The Register Home Page

* Posts by EricM

645 publicly visible posts • joined 2 Sep 2016

Page:

Trump wants to grant private cyber firms a license to hack back

EricM Silver badge

Re: Likely illegal

> as there is no "history" of the US using privateers to hack enemy nations

At least there is a history of using privateers to kill brown people around the world. Think Blackwater or whatever they are called these days...

OpenAI ad service can bill customers for up to one day after they pause campaigns

EricM Silver badge

Par for the AI course I guess

1) Vibe code faulty transaction management and status propagation

2) Blame the victim

3) Claim everything works as designed

I'm pretty sure the OpenAI code that pulls the money off the customer's/victim's bank accounts is not vibe coded and will never execute a day late.

Big Cloud is poised to corner the market for enterprise hardware

EricM Silver badge

And all this woe was made possible by AI.

To be exact: It was made possible by the belief, that centralized, remote big-AI by OpenAI, Meta, xAI, Anthropic, Google and the like will eliminate basically all white-collar jobs and transform them into gigantic revenue streams for these AI companies.

Which will probably not happen anytime soon, because a) so far AI keeps hitting this plateau of 92%-96% reliability and b) success for the AI companies would mean instant recession of the world's leading economies.

Due to all this woe named in the article and all the theft by the AI companies I will cheer the death of every singe AI company being crushed under its load of debt.

ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses

EricM Silver badge

Re: NEVER pay a ransom. Period.

I need to agree. Meaningful "support" in this specific setting (critical health data linked to clear names and home addresses) is probably not possible. This sentence was more meant as a general rule dealing with the financial fallout for the victims of a generic data publication extortion.

But also in this case, Money should go into services protecting the victims from ID theft attempts, as the published information may in addition to its damaging nature allow for impersonation attacks on credit card companies and banks.

EricM Silver badge

NEVER pay a ransom. Period.

Because

1) Even if you pay, there is absolutely no guarantee that the data is deleted. You talk to criminals after all. Imagine the lack of honor of a person attacking a cancer diagnosis biz in the first place.

2) The only thing a paid ransom does, is keeping this scum in business, making the problem worse for everyone.

Keep the money, pay for upgrades of your security (and maybe fines) and support the victims of the data theft.

Brit boffins boast of beating barriers to building fusion power

EricM Silver badge

Re: The way

> I'd much rather have this properly funded than ...

the 1.1B AI hardware plan...

'Asimov was right' about rules for robots, says ex-US Cyber Director

EricM Silver badge

Re: Interesting hypotheseis with truely staggering consequences

Fully agree. One more reason to come with this term with a bit more caution and less hype, I guess.

EricM Silver badge

Re: Chris Inglis hasn't read Asimov

It seem, that, at the very least, he hasn't truly understood the robot stories ...

EricM Silver badge

Interesting hypotheseis with truely staggering consequences

> Don't waste time worrying about AI models achieving sentience – they're essentially already there

When models become sentient, we need to discuss what rights they have, if they are rightless "digital slaves" or "digital persons" with rights.

When models become sentient, spinning up a model will in fact create a sentient being - and a model shutdown will become homicide.

SF has discussed these concepts for ages now...

How can AI sentience being discussed with such a pure marketing focus and such a complete lack of problem awareness throughout this industry?

Time Magazine has a separate version of its website with ads only AI can see

EricM Silver badge

Re: Any lawyers reading this?

But then it must be misleading advertising when the chatbot generates responses for a human based on this information?

An illegal action does not become legal, if you break it down into 2 distinct steps...

EricM Silver badge

Re: Brilliant.

Not really, AI is just served *different* ads than you to poison its training data with selected lies made up by brand owners...

AMD acquires AI chip startup Taalas to boost inference performance by etching models into silicon

EricM Silver badge

Really inflexible?

I'm currently trying to keep pace with the flurry of releases of local models on Hugging Face ...

As the article mentions, this idea seems to lend itself best for _really_ static environments.

Maybe if they come up with a modular design, where you can clip in different model-chips into a base card already integrated into a server? Ideally from outside of the server like via an external USB port?

Interesting concept, nevertheless...

Microsoft tells engineers to curb their token-burning enthusiasm

EricM Silver badge

Burning tokens not for fixing issues or even creating new issues in the process might pose an even bigger problem ...

