Hacker Newsnew | past | comments | ask | show | jobs | submit | anonreplier's commentslogin

Right wing selling off national assets on the cheap: good Left wing blocking off national assets: bad

Why is this being framed as 2 types of users, lovable pranksters and fraudsters? There's a whole spectrum between these 2.

Also I'd like to know if a "joke" is likely fake.


I don't suspect there is a uniform spectrum between those two. I think this is something that's going to be clinal, which we see in a lot of other comparable social contexts. The number of people actually willing to cross a moral threshold into outright crime is relatively small, but those are precisely the people who cause the most damage when they get away with their behavior.

Bur I don't even really think that's really relevant anyway, because whatever the density of "malicious" motivations is, the point here is that the fact that it only is an effort/motivation threshold that allows this technique to "block" malicious uses, and the motivation to overcome that threshold correlates directly with the stakes involved in the malicious use.

In other words, the more malicious the abuse is, the less effective this solution will be: the boundary of its usefulness will be wherever the line between pranksters and actual criminals happens to lie.


Your idea of a criminal seems to be hypercompetent and think of everything. These do exist, but most criminals are not very smart. Smart, dedicated, technical people can typically make more money legally.

Your argument applies to any imperfect security technology -- aka practically all of them.


> Your idea of a criminal seems to be hypercompetent and think of everything.

No, my idea of a criminal is someone who is motivated to commit crime, and I feel that we've already established in this thread that the approaches we're discussing are motivation gates far more than competence gates.

> Smart, dedicated, technical people can typically make more money legally.

Then who's been running all the botnets, writing cryptolocker malware, and running phishing scams for the past couple of decades?

We've always had script kiddies, and now we have people using AI itself to do malicious things. Technical skill has never been an obstacle for sufficiently motivated scammers.

> Your argument applies to any imperfect security technology -- aka practically all of them.

Ultimately, everything has weaknesses, and with enough effort, most measures can be circumvented. But how much effort is enough varies wildly between solutions.

There's a huge gulf between a "no trespassing" sign, on the one hand, and a concrete wall topped with barbed wire, on the other. The "no trespassing" sign only keeps out people willing to obey it; the concrete wall keeps out anyone who isn't willing and able to accept the time, effort, and risk necessary to climb over it or knock it down.

And the point is that using digital signatures to distinguish AI-generated media from hand-made media is much closer to the "no trespassing" side of things than it is to the wall. Maybe it's analogous to a gate with a latch you can open from the other side if you reach over in just the right spot.


> We already could do that with VMWare Workstation and VirtualBox, since at least 2010.

Yes but MS obviously viewed it as important enough to bring it inside their ecosystem.

As for the POSIX subsystem in NT, MacOS is POSIX compliant but Apple provide virtualization APIs to run Linux.


Because nowadays Linux ABI is more relevant than pure POSIX compliance.

BSDs and all surviving mainframes and micros also have either Linux VM support or syscall compatibility.

Microsoft saw those geeks that were buying Apple as shinny Linux, and then complaining about lack of compatibility, or that they only cared about POSIX toys but not really Linux proper, and saw a business case in shipping Linux in the box to counter that.

Which had they kept and improved POSIX support since Windows NT 3.51, that would never been a matter to discuss about.


What applications?

we're talking about logs for finger here, not bank transactions

Well, the brainchild of YC Founder Robert Morris, the Morris Worm, exploited a zero-day in fingerd, so yes, after 1988, fingerd was extremely important for network security.

https://en.wikipedia.org/wiki/Morris_worm


I'm not sure a hard copy would have particularly helped

FINGER IS VERY IMPORTANT!

ah my bad :D. i wasnt talkin about bank transactions but yeah :p not finger logs either haha.

Perhaps you can offer your time to proofread the website?

and when malware is discovered in the rare case of signed apps signing can be revoked

Signature revocations are functionally equivalent to malware definitions and correspondingly don't actually require code signing.

Except that it's easier to invalidate an entire signing certificate than to hope your malware definition satisfies all mechanically generated permutations of the malware.

How does that help you when the malware authors can get more signing certificates the same way they got the first one?

Notice that this is easier for malware authors to do than ordinary people because their business is compromising others' machines, so then they can use the signing keys of any victims who have a developer account, or sign up for new ones using stolen cards from any of the victims.

Meanwhile you would then have Apple revoking the victims' signing certificates and screwing their honest users who can now no longer install the non-malicious software they previously released.

The entire premise is a scam to extract an annual fee from a million small developers.


You know what's even easier than getting a signing certificate for malware? Not bothering with signing at all.

And revoking a cert for one "dev" does not mean revoking everything, as for them stealing signing keys from other devs (not typical users, but security literate) how often does that happen, especially in the case of apple with sandboxing etc?


Hmm does this "aesthetic" include shrinking national parks?


Birds get confused when they have to much greenery, you need more land strip-mined for coal to keep them safe while migrating.


Why would Google be the only interested buying party?


They wouldn't be the only party, but they are in my opinion the most likely party.

What the people that can monetize it? Microsoft, X, IBM, Salesforce, Discord, Google

Microsoft would likely buy OpenAI due to their investment and integration with OpenAI. Making Anthropic not that valuable.

Google would likely buy Anthropic due to their investment and ties to Anthropic.

X, Salesforce maybe. Not sure Discord has the money. No idea if IBM capable of growing.

All this changes if Anthropic figures out a moat/sticky product that doesn't just depend on having the best LLM. If they pull off https://claude.com/solutions/healthcare then all bets are off.


But there would be enough other interest that they would not be getting bought "for cheap"


Not hard to accelerate something going that slowly


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: