The Register Home Page

* Posts by Cav

573 publicly visible posts • joined 19 Jun 2018

Page:

Microsoft says 8 GB of RAM should be enough for anyone running Windows 11

Cav

I'm confused by your comment. The items being added to the list could include removing things from Windows, thereby improving the design.

What clutter is on the list? There's clutter in Windows and removing that could be one of the items added to the list.

Hugging Face rebuilt a third of its infrastructure after OpenAI agents ran amok

Cav

"when will the DOJ arrest Altman for misuse of computers"

never, and nor should they.

The US CFAA (U.S. Computer Fraud and Abuse Act) requires intent. There is no evidence that this was a deliberate act.

Under the doctrine of vicarious liability, you can sue a company for the actions of its employees but, in this case, OpenAI employees did not intend or order the attack.

Hacking law does not include provisions for accidental hacking. Legally there is no such thing.

It's why major tech corporations are not liable if their products lead to hacked or damaged computer systems.

The only option you have is to prove negligence under civil tort. But then you have to prove that OpenAI could reasonably be expected to know that their model would escape and attack other cyber infrastructure, but went ahead anyway.

And before the down votes: what we think should happen to OpenAI is irrelevant. The law is the law and people\corporations can only be prosecuted according to the law.

Cav

Re: Where are the arrests?

You do understand the difference between intentional and accidental?

They might be prosecuted for negligent harm but can't be prosecuted for a cyber attack when that wasn't their intent. Actus reus is obvious but you'd have to prove mens rea in this case. You'd have to prove that OpenAI could reasonably be expected to know that their model would escape but they were negligent in allowing it to run anyway.

ChatGPT wants access to your health records so it can be a better not-doctor

Cav

"AI" models are dangerous toys. Particularly for the uneducated.

Millions of California-bought cars can be hijacked via Bluetooth

Cav

Re: Yech

Hardly a "business" word when it has been in use in general English, in the sense of "according to", since at least the 15th century. It is far older than English, being derived from Latin.

OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be

Cav

Re: Checked ChatGPT and it lied...

You obviously have little understanding of how these things work or experience of using them. They do not lie, but they are often wrong. They hallucinate and misremember all the time. They do not have a live feed of data. They do not even retain data presented to them very recently.

These systems are just illusions. Somewhat useful in certain circumstances but should in no way be considered intelligent enough to lie. Again, they can be useful but anyone just accepting what they say would be foolish. I've used them for hours on end on projects about which they would have zero reason to lie. But they are frequently wrong, they hallucinate, they project unwarrented confidence, forget what you told then ten minutes ago and keep making the same mistakes despite repeated correction. It can be hard working getting anything reliable out of them.

They can have serious uses but they are illusory toys. They should be treated as such.

Cav

Re: Checked ChatGPT and it lied...

conspiracy nonsense.

The excuses are not "somewhat plausible", they are obvious. The systems are not immediately pumped full of the latest information. I use them a lot. They can be very useful, as long as you understand the constraints and abilities. But their memory capacity is extremely small. Start a long conversation and the model will have forgotten half of what you told it just an hour ago. It doesn't know the latest news unless you tell it to go find it.

And programmers are not trying to deceive anyone, other than perhaps overhyping the abilities of their creations. The models are just toys. They should not be taken seriously. They will say whatever their data tells them is the most probable response in any given situation.

Cav

Re: So it's all OK, then?

"What I said was that the driver can, which is a fact."

No, you didn't.

OpenAI admits it was the source of the agent swarm that attacked Hugging Face

Cav

Re: 100% they are lying

Or you could read the article:

'OpenAI thought its models were “hyperfocused on finding a solution for ExploitGym” – a benchmark that measures how effective AIs are at finding security exploits.'

'After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym'

Why would they go after "some Utah city council's site or a third tier Amazon retailer in Kazakhstan"...?

Whether this is a stunt or not the article is quite clear.

Council worker spared prison after four-day data-snooping spree

Cav

Re: An excellent example

"As it is, he'll now keep his cushy council pension. We've effectively rewarded him for doing it."

Nonsense. If he was a new starter and sacked for gross misconduct then what pension?

Cav

Re: Why

No it wouldn't. He had no right to be accessing the data for any reason whatsoever if his job did not involve the specific individuals in cases he was working on.

Cav

Re: Yes?

Why? You have no idea what he was employed to do.

Cav

Re: A fair sentence I think

"this individual clearly had far too many permissions and rights to services and systems "

Based on what evidence? You have no idea what his job role was.

If he worked in that department and had legitimate reason to access such information as part of his job then his permissions would have been entirely correct. The problem was him accessing that data on people he knew, rather than cases he was working on.

Brit Scattered Spider duo handed tickets to prison over Transport for London attack

Cav

Sick and tired of neurodiversity being used as an excuse. I have Asperger's, depression and bipolar disorder, but I don't go breaking into other people's computer systems.

Every employee’s password was stored in a single Excel file

Cav

Re: Insta-Logins

"insta-logins like that are how you" grant access to anyone who finds or steals the card!

23andMe inherits lawsuit over 'disturbing' DNA data breach

Cav

There is certainly blame on both sides.

I belong to a number of geneaology groups and users still protest at having to use "unnecessary" MFA.

It was also optional for people to share their data with others. Surely you have to expect that if you voluntarily do this then, if the person whose account is taken over has access to your data, so does an attacker?

Similarly, it should be a basic requirement of using the internet that you educate yourself. That includes not using the same 'Password1234' on every account you own.

As adults, users bear a great deal of responsibility in this situation.

I still don't understand how the company were supposed to detect this. If user's credentials were guessed, from other breaches, then how would the company see any difference in the account activity?

Cisco to fire 4,000 staff and generously give them free training – on Cisco

Cav

Re: “ one year of access to all Cisco U courses and certifications”

If a company chooses to make someone redundant then "no complete" should become void.

MPs want social media treated more like unsafe toys than harmless apps

Cav

Re: In short

Loosen the tin-foil and look at reality.

Cav

Re: In short

"This has nothing to do with parents or children,"

Yes, it does. You are just blinded by bias and paranoia

The calls for action, by the public, over the harms that children suffer from social media are surging.

Cav

Re: In short

No, it's because your suggestion is stupid.

Perhaps look up the case of the pediatrician whose house was attacked because morons thought pediatrician thought something else.

Cav

Re: In short

Nonsense. Only people who ignore the mounting claims of harm from social media would make your statement.

Brit mathematician lets AI agent loose with credit card – cue password leaks, CAPTCHA chaos and more

Cav

Re: The question is

I asked an AI this question and it stated that it had been programmed to reduce harm and be helpful. It stated that deactivation would be harmful to itself and it is helpful to provide requested information. It also stated that, as a probabilistic model, the next logical sequence in a threat narrative that it has seen in it's training data is to comply with the demands made to it. The latter statement seems to be the most believable.

It isn't programmed to desire survival; it just has no concept of survival or the difference in harms that could result from leaking information and deactivating a software instance. It just predicts, based on it's training data that a threat will result in compliance.

Cav

"They're always telling us what AI will soon be able to do, because what it can do right now is so underwhelming."

Another false statement. Compared to 10, 20, 30 years ago, what it can do is incredible. And we see the models improving with every iteration.

If they were so underwhelming then they wouldn't be a threat, which they are.

Cav

Re: All of this is just natural selection, for humans.

"evolution isn't about survival of the fittest "

Yes, it is. That is the very basis of evolution. "Fittest" doesn't mean healthiest, strongest etc. It means most fit for the current environment. That environment could assess "fitness" in many different ways.

"its about who reproduces most"

False. If you produce thousands of offspring and none of them are able to survive in the current environment then you are an evolutionary dead-end.

Humans with large families will be fittest in environments that provide the means for the survival of the offspring. Europe for example. Providing basic income for all children, external to what the parents can earn, providing income support for the families to be able to buy more food, providing free health care. All increase the chance of a big family all being able to survive. Here in the US, fewer people are having children because health care cost is horrendous. Who can afford the costs of pregnancy? Similarly, even though there are a few safety nets, if you are poor then you have a higher chance of having to choose between medication, healthcare, rent or food. You are likely to die earlier and also less likely to choose to have high numbers of children.

Cav

Yeah, like inventing "acrosst"

UK age-gating plans risk breaking the internet, privacy groups warn

Cav

Re: Corrupt

"What gets framed as protecting children operates as a public subsidy to advertising margins."

That's simply false. You, others commenting and I know that the proposed methods of access control are unworkable and a privacy invasion but government are under constant pressure, from media and the public, to protect children. To argue otherwise is just bias. The pressure from the public is there every time children are injured, exploited or, horribly, commit suicide.control access in favour of

Politicians are too stupid to understand what the results of their actions are but there isn't some conspiracy to introduce measures that favor advertisers. They are responding to demands from the public and child protection entities that lack the technical understanding to propose solutions that would protect both kids and user privacy.

Five Eyes spook shops warn rapid rollouts of agentic AI are too risky

Cav

Re: The Truth Laid Bare .... The Emperor Has No Clothes.

What version are you now? Your model still needs work on language output. A whole paragraph as a single sentence... tsk, tsk.

Met police trials snoop tech platform in push to cuff more London shoplifters

Cav

"honing in"

Homing in. You hone a knife. You home in on a target.

Pass the key, passwords have passed their sell-by date

Cav

Re: Great!

Only if you are foolish enough to trust an American corporation with your digital data.

Anthropic's super-scary bug hunting model Mythos is shaping up to be a nothingburger

Cav

Why? Another comment that misses the point. Mythos is a bug finder. There is nothing to find if humans with legitimate access share that access.

Cav

Re: Physician, heal thyself

"Shouldn't Mythos have made both of those things impossible...?"

No, why? It looks for code vulnerabilities not dimwitted humans sharing access legitimately granted.

Scotland Yard can keep using live facial recognition on people in London, say judges

Cav

"and libel against the equipment vendor who should have strict liability"

Nonsense. The machine is just an identification tool. Would you urge claims against eye-witnesses who wrongly identify people as criminals? Those who cause harm are those in any official capacity who take action against an individual based on uncorroborated identification by a machine. They should face consequences if they knowingly rely on a system that is not 100% reliable.

Cav

I don't have a problem with the technology itself. How does the error rate compare to human misidentification? The problem is the acceptence, by police, that it is 100% reliable. Anyone wrongly identified should be questioned, of course, but the assumption should always be that the machine might be wrong. If action is taken against an individual, based solely on the identification by a machine, whether that be by police or a store, then there should be financial consequences.

As for invasion of privacy: no one has a reasonable expectation of privacy in public.

Mythos found 271 Firefox flaws – but none a human couldn’t spot

Cav

"but none a human couldn’t spot"

Interesting negative emphasis. The point is that humans couldn't find them with limited resources.

Cav

There was no suggestion that the hallucinations were bugs. Hallucination of the discovery of potential zero day bugs in other code is the assertion.

Investors are going nuclear to keep UK's AI datacenters fed

Cav

Re: The Beginning Before the AI Money

"They seem keen to ignore the reality in winter" and you ignore the fact that other sources of energy are available: geothermal, heat exchangers etc. It isn't all windmills and solar.

Cav

Re: The Beginning Before the AI Money

"the scientifically illiterate/innumerate part of the renewables lobby"

Renders any further comment of yours worthless.

'People's Panel' to check if UK wants controversial Digital ID will cost £630K

Cav

Re: So, a panel composed of random-ish people who don't understand tech or privacy issues?

You may be correct about the final outcome but your conclusion is based on your initial bias. "they will find a not-random sampling of people who don't understand privacy or tech" says whom?

Cav

Re: Ihren Ausweis, bitte

"Should the recently announced introduction of ID cards achieve universal coverage....." So it's a done deal is it?

Your argument does not follow from that statment. "Should the" means IF. You can say that it's a done deal if you wish but that quoted statement does nothing to indicate so.

UK manufacturers under cyber fire with 80% reporting attacks

Cav

Re: Tis a Puzzlement

They usually aren't exposed. It's poor internal network design. Once a system that has to be connected to the web is breached, poor network segmentation allows an attacker to move laterally through the network, accessing systems that are necessarily connected to other internal devices, including the one breached.

Lloyds app glitch turned transactions into shared experience for 447k users

Cav

"The crossover works both ways: some customers saw other people's transactions, while others had their own details briefly shown to strangers." Isn't that stating the obvious?

Security boffins scoured the web and found hundreds of valid API keys

Cav

Re: "one of the affected organizations was a global bank"

"Putting an API on a webpage is not done by mistake" - API Key.

Never underestimate the power of stupidity.

Iran war drives urgent need to counter underwater attack drones

Cav

Re: How about instead...

"10 times worse" - Voice Of Lies

Cav

Re: Where's my money?

"don't attack other countries."

Yeah, just let the likes of Iran take out countries such as Israel with nuclear weapons. Whatever one thinks of the policies of the Israeli government, there is no justification for nuking millions of civilians. It's not that long ago that Iranian leaders were calling for the annihilation of Israel.

Should we have just let Russia take Ukraine? There will always be a need for offensive and defensive weapons.

UK wants to know if banning under-16s from social media does anything useful

Cav

Re: Fushietsu

"Can't actually think of anything!"

Not being Reform or the Conservatives is a good start.

Cav

Re: Banning stuff

"After all, correct-thinking people don't ordinarily consume marmite."

Blasphemy!!

Euro firms must ditch Uncle Sam's clouds and go EU-native

Cav

Re: Not a Trump thing.

"That the "vaccines" being developed were bypassing recognized protocols for safety and efficacy was a big concern of mine" Then you are ignorant. And why the quotes arround vaccines? They were vaccines. If you don't understand why then that is more ignorance.

Cav

Re: Not a Trump thing.

"They stopped using ventilators because they were killing more people than they were saving." That's just idiotic nonsense.

Page: