logoalt Hacker News

areoform • today at 2:58 AM • 2 replies • view on HN

This kills the talent pipeline, and it'll create a spam problem for the other folks because now people will try to github PR spam their way to getting on a CVE.

It's worth talking about the fact that you can't even talk about DMCA to a model trained on the Library of Congress unless you're one of the approved people. And that's before reverse engineering something or writing code.

So in this future, it sucks to be you if you're someone trying to make your small app more secure, someone trying to upskill, a tinkerer trying to bypass corporate lockdowns for a device they own (a recognized DMCA exception, btw), a teenager trying to learn about security...

It locks away much of the richness that produced hacker culture behind glass. You can look at their press announcements and PR pieces, but you can't touch.

And as they're lobbying the government for "sensible regulation," this inevitably leads to a future where computing is controlled.

It's the direction their existing reports are taking. They recently released one in September that talked about how they stopped "bioweapons." What were said bioweapons efforts? Oh, it was scientists using Claude for grant writing, paperwork and grammar. At national labs.

These people are basically proud of impeding real research to make better painkillers and study a neglected tropical disease, https://news.ycombinator.com/item?id=49651727

And this is being used to lobby against "dangerous" open-weight models because gasp a scientist might use them to write a grant! To make better antidepressants.

At what point do they start reporting someone taking apart an iPhone and trying to DIY a repair with a schematic as a thwarted "cyber security incident?"


Replies

jasomill • today at 4:19 AM

A funny, but slightly chilling safety violation I once got was ChatGPT being unwilling to recite the full text of Article I Section 2 of the US Constitution, aborting as soon as it hit the passage about "three fifths of all other persons".

Another funny one was Claude's refusal to provide the original untranslated text of a passage from Dante's Inferno on copyright grounds, though in this case pointing out that no 14th century literature was subject to copyright anywhere in the world was sufficient to override its objection.

LoganDark • today at 4:29 AM

Agree on the talent pipeline. It can take a long time for someone to obtain a CVE that has their name on it. You don't start being a security researcher only once that happens.

Several years back, I was working on generating AVB2 hashes on top of modified Android distributions, to increase the security after an owner has made their desired changes. I was doing this before the age of LLMs. Among other things, this would've enabled the secure features to work again, and potentially reduce the risk of root access being usable by malware. But apparently I'm not a security researcher because I didn't get a CVE about it.