← Back to context

Comment by fidotron

1 month ago

> what should be done about open weight bioweapon

Does not exist. What has in fact happened is some cults had bioweapons programs but any failure points were at deployment. (Aum Shinrikyo https://en.wikipedia.org/wiki/Tokyo_subway_sarin_attack and https://en.wikipedia.org/wiki/1984_Rajneeshee_bioterror_atta... )

> and cyber-offense capabilities?

You mean defense. That's how things get hardened. Anyone that was working during the XP era before Service Pack 2 knows what that was like, but it's very manageable.

The bigger real problem here is hardening like that would remove the opportunity for intelligence agencies to spy on everyone.

I don't think the Aum case points the way you're describing: they used a non-pathogenic strain of anthrax because they didn't know any better. That's a knowledge failure.

But even then, the debate isn't about whether open weight bioweapons exist today: it's about whether they will exist in the future. I think Amodei's argument here makes a lot of sense: "what I believe currently keeps us safe in biology is not 'defenders', or even the availability of materials, but a negative correlation between intellectual capability and desire to commit catastrophic harm. Previous technologies like internet search or even DNA synthesis were nowhere near powerful enough to break this correlation, but I worry that at its current rate of progress, AI will do so very soon."

(I'm not just spouting off; I put my time where my mouth is. I used to work in big tech, but I left for a much less well-paying job building an early-warning system for engineered pandemics.)

  • > I don't think the Aum case points the way you're describing: they used a non-pathogenic strain of anthrax because they didn't know any better. That's a knowledge failure.

    No, check https://en.wikipedia.org/wiki/Matsumoto_sarin_attack

    There are a lot of interviews with former cult members around. They had armed helicopters, a testing station in western Australia, produced piles of sarin. This wasn't a lack of science knowledge that screwed them up, they notoriously involved the elite class of Japan - it was a whole other category.

    There is no link between AI and bioweapons that makes this stuff any more reasonable than availability of detailed descriptions of nuclear reactors enables us to be purifying weapons grade plutonium in our yards.

    • > > they used a non-pathogenic strain of anthrax

      > No, check https://en.wikipedia.org/wiki/Matsumoto_sarin_attack

      That's a different attack. I'm talking about their 1993 anthrax attack: https://pmc.ncbi.nlm.nih.gov/articles/PMC3322761/

      Analysis of the 48 suspect colonies confirmed them to be B. anthracis ... This genotype was identical to that of the Sterne 34F2 strain, used commercially in Japan to vaccinate animals against anthrax.

      They used a vaccine strain because they didn't know any better. Even members of the elite can make mistakes, especially when operating outside areas they know well!

      (This was not the only thing that went wrong, but several others were also knowledge failures.)

      2 replies →

  • >they didn't know any better

    I started writing up a blog post about this and did some more reading, and this isn't right. They actually did know that the strain they'd obtained was the vaccine strain, and it was the knowledge (or competence) to turn that into a dangerous one that they lacked: https://www.files.ethz.ch/isn/156879/CNAS_AumShinrikyo_Secon...

    (Aiming to get something out with more detail on this soon)

You admit that some attackers have the inclination to use bioweapons. Why would they not use the best tools at their disposal going forward?

From the WSJ the other day:

> After OpenAI enhanced the brain power of its chatbot last summer, hundreds of users worldwide began asking it how to make and deploy biological weapons and poisons.

https://www.wsj.com/tech/ai/openai-chatbot-biological-weapon...

On cyber, the attacker/defender asymmetry strongly favors attackers. There are millions of soft targets on the internet which do not have the savvy to use AI to shore up their defenses.

  • > Why would they not use the best tools at their disposal going forward?

    Because AI doesn't solve any of the problems any attacker would actually have. It's a classic case of nerds not seeing the actual problems because they involve reality.

    It's worth pointing out that those bioweapon attacks I linked to also predate widespread access to the Internet, and there was similar scare nonsense about that.

    > On cyber, the attacker/defender asymmetry strongly favors attackers. There are millions of soft targets on the internet which do not have the savvy to use AI to shore up their defenses.

    Do you think they are not being exploited today? The reason they aren't more exploited is there really isn't much to gain from doing so.

    • jefftk addresses your bio thought well.

      > The reason they aren't more exploited is there really isn't much to gain from doing so.

      This is incorrect. The long tail of soft targets aren't being exploited more because attackers are bottlenecked on labor. AI removes exactly this bottleneck.

      1 reply →