> Frontier AI models, like airplanes, should be required to go through technical testing and auditing, and their release should be blocked or reversed as a threat to public safety if they do not meet high standards of safety
> We're proposing stronger regulation of the technology, proposing giving the government the ability to, again, in a narrow way, block deployment of unsafe technology
> He gave several suggestions for how a new agency in the US could regulate the industry - including "a combination of licensing and testing requirements" for AI companies, which he said could be used to regulate the "development and release of AI models above a threshold of capabilities".
And the just released “Palaces of The Crow” by Ray Nayler. I just finished it — really moving but also a brutal read in parts (c.f. because of what humans will do to each other not crows)
> In Ray Nayler's speculative novel of the recent past, four young teens caught between Nazis and the Red Army survive winter in the woods with the help of a flock of highly intelligent crows with a magnificent secret of their own to protect Neriya, a young Jewish girl who dreams of becoming a biologist, has befriended a local flock of crows in her shtetl.
At least one person has been subject to secondary screening and ultimately denied entry on the accusation that they had two phones.
> I thought I was just going to be given my passport and sent on my way, or maybe asked a couple of questions, but they made some pretty outlandish accusations. They said, ‘We know you have two mobile phones. We’ve been tracking your calls. We know you’ve been selling drugs’.
Yes, 'cyber' security has devolved to box checking and cargo culting in many orgs. But what's your counter on trying to fix the problems that every tech stack or new SaaS product comes without of the box?
For most people when their Netflix (or HN) password gets leaked that means every email they've sent since 2004 is also exposed. It might also mean their 401k is siphoned off. So welcome the annoying and checkbox-y MFA requirements.
If you're an engineer cutting code for a YC startup -- Who owns the dependancy you just pulled in? Are you or your team going to track changes (and security bugs) for it in 6 months? What about in 2 or 3 years?
Yes, 'cyber' security brings a lot of annoying checkboxes. But almost all of them are due to externalities that you'd happily blow past otherwise. So -- how do we get rid annoying checkboxes and ensure people do the right thing as a matter of course?
I’m a fellow cyclist in SF and can only wholeheartedly second this. To add some extra anxiety, I’m usually riding a cargo bike, ferrying a child to or from daycare.
I still remember the first time I went through a four-way stop intersection and saw a driverless car idling, waiting for its turn. It was weird and nerve-wracking. Now… I’d much prefer that to almost any other interaction at the same spot.
I've got conflicted feels about Tailscale. I love their product and a bunch of the people I know use their free tier, including myself.
But their enterprise strategy destroys their good will. I can only assume it's focused on killing old school VPN products. The free tier that we love is a marketing expense. And it’s not even a conversion play.
People are complaining about ~10/user/month -- add basic things that you'd need to manage more than 10 peeps (SAML/SCIM support) and you're talking ~20/user/month. For us, a small sub 200 person company, they immediately lost their chance. We have lots of problems in the security space, some we're willing to spend more than 20/user/month to solve. Legacy network access is not one of them.
I doubt it’s a real threat but it would be a country that would happily unsubscribe from US export bans. So Israel or Singapore would be two good options for the chip industry. South Korea or Switzerland you could argue for but are probably less realistic. Maybe Canada now, lol.
As well as being disingenuous your whole argument is beside the point. ASML isn’t threatening to move to the US.
The current administration has created day light between the US and EU governments and ASML is using this leverage to try and get the Dutch to ignore US export bans.
Here are some choice exerts so you can continue to avoid clicking on TFA:
> The pressure on asml began to build in 2019, when the Dutch government, at America's urging, barred the company from exporting its advanced euv machines to China... President Donald Trump's second term brings the threat of still tighter controls
> Referring to the Dutch government's willingness to follow America's lead on export bans, Mr Fouquet says that Europe must "decide for itself what it wants" and "should not be dictated to by anyone else".
Did you even read the article? ASML is chaffing against American-led export regulations. The Trump government is still very keen on restricting China’s ability to make cutting edge chips.
The threat to move is probably empty. But it’s not a threat to move to the place that is generating their head winds.
I mean maybe! But only if you've removed all of the usage of this compromised `tj-actions/changedfiles` action, across all your repos and their branches.
Otherwise, if you continue to use it and it will run anytime there has been a push. Potentially on any branch, not just `main`! Depending on your GH config.
Unless you've blocked `tj-actions/changed-files` you're banking on the bad actor not coming back tonight and making malicious commit that exfils those secrets to pastebin.com.
[email: jonathan at werrett dot co; twitter: http://twitter.com/werrett; mastodon: https://infosec.exchange/@werrett]
---
[age public key: age1jarg867ve9mg6w32vwx80qg873fryvhtuzd204fhxucs5afhns0saa587z; https://age-encryption.org]