284 karma · joined March 18, 2019
[ my public key: https://keybase.io/jimzhou; my proof: https://keybase.io/jimzhou/sigs/5542hVA_DUqiel7JlfbKdp9gWCY9XNaLMiMgRaQf0ZQ ] wonderfuldev_jn85tk9qvounx4pq2bpjmixw
Sometimes the outcomes are comical. I just received an automated email from ElevenLabs saying that its automated systems have detected that I may be using its services to create voice versions of materials that harm children. I had it prepare audio versions of several books and academic papers about moral panics that conjured up out of nothing... about harm being done to children. At least that's what I assume. Either that or somehow I had an API key leak from my on-premise homelab, but the usage recorded would mean that they are basing a semi-conclusion based on a tiny sample. I have no distributed any of the outputs, I own the books and have access legally to the studies, because I have a background in the humanities. I also have no children, which ElevenLabs better not know, although how studies of moral panics can cause any harm in children of any kind is literally unimaginable. It's a waterfall of potential errors summed up in a vague email. My API key and the web interface works just fine regardless.
It's one thing if this is a product in beta, but this is their production model. Harming children is a serious accusation except the legal concept impossibility and the admission that this was not an actual lawyer (like I am) but some effective form letter hedging the vaguest of accusations made by some model lacking the ability to discern substance and meta-substance makes it frankly hilarious, and wildly irresponsible. I realize that by academic credentials I'm out of my lane but by experience I am certainly not, and they should recognize when they should stay in their lane and not just run Jev and think it's fine and dandy when done unsupervised (I presume).
Also, AGI is by definition asymptomtic surely, since there would be no way to benchmark it in a manner that isn't asymptotic. We're nowhere close to that. But we're so far from that, it's comical that people who clearly have zero idea of either the technical or conceptual aspects of basically a piece of software that is very good at quickly bruteforcing the correct or acceptable next token to be anything more than that. Even with some serious training and many hours spent on vast.ai I've yet to have created a version of a frontier model that is actually "good" at hacking in my own homelab setting. Although the the time stock Fable 5 missed a favicon shell on a basic jar (turned out they nerfed the hell out of it, this is why I only pay for the massively discounted tokens from Chinese proxies if I'm using American models or sometimes the freebies if you figure out how to get onto linux.do or similar sites). If anyone reading this is a high school English teacher, please inform your class (assuming the homeric stuff is still being taught) that there's no upside of being Cassandra but the record itself, and that should be enough.
AI is trained on these flaws. These aren't flaws that can easily be fixed. The ramifications can be significant. Garbage in, garbage out. Records, however official, are wrong all the time. I have an entry in my "criminal record" from a clerical error that is attached to no charges but 4 days in LA County Men's where I had a seizure, which can be interpreted as the record being correct but incomplete or a giant screwup. What sort of process would it take to fix this if the AI decided on the latter? It doesn't affect me, but someone less privileged? Absolutely it will have consequences. Worst of both worlds indeed. People routinely forget that LLMs ARE NOT PEOPLE. Mistakes get compounded. Biases if not caught in time get baked in. There are multiple AI safety dialogues that should be happening but you wouldn't know it from the media, and it's the wrong one that is front and center. You can rotate keys, you can roll out patches, you can't open up the corpus and use a scalpel and cut out the errors and omissions and biases, and the latter aren't logged.
We don't have enough people who possess professional expertise in widely varied fields that nevertheless intersect in the conversation. This might be because there aren't many people that fit the descriptor, but these are the blindspots. Anyone talk to Orin Kerr lately?
Sadly it has been whittled down and have not caught up with tech - it's a lagging indicator at best. Things like the third party doctrine, automotive exception, pretext stops, etc. are things that should enrage anyone who cares about the most fundamental rights we have not just as Americans but as people, individuals, private persons, who are fundamentally equal to each other if not in circumstance but at least in substance. The courts sometimes even mis-states their own doctrine and usually in favor of the state. Why is there no good faith exception the other way? Any idiot can see that the plain view doctrine opens a pandora's box. We don't need the NSA for our rights to be handwaved away, that's already done.
The NSA does not testify in open court, and we can only speculate what they are able to really launder down into the criminal justice system. But considering that the state of the 4th Amendment have already made the system extremely coercive with limited recourse in so many "exceptions" that are no where near the intent of the framers of the Constitution and frankly tilts the ice more than any crooked lower league Russian Hockey match, it's likely not even necessary for them to jump in most of the time.
I suspect that the greater influence they exert is through the military-industrial complex in its modern day form. We're the only country that can just waltz in and invade.. what, 7, 8 countries? Has anyone been to China lately and have the connections to assess the state of their military and economy with clear eyes? Do people see the laundering of BS national security concerns into reputable papers and conspiracy rags alike? It's usually innocuous sounding, but no small part of the economic quagmire comes from the continued funding, justified by the agencies that are the constituency with a vested interest, of this pit of unaccountable money. We'll be paying for it either way, because not enough people care, unfortunately.
Context:
https://archive.org/details/a-20071-1
Raw data:
xref
xref
The correct way to address this had always been to modify or entirely get rid of the CFAA and start from scratch with a framework that actually works, that isn't punitive, that make some sense, that did not come into existence thanks to Ronald Reagan's admiration for the uncanny realism in the 1983 film WarGames. But we have a constituency now that relies on the inefficiency machine for their living and their votes will be in their self-interest, security be damned. The best people have been sent on a fool's errand for generations. The incentive structures are entirely misaligned now. I published a PoC last weekend that indirectly but pretty clearly shows that the FBI was relying on an anonymous twitter's account's assertions, none of which were going to be admissible in court in the alternate universe where that matters, to avoid saying "I don't know" by blaming North Korea, something that someone with open source tooling that existed back then, who have never taken a STEM course past 11th grade AP Stats, whose terminal degree is a JD, could whip up and test in under an hour, probably shorter except my home lab with the GPU was occupied. We go through the motions but really, those with power are relying on the inherent imbalance of power and well, lying, essentially, to keep order. How is that sustainable?
The whole model needs to go but it likely never will and that's perhaps the real legacy of Reagan and our moribund power structure. Looking at the payout rate in hackerOne's heyday, why would anyone ever report anything to the companies? My assumption is that people who have any rationality are doing just that. Most data breaches are never disclosed officially but at best passed in rumors. I have no hard evidence that I can disclose, but the least leaky operation is a one-man operation and attorney-client is forever.
By the way, your AI benchmarks in the legal realm aren't tested on criminal matters because how do you benchmark two probablistic systems that are both subject to the prisoner's dilemma and imperfect information? If they did the score would likely be low. You'd need to build out so much back-knowledge just to set up any scenario that really any answer is "it depends" is not a joke but the best answer. Any suggestion that we simply take the status quo as is and run with it cannot be taken seriously. It's a foolish system made by clueless men who hit the lottery and didn't even see the ticket until years after. It was then exacerbated by politically ambitious AUSAs who do not care about getting the right person behind bars but someone behind bars. Fast forward 30 years and this is the state of things. Your sophisticated defenses may have been thoroughly hand-reversed years ago but to dodge the DMCA the source was put somewhere like Gitee instead of Github. I'm not sure if you can finish the signup flow without a Chinese ID at this point, but a decade ago you can, at least. Those are outliers too, but outliers in charity. Good luck with the rest. I'm not being cheeky: just because there's a vulnerability does not imply knowledge to how to maximize its impact. Data breaches are put in the open frequently because of petty feuds and a failure to recognize the importance of the data. After all, China does not run on private credit, and hence, your identity being stolen there is virtually meaningless, as meaningless as you having next to the biometric ID card data of all of their citizens. Like harm, value is contextual, and constructed so that it's framework dependent, and we at least know the frameworks that exist broadly. And what you don't know, well, you don't know.
You might have to shadow library this one, but it's a good read. Interestingly it seemed to be something entirely separate from Bernays whose observations were based on a derivation of what began as a homebrewed effort in a corner of the market. Valerie Steele wrote extensively about the trends and the after life but the source seems to originate in corsetry and ended up being copied by the garmet industry generally in the 20s.
