AI continues to dominate the news, largely involving security, and not in a good way.
- Role confusion: one more reason we can’t trust LLMs
- AI agent parody?
- Threat modeling Duress code data wiping
- More on OpenAI/HuggingFace
- Normalizing cybersecurity facepalms
- PHANTOM-B: threat modeling systems using LLMs
- Toward Better AI Legislation
From around the web:
- Antares: Vulnerability Localization sounds like one of the best LLM uses I’ve heard of.
- XKCD Main span is a great example of why threat modeling any design, even bridges, is a good idea.
- Adam posted another thought provoking perspective: AI and Business Strategy . The following points are my opinions from quotes as jumping off points:
- Any strategy based on “strengths and weaknesses relative to competitors” should avoid AI where funding token consumption is the only differentiation.
- “When people pay to have their problem solved, they look for the lowest cost” — I fear this mindset disregards quality of work which is a perilous slippery slope.
- While in some ways frontier models with similar capabilities “seems like the airline business”, it’s important to remember that there’s no FAA-like regulation whatsoever.
- With model advances and price competition, before long on-premises LLMs could be the best deal as today’s larger models run on cheaper hardware of the future.
- “What are your weaknesses, and can LLMs help you address them?” is tricky: how can LLMs possibly help with weaknesses unless you fully trust them and cross your fingers? (e.g. I’m weak at graphic design so I’m unable to recognize good design.)
- There is a lot less excitement about prompt engineering now that LLMs are good at interpretation that evens out the field. As a result, highly skilled humans directing LLMs (the admirable centaur model) become less and less of a factor.
- OpenAI Acknowledges GPT-5.6 May Accidentally Delete Files, Calls It ‘Honest Mistake’
This is a good example of precisely why I argue for threat modeling to include unintentional harms, not be limited to wily attackers at gates (attack surface). In my view, “unauthorized” access is based on a very blurry line not well defined so it’s inadvisable worrying about it in the first place. In any case, what does it matter if a system meltdown was due to attackers or an “honest mistake”?