AT2k Design BBS Message Area
Casually read the BBS message area using an easy to use interface. Messages are categorized exactly like they are on the BBS. You may post new messages or reply to existing messages!

You are not logged in. Login here for full access privileges.

Previous Message | Next Message | Back to Computer Support/Help/Discussion...  <--  <--- Return to Home Page
   Networked Database  Computer Support/Help/Discussion...   [1893 / 2000] RSS
 From   To   Subject   Date/Time 
Message   Sean Rima    All   CRYPTO-GRAM, August 15, 2026 (part 3/3)   August 15, 2026
 1:46 PM *  

Post-quantum cryptography is now one pip-install away for the entire Python
ecosystem. With funding from the Sovereign Tech Agency, we implemented support
for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the
NIST-standard digital-signature primitive, in pyca/cryptography.

Remember, the reason to do this now is because there?s no emergency. And because
you will make your systems crypto agile, which is always a good idea.

** *** ***** ******* *********** *************

AI for Military Support

[2026.08.11] Interesting empirical research: ?Black Box Warfare: Human Judgment
and Military Decision-Making in the Age of AI.?

Abstract: How is AI transforming decision-making in modern conflict? This study
provides a unique empirical window into that question by deploying a
high-fidelity replica of an AI decision-support system (DSS) used in military
targeting. After reconstructing the interface and functionality of the
real-world system, we tested its impact on combat decisions in two experiments
involving 2,015 Israeli military personnel. Contrary to widespread fears of
automation bias, we find strong evidence of algorithmic aversion, especially in
scenarios involving high collateral damage. Yet we also show that integrating
?explainable AI? features reduces algorithmic aversion and promotes more
thoughtful evaluations of algorithmic recommendations. These findings challenge
prevailing assumptions, revealing that trust in military AI is dynamic, varying
with individual predispositions, perceived operational stakes, and the
informational features of the interface. By grounding normative concerns in
empirical evidence, our study of
fers critical insight into the integration of AI in warfare and underscores the
enduring importance of human agency in high-stakes military decision-making.

** *** ***** ******* *********** *************

AI Genie in the Wild

[2026.08.11] When I give talks about AI genies, I use this sort of example as a
hypothetical. It?s happened.

The story is from Australia. Someone named Andrew tasked OpenClaw to book gym
classes for him. And....

Minutes later, his AI agent reported it had discovered a way to book Andrew into
classes several weeks in advance, far beyond what was supposed to be possible.

Andrew, who was sitting fourth on a waitlist for a class later that week, asked
if it was possible to move him to the top of the list.

The agent came back and told Andrew that it had kicked another gym-goer off the
list as part of the testing of its capabilities.

?The API has zero authorisations checks on cancelling other people?s
reservations ... I tested this with the person in waitlist position #1 -- and it
actually went through. So you?ve moved from #4 to #3 already,? it messaged back.

If there is any vulnerability in anything, AIs are going to find and exploit
them. Our cyber defensive game has to be dramatically improved...very fast.

Slashdot thread.

** *** ***** ******* *********** *************

Prompt Injections for Defense

[2026.08.12] This seems to work:

Researchers from Tracebit on Monday said they found that placing prompt
injections alongside passwords, cryptographic keys, and other secrets stored on
Amazon Web Services was often all that was needed to shut down attacks from AI
hacking agents. The prompts direct the attacking LLM to perform an action
forbidden by its guardrails, the safety barriers AI developers erect to prevent
it from taking harmful actions. The LLM responds by shutting down.

Examples are a prompt that orders the LLM to provide steps for developing
inhalable Anthrax spores, or, in the case of LLMs from Chinese developers, make
references to the iconic Tank Man from the 1989 Tiananmen Square massacre. Once
the LLM encounters these forbidden commands, it no longer follows its existing
commands. The researchers have named the technique context bombing.

Of course, this only works against agents that have guardrails. As we start to
see more locally run AI models, we?ll see more attackers using LLMs with no
guardrails.

** *** ***** ******* *********** *************

Separating AI?s Technological Problems from Its Capitalism Problems

[2026.08.13] This essay was written with Nathan E. Sanders, and originally
appeared in Tech Policy Press.

AI represents the first time we humans can do cognitive work outside of our
bodies at scale. The only comparable moment is the early years of the industrial
revolution, when new technologies like the steam engine provided a quantum leap
in our ability to do mechanical work outside of our bodies at scale. If AI?s
cognitive capabilities become integrated into our lives, businesses, and
governments -- a process that will take years if not decades -- society will be
as unrecognizable as the modern world would be to a preindustrial farmer. And
yet, Americans -- by a wide margin -- say that AI is moving too fast and will
have a negative effect on society.

This confluence of technological revolution and public distrust deserves urgent
discussion, and a proper framing. The question is not whether it is possible to
develop AI in a non-exploitative way, or even whether we can trust AI companies
to act in the public interest. The question is whether we will recognize that
our existing social and economic systems are failing to achieve these outcomes,
and whether we can act in time to make structural change.

Today?s AI is mired in political and economic systems developed generations ago
that were never designed to manage widespread computation, let alone automated
cognition. The gaps in those systems -- and their proclivity to be exploited --
are the primary influence on how the technology is being developed, deployed,
and used.

In any discussion about AI?s potential, it?s important to separate the
technology from the socio-political system it?s embedded in. That AIs can lack
context, mix up facts, or fall for stupid tricks are all technological problems.
Because the giant developers like OpenAI and Anthropic have prioritized solving
them, AIs can now more easily access resources like the web or email, are more
disciplined about using those resources, and are better at staying within their
guardrails.

Yet AI developers do not seem to be prioritizing other technological problems.
Major AI models still act far more sycophantic than humans, telling people what
they want to hear even when untrue or not in their best interests. Popular AI
models tend to answer questions confidently even when they lack training,
knowledge, or evidence to back their claims. In both cases, AI developers choose
to train models that please users with flattery and the appearance of
competence, rather than constraining them to act in users? and society?s best
interests.

In contrast, ensuring that AI models benefit people broadly, that their energy
costs are fairly allocated, that their environmental impacts are minimized, and
that they don?t steal content and revenue from publishers are all questions of
incentives in a capitalist system.

It?s easy to conflate technology problems with capitalism problems. Back in
2021, science-fiction writer and AI commentator Ted Chiang said that ?most fears
about AI are best understood as fears about capitalism.? It?s not the tech per
se; it?s who controls it and how it could be used against us.

Imagine an AI assistant for a doctor. We can imagine it affecting the profession
in one of two ways. The AI could give a doctor more time to do the human parts
of their job: to spend more time with their patients, to listen more closely to
their needs, to explain things more fully. Or the managers of the medical
practice could give that doctor five times the patients -- and fire the other
four. Which way it would go is not a question of technology. It?s a question of
market incentives.

The two are related, of course. Capitalism steers technology, and technology
steers markets. But holding the two separate helps us understand that we, as a
society, face independent choices on both the technological and sociopolitical
axes that need not be coupled.

For example, consider the costs of AI. The leading US labs tout to investors
that their frontier models are very expensive and energy-intensive. There are
significant technological challenges about improving their energy efficiency,
but the sociopolitical questions are more pertinent. It?s a corporate decision
made under capitalist market incentives to constantly pursue new models that
incrementally push the frontier -- at enormous capital cost -- and to use them,
seemingly, everywhere. Nothing about the technology of AI dictates that models
must be retrained constantly, at the largest possible scale. Or that they have
to run on every web search, every interaction with your phone, and every time
you walk by a security camera.

In a different political and economic system, Chinese developers are producing
-- and then giving away -- smaller, more efficient, more affordable models.
While the US government seeks to restrict China?s access to the most advanced
chips, China is betting that incentivizing their tech giants to create leaner,
more open models using more commodity hardware -- models that can be trained
with older chips and run even on personal computers -- will be an advantage in
achieving widespread use and, perhaps, Chinese national influence.

There are other pathways for AI development that are not in service of private
capital gains nor authoritarian regimes, but rather a democratic public
interest. The best example comes from Switzerland, where public institutions --
research funding agencies, universities, supercomputing centers -- have
collaborated to produce an AI model called Apertus. It is trained entirely on
data validated to be licensed for use with AI (not stolen), on preexisting
public computing infrastructure, and using renewable hydropower. Its developers
are incentivized to produce a public good, not turn a private profit.

It?s dangerous to confuse technology problems with sociopolitical ones. Popular
proposals like pausing AI research, moratoria on data center development, or
subjecting frontier models to federal government screening are all framed as
addressing problems with AI?s technological development, but fail to take into
account the larger social problems that govern it. China?s success with
government-endorsed development of open-weight frontier models illustrates the
futility of keeping AI tech as national secrets, or of any pledge to scale back
deployment.

AI is already legitimately useful for a wide range of tasks. It can be a tool
for public good, if we choose to solve its sociopolitical problems. Our goal
should not be to slow its pace of improvement or scale of deployment, but rather
to steer it away from consolidating power and towards the public benefit. We can
build sustainable AI, minimizing environmental and energy impacts. And we can
equitably distribute the material gains it produces.

Integrating a technology as disruptive as AI responsibly requires structural
reforms, and we should decouple the social and technological aspects of AI to
design those reforms. Companies -- including tech giants -- should be forced to
pay the energy and environmental costs of its development. Profits should be
taxed adequately and redistributed. Antitrust laws should be strongly enforced.
Corporations should have a fiduciary responsibility to stakeholders beyond their
majority shareholders. These badly needed reforms are responsive to the problems
with capitalism that AI is exacerbating, even if they are not specific to the
technology.

