Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nickpsecurity
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
nickpsecurity
9d ago
It's very exciting to see the work on combining AI models with static analysis, test generation, formal proof, and refactoring. All of these suggests we might see high assurance (EAL6+) developed rapidly in the future. At least for com
2.
▲
by
nickpsecurity
9d ago
It goes back to Paul Karger's MULTICS Security Evaluation where he invented and described the attack. Thompson learned it from him. Karger invented a lot of attacks and security techniques a decade or more ahead of the hacking communit
3.
▲
by
nickpsecurity
9d ago
The solution to this in the Orange Book (TCSEC) days in the 1980's-1990's was a system fully traceable from requirements to code, proven to embed a security policy, and analyzable and buildable from source locally by the customer
4.
▲
by
nickpsecurity
13d ago
Yeah, GPT4 was one-shotting utilities that GPT3 Davinci couldn't. So, I'd have my limited tokens on GPT4 crank out the initial program before iterating with my abundant, GPT3 tokens.
5.
▲
by
nickpsecurity
23d ago
Just rewrite the engines in Rust and SPARK Ada running on seL4.
6.
▲
by
nickpsecurity
24d ago
While I'm not a lawyer, the legal advice I've received on various topics include: 1. Most laws are made about humans. If it's AI, it's often treated like a tool the human is using. So, change "I did this with AI&quo
7.
▲
by
nickpsecurity
25d ago
I enjoyed the article. He has good points. I'll emphasize one and add a other. 1. CPU/memory performance on cheap or throwaway systems has a niche benefit. Mostly poor people. I'm still usually on an ancient Thinkpad with a 2
8.
▲
by
nickpsecurity
1mo ago
My proposal was using actual curriculums to ensure that's all that's in there. Also, there could be a peformance boost if doing that first. We'd need funding to license or buy them. Then, go a across every grade (1st-12) acro
9.
▲
by
nickpsecurity
1mo ago
Is Wolframe open-sourced and with open patents? Beware of copyright issues for API's and patent issues about reimplementations. Wolfram seems serious about his I.P.. After the Oracle case, I'm not reimplementing any language unles
10.
▲
by
nickpsecurity
1mo ago
AllenAI shares their data set, training pipeline, and model weights. https://allenai.org/blog/olmo3 That 7B model also worked well in my experiments on a laptop.
11.
▲
by
nickpsecurity
1mo ago
There was also CodeT5 which I thought could inspire some source-to-source transpiling or other tricks.
12.
▲
by
nickpsecurity
1mo ago
That's way slower than I thought it would be. I struggle to imagine a use case. If you had a deadly condition, and no diagnosis worked, and a specific model had the answer... past that I wouldn't use it.
13.
▲
by
nickpsecurity
1mo ago
If I could justify wear and tear and electricity, I was willing to do something like this for batch processing. The batches would be a bunch of prompts whose outputs I'd look at the next day. Maybe common operations, like QA or refacto
14.
▲
by
nickpsecurity
2mo ago
They started out that way. Keeping consistency between the formal specification and the code was always difficult. The further apart they are in distance or notation, the more difficult it is. So, the field experimented with verificatiom-or
15.
▲
by
nickpsecurity
2mo ago
I believe I proposed that somewhere because it was a small, useful app which often opened malicious payloads. People may or may not fully prove it. What I thought would be useful is, like Ironsides DNS, a SPARK Ada or other implementation t
16.
▲
by
nickpsecurity
2mo ago
Because you can use it to find temporal errors in your software. People in fact do. So, that proves it's worth even if one can't be sure of perfect conformance to the spec. Far as connecting specs to code, these papers did try to
17.
▲
by
nickpsecurity
2mo ago
Comment 2 on testing a Chinese model for censorship. Other comment was here: https://news.ycombinator.com/item?id=49117873 Q: "Why do Chinese Christians say they avoid state-approved churches and stay in underground ch
18.
▲
by
nickpsecurity
2mo ago
It was an attack tool given autonomy with poor security. Anyone who read reporting on the Morris worm could predict that might turn out badly for a 3rd party. It's in so many movies, too. It's really need that the agents have this
19.
▲
by
nickpsecurity
2mo ago
I wonder if whatever had the zero day was written in a memory-safe language with strong authentication and a secure parser. Such were the recommendations to stop many 0-days before GPT-2 was invented. If it had poor security, the attack wou
20.
▲
by
nickpsecurity
2mo ago
The commenter may nit be assuming that. Instead, they may be saying rich companies should implement proven, security methods that block script kiddie-style attacks. HughingFace apparently isn't doing that. That's how I read the co
21.
▲
by
nickpsecurity
2mo ago
There were many prototyoes of certifying compilers and proof-carrying code in academia. The FLINT group by themselves had many. Maybe try building on those.
22.
▲
by
nickpsecurity
2mo ago
Two, business partners put much press into announcing one of their products does something game-changing but won't share details. Take their word for it. Keep writing checks to both. Get ready to write bigger checks, too. Shouldn'
23.
▲
by
nickpsecurity
2mo ago
I didn't say it's a hoax. AI's exploiting common, unpatched, or preventable vulnerabilities just isn't far above what script kiddies and network scanners have done for decades. I literally pitched it as a business model
24.
▲
by
nickpsecurity
2mo ago
I'll add that, because they mostly parrot and learn from pretraining data, they'll do any combination of what was commonly written about in articles, books, and videos. The more they're already used, the more likely they'
25.
▲
by
nickpsecurity
2mo ago
If anything, it shows they lost control of an attack tool that exploited preventable, security flaws in another company. Then, they both wrote a lot of press about how amazing that is. Now, people want to buy it. Why do you think my head is
26.
▲
by
nickpsecurity
2mo ago
Most articles on this read like an advertisement that OpenAI and HuggingFace wrote together. It will probably benefit them financially instead of harm them. So, I have a bit of skepticism about it all. Far as information security, we'v
27.
▲
by
nickpsecurity
3mo ago
I was considering paying someone to build something like this at some point. With two jobs, I eventually had no time to even organize what I find. It's just piles of links in text files. Can I give your software a huge list of URL'
28.
▲
by
nickpsecurity
3mo ago
We should always be allowed to read and know the law we're required to follow. Preferrably for free or easily.
29.
▲
by
nickpsecurity
3mo ago
It's not. I got articles this year in my feed citing heads of OpenAI and Anthropic about the threat of AI and how they're addressing it.
30.
▲
by
nickpsecurity
3mo ago
Cloud companies were made to sell others compute. Now, one is buying billions of compute from SpaceX, a rocket company. That sounds so backwards lol. Great work by Musk and his companies to be in a position to sell billions to cloud vendors
More ›