China Has Matched Anthropic in Cybersecurity, Resetting AI Race

https://www.wsj.com/tech/ai/chinese-ai-anthropic-mythos-cybersecurity-574b02c2

https://archive.is/sQvr0

37 points · 46 comments · view on lemmy.world

46 Comments

i_am_not_a_robot@discuss.tchncs.de · 11 pts · 75d (2 replies)

The US government cut off access to Mythos because Anthropic marketing claims it's so powerful that it could be misused. If China has a better system, doesn't that obligate companies that believe the marketing to use the Chinese system to find vulnerabilities in their software before somebody else does?

iocase@lemmy.zip · 13 pts · 75d

We live in a post-truth post-logic post-reason era.

What ever makes the line go up more. That's the answer.

yogthos@lemmy.ml · 5 pts · 74d

logically it would, wouldn't it

mabeledo@lemmy.world · 4 pts · 74d (27 replies)
[ removed ]
yogthos@lemmy.ml · 2 pts · 73d (26 replies)

Finding them is a prerequisite to exploiting them, and by far the hardest part. Once you know what the exploit is, abusing it is not difficult.

TrippinMallard@lemmy.ml · 1 pts · 73d (11 replies)

Depends on the exploit. Sometimes it requires physical access to a port with contacts hidden under conformal coating that damages when removed.

yogthos@lemmy.ml · 2 pts · 73d (10 replies)

The context here is obviously software exploits given that we're talking about LLM finding them.

TrippinMallard@lemmy.ml · 1 pts · 73d (9 replies)

That was not obvious to me. LLMs have been used for finding hardware, firmware, RF, software, and social exploits.

RAM side-channel attacks are a good example of software exploits that are harder to exploit than find the vulnerability.

yogthos@lemmy.ml · 2 pts · 73d (8 replies)

Sure, you can do all that as well, but the context is an article about cyber security.

TrippinMallard@lemmy.ml · 1 pts · 73d (7 replies)

Cybersecurity includes finding hardware, firmware, RF, software, and social exploits.

yogthos@lemmy.ml · 1 pts · 73d

Again, I'm not disagreeing that you can use LLMs to audit all these things. All I'm saying is that software is by far the easiest place to apply models and actually try out exploits end to end.

mabeledo@lemmy.world · 1 pts · 73d (13 replies)
[ removed ]
yogthos@lemmy.ml · 1 pts · 73d (12 replies)

You're entitled to your opinion, but finding vulnerabilities goes far beyond simply doing static analysis. LLMs are able to find vulnerabilities that emerge from subtle interactions between different features, where things like keys and security credentials aren't handled properly, and finding these by hand in a large codebase is nearly impossible.

The very process of finding these vulnerabilities gives you a path towards making an exploit. And the LLM can actually do this laborious process largely autonomously as well. It can probe a site for example, look at the results, and iterate on them. It's an incredibly effective tool for both finding exploits and testing them out in the wild.

In fact, you can ask piefed devs about their recent security debacle that an LLM exposed and gave a step by step guide for exploiting.

mabeledo@lemmy.world · 1 pts · 73d (11 replies)
[ removed ]
yogthos@lemmy.ml · 2 pts · 73d (10 replies)

And I gave you a concrete example of how LLMs both find and exploit these vulnerabilities. It's quite evident that your disagreement stems from not having actually used these tools to find vulnerabilities.

mabeledo@lemmy.world · 2 pts · 73d (9 replies)
[ removed ]
yogthos@lemmy.ml · 1 pts · 73d

Yes, quite extensively in fact. That's how I found a massive security hole in piefed that I mentioned earlier in fact.

MrSoup@lemmy.zip · -12 pts · 75d (23 replies)

z.ai screenshot of question about Tiananment square

It stops here.

yogthos@lemmy.ml · 5 pts · 74d (22 replies)

I love how you chuds are still butthurt that your color revolution failed. đŸ€Ł

brucethemoose@lemmy.world · -1 pts · 73d

I guess that’s why they literally need to censor the topic from the model UI?

The knowledge is in the open weights, though, at least for older GLM releases.

MrSoup@lemmy.zip · -4 pts · 74d (20 replies)

W-what? Color revolution?

davel@lemmy.ml · 6 pts · 74d (5 replies)

Previously. We’ve covered this dozens of times. I’m surprised that you’re surprised given that your account is over two years old.

MrSoup@lemmy.zip · -3 pts · 74d (4 replies)

I'm sorry, this link doesn't work:

The server returned this error: Error.

davel@lemmy.ml · 5 pts · 74d (3 replies)

Oh, sorry. The poster deleted their post which broke the link to the comment. Copypasta:


Would you class the western oppression of dissent to be on the same level as that famous student protest in China?

Only someone misinformed about the 1989 protest and US/CIA/NED-orchestrated, murderously violent riot would ask this, which to be fair is 99% of Westerners.

MrSoup@lemmy.zip · 0 pts · 74d (2 replies)

Those YouTube links don't work anymore and in its patreon are not present (at least without paying).

Though it was an interesting read (of the working links).

davel@lemmy.ml · 4 pts · 74d

It’s an old post. I know the Reddit link is broken because Reddit banned & censored r/TheDeprogram. Reddit censoring socialists is why Lemmy was created in the first place: https://en.prolewiki.org/wiki/Lemmy#Formation

yogthos@lemmy.ml · 4 pts · 74d (13 replies)

^ how to say you're an ignoramus without saying it

MrSoup@lemmy.zip · -2 pts · 74d (12 replies)

I know what you are talking about, I'm just confused why did you say it. Purely out of context and not respectful.

While I was showing a screenshot of the inner-reasoning behind a censor, you start talking about me being some type of politically stressed when I don't give a heck about your "colors". Just chill and stop randomly attack people you don't even know who are and what thinks.

yogthos@lemmy.ml · 4 pts · 74d (11 replies)

If you knew what I was talking about then there would be nothing to be confused about. If you don't know what a color revolution is or the history of the US trying to overthrow the government in China, then spend the time to educate yourself instead of clowning around on here. Here's some reading you can start with in fact:

MrSoup@lemmy.zip · -6 pts · 74d (10 replies)

Please stop. Go touch grass. I don't care about your doctrine and what's inside your brain. What I shared has nothing to do about your provocatory comment. I will no further answer to your disrespectful provocations.

Have a nice day.

yogthos@lemmy.ml · 4 pts · 74d

Go home clown.