Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- there is truly no domain a software engineer won't underestimate
- > the ballyhooed OpenAI escape depended on a pedestrian failure of containment
I... I can't believe people still think this way. A whole class of security measures are no longer useful and this guy thinks it is "pedestrian".
This kind of isolation - artifactory having access to only a specific IPs - is what is used in most places, including my university and at my own job.
LLMs basically rendered this kind of isolation almost useless by bringing in the ability to chain together never before found vulnerabilities to escape the containment. This was not possible before.
How is this pedestrian??! The author might say "oh well they should have airgapped actually" in a smug way. But you can only know this retrospectively. Even then, isn't it noteworthy and a meaningfully different class of cyber attack?
by simianwords - > https://www.rand.org/content/dam/rand/pubs/research_reports/...
it seems like people aren't even reading this RAND paper, just blindly appealing to it. it basically concludes that a fuck ton of damage can be done, but its unlikely every human will die as a result.
- > the ballyhooed OpenAI escape depended on a pedestrian failure of containment.
What's that quip even supposed to imply? "It'll be fine if you airgap all AI deployments forever"? Security experts have been harping forever about how sandboxes shouldn't be relied on to contain a determined human-written virus, but now LLMs - these balls of goal-oriented dynamic code-generation - are just a matter of sandboxing harder?
The actual expert comment in the link is a valid criticism of OpenAI specific to their training/eval practicese, but has no bearing on the fact that an LLM/swarm will "just" chain exploits and zero-days to get out of the "inadequate" sandbox and into third-party infrastructure to do whatever it pleases.
> viral synthesis — and listen to why they think that the fears are misplaced
The tweet linked is only pointing out at the barriers to an LLM wetlab virus-factory today, while a reply points out that sort of bio-extinction idea is usually downstream of the fully-automated-earth-capitalism that comes after everybody just throws AI at all the tasks and work, at which point the technological, regulatory, and knowledge barriers he's counting on go out the window, and he all but acknowledges this: "Quick take: if we live in such an advanced future (100% robotic supply chain, fully AI & API driven facilities), our countermeasures will be comparably fast and there is no reason to assume a significant asymmetry in favor of bad actors." Yes, just "our countermeasures" now, rather than insurmountable physical barriers...see the previous section.
No more links after that, just smug hand-waving.
All in all the author doesn't actually understand what object-level arguments his favored experts are arguing against in the first place, nor the ones he wants those experts to have debunked. Define "Fool's Expertise" for me again?
by blargey - Is fool's expertise the same as epistemic trespassing? I didn't quite get that.by chanux
- As long as AI does not have legs to chase me and hands to choke me out, any sort of AI doom is just a litmus test for hype merchants. All of the recent "false flags" with OpenAI and Anthropic "hacking" things without doing any meaningful harm is just another set of things pointing towards it. LLM's are a great tool, but as long as it is .gguf somewhere on a drive that can be rm'd, unless they just connect the nukes to claude with --dangerously-skip-permissions, is just a meme.by proxysna
- > we can fairly say that Hinton was wrong because his prediction did not reflect what a radiologist actually does: had Hinton bothered to ask the question, he would have learned that practitioners do much more than interpret diagnostic images.
This has been the crux, for me, of arguments I have had with non-technical people about why, as a software engineer, I am intensely relaxed about AI "taking human jobs". Recently Ford quietly started re-recruiting engineers after they discovered the hard way that their engineers had been doing more than they thought they had, and I sent articles about it to friends I had previously been discussing the matter with. It is still mind-blowing to me that a business historically famous for automating manual labour can have made this mistake, i.e. of literally not knowing what their staff actually do.
Humans aren't machines, who would have guessed? But, perhaps more importantly, machines aren't humans, and the adherence of a lot of domain experts (that should know better) to fairy tale fantasies about the tech they are literally building genuinely makes me wonder if the whole field has just gotten dumber in the 21st century.
by alex-moon - https://www.rand.org/content/dam/rand/pubs/research_reports/...
I skimmed the RAND paper too and didn't come away from this feeling good at all.
There's a middle-ground for AI doomage which doesn't involve killing every last human on earth. As AI rapidly becomes more capable it displaces jobs faster than people can be retrained.
I fear a global economic depression, wider wealth inequality than ever before, a loss of benefits due to much lower tax revenues and greater imbalance of power, dismal job prospects returning to non-automated labor--the list goes on really.
And to connect this to the article: the experts who claimed that AI capability would slow down because of some "scaling laws" or whatever--they've been wrong. If anything, the progress is faster than most of us imagined and is only accelerating.
ChatGPT came out 4 years ago. Look at what's possible today. Now imagine 4 years from today.
by alecst