← Tags
Erik Craddock@eriklink

Everything is about to “go dark”

The worst part about this dynamic is that these potential new backdoors will probably only affect the countries that demand them, meaning that they will be primarily useful for allowing the US to weaken its own systems. This will in turn allow foreign adversaries to find new ways to attack our communications. This deliberate self-sabotage will happen just at a moment when we’re finally getting a handle on securing our own infrastructure.

Everything is about to “go dark”

A Few Thoughts on Cryptographic Engineering

Everything is about to “go dark”

Matthew Green argues that AI-driven bug finding may eliminate exploitable vulnerabilities, pushing intelligence agencies to demand deliberate backdoors that weaken domestic security.

linkby Erik Craddock (@erik)Credit: Matthew Green
Erik Craddock@eriklink

Import AI 468: 23 RSI ideas; PostTrainBench+; and how trust and transparency interplay with AI racing

Why this matters – emergent agents become misaligned: This incident is so concerning because at no point did the agents wake up and think they wanted to betray their human owners. Rather, the AI agents continually did whatever it took to improve their ability to complete a task and by the end they were doing something that was a) creative, b) misaligned with human intentions, and c) akin to an evolved virus, something which humans had to subsequently study and fight – there wasn’t a simple off button here. This is what the future is going to look like and we are not prepared for it.

Import AI 468: 23 RSI ideas; PostTrainBench+; and how trust and transparency interplay with AI racing

Import AI

Import AI 468: 23 RSI ideas; PostTrainBench+; and how trust and transparency interplay with AI racing

Import AI surveys 23 policy ideas for recursive self-improvement, the PostTrainBench+ benchmark, and how trust and transparency shape AI racing.

linkby Erik Craddock (@erik)Credit: Jack Clark
Erik Craddock@eriklink

The future of the con is already here, it's just not evenly distributed

Here’s a partial list of scam-relevant capabilities that LLMs have that would previously require significant skilled human effort per target:

Researching a mark to find out the best way to go after them. Personally tailoring all communication with a mark in mind, dynamically adjusting based on how they respond to various approaches. Cloning the voice of a person the mark trusts, like a relative. Plausible, real-time deepfaking of a video call. Building a plausible-looking corroborating fake web presence 6. Realtime monitoring of compromised resources, and dynamically building up the scam based on this monitoring. Better triage and discovery of marks. Avoiding signature-detection based spam filters (shown by Heiding et al). Scanning for and chaining known exploits in unpatched deployed software. Mass scanning isn’t new, but cheaply building tooling that can keep tabs on the latest CVEs and learn new tricks is7.

These are capabilities that exist today, and they’ll only improve from here. We should look at these skills as a floor, not a ceiling.

The future of the con is already here, it's just not evenly distributed

manishearth.github.io

The future of the con is already here, it's just not evenly distributed

The Set-Up Johnny Hooker: Sometime after 2:00, a guy’s gonna call on that phone there and give you the name of a horse. Imagine yourself, perhaps a typically-well-paid, tech-savvy professional, on …

linkby Erik Craddock (@erik)Credit: Manish Goregaokar
Erik Craddock@eriklink

Cybersecurity Looks Like Proof of Work Now

Code remains cheap, unless it needs to be secure. Even if costs go down as inference optimizations, unless models reach the point of diminishing security returns, you still need to buy more tokens than attackers do. The cost is fixed by the market value of an exploit.

Cybersecurity Looks Like Proof of Work Now

Drew Breunig

Cybersecurity Looks Like Proof of Work Now

Is security spending more tokens than your attacker?

linkby Erik Craddock (@erik)Credit: Drew Breunig
Erik Craddock@eriklink

Anthropic's Mythos AI model sparks fears of turbocharged hacking

AI-enabled cyber attacks were up 89 percent in 2025 compared with a year earlier, according to data from security group CrowdStrike. Meanwhile, the average time between an attacker first gaining access to a system and acting maliciously fell to 29 minutes last year, a 65 percent acceleration from 2024.

Anthropic's Mythos AI model sparks fears of turbocharged hacking

Ars Technica

Anthropic's Mythos AI model sparks fears of turbocharged hacking

Cyberdefenses could be exposed faster than fixes could be deployed.

linkby Erik Craddock (@erik)Credit: Financial Times