1,160 karma · joined January 2, 2019
amen brother.
The second best part is either getting really good at patching every single thing, or playing the POA&M game.
We did an analysis across all the HSM hardware vendors and found, unsurprisingly in hindsight, that all of these hardware vendors had all the same awful security practices as every other enterprise hardware vendor, and each had vulnerabilities that leaked private key material.
The conclusion was that cloud providers fronting managed HSM had more to lose than the hardware vendors did, and would be more likely to patch and address these kinds of issues.
What surprised me was my own reaction, I thought for sure managing our own HSM hardware had to be a better guarantee over the key material, but like many things, it turned out to be unscalable security theater.
Let's skip the strange purity tests and engage in good faith discussion.
There have been hundreds of MUD clients and many of them were not purely text based at all. Many had images and map screens built in.
It seems like you are more interested in being a doomer than engaging in good faith discussion. I'll pass on the defeatist doom porn.
I'm not sure if your intent was to come across as having written this yourself, but it did not have the effect of improving my perception that this approach is flawed.
I was also disappointed that you didn't address the variability in scores. I'm inferring that you believe the larger model takes care of the main observation in the post, but I don't really see you directly addressing the points.
Maybe it's just me.
Been in the security industry a long time as a software engineer. Security research is no different than any other engineering discipline. It is down to the time you are willing to invest and where in the abstraction you focus.
All of this pearl clutching and hand wringing over the capabilities of the models is silly to me. It has much less to do with some magical cybersecurity ability and much more to do with increasing ability of models to stay on task for long horizons. Any passionate engineer will recognize this - if you grind 10,000 hours you will find the solution to most problems, the problem is most people lack the motivation to even start, and are too risk averse to play hacker.
The NSAs claim that all government systems were hacked by mythos and they were shocked by that is farcical. They have been hacked over and over and over by many who took the risk and tried.
It's like they hired a competent red teamer to do internal pen testing for the first time, which we know is absolutely not the case. They have been doing it for years, and almost certainly surfacing the exact same kinds of findings each time, but they haven't been honest with the public about it and can scapegoat mythos now.
The question is do you care? if a user asks your chat bot for baking instructions and gets them, does it matter?
The answer depends a lot on what capabilities your agent can leverage via tools and your intended use case, but it's not something you defend with Java or spring, it is inherent the llm.
Someone else blindly operating an llm on a corpus you created with an llm is comical.
You don't have to teach a monkey language for it to feel sadness.
The irony of systems of record is that if there is more than one, there are effectively none. Just data stuck in silos waiting for compute.