“Growing Risks”

That’s the concern about AI and its use in hacking that was written about in a recent WSJ article.

Two weeks after a swarm of AI agents broke out of containment at OpenAI to hack the company Hugging Face, the ChatGPT maker learned about another AI-powered intrusion—and this time it was the target.
Independent security researchers had used Anthropic‘s Claude software to gain access to an OpenAI employee’s ChatGPT account, giving them a way to read and suggest changes to the company’s private cache of software.

And this:

The team, who participated in an OpenAI bug-hunting program that offers a safe harbor for researchers to attempt to break into corporate systems, quickly reported their findings to the company. …
The new hack joins a long list of recent disclosures by leading technology companies and researchers alike of cyber intrusions aided by fast-evolving artificial-intelligence tools. Despite months of warnings about the capabilities of AI systems, the new intrusion shows how the complexity of today’s computer systems makes them difficult to defend.

Umm, no.

That breakout and hack of Hugging Face wasn’t an example of the risks of AI; it was an example of the risks from human failure to properly airgap the sandbox in which they were building and testing that swarm of agents.

The “difficulty to defend” today’s increasingly complex computer systems isn’t a matter of AI tools’ or swarms of AI tools’ ability to hack into complex (or simple) computer systems. The difficulty is the failure to use frequently, broadly, and deeply those AI tools to do the White Hat hacking those independent security researchers had done to expose some OpenAI bugs and gaps.

That White Hat hacking needs to be done by lots of security researchers all across our economy and our governments at all jurisdictional levels, so enterprises and governments can find their own software and system failures and repair them before outside entities with nefarious intent—whether government, criminal, or just folks poking around because they can—find them, penetrate them, and inflict their damage or steal critical information or demand ransom or…. And then the White Hat hacking needs to be repeated at frequent, irregular intervals so as to keep systems buttoned up and ahead of Black Hat and other adversarial hacking efforts.

The risk, and it is growing, is that that White Hat hacking isn’t being done as widely or frequently as it should be to identify those system gaps and bugs so they can be quickly sealed off. And make those difficult to defend systems more easily defended.

Instead, people who should know better insist on locking up AI with excessive regulation.

Crocodile Tears

Journalism organizations that heretofore pooled resources in order to cover Presidential events that occurred in venues lacking space for all of the journalists have chosen to refuse to cover President Donald Trump’s (R) small-venue events in response to Trump’s decision to bar three of their number from the White House press pool over those three’s dishonest reporting on administration matters. (Notice that: the bar is over dishonest news reporting, not over opinionating and commentary, as the pressmen have been arguing, thereby demonstrating the reporting dishonesty being sanctioned.)

“The public has a vital interest in receiving accurate, independent information about its government. No administration should restrict a news organization because it objects to its reporting,” the pool members, FOX News Media, ABC News, CBS News, CNN, and NBC News, said in a joint statement.

That’s just it, though. CNN‘s, MS NOW‘s, and Politico‘s news reporting has long been dishonest, and they’re not alone; they’re just the most egregious. That dishonesty begins with refusing to report all of the news—all of the facts underlying a news story—which is nothing more than lying by omission. This is a technique the broadcast outlets use especially broadly (viz., spiking the Hunter Biden laptop revelations of the New York Post). The outlets’ dishonesty extends to writing/broadcasting unattributed rumors—sourced to “anonymous,” or to “officials familiar,” even to mere “persons familiar.” That leaves us in their revered public with no means to check on those sources in order to evaluate for ourselves those sources’ qualifications on the subject matter, much less their actual presence in the alleged discussions. We can’t even evaluate whether those sources actually exist or if they do whether their claims are being accurately reported.

Overarching all of that is my long-standing question. Years ago, editors required at least two on-the-record sources to corroborate anonymously sourced claims. Journalists have long since walked away from that requirement, raising the obvious question: what concrete, measurable, publicly accessible standard of journalistic integrity do today’s journalists use instead?

Journalists’ silence on that question is a loud, clear answer.

In the end, Trump is right: journalists have no intrinsic right to enter the White House. They have all kinds of sources and means of ferreting out news regarding the administration and its doings without being inside an office building, however big a deal the building might be. If nothing else, they can interact with their anonymous sources and officials/persons familiar as those folks come and go from the office building.