UL NO. 414: LastPass Settings Upgrade, Boosting ChatGPT Output, AI Adding Societal Transparency
š Continue reading online to avoid the email cutoff issue š

Unsupervised Learning is a Security, AI, and Meaning-focused podcast that looks at how best to thrive as humans in a post-AI world. It combines original ideas, analysis, and mental models to bring not just the newsābut why it matters, and how to respond.
TOCINTROHi!
Super hyped for this week. Iām making great progress on adding stuff to my AUGMENTED AI class, which Iām giving live on Saturday. Weāre closing signups on Wednesday, so get in while you can! RESERVE A SLOT
Iāve also got a ton of work done on my big open-source AI project Iāve been telling you about for a while! And Iāll be releasing that probably next week! I cannot wait to share this thing!
Alright, letās get into it.

AIās Predictable Path: 7 Things to Expect from AI in 2024+
My latest essay on where AI is heading, based not on trying to guess future tech, but based on looking at what all humans want. READ IT
My Response to Cory Doctorow Saying AI is a Bubble
Cory Doctorow thinks AI is a bubble and that itās going to blow up soon. I think heās right about a lot of valuations and gimmicky companies, but very wrong overall. READ IT
LastPass is mandating at least a 12-character master password after last year's security situation(s). Updates also include checks against breached credentials and other protections against credential-stuffing attacks. MOREĀ
Mandiantās X account got taken over, which is a bit embarrassing for a security company as well-respected as them. Itās not clear yet what the failure was, i.e., whether it was a password/2FA issue or a vulnerability like the XSS/CSRF one reported by Chaofan Shou. Mandiant is now part of Google. MORE
š Reminder to please check out our sponsors each week. They help us keep the newsletter and podcast as a viable business model, and are often sharing some pretty cool stuff. š«¶š»
Sponsor
Ā šØUnveiled: The 2023 Kubernetes Security ReportšØ
Dive into the unseen depths of Kubernetes security with our latest findings! Our comprehensive scans of 200,000+ cloud accounts reveal a startling landscape of exposed containers ripe for the taking.
š Inside, you'll unlock:
Expert analysis of Kubernetes attack vectors
In-depth breakdown of Kubernetes attack chains
Current statistics on security controls and mitigations
The best defenses against cloud attacks
Itās a current playbook on the best ways to address cloud threats.
š Secure Your Insights:
Ā wiz.io/lp/the-2023-kubernetes-security-report
šAccess Your Blueprint to Cloud Security Now!ā ļø Stealthy AsyncRAT Attacks ā US infrastructure has been targeted by AsyncRAT malware for 11 months. | SEVERITY: HIGH | RESPONSE: AT&T Alien Labs provides detection tools. MORE
Drones are becoming a go-to method for smugglers to transport drugs across borders. According to a Vice report, these unmanned aerial vehicles are increasingly being used to bypass checkpoints. MORE
š„ HealthEC Data Breach ā Over 4.5 million individuals had their personal data exposed in a breach at HealthEC. The compromised data includes sensitive information, which is always concerning. MORE
š Continue reading online to avoid the email cutoff issue š
TECHNOLOGYš¤ Some folks at Deepmind created a completely insane new robot. It does a lot of the stuff that weāve seen promised for years, like cooking, cleanup, etc., and itās all running off of consumer parts and compute. The demo video is a must. MORE
š”As big as AI is going to be, itās nothing compared to that same AI inside of a household robot. TESLA is betting big on this, and so am I. Virtually everything about AI is made better by being in a physical form, but this is especially true for companionship, elderly assistance, and use cases like that. Being a security guy, however, I really do worry about the threat model here. Remote access and RCE to these things will be nightmare fuel.
š Principled Instructions Are All You Need Paper ā A new paper is out describing how to get a stable 50% improvement in ChatGPT output. They provide 26 different techniques to get there. MORE

From the linked paper.
OpenAI's GPT store, a marketplace for custom AI agents, is set to launch this week after some delays. The platform will enable ChatGPT Plus and enterprise subscribers to create and sell personalized chatbots, and the more people download and use your GPTs, the more you get paid. MORE
Google is pushing to remove third-party cookies from Chrome in 2024, which critics are saying is way too fast. Critics argue that the industry will need far more time to get ready, and that solutions like Googleās Topics arenāt ready yet. Topics works by collecting things a given user is interested in and sharing that list, rather than sharing browsing history. MORE
š” This Google Cookies thing is starting to feel a lot like a lot of their product rollouts, i.e., rushed and half-baked. The difference in this case is that it could cost them a LOT of money if they mess this one up. And potentially set the whole anti-3p-cookies effort back years.
Flush is an app that lets you book a cafe's bathroom for $5, aiming to solve the public bathroom problem. The app, created by Elle Szabo, offers a double-sided marketplace where businesses can list their restrooms for rent and users can reserve them, with Flush taking a 5% cut. MORE
Starlink just launched satellites that'll let you use your LTE phone from almost anywhere. Itās a partnership with T-Mobile to cover dead zones, and the service is expected to roll out by the end of 2023, starting with messaging and expanding to voice and data. MORE
Apple's Vision Pro headset might hit stores as early as January 2024, which means I should get ready to get in line. MORE
Microsoft believes so strongly in AI that theyāre going to put a dedicated key on Windows keyboards. Theyāre calling it a Copilot button, but I think thatāll end up getting more generalized to the assistant button. Clippy in just one click. MORE
HUMANSChina's Ministry of State Security is cracking down on military fans sharing photos of army equipment online, threatening up to seven years in prison. MORE
Suicide rates among Gen Z, particularly girls, are climbing across English-speaking countries. The data shows a worrying trend, with suicide becoming a leading cause of death for young people in these regions. MORE | MY PIECE ABOUT PURPOSELESSNESS

From After Babel
The US economy outperformed on jobs by adding 216,000 positions in December. MORE
Gallup's latest poll reveals just 28% of Americans are satisfied with democracy, a new low. The drop from 35% follows a trend across all political affiliations, with Democrats at 38%, Republicans at 17%, and Independents at 27% satisfaction. The Republican trend line is super interesting, with them starting the highest and ending the lowest. MORE | MORE
Starbucks is now letting you use your own cup for drive-thru and mobile orders to cut waste. Starting January 3, 2024, the initiative is part of their goal to slash waste by half by 2030, making them the first national coffee chain to offer this option. MORE
Most Americans still reject the Jan. 6 Capitol riot, but a CBS News poll shows Republican disapproval is slipping. Three years on, 78% of Americans condemn the insurrection, yet Republican approval has grown from 21% to 30%. 30%. MORE
š”So just to be clear, Republicans currently have 17% support for Democracy, down from 80%, and 30% support for the January 6th riot, up from 21%. I get their point about the system and the Left, being broken. But authoritarianism aināt it, my guy. Goodness.
California's courts have ruled that police drone footage isn't automatically off-limits to public records requests. The decision marks a win for transparency, as it clarifies that footage from police drones can be requested under the California Public Records Act (CPRA), rejecting the argument that all such videos are exempt due to investigative purposes. MORE
š Continue reading online to avoid the email cutoff issue š
IDEAS & ANALYSISComing for Neri Oxman
Thereās a witchhunt for Neri Oxman for some stupid reason. Business Insider wrote an āarticleā claiming she plagiarized part of her dissertation. But if you look at the actual claims, itās like forgetting some quotes for someone she had already heavily quoted and cited numerous other times in the paper. Itās complete garbage. What I donāt get is the reasoning.
Like who thinks this is helpful to anyone? One possible reason is that her husband, Bill Ackman, had gone after the Harvard president for doing actual plagiarism, so someone decided to counterattack with the full force of the media. Super gross. Canāt wait for this kind of trash to be made transparent by armies of AI research bots.
And I knowāIām like seeing AI as the solution to everythingābut there are lots of things AI wonāt help, or will make worse. But in this case, we really do need to see connections between things that are virtually opaque due to complexity. Like Iād love to instantly know the backgrounds and political leanings of everyone who writes hit pieces on a given personāof any affiliationācombined with a sequence of events in time, combined with the claims made, etc.
AI will be exceptionally good at finding possible motives and plots in such things. And itās not the type of thing that humans can do well. Itās too many threads, too many things to research, and then assemble, and then put together into a narrative. AI will do all that for us in minutes, and itāll do it continuously.
Sure, itāll also help people find connections and conspiracy in places where there is none. But thatās ok, because most other AInalisys will find that the connections are tenuous, and the conclusion is a stretch.
Anyway, these charges are crap, and Iām very tired of political takedowns of people just because they can. MORE | MY PIECE ON AI BRINGING TRANSPARENCY | GARBAGE āREPORTINGā
NOTESIām playing a lot more with local AI models lately. Lots of Ollama but also oogaboogaās web UI for Hugging Face models. Iām going to be integrating these into my AI framework/ecosystem soon. GPT-4 is still king, but lots of use cases donāt need the king.
DISCOVERYš VIM for Pentesting ā Tom Hudson, known as tomnomnom, teams up with STĆK to teach security people how to level up their command line game. This one is from like 2019 but itās still one of the best videos of its kind. | by stokfredrik | MORE
š ļø CrewAI ā A new agent framework for creating different agents in different roles, and having them interact to produce an output. Itās like Autogen, but I think I like the structure better. MORE

Defining a Writer in CrewAI
š”ļøWhiteRabbitNeo-13B ā A fine-tuned version of Llama2 that allows you to ask both offensive and defensive security questions. MORE
š„ļø asitop ā A super badass Python-based CLI tool for monitoring performance on Apple Silicon Macs, inspired by nvtop. | by tlkh | MORE

aistop output
š§ Preparing for Security Engineer Interview ā TryHackMe offers a comprehensive guide for security engineer interviews, blending general advice with technical sample questions. MORE
ā±ļøtime cat ā A super low-rent stopwatch for the command line. You run time cat and you CTRL-c when youāre done, and it tells you how long that was. lol | HT to Charlie Campbell for the tip.
š ļø github-blog ā Transform GitHub issues into a blog content management system with just an API. | by Renato RibieroĀ | MORE
š Webmention.app ā Automate sending web mentions for links on your site with this simple API. | by colindeanĀ | MORE
š± Offline Chat Private AI ā This app lets you run the powerful Mistral 7B 0.2 LLM on iPhone Pros, all without an internet connection. | MORE
Ivan Tolkunov built an AI to spot AI-generated images using a resnet-based model with FastAI on an M2 MacBook Air, hitting over 99% accuracy in testing. MORE
š© Greenphone ā Create greenscreen prompts in Midjourney for custom art placement within an image. MORE
āļø Typefully ā A tool that makes tweeting easier with smart tips and automated features. Still messing with it, but Iāve heard amazing things about this one. MORE
š Weekly Wins Planner ā A fresh template to help you organize your weekly achievements and ensure they align with your quarterly goals. It's a practical tool for staying on track. MORE
š Challenge Bowl Icebreakers ā Looking to spice up team meetings? This free Challenge Bowl icebreaker template offers a creative way to engage team members with questions and activities that build camaraderie. MORE
The Antilibrary ā A bookshelf of stuff you havenāt read yet. MORE
Potheads, Planners, and Players ā Different ways to approach projects. MORE
RECOMMENDATION OF THE WEEKRemember that goals donāt win us anything, which is why New Yearās resolutions seldom work. Itās all about the systems.
The algorithm for winning is:
Start with your goals
Build systems that will get you to those goals
Execute on the system
Another word for system is: routine. So itās not about what you want to do, or set out to do. Itās about what you actually do, day-to-day, throughout the year.
So build the ultimate system/routine for 2024. That should be the top priority. Build the routine thatāif you follow itāwill result in you accomplishing your goals for the year.
No better time to do this than early January!
APHORISM OF THE WEEKThank you for reading.
UL is a personal and strange combination of security, tech, AI, and lots of deeply human content. And because itās so diverse, itās harder for it to go as viral as something more niche.
So if you know someone weird like us, please share it with them. š«¶Ā
Share UL with someone like usā¦Yours,

Powered by beehiiv
Daniel Miessler's Blog
- Daniel Miessler's profile
- 18 followers
