• 0 Posts
  • 43 Comments
Joined 3 years ago
cake
Cake day: March 22nd, 2024

help-circle
  • And they will say things like the writer of this piece who says ‘we know how they work.’ We don’t, actually.

    Okay, but we really actually do. There’s nothing magic about the kind of statistical brute force that these things operate on. The training stage breaks down and identifies patterns in the source data, and the operational model uses those patterns to “predict” what a person would say next. The patterns that these things identify are incredibly complex and can’t be easily traced or understood in practical terms, but fundamentally these are still stochastic parrots.

    Especially if you want to go into the Christian context, no church is going to ascribe the ineffable miracle of life to a multiplication of matrices, no matter how many dimensions they have in the math.










  • Joyless and also bloodless. Like, there is plenty to criticize about the “I guess I got isekai’d to Gor and now I’ve got a sexy slave harem” premise. But somehow he still manages to write with barely any actual empathy for the victims of that system, foregrounds how hard it is for our hero to bravely abstain from that sweet wolf sex and how maybe it’s not even the right thing to do, and then after confronting the horrifying realities for all of one scene proceeds to write the character out of the story without even giving her a fucking name in the text. Like, he somehow wrote a story about rescuing sex slaves that feels more pro-sex-slavery than a story that just embraces the sleaze of it.



  • It might be wishful thinking, but it would also answer the question: why now? It’s not like the concerns are meaningfully different now compared to when the bubble started. If they were so convinced that the AI future was both inevitable and possibly catastrophic, they could have followed Yud into the “research foundation” game rather than accelerating the timeline. I guess they’re probably more convinced than I am that the latest round of security breaches are actually a sign of new capabilities in the models, but it still feels really convenient. Frontier model advancements have been slowing down and costs have been accelerating exponentially, and now they’re taking the line that they’re choosing to slow progress and spend less money on arguably their biggest cost center.









  • I need someone with more actual software dev knowledge to back me up on something. It looks like there’s a new zero-interaction remote code execution vulnerability in most major vibe code generators. I’ve seen it called Plugin4Shell because apparently we’re still doing marketing names instead of actually getting CVE numbers for these things. The link there seems like a decent overview.

    The bug, dubbed Plugin4Shell, breaks SHA pinning, the mechanism developers rely on to lock an installed plugin to a specific, reviewed version of its code. Pinning is supposed to mean that once a plugin passes review, it cannot change without the developer’s knowledge.

    AIR’s researchers found that every one of the four agents checks out the pinned commit without verifying the checkout landed there, letting an attacker swap in malicious code while the pin still looks intact.

    So if I’m reading this right, the mechanism to cryptographically ensure that your AI agents are using the code they say they are just was straight-up not being checked? This feels like it should go on the big board of incredibly obvious failures, but I’m not familiar enough with the git side of things to be absolutely confident in that. Like, if a person tried to pass off software that did this it would have significant career implications, right? Or am I misunderstanding something somewhere?