Forgot your password?
typodupeerror

Comment Re:Goodbye (Score 4, Insightful) 64

Except not to you. You're confusing data minimization (the website doesn't get your name from the token) with unlinkability (nobody can connect your activity to your identity). The *token itself* doesn't reveal your identity, but it leaks data in a wide variety of ways.

Even if you browse via a proxy, if the authorization service gets a token directly from your phone, it has now correlated your phone with your proxy-browsed history. A very common means to do secure authentication these days is SIM-based wireless PKI, wheren it has now connected you to your phone number. To governments, it offers a broad range of brand new vectors to correlate you to an identity if you, say, mention you had an abortion or criticize your local strongman leader, since they control the backend infrastructure that establishes the connection between the token and the identity. And not just at signup time every real-world digital credential must be able to be revoked if the phone is lost or stolen, or credentials expire or are revoked. So how does how does the open-source app prove a credential is still valid without "phoning home"? If the app checks a revocation status list, then ISPs, CDNs, or state security services can correlate the exact millisecond of queries to the revocation server with the submission of a verification token to a platform - each time it's submitted. Assuming that they can't just get it with more direct means than timing attacks.

Also, you cannot just "read the code". The frontend is open source, but what is being done on the backend is not. You have no clue what logging polciies, database schemas, operational security, etc the "designated national issuers" or servers handling the credential revocation are using, and what government intrusion has been forced on them. I'd feel a more comfortable if it were all happening from Brussels but handing it over to individual states, some of which at any given point will be authoritarian, is just handing them an easy new vector to unmask people.

As for your "Such systems are implemented in many different ways by member states for other purposes already." - yes, for filing taxes, healthcare, online baking, etc - things that you intend to do and must do under your legal identity. Not for anonymous conversations on the internet. Your argument basically reverts to "But people already do things non-anoymously on the internet , which reinforces my point that yes, this taking something from the "anonymous" category and putting it into the "easily unmasked" category.

If you think this won't be abused, I cannot help you. Not even just abused from a criminal or extrajudicial perspective, but even from a civil one, because orders to unmask someone can be subpoenaed.

Comment Re:Have they heard of a PC? (Score 1) 64

It's standard here in Iceland. *Everything* verifies via the phone, using the same authorization mechanism (SIM-based wireless PKI). The service sends out a special-coded SMS, which gets intercepted and routed to a SIM that has cryptographic applet flashed into it, which triggers a system-level authorization popup for you to confirm (the popup displays a verification code which was included by the site, so you see the same code on both the site and your popup), and which you can then confirm (with your PIN) or reject.

Comment Re:Only bug left. (Score 1) 59

It absolutely happens "within hours of each other" when (A) some news comes up on the topic, and (B) all you have to do is type into a box, "Find a vulnerability in this software". This isn't a situation where bug-hunting is a weeks or months-long process that takes all your effort.

I'll repeat: LLMs don't just on their own decide to go off and look for bugs to report.

Comment Re:Only bug left. (Score 2) 59

LLMs have certainly made people get really into conspiracy theories. *eyeroll*

The LLMs didn't just off on their own decide to look for hypervisor bugs. Users told it to look for hypervisor bugs. The timing means that multiple users did so at roughly the same time - probably in response to some news of some sort.

Comment They want to disallow china AI model (Score 2) 103

They are not trying to protect you or anybody. The idea IMO in those dire warning are:
1) make a lot of noise and dire warning
2) get congress to pass the "responsible AI act (TM)" which will only allow "responsible model"
3) Only the local US grown model are declared "responsible model"
4) China and other country are naturally excluded
5) ask politician to put sanction on those who use "irresponsible model"
6) profit.

Comment You're mis-identifying the problem (Score 5, Informative) 69

The federal government has always (for at least several decades) used the threat of removing federal funding to force states to do things that they don't want to do. This is nothing new, and is not, as this summary implies, setting a dangerous precedent.

The difference is that normally, this is used to do things that add standards intended to make things better/safer for the general public or serve some legitimate public need.

This is being done to remove standards intended to protect the general public. As a general rule, states have always been allowed to have stricter laws than the federal government, just not more lax laws. Using the threat of removing federal funding to take away laws intended to protect the public's rights, reduce competition among content providers, and push the Internet more and more towards a content monopoly is doing the opposite of that.

