187 karma · joined August 20, 2014
Yes, generalizing is how we reason, because it lets us strip away information that is not relevant in most scenarios and reduces complexity and depth without losing much in most cases. My point is, this is not a scenario that fits in the set of “most cases.” This is actually probably one of the most unique and corner-casey example of board dynamics in tech. Adherence to generalizations without considering applicability and corner cases doesn’t make sense.
I’ve spent a decent amount of free time doing what feels like coercing, tricking, or otherwise manipulating GPT-4 and Llama2 into doing my bidding - with my bidding being mostly toy ideas for little tools to make random small tasks easier and one or two more interesting ideas that are fun to mess around with, but would probably require some medical-grade antianxiety meds to even consider using in a real production setting (ie a universal ORM.) Even though I’m not developing (or I guess we now call it prompt engineering) in a rigorous or serious way, I’ve found that making the LLM _actively_ reconsider and validate its output works very well, with the effectiveness seeming to be a rough function of “how actively” you trick it into doing so. Giving a list of “be sure to consider these things” at the end of your prompt often works, but also very often doesn’t; adding another step to the process you’re asking them to perform comprised of subtasks that map to the list of gotchas, but reframed as actions you are requiring them to perform, is often the remedy for cases where the simple suggestion list isn’t enough, and is basically a more active variant of the same idea as providing the gotcha list. Dialing it up a bit more, requiring them to provide an update after they complete each subtask to confirm they indeed performed it and to provide a summary of what they found makes their retrospective assessment even more actively involved, and has been a pretty damn reliable trick for ironing out kinks and known failure modes in my prompts.
All that being said, I think the simple fact that you’re now actively requiring them to reflect on their confidence in their output, and therefore the correctness of their output, may lead to this idea improving the quality of output/results as an unintended side effect that would alone make it worth doing.
As more of an aside, I gave the paper a quick skim and plan on circling back to it when I have more time - are the ideas in the paper an accurate/complete representation of the under-the-hood workings, and general type of optimizations being performed, of the current state of the project?
As another related aside, I vaguely remember coming across this a month or two ago and coming away with a different impression/understanding of it at the time - has the framing of or documentation for the project changed substantially recently, or perhaps the scope of the project itself? I seem to recall focusing mostly on the LM and RM steps and reading up a bit on retrieval model options afterwards. I could very well be mixing up projects or just had focused on the wrong things the first time around of course.
I do not understand your hand-wavey dismissal of the documents I linked to, as I do not understand how you could have checked their contents and came away believing they all discussed Trump-Russia collusion. For example, the indictment I linked to is very clear, direct proof of election interference activities performed by an offensive cyber unit within the Russian military and never makes any implications of involvement by Trump.
Regarding Trump-Russia collusion - since you brought the topic up - the things you are asserting still seem potentially dubious.
A decision to not indict and prosecute is not based on whether it is more likely that the crime was committed than not, but whether or not it can be proved beyond a shadow of a doubt, especially in a scenario like this. It is not 50% sure, not 80%, closer to 99% sure. If you read the Mueller report is is most definitely not a conclusive exoneration of Trump. You cannot honestly argue that collusion did not occur because Mueller did not indict.
Opposition research is research funded by opposition. That does not imply that the output of the research must therefore be asserting the opposite of the reality of its subject matter. I don’t understand this point.
Somebody who was a source for Steele, who is ex-Western intelligence, also being a source for other components of Western intelligence like the FBI seems wildly unsuspicious. Of course, the Post tries to spin it anyway, which is unsurprising for media outlets in general today, but particularly unsurprising for this particular outlet.
Basically, I am not saying that collusion did or did not occur, because I do not know. And if we do truly live in the same universe, you do not know either, you just think you do.
- https://www.justice.gov/file/1080281/download
- https://www.intelligence.senate.gov/sites/default/files/docu...
- https://www.dni.gov/files/documents/ICA_2017_01.pdf
- https://www.intelligence.senate.gov/sites/default/files/docu...
- https://www.justice.gov/archives/sco/file/1373816/download
Spending some time flipping through these (ignore the last two if you please, one heavily redacted and the other focusing on Trump) after reading your comment makes me wonder if we live in two parallel universes that are in the process of converging.
> but the focus of the Twitter files in this regard is clearly specific to the false Russia Trump connection propagated by Dem polticians and leftists.
Which makes the comment I was replying to (which is the comment one level above mine, not two levels above mine) even more incorrect, as it claims that the Twitter files prove that Russian meddling did not occur, which is a claim orders of magnitude broader than the claim that Trump-Russian collusion did not occur.Let's start with a concrete example, like the 2016 DNC hack and subsequent document leaks. US intelligence agencies, and private cybersecurity companies that helped handle the response and investigation, have all claimed with high confidence that an offensive cyber unit within the Russian military had carried out the attack. I assume you are familiar with this example and the corresponding reports/indicment, but I would recommend skimming the indictment for a refresher (https://www.justice.gov/file/1080281/download) while paying particular attention to parts that relate to the observable events that implied election interference-related motives, like:
on or about April 15, 2016, the Conspirators searched one hacked DCCC computer for terms that included “hillary,” “cruz,” and “trump.” The Conspirators also copied select DCCC folders, including “Benghazi Investigations.” The Conspirators targeted computers containing information such as opposition research and field operation plans for the 2016 elections.
With this example as a jumping-off point, here are some questions off the top of my head:- Do you believe (1) that this incident did not occur, (2) that the incident did occur but was a case of misattribution, (3) that the incident did occur, and was executed by the GRU, but was not done as part of a broader Russian government effort related to the US election, (3) that the incident did occur [...], but that the broader effort does not constitute election interference?
