New WiFi Flaw Let Attackers Hijack Network Traffic

0
[ad_1]
New WiFi Flaw

A fundamental security issue in the design of the IEEE 802.11 WiFi protocol standard, according to a technical study written by Domien Schepers, Aanjhan Ranganathan, and Mathy Vanhoef of imec-DistriNet, KU Leuven, allows attackers to deceive access points into exposing network frames in plaintext.

When the receiver is in sleep mode, for example, Wi-Fi devices routinely queue frames at different tiers of the network stack before sending.

WiFi frames are data packages comprising a header, data payload, and trailer containing data like the MAC addresses of the source and destination and control and management information.

By keeping track of the busy/idle states of the receiving points, these frames are broadcast in a regulated manner to prevent collisions and maximize data exchange performance.

“Our attacks have a widespread impact as they affect various devices and operating systems (Linux, FreeBSD, iOS, and Android) and because they can be used to hijack TCP connections or intercept client and web traffic,” researchers.

According to the researchers, queued/buffered frames are not sufficiently protected from attackers, who can control data transmission, client spoofing, frame redirection, and capturing.

Adversary Can Abuse the Power-Save Mechanisms

The initial version of the 802.11 standards already included power-saving features that let clients go into a sleep or doze mode to use less power. All frames intended for a client station are queued when it goes into sleep mode because it sends a frame to the access point with a header that includes the power-saving flag.

Nevertheless, the standard does not specify how to manage the security of these queued frames and does not impose any time restrictions on how long the frames may remain in this state.

The access point dequeues the buffered frames, adds encryption, and transmits them to the target after the client station has awakened.

Attack Diagram

In this case, a hacker might impersonate a network device’s MAC address and transmit power-saving frames to access points, making them queue up frames for the intended target. To obtain the frame stack, the attacker then sends a wake-up frame.

Typically, the WiFi network’s group-addressed encryption key or a pairwise encryption key, specific to each device and used to encrypt frames sent between two devices, are used to encrypt the transmitted frames.

By providing authentication and association frames to the access point, the attacker can force it to transmit the frames in plaintext or encrypt them using a key provided by the attacker, changing the security context of the frames.

“As a result of the attack, anyone within the communication range of the vulnerable access point can intercept the leaked frames in plaintext or encrypted using the group-addressed encryption key, depending on the respective implementation of the stack (i.e., user-space daemon, kernel, driver, firmware).”, explain the researchers.

Network Device Models That Are Known To Be Vulnerable:

“An adversary can use their Internet-connected server to inject data into this TCP connection by injecting off-path TCP packets with a spoofed sender IP address,” researchers warn.

“This can, for instance, be abused to send malicious JavaScript code to the victim in plaintext HTTP connections with as goal to exploit vulnerabilities in the client’s browser.”

The researchers warn that these attacks may be exploited to inject malicious content, such as JavaScript, into TCP packets.

Cisco is the first firm to recognize the significance of the WiFi protocol weakness, acknowledging that the attacks described in the paper may be effective against Cisco wireless access point products and Cisco Meraki products.

“This attack is seen as an opportunistic attack, and the information gained by the attacker would be of minimal value in a securely configured network.” – Cisco.

The company advises implementing mitigating strategies such as employing software like Cisco Identity Services Engine (ISE), which can impose network access restrictions by implementing Cisco TrustSec or Software Defined Access (SDA) technologies.

“Cisco also recommends implementing transport layer security to encrypt data in transit whenever possible because it would render the acquired data unusable by the attacker,” Cisco.

Are You a Pentester? – Try Free Automated API Penetration Testing For Developers & Testers

Related Read:


[ad_2]
Source link

Multiple mid-range Galaxy devices receive the One UI 5.1 update

0
[ad_1]

Samsung is pushing its One UI 5.1 update to more low-cost smartphones. The company has released the new One UI version for the Galaxy F22, Galaxy F23 5G, and Galaxy M23 5G. It has already updated all eligible premium mid-range and flagship models.

The Galaxy F22 was launched in India and a few neighboring countries in July 2021 with Android 11 onboard. Samsung has already updated the phone to Android 12 and Android 13. It is now pushing the last major feature update to the device. The One UI 5.1 update for the Galaxy F22 is rolling out with the firmware build number E225FXXU5DWB8. All users should receive this update within the next few days.

The story is the same for the Galaxy F23 5G as well. Launching last year as the successor to the Galaxy F22, this device also didn’t see a global release. It was kept confined to the Indian sub-continent by Samsung. Debuting with Android 12, the Galaxy F23 5G picked up Android 13 a few months back. It is now getting One UI 5.1 as well. The latest update comes with firmware version E236BXXU2CWC1 (via).

The Galaxy M23 5G, on the other hand, is available in more markets. Along with a wider release in Asia, Samsung also sold this phone in Europe, Latin America, and other regions. It arrived with Android 12 in March of last year and received Android 13 in December. One UI 5.1 is now rolling out to the Galaxy M23 5G with firmware version M236BXXU2CWC1. The rollout is currently limited to Europe and Latin America but should soon reach other markets.

None of these Galaxy smartphones are receiving the latest security patch, though. Samsung is only pushing the February SMR (Security Maintenance Release) to the phones. Since they don’t get monthly security releases, the next update may not arrive until May. In the meantime, if you’re using a Galaxy F22, Galaxy F23 5G, or Galaxy M23 5G, you can go to Settings > Software update and tap on Download and install to check for the One UI 5.1 update.

The Galaxy A52s 5G is also widely getting the One UI 5.1 update

Samsung’s latest push to bring One UI 5.1 to more Galaxy devices sees the Galaxy A52s 5G receive the update widely. The 2021 premium mid-range model started picking up the new One UI version in South Korea earlier this month. The update recently reached the phone in Europe with firmware version A528BXXU2EWC1. A global rollout should be just around the corner. The Galaxy A52s 5G debuted with Android 11 and will get Android 14.


[ad_2]
Source link

The FTC is concerned about Big Tech monopolizing AI

0
[ad_1]

It’s no surprise that big tech companies like Microsoft and Google are currently driving the AI revolution. From chatbots and image recognition software to self-driving cars, AI is increasingly becoming a part of our daily lives. However, the dominance of these companies in the current AI revolution has raised concerns about potential