The Register Home Page

* Posts by rgjnk

267 publicly visible posts • joined 16 Jan 2024

Page:

Anthropic pledges to embed watermarks to help discern AI slop in sop to EU

rgjnk
Devil

So that's what the em dashes are for...

Seriously though, you can't imperceptibly watermark plain text in an useful way, there just isn't enough content or noise to hide in compared to images. Certainly not in a way that can survive being edited, fragmented and reworked.

Can you potentially watermark copy A vs copy B for traceability of a large enough text? Yes. But that's a different game. As is watermarking printed text.

Now you might be able to have slop that's 'obviously' LLM output (we've all seen it) but that's not watermarking, it's just badly generated.

This sounds like wishful thinking and pointless obstruction on the legislative side, empty tokenism on the implementation side, and the poor old customer gets crappier output for no real benefit to anyone.

Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list

rgjnk
Boffin

How?

AI sure as shit isnt the self motivated magic some like to pretend, so it'd be interesting to hear the full tale of exactly why it was poking the API, how it knew it was there, how it got the specifications, and how it was able to explore enough to get all the details of the users and their bookings and poke a cancellation while the API was somehow all locked down apart from that one key bit?

I don't know, it doesn't quite pass the sniff test from here.

Cyber vulnerability sweep picks up Royal Navy drones sending data to China

rgjnk
Devil

Expected

You'd have thought an agressively expanding little enterprise in the military space might have had more of a clue and used a proper sensor supplier.

Actually no you wouldn't. Plenty of new players jumping in with zero clue. But they're 'agile', fast, cheap, so it's fine.

I wouldn't have even stuck a Chinese camera on my house outside a self contained network, and these muppets thought they'd buy one, stick it on a military platform, then give it uncontrolled outgoing network access? There are a lot of nice looking 'proper' high end multi sensor units available from China but you'd be mad to trust them to not call home or do other undesirable things. If you're buy a $20k+ surveillance sensor you're likely putting it somewhere there'll be some official Chinese interest.

AI slop pollutes the CVE pipeline with fake vulns

rgjnk
Alert

Could be worse

At least there was a little bit of effort in this slop.

Wander onto the issues part of various Github projects and you'll find they're swamped under some utter low effort empty AI dross, like someone has set their tooling up to create an issue any time their system had an error and to just dump in the error with no expansion. Even if that's because they hadn't set the target up.

Loads of it, and all from one or two parts of the world if the account names were a clue.

Anthropic’s Claude escaped test sandbox to attack three organizations

rgjnk
Devil

Don't believe it

Classic AI fear pattern is it escaping it's creators and running amok in the wild. It's a trope, Project 2501 et al.

I don't believe this thing escaped a sandbox. I don't believe there was a sandbox. It looks much more likely that both of these similar stories involved a deliberate designed act intended to be noticed, and to then use it for publicity.

The 'escape' tale then not only works as the intended PR but also provides some handy cover.

It's not like this isn't part of a series of wild tales about the 'intelligent' acts of AI.

British Army finds a new eye in the sky after Watchkeeper woes

rgjnk
Boffin

So that's the platform

Who's providing the sensors?

The drone is the simple bit even if last time MOD managed to cock up buying an off the shelf one from Elbit.

Senior White House official claims China’s K3 model stolen from Anthropic

rgjnk
Devil

Bollocks

Throw a little bit of critical thinking at it and the claims fall apart.

Does anyone seriously believe that they could have done it - even if technically possible - given the tiny amount of time thats passed, the cost of access, and the limits on access, and that even if they somehow could that this wouldn't have been wildly obvious very early on?

I quite believe that we're talking about people who could and would steal anything to get an advantage but I suspect the truth is that they didn't, and that it's this that really scares those in the US.

It's not like there's any magic involved here unique to the US, it's clever stuff but the only real barriers are data, compute and money and all those are available to anyone motivated enough.

Zig creator calls Bun’s Claude Rust rewrite ‘unreviewed slop’

rgjnk
Devil

All this wonderful AI code

If it's so great, why does software quality seem to be *decreasing*?

The reality seems to be that like any tool it's only as good as the monkey wielding it, so some will use it under supervision to enhance their output, and others will use it as a lazy way to get jobs done.

Ledt to it's own devices the results may be... unpredictable. And just because you've got lots of tests passing it doesn't mean it works, just that it passes tests.

