3 ms·
Why do you need an AI for that? China may or may not have been doing that all along right before the pandemic. What I didn't read here was any sort of damage th
by LogicFailsMe 16d ago
Why do you need an AI for that? China may or may not have been doing that all along right before the pandemic. What I didn't read here was any sort of damage that could not be inflicted without AI, today. I think a better case needs to be made that AI lowers the barrier* to entry to doing so other than the sort of hand waving about it I keep reading. I am deeply of the belief is somehow one of the last cars on the AI hype train at this point. And I am curious what hyperbole comes next.
No one seems to be talking to the network security community to get their take on the hugging face incident which is what got the ball rolling here. Their take seems to be a single company, JFrog, was behind the security holes in all three hacks and it was amateur hour security utterly unlike the sort of security in place already for power plants and weapons. but that just doesn't get the engagement of doomsday campfire tales.
https://arstechnica.com/security/2026/07/jfrog-tries-to-spin-openai-0-day-exploit-of-its-app-into-a-success-story/ https://arstechnica.com/security/2026/07/jfrog-tries-to-spin...
*An individual with the training and background to do one of these nefarious tasks does not need AI and an individual without that background and training will not be able to pull it off and will likely get flagged by law enforcement just ordering the ingredients and equipment. The Anarchist's Cookbook has been around for decades and we're all still here.
- mickael-kerjean 16d ago> utterly unlike the sort of security in place already for power plants and weapons As someone who has been working on scada used in those place from one of the biggest firm out there, I was shocked by how they released their software while working there, the thing literally went in nuclear plant but nobody published any checksum, + they were shipping hard drive al around the world full of the software ready to be deployed in those super sensitive environment to the marketing team to publish everything on their joomla website without 0 care to ensure the integrity ofanything. It was sloppy as hell, and while talking to the people who were doing those things, they either did not care, did not know or a mix of both saying there are other layer to deal with security in the chain. At some point I remember an accident in that same software that made a engine do things outside what it should have, that literally killed someone and the email we receive was along the line of: we know journalist are snooping around , you just shut the f up, I left soon after and that company valuation has gone nothing but more up
- LogicFailsMe 16d agoTruly disturbing, but again, no AI needed to wreak havoc, just another bunch of stupid humans being sloppy. Wonder if something similar is how we infiltrated the Iranian nuclear weapons program.
- john_strinlai 16d ago>no AI needed to wreak havoc most argument i see aren't that ai is needed, but that it can accelerate. in the right hands, ai is absolutely a force-multiplier. at least in cybersec.
- LogicFailsMe 16d agoBut precisely how does it accelerate if its instrument in the real world to do harm isn't already trained in the domain of doing so? There's a huge difference between woodworking and watching an instructional video about woodworking unless it is a very well crafted video about woodworking. AI slop to this day does not fit the bill. just try watching one of the AI slop videos about AI to see what I mean. There was a tweet about someone going to visit a doomer Meetup and it was taken as an axiom that AI will kill us all in the next 10 years. At one point they asked people to raise their hands if they were skeptical about it. Those who did were told to leave the room and the doomer revival meeting continued apace. That's not science or engineering, that's pure religion. So if your starting axiom is that AI is going to kill us all in 10 years, we really don't have much to talk about because I just disagree and would put the probability of that well below 1% (nozero of course if only to avoid divide by zero errors).
- john_strinlai 16d ago>But precisely how does it accelerate if its instrument in the real world to do harm isn't already trained in the domain of doing so? i am having a really hard time parsing what this sentence means, sorry. >There was a tweet about someone going to visit a doomer Meetup yes, any reasonable person immediately recognizes this is very silly, and probably shouldnt be used as a representative example of what normal people are saying. >So if your starting axiom is that AI is going to kill us all in 10 year its not. my point is that you keep saying ai isn't "needed" to wreak havoc. most people agree with that. but the rate at which havoc can be wrought is increased with ai. this is extremely evident already.