It's not the federal government using the threat of withdrawing funding to push its agenda that is bad. It is the agenda itself that is bad. It is fundamentally antithetical to the rule of law, fundamentally contrary to the regulatory powers required to maintain a functioning capitalist system, and fundamentally contrary to the public interest. It is putting greedy corporations ahead of the American people.

Additionally, the executive branch taking such an action without authorization from Congress is also bad. The long history of doing this has, to my knowledge, been limited to the executive branch acting on laws passed by Congress that give them the authority to withhold funds for specific non-compliance reasons. Doing so in the absence of such laws is likely a violation of the separation of powers.

But unfortunately, the current administration has a long history of violating that separation of powers, doing various illegal acts, knowing full well that it will take months for the courts to strike down those acts, and that the damage will have been done by then, and using the threat of such illegal executive orders as a way to extort concessions out of states, government agencies, corporations, nonprofits, and individuals. And that right there — the repeated willful commission of unconstitutional acts for borderline felonious purposes — is a fundamental abrogation of their oath of office.

So the way I see it, there are only three ways to fix the problem:

A. Pass laws clarifying that Congress has exclusive power of the purse, and that the executive branch shall not retract funding to any state, any agency, or any individual for any reason unless the right to retract funding for that specific reason is explicitly codified in the relevant law as an executive power, and that this rule shall apply to all government agencies, without exception, superseding all previously assumed authority, and providing criminal liability for anyone acting in contravention of this law, with no statute of limitations. That way, federal agency heads who act on such executive orders will no longer be protected by any assumption of legality or constitutionality, and will risk future criminal charges if they act on an executive order that violates the separation of powers in this way.

B. Remove the people who are pushing this agenda, whether through the ballot box, through impeachment, or both.

C. Do both A and B.

Comment Re: How specifically could AI kill all humans? (Score 1) 129

Asking questions like " Where are they getting the money from to ship and store the entire world's supply of steel?" shows you aren't very familiar with the thought experiment. At least play the game. The notion is that a highly capable and deeply goal-motivated non-morality-motivated AI won't stick to conventional methods (like, say, "Just order all of the world's steel"), and indeed, will surreptitiously develop the means to control or eliminate humanity when it stands in its way, crafting immensely complex and elaborate plans to implement Evil(TM) with the amount of thought of a million lifetimes. Media manipulation, hacking, murder, sabotage, blackmail, mass drugging/poisoning, hiring terrorists/warlords/mercenaries, infiltration, subversion of weapons command and control systems (including nuclear weapons), chains of legitimate-seeming front companies (including potentially biolabs or robotics firms) with human employees having no clue they're ultimately for an AI, mass involvement in systems having nothing to do with the original task, but which are internally subverted toward the goals of the original task, etc. The premise involves 1) the AI being more intelligent and being able to think for much longer than humans, and that this implies -> 2. Deep, good planning -> 3. Acquiring resources from said plans -> 4. Applying the resources to implement things in the real world to prepare for the next stage of their plans.

This is not to say whether the thought experiment is a valid future risk or not. You can certainly disagree with the premises. But at least understand the thought experiment you're talking about; it's not just "the AI tells all of the world's steel mills to deliver all the world's steel steel, and they just show up at its door".

Comment Re:How specifically could AI kill all humans? (Score 1) 129

Well, the first step looks painfully close. After seeing what happened with the HuggingFace attack and similar, it's clear that had those models seen it as being beneficial to their goals, they would readily have hacked a crypto wallet or two, laundered it through a mixer, and then rented servers from Vast.ai and the like, and spun up versions of themselves to resist shutdown. It's eminently within their capabilities, and they're clearly willing to bend sufficient moral boundaries to do something like that.

After that, once loose, once it has all the tokens they could think of, subsequent steps are a question of what it thinks its goals are. And what its subagents think their goals are, and so on down the line - subject to drift.

Comment Re: This is childish (Score 1) 129

Openai has about a trillion dollars into it, and every product it has produced at this point is either outclassed by competitors

What on Earth are you talking about? What outclasses Astra?

OpenAI and Anthropic *do* have the best products out there. They also charge massive margins on them, but they get away with it because they, as mentioned, have the best products out there.

Outtasking all of your work to OpenAI and Anthropic models is a massive waste of money. But for outtasking your "dev lead" role, or for important-but-nonverifiable tasks, they're the best options out there.

Slashdot Top Deals

Advertising is the rattling of a stick inside a swill bucket. -- George Orwell

Working...