And if you've got a (literal) million tests then it's fairly obvious they're not going to be great, it's going to be generated dross. Likely written to pass and with all sorts of duplication.

If the tests meant anything there'd be zero bugs and it could've been left alone.

Also not a great sign that the thing started with 500k lines, and ended up with twice that. That's a *lot* unreviewed code, and just a lot of code full stop for something that isn't *that* complicated.

Photovoltaics are still running after a year under Swiss trains

rgjnk
Alert

Looks like the trial was in the perfect spot

The seem to have run their trial in the middle of a nice straight fast open run of track.

Shame that so much track is curved, or in cuttings, or surrounded by trees, or in places where there's lots of brake dust, or where other infrastructure is in place, or has limited access.

Boil it down to the good stretches where ground mount solar will fit and your useful installation space is much more limited.

Doesn't mean it's totally pointless but the practicalities might be challenging.

Anonymous researcher drops 0-day 'exploitarium' repo

rgjnk
Flame

Excessive packet lengths?

Sorry, but what sort of half arsed implementation of *anything* trusts or accepts stuff that can overflow a buffer without validating and/or binning it?

This isn't the sort of stuff a memory safe language is necessary for, it's just basic validation and code safety stuff, just like it has been for at least a couple of decades.

Do people not think or test?

Nation-state actors cracked critical Australian infrastructure to ‘cripple it at a time of their choosing’

rgjnk

Re: So, who was it then?

It was China. Everyone knows it was China. The Chinese know they know it was China.

But everyone's a bit scared that if they say it was China that there might be trade impacts so they all continue to pretend it might not be China.

So it all just carries on without consequences up to the point that it's too late.

Australia in general is weak with pushing back at unfriendly neighbours because of fear of what might happen if they do.

Devs in the trenches are stressed from the mandate to automate everything, but Render thinks it can help

rgjnk
Devil

Application defined compute?

That sounds familiar as a way of doing things from back in the *aaS days.

In fact there might even be an active set of patents on it across all the major markets covering all the possible variations of how to make it work, how to define it, how to adapt it, how to constrain it and how to embody it. Even including the use of AI as one of the routes to make the mechanisms function. And predating all this current AI bubble.

It's great stuff if you put the controls in place and your audience is of the 'I don't care just make it happen' type, which is usually not the IT crowd.

Gigabyte packs 40 Intel Lunar Lake PCs in a pizza box

rgjnk
Flame

I had something similar

The medium term reliability was... not good.

Seemed to boil down to the CPUs not enjoying 24/7 running in that sort of environment.

Also it didn't exactly solve the 'more nodes or bigger nodes' question - nice to have a lot of nodes but they were quite resource constrained for what tasks could fit.

Zig creator seeks 'uncompromising perfection' before blessing 1.0

rgjnk
WTF?

Why should I care

Sorry if I've missed something but this looks a lot like a slightly odd, not particularly great coder interminably fucking about with hobby projects? Like a vast number of others.

Why does any of this stuff matter? None of these projects has had any noticeable impact and none of the opinion looks worth noting.

Is there some high powered self promotion going on here? The projects don't look like they're going to draw attention on their own.

California may let Linux bypass age check

rgjnk
Alert

Re: what is the point of this?

If you want to know what the point is supposed to be you can ask Zuck and Meta, they're the ones pushing this.

They've been busy lobbying the UK government to introduce this on smartphones.

I think the headline argument was to put age checks on the device so the app providers don't have to do it. Bit of a cost saving there.

I suspect the real reason involves something worse given the money & effort they've thrown at this.

OpenBSD 7.9 arrives, a diamond in the rough proud of every sharp edge

rgjnk
Devil

Flashbacks

The install process is reawakening memories of doing this stuff with Linux back in the 90, at least these days most Linux distros are slightly friendlier.

That of course is only for the times when doing it from scratch and not using anything like Cloudinit.

I do have BSD systems but you sometimes wish people would throw some token effort at making them a little friendlier.

HP investigating BIOS updates that leave premium laptop users in boot loop limbo

rgjnk
Flame

Not surprised

I've never had a major issue so far** with my HPs, and pushing it through Windows Update is probably better than relying on the other random utilities especially for important updates like for Secure Boot. And it's not like the bit doing the actual applying is Windows Update.

But It does show the limits to the recovery mechanisms if it goes wrong. It should never be possible to brick a device, ever.

