Hacker Newsnew | past | comments | ask | show | jobs | submit | johndhi's commentslogin

I'd be curious to see whether these models can create new forms of unbreakable encryption themselves!

Private key cryptography is essentially unbroken by these models.

Normally "private-key cryptography" is the antonym of "public-key cryptography", which is to say, conventional symmetric-key cryptography such as AES or Enigma. That's what "private-key cryptography" redirects to on Wikipedia. This article is about Astra breaking a message encrypted with a private-key cryptographic algorithm, but one that was already known to be weak. I'm guessing that if you had messages encrypted with weak public-key algorithms it could break those too.

But they said new forms, I think that implied not the ones humans already discovered/designed

I see what you’re saying. It is generally harder to build a crypto system than to break one so I would find it hard to see potential from the design end before progress on the attack end.

> It is generally harder to build a crypto system than to break one

It was harder to design Symmetric Encryption using e.g. AES-256 than to break it? As far as I know it's design is pretty straight-forward but there is no known way to break it even with all compute of the planet at your disposal (excluding trivial ways like exposing the key).


Yes, it was. An attack only needs to work one way, but an encryption standard must resist all attacks.

There are many examples of would be crypto algorithms that died on the vine because an attack was found. It is often recommended for beginners to study breaking cryptographic algorithms long before they attempt to create them.


It didn't take 25 years to come up with Symmetric Encryption and AES but even though people try extensively to break it for the last 25 years no-one has come even close to anything that is not brute force (which is practically impossible even assuming very generous computing resources). So at least in that case coming up with the encryption seems to be a very solvable problem but breaking it seems close to impossible.

It’s worth considering AES is the result of many decades of development of prior block cipher algorithms. It is no so hard to make a variant of AES that looks similar but is not secure.

Building a crypto system has so many footguns, I'd be amazed if it could build one that stands up to attack

I think it’s all about the harness. If someone can find a way to create an iterative loop, with a good validator, I wouldn’t be too surprised if an LLM can end up with a solution. So far that’s how pretty much all problems have been solved by LLMs. That’s a very big if though!

Isn't the other way round? It does not mean that breaking one is easy, but it does mean that writing one that's unbreakable it's very, very, very difficult.

Yes it is; that’s what I was thinking when I started to comment but somehow I ended up reversing course. Comment is appropriately edited now.

They seem to be better at solving concrete problems than designing new things (at least for now)

It's easier to evaluate certainly. Did it solve the problem? Yes/No

When you design a new thing it will have a dozen drawbacks and a dozen and one benefits. If people then have a bias that everything ai is bad, the signal won't be strong enough to convince.


I believe an LLM can solve pretty much any problem for which we can define a fast iterative loop and for which we have reliable tools to automatically verify the correctness of a result. That’s how they are able to solve some math problems, and how they are able to generate working code. Then it’s a question of how much you have to pay for the model to explore the space of solutions in a reasonable timeframe

In math a lot of the spectacular results have been made by finding a counterexample or worming their way toward a proof that is very well defined.

There's some debate over to what degree current generation AI can be creative at all, or whether it can only crawl around its latent space and explore within constraints. One might ask: were all the solutions to all the math problems AIs have solved already "there" latent in the training data and just hadn't been spotted by humans and put together?

But then... isn't everything latent in our training data if training data is "all observations made about the universe?"

But then... what even is creativity? That gets into philosophy and metaphysics. Creativity, like consciousness and sentience and self-awareness, is not a rigorously well defined concept. So to a degree we don't even know how to ask the question of whether these things are creative.

This gets interesting.

One of the things I love about AI is the glittering Pandora's box of philosophical questions it poses.

Another one I love: if LLMs and their relatives are not, in fact, sentient or self-aware or alive in any way whatsoever (which I suspect is true given how they work), then it means intelligence and consciousness are unrelated phenomena. I'm pretty sure every animal and maybe even every living things has consciousness in some form, but my pet bunny rabbits definitely can't write code. LLMs can write code, but I don't think they experience existence or have volition.

IMO we have always implicitly just assumed some kind of connection between intelligence and consciousness because we have both. It was just an assumption. It's probably a false one.

I suspect (a hypothesis) that consciousness is a property of life and is probably emergent from life's intimate relationship to thermodynamics and the arrow of time. Life has also evolved intelligence because it's useful to satisfy its implicit survival goal function, but the two are unrelated. Intelligence is just an adaptation.


Yea, when you start digging into intelligence/learning/creativity/language you realize that you're talking about more information on these topics than a human could ever learn in their lifetime, and you learn just how much we don't know about ourselves and these processes.

Whenever I hear "AI can never" I know I can disregard them as an unserious person when it comes to anything around AI, learning, or philosophy.


I think of the extent of human knowledge as a circle or cloud shape, and true expert thinking happens just inside the edge. And creative thinking that leads to knowledge breakthroughs happen when you are thinking in that edge area, but also make a connection way around the circle to some other location. And my guess is there’s absolutely no reason why AI can’t learn to do that too.

They are only good at brute forcing stastically likely solutions.

Careful what you wish for. The swarm will probably use it to communicate.

We already have a plethora of cryptographic algorithms that literally anyone can use to send messages nobody can read with current technology, unless of course they have the key. You're using at least one of them right now to read this website.

Sounds cool. Needs network effects of lots of highly rated stores to succeed, I think.

Yes but users can build adapters and bring their own stores.

What evidence shows he wanted this? Why would he play the victim internally?

Facebook knew about the Kogan/CA transfer in 2015 and failed to respond adequately, instead they relied largely on deletion assurances rather than immediately auditing, and users weren't informed until 2018.

