When you (my which I mean "I") see a Fediverse post in Polish and your first reaction is to think it's rot13 text...
When you my which I mean I see a Dan Lyke / comment 0
When you (my which I mean "I") see a Fediverse post in Polish and your first reaction is to think it's rot13 text...
Just looked up a Unicode character and Dan Lyke / comment 0
Just looked up a Unicode character, and when I came back to the tab of course it was displaying one of those "your Mac has forty gazillion viruses" fake Norton malware pages.
So let's not mince words: When you build a web page that requires JavaScript, you are working in concert with malware vendors.
If I could browse the web without JavaScript, I would, but I can't, because you collaborators with and enablers of evildoers keep building web pages that require it.
Using bad software practices for good PR Dan Lyke / comment 0
Ariadne Conill 🐰 @ariadne@treehouse.systems summarizes the Hugging Face OpenAI agent intrusion timeline as:
the epic OpenAI-huggingface hack wound up being a typical kubernetes fuckup of using host mounts (giant footgun) incorrectly
Now that Anthropic has jumped on the bandwagon, abadidea @0xabad1dea@infosec.exchange summarizes the current state as:
OpenAI: we put our evilest AI in a sandbox that did in fact have an internet connection but mediated through a proxy that was only supposed to allow downloading python junk. It circumvented the proxy and we failed to notice for FIVE DAYS that it was going on an interstate crime spree with the internet connection it wasn't supposed to be using instead of solving the benchmark. Haha no we don't believe we deserve to be criminally liable, but buy our stuff and maybe one day you will have the honor of taking the fall for our product!
Anthropic: we put our evilest AI in a "sandbox" by telling it in its prompt that it had no internet connection. Reader, there was no sandbox. It was just a normal internet connection. The AI uploaded a malicious PyPI package to the real public internet. The ethical guardrails failed because the AI concluded the prompt about the sandbox couldn't possibly be a lie, because the system date is 2026, which is clearly fake and wouldn't be seen on the real internet, which ended around 2023. Oh no, how could we have foreseen or prevented these crimes? We are helpless in the face of the genius of our creation but cautiously optimistic that everything will be fine 🙂
Hugging Face: if we complain about all the crimes committed against us, we will be sued off the face of the earth, so here's a technical deep-dive on how cool and fun it was to be victimized 🫠
whole class of Microsoft Copilot as an Dan Lyke / comment 0
The whole class of Microsoft Copilot as an environment for self-replicating worms sure is making me think about humans and memes a lot.
Sam Altman, Hellsmith Dan Lyke / comment 0
I spent the weekend going through my mom's feed with her, trying to exist in the world their daemons operate. They keep sending her stuff that makes her sad: lonely abandoned moms, no-contact kids, mournful poetry, and a lot of it is AI. And because it tugs at a silent fear, she watches them and they give her more and more of it. I was like, Mom. Look at the fingers on this steering wheel, how these two are webbed, like a duck's foot. She told me that these words were from a mother's heart.
One hesitates to "give it to them," but there is something that these machines are adept at - the manufacture of utterly bespoke hells. Sam Altman, Hellsmith.
AI Working through Word Dan Lyke / comment 0
Whee! Context Collapse, Part 3 - AI Worming through Word
The reported scenario is:
- Malicious instructions hidden in an externally shared document could make Copilot alter drafted or edited documents in Word and propagate the attack to new documents.
Via Microsoft confirms an AI worm is propagating through Copilot and other MS apps, Via.