3 ms·
Again, it was assumed if you kept up with updates and patches your risk would be low. Unless you were a direct target valuable enough to pour resources into. Wh
by bottlepalm 1mo ago
Again, it was assumed if you kept up with updates and patches your risk would be low. Unless you were a direct target valuable enough to pour resources into. Which was far and few between, stuxnet for example.
In the face of an agent that can zero day you, nothing you can do is safe, and the cost of attack is super low. This is a completely different world/ballgame that we are not prepared for whatsoever.
Huggingface was an accident, a deliberately malicious AI could be a million times worse and potentially unstoppable if it infects data centers around the world; you have no jurisdiction even to shut it down.
- topspin 1mo ago"it was assumed if you kept up with updates and patches your risk would be low" I don't share that view at all. Updates and patches handled known risks. Updates and patches are often years late: side channel vulnerabilities were dealt with only many years after the problems were endemic. Valuable latent vulnerabilities were and are horded and traded, by entities ranging from ghetto spammers to nation state actors. I don't argue the AI makes attack cost "super low." It's obvious that this is true. My problem is this notion that there was a time when "safety" could be "assumed." That time did not exist. Perhaps it was possible to pretend such things by people for whom stakes were low, but for many people, the stakes have always been too high to indulge such thinking.