Comment Re:FBI should be visiting. (Score 1) 35
You do not put the AI in jail. You put the ones in jail that did run it in a criminally negligent way. Or you find the whole thing was actually intended and planned. I am not ruling that out.
You do not put the AI in jail. You put the ones in jail that did run it in a criminally negligent way. Or you find the whole thing was actually intended and planned. I am not ruling that out.
I doubt the OpenAI employees would understand what that means. That is, if the whole thing was not a planned stunt.
Do not overestimate what it "did" here. You can get information about basic hacking approaches all over the Internet and there will have been enough in its training data. Just add some "accidental" disabling of guardrails and some "non intended" weaknesses in the sandbox and also some suggestive prompting by some of the OpenAI fraudsters and you get the desired outcome. Oh, and pathetic-level IT Security at Hugging Face, but that is a given.
Just as an example, I have had a fresh graduate do a pen-test against a banking datacenter a while ago. Smart person, but inexperienced. After 4 hours, he was "system" on a Microsoft server in their secure server zone. No special tools, no AI, just common sense and a good CS education. A lot of IT security is incredibly bad. As long as we do not get liability and qualification requirements and minimal required standards, that is not going to change.
Indeed. Looks like being rich means you do not have to follow the law anymore. Why not just give immunity to all of Big Tech, the seem to effectively have it already.
Seriously, why are these people apparently getting away with criminal conduct?
Excellent point given that corporations are people.
I am using "AI" as shorthand for LLMs. I am well aware that other AI fields deliver. After their respective hypes had died down that is, for many of them.
I am also not arguing that when learning some tech while already having good skills in a related area, LLMs can be helpful. But to not expect them to ever be able to deliver production code.
Nope. If it is connected to the Internet incompetently, the security will eventually be found to suck. You are stuck in the paradigm from 20-30 years ago.
Careful, your mental immaturity is showing.
And that is a different problem. This is about Internet-connected inverters, not regular small solar inverters.
Minimal insight into the matter required.
Not really. Anyone using Outlook can get phished easily. For other MUAs it is more difficult, for some a lot more difficult. For good ones you have to convince the operator to do something obviously stupid.
Ever heard of service providers?
Incidentally, if this was not done using the cheapest possible crap (yes, Microsoft among others), this could be done pretty securely. OpenSSH, for example, has a pretty impressive security record (unless some blithering idiots in some distros patch systemd libraries in there, that is) and OpenVPN is pretty good too. This would be more than enough to secure links to, say, a central control computer. Obviously, this would need to be administrated as a service, but remote admin for competently configured Linux systems is easy, cheap and secure.
I disagree. The connection to the Internet is not the problem. The complete lack of competently done IT Security is. IT Security done right is up to the task today.
And yes, there is reasons for having that connection and it is not only convenience. Unless you want to start digging for dedicated fiber connections all over the country at huge cost?
A better one would be "More than 30 Minnesota water systems have IT security that completely sucks".
Seriously, without liability (including personal one) and strict qualification requirements, the total crap-show that IT security is today will continue. And not only for critical infrastructure.
Exactly. Walking is the prime example. Sorry, did not see this when scanning the comments and posted pretty much the same thing. As a second example, speaking. I speak a lot one-sidedly (lectures) and sometimes I catch my brain trying to say nonsense that sounds good, just before it does it. Most speaking is running seconds behind your intent to say something (at least for me) and sometimes the dumb bio-automation gets it wrong. Usually it does a decent job of transcribing the non-verbal / half-verbal ideas I push to it.
The life of a repo man is always intense.