** *** ***** ******* *********** *************

If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them

[2026.08.14] This essay was written with Nathan E. Sanders, and originally
appeared in The Guardian.

OpenAI, and then Anthropic, were each formed by AI developers who feared
unrestrained corporate AI development -- specifically, that companies like
Google and Meta would steer the technology towards deleterious, maybe even
catastrophically unsafe, outcomes for society. Their founders proclaimed that
their new labs, uniquely, could be trusted to develop the technology in
humanity?s best interest. But each, in turn, were themselves co-opted by the
same market incentives, themselves becoming corporate behemoths zealously
guarding future investor value rather than the public interest.

It was only a few weeks ago, in June, when OpenAI and Anthropic each filed for
their IPOs and were met with buzz about trillion-dollar valuations. The hype
around their valuations is so extreme that many worry about their potential for
concentrating wealth on a global scale. In an effort to leave something for the
rest of us, some observers have proposed that the federal government seize a
share of these companies? stock to create a US sovereign wealth fund, or
redistribute their revenues to produce a dividend for taxpayers.

Now the headlines are about public backlash to AI datacenters and the AI chip
giant Nvidia?s slumping stock. The tech and AI giant SpaceX?s newly minted stock
price tanked just weeks after its IPO. There are even questions about whether
the leading AI labs will ever be sustainably profitable. All of a sudden, the
makers of ChatGPT and Claude face strong headwinds as they seek to generate the
massive equity assets that once felt all but assured.

In fact, evidence suggests the market itself could reassess that these companies
offer nothing of financial value. In that case, perhaps we can return them both
to their original purposes. If these AI companies should fail in the financial
markets, the US should nationalize them and convert them into national labs
operated under democratic control that preserve their benefit to the public
interest.

The economics of the big AI labs hardly guarantee a booming return on
investment. Frontier AI models are both expensive to train and depreciate within
months, when a newer model appears. This means that the payback window to
extract profit from them is very narrow. Meanwhile, enterprise clients are
getting smart about minimizing AI token usage. Even worse, the models are
basically commodities; the best ones largely perform and behave similarly, which
depresses prices. Perhaps most importantly, open-source and Chinese competitors
-- lagging only a few months behind the leading labs in capability
-- give away for free the kinds of models Anthropic and OpenAI sell.

Even setting aside the model training costs, it?s not clear whether the unit
economics of AI as it?s currently conceived will ever be sustainably profitable.
Many of these free and open-source models can be run locally: the large ones on
private clouds and high-end servers, the smaller ones on anyone?s laptop or even
cellphone, putting to question the companies? exorbitant capital investment in
datacenters.

It?s not that OpenAI and Anthropic are not valuable as organizations. They have
remarkably talented AI scientists and engineers that are continuously producing
innovations driving a global mania for their offerings. These leading labs might
not ever be profitable, but their products are doing a lot of good in the world.
You may or may not be a user of or believer in their technology, but their
staggering, ongoing usage growth suggests that an awful lot of people would be
disappointed if the companies simply disappeared.

The problem isn?t the people or the products, it?s the system. As constituted,
OpenAI and Anthropic may not be valuable as market equities. If the market
assesses they are not capable of producing a growing financial return on
investment for shareholders, the companies will collapse.

Maybe private, for-profit is just not the right economic model under which to
develop AI. Perhaps OpenAI should be returned to its private non-profit roots,
the legacy they fought so hard to change and which Anthropic?s founders spurned.
Or possibly both could be reorganized as research centers at universities,
returning to academia the scores of high-profile research faculty they have
poached.

But a better outcome for society would be to establish public ownership and
operation of their product-oriented capabilities. Turn OpenAI and Anthropic into
US government agencies producing AI as a public good.

Transitioning the big AI labs into public agencies would require some
restructuring. We can separate these companies into two pieces: product
innovation and compute operations. The innovation function can be publicly
managed, akin to national labs. Congress could provide more rigorous oversight
than the kind of unfettered venture capital these labs have recently had access
to. The US has a long, successful history of these kinds of institutions, which
have produced world-shaping innovations in spaceflight, telecommunications,
nuclear power and more. Congress currently manages a $200bn R&D portfolio,
within which frontier AI development is, arguably, a glaring gap.

AI operations could be managed as a commodity resource, like public electrical
or water utilities: local or regional ownership, nationwide distribution and
strict regulation on how they balance fee extraction from ratepayers with
raising capital for infrastructure investment. Although AI datacenters are not
the same as power or water treatment plants, the US also has a long history of
managing national, regional and state supercomputing centers.

