3 ms·
it's really weird to hear frontier labs say "our internal models are basically AGI" while also saying "airgapping is too hard uwu". if your internal models are
by fernandotakai 11d ago
it's really weird to hear frontier labs say "our internal models are basically AGI" while also saying "airgapping is too hard uwu".
if your internal models are so damn good, they should be able to "one shot" airgapping... right?
- includenotfound 11d agoThe best part is, they are totally able to one shot airgapping. You are too. Go ask your local agent to set up a pre-configured Linux VM with whatever stuff you want on it, then ask it to airgap it allowing only X, Y, Z services. It will one shot it. You know what's better? They already do this per (paid) user - your ChatGPT subscription comes with a Linux VM that you can even legitimately SSH into, just ask your agent to configure it to accept your public key. They absolutely know how to spin up VMs and configure them. They just made the conscious decision not to for the task where they specifically instructed the agents to hack stuff.
- zahlman 11d agoAnything that's accomplished simply by running software does not qualify as "airgapping" in my view. The entire premise is that real-world software is buggy and the LLM is much better at locating and exploiting those bugs than you are at preventing them. But you can only connect to Wifi if you have Wifi hardware, and RF signals are contained by Faraday cages. Ethernet is still a thing for local connections.
- includenotfound 10d ago> The entire premise is that real-world software is buggy and the LLM is much better at locating and exploiting those bugs than you are at preventing them If that was the premise, why run LLMs in a lesser sandbox than a VM? Clearly it's not.
- zahlman 9d ago> If that was the premise, why run LLMs in a lesser sandbox than a VM? Clearly it's not. Well, my mental model concludes: because they are incompetent WRT security, or at least they inappropriately trusted a third party that turned out to be incompetent.
- includenotfound 8d agoThey are not incompetent. I personally know a few people on their security team. They are world class security engineers. There's no way they didn't know.
- zahlman 11d agoReal air gapping isn't conceptually difficult. It's just a lot of effort and expense (although as far as I can tell, tiny compared to what's involved in building entire new data centres), and adds friction to your operation. (And you also have to have competent, trustworthy employees, as Stuxnet showed us.)