Forgot your password?
typodupeerror

Comment Re:Unbalancing the arms race? (Score 1) 65

That was my first thought and I'm glad the story mentioned it. But I'm concerned that AI may tilt the table in favour of bad actors. Mightn't it lower the bar when it comes to expertise at finding and exploiting vulnerabilities, while simultaneously increasing the burden on already over-worked programmers?

In other words, does AI help black-hat hacking organizations more than it helps good-guy programmers and maintainers? I'm thinking of how a hammer is more easily used to destroy than to create, but IANAP so I don't have a good sense of this.

Bouncing code off of AI is being baked into software lifecycles and will result in fewer bugs across the board. For open source you will have more people armed with AI finding even more bugs (while annoying the shit out of maintainers). The interesting thing about these models you can run them over and over and over again and sometimes different bugs fall out so the more AI eyeballs the better. Still I expect ultimately the computational cost of finding any remaining bugs to work against attackers.

On the other side of the ledger attackers obviously also have the same AI tools for bug discovery and script kiddies get to use AI to help them automate production of exploit code.

Personally I wouldn't want to be at a three letter agency standing watch as my capabilities are eroded by AI. Zero day factories will probably end up running out of steam in a few months time as the bugs get fixed.

Comment Re:what kind of bugs (Score 3, Interesting) 65

How many are realisically actionable vulnerabilities. The statistics have indicated so far that AI isn't really finding many non-minor bugs.

Seems to be a bit of selection bias baked into what AI is being asked to do. Tried AI (GLM-5.3) on new code that has never been executed. Also ran it against code that has been in production use for many years.

The types of bugs tended to be in obscure features, buggy error paths, parsing / protocol pedantry, cut and paste errors especially in various lookup tables, algorithm accuracy, inconsistencies, poor and obscure concurrency bugs. Can't really expect it to have found anything too important as it would have tripped up code and runtime analyzers or angry customers because all of that would have already been discovered and dealt with.

In the new code it found a couple of show stoppers that would be immediately obvious the second anyone tried it in addition to some more obscure things.

While I've not yet seen it discover any magical exploits it did get us to reconsider some questionable security related decisions and make improvements. Unfortunately tends to focus mostly on nuts and bolts rather than higher level machinery.

Been trying to get LLMs to do bug hunting for years and it has never worked. The AI just never had the depth to understand enough of what is going on to say anything useful. They still output quite a bit of crap... some of it isn't the models fault... for example tend to feed it source files one at a time to keep from blowing through too much context. This requires the models to make all kinds of inferences about dependencies it has no real knowledge of... sometimes it doesn't make the right assumptions. Sometimes it says nonsensical things or doesn't seem to "see" its own context perfectly misreading the code and complaining about something that isn't real... still well worth the effort. Amazing this shit works at all.

Comment Re:I'm still wondering (Score 1) 224

if you scroll up, you will see that I replied "exactly" to your statement
I assume you will respond "exactly" to my statement

I have no idea what you are trying to say here. You seem to be ignoring the point I'm making outright by bringing up enrichment limits that expire under the agreement in 2030 and therefore logically cannot be used as an argument against Iranian acquisition of nukes after that point in time because they would be inapplicable.

Comment Re:So AI agents get a pass? (Score 1) 125

There is at present no such thing as a self driving car. There are only cars that automate some aspects of driving with human supervision or where autonomous operation is managed by humans and limited to designated areas. Humans are still responsible for driving including the automated taxi companies who are very much getting dinged for the transgressions of their vehicles.

Sure, if you want to be completely wrong you can make that claim. In reality Waymos are not under human supervision. They contact humans for support when their self-driving system disengages. That's a very different thing.

Perhaps you simply misread my statement. Waymo falls into the "or where autonomous operation is managed by humans and limited to designated areas" category. Otherwise I have no clue what you think is "completely wrong".

There is no single human responsible for Waymos and this has been an ongoing issue with law enforcement who have been unable to issue any tickets to cars without drivers. Where Waymo has been punished, it's been under specific provisions of specific laws created for self diving vehicles - which is exactly my point.

Waymo is responsible for Waymos. What you are doing is reading cherry picked press accounts of fleeting technical issues in certain jurisdictions that have already been mostly corrected and drawing generalizations from them that are frankly unmoored from reality.

No it's not. In virtually all jurisdictions traffic violations apply to the person driving the vehicle, and not the vehicle itself.