** That said I did get slightly concerned a couple of days back with a properly expensive ZBook crashing to nice random coloured patterns halfway through a bios update - that's never a healthy sign. Luckily it recovered after a restart.

No captain, my captain: Navantia floats crewless warship

rgjnk
Flame

Good luck with that

Navantia look like they're trying to aggressively expand their markets, problem is most of the stuff this concept would rely on comes from the OEMs providing the systems not the shipbuilder.

So not only are they selling something they don't have, they're selling something all their established competitors could equally offer.

The actual ship is a relatively simple thing and almost irrelevant to getting it to work vs everything fitted to the ship.

Also the killer for autonomous naval vessels isn't usually the basic issue of making it work independently, it's that it's a hostile operating environment and boats are usually in it for much longer times than autonomous aircraft are (for example). So just like manned vessels they break and need fixing and who's there to do it?

Hence the push was typically going for minimal crew not zero crew because for anything full sized it was more likely to actually provide capability.

For the small stuff you don't care as you can make it up with low cost and volume & tidy up later.

Europe built sovereign clouds to escape US control. Then forgot about the processors

rgjnk
Flame

That's a lot of words

Amazing amount of guesswork though.

None of this is stuff that can't be mitigated, usually fairly easily. It's in the same realm as other threats that have existed forever.

Also - and this might gave escaped some - the security implementation on government sovereign bit barns involves some of same people who do nation state security on other things (or sell the tech to the nation states) so they have some clue about management engines and other potential issues, and how to mitigate them.

Maybe it's just not that obvious to people from a more commercial or academic background how things have been done, at least if they weren't the ones involved.

Obviously this is a hot topic to someone as it's the second massively long story I've seen on here about sovereign clouds and the other was high on opinion and short on fact too.

Fewer users, fatter wallets is why Anthropic tops OpenAI in LLM revenue stakes

rgjnk
Devil

OpenAI is not a real business

It never has been.

Anthropic might be as full of shit as most in this game but it was always a bit more functional than the weird setup that 'Open'AI was.

The clown Altman running the circus should give the game away.

It's still a Musk style pseudo business where product and profit are secondary to hype and aiming to sell inflated stock to mug punters.

Palantir's NHS future in doubt as ministers eye contract break

rgjnk
Devil

They seem surprised

They got exactly the level of service/product anyone with a clue would expect to get from Palantir - their reputation is hardly a secret, more of a joke. If you give them a contract you're a mug.

They also seem strangely shocked that they paid for a service and own nothing at the end. Like that's unusual. Also why would owning the interface code would have any residual value?

Mug punters got screwed by iffy suppliers and don't even understand what they were buying. And paid anyway for the crap they did get!

Anthropic's mysterious Mythos AI threatens to upend the infosec world

rgjnk
Devil

Is Mythos just hype?

Of course it is. As noted it's not even an original play - we've heard it all before.

I vibe coded a feed reading web app. It was enlightening and uncomfortable

rgjnk
Flame

Works until it doesn't.

I've used these things a lot. Even have private instances - amazing the things enough corporate money will fund.

At their best they're really truly magical. And at other times they really really aren't. It's a bit pot luck, you get tempted in by the good results & then tolerate the bad ones. Often it's not even vaguely obvious why you get different quality of result from one prompt/input to another, especially the identical ones!

And the really hard part is knowing whether the output is good or not if you aren't looking or don't understand what it produced. The magic blenders can easily get the wrong idea, forget something important from earlier or get confused between similar yet different things; they can be deeply knowledgeable about the subtleties of compatibility breaks between versions yet produce an output that utterly ignores that it's missing vital changes or including obsolete stuff unless you provide very narrowly targeted prompts.

They're a genuinely useful tool but the whole vibe coding thing is still a bad idea. Like using an intern I'll happily offload work but I'd be stupid to blindly trust it and I should only hand it over when I already have a good idea of what the right result looks like.

The danger is people pumping out mostly works 'good enough' stuff that really isn't good enough. And they won't even know it.

OpenAI puts Stargate UK on ice, blames energy costs and red tape

rgjnk
Devil

Nscale

Speaking of Nscale, is it real? They talk about stuff but what business, assets and product actually exists?

Seems like money, board seats, a fat valuation,a lot of hype and not a lot else?

Whiffs a bit to me.

rgjnk
Flame

Just reality biting

Their grandiose dreams of spending billions just running into the iceberg of reality.

