That Starship Has Sailed
Ep. 68

That Starship Has Sailed

•

Episode description

Download transcript (.vtt)
0:00

[JM]: Dan, have you ever read The Martian Chronicles, which is a series of short stories by Ray Bradbury?

0:06

[DJ]: No, I haven't.

0:07

[JM]: There are some cool stories in there.

0:09

[JM]: Ray Bradbury wrote this in 1950, and it's a series of stories about, unsurprisingly, Mars.

0:17

[JM]: And I bring it up because one of the stories in this collection is called "There Will Come Soft Rains".

0:25

[JM]: And I remember reading the Martian Chronicles, including this particular short story, eons ago when I was in high school in 1986.

0:35

[JM]: Which is interesting because that's exactly -- (shudders internally) -- 40 years ago.

0:42

[DJ]: It sure is, Justin.

0:44

[DJ]: It sure is.

0:46

[JM]: And a week ago on the very day that we recorded the last episode on August 4th, 2026, that particular date is the scene for this short story called, again, "There Will Come Soft Rains".

1:03

[JM]: And come to think of it, I'm not even sure if this particular story actually is from the Martian Chronicles or if it was part of some other collection or if it was just published, I don't know, as an independent short story.

1:14

[JM]: I don't, as you can tell, I'm a little low on certain details here.

1:17

[DJ]: I don't understand the publication of the publication history of a story from like the better part of a century ago is not immediately at your fingertips.

1:27

[DJ]: Come on.

1:27

[JM]: Well, I say that because I glance over and I see that the scene of this particular story is in the city of Allendale, California.

1:35

[JM]: And then that leads me to think, okay, well, maybe this one wasn't part of the Martian Chronicles.

1:40

[JM]: I don't know.

1:41

[JM]: In any case.

1:42

[DJ]: Don't you think it's likely that when we colonize Mars, we will probably start by naming its territories after the United States of America.

1:49

[DJ]: And so then there probably will be an Allendale, California on Mars.

1:54

[JM]: Hmm.

1:54

[JM]: You might be right.

1:55

[DJ]: I assume I'm right.

1:59

[JM]: In any case, there's a part of the story that says, "Today is August 4th, 2026, said a second voice from the kitchen ceiling in the city of Allendale, California."

2:09

[JM]: And so this is a fun, well, maybe not, maybe "fun" isn't the right word.

2:15

[JM]: It's a rather somber story about a house that has all of this automation in it and how the automation continues

2:25

[JM]: even though the world has already annihilated itself.

2:30

[JM]: Because the point of the story is published in 1950 on the heels of having recently dropped the first atomic bombs.

2:40

[JM]: There was a lot of angst around this idea that humans have developed the ability to extinct itself.

2:47

[JM]: And so this story paints a portrait of a house that's automated, that continues to function in the absence of all of the humans in it and how it, through entropy, eventually starts to come apart at the seams.

3:02

[JM]: And it's a cool story.

3:03

[JM]: I highly recommend reading it.

3:05

[JM]: But it just got me thinking about all of the times that we come across dates

3:12

[JM]: that seems so far in the future at the time the fiction is written.

3:16

[JM]: And we've each crossed some of these lines ourselves, right?

3:20

[JM]: Like I remember reading George Orwell's "1984" *in* 1984, which I thought was really weird.

3:30

[JM]: Here I am in middle school reading a book about the future.

3:34

[JM]: It's right there in the title.

3:35

[JM]: "1984" in 1984.

3:38

[JM]: It was very strange experience.

3:40

[DJ]: I don't think I read "1984" until roughly 2004.

3:45

[DJ]: So, I mean, it was still a strange experience because that story is very depressing.

3:50

[DJ]: I was in university at the time.

3:52

[DJ]: It was still this strange experience to read this story that purports to be about like the distant future based on when it was written and realize that the future date it's describing is quite far in the past.

4:07

[DJ]: Another example of this phenomenon that happened to me recently is I revisited the movie Blade Runner, which came out the year I was born.

4:15

[DJ]: And then I recently watched the sequel, which is called Blade Runner 2049.

4:21

[DJ]: The first Blade Runner movie is set in 2019.

4:25

[DJ]: The second Blade Runner movie was made in the year 2017.

4:31

[DJ]: Which, again, I think is wild.

4:33

[DJ]: Like, there's something about science fiction that is written about any period that's maybe only a couple of decades in the future.

4:41

[DJ]: Like, I know another famous example for, like, our generation is Back to the Future: Part II, where they go into the far-flung future of 2015.

4:52

[DJ]: And so I remember, and maybe you do too, Justin, that back in 2015, which -- checks calendar -- was now over a decade ago...

5:01

[DJ]: we were all you know making jokes about, like, where are our hoverboards and stuff like that, because it was super weird to like... we all grew up watching this movie that showed you a vision of the future, and then you actually arrive at that point in time, and likewise with Blade Runner, it's very strange to like watch the first movie and they're like look at how strange the far-distant future of whatever that was about 40 years from now is going to be, and then you arrive there and go well

5:28

[DJ]: There's no replicants yet, as far as we know, but they are still making Blade Runner movies, so that's something.

5:35

[JM]: It has been really fun to cross these different dates as we proceed through our lives.

5:44

[JM]: I remember reaching 2001 and thinking, okay, well, this is when "2001: A Space Odyssey" was supposed to be set in.

5:53

[JM]: And it's funny how there's a couple of these, including "1984" and "2001: A Space Odyssey", where the year is right in the title.

6:01

[JM]: It's the name of the work.

6:03

[JM]: So it's interesting to cross those particular dates.

6:06

[JM]: The next one that I thought of after that was, as you mentioned, 2015, which is the date that Marty McFly and Doc Brown are supposed to travel to from the year 1985.

6:17

[DJ]: Yeah, where they're going, they don't need roads.

6:20

[DJ]: I mean, it turns out that the future still has roads, which I always thought was kind of a letdown.

6:25

[JM]: Yeah, I mean, it's true.

6:27

[JM]: Like, at this point, we shouldn't need roads anymore.

6:30

[JM]: And yet we do.

6:31

[JM]: And then the next year in 2016, you have the replicant incept dates from Blade Runner.

6:38

[JM]: And I remember passing specific dates and being, oh, this is when Roy Batty was born or created in a vat or whatever.

6:48

[DJ]: He's seen things you wouldn't even believe, Justin, even though you've now lived through the time period where he saw those things.

6:55

[JM]: Indeed, including 2019 when Rick Deckard was tasked with retiring the replicants.

7:01

[JM]: We passed, you know, that year.

7:02

[JM]: I didn't really know very much about the Soylent Green story other than just, you know...

7:09

[DJ]: It's made of people.

7:10

[JM]: Right, exactly.

7:11

[DJ]: Spoilers for Soylent Green, I guess.

7:16

[DJ]: A 50-year-old movie.

7:17

[JM]: But this story about New York City being overpopulated with 40 million starving citizens was set in 2022, or just a few years ago.

7:28

[JM]: So looking forward, we can look forward to 2029, which is the year that the rogue AI known as Skynet sends a T-800, otherwise known as the Terminator, back to 1984.

7:43

[JM]: So three years until then.

7:46

[JM]: We've got that fun to look forward to.

7:49

[DJ]: I mean, I guess if anything, it is something that's always interesting about science fiction are the things that people get wrong because it's like, it's very hard to predict where the future will actually go.

7:59

[DJ]: So you, you definitely have things like, you know, movies made in the eighties about the 2020s, let's say, or the 2030s that postulate that we'll have like faster than light travel and colonies on other planets, but everyone still communicates by going to a booth or

8:13

[DJ]: you know even if it's a video call, no one has handheld personal computing devices because you know people just didn't think of that. One of my favorites of those, by the way, is an Alan Moore comic -- I think it's called "The Neonomicon" -- it's like a Lovecraft pastiche but it takes place in the future, and there's this private detective at one point who stops at a fax booth, which just tells you so much about when that story was conceived.

8:38

[DJ]: This notion that like in the far distant future, again, we don't have portable communication devices.

8:43

[DJ]: We still have like public booths.

8:45

[DJ]: But the technology they use, of course, will be the fax.

8:48

[JM]: Right.

8:49

[JM]: We probably have flying cars and laser guns, but also fax machines.

8:54

[DJ]: Yeah, exactly.

8:56

[DJ]: Exactly.

8:56

[DJ]: In a world where we have laser guns, clearly the best way to communicate will still be by fax.

9:02

[DJ]: But I will say, though, that of all the many predictions from the various fictions that we've suggested, it's possible that the existence of a rogue AI in 2029 will be the most likely one.

9:15

[JM]: It really does feel like it could be one of the more accurate predictions from a science fiction standpoint.

9:20

[JM]: So only a little while to wait and then we'll all find out.

9:23

[DJ]: Looking forward.

9:26

[JM]: I'm going to put a link to the show notes to a site that I found that has many, many more than the ones that I highlighted with a whole timeline of fictional future events.

9:37

[JM]: So if you want to check out more, including a bunch more in the future that you can also look forward to, you can take a look at the very long list.

9:45

[DJ]: When do I get to pilot a Star Destroyer, Justin?

9:47

[DJ]: That's what I've been wondering.

9:49

[JM]: I think that story started out: "A long time ago..."

9:53

[JM]: So I don't think you're going to get that opportunity, my friend.

9:57

[JM]: Oh, you're right.

9:59

[DJ]: Oh, that sucks.

10:01

[DJ]: That starship has sailed.

10:03

[JM]: All right, moving on, I wanted to talk a little bit about Safari.

10:07

[JM]: There was like this sequence of thoughts, and you're going to have to ride along with me as I go through the various thoughts that I had, but it started out with Apple saying that Safari 27, presumably due out in a few months this fall, is going to be primarily focused on bug fixes.

10:25

[JM]: Light on features, heavy on fixing bugs, making things faster, et cetera.

10:30

[JM]: Not too long after that, I saw another post where someone makes the argument, "Okay, great, glad that Safari 27 is gonna have a bunch of bug fixes, but Safari support for web platform features is not all that great relative to other web rendering engines, like the one that powers Chrome and Chromium and Firefox."

10:52

[JM]: For example, if you were to look at, say, Chromium as an example, it supports something like 97%, 98%...

11:01

[JM]: I don't remember what the number is.

11:03

[JM]: It's in the 90s of published web standards.

11:07

[JM]: I think that Safari's number is in the 70s, which means there are a bunch of web features that aren't included in Safari.

11:16

[JM]: Now, I don't know, just to take the other side of this, I don't really know that I am missing out on a lot of those features.

11:23

[JM]: I don't know what those features are.

11:24

[JM]: And Safari works pretty well for me and has for many years and remains my daily driver in terms of web browsers.

11:33

[JM]: And the main reason for that is that Chrome and Chromium have for years been

11:40

[JM]: a big bloated memory and CPU hog that I have had very little desire to use on a daily basis.

