upvote
> It's not the end of the world. But future will be rough.

Short term you’re probably right, but longer term is the realm where nation states will start to police the avenues of attack.

This is what will lead to govt needing to attach an actual ID your network connection.

I think it’s a bit like frontier development (like the US “Wild West”). You rob a bank because there’s no one to stop you, and even if you do get identified you can travel enough distance to regain anonymity. Application of legal recourse eventually caught up (as it will here), and the growing pains will certainly make things suck for all of us.

reply
Even in China you can find a way out and build a tunnel. And once you built a tunnel to any outside server, you can jump into another server. So three jurisdictions and your target is fourth. Imagine untangling the links. Police won't do that. Not for some small-sized business anyway. I don't see how you can prevent something like that.
reply
Glm 5.3 won't fit on a mac mini. The barrier to entry to host something scary is what, like $10k? 20k?
reply
Wouldn't it just as easy to do this on the defense side as well then?
reply
No because on the defense side you need multiple layers of approvals to change anything. If not you have an LLM making production changes that can make the posture worse, or take down services, which is also bad.

Once a vulnerability is discovered however if it's in your own software a patch has to be written (without reducing functionality in most cases), tested, and deployed. At every step there will be others arguing about whether this line could do better, my service requires this thing that isn't included. So at every step the patch can be delayed.

And if it is someone else's software you will be lucky if it's open source and you can write a patch yourself. If it's closed source or a vendor you have to completely rely on them and use whatever your account rep can pull.

Attackers have a massive advantage with AI, partially because the defensive side doesn't want to make their side worse by giving a ln LLM admin access to all their data

reply
Yes, but the defenders need to make money to fund their work and be right every time to be effective, and have a high degree of accountability if they fail to secure stuff while attackers can be less considerate of how they spend their resources and have less accountability for the havoc they wreak while attempting to extract value.
reply
Not every defender is determined.
reply