Forgot your password?
typodupeerror

Comment Re: the real answer is openAI hires incompetent pe (Score 1) 72

Let us see:

  1. I never expressed any opinion about the incident itself because I am not a judge and I do not care much about OpenAI or AI in general.
  2. I did say that the statement OpenAI hires amateurs! is offhanded because it ignores a larger problem, which is neither IT, nor security or OpenAI.
  3. You called me he (in your response to the other poster) for no apparent reason. The fact that I am a male and that he is my preferred pronoun does not magically fix your obvious inability to read carefully.
  4. I have zero intention of having an argument with you.

Good luck.

Comment Re: the real answer is openAI hires incompetent pe (Score 1) 72

Packet filtering, red teams, and all other security cyberdung is simply not interesting here. Just assume, for a moment, that OpenAI guys not only not worse IT pros than you but actually very much better. I understand that it is hard to believe, but do make that effort just for the sake of your own understanding.

The problem belongs to a higher level of abstraction. Assume that OpenAI built a perfect network isolation. Nothing, absolutely nothing gets outside of the lab unless OpenAI decide to let it through. To train those hacking AI algorithms, OpenAI still must grant them access to the Internet (that access must be granted promptly, AI-training promptly, otherwise the algorithms either cannot train at all or they do it so slowly that the competition takes over). Granting access, on the other hand, is dangerous.

This is the issue at hand. How do you decide whether to push that knob granting access? Forget all that quasi-security jargon. Imagine that you have a single button in front of you that is labelled LET IT THROUGH. The button functions perfectly. No push — not a single octet gets out. (Note that I am helping you by modelling a proper whitelisting mechanism.) When do you push it and when you ignore a request to push it?

To deepen your understanding of the issue, imagine that the algorithm may figure out that not all of its requests make it through. Since this is not a human conscience, the algorithm turns into a bitter liar attempting to masquerade its suspicious requests, turning more skilful every day.

Continue thinking in that direction and, perhaps, you shall be enlightened.

It is not an IT problem or a security problem.

Comment Re: the real answer is openAI hires incompetent pe (Score 1) 72

There's the fundamental problem of telling Good from Evil (esp., when Evil is a skillful lier).

Drip feeding/tripwires/sanboxing/yadda-yadda are all good as long as the process of vetoing network access does not slow down development of the model to, basically, a halt.

That They hire amateurs! opinion is offhanded. Those guys have a real problem on their hands. Not all engineering endeavours are successes.

Did you ever have a chance to talk with a smart person that is properly, clinically diagnosed as a patological lier? These poor souls can be extremely creative.

Comment U.S.C. 2232 (Score 1) 182

(a) Destruction or removal of property to prevent seizure.--Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government's lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both. (source)

IANAL, but, first of all, "search for property" or "seizure of property" must be applicable to the case at hand. What is "property" in this case? The physical phone? The data stored on this phone? The physical phone, apparently, was already "seized" (the police entered the password themselves). So, it sounds like "property" is the stored data. Now one cannot really maintain that the police was in the process of "seizure of" the data because, again, they seized all of it (together with the physical phone). How can one "search for" something that is physically in that person's hands is below my understanding.

To apply this statue, the police must describe (a) what they were hoping to find in that particular phone's data; (b) what were the grounds for that hope of theirs.

Otherwise, it sounds like they did not know themselves what they were after. See data, in material world, is most likely synonymous to thing. Police cannot maintain that they wanted to seize or were in search for a thing.

Of course, the guy may maintain that he gave the wrong password in a stressful situation, i.e., there was no intentional damage or destruction or attempt to damage or destruct knowingly. A human error. The guy was scared by police. Unlocking p/w was '123'; self-detstruction p/w was '223'. Yes, Your Honour, my selection of passwords was imprudent, I understand and admit that now, sir.

Comment It is A Lost Game (Score 2) 218

A smart person knows how how to get of of trouble; a wise one avoids it.

The moment you provide a wipeout password or plausibly deny a fact (i.e., basically, you tell a lie that you think sounds good enough), you start a game with an extremely powerful organisation that has a proven history of bending rules of all games. You also foolishly make a mistake of thinking that you know that special trick that helps you win the game. You also foolishly ignore clear warnings about the jurisdiction in effect. You start the game being in a tremendous disadvantage that you fail to recognise.