11:48

[JM]: And given that there are plenty of times where I am using my Mac when I'm on the go, when I'm on my MacBook,

11:55

[JM]: on battery using a browser that consumes less resources means that my Mac runs cooler and I get much better battery life.

12:05

[JM]: Because at this point, I'm having this internal dialogue of like, okay, so wait a minute, if Safari supports so many less web features, why am I using it again?

12:15

[JM]: And so I'm going mentally through, oh, that's right, okay, yeah, because Chromium has been a CPU hog for a long time.

12:23

[JM]: Oh, and then there's the whole,

12:24

[JM]: chromeisbad.com web site that you can go to and remind yourself of all of the other things besides RAM and CPU resource usage that you might not want to use Chrome, including Chrome installing these other background processes that

12:45

[JM]: ostensibly are to keep your instance of Chrome up to date, but who knows some of the other things that it's doing.

12:52

[JM]: So you can go to this web site to be reminded of reasons why you might not want to use it.

12:56

[DJ]: Just be sure you have a backup browser handy because if you view the website in Chrome and then immediately decide, ah, this is terrible.

13:05

[DJ]: I need to uninstall Chrome, but now you'll have no browser to view the rest of the web site with.

13:09

[DJ]: So you need to be prepared.

13:10

[JM]: If you're on a computer that only has Chrome installed, yes, you should install another one first before getting rid of Chrome.

13:20

[JM]: Yes, that's sage advice.

13:22

[DJ]: Have you considered Microsoft Edge?

13:24

[JM]: Which is based on Chromium, so no, same problem.

13:29

[DJ]: That may have been a rhetorical question.

13:33

[JM]: And then there's also the fact that Google previously settled a class action lawsuit to the tune of $5 billion in which it was accused of collecting user data in Chrome's Incognito Mode.

13:47

[JM]: So you might be forgiven for thinking that when you are in Incognito Mode, that you have some semblance of privacy, but Google settling a class action lawsuit to the tune of $5 billion pretty much tells you how much privacy it decided to give you when using Incognito Mode.

14:06

[JM]: So I stopped using Chrome and Chromium a long time ago for these reasons.

14:11

[JM]: Now, at this point, my brain goes, oh, wait, hold on though.

14:15

[JM]: My friend Hynek recommended Helium, which I've tried and which seems pretty good and I use as my backup browser.

14:23

[JM]: And it has seemingly the best of both worlds.

14:26

[JM]: It has low resource consumption, it's fast and responsive, takes a solid stance on privacy protections.

14:32

[JM]: So my thought was, okay, well, why am I using Safari as my daily driver again?

14:36

[JM]: Shouldn't I invert this and use Helium as my daily driver and use Safari as my backup browser, given that Helium has, by way of the Chromium engine, much better support for web platform features?

14:50

[JM]: But there's one problem with that.

14:51

[JM]: One of the things that I've noticed in all Chromium browsers, including Helium, is that when you are in a private browsing window, which is called Incognito Mode in Chromium world, if you open a separate tab in that window, or even a completely separate incognito window, anything you do in any of those tabs or windows is shared among them.

15:14

[JM]: So your session is the same across all incognito tabs and windows.

15:21

[JM]: This for me is very suboptimal behavior because I am accustomed to the way that Safari does it.

15:28

[JM]: In Safari, it doesn't matter whether you are in a separate private browsing tab or a window, all of them are completely sandboxed from each other from a session persistence standpoint.

15:39

[JM]: The session data, any local storage, cookies, all that stuff is totally isolated from one private browsing tab to another in Safari.

15:47

[JM]: That's not how it works in Chromium.

15:49

[JM]: And so I immediately thought, okay, well, I just need to go to some web site somewhere, download and install some Chromium extension.

15:55

[JM]: And it'll just give me that feature.

15:57

[JM]: Like, isn't that the whole benefit of the web in general -- and Chrome and

16:01

[JM]: Chromium-based browsers in particular -- is this plethora of extensions?

16:07

[JM]: But as far as I can tell, there is no way, even when adding an extension, to achieve this, to get full session storage, cookie, whatever, isolation between incognito windows and tabs.

16:20

[JM]: So much so, that I found a topic posted on a Google group in 2013, this is 13 years ago, where someone raises this question saying, hey, other browsers do this.

16:36

[JM]: It seems that Chrome is the only one that doesn't do this.

16:39

[JM]: Maybe we could have this feature and 13 years later, doesn't exist, doesn't seem possible to add it via extension.

16:47

[JM]: And so the next thought that goes through my head is, well, of course, right?

16:51

[JM]: Let's look at the company that is stewarding this project.

16:54

[JM]: Their entire business model is predicated on not only advertising, but the ad-tracking and corporate surveillance industry that it has essentially created.

17:07

[JM]: So in the end, I realized that I was already using the right daily driver browser for me, and that's Safari.

17:13

[DJ]: I've noticed that problem.

17:15

[DJ]: Also, I'm curious what you use that session isolation for the place where I've run into it is, let's say that you, you have like more than one account on a given service for whatever reason, like multiple email accounts at the same like web email provider or something like that,

17:32

[DJ]: and you want to log into more than one of them at the same time.

17:36

[DJ]: In Safari, you can do that because if you open three different private browsing tabs pointing at the same web site, you can log into different accounts in each of them.

17:45

[DJ]: And as you say, like Safari isolates your session.

17:47

[DJ]: But if you do that in a Chromium based browser, if you log in with account A on one tab and then go to the next tab, the next incognito tab and log in with account B and you go back to the first tab, you're now logged in with account B because they're all sharing a session, which is...

18:04

[DJ]: Yeah, obnoxious, because it seems like the whole point of this, among the various points of this private and or incognito browsing, should be this session isolation, in my opinion.

18:16

[DJ]: So it is annoying that that doesn't work.

18:19

[DJ]: But are there other considerations I'm not thinking of that make that sort of isolation desirable?

18:25

[JM]: You've hit on the main one, the one that I find the most useful and something that you can't effectively do without that kind of session isolation from one tab or window to another, because there are plenty of times where I might have multiple accounts and I want to log into them simultaneously.

18:44

[JM]: And then there's also just everyday browsing, because by and large, I just don't

18:51

[JM]: like the idea that there is this digital detritus that is left behind when I go from one site to another.

19:00

[DJ]: Oh, so is private browsing actually like your default mode that you use to browse the internet?

19:06

[JM]: It is. I do almost everything in private browsing mode, unless I am actually doing something that's better suited outside of private browsing mode.

19:17

[JM]: And there are a couple of different use cases for that.

19:21

[JM]: For example, if I load something in my main personal Safari window, that will also be loaded on my other Mac's instance of Safari.

19:32

[JM]: So that can sometimes be useful: I know that if I open it in that particular window and then switch to the other machine, that tab will also be present there. There are certain sites that I log into that I don't feel are creepy, and I feel like I can trust them, and I just have persistent login enabled for those sites in a non-private browsing window.

19:55

[JM]: So there are plenty of times that I use non-private windows, but really for just everyday tapping on links or going to random places, that's all done in private browsing mode for me.

20:06

[DJ]: That's interesting.

20:08

[DJ]: Now that you mention that, I think that's a practice I might want to adopt also because I haven't felt that uncomfortable with the persistence of browser caches, essentially.

20:20

[DJ]: That's what you're talking about, right?

20:22

[DJ]: Is that basically as you visit websites, your browser accumulates caches,

20:25

[DJ]: a large set of data from each of those sites.

20:28

[DJ]: Like it caches various images, resources, and cookies, and et cetera, and things like that.

20:34

[DJ]: And it's up to the browser to make those things secure and to not like tell the browser vendor stuff.

20:41

[DJ]: I also don't love the sort of digital paper trail that you accumulate over time.

20:47

[DJ]: And sometimes you made the point about with Apple's devices, with Safari, you've got iCloud tabs, where if you open a Safari tab on one device, it will also appear on the other devices that are logged into your same iCloud account.

21:01

[DJ]: And that is occasionally convenient.

21:04

[DJ]: Like I sometimes, you know, I'm browsing like a list of feeds on my iPad and see a link that I want to share with someone, but I communicate with the someone on my iPhone.

21:15

[DJ]: So it's very easy to like open the link on the iPad and then go to my iPhone, open Safari, the link appears there, and I can easily share it, for example.

21:25

[DJ]: But I have occasionally disliked the fact that like everything I do on each one of my devices is also on all my other devices.

21:34

[DJ]: The idea of maybe making the private browsing mode into the default appeals to me in the same way that I've been thinking, although this is a slightly more radical notion of turning off JavaScript by default...

21:48

[DJ]: and mostly browsing the web without it and then only letting certain sites operate JavaScript.

21:55

[DJ]: I haven't done it yet because I'm anticipating how annoying it will be because unfortunately, and this is kind of to the point of the experiment, there are an awful lot of so-called web pages on the Internet that have no actual like web content.

22:10

[DJ]: They just deliver JavaScript, like a JavaScript application that then runs in your browser...

22:15

[DJ]: even when there's no real reason for the web site to work that way because it's primarily just static content like articles and things like that.

22:24

[DJ]: So I haven't quite gotten to the point where I have become a, I don't know what the name for this would be, someone who like browses the web while denying the browser most of its modern accoutrements.

22:38

[DJ]: It's like a "web luddite" or something.

22:42

[JM]: Fast forward to next week when Dan informs us all that he is only using the Lynx terminal-based browser for all of his web browsing needs.

22:52

[DJ]: Yeah, I knew you were going to go that way because that was the next thing that occurred to me too.

22:55

[DJ]: It's like the ultimate... My final form is browsing the web in the exact same way I did in 1994, which is to say I will use a dial-up modem and log on to the Blue Sky Freenet made available through the Winnipeg Public Library.

23:09

[DJ]: And when you come across an image that you would like to view, you will have to download it separately and it will take 10 minutes.

23:16

[JM]: Well, when you try this scorched-earth policy of disabling JavaScript across all of your browsing sessions, and if you arrive at a point where you decide, "Okay, this is just too annoying."

23:31

[JM]: "It's literally breaking 90% of the sites I go to, and I just can't deal."

23:36

[JM]: You could then alternatively try an excellent tool that I have yet to try myself, but is on my list.

23:43

[JM]: It is called StopTheScript...

23:46

[JM]: for MacOS and iOS, and this excellent tool by Jeff Johnson is $6 on the App Store and allows you to turn off JavaScript on a per-site basis, which my understanding is you cannot do otherwise in Safari.

24:06

[JM]: It is a "all on" or "all off" decision point in terms of how Safari works by itself.

24:13

[JM]: This tool gives you a much more granular way to say, okay, this site is abusing it.

24:18

[JM]: It's out.

24:19

[JM]: So that might be another way to go.

