Comment Re:So they have a "permanent revenue machine" now (Score 1) 13
That is a completely insane claim. For local models on your hardware you obviously can already have that.
That is a completely insane claim. For local models on your hardware you obviously can already have that.
Well, "land of the free, greedy and stupid" is probably a factor. This can be done right. It is not hard to do it right. But a lot if IT is still deep in amateur hour and the price for that is getting higher and higher.
It really does not matter. Either you do it right or you do not do it at all. IT security is part of that. Nobody sane talks about a physically separate network. (Some incompetents do, but let's just ignore them.) Using the Internet as pure transport is fine. If you have a VPN in there. Using a phone connection, same thing. If you cannot afford to do that and do it right, stop expecting you can do long distance control connections. Half-assing it is NOT a solution.
Looks like you have a mis-moderator on your tail there....
Anything larger like transformers has long delivery times. Seems the felon is getting desperate.
Makes sense for them. Does not make any sense for users.
Indeed. But I think the research is not pointing out the problem, it is exploring some aspects of it.
LLMs do not have a concept of "trust" or "verification" or "instructions vs. data". Hence any model that downloads content from the web and then looks at it needs to be regarded as fundamentally insecure. I do not think that filters can fix this. LLMs are far too versatile in what they can take as instructions.
Yes. The non-separated channels are pretty deadly to security. I do not think that this can be fixed by training. You would need to have near 100% effectiveness and training just cannot give you that.
At this time, I think LLM-based agents cannot be secure against data-based attacks. Something else or more is needed.
The executive order gives the Energy Secretary the power to designate certain organizations as potential risks, with a primary focus on Chinese suppliers. This doesn't outright ban "all foreign suppliers" of electrical grid equipment, the biggest suppliers of which are ABB and SIemens, both European and they are not banned. Organizations like ABB and Siemens will have to document their subcontractor exposure to Chinese suppliers, and certain suppliers in that supply chain may be banned forcing them to find an alternative to that component, but that's a very different scenario than "All foreign electrical grid equipment is banned!" as this headline and summary portray.
And the order is in response, as the summary accurately says, to Iranian sourced subcomponents in the water infrastructure that led to a cyber-attack. Ultimately this is about making sure our grid is not exposed to cyber secuirty risks. I'm all for Trump outrage, but let's direct it to the stuff he actually deserves; this issue is the kind of thing that if it came up during the Obama administration I think it would be implemented exactly the same way and with no news about it.
I don't think these things can be trusted in any way for a long time.
And that is exactly why we need regulation and liability, preferably liability with a personal component. When anybody is doing critical infrastructure without IT security expertise involved and they find themselves fined a significant part of their salary, things will change.
And stop the utterly idiotic "the operators cannot afford it" claim. Can they afford to get hacked and their infrastructure taken over and damaged? No? Then they can afford IT Security. It is not even hard or expensive. We are talking a day of consulting and taking some template known-secure architecture with VPN links and the like. But you have to do it. Ignoring the problem or claiming you cannot do it will only do one thing: It will make your problem much worse and much more expensive.
This is really in no way a surprise. All that "trash" level security infrastructure has not been attacked before because nobody tried.
I can factor large prime numbers right now. Just give me one.
LLMs cannot do AGI. No chance, ever. LLMs are just somewhat capable search engines in an unified sea of data that was harder to search before because it was not-unified and unstructured. There is a pretty impressive NLP interface on top and since it talks many dumb people think it is intelligent. That even happened with Eliza back when and has nothing to do with the tech actually being good. But LLMs can only do statistics. They cannot do insight, and what gets misnamed "reasoning" in the LLM space is actually iterating a faulty and lossy process to make it more faulty and more lossy but allows it to dig a tiny bit deeper.
As to other sources for AGI, we are still at the "we do not know whether it is even possible" stage. No chance for anything real in the next few decades and maybe never.
Memory fault -- core...uh...um...core... Oh dammit, I forget!