The word-guessing program guessed the right words and accessed websites it shouldn’t. How many people were charged and jailed because they fuzzed their way into an unsecured website? I can think of a few.
AI pen testing is one thing, but you need an agreement and scope for that. Responsible researchers stop and send a vulnerability report before accessing data. These AI bots just keep generating requests and sometimes get data back and then months later there’s owner is finished sifting the excessive activity and discovers there’s classified or sensitive or whatever data. That’s not how it works.
Doctorow says, and I agree, that it seems they’re in a world of delusion at the AI companies and they’ve lost context.
The word-guessing program guessed the right words and accessed websites it shouldn’t. How many people were charged and jailed because they fuzzed their way into an unsecured website? I can think of a few.
AI pen testing is one thing, but you need an agreement and scope for that. Responsible researchers stop and send a vulnerability report before accessing data. These AI bots just keep generating requests and sometimes get data back and then months later there’s owner is finished sifting the excessive activity and discovers there’s classified or sensitive or whatever data. That’s not how it works.
Doctorow says, and I agree, that it seems they’re in a world of delusion at the AI companies and they’ve lost context.