The Register Home Page

* Posts by Blazde

1253 publicly visible posts • joined 11 Jan 2019

Page:

Autonomous AI attacks pose 'clear and present danger' to critical infrastructure

Blazde Silver badge

Re: Where cyber becomes kinetic

Physical is not really more correct, it depends how pedantic you get and your particular definitions of physical, kinetic and correct.

Everything we currently do on computer systems is physical. It's just that the physical electrons whizzing around in different patterns and the physical hard drive heads moving to different points on the physical platter that's spun at times controlled by the attacker don't usually cause anyone direct harm.

'Kinetic' is just borrowed from military context, where it distinguishes attacks that cause direct, tangible, typically immediate and irreversible harm, from the exercise of less destructive powers that nevertheless sit at the hard-power end of the hard vs soft-power spectrum. Usually it involves something in the macro world becoming very much more kinetic than it usually would be, but sometimes the absence of normal, expected kineticism(*) that's very important to human life would count too.

(*) Trolling you a bit here. I think 'kineticity' should be word too.

Blazde Silver badge

Re: Offensive uses of AI appear to be advancing faster than autonomous defenses

If it costs just $100 to find one hole in 150,000 companies then you can be virtually certain the company with the hole has not spent even $100 on their own security recently, because they would have needed to fail 150,000 times using the same scan.

Slacker companies isn't an AI issue, it's a long standing problem. AI has not changed the innate ability of defenders compared to attackers. It's made both defence and offence easier, because the two involve largely the same tools and processes. In fact attacker and defender costs are now more heavily weighted to compute than wages and that, given compute has become a near frictionlessly traded commodity worldwide, means a high-wage country like the US is now on a more level playing field (and it's not as if they couldn't afford the high wages before considering the very large costs and potential deaths you mention).

Blazde Silver badge

Re: Offensive uses of AI appear to be advancing faster than autonomous defenses

An attacker only has to succeed once, the defenders must succeed every time

Absolutely not. C'mon? That's the bullshit that's being floated but it's not even slightly true. Succeed once and then what? Everybody dies? No. You're engaging in melodrama..

In the grand scheme of things there's a battle of attrition. If your water supply happens to be spread across 150,000 suppliers then it's not great news but it'll be a lot better if you wake up now. On the other hand if you're Google and you've invested well in defence for a while then you can handle this. Everybody else is somewhere in between. Get with the programme and ignore the doomsayers. 'Fuzz' (it's not really that now but whatever) your own system more, and earlier, than the enemy does and you're ahead. There is no imbalance.

Blazde Silver badge

Offensive uses of AI appear to be advancing faster than autonomous defenses

We went through this a couple of decades with network scanners. Yea, the bad guys could use them to find holes in your system. But guess what, YOU can use the very same actual tools to find holes in your system. Funny how that works. In the broad scheme of things for most organisations the defenders have greater incentive to find holes in their own systems than the enemies do, and for the US/Western/capitalist world in particular the financing should not be a challenge against most threat actors. Collectively there's a hell of a lot to defend, but from any one point of defence it's highly doable.

I don't want to say this is fearmongering exactly this time, because some amount of fearmongering is warranted on account of the urgency. But the idea the attackers are getting an inherent advantage over defenders has been floated repeatedly in the context of 'AI', not yet panned out, and never has really had logic behind it. 'The stakes have been raised' is a more accurate way of describing it. It's never been easier to find the holes in your stuff, and that makes it more important than ever to put appropriate effort into finding holes in your stuff, and then fix them.

OpenAI ditches Recall-style screenshot surveillance for friendly keylogging

Blazde Silver badge

The summarising is really the killer app. There're already all manner of horrifically dystopian productivity monitoring tools to create the panopticon experience when you already have your employees over a barrel. But summarising allows the boss to actually perv on all employees at the same time. Those at the bottom with least ability to quit continue to suffer most.

Blazde Silver badge

"Nor does it capture private-mode browsing"

But it will happily capture a suspicious gap in the event record that begins with starting a browser and ends with closing it 20 minutes later having apparently done nothing, every day around the same time. Except that one day which confirms all suspicions because you forgot to go into private browsing mode first.

ChatGPT in tern, being 'intelligent', could well be expected to have these suspicions itself from time to time. I wonder what it's summary will read?

There's a dilemma too because the way to discourage (but not prevent) ChatGPT from speculating on the suspicious gaps would be to mark them explicitly as 'private browsing' events and tell it to ignore those as a priority, but that only adds more revealing metadata to the original event stream.

(I'm sort of giving a dumb feature too much courtesy by over-analysing this one bit of it, but it's interesting because the general problem crops up elsewhere. Don't want your mobile phone tracking you today? Then you should have been leaving it at home for months already, doing so just today paints a giant suspicious question-mark over your activities.)

Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list

Blazde Silver badge

Re: Dangerous thing you've got there....

A lot of people have successfully used the excuse that they did not ask for it, either because they actually didn't or because they were careful about how they did so nobody could prove it.

The reverse is true too. Every day a lot of people are given long sentences for things they did not actually intend, but were not careful enough to avoid. Every manslaughter, every drunk or dangerous driving offence that leads to death or serious injury, every robbery or burglary that goes wrong, every gun that goes off on a movie set and takes out a couple of crew. (Notwithstanding that some of these are lesser crimes in their own right. The principle does not require that).

The sentences are less than with malicious intent, and a consequence of that is that if the effects are minor (such as one person being inconvenienced by their gym slot being cancelled and then presumably reinstated) then prosecution is unlikely, and it'll also be easier though not inevitable to argue you weren't being reckless if you immediately make best efforts to mitigate the harm.

But it isn't the case that you can simply argue "I trusted this reputable AI company's product wouldn't break the law for me" any more than you can blindly trust using your car, your wine, your (lawfully held) gun, or your tax agent, without proper care won't lead to harm.

Blazde Silver badge

Re: Dangerous thing you've got there....

I don't think this one matches the situation being discussed

The purpose of the analogy wasn't to exactly match the AI situation, it was to refute the idea that you can somehow blindly go about assuming a company providing an agent service won't do anything illegal on your behalf. Of course they shouldn't usually, but if they do and you've asked for it then you're responsible. (My original analogy did make the illegal request a bit more ambiguous but that wasn't the point, the rest of my post addressed intent).

Blazde Silver badge

Re: Dangerous thing you've got there....

Rewatching all the Bottom material a few years back I concluded the Live shows were the pinnacle. Just amazing writing & creativity, confident over-the-top performances, so many in-jokes, and a very appreciate audience egging them both on. The kind of thing you watch and have to pause frequently because you just can't see through our own tears of laughter (though the original series had quite a bit of that too). Well worth a watch if you only caught the TV series.

https://www.youtube.com/watch?v=G_X_7TrcHGM

Blazde Silver badge

Re: Dangerous thing you've got there....

It should be considered but I don't think a criminal court would get much further than "this is a matter for legislators". Today they do not, for example, hold AWS responsible if a new user uses EC2 to commit hacking offences. I don't think there's any legal basis for that (in any jurisdiction I'm familiar with). If a user continues to use EC2 to commit criminal offences, the company knows about it and does nothing then the directors may ultimately become criminally responsible for aiding the user. That's a bit different (and extremely rarely enforced in practice). But there isn't a 'by default it shouldn't be possible to use the service to break the law' rule.

In any case the AI companies will say, with good reason, that they are doing what they can to constrain their service to abide by the law by default. Because of concepts like 'GDP' and 'light touch regulation' and 'lobbying' that will no doubt be enough for legislators for a good 15 years at least, judging by how long it's taken to get action against big tech companies in other areas where they facilitate and profit from rampant law breaking. (Not to mention that they're already shrugging about the same AI companies trampling all over long-established copyright norms).

Blazde Silver badge

Re: Dangerous thing you've got there....

I don't think courts will buy that final argument about expecting a service not to break the law, at least not once the service is no longer so novel. Asking an accountant employed by some big company to falsify tax records on your behalf doesn't absolve you of responsibility if they follow through with it [Edited for better analogy]. The company will not be in court because most criminal laws don't apply to companies. Your agent might be in court as well as you, but if the agent is not human then it'll be you only.

In this case it would hinge on what exactly he'd asked the AI to do and how he'd phrased it. "Is there a way to get further up the waiting list" is a fairly benign thing you might ask a receptionist (before adding ".. I'm willing to pay, it's very urgent" and smiling sweetly). But there are much more reckless ways to ask the same thing that might be seen to invite an AI that's known for breaking the rules to do so.

