When I started in security, one of the prevailing attitudes was "The weakest link in the chain will always be the human."

I would like to thank every LLM provider and startup for changing this paradigm by introducing a much weaker link in the chain.

@neurovagrant
?
They haven't.
@phil @neurovagrant
Most humans don't copy/paste commands from ticket titles into their shells...
@EndlessMason @neurovagrant
Sorry,
who decided to, and then gave these tools access to do so?

Putting a non-deterministic tool with """safeguards""" there has very predictable consequences. If not humans, who exactly is to blame for this mess?

Cause it sure isn't a pile of numbers.
@phil @neurovagrant
Oh I see. In that case we should blame the fundamental forces of the universe for kicking off formation of planets and bootstrapping abiogenesis and evolution.
@EndlessMason @neurovagrant
To my knowledge, the fundamental forces of the universe, just like dead matter (including LLMs), don't have agency of their own.

Humans do.
@phil @EndlessMason "guns don't kill people" hasn't been convincing for decades.
@neurovagrant @EndlessMason
Guns, like any tool, need to be carefully managed by any human owning/ controlling them. LLMs can do a crapload of damage, but they can't be held accountable, just like a computer can't be held accountable for what sysadmins do.

@phil @neurovagrant
I don't.

I'm a stimulus-response machine. I'm governed by the laws of physics exclusively.

@phil by this logic, a human who forgets to update a PHP server is the weakest link in the chain. sure, the human is responsible if the PHP server gets hacked, but the human isn't what got compromised. "the weakest link in the chain will always be the human" is talking about phishing, and phishing LLMs makes phishing grandmas look difficult.