← Back to context

Comment by subscribed

5 hours ago

But also the American models (case in point: Fable) refuse to engage in *defensive* activity, so anyone who's not the American government or one of the handful American companies has no choice but to turn to Chinese models to defend themselves.

Not everyone is an attacker, but now the public discourse is "but the evil Chinese will break everything" - yeah, that's because no one is permitted to do vulnerability checks of their own software or infrastructure with the capable models.

Security team in my company is salivating seeing the news, because we have a fighting chance to find and patch many vulnerabilities we didn't previously notice, thanks to the Chinese models.

You have to wonder if any of these models, from any providers or countries, are set up to lie. i.e. tell you no vulnerabilities while quietly siphoning off the ones they do find into a database.

Yet another reason that self hosted will prove to be the only sane way forward, and it'a almost certainly necessary to have multiple different model providers working adversarially.

  • Assuming the providers are compromised (and I agree that some of them probably are) then I doubt the angle taken will be to poison the product. That kind of thing usually gets noticed eventually.

    A more likely scenario is to focus on the model users as potential victims, e.g. by logging internal infrastructure descriptions, capturing private access tokens from chats, etc. That is very deniable, because it's hard to prove where the compromised data originated.

  • Of course, I'm not claiming PRC is a friend of the world. And I agree with your last point, however I don't think it's feasible to self-host Kimi-3 sized inference.

  • Self-hosted local models can't become viable soon enough... Currently they require hundreds of thousands of dollars if not millions in capital. That needs to change!