26 karma · joined December 28, 2023
OpenAI is bending over backwards to research and win those juicy government contracts to ensure their place as a strategic supplier worthy of protection and bailouts as needed.
Seriously though, it would be interesting to learn how these ended up being targeted. Unfortunately there's lower odds of full public RCAs with governments.
I think they are working with customers to improve the LLMs and tools for these use-cases. They almost certainly also hire experts to help filter out nonsense, pseudo-science and help curate trusted knowledge bases for training, but it will almost certainly be the customers who deliver the major results, and the AI companies will claim some of the credit. That said, patents for important medicine might help with the bottom line, so I could imagine partnerships and JVs.
> at the very least it will be a good tool to help researchers do their jobs.
Indeed.
It makes more sense to leave curing disease & cancer to the experts, with tools (like AI) being developed by AI experts.
Call me crazy, but I want separate organizations and experts for medical vs finance vs space vs climate vs AI research.
Correct. Every home wifi router worth its salt will firewall incoming connections by default, whether v4 or v6. It's then possible (unless it's some shitty ISP-provided locked down device) to add specific allow rules, or allow all for a particular client.
egress is typically wide open, although sometimes they lock down particular protocols by default (eg. smtp, bittorrent)
One may as well say "given unlimited budget".
https://netflix.github.io/chaosmonkey/ and similar can help.
That said ... most instability is introduced with normal changes, so every engineer can be a chaos monkey. ;-)
Software has a huge surface area these days. That a trained software engineer isn't aware that HIDs and input subsystems are often highly hackable from userspace is no surprise to me.
They may also have been leaning into a compliment of OP in a self deprecating way.
shrug
Not everyone has had the same experiences, interests, or life/work opportunities in the same way, and this person seems genuinely interested in learning more. It's something to be encouraged.
I think the bigger personal challenge is to not outsource thinking, understanding and judgement as we leverage new tools, and to continue our personal learning journeys. After 20+ years as a software engineer, you can probably coast on past experience for a long time... but if you aren't learning and exercising (one way or another), your skills will stagnate. That would be sad.
That's configurable in codex.. but there is a higher cost/usage to using it.
The failure is likely in detection, where they assumed traffic to internal systems (eg. Artifactory) was inherently safe. Which is a daft assumption at this point.
At the same time, I use the Q&A cycle to improve my vetted knowledge base, which I also share (and can reference in answers).
I do a lot with orchestrating cloud infra, provisioning and deprovisioning workflows, lifecycle management, updating CMDBs, access management, deployment automation, auditing configurations, and some APIs in front. The code is boring, mostly glue. The agents nail it quite consistently, especially with some guidance.
I do know what I want out of it, and that is deterministic quality code to solve specific business problems, so that we don't have people (or their agents) running amok.