Skip to main content
CrankySec

Appeal to deez nutz

How are you, friends? It's been a minute, eh? As I've mentioned, we're not dead. In fact, I've been busy as hell doing things I know how to do for the benefit of the almighty shareholder. The funny think is that the "things I know how to do" are not that complicated: if you want to do those things, all you need to do is add some general knowledge and brainpower to the problem at hand, and the solutions start to emerge. Your brain needs the workout. And your brain is excellent at making connections between things, identifying patterns, and coming up with ways to handle information more efficiently. You just need to give a shit and have at least a superficial knowledge of things outside of your immediate surroundings.

Let me give you an example: you don't prioritize your patching based on the CVSS score. A lot of people do, but that's because they don't know any better. If you do know better, you know that a whole bunch of other factors influence your prioritization strategy. You take into account the controls you have in place already. You take into account the exploitability of the CVE. You take into account the vectors. You take into account the importance of the thing this CVE affects. In other words: you measure risk, and you need to measure the risk. NIST cannot do it for you. If you don't understand that, if you don't understand how the CVSS fits into the big picture, how to do threat modeling, how to do risk assessments, and how to measure the effectiveness of your controls, you're just a state machine that does "CVSS > 9 = Patch". A shell script can do that. In other words: to be good at what you do, you need expertise. And you gain expertise by looking at the whole picture, understanding what influences what, looking elsewhere, and making connections. One day you're watching a video or reading about something completely unrelated, and you go "Well, shit. I can totally apply this to my dayjob." It happens a lot.

What also happens a lot is people who don't know shit about shit saying stupid shit. That, by itself, is dangerous enough. It gets really bad when the people who don't know what they are talking about believe they do know what they're talking about, and other people who know even less believe them. It gets ultra bad when the reach of the dumbassery is enormous. It's probably my favorite logical fallacy.

Let's take, I don't know, Dario Amodei. He's the big boss at Anthropic, and he's been making the news again because "Ohmygod this thing I am making and have total control over is going to kill us all because of botnets or worms or exploits or something that can Hack The Planet! so please someone who has some kind of power and influence over this industry make them slow down!" This man is a physics major, and got his doctorate in biophysics. Impressive! What's your experience in actual, real world cybersecurity? None. Is Anthropic even employing cybersecurity people he can run his thoughts through? Doubtful. Will he say dumb shit like this and the press will eat it up and just press the "Post Now!" button without even thinking about it for 2 seconds to ponder "Is this guy full of shit and using his position as the leader of a very big corporation to spread his self-serving, yet stupid, views?" You know it.

Same with the other guy who quit Anthropic because of reasons. He, (after working for OpenAI and Anthropic, surely drawing a significant paycheck) is making the rounds and being interviewed by The WSJ, Wired, et al. and saying pretty much the same shit. The difference is that Amodei has an agenda. This dude? Who knows. Amodei is doing this because a) he doesn't know what he's talking about, b) people who listen to him don't know anything about it either, and c) saying "This thing is dangerous. No one better than US to handle it." is good for business because it tries to bring the decision making in-house, and no one wants pesky "rules and regulations" that are not business-friendly.

Whatever happened to those "Project Glassdoor" terrifying vulnerabilities, by the way?

And let me do some both-sides-ism be fair here and also point out that people predicting the demise of the whole AI ecosystem any minute now are, too, full of shit: if looking at balances and P/L numbers, and AAV, and things like that could predict the economic outcomes of companies, no one would lose money in the stock market. Just go to /r/wallstreetbets with your "tEcHnIcAl AnAlYsIs" and see what happens. Trying to predict some future events is difficult, and people should not try to do that.

And, hey... I say dumb shit all the time, and I vomit opinions on topics I know very little about. But I am me, and no one from the WSJ wants to interview me and ask what I think about this or that. In fact, every time I say something dumb, you can bet your ass I'm getting "Well, actually"'d by someone who may or may not know more than I do. But also, a little commonsense goes a long way.

"AI is going to hack us all to death just like it hacked Hugging Face!" doesn't take into account that human beings have agency, that literally billions of people across the globe have never even seen a computer and would be just fine even if Claude hacked everything, that everything the OpenAI agents that hacked Hugging Face could have been done by a human, and, crucially: Hugging Face didn't die. Quite the opposite. They're getting the bag from Nvidia. Thinking that humans will just "Oh, well. Nothing we can do about it. Better just roll over and die." is dumb and disrespectful at the same time. The real threat to mankind is people who go to Stanford, but for other reasons.

Just like you shouldn't take health advice from your drug dealer, don't take cybersecurity advice from people who don't know anything about cybersecurity.

Join our Discord, will ya? We're SO back.