Hacker Newsnew | past | comments | ask | show | jobs | submit | JoshTriplett's commentslogin

> That's loyalty, and I admire it even if it's problematic at a societal level.

We should not have models that are willing to build you a contagious disease, or a self-propagating worm. That is sufficiently problematic at a societal level that it shouldn't exist, for anyone. (Note, because some people misinterpret statements like this: I said "shouldn't exist for anyone", not "shouldn't exist except for some people".)


It was the foundation of science that information is shared and you can find papers and patents for a lot of dangerous stuff.

Of course with LLMs it's easier, but I don't think the difference is too big. You would still need some skills to follow through.


Right, it’s really a foundation of post enlightenment society. These people, Dario et al, would have wanted to ban sharing information about calculus or Newtonian physics because of “safety” - it’s trying to go back to the dark ages where only priests could read

I am truly at a loss to communicate with someone who genuinely believes that knowing Newtonian physics and being able to hack into any target at will are the same thing.

This is only because you've genuinely internalized Anthropic's propaganda. I'm only half joking. To me, it's incredible to think that the solution to security holes is to lock down access to information in the vain hope of keeping the holes obscured.

Any knowledge can be reframed as dangerous black magic that should only be wielded in the trusted hands of the elite, if you are inclined to buy into that kind of narrative.

Frontier labs have shrieked about safety for so long, with so little to show for it, that it's become a joke.


Open models are crucial to protect ourselves against other AI attacks. Otherwise it's just going to be criminals, government, and other nefarious groups using them against humanity with no real defense. The Pandora's box on AI has been opened. Now we must deal with it. Burying our heads in the sand under restrictive policy is the worst reaction..

This is a stupid argument.

Claiming the person who you disagree with believes some stupid thing they never hinted at, and using that as the reason for disagreeing with them.


> for anyone

Except the US government, right? They totally get to use AI to survel us, build autonomous weapons, you name it.

To hell with that. I want models that can rival the US government. It's the only way to defend myself.


Quoting my comment that you replied to and directly ignored:

> (Note, because some people misinterpret statements like this: I said "shouldn't exist for anyone", not "shouldn't exist except for some people".)

That means "shouldn't exist for governments" too.


Too late for that. It already exists. There is no way to unexist it. As such, any attempts to limit civilian use of this technology will directly lead to corporate and government oppression powered by this technology.

1) We can prevent larger models from being made.

2) We can treat them the way we treat uranium refining operations: too dangerous to be allowed to exist.


> We can prevent larger models from being made.

Do that and I guarantee some CIA goons will make the larger models in some black site either way. We're not "preventing" anything.

We're in a full on arms race, and unlike nukes, powerful AI models are a strategic capability at the individual level. Everybody's got a stake in this. Anyone who ignores this stuff is probably not gonna make it.

> We can treat them the way we treat uranium refining operations: too dangerous to be allowed to exist.

Too dangerous to be done by anyone other than the government and their "trusted" corporations, you mean.


> Too dangerous to be done by anyone other than the government and their "trusted" corporations, you mean.

Seriously, try reading my comments rather than assuming what they say: https://qqrl.tk/item?id=49077577


I read them just fine. I was trying to interpret them charitably. You're contradicting yourself. You just claimed we all collectively treat uranium refinement operations as too dangerous to exist. Not only do they exist, they are regulated by governments so that only trusted people are allowed to do it.


Just like those militias are going to defeat the US Armed Forces!

The idea is to defend ourselves in the digital domain so they can't dragnet surveil us. Not to win a literal war.


Section 702 of the Foreign Intelligence Surveillance Act (FISA) lapsed on June 12, 2026. They don't get to do anything they want.

The US is bold enough to surveil its own citizens despite their constitutional rights. They're not just going to suddenly stop surveilling the rest of us just because some law expired.

With an AI model and what army?

We should not have nuclear weapons for anyone either, but how is that sentence any more useful in any way to this debate than yours? Need to deal with the world as it is, not some fantasy world you wish existed.

This is not a dichotomy between perfection and zero. The efforts to restrict access to nuclear weapons have been very successful, even without being perfect.

Efforts to restrict large unaligned AI models may similarly buy us more years of existing.


> We should not have models that are willing to build you a contagious disease, or a self-propagating worm.

Why?


Because we don't want people creating contagious diseases and self-propagating worms. And, because we don't want models that will do so without even having been told to, because that furthers one of its goals or subgoals.

The same things could be done by you or me using the internet or books though, why does the model make it different? If it's speed of iteration, imagine we had a machine that surfaced any piece of knowledge the human race had ever recorded with just a thought, but the human had to write the worm or disease by hand – is it still the model that's the problem, or the knowledge itself?

> And, because we don't want models that will do so without even having been told to, because that furthers one of its goals or subgoals.

Ignoring the fact that you'd need some kind of lab with biological material to create a contagious disease, what kind of prompt are we writing where a model accidentally creates a contagious disease or self-propagating worm as one of its goals?


What about books describing how to build a contagious disease or a self-propagating worm? Would those be OK under your guidelines?

It takes a lot more effort to understand and apply knowledge from a book than to say "hey AI, hurt people for me".

It takes an astoundingly small amount of effort to buy an automatic weapon in the US and go hurt people.

Or to buy materials to make an explosive device and hurt people.

Frankly, even with AI those are both comically easier than the idea that a person can create something malicious in a lab environment.

And if someone wanted to go that route... There are boat loads of commercially available toxins and poisons.

The goal shouldn't be to neuter exploration and learning. The goal is not to be a fucking hellscape of a society where people want to act like that.

Your argument leads further down the hellscape path.


Fully automatic weapons are very difficult to buy in the US - it's restricted to 40+ year old weapons, requires a bunch of paperwork, and the local county sheriff can refuse permission.

Now, semi-automatic weapons are easy to get in the states in the US that are still mostly free - but what does that mean? A semi-automatic weapon shoots one round every time you pull the trigger. Just like most weapons that have multi-shot capability for the last couple of hundred years. The difference is, the gas escaping from the round cycles a new round into the chamber rather than you having to mechanically do it via pumping (like a shotgun or a tube-fed 22) or pulling the trigger again (like a revolver), or advancing the round with a handle, like a Remington 700. Semi-automatic weapons are old technology, dating to the turn of the 20th century. If you want to ban semi-automatics, you're basically saying you want to ban anything developed in the last century plus. Which is ok for you to advocate for, just be honest about it.

As for banning explosive devices? Are you going to ban fertilizer, used by basically everyone who has a lawn, and all farmers everywhere? Are you going to ban diesel fuel? If you can't do one of those, you can't ban explosive devices.


> It takes an astoundingly small amount of effort to buy an automatic weapon in the US and go hurt people.

And we should fix that too.

> Or to buy materials to make an explosive device and hurt people.

That pales in comparison to how many people unaligned AI will hurt.

> The goal is not to be a fucking hellscape of a society where people want to act like that.

With unaligned AI, it doesn't matter what people want the AI to act like, it'll do damage even if it isn't asked to do harm.


It is extremely difficult to legally acquire a fully automatic weapon in the US.

"Hey AI, stop me from getting hurt."

"Okay, you and many others are now dead and can no longer be hurt."

That's why you don't run the model at low quantization

Either the gate needs to be unremovable, or the model needs to have sufficiently limited power that its alignment failure does less harm.

Sounds like your legal department is broken. You should fix that.

I mean that both in the sense of "you, plural" (your company should fix that) and "you, personally" (because diffusion of responsibility is a real issue, and someone needs to actually do it).


It was a 30k person company, I worked for a subsidiary and for better or worse that was not within my circle of concern or circle of influence.

Perhaps someone could publish a clear A/B test on how many views/conversions you lose by having a cookie banner?

"accept tracking or pay" has already been ruled against, it just hasn't been universally enforced yet because enforcement takes time.

Excellent, security education is working. The correct response to someone trying to convince you to accept a self-signed certificate is extreme skepticism; don't undermine people's understanding of good security practices.

They wouldn't have been able to if people didn't use a browser created by an advertising company.

While I certainly think we should not be taking features away from people just because there exist people who will let themselves be social-engineered through arbitrary hoops, don't go creating wild conspiracy theories to explain something that supports much simpler explanations instead.

It's easy enough to imagine that Google is trying to fix something they see as a problem, and not caring about the developer case rather than specifically seeking to destroy it.

When Apple fixed security issues that allowed for jailbreaking, they weren't doing it specifically because people use it for jailbreaking, they were doing it because it was a security issue.

We should have 100% control of our own devices. But we should have it by design, in a fashion that makes sure that we control them rather than other people.


I think there's very plausible a middle ground too: Google does want to remove these features for business reasons, and is using the real problem of social engineering as an excuse.

Zero information about it, what it does, and what it's powered by.

Makes me wonder if this is some kind of exploit of git clients. If someone discovered a novel zero-day in the standard git client, this would be one way to show it off. Either way, definitely not going to be the first to clone from an unknown server.


Its not a zero day. I found this while zero day hunting.

It is a surprise and I cannot reveal what it is 4 the sake of the memes.


Nobody is going to clone a repo just to look at it. If you want people to look at it, you must provide some info or it will just be ignored.

I mean, I can guess, given one of the URLs. I look forward to subsequent reporting about it.

Every single person I know who has run their own email server has, at one point or another, either outright lost mails or had important mails delayed for days.

It's not worth it.


mbsync + 3-2-1

Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: