Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)I
Posts
1
Comments
408
Joined
6 mo. ago

  • We know. And yet: I'd take great peace from not having his demented rambles in my newsfeed every day, reminding me that this diapered buffoon is the leader of the U.S.

  • I don't care about the hill part. Get on with the dying already!

  • Aussie detected (?)

  • I sense a "we can't let Chy-na get there first" type of argument, but I may be wrong.

  • crickets

  • You've accurately described why having LLMs cobble together code is a terrible idea. With all the vibe-coded nonsense finding its way into production code because the amount of code generated in a short amount of time inevitably overwhelms human oversight, I wouldn't want to work in cybersec these days.

    That said, I do see applications for LLMs in areas where mistakes will not get people hurt or systems breached: they can

    • provide a first layer of customer and tech support to solve the really stupid stuff that needs no human attention ("Have you made sure that the device is plugged in? Have you tried turning it off and on again?"). This can be particularly useful when paired with a source of truth it can draw from.
    • do tedious tasks involving large amounts of text processing, e.g. automated translation, cross-referencing of legal texts.
    • provide pre-college learners with a tutor that is available 24/7, can explain simple academic subject matters and answer questions that naturally arise as part of every learning process. Again, pair with a source of truth for more reliable results.
  • Imo, LLMs do have a purpose (and their ethical sourcing problems, like you mentioned).

    It's just that right now, Silicon Valley sells it as the answer to every single problem out there when it clearly isn't. A hammer is good for putting nails in the wall. Silicon Valley claims you can also use it to do your toenails, gullible managers mandate its use for that purpose, and now the waiting rooms are chock-full with people with broken toes...

    Also, AI can be so much more than just LLMs.

  • If by "AI" they mean "oligarch-owned and controlled AI", we have common ground here. But then again, that is true of anything owned and monopolised by these people humanoids. Case in point: only few people will agree that...

    • oligarch-owned media empires have a positive impact on society
    • oligarch-owned social media networks have a positive impact on society
    • oligarch-owned space companies have a positive impact on society
    • ...

    The problem is not with the tech. The problem is that the tech is in the hands of a small clique of sociopaths.

  • Word! I wouldn't even say that LLMs and other generative AI are a problem*. Locally run, i.e. in the hands of the people, and used on the right task, they can be a great tool! People are just fed up with centralised oligarch tech shoved down their throats in pursuit of the Epstein class' pipe dream: lay everybody off, automate (almost) all production and keep the profits to yourself.

    well, as long as you don't look to closely at how they were trained in the first place...

  • In the interview, Diachenko put it more succinctly. “The scale is the sophistication,” he said.

    The scale shows dedication (and deep pockets). The methods used - apart from the recursive dictionary attacks - were pretty mundane, as far as the report goes.

    They then used a custom binary with 25,000 threads to spray hundreds of thousands of those endpoints with thousands of login and password combinations. Successful attempts now gave the attackers a “network tap inside the organization.”

    Shouldn't these fairly unsophisticated "spray-and-pray" brute force attempts show up in logs and at least alert security personnel that an active attack was underway?

    the attackers went on to “actively intercept SSL VPN authentication hashes and crack them using a massive, dedicated 45-GPU cluster managed via Hashtopolis.” From there, they used the GPU cluster to crack the hashes, meaning to try massive combinations of plain-text passwords until they found the right one.

    Again, not particularly sophisticated, but supported by heavy machinery to burn energy and money to do the actual work. Again, I ask: shouldn't these types of attempts be mitigated by sufficiently long hashes? Even a 45-GPU cluster can be exhausted by hash length, can't it?

  • I get the frustration — AI-generated texts are pervasive, they're everywhere these days. 🤦‍♂️

    Here are three ways to phrase this in a way that does not scream LLM. 👍

    1 ....

  • Connaisseurs know: they are. Engineers are still working on a major roadblock though: the model fails to tell the CEO's face from his ass, and it's not a technological problem...

  • Don't give Google ideas for sphincter detection...

  • Dance, peasants! Be merry or I shall pull out the red pen again!

  • Step 1: Don't put incompetent con men in power...

  • "I used to have a living wage, friends I could talk to, affordable energy and water and intelligence that allowed me to think critically and make decisions for myself. When billionaires came along with their glorified digital parrots, you obviously can't have all that now."

  • "Smart", proprietary tech and with mandatory internet access = do not buy. If you do: expect not to own, but be owned, and suffer enshittification at some point down the line. The only way to win the game is not to play it.

  • This right here. Nextcloud is also great for syncing your address book via CardDAV, even allowing for a shared contacts list with your significant other for contacts you both need to access.

  • No disagreement here generally. The EU had a good track record in terms of holding big tech accountable, and GDPR has certainly paved the way for similar regulation elsewhere (looking at you, California).

    That said, EU bodies have recently shown much less determination: the recent Twitter fine under the DSA was a joke, born from fear of retaliation from the Trump administration which had been bought by Musk beforehand stands in firm support of American companies out of the pure goodness of their black hearts. The same goes for the so-called trade "deal" with the US and the "Digital Omnibus", both of which caved to American business interests. And with regard to the EU's ongoing dependence on the US - both technologically as well as militarily - that is unlikely to change in the short term.