Bing Chat responses infiltrated by ads pushing malware
bleepingcomputer.com
bleepingcomputer.com
I understand why people want AI search engines, the problem is, this is not an AI search engine. None of them are to my knowledge. It's just an ML bot mediating a search between you and the engine. The web page accomplishes the exact same task, without the unearned air of authority.
Like, the IDEA of an AI search engine, an artificial intelligence that knows all this stuff and can weigh in alongside you with insight and comprehension, that's incredibly cool. But this is not that. ChatGPT knows much but understands nothing.
Unless I guess you train an AI on a given topic, like a few languages or a database or something. But given ChatGPT's apparent vulnerability to just making shit up, you'll have to call me skeptical if this has any real use.
Not as accurate, but faster.
For some people - I am reluctant to say "for some use cases" - that's very appealing.
Like hell, if that's the standard, I'll be ChatGPT. You won't need an outrageous graphics card to ask me a question and I'll get you an answer right away. It'll almost certainly be the wrong answer, and is just an ass-pulled guess, but if that's all you want, I'll setup a chat website for myself and start taking queries today. Then investors can give me 10 billion dollars.
Also, not super relevant, but in e.g. combat situations one is often better off running now in any direction rather than pondering which direction is absolutely optimal for running from the lion. You'll know soon enough whether it was the right direction. There's probably a metaphor somewhere in there.
>> For some people - I am reluctant to say "for some use cases" - that's very appealing.
You're preaching to the choir.
However, do keep in mind that even authoritative sources found during your own research may be inaccurate. And for some questions, which answer is "right" or "wrong" may not be black and white.
I mean, sure. But again: that's just my point restated. What is this doing that a standard search engine does not?
Like, I put shit in my phone's calendar and set reminders so that I don't to think about it anymore. That is a cognitive load (remembering my dentist appointment) that I have now offloaded to technology. And that's useful as all hell, which is why my phone's calendar is full to the tits of everything one would put in a calendar. Now I don't need to think about it. I get messages from my phone when events are coming up, and I get a literal calendar on my screen when I want it, showing me all these things with perfect accuracy.
What is BingGPT in this scenario offloading? It's just a search engine but slower. It doesn't understand what good software is, so it can't make value based judgements on which to recommend. It doesn't know what reliable sources are, and can't evaluate for them, so every bit of information you get back must be treated with a grain of salt. It (probably) doesn't even remotely conceive of why you are asking it a thing or what a good answer to that query would look like because it doesn't know you, it just knows a massive, incomprehensible amount of averages about a ton of things that might be what you want.
And like, that's fine, search engines have had these limitations for my entire life. That's why I'm saying, I don't understand why this is better. It's the same thing as Bing, but slower, and in a chat box.
And again, it is quicker than clicking multiple links and can generalize / contextualize what it finds, mapping it to the answer you're looking for.
Have you tried asking one of these tools to write some simple scripts for you? It works decently, actually.
If you didn't already know how to program, this could save you a TON of time, even if it doesn't work perfectly on the first try.
Nice thing is, if it doesn't work perfectly on the first try, you can describe the problem (or paste the whole output, errors included), and get back a fixed version that's likely to work this time around.
If you “have to double check everything”, what’s the point? Skip the AI and do the check you were going to do anyway.
Problem: I want an AWS CLI command line that requests a whole bunch of wildcard certificates from AWS Certificate Manager (ACM) for a TLD.
Ostensible solution: the AWS official docs have a small snippet to achieve this, BUT -- the snippet on the official page is inadvisable as it leads to a browser cert warning.
So I (skeptically) asked ChatGPT for a command line to achieve what I was trying to do.
Try 1: got basically the snippet from the AWS official docs (but with the inadvisable flag set to the _Correct_ value, strangely)
Prompt 2: please give me more best practice options
Try 2: get back a bunch of new CLI options and their meanings. 3 are useful. 1 is hallucinated. 1 is deprecated.
Prompt 3: keep going with more options
Try 3: 2 more useful new options, 2 more options I chose not to use
As a skeptic, the overall experience was much more efficient that googling around or even reading a manpage. I put it all on the fact that context is maintained between questions, so you don't have to repeat yourself when asking for clarifications.
This might be a big part of why GP's case works. The model (GPT-4) most likely understands the concept of documentation being deprecated, so the more often v1 docs say it, the stronger a semantic link between current and obsolete docs, and the more likely it is for ChatGPT to give you answer based on non-deprecated docs.
