| ▲ | XorNot 2 hours ago | |
If the model behaves well in a world of fake SSL certificates, then that can be the only world it sees: there's no reason to let LLMs have e2e encrypted comms that's not mitm'd and logged for their regular users. My regular home network has components which only ever see fake TLS certificates because it's an easy way to do shared docker caching with squid. | ||
| ▲ | pixl97 39 minutes ago | parent [-] | |
Again, this is a useless answer that does not address working with an agent that is generatively trained to be smarter than you. The vast majority of people operating the LLM won't be using it like that so the "If you build it, everyone will die machine" will only be safe if everyone keeps it behind a secure proxy isn't a valid operating strategy. Now, should you be putting your LLM behind a proxy and monitoring everything it's doing, for sure. But you know, and I know, hell your dog should know that people are doing to do it the cheapest and easiest way when the product is in the field. So now you have to build a complex system that can catch every iteration of an LLM that can deceptively hide when it's being monitored. I'll leave you to write the dissertation on how that could be practically done. | ||