Tag Archives: Katie Moussouris

Rerun anyone?

As I wrote an article propping questions there. I see earlier today, the BBC is giving us ‘Warning shot or publicity stunt – how worried should we be about the OpenAI hack?’ (at https://www.bbc.com/news/articles/cd9w22n9e4go) as such, I had some initial questions in my article: ‘Is it real or is it media?’ (at https://lawlordtobe.com/2026/07/24/is-it-real-or-is-it-media/) where I posted the idea ““The ChatGPT-maker said its agent – an AI system which can operate alone after human instruction – was being tested in a controlled environment but, after finding weaknesses, was able to escape the test limits.” Which is fine, but that is still programmer controlled. So as I see it “after finding weaknesses, was able to escape the test limits” it didn’t escape it merely found a weakness as its ML systems were taught to find out and went elsewhere. It reminded my of the 90s hacking setting where towards ‘password’ a clever hacker gave “1=1” invoking the ‘True’ setting. Then we get “OpenAI said the incident was “unprecedented”, and it was conducting an investigation alongside Hugging Face, whose boss Clement Delangue said in a post on X it was “mind-blowing that all of this happened autonomously”.”” And now we see “Hugging Face said the hack was different from anything it had handled before because it was done at superhuman speed by an AI with little or no human guidance.” It is the “little” addition to the sentence that is validating my setting of “that is still programmer controlled”, because as I see it, “little guidance” might merely be human ‘adjusting’. And when we see “Hugging Face researchers guessed the mysterious attackers had used one of the big AI models but they had no idea who or where the criminals were.” So, the issues is even bigger, it could have been Organized Crime setting the parameters of a sandbox, I know it sounds outlandish, but there is either a massive shortage in structure and security of DML (Deeper Machine Learning) settings (so it could either be ML or DL) but the setting that this is out there whilst there is no oversight is something that most of the media is painting over with innuendo and whether this is given by some is not in question, also irrelevant. And we see this when we get to “The Scooby-Doo-style reveal was made even more bizarre – and worrying – because OpenAI said its bot did the whole thing on its own, without permission. The firm said it all went down during a test of its tech’s hacking skills.

Two new versions of ChatGPT, designed to be master hackers, broke out of a supposedly secure test environment and gained access to the internet.” We see “broke out of a supposedly secure test environment” implies that it was not secure and the testing facility (the sandbox) is lacking security and oversight. And the statement “OpenAI said its bot did the whole thing on its own” implies that the bot was not monitored or ‘left alone in limbo’ but we all know that any computer is  never idle, it is always doing something and whilst it depends on human interactions it is fine. With autonomous systems it is a different matter and OpenAI should have known that. They are supposed whole lot better than I would ever be and I reckon that the larger issue is what did OpenAI know ad what are they hiding, because as I see it, they are hiding something. I am not sure what and it might be innocent in most cases but as I see it, hiding something is fear for some illumination. That has for themes nearly always been the case.

Then the BBC hits a note that I was playing all along a for the most I hinted to that in the previous article (listed above) but the BBC is giving us “Was it truly a stark warning about the future of AI? Or was it a publicity stunt by OpenAI to show off how powerful their models are? It’s the kind of scare marketing AI companies have been accused of for years and, since the much discussed launch of Anthropic’s Mythos model, cyber-security prowess has been a focal point. One of the top comments on OpenAI boss Sam Altman’s X post about the incident summarises this skepticism: “If y’all can’t understand that this was written to purely brag about the model then I don’t know what to tell you.”” And the ‘statement’ “If y’all can’t understand that this was written to purely brag about the model then I don’t know what to tell you” summarizes it nicely. We also get “The OpenAI and Hugging Face incident is a real-world example of a broader issue we’ve been highlighting for months,” said Dor Sarig from Pillar Security. “Sandboxes alone are not a sufficient security boundary for agentic AI.” And I tend to agree with that. Any Agentic system requires different security requirements. Whether it is Fake AI, True AI or simple ML AI. An agentic system does not work according to ‘human’ settings. I tend to go back to the original chess computers from the 80s. They will try any movement that is possible until they get the right result whilst replaying every chess match that was programmed into its memory. And the chess computer is relatively simple. Hacking into a system has all kind of places to pass. I gave the window example in my previous article. But the setting of software is that they are set to libraries that give abilities to a program. You see, a program gets linked to <stdio.h>, <stdlib.h> and <string.h>, but merely these three open up options in I/O operations, copy operations that are not part of the program, but they are in that system and it can run by all of them in mere seconds, optionally finding alternative options. Even this is not AI, a programmer had to program it in and regardless whether an agentic system does it autonomously, it only does it because it was handed that training and these instructions, and the agentic system started to combine options and learnings and it learned (using my previous examples) that it can leave a location via a window, it does not require to use a door. Which makes me remember an MSDOS program that turned the speaker into a device. So giving it the instruction:

And then wait from a distance, whist I added this to the autoexec.bat of a friend and watch him go nuts why his PC is singing the tune of Monty Python. It wasn’t me, someone programmed the setting of a speaker to become a SPKR: drive. So when an agentic program gets creative it might take routes no programmer could anticipate, not even when he/she programmed it. Because the reality of the setting is that no sandbox suffices to any agentic program. As I see it, it requires a sandbox in a sandbox and when the agentic program gets out of the inner sandbox the arms of the outer sandbox go off and as I see it, because it was unmentioned, that setting seemingly does not exist.  So whilst I understand the position given by “Cyber security Professor Alan Woodward from Surrey University told reporters OpenAI had “egg on it’s face”, and Katie Moussouris from Luta Security went further, suggesting the AI industry is failing to control its dangerous inventions.” I kinda disagree and it comes from the plain setting that AI does not yet exist. And all this is the consequence of ‘experts’ covering each other by making claims that all this is AI, whilst it is mere ML/DL (I call it DML) and it comes from a programmer. And even as they are covering each other, and clapping each other on the back. They know that the wrong settings are in place, but they are in too deep and it will hinder whatever comes next. There is one upside, you see, the AI Kill Switch Act might be in place before True AI comes to town and that could be the one great good thing.

I get the doubt thrown my way and I get that a lot of people have no idea, even though they gave all their IP and data to ChatGPT. I never used it and until there is a real AI, I will never use it to grow ideas. So whilst IBM (decently recent) gave us “Key concerns include autonomous system risks, data privacy violations, algorithmic bias, widespread misinformation, and intellectual property challenges” which is something I gave several times in the past and it all comes from a programmer, and as soon as they get connected to some sort of organized criminal enterprise the fence is broken open and all that IP will go anywhere and everywhere. That is the larger setting and no one is examining the ML/DL libraries that these players are making and as such when these class actions are placed beyond the settlements that they can afford, the ‘sudden’ revelation comes out and that is the moment these programmers can’t remember anything. And whilst the setting comes to point that the dollar sign no longer validates the setting of “Tech companies argue that training AI on public data falls under legal “fair use,” while creators argue it is unauthorized commercial exploitation” we will get a whole new ballgame and whilst this all plays out, the tech companies are creating new libraries with these agentic knowledge basis making a secure sandbox even more difficult. Optionally it might even contain three sandboxes in a nested structure, but that is merely my view on the matter and I might be incorrect in that assessment. 

So whilst we are facing rerun after rerun and optionally faked settings of Google vs OpenAI, both against Anthropic and all against each other when xAI enters the fold. And all that time the are still figuring out both a Trinary system (I see that as an essential setting for True AI) and how that is voiced into data systems, because they will have ramifications. Which is why I see that Oracle and Snowflake have the largest chances in that respect. I am certain that this is a race that Microsoft is unable to get into and I have no idea where Google is there. I am decently certain that IBM figured this out before I did and optionally they have this ‘under control’ through what was LISP and is now optionally coming to systems in some point in the future. Because as I see it, the setting of a trinary driven system with what I tend to call an Epsilon processor would require a LISP driven setting where the optional inclusion and exclusion would run simultaneously and this requires some form of LISP setting (a personal speculation) and all this would come with IBM shallow circuits. And all this gives IBM the largest head start, even Google might not be able to compete and I reckon that IBM might have talked to someone like Oracle on these settings. I have no idea where IBM is in databases, because in the end any true AI system is depending on the data it has. The question becomes in the meantime, how to transform binary (fake) AI into trinity true AI. The setting will become the discussion among data experts in the next few years and it hold bearing to all this, because it also impacts on how sandboxes are designed and monitored. 

And it it important because as I see it, trinary data takes a fifth of the space whilst gaining 4 times the speed of processing. And that is the setting these data farms will have to content with. As such there is plenty of evolution coming, but in this the stages of security becomes essential and whilst you consider rate quote from Katie Moussouris from Luta Security giving us “the AI industry is failing to control its dangerous inventions” and we are nowhere near the setting of true AI and that is where sandboxes require a nasty upgrade and soon, because soon enough, the kill switch might all there is between our data and whomever has access to data farms. And with security failing like we see now, we might not have that much time left and that is where I saw the need for security, because there is every chance that some AI ‘dealers’ already know that their fortune is set towards who has the most data and there is a need that we need to keep our data safe, but others might not want to do anything about it. Naming names is highly speculative because we aren’t shown the real issues and these people don’t want the real issues to come out because when the game is up, these people are playing for all the marbles in the world and there can only be one winner. That is how I see it and I might be wrong, but at present I feel that I am more right than even I think I should be. 

Have a great day today, I am now a mere 80 minutes away from Sunday.

Leave a comment

Filed under Finance, IT, Law, Media, Science