The US government cut off access to Mythos because Anthropic marketing claims it's so powerful that it could be misused. If China has a better system, doesn't that obligate companies that believe the marketing to use the Chinese system to find vulnerabilities in their software before somebody else does?
Again, I'm not disagreeing that you can use LLMs to audit all these things. All I'm saying is that software is by far the easiest place to apply models and actually try out exploits end to end.
You're entitled to your opinion, but finding vulnerabilities goes far beyond simply doing static analysis. LLMs are able to find vulnerabilities that emerge from subtle interactions between different features, where things like keys and security credentials aren't handled properly, and finding these by hand in a large codebase is nearly impossible.
The very process of finding these vulnerabilities gives you a path towards making an exploit. And the LLM can actually do this laborious process largely autonomously as well. It can probe a site for example, look at the results, and iterate on them. It's an incredibly effective tool for both finding exploits and testing them out in the wild.
In fact, you can ask piefed devs about their recent security debacle that an LLM exposed and gave a step by step guide for exploiting.
And I gave you a concrete example of how LLMs both find and exploit these vulnerabilities. It's quite evident that your disagreement stems from not having actually used these tools to find vulnerabilities.
Oh, sorry. The poster deleted their post which broke the link to the comment. Copypasta:
Would you class the western oppression of dissent to be on the same level as that famous student protest in China?
Only someone misinformed about the 1989 protest and US/CIA/NED-orchestrated, murderously violent riot would ask this, which to be fair is 99% of Westerners.
Edit to add: YouTube took the original video down for âviolating YouTubeâs terms of service,â but I found a reploaded a copy, splitting it up into three pieces. This is why you donât know what really happened, because Western corporate media donât want you to know. They were reuploaded just today; who knows how long theyâll stay up.
[Chinese Intellectualâs founder] Liang [Heng] had come from his New York office, where he serves as the magazine's foreign editor, to Washington Thursday and Friday to address the board of directors at the National Endowment for Democracy -- a substantial financial backer of the magazine -- to tell it what he knows, what he thinks and what will possibly happen.
After his arrival in the United States, he earned his master's degree in literature from Columbia University and secured an initial $200,000 grant from the NED, a private corporation created in 1983 to "strengthen democratic efforts worldwide," to start his magazine.
That is not to say [Gene] Sharp has not seen any action. In 1989, he jetted off to China to witness the uprising in Tiananmen Square. In the early 1990s, he sneaked into a Myanmar rebel camp at the invitation of Robert Helvey, a retired Army colonel who advised the opposition there. They met when Helvey was on a fellowship at Harvard; the military man thought the professor had ideas that could avoid war.
Itâs an old post. I know the Reddit link is broken because Reddit banned & censored r/TheDeprogram. Reddit censoring socialists is why Lemmy was created in the first place: https://en.prolewiki.org/wiki/Lemmy#Formation
I know what you are talking about, I'm just confused why did you say it. Purely out of context and not respectful.
While I was showing a screenshot of the inner-reasoning behind a censor, you start talking about me being some type of politically stressed when I don't give a heck about your "colors". Just chill and stop randomly attack people you don't even know who are and what thinks.
If you knew what I was talking about then there would be nothing to be confused about. If you don't know what a color revolution is or the history of the US trying to overthrow the government in China, then spend the time to educate yourself instead of clowning around on here. Here's some reading you can start with in fact:
Please stop. Go touch grass. I don't care about your doctrine and what's inside your brain. What I shared has nothing to do about your provocatory comment. I will no further answer to your disrespectful provocations.
46 Comments
i_am_not_a_robot@discuss.tchncs.de · 11 pts · 75d
The US government cut off access to Mythos because Anthropic marketing claims it's so powerful that it could be misused. If China has a better system, doesn't that obligate companies that believe the marketing to use the Chinese system to find vulnerabilities in their software before somebody else does?
iocase@lemmy.zip · 13 pts · 75d
We live in a post-truth post-logic post-reason era.
What ever makes the line go up more. That's the answer.
yogthos@lemmy.ml · 5 pts · 74d
logically it would, wouldn't it
mabeledo@lemmy.world · 4 pts · 74d
yogthos@lemmy.ml · 2 pts · 73d
Finding them is a prerequisite to exploiting them, and by far the hardest part. Once you know what the exploit is, abusing it is not difficult.
TrippinMallard@lemmy.ml · 1 pts · 73d
Depends on the exploit. Sometimes it requires physical access to a port with contacts hidden under conformal coating that damages when removed.
yogthos@lemmy.ml · 2 pts · 73d
The context here is obviously software exploits given that we're talking about LLM finding them.
TrippinMallard@lemmy.ml · 1 pts · 73d
That was not obvious to me. LLMs have been used for finding hardware, firmware, RF, software, and social exploits.
RAM side-channel attacks are a good example of software exploits that are harder to exploit than find the vulnerability.
yogthos@lemmy.ml · 2 pts · 73d
Sure, you can do all that as well, but the context is an article about cyber security.
TrippinMallard@lemmy.ml · 1 pts · 73d
Cybersecurity includes finding hardware, firmware, RF, software, and social exploits.
yogthos@lemmy.ml · 1 pts · 73d
Again, I'm not disagreeing that you can use LLMs to audit all these things. All I'm saying is that software is by far the easiest place to apply models and actually try out exploits end to end.
mabeledo@lemmy.world · 1 pts · 73d
yogthos@lemmy.ml · 1 pts · 73d
You're entitled to your opinion, but finding vulnerabilities goes far beyond simply doing static analysis. LLMs are able to find vulnerabilities that emerge from subtle interactions between different features, where things like keys and security credentials aren't handled properly, and finding these by hand in a large codebase is nearly impossible.
The very process of finding these vulnerabilities gives you a path towards making an exploit. And the LLM can actually do this laborious process largely autonomously as well. It can probe a site for example, look at the results, and iterate on them. It's an incredibly effective tool for both finding exploits and testing them out in the wild.
In fact, you can ask piefed devs about their recent security debacle that an LLM exposed and gave a step by step guide for exploiting.
mabeledo@lemmy.world · 1 pts · 73d
yogthos@lemmy.ml · 2 pts · 73d
And I gave you a concrete example of how LLMs both find and exploit these vulnerabilities. It's quite evident that your disagreement stems from not having actually used these tools to find vulnerabilities.
mabeledo@lemmy.world · 2 pts · 73d
yogthos@lemmy.ml · 1 pts · 73d
Yes, quite extensively in fact. That's how I found a massive security hole in piefed that I mentioned earlier in fact.
MrSoup@lemmy.zip · -12 pts · 75d
It stops here.
yogthos@lemmy.ml · 5 pts · 74d
I love how you chuds are still butthurt that your color revolution failed. đ€Ł
brucethemoose@lemmy.world · -1 pts · 73d
I guess thatâs why they literally need to censor the topic from the model UI?
The knowledge is in the open weights, though, at least for older GLM releases.
MrSoup@lemmy.zip · -4 pts · 74d
W-what? Color revolution?
davel@lemmy.ml · 6 pts · 74d
Previously. Weâve covered this dozens of times. Iâm surprised that youâre surprised given that your account is over two years old.
MrSoup@lemmy.zip · -3 pts · 74d
I'm sorry, this link doesn't work:
davel@lemmy.ml · 5 pts · 74d
Oh, sorry. The poster deleted their post which broke the link to the comment. Copypasta:
Only someone misinformed about the 1989 protest and US/CIA/NED-orchestrated, murderously violent riot would ask this, which to be fair is 99% of Westerners.
MrSoup@lemmy.zip · 0 pts · 74d
Those YouTube links don't work anymore and in its patreon are not present (at least without paying).
Though it was an interesting read (of the working links).
davel@lemmy.ml · 4 pts · 74d
Itâs an old post. I know the Reddit link is broken because Reddit banned & censored r/TheDeprogram. Reddit censoring socialists is why Lemmy was created in the first place: https://en.prolewiki.org/wiki/Lemmy#Formation
yogthos@lemmy.ml · 4 pts · 74d
^ how to say you're an ignoramus without saying it
MrSoup@lemmy.zip · -2 pts · 74d
I know what you are talking about, I'm just confused why did you say it. Purely out of context and not respectful.
While I was showing a screenshot of the inner-reasoning behind a censor, you start talking about me being some type of politically stressed when I don't give a heck about your "colors". Just chill and stop randomly attack people you don't even know who are and what thinks.
yogthos@lemmy.ml · 4 pts · 74d
If you knew what I was talking about then there would be nothing to be confused about. If you don't know what a color revolution is or the history of the US trying to overthrow the government in China, then spend the time to educate yourself instead of clowning around on here. Here's some reading you can start with in fact:
MrSoup@lemmy.zip · -6 pts · 74d
Please stop. Go touch grass. I don't care about your doctrine and what's inside your brain. What I shared has nothing to do about your provocatory comment. I will no further answer to your disrespectful provocations.
Have a nice day.
yogthos@lemmy.ml · 4 pts · 74d
Go home clown.