I'm Phil, I do things, I know things.
It's good to make friends.
#emacs #foss #selfhosted #actuallyautistic #cptsd #cybersec #infosec #systemadministration
Bots /not/ welcome.
Bridges out of Fedi /not/ welcome.
Corporations/ businesses /not/ welcome.
-
There is no legal entity for terrorist organizations, but they're subject to every country's laws where their members are regardless.
-
See 1.
Man #Vanta is so bad...
Their Entra MFA enforcement check is horrible. It only checks if a conditional access policy exists, and if it has 'MFA' in the builtinControls. If it does, it's a pass.
But it doesn't check...
- if any users are excluded from the policy
- if any groups are excluded
- if the policy covers all users even after exclusions (e.g. if the exclusions are service accounts for any reason)
- if the geoblocking is functional
- if any of the excluded users are privileged
Vanta is a tool designed to mislead auditors, presenting as a third-party authority with their 'trust center' and all the flashy shiny dashboards.
Yet the core is rotten.
I haven't been this insulted since I found out that #vanta has a barely functional risk API (was trying to sync our risk register from our internal repo... long story).
Just... I lack words.
#infosec #cybersec #grc #privacy #compliance #fintech #informationsecurity #audit #soc2
@lproven@social.vivaldi.net @xs4me2@mastodon.social @reading_recluse@c.im So let me get this straight.
- You don't use the tools you're criticizing.
- You're relying on outdated and fundamentally flawed examples.
Transformers aren't everything; there's also embeddings, RAG, tools, pre- and post-processing of inputs/ outputs, all of which can and do affect the quality of the output.
I don't disagree with you entirely, to be clear. But I do find the absolutism a little much, when the core of your original argument (about these things being dangerous) hinges on handing off all responsibility and accountability for the result to the machine.
Something that we shouldn't be doing no matter what the machine is.
@lproven@social.vivaldi.net @xs4me2@mastodon.social @reading_recluse@c.im
I keep detailed journals about nearly everything I do day-to-day, and review them regularly to ensure I'm on the right track in life. I am self-aware enough to know what I do and don't know, thanks to this. My journal since August 2023 is 16k lines, without word-wrapping.
To address your questions:
-
Yes, and I don't scrape websites. In fact, none of the things I post online or in any personal communications are ever touched by an LLM. I take pride in my prose (for the most part, lol).
-
As I said elsewhere, I tested this recently and running an LLM (during the inference itself) takes as much power as running Kerbal Space Program. With Power Limiting, I can make it use even less. Third-party API providers are a separate matter, and not relevant to using LLMs per sé.
-
I don't train or build LLMs. Also not relevant to using LLMs, which was the original topic.
-
Already addressed - it's the human's part to ensure the work is up to standard. LLMs are tools, they're not thinking machines.
-
Great (/s), I can't do anything about it. In fact I'm in a position where if I wasn't using LLMs to maintain an insane pace of work (I'm filling 5+ roles atm), I'd be quickly replaced by an MSSP. I'm affected by this, but your implicit message is that you can afford not to use LLMs to keep your job/ health/ standard of life. I can't afford that. On the personal use aspect, sure, I could, and my quality of life would decrease accordingly considering the way my brain functions.
-
See 5.
-
You're propagating the belief by acting as if people believe this in the first place. Nobody in this thread does as far as I can see. Nobody's saying "my LLM is so smart!"
-
I disagree. LLMs aren't the ones causing losses. It's people misusing a tool that are causing losses. Just like it's people making harmful decisions based on appeasing stockholders.
LLMs (as in, the actual models) are fine. The problem is the people around the development of those LLMs.
I think we're overall on the same page, but we live in different 'tiers' of society.
You have the luxury of rejecting the tech without losing a needed crutch. Sadly, many aren't in the same position of privilege.
If I can have 50% of a personal assistant for a few cents a month in power bills, why should I give that up?
@lproven@social.vivaldi.net @xs4me2@mastodon.social @reading_recluse@c.im
- Paper from nearly 2 years ago. A lot has changed. Not to mention the 'test' the author (can't find their name, sorry) did is pretty dumb. It's much better to use an API, where you can control the full input pipeline to ensure the vendor isn't adding hidden instructions without your knowledge.
- I already addressed the point in my previous comment - it's on the user to verify that tools have correct output. Relying on an LLM to do the reading in one's stead is a recipe for disaster.
You haven't said anything about YOUR use-case, experience, or the tests you tried.
I'm genuinely curious, what do you imagine using an LLM is like?
The reason I ask is because a lot of the criticism and panicking (sometimes crossing into outright disrespect and bigotry) I see online comes from an assumption that using an LLM is predicated on turning off one's brain and taking the output at face value... something that we shouldn't be doing with any software anyway.
I guess put another way: I don't believe that the problems people attribute to LLMs are specific to LLMs. How many instances were there where management/ execs took Excel output as fact, when the formulas were set up wrong?
These statistical models are no different.
