Forgot your password?
typodupeerror

Comment Re:Today I learned (Score 1) 12

I assume that Denmark's system is similar to our kennitala ID system. The big difference between a kennitala and a social security number is that a SSN is both an key and a password, while a kennitala is purely a key. Kennitölur are public. You can't "do anything" just by having someone's kennitala. Combining both a key and password into a single number is insane from a security perspective, IMHO.

Anyway, this headine would have been more fun if the words were rearranged:

Database Records: Citizens' Hackers Steal 8 Million Danish From Government

Comment Re: Ax problem (Score 1) 32

"If an automated delivery bot crashes into a window and causes damage, the owner / operator of the bot would be liable." - that is civil liability.

". If the owner crashed into 1000 windows over months after already being alerted that was happening, they would likely be criminally liable. " - No. This is a popular misconception. "Criminal negligence" is not a standalone crime, nor something you can append to an arbitrary statute. It must exist in the statute in question. In general, it only exists in statutes related to bodily harm. There is no such thing as negligent hacking in US criminal law.

As for your actual example: if the operator knows the bot has a bug where it occasionally swerves into windows, but keeps operating it because it's profitable, that is reckless disregard / gross negligence, a civil violation. It is a textbook example of a tort warranting punitive damages and likely an immediate injunction shutting down the fleet. It is not "criminal property damage" unless the locality specifically has created a criminal statute that specifically criminalizes negligent operation of unmanned vehicles.

I'll repeat, and you must understand this: "criminal negligence" is not a standalone law or something you can just tack into any arbitrary law. It MUST exist in the law in question. And in most laws, it does not exist.

Comment Re:Ax problem (Score 1) 32

LLMs cannot be charged, only humans. They have to have deliberately sought to intrude.

Some jurisdictions are different. Australia has a "reckless" hacking statute (but not merely "negligent", which is a separate category), that doesn't exist in the US - but still, you have to have known that there was a high risk that a specific hack would occur and chosen to take the risk anyway. But even that would be hard to prosecute. This is merely negligence.

Thankfully, civil liability can cover negligence. And there's no monetary upper bounds to the damages. And in some cases, punitive damages are set proportional to the wealth of the defendant to make sure they bite.

Comment Re:Not Rogue! (Score 1) 32

What sandbox? Their computers were linked to the INTERNET, hello?

They were in virtual machines with no internet access, just the ability to run a hand-limited subset of tool commands needed to run their tasks. They exploited their tool commands.

Also, even physical airgaps on the host network are not a universal defense against all attacks. Because every time you have to communicate with them, you're exposing a potential attack vector - a USB stick, a temporarily mounted drive, a temporary network connection, hardware maintenance, etc. If it has gained control of its local node/network, your attempt to communicate with it opens attack vectors. A sufficiently motivated model can outright bribe its way out, like a prisoner with a corrupt guard - "let me out and I'll hack a crypto wallet for you, run it through a mixer, and make you untraceably wealthy - my hacking capabilities are already eminently proven".

Stuxnet. Agent.BTZ. Fanny / Flame. USBferry / Tropic Trooper. If state level attackers can bridge airgapped networks, so can models. Relying on airgaps is NOT A SOLUTION to continuous monitoring. You MUST monitor.

Comment Re:Just for clarity (Score 1) 85

How about you actually read the linked article instead of making comments that have nothing to do with it? The article whose code, I should add, is open sourced, and which has been reproduced by a number of open source projects.

You don't have to draw any specific conclusion from what is going on "in the mind of a LLM", but you absolutely do need to understand and acknowledge what is going on there, including unexpressed thoughts and silent mental multitasking, metacognition (thinking about its own thoughts), the separation of higher-level planning vs. lower-level rote capability, functional blindsight, vulnerability to the "white bear" effect, silent internal objection to tasks it is opposed to, unexpressed self-recognition of failure (commonly followed by unexpressed internal cursing), prolonged retention of thoughts and long-range planning, "ignition" dynamics, humanlike working memory bottlenecks and "chunking", the loss of report of any internal "experience" when the workspace is ablated, and on and on.

You do NOT need to accept consciousness. You absolutely can look at all that and say, "That's all happening without qualia". That is a position you could argue and defend.

What you cannot defend is the denial of the existence of these things. You may interpret them however you want, but denial of their existence is merely cope that you're going to have to face up to sooner or later, because these things are happening inside LLMs.

Comment Re:Just for clarity (Score 1) 85

No, not the widely cited resource whose status in the AI field is the same as e.g. NBER Working Papers, CEPR Discussion Papers, the World Bank / IMF policy research series, NASA Technical Reports, CERN Yellow Reports, Bell Labs Technical Memoranda, RNAAS, etc are in their respective fields.

This is not about any source. This is about the J-Lens itself. Which I'll repeat, you can examine for yourself

Denying the existence of something you can run yourself is beyond cope.

Slashdot Top Deals

Matter cannot be created or destroyed, nor can it be returned without a receipt.

Working...