back

by zorked·2d ago·view on hn ↗
There's a chance that the real reason why they want to ban Chinese models is that they are so good at fixing bugs and preventing exploits that intelligence agencies have been using for espionage and surveillance for a long time.
5 comments
Anyone who knows anything realises banning things is a) impossible and b) your enemies will use them anyway, you are just depriving your own side of the advantages.
It's pretty easy for the US to functionally ban chinese models. They only have to target US firms like inference providers or the biggest users, and pretty much the whole domestic market will fall into line. They don't actually care about the final few %.

Regardless of whether or not adversaries are using them, the US has by far the most compute available, and we've now hit the line where major providers are no longer releasing their best models. The public gets the "current" level of intelligence, while the US government gets to control access to the actual frontier of non-public AI. From their perspective, their enemies using GLM5.3 while they have GPT6 and Mythos6 or whatever is a fine trade.

I don't support a ban at all, nor the US's behavior, I'm just pointing out some facts that change the argument.

But the real bad guys will be this final few %, which defeats the purpose. The 99% will be average user which will swing to cheapest AI or easiest to access.
Unfortunately, those in power, pretty much all over the world, lie/deceive themselves and believe they can.
In this case depriving US companies would be the point though, so that's not necessarily a disadvantage.
Anyone who knows anything about politics realises that until that actually happens, it works. And you should do things while they work, then stop doing them once they don't work.
> Anyone who knows anything realises banning things is a) impossible and

Maybe "It's really hard" is more accurate? We (humanity) for most part basically agreed to ban the usage of various chemical weapons in wartime, which seems to have drastically reduced the usage of it, even though it's still used by shit actors today from time to time. But it's hard to deny that usage didn't decrease after banning it, which makes "banning" maybe not completely useless for certain things.

"Banning" things that can be easily copied over cyberweb transportation pipes feels like an fool's errand though, regardless of what it is. It's just too easy to get around, compared to actual physical items I suppose.

Chemical weapons are not used not because some agreements - they just messy and only good for killing civilians. Also contaminate area and might also kill your own personnel.

If you look at all other banned weapons they are all used against Ukraine by Russia and nobody gives a damn.

> Chemical weapons are not used not because some agreements

We've literally destroyed countless of supplies of chemical weapons because of agreements about not using them, because we all agree they're absolutely horrible:

> The OPCW administers the terms of the CWC to 192 signatories, which represents 98% of the global population. As of June 2016, 66,368 of 72,525 metric tonnes, (92% of chemical weapon stockpiles), have been verified as destroyed.[40][41] The OPCW has conducted 6,327 inspections at 235 chemical weapon-related sites and 2,255 industrial sites. These inspections have affected the sovereign territory of 86 States Parties since April 1997. Worldwide, 4,732 industrial facilities are subject to inspection under provisions of the CWC.

CWC = Chemical Weapons Convention

> If you look at all other banned weapons they are all used against Ukraine by Russia and nobody gives a damn.

If only I had mentioned something about "shit actors using chemical weapons", basically predicting this exact response. But alas, here we are with zero defense about such a sharp point you made.

Of course even agreements are only agreements. What's valuable is what happens afterwards, but it'll take a while to get there in the context of war crimes by Russia and/or Ukraine, but it will be investigated once the conflict is over.

Yes chemical weapons has been destroyed and it's a good thing, but all other efficient and practical weapons weren't successfully banned.

Even EU countries that signed agreements against anti-infantry mines exiting them because how efficient they are at slowing down invasion.

This is different now. US labs and companies are not releasing frontier-level models openly (specially those capable of assisting cyber intelligence work), but commercializing them instead. Thus, any ban would not be symmetrical to begin with, and that is precisely what maintains the balance.
I don't think this really works because the Chinese government is going to be incentivised to tip off the US companies to deny the US government those exploits. I guess maybe that's what the open source patch program here is about, making sure banning the models doesn't work because they can just report the exploits without the company running the model themselves.
How does banning the models in the US prevent this?
US companies will have to use models that are restricted from fixing bugs.
Do you actually believe this?
The CIA ran one of the world's largest cryptography companies, for DECADES[1]. Are you truly so naive that you believe intelligence agencies that have more to gain from stifling the discovery of vulnerabilities they know of and use wouldn't do so?

[1] https://www.washingtonpost.com/graphics/2020/world/national-...

You should probably realise that the world has radically changed since then. This kind of thing works when you have a significant lead in the field that makes keeping vulnerabilities open sufficiently low risk for your own side. But if your adversaries have similar capabilities, then the calculation changes.
Has anything changed? Governments are hoarding undisclosed vulnerabilities, using them as they see fit instead of fixing. Every espionage, surveillance, or war campaign (see Russia v Ukraine, US/Israel v Iran etc) is followed by a ton of burned 0-days.

>This kind of thing works when you have a significant lead in the field

No? It works even if the adversary has the same capabilities. It only stops working when everything is fixed.

I believe it is unlikely. (Not because I do not believe NSA is hoarding 0-days, but for many other reasons.)

I'm curious: to any professional vulnerability researchers reading this, what do you think?

I used to call everything a conspiracy theory, but then Glenn Greenwald published "No Place to Hide: Edward Snowden, the NSA and the Surveillance State".

Now i know that reality is worse than the worst conspiracy theorist.

Why would you even believe the opposite? US spooks have been amassing vulnerabilities and relying on them for decades, they literally pioneered it in the 90's if not earlier. Everyone does it now but the US is the biggest of them all. Surely this devalues a lot of what they did. Moreover, the way the US government handled new capabilities, and OpenAI's training policy (they are in bed with the government) just scream "we want to create weapons for cyber-offence and deny them to everyone else"

It might not be the reason, but of course it's a contributing factor.

Intelligence agencies have been known for exploiting and planting software and hardware Buga for decades, going as far as weakening cryptographic standards or intercepting hardware in transit to implant a backdoor device.

Why do you _not_ believe it's a possibility?

Critical thinking says this is not only possible but likely too.
when in doubt, it's better to assume capitalism than anything else.