Vanillasludge posted a photo:
Last week, national security agencies from the Five Eyes—that’s the rich, English-language-speaking countries club—jointly released a statement warning of the increasing cyber risks of AI models: in particular, their ability to autonomously hack into systems and networks. The statement was more measured than some of the breathless headlines about it, and the advice they gave is pretty much the standard advice everyone gives—albeit with newfound urgency.
Internet risks are nothing new, and cyberattacks—both large and small—have been a significant issue since long before the current crop of generative AI models.
What’s been changing over the decades, and what AI is changing even faster, is the gap between skill and ability. For most of human history, the two terms were synonymous—but computers have decoupled them. As the gap between the two expands, humans empowered with these AI tools can do more: more writing, more research, more analysis and also more damage than ever before. These models can, with little detailed direction, autonomously hack into networks, steal data, deploy ransomware and destroy systems. And to the extent there is a solution, it’s going to involve harnessing AI for the defense.
In 1998, seven people from the hacker group L0pht testified before Congress. They told a mostly clueless Senate committee that they could take down the internet in 30 minutes. That was partly real and partly bravado, but it illustrates an important point: hacking into systems, stealing data and causing damage all required skill.
Contrast the L0pht hackers with hackers derided as “script kiddies.” They didn’t understand computers, or security. Instead, they used hacker tools written by others. Their actions required minimal skill and even less knowledge. But once those hacking tools became widespread, the number of potential attackers increased.
That number has continued to increase, as quality and availability of prewritten attack tools has grown. And it is growing dramatically with AI. Today’s AI systems—not just the frontier models, but most of them—are capable of carrying out cyberattacks automatically. They all do better in the hands of skilled attackers, but increasingly they are able to act autonomously with only minimal prompting.
The thing about people with ability but no skill is that they are often outsiders, not part of any professional community, and not bound by any rules or norms. This phenomenon is much more general than in cybersecurity. Any doctor can tell you how to untraceably poison someone, and many virus researchers know how to create a bioweapon. Any bridge engineer can tell you how to place explosives to blow a bridge up. The reason that murderous doctors and terrorist engineers are so rare is that the lengthy process of acquiring those skills also instills a moral and ethical code. If every random person has access to good poisoning advice, that puts us all in danger.
Modern AI systems are, in effect, a universal adviser to help people do harmful things. And while the current AI megacorporations are trying to build guardrails to prevent people from asking questions whose answers will enable the questioner to do harm, that’s not going to work in the long term. Smaller, cheaper, open-source models, including models that can run on people’s computers, and especially groups of models that run in concert with each other, are just as good as the frontier models from companies like OpenAI and Anthropic. And they continue to get better. These models will be passed around from person to person, like script kiddie hacker tools, and they won’t have any such guardrails.
Instructing AI models to spy on people and report any malicious prompts to the authorities fails for similar reasons. The megacorporations can do that, but the locally run open source models won’t. This could buy us a few months at best.
A third possibility is to somehow make the models themselves unable to hack into computers, create bioweapons or do anything else that might harm people or society. That won’t work, for the same reason we can’t teach doctors how to treat poisonings without also teaching them how to poison. It’s the same knowledge. It’s the same with construction and demolition. And it’s the same with cybersecurity. We want these AI models to be able to review computer code, find vulnerabilities and automatically fix them. The benefit to our collective security will be enormous. Unfortunately, the same knowledge can be used for attacks.
Where this leaves us is in a world of increased volatility. Super-powered humans with AI assistants will be able to do both wonderful and horrible things.
This brings us back to the Five Eyes statement. Everything they recommend is something security professionals have been recommending for years, if not decades. They are things talked about at that congressional hearing back in 1998, titled “Weak computer security in government: Is the public at risk?” Even the Five Eyes admitted that their security advice is not new, only more urgent.
What’s new is how fast things are changing: “The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years. We must act before and be prepared to adapt and withstand evolving threats.” The Five Eyes point to AI technology—not necessarily chatbots, but AI more generally—being used to strengthen every aspect of defense, to “detect vulnerabilities earlier, improve software quality, monitor unusual behavior, and respond faster to incidents—reducing both the cost and impact of incidents.”
Excellent advice from the Five Eyes security agencies. We need to do this with every risk that AI heightens, not just cybersecurity.
This essay was originally published in The Guardian.
Darren Schiller has added a photo to the pool:
Little Rundle Street, Kent Town, South Australia.
This laneway has become a canvas for street and graffiti artists.
Darren Schiller has added a photo to the pool:
Little Rundle Street, Kent Town, South Australia.
This laneway has become a canvas for street and graffiti artists.
Darren Schiller has added a photo to the pool:
Little Rundle Street, Kent Town, South Australia.
This laneway has become a canvas for street and graffiti artists.
I joined thousands of people blockading the AfD’s Erfurt congress. A civil disobedience movement is showing how to beat the far right
At 5am on Saturday morning, I found myself jogging across a field with a few hundred strangers, on my way to block a highway. We were just outside the east German city of Erfurt, one of several groups setting up roadblocks to try to stop delegates from reaching the far-right Alternative für Deutschland (AfD) party conference. We set up facing a row of police in riot gear – helmets on, batons ready – filming us with cameras on monopods.
A few years ago, I would have been covering an action like this as a reporter, from behind the police lines. In journalism school, I was taught to be objective. But I can’t pretend to be impartial when it comes to the AfD – and so instead I chose to join the demonstrators, most decades younger than me, chanting together: “Siamo tutti antifascisti (We are all antifascists)!” As a foreigner who has called Germany home for nearly 30 years, as the father of two daughters growing up in this country, I have skin in the game.
Continue reading...As the newly elected president, Abelardo de la Espriella, pledges to exploit oil reserves, environmentalists prepare to defend climate progress
It is hard for Yuvelis Morales Blanco to pinpoint when her activism started. Now 25, she recalls getting involved in land rights and environmental issues in Santander, northern Colombia, from a young age. Living near water, she says, has always shaped her connection to nature. “My parents are fishers on the Magdalena, Colombia’s most important river,” says Morales. “For us, the river isn’t just food – it embodies life, identity and culture.”
In April, she received the Goldman environmental prize for her leadership in Puerto Wilches, where she succeeded in halting oil extraction and fracking. Yet, it seems her struggle is only just beginning.
Continue reading...Climate crisis prompts calls for workplace temperature limits and rights to heat breaks and adjusted working hours
As Europe’s sweltering summer continues, trades unions are mounting a push for new laws to counter deadly heat stress that is linked to an estimated 230 workplace deaths a year.
This year’s toll may be even higher, with 1,300 excess European deaths already connected to the June heatwave by the World Health Organization, and other estimates running as high as 20,000.
Continue reading...PS5, PC, Xbox Series X/S; Ubisoft Singapore/Ubisoft
Ubisoft has removed all the boring parts of pirate life from its fantasy RPG, creating something more focused and fun
Edward Kenway isn’t your dad’s Assassin’s Creed protagonist. Neither sworn to ancient oaths nor given a noble destiny, he’s just a guy who likes coin, dislikes rules, and whose gold-chasing, rule-dodging lifestyle sees him embroiled in an ancient war between Templars and assassins quite by accident. After he’s shipwrecked with a man named Walpole who turns out to be a Templar, Edward assumes Walpole’s identity in the hopes of securing the bounty he mentioned.
Edward wears life lightly. The world around him is violent and chaotic, and those in his vicinity are more obsessed with double-crossings than a Mission:Impossible movie writers’ room. Ed just smiles, undeterred by it all, and gets on with plundering. It’s all just fun and games to him, and he is set on conquering the Caribbean on his own terms. He is a brilliant extension of the player, in that way, and that’s what this remake of the 2013 pirate-themed Assassin’s Creed does so well: the sense of freedom.
Continue reading...