Yes! Note that I had to use my domain knowledge to sift through the options and eliminate the garbage, but the experience was just _faster_ than repeated searches and digging through ad-laden garbage sites.
Almost anything related to software development. Any answer I get online, whether from Wikipedia or a Github search or a Stack Overflow question or anywhere else, will require careful study and adaptation before I can use it. There will inevitably be things about any given solution that don't apply to whatever I'm doing, or that will be out-and-out wrong. But does that mean I'd be better off without doing a search at all? Of course not.
Same with AI. It can point me in the right direction and save me a lot of trouble, but it can't (yet) do my job for me.
When it gets 10x better -- and I'm sure it will -- then that last part can be expected to change. Which is awesome.
Meanwhile, Stack Overflow and Wikipedia and Github aren't going to get 10x better, ever. Not without cross-pollinating with AI.
I had this really annoying requirement to get multiple incompatible status codes, and output them in a consolidated human legible way.
So pretend I am using MSSQL, and I have 3 status code tables.
The status code integers are all slightly different. NEW is always 1, but "Completed" could be 5, 7 or 21 depending on table.
The actual "text" is an integer that can be linked to a Text table via the ID and Language name. But, due to the nuances being slightly different, each version can have a different ID. I can't just use DISTINCT on the text ids.
This is even more true when slight differences like "Complete" and "Completed" exist.
So I need to use UNION, to 'combine' multiple unrelated status code tables.
Then I need to get the language text, and SELECT DISTINCT (or something similar) per language.
Then that needs to be outputted as a drop down for the user.
Then, I have to use that as a other, separate input for another SQL query.
To say "using fast, slightly inaccurate GPT code" was faster than doing it by hand would be an understatement.
It gave me about 15 iterations, where about 6 sort of worked. Then I figures it out myself from there.
How many times have you asked a co-worker about something and they gave you a convincing answer that was totally wrong? Did it make you stop asking co-workers for help?
That specific unreliable coworker who doesn’t properly qualify that they aren’t completely certain … I believe for most people, yes.
We tend not to trust bullshitters.
These chat bots "know" a shit ton and a half of stuff in that they are connected to the largest collection of knowledge known to man, the Internet. But "knowing" and "understanding" are two different things. The various search engines also "know" a ton about where to find things online, that doesn't mean they know shit about those things. And as we're seeing here: without the context to know that when someone wants an IP scanner, they want something good, that won't give their computer malware, that'll be reasonably priced or even open source, or even what platform, it just gives an answer based on a search.
You could just search for ip scanning software and gotten all the information BingGPT shared with the author of the piece.
And like, if you wanted to be charitable, you could say "well the author should've given more information about what they wanted" but again, that's not different from an existing search engine and more crucially: the AI didn't ask questions. Didn't ask for platform, how much they wanted to spend, if they preferred open source, or even something more general like what they were trying to accomplish. Nada. Just did a search, and reported results.
I'm sorry, but that's a stellar example of holding an LLM wrong. These models are frozen in time.
> But "knowing" and "understanding" are two different things.
Indeed, and that is a big part of misunderstanding. GPT-4 is, on many topics, closer to understanding than knowing (note that neither is a subset of the other). The conceptual patterns are there, even if sometimes are easy to accidentally overpower by the prompt, or by the sequence of tokens already emitted.
Y'all keep throwing out these gotcha statements that just make the technology you're trying to tell me is great seem more and more useless.
How can you even attempt to call something artificial intelligence if it doesn't even know the year it is!?
> Indeed, and that is a big part of misunderstanding. GPT-4 is, on many topics, closer to understanding than knowing (note that neither is a subset of the other). The conceptual patterns are there, even if sometimes are easy to accidentally overpower by the prompt, or by the sequence of tokens already emitted.
I don't think it's either understanding or knowing. Someone who knows something isn't going to spontaneously forget it because someone asked them a question incorrectly.
Never actually. My coworkers have never told me something with confidence that they just made up. If they don't know an answer, they may provide hints and directions, but it will be clear they don't know.
Conversely, there are people who I will go to for topics that they are not the SME in, maybe their teammate even is, but I trust their ability to do quality research and intelligently interpret that research for case specific nuances. Like I'll go to the networking guy to talk about some DB thing because the DB guys are morons and live and die by junk SEO sites but the networking guy can think analytically and find the source of truth documentation and provide excerpts from it.
One usually stops asking the bullshitter, yes.
i mean, in many circumstances, we absolutely stop asking them...
when i ask a trustworthy human a question, they will absolutely tell me if it is out their depths. they understand their own limits on around the subject and say so. and if they understand a little, they’ll help point towards people who would be a better authority on the subject.
that’s basic level human connection stuff.
if someone confidently gives you the wrong answer, refuses to know their own limits, and repeatedly leads you astray you don’t trust them after this do you?
