@flyingpenguin@infosec.exchange
Post #3895052
2026-07-17 20:54 UTC
Replies (1)
-
@DavidJBianco@infosec.exchange 2026-07-17 21:43
@flyingpenguin@infosec.exchange I'm sorry, but I must disagree on two counts. First, guardrails aren't a service tier. If you're using the model, you abide by the guardrails and you really don't have a choice except to change models or, more likely, service providers. Which is a big part of the issue, because this has costs and risks, and isn't the sort of thing you want to have to worry about in the middle of an active security incident. The other point I have to disagree with you on is your characterization of capability parity as "vigilantism". It's hard to know where to begin, but I'll start with this: parity may or may not be achievable, if it *were* possible, it'd be great. But the idea of vigilantism (i.e., infosec Batman) doesn't enter into any conversation where the victim is solely defending themselves and not going out on the Internet looking for trouble. So yes, when one side is subject to limiting guardrails and the other isn't, there is an issue. Not that the guardrails themselves are bad, but HF clearly hadn't anticipated running into them and was forced to work around them at a time when they most needed their processes to be smooth and well-oiled.