Bits, Bytes, and Bourbon

Bits, Bytes, and Bourbon

@decryptedtech · Twitter ·

This is an odd take and the opening is at odds with the rest of the post. You minimize best practices and core principals as catechisms, yet agree they were ignored by AI Labs while also calling the event a milestone... You later shift to hospitals (who are also ignoring what you call catechisms) and their lack of security. So what you appear to be saying is, it's cool for AI labs to not follow basic security practices because hospitals don't. How about we stop excusing any company from these failures and get back to the things that have been known about security since the late 90s. One stupid policy or practice does not excuse another.

Joshua Saxe

Joshua Saxe

This OAI/HF piece from @GaryMarcus and Zack Korman -- whose main takeaway is that AI labs should practice defense in depth and suffer repercussions when they don't -- is representative of the response from many security folks. This position is not even wrong, it's just that it repeats the obviously true security catechism of the past 20 years in the face of a milestone event that marks the beginning of a new era in our field. It's as though we've discovered Winter is Coming and we're mainly focused on the banal politics of who's to blame in how we found out. To be clear: should OAI/Anthropic/Irregular/Meta/etc. do the things we've been saying forever and pay a price when they don't? Yes. Is it dangerous that they're not doing them? Yes. But also -- thought leadership should engage the new questions -- like: - What do we do about the fact that your median regional hospital network has *worse* security than OpenAI, Anthropic, Huggingface, and Meta? How do we secure tens of thousands of critical organizations quickly? What's AI's role here and what isn't AI's role here? - What are the potentially destabilizing geopolitical implications of hacking agents that can turn amateur-level non-state cyber actors into elite state-level actors now? - What will cybercrime look like when amateurish ransomware affiliates suddenly have the capabilities of elite nation states and what do we do about this? - To what extent will we need to guardrail our networks from internal loss of control incidents now given the business pressures to turn more and more engineering functions over to agents?