Elektrine lite

← Feed

@DavidJBianco@infosec.exchange

Post #3896088

2026-07-17 21:43 UTC

@flyingpenguin@infosec.exchange I'm sorry, but I must disagree on two counts. First, guardrails aren't a service tier. If you're using the model, you abide by the guardrails and you really don't have a choice except to change models or, more likely, service providers. Which is a big part of the issue, because this has costs and risks, and isn't the sort of thing you want to have to worry about in the middle of an active security incident. The other point I have to disagree with you on is your characterization of capability parity as "vigilantism". It's hard to know where to begin, but I'll start with this: parity may or may not be achievable, if it *were* possible, it'd be great. But the idea of vigilantism (i.e., infosec Batman) doesn't enter into any conversation where the victim is solely defending themselves and not going out on the Internet looking for trouble. So yes, when one side is subject to limiting guardrails and the other isn't, there is an issue. Not that the guardrails themselves are bad, but HF clearly hadn't anticipated running into them and was forced to work around them at a time when they most needed their processes to be smooth and well-oiled.

Replies (1)

  • @DavidJBianco@infosec.exchange You are agreeing with me. "Your only choice is to change models or providers" describes a product, a market. Token limits are tiers. If you use pro and they use max, is it breaking a rule? HF's own lesson was to change procurement: vet the incident model before the incident. The vigilante is defined by self-issued license, and hunting on the open Internet is only one symptom of it. Proportionality covers every legitimate defensive need because it scales. Parity is the opposite and means no law, no data obligations, no accountability. Whatever it adds beyond proportionality is the definition of what no defense requires.

    Open ##3896087