logoalt Hacker News

paxystoday at 3:55 PM2 repliesview on HN

Before LLMs we had a pretty good idea of security boundaries in software. Applications didn’t trust user input. Operating systems didn’t trust applications. Services and processes didn’t trust each other. There were always tokens, scopes, delegated grants.

Suddenly every AI company’s security model seems to be to say “pretty please” to a non-deterministic machine and hope for the best. And if there is a security failure instead of accepting blame they go “well we can’t help it, our model is too intelligent”.


Replies

orbital-decaytoday at 8:11 PM

Suddenly determinism has other meanings than "same input leads to the same output". I'm still confused by this and not sure how it happened so easily, but it seems to be accepted by everyone now.

mannanjtoday at 5:12 PM

Before LLMs we didnt have much accountability from leadership, that was eroding over time. After LLMs we still dont.

show 1 reply