•••••••••
Just to be absolutely clear, the giant OpenAI math dump replaces two (2) already efficient probabilistic algorithms with deterministic ones. Neither affects encryption as it is deployed today (one is a quantum algorithm, and the other is factorization over prime fields). I think it's fair to say that in the last month we have learned 0 things that would specifically confirm or disconfirm this stated view, either directly or indirectly. And that is not really Matthew's concern, anyway. His actual concern is that computers are really good at math, and if we point them at something like Module LWE or ECDLP there is a real chance that it (essentially magically) breaks them. See his statement at [1]. For better and for worse I think we are in a crisis of empiricism. As a community we are worried enough about the outcomes of breaking something like encryption that we're willing to admit statements like this one, even though we have no real, actual, concrete evidence that would indicate whether they're true or not. The line of thought Matthew articulates here ( i.e. , we can solve millennium problems thus "optimism [related to encryption] is a very opinionated bet") may be defensible from a risk management perspective, but it is absolutely not defensible as a statement of knowledge. Internally that's fine, but the public (including the technical public) is not going to make that distinction. They will interpret it as knowledge. That does not help us. [1]: https://x.com/matthew_d_green/status/2108281944291393983
•••••
Later in the linked Twitter thread: https://twitter.com/matthew_d_green/status/2108282817343824147 > So what does “losing public-key [encryption]” mean? It does not mean cryptography or encryption is impossible, or that we live in Minicrypt. It does mean that we imminently see new cryptanalytic results that substantially improve our ability to attack standardized schemes. > The more modest effect of this would be that several schemes we’d previously agreed were “good enough” (128 bit security level) aren’t. Maybe they’re 96-bit or 108-bit secure. > In any case, honest standards bodies have to step back and deprecate at least those smaller parameter sets , which are already deployed in some live systems. But in principle, we can usually just crank up parameter sizes. Right? > But crank them up to what? Right now we’re saying we have the right numbers, because humans spent 40 years (or 25 years) studying these assumptions. If suddenly it turns out we were off by 26 bits, that’s obviously not something we can lean on. > So then, we could lean on the fact that the machines now say they’re stuck — the assumptions at the new numbers seem pretty robust, and no lab is able to make further progress. > How do you feel about that? I don’t feel great about it. I think nobody will feel good about it. > And what happens if we tentatively agree to trust that progress has stalled, and then some new internal model makes another step-change jump? We could end up losing trust in these assumptions at any security level except for painfully high ones. > So again I’m not saying that any of this will happen. What I am saying is that I would be very surprised and pleased to find out that human cryptanalysis (of the non-classified form) handled by a couple of dozen people, turned out to be the best we could ever do.
••••
it's speculation about behavior. and it's grounded in a very real truth, that law enforcement in many nations has not been impeded by security / cryptography: they've had the means to break it, route around it. the assertion that this is changing feels imminently clear. what happens is anyone's guess. (those who know certainly aren't gonna talk to us plebe public about it, haha yeah never.) but generally i think governments have been very much on the warpath to grab control, adding age (and thus identity) verification to basically all websites, and otherwise doing all they can to increase their ability to dragnet the internet and monitor it. your accusation that it's conspiracy nonsense does indeed some what check out with me. i'm a fan of not going glonzo. i'm a fan of keeping our head and being realistic. it might not go so bad. but also: these people have done nothing to earn the public's trust. their attempts to make the internet bad and un-private have dragged on for decades, and they lose and they lose and they lose. but eventually they get a shot through. they get lucky and it gets worse. there's been very little ratchet the other way, just a general ratchet of loss and woe for the public, for privacy, for electronic freedom frontiers. the governments have not played nice at all, have demonstrated no interest in listening to the public, have disregarded all advocacy, and keep passing bad no good very bad laws, trying with persistence until eventually they find a chink in the armor. so yes this is a glonzo theory. somewhat. i somewhat agree. but looking at who we are looking against, how things have gone, well: it seems all too realistic. as for "usual paranoid corners of the internet" i think you are completely fucking off base out of your mind. this is from someone very respected very in the know and very good and very serious and you're just some shithrower with nothing to say. this kind of vacuous uncontestable low grade bullshit can go piss right the fuck off.
•••
Ok I'm here for the same arguing as y'all are (namely: seems both unenforceable and completely against the FLOSS ethos, and adding a clause by hand is more like a sign than a rule in practice) but that's all less interesting than the 'moral rights' he bases this all on philosophically -- or, in less dramatic terms, non-economic intellectual property rights. These would be completely separate from any "license" changes, but it's still interesting. For one thing, the United States has it but it only applies to the kinds of things a 6y/o says when asked "what is art?" which is pretty funny (paintings, drawings, sculptures, photographs), and would exclude David's work. I wonder if he's been webcomicing long enough to remember the days when drawing tablets were a violation of the sacred... For another, "I assert my rights" sounds like some SovCit tomfoolery like we have in the ~Commonwealth, but is indeed a thing! Pretty funny as well, I think. More relevantly, these 'moral' rights (ugh) seem to... well, I'll just link France's insanely nice statute site: https://www.legifrance.gouv.fr/codes/section_lc/LEGITEXT000006069414/LEGISCTA000006161636/1992-07-03?page=2&pageSize=25&query=%22L121-1%22 (Article L121-6 of the Intellectual Property Code). The relevant clause is the first: > L'auteur jouit du droit au respect de son nom, de sa qualité et de son oeuvre. > ~=> The author has the right to respectful, accurate attribution (both name and role), and the right to respectful treatment of their work (both physically and in spirit). I wasted a bunch of time on this but in the end it's simple, and explained pretty definitively by a recent case about fine art depicting Tintin: A) characters and vague story elements are indeed covered, and B) the Tintin usage was illegal because it had women in it, which the author explicitly disavowed (which: ???). If David explicitly tells people that AI art makes him mad, that seems to be enough to get the state to punish anyone who uses it. There are carve-outs for parody and use among a "family circle", but they're superceeded in turn by a clause on the author's "legitimate interests". Unless that has some special french meaning (e.g. only economic?), this is all down to "does a French judge think AI is legitimately hated." Given the vibes I'm getting from the precedents, that seems very, very likely. (They tried to pass a law once to make that official, but it failed in the EU -- will surely try again soon, with the Pope's support) TL;DR: David's almost definitely correctly understanding the law here. That's... that's wild. Honestly sucks to know that even my #1 emmigration dream is so thoroughly infested with intellectual property laws :(
•••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
 Top