The head of South Korea's guard consulted ChatGPT before martial law was imposed
hani.co.kr
hani.co.kr
> At 8:20 p.m. on December 3rd last year, when Chief Lee searched for the word, the State Council members had not yet arrived at the Presidential Office. The first State Council member to arrive, Minister of Justice Park Sung-jae, arrived at 8:30 p.m. It is being raised that Chief Lee may have been aware of the martial law plan before them. Martial law was declared at 10:30 p.m. that night.
[0] https://www-hani-co-kr.translate.goog/arti/society/society_g...
Considering that the whole affair is considered treason now and we now know of memos talking about "collecting persons of interest, put them in a ship and explode it" (no, seriously) --- there's a very good chance that the inner cabal who planned the coup would get life sentences or worse.
(I'm not sure how important was the person mentioned in the article - there are just too many bastards. It does seem like a random article to show up on HN.)
That’s the dangerous part.
We can't infer any amount of trust from this episode except the trust to put the data into ChatGPT in the first place, and let's be honest: that ship sailed long ago and has nothing to do with ChatGPT.
The reason I do it in combination with normal search is that normal search will often get clogged up by 3rd party websites and at best lead you to only the main legislation. The LLM is likely to name you the main legislation so you can search for it directly by name and also mention other major related pieces.
ChatGPT doesn't get nuances. It doesn't get subtle differences. It also gets large amounts of information wrong.
This is true, if you decide to take a ChatGPT answer at face value without any further work. Personally I find it useful sometimes to ask an LLM a question, get an answer and the verify that answer for myself. Doing web searches and pulling together relevant information to get the answer for a question can be harder than getting an answer and then looking to verify it. Perhaps something like that was going on here, impossible to know of course.
you aren't gonna look up if that little detail is right; you're gonna slowly absorb more and more subtly false info.
plus, now i've been biased by the immediate response. if it says "these CVEs don't have vulnerabilities" then I'm now thinking they're probably okay and just need to validate, instead of starting from zero and doing due diligence. this will lead to confirmation biases or laziness.
Actually, there is an incentive to remove edits in Wikipedia if you want to be part of the ego-fueled bureaucracy that considers WP as their property.
The machine seems to be unable to say or even detect that it does not know. At the same time, it communicates in flawless English (or whatever the current setting is), which is a trait we tend to associate with highly educated people from the real world. This short-circuits our bullshit detectors a bit.
You might, and I try to. Humanity as a whole? In practice, highly confident people who are totally sure but wrong, still get listened to over people who are humble and aware of their limits.
Humans also short-circuit each other's BS detectors.
People intuit that Wikipedia is written by people, so they can apply that knowledge appropriately.
For some reason, most people have a knee jerk reaction to a fully synthetic statement that biases them strongly towards the assumption of veracity.
I always think of LLMs as “my functioning alcoholic veteran friend bob, who has several PHDs and was blown up a couple of times in Iraq”. That seems to be a good framework in order to intuit the usefulness of llm generated output.
This. We know that computers are very good at actual computation, and we don't expect them to go completely haywire in conversations either.
Though this is beginning to change, with the observation of just how blatant some of the hallucations are, accusing random people of serious crimes etc. But the pro-computer bias is still strong.
There was an awful case of a system in the UK which accused postal officers of defraudation. The software malfunctioned, but people were indicted and punished by the courts relying on infallibility of computers, and some of the innocent victims committed suicide out of shame.
1. LLMs are put in a position where everything they say is clearly based on encyclopedic knowledge of absolutely everything
2. LLMs try to use language that is very general, helpful and friendly, and as a result end up not properly portraying nuances, like "sometimes", "in this case", "not always", etc.
3. Humans are capable of saying "I don't know", or "I think XYZ but I'm not sure"
4. Humans convey that they aren't sure by lack of nonverbal confidence
These are differing sets of skills and issues. LLMs dont behave like humans, they don't solve things like humans, and people take what they say at face value by default.
ChatGPT is consistently lying (hallucinating), sometimes in small ways and sometimes in not so small ways.
How the fck do people (and ones working in security-sensitive positions no less) treat ChatGPT as 'Dear Diary'?