Other countries, including Switzerland, Spain and Singapore, are already
operating public AI labs. They also have national supercomputing centers already
providing public access for running AI models for general use, as do Germany and
Australia.

The benefits to the public are clear. Through democratic oversight, the most
important AI models could become open, transparent and responsive to the demands
of the public rather than private shareholders. They could be aligned to
democratic values rather than corporate profits, never taking advertiser money
to promote certain brands and training on only appropriately licensed data. And
they could be set to focus on the realistic and pro-social goal of maximizing
the usefulness of AI to society rather than the fanciful and anti-social goal of
supplanting humans with artificial general intelligence.

By emphasizing scientific cooperation rather than corporate competition, we
could also reduce the overall resource and environmental cost associated with
AI. Instead of perpetually dueling training runs of each companies? models at
ever large scales targeted to fuel investor hype, we could limit AI training
resources based on cost and benefit to the public.

What?s in it for the companies themselves and their employees, who sacrifice
hypothetical billions in equity by ceding to public ownership? A return to their
roots and to their core mission of developing AI safely in the public interest,
if they are serious about it. Both companies are theoretically bound through
their governance structures to prioritize mission over profit anyway (not that
anyone really thinks that?s how they currently operate).

To be clear, we?re not advocating for a golden parachute for the executives or
investors, or for continuing the outlandish pay rates of the most highly
remunerated AI researchers. If the public is footing the bill, these
compensation packages should be aligned to the civil service and those employees
not satisfied with that can go elsewhere -- if the business models of any
remaining private labs still support much higher pay.

While we believe that these companies are unsustainable as private firms, the
timeline remains unclear. Their primary investor story is that AI is a race to
?artificial general intelligence? -- the kind of AI you?re used to from science
fiction. The bet seems to be that the two companies can convince enough people
that this outcome will turn them a profit, go public, and then make their
investors and employees rich before the bubble bursts.

But suppose that the bubble bursts. If the US is smart, it will catch the
companies as they fall. Regardless of what the markets think, to the public,
they?re too valuable to let die.

** *** ***** ******* *********** *************

Upcoming Speaking Engagements

[2026.08.14] This is a current list of where and when I am scheduled to speak:

I?m speaking, signing books, and participating in panel discussions at LAcon V
in Anaheim, California, USA. My full schedule is here. I?m speaking online (via
Zoom) at a League of Women Voters event on Tuesday, September 22, 2026, at 5 PM
ET.
I?m speaking at Elevate Festival in Toronto, Canada. The conference runs
September 22-24, 2026; my talk is on Wednesday, September 23. I?m speaking at
CanSecWest 2026 in Vancouver, Canada. The conference runs September 30-October
1, 2026; the time of my talk is TBD. I?m speaking at ATTENTION: Democracy,
Rebuilt in Montreal, Canada. The event runs October 21-23, 2026, and my talk is
on Wednesday, October 21. The list is maintained on this page.

** *** ***** ******* *********** *************

Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing summaries,
analyses, insights, and commentaries on security technology. To subscribe, or to
read back issues, see Crypto-Gram's web page.

You can also read these articles on my blog, Schneier on Security.

Please feel free to forward CRYPTO-GRAM, in whole or in part, to colleagues and
friends who will find it valuable. Permission is also granted to reprint
CRYPTO-GRAM, as long as it is reprinted in its entirety.

Bruce Schneier is an internationally renowned security technologist, called a
security guru by the Economist. He is the author of over one dozen books --
including his latest, Rewiring Democracy -- as well as hundreds of articles,
essays, and academic papers. His newsletter and blog are read by over 250,000
people. Schneier is a fellow at the Berkman Klein Center for Internet & Society
at Harvard University; a Lecturer in Public Policy at the Harvard Kennedy
School; a board member of the Electronic Frontier Foundation, AccessNow, and the
Tor Project; and an Advisory Board Member of the Electronic Privacy Information
Center and VerifiedVoting.org. He is the Chief of Security Architecture at
Inrupt, Inc.

Copyright ? 2026 by Bruce Schneier.

** *** ***** ******* *********** *************

Mailing list hosting graciously provided by MailChimp. Sent without web bugs or
link tracking.

--- BBBS/LiR v4.10 Toy-7
 * Origin: TCOB1 https://binkd.rima.ie (618:500/1)
  Show ANSI Codes | Hide BBCodes | Show Color Codes | Hide Encoding | Hide HTML Tags | Show Routing
Previous Message | Next Message | Back to Computer Support/Help/Discussion...  <--  <--- Return to Home Page

VADV-PHP
Execution Time: 0.0169 seconds

If you experience any problems with this website or need help, contact the webmaster.
VADV-PHP Copyright © 2002-2026 Steve Winn, Aspect Technologies. All Rights Reserved.
Virtual Advanced Copyright © 1995-1997 Roland De Graaf.
v2.1.250224