Post #3961458
2026-07-20 14:09 UTC
Replies (2)
-
@flyingpenguin@infosec.exchange 2026-07-20 14:14
@fj@mastodon.social yeah, although I read it more like they had been ordering delivery pizzas and then when explosive diarrhea hit they called the pizza place and said "help our toilets aren't working". i'd hang up the phone on them too. incident response is supposed to have incident response tools setup and tested, dry runs, etc. and closed stuff /could/ work in theory. but the idea of dumping internal sensitive data and pounding the easy button... that's worse than just the generic tool being a bad fit.
-
@aristot73@infosec.exchange 2026-07-20 14:49
@fj@mastodon.social see also the conclusion from @nielsprovos@ioc.exchange post https://www.provos.org/p/case-for-open-weight-models/ "Frontier models have a place. They are tools for leverage, evaluation, and exploring the edge of what is possible. The mistake is letting them become the invisible policy engine inside a production system, where their price, their values, their refusals, and their availability are set by someone else. Use them from outside the boundary. Keep the model you depend on auditable, forkable, and yours."