But more, CA was created as consequence and a way to profit out of the 2012 Six4Three scandal, after Mark Zuckerberg personally designed/approved the permissive data-sharing ecosystem specifically for these use cases (as several internal mails show).


You’re arguing with a conspiracy theorist. Don’t do it, it’s not worth the effort!

> Why would he play the victim internally?

To create evidence that he didn't know about it?


both can be true:

-the US gov't is stupid and overly aggressive and absurd

-Anthropic for reasons no one can quite conceive keeps describing every product release of theirs as an imminent threat to civilization (and simultaneously keeps pushing the market forward as fast as they possibly can).


They never said Mythos was an imminent threat to civilization. You are constructing a straw man.


They said it was too dangerous to release before the companies that run internet for civilization could patch the holes it was finding.

That's a threat to civilization.


Were they correct or incorrect in this? Whatever your answer, why do you hold that opinion?

I work for Mozilla. We fixed a ton of security vulnerabilities that Mythos found during its early period. So my bias is to be sympathetic to Anthropic's warnings.

If I were in an organization that did not have access to Mythos during that period, I would probably be biased the other way: "great, now other people have access to a tool that could probably poke holes in my security perimeter, and I'm not allowed to use them myself."

Both biases are understandable. I'm not sure who to look to for a usefully objective 3rd party opinion. And it's not like one "side" is right and the other is wrong, either. It seems like the best we can do is to justify our positions with data. (Which is itself kind of hard; the detailed information that would be relevant here is understandably sensitive, and I don't have access to most of it even for my organization. I don't even personally have access to any unfettered Anthropic models. The bugs coming in from people who do are plenty enough to keep me busy.)

Also, I'll note that even with my bias, I wouldn't claim a threat to civilization. But even the leakage after the controlled release seems a lot worse than the Y2K problem ever turned out to be, and I will note that whatever you think of Anthropic, it's clear that OpenAI is going to let the AIs cause as much damage as they need to in order to get good training and evaluations. I'm sure they're trying to keep them contained, but the evidence shows that they're only trying up to the point where it interferes with their evaluations.


I mean, I have no love for Anthropic, but from my perspective, OpenAI has hyped their models in the exact same way. I don't know why this criticism stops at Anthropic. Sam Altman keeps describing his product as a radically dangerous technology only he can be the steward of.


> That's a threat to civilization.

No it's not. Even if it were, they never said it is a threat to civilization.


It's the party line so people forget the week it actually happened - anthropic said they would work with DoD/DoW but with two conditions:

1. Kill orders from ai decisions had to go through a human 2. The govt couldn't use their models for illegal surveillance of Americans

Hegseth threw a fit, Trump called them traitors and a supply chain risk, openai said they wouldn't require those restrictions and got all the contracts.

Both companies are corrupt and dangerously reckless and have doomsaying advertising (50% of jobs destroyed vs money won't have meaning anymore). One didnt kiss the ring correctly.


By the pigeonhole principle, "mostly A" and "mainly B" cannot both be true if A and B are not the same entity


>no one can quite conceive

Isn’t it like their main goal is attention capture, and existential threat is extremely effective at capturing human attention? Combine that with the "There is no such thing as bad publicity" mindset, and this explain it all, doesn’t it?

https://www.phrases.org.uk/meanings/there-is-no-such-thing-a...


I'm sympathetic with this sentiment but surely it's pretty rare the law actually gets involved? Our kids play outside a lot and no cops have ever raised an eyebrow (except for at our crazy drunk of a neighbor, where eyebrow raising is appropriate).


It’s Foucault’s interpretation of the panopticon. If we know that we may be watched — and punished — we self-police into following the norm, even if we do not know when we are being watched or that someone is necessarily monitoring us individually.

When I was a kid in the 80s none of this was an issue and I was free to roam. Starting in the 90s this became an issue and not only will parents not let their kids roam but the kids themselves have less interest because the norm is to stay in or only go out when supervised. You know you are doing something slightly wrong. It only takes occasional reminders like this to reinforce the rule, once established.


It's rare, but if it happens it is catastrophic. You will be paying a lawyer 10's of thousands of dollars and if you do have to plead out, the charges you plead to may look very bad on paper on a background check.


How does growth potential relate to legal enforcement?


In the current system, political parties who do things that stop the economy growing are usually voted out, more than political parties that refuse to take action against nebulous criminal activity. That's why, for example, my city refuses to do anything to stop the factories in the city from dumping waste into the river.


The way everybody involved makes money


In the US, "printing money" is the most sacred act there is. If you're doing that, laws suddenly don't apply.


I'm more on your side than most but surely you don't think zero antitrust enforcement is best for our country?


I started going in 2002 and have friends who have gone every year since then.

There has been a meme that burning man sucks now and used to be better that entire time.

That doesn't mean the meme is false. It definitely has changed. There's an article in sfgate today that quotes the head of the Death Guild (Thunderdome) camp as saying something like, do people want to carry on the traditions their parents had, or invent their own?

I thought that was a great question. Both are valid paths.


Festivals have changed. People want high speed internet, good food, professional security and not having to put up their own tent.


> People want high speed internet, good food, professional security and not having to put up their own tent.

That's daycare for adults, not an experience.


The others are pretty dependent on what you mean by good food or professional security. But who wants high speed internet at a festival?


> But who wants high speed internet at a festival?

A shocking amount of people


It was better next year.


i went 95-2000 then got cajoled back in 2012. It sucks now. It actually sucks now.


Hmm. I have a decent shed outside my house and my current office (in the house) is decent but when kids get home it gets a bit harder.

I wonder if I can convert an existing shed...


Same


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: