Running With Spoons
@runswithspoons
Maybe we deserve this
futurism.com/artificial-i... "Though only 28 percent of wage-earning employees said they used AI for over two hours a day, more than half of all executives — 64 percent — said the same." In case anyone wonders why things look so bleak now
The cost to investigate and restore the environment would normally be covered by insurance and could be seen as damages. Per the cloud security alliance writeup, Huggingface had to rebuild a third of its infrastructure.
They didn't have (at least) a level1 monitoring team because they relied on an LLM to do that work
So many opportunities for detection. From the below, the LLM did something (likely many things) that were blocked by controls, but the security ops teams didn't notice
Their security monitoring failed to notice the attacker in their front line production environment for (at least) two and a half days. Don't they have security teams for this, like all modern companies with an Internet presence?
If this were ethical, they wouldn't need to hide what they're doing.
OP on Mastodon is spot on about this. Huggingface has demonstrated it is a soft target. Also a very appealing target as a supply chain attack. They host widely used Python code, and some of the models are pickled so they also include code.
No it is not just a tiny keyboard with a "brainpower dial". It is a tiny keyboard with a dial for brainpower
Are you ready for extreme productivity? Can you handle the power of Work Louder™? openai.com/supply/co-la...
www.aisi.gov.uk/blog/our-eva... None of these models are scoring 100% even on the easy benchmarks we created for them. Here is an example. AISA evaluated Mythos and other frontiers on some fairly easy security challenges. In the chart below, even Mythos solves less than 90% of "apprentice" level
He needs someone who gives practical advice, like Ben Wittes
They're somehow worse than the dystopian TV programming in Idiocracy
Also they do not even try to grapple with whether this is a spaceship company or a chatbot company. They don't question whether that makes any sense
This part is a barrier for me. I think a local LLM could be useful for tactical coding work but the complete disregard for attribution and licensing in training data is an ethical problem I can't easily get around.
Keep up the great work, maybe you can reach 100 hate followers this year
Gotta free up those hours to beat down your brain with TikTok slop
This book changed how I think about people. The author observes most of the "heroes" in our "classics" are better seen as thugs, war criminals, or oftentimes rapists Some heroes we've chosen
Great article. I'm skeptical... that Dario believes the things he says.
This isn't the most important part of the story, but I wish police in the US would find the strength within themselves to arrest rather than shoot. UK policework proves this is possible.
Or... Maybe reliable quantum computing (analog computing) will always be 10 years away