Skip to content

AI agents wrong ~70% of time: Carnegie Mellon study

Technology
92 52 0
  • AI Job Fears Hit Peak Hype While Reality Lags Behind

    Technology technology
    16
    1
    73 Stimmen
    16 Beiträge
    58 Aufrufe
    S
    The company I work at has an AI-related job freeze. At the same time, AI is in the evaluation phase in the company and hardly anyone uses it for anything really. There are surveys, and they all say that AI can help a little bit in some niche circumstances, but that for most of the work it really does nothing. Also, the AI evaluation is entirely driven by some curious employees and doesn't really have anthing to do with upper management. In fact, upper management doesn't want to pay the AI subscription fees.
  • 565 Stimmen
    127 Beiträge
    22 Aufrufe
    T
    They also bundle twice as much crapware
  • 229 Stimmen
    10 Beiträge
    38 Aufrufe
    Z
    I'm having a hard time believing the EU cant afford a $5 wrench for decryption
  • 1 Stimmen
    8 Beiträge
    33 Aufrufe
    L
    I made a PayPal account like 20 years ago in a third world country. The only thing you needed then is an email and password. I have no real name on there and no PII, technically my bank card is attached but on PP itself there's no KYC. I think you could probably use some types of prepaid cards with it if you want to avoid using a bank altogether but for me this wasn't an issue, I just didn't want my ID on any records, I don't have any serious OpSec concerns otherwise. I'm sure you could either buy PayPal accounts like this if you needed to, or make one in a country that doesn't have KYC laws somehow. From there I'd add money to my balance and send money as F&F. At no point did I need an ID so in that sense there's no KYC. Some sellers on localmarket were fancy enough to list that they wanted an ID for KYC, but I'm sure you could just send them any random ID you made in paint from the republic of dave and you'd be fine.
  • 1 Stimmen
    8 Beiträge
    31 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.
  • 56 Stimmen
    4 Beiträge
    21 Aufrufe
    cupcakezealot@lemmy.blahaj.zoneC
    !upliftingnews@lemmy.world
  • Discord alternatives?

    Technology technology
    4
    0 Stimmen
    4 Beiträge
    17 Aufrufe
    R
    XMPP is a standard and doesn't have mandated UIs. If you want a voice chat, then Mumble. It's very narrow, just for games.
  • 0 Stimmen
    3 Beiträge
    20 Aufrufe
    J
    I deleted the snapchat now.