Wise people follow a set of rules:

  1. Have your papers in order; do not carry anything incriminating across the border. This is a non-negotiable rule.
  2. Be 100% sober. Getting stoned or drunk en route is a terrible idea anyway.
  3. Look plain and unassuming. Live that Mr. Robot hoodie at home. Dress as an average boring commoner of your age and sex would. Be clean and look clean. Smell good. Wear appropriate footwear, always prefer closed footwear. Do not carry items that attract attention, e.g. a dirty laptop with political slogans all over it does attract attention. Items that do not look the way you look do attract attention (e.g., you wear a business suit and hold a dirty and beaten Nokia 3220). Carry an appropriate amount of luggage (entering with a slim backpack after being away for 90 days does attract attention).
  4. Do not carry anything that looks strange or curious. The use or purpose of anything you have with you should be easily recognisable.
  5. Put on your best behaviour. Spitting on the floor, yelling across the hall, etc. will get you noticed. Remember: in most large ports of entry you are being watched, both remotely and by plainclothes security personnel.
  6. Be attentive, serious, polite, reserved, and respectful. Take out both of your earbuds or take off headphones immediately when addressed. Do the same before addressing others. Do not eat, drink, or chew. Do not speak unless you are spoken to or unless speaking is absolutely necessary for crossing the border. Greet and address all personnel appropriately: Madam, Sir, Officer. Being cocky will surely get you noticed. Do not attempt making jokes — security personnel may not share your wonderful sense of humour.
  7. Cooperate. Cooperate. Cooperate. Remember that you deal with people that perform boring, repetitive work. Do not be that person that makes their work any harder. If an officer is overly curious, feed that curiosity readily but in small portions, without making a scene.
  8. Being sad or mildly upset is OK. Being outraged and indignant is NOT OK. Do not ever raise your voice. Be calm.
  9. Answer all questions but do not volunteer information. When asked Do you go to a college?, the proper answer is either Yes or No, depending on your circumstances. The improper answer would be the complete details of the place followed by a prolonged rant how you hate that professor. You should provide further details if and only if asked about them.
  10. Remember, your main purpose is to leave the port of entry ASAP and continue freely to your destination.

Comment Evolution? (Score 1) 36

Assuming (yes!) that the statement is truthful, it is yet another case of a business that failed to recognise the importance of information systems' security and have not survived (at least, in its present form). The generation of businesses that rely on IT and fail to protect their IT (proactive measures, mitigation of attacks, contingency plans, etc.) will inevitably die off.

Comment Several Problems, Actually (Score 1) 98

Hearing a siren is not an issue: an in-car mic plus FFT should do the trick is just fine. The real catch is what to do next. Emergency drivers often overtake agressively which is very much unlike the usual driving that AI is trained for. What to do if there is an ambulance behind but all lanes around an autonomous car are occupied? Human drivers mostly attempt to squeeze away from the ambulance, which is a dangerous maneuvre for an autonomous car. A person having a heart attack on a crossing is indistinguishable from a manhole w/o a cover with a couple of cones around â" just an obstacle. By their nature, emergency situations are rare, hard to train for and unpredictable also for humans. We still believe in miracles and technology being superior to us.

Comment What is the Security Architecture? (Score 3, Insightful) 65

I am not familiar with it, and I assume that so are you. So, fantasies...

There might be nonces or other tokens attached to a vote that must remain secret (proof of voting only once, etc.). Another use of encryption is avoiding claims along the lines "The results published by authorities are false! Here is the true copy which cannot be validated because dem computors are broken! But everyone knows that the copy is REALLY TRUE!" With the present system, if dem computors are broken, there cannot be any alternative results.

The architecture, BTW, must be a public knowledge, otherwise it cannot be trusted. I believe that you can find it somewhere if this is a matter of interest to you.

Slashdot Top Deals

Saliva causes cancer, but only if swallowed in small amounts over a long period of time. -- George Carlin

Working...