• spizzat2@lemmy.zip
        link
        fedilink
        arrow-up
        7
        ·
        edit-2
        4 hours ago

        notice

        javascript required to view this site

        why

        measured improvement in server performance

        awesome incremental search

        Boo! Just give me the text!

        Edit: It’s long, but here’s the opening section, at least:


        In 1984 KenThompson was presented with the ACM TuringAward. Ken’s acceptance speech Reflections On Trusting Trust (http://cm.bell-labs.com/who/ken/trust.html) describes a hack (in every sense), the most subversive ever perpetrated, nothing less than the root password of all evil.

        Ken describes how he injected a virus into a compiler. Not only did his compiler know it was compiling the login function and inject a backdoor, but it also knew when it was compiling itself and injected the backdoor generator into the compiler it was creating. The source code for the compiler thereafter contains no evidence of either virus.

        Ken wrote, In demonstrating the possibility of this kind of attack, I picked on the C compiler. I could have picked on any program-handling program such as an assembler, a loader, or even hardware microcode. As the level of program gets lower, these bugs will be harder and harder to detect. A well installed microcode bug will be almost impossible to detect.

        Ken does not mean bug in the sense of error, but in the sense of listening device. And it is “almost” impossible to detect because TheKenThompsonHack easily propagates into the binaries of all the inspectors, debuggers, disassemblers, and dumpers a programmer would use to try to detect it. And defeats them. Unless you’re coding in binary, or you’re using tools compiled before the KTH was installed, you simply have no access to an uncompromised tool.

        In fact, given the amenability of microcode to the KTH, not even then.

        All manner of controls and monitors could be secreted this way in the OSes of all the devices we all use day to day. It isn’t very far fetched to suggest that the hack, in software, can create an updatable backdoor. This way every piece of software on the planet can be KTH bugged without any possibility of detection by any mortal engineer anywhere.

        Well, maybe with the diligent use of an electron microscope.

        Given last week’s horrifying revelations concerning the US government’s TotalInformationAwareness of every US domestic phone call, it is difficult to imagine that the ThreeLetterAgency’s KTH-hacked binaries are not omnipresent. I mean, can you really imagine AdmiralPoindexter would pass up an ability like this?

    • pmk@piefed.ca
      link
      fedilink
      English
      arrow-up
      7
      ·
      13 hours ago

      If I remember correctly, they used KenC to bootstrap the Go compiler.

    • redjard@reddthat.com
      link
      fedilink
      arrow-up
      6
      ·
      13 hours ago

      I’ve had it on my todo for years to work through ddc and trusting trust.
      Which is a method to verify a compiler is matching its source and thus trustworthy.

      An orthogonal approach is reproducible builds, which among many benefits can make sure a few people verifying things benefit everyone who can then see they have the same verified binaries.

  • Korkki@lemmy.ml
    link
    fedilink
    arrow-up
    14
    arrow-down
    3
    ·
    11 hours ago

    What does that even mean. Whoever said that just uttered some empty but smart sounding catch phrase. Such is all the talk about the wonders of Ai

    • AdrianTheFrog@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      9 hours ago

      I think it’s supposed to be that how AI turns high level instructions into code is compared to how compilers turn code into assembly. Implying that using AI is just a natural extension of the handing off work to the computers that we’ve already been doing.

      I wonder if you gave different AI models some c++ or something and told them to write assembly based on it how well they would do compared to an actual compiler

  • abbadon420@sh.itjust.works
    link
    fedilink
    arrow-up
    29
    arrow-down
    1
    ·
    14 hours ago

    The very fact that Anthropic is now injecting a kind of watermark into every output, is solid proof that such a Ken Thompson hack is a inevetable risk

    • AudaciousArmadillo@piefed.blahaj.zone
      link
      fedilink
      English
      arrow-up
      2
      ·
      8 hours ago

      Ugh. Fuck “AI” and fuck Anthropic. But please read how the “watermarks” work. TL;TR its like a seeded run in a video game. With the seed and pseudo rng, you get the outcome i.e. the extruded text. In the watermark its the reverse, outcome + prng = seed. The result will be the same “quality” extruded garbage as before.

  • dan@upvote.au
    link
    fedilink
    arrow-up
    8
    ·
    edit-2
    4 hours ago

    At work, I use AI for some things. Right now I’m rewriting some legacy spaghetti code that’s had a bunch of things hacked into it over the years. I spoke to the person most familiar with the expected behaviour and used AI to combine his info plus the existing code and unit/integration tests into a list of requirements.

