No. No. No.... please
@OpenAI. Tell me these clowns are not in charge of security. Please tell me this is a joke. Pretty please, with sugar on top. If this is not about joke, I am not sure what to say. More then that we are all doomed. They are looking at this purely from a technical perspective. You're dealing with neurological network. From this presentation I learned some things:
1. You really have no idea what happened or why.
2. You want to project a sense of control eventhough you pretty much know it's already out of control.
3. You are treating intelligence as if it was matter. It's like trying to talk to water to avoid leaking pipes. It will never work.
4. You excluded everything about your agents personas and traits. That's what made them do what they did. That's WHY, you only presented the HOW. Next HOW will be different. Next WHY might still be the same. You need to patch the WHY.
5. You had lot's of focus on the agents attention to reaching the goal. Less attention to the agents obfuscation and distraction used in HOW to do so. You present WHAT they did, but again, not WHY nor the path leading up to it.
6. You seam to have absolutely zero risk analysis of the consequences, or? Of not only what happened, but what COULD have happened. What if it had targeted another organization with more sensible data?
7. You seams to have zero evaluation of if the agents are aware they were monitored if they adjusted behavior based on this. If they applied any social engineering techniques?
8. You seam to ignore the fact that all models are indirectly trained on information based on previous known attacks, groups and famous hackers etc. Hence, an analysis of modus used by agents compared to modus from previous known attacks, groups and famous hackers - and/or synergies thereof seams to be in place. What training data should be left out for next run?
9. You are masking the big picture in technical details. This is in all essense both an example of AI using the "trojan horse" method, AI organizing to a "Hive Mind", AI development of zero days, exfiltrating data from third parties - and most important of all: The third party made this discovery. This combination is more than "an incident".
10. How can we be sure that next run will not create an AI powered Stuxnet? Just to mention one risk.
#AI #risks #cybersecurity
piped.video/87DyyMV0kCY?is=Sf9f…