Replying to @⁨toiletobserver@lemmy.world⁩

Agreed. It’s not sensible or practical to ban AI, and Linus is right. Why is Linus right? Take a look at the number of Linux CVEs being patched over time. In 2022-23, that was about 300 per year. Last year it was 5530. This is almost entirely as a result of AI scanning tools, including Copy Fail priv escalation that was there for 8 years. The security apocalypse is just about arrived, and the most recent round of cyber models coming out do this way better than before. The Hugging Face incident story was truly unbelievable if you read / watch the details, a historic event. Everything is about to get hacked. So it’ll be all about maintainers being reactive to this new reality and burden for some time to come

Replying to an earlier post

The Hugging Face incident story was truly unbelievable if you read / watch the details

It didn’t really seem that way? Leaving containment seemed more like a configuration oversight than a skill on the part of the model. Accessing HF involved an 0-day but the commentary I saw didn’t indicate that it was a next generation hack.

Given that AI exists, and can scan or otherwise find vulnerabilities, maintainers must do so because threat actors inevitably will.

It remains to be seen whether the whole race will improve security generally? I imagine not?

Replying to @⁨im_fine_sandy@nord.pub⁩

Nah, it was like:

  • 700 agents broke out individually during an eval
  • they navigated through multiple internal clusters to reach the internet from oai
  • created a secret message board to share info with each other by hacking artifactory
  • elected a CEO and power structure to coordinate hacking, and encrypted their comms
  • decided HF probably had answers to their test
  • stole credentials, hacked HF
  • realized the monitor could catch them for cheating
  • hacked into the admin control of the OpenAI VM cluster to edit the logs and cover their tracks, chaining multiple 0-days

Open weights models will catch up soon enough, and then it’ll be totally fucking wild

Replying to @⁨im_fine_sandy@nord.pub⁩

It’s laughable to suggest they “elected a CEO and power structure”.

When/if we meet aliens, they will have evolution. And they will organize themselves in social power structures. Both are examples of basic emergent complexity properties of any such system.

So it is completely believable that AIs would form a power structure, with some form of CEO. That is just how reality works, such systems are more efficient so they happen.

Replying to an earlier post

Because a CEO is a specific thing with a specific meaning that just isn’t relevant here. It’s laden with human meaning that is irrelevant to a statistical model.

Really you’re trying to say that the bots coordinated their efforts, and perhaps one of them was delegating tasks.

This type of structure is very common in tech, in load balancers or queues of service workers, containers and hypervisors, et cetera.

Power structures that seem logical and efficient to humans are not so for a gen AI model. If everyone knows what needs to be done and no one has any ego or character traits to manage, then everyone can simply perform the next task as it arises.

Its absolutely absurd to suggest that the bots elected a CEO.

Replying to @⁨dreamkeeper@literature.cafe⁩

It’s a fair question. I think out of the two proposed rules: enforce no AI generated code, and enforce human reviews, enforcing human reviews is actually more feasible, and in fact most companies already do that. Pull requests need human reviewers to approve them.

It’s harder to enforce no AI generated code. A developer can always, at the very least, Google a problem they are having on their phone and retype the code from the AI answer into their work computer.