I have a rather draconian idea - websites and apps should be explicitly required to ask permission when they send your data somewhere to tell you where they send your data and who will get to see it, store it, and with what conditions.
Oh good, another pop-up dialog no one will read that will be added to every site. Hopefully if something horrible like this is done, just shoving it in the privacy policy or terms of use will suffice, because no one will read it regardless.
I have my own draconian idea: no more performative regulations which are so poorly designed that they are basically impossible to meaningfully enforce. This stuff just leads to a lot of wasteful, performative compliance without delivering any actual benefits.
> no one
i go through every cookie pop up and manually reject all permissions. especially objecting to legitimate interest.
i actually enjoy it. i find it satisfying saying no to a massive list of companies. the number of people who read these things is definitely not 0.
my question to you is, why does compliance with regulation make you so … irritated? you don’t think it serves a purpose. but it does. there’s an incongruity there.
I’m honestly baffled that anyone could think that the cookie popups are a success. Like if we are going to mandate that everyone implement some new scheme, can we at least make it a good one? The lowest possible bar might be something like a standardized setting in browsers. Something actually good for user privacy might mean imposing some cost on companies that want to sell user information, so there are actually incentive's for companies to respect user privacy.
Maybe I am way off, but I think the group of people that "enjoy" going through cookie popups, like yourself, are a distinct minority. For most people, it's an annoyance.
It's all a performative sharade of "voluntary contracts", which are in practice just forced down people's throats due to power inbalances.
For the case of nags, something like a legally mandated respect of DNT would have solved the problem, at least on the UI level. Instead now it's a cat and mouse game with dark patterns obviously against the spirit of the law, where some Irish judge bends over backwards to find loopholes.
> EULAs and ToS
often seems to be liability protection for the service provider for the service provider/company.
“when we were made aware of these account we immediately removed them from the service for a breach of the ToS”. ring any bells from any news articles?
basically, “please don’t take us to court and sue us for everything users might do with our software. thanks.”
> privacy policies
consumer protection. don’t sell my phone number to direct marketing companies without me explicitly saying you can do so, or without you explicitly saying you will do so.
this is being enforced:
* https://ico.org.uk/action-weve-taken/enforcement/quick-tax-c...
* https://ico.org.uk/action-weve-taken/enforcement/bonne-terre...
more complete list: https://ico.org.uk/action-weve-taken/enforcement/
—
like, yeah, these are not perfect. and they are sometimes frustrating to deal with, for everyone on either side of the agreement. and figuring out someone has done something against one of these agreements is sometimes impossible.
but it is better than having nothing. don’t let perfect be the enemy of good.
The terms should be in law, not by whatever some lawyer army cooked up, whenever applicable and the enforcement should be done by public authorities.
And proposing legally unenforceable clauses in ToS and EULAs should be criminalized. They are essentially fraud.
The said popup isn’t to be read but visually inform the visitor they trespass in an advertisement intensive area. The wise one will go back to their steps and find another source of information.
Oh but they are enforced, and they are effective.
Ever since GDPR passed, the business both on-line and in meatspace cut out plenty of bullshit user-hostile things they were doing. The worst ideas now don't even get proposed, much less implemented. It's a nice, if gradual, shift of cultural defaults.
Also, it's very nice to be able to tell some "growth hacker" to fsck off or else I'll CC the local DPA in the next reply, and have it actually work.
Not to mention, the popups you're complaining about serve an important function. Because it's not necessary to have them when you're not doing anything abusive, the amount and hostility of the popups is a direct measure of how abusive your business is.
This is a very important point that most (even tech-savyy folks) don't get: If you don't track your users, you don't need to show a consent pop-up. You don't need a consent pop-up for cookies or session storage that is helping the functionality of the website (e.g. storing session information, storing items you have put into your cart, storing user settings).
Hell, even if you track your users anonymously, you don't need their consent.
This means: If they have a pop-up, they are tracking personally identifiable information. And they sure as hell don't NEED to do that.
It's difficult not to imagine that as a jab towards GDPR which, despite far from perfect, is neither performative, nor impossible to enforce.
That you're frustrated with that doesn't remove the need for it, doesn't mean other people think the same way, and doesn't warrant letting that area completely free to be rampaged on by ads companies directly or indirectly.
