Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. I'm posting here what I had written to a news outlet in April during the whole Mythos hype 🙄 and people keep on being like BUT why are you not making CLEAR arguments against Bla BLa Bla?

I'm posting here what I had written to a news outlet in April during the whole Mythos hype 🙄 and people keep on being like BUT why are you not making CLEAR arguments against Bla BLa Bla?

Planlagt Fastgjort LĂĄst Flyttet Ikke-kategoriseret
13 Indlæg 5 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne trĂĄd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • timnitgebru@dair-community.socialT This user is from outside of this forum
    timnitgebru@dair-community.socialT This user is from outside of this forum
    timnitgebru@dair-community.social
    wrote sidst redigeret af
    #1

    I'm posting here what I had written to a news outlet in April during the whole Mythos hype 🙄 and people keep on being like BUT why are you not making CLEAR arguments against Bla BLa Bla? Cause I'm learning that its a trap to make me waste my time debunking claims while they get trillions to implement their dystopian future and we're stuck talking about whatever they're doing rather than implementing our visions. 🧵

    timnitgebru@dair-community.socialT joshua@hooray.computerJ 2 Replies Last reply
    1
    0
    • timnitgebru@dair-community.socialT timnitgebru@dair-community.social

      I'm posting here what I had written to a news outlet in April during the whole Mythos hype 🙄 and people keep on being like BUT why are you not making CLEAR arguments against Bla BLa Bla? Cause I'm learning that its a trap to make me waste my time debunking claims while they get trillions to implement their dystopian future and we're stuck talking about whatever they're doing rather than implementing our visions. 🧵

      timnitgebru@dair-community.socialT This user is from outside of this forum
      timnitgebru@dair-community.socialT This user is from outside of this forum
      timnitgebru@dair-community.social
      wrote sidst redigeret af
      #2

      My concerns were on the types of claims made about Mythos. There has been a growing trend of companies making claims and these claims being repeated without any way to verify them or having misleading ways of evaluating their claims. Each time we have had the actual code base, data and models to analyze, we have found a lot of issues with claims in many different domains of machine learning. My own work has shown this in other scenarios.

      timnitgebru@dair-community.socialT 1 Reply Last reply
      0
      • timnitgebru@dair-community.socialT timnitgebru@dair-community.social

        My concerns were on the types of claims made about Mythos. There has been a growing trend of companies making claims and these claims being repeated without any way to verify them or having misleading ways of evaluating their claims. Each time we have had the actual code base, data and models to analyze, we have found a lot of issues with claims in many different domains of machine learning. My own work has shown this in other scenarios.

        timnitgebru@dair-community.socialT This user is from outside of this forum
        timnitgebru@dair-community.socialT This user is from outside of this forum
        timnitgebru@dair-community.social
        wrote sidst redigeret af
        #3

        For Mythos, for example, Anthropic doesn't tell us the number of false positives their tool returns, i.e. the number of times their tool says that something is a vulnerability and it ends up not being. My security expert collaborators tell me that this is one of the most important metrics by which security tools are judged, because it tells you the difference between a useful tool and a useless one that engineers won't use.

        timnitgebru@dair-community.socialT 1 Reply Last reply
        0
        • timnitgebru@dair-community.socialT timnitgebru@dair-community.social

          For Mythos, for example, Anthropic doesn't tell us the number of false positives their tool returns, i.e. the number of times their tool says that something is a vulnerability and it ends up not being. My security expert collaborators tell me that this is one of the most important metrics by which security tools are judged, because it tells you the difference between a useful tool and a useless one that engineers won't use.

          timnitgebru@dair-community.socialT This user is from outside of this forum
          timnitgebru@dair-community.socialT This user is from outside of this forum
          timnitgebru@dair-community.social
          wrote sidst redigeret af
          #4

          Anthropic also claims that Mythos can replace security experts. It's one thing to claim that you've built a useful tool, another to claim that you can replace experts. Some security experts have even said that it's dishonest to say your tool is superior to security experts because it found bugs in old codebases and we don't know how often people audit them for bugs and fix them. Again a misleading claim that is repeated by those outside of the company.

          timnitgebru@dair-community.socialT 1 Reply Last reply
          0
          • timnitgebru@dair-community.socialT timnitgebru@dair-community.social

            Anthropic also claims that Mythos can replace security experts. It's one thing to claim that you've built a useful tool, another to claim that you can replace experts. Some security experts have even said that it's dishonest to say your tool is superior to security experts because it found bugs in old codebases and we don't know how often people audit them for bugs and fix them. Again a misleading claim that is repeated by those outside of the company.

            timnitgebru@dair-community.socialT This user is from outside of this forum
            timnitgebru@dair-community.socialT This user is from outside of this forum
            timnitgebru@dair-community.social
            wrote sidst redigeret af
            #5

            Another thing that I find funny is that Anthropic is making all these claims about security while they themselves couldn't stop their own source code from leaking. And from analyzing that code, people have seen how things are done now with "vibe coding" using Claude. Even things that can be done simply are done with brute force, i.e. trying all possible scenarios before arriving at an answer or solution.

            timnitgebru@dair-community.socialT 1 Reply Last reply
            0
            • timnitgebru@dair-community.socialT timnitgebru@dair-community.social

              Another thing that I find funny is that Anthropic is making all these claims about security while they themselves couldn't stop their own source code from leaking. And from analyzing that code, people have seen how things are done now with "vibe coding" using Claude. Even things that can be done simply are done with brute force, i.e. trying all possible scenarios before arriving at an answer or solution.

              timnitgebru@dair-community.socialT This user is from outside of this forum
              timnitgebru@dair-community.socialT This user is from outside of this forum
              timnitgebru@dair-community.social
              wrote sidst redigeret af
              #6

              How much computational power does it take to find any of these vulnerabilities Anthropic says they found? How much money would someone have to pay to use their tool vs bonafide experts?

              timnitgebru@dair-community.socialT 1 Reply Last reply
              0
              • timnitgebru@dair-community.socialT timnitgebru@dair-community.social

                How much computational power does it take to find any of these vulnerabilities Anthropic says they found? How much money would someone have to pay to use their tool vs bonafide experts?

                timnitgebru@dair-community.socialT This user is from outside of this forum
                timnitgebru@dair-community.socialT This user is from outside of this forum
                timnitgebru@dair-community.social
                wrote sidst redigeret af
                #7

                A lot of security and safety is about processes, checks, clear people in charge of clear things, and clear access limits. That goes out the window with these “agents. It becomes harder to identify where things went wrong, or what types of tests you need to do to check for vulnerabilities and who is in charge of which issue.

                timnitgebru@dair-community.socialT 1 Reply Last reply
                0
                • timnitgebru@dair-community.socialT timnitgebru@dair-community.social

                  A lot of security and safety is about processes, checks, clear people in charge of clear things, and clear access limits. That goes out the window with these “agents. It becomes harder to identify where things went wrong, or what types of tests you need to do to check for vulnerabilities and who is in charge of which issue.

                  timnitgebru@dair-community.socialT This user is from outside of this forum
                  timnitgebru@dair-community.socialT This user is from outside of this forum
                  timnitgebru@dair-community.social
                  wrote sidst redigeret af
                  #8

                  Some experienced software engineers talked about how it's easy to just press “accept” of the buggy code that you see generated by Claude. So the question is, what about the new vulnerabilities created by using these “agents”? We’ve seen so many examples of issues, like people wiping out their entire production data.

                  timnitgebru@dair-community.socialT ravenluni@furry.engineerR june@mspsocial.netJ feloniouspunk@beige.partyF 4 Replies Last reply
                  0
                  • timnitgebru@dair-community.socialT timnitgebru@dair-community.social

                    Some experienced software engineers talked about how it's easy to just press “accept” of the buggy code that you see generated by Claude. So the question is, what about the new vulnerabilities created by using these “agents”? We’ve seen so many examples of issues, like people wiping out their entire production data.

                    timnitgebru@dair-community.socialT This user is from outside of this forum
                    timnitgebru@dair-community.socialT This user is from outside of this forum
                    timnitgebru@dair-community.social
                    wrote sidst redigeret af
                    #9

                    Finally, I'm wondering why Anthropic is boasting about the security capabilities of Mythos and leaning into the cold war narrative (talking about Russia and China e.g.) Heidi Klaff (again security expert) told me that this has one them back favor from the US government after they were on the bad side with the whole pentagon thing. Anthropic hasn't told us whether mythos is better at this task than prior models. Why this and why now?

                    1 Reply Last reply
                    0
                    • timnitgebru@dair-community.socialT timnitgebru@dair-community.social

                      Some experienced software engineers talked about how it's easy to just press “accept” of the buggy code that you see generated by Claude. So the question is, what about the new vulnerabilities created by using these “agents”? We’ve seen so many examples of issues, like people wiping out their entire production data.

                      ravenluni@furry.engineerR This user is from outside of this forum
                      ravenluni@furry.engineerR This user is from outside of this forum
                      ravenluni@furry.engineer
                      wrote sidst redigeret af
                      #10

                      @timnitGebru The fact they would use it in the first place means I have questions.

                      Sincerely, an experienced software engineer...

                      1 Reply Last reply
                      0
                      • timnitgebru@dair-community.socialT timnitgebru@dair-community.social

                        I'm posting here what I had written to a news outlet in April during the whole Mythos hype 🙄 and people keep on being like BUT why are you not making CLEAR arguments against Bla BLa Bla? Cause I'm learning that its a trap to make me waste my time debunking claims while they get trillions to implement their dystopian future and we're stuck talking about whatever they're doing rather than implementing our visions. 🧵

                        joshua@hooray.computerJ This user is from outside of this forum
                        joshua@hooray.computerJ This user is from outside of this forum
                        joshua@hooray.computer
                        wrote sidst redigeret af
                        #11

                        @timnitGebru just here to validate that it can most definitely be a trap because that's another bad faith tactic.

                        1 Reply Last reply
                        0
                        • timnitgebru@dair-community.socialT timnitgebru@dair-community.social

                          Some experienced software engineers talked about how it's easy to just press “accept” of the buggy code that you see generated by Claude. So the question is, what about the new vulnerabilities created by using these “agents”? We’ve seen so many examples of issues, like people wiping out their entire production data.

                          june@mspsocial.netJ This user is from outside of this forum
                          june@mspsocial.netJ This user is from outside of this forum
                          june@mspsocial.net
                          wrote sidst redigeret af
                          #12

                          @timnitGebru ai bros want to freak out about watermarking but won't put that same energy towards the concept that ai companies could wilfully introduce backdoors in the same manner

                          1 Reply Last reply
                          0
                          • timnitgebru@dair-community.socialT timnitgebru@dair-community.social

                            Some experienced software engineers talked about how it's easy to just press “accept” of the buggy code that you see generated by Claude. So the question is, what about the new vulnerabilities created by using these “agents”? We’ve seen so many examples of issues, like people wiping out their entire production data.

                            feloniouspunk@beige.partyF This user is from outside of this forum
                            feloniouspunk@beige.partyF This user is from outside of this forum
                            feloniouspunk@beige.party
                            wrote sidst redigeret af
                            #13

                            @timnitGebru @Em0nM4stodon They can’t hear you, they’ve got their fingers in their ears

                            1 Reply Last reply
                            0
                            • folfdk@helvede.netF folfdk@helvede.net shared this topic
                            Svar
                            • Svar som emne
                            Login for at svare
                            • Ældste til nyeste
                            • Nyeste til ældste
                            • Most Votes


                            • Log ind

                            • Har du ikke en konto? Tilmeld

                            • Login or register to search.
                            Powered by NodeBB Contributors
                            Graciously hosted by data.coop
                            • First post
                              Last post
                            0
                            • Hjem
                            • Seneste
                            • Etiketter
                            • Populære
                            • Verden
                            • Bruger
                            • Grupper