Hacker Newsnew | past | comments | ask | show | jobs | submit | durdn's commentslogin

First, it’s LLMs can’t do cryptanalysis. They can barely solve toy substitution ciphers without hallucinating.

Then it’s OK, they can reproduce known attacks, but that’s just pattern matching against papers already in the training data.

Then it’s OK, they found previously unknown attacks on SpoC and a flaw in KINDI’s security proof, but those are obscure competition schemes nobody uses.

Then it’s OK, Claude found a new attack on HAWK that cuts the effective security of a NIST post-quantum signature candidate roughly in half, but HAWK isn’t deployed and a human researcher was involved.

Then it’s OK, Claude independently found a new cryptanalytic attack on AES that improves the previous best technique by 200–800×, but it’s only 7-round AES, not the full 10 rounds.

Then it’s OK, it found a practical key-recovery attack on 13-round LEA that runs in under an hour instead of requiring ~2^86 work, but LEA has 24 rounds.

Then it’s OK but none of this breaks a production cipher.

Wake me up when it breaks full AES.

Then—


This particular exploit belongs something between points 2 and 3 in your list and was more about processing data with a known algorithm and known key for the dataset that nobody had tried, so I'd say it is less impressive than a lot of other results LLMs have had in cryptanalysis. I object to the headline but the article was interesting.

then it's "fun" to realize the NSA has been storing encrypted traffic for at least two decades that they can't decipher, yet

There was news like 10-15ish years ago that the US government was making massive data storage facilities across the country. Like spending over a billion dollars on them. When I read that I knew that basically every email and text and call and DNS lookup I made was in a permanent record. I operate as though anything I do on a computer is being permanently stored, because it likely is if it's going through any US operated or controlled service providers or companies.

I fear someone higher-up taking the dataset, pointing AI at it, and saying "find me people who said something I don't like."

They’re holding off on doing that kind of thing until they have assurance that it won’t matter if the general public know who specifically they are, that they have this capability, and that they are willing to use it without caring for legality. I estimate that we’re probably right on the precipice of that time period.

I found this post hilarious exactly about this the other day:

First, it’s AI can’t multiply 4-digit numbers.

Then it’s AI can only, by brute force, get silver in the IMO with specialized systems.

Then it’s OK, well, now a general-purpose model can get gold, but it’s still just the IMO, it’s for high schoolers.

Then it’s OK, it can solve a few trivial Erdős problems, but only because nobody seriously tried them before, they were low-hanging fruit.

Then it’s OK, a lot of serious mathematicians tried this one, but the result was still obvious in hindsight, it just combined knowledge from a thought-to-be-unrelated field, if any human knew that, they would solve it.

And then to OK, but there are still Millennium Prize Problems.

Then OK well it's just Navier-Stokes wake me up when its the Riemann Hypothesis.

Then-


If AI does solve the Riemann it will be the watershed moment when the world realises what has happened.

I did a similar thing, took those sub agents primitives and ran with it: https://github.com/durdn/herdr-interactive-subagents I do still use more than one harness though.

My same line of thinking and apparently of several others, turns out herdr has a plug-in for this: https://github.com/nikok6/herdr-mirror which is close to what I need.


He wrote a lot about this. For example he built an e-commerce meta platform in Lisp that would allow anyone to build and customise their own shops that was far ahead of anything that existed at the time.


I've been using ChatGPT for similar visual recognition things. Recently I took a video of a car because I really liked its color. I upladed the video to ChatGPT and asked to extract which paint color I'd need to specify to a modding garage to put a foil on my car. ChatGPT really impressed me, extracted a screenshot, did a color analysis of the paint, found the palettes from paint vendors and found for me the exact paint code to tell the garage. I was speechless.


Wow! Simply wow!

I had a similar requirement a few days back, but I stopped at Google lens. TIL


In the same domain I used for years timebuddy https://www.worldtimebuddy.com/


I liked this metaphor:

>It was more like handholding a fresh grad who had absorbed all of human knowledge but needed someone to tie various parts of that knowledge to create something useful.


This has definitely been my experience.

I experiment every so often with ChatGPT, usually having it create a simple multiplayer browser-based app with a server-side backend. The most recent being a collaborative pixel art app similar to /r/place.

Usually by the time ChatGPT generates something that actually works, after some guidance and generally minimal code edits (usually due to its context loss), I could've written a far more optimized version myself. Its capabilities are still extremely impressive nonetheless and I look forward to future iterations of this technology. Super nice tool to have for mundane code generation and it'll only get better.

Really wish I could use anything like this at work to generate tests... it's really good at that.


Very impressive. Recently I watched this really amazing lecture on building GPT from scratch from Karpathy, I was blown away: https://www.youtube.com/watch?v=kCc8FmEb1nY&t=642s


The date of the merge has been known for sometime, so the price increase has been mostkly priced in the previous weeks (see recent pumps). Unfortunately the recent US CPI info release has sent the markets (including crypto ones) into a frenzy. In any case I am optimistic that the price of Eth will explode once the better part of this "recession" is behind us.


Makes sense. The bit I didn't understand was that presumably there was uncertainty around whether the merge would be successful. But perhaps there still is, or like you say, the CPI info release has obscured things.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: