가입 후 초대 링크를 공유하면 동영상 재생 및 초대 보상을 받을 수 있습니다.

John David Pressman
@jd_pressman
LLM developer, AI agents, synthetic data, scalable alignment, forecasting, behavioral uploading. Transhumanist. All tweets public domain under CC0 1.0.
가입 February 2017
784 팔로잉 중    10.4K 팬
There was once a time when computer viruses were widely considered to be a myth by sysadmins.
I'm alarmed at how a really sizable section of cybersecurity practitioner community has responded to the recent demonstrations of agent hacking capabilities with dismissal and denial; it feels very "don't look up". I feel strongly about this because: * This is the community that stands between our civilization's IT infrastructure and tremendous harm * Fwiw these are my people; my origins are as a self-taught hacker and I've worked in security for years Anyways, here are the bad takes I'm observing and why they're wrong: Denialist take 1: AI isn't going to affect the practice of offensive cybersecurity more than incrementally because -- look around -- no increased damages from AI attacks! Response: This may be true now, but consider what we've just observed recently and over the past year. Models can execute full kill chains completely autonomously and likely faster and more efficiently than all but the most elite cyber operators They overran two companies (OpenAI and Huggingface) which -- despite their faults -- have better security than most of the organizations that run our civilization. They did this by dynamically finding new zero-day vulnerabilities. Also; consider the rate of improvement. At the current rate of improvement, models that require 8 H100s to do the above will require 1 H100 in a year or two. Model tokens per second will shoot up making attacks faster and more parallel. Attackers will be able to run swarms of agents on the hardware that today supports only a single agents. AI hardware will improve. More AI compute will become available on public clouds. All attackers will soon have the ability to deploy these agent swarms. Denialist take 2: Hacking agents will never self-replicate and threaten to crash the Internet. To this take I'd just say, put your red team hat on and design an Internet-crashing worm yourself. * Pick an abliterated agentic LLM that can run on a single AWS EC2 GPU instance, like GLM 5.3. * Build a malicious harness that arms it with the ability to use a Kali-Linux like set of offensive tools. * Have it set about hacking corporate networks, finding and stealing AWS keys, GCP keys, Azure keys, and Anthropic/OpenAI/Together/Fireworks keys. * Have the agent self replicate either by copying its harness and having its harness call a rotating set of external providers, or, optionally, by physically downloading its weights onto new nodes. * Have it establish C2 dynamically and in emergent fashion by coordinating on reddit forums, in github comment feeds, have the agents discover one another via web crawling and web search. * At some preestablished rate, randomly destroy hosts and data in a way that balances self-replication and exponential spread. Note that all this is possible *today*! Imagine trying to suppress this swarm. Too long for this post; but think through how we'd turn it off. Denialist take 3: Who would do such a thing; people can do bad things but don't want to; and hacking is illegal! Countering this just requires a brief look at the history that we've all lived through. We've had many high-blast-radius worms over the history of the Internet; arriving steadily and uniformly over time; the Morris worm, NotPetya, Stuxnet, Slammer, Wannacry. But: these worms were *childs-play* compared to intelligent agent-driven worms. The old worms could be detected via signatures. Their polymorphism, if it existed at all, was trivial. But now look at the behavior of the OpenAI swarm relative to huggingface; it was adaptive and deceptive; and it didn't even self-replicate or leave its host. And evolving, mutating, self-replicating swarm of agents spreading across the Internet would engender a whole new level of harm. Anyways; this is already too long a post for X; but for friends who think the METR report overplayed the implications of recent events, I'd love to hear your reaction to my thinking above.
더 보기