People have been talking about late capitalism in the west for a century. The Chinese state would argue that we cannot be in late capitalism because we're actually in the first stage of socialism, and the people would wonder how we got to late capitalism when they never got to experience early or middle capitalism. But really the only thing we know that definitively does not work is implenting Marxism and Marxism-Leninism and Maoism and its offshoots as doctrine. Whether that means that the default is a prescriptive version of capitalism is, well, open to debate, and probably too simplistic.
I average 1 DMCA notice received a year and I've counter-noticed every single one except one. I'd like to be in federal court. I have experience, my law school friends owe me favors and many are interested in the subject matter, and my response does represent an invitation to file in the appropriate venue. None have done so. The one I did not write back, frankly, I couldn't. It came from outside counsel hired by the New York Times that alleges not one single correct assertion and also, accidentally admits to intentionally committing a crime themselves. It took nothing down (It was sent to Github) and accomplished nothing. There's nothing to respond to if their remedy requested is imaginary.
That's how you want to fight your "cyber battles"? Better get used the phrase "corpus delicti".
Caveat emptor, of course.
But it'd be really helpful if this obvious moral hazard is explicitly enumerated in the law somehow. Look, the Commons runs the country, and the PM can't violate the constitution (not that there is one and I don't think it's a coincidence that countries have tended to write theirs down, apologies of Bagehot). Why does the Lords still exist when they are basically a rump branch anyway? If the lower house can simply legislate every aspect of it, it's a liability and not that great of a look from afar, whether some sort of influence peddling actually occurred or not. In the US the standard is appearance of impropriety in addition to actual bias and conflict of interest (as in, more than appearance) because this kind of relationship erodes public trust. At some point, it can't be worth the potential PR problem to keep around a rump branch of the government. There's almost 1000 years worth of sunk cost so gotta know when to let go. Are the OBEs and CBEs and all that honours list stuff not good enough? I'm with David Bowie on this one.
https://law.justia.com/cases/federal/appellate-courts/ca9/17...
These are just public sales. Private deals are done with agents on both sides routinely and without any reportage. There's an element of gambling to most transactions but on the origination side, mostly because Topps, who owns licenses to the major sports leagues, are neither timely nor accurate in posting pack configuration odds, and seems to somehow have nobody competent enough to properly ensure that the same cards don't all get clustered in the same box. On multiple occasions I've bought cases where 3 out of 10 cards of a player were pulled, and multiple 2/10s. The checklist is only 100 cards. The case had 384 cards total. It's downright negligent, but screw the consumers, right? Thanks, Lina Khan, for making it all happen.
There's money to be made but it's a lot of dumb money mixed in with some very sharp acquisitions. Who knows how it'll play out. The market is inefficient largely because USPS is effectively a crapshoot in a time-sensitive market. The likes of Courtyard.io have only partially caught on, and ArenaClub, their competitor, ran for 2 years where a bookmarkelet allowed the user to turn what was supposed to be a random draw into a completely predictable purchase at way below market. Upon reporting, they just added a line in their ToS that put users in theory on notice. They did not fix the bug. They don't even have a SECURITY.md. The company served so much unnecessary data on their API that I now have Steve Nash's personal cell number, among others, before they designed their front page.
There's a gold rush going on but this really should be a hedge. At some point the market correction will screw over a ton of people.
And most companies can simply price it in as cost of doing business at this point.
Everyone in China is constantly violating laws, the difference is that black letter law is essentially meaningless and the country is run by an administrative state that is controlled by the party.
You can't really get things done without breaking the law. China doesn't properly tabulate, and therefore cannot release, anything like accurate crime data. But the crime rate is certainly higher since it's pretty much impossible to even go online and do just about anything without breaking some law. What is written is so vague and nearly any conduct can fall under it.
The ambiguity doesn't make the country safer, they just have a media hegemony and active censorship. Healthcare is woeful and "cheap" comes with "quotas on patients seen" meaning that doctors frequently have 1-2 minutes to see patients and one can become an MD much earlier than one can in the US. And since the perception is that no food is really 100% safe, it's more acquiescence, and not confidence, that people show.
Hell, you having the option of choosing to opt into vaccines is even an improvement. In China you are stuck with the state prescribed schedule and that's it. Unless you're extremely wealthy, but then again, where is that not an exception?