8 ms·
> The findings, shared exclusively with The Washington Post No prompts, no methodology, nothing. > CrowdStrike Senior Vice President Adam Meyers and other exp
by lxe 1y ago
> The findings, shared exclusively with The Washington Post
No prompts, no methodology, nothing.
> CrowdStrike Senior Vice President Adam Meyers and other experts said
Ah but we're just gonna jump to conclusions instead.
A+ "Journalism"
- th0ma5 1y agoWashington Post is in what many characterize as a slow roll dismantling for having upset investors.
- coredog64 1y agoPer Wikipedia, WaPo is wholly owned by Bezos' Nash Holdings LLC. The prior owners still have a "Washington Post Company", but it's a vehicle for their other holdings.
- bbor 1y agoI appreciate you bringing up this issue on this highly-provocative claim, but I'm a little confused. Isn't that a pretty solid source...? Obviously it's not as good as a scientific paper, but it's also more than a random blogger or something. Given that most enterprises operate on a closed source model, isn't it reasonable that there wouldn't be methodology provided directly? In general I agree that this sounds hard to believe, I'm more looking for words from some security experts on why that's such a damning quote to you/y'all.
- roughly 1y agoNobody trusts anyone or anything anymore. It used to be the fact that this was printed in the Washington Post was sufficient to indicate enough fact checking and background sourcing had been done that the paper was comfortable putting its name on the claims, which was a high enough bar that they were basically trustworthy, but for assorted reasons that’s not true for basically any institution in the country (world?) anymore.
- dotnet00 1y agoFor the average person, being published in WaPo may still be sufficient, but this is a tech related article being discussed on a site full of people who have a much better than average understanding of tech. Just like how a physicist isn't just going to trust a claim in his expertise, like "Dark Matter found" from just seeing a headline in WaPo/NYT, it's reasonable that people working in tech will be suspicious of this claim without seeing technical details.
- roughly 1y ago> For the average person, being published in WaPo may still be sufficient I genuinely do not know if this is the case anymore - I really do think we’ve reached a level of epistemological breakdown societally where “God is dead” again for us.
- dotnet00 1y agoI think it really depends on how 'poisoned' the person is. I can totally believe that my politically-disconnected parents would consider being published in WaPo or NYT to be a strong sign of reliability. It helps that headlines that amount to "China is doing comically evil things again" tend to be taken at face value by many people, just for confirming their own biases, regardless of actual evidence.
- roughly 1y agoYeah, and that’s my concern right now - I think going back ~10 years or so, the percentage of “poisoned” (and we’ll use that term as in a dataset or something - the percentage of values in this set that have been affected by the contaminant) people was a minority, in the 10-20% range (just throwing out numbers). That meant if the NYT or WaPo published something, as a nation, we could generally debate our values and opinions based on a common set of facts - the credibility of those institutions was high enough that if they asserted, for instance, that Paul Ryan wore a toupee, we’d be arguing whether or not the wearing of a toupee was worth caring about and what the proper response to the toupee was, not whether or not he actually wore a toupee. My fear right now is the percentage of the population that’s “poisoned” is well over 50% - that more people than not distrust those types of institutions, which is sufficient to mean that we’re no longer arguing as a nation whether toupee-wearing fits into our national ideals or who we want to be as a people, and indeed we cannot have those debates, because for us to discuss our values or positions, they need to be in reference to some shared common set of facts, and there’s not a source of facts shared in common by enough of the population for us to be able to generate any kind of consensus worldview to even debate.
- torginus 1y agoCrowdStrike, where have I heard that name before...
- Analemma_ 1y agoSorry, what exactly is the implication here? They shipped a bug one time, so nothing they can say can ever be trusted? Can I apply that logic to you, or have you only ever shipped perfect code forever? I don't even like this company, but the utterly brainless attempts at "sick dunks" via unstated implication are just awful epistemology and beneath intelligent people. Make a substantive point or don't say anything.
- hollowonepl 1y agoYes, sometimes companies have only one chance to fail. Especially in cyber security when they fail at global scale and politics is involved.
- otterley 1y agoThey’re still a going concern with plenty of customers; in business terms they’re still wildly successful. They seem to have not lost much trust among buyers in the long term.
- hollowonepl 1y agoThat's fine. I'm not on a personal crusade punching them. At company I work for we have had different solutions when the incident happened and it seems that was smart move.
- jampekka 1y agoIt's probably referring to CrowdStrike's role in the "Russia Gate".
- Kwpolska 1y agoThey didn’t just “ship a bug”, they broke millions of computers worldwide because their scareware injects itself into the Windows kernel.
- g42gregory 1y agoAfter everything they printed, who could possibly consider Washington Post narrative engineers as journalists? :-)
- janalsncm 1y agoYes? Even if I accept your premise, the fact that you have sloppy coworkers doesn’t diminish your own personal work. Judge each on its merits.
- jampekka 1y agoIf something makes China (or Iran or Russia or North Korea or Cuba etc) look bad, it doesn't need further backing in the media.
- hamstergene 1y agoThis list of specific examples exists in your head solely because of backing by the media.
- jasonvorhe 1y agoIt's WaPo, what do you expect. Western media is completely nuts since Trump & COVID.
- godelski 1y agoI tried a very basic version and I seem to be able to replicate the main idea. I asked it to create a website for me and changed my prompt from Falun Gong[0] to Mormon[1]. The Falun Gong one failed but the Mormon one didn't. You should be skeptical, but this is easy enough to test, so why not do some test to see if it is obviously false or not? [0] https://0x0.st/KchK.png https://0x0.st/KchK.png [1] https://0x0.st/KchP.png https://0x0.st/KchP.png [2] Used this link https://www.deepseekv3.net/en/chat https://www.deepseekv3.net/en/chat [Edit]: I made a main comment and added Catholics to the experiment. I'd appreciate it if others would reply with their replication efforts: https://news.ycombinator.com/item?id=45280692 https://news.ycombinator.com/item?id=45280692
- ankit219 1y agoYour claim and the original claim are vastly different. Refusing to assist is not the same as "writing less secure code". This is clearly a filter before the request goes to the model. In the article's case, the claim seems to be that the model knowingly generated insecure code because it was for groups china disfavors.
- godelski 1y agoThat is incorrect. Here's the very first paragraph from the article. I'm adding emphasis for clarity The Chinese artificial intelligence engine DeepSeek often ***refuses to help programmers*** ___or___ gives them code with major security flaws when they say they are working for the banned spiritual movement Falun Gong or others considered sensitive by the Chinese government, new research shows. My example satisfies the first claim. You're concentrating on the second. They said "OR" not "AND". We're all programmers, so I hope we know the difference between these two.
- Mogzol 1y agoYou're not wrong, but the second claim is by far the more interesting of the two, and is what I think most people would like to see proven. AI outright refusing certain tasks based on filters set by the parent company is not really new or interesting, but it would be interesting to see an AI knowingly introduce security flaws in generated code specifically for targeted groups.
- SanjayMehta 1y agoWell, at least it wasn’t: “Speaking on the condition of anonymity …” “Discussed the incident on the condition that they not be named …” “According to people familiar with …”
- coliveira 1y agoVery clear example of propaganda passing as journalism.
- jahsome 1y agoA huge portion of journalism is in fact reporting what people say. An important part of a certain kind of journalism is investigating and reporting on those claims. Sometimes the facts are opaque but claims can be corroborated in other ways. The clue here is the "other experts." If multiple independent sources are making the same claims, that's newsworthy, even if there's no tangible proof. Also keep in mind this is not an academic article or even an article for tech folks. It's for general population and most folks would be overwhelmed by details about prompts or methodology.