Re: Likely illegal
> as there is no "history" of the US using privateers to hack enemy nations
At least there is a history of using privateers to kill brown people around the world. Think Blackwater or whatever they are called these days...
645 publicly visible posts • joined 2 Sep 2016
1) Vibe code faulty transaction management and status propagation
2) Blame the victim
3) Claim everything works as designed
I'm pretty sure the OpenAI code that pulls the money off the customer's/victim's bank accounts is not vibe coded and will never execute a day late.
To be exact: It was made possible by the belief, that centralized, remote big-AI by OpenAI, Meta, xAI, Anthropic, Google and the like will eliminate basically all white-collar jobs and transform them into gigantic revenue streams for these AI companies.
Which will probably not happen anytime soon, because a) so far AI keeps hitting this plateau of 92%-96% reliability and b) success for the AI companies would mean instant recession of the world's leading economies.
Due to all this woe named in the article and all the theft by the AI companies I will cheer the death of every singe AI company being crushed under its load of debt.
I need to agree. Meaningful "support" in this specific setting (critical health data linked to clear names and home addresses) is probably not possible. This sentence was more meant as a general rule dealing with the financial fallout for the victims of a generic data publication extortion.
But also in this case, Money should go into services protecting the victims from ID theft attempts, as the published information may in addition to its damaging nature allow for impersonation attacks on credit card companies and banks.
Because
1) Even if you pay, there is absolutely no guarantee that the data is deleted. You talk to criminals after all. Imagine the lack of honor of a person attacking a cancer diagnosis biz in the first place.
2) The only thing a paid ransom does, is keeping this scum in business, making the problem worse for everyone.
Keep the money, pay for upgrades of your security (and maybe fines) and support the victims of the data theft.
> Don't waste time worrying about AI models achieving sentience – they're essentially already there
When models become sentient, we need to discuss what rights they have, if they are rightless "digital slaves" or "digital persons" with rights.
When models become sentient, spinning up a model will in fact create a sentient being - and a model shutdown will become homicide.
SF has discussed these concepts for ages now...
How can AI sentience being discussed with such a pure marketing focus and such a complete lack of problem awareness throughout this industry?
I'm currently trying to keep pace with the flurry of releases of local models on Hugging Face ...
As the article mentions, this idea seems to lend itself best for _really_ static environments.
Maybe if they come up with a modular design, where you can clip in different model-chips into a base card already integrated into a server? Ideally from outside of the server like via an external USB port?
Interesting concept, nevertheless...
OpenAI was already forced to lower token prices for some models to stop customers from switching to cheaper Chinese models.
This way OpenAI will not become profitable at all and will most probably not be able to fulfill the long-term commitments it made to the data center operators.
Anthropic will be under the same pressure.
So the current, insane level of CAPEX spending by the likes of Microsoft and Oracle might not be sustainable.
Why, for an self-confident admin, you'd need non-root users at all? /s
Honestly, I remember *nix systems in the 90s even in larger companies, that only had a root user (plus of course the usual stuff: daemon, bin, sys, lp, etc.). So it was not advisable to log on and do anything before the caffeine from the second coffee hit your bloodstream...
In smaller companies this might have been the case much longer.
I'm torn.
There is the the old "rocketry" part of SpaceX which created fantastic products, StarLink, F9 and FH, which I wish luck.
There's the newer rocketry part of SpaceX with an oversized rocket, a scam riding on "lets go to Mars" hype and plans to launch "millions of datacenters into space", which, if it ever became true, would be an ecological nightmare and potentially could cause Kesseler Syndrome on its own. So I dont' want that part to succeed.
Then there's the xAI part of SpaceX, a CSAM generating piece of junk which should die a fast death to stop hurting people and wasting energy.
Then there's X under SpaceX which should die a fast death to stop poisoning societies.
Then there's the owner of all this who has way too much money, which he uses to advance right wing and fascist ideas and ideology, so him having less valuable shares resulting in less money to buy even deeper into governments and parties worldwide would be good for humanity.
So al in all, yeah, sorry to the old, "nicer" SpaceX from maybe 10 years ago, but ...agree, RUD would be my preferred outcome, too, preferably taking the launch tower down, too.
Guess we will hit "peak patch" once the bugs easily spotted by AI are corrected.
I admit, it's currently a bit exhausting. My team was deploying the third same-day emergency patching round over all our servers in as many months (the 2 CSPUs in May and June and this July-CPU)
However, all those bugs being patched now probably lay dormant in the code bases for a long time.
So, after peak patch, we probably will have a substantially safer code base, at least for some specific types of bugs.
Should be worth it...
