User's avatar
Terry's avatar
1hEdited

Regarding Anthropic and its new super hacker AI:

The time has come for corporations and government agencies to close all external ports and connections to their computerized operations.

Why does a power plant need to be reachable over the Internet? What a stupid vulnerability. If it is a must-not-fail service (power, communications, hospital operations), stop leaving the door unlocked.

Hackers can't hack when there's nothing to hack.

I used to keep a single open port on my home network, so that I could SSH in from any location on the global internet. It was so convenient! I could access files, run processes, even view my office through the computer's camera.

Then one morning around 4am my phone startled me with a message: "Did you authorize this login?" I ran downstairs and discovered someone had taken over my Mac; the mouse was moving itself, opening PayPal and wiring money to some recipient in the U.K., deleting my Google browsing history. They were smart and thorough. I powered down the computer and contacted PayPal, which promptly canceled the transaction and (I believe) removed the hacker's account. I changed all my passwords on the computer and network, closed the port, and hopefully have had no further break-ins. Though, malware still can get in if you open the wrong website and click the wrong link.

I still have no idea how they did it. A dictionary attack (trying a billion different passwords) would take a long time. Apparently there was some other way to get in.

Now think about government and corporate systems that are full of vulnerabilities, some known and some not. Approximately several times a year, we hear of some major government site that was compromised and a couple hundred million names, social security numbers, birthdates etc. were leaked. Several times a year I get a vaguely worded email from some internet services provider to my health insurer or credit card company, informing me "There has been an incident" and offering me some measly bit of credit toward ID theft tracking.

Just close it down. If you can't be on site to do your work, you probably shouldn't access the computer systems from outside of work. That's how dangerous the world is now.

Scrith's avatar
1hEdited

Mythos has not been quietly rolled out. It wasn’t released. There’s a very interesting story here on what the internal testing revealed and Project Glasswing. A simple fact check would have found this.

9 more comments...

No posts