Paleo artists often "shrink wrap" fossilized animal depictions
The T-Rex, Utahraptor, Triceratops—popular depictions of each of these animals shows skin so close to bone that it might be unrealistic
So let's shrink-wrap existing animals🧵
Can you guess what this is?
AI text-to-video is here and we need to discuss the risks.
They mention in this thread that they’re considering the ways adversaries would leverage this content to harm thru red teaming but I’m still concerned.
My biggest concern is how this content could be used to trick, manipulate, phish, and confuse the general public.
- for example, imagine an adversary uses this tool to build an AI video that appears to show a vaccine side effect that doesn’t exist
- imagine an adversary uses this tool to show unimaginably long lines in bad weather to convince people it’s not worth it to head out to vote that day
This tool is going to be massively challenging to test and control under many, let alone most, adversarial conditions.
No @elonmusk, he did more than just say things. He defamed people and incited violence and harassment against them. He has a 1.5 billion judgement against him. You are free to say stupid shit as you often do, but lying about your motives only reinforces how pathetic you are.
Sen. Rafael Edward Cruz, who uses the preferred name Ted, has introduced a bill to limit the use of preferred names and pronouns. https://t.co/IAcx2YldHr
@stijnhommes Google does not treat passkeys as a username replacement that can be “further secured” with SMS OTP. This is unfortunately what @GitHub is currently doing.
Passkeys are great when implemented in a sensible way! Identity and identity assurance in one package.
@stijnhommes@github@GitHubSecurity That isn't a good comparative. GitHub displaced their excellent, long standing Security Key support (FIDO U2F) with passkeys (FIDO2)...but mischaracterized passkey's risk profile. See Microsoft or Google's implementation of passkeys for a better example.
Today the OAuth step up authentication challenge protocol becomes RFC9470.
https://t.co/eU4NnDX4MX
We now have an interoperable way for resource servers to tell clients when the authentication with which the current access token was obtained in insufficient and (crucially) allows the RS to express what requirements would be acceptable… and a way for clients to use that info to influence the next authentication ceremony with the authorization server. Both are obtained with ultrasimple primitives easily added to existing SDKs, achieving sophisticated runtime behaviors without the need for complex eventing systems.
One unexpected benefit of this document is clarity we didn't know we needed. The discussion made clear that we all have different ideas and expectations about what step up authentication really means. The non normative sections of RFC9470 capture the salient point and outcomes of that discussion, hopefully facilitating communications and preempting common errors.
On a personal note. This will be the last spec I drive from idea to RFC in my life, and I couldn't have had a better coauthor than @__b_c . From his world class competence to his encyclopedic knowledge of this space, but above all through his genuine desire for the best outcomes for everyone, Brian is just incredible and a joy to work with. Thank you for this wonderful last ride, dear friend.