SpaceX revenue rockets while AI spending burns billions

EricM Silver badge

80% of growth perspective and TAM of SpaceX is xAI

So from an investor's perspective SpaceX is now xAI with some space-stuff attached.

EricM Silver badge

losses from AI operations fell to $1.3 billion

So did they finally shutdown their failed AI experiment Grok to rent Colossus exclusively to their competitors that have actually paying customers?

Cloud giants pour nearly $600B into capex as AI demand surges

EricM Silver badge

The fuse has been lit ...

OpenAI was already forced to lower token prices for some models to stop customers from switching to cheaper Chinese models.

This way OpenAI will not become profitable at all and will most probably not be able to fulfill the long-term commitments it made to the data center operators.

Anthropic will be under the same pressure.

So the current, insane level of CAPEX spending by the likes of Microsoft and Oracle might not be sustainable.

IT boss left root session open for bring-your-kid-to-work day

EricM Silver badge

Re: Groups!

Why, for an self-confident admin, you'd need non-root users at all? /s

Honestly, I remember *nix systems in the 90s even in larger companies, that only had a root user (plus of course the usual stuff: daemon, bin, sys, lp, etc.). So it was not advisable to log on and do anything before the caffeine from the second coffee hit your bloodstream...

In smaller companies this might have been the case much longer.

Too many AI agents can get in each other's way

EricM Silver badge

> Anthropic and OpenAI have both proposed the deployment of agent armies as a way to maximize

token consumption, of course.

Who are they trying to kid?

Leading AI models (even Grok) are all a bunch of leftist punks

EricM Silver badge

Re: Probably not that surprising...

Just re-read my statement. No, I did not.

My statement just said, that everything might look left, if seen from the far right.

Including AI output.

EricM Silver badge

Probably not that surprising...

as, according to hardcore conservatives, even science and nature have a leftist bias.

Reality itself probably looks "leftist", you just need to look at it far enough from the right side

SpaceX to try its luck again with Starship Flight 13 after engines and weather say no

EricM Silver badge

Re: RUD Please

I'm torn.

There is the the old "rocketry" part of SpaceX which created fantastic products, StarLink, F9 and FH, which I wish luck.

There's the newer rocketry part of SpaceX with an oversized rocket, a scam riding on "lets go to Mars" hype and plans to launch "millions of datacenters into space", which, if it ever became true, would be an ecological nightmare and potentially could cause Kesseler Syndrome on its own. So I dont' want that part to succeed.

Then there's the xAI part of SpaceX, a CSAM generating piece of junk which should die a fast death to stop hurting people and wasting energy.

Then there's X under SpaceX which should die a fast death to stop poisoning societies.

Then there's the owner of all this who has way too much money, which he uses to advance right wing and fascist ideas and ideology, so him having less valuable shares resulting in less money to buy even deeper into governments and parties worldwide would be good for humanity.

So al in all, yeah, sorry to the old, "nicer" SpaceX from maybe 10 years ago, but ...agree, RUD would be my preferred outcome, too, preferably taking the launch tower down, too.

Oracle drops 1,449 security patches like it's the new normal

EricM Silver badge

Guess we will hit "peak patch" once the bugs easily spotted by AI are corrected.

I admit, it's currently a bit exhausting. My team was deploying the third same-day emergency patching round over all our servers in as many months (the 2 CSPUs in May and June and this July-CPU)

However, all those bugs being patched now probably lay dormant in the code bases for a long time.

So, after peak patch, we probably will have a substantially safer code base, at least for some specific types of bugs.

Should be worth it...

Senior White House official claims China’s K3 model stolen from Anthropic

EricM Silver badge

Re: "Distillation" is just training on Question-Answer pairs...

Yeah, but that part is supposed to be "legal" as per the AI company's arguments, based on the assumption that training is different from copying...

Which, curiously, adds another question mark to this "distillation equals stealing" statement, as distillation is just another form of training.

EricM Silver badge

"Distillation" is just training on Question-Answer pairs...

The questions come from the entity doing the distillation. The answers are AI-generated, so they are not even copyrightable. The distill-training with this information is done by the entity that formulated the questions.

Wonder where they construct "stealing" here...

What exactly was "stolen"?

AI ops tools will create console sprawl and break IT more often: Gartner

EricM Silver badge

Still waiting for "and here a miracle occurs" to be defined

This industry is still just layering multiple levels of non-deterministic tech above each other and call it "agentic AI ops".

Actions of an LLM are supposed to be guarded by a "harness" and both have multiple "guard rails" implemented , and all of that components work non-deterministic as on every single level, as their responses to minimally different inputs can vary significantly. These systems still suffer from the "butterfly effect". The behavior becomes complex and chaotic.

Nothing you'd like be active in your infrastructure...

EricM Silver badge

Re: can't be any worse that what we have today

Oh, you'd be surprised :)

Torvalds challenged the haters to fork Linux. Someone said 'hold my beer'

EricM Silver badge
Pint

Very interesting choice to start a rewrite from ...

Cheers to @Poseidon at Bejing Universtity and a very promising project :)

Zuck's AI ambitions put Meta on course to become America's next big cloud provider

EricM Silver badge

[...] connecting users with advertisers.

> Both Meta and Google offer various services which generate revenues by connecting users with advertisers.

Let's be clear here: Both are making that insane amounts by basically selling the eyeballs of their users to advertisers under the pretense of offering services to end-users for free.

Meta can use this advertising money to build AI-related infrastructure services that can be rented to AI companies, even though

- AI companies have yet to figure out how to make a profit or any sustainable business at all

- The recent bills of AI companies shocked their customers into re-evaluating their credit lines ( and their AI strategies).

- xAI is already renting out over-commited infrastructure to competitors.

But then what? Wait for AI customers and/or AI companies to go broke?

Meta has a proven track record of blowing billions into Zuckerberg's bad ideas and I fully expect this one to be at least as successful as the Metaverse.

The price is wrong: AI cost calculation has to consider task completion rates, not just token costs

EricM Silver badge

" built a tool called Omnigent to harness the harnesses "

And LLM based guard rails try to protect the LLM based guard rails that are meant to protect the LLM itself...

We are trying to layer multiple non-deterministic levels of tech over each other, hoping to get that stuff reliable. Somehow ...

"It's turtles all the way down" ...

Microsoft chief turns hostile on frontier AI labs, warns companies to guard their IP

EricM Silver badge
Alert

Er, guys, I think the monster we helped create is actually pretty scary ...

Yeah, right. And expensive...

And a lot of people told you so, Dr. Frankenstein...

The AI that spawned MechaHitler and deepfake porn puts on a suit to become legal advisor and Excel jockey

EricM Silver badge

Re: No thanks

This.

Plus: Given the escalating complexity of debugging complex Excel sheets (I've managed to get lost in debugging sheets I had "hallucinated" myself 2 days prior without the "help" of AI ) Excel is generally a very good example on what to use AI generated content not for.

EricM Silver badge

Risk Assessments?

I'd just love to read the risk assessment protocols of the companies that deploy this crappy tech now, only to be hit by hallucinated legal precedence, web evidence or subtly borked Excel formula in the near future.

Ex-NASA boss points out small flaw in Moon landing plan: No lander

EricM Silver badge

Re: Did no one watch 2001?

Technically this would be a good proposal :)

And we'd just need to divert, say, 30% of the worldwide military budgets to that plans. Maybe only 20%.

However, judging by the way this planet is currently run, I don't think that reducing military budgets is planned anywhere.

Buying stuff that can blow up other stuff is so much more fun for governments, apparently ...

Even banks and hyperscalers are now sounding the alarm about the AI bubble

EricM Silver badge

Re: Dancing around the AI seesaw

Given the size of their accumulated debt, that already forced them to lay off staff to pay their dues, going back to fundamentals now might not provide a path to survival for Oracle...

EricM Silver badge

Re: I don't understand how the bubble didn't POP yet.

Too many people financially invested, hellbent on stocks going up, raising expectations and promoting stocks beyond reasonable means through all available channels.

Too many people in CxO roles, without practical AI knowledge beyond an occasional ChatGPT session, being easily manipulated by AI sales people in FOMO purchases.

Too many semi-technical people intellectually invested, thinking their "prompting skills" somehow make them special and fearing an environment where you have to possess actual technical skills yourself to make a buck.

At least the last list item distinguishes the AI bubble from "normal" financial bubbles and gives it some kind of inertia that might lead to more inflation before the pop (and more damage).

Zombie ‘who owns Unix?’ lawsuit comes alive again

EricM Silver badge

I'm confused

> The case and its successors ended in 2021, with a settlement that saw litigants agree to end the matter without IBM admitting fault.

> But by then, SCO had sold its software to a biz called Xinuos that decided to fight on.

So, what is it:

Did SCO accept the settlement for a software that was already owned by Xinuos at that point?

Did SCO accept the settlement for a software it still owned own at that point, then sold it and Xinuos now tries to somehow "un-accept" the settlement?

UN warns of need for global governance to avoid an AI-pocalypse

EricM Silver badge

"Governance"? Why? How?

In the context of IT security we probably have no choice, as the genie is already out of the bottle.

How does the UN suggest to stop criminals using local AI model to find bugs, generate exploits and use them by using "governance"?

No amount of governance will control the dissemination and application of knowledge in and by this group.

Any attempt of governments, to control the application of AI via enforced governance and limitations will only hurt law-abiding defenders. Case in point: The German "Hacking law" that makes the creation, distribution, maintenance and possession of dual-use IT security software like port-scanners potentially punishable by jail.

I acknowledge that the IT industry is currently in a transition phase that is difficult for defenders ( me among them...) , where newly introduced AI capabilities make it easy to spot bugs and convert them to exploits.

Once the same capabilities to spot bugs are established in build pipelines, I expect the threat landscape will find a new equilibrium, with existing, non-discovered bugs at a much lower level than today.

However, any ill-advised attempt to control/limit access to good bug-hunting models (like the U.S. is currently trying to do) will only extend that transition phase, as "governance" tends to primarily stall efforts of legally operating defenders from applying advanced techniques, while attackers will work with whatever they can get their hands on.

There are enough free and O/S models available for everyone with a 12GB graphics card and a decent CPU to have a model go bug hunting to make this a problem for every defender without legal access to. While those are no so-called "frontier" models, the results a good enough to pose a problem for defenders not supported by such tools at all.

TL;DR: You will not solve the problems caused by AI capabilities by governance.

Anthropic is removing its covert code for catching Chinese competitors

EricM Silver badge

Re: The biter bit?

Same here. robots.txt? Why should it apply to AI? Let's start another 1000 scraping sessions...

T-Mobile appears to be quitting VMware – and fighting a very familiar battle for support rights on the way out

EricM Silver badge

Re: "Thousands upon thousands have successfully migrated to subscription"

Sure, there probably is is a sweet spot for the companies Broadcom has taken hostage.

I'm talking about customers for new deals. How many potential customers are still willing to buy for example new enterprise software from Broadcom despite their "customer-friendly" behavior?

EricM Silver badge

"Thousands upon thousands have successfully migrated to subscription"

You see, your honor, thousands upon thousands of businesses have had no problems to pay their monthly "protection" to the Godfather, just this little store here chose to litigate...

The name Broadcom probably was moved from the list of trusted providers into the risk handling list of most of its customers.

UK firm bombarded debt-ridden people with 5.5M texts

EricM Silver badge

Agree

But from Jail ...

Honestly: 300k "fine"? That's probably just a fraction of what the company earned from that scheme.

Add 2 zeroes and jail this A-hole. I think we need to punish financial fraud, especially against the vulnerable, no longer as "white collar" crime, that is somehow better than normal crime. It's extortion, it's crime. Plain and simple. Punish it accordingly.

Oracle promises to open up MySQL governance, but the community wants guarantees

EricM Silver badge
Happy

Oracle promises to open up

You had me at "Oracle promises" :D

Engineer accused of insider trading tied to Microsoft's reboot of Three Mile Island nuclear plant

EricM Silver badge

Hard to defend a prosecution here ...

... while Insider Trading from top political appointees in the White House and their families is not only ignored by the SEC AND federal prosecutors, but has become the new norm.

Infosys boss says vibe coding is no threat because there’s more to writing software than writing software

EricM Silver badge

He probably has a point.

If I look at what/how actually has been vibe coded over the past 18-24 months, I cannot help but be reminded to the late 1980s. We are back to the era of the "Whiz Coder Kid", who just coded along - without full understanding, without plan, without architecture, with under-defined specs, but with a massively inflated ego. Double, triple re-implementations of the same functionality instead of re-use. 3 similar frameworks used in the same project. Even redundant databases being thrown in sometimes.

Even if everything kind of "works" on initial deployment, the shit hits the fan on changes and maintenance.

It took the IT industry the better part of a decade to finally bring a structured approach to spec gathering, developing an architecture and (finally) coding, testing and deploying software, after the "Home-Computer" crowd stormed IT departments.

Today, Devs+AI behave much like the Whiz Coder Kids of the 80s, vibe coding their way through existing code bases, re-implementing, circumventing deliberate architecture choices and causing tech debt. They exhibit the same ego problem and they are having the same effects on software quality, just at a much larger scale, thanks to AI.

So, yeah, there might be huge opportunities ahead for Infosys to fix all this vibe-coded mess.

21,000 Oracle jobs vanish amid Big Red's big bets on AI

EricM Silver badge

Great, and at the same time we see Oracle SRs stall left and right...

...while we get only late, nonsensical replies completely out of context that just scream AI-Slop.

They clearly fired people doing the actual work, while dreaming of an AI future that simply does not exist ...

Result, to quote Cory Doctorow:

AI can’t do your job, but an AI salesman can convince your boss to fire you and replace you with a chatbot that can’t do your job.

This currently plays out at Oracle Support teams in full force.

Would be funny to watch how one of the chief AI salesman sold crap to himself, if Oracle would not have destroyed that many jobs/lives in the process ...

Texas lassoes massive Microsoft datacenter – and 20 years of gas turbine emissions

EricM Silver badge

Fascinating... how reality starts to converge towards those cyberpunk storylines ...

... where citizens are forced to organize self-defense against the seemingly overwhelming power of huge global corporations that operate without being restricted by law (or making their own law in some versions) , show up at a peaceful place and start using land and other natural resources in exchange for polluted water and air.

From what I read, many of the rich AI bros are huge fans of this SF genre - did they ever notice how these stories usually end?

Why Amazon hates 'human-in-the-loop' AI governance

EricM Silver badge

Re: Dear Mr Brandwine, I call BS ...

> That is not the PatternRecognitionReproduceMachines fault, it is the training data. Humans, way to often, say "I've checked, and that's entirely correct.". And surprisingly many with perfect conviction. Same goes for liars, scammers, bullshitters, conspiraciators, preachers etc.

Fully correct, that's why we assign trust to an identity, to a specific person - who does not show that behavior.

AI does not have an identity, no memory, no conversational context beyond the current session.

Talking to an AI is more like talking repeatedly to a call center.

EricM Silver badge

Dear Mr Brandwine, I call BS ...

On equating AIs with humans.

> [AI and humans] will make mistakes and even make stuff up.

Yes, both can potentially fail, but in vastly different ways.

With humans,

- you select the ones that make the least mistakes and do not make stuff up.

- You let go the ones that make frequent errors or put them in roles where this errors do not matter.

- You let go immediately the ones that make stuff up.

Human behavior with regard to that aspects is pretty consistent.

That is why most people trust specific other people. That's why people build careers by being consistent, by delivering consistently.

With AIs

- most AIs work is somewhat OK for most tasks, but every now and then all LLMs produce an outlier result out of nowhere. Some more than others.

- It is not a specific AI that makes errors or makes stuff up, hallucinations are a as-of-now unresolved general problem of LLMs.

AI behavior with regard to errors and hallucinations is extremely inconsistently mixed with good results.

That is why employing AI for any work that is not purely informational and fully checked by humans is a risk.

AI is like a heavy equipment operator that usually does a superb job, but turns up to work intoxicated once a month, damaging property and endangering lives.

Even though the work is great most of the time, the overall risk of employment is too high. That's why conflicts between dev teams and security leads are raised. The dev team sees what a working agent can accomplish. The sec lead sees what it can damage.

NanoClaw now armed with JFrog for safer packages

EricM Silver badge

A secure agent framework?

As LLMs are still inherently non-deterministic, so is every Agent, that is based on LLMs.

As NanoClaw it is still an agentic framework, combining LLMs with tool access, providing tool access to hallucinations, I would not suggest to use the absolute adjective "secure" in that context. One can argue, however, that NanoClaw's sandboxes provide "more security than OpenClaw", but that's about it...

Oracle's AI datacenter splurge gives investors the capex jitters

EricM Silver badge

Re: Chasing rainbows

Not sure if many CEOs today consider LLMs/Agentic AI even potentially a failure/scam - as a growing number of technologists do.

So this thought might not yet have crossed their mind...

Page: