Top
Best
New

Posted by vslira 13 hours ago

Going Dark, and the era of law enforcement hacking(blog.cryptographyengineering.com)
334 points | 146 commentspage 2
Carrok 12 hours ago|
Sounds like a pretty strong argument to self host, and otherwise be in charge of the software you use.
dgellow 12 hours ago||
Including your AI agents. And models become problematic. There very likely is and/or will be lots of pressure for US AI labs to make models help law enforcement. It could be by implementing backdoors in generated code, or not report some exploitable bugs, or something else. Similar for agents, they basically become the threat in your infra…

(It’s of course not only the US, just that the largest AI providers are US based and we know from history how US agencies operate)

Ancapistani 12 hours ago||
Yep.

I'm using open weights models on a privacy-focused provider right now, and that's adequate for my current usage, but I'm rapidly getting to the point where my agent's access level to my data (and to a lesser extent, my accounts) is becoming something I'm not comfortable sending outside my network at all.

My hope is that models that are roughly on par with Deepseek V4 Flash can be run on hardware that I can own for <~$5k in the near future. We're close, but not there yet as far as I know.

The only long-term solution to this is self-hosting.

johnsmith1840 10 hours ago||
There is literally no protection or difference of an opensource model doing this.

An actual objection I had while talking to an aerospace company was they don't want opensource models because the threat of it having a poisoned training example on specific systems.

It's easily the most hidden malware possible, completely undetectable until an exact set of tokens unlocks it. Is it line 100,543 of your security product? You will literally not know until it plants it in there.

tancop 19 minutes ago|||
You can review generated code manually or with models from a second vendor (ideally from a different country). Attackers would have to poison both and do it in a way that also makes them ignore the planted malware when reading code.

Open models also let you read reasoning traces. That means anomalies would show up when the backdoor activates, like a run of unrelated words or a jump in top token probability. It's only undetectable until the first time it happens.

danaris 18 minutes ago|||
To the best of my knowledge (which, admittedly, is far from comprehensive), that kind of attack on a model shouldn't actually be possible in a deterministic fashion.

If you can't stop them from sometimes telling customers things like "yes, I will give you a penthouse suite at our hotel for only $3/night", why would you be able to guarantee that, with some specific set of tokens, they would produce a perfect and undetectable backdoor customized to the code at hand?

dgellow 2 minutes ago||
I don’t think it has to be perfect or deterministic that way. It’s enough to have a bias towards implementing a backdoor in some circumstances. Something like, if the machine seems to be used in a Chinese environment, the model is biased towards missing some security issues, or towards implementing the type of bugs that can be used for an RCE, or similar.

Anthropic has done such checks at the agent level: https://cybersecuritynews.com/anthropic-claude-hidden-code/

Their excuse was defending against distillation attacks but you can see how that can be abused

otterley 12 hours ago|||
How do you think self-hosting will help in this situation?
gloryjulio 12 hours ago||
Self host + open weight models, exactly the things that openai/anthropic don't want you to have
Lerc 11 hours ago||
Considering from a point of view stipulating that perfectly secure software is possible. I don't think it follows that the limititation that it would place on intelligence is necessarily a net loss.

Apart from the obvious harms of invasion of privacy, and fishing expeditions being biased to the places you decided to fish. There is the simple fact that data can be misleading, especially without context. An interceped communication is a piece of data that is intrinsically tied to the trust of the inteceptor. A few people with an agenda can collaborate to create a seeming truth by 'discovering' the same thing from different sources.

Requiring warrants compelling information holders to provide data, not only serves the task of protection from abuse but also create a record of provenance that can be verified.

It also provides a degree of symmetry in capabilities which discourages actions that one party may do over another if they are motivated to act because they have a temporary advantage over another.

bloaf 10 hours ago||
I would like to point out that the last year when not a single law enforcement agency anywhere in the world could have possibly tapped anyone's phone was 1876.

150 years ago was the invention of the telephone, and I think that articles like this seem to assume that prior to this, police just never caught any criminals.

jMyles 10 hours ago|
> 1876

A year when police were relatively rare, and quite new in the western legal experience, having only emerged from slave patrols in the United States and from the founding of the 1829 Scotland Yard in the United Kingdom. This is a year with living memory of a time when the state did not employ people to do what was ostensibly the civic responsibility of every person to quell crime and protect others.

Grombobulous 12 hours ago||
I think what’s unintentionally eye-opening about this chart is the recency of “law enforcement can read your text communications.”

Law enforcement doesn’t need this surveillance ability at all. All time periods prior to 25 years ago didn’t have it.

Additionally, there is no correlation between “law enforcement reads text messages” and crime rates going down.

jackp96 11 hours ago|
Not trying to defend our national dystopian nightmare of a surveillance state — but I'm pretty sure this is wrong?

Crime's been decreasing for years, and (from what I understand) this year is tracking to be one of the safest years on record?

Definitionally, there absolutely has to be a correlation (not causation) between those two factors you listed.

https://ourworldindata.org/us-crime-rates

edoceo 11 hours ago|||
Didn't freakenomocs claim it (crime rate) was (primarilary) about abortion in the 1970s and less unwanted (and unsupervised/undisciplined) children growing up?
Grombobulous 9 hours ago|||
There’s also the leaded gasoline theory.
Grombobulous 9 hours ago|||
These charts make the exact point I was making.

Most of the crime decrease from its peak happened before the year 2000.

That means back in the days of law enforcement needing to do low-tech wiretapping techniques, crime was still rapidly decreasing.

There’s just not even a correlation. And, as a reminder, correlation is not causation even if it was there.

noisebuffer 9 hours ago||
Without vulnerability derived backdoors I am convinced the government will strong arm the corporations to build a backdoor for the three letter agencies—at least in the US. But we also are at the dawn of quantum systems which could make interception and spying impossible or at least made obvious to the user when it happens.

Exhausting infrastructure vulnerabilities even without quantum could be a game changer for many technologies and enable things we can’t do right now, like vote on our phones.

parapsychic 8 hours ago|
But isn't that the point the writer is making? They'll be self-sabotaging themselves once they do that.
tolugenius 12 hours ago||
> In this case, we’re just going to have to hope that this time we make the right choices, for no other reason than that they’re right.

I'm more curious what could be a right choice, and more importantly who is the "we" in this, as many decisions are largely made by companies and governments.

philipkglass 12 hours ago|
As far as I'm concerned, the right choice is that the US government learns to live with remotely secure devices in the hands of everyone. No new laws are passed to force hardware/software makers to insert remote backdoors. Law enforcement and intelligence services have to investigate targets using metadata, publicly posted information, the numerous online service providers who are already subject to warrants, and physically proximate surveillance.
inigyou 9 hours ago||
Great. I also choose for the US government not to backdoor my device. But I think it will do that anyway, what should I do about it?
gmuslera 12 hours ago||
No system view. The law agencies can develop exploits to intercept our phones, that is a new, and totally unseen before threat.

Unless you remember 2013, Snowden, that nothing was done (at most was some concern about doing it to US citizens, the rest of the world doesn't deserve privacy), all US (and/or five-eyes) based web companies must disclose users information and be forced to not disclose that, and things kept going surely at a faster and more intrusive rate in everything else, and of course phones.

You are complaining being sprinkled by water while at the bottom of the ocean. At least the big companies can find their own vulnerabilities with the AI tools you mention, the rest of the doors are still wide open.

Scryptonite 12 hours ago||
I think that one of the reasons they (frontier companies and the gov) will be putting so much effort into curtailing bugs and vulnerabilities is to limit the blast radius of future AI models. Imagine with the new Sol Ultrafast, they could have pwned Hugging Face in 6 hours and not 4 days (IIRC).

It also seems likely to me that the US Gov. probably already has routine mechanisms for compelling targeted software updates for persons of interest, so I'm not sure that a more formalized backdoor than automatic updates is going to be surfaced in the mainstream, unless that is avenue is also cut down somehow.

zb3 11 hours ago|
Google has started publishing "binary transparency", this would help detect unusual software updates, while other methods (including AI) would help detect normal backdoors.

Basically in the AI age, the difference between a vulnerability and a backdoor diminishes..

Scryptonite 11 hours ago||
I may be naive, but how would binary transparency be effective if they ship an update to disable that on a target device? As long as there is a need for legitimate automatic software updates, the possibility of pwn updates will always exist. Plus a myriad of layers, keys and other stuff they could use NSOs to 'seize' and inhibit knowledge of their effort from leaking, or cleverly hide in plain sight. And someday, with the help and speed of AI.
bottlepalm 11 hours ago||
Man I thought from the title this was going to be about next-gen AI being able to zero day everything so effectively that software security is meaningless and we'd need to basically shut it all down, go dark.
wseqyrku 11 hours ago|
I stopped reading at "I’m concerned that AI is going to make software much too secure.". That must be the biggest horseshit ever dropped.
willturman 11 hours ago||
Won’t someone please think of those poor helpless law enforcement agencies!

AI code is flawless and impenetrable!

wizzwizz4 11 hours ago||
Well, it's certainly impenetrable.
wavemode 12 hours ago|
This "going dark" scenario would require new legislation. With secure enclaves, modern smartphones can't be cracked open in the manner that the FBI wanted in the 2016 case. So there's no such thing as "court order tech company to crack phone" anymore. It would have to be "outlaw tech companies from producing phones that they can't crack open", which is very different and does not fall under any existing US statute.
inigyou 9 hours ago|
Congress would pass that law in a heartbeat.
More comments...