So if you steal something it means the owner didn’t do a good job securing it and if you murder someone they didn’t do a good job protecting themselves?
The diff is that owner is responsible for their own shit where a telco has everyone's things in there and is exposed to the whole world instead of just one street.
It is like a bank that has sloppy security and exposes you to the whole world, including adversaries from Russia china NK etc.
Things like Telco cloud banks should absolutely be thrashed for having bad security. Responsible disclosure should also be a thing but we all know these companies sue people for that too.
Does that extend to medical systems? If someone hacks my pacemaker and destabilizes my heart, or my pharmacy/hospital and prevents me from receiving medical care, is that something that should be legally permitted on the basis that "medical device makers/pharmacies/hospitals should try harder, and should somehow compensate their patients if a hack occurs"?
Anything network connected that can be reached by an adversary. And, I did not say it shoukd be legal or illegal, just that the fault lies with who administers/secures those systems, not with whoever breaches them.
> How do you compensate someone who's dead?
In some countries where I lived, there were pricelists based on nationality that insurance would pay out in case of accidental death. If you live in a more homogenous country, you can use other factors to determine what the payout should be.
Since you mentioned it below several responses to this comment: Why do you think this is okay for software, but not okay in the "physical world"?
Is it about a perceived lack of consequences of the one vs the other? What if the hack caused real damage and suffering? For example, people's medical histories get stolen and exposed? Ransomware encrypts hospital systems, disrupting medical care?
Or, the inverse: while you're away, somebody breaks into your home non-destructively, takes some photos, sleeps on your couch, and leaves. Should that be forbidden? Your fault for allowing it? It is easier to pull something like this in the digital world, is that why it seems different to you?
I don't agree with GP at all, but making hacking illegal indeed gives companies a false sense of security.
Making burglaries illegal is a real way of preventing many burglaries from happening, because it puts people committing them in prison and deters some from doing it in the first place. This only works because the burglar is in the same place as the burglary, and so they can be arrested.
People with little to no computer experience apply the same standard to cybersecurity and treat foreign hackers the same way as burglars. Then they get surprised when the Russians hack them and the FBI does nothing.
You're presenting a false dilemma, there are more options than "all hacking is completely illegal" and "all hacking is a free-for-all".
We're in a thread that starts from the notion that it should not be illegal to "hack a telecom network and take control of it", because "the people running it did not do a good job configuring and securing it." That's essentially the free-for-all position, and defending it by claiming that the opposite extreme is the only other option is a false choice. Nuance and compromise exist, and our world is made of them.
Also, your argument about burglars can be applied to "hackers", too. Police can find and arrest people domestically and beyond. Consequences deter people from all sorts of illegal activity. On the other hand, nation states are not necessarily deterred by laws from kidnapping and killing people inside the territory of other countries. You've probably seen the news.
What's different is the ease of access to digitical, internet-connected systems, and the scale of abuse that affords. That's a reason to think differently about _how_ to shape the rules and laws around "hacking", but not a reason to have no rules or laws at all.
Because it is a battle of the brains, like when you play chess. And I believe the smarter one should win. This is why I have this strongly held belief that if you get hacked, it is on you. The attacker was smarter than you, simple as that. So you have to get smarter and become better. Or you get hacked again and again.
I really don’t understand the urge or need to compare software security with physical security.
> I really don’t understand the urge or need to compare software security with physical security.
Both are about preventing harm in many different forms. Software famously has effects in the physical world, that's the reason why a lot of it exists, and why people get paid that deal with software because it makes their brains feel good.
I also notice that you haven't really answered my questions around that.
> if you get hacked, it is on you. The attacker was smarter than you, simple as that.
From your perspective, what makes "smarter" different from "stronger", or "more resourceful" here? Or do you think that if your door gets bashed in, it's your fault, because your door was too weak? Or your head? What if someone outsmarts your physical security arrangements to wander around in your house? Where's your boundary here?
I think physical and "cyber" security are not so dissimilar in the need to back them up with rules and laws at some point. Still, there are differences, so I don't think the rules and laws need to be the same. You seem to be advocating to have none at all for the software case, and I'm trying to find out about that.
> Both are about preventing harm in many different forms. Software famously has effects in the physical world, that's the reason why a lot of it exists, and why people get paid that deal with software because it makes their brains feel good.
Yes, it would suck if the hospital got hacked while I underwent a surgery for example, and the ventilator stopped working. But if that happens, whoever is doing it is not stronger, just smarter than the people administering the hospital network.
> From your perspective, what makes "smarter" different from "stronger", or "more resourceful" here? Or do you think that if your door gets bashed in, it's your fault, because your door was too weak? Or your head? What if someone outsmarts your physical security arrangements to wander around in your house? Where's your boundary here?
I gave an analogy with chess. You don't have to be strong in the physical sense to win a chess match, just smarter than your opponent. This is how I see the difference.
> You seem to be advocating to have none at all for the software case, and I'm trying to find out about that.
For software, the playing field is level: you use a computer, your opponent uses a computer. But the difference is the other person's capabilities. You can be smarter and you don't get hacked, or your opponent is smarter and hacks you.
You think it's okay when actual harm and suffering results from a "battle of the brains" via computers, because one party "outsmarted" the other. Sure, it would "suck", but you think the playing field is pure and level, making it a fair contest and any consequence fair game, and therefore it should not be illegal.
You are unable or unwilling to engage with the question if and why using a computer and "smarts" to cause harm is different from using strength, or any other advantage, to cause such adverse outcomes in other ways; it is not clear to me if you would also regard that as okay and think we should not have the laws that sanction such things; or if and why you think this anarchy should only exist in some sort of "digital computer space", crossing which would serve to make actual, real world consequences not matter that much anymore. It's almost like, by putting a computer between actions and consequences, one passes through a waterfall that washes away responsibility and "sin", in the ethical sense. But that depends on whether you think those were there to begin with, and is only an interesting metaphor for me; please don't get distracted by it.
In any case, that's a very interesting position. I'm curious what you gain from arguing it. Where does that come from? It's possible you're just trolling, but maybe smarts and brains connected via networks are truly special to you. Why?
(Edit: Please disregard "what you gain", it comes across completely wrong and takes it in an unintended direction. "Where does it come from" is what I mean.)
> You think it's okay when actual harm and suffering results from a "battle of the brains" via computers, because one party "outsmarted" the other. Sure, it would "suck", but you think the playing field is pure and level, making it a fair contest and any consequence fair game, and therefore it should not be illegal.
I said the fault lies with the administrators of those systems, not with attackers. I really think I never said it should be legal or illegal. I don’t really care if it is illegal or not, hackers are not dettered by the legality of it. Do you think someone in The Gambia cares that hacking is illegal in Canada?
> You are unable or unwilling to engage with the question if and why using a computer and "smarts" to cause harm is different from using strength
For me being smart and being strong are two wildly different things. It is like asking me why I don’t compare apples to oranges. I can’t.
> In any case, that's a very interesting position. I'm curious what you gain from arguing it. Where does that come from? It's possible you're just trolling, but maybe smarts and brains connected via networks are truly special to you. Why?
I am not trolling. I see this, hacking and securing something against hacking, as an “intellectual fight”.
Let’s say you are a 50 year old security admin that gets owned by a 14 year old with a computer. You were beat because the 14 year old one was smarter than you, not that he had more experience or was physically stronger than you. Just smarter.
Now imagine you’re part of a security team and you still get owned. What does that say about you?
I am at a loss on how to explain that when it comes to computer security the fault, in my book, does not lie with the hacker.
Just like when a flaw is found and exploited I do not blame the one who found it, but whoever made it possible in the first place. And in the case that the flaw was patched and a software update was made available, but it was not installed promptly, then the fault lies with whoever did not update the system.
Regarding arguing: I made a statement expressing my position and got mobbed for it. Now I am defending my position.
We can agree to disagree and keep enjoying what is left of our weekends.
Oh, I don't mind the disagreement, I'm curious to understand why your position is so different from mine, after getting closer to understanding what your position actually is. (I had to do that because there are some implicit premises in my thinking vs what you're saying which seem fundamentally different, and I had to work those out for myself.)
I think I do get it now, and it seems to be pretty much to what I described before. While I think that there is responsibility for the outcomes of one's actions no matter through which ways and means they are accomplished, for you, it seems to depend: making it about smarts or intellect or whatever, and putting a computer in between, causes it to transcend legality and morality. Adverse consequences are not on the actor anymore, and purely on the "defender".
That's not how a lot of people (including myself) see this issue. They would not agree that responsibility and outcomes should get disconnected or redistributed by changing the ways and means in between. (Edit, just to make this extra clear: The idea is that it should not matter if one uses their brain and a computer to effect damage, or some other means. Computers are a different tool, not a different game.) Even more, people find it hard to follow both the ethics and the logic of your argument, because you've not been able to express WHY an exception should be made for "smarts" and "computers" and not in other cases. Whenever I've asked you to explain, you've either misunderstood or evaded the question and responded with re-iterating that "smart" is different from "strong", as if that explains anything. (It boils down to being asked: "Why should the difference between red and blue matter here?" and answering with "Because they are different.")
So, you're taking an position that people find ethically problematic and logically inconsistent, and that's the reason why you receive this pushback: people feel motivated to counter what they see as an uncontested "ethical divergence", and you gave them an obvious logical chink to pry a lever into.
What I'm taking away is that you truly believe this, which is so foreign to me that I'm completely mystified. It makes me curious, and also uncomfortable, and for both reasons I wonder: How? Why? However, you're simply re-iterating your position, and I've come no closer to finding out, nor do I think I actually will, because I can't find a way to phrase my questions in a way that would bridge a barrier of understanding between us and make you respond to what I'm asking.
I'm still curious. But in any case, please do enjoy the rest of your weekend.
You don’t have to be smarter than your opponent to beat them in chess. You need to be better at chess, that’s it. Sure you need some degree of intelligence to be good at chess but being better at chess is not an indicator that you are smarter than your opponent. Same goes for computer security or any other intellectual field.
For instance, I’m pretty sure I’m better at computer security than Terence Tao but no way would I say I’m smarter than him.
Semantics. If you have a computer, the hacker has a computer, and you get hacked, the hacker is smarter. For whatever values of better/creative/resourceful you want to attribute to “smarter”.
My issue is that software security is not taken seriously most of the time because features are more important than spending a little more time on code quality.
The origin of OK is disputed; however, most modern reference works hold that
it originated around Boston as part of a fad in the late 1830s of
abbreviating misspellings – that it is an initialism of "oll korrect" as a
misspelling of "all correct". This origin was first described by linguist
Allen Walker Read in the 1960s.
I think the point is that tremendous complexity can arise from relatively simple mechanisms. That is what life is, at many levels. I’m not at all convinced that the current LLM approach will yield something we can broadly call consciousness but saying that it’s a simple concept and therefore won’t support consciousness is a specious argument imo.
I completely agree, tremendous complexity can arise from simple mechanisms. Gleick's Chaos is a really good introduction to that. I was talking about the article though, and the mechanisms currently used for training and inference in LLMs. Those mechanisms are mathematically precise (unlike Chaotic attractors) and as the author points out, achieve the same function as compressors do in a strict bit pattern minimization role. Sometimes tensor math is pretty complex, like the FFT and DCTs on JPEG compression, but with the same inputs you get the same results. And while a JPEG will never decompress to a different image than the one that was compressed in the first place, LLMs do not 'infer' token streams that haven't been trained in their training process. The big difference here is that if you imagine a JPEG compressor that compresses 100 different images into one 'chunk', you can see how to provoke it to produce any one of the images it previously compressed. And with a bit of creativity you can have it express different images in different parts of the resulting composite. FWIW I looked at patenting something like this for digital cameras to give them more "shots" space for a given amount of SD storage.[1]
Given the way that models work in 'inference' mode (vs 'training' mode) you can't forward bias the result into the correct result when there are multiple forward results that have identical weights. It's the root cause of hallucinations, and you've lost information in the training phase that you can't then use to discriminate between the 'right' answer and an equally valid 'wrong' answer.
[1] FWIW I could never recover enough state to insure that the image it regenerated was all of the same image you took. So you might get the street but one of the houses might be a house that was in a different picture you took. That kind of bug. Mostly arising out of the same kind of problem you have with using hashes to find documents, when you get a hash collision two documents have the same hash, so you don't know which one to return.
I do not understand this intuition that "true consciousness has to be random". The things that make me me are highly deterministic!
> LLMs do not 'infer' token streams that haven't been trained in their training process
While we're at it, this is simply untrue (in-context learning) unless you generalize "token streams" so radically that it could be readily analogized to humans as well.
> The things that make me me are highly deterministic!
Are they though? :-) There are some interesting papers in the tissue regeneration space which are working on building tissue (and organs) from stem cells for medical purposes (transplants, injury treatment, Etc.) and one of the things that comes out from that is that a set of stem cells make unique tissue every time in that it's compatible but the fine structure is always randomly different!
While the growth of brain matter is a minefield of ethical issues, at some point I suspect we're going to have to figure out how to do that to treat things like TBI and neurodegenerative diseases. In terms of understanding how randomness plays a part in your existence though cellular biology papers are a pretty good source.
Yes they are :-) At some point it's a question of definition. If I am anything, it's a pattern of behaviors; I am not defined by thermal noise. Thermal noise may be a reason my brain grew as it did, but having grown that way, I disagree that a version of me that grew the same way due to less random reasons would thus "not be me."
edit: And of course, any pattern that you can recognize about yourself, as "you", has to be deterministic by definition of pattern.
I’m horrified to imagine a blood pump or any life support system being network connected, or to rely on the precise time of day in order to function correctly. Accurate time keeping for anything in this realm can and should be done without a network.
The equation is different if the life saving surgery couldn’t be performed otherwise. Still pretty crazy and I don’t know how comfortable I’d be with it if I were the patient.
I had a great evening with a friend playing through TIS-100 together. We plugged in two keyboards and mice so we didn't have to pass them back and forth.
I used to run tomsrtbt (https://en.wikipedia.org/wiki/Tomsrtbt) from a floppy on an old 486 hooked up to a monitor and keyboard for use as a terminal. Was nice and silent, pretty convenient to be able to just turn the screen on to check irc or whatever.
reply