F/k/a Putting a thing on the internet for randos to identify and explain. As long as it cites the LLM cites its sources, general questions in the form of "what is this" or "what's going on here" while you point to a page or an image or in a general direction are not well suited for search engines.
Engines like you.com, phind.com, aisearch.vip, or kagi have the advantage because their business model doesn't depend on this
For example, injecting ads and even content moderation to keep ChatGPT from joining Hitler's Youth, could both be considered non-fiduciary functions.
These websites don’t use “AI search”? It seems the problem has nothing to do with AI, it’s the business model.
What question could we ask that would convince you that a hypothetical future system actually understands what it's spitting out, regardless of if it were based on current LLM technology or not?
In the search engine/chatbot context pretty straight forward, having the capacity to automatically correct obviously illogical or non/counter factual info.
Say I do a historical search and bing or chatgpt hallucinate something that's wildly implausible or straight up makes no sense. If it could spot that on its own and say. "I'll consult some credible sources specifically to resolve that, as what I have found doesn't check out" and then comes up with something that's congruent, that'd show understanding.
Same with code. Understanding code would imply something like being able to run a code snippet through a debugger, interpret the meaning of the error message, and fixing what's broken. Right now these things give you nothing more but a stochastic guess.
This is not a philosophical argument about what it "means" to understand btw, just real limitations. Right now it is always the user who has to supplement the understanding and coax these systems into fixing any mistake they make.
https://chat.openai.com/share/0cec4f44-2245-45fd-b4c6-304e10...
Personally, I think we need new words to describe these things. Understanding, thinking, and reasoning don't really capture the meat of what it is and isn't doing. It's very good at a very specific slice of tasks, but it can also get fooled and be shown to be the stochastic parrot that lies beneath. But I spout incomprehensible gibberish when I get drunk, so, honestly, humans do that too.
But that's not what this is being sold as. This is being sold as a universal augment for all search engines. I have yet to see examples of it say, letting you know that a travel destination you're interested in is busy this time of year, and suggesting different dates. Or something like, noting that a car you want to buy has exceptionally bad safety ratings compared to similar models. That sort of thing. Contextual analysis that imparts a feeling, even if fleeting, that it actually knows what it's talking about. Like it seems to with code.
> But I spout incomprehensible gibberish when I get drunk, so, honestly, humans do that too.
Yeah and if you were habitually drunk at all hours of the day, I doubt many people would seek you out for advice?
I think I see your point. If I tell it that I hate rain and want to visit, say, Boracay in August, it'll tell me that it's in the middle of their rainy season, but what you're looking for is a system that has an idea of who you are, and can give that advice without having to tell it that you hate rain, for example. If I ask it about buying a 1953 Chevrolet Bel Air, it doesn't mention safety until I ask it if it's safe, at which point it does tell me that it doesn't have modern features like crumple zones or air bags. Or seat belts.
That's interesting. I find it kind of annoying when Clippy pops up and offers to help, or when Google Home says "by the way... <new feature>", but I can see where you're coming from. It would have to know me and who I am, and offer personalized opinions to demonstrate a thorough understanding of a topic, instead of me having to explicitly ask about specific aspects.
* https://www.vice.com/en/article/epzyva/ai-chatgpt-tokens-wor...
If you ask it, for example, what color paint to use in a given room, it could use a set of assumptions to help inform that decision. Most people use eggshell colors for a slight reflectivity that brightens a room. Most people use warmer colors for similar reasons. Most people avoid super dark colors unless they're into them and they own the home since landlords typically dislike that. On and on. Now does that apply to me, goth ass that I am who owns a home and has an office painted black? No. But I also understand I am not the norm and would not be opposed to correcting the AI of these assumptions.
And, even further, since both Bing and Google operate amongst both tech conglomerate monoliths, they could start to know me personally. Like that whenever I search for new restaurants I look for the traffic indicators because I don't like crowded places, so when I ask about where to eat, it might check for local eateries I haven't been to before that aren't particularly busy today. Or that when I look for electronic home gadgets they need to be compatible with HomeKit, or I don't buy them/am not interested. And REAL HomeKit, not "works with Siri" shit that requires an app and shortcuts.
In my mind, this is what would differentiate AI from just chatbot search.