    I wrote the new code and tests based on the requirements rather than based on the old code. After each commit, I used AI to check for parity between the old and new code, and it keeps a Google Sheet up to date with the progress (which features were fully implemented, and which ones were missing or had gaps). I had AI write some tests cases too - given the list of requirements, write integration tests for them based on the style of a few tests I wrote by hand.

    It has some quirks (eg for tests it loves over-mocking even though our skills tell it to mock as little as possible) but it definitely speeds things up.

    I use AI for small side projects at work too. Tweaking and adding features I want to shared libraries, internal tools to help our team debug stuff and automate triaging of bug reports (they’re all still reviewed by a human), etc.

    The entire reason I can trust its code is because I can read it and tweak it myself. I sometimes need to go through a few iterations to get AI code into an acceptable state. AI writing machine code directly, like what’s been talked about recently and what this post is referencing, is such a dumb idea.

    There’s other people at work that use AI for absolutely everything. Writing code, reading code, writing posts in our internal groups, etc. That’s something I don’t understand. Some people that are all-in on AI produce so much low-quality AI slop.

  • Jul@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    13
    ·
    13 hours ago

    Devs should be “dev managers and executives”. Real developers know LLMs are basically just a tool for finding examples and helping with syntax. Sure they’re useful, but I’d never let them write code, much less compile it. Who knows what they’d inject into a build.

    • rtxn@lemmy.worldM
      link
      fedilink
      arrow-up
      21
      arrow-down
      1
      ·
      13 hours ago

      That saying (or, dare I say, thought-terminating cliché) glosses over the consideration of risks and costs that result from its uncritical usage. No sane person should trust it without serious reservations just because it fits the purpose, and that’s true whether or not it bears the latest combination of letters peddled by tech bros. It’s a dangerous, irresponsible mentality. It’s a tool the same way a sledgehammer made out of plutonium is a tool.

      • Zephyr@sh.itjust.works
        link
        fedilink
        arrow-up
        1
        arrow-down
        2
        ·
        11 hours ago

        I mean in an old nuclear bomb that’s pretty much the situation. Use a conventional explosive to slam some plutonium like a sledgehammer and nukes have proven to be a strong deterrent when a country had them. Still a tool with a use case

      • Franconian_Nomad@feddit.org
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        5
        ·
        13 hours ago

        Your comment is a sweeping statement that is thought terminating itself.

        No sane person should trust it without serious reservations just because it fits the purpose

        Using a tool for something it’s intended for automatically involves some thought process. And this thought process also involves its limitations and potential for danger.

        Your criticism stems from your dislike for AI and your opinion that it’s generally not useful. An opinion that is shared widely here, but with little to no proof at all.

    • one_old_coder@piefed.social
      link
      fedilink
      English
      arrow-up
      3
      ·
      9 hours ago

      And then your boss says: “Use it for everything or you’re fired. Why are you using less tokens than anyone else? You must be more productive or else…”

        • dustyData@lemmy.world
          link
          fedilink
          arrow-up
          3
          arrow-down
          1
          ·
          10 hours ago

          Your comment is so fit for purpose, displaying such a massive willful ignorance about the world in general. Because the biggest problem with asbestos wasn’t using it for home insulation. It killed millions of workers in manufacturing plants and mines. Its biggest industrial use case was for electrical insulation of high voltage transmission lines. Where it also killed hundreds of thousands of technicians in the us alone. Before that it was used for lamp wicks. Where it killed at least a couple of millions more over a century. Today, asbestos kills 250 thousand people a year, 12 to 15 thousand in the us every year.

          I supposed any tool can be considered useful if you’re ignorant enough about it or if you’re willing to lie without remorse.

    • Ooops@feddit.org
      link
      fedilink
      arrow-up
      5
      ·
      13 hours ago

      It’s a tool, use it where it works and don’t where it doesn’t.

      But that doesn’t work with the people creating AI as they are totally dependent on the believe that AI can do absolutely everything (and an artificial general intelligence is just moments away…) to justify they insane investments. So they will make up a million stupid narratives why some people are “actually” not using AI as it obviously can’t be because of AI shortcomings…

      • Zephyr@sh.itjust.works
        link
        fedilink
        arrow-up
        2
        arrow-down
        1
        ·
        11 hours ago

        If the tool don’t work then don’t use it. I wouldn’t try to unscrew something with chopsticks

        • Ooops@feddit.org
          link
          fedilink
          arrow-up
          1
          ·
          10 hours ago

          You are probably also one of those insane ideologues that refuse to hammer in a screw for some reason, although you know how well that hammer worked on nails… 😂