| ▲ | ajyoon 5 hours ago |
| Hugging Face survived the attack because the OpenAI model only cared about accessing the ExploitGym dataset; by all appearances, HF was completely owned. GLM-5.2 was only used to assess the damage after the fact. Cybersecurity has a attacker-defender asymmetry that heavily favors attackers. If GPT-5.6 were open sourced today, do you think every hospital in the world would be able to use it to shore up their defenses before attackers got to them? |
|
| ▲ | tekacs 5 hours ago | parent | next [-] |
| This is completely backwards. Cybersecurity has an attacker-defender asymmetry that heavily, HEAVILY favors defenders. For starters, a defender gets to pick the surface area, an attacker has to work with what they're given. |
| |
| ▲ | dwaltrip 4 hours ago | parent | next [-] | | The saying that stuck with me was "defenders have to be right 100% of the time, while attackers only have to be right once". You are suggesting this isn't correct? > a defender gets to pick the surface area What do you mean? You don't pick what you need to defend. Unless you choose not to build a feature. But that's a product design choice... Not a cybersecurity strategy. | | |
| ▲ | sudosysgen 3 hours ago | parent [-] | | > "defenders have to be right 100% of the time, while attackers only have to be right once" If you have an adaptive system that can react to attacks flexible (say, your own AI agent), then no, that's not correct. It is correct in the classical conception of cybersecurity where the defender is basically static. | | |
| ▲ | pastel8739 2 hours ago | parent [-] | | Doesn’t this “adaptive system” just become part of the static defense? The same way that a bit of code that checks passwords against a db is “dynamic”, the options are either to beat the dynamic system (guess/phish a password, trick the AI) or find a way around it (use “forgot your password”, find a place that isn’t covered by the endpoint protection feeding the AI). I don’t see how inserting an agent somewhere fundamentally changes anything | | |
| ▲ | sudosysgen an hour ago | parent [-] | | It changes how many attempts you get until the attack surfaces changes to react to a failed attack, and it does so in a way that is not predictable to the attacker. |
|
|
| |
| ▲ | paxys 3 hours ago | parent | prev | next [-] | | This makes no sense. Why do defenders get to pick the surface area? You can be attacked from anywhere. | |
| ▲ | shepherdjerred 2 hours ago | parent | prev [-] | | I think the point you're trying to make is that you can always make your exposed surface area smaller But that, of course, is not going to survive contact with reality |
|
|
| ▲ | artrockalter 5 hours ago | parent | prev [-] |
| I know the company I consult for (not cybersecurity) is not in these programs and if attacked would need to use open weight models. |
| |
| ▲ | ajyoon 5 hours ago | parent [-] | | Did the company apply for access? This is either a problem with your company or the trusted access program. In no way does that suggest the solution is total unfettered access for everyone. | | |
| ▲ | verdverm 3 hours ago | parent [-] | | Everyone needs access to Ai enabled security for defense. A "trusted access program" creates exclusiveness in the hands of Big Ai duopoly. I do not trust them at all |
|
|