Pure semantics. This whole class of "it's not AI, it's ML" argument is incredibly tedious, these arguments rely on implicit special snowflake definitions of AI. Arguments like "real AI can understand things" are completely ass-pulled. Who ever said that true understanding, whatever the hell that even means, is a necessary quality of an AI? This isn't taught in any university AI course (which teach even ELIZA as an early form of AI), nor is such a meaning implicit in popular culture, so where is it even coming from?
The difference is more just what output format they give you the results in - bespoke text, or a set of links most relevant to the query. The extra layer of text2text processing probably doesn't add much if the top result already answers your query.
What people really want to do though, is to set custom criteria that synthesise data across multiple different sets to draw novel conclusions that aren't in any webpage. That is probably very expensive computationally though, hence there still being a need for bespoke sites that semantically index data for certain types of queries.
I can't wait for Cupertino to do LLMs. If I'm walking down a street, I could ask Siri "what's the building to my right." It's not noncritical information, just slaking curiosity, and entirely unsuited for a text-based search engine. The way I'd answer it, today, would be to look it uourp on a map or ask someone near me.
The problem is our Gen1 LLMS are all liars. Oops. (Fortunately, so are most kids.) If we can solve the trust issue, where the LLM is able to self evaluate confidence in its answers, it's game over for search as a mainstream product.
Current search is determinative (in theory, Google ad-meddling aside). New search is stochastic. Two queries may yield different paths.
I mean, it's blatantly a new level of dark patterns, but it's being seized up on by the psychopaths and sociopaths for that.
It feels instantly novel.
ChatGPT is badly in need of a content update - too much has happend since 2021.
And naturally ChatGPT understands nothing. We created the Chinese room as software, it doesn't have to understand anything.
I totally agree with you, and I will never understand the core concept either. But everyone should be forced to work for tier 1 tech support for two weeks of conscripted service. The entire job can be summarized by your one sentence, and yet MASSIVE quantities of people insist on getting the first answer from the FAQ read to them by a human bean for some reason.
So in a funny way the AI is bringing easier access to the malware sites than a traditional search engine would. I'm sure the cretins are delighted with Microsoft right now. For the given test question, the first answer in any search engine would have been the official site.
GPT: Due to the global food shortage, many companies are forced to cut back on food supplies. But don't worry, you can still enjoy delicious meals with Soylent. Soylent is a meal replacement drink that provides all the nutrients your body needs to function at its best. Soylent. The future of food.
Love it. Very fun project!
It’s just a matter of time…
Well, I'm sure someone will get killed because AI makes shit up and spreads fake news.
What will you do if the AI talkes shit about you like here: https://cyberplace.social/@GossiTheDog/111145003189474081
Bing Chat says I'm a Smart Home and Linux expert. That's what I get for talking about Node-RED and OpenBSD on my blog...
At this point I'm guessing anything in Azure Repos or private Github repositories are just a small oopsie away from being leaked by some accidental training mistake or misconfigured token.
We're so close to coming full circle with this 30 year old joke...
--
At a computer expo, Bill Gates reportedly compared the computer industry with the auto industry and stated that “If GM had kept up with technology like the computer industry has, we would all be driving twenty-five dollar cars that got 1000 miles/gallon.”
General Motors addressed this comment by releasing the statement: “Yes, but would you want your car to crash twice a day?”
The writing is on the wall. Open source or bust.
The alternative is MS figures out AI and we wind up with Bing and CoPilot peering, evaluating and continually reporting back every thing that runs in/near Windows.
[1] https://ritholtz.com/2013/07/organizational-charts-of-amazon...
MS seems to be taking a page from their own WinMo6 -> Phone7 playbook. Instead of improving the working ecosystem, they go all-in on a half-cooked effort to build something wholly different - and hope that somehow, this finally leads them to gain Apple-like control over their user base.
Access Controller or Modifier, Automated Downloader, Communication Modifier or "man-in-the-middle", Email or Msg Spoofer, Software Backdoor, Rootkit / Bootkit, Website or Browser Redirector, Activity Monitor, Data Scraper, Duplicator, Eavesdropper, Exit Node Logger, Keylogger, Locator, Path Tracer, Sniffer, Snooper, Bricker, Fork Bomb, Logic Bomb, Time Bomb, Adware, Browser "Helper", Crimeware, Cryptojacker, Malware (generic), Ransomware, Scareware, Spyware
Links to the Wiki articles on each topic are at: https://en.wikipedia.org/wiki/User:Araesmojo/Computer_Securi...
Ignore the rest unless you want to read about Shadowrun / Neuromancer / Ghost in the Shell speculation.