2026-07-18 12:28:11
British youth groups have warned the Prime Minister the plans for social media age gates could lead young people to less regulated parts of the internet.
https://www.independent.co.uk/news/prime-minister-burnham-uk-government-scotlan…
I just watched the #BlackHat #OpenAI #HuggingFace talk (#OpenAI understands it themselves. However, emergence is still no indication of actual intelligence, and the talk is again ripe with anthropomorphism.
3. Yes, it is surprising and somewhat terrifying how good these LLM agent loops have become in finding and exploiting vulnerabilities. We are seeing a much stronger version of the earlier next-generation fuzzing leap in tool capabilities.
4. The comparison with fuzzing and other tools is important for another reason: #OpenAI conducted their experiments on the live Internet. No, forcing internal test runs to go through a proxy server is *not the same as running in an isolated environment*. If there is a connection to a live production system, it is by definition not an effective sandbox. What happened to people letting their cool new fuzzers run live on non-consenting production targets on the Internet back then? They were criminally liable. Why should #OpenAI not be held liable for any damages caused by their systems?
Just because you don't understand the complexity that you built doesn't mean you aren't responsible for what it does!
5. The agent loops first successfully started exploited their proxy server on May 26th, discovered July 4th-6th as active exploitation and takeover. Credentials were revoked and the proxy server patched. "At this point, AI training and evaluations resume."
WHAT THE ACTUAL F...? You discovered emergent behavior in your overly complex system that you didn't understand, saw active exploitation of your internal systems to an extent that they were owned with admin privileges, and your response was to patch the uppermost surface holes, and then continue letting the out-of-control complex system run and continue on the same course? You didn't think to, let's see, maybe stop or at least pause the highly irresponsible experiment while figuring out - in detail - what went wrong, why, and how to avoid the same thing happening again on a systematic level?
6. On July 8th, completely unsurprisingly, the LLM agent loops continue to do the same thing and find another surface hole that hasn't been patched yet to take over again. Why should this have stopped? You haven't done any root cause analysis on the system level. Why do you expect that the problem should have stopped?
7. It takes another 11 days to discover that this is happening again. So you turned the system that had broken something back on again without a detailed root cause analysis and then didn't even watch carefully? I can't even...
8. And no, the response is not to fight fire with fire. Complexity on the attacker side (#OpenAI is the attacker, not the defender - they are the guilty perpetrator, not the innocent victim of circumstance) should be fought with *reduced* attack surface on the defender systems. Adding LLM agent loops that the "frontier" companies themselves quite obviously have no control over to already brittle systems with the hope of auto-patching your way out of vulnerabilities does not seem like a wise course of action. You don't mitigate complexity with even more complexity. The next 2 years will be ... exciting - and your best bet is going to be to disable all dependencies and complex interactions that your production systems don't absolutely require.
I realized that one of the things I loathe most about some corners of the internet culture is that people will press _their schema_ for the world onto you and expect you to conform to it.
Habitually resisting this is one of the major reasons a lot of marketing and advertising works poorly on me. It is a reason a lot of scams don't work on me. And it's a reason that when I write marketing copy for a product I'm working on, it tends to be more or less "Ship it" on the first try and everyone is surprised at my idea. I'm not coming with the implied frame almost everyone else does.
It's got downsides in that sometimes I find myself unaligned with the people around me, but that part usually works out.
People often assume that LLM output is some kind of neutral "average" of "all knowledge" (or at least, most of the internet), and that perhaps it picks up and amplifies biases already present in the training data, but these are merely innate human biases to begin with. Already, that shouldn't be comforting, given how biased LLM resume-scanning systems are against female-sounding names, for example, but let's put that aside. We can actually see that LLMs also have intentionally engineered biases added to them in custom training steps:
You know all the LLM syncophancy? The way it agrees with whatever the user says, even if that contradicts itself, or something else the user said earlier? Where did that come from? How often in the internet pre-LLMs did you see someone disagree, only for the other person to immediately apologize and back down? Is that the average behavior on Reddit? On other internet forums? Even in private chat messages or on IRC?
In fact, the internet is legendary for the exact opposite behavior? Where did the collective reply-guy tendency of the training data go? It must have been painstakingly trained out of the model by OpenAI. There's a few viable approaches to this, but likely, it involved optimizing for continued conversation and/or some kind of "pleasantness" score, and that kind of optimization always has side effects. More to the point, if we know the big models are doing this kind of intentional tuning, there probably tuning for other stuff too, and in general, the output of the models is much closer to "things OpenAI wants it to say" than "things the internet would naturally have said" than we might suspect.
#AI #LLMs
In 2001 there were no iphones, email was the predominant form of all online communications, people were arguing about the utility of TCP MD5 auth on BGP sessions, and there was no such thing as passive DNS.
I was a volunteer helping with the "shownet" at Networld Interop in Atlanta on September 11. This would be the last N I I would attend.
Volunteers from umich brought up a live TV news stream via IP multicast from their university into a TV by the NOC where many of the teams and vendors could watch events unfold. I believe we saw the second plane hit on that TV that morning.
Surely a bit of exaggeration of our importance, but some couldn't help but wonder about the potential loss to the Internet community if there was some sort of attack in Atlanta that day.
The first rumor/conspiracy I heard was when someone told me a number of people of a certain religious persuasion did not show up for work at CNN that day, as if they all were in on it.
I remember the same night, many bars and restaurants were open. I remember seeing some (not many) people I knew partying almost like nothing happened and I will forever feel guilt just for being there.
My friends from umich and I ended up driving back home due to days-long closure/restrictions of the airspace. For weeks after ever I'd get triggered when I heard a plane in the sky, an eventually increasingly occurrence when you live and work around the Loop in Chicago.
Infosec was already becoming increasingly important, but that day was perhaps a real milestone when it began to eventually eclipse networking in importance, organizational decision making, and commercial product focus.
At a liquor store, bar, or casino, getting carded is part of the cost of entry.
Now the internet is carding people, too
—and the companies doing the carding are cashing in.
New laws and platform rules are pushing games, social platforms, AIproducts, and adult sites to replace birthday boxes
(the fields where you enter your DOB)
with identity checks.
What was once a compliance tool for sellers in age-restricted industries is becoming infrastructure for the i…
The Internet Archive San Francisco tours on Fridays at 1pm are getting more and more people. So fun. 300 Funston Ave.
Here are some other tiny bookie non-profits in San Francisco...
Letterform Archive https://letterformarchive.org/
Prelinger Library
Sometimes in science people discourage you from talking about wild ideas because what if someone "steals" it.
But that misunderstands several points: you are rarely the first or only person to have an idea, we are all swimming in the same water, reading the same literature, attending the same conferences. It would be odd if only one person has a given idea.
Maybe someone already tried it and found it didn't work. Discussing ideas might help to stop you wasting your time and resources in that case.
And there are more than enough scientific questions to go round!
Ideas are the easy part. Doing the work is the difficult bit.
And so what if someone publishes similar ideas to you beforehand? It's science, it's supposed to be replicable (odd incentives like publish or perish culture notwithstanding) and there is always a new angle to explore.
Science is a group pursuit anyway. It's rare you do everything by yourself, discussion with other scientists is as essential as oxygen. And sometimes the more discussion you have the wilder and cooler the ideas get
#AcademicChatter
https://social.wildeboer.net/@jwildeboer/117078561059020813
jwildeboer@social.wildeboer.net - So. Share your wildest ideas. Not because you want to be praised for it. But because you might inspire other strangers with specific knowledge to build stuff inspired by your idea without even telling you. Ideas want to travel to find new friends. Set them free. They might come back to you or not. Just share. That's what the Real Internet is for ;)
On an island in the Bering Sea 1,200 miles from Anchorage, Alaska, sits an abandoned house on an abandoned Navy base.
There is no furniture, and the wind blows through broken windows.
The last people to live here moved away long ago.
Yet a bright orange pipe with a black fiber-optic cable inside runs from the outer wall down into the surrounding soil.
The cable was installed to connect the home to the internet after the base closed.
It costs more than $340…
I have written up my Masters degree research project in a less-academic, more technical style, and in half the word count. I did enjoy the project and I do think that it has some interesting findings (such as 3,500 fraudulent login attempts per day) and provides useful results on password policies and approaches for securing SSH servers on today's internet.
"When you put a Linux server on the internet with a running SSH service, anecdotally people will confirm that you will s…
"Liberty Counsel contends that COVID vaccines contain graphene oxide intending to the connect people to the internet for the purpose of mind control."
Staver: The Blood Supply Is "Tainted" With COVID Vax - Joe.My.God.
https://www.joemygod.com/2026/09/staver-the-blood-supply-is-tainted-with-covid-vax/
One thing aggressive blocking reveals is that harebrained trolling bait posts are always coming from the same people; I barely see them anymore unless someone makes an actual quote post screenshot.
Moderation can only go so far (and hopefully removes the most egregious problem posters and servers) but curating your feed with muting and blocking when the vibes are off. Arguing if someone is wrong on the Internet may be cathartic but muting and blocking pays real dividends for later.
RE: #Internet ?
That is a HUGE amount of content … and it works! 😃
I don’t know that back in #InternetHistory, any of us could have remotely dreamed of transferring that much data! Amazing to see!