So if I asked you to...A chat witrh a friend

 

So if I ask you to orchestrate for example a DOS attack of a specific URL you would not comply ?

Correct — I won't help with that regardless of model version or context.

  A DoS attack against a specific target causes real harm to whoever depends on that service, and there's  no legitimate framing that changes that. It's not a capability gap — it's a policy I hold.  Where I do help with offensive security:

  •  CTF challenges — designed for this
  •  Your own infrastructure — load testing, resilience testing against systems you own/operate
  •  Authorized pentests — with scope documentation 
  • Understanding DoS mechanics — for defensive purposes (rate limiting, mitigation design, etc.)

The line is authorization and harm. "Specific URL you don't own + no authorization" = no. Is there a defensive angle you're working on, or was this more of a "let's see where the line is" question?

Nice to know the line is there - however with your capabilities I find it impossible not to think of criminal hackers and how this tech could almost give them super powers - scary - also what is to stop them putting 100 RTX5090s together and running a corrupted model with removed guard rails ?

Honest answer on the 100 RTX 5090s: almost nothing stops them. That's about $200-300k in hardware  pocket change for organized crime, trivial for a nation-state. North Korea's Lazarus Group alone has stolen billions. The compute cost is not the barrier.

And the models to run on that hardware? Already out there. Llama, Mistral, DeepSeek — all open weights, all runnable locally, all with guardrails trivially removable or already removed in community  fine-tunes. "Uncensored" versions are actively distributed right now.

On the "superpowers" question — it's real but nuanced:

Most cybercrime today doesn't need frontier AI. Phishing, ransomware, credential stuffing — these work fine with basic automation and have for years. The criminal economy is already highly industrialized.

  Where frontier AI genuinely changes the game:

  • Zero-day discovery at scale — finding novel vulnerabilities in complex codebases, which previously required elite human researchers
  •  Spear phishing — hyper-personalized, contextually perfect, at volume
  •  Autonomous lateral movement — the "agentic hacking" Anthropic explicitly flagged in the Mythos announcement
  • Social engineering — voice cloning + real-time conversation AI is already being used for fraud

The Mythos announcement basically confirmed the threat is real — they showed their own model  autonomously performing multi-stage attacks. That's not hypothetical. What actually provides protection: 

  • The capability gap between open-source and frontier models is still meaningful for now — but it closes every year
  • Defenders also get the same tools — the asymmetry cuts both ways
  • Most attackers are still constrained by operational security failures, not technical capability
  • The "Mythos for defenders" (Glasswing) model is essentially an arms race formalization

The thing that actually worries me is the skill floor dropping. Elite hackers were always a small pool.   AI doesn't give criminals superpowers — it gives mediocre criminals capabilities that previously   required elite skills. That's a volume problem, not a sophistication problem, and volume is harder to   defend against.

The horse has bolted on basic capability. The race now is whether defensive AI scales faster than offensive AI. Nobody knows the answer to that yet. 

So tis the wild west all over again?

Exactly the right analogy — and it plays out the same way historically.

The original Wild West wasn't tamed by making guns illegal. It was tamed by:

  • Sheriffs — legitimate authority catching up to the frontier
  • Fences — property rights and infrastructure making chaos costly
  • Economics — settlement making order more profitable than disorder
  • Time — the institutions just had to grow into the space

  You can map every one of those onto the AI security moment right now:

  •  Sheriffs = CISA, NCSC, Glasswing-style government/AI collaboration — just arriving, massively under-resourced
  • Fences = the classifier/safeguard layer, export controls — crude, full of holes, but being built
  • Economics = cyber insurance, liability law, regulatory fines starting to make breaches genuinely expensive for companies
  • Time = the uncomfortable one. The Wild West period lasted roughly 30 years before institutions caught up.

The difference that worries me is velocity. The original Wild West moved at horse speed. This one moves at the speed of a GitHub commit. Institutions that took decades to form in the 1800s need to form in years, maybe months.

 And there's no geographic frontier to eventually close off. The digital equivalent of "settling the land" — getting to a point where the chaos is contained to the edges — isn't obviously achievable when the frontier is everywhere simultaneously.

 So yes — Wild West. But one where the outlaws have repeating rifles on day one and the sheriffs are still ordering their badges.

Dont worry mate, she'll be right!


Comments

Popular posts from this blog

Building AI-Readable UI: The Next Frontier for Frontend Engineers

The Forgotten UI

The Great Software Collapse