Elektrine lite

← Feed

@flyingpenguin@infosec.exchange

Post #3895052

2026-07-17 20:54 UTC

@DavidJBianco@infosec.exchange Rules? That's like calling instance tier limits the "rules". The attacker license is higher, they aren't playing by the "rules"? No, sorry, those aren't actually rules. They are just vendor configurations like how many tokens you get. Self-defense allows proportionality, never parity. Parity with the attacker is called vigilantism. The guardrail as a vendor setting was exited by changing products, as HF did mid-incident. That makes it nothing more than a service tier. Law binds both sides. Nobody here ignored a rule, because there was never a rule in play. There was a configuration, and HF changed it.

Replies (1)

  • @flyingpenguin@infosec.exchange I'm sorry, but I must disagree on two counts. First, guardrails aren't a service tier. If you're using the model, you abide by the guardrails and you really don't have a choice except to change models or, more likely, service providers. Which is a big part of the issue, because this has costs and risks, and isn't the sort of thing you want to have to worry about in the middle of an active security incident. The other point I have to disagree with you on is your characterization of capability parity as "vigilantism". It's hard to know where to begin, but I'll start with this: parity may or may not be achievable, if it *were* possible, it'd be great. But the idea of vigilantism (i.e., infosec Batman) doesn't enter into any conversation where the victim is solely defending themselves and not going out on the Internet looking for trouble. So yes, when one side is subject to limiting guardrails and the other isn't, there is an issue. Not that the guardrails themselves are bad, but HF clearly hadn't anticipated running into them and was forced to work around them at a time when they most needed their processes to be smooth and well-oiled.

    Open ##3896088