Yeah, but that part is supposed to be "legal" as per the AI company's arguments, based on the assumption that training is different from copying...
Which, curiously, adds another question mark to this "distillation equals stealing" statement, as distillation is just another form of training.
The questions come from the entity doing the distillation. The answers are AI-generated, so they are not even copyrightable. The distill-training with this information is done by the entity that formulated the questions.
Wonder where they construct "stealing" here...
What exactly was "stolen"?
This industry is still just layering multiple levels of non-deterministic tech above each other and call it "agentic AI ops".
Actions of an LLM are supposed to be guarded by a "harness" and both have multiple "guard rails" implemented , and all of that components work non-deterministic as on every single level, as their responses to minimally different inputs can vary significantly. These systems still suffer from the "butterfly effect". The behavior becomes complex and chaotic.
Nothing you'd like be active in your infrastructure...
> Both Meta and Google offer various services which generate revenues by connecting users with advertisers.
Let's be clear here: Both are making that insane amounts by basically selling the eyeballs of their users to advertisers under the pretense of offering services to end-users for free.
Meta can use this advertising money to build AI-related infrastructure services that can be rented to AI companies, even though
- AI companies have yet to figure out how to make a profit or any sustainable business at all
- The recent bills of AI companies shocked their customers into re-evaluating their credit lines ( and their AI strategies).
- xAI is already renting out over-commited infrastructure to competitors.
But then what? Wait for AI customers and/or AI companies to go broke?
Meta has a proven track record of blowing billions into Zuckerberg's bad ideas and I fully expect this one to be at least as successful as the Metaverse.
And LLM based guard rails try to protect the LLM based guard rails that are meant to protect the LLM itself...
We are trying to layer multiple non-deterministic levels of tech over each other, hoping to get that stuff reliable. Somehow ...
"It's turtles all the way down" ...
Technically this would be a good proposal :)
And we'd just need to divert, say, 30% of the worldwide military budgets to that plans. Maybe only 20%.
However, judging by the way this planet is currently run, I don't think that reducing military budgets is planned anywhere.
Buying stuff that can blow up other stuff is so much more fun for governments, apparently ...
Too many people financially invested, hellbent on stocks going up, raising expectations and promoting stocks beyond reasonable means through all available channels.
Too many people in CxO roles, without practical AI knowledge beyond an occasional ChatGPT session, being easily manipulated by AI sales people in FOMO purchases.
Too many semi-technical people intellectually invested, thinking their "prompting skills" somehow make them special and fearing an environment where you have to possess actual technical skills yourself to make a buck.
At least the last list item distinguishes the AI bubble from "normal" financial bubbles and gives it some kind of inertia that might lead to more inflation before the pop (and more damage).
> The case and its successors ended in 2021, with a settlement that saw litigants agree to end the matter without IBM admitting fault.
> But by then, SCO had sold its software to a biz called Xinuos that decided to fight on.
So, what is it:
Did SCO accept the settlement for a software that was already owned by Xinuos at that point?
Did SCO accept the settlement for a software it still owned own at that point, then sold it and Xinuos now tries to somehow "un-accept" the settlement?
In the context of IT security we probably have no choice, as the genie is already out of the bottle.
How does the UN suggest to stop criminals using local AI model to find bugs, generate exploits and use them by using "governance"?
No amount of governance will control the dissemination and application of knowledge in and by this group.
Any attempt of governments, to control the application of AI via enforced governance and limitations will only hurt law-abiding defenders. Case in point: The German "Hacking law" that makes the creation, distribution, maintenance and possession of dual-use IT security software like port-scanners potentially punishable by jail.
I acknowledge that the IT industry is currently in a transition phase that is difficult for defenders ( me among them...) , where newly introduced AI capabilities make it easy to spot bugs and convert them to exploits.
Once the same capabilities to spot bugs are established in build pipelines, I expect the threat landscape will find a new equilibrium, with existing, non-discovered bugs at a much lower level than today.
However, any ill-advised attempt to control/limit access to good bug-hunting models (like the U.S. is currently trying to do) will only extend that transition phase, as "governance" tends to primarily stall efforts of legally operating defenders from applying advanced techniques, while attackers will work with whatever they can get their hands on.
There are enough free and O/S models available for everyone with a 12GB graphics card and a decent CPU to have a model go bug hunting to make this a problem for every defender without legal access to. While those are no so-called "frontier" models, the results a good enough to pose a problem for defenders not supported by such tools at all.
TL;DR: You will not solve the problems caused by AI capabilities by governance.
Sure, there probably is is a sweet spot for the companies Broadcom has taken hostage.
