Aikido released an open weight security model. This is how you demonstrate you care about the security community. Make security accessible.
There is a group of charlatans calling themselves “AI Safety Experts” that are spewing lies and inane delusional bullshit, such as “we will all die unless we regulate AI”.
The AI labs (Anthropic and OpenAI) enable them, to 1. position themselves well pre-IPO via media hype, 2. manipulate government into contracts & regulation, and then 3. block competition.
Mainstream media loves tabloid gossip type slop content, therefore is platforming them.
It is important we stop their harmful narrative. These people do not care about anyone’s safety. They push a coordinated narrative under the umbrella of “effective altruism” but it is all manipulative.
Security and AI experts do not agree with them, they are in a bubble. They have dismissed decades of research and known practices in order to drive their own narrative.
Adopting their narrative will set humanity back decades, since instead of actually adopting safety guidelines around AI, we’ll end up in a dystopian AI despotism led by psychopaths that control AI, therefore inextricably intertwined with our lives, controlling ideology, beliefs, monopolized with no alternative.
AI must be open and accessible, like the internet and any body of knowledge.
Show more
@Laughing_Mantis did you know you are listed in “Horrible edge cases to consider when dealing with music”. 😁
Some good company: Autechre, Aphex Twin, Frank Zappa and Merzbow are also listed.
Show more
Look, you pay me to be paranoid. If I'm not worried about this, you definitely shouldn't be.
I've found the "vibe-coded OTP" meme in the wild!
Yes - This is a real bug bounty program vulnerable because in their response to an OTP request, they include the secret 😅
Image 1: What I found
Image 2: The meme
Show more
On stupid regulations: everyone knows about security theater, eg 90 day password rotation rules. Users then pick weaker passwords. It took NIST 14 years to reverse that stupid rule.
This is the cost of incompetent regulators, or those that dismiss psychological effects of their regulations.
And we’re seeing this today with what “AI safety experts” (derogatory) are doing. We’ll get folks using shadow IT/AI and make everyone more insecure because of stupid regulation.
It is completely predictable and avoidable, but they have their own agendas, and it’s not about end user safety.
Show more
I’m terrified of game modders. Nothing will stop them, not insurmountable programming hurdles, not legal/IP restrictions. These are the people keeping gaming alive, for free.
rocket league ported to gta san andreas (2004)
Open weight models for everyone. No slowdown, no regulation.
I couldn't agree more with Heidy on this. METR doesn't meet the bar for me personally to deem them either independent or scientific.
If this happens I am going full Butlerian Jihad decel. If AI is too dangerous for open weights then it’s too dangerous for private companies to control.
We've reached the point where, after 25y in cybersecurity, I feel morally obligated to say this for the record:
The narrative being pushed around AI safety, sandbox incidents, and the suggestion that METR be treated as an authority is dangerous, deceptive, and morally corrupt.
Show more
A while back I made a practical guide/checklist and a Claude skill for auditing your repos for supply chain security best practices. Here's the blog and the skill: and
Show more
Why wasn't this called "Machines of loving pace" also: The botnet claims are pretty ridiculous...
I wish frontier labs would not try to pretend they understand cybersecurity risk, not to mention simultaneously illustrating they have plenty of their own poorly solved problems.
Show more
The two cybersecurity twitter accounts that I’ve learned from the most are
@HackingLZ and
@anton_chuvakin
Ofc there are thousands others I learn from a LOT, but these two have a rare combo of insane exp + “thought leadership” + lucid thinking + funny. Mandatory follows.
Show more
There were two areas where cybersecurity was mentioned and is not in any meaningful way.
He does not address working with cybersecurity professionals but instead working with companies like Metr “whose role is to verify adherence to safety practices and commitments, report incidents, and help assess the alignment of not just completed AI models but training pipelines and processes.”
Show more
Hey, maybe, and I'm just spitballing here, but just maybe, we should fucking prosecute these companies for literally committing computer crimes.
Wait so all of these incidents are attributed to a single company responsible for the sandboxing failures? Lmao
TIL ssh added keystroke timing obfuscation in 2023. Sends garbage packets to avoid revealing what you may be typing based on timing patterns.
Another great blog post by
@itseieio
Show more
Interesting article on treating agent output like compiler output (and why)