Advice from the UK: keeping code secret will not really save you from LLM-powered vulnerability search.
https://www.gov.uk/guidance/ai-open-code-and-vulnerability-risk-in-the-public-sector
ISP veteran.
Built up CERT.at.
National and international CSIRT liaison for CERT.at
Private Blog is here: https://lendl.priv.at
| Website | https://lendl.priv.at/ |
Advice from the UK: keeping code secret will not really save you from LLM-powered vulnerability search.
https://www.gov.uk/guidance/ai-open-code-and-vulnerability-risk-in-the-public-sector

Yesterday I attended the first assembly of the Democratic Tech Alliance (DTA), which gathered in the European Parliament. Membership of the alliance includes European political groups like the Greens/EFA, the liberal/center right Renew Europe, the European People’s Party of Christian democratic, conservative and liberal-conservative persuasion and also the Progressive Alliance of Socialists and Democrats. This is a broad, quite sane and actually impressive collection of political groups, which gives me some hope.
@EUCommission the only way to enforce age verification of minors is through total internet supervision of everybody. And it won't help with any of the problems on the internet, because facilitating and effectively rewarding terrible behaviour optimises the revenue of the main players.
If you want a better internet, step one is to ban behaviour-based profiling for advertising, with no "consent" loophole. It makes surveillance ("tracking cookies") immediately illegal (no "legitimate interest" excuse, GDPR does the rest). That trashes the direct "more bullying and hate leads to greater revenue" connection, which immediately removes the incentive to put active effort into more vicious online spaces. This applies to Google, Meta, X, Reddit, etc.
Note that the "consent is not an excuse" part is critical. "Ask me later" just means that people are worn down into clicking "yes" eventually, just to get it out of the way, you know yourself the dark patterns, you know yourself the cookie consent forms, where "none of them" is tedious and must be repeated on every visit, but "yes please" is simple and eternal. Try changing that decision later.
Ban the surveillance. Yes, it's many companies' entire business model. That's too bad for them, should have tried being socially positive. Yes, many services will have to start some sort of subscription or pay per use model instead of being fake-free. That's OK, they'll also be disincentivised to enshittify.
It'd make the internet better for everyone, including children, who could continue to find and create so many positive communities online, instead of being blanket-banned.
I'm endlessly confused by the wave of legislation to ban children from accessing social media, rather than banning social media companies from harming children.
And yes I know Free Speech but now we know that we can torture and sicken people, including kids, in this medium. Some of the things we currently call Free Speech turn out to be poison, mental control, and torture.
At some point we have to separate the "innovation" from the digital lead and asbestos tech companies are feeding people.
I just read https://philpapers.org/rec/LERTAF
I have a really hard time reading philosophical reasoning. Nevertheless, for me, there are a number of red flags in the text. I cannot support the conclusion of the author.
What do you all think?

Computational functionalism dominates current debates on AI consciousness. This is the hypothesis that subjective experience emerges entirely from abstract causal topology, regardless of the underlying physical substrate. We argue this view ...
Triggered by reading my slides from last year:
What happened with the minerals deal that Trump so desperately wanted from Ukraine last year?