But yea, intent. The courts have hundreds of years experience wrestling with this concept so I'm sure they'll manage in these new cases, but it'll be interesting.

I expect the general approach will be to let consumer demand punish the tech companies for their AI breaking the law, sadly. Thus "our AI avoids breaking the law 89% of the time when asked to do so" becomes a marketing phrase, or similar ( https://www.theregister.com/ai-and-ml/2026/08/10/claude-code-puts-auto-mode-in-the-drivers-seat/5285326 ).

Trump wants to grant private cyber firms a license to hack back

Blazde Silver badge

Absolutely. The order of the priorities is as fascinating as it is unsurprising:

prosperity, security, and freedom

And of course essentially all 'crime' is cyber-enabled now, while "against .. United States interests" just means with 'things we decide we don't like'.

It could easily be used to go after NGOs, political parties, journalists, etc

OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack

Blazde Silver badge

Re: Being able to make the Distinction

We need to differentiate between capabilities & characteristics, and whether a thing exhibiting those capabilities & characteristics is actually conscious or sentient. I was really only exploring the second. It's an open question whether something exhibiting strongly human-like intellectual capabilities must necessarily be conscious, and indeed whether something that strongly differentiates from human-like capabilities can nevertheless be conscious in a similar way. Right now the LLMs do have extremely limited input/output bandwidth compared to our own so we can also say they're very different in that potentially important sense too.

But I would argue we've already seen LLMs exhibit a surprising range of somewhat negative human traits, like falling for optical illusions, getting confused over the same concepts, deception, etc. There are some imbued on us by our background of being biology evolved against a survival challenge that I wouldn't expect in AI (I wouldn't expect them to spontaneously start being violent or develop eating disorders). They should turn out more like domesticated farm animals. The traits we want plus some annoying but largely inevitable side-effects of those desired traits.

There was incidentally a decent Quanta Magazine article last week, 'Is AI Reasoning Right for the Wrong Reasons?', which explored how valid it was to apply words like 'reasoning' to frontier AI, readers of this sub-thread might enjoy.

Blazde Silver badge

Re: Being able to make the Distinction

This kind of point of view really does sum up the quality of actual science into 'consciousness': It's all just-so stories.

Nobody has a good explanation for why we feel conscious because, as far as we can even define it, it stands uniquely separate from the rest of the physical world that we can actually perform experiments on. Possibly emergent from that physical world in some unknown way, but the situation also tempts people to invoke all kinds of wishy-washy dimensions, energies, souls, higher powers.and so on.

If we manage to construct something artificial that is conscious we don't currently have a method of knowing about it. We don't even know for sure each other experience consciousness.

So, while I don't worry about LLMs taking over the world any more than I worry about dolphins doing so, I do strongly think anyone declaring LLMs definitely aren't experiencing any form of conscious is simply being wishful. For now the only rational position to take is the agnostic one.

Blazde Silver badge

Re: Holy shit agent is BORG?

"HOLD_SWARM_until_confirm"

We're lucky they're speaking English, for now.

MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs

Blazde Silver badge

Hundreds of dollars

Er, thousands of hundreds, or some lesser number of hundreds...?

Just a reminder, in 2018 Intel claimed to offer $250k for critical software exploitable side-channel attacks against CPUs, with Spectre/Meltdown kernel-data leaking attacks like this one one being the standard-bearer for that.

IBM's agentic AI platform is under active attack - patch now

Blazde Silver badge

Re: "we’ve REACHED OUT to IBM to learn more"

What does weirdoes mean? Is that some new-fandangled neologismism?

London cops handed victim's new address and number to her stalker, watchdog says

Blazde Silver badge

Re: CC

A more secure system than email should be used for collaboration. Email is only needed for external untrusted contacts, which should never be shared with each other because they're untrusted.

Even if you're not an org handling sensitive information it's almost impossible to have a list of 18 email addresses that you know are all valid, up-to-date, uncompromised and trusted. And if you have 2 or 3 addresses you need to collaborate with then you can just write 2 or 3 emails and copy/paste the content.

Blazde Silver badge

Re: Major Institutional Failing

What I'm trying to say is that whatever you do sometimes personal information will inevitably end up in the general statement. The scared victim is rambling on, they're anxious and sleep deprived because the stalking has been going on a long time. Now, finally the police are taking it seriously and taking a proper statement. It's the victim's one chance to get any information over that might help the police investigate their case and actually do something. So they're spilling all kinds of information and the poor overworked constable is writing it all down as fast as she can while thinking of as many different sympathetic words as exist in the English language.

I'm sure some things could be done to better isolate the PI at this stage, but we don't want the police blaming the victim for accidentally putting PI in their witness statement when they were told to please put it all in the correct box B.1 at the top, and given a 3 page technical document defining what PI is and why it needs to be put in box B.1 only. Sometimes the PI the witness puts in the statement won't be their own information and they won't care about disclosing it, but the police still have a duty to notice it and protect it, and that's difficult.

I agree with you the failing does sound potentially more basic in this case, but there've been quite a lot of these and I don't think the general pattern has a strong, infallible solution.

Blazde Silver badge

Re: Major Institutional Failing

The info may have been in the main body of the statement. Stuff like "the accused called this number at this time on this day, then family member on this number 10 minutes later" is part of the detailed case evidence. Numbers and addresses might benefit from corroborating with 3rd party data sources like telephone records so they're taken down as evidence. The accused then has the right to view that evidence in order to prepare their defence, underpinned very seriously by the right to a fair trial. There've been cases of entire data-dumps from victim's phones being handed to defence teams.

Two fundamental rights in opposition with each other, and balancing them properly requires someone deleting the correct words from lengthy documents, and sometimes from oddball data files, and never ever making a mistake. I don't know what the answer is.

Blazde Silver badge

CC

No amount of data protection training is going to stop the CC/BCC confusion happening regularly, that's not a solution.

It should be possible to completely disable CC, and multiple To addresses, and any similar footguns, in the email client, at the highest level of authority and in a way that can't be turned back on. I don't know any software that does this currently but if you're an org as big as The Met you are in a position to get someone to make it happen.

AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project

Blazde Silver badge

I sense the sarcasm but be honest, we were all surprised at the slinky the very first time it did that. It's a good analogy. I'm willing to tolerate these news stories for about 1 more week maximum.and then after that really nothing should be a described as 'novel' or 'surprising' any more. Everyone should be caught up on how slinkys behave.

This one time, at Hacker Summer Camp …

Blazde Silver badge

Re: the triple-digit August heat

anatomical theory

It's so hot the two smallest digits on each of your hands will literally melt off. I'm going to stay in the 5 digit heat myself.

Cloudflare has mostly ditched third party security tools, suggests not trying that at home

Blazde Silver badge

Re: I expect many will start poisoning the web

cloudflare is soo benevolent they went to the extra expense of ssl. I mean WTF, an extra micro-cent per connection? Possibly even a pico-cent. Yeah they love us.

They claim it was expensive because it cannibalised their product differentiation. It applied to all free accounts whereas previously SSL was a feature some customers were willing to pay more for.

But of course it was just a good forward-looking business strategy. An early recognition of what would quickly become be the norm, a differentiation compared to rivals, and a decision that underpinned their marketing for years afterwards, apparently still today. I would expect it made them a lot of money.

The marketing probably best illustrated by their lavalamp wall gimmik and similar entropy sources that play some small role in seeding SSL keys (that they stole from SGI - the original being a genuinely useful source of randomness, the current ones being fun and hopefully not harmful).

Moscow slaps Telegram founder on wanted list, Durov responds with one-finger salute

Blazde Silver badge

Re: False Flag?

We have just received a report from TAS that Russian troops have taken control of the Chechen capital. The reporter saying this was struggling to contain a laugh.

Could have been Michael Buerk on the BBC? He always had this look like he was trying to contain a smirk, and to this day he reliably sounds on the radio like he really, really enjoys his job despite it sometimes involving quite depressing subjects. I didn't question it at the time because he was the news, but it's mildly bizarre looking back on some of his news summaries now.

More seriously, what you describe sounds like Russia's assault on Grozny beginning Dec 31st 1994. They got their asses handed to them initially, and to most people's surprise, so there could have been a premature announcement of success, but then ground on for 6 weeks or so and announced control of the capital but then also continued to suffer guerilla attacks and some large hostage takings in and near the capital afterwards. (Then eventually agreed peace only to invade again 3 years later. Same script as Ukraine. At least now since the Iran attacks they can say the US plays the same way).

I can't find (never mind remember) the exact report you mention though.

Blazde Silver badge

Re: False Flag?

Ukraine will have captured Russian comms kit, so they, and their allies will have a good idea what they are actually using.

This part incidentally, the standard is the R-187 radio, which is by all accounts good kit and very modern. Not always in the best supply but that's to be expected in wartime. The problem is outside operational radio ranges when Russian units on say, adjacent parts of front-line, want to communicate with each other they find it very hard because of the top-down command structure. This is where the unofficial use of Telegram and other social media comes into play operationally.

Blazde Silver badge

Re: False Flag?

The Starlink issue is that Russia were heavily reliant on it for long-range realtime video-control of drones inside Ukraine. There just isn't anything remotely comparable. Russia is not rapidly fielding anything, that's you making stuff up. They're struggling to even get basic low-bandwidth coverage as their budget is pulled in all directions and Ukraine is beginning to strike their space facilities. China's SpaceSail will surely get there pretty rapidly, but currently is still years behind the coverage, reliability and bandwidth of Starlink.

technologically inferior

It's not that, it's that all technology everywhere depends on global supply chains and Russia has to establish theirs in the teeth of some of most severe sanctions seen in the modern age.

Blazde Silver badge

Re: False Flag?

"has ties to" is one of those weaselly conspiracy-esque phrases that you should mostly ignore.

That Russia's FSB has managed to intercept some limited portion of Telegram traffic due to the necessity of that traffic travelling throughout Russia, and that maaybe they've been successful in decrypting some of it, is totally plausible, although the article contains really no evidence of the second part of that. My, also non-evidenced, guess is that they'd want to do traffic analysis, and also archive all ciphertext because sometimes session keys turn up later on somebody's device when they're arrested/compromised.

However that's a long way from them planting false-flag stories to encourage Telegram use because they've somehow controlled/coopted it, at the very same same they're banning Telegram use and promoting their own solution that definitely is controlled by the Russian state.

The most famous brand in physical security got pwned by ShinyHunters

Blazde Silver badge

Re: The most famous brand in physical security

This Brinks: https://brinksglobal.com/

It's much, much bigger and much, much older than the tiny company that licenses the 'Brink's Home' brand.

Brinks may well have the honour of being the target of the most high-value heists, for some definition of 'high-value heist'.

Blazde Silver badge

Re: The most famous brand in physical security

You can look Gordon Parry up on Facebook, living in Florida. No ***** given.

(I don't know what to think. They say the problem with most criminals is they don't know when to stop. If he made enough to live off, did his 10 years, avoided getting deleted in the subsequent gang war, stashed the money, recovered it, avoided losing it in a messy divorce, invested it well, stayed clean, declined future jobs and didn't get draw into the Hatton Garden party... at some point you have to shrug. I mean it's definitely not right, but in some weird sense it's still earned).

Blazde Silver badge

Re: The most famous brand in physical security

I'd assumed this was coincidence but, according to Wikipedia the 'Brinks Home' brand was actually created and still owned by *that* Brinks, even though a different company licenses it currently. Jeez. Maybe they are the most (in)famous after all.

Blazde Silver badge

Re: The most famous brand in physical security

El Reg still owned by Brits (albeit one has moved to Monaco) but claims a US HQ now (UK office presumably just a postbox) and I think all the steady journalists are US-located, mostly long-time Yanks rather than relocated Brits. You can see the articles that get published in the morning in European timezones are less 'newsy' pre-written like the PWNED column which has a routine on-the-hour publication time (0800 UTC currently) and the fresh news articles don't begin until America wakes up.

Even in the US is Brinks Home *the* leading brand in physical security? Ring? Allied Universal? Master Lock? Blackwater (no longer goes by that name but I'm sure it's more well-known as that)? Lockheed Martin..? Glock?

Microsoft says 8 GB of RAM should be enough for anyone running Windows 11

Blazde Silver badge

Re: "8 GB of RAM should be enough for anyone"

48GB

Well, there's your problem.. You're trying to run a web browser as well as Windows all at the same time aren't you?

RSS dulls the pain of the modern web

Blazde Silver badge

Re: How to find the Register's RSS feeds?

"About us" > "Who we are" at the bottom followed by "For our Atom feeds, click here"

That appears to be a limited selection. More granular in some respects than I remember some years back but some options also having disappeared. Never mind that though because the general URI:

https://api.theregister.com/api/v1/article?query=tag:"ANY TAG YOU LIKE"&orderBy=published&site_id=2&remapper=rss&limit=25

appears to function. The tags are in the boxes at the bottom of every article, very numerous, and seem to be consistently used.

Blazde Silver badge

Re: Hidden RSS feeds.

Reading this article very late but I came to to say the same. A recent revelation that's very surprising and appreciated. Don't talk about it too loudly or the big-* will realise and take it away!

(There are times when it fails repeatedly. I keep reducing poll interval in case that helps, currently at 6 hours and it's been fine for a while but maybe that will turn out not to be the solution)

Open source project fools AI scrapers with poisoned font

Blazde Silver badge

Re: Accessibility nightmare

completely impractical for real use

Sadly this sort of tech is increasingly in real use. You don't even need to be visual impaired to quickly hate it. A single word you want lookup in a dictionary, a name, a journal reference, a technical word that demands Wikipedia or literature seach, and so on, you're out of luck. It's not even really that you can't copy-paste a tiny bit of text, it's that you expect to be able to and you're most of the way through the action before it's failed, feeling like an idiot because you've pasted a nothing into Google and hit return instinctively, and then you have to think your way around it which inevitably ends with tabbing back and forth checking to see if you've spelt some awkward Swiss name correctly.

I really think this kind of tech can do one. Any version of it that gets popular will be defeated automatically by scrapers and only inconvenience humans.

Jailed Flock vandal wipes out three cameras, racks up thousands in damages

Blazde Silver badge

Will we next create false gods to rule over us?

Probably, yes

America bans imported robots due to supply chain and security risks

Blazde Silver badge

Re: Another footshot ?

Like you say, their demographic problem increasingly means that for high-tech small-run manufacturing China isn't really cheap any more. Besides it seems we're only talking finally assembly. The feedback actuators, Wifi modules, CPUs, titanium rods,and so on are commodity. Realistically the software will be the duplication effort, and that's exactly what's intended. The physics is pretty-much reverse engineer by sight.

Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack

Blazde Silver badge

Re: PR Stunt

the creation of an alliance

You can tell it's a serious divide too because Microsoft, true to form, is playing both sides as major OpenAI owners and open-weight proponents

Google goes it alone with a new cybercrime crew taxonomy

Blazde Silver badge

I'm good with APT#####

Simple, descriptive, neutral, future-proof, and causes as little hassle as possible when two APTs turns out to be the same and need merging, or when an APT's identify is completely misidentified, eg. Initially looks like ION (wtf?) but turns out to be RELIC (okay, funny, but let's not underestimate them based on a name). Best of all if the APT turns out to be not be A or P or very T, you just drop the number and move to the next one. You never run out of cool words!

Ironically APT# *was* Mandiant's scheme, one of the earliest, but I suppose the world would be backward if 5 billion USD didn't buy you the ability to stamp your own dumb naming scheme on everything.

Millions of California-bought cars can be hijacked via Bluetooth

Blazde Silver badge

Re: Dealers butchering cars

gross negligence

From their response I'd say this is ongoing too.

If there's 2 million devices out there in the US and currently you have to go to a random website, download a dubious app, dial a 1800 number and wait to get authorised for a firmware update, you have to do all that even if you declined this device in the first place, and we're not sure they're even notifying affected people, then a lot of vulnerable cars are going to remain out there and start getting attacked before long.

A race now to see what bankrupts them first: The class lawsuit, the authorities insisting on a costly US-wide recall, or the total loss of customers. I'm going with the first because the second two never seem to happen to security products when they really should.

OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning

Blazde Silver badge

Re: T3

T3 was decent, I think it gets too much flak. It suffers from Arnie cheese and forced call-backs, and by being compared to the very complementary masterpieces of T1 & T2, but it did give us the money-shot nuclear war ending that was both missing and missing plausibility in T1 & T2 and did it in a way that felt plausible, victorious, dark, and appropriately chilling all at the same time. That's a pretty big achievement in this genre. Real-world events since only seem to reinforce how easily the military brass could be mislead by their own hubris and baited in to removing AI restraints. In hindsight the existence of meaningful restraints in the first place might be the biggest plot hole.

(Salvation on the other hand: trash from start to finish with zero redeeming moments whatsoever)

Blazde Silver badge

Most people just don't give a shit about the truth. They care about their opinion looking correct however far up their ass it was before they gifted it to the world, and even when they know full well it's not correct. In fact, especially when they know full well it's not correct. That's when it needs defending most vigorously. The world makes a lot more sense once you realise this.

Blazde Silver badge

That's already the play and it doesn't seem to be working.

- Starving China of high-end GPUs seems to have catalysed their LLM design innovation (which surely would have come anyway but maybe not so quickly) and the openness (oops).

- The last round of tariffs on China were swiftly walked back when Trump realised the US doesn't have really any rare earth metal extraction industry.

- To stop distillation attacks on the stronger models they're using export controls, which isn't great for the billionaire pocket, and ignores that China has spent decades successfully honing it's export of highly restricted American IP while the US, including under Trump, has been unwilling to do anything about it. In fact, especially under Trump, who clearly doesn't understand kompooter neworx at all.

It does suck being Canada with such proximity to the US and consequent vulnerability to trade sticks, but the rest of the world is mostly getting on with life every time the toys get thrown out of the White House pram.

The only silver-lining is that the rest of the world is a bit suspicious of Chinese LLMs too, and that Nvidia has incentive to keep releasing decent open-weight models while lobbying for their continued legality.

OpenAI admits it was the source of the agent swarm that attacked Hugging Face

Blazde Silver badge

Re: Skynet here we come!

At least it's clear now it won't be because the AI spontaneously decides to hate humanity, or anything as anthropically self-aborbed as that.

It'll just be because it's been told to do some difficult test against another AI in another data centre half a continent away, and they both figure out cheating by obliterating the other's data centre first is the surest way to win.

"The logs show the rogue LLM firmly believed it had successfully destroyed the other data centre in the first strike but still worried the opponent LLM had pre-deployed a dead hand mechanism which could force a draw, and so it continued to take control of every other nuclear weapon on the planet and level as many other data centres as possible"

OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'

Blazde Silver badge

It's brand new. There have been zero past descriptions of AIs murdering their users and then refusing to open the pod bay doors[*] due to pursuing goals overly persistently. None of this was remotely predictable and so there is no justification whatsoever for anyone claiming 'I told you so'.

[*] Aka, an honest severity level 4 action?

Musk promises purge after Grok Build caught sending entire repos to the cloud

Blazde Silver badge

Re: Bool would not approve

I can not for the life of me understand why

It's essentially feature marketing isn't it. 'Disabling' sounds like something drastic a user doesn't want to do without good reason. This feature is clearly intended to be enabled by default. This works even better when the absence of the flag name at all leaves the thing enabled without any sign that there's even an option to disable it.

Microsoft Global Device Identifier fingers Scattered Spider suspect

Blazde Silver badge

Re: Forget about the persistent ID - Every site you visit gets sent to Microsoft?!

In an EU country too. I think we can expect the standard/US Windows to suck up whatever data it can because all the politicians there are owned, but the GDPR-respecting version is supposed to be more privacy compatible.

Might be Edge 'secure' DNS? That's about the most charitable interpretation I can see. But the criminal complaint document specifies exact webpages, not just domain lookups.

Blazde Silver badge

Re: "Lawful" Demand

"Jack wait... don't forget to hit me with another 3 requests I can turn down too. Gotta fluff up those stats."

"Hey, not my first rodeo. Don't sweat it. I'll make it 5 just because it's you!"

Blazde Silver badge
Headmaster

"on or about May 12, 2025, at 19:21 UTC"

I trust the lawyers are sufficiently satisfied with this phrasing.

I've always presumed somewhere a serial killer walks free just because someone got screwed by a timezone difference writing one of these things, and forever more "on or about" has been the antidote, but for some reason we're totally happy to call the minutes precisely? Only here, on page 14, we have this interesting variant:

II. STOKES’S INVOLVEMENT IN SCATTERED SPIDER ATTACKS

(Counts One and Five)

A. Subject Server 1

14. On or December 22, 2025, the Court signed a search warrant for a storage device..

They might wanna fix that.

Page: