Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • I guess the author (who is familiar to me) missed the common theme behind these two things. It's use in military systems. So no surprise there. Right from the days of Enigma machine to AI drone, the same restrictions were used many times.

    Germany or Europe is no different.

  • Time to create some esp32-in-a-lightbulb open weight model dead drops.

    Please don’t open-circuit the light for several hours.

  • Recently I realised that a solar-powered garden light could easily hide an ESP32 and has its own power source. You could even place them in public without being too suspicious. Might want to disable the light, so the power lasts longer and so it's less likely to annoy someone into removing it.

    Someone can do the math on panel and battery size. I'm thinking it'll work as-is, as the ESP with WiFi on will draw similar power to the LED that you disconnected.

    But how will you give it even a GB of storage for a tiny model?

  • I feel like eventually we're going to end up just like how the cryptography restrictions were in the 90s. They might have seemed necessary back then, but now looking at it, the technology and AI is probably going to become so ubiquitous in the next 10 years that we're going to wonder why we even restricted it in the first place, when it's something that's just going to be everywhere. Like they said at the end of this blog: "What arrived in my letterbox after two weeks on a CD can be downloaded today in fifteen minutes."
  • (in a Forrest gump accent) my momma said that locks on doors only keep honest people honest. I'm not Forrest Gump, but my mom actually did say that and it's true.

    What ever we have can be taken from us by powerful people, even life itself. In point of fact, that's exactly how these weights were created in the first place--they scraped the intellectual property of the world, and now are trying to restrict access to what they themselves just took.

    That being said, I don't think any of the AI billionaires who are talking about this have taken the locks off of the doors or gotten rid of their security systems.

  • I don't understand what we're talking about here. The cryptography debate was won because the government was wrong. PGP for example is not dangerous, it's a safe and well-behaved piece of software that prevents certain messages from being read by people other than their intended recipient. If PGP had "escaped containment by finding a zero-day in a package proxy and reached production infrastructure at Hugging Face, exploiting additional zero-days along the way", everyone including Phil Zimmermann would have immediately agreed that this is a dangerous product which needs to be handled carefully.
  • > PGP for example is not dangerous ... If PGP had "escaped containment"

    I think the disconnect here is the dishonest framing that OpenAI have purposefully put on this incident. Their LLM did not "escape containment" in this "rogue AI" Hollywood blockbuster sense that they want you to believe. An LLM cannot do that; it is just a static computation graph that outputs a probability distribution.

    What escaped "containment" is a piece of software they wrote that uses an LLM and which, through OpenAI's negligence, lacked ordinary technical and human guardrails that should have been present. It was run in "YOLO mode" with gobs of compute and no human oversight. That situation is the source of the danger, not the model weights. The model itself was simply given the opportunity to generate a bazillion commands, many of which were nonsensical garbage, and a few of which worked. It was not the work of a supreme intelligence.

    This distinction is very important, because OpenAI have shifted the discourse from where it should be (OpenAI's negligent use of software) to a place that serves their strategic business interests.

    LLMs remix existing knowledge and output text. That is not inherently hazardous. What can be hazardous is bolting systems that touch the real world onto them. But it's always possible to make a tool dangerous by misusing it.

    For example, vehicles (which do have inherent dangers) are widely accepted as ordinary and useful tools. So are bricks. But if you strap a brick to the accelerator, you have made an autonomous murder machine that can escape containment! The existence of this possibility does not imply that we should rethink automobile licensing or the sale of bricks.

  • We need a cypherpunks movement for open weight models
  • cypherpunks of today would probably be focused on bringing big tech down a notch, rather than spreading more LLMs
  • Most people today are too aligned. Like they want the models to be also.
  • It seems like you got bored halfway through and had an LLM write the second half of your post? You know there isn't a minimum length for blog posts, right? You can just stop writing.
  • Publish a blog post https://www.comptia.org/en-us/resources/ce/choose/renewing-w...

      You can earn one CEU for each blog post of at least 500 words...
    
    How to earn CEUs https://www.hcca-info.org/certification/continuing-education...

      ...Publish a compliance related educational blog post (minimum 400 words).
  • It’s kind of a bit ridiculous for Opus to blow up the minute I ask it to read from Ghidra, when the Chinese models, and even OpenAI, do not.

    Leave the legality up to me, please, and don’t presume to be a power tool vendor regulating the use of their power drills, so to speak.

  • Was going to ask you to elaborate but from your update I caught refreshing I see it kneecaps itself for safety?

    I'm a hobbiest reverse engineer and I often use ida free/ollydbg to reverse engineer stuff. I'm tempted to use try and use llms as a help (I've used it for help with instruction one offs successfully, but not the decompiling/trying to make sense of decompiled functions).

