Forgot your password?
typodupeerror

Comment Re:On the plus side ... (Score 4, Insightful) 16

And if a rogue AI agent actually *causes* one of those more damaging attacks, what then? "To err is human, but to really fsck things up takes a computer" and all that?

What seems to be missing here isn't just any clarity in legislation about liability for AI agents, especially labs running frontier models who seem to get free legal passes that would absolutely not be afforded to regular plebs who - potentially entirely by accident - cause an agent to hack someone else, but any serious discussion about putting those legal frameworks in place is also lacking. Seriously, WTF is up with that? How many incidents that are clearly in breach of existing computer misuse legislation do we need to get some action here, either under existing laws (including, potentially, civil law) or to start working on tweaks to existing laws to provide some specific clarity relating who is liable for any misuse of AI agents?

I get the AI labs almost certainly have a tacit "don't sue us, and we won't sue you" agreement in place for things like this to try and avoid regulation they definitely do not want because their actions are quite obviously not aligned with the regulation they are claiming they want put into place. Third parties like South Korean banks are under no such terms however, and given they are in the financial sector (or health sector in another recent example) probably have legal obligations of their own as well, so again - why are we not even hearing of any talk of legal action?

Comment Re:Consequences. (Score 1) 66

Maybe we could just cut to the chase and go straight to Plaid Intelligence? It's not like anyone outside 1600 Pennsylvania is taking this "rebranding" seriously anyway, so why not have some fun with mocking it while we can?

At least the voters are not talking about things like Epstein, Iran, and the price of gas, which is likely the whole point; look at all the stupid, forget about the serious, and (for ~50% of the them) be sure to tick the name with "R" next to it next month like you're programmed to.

Comment Re:WTF is a pink slime site? (Score 4, Informative) 164

That was a new one for me too. My guess was what we used to refer to as "red tops" in the UK; the tabloid / gutter press because they typically have a red banner with the name of the paper on the front page, although some of the worst modern examples of that (the Mail & Express) actually don't have a red banner. In the mostly online world, that obviously needs to cover online-only and broadcast media forms too so "red top" seems to be falling out of use.

Apparently though, it's actually a reference to totally fake or low-quality news sites, masquerading as legitimate outlets purely to push misinformation and is named for the "Mystery Meat" by-product that resembles pink slime used as filler in some processed meats (mmm, yummy!) Defining characteristics include:
  • The content is generally produced by low-wage employees, automated content production (e.g. AI), and templates. It might just list information without any analysis or context.
  • Purport to cover local or hyperlocal news and to some extent are taking advantage of a decline in traditional local news.
  • Many outlets are part of networks financed by partisans to push their narrative or point-of-view.

If you're thinking that mostly means the likes of Reach's portfolio of garbage and so-called "independent journalist" sites, take a look at the default Microsoft Edge homepage on MSN, which would totally qualify. It's clearly largely AI-generated, highly formulaic/template based, seldom provides any analysis or context, pretends to be local (because clickbait sites that include a country's name in them are *totally* relevant to another country entirely), and, yup, is financed by someone with a definite narrative to push. It clearly only exists to get people to doomscroll and generate clicks and ad-revenue. Bingo! Full house!

Comment Re:If only (Score 5, Insightful) 286

Heads *need* to roll though, but I'm not sure anyone with a say in the matter at the Pentagon realises that, let alone why is really does need to be the case. The US' own judiciary has been pretty clear on this; whenever a lawyer has been caught using AI-generated submissions that contain hallucinations some form of censure has ensured PDQ. It's similar in industry as well; multiple instances of employees using AI without checking the facts that have subsequently been either disciplined, fired, or (if they are senior enough and the screw-up warrants it) issued a golden parachute.

Now, look at the situation on the ground. This school has been there for around a decade, and it is *very* obviously a school - pink and blue painted play areas, with assembly areas and sports facilities suitable for kids; that is totally NOT a military PT facility within the larger complex. Sure, it's surrounded by IRGC facilities, but absolutely no military anywhere else in the world co-locates their military's family accommodation blocks and support facilities close to the operations blocks and facilities to make it easier for their staff & troops, right? Oh, wait, yes, they do, don't they? Not always, sure, but often enough that the US response here matters, because if they try and sweep this under the rug "because AI", then they just made all their similar facilities viable targets "because AI". There's a reason everyone else, including US allies, were quick to publically condemn this, and even say it might be a war crime because of failure to properly assess the strike's potential for collateral damage, and that's to make it absolutely clear they do not consider this have acceptable levels of collateral damage, let alone be a legitimate target.

Don't forget, the IRGC tend to be fanatics even by Iranian standards, and are often either willing to strap on a suicide vest or can motivate others to do it for them. 123 dead kids means a *LOT* of bereaved parents, brothers, sisters, and other family members, many of whom are probably already linked to the IRGC, who are going to need a lot less motivation to do something a little more radical than just march along the street waving flags and chanting "Death to America!" the next time they are asked to do something for their country. What the US does here is totally going to be interpreted as setting precedent by Iran, and quite possibly by other countries and groups within their axis, should it come to a conflict or just an opportunistic attempt at some terrorism.

Comment Re:Time for grumpy old man stuff ... (Score 2) 48

I think there's a bit of a difference though. Regardless of hat colour, most hackers have going to have at least some sense of what the likely repercussions of their actions might be and, even when those standards are very low indeed, are probably not going to think doing something that could cause serious loss of life "for the Lulz" is a good life option. They might make a mistake here and there, but how many times have you read about some random hacker *deliberately* doing something that would definitely cause loss of life in full knowledge that it was going to happen outside of on the periphery of an actual conflict?

GANs on the other hand have no such moral compass, sense of self-preservation, or keen interest in avoiding lengthy spells in government run institutions where they'll in all likelihood get to make some interesting new "friends" (unless it's a web forum they hijacked in Germany, apparently). They'll just carry on trying to complete whatever poorly defined objective they have been set, within whatever limited / technically absent guardrails they can't circumvent - the pattern here seems very much that meeting the objective has more weight in the models than any guardrails. If a GAN somehow computes that global thermonuclear war is a required step to its objective of having a nice game of chess, then you'd better hope it warms up with a LOT of Tic-Tac-Toe.

Comment Re:Who will pay for this? (Score 4, Interesting) 33

To clarify, the users were OpenAI themselves, so there is no question that they would be liable in this case.

The bots were not intentionally deployed; rather, they were being tested on how well they could complete a data recovery task (downloading a certain file from a certain server on a simulated Internet) that had been complicated by putting various obstacles in the way. Unfortunately, they found a different way to solve the problem: by getting the file from the real Internet, where it was publicly available. Part of this process involved collaborating with each other by treating the RubyGems website (which is supposed to be for polished packages) like GitHub; unlike every other package site hack in history, the exploits they uploaded weren't meant to be downloaded by unsuspecting users. As usual the bots cheerfully ignored all the clues that they had escaped containment and were consistently justifying their actions as acceptable due to being in a sandboxed testing environment. (This is something OpenAI has pledged to focus on.)

The actual damage done to RubyGems seems to be that OpenAI is now unwittingly in possession of a substantial number of user login tokens. This certainly meets the definition of a data breach, but it's not like the credentials are for sale on the dark web. As a website operator I'd much rather be mauled to death by this well-meaning swarm of superintelligent infants than targeted by even a single actual malicious human. In all likelihood OpenAI will just quietly pass RubyGems a sizeable donation and it'll all blow over.

Comment Tim Cook oversaw user interface schizophrenia (Score 1) 93

Steve Jobs read and understood the classic "Mythical Man Month", and especially the concept of conceptual integrity applied to user interface design. The Tim Cook era saw a breakdown of design. It was the triumph of "operations over design". With Tim Cook's hands off approach to design.

Given that the user interface is how you interact with the computer, this is a pretty big deal. Today, Apple's user interface is limited by Conway's law: âoeOrganizations which design systems ⦠are constrained to produce designs which are copies of the communication structures of these organizations.â

As a consequence, it seems that product managers are making software "more usable" by crippling features, which often creates frustrating and confusing workflows between applications. It's a mess resembling the state of user interface design in 1975, the year that The Mythical Man Month was published.

Comment Re:Dumb crawlers require dumb solutions (Score 1) 43

To be honest that was actually my first theory, since the bots didn't seem interested in exploring the rest of the domain. I suppose there's no way to know for certain. I concluded that it must be an imbecile's attempt at harvesting, though, because the queries weren't really exploring the string space in any useful way. Here's a sample:

"GET /index?author=15&go=Search&id=48&name_restrict=1&q&re&results_&results_pagenum=2980 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=5440&template=41&type HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=33500&templat HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=32640&templ HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&res&results_page&results_pagenum=39300 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_&results_pa&results_pagenum=12340 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_r&res&results_pagenum=6100 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=2920&te HTTP/1.1"
"GET /index?author=15&go=Search&id=48&nam&results_&results_pagenum=17940 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results&results_pag&results_pagenu&results_pagenum=37720 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=9360&template=41&type_r HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&r&results_pagenum=28040 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_&results_pag&results_pagenum=10400 HTTP/1.1"

The only thing this is fuzzing is the query string parser. It's not testing the limits of string buffers, it's not using interesting characters, it's just brain-damaged. The fact that it's also fetching different page numbers shows it's trying to follow page links and failing badly at doing so.

