we build this on the cheap? Do we really need to employ security experts? Nah, it'll be fine.
None of this has anything to do with AI though. All AI is doing is crawling known exploits and trying them elsewhere. Eventually they would have been exploited anyway. This is just accelerating that and the AI companies will happily sell you the solution but it won't be a proper solution. It will need to be maintained and ongoing. Just like pharmaceutical companies don't want cures, they want ongoing treatments. Why would AI companies be any different? Every new novel exploit found tested against your systems by our new AI infosec products. What a time to be alive.
And not just profits per se. If it was only about making a living, it might be good. But stock value depends on *increasing* profits over time, which sooner or later will leave any stockholder owned corporation in an impossible position.
But the problem around the problem is, no one can point to a better system. "Solutions" generally involve some small number of people with arbitrary power to impose decisions, which for obvious reasons never works out very well. I mean, that is what we are looking at here, just different people.
I run Firefox on two platforms, Windows 11 and NetBSD 10.1. Privacy & Security settings are identical on both. On NetBSD the User Agent mimics the one on Windows 11.
You know that little Cloudflare "Verify you are human" checkbox that pops up when you try to access websites. On Windows this works fine. On NetBSD it kicks itself around and around in an endless loop, asking me to check the box over and over, getting nowhere.
With identical Privacy & Security settings, and the same User Agent. This implies to me that Cloudflare must have some kind of *backdoor* into Windows itself.
Now I have even more reason to suspect a backdoor of some kind. I tried Firefox on OpenBSD -- same version and settings as NetBSD, except the User Agent was still for Linux (default on OpenBSD). Lo and behold, the Cloudflare checkbox worked without issue and I had access to sites. Then I changed the User Agent to Windows, and suddenly the checkbox did not work at all, just like on NetBSD. This suggests to me that when Cloudflare sees the Windows User Agent it does indeed try to use some kind of backdoor into Windows, which is of course not there on the BSDs, while with the Linux User Agent it does not look for it and everything works fine. I imagine telling the truth about the OS might work just as well.
The problem is that UPS tracking on the UPS website only works with the Windows user agent! And of course I do need to use that tracking sometimes.
Tell me you knew ....
First time I have seen this pop-up (all in red too.)
Been popping every few minutes.
A new service offered by the Vulture for the coding S&M community ?
With the deprecation over the last few decades, of gendered terms relating to roles seeing a moderatrix seems positively kinky (she attired in a a tight red morocco leather outfit? Who doesn't love the fragrance of a well bound tome?)