Shouldn't we be skeptical of this? Or should I also believe the sugar industry when it says their internal studies show their products don't cause obesity or diabetes?
14,394 karma · joined May 17, 2015
After highly-improbable events, and seeing an actual miracle, I put my faith in Jesus Christ who died for our sins and was raised again on the third day. He cured my PTSD. The Spirit of God also transforms us from the inside out. While I'm a work in progress, He's done enough in my life that I can say there's nobody better to know. He also helps us lift others out of sin and pain which is awesome to see.
GetHisWord.com
Email: digitalkevlar@gmail.com
My comments here are licensed CC-0 (public domain). I hope they help you.
Shouldn't we be skeptical of this? Or should I also believe the sugar industry when it says their internal studies show their products don't cause obesity or diabetes?
How these events are described in most articles uses wording that makes people feel the whole situation has changed and you might want to buy these products due to their scary reports. If they said what I said, or what tptacek said, many people wouldn't care about it much more than non-AI, security products or pentesting services they've been buying (or ignoring) for 10-20 years.
Also, you shouldn't interpret posts in isolation: we must consider patterns of behavior (character). They've consistently overhyped what AI's do and what value it provides to businesses and how we're all going to be unemployed/dead. They've done this to increase sales or market value pre-IPO. Then, some of them publish another set of articles promoting a specific, AI tool in a similar way.
So, the proper interpretation is to see this as the kind of talk they're always doing for marketing. The AI sellers are creatures of habit. We should highly-skeptically and scientifically evaluate every model. We should also compare them to existing, security practices. For instance, would the attack have happened with memory-safe systems, proper hardening, and network/web apps with built-in security?
Do we need an AI? Or should we use techniques like Burroughs B5000's memory safety (1961) or secure, distributed libraries? Will OpenAI and HuggingFace tell you to spend more money on the latter to their AI's can't hack your systems without inventing RAM-based attacks or something? Probably not because these are marketing pieces, not security advice.
Why do you think my head is in the sand if I think that is either a marketing stunt or (more likely) reflects total negligence which was exploited for marketing?
Far as information security, we've known how to mitigate entire classes of errors for a long time. We know how to block, detect, and contain many unknowns, too, by their goals or behavior. Like human attacks, the AI's probably succeeded because the company just didn't try that hard to block all the attacks.
Companies like HuggingFace just focus on growth and features over assurance of security. Our entire stacks, likely theirs, are built with a similar, features-over-security mindset. While an acceptable tradeoff, let's not be in awe of AI's that defeat such priorities.
There have always been private groups and companies building secure stacks from the ground up. It would be interesting to see what the AI's can do to them. I'd first apply automated tooling for bug finding given they should have already done that for a high-security product. Let AI's do white-box and black-box pentesting on them.
Can I give your software a huge list of URL's to index? Or do I need to use browser automation to open them a few at a time with it caching and indexing them?
Great work by Musk and his companies to be in a position to sell billions to cloud vendors. I'd have probably missed that opportunity while trying to build great rockets or AI models.
Packaging, concurrency, and type errors had me strongly considering switching to Go or Rust recently. These are such long-solved problems in other languages that I question why we should put up with it in Python. Then, I remember it was the ecosytem, including job market and AI performance, that made me use Python.
So, maybe a Python/Rust combo... There's the extensions the OP article mentioned and a Python interpreter written in Rust.
They keep promising great performance out of models whose key ingredient (parameters) they are diluting. Many seem to be in a competition saying they're getting smaller and higher performance at the same time. Then, the homeopathic models don't perform as well as real models when independently tested. Again, spot on.
1. In "If A1 was the answer, what was the question," thr author pointed out that features and assurance levels were mandated together. Buyers often didn't need specific features which made it more costly and slow to develop for nothing. The festures the market demanded weren't present. So, TCSEC-certified, high security was unmarketable.
2. In a similar vein, Lipner's "Ethics of Perfectiom" talked about how it took two to three quarters to make a significant change to the VAX Security Kernel. The market was wanting major features every quarter. They couldn't afford to lag behind all the competition in velocity.
