‹ BackHN Continuity

Thread

Nvidia wants to put a watchdog chip next to every AI agent

230 points · 299 comments · jonbaer

  1. cedws · · focus · HN ↗
    A new chip solves nothing. Nobody wants to hear this but there is no solution for the security risks posed by agents today. You can put it in a sandbox, it doesn't make a difference, for it to be useful it inherently needs wide, unattended access. Put a human in the loop and you just end up bottlenecking it and throwing away any purported productivity gains. Auto mode doesn't matter either, it's trivial to trick and for the agent to break out.
    1. johnsmith1840 · · focus · HN ↗
      "Inherently needs wide unattended access"

      And what if you could? What if you could give a space secure enough it could have direct control over your bank account. It may do something dumb but it's boundaries are beyond the agent.

      It could use your routing number and run your gmail without risk of abusing the routing number.

      1. jagraff · · focus · HN ↗
        How would it have access to my routing number and gmail without the risk of sharing my routing number over gmail?
        1. johnsmith1840 · · focus · HN ↗
          Just assume it's possible, how interesting is it to you?
          1. jagraff · · focus · HN ↗
            Oh I think I misread your comment slightly; I would not be interested in an agent that could do something dumb with my routing number, but if somehow there was an agent that I trusted as much as, eg, the payroll department at my employer, I would absolutely want and use that agent; I would love to have an agent that can handle all of the boring parts of my life such as paying bills, scheduling maintenance, dealing with bureaucracy, etc.
            1. johnsmith1840 · · focus · HN ↗
              Dumb's not department, really just a question of how good an AI you want to use. An AI will always be able to do something dumb, just like people.

              I just mean an AI that could use a routing number or SSN and gmail/slack/whatever at the same time without a leak.

              1. jagraff · · focus · HN ↗
                Yea I think being able not to leak is the bare minimum? But it really depends on how good it is at specific applications; I wouldn't give a tax-preparation agent my SSN unless I was confident that it was no more likely to misfile my taxes than a professional tax preparer.

                In other words, the risk of harm doesn't need to be zero, just less than the equivalent risk of a human with similar skillset. So I'm comfortable riding in a waymo, and not comfortable giving chatgpt my SSN at this moment in time, but I expect that within 5-10 years (assuming no doom) I will trust some AI agent with my SSN because they will be better at handling sensitive info than humans

                1. lelanthran · · focus · HN ↗
                  The problem is not one of intelligence, it's one of consequences.

                  Humans face negative consequences for mishandling your data, LLMs face none.

                  1. Ukv · · focus · HN ↗
                    I feel punishment is largely a means to the end of reducing overall harm. If a vehicle is less likely to kill me, that's my preferred option regardless of whether it achieved that safety through negative consequences for the driver or through gradient descent optimizing a loss function.
                  2. jagraff · · focus · HN ↗
                    I will happily ride in a waymo today, even though the AI powering it faces no consequence if it gets in a crash; it is clear that waymo is safer than human drivers in the areas in which they operate, so who would technically be liable in the event of a crash isn't really of concern to me
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.