The first things I think of with "fake it til you make it" are Tesla FSD[0] and Reddit[1]. To this day, if you visit Reddit while logged out it makes the claim that it's a place for "empathy"[2].
Reddit is a hotbed of harassment, targeted abuse, political extremism, celebration of violence, and encouragement of health disorders. Depending on Tesla's self driving technology has gotten people killed. Let me know if you want any citations for those claims but I think you probably know examples of what I'm referring to in each case.
I would posit that people's health and lives are more at risk in both examples, but nobody is being imprisoned for it. Both companies are well aware of the risks but choose to profit off it rather than take responsibility.
"Nonviolent" does have a pretty straightforward definition that I think you can differentiate from your examples if you were inclined to judge impartially.
When you're predisposed to an opinion, it's easy to come up with justifications. Often those result in misreading/misinterpreting information and then spreading that misinformation for more folks to use as justification.
I don't want to draft a speculative narrative about someone else's life (or its sad end) but I will say that your first allegation sounds like a misinterpretation of the events, at least from reading the Wikipedia article about who you're referring to.
It's odd how vilified Holmes has become, and how gleeful people--even in these comments--are at her lengthy prison sentence for a nonviolent crime.
She faked it until she (didn't) make it--a strategy praised in other startup narratives. Most of that faking involved secretly running blood tests on traditional test equipment instead of her in-development devices.
I believe there were a handful of tests done on their development devices that returned questionable results for actual patients, which I'm hoping is where all the angry people are focused. But to that point, how accurate and responsible are traditional testing facilities? I personally have had my bloodwork mixed up with someone else's, causing quite a lot of anxiety and extra work from me to sort out.
There are countless instances of labs forging results[0][1], making mistakes[2], and issues with equipment[3] (citations are just the most easily at hand).
Some of the stories cited resulted in criminal convictions, like 3 years for someone who faked thousands of drug-test results leading to false convictions. Compared to what Holmes did, it's hard to see how 11 years (and our society's complete fascination and vilification of her) is appropriate.
The original tweet author eventually realized this didn't decrease tokens. In most cases it actually increases them compared to just asking GPT to summarize while retaining all functional data. If a word == 1 token, a related emoji will also == 1 token.
> My polish grandmother has it as a painting in her house (a jew counting coins). She bought it few years ago. She says the jew brings good luck. She is absolutely not racist nor antisemitic.
> Even today despite global jews being less than 0.2% of world population are 20% of Forbes 200 richest, e.g. 5 of the 10 richest americans are jews.
While I don't know your grandmother, your representation of yourself reads very antisemitic to non-Polish audiences. You may want to take a minute of introspection as to what shared cultural influences led to your grandmother's art choices and your insistence that antisemitic stereotypes are valid. There might be a connection there. That said, you probably wouldn't want me painting all Poles as insensitive oblivious racists.
This is a low quality article that would lead people to believe incorrect information. The headline is incorrect, as they won't be "fixing" the problem.
The latest news that I believe accompanied the statement quoted is that they are giving out (or reimbursing) steering wheel locks (as in "The Club") to some customers,[0]. Steering wheel locks are very frustrating to use and easily defeated.
They're also not adding immobilizers but rather connecting the fob buttons to the engine via software:[1]
> The software upgrade modifies certain vehicle control modules on Hyundai vehicles equipped with standard “turn-key-to-start” ignition systems. As a result, locking the doors with the key fob will set the factory alarm and activate an “ignition kill”
This software update will require a service visit and isn't yet available for most affected vehicles.
And to put things in perspective:
> 96 percent of vehicles had engine immobilizers as standard equipment in 2015, the feature was standard on only 26 percent of Hyundai and Kia models [up through 2021].
It's naive to think the danger is in self-aware evil AI. AI is a tool, and can be used as a weapon.
There's a functional power difference between a knife, an assault rifle, and a nuke. Everyone owns knives--they're in your kitchen--they can't cause much trouble. Access to assault rifles has turned out to be a dangerous problem to society, and is a contentious issue as such. Nukes are obviously too dangerous for people to own willy-nilly.
The issue is where along that spectrum AI will fall into in 6mo, 1yr, 5yrs, etc.
It's troubling to think anyone, especially on a technical forum like HN, believes GPT-4 doesn't have arms or legs (anyone can hook it up to any machinery/robotics) or can't think very fast. Its training set is a good chunk of human knowledge, and it outperforms most humans already.
Even if you assume AI won't be very clever (which seems unwise given its development pace), consider just its ability to perform thoughts and actions at the speed of a computer compared to a human. There are quite a few examples of modern military engagements where a larger, weaker, and less-well-trained force overcame better-equipped opponents, like Mogadishu, Vietnam, Iraq, Afghanistan, etc.
It's a lot easier and faster to destroy than to defend. To defend, you need to know what you're defending against, develop the defense, and then roll it out, all reactively post facto.
If a computer has the ability to quickly make millions of novel viruses, what antidotes are you hoping for to be rolled out, and after how many people have been infected?
Also, if you follow the nuke analogy that's been popular in these comments, no country can currently defend against a large-scale nuclear attack--only respond in kind, which is little comfort to those in any of the blast radii.
Thanks for your thoughtful reply. Maybe Google could benefit from having you train customer service for a few days ;)
> you don’t really want to be noisy with how you’re using an exploit because then people will catch on and try to defend against it
My initial reaction was that the vulnerability was already published so why would they care, but I can also imagine how the actual payload could be something to hide as well. That said, couldn't an exploit simply turn off security updates? It sounds like this vuln has full access to everything on the phone.
> In the very rare cases you see actual 0-days used
But that's the issue--it's not a 0-day. It was publicized before the patch went out for millions of users. Was the patch force-updated for everyone else? If not, that number of unpatched users is probably an order of magnitude greater.