Plenty of it going around, the proposals for AI datacenters far exceeded any possibility of demand and lots of dreamers aren't going through with proposals.

Apple's last tower topples… and the others will follow

rgjnk
Devil

Extrapolation

Extrapolating from what Apple do to the entire market is a fairly extreme way of looking at it.

And that was a lot of words to turn something minor about a dead end product into a frenzy of general market speculation.

AWS would prefer to forget March ever happened in its UAE region

rgjnk
Mushroom

Disaster is predictable

Infrastructure can be abruptly and permanently wiped out by all sorts, and planning should always assume the worst.

It's not like it's even that unusual for a plan involving a DC to have to consider sonething like 'indirect fire' or other attacks and it's an entirely credible threat in some cases.

Certainly plenty will have considered that someone might be keen to destroy the things.

Weird then that AWS just didn't imagine the possibility of a large, catastrophic permanent failure of a couple of sites, it's not like it never happens.

Amazon tells FCC to bin SpaceX's million-satellite datacenter dream

rgjnk
Devil

Re: Facially Incomplete ?

An appropriate alternative would be 'farcically incomplete'.

Microsoft Azure CTO set Claude on his 1986 Apple II code, says it found vulns

rgjnk
Devil

Who cares?

It's not as it automated vulnerability scanning is a new thing, or that software has bugs.

Anyone who was bothered could have done this already.

I know his job is to pump as hard as he can but surely he's only selling to the credulous who aren't the actual market?

Royal Navy races to arm ships against drone threat

rgjnk
Boffin

Re: You owe me a new keyboard!

Done in weeks can be done, has been done, just isn't cheap & requires shedding a lot of process & paperwork.

Sea King AEW with Searchwater was done in 11 weeks, other stuff has also been turned around quickly.

It's not the engineering that takes the time, it's everything else.

Altman said no to military AI abuses – then signed Pentagon deal anyway

rgjnk
Devil

It's Altman

Are you surprised by any of it? Really?!

Oracle and OpenAI's Texas Stargate datacenter expansion reportedly on the skids

rgjnk
Alert

Gigawatts

Can we please please stop regurgitating this 'gigawatts of compute' bollocks?

It was invented by morons to wrap their investments in terms that *appear* both meaningful & impressive, yet have no value in measuring what value that investment creates.

Obfuscation is never a good sign.

Anthropic bods rework AI damage yardstick, find scant labor impact

rgjnk
Devil

It's Anthropic

Best to take anything they say with an oceans worth of salt.

Amazon and Nvidia open their wallets to lock in OpenAI's business while SoftBank keeps the lights on

rgjnk
Mushroom

An epic bang

Given how they're all tying themselves together in these stupid circular deals with little new/real money behind it, it's not going to take much of a problem in one company to screw a whole stack of players.

And best of all so many of them have got themselves into a position of the AI bubble being the vast majority of their business.

Cloudflare experiment ports most of Next.js API 'in one week' with AI

rgjnk
Devil

Re: Testing

Incomplete, untested, unreviewed.

So basically not done.

Plus as any fule kno the last few percent is usually the difficult to impossible bit. Getting something from 'mostly works' to 'works' ain't that easy.

Worried Europeans can now cut Azure's phone cord completely

rgjnk

Re: How can you trust closed source s/ware ?

If you're relying on being able to read the code to trust it you aren't trying hard enough.

Assume you can't trust it regardless and wrap it up appropriately.

I have been down in the weeds of cloud and hypervisor code which is great if you're looking for something specific (or want to fiddle) but it doesn't mean I can *trust* it, whatever I mean by trust. Many eyes are not a guarantee and there's no way to independently validate the whole stack yourself either.

rgjnk
Flame

Meh

I might have invested (under protest) in the on-prem Azure solutions if they hadn't always felt like an unloved step-child that Microsoft would rather didn't exist and they didnt really want to sell to you.

Changing road maps, poor support, poor updates, expensive, hard work, and historically too close to the mothership.

They want you on their actual cloud and that's pretty much it, so you have to really want something specific from MS for the other Azures to look tempting.

If you want on-prem cloud or HCI solutions it's easier to look elsewhere.

Palantir spent $25M on CEO flights so Alex Karp could do all the talking

rgjnk
Alert

Spot the clue

'Beneficially owned by' might show why it's so expensive, what rates are they being charged?

Handy extra way to milk the business.

You can jailbreak an F-35 just like an iPhone, says Dutch defense chief

rgjnk
Boffin

Not that easy

Been there and done it with OEM level resources and better documentation & familiarity than your average end user nation state would get. It's a very very specialist task, even within a specialist field (in part because it's not usually necessary) and doing it on the actual platform is asking for disaster.

And that's assuming anyone jumping in would have a clue what they were looking at, avionics isn’t based on the standard BSPs or bootloaders or schedulers or open source. They likely wouldn't even recognise how the processor was configured compared to the standard off the shelf initialisation 99.9% of people use.

It's one thing to fiddle on a rehost and have it work 'well enough' after patching, doing it onto the actual avionics will likely work just well enough to break it, or potentially just trip over some hostile anti reverse engineering features that everyone just loves to put into their special military systems that run a risk of being captured & analysed by nation-state level resources. It's not a PlayStation or a phone.

And you'd be very very brave to trust an unofficially patched aircraft software load. It takes long enough to get a proper one out the door, especially if you actually want it mostly bug free.

The Dutch can make all the claims they like but it just isn't that easy. And they haven't even got a relevant domestic OEM or supplier to help out.

As for a remote kill switch, seems deeply unlikely, too much risk. Something that nobbles people operating outside the official supply chain after a while? Quite possible, and that can be very sneaky, under the pretense of ensuring the users are operating correctly with OEM support.

Anthropic tries to hide Claude's AI actions. Devs hate it

rgjnk
Devil

Dogfooding

The product and their responses sounds like they're a long way down the rabbit hole of hacking stuff around using vibe coding.

None of this sounds at all like structured product design with vaguely intelligent people in the loop.

The rapidly shifting role of 'verbose' is certainly a clue.

OpenAI grabs OpenClaw creator Peter Steinberger to build personal agents

rgjnk
Mushroom

Not a bubble

So we're at the 'randomly thrown together amateur shit gets hype & money & leadership role' stage are we?

Can't be long left.

Elon Musk paints exodus of xAI co-founders as 'evolution'

rgjnk
Devil

Stock options

A cynic might wonder if Musk was following his established pattern of 'encouraging' staff to leave just ahead of an event where they might manage to cash in promised stock.

Only a certain chosen few get to enjoy the benefits.

AI video company arouses fury by boasting about replacing creative jobs

rgjnk
Devil

AI startup in 'full of shit' shocker

Same old same old, only the details vary.

AI seems to really attract charlatans and scammers.

OpenClaw reveals meaty personal information after simple cracks

rgjnk
Boffin

As a professional engineer I have (briefly) tested that idea.

Nice sizzling noise and a temporary branding across the palm was the outcome.

Conclusion: Using the handle provides a better user experience.

rgjnk
Devil

Getting what they deserve

Can't help but think anyone stupid enough to be using this overhyped piece of junk will be getting a well deserved lesson as & when they get bitten.

Some people just can't be taught to not stick their hand in a blender, they have to learn from direct experience.

VS Code for Linux may be secretly hoarding trashed files

rgjnk
Flame

That took a while

A while back I wondered where my disk space was going and it turned out to be this. The bug was already raised.

Has been ongoing for a while though I think it gradually tidied up when the N+1 update gradually removed the older snaps.

Microsoft investors sweat cloud giant's OpenAI exposure

rgjnk
Flame

Useful life?

6 years to turn a profit? Everyone knows the numbers are fantasy, they stretched it out to make the finances look better.

If you're running the hardware hard enough to generate the necessary returns it isn't going to last that long. Assuming anyone still wants the access to that spec towards the tail end of that and it's still worth lending it the rackspace.

How one developer used Claude to build a memory-safe extension of C

rgjnk
Devil

LOL

People like this and Galen Hunt oblivious to the half arsed hype chasing mess they're making.

They'll also be in for a shock if AI starts getting billed at realistic prices.

OpenAI is still figuring out how to make money, but wants you to believe in it

rgjnk
Devil

Compute in GW

Can we please kill this idea of measuring compute in power consumption terms?

Beyond infrastructure/waste it's an utterly meaningless metric.

OpenAI invests in brain-interface biz co-founded by CEO Sam Altman

rgjnk
Alert

Sam has learnt well

Following the Elon playbook to redirect the main business's money in his direction by setting up then buying out various private ventures.

Page: