Damus

Recent Notes

Taggart :ifin: · 1w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq25ys6m6zxxdggtg8vtcycfv2pzmv44h6lsne9d0gy6hz6nd3epvsa3q2xw I am confused why we're talking specifically about getting access to no-guardrail mode...
Dave Wilburn :donor: profile picture
@nprofile1q...

So, correct me if I'm wrong, but Hugging Face ran into a brick wall early in their incident response process when they were blocked by one or more models from analyzing security log data due to guardrails. Their work around was to use a Chinese-sourced open weight model with fewer guardrail restrictions. Part of OpenAI's response to this debacle was to offer to enroll Hugging Face into their trusted access program, which is clearly marketed as providing at least infosec functionality, implied to include some functionality that Hugging Face struggled to access past guardrails. Some invite-only portion of OpenAI's trusted access program includes further loosening of guardrails to allow even greater use in the infosec domain, although it's not clear to me that Hugging Face is approved for that specifically.

For me, the fundamental issue is that the set of potential GenAI model users with legitimate requirements for so-called dual-use functionality (e.g., common infosec use cases) is so large as to be unmanageable at scale.
Taggart :ifin: · 1w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq25ys6m6zxxdggtg8vtcycfv2pzmv44h6lsne9d0gy6hz6nd3epvsa3q2xw I would push back on this. There is absolutely a way to build the access control you'r...
Dave Wilburn :donor: profile picture
@nprofile1q...

I think the issue is more around the infeasibility of managing an embargo that large with so many stakeholders with conflicting requirements. It's similar to the problem of closed CTI sharing circles.

You know that the Trump regime is going to demand access, and also have opinions about who else gets access and who doesn't (mostly revolving around who grovels and pays them enough). And other governments with sometimes-conflicting interests will also demand access. And defense contractors, spy agencies, law enforcement, research institutions, infosec vendors, software vendors, etc.

If your circle of who gets access to frontier models with unrestricted guardrails gets so large that it includes the security team from a company like Hugging Face, then who DOESN'T get access? You're maybe talking about millions of people by that point.

How would you vet any of them? You'd need to stand up a whole department of 24x7 support personnel dedicated to managing this kind of access, probably subcontracting with a major data broker for identity verification, plus active monitoring for abuse.

And if we've learned anything at all from the Flock scandal, it should be that a user base that large is going to have a LOT of people engage in misconduct. At least some of that misconduct will render the embargo functionally useless.
1
Taggart :ifin: · 1w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq25ys6m6zxxdggtg8vtcycfv2pzmv44h6lsne9d0gy6hz6nd3epvsa3q2xw I am confused why we're talking specifically about getting access to no-guardrail models when that's not what happened. Hugging Face wasn't enrolled in Anthropic's Cyber Verification Pro...
Taggart :ifin: · 1w
We now know Hugging Face's AI cybersecurity "program" was running Claude Code Opus 4.8 against some logs. They weren't in the Cyber Verification Program so got a refusal. They moved to GLM 5.2 with th...
Dave Wilburn :donor: profile picture
@nprofile1q...

IMO there's no reasonable way to vet and manage access control to models without guardrails for a global customer base of this size and with so many conflicting interests. And some of the GenAI firms like Anthropic are going to be reluctant to remove all guardrails for their customers (e.g., their conflict with Trump/Hegseth).
1
Taggart :ifin: · 1w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq25ys6m6zxxdggtg8vtcycfv2pzmv44h6lsne9d0gy6hz6nd3epvsa3q2xw I would push back on this. There is absolutely a way to build the access control you're describing; that part is not a mystery. But what I think you might be driving at is that nobody wa...
Taggart :ifin: · 1w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq25ys6m6zxxdggtg8vtcycfv2pzmv44h6lsne9d0gy6hz6nd3epvsa3q2xw I have a similar experience but if I examine it closely, the who does not matter. I fi...
Dave Wilburn :donor: profile picture
@nprofile1q...

Maybe we're talking cross purposes. At least from my experience, the spectrum of attribution can range from a cluster of similar activity on the one end, to specific named organization/agency/individuals on the other. Somewhere in the middle includes the goofy industry cover terms, often with nonspecific links to suspected countries of origin. I would agree that most defenders benefit from cluster-of-similar-activity level of attribution. Some larger organizations, especially ones that need to do more formal threat modelling, probably benefit from group names. I don't think anyone except governments benefit from attribution down to specific orgs/agencies/individuals.
1
Taggart :ifin: · 1w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq25ys6m6zxxdggtg8vtcycfv2pzmv44h6lsne9d0gy6hz6nd3epvsa3q2xw Right so as I said, I believe "clustering" has value. To me, the strong form of "attribution" is "This is who did it and we're making a claim about it." And the reason I don't care is be...
Taggart :ifin: · 1w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq25ys6m6zxxdggtg8vtcycfv2pzmv44h6lsne9d0gy6hz6nd3epvsa3q2xw That puts the value on identifying relevant TTPs, where it should be. The who does not...
Dave Wilburn :donor: profile picture
@nprofile1q... my personal experience has been that, at least during incident response, narrowing down the universe of possible TTPs down to the ones most commonly used by a specific, attributed threat actor helps focus and speed up incident scoping and response in critical ways. It's less helpful in general defense, but absolutely critical in time-sensitive breach response.
1
Taggart :ifin: · 1w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq25ys6m6zxxdggtg8vtcycfv2pzmv44h6lsne9d0gy6hz6nd3epvsa3q2xw I have a similar experience but if I examine it closely, the who does not matter. I find relevant threat intelligence that describes a similar campaign. Great. I then hunt for those TTPs...
Taggart :ifin: · 1w
My contribution to the threat actor naming discourse https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/975/957/486/476/308/original/801269bafab7e0f4.png
Dave Wilburn :donor: profile picture
@nprofile1q...

Hmm...

I suppose the commoditization and separation of initial access and post-initial access crews, that's probably true for most criminal activity. But I don't know if I'd say that's universally true. There are still some criminal shops out there that, while not as monolithic as state actors, tend to maintain stable TTPs for long enough and for enough of the attack lifecycle that attribution can help defenders and responders.
1
Taggart :ifin: · 1w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq25ys6m6zxxdggtg8vtcycfv2pzmv44h6lsne9d0gy6hz6nd3epvsa3q2xw That puts the value on identifying relevant TTPs, where it should be. The who does not matter; you are aligning defenses against observed behavior. At best clustering can be useful, but...
Kevin Rothrock · 2w
U.S. intelligence is investigating whether Russia gave Iran targeting data or drone technology for strikes on "CIA facilities in the Gulf." If true, it would mean Moscow is doing for Tehran a version ...
Dave Wilburn :donor: profile picture
@nprofile1q...

Russia and the US have been screwing with each other through (barely) deniable proxies since longer than any of us have been alive.

The only thing surprising about any of this is the hesitancy by the American far right currently in power in treating the Russian regime as a persistent adversary, along with their willingness to stick their dicks inside the car door over and over again.