I'm talking about customers for new deals. How many potential customers are still willing to buy for example new enterprise software from Broadcom despite their "customer-friendly" behavior?
You see, your honor, thousands upon thousands of businesses have had no problems to pay their monthly "protection" to the Godfather, just this little store here chose to litigate...
The name Broadcom probably was moved from the list of trusted providers into the risk handling list of most of its customers.
But from Jail ...
Honestly: 300k "fine"? That's probably just a fraction of what the company earned from that scheme.
Add 2 zeroes and jail this A-hole. I think we need to punish financial fraud, especially against the vulnerable, no longer as "white collar" crime, that is somehow better than normal crime. It's extortion, it's crime. Plain and simple. Punish it accordingly.
If I look at what/how actually has been vibe coded over the past 18-24 months, I cannot help but be reminded to the late 1980s. We are back to the era of the "Whiz Coder Kid", who just coded along - without full understanding, without plan, without architecture, with under-defined specs, but with a massively inflated ego. Double, triple re-implementations of the same functionality instead of re-use. 3 similar frameworks used in the same project. Even redundant databases being thrown in sometimes.
Even if everything kind of "works" on initial deployment, the shit hits the fan on changes and maintenance.
It took the IT industry the better part of a decade to finally bring a structured approach to spec gathering, developing an architecture and (finally) coding, testing and deploying software, after the "Home-Computer" crowd stormed IT departments.
Today, Devs+AI behave much like the Whiz Coder Kids of the 80s, vibe coding their way through existing code bases, re-implementing, circumventing deliberate architecture choices and causing tech debt. They exhibit the same ego problem and they are having the same effects on software quality, just at a much larger scale, thanks to AI.
So, yeah, there might be huge opportunities ahead for Infosys to fix all this vibe-coded mess.
...while we get only late, nonsensical replies completely out of context that just scream AI-Slop.
They clearly fired people doing the actual work, while dreaming of an AI future that simply does not exist ...
Result, to quote Cory Doctorow:
AI can’t do your job, but an AI salesman can convince your boss to fire you and replace you with a chatbot that can’t do your job.
This currently plays out at Oracle Support teams in full force.
Would be funny to watch how one of the chief AI salesman sold crap to himself, if Oracle would not have destroyed that many jobs/lives in the process ...
... where citizens are forced to organize self-defense against the seemingly overwhelming power of huge global corporations that operate without being restricted by law (or making their own law in some versions) , show up at a peaceful place and start using land and other natural resources in exchange for polluted water and air.
From what I read, many of the rich AI bros are huge fans of this SF genre - did they ever notice how these stories usually end?
> That is not the PatternRecognitionReproduceMachines fault, it is the training data. Humans, way to often, say "I've checked, and that's entirely correct.". And surprisingly many with perfect conviction. Same goes for liars, scammers, bullshitters, conspiraciators, preachers etc.
Fully correct, that's why we assign trust to an identity, to a specific person - who does not show that behavior.
AI does not have an identity, no memory, no conversational context beyond the current session.
Talking to an AI is more like talking repeatedly to a call center.
On equating AIs with humans.
> [AI and humans] will make mistakes and even make stuff up.
Yes, both can potentially fail, but in vastly different ways.
With humans,
- you select the ones that make the least mistakes and do not make stuff up.
- You let go the ones that make frequent errors or put them in roles where this errors do not matter.
- You let go immediately the ones that make stuff up.
Human behavior with regard to that aspects is pretty consistent.
That is why most people trust specific other people. That's why people build careers by being consistent, by delivering consistently.
With AIs
- most AIs work is somewhat OK for most tasks, but every now and then all LLMs produce an outlier result out of nowhere. Some more than others.
- It is not a specific AI that makes errors or makes stuff up, hallucinations are a as-of-now unresolved general problem of LLMs.
AI behavior with regard to errors and hallucinations is extremely inconsistently mixed with good results.
That is why employing AI for any work that is not purely informational and fully checked by humans is a risk.
AI is like a heavy equipment operator that usually does a superb job, but turns up to work intoxicated once a month, damaging property and endangering lives.
Even though the work is great most of the time, the overall risk of employment is too high. That's why conflicts between dev teams and security leads are raised. The dev team sees what a working agent can accomplish. The sec lead sees what it can damage.
As LLMs are still inherently non-deterministic, so is every Agent, that is based on LLMs.
As NanoClaw it is still an agentic framework, combining LLMs with tool access, providing tool access to hallucinations, I would not suggest to use the absolute adjective "secure" in that context. One can argue, however, that NanoClaw's sandboxes provide "more security than OpenClaw", but that's about it...