- Do the Twitter files include any evidence that the indictment, conclusions of the federal investigation, and conclusions of the private investigations were false? This is a genuine question, I read the early tweets but did not believe continuing to read the later ones was worth the time. Twitter & this incident were intertwined from the very beginning, as the GRU had created a fake Twitter persona for leaking documents, so I would assume there are some files somewhere inside Twitter related to this.
- Your first comment rhetorically implied that "Russia meddling" was a fabricated story, while your second comment changes the framing and refers to "material Russian interference." Is the root of this disagreement that you believe a successful outcome is required for activities to be deemed election meddling/interference? If so, what do you think a reasonable definition of "outcome" is in this context - the ultimate outcome of the election, the outcome of a single voter's time spent in ballot box, somewhere in between? Is your belief that meddling was attempted, but not successful and therefore not ultimately meddling? Are you aware of any estimates of impact of claimed meddling, and/or the methodologies used for estimating it? Personally, my answer to the last question is "no," and I think the most likely case is that the election outcome would be identical in a parallel universe where Russian does not exist, but I personally don't believe that makes the issue significantly less concerning. Your first time doing anything is usually pretty sloppy.
- If yes to the above, let's say you were to learn that a foreign government was preparing for an election interference campaign related to an upcoming US presidential election. Would you find this problematic enough to warrant government response and public awareness via media coverage, even though you do not yet know if the operation will be successful? If government response and public awareness are important in this scenario, are they not also important in similar scenarios where our awareness of the campaign does not come until after the campaign has concluded?
- Taking the above a few steps back: would you consider efforts coordinated by a foreign government with the express goal of influencing the outcome of a US election to be election meddling? If not, does your opinion change if the efforts intentionally used misinformation as a weapon for achieving the goal? If still not, does your opinion change if the efforts are performed covertly with the intention of avoiding attribution? Are there any additional factors that you would consider requisite here?
- If yes to any of the questions in the above bullet, other the last one, then do you simply believe that the Russian government did not coordinate any such activities, including covert activities that made use of false "information" the actors knew to be false, occurred at all throughout the past two election cycles?
- If yes to the above, can this belief can be entirely supported by the information in the Twitter files, as your first comment implies? As in, did the Twitter files alone contained sufficient information that all claims, reports, and associated details of Russian election interference were fabricated?
- In making this claim, are you confident that you are sufficiently aware of the various information and evidence that has been released, by both government and private entities, that was used to back claims of Russian meddling? If not, is there anything else you have read or learned that helped you become comfortable with claiming this information and evidence were false/fabricated even though you are not aware of what the full scope of the information and evidence is?
- Do you have any theories as to how private companies were coerced or tricked by the US intelligence communities into release false conclusions that supported the government's desired narrative? They must have had to be doing significantly more than second-hand moderation of tweets if your claim is valid, so do you have an idea of what else they were doing?
If this was indeed a sarcastic comment, I would consider dialing back the subtlety so you don’t inadvertently appear to lend credence to misinformation currently being spread among less scrupulous portions of the population.
Regarding the assumptions you list:
1. Information regarding Russian activities in cyberspace is the most relevant category of "possible" anti-Russian propaganda related to the topic you bring up, and what I believe most people will imagine when reading the words "anti-Russian propaganda" in your comment, regardless of whether or not you had it in mind when writing them.
2. Do you have an example of reporting on this topic whose primary points have proven to be inaccurate, even if unintentionally? I would go as far to argue that the amount of realized and attempted damage caused by Russian cyber actors, and the audacity of some of the operations, would significantly reduce the need for entities pushing anti-Russian narratives to fabricate or twist facts.
3. There is a chance that, after arguing the semantics of the word propaganda, you could convince me that accurate reporting of facts regarding cyber attacks against our nation could be technically viewed as propaganda, based on some definition that doesn't include terms like "misleading" or a book on the topic that I have not read. However, I don't think that really matters here, because for the significant majority of people the term "propaganda" carries implications of incorrect or misleading information, and I believe the effects of these types of claim can do much more harm than a comment derailing a conversation, like mine.
Unfortunately, the answer is largely no. Phishing emails containing malicious documents, now sometimes accompanied by call center operators priming the victims or walking them through the process of infecting themselves, are to blame for a large number of ransomware attacks. Exploitation of recent vulnerabilities (i.e. a handful of CVEs from 2020 affecting VPN devices) is also often used for initial entry, as well as plain old bruteforcing RDP servers and the like. Some groups have begun to invest in in-house vulnerability research teams but I have not seen much come from that as of yet, aside from implementation of exploits for existing CVEs.
> but on the other hand how are these networks and computers actually getting compromised with what appears to be such speed and ease?
The scale and architecture of some of the larger cybercriminal groups responsible for many of these attacks parallel your typical silicon valley startup. One of the larger groups has dozens of employees across a range of different focus areas/departments from malware development, infrastructure management, crypting services, redteam operators, ransomware negotiators, layers of management, etc. These groups work with other affiliate groups which only accelerates the process from initial infection to ransomware deployment, with affiliate groups that blast out malspam broadly as well as to curated target lists often responsible for supplying the steady flow of infections to malware-as-a-service platforms that provide the ability to view and manage bots to yet another set of groups that drop secondary payloads like Cobalt Strike and begin the process of lateral movement towards the domain controller so the final ransomware payload can be deployed. These groups have employee handbooks, training videos, slack-like chat services, Gitlab instances with dozens of projects, CRM-like tools for victim management, and even (in at least one case I'm aware of) physical offices in Russia.