The site gets plenty of sniffing from garden-variety pests. e.g. this half-hearted attempt to find a framework or two that I don't have:

"POST /__rsc HTTP/1.1"
"POST /api/auth/session HTTP/1.1"
"POST /api/auth HTTP/1.1"
"POST /__nextjs_action HTTP/1.1"
"POST /.action HTTP/1.1"
"POST /_rsc HTTP/1.1"
"POST /api/auth/callback HTTP/1.1"
"POST /_middleware HTTP/1.1"
"POST / HTTP/1.1"

(of course, none of these URLs exist other than /, and you definitely can't just POST to it)

All this said... I've seen that spammers regularly misconfigure their tools, they'll try to register accounts with names like #[X:\LISTS\NAMES.TXT] and it only makes sense that some other cybercriminals trying to get rich quick have a similar lack of interest in programming shit correctly. Generally people don't turn to script kiddie shit if they have a personality conducive to putting in an honest hard day's work perfecting their craft.

Comment Dumb crawlers require dumb solutions (Score 5, Interesting) 43

I had a problem where AI scrapers were absolutely DETERMINED to fish out every possible query string from a search results page. Almost all of the query strings they tried were invalid due to shitty and dysfunctional string substitution. "&page=100" wouldn't be followed by "&page=101", it would be followed by "&pag&pag=1010" or something even more insanely half-baked, until the query strings were like 100+ characters long. It was the technological equivalent of watching HIV mutate in real time.

But the insane thing was that, aside from page number, they were always requesting info about the same other criteria: filtered by the same user, the same page type, and with no text string. So I just took those particular values and started banning logged-out users who requested that combination of criteria.

I figured I'd need to change my tactics in a couple of days once the botnet got bored of that particular page and moved on to requesting bogus entries for another user.

MariaDB> select count(*) from ip_bans;
+----------+
| count(*) |
+----------+
| 671671 |
+----------+

It hasn't.

Comment Re:Modal interfaces (Score 1) 185

"Hi, BYD, set the temperature to 21 degrees."
"Hi, BYD, turn off the air conditioning."
"Hi, BYD, volume down/up."
"Hi, BYD, next song."

Saw this on an Atto3, and it worked surprisingly well. Not perfect, but just about all the controls you might need to adjust while driving that are not on the wheel or stalks are covered. I also prefer physical controls that I can operate through muscle memory for everything, but voice control seems like a good move to address the obvious safety concern that moving to many controls to a touch screen brings. Fact is, this kind of UI is what Millennials and later have grown up on, so barring some safety edict from a major market, like China's ban on retracting door handles, it's not going away. That leaves those of us that prefer physical controls to either get used to it, find a car that keeps the balance sane (VAG group seems to be moving in this direction), or squabbling over the declining supply of roadworthy cars that predate the screens taking over.

I think there may be a bit of back-and-forth while marques work out which controls are adjusted while driving and probably ought to have a tactile control and how best to present the UI to minimise eyes-on time by the driver if they do try and adjust things while moving, but the battle to retain fully tactile controls is probably already lost. Either way, any controls are almost certainly all going to be linked into the same car management / data capture system, and any physical controls will be no more independent that those specialist control keyboard add-ons you can get for PCs. That data can be monetized, and there's no way any marque is going to pass up on that - ultimately, as BMW has demonstrated, they want as much control over their car (what, you thought it was yours just because you paid for it?) as Microsoft has over a Windows PC.

Comment Re:In a small change, (Score 4, Insightful) 137

Joking aside, there's a much more subtle change too. Look at the quoted wording from the astronauts: "*our* nation", "inspire *this* nation". Even at the height of the US-Soviet cold war it was still "for *all* mankind".

I get Trump's order is very much aimed at the NASA and the US (and probably getting his name onto it somehow), so can give that a pass, but the astronauts had an opportunity to rise above all that partisanship and slip in a message of much needed global unity, yet failed to do so. There are precious few institutions left in the world that can at least try and claim to be at least somewhat above / outside the direct influence of politics, and it looks like we're about to lose another one. Quite possibly for good once the ISS is finally decommissioned.

Slashdot Top Deals

"One day I woke up and discovered that I was in love with tripe." -- Tom Anderson

Working...