这篇文章讲述了作者团队在2023年参加Google的LLM bugSWAT活动时,发现并利用了Gemini系统中的漏洞。他们通过一个简单的提示“run hello world in python3”发现了Gemini的Python沙盒解释器中的漏洞,并成功提取了系统的源代码,获得了Google的Most Valuable Hacker(MVH)奖项。文章强调了AI系统安全性的重要性,指出快速部署AI系统可能会忽略基本的安全原则,导致新的漏洞出现。
HN 热度 630 points | 评论 128 comments | 作者:topsycatt | 1 day ago
微软宣布即将发布的 Windows 11 版本将要求用户在安装时连接到互联网并使用微软账户,这一变化引发了用户的不满和担忧。用户担心这可能增加微软对用户的控制力和数据收集,同时可能损害安全和隐私。一些技术人员认为用户可能会寻找绕过限制的方法,而微软的这一决定可能会促使用户转向其他操作系统,如 Linux。
8. 今天 Google 强制安装隐藏扩展导致我的 Chromebook 无法使用 (Today Google bricked my Chromebook by force-installing a hidden extension)
https://cloudisland.nz/@rmi/114219847307106213
Rob Isaac 在 Mastodon 上发布消息称,Google 强制安装了一个隐藏的扩展程序,用于训练机器视觉模型,且未经用户同意。该扩展程序持续读取屏幕像素,导致 Chromebook 电池寿命缩短、过热,甚至无法使用。用户尝试停止该进程,但扩展程序会立即重启,占用大量内存,导致设备变慢。用户认为这是 Google 的恶意行为,侵犯了隐私权。其他用户建议卸载 Chrome、安装 Linux 或禁用相关功能来解决问题。
HN 热度 198 points | 评论 80 comments | 作者:helloworld | 1 day ago
• 美国的法律已经不再被遵守,尤其是对企业的监管
• 企业可以通过收集和分析个人信息来控制和排除某些人
• 美国的司法系统已经失去了公正性,普通人很难与企业和政府抗争
• 个人信息的收集和使用需要更加透明和受到监管
• 企业的行为可能是出于对自身利益的保护,但也可能侵犯了个人权利
完整摘要请点击 “阅读原文” 👇👇👇
Hacker News 精彩评论及翻译
Blender releases their Oscar winning version tool
https://news.ycombinator.com/item?id=43490096
Aside from all the usual and well-deserved high praise I'm seeing, I feel like there's something more worth pointing out:
Blender has made 3D work much more "mainstream". I see many videos/pictures/tutorials with views in the millions(!), and much more overall interest in using the software. Not just the pretty visuals and talented people, but the whole program itself seems to be gaining traction with the more "normie" crowd.
That also made me realize something else: Blender is now the default for anything that's not extremely high-end/resource-intensive. If you ever hear about anyone doing any kind of 3D work, they're probably using Blender.
And this has creeped into the mainstream in a way only very established brands like Coca-Cola have. Nowadays, "Blender" might as well mean 3D photoshop/illustrator for most people.
EMIRELADERO
除了看到的众多实至名归的好评以外,我觉得还有一点值得提出来:
Blender 使得 3D 软件更加主流化。我看到很多视频、图片和教程的浏览量以百万计(!),并且整体对使用该软件的兴趣大大增加。不仅仅是漂亮的视觉效果和人才,同时整个程序本身似乎也获得了更广泛的“正常人”的关注。
这也让我意识到另一件事:Blender 现在已经成为非极高端/资源密集型 3D 工作的默认选择。如果你听到有人谈论任何类型的 3D 工作,他们很可能在使用 Blender。
这种现象已经以一种只有像可口可乐这样非常成熟的品牌才能做到的方式融入主流。今天,“Blender” 对于大多数人来说就像 3D 版的/photoshop/illustrator 一样。
Has the decline of knowledge work begun?
https://news.ycombinator.com/item?id=43488436
I think people need to get used to the idea that the West is just going backwards in capability. Go watch CGI in a movie theatre and it's worse than 20 years ago, go home to play video games and the new releases are all remasters of 20 year old games because no-one knows how to do anything any more. And these are industries which should be seeing the most progress, things are even worse in hard-tech at Boeing or whatever.
Whenever people see old systems still in production (say things that are over 30 years old) the assumption is that management refused to fund the replacement. But if you look at replacement projects so many of them are such dismal failures that's management's reluctance to engage in fixing stuff is understandable.
From the outside, decline always looks like a choice, because the exact form the decline takes was chosen. The issue is that all the choices are bad.
AI models miss disease in Black and female patient...
https://news.ycombinator.com/item?id=43496999
"AIs want the future to be like the past, and AIs make the future like the past. If the training data is full of human bias, then the predictions will also be full of human bias, and then the outcomes will be full of human bias, and when those outcomes are copraphagically fed back into the training data, you get new, highly concentrated human/machine bias.”
This also lets all of his co-investors in X, who were likely pissed that their shares tanked, exchange their shares at an inflated value (but one that still sees them losing 25% of their original investment) for shares in a trendy yet likely overvalued AI company that they consider to have more upside.
The other part of this is that if TSLA stock drops to $100-ish he'll be at risk of being margin called on the loans he took against his holdings to buy X. I wouldn't be surprised if this deal involves some X shares being sold for cash (that was raised from VCs) to pay down those loans, and/or the lenders agreeing to take xAI stock in lieu of cash.
This whole thing seems like a big pyramid scheme. I don't think this is the last time we've seen this type of move: he'll keep starting companies that are at the forefront of whatever the current hype cycle is, then leverage the extremely inflated valuations to benefit himself.
So he just sold himself a company he already owns for a valuation that he himself assigned to that company but that was less than what he paid for it, and he paid entirely using “money” that has a made up value and which he issues himself?
In similar news: my left hand acquired my right hand today in an all stock deal valuing the combined hands at $1T. Praising the announcement my arms noted on the deal: “With these two hands now together, there’s nothing our combined fist of might can’t do.” Competitors, my left and right feet, declined to comment on the merger but are said to be in their own separate talks about a deal.