Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Robert M

๐Ÿ‘ค Speaker
195 total appearances

Appearances Over Time

Podcast Appearances

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

This post is meant to be two things.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

1.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

A PSA about LessWrong's current security posture from a LessWrong admin.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

2.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

An attempt to establish common knowledge of the security situation it looks like the world, and, by extension, you will shortly be in.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

Claude Mythos was announced yesterday.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

That announcement came with a blog post from Anthropic's Frontier Red team, detailing the large number of zero days and other security vulnerabilities discovered by Mythos.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

This should not be a surprise if you were paying attention, LLMs, being trained on coding first was a big hint, the labs putting cybersecurity as a top-level item in their threat models and evals was another, and frankly this blog post maybe could have been written a couple months ago, either this or this might have been sufficient.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

But it seems quite overdetermined now.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

Heading Less wrong security posture

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

In the past, I have tried to communicate that Lesrong should not be treated as a platform with a hardened security posture.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

Lesrong is run by a small team.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

Our operational philosophy is similar to that of many early-stage startups.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

We treat some less wrong data as private in a social sense, but do not consider ourselves to be in the business of securely storing sensitive information.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

We make many choices and trade-offs in the direction that marginally favor speed over security, which many large organizations would make differently.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

I think this is reasonable and roughly endorse the kinds of trade-offs we're making.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

I think it is important for you to understand the above when making decisions about how to use LessWrong.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

Please do not store highly sensitive information in LessWrong drafts or send it to other users via LessWrong messages with the expectation that LessWrong will be robust to the maybe upcoming wave of scaled cyber attacks.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

LessWrong is not a high-value target.

LessWrong (Curated & Popular)
"Do not be surprised if LessWrong gets hacked" by RobertM

While LessWrong may end up in the affected blast radius simply due to its nature as an online platform, we do not store the kind of user data that cybercriminals in the business of conducting scaled cyberattacks are after.

โ† Previous Page 1 of 10 Next โ†’