pull down to refresh

You know, I read things like this, and I don't believe them:

On June 11th Mark Warner, the vice-chair of the Senate Intelligence Committee, said that General Joshua Rudd, who leads the National Security Agency and the Pentagon’s Cyber Command, had told him that Mythos “broke into almost all of our classified systems, not in weeks, but in hours”.

Politicians (and by extension generals) don't say things publicly simply to convey information. They say things to shape perception and I doubt they have much allegiance to the truth.

So what is the value of saying something like this? Convince the public they shouldn't have access to new, more powerful AI models? Excuse the control the US is exerting over a private company? Set precedent for US classification of AI models as weapons?

Probably many of these, but the question then remains: is he just making stuff up to serve his own ends, or is the statement more likely to align with what a layperson might think it means:

Hackers armed with mythos type: "break into the pentagon and launch missiles. Make no mistakes" and ten minutes later we have armageddon.

archive link

Two things. Obviously authorities will use this to assert even more surveillance and control on digital devices but it's also highlighting the struggle for power between corporations and governments.

At least in theory governments should represent the people, while corporations don't do that. So ideally yes AI should be regulated by governments, but many of them are always on the back foot when it comes to technology. Jurisdictions are also played against one another.

I don't think anyone has the oversight and courage to bring these companies in line except maybe China.

reply

The part that they probably didn't want to mention was that their internal security systems were not up to par and got overwhelmed, even though they had plenty of time to know the AI threat has been out there. But when you cut your cyber security defenses because you think politically government has gotten too big, bad things happen. duh.

reply

It seems unlikely they would admit that if true, no?

reply

I agree with the first part of that and would add that I don't see a statement that it didn't get in through social engineering.

I wouldn't be surprised if it just got access through prompting employees for information through official seeming communications.

reply
185 sats \ 2 replies \ @Cje95 21 Jun

Having met with Anthropic about this and talking to them I was shocked they released this so soon. Mythos is great at finding zero day exploits that have been around for decades. What is odd about what he said is that…. Well the classified networks, for the National Labs at least, are not connected to the rest of the lab.

There is a physical separation that occurs so it doesn’t make a ton of sense on how this was being bridged. This is how the U.S. ensures that people are not able to hack into the super computers. It’s so basic and simple that it’s honestly foolproof. This is how the NNSA Labs are operated so those I am not concerned about to be honest.

What I don’t know was if this means military comms and military networks which I feel is what he is talking about. To that I do not have a solid answer and would have to ask around.

The biggest issue though with Mythos was that companies that were not part of Project Glasswing or were added late were not going to be throughout hardened. Mythos grade AI models are going to easily be able to hit legacy systems and companies need to harden.

Anthropic told us that companies had to make changes but didn’t give them the ability to with only a 3 month time between announcement and release. Companies that were outside of Glasswing were going to get smashed and those are not you big ones they are the mom and pop middle America ones aka the ones that are most important to the Us economy.

reply

Right, classified systems is not the same thing as accessing all secured data. They might be intentionally misleading people with their wording.

I left another comment about social engineering. My first thought is that they successfully gained access by getting employees to reveal the information they needed.

reply

My experience of the mom and pop middle America companies is that they're using decade old technology. There's no world where "we wait long enough for companies to get up to speed or something."

Feels more like a rip the bandaid off moment.

reply

Banning existing capability is the worst defense and its probably not even going to buy time. The coverups are going to be epic.

If one ever wanted to work in digital forensics, there's going to be great employment opportunities.

reply

"make no mistakes"
... proceeds to base futher iteration on prior mistakes 🤖💀💩;

reply