This isn't an issue of some state-level actors sitting on a secret 0-day, it's a use-it-or-lose-it moment for anyone who's heard about it straight from Google's mouth.
Full access to SMS 2fa and email accounts seems like everything. That gives you access to most people's bank accounts. You could search emails for crypto accounts and MITM non-SMS 2fa apps if you have root access to the phone. Sending money requests to contacts using real names. I could think of a million ways to use root access. I don't know the cost of exploiting this vulnerability, but I know that sort of access is valuable to a lot of people.
Why wouldn't this have been a goldrush to exploit by unsophisticated attackers? Maybe I'm missing something?
> If they want to spam a million users they could do that too, although these kinds of things are typically not done this way
That seems like a convenient assertion not based on evidence.
Without trying to sound confrontational, it appears as if you are a current employee of Google, which might have colored your comment and should probably have been disclosed.
The blog post was published on the 16th.[0] Pixel 6 and 6a started the update rollout on the 20th.[1] The March security update was scheduled for earlier but was delayed for 6/a for some reason, and it seems like the Project Zero team didn't check on the actual status of the rollout.
I read that as well, and either it's unclear or I lack the technical understandings to apply that to my question.
What does "at the baseband level" mean in terms of remote attack vector? Do they need to be physically nearby with an antenna or could they be across the world connecting through VOIP?
And why do they need to know a phone number? If it's that they need a nearby antenna + knowledge of a phone number, it sounds like this vulnerability might not be a big deal, and it would be great if they communicated that clearly. Alternatively, if the vulnerability is accessible from any remote phone connection, knowledge of a phone number wouldn't matter because attackers would spam the attack against millions of numbers.
1. I've not seen anyone explain whether this could be exploited by anyone with access to phone lines (i.e. Twilio users) or not and if it would be trivial to try the vuln with every phone number you could find in any DB. If those things are the case, it seems like the chances would be very high that this would be or has already been exploited and affecting every unpatched phone.
2. It seems like Project Zero mistakenly thought that Google devices were already patched when they made their announcement ("affected Pixel devices have received a fix"). Whoops! Thanks for giving attackers a heads up.
3. When contacting Google support (specifically Fi) multiple CS reps told me repeatedly this was all fake news and that Project Zero was unaffiliated with Google. They assured me there was no problem, and if there was a vulnerability, it would be communicated on the Fi website (which has no service status or security pages and has never published any outages or vulnerabilities in the past).
4. The delayed March update for Pixel 6 phones doesn't even show up when you open the software update panel (which shows a checking animation that I assume does nothing). You have to manually check again. Who knows when the folks who are unaware of this vulnerability will actually be prompted to install the patch.
Google have guaranteed at least one person and their family to never purchase another Google product or service.
Since I don't think anybody's linked it yet, there was a lot of press about the anti-fire foam the airforce uses in drills (and actual fires) being toxic and leaking into the water systems in every base.[0]
They said they'll phase it out by 2024,[1] so if you're planning on enlisting, you should wait to enlist until then so you can be part of the next cohort for this study. Also, if you live near an airbase, you might want to wait to have any future children until then too, as it affects people around all the bases, as well.
Related to Listerine: I have a memory of reading a study that had people use mouthwash (possibly Listerine) the night before taking a cognitive test. The mouthwash group did worse than the control group for some reason.
I'd really love to find the study again if anyone else knows where it is (my googling is apparently not good enough)
I can't say if it's right or wrong, but in relation to your specific example, there are "adverse possession" laws that grant legal rights to the occupier of land in the US.[1]
I didn't see the commenter arguing on behalf of outdoor dining, so that's a bit of a straw man argument. Additionally, there's a difference between people opting to participate in mutually risky behavior (eating maskless in a restaurant during a pandemic) vs. imposing their risky behavior on people not participating (maskless jogging in shared spaces where others are acting responsibly by wearing masks).
Reading your comment, it's unclear how far you're keeping from others. The only information is that other people don't feel safe given your distance and lack of mask.
It's analogous to you feeling like you're a safe driver but having passengers asking you to slow down. If you're not judging the danger to others commensurately to them, it seems like the onus should be on you to adjust your behavior.
Also, as others pointed out, this study's idea of "crowded spaces" might not align with your idea of it. If someone with COVID-19 passed me on an average-sized trail path or sidewalk breathing heavily while running, I wouldn't feel safe and I doubt many other reasonable people would either. It's not an issue of outside air vs. inside air as it is whether you end up breathing the same air as others, and you might not be a great judge of when that is or how it applies to this study.
Also, if you're interested in backing up your actions with studies, you should note that "social distancing" meaning 6ft distance which I'm assuming you're referring to has been debunked by MIT and Oxford studies.
Figuring out exactly what's safe and not is not clear cut, which is why simple rules like "wear a mask outside" is so important, because we clearly can't all be trusted to make good judgment calls.
Speaking of misleading cybersecurity language, note how you used the term "nation-state", which is a word that indicates a specific subset of countries and is not just a fancy synonym for "country".
Reddit is a hotbed of harassment, targeted abuse, political extremism, celebration of violence, and encouragement of health disorders. Depending on Tesla's self driving technology has gotten people killed. Let me know if you want any citations for those claims but I think you probably know examples of what I'm referring to in each case.
I would posit that people's health and lives are more at risk in both examples, but nobody is being imprisoned for it. Both companies are well aware of the risks but choose to profit off it rather than take responsibility.
[0] https://www.latimes.com/business/story/2022-12-08/tesla-laws...
[1] https://www.inc.com/karl-and-bill/best-advice-fake-it-until-...
[2] https://i.imgur.com/y1Sicxl.png