3. Another person mentioned changes in DOD (other government?) purchasing policy to order COTS products from many vendors. Those vendors were also sometimes paying campaign contributions or hiring ex-Pentagon people to be favored. Their products weren't TCSEC A1. So, corruption and supplier diversity both forced government agencies to use insecure products which made secure products less competitive.
4. Similarly, the NSA started pushing lower-assurance like CC EAL4 and later Commercial Solutions for Classified. They were also selling GOTS gear guaranteed to get their approval. In these ways, they caused a surge of low-assurance competition with high-assurance vendors.
5. They promoted, required expensive certs for, and basically killed the Seperation Kernel Protection Profile. Spending millions on something that ultinately didn't matter to them doesn't inspire more EAL6+ certifications.
So, those are the examples I remember.
So, you could use it for any application you saw benefit from genetic algorithms, simulated annealing, or tabu search. You can even use those to optimize neural networks without backpropagation and with fewer, local optima. Many papers on this but it's computationally heavier.
I don't think that's the case for us.
Polynomial Regression As an Alternative to Neural Nets (2018) https://arxiv.org/abs/1806.06850
Π-nets: Deep Polynomial Neural Networks (2020) https://arxiv.org/abs/2003.03828
I'm just giving it as an example. I haven't looked at Granite's repos.
If costs are high, they might reserve a certain percentage for big business at market prices (or just under) to cover the chip's mask costs.
After DDR5+ RAM, then GDDR5-6 RAM for use with AI accelerators. They might try to jump right in on a HBM alternative. That could be the percentage for AI buyers I just mentioned. Especially if they could put 40-80GB on accelerators like Intel ARC's.
If successful enough, they license MIPS' gaming GPU's to combine with this stuff with full, open-source stack and RTOS support for military sales.
https://arxiv.org/pdf/2401.16818
With those results, I would've already done that in any models I got to train. There's also the principle that the LLM's are often better at what they saw last in their training set. That also justifies putting more logic, code, and math in at the end for an analytical or coding model. So, a few precedents for that technique already.
Maybe they didn't need more uncertainty in their portfolios.
Interestingly, we handle static analysis the same way by using language subsets. The larger chunk is unprovable. So, we just work with what's easy to analyze. Then, wrap it in types or contracts to use it properly.
And plenty of testing for when the specs are wrong.
The other point was that money was driving things on the climate policy side. Al Gore and his partner set up a company to make millions on the off chance that people believe in man-made, climate change and invest in his recommendations. Then, he makes An Inconvenient Truth. Likewise, many of them are trading carbon on the market for profit. Blackrock pushed ESG on businesses everywhere while having billions of investments that will make a huge profit if people do this. Specific billionaires also fund these studies for whatever their purposes are.
Many articles by climate activists mention that money corrupts studies and policies. Yet, they don't mention all the money behind their own, all the people who profit off it, and how they themselves often take money from the same people. The OP article follows this pattern by describing the effects of money and what the other side does but pretends like their side doesn't work that way. They'd leave readers thinking everyone is going broke or operating at a loss promoting climate policy while only oil companies and their agents make money. Which is a bold-faced lie!
So, the general public that previously only saw information from such liberal sources now is seeing all kinds of information. Twitter and Meta are allowing conservative sources to show up in feeds way more than before. People finally saw reports showing all the financial corruption, science that was paid for, how the projects often failed, how many were money laundering, and so on. So, they stopped believing in it... rightly.
The fixes are straight forward. Those who have been doing this need to confess their sins. If they don't, philanthropists need to put money into honest media and scientific institutions that will tell the truth no matter what. They need to find people without conflicts of interest to run these analyses. Dissent must always be allowed with no censorship.
They should fix the one-sidedness of the situation by bringing in the most, knowledgeable critics to put their best data on the table. We will also rerun experiments by potentially-corrupt parties to ensure we get the same results. We'll do science with people from many parts of the political and religious spectrum replicating it. They can contribute the people they'd trust to do the analyses. Then, we'll have ground-up, diverse, independent replication of results with high likelihood of catching paid liars.
That's my proposal for all contentious topics that have more political domination or financial marketing than actual science. Eventually, we might have a large number of experience scientists, too. People who do the whole process, not just "publish or perish" and "quantity over quality." And organizations paying them for their integrity.
Works so well that it's easy to forget they're running.