Fokke en Sukke

F & S

Slashdot

News for nerds, stuff that matters

New MCP Specification Addresses the Main Barrier To Enterprise Adoption

An anonymous reader quotes a report from Ars Technica: This week, the Model Context Protocol (MCP), an open source standard for how AI systems interact with external tools and data sources, saw its largest update since its introduction. Most notably, MCP's protocol core is now stateless, so requests are no longer dependent on a session tied to an individual server instance. This change has the potential to address long-standing barriers to scalability.

The blog post announcing the specification, written by lead maintainers David Soria Parra and Den Delimarsky (who both work at Anthropic), says: "The highlight of this release is a stateless protocol core -- MCP is transforming from a bidirectional stateful protocol into a request/response stateless protocol. It was one of the most highly-requested features from developers who were eager to get better reliability and scalability for their MCP servers."

[...] There is also a new deprecation policy that ensures at least 12 months between when a feature's formal deprecation is enacted and when the feature may actually be removed -- with a narrow exception for critical security updates. This is again in keeping with the general "let's make this work better at enterprise scale" theme of the new specification. This update is "MCP's most important since remote MCP first launched over a year ago," Soria Parra wrote. Other additions include "Multi Round-Trip Requests, header-based routing, cacheable list results, authorization hardening, a formal extensions framework, and updated Tier 1 SDKs."

A full list of changes can be found here.

Read more of this story at Slashdot.

A Fundamental Flaw Leaves LLMs Strikingly Vulnerable To Attack

joshuark quotes a report from MIT Technology Review: It is impossible to make large language models fully secure against hacks because of a fundamental flaw in how they work, a team of researchers argue in a paper presented at the International Conference on Machine Learning, a top AI conference, this month. The claim has huge implications for the safety of this technology. By taking advantage of this flaw, which concerns how LLMs identify who or what is giving them instructions, the researchers were able to make popular LLMs spit out information they had been trained not to provide, such as how to synthesize cocaine and how to sabotage a commercial aircraft's navigation system. "There's a real probability that this is going to be a problem that's fundamentally unsolvable," says Charles Ye, an independent researcher and coauthor of the ICML paper. [...]

The ICML paper describes attacks against several of OpenAI's models, but Cui and Ye say that they have since seen similar results with models made by Anthropic, Alibaba, and DeepSeek. Cui and her colleagues wanted to find out why an attack like chain-of-thought forgery was so effective. They suspected it had something to do with the mechanism that LLMs use to keep track of where their instructions are coming from. But what Cui and her colleagues discovered is that LLMs are in fact very bad at keeping track of different roles.

In a series of experiments that looked at what was going on inside a handful of different models, the researchers found that LLMs seem to identify the role of a specific chunk of text not by the tags around it but by the style of that text and the words it contains. The upshot, the researchers claim, is that all an attacker needs to do to hack an LLM is write text that spoofs a certain role. And because roles are a fundamental part of how LLMs work, no amount of training will fully solve the problem. "There's going to be a huge economic incentive for people to do jailbreaks and prompt injections," says Cui. The best defense could be to expect the worst. Organizations shouldn't trust LLMs, and they should expect that anything done by agents could be unsafe, he says: "That's not a great solution, but it just might be what we have to do."

"It's really incredible that these things are being deployed everywhere to control super-critical systems. There's been no study of the fundamental science here. We're all doing it ad hoc."

Read more of this story at Slashdot.

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Trump claims agreement for ‘complete disarmament’ of Hamas in Gaza but support uncertain

US president’s Board of Peace says Israel will withdraw from Gaza following disarmament of Hamas but no immediate statement from either side

Donald Trump on Thursday announced an agreement for the “complete disarmament” of Hamas, calling it a critical step toward a new Palestinian government in Gaza. There was no immediate statement from Hamas or Israel on the agreement.

“This agreement is a critical step towards Gaza finally being governed by a new Palestinian government that will work closely with the Board of Peace to help the Palestinian people,” Trump said in a social media post.

Continue reading...

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Trump kondigt ‘volledige ontwapening Hamas en alle andere gewapende groepen’ in Gaza aan, Hamas bevestigt

Vorto


Woordzoeker


Cijferblok


Koprol


Aan Zet


Geen Wifi

Op vakantie in Italië: een B&B in een oud landhuis. We rijden het grindpad op en de plek overtreft onze verwachtingen.

sudoku

Je krijgt een paar cijfers cadeau, maar het grid van 9x9 moet foutloos ingevuld worden.


cinco

Als je wel zin hebt om te sudokuen, maar het liever bij een gridje van 5x5 houdt.


precies vier

Een Precies Vier bestaat uit 16 woorden, begrippen of namen, die moeten worden verdeeld in precies vier groepen van vier. Er is telkens maar één oplossing mogelijk. Welke woorden vormen een connectie?


in het midden

Wie of wat staat er midden in het nieuws? Een actuele puzzel, die makkelijker is als je het nieuws een beetje volgt.


MetaFilter

The past 24 hours of MetaFilter

"it's fun to let your imagination run wild."

"Tonight I typed just one sentence into Google Earth and put refugees near the Mexican border. Then I planted a nuclear plant in Iran. Then I put a fatal crash on a street in Amsterdam. Google's own satellite imagery underneath all three. What on earth is Google doing? Henk van Ess goes on to posit "You only censor a map that works. Every blur, every polygon, every diplomatic request was an admission that Google Earth was accurate enough to be dangerous. Governments were not worried the map would lie. They were worried it would tell the truth.,"
How to plant a nuclear plant in Iran. [Substack]

Why All the Coppers Up in Their Choppers?

Thomas Hawk posted a photo:

Why All the Coppers Up in Their Choppers?

Expo

Thomas Hawk posted a photo:

Expo

Castro Street Fair

Thomas Hawk posted a photo:

Castro Street Fair

4 Hour Shirts and 1 Hour Cleaning

Thomas Hawk posted a photo:

4 Hour Shirts and 1 Hour Cleaning