I don't suspect there is a uniform spectrum between those two. I think this is something that's going to be clinal, which we see in a lot of other comparable social contexts. The number of people actually willing to cross a moral threshold into outright crime is relatively small, but those are precisely the people who cause the most damage when they get away with their behavior.
Bur I don't even really think that's really relevant anyway, because whatever the density of "malicious" motivations is, the point here is that the fact that it only is an effort/motivation threshold that allows this technique to "block" malicious uses, and the motivation to overcome that threshold correlates directly with the stakes involved in the malicious use.
In other words, the more malicious the abuse is, the less effective this solution will be: the boundary of its usefulness will be wherever the line between pranksters and actual criminals happens to lie.
Your idea of a criminal seems to be hypercompetent and think of everything. These do exist, but most criminals are not very smart. Smart, dedicated, technical people can typically make more money legally.
Your argument applies to any imperfect security technology -- aka practically all of them.
> Your idea of a criminal seems to be hypercompetent and think of everything.
No, my idea of a criminal is someone who is motivated to commit crime, and I feel that we've already established in this thread that the approaches we're discussing are motivation gates far more than competence gates.
> Smart, dedicated, technical people can typically make more money legally.
Then who's been running all the botnets, writing cryptolocker malware, and running phishing scams for the past couple of decades?
We've always had script kiddies, and now we have people using AI itself to do malicious things. Technical skill has never been an obstacle for sufficiently motivated scammers.
> Your argument applies to any imperfect security technology -- aka practically all of them.
Ultimately, everything has weaknesses, and with enough effort, most measures can be circumvented. But how much effort is enough varies wildly between solutions.
There's a huge gulf between a "no trespassing" sign, on the one hand, and a concrete wall topped with barbed wire, on the other. The "no trespassing" sign only keeps out people willing to obey it; the concrete wall keeps out anyone who isn't willing and able to accept the time, effort, and risk necessary to climb over it or knock it down.
And the point is that using digital signatures to distinguish AI-generated media from hand-made media is much closer to the "no trespassing" side of things than it is to the wall. Maybe it's analogous to a gate with a latch you can open from the other side if you reach over in just the right spot.
Because nowadays Linux ABI is more relevant than pure POSIX compliance.
BSDs and all surviving mainframes and micros also have either Linux VM support or syscall compatibility.
Microsoft saw those geeks that were buying Apple as shinny Linux, and then complaining about lack of compatibility, or that they only cared about POSIX toys but not really Linux proper, and saw a business case in shipping Linux in the box to counter that.
Which had they kept and improved POSIX support since Windows NT 3.51, that would never been a matter to discuss about.
Well, the brainchild of YC Founder Robert Morris, the Morris Worm, exploited a zero-day in fingerd, so yes, after 1988, fingerd was extremely important for network security.
Except that it's easier to invalidate an entire signing certificate than to hope your malware definition satisfies all mechanically generated permutations of the malware.
How does that help you when the malware authors can get more signing certificates the same way they got the first one?
Notice that this is easier for malware authors to do than ordinary people because their business is compromising others' machines, so then they can use the signing keys of any victims who have a developer account, or sign up for new ones using stolen cards from any of the victims.
Meanwhile you would then have Apple revoking the victims' signing certificates and screwing their honest users who can now no longer install the non-malicious software they previously released.
The entire premise is a scam to extract an annual fee from a million small developers.
You know what's even easier than getting a signing certificate for malware? Not bothering with signing at all.
And revoking a cert for one "dev" does not mean revoking everything, as for them stealing signing keys from other devs (not typical users, but security literate) how often does that happen, especially in the case of apple with sandboxing etc?
They wouldn't be the only party, but they are in my opinion the most likely party.
What the people that can monetize it? Microsoft, X, IBM, Salesforce, Discord, Google
Microsoft would likely buy OpenAI due to their investment and integration with OpenAI. Making Anthropic not that valuable.
Google would likely buy Anthropic due to their investment and ties to Anthropic.
X, Salesforce maybe. Not sure Discord has the money. No idea if IBM capable of growing.
All this changes if Anthropic figures out a moat/sticky product that doesn't just depend on having the best LLM. If they pull off https://claude.com/solutions/healthcare then all bets are off.
reply