Remix.run Logo
estearum an hour ago

You can literally send an email to one of hundreds of companies that do exactly this. They have no way of knowing whether you're asking them to synthesize a virus or a drug candidate or what.

timr an hour ago | parent | next [-]

No, you literally cannot. Synthesizing a stretch of DNA is trivial, and what you can send away for [1].

Building a functional virus is not even remotely a turn-key operation. Assuming you could get the genome, expressing that genome in a way that results in infectious virus is non-trivial.

[1] Even then, the companies will rarely give you long enough reads to make a full genome scaffold. It looks like there are two companies that will do 50-100kb assemblies as a service today, but I guarantee you they're going to look at what you're trying to make, and who is asking them to do it.

estearum 43 minutes ago | parent | next [-]

https://www.genewiz.com/public/services/gene-synthesis/custo...

There you go!

Steps from your mailbox to an actual virus is a few days of bench work.

timr 34 minutes ago | parent [-]

Yes, that's one of the ones I was talking about.

That's not a service that makes you a virus, and making one from an mRNA transcript is not trivial.

estearum 22 minutes ago | parent | next [-]

Here let's just get specific.

For each of the years below, what is YOUR estimate for how long would it take a person of 80th percentile intelligence with $10,000,000 (2026 money) to get from "I'd like to kill a lot of people" to a working virus?

You can provide a range for each if you'd like.

In the year 1800 – how long?

1950?

2020?

2026?

2050?

2200?

smallmancontrov 24 minutes ago | parent | prev [-]

And one wouldn't make one from mRNA. This guy doesn't know what he's talking about. Still: the difficulty isn't comparable to EUV machines or refining uranium and does not form a comfortable security barrier.

timr 15 minutes ago | parent [-]

I generally agree -- the actual risk is from serious/state actors, and for those, the barriers are not high.

I'm just saying that people are focused on the wrong problem because they've got LLM-brain.

rbliss an hour ago | parent | prev [-]

Yet.

timr 36 minutes ago | parent [-]

No, the sophomoric LLM argument does not apply here. The world is not a big computer.

The point is that the rate-limiting step in producing something infective is a couple million dollars in special lab equipment, skilled practitioners, and incredibly tricky and tedious procedures that take time and repetition to master.

So yeah, you can try to pay someone who has that expertise to make your top-sekret superbug (good luck with that), or you can do what any real threat actor is going to do, and put in the time and investment. That's the hard part, not asking ChatGPT for a genome sequence.

Let me put it another way: despite the synthesis pathways for many common illegal drugs being widely known and trivial enough that an undergrad O-chem major could do them, in fact doing this is a very good way to get caught and arrested. And that's easy.

estearum 31 minutes ago | parent [-]

Your example of how easy it is to control outputs behind specialized knowledge is a thing (recreational drugs) that exist in mass quantities every place on the planet at consumer-accessible prices?

timr 19 minutes ago | parent [-]

No. My argument is that many things in the world are hard in a way that computers cannot solve, and the existence of LLMs does not change that.

Synthetic biology is one of those things.

estearum 12 minutes ago | parent [-]

Uhhh right... but all the other hard parts are being solved too, correct?

LLMs are clearly going to solve a part that, 10 years ago, one would've assumed would be one of the highest and last barriers to go down.

Without LLMs, a reasonable security apparatus would be:

Step 1. Disallow dissemination and synthesis of known pathogens

Step 2. Watch closely anyone with the decades of training required to come up with their own pathogen

demibabs an hour ago | parent | prev | next [-]

Would they not be like “hmmm this one looks kinda similar to a known virus”

They really just synthesize anything for you?

estearum an hour ago | parent | next [-]

I'm sure some of them would, but they're not required by law to do so. And historically the way you'd do this is by actual fragment/substring matches. But these are novel viruses now. So what you really want to do is try to predict whether a novel genome is pathogenic... which is itself obviously a very hard technical problem.

Enginerrrd 33 minutes ago | parent [-]

That’s not too much a concern I think. Most of the real pathogenic qualities result from known genes. Inventing a totally novel virus that is also pathogenic is basically science fiction right now. Splicing together known components that could be bad in combination is closer to current technology.

smallmancontrov an hour ago | parent | prev [-]

No, of course not. In 2010 I went to a guest lecture from a guy who worked on the scanning algorithm for IDT. A few years later, there was a minor scandal when someone in a nearby lab used a personal credit card for a purchase and got a big shared account locked. So not only were they scanning the content of synthesis orders, they were validating payment back to labs. In 2010, when HTTPS was rare and facebook didn't even offer it.

estearum 42 minutes ago | parent [-]

"There are websites where you can just buy prescription drugs online?"

You: "No, of course not. I once went on a website to buy a drug, and they made go to a doctor and get a prescription and send it to them"

smallmancontrov 35 minutes ago | parent [-]

The legit synthesis sites have been scanning and authorizing since before the internet was encrypted. You suggested otherwise, demibabs expressed surprise, and was correct to express surprise because your implication was incorrect.

The black market exists -- but comes with black market problems.

estearum 28 minutes ago | parent [-]

If that's the understanding you came away with, it was clarified in my immediately following comment.

Glad we agree that there are labs that will solve very hard parts of creating a novel virus, either by accident or by negligence.

smallmancontrov 11 minutes ago | parent [-]

It was dishonest then for you to imply that readily accessible commercial labs didn't take reasonable precautions and it's dishonest now, too.

estearum 7 minutes ago | parent [-]

Can you describe specifically what is "reasonable precautions" as far as labs detecting novel pathogens sent to them?

an hour ago | parent | prev | next [-]
[deleted]
transcriptase an hour ago | parent | prev | next [-]

Yes in much the same way you can literally build a rocket and go to the moon.

You may be skipping a few of the involved steps.

estearum an hour ago | parent [-]

What involved steps are those?

You email the RNA strand (a text file) to a lab along with some money. The lab converts that information into a physical object (read: virus) and sends it back to you in the mail.

What step is missing?

smallmancontrov 43 minutes ago | parent | next [-]

The part where that service doesn't exist and isn't close to existing.

estearum 41 minutes ago | parent [-]

https://www.genewiz.com/public/services/gene-synthesis/custo...

Distance from mailbox to live virus is a few days of bench work from a semi-competent biochemist.

And yes, this service claims to have safeguards. Does every service? Does every future analogous service? Are those safeguards guaranteed to be robust against totally novel pathogens?

Answers: No, no, and no.

smallmancontrov 30 minutes ago | parent [-]

Really? mRNA? What kind of meme nonsense is this? You really don't know anything about these protocols do you.

Still, even though your estimates are silly, they aren't silly enough to change the conclusion that this isn't a comforting security barrier, so I suppose we agree on that much.

an hour ago | parent | prev [-]
[deleted]
consensus1 an hour ago | parent | prev [-]

One of the easiest and most effective AI regulations would be to simply require all these labs to run all incoming requests through a suite of the most advanced models asking if the request is likely to be a pathogenic agent.

estearum an hour ago | parent | next [-]

Yes probably true. Unfortunately we need only one defector lab to severely degrade the overall effectiveness of this approach (leaving aside the effectiveness of the detection models themselves).

wat10000 an hour ago | parent | prev | next [-]

Who’s going to simply require that? There are ~200 sovereign nations on the planet, they’re not all going to do it, or have effective enforcement if they do.

ben_w 35 minutes ago | parent [-]

This is the kind of thing that would be relatively easy to convince nations to sign up to*; actually enforcing, I suspect you're right.

* there's not an obvious benefit to being the one nation that says "you know what? We want to be known as 'the nation whose biolab insecurity wrecked the world', because taking blame works out so well for everyone.", though I'm fairly sure a large portion of the world will be totally willing to wargame the impact of hosting a lab as a deadman switch so nobody else attacks them first…

dgellow an hour ago | parent | prev [-]

That’s one interesting way to generate demand for AI vendors if the AI bet doesn’t pay off /s