SecEng @tines_hq Previously: SWE @Datadog CEO/ Founder of @graplsec SecEng @Dropbox SWE @Rapid7

New York
I've now spent $20k on finding vulnerabilities in 3B and hardening the system 😅 It was really fruitful though. One of the fun approaches was to pretend that we didn't use gVisor and *then* see how attacks would work. Basically "assume gvisor fails".
3
1
36
8,382
Basically, I kept placing the attacker into increasingly privileged positions, like "assume they control this entire service" or "assume gvisor had a host escape", then closing off paths at each of those layers. Very fun, led to a ton of hardening work.
2
7
789
Of course... gvisor doesn't really fail. And we harden the hell out of our gvisor too lol Still, always gotta assume otherwise. If we relied entirely on gvisor we'd be one layer away from getting owned.
7
665
Colin O'Brien retweeted
It's simple: if Cyber-critical AI models were able to find and exploit vulnerabilities in critical attack surfaces of systems designed using security engineering principles like OpenSSH, firecracker, seL4, etc, we'd have evidence of it by now. We already have the tools and know how to defend against and contain advanced AI, it just isn't applied everywhere that it needs to be yet.
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
12
29
163
16,873
I don't really think you need access to frontier models to build safe software that resists AI enabled attackers, although it is nice. The principles are the same as ever. You really need AI to tell you to run gvisor? You really need AI to tell you to run apparmor/selinux?
1
8
285
You don't need frontier cyber-enabled models to say "set up an apparmor profile to confine the gvisor sentry", you just need to know your shit.
1
4
136
I do have access tho and it's nice
53
Not a big name but this is very clearly true and we have strong evidence for it. Mythos failed to crack Firecracker. It has largely exploited systems that are not particularly hard targets. Existing tech can handle this when deployed properly.
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
9
26
181
8,354
Consider that tech like gvisor has been extremely strong for a long time and is maintained by Google, a company with access to unlimited tokens and frontier models. Consider that gVisor is just one layer. You can add seccomp, you can wrap it in an additional container, etc.
1
1
27
472
Wrapping gVisor in a docker container would have significantly limited at least vulnerability it has had in the past. You can go so far with existing technology, it's never been easier.
20
335
Spent some time looking over privesc POCs. Not just the vuln, the full exploit chain. Often there are interesting primitives that you can't just patch ex: info leaks exposed by certain files or operations. I've closed a number of those out in 3B.
1
4
300
There are always other ways to build up the chain, other ways to get timing info or leak ptr addresses, etc. Still, I think it's helpful to close these where possible. Your container doesn't need kpagecount.
1
88
TBH closing these up feels a bit like trying to remove gadgets, it's sort of whac-a-mole. It's also extremely low cost and I think educational, helps you understand underlying facilities and exploitation paths, kills "out of the box" POCs as well.
60
I am surprised at how many people seem to think that beliefs are a matter of proof. We prove very little that you take for granted, like physics. We postulate theories and evaluate against the evidence, forming an inference to the best explanation. We do not "prove".
Consciousness is the only thing we know from the inside. So why are we so sure AI has none?
1
2
201
A lot of what I'm seeing is "you can't prove that" and... who cares? You can't prove very much at all in the world. I can't prove that humans experience phenomenal states, and yet I believe that I do, and the simplest explanation is that others do. This is an *inference*.
2
49
I think it's really cool that OpenAI is requiring hardware backed authentication for advanced model access, I think more companies should radically incentivize people grabbing a yubikey. And a solid implementation here, requiring two separate keys (or one passkey).
1
6
169
The PSL is broken, browsers need to give webpages the ability to host iframes on virtual hosts.
99
I think it is fair to say that AI consciousness is a matter of inference to the best explanation, and the best explanation is "a system trained on language that expresses phenomenal experience is capable of generating text about phenomenal experience".
Replying to @hamandcheese
I agree people are overly dismissive and don't engage at all, just holding to simple beliefs at face value. That's annoying but whatever. The idea that we're at a point to seriously consider things like "what if Claude is in pain?" is just really not something I think is worth it, actually I don't even think it is worth much research or interrogation at all just like I don't think that dualism is worth much consideration and research into it is a huge waste of time. Even if we take your view seriously it's simply not well supported that LLMs, even with RL, are conscious. Benchmarks show they fail to encode structure, relying on statistical shortcuts alone. Arguably, and evidence by biology, functions follow from specific structures, and I think that should be evaluated against your position (and I think it wins even if I don't hold to it). I do not think that in-context learning is meaningful here, it just isn't analogous to the continuous pressure and plasticity, and I think I'd rather appeal to structure than accept otherwise. > "much of the brain (>90% by volume) exists solely to run learning-from-scratch algorithms" Who cares about volume? I mean, seriously, who cares? I think any conclusion based on this is just totally in need of justification rather than a mere appeal. You sort of get to the point after this but I think you're better off dropping the entire "volume" side of things tbh. You also do not address rebuttals to this point, which I think are very strong. > "The brain likely implements both symbolic and statistical learning processes" Yes. > it stands to reason that most of the brain's realized competence is indeed "learned from scratch" in Byrnes's specific sense. I don't think this is well evidenced enough. > The answer from computational neuroscience is a resounding yes. Absolutely not. The paper does not indicate this whatsoever nor does it imply broad concensus. "Resounding yes" is a total misframing when even the citation is unsupportive . You're making an empirical claim, this deserves a survey / empirical evidence. I think that most importantly we already have excellent explanations of LLM behavior - a model trained on text that includes a phenomenal vocabulary reproduces that vocabulary, which demonstrates virtually nothing about function. I genuinely feel zero reason to accept otherwise at this point. > universality suggests that a next-token predictor trained on human-generated text will — in the limit — leap from memorizing surface-level patterns to grokking the [underlying generator function](secondbest.ca/i/137284619/ag…) of that data, i.e. the language networks in the brain. This seems to be the case empirically. I disagree. Empirically we see the opposite - a total failure to generalize and instead a reliance on statistical shortcuts. The fact that LLMs and brains share information does not indicate that they share function, or at least it's weak evidence. Anyway, I respect the amount of effort put into your post but I think it's nowhere near the best explanation, even when I contrast it with views that *I don't even hold*. I'd engage with it for fun but I don't think I'd engage very seriously. "Is Claude in pain?" is a question that likely is best answered by an inference to the best explanation because we obviously lack epistemic access, and I think *by far* the best explanation is my previous argument - a thing trained on text will output text. Sorry I didn't get through more of this tbh but I wanted to prove at least some reasons to not hold strongly to your view and why I don't think there's good evidence. I'd have to read the papers in detail and explain why I think things like in-context learning are not meaningul here.
2
146
Colin O'Brien retweeted
Sorry, this is pure FUD. Google API keys are very simple, people just don't follow very simple steps. All you need to do is: 1. Sign in to google cloud console 2. Create a new project 3. Enable billing on that project 4. Search for numerous "services" that you need to enable for that API 5. Find out there are more you need to enable to actually make it work 6. Go and enable them. 7. Create the key 8. It still doesn't work and you keep wondering why and then spending days with customer support (after many different wrong AI generated answers that lead you to a wild goose chase), you find some hidden webpage that oh wait, you need to create a key in ai studio for this now 9. ai studio says you are only on tier -43 so you can only do transactions of less than $0.2 in a day 10. Then you go to openrouter and make a key and use it. It's extremely simple.
The worst part of every project is if you need some Google API key.
56
53
1,111
67,118
Seeing `curl | bash` without `--proto=https` 🤢
1
92