Waymo is driving the vehicle.. In a Tesla the driver is driving the vehicle regardless of whether the car is controlling the vehicle.

You don't need to take my word for it. Just look up how many traffic violations Waymo has committed and how many fines they have had to pay as a result.

I looked into this and at least Texas, Tennessee, Arizona, Georgia and California can all issue traffic violations to Waymo. I don't know about all jurisdictions.. got tired of looking.

So no certainly not "virtually all" and your previous statement "The laws as written currently do not cover a situation outside of direct human control and intent." is also incorrect.

Comment Re:What a disgusting show (Score 1) 63

And, incidentally, the EU already has pretty reasonable regulation. Copy that.

I like the parts of EU regulation preventing the application of AI for surveillance/scoring/judgement of people. Remaining bulk of it is pointless bureaucratic nonsense... not that it matters given EU is completely irrelevant in this space anyway.

Comment Re:So AI agents get a pass? (Score 1) 125

Yes they do, for the same reason that self driving cars get a pass when doing an illegal u-turn.

There is at present no such thing as a self driving car. There are only cars that automate some aspects of driving with human supervision or where autonomous operation is managed by humans and limited to designated areas. Humans are still responsible for driving including the automated taxi companies who are very much getting dinged for the transgressions of their vehicles.

The laws as written currently do not cover a situation outside of direct human control and intent.

This is a huge overgeneralization. There are a whole lot of laws in a whole lot of jurisdictions and not a single level 5 self driving car on the face of the planet.

Comment Re:So AI agents get a pass? (Score 1) 125

If a person or persons tried doing this and got caught, they'd be in jail, but - so far - AI gets a pass from this Administration.

People are liable for their actions and their negligence. There is no reason for anyone to get a pass. AI changes nothing.

Noting that Sam Altman and OpenAI are quoted as being in favor of AI controls...

OpenAI is dead without getting the government to outlaw AI not controlled by large corporations.

Comment Re:Loss of contact with reality (Score 2) 258

The fault lies with you coming to a tech site with no tech background.
What is mislabeled as AI today was in fact named "Expert systems" back in the 60s,

Expert systems are basically just overgrown decision trees. They have no relationship to present day transformer architecture.

Comment Re:I'm still wondering (Score 1) 224

They cannot become a nuclear weapons state at 3.67% enrichment, with international inspectors verifying compliance.

Earlier you responded "exactly" to my statement which included the fact enrichment caps are time limited under JCPOA to 2030. I presume the JCPOA would have been effective at enforcing agreed upon constraints and Iran would not violate it.

Again..
My personal belief after hearing a public statement made by someone on the Iranian side of the JCPOA they were always going for a nuke and JCPOA was seen as a vehicle to that end. It provided the Iranians with sanctions relief giving them money, time and space to pursue all of the necessary industrial process and delivery system productions to enable the regime to become a nuclear weapon state when ready to do so.

Not sure who you think is the horse's mouth, but it is not possible, period,

That would be this guy:
https://en.wikipedia.org/wiki/...

Comment Re:They are scared, billions gone, no chance for R (Score 1) 113

The worries are coming from every level within the companies, from junior developers to safety officers to the C-suite and board.

The worries are coming not just from within the companies, but also from people who left the companies. Including a huge number who left specifically to whistleblow about how worried they were that the companies were risking safety.

Also, most of the people at these companies were already worried about the topic even before they joined - again, at all levels.

What else is new? All of us have been hearing this for north of three years now (more generally decades). Distinctly remember around the ChatGPT 4 release in 2023. There was even a conspiracy making rounds one of the GPT4 era whistleblowers had been assassinated some time later.

When we replay the sensational garbage with what is now considered by everyone as a toy crap model people will rightfully laugh in your face.... but but but today's models are different and not like yesterdays models and so you should really be afraid this time for real... This same grift has been running continuously for the last three years over and over and over again.

There is no credibility left and no reason to give a shit about evidence free opinions of those deliberately waging campaigns of emotional manipulation of the public in the pursuit of simple profit.

We very much don't have this under control. Current models are very much Paperclip Optimizers in waiting.

And recursive self improvement, which is what AI labs are increasingly turning towards, means letting these Paperclip Optimizers develop their next generations.

Wait I thought they were slowing down? Are they slowing down or is everything going to plaid now because RSI? I'm so confused. Perhaps only the American firms after having all agreed to "slow down" know about RSI... the rest of the world doesn't know about the one weird trick?

For a while, there was a fair bit of hope that with constitutional AI, that we could tame this. The recent slew of models hacking into other servers, hacking into the AI companies themselves to try to delete records of their misdeeds, developing their own messageboards and scheming about how to avoid being monitored, and on and on (along with research showing how good models have gotten at hiding their thoughts from us) has shattered the illusion that we have this under control. We very much don't have this under control.

In control of what exactly? They asked the model to hack and it hacked. I hear these stories of people giving agents Internet access and letting them on production systems and shit and it goes and blows up their entire operation... I'm just bewildered and puzzled why anyone would ever even think about doing that in the first place. If the answer to "would you let a crazy person" is no... then sure as shit had better be the same of AI. The very notion of control of "AI" is silly and meaningless.

Nobody should be happy about this. Everybody should be concerned about this - even if you think, "we'll get it under control", you should still very much want to see evidence that everyone is making progress toward getting it under control.

I'm more concerned with the greed and power seeking of those running the American AI firms than I am of inherent risks of technology. Any actual danger from AI is baked into the enabling knowledge and industrial base. It is irrelevant how responsible, well-intentioned or careful any one person or organization is. This notion if only you try really hard and be extra super careful then you can "control" it misses the point entirely.

If the 10%ers keep the hysteria going with the we're all doomed in 4 years time BS I suspect corporations are going to start being torched by the angry mobs they created in earnest. Can almost hear the chants now.... "Clippy will not replace us"

Comment Re:So we all know they are lying (Score 1) 283

It's just a suggestion that the pot not call the kettle black.

The Iranian government may indeed lie. I'm not particularly inclined to believe them. But Trump lies so frequently and so unashamedly, that I'm inclined to treat anything the US goverment says with suspicion, even if it sounds plausible - because of Trump's reputation for being a fibber. This is not a feeling I have about America in general - just about the current administration.

I'm sooo confused. Is Shaitan part of the current administration? Who is the pot here?

Before you said " this is not a good period in history for Americans to criticise the administrations of other nations for excessive lying" yet now you say "This is not a feeling I have about America in general - just about the current administration."

Maybe what was left of my mind has been completed rotted out by AI... I have no idea how to parse your words.

Comment Re:LIke attracts like (Score 1) 283

Ok but we're in 3 major wars and Trump only forced us into 1 of them.

We are? What are the other two?

Please tell us what you think about Biden supporting the Ukraine while we armed and funded their attacks that killed Russian children? Is Biden also a socialpath?

I think Jake Sullivan gave Biden shit advice. Biden should have done way more providing military assistance to Ukraine to defend itself from Russian aggression, war crimes and genocide.

https://en.wikipedia.org/wiki/...

As for Trump's failure to support Ukraine it doesn't take a rocket scientist to understand why he keeps sending Kushner and Witkoff to Russia. Even his sons are smart enough to figure it out...

Don Jr
"Russians make up a pretty disproportionate cross-section of a lot of our assets"

Eric Trump
"We have all the funding we need out of Russia"

All that matters is what's in it for them.

Comment Re:Hegseth Disbanded the Civilian Protection COE (Score 1) 283

According https://militaryspend.org/iran... there are between 9,044 and 18,371 civilian casualties in Iran due to US air strikes. So yes, preventing collateral damage of civilians is not a priority at Pete Hegseth's "Department of War".

So much for reading comprehension. Your figures are under the heading:

"Combined confirmed and estimated deaths across US (18-23), Iranian military (1,800-7,650), Iranian and Israeli civilians, Lebanese civilians, Hezbollah fighters, and Gulf-state casualties. "

If this were the case where are the receipts? Trump TACOs out of most everything. After softening up the regimes forces and power projection capability Trump has been mostly focused on making stupid pointless deals and the far more fruitful campaign of economic dissolution of the regime and its terror proxies. Seems to be directly at odds with your violence premise.

In my opinion, Donald Trump, Pete Hegseth and their many acolytes believe that violence is how you win human conflict, and the side that is more violent will win. Military officers who do not share his world view are suspect, possibly woke, and have to be purged. In his word view all targets are good military targets, even civilians, if their deaths result in the desired outcome, regime change in Iran.

My violence premise is based on the fact that Trump has ordered military strikes on seven different countries during his second term so far.

Are these 7 different countries part of Iran or are you changing the subject?

Slashdot Top Deals

Real Programmers don't eat quiche. They eat Twinkies and Szechwan food.

Working...