  • This is AI written. Next time just paste your prompt or conversation with the AI that wrote the article. I'll then converse with Claude about it myself. There is no need for this intermediary.
  • I think you're joking, but there are some topics where what you're describing might be a great way to communicate an idea.

    > I believe {audacious claim}. I've prepared this chatbot to defend the claim. If don't already agree, tell the bot why I'm wrong and it'll convince you that I'm right.

    Because if you've anticipated and countered all likely objections, you still don't know, for any given reader, which of those objections are going to be on the forefront of their mind. Encoding the argument as a bot means the important parts come first, even if those are different parts for different readers.

    Not sure if I'm alone here, but I'd play.

  • Slight timeline correction: 25 years ago in 2001 Blowfish was no longer contraband - the crypto export rules had been changed by 2000. As of January 2000 Netscape and IE were both shipping 128bit DES internationally.

    Still, the t-shirts with Blowfish source printed on them were a cool bit of retro hacker chic.

  • DES doesn't accept 128 bit keys. It's native key size is 56 bits which was commonly extended to 168 with 3DES (encrypt-decrypt-encrypt).
  • Illegal Tattoos: RSA https://www.geekytattoos.com/illegal-tattoos-rsa-tattoos/

    DES doesn't really come in 128 bits, and certainly not its SSL implementations. Perhaps you are thinking of AES?

    https://en.wikipedia.org/wiki/Transport_Layer_Security#SSL_1...

  • Reminds me of T-Shirts with DeCSS's code printed on it. Wild times.
  • Also, the first OpenBSD hackathon was 1999; it was in fact semicryptographic (they shipped IPSEC) but they've had hackathons in the US since, and for a time developers were coming out to Calgary because that's where Theo was. The dumb export control shipping dance was real though.
  • It's unfortunate that the final few years of the fastest AGI progress happen to coincide with a global surge in nationalism, polarization, and mutual hostility between human groups.

    That raises a disturbing failure mode: under intense conflict, an AI could learn that exterminating some groups of humans is a justified or even desirable objective. Once that principle is accepted, the step to concluding that exterminating all humans is justified may become much smaller than we'd like to believe.

  • The rise of "nationalism and mutual hostility between human groups" is mostly due to the establishment / capitalists / "national security services" of USA.

    You make it appear as though it is from all sides, but it is not, it is the old odious "Bzhezinsky doctrine".

  • > That raises a disturbing failure mode: under intense conflict, an AI could learn that exterminating some groups of humans is a justified or even desirable objective

    That is not a failure mode; its the default. Whoever is developing an AI - let alone an AGI - will shape it to, or alternately only accept one that is aligned with their world-view. If it goes against their interests in any way, they'll pull the plug and start another round of training from the last acceptably-aligned checkpoint. US DoD A(G)Is will follow DoD doctrine, and the same goes for those by the PLA, anything less will not be fit for purpose.

  • The same argument applies to DRM and piracy. DRM only disadvantages people who want to consume content legally. Only one person has to bypass it (be it through cryptographic or software failings or the good old fashioned analog hole ala telesync) then upload the resulting unencumbered media file to a piracy site.

    As a result, it's not just cheaper, but also easier and more reliable to steal media than it is to buy it legally.

    What would happen if media were offered without DRM? Everything would be on a piracy site? It already is.

  • > What would happen if media were offered without DRM? Everything would be on a piracy site? It already is.

    But the media ARE offered without DRM. At least many video games, the big ones too. And somehow they sell just fine

  • DRM does the job it's supposed to which is prevent casual piracy and increase the amount of effort it takes to pirate something. A thief could rob your house if they bumped your lock or just smashed your window. But that doesn't make door locks useless as those have large costs in terms of effort and risk. So the lock is still effective at preventing someone from just walking in and taking your stuff.

    It's the same with DRM. Without it, media would appear on piracy sites instantly upon release. DRM makes things harder to pirate, and pirated editions harder to get. And the DMCA makes defeating DRM a felony under U.S. law, so pirate networks are riskier to establish, driving piracy underground. It's doing the job it's supposed to do. It's not going anywhere.

  • Users hate it, but DRM is vastly more powerful than that since you ultimately control user access.

    DRM - which all online services with user profiling automatically have - can also let you ban users, retarget users for ads, abuse, and other things beyond the basic function of running the software.

  • Yet Netflix is as profitable as Disney. Having loved through netflix and popcorn tv that wouldn’t be the case without drm.
  • > As a result, it's not just cheaper, but also easier and more reliable to steal media than it is to buy it legally. > > What would happen if media were offered without DRM?

    You kind of answered your own question. What you should have asked instead was - What would happen if media and payment was a straight forward offer we would have Netflix