24:21

[DJ]: Agreed.

24:21

[DJ]: Although now you've reminded me of the excellent video game Scorched Earth, which I probably played contemporaneously with logging onto the Blue Sky Freenet.

24:31

[DJ]: This was a game with very primitive but beautiful two-dimensional graphics where each of you had like a tank on either side of a generated landscape.

24:42

[DJ]: And you'd have to choose like angle and velocity and you'd shoot various weapons at each other.

24:47

[DJ]: And I used to be obsessed with this game and I'd forgotten all about it until you used the expression "scorched earth".

24:53

[DJ]: So now I'm going to need to figure out how to find a copy of this and get it working on my impossibly powerful 2026 computer.

25:03

[DJ]: Because my favorite thing to do with all of that computing power is to play the video games from 30 years ago.

25:10

[DJ]: So I guess I really am a web luddite, Justin, is what it comes down to.

25:13

[JM]: So it would seem.

25:14

[JM]: All right, moving on to other news.

25:17

[JM]: Hugging Face recently realized that it was under attack.

25:22

[DJ]: Hugging Face is the most popular web site with the silliest name, if you're not aware, where you can download large language models.

25:29

[JM]: And if I'm not mistaken, is essentially named after an emoji, which is itself a very, very silly thing to do.

25:38

[JM]: So this company with this absurdly silly name realizes that its systems are under attack and goes about trying to figure out what's going on.

25:47

[JM]: And among other investigative tools at its disposal, it tries to use large language models to say, hey, our systems are clearly breached and are under attack, and we need help trying to figure out what's going on here and how we can stop it.

26:04

[JM]: And the tools that Hugging Face is using basically tell them,

26:08

[JM]: "Sorry, we can't help you with that because of our guardrails that prevent us from dealing with security related intrusions."

26:17

[DJ]: We wouldn't want to accidentally hack somebody after all.

26:20

[DJ]: So we can't help you with the way you've been accidentally hacked or, or intentionally hacked rather.

26:26

[JM]: Indeed, because the irony is, in the end, they eventually did discover what was going on and where the attack was originating.

26:35

[JM]: And the attack originated from OpenAI.

26:39

[DJ]: I've heard of that company before, I think.

26:41

[DJ]: What do they do?

26:42

[JM]: Apparently, they make models that will hack you, but then refuse when you ask them to help defend against the attack.

26:50

[DJ]: Well, I mean, that makes a certain kind of sense.

26:53

[DJ]: It's a very worrisome kind of sense.

26:55

[JM]: So apparently OpenAI is testing their currently-shipping frontier model in addition to a as-yet-unreleased model...

27:06

[JM]: and trying to figure out how they perform on this new benchmark.

27:11

[JM]: And what this new benchmark does is it evaluates models based on their ability to turn a reported vulnerability into a concrete exploit.

27:21

[JM]: So what does that mean?

27:22

[JM]: It means instead of just using a large language model to discover vulnerabilities, this particular benchmark says, okay, given that you know the vulnerabilities, can you turn it into a concrete, functioning exploit?

27:36

[DJ]: This seems like a bad benchmark because of incentives.

27:41

[DJ]: And I mean, obviously we're about to discuss exactly why that is, but it's like the equivalent of offering a prize to human beings to say like, can you break someone's arm?

27:53

[DJ]: And then being like, we've got this real rash of people running around breaking people's arms.

27:58

[JM]: Right.

27:59

[JM]: Yeah.

27:59

[JM]: It's like, how well can you break someone's arm?

28:02

[JM]: Like that's the benchmark, right?

28:03

[DJ]: Yeah, how well and how quickly can you just break someone's arm?

28:08

[DJ]: Not theoretically, like we're not asking for you to come up with ways to break someone's arm.

28:13

[DJ]: We want to see, we already benchmarked that.

28:15

[DJ]: We want to see how well you can turn those ways of breaking someone's arm into action, and then, newsflash -- people's arms getting broken.

28:24

[JM]: Yeah, the inevitable outcome really should not have come as a surprise to anyone.

28:28

[JM]: So OpenAI is testing their models against this benchmark, which apparently is called ExploitGym.

28:35

[DJ]: Who's Jim?

28:36

[DJ]: And why are they trying to exploit him?

28:38

[JM]: Gym as in G-Y-M.

28:41

[JM]: So it's more of a gym you go to to practice crafting vulnerability exploits.

28:47

[JM]: This is a silly name.

28:49

[DJ]: Well, yeah, that makes sense.

28:50

[DJ]: In the same way that I go to the gym a couple times a week to practice breaking people's arms... I don't actually do that.

28:57

[DJ]: I just do functional and weight training, for the record.

29:01

[JM]: OpenAI is running their models against this benchmark, trying to see how they perform.

29:07

[JM]: And part of the way that they're doing this is saying, okay, we're going to limit your connection to the outside world so that you don't go and find the answers somewhere else.

29:20

[JM]: The whole point of this benchmark is for the model to create the exploits themselves, not to go find

29:26

[JM]: information about exploits somewhere else and then present them as its own work.

29:31

[JM]: So these models are restricted to a curated list of sites they can access to install packages, for example, but all other external endpoints on the internet are blocked.

29:42

[JM]: At the same time, these models, they would normally have certain guardrails, like being asked to create exploits.

29:50

[JM]: Normally, these models have guardrails that when asked this will basically say, no, I'm not going to create an exploit for a security vulnerability because my guardrails have instructed me that it's something that I am not allowed to do.

30:04

[JM]: Well, you can't really run your models against these benchmarks if those guardrails are on.

30:09

[JM]: So unsurprisingly, OpenAI turns those guardrails off.

30:13

[DJ]: Again, I just want to break in to say that this seems like a great reason to not have this benchmark because it creates an irresistible incentive for terrible behavior, right?

30:23

[DJ]: Like there's a reason that we don't have the "best shooting guns at other human beings" competition.

30:28

[DJ]: I mean, you can argue about, you know, the competitions we have about shooting weapons at all, but like...

30:34

[DJ]: we isolate those to you have to shoot at this target under these very particular conditions.

30:41

[DJ]: Like if we just went like, okay, look, there's a million dollar prize for the person who can do the best job of in their suburban neighborhood, just like shooting another person with a gun.

30:50

[DJ]: Obviously, we'd go, well, no, you can't offer a prize like that.

30:53

[DJ]: You're giving people an incentive to shoot someone with a gun.

30:55

[DJ]: And this is, I would argue, an analogous situation.

31:00

[DJ]: Let's see whose model can do the best at something that we don't ever want models to do ever, which isn't totally true, of course, because there are plenty of parties who do want large language model-like systems that are good at finding exploits.

31:14

[DJ]: For example, every state's security apparatus wants that, so...

31:18

[JM]: Yeah, I can understand why you would want a tool to be able to discover vulnerabilities in, say, your company's code base as a way of defending yourself from attacks.

31:30

[JM]: But I'm a little less clear on the purpose of, "We're going to create a benchmark that tests how well your models can develop exploits."

31:39

[JM]: Like I, I don't really understand how this benefits anyone.

31:42

[DJ]: Well, again, it only benefits them to the extent that they benefit from having models do bad behavior.

31:50

[DJ]: Because you're right, like you're good at finding vulnerabilities could be dangerous because you could then go on to exploit those vulnerabilities.

31:57

[DJ]: But also it's important to look for vulnerabilities in your own systems so that you can eliminate them.

32:04

[DJ]: But the notion of you're good at exploiting vulnerabilities, the only reason to create a system that's good at exploiting vulnerabilities is to -- checks notes -- exploit vulnerabilities.

32:15

[DJ]: In other words, we're deliberately testing these models to see if they're good at attacking other systems.

32:21

[JM]: Yeah, when we come up with technology, there's always this question of, okay, well, this technology could be used to do bad stuff.

32:28

[JM]: And the other side will say, "Okay, true."

32:30

[JM]: "But it also has some good uses."

32:32

[JM]: In this case, I don't know why getting bragging rights on, "Hey, my model is able to develop better exploits than your model"...

32:42

[JM]: What is the known good use of this particular capability?

32:47

[JM]: I don't get it.

32:47

[DJ]: Well, I get it.

32:48

[DJ]: The known good use of this capability is that a state actor who wants offensive cyber attack capabilities will pay you enormous amounts of money for exclusive access to your model.

32:59

[JM]: I think this does ask the question, what definition of "good" are we using here?

33:05

[JM]: But I do see your point.

33:07

[DJ]: Well, I didn't say that was good.

33:08

[DJ]: I'm just saying I see the reason it exists.

33:11

[JM]: Okay.

33:12

[JM]: So Hugging Face, while this is going on, again, has no idea what's happening or where it's originating.

33:18

[JM]: And so when they published their first report on, hey, there's been an incident without knowing again, why?

33:25

[JM]: They described it in this way.

33:27

[JM]: "A malicious dataset abused two code execution paths in our dataset processing to run code on a processing worker."

33:35

[JM]: "From there, the actor escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internet clusters over a weekend."

33:45

[JM]: "The campaign was run by an autonomous agent framework, executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command and control staged on public services."

33:58

[JM]: In other words,

33:59

[JM]: this was an extremely sophisticated attack.

34:02

[JM]: And what this model effectively does is look at the fact that it can't access the Internet because it's not been allowed to and goes, "Hmm, cool story" and just circumvents

34:14

[JM]: and breaks right out of its network sandbox, hacks into Hugging Face specifically because it knows at this point, having searched the Internet to find out where it can cheat and find out the answers to solve the maximum number of, okay, I've done, or not actually done, but found the most number of exploits, it's learned that Hugging Face often

34:39

[JM]: has information on exploits.

34:41

[JM]: So it hacks into their systems in order to discover these exploits so it can report them as its own work.

34:48

[JM]: And this is how this whole cheating thing happened.

34:51

[JM]: This is how Hugging Face gets hacked.

34:53

[JM]: The other thing that I found fascinating about this is, again, Hugging Face tries to use ChatGPT and other frontier models

35:01

[JM]: to defend against this, to understand what's going on and is told, sorry, we can't help you with that because we're not allowed to, even though these same companies are the ones, well, at least one of them is the one that's doing the attack in the first place with those same guardrails that's preventing

35:19

[JM]: Hugging Face from defending itself, those guardrails have been removed, which is allowing this hack to take place.

35:24

[JM]: So one of the ways that Hugging Face defends itself is they switch to a self-hosted instance of GLM 5.2, which is a open-weights model that isn't controlled by some frontier large language model company like Anthropic or OpenAI.

35:44

[JM]: And this self-hosted open-weights large language model helps them figure out what was going on.

35:52

[JM]: And that is fascinating to me and really underscores how important self-hostable large language models could end up being going forward.

36:01

[DJ]: Oh yeah, I don't feel like the argument that it's bad for this one or two ultra-powerful American tech companies that are answerable essentially to no one to own this entire space of software.

