Forgot your password?
typodupeerror

Comment Re: Or build better sites (Score 2) 50

This isn't true. It is not a given that an online system has exposed viable vulnerabilities. The more complex the surface exposed, the harder it gets to be confident, but ultimately a secure system is possible even online.

Don't feed into the fiction that a smart enough AI could get into any system it wanted if adequately hardened.

Comment Re:Too stupid (Score 1) 49

LLM input tends to, above all else, end up *super* verbose, especially when wielded by people that don't actually understand what they are trying to get done.

So while that assessment may stand, the challenge is *volume*. If you see a large LLM contribution, you know it's going to be a slog, and your feedback is likely to be a telephone game between you, the human curator of the work, and the LLM they are actually interacting with, with the human in the middle adding nothing but confusion to the whole thing. If they just stated what they wanted plainly, then the project could have, at their option, used LLM even better than the submittor could have, if it would help.

You have issues like: https://github.com/rhinstaller... Where a detailed rationale is provided, and from a human one would have assumed they wouldn't have had such a concrete analysis unless they had a point, then it turns out that it was LLM hallucinated guesswork with no bearing whatsoever on the reported problem. I've had a few like that where they proposed broken nonsense because the LLM made a credible sounding guess, where their change didn't actually fix the problem, but instead did something pointless or even worse, just swallowed the error message.

Comment Re:Waste of a keyboard key... (Score 2) 62

Thing was keyboards were *already* ditching the context button. My kid's laptop lost the right Ctrl key, and my kid happened to get used to using the right ctrl key to do shortcuts so it was very jarring when that became the copilot key and had to switch to the other side of the keyboard. Especially since accidentally hitting it was so intrusive.

Comment Re:Or build better sites (Score 2) 50

Thing is that when these sites come up against sufficiently conventionally hardened sites, they already don't really get anywhere.

Problem is just *so* many sites especially during prime hype recklessly move forward without appropriate hardening.

It is sort of like how in the late 90s we had the trope of the hacker kid who could get into anything he felt like if he just wanted to, and nothing could stop them, just slow them down. Brought on by the very real low hanging fruit that the broader public would have assumed to be hard to break into, but were lax in practice. We see the same thing with LLMs, sites that most would *reasonably* assume to be run by smart folks that should protect themselves actually being pretty shoddy in security.

Comment Waste of a keyboard key... (Score 4, Informative) 62

Lots of keyboards ditched more useful keys to fit a copilot key, and then on top of that it's generally awkward to remap back to useful (commonly they replace a modifier key, and mapping some key to a modifier key is usually difficult). Even in KDE trying to make a shortcut out of it doesn't work because it doesn't recognize XF86Assistant,

Comment Re:Wat (Score 3, Interesting) 46

Well, to me it's funny to hitch this finding to post quantum as it is a totally orthogonal concern.

Along with saying RSA is *totally* useless because a rather niche application of it has an evident weakness, that is not claimed to be more generally applicable.

They may have an interesting and important finding, but are stirring up a bigger mess than is warranted by implying a broader impact to anything using RSA.

If you weren't considering migration from RSA an urgent issue before, this changes nothing.

Comment Overblown... (Score 1) 46

The new attack will further increase the urgency of completely moving away from the cryptosystem.

Depends on what they mean by "the" cryptosystem. If they mean use of RSA in general, then not really, it narrowly only applies to a specific application of RSA allowing an authority to sign something without actually seeing the something, which almost never is done. It sounds like it does not speak to RSA more broadly.

Comment Re:I kinda agree with the lock, Ill explain (Score 2) 116

Feel like that's not what is being said at all. It's saying in a world where they are willing to lie about capacity and have the technical ability to do so, they *certainly* would also have the ability to defeat this mechanism to lock out changing the RAM chips.

It just seems on the face of it a bit silly when the reporting is 'they are blocking supply chain BS by blocking ram modules' but at the same time 'but don't worry, you can easily undo the lockout'.

Comment Re:Good new for bitcoin? (Score 1) 122

Have to keep in mind that to a lot of folks it's almost 'bitcoin === cryptocurrency', where anything cryptocurrency must be bitcoin related. Not just this field, but investing in general.

Companies have gotten big boosts just by having a similar symbol to something in the news that they had nothing to do with.

Comment Re:Bullshit Lawsuit (Score 1) 113

I want to agree with you, and appreciate the spin of a 'safety standards committe'.

However, they could make the argument that an agreement to 'slow down' at current prices, means an agreement to keep prices high rather than someone developing an advancement to make it cheaper.

That said, it's completely counter to the trend where they have been making it more and more expensive, and doesn't seem to be interest in more competitive pricing anyway.

Comment Re:They are scared, billions gone, no chance for R (Score 3, Insightful) 113

We won't have 'our' side under any better control than the other side. Essentially kids playing with landmines, triggering all sorts of unexpected mess while playing with the technology.

I don't even know if you want to consider the likely ones calling the shots 'our' side. For example, a quote from Larry Ellison on AI augmented surveillance:
“Citizens will be on their best behavior, because we’re constantly recording and reporting everything that is going on."

Note the pronoun choices, *their* best behavior (not *our* best behavior) because *we're* constantly recording. Clearly his natural go to language has already set up an 'us versus them' scenario that puts the average citizen on the 'other side' compared to wherever Larry is sitting.

Comment Re:What should be a straightforward engineering... (Score 1) 113

What's worse is that it came up at a time when everything else is hitting economic headwinds. It has become the one shaky pillar vaguely holding up the entire stock market. Hence Trump's panic over the only saving grace of his remaining decent economic indicator being put at risk.

Comment Re:Standing? (Score 1) 113

The theory seems to be about the coordination. You can't sue that McDonald's refused to use some better ingredient, but if all the burger joints jointly announced they were all working together to refrain from using that ingredient, then you might have something.

This is precisely why they needed the governmental regulation they asked for, when they 'self-regulate', it can come off as anti-competitive.

Of course, plenty of examples of industries collaborating, they just generally need some spin that has it as a collaboration to improve the industry in some way. So here the pitch could be that they are collaborating to improve safety, and the 'slowing down' is a natural consequence of the improved safety.

Comment Re: Move to the beat. (Score 1) 48

Exactly. Most of us can recall an era where script kiddies had similar unreasonable success even if they had no actual skill or thinking behind the attacks. Just canned toolkits designed around known vulnerabilities, common password databases, understanding of common, bad security practices, and bundled up in easy to use harnesses.

So whether it not an agent can actually "think" or is just putting together a potentially workable narrative of how hacks can happen and running it against real world targets doesn't matter too much. If you wired up the script of Terminator to the real world and it somehow launched nukes, it wasn't that skynet was thinking, it was that the systems folded easily to a movie script. Either way the distinction would hardly matter.

To the extent lack of thought may matter, compromising security is a use case that heavily favors AI systems that repeatedly "get it wrong", as it can have nearly limitless tries to get it right and even if it utterly fails, no one will really notice or write about it. It only takes a few successes, even if rare, to be pretty critical.

Comment Re:Which is it? (Score 1) 128

Well, one scenario is letting the hype get ahead of the capabilities, and do the 'AI store' experiment, but for real with responsibility for something actually important.

Another is that it is far easier to just screw things up than it is to make things work. I may not have it in me to make a house of cards, yet I can trivially even accidentally destroy a house of cards someone else built without a whiff of understanding.

The assessment of the capabilities based on bottom line certainly is subjective, which is precisely why Jensen Huang is so aggressively gung-ho about we must do everything we possibly can to spend more money on nvidia stuff. The motivation for Anthrophic seems either they have legitimate concerns or are looking to rationalize a plateau after promising the world. It certainly doesn't serve their bottom line to slow down otherwise.

Slashdot Top Deals

Slowly and surely the unix crept up on the Nintendo user ...

Working...