HN user

ritwikgupta

410 karma

Assistant Professor at the University of Maryland, College Park

[ my public key: https://keybase.io/ritwik; my proof: https://keybase.io/ritwik/sigs/88iY5DNjp9zGJxyemrVgtXw0TsrESOi3zGYoqTTwPZM ]

Posts7
Comments60
View on HN

This is about changing the way FedRAMP accreditation is done for any cloud service, like Box (or a new SaaS that you may create tomorrow). The FedRAMP process requires you go through a certain set of audits, meet a certain set of standards, etc., in order to be approved to host CUI (IL4/5) or SECRET (IL6) information.

Normally this can take a lot of time and monetary investment. On one hand, these processes encode cybersecurity best practices. On another hand, it keeps new companies out of the market.

It seems this effort is doing away with a lot of those processes. I hope the level of compliance stays the same.

Public trust is not a security clearance; it is simply a more involved background check. A security clearance is only granted after a T3/T5 investigation and adjudication of the request. The SF312 NDA signed in order to receive your clearance does not expire.

Chickens in Trees 2 years ago

Fascinating. The massive variance in the percentage of chickens that prefer roosting off the ground is interesting. I wonder what environmental pressures drives this decision.

1. The PROTECT Act provisions have repeatedly been upheld by both appellate the Supreme Court as constitutional as long as the CSAM in question meets the Miller or Ferber standards. Either the law is constitutional, or you’re proposing that the courts are illegitimate, the latter of which is conspiratorial.

2. You are right that there is a campaign to limit access to open source generative AI models, but it is not an initiative led by the government. Companies such as OpenAI, Anthropic, and Google are leading the charge when it comes to emphasizing the danger of open source models and are lobbying every day to limit access. The executive and legislative branches are following suit with what industry executives tell them because they are deferred to as experts.

Industry policy teams have invented vague, ill-defined terms such as “frontier models” and equate these models as having the same power as nuclear weapons. They have a vested interest in being the sole controllers of this technology.

If you want to counter governmental efforts to limit access to such models, start by countering the FUD pushed by industry in this space.

You are grossly under-estimating the ability of the FBI’s cyber forensics teams to discern whether or not data was planted maliciously or produced overtly, as well as under-estimating the ability of the courts and a jury to understand when someone is willingly producing CSAM versus accidentally being in possession.

This prosecution is the first of its kind for the DOJ. It is highly unlikely that they would pick this case to take to trial if there was not certainty about the actions the perpetrator engaged in.

This is a misinformed and incorrect take. The PROTECT Act of 2003 [0] makes it illegal to possess CSAM that is generated by superimposing faces of minors onto sexually explicit imagery, or vice versa.

This bill predates generative AI models by decades. There is no need to engage in conspiracy theories here — the law is clear that this kind of imagery is illegal.

[0] https://www.congress.gov/bill/108th-congress/senate-bill/151

Apple may already be headed in that direction. They already have unified CPU and GPU RAM. It doesn’t seem far-fetched to imagine that they could unify persistent storage and memory.

This is survivorship bias. No counterexamples emerge because successful and working capabilities can’t and won’t be shared? Not until declassification of those sources kicks in.

The government should not give up powerful intelligence tactics, techniques, and procedures solely because the general public has a want to know. We have elected representatives with clearances for those purposes.

There’s no feeling of power here. I took on this role because the FBI needs people to help them answer these hard questions, and your traditional Silicon Valley crypto bros won’t help.

I was raised in this country post-9/11 and was taught to fear the FBI. I grew up strongly critical of our surveillance state and the overreach of power that was reported upon. The FBI hosting a deeply critical voice inside to help provide insight to their processes seems like a pretty just thing to me.

If you have better ideas, then I invite you to help change the institution. Come “be in on the secret” (a security clearance to guard national intelligence?) and do the right thing.

The FBI needs to do a better job of communicating to the public the existing oversight mechanisms it has, as well as reporting in aggregate types of issues it has prevented through the use of the authority. Additionally, more frequent (quarterly) testimonies to Congress (closed and open sessions) would be extremely beneficial.

I am a Ph.D. student at UC Berkeley in AI and currently serve as an external advisor to the FBI on AI and AI Policy. I've worked very closely with the teams that utilize FISA Part 702 and have seen the types of issues they are actively preventing with the use of the authority.

This simply is not true! NASA and IBM need to do further literature review and rely less on press releases.

There are larger foundation models for geospatial imagery available. Our pre-training method, Scale-MAE [0], has 323M parameters, makes encoders robust to changes in satellite imagery resolution, and is therefore trained on satellite imagery of all resolutions. Work out of SI Analytics [1] presents a 2.4B parameter transformers for satellite imagery.

[0] https://arxiv.org/abs/2212.14532

[1] https://arxiv.org/abs/2304.05215

CONFIDENTIAL is one of the collateral security levels. It goes UNCLASSIFIED (this data can be also additionally marked CUI/FOUO, for official use only), CONFIDENTIAL, SECRET, and TOP SECRET. S and TS have compartments which further gate access to information.

The software being marked CONFIDENTIAL means that it is classified software, the exposure of which can cause damage to national security.

That's just the part of the equation when using electro-optical imagery. You're paying to task a satellite, not necessarily a clear picture. To me this will be an interesting test for SkyFi. Casual customers just expect to see the ground when they "buy an image" and giving them clouds will put them off from using the service further.