← Back to context

Comment by revolvingthrow

5 hours ago

I know very little about hardware hacking so I can't really judge, but my gut feeling is that this is pretty advanced stuff, right? Granted the models didn't start at zero - the CVE was described online so it had a hook, and missing that the installed kernel and the one from OTA build had different versions was a bit embarrassing - but if all it takes to jailbreak a device is $250 in API charges... isn't almost all security kind of fucked until AI plateaus hard?

Even an unsophisticated attacker with a bit of money (NVIDIA DGX B200 is $500k or so - not something you buy yourself as a treat, but not expensive expensive) can put an excellent open weights model on it and have it probe and poke things day at night. Given that attacker needs to succeed once while defender has to succeed all the time... who's doing that at a large enough scale that the tech is resilient? Apple probably does, maybe some other big names like Samsung, but what about everybody else?

In fact, forget consumer hardware. My brief foray into electrical engineering and power transmission/distribution, seeing the ancient dinosaurs making decisions and generally abysmal state of IT leave me with a healthy dose of paranoia. What about other systems such as rail infrastructure? Banking system? Tons of legacy systems everywhere, whose only real defense seems to be that there's very little documentation on them.

> my gut feeling is that this is pretty advanced stuff, right? Granted the models didn't start at zero - the CVE was described online so it had a hook

Did I miss something? The article mentions that a similar tablet was rooted and described online with the exact CVE the AI ended up using on this tablet. Why is that super sophisticated?