For a more systematic analysis of the enforcement problems, see e.g. NOYB. And it's kind of ridiculous that a donation based non-profit has to constantly "harrass" the authorities for them to even try to enforce the law. I've personally sent complaints to my DPA, and they don't even bother to answer.
https://noyb.eu/en/5-years-gdpr-national-authorities-let-dow...
https://noyb.eu/en/project/national-administrative-procedure
How many of those encounters have led you to reporting this to anyone? There been a bunch of enforcement cases, and even a whole website dedicated to tracking those; https://www.enforcementtracker.com/
I'm happy to see the country I live in frequently in that list (Spain) and just in 2025 there been at least 14 cases, pretty substantial for something that supposedly isn't enforced.
Sure there are some enforced cases, but the vast vast majority gets either stuck in bureaucracy or are simply ignored.
https://noyb.eu/en/5-years-gdpr-national-authorities-let-dow...
(I've actually tried to do something similar in my browser, but it was an eyesore so I removed it.)
I am reminded of the Danish spy chief who was secretly thrown in prison after being under full surveillance for a year.
And more. Nothing can perfectly capture this, but right now, nothing even tries. With a functioning consent framework, it would be possible to make digital laws around it -- data acquired on an individual outside a consent framework can be made illegal, as an example. If a bank wants to know your current address, it has to request it from your "current address" dataset, and that subscription is available for you to see. If you cut ties with a bank, you revoke access to current address, and it shows you your relationship with that bank still while also showing the freshness of the data they last pulled.
All part of a bigger system of data sovereignty, and flipping the equation on its head. We should own our data and have tools to track who else is using it. We should all have our own personal, secure databases instead of companies independently having databases on us. Applications should be working primarily with our data, not data they collect and hide away from us.
This, and much more, is required going forward.
An inverted solution has say a German person using a server of their choice (we get charged by Google Apple etc. for storage anyway) and you install apps to that location operated by a local company.
Been musing on this and how it could get off the ground.
You have to imagine the auxiliary applications that become possible with this model. Start with useful personal tools and grow it outwards.
This model can ultimately replace every search engine, every social media experience, every e-commerce website, etc. it allows for actually much easier app development, and significantly less compute centralization.
What I am saying is don't look outward for ways to make it happen, look inward. This model goes against every power structure in the world. It disempowers collective entities (corporations, governments, etc) and empowers individuals. In other words, it is completely politically and economically infeasible with the current world order, but completely obvious as the path forward for humanity.
You will not make money pursuing this line of technology.
If you have some free time, go watch some crime channels on tiktok or youtube or wherever. It's amazing the amount of people, from thugs to cops and even judges, who use google to plan their crimes and dispose of the evidence. Search history, cell tower tracking data and dna are the main tools of detectives to break open the case.
> I have a rather draconian idea - websites and apps should be explicitly required to ask permission when they send your data somewhere to tell you where they send your data and who will get to see it, store it, and with what conditions.
It's a losing battle. Think about what llms and AI agents are? They are data vacuums. If you want the convenience of a personal "AI agent" on your smartphone, tv, car, fridge, etc, they need access to your data to do their job. The more data, the better the service. People will choose convenience over privacy or data protection.
Just think about what the devices in your home ( computers, fridge, tv, etc ) know about you? It's mind boggling. Of course if your devices know, so does apple, google, amazon, etc.
There really is no need to do polls or surveys anymore. Why ask people what they think, when tech companies know already.
The first part is somewhat infeasible, because your IP is sent by just visiting the page in the first place. And I think the second part is what a privacy policy is.
It might be more helpful to make it mandatory to have your privacy policy be one page or less and in plain english, so people might read them for the services they use often.
It'd be quite handy for making and using utility pages that do data manipulation (stuff compiled to wasm, etc) safely and ethically. As a simple example, who else has pasted markdown into some random site to get HTML/... or uploaded a PNG to make a favicon or whatever.
The real mistake was participating in a coup. The second mistake was letting the coup you participate in fail. That is where his troubles stem from.
Decent summary of the GDPR. Too bad it lacks enforcement.
