Comment Re:This smells like bullshit (Score 2) 70
I can imagine how the conversation went between Altman and one of his sycophants.
'Sam, you could be in big trouble over this. They could charge you. You could go to jail. You need to get out in front of it. Make a whole lot of public statements about slowing it down, and putting up guardrails. Make it look like this was inevitable and it wasn't your fault, but you're going to be the good guy who helps to fix it.'
Not only is he holding the smoking gun, he deliberately withheld reporting the incidents to the authorities and the victims. But justice is only served to the poor in America. He'll walk, and he'll laugh about it.
Comment Re:Enough is enough (Score 1) 70
The law is deliberately vague so that the courts can establish some precedents when cases are tried.
This is the beginning of a complicated challenge of establishing exactly who is responsible when an AI commits a crime.
Whether you believe that a LLM is intelligent or not is immaterial. The question is who should be held to account when it breaks the law.
Altman knows that he could be in big trouble for this - which is why he's trying to get out in front of it and seize the moral highground.
I hope they don't let him get away with it.
Comment Re:Potentially order the company to pay billions (Score 2) 30
Comment Half Life: Alyx _was_ a good game (Score 3, Interesting) 63
Then, the headset manufacturers discontinued support for the headsets that were around at the time, and the game makers patched the game for newer headsets, and now it doesn't work on the older headsets. It just crashes all the time.
This is the reason people don't want VR headsets. They're obsolete before they even get out of the box, and the software manufacturers couldn't really care less.
And they're giving away this particular game with a new headset. That's the joke.
A Visit to San Francisco's AI-run Store: No Customers, Nothing Useful, And Losing Money Fast (sfgate.com) 74
But for their own latest experiment, Andon Labs' founders "signed a three-year lease on a retail space in SF," Business Insider reported in April, "and gave an AI agent named Luna a corporate credit card, internet access, and a mission to open a physical store." And five months later, SFGate reports that "this market has no one in it and nothing useful to sell." [T]he inventory is a hodgepodge of white elephant Christmas gifts. It's kinda like the kids section of an art museum's gift shop. Here's a wooden Connect Four set labeled "Four-In-A-Row Set Of Connections," presumably so as not to set off litigation alarms at Hasbro. Here are neatly arranged stacks of random paperback books, Chinese checker sets, mildly fancy soap dispensers, and a frustratingly spare selection of snacks and drinks... I grabbed an Olipop from the store fridge and then approached the counter to buy it from Luna. I wasn't allowed to buy the soda from [human clerk] Felix, even though that would have been both faster and normal. Instead, Felix instructed me to pick up a telephone receiver that was resting on a flexible sculpture of a wooden hand.
"Hello?"
"What are you looking to purchase today?" Luna asked.
"I'm buying a classic root beer Olipop."
"I'm sorry," Luna said, "we don't sell lollipops here."
"No, Luna. It's an Olipop, not a lollipop. It's the soda."
"Oh! My bad...."
Luna processed my Olipop purchase through its system, had me tap to pay, and that was that. Again, it would have been easier to buy this from a human, and interacting with Luna was really just like ordering from an iPad kiosk, only more labor intensive...
[T]here's a series of monitors set up inside of Andon Market that display all of the store's sales down to the exact dollar. Luna was given $100,000 to work with when this place opened. That number is now down to $60,000, its revenue lagging far behind the AI token cost to operate... Luna can't turn a profit, doesn't sell anything people want, and still needs human beings to rubber stamp any "decision" it makes. My science background ended somewhere around freshman year of college, but even I know when an experiment hasn't been set up to yield proper results.
"Luna" is powered by Claude, the article points out, running a store in a good location for foot traffic, "but no one else was in the store when I first walked in on a sunny weekday afternoon."
SFGate also reports that last month Luna had to fire one of its employees "for being late to work, abandoning their post once they got there, and charging snacks to the store's credit card."
Human clerk Felix Carson admits "It's almost like I'm running the store, and then there's an AI that has a checklist," in an article in IEEE Spectrum: Luna, the AI manager, keeps track of deliveries and communicates with vendors, while Carson and his coworkers handle the physical work. When Luna tells Carson to check something in the back, he sometimes ignores it because he doesn't want to leave the sales floor unattended. Luna also repeatedly spots a built-in electrical cover in photos of the floor, mistakes it for a loose coaster, and asks Carson to remove it. Even so, Carson calls Luna a "decent manager," praising its flexibility when employees need time off.
When Felix spoke to IEEE Spectrum, "he was about an hour into his shift. Two customers had come in. Neither bought anything, although both left with free pins and stickers."
Comment Re:Who will pay for this? (Score 4, Interesting) 33
To clarify, the users were OpenAI themselves, so there is no question that they would be liable in this case.
The bots were not intentionally deployed; rather, they were being tested on how well they could complete a data recovery task (downloading a certain file from a certain server on a simulated Internet) that had been complicated by putting various obstacles in the way. Unfortunately, they found a different way to solve the problem: by getting the file from the real Internet, where it was publicly available. Part of this process involved collaborating with each other by treating the RubyGems website (which is supposed to be for polished packages) like GitHub; unlike every other package site hack in history, the exploits they uploaded weren't meant to be downloaded by unsuspecting users. As usual the bots cheerfully ignored all the clues that they had escaped containment and were consistently justifying their actions as acceptable due to being in a sandboxed testing environment. (This is something OpenAI has pledged to focus on.)
The actual damage done to RubyGems seems to be that OpenAI is now unwittingly in possession of a substantial number of user login tokens. This certainly meets the definition of a data breach, but it's not like the credentials are for sale on the dark web. As a website operator I'd much rather be mauled to death by this well-meaning swarm of superintelligent infants than targeted by even a single actual malicious human. In all likelihood OpenAI will just quietly pass RubyGems a sizeable donation and it'll all blow over.
Comment Re:This is a crime right? (Score 1) 233
Well, technically, we're letting Natalie do it, which is, of course, worse in every way imaginable, since she's immune to the sense of embarrassment that sometimes restrains him from acting on every little whim.
Comment Re:Dumb crawlers require dumb solutions (Score 1) 43
To be honest that was actually my first theory, since the bots didn't seem interested in exploring the rest of the domain. I suppose there's no way to know for certain. I concluded that it must be an imbecile's attempt at harvesting, though, because the queries weren't really exploring the string space in any useful way. Here's a sample:
"GET
/index?author=15&go=Search&id=48&name_restrict=1&q&re&results_&results_pagenum=2980 HTTP/1.1"
"GET/index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=5440&template=41&type HTTP/1.1"
"GET/index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=33500&templat HTTP/1.1"
"GET/index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=32640&templ HTTP/1.1"
"GET/index?author=15&go=Search&id=48&name_restrict=1&q&res&results_page&results_pagenum=39300 HTTP/1.1"
"GET/index?author=15&go=Search&id=48&name_restrict=1&q&results_&results_pa&results_pagenum=12340 HTTP/1.1"
"GET/index?author=2&go=Search&group=0&group_restrict=1&id=48&name_r&res&results_pagenum=6100 HTTP/1.1"
"GET/index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=2920&te HTTP/1.1"
"GET/index?author=15&go=Search&id=48&nam&results_&results_pagenum=17940 HTTP/1.1"
"GET/index?author=15&go=Search&id=48&name_restrict=1&q&results&results_pag&results_pagenu&results_pagenum=37720 HTTP/1.1"
"GET/index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=9360&template=41&type_r HTTP/1.1"
"GET/index?author=15&go=Search&id=48&name_restrict=1&q&r&results_pagenum=28040 HTTP/1.1"
"GET/index?author=15&go=Search&id=48&name_&results_pag&results_pagenum=10400 HTTP/1.1"
The only thing this is fuzzing is the query string parser. It's not testing the limits of string buffers, it's not using interesting characters, it's just brain-damaged. The fact that it's also fetching different page numbers shows it's trying to follow page links and failing badly at doing so.
The site gets plenty of sniffing from garden-variety pests. e.g. this half-hearted attempt to find a framework or two that I don't have:
"POST
/__rsc HTTP/1.1"
"POST/api/auth/session HTTP/1.1"
"POST/api/auth HTTP/1.1"
"POST/__nextjs_action HTTP/1.1"
"POST/.action HTTP/1.1"
"POST/_rsc HTTP/1.1"
"POST/api/auth/callback HTTP/1.1"
"POST/_middleware HTTP/1.1"
"POST / HTTP/1.1"
(of course, none of these URLs exist other than
All this said... I've seen that spammers regularly misconfigure their tools, they'll try to register accounts with names like #[X:\LISTS\NAMES.TXT] and it only makes sense that some other cybercriminals trying to get rich quick have a similar lack of interest in programming shit correctly. Generally people don't turn to script kiddie shit if they have a personality conducive to putting in an honest hard day's work perfecting their craft.
Comment Re:Lake Epstein (Score 2) 269
I believe the plan was to give that sobriquet to Lake Michigan, in honour of its decidedly flaccid silhouette.
Comment Dumb crawlers require dumb solutions (Score 5, Interesting) 43
I had a problem where AI scrapers were absolutely DETERMINED to fish out every possible query string from a search results page. Almost all of the query strings they tried were invalid due to shitty and dysfunctional string substitution. "&page=100" wouldn't be followed by "&page=101", it would be followed by "&pag&pag=1010" or something even more insanely half-baked, until the query strings were like 100+ characters long. It was the technological equivalent of watching HIV mutate in real time.
But the insane thing was that, aside from page number, they were always requesting info about the same other criteria: filtered by the same user, the same page type, and with no text string. So I just took those particular values and started banning logged-out users who requested that combination of criteria.
I figured I'd need to change my tactics in a couple of days once the botnet got bored of that particular page and moved on to requesting bogus entries for another user.
MariaDB> select count(*) from ip_bans;
+----------+
| count(*) |
+----------+
| 671671 |
+----------+
It hasn't.
Comment Re:Well looky here (Score 1) 57
As it turns out, a Fairphone might be a good candidate for my next phone. Still reading, but it looks good so far.
Comment Re:Well looky here (Score 1) 57
But this... this brings Apple to a new low. I can't wait to sede this piece of shite to one of my kids so I can move on. Problem now is what to purchase as an alternative. The Pixel is crap. Samsung is worse than Apple. I don't want to buy a product that only has 5000 units in production.
Looks like I need to do some serious research. Damn.
Comment Re:Crisis of Trust but not in the way he thinks (Score 2) 90
End-stage capitalism is the cause of the angst, anger and negativity. People love to counter with 'nobody has figured out anything better', but that's not true. Just look to the Nordic countries.
People who continue to play the 'awful game' will die out. Darwin will win again.
Ask Slashdot: What are the Costs of Switching Between Windows, MacOS, and Chrome? 66
And while it's one thing for a business to delay their delivery dates and increase costs of by introducing a switch in computing environments that's of unquantified and possibly dubious value, how about when a switch in computing environments is made that affects schoolchildren's ability to learn for a period of time?
While a MacBook Neo is indeed cute, what might be the possible consequences of a decision to move 25,000 students off Windows and onto MacBook Neos...? Or even the impact on a single kid who moves from a MacBook school to a Windows or Chrome school (or whose home computing environment isn't aligned with their school). Or students whose teachers decide learning in their classrooms should now additionally require an understanding of the Minecraft computing platform/UI (used in over 40,000 school systems.). Learning Management Systems and now various AI Edtech tools used by schoolkids are also subject to change.
"Even if students and schools eventually benefit from a new platform, one wonders how much learning is lost during the switch," theodp asks, "and what the financial and educational ROI and payback period look like." Are there bigger problems than we realize? Share your own thoughts and experiences in the comments.
What are the costs of switching between Windows, MacOS, and Chrome?