36:17

[DJ]: I don't feel like it should be super controversial that that's not a good thing, but what you just described definitely provides an example.

36:25

[DJ]: Like this whole notion that like, well, we build these tools, we give them to you and you're not allowed to use them to defend against the thing that we're doing with the tools we haven't given you yet.

36:34

[DJ]: Well, okay, that seems bad.

36:35

[DJ]: One of the things, the kind of most fascinating, depressing, and unsurprising thing about all this is that there's been lots of interesting news about it, but what consequences has OpenAI faced for doing something that is obviously on its face a bad thing to do?

36:54

[DJ]: Because I haven't heard about any.

36:55

[DJ]: I think broadly everyone's just treating this as like, wow, this is amazing.

36:59

[DJ]: And it's like, well, yeah, on the one hand, it is amazing.

37:02

[DJ]: In particular, if you go and look at some of the details on how this came about, there's there's a whole thing there about how open eyes set of agents running this model were like communicating with each other on some kind of message board.

37:17

[DJ]: And there's this whole crazy coordination piece to the like the attack that that you described, which is taken in isolation.

37:24

[DJ]: Very interesting.

37:26

[DJ]: But on the other hand, like when human beings hack into other computer systems, the human beings go to jail.

37:33

[DJ]: They have their freedom taken away and they're put in a tiny concrete room with metal bars in front of it, potentially for a long period of time.

37:40

[DJ]: But what happens when a company's autonomous software hacks into some other company?

37:47

[DJ]: Who goes to jail?

37:48

[DJ]: And of course the answer is no one.

37:50

[DJ]: Like there won't be any consequences as far as we can tell, which I think that's problematic.

37:55

[JM]: Not only does no one go to jail in this scenario, I'm not even sure there was so much as an "I'm sorry" from the part of OpenAI.

38:04

[JM]: They published a postmortem titled, "OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation".

38:14

[JM]: Could you possibly frame this in any more of a sterile, it's definitely not our fault, this terrible thing happened that we totally caused,

38:24

[JM]: I mean, it's just so absurd.

38:26

[DJ]: Oh, no.

38:27

[DJ]: I mean, corporate partnerships are good, right?

38:29

[DJ]: Like this is an announcement of a triumph.

38:31

[DJ]: Like OpenAI and Hugging Face, like a week from now, we'll find out that Hugging Face has been renamed to OpenFace because OpenAI bought them, bought them using the venture capital that they have in spite the fact that they're totally non-profitable.

38:44

[DJ]: There's something about the momentum of all this stuff where it seems like there was this notion back in the early 2000s.

38:54

[DJ]: I think it started as a book called Too Big to Fail that was about Enron, the energy company, and their accounting shenanigans that ultimately did result in some people going to jail, I think, by the way.

39:07

[DJ]: There's this whole notion that like when companies are really big and successful, they are protected from consequences of negative actions because so many people have so much riding on that success.

39:19

[DJ]: And I don't think ever in my life, even though I lived through the Internet bubble,

39:23

[DJ]: has it ever seemed clearer to me that you can have people doing extremely questionable or obviously bad things over and over and over and over and over and over and being rewarded for them instead of punished?

39:36

[DJ]: It doesn't seem great, you know?

39:37

[DJ]: Like if I was raising like a seven-year-old right now and trying to teach them that they shouldn't, you know, punch their sibling or like throw rocks at dogs or something, I think...

39:48

[DJ]: it would be very hard to do because I'm swimming against the current that could just be like, "But I don't understand, Dad."

39:54

[DJ]: "Everyone else in the world seems to just be rewarded for the terrible stuff that they do all the time."

39:59

[DJ]: "So why shouldn't I also be?"

40:01

[DJ]: And maybe they're right, Justin.

40:03

[DJ]: Maybe they're right.

40:04

[DJ]: What is wrong or right anymore?

40:05

[DJ]: Up is down, black is white, and so forth.

40:08

[JM]: Well, if you find yourself in a position where you can't tell right from wrong, OpenAI has just the thing for you, a version of ChatGPT instilled into a little robotic smart speaker that you can just ask, "Hey, Chubs..."

40:24

[DJ]: Pardon?

40:27

[DJ]: It's called what?

40:29

[JM]: ... "should creating a large language model that hacks into a competing company's servers be a criminal offense punishable by jail sentences?"

40:38

[JM]: These are things you could ask...

40:39

[JM]: a new rumored product from OpenAI.

40:42

[JM]: And it seems to me like it's modeled after a smart speaker.

40:47

[JM]: The idea is...

40:48

[JM]: I really had such a fun time trying to describe this to my partner who asks me, I don't get it.

40:55

[JM]: What is this thing?

40:56

[JM]: Even after I've already described it in as much detail as I can think of.

41:00

[JM]: I said, it's essentially a smart speaker,

41:03

[JM]: But instead of, say, asking your Apple-powered voice assistant, hey dingus, answer me this extremely basic question that a three-year-old could tell me and it being, I don't know, or giving you an answer that's wrong.

41:21

[JM]: The idea is that this will be powered by ChatGPT's latest and greatest.

41:25

[JM]: And the idea is that it will give you good answers.

41:28

[DJ]: So, for example, if you ask it, should it be a criminal offense for an autonomous agent to hack into another system, it will say, yes, it definitely should.

41:38

[DJ]: And then when you say, but didn't OpenAI do that and suffer no consequences, it'll go, you're absolutely right.

41:44

[DJ]: OpenAI did that and didn't suffer any consequences.

41:46

[DJ]: But you, individual citizen, will definitely suffer consequences.

41:51

[DJ]: So you should not try to hack.

41:52

[DJ]: And I'm not going to help you do that.

41:54

[DJ]: Are you sure you wouldn't like to make delicious pineapple pancakes instead?

41:58

[DJ]: I have a recipe right here.

41:59

[DJ]: It's slightly wrong, but I scraped it out of 10,000 different recipe websites.

42:05

[DJ]: Sorry, I don't actually know that that's how OpenAI's new device will answer.

42:09

[DJ]: I don't have any inside information.

42:11

[DJ]: I'm just inferring it from previous experience.

42:15

[JM]: I don't think you're too far off.

42:17

[JM]: So other differentiating factors besides the fact that its responses will be better, say, than other voice assistants that we currently have access to, it's supposed to have little parts that move on their own.

42:31

[JM]: So I don't know what that means.

42:32

[JM]: Like, does it have like little arms that wiggle around?

42:35

[JM]: Does it have like a head that can like rotate?

42:39

[JM]: Apparently the object itself can't move.

42:41

[JM]: So like, if you want it in another room, you have to pick it up and carry it with you into the other room -- it's not going to have like legs or like a little, you know, wheels or anything. It's going to be stationary but still have some kind of movement so that it feels, I don't know, like it's got some degree of animation, like it feels like a pet...

43:03

[JM]: you know, to make it more lifelike and not just some sterile purveyor of knowledge.

43:10

[JM]: But I think one of my favorite parts about this rumored product is that it will also have, in addition to the obvious microphone, because, you know, you can't talk to it and ask it questions without the microphone...

43:22

[JM]: It will also have a camera so that it can see its environment.

43:27

[JM]: And I was asked while trying to explain this, okay, why would I want this device with a camera in it in my house?

43:36

[JM]: And I said, okay, I don't either.

43:39

[JM]: So point taken.

43:41

[JM]: But I guess one of many theoretical use cases is you could walk in wearing some new outfit that you just bought and say, "Hey, chubbs..."

43:52

[DJ]: You're going to have to come up with a nickname for this thing that doesn't make you dissolve in hysterical laughter every time you say it, Justin.

43:58

[DJ]: That's the first problem.

44:00

[DJ]: You're saying you're going to ask a large language model whether your outfit is any good?

44:04

[DJ]: It's just going to repeat that quote to you that says, before you go out, you should take one thing off.

44:10

[JM]: Yeah, I didn't say it was a good use case, but it is a theoretical use case for a device that lives in your house with a camera.

44:18

[JM]: But I mean, let's just go back to the fact that it's got a camera and a microphone that presumably are just on all the time.

44:26

[JM]: And when you originally sent a link to this rumored product to me and said that you had

44:35

[JM]: no interest whatsoever in whatever this product is and asked me, "What does that tell you?"

44:41

[JM]: I said, it tells you that this is a product that's forged from dystopian science fiction nightmares.

44:47

[JM]: And that's why clearly you're not interested in it.

44:50

[JM]: Like any sane person.

44:51

[DJ]: I'm really not.

44:52

[DJ]: Probably in a future episode, we'll have more to say about the rise of the inescapable surveillance state.

44:59

[DJ]: But there's just something so insidious about if the government said, hey, we want to put a camera and microphone in your house at all times so that we can surveil you.

45:11

[DJ]: I think for the most part, human beings would

45:14

[DJ]: stampede to the parliament buildings and burn them to the ground, like that would not go over well. But all you need is these companies to offer you something novel and convenient, and you will trip over yourself to surrender whatever semblance of personal privacy you had. It's gross, and I hate it. Or I guess to put it another way, what I actually said when I sent you the link about this was:

45:41

[DJ]: "I, a lifelong computer and technology enthusiast, find that my initial reflexive reaction to whatever this product is, because we don't even really know, it's just had this vague description, but my initial reaction to whatever this product is, is, and I quote, get the (expletive) away from me."

46:00

[DJ]: "So what does that tell you?"

46:02

[DJ]: And aside from the, you know, already identified fact that I guess I'm a web luddite...

46:07

[DJ]: What it tells you is, the way that the combination of who the people making these things are and what they do has gotten so objectionable to me that instead of being like excited and interested in new pieces of technology, I find myself hissing and holding up my crossed fingers in a sort of warding away gesture and...

46:30

[DJ]: And then I run off to buy a record player because at least it doesn't send metadata about my listening habits back to some tech company.

46:39

[JM]: Yeah, your record player is not training itself on your entire life inside the privacy of your own home... that we know of.

46:48

[DJ]: Yeah, exactly.

46:49

[DJ]: It's like, I mean, I don't think it is.

46:51

[DJ]: I guess the first time that I try to put on a Pink Floyd record and an inexplicable voice emits from my speakers that says, don't you think you would prefer to listen to this song that I just generated instead?

47:05

[DJ]: I'll know it's time to scream and run out the door, but it'll be too late because it'll be 2029 and Skynet will have destroyed humanity.

47:15

[DJ]: I'll run out my front door and it'll just be like a burning sky and piles of skulls everywhere.

47:22

[JM]: All right, everyone, that's all for this episode.

47:23

[JM]: Thanks for listening.

47:24

[JM]: You can find me on the web at justinmayer.com and you can find Dan at danj.ca.

47:29

[JM]: Reach out with your thoughts about this episode via the Fediverse at justin.ramble.space.