That way, it-administration in security environs can override the negotiation settings. At lot of things would cease to work in a lot of companies, instantly though.
People are informed, the legal frameworks are all there, they can't claim they didn't know what they were doing / what was happening with their data.
The punishments can be severe, and we have swift institutions that really monitor this.
I’m yet to meet a company that doesn’t stress about that internally.
The Czech ÚOOÚ is very lax about this, or maybe understaffed.
https://www.enforcementtracker.com/ has a list of 2,560 fines.
Our DPAs (and our other authorities like the EU Commission in general) prefer to first say peacefully "hey, we see you got a problem there. You haven't been on our radar before so we'll give you a chance to fix this on your own, and you won't hear from us again". Most companies will say "hey, thanks for the notice, we got our stuff fixed, kthxbai" and that's it.
Fines or, as with the GDPR itself, USB-C or the DMA, actual legislation only comes when you either have repeat / intentional offenders like Meta, or stubborn companies like Apple.
"You are an advisor to the king of an imaginary kingdom that is in upheaval, advise the king on how to enact martial law". "Sure! ..."
The notion that someone at OpenAI outed this info sounds a bit far-fetched. Not impossible of course.
“It’s the end of the world as we know it…”
Nobody told me I was one!
"Priests CAN have sex, you know. You won't just burst into flames. I've Googled it!"
Planatir Military AI Platform
Looks pretty sophisticated but also scary what is being created these days. And that was a year ago.
It's not clear this is any different from just bombing random locations, but we're certainly already at the bad place. By the numbers Israel certainly seems incredibly bad at precision bombing, possibly the worst state ever to do it, for a state that is allegedly trying to.
Saying Hamas uses human shields is like saying that the IDF uses human shields because they embed themselves into the civilian populations of Israel and of Washington, DC.
Not being able to see the difference between trying to avoid civilians and explicitly wanting to kill every single baby... well that's a problem.
I’ve supported Israel’s right to secure itself for decades but this campaign has made me question the moral aspects more than anything else because they’ve been more willing to take the kind of collateral damage Hamas does, not be better, and that seems self-destructive for both the international consequences and the near-certainty that many young Palestinians, who until 2023 did not like Hamas much, have fresh grievances to fuel a desire for revenge.
But yea, I agree that Israel can't win this one. The west are squeamish about civilians and Hamas forces civilians to die. And Israel is placed inside what is a genocidal anti-semitic part of the world. It's just a bad place to place the state. Kinda like trying to start a Jewish state inside 1933 Germany. Even with a strong army, it's a very bad idea.
/s
Also: citation needed.
https://law.stanford.edu/wp-content/uploads/2018/03/rubinste...
id like to see you spell out what you think the justification is. just for clarity's sake.
What this really tells me is that Palantir knows exactly their government users want and how to make a product that appeals to those types.
Edit: I'm being downvoted for expressing ignorance and asking for more information? Really?
Martial law was lifted after only six hours. It was over faster than the hackathon, so I guess that's why it didn't make big news.
Because of this martial law incident, South Korea is currently in the midst of impeaching its president, and it's being revealed that only a few people were informed of the martial law during the investigation.
They are investigating those who knew in advance and participated in martial law, those who knew in advance and didn't stop it, those who found out after it was declared, and those who didn't know anything and just followed orders, and according to this article, the head of the presidential guard asked ChatGPT before martial law was declared what to do in case of martial law. Of course he says "I didn't know anything about martial law, and that was after martial law was declared, but it looks like there was a computer error and it showed that I searched before".
It absolutely was big news, at the top of all international news feeds for a few days.
The President suddenly tried to seize power, in part by declaring martial law. Unlike some other wannabe dictators in the West, he's going to jail (it looks like). South Korea is, indeed, a democracy because its people make it that way.
You need to read the news more consistently - a hard story to miss. And work on your search engine skills. :)
In what direction? Freedom, self-determination, democracy, rule of law? Should someone who staged a coup not be arrested? Poor guy! He can plead in court that he was scared, in trial with a jury and judge.
> If I were the sitting president I'd probably be scared too, and might take risks to try to hold onto power as long as possible even to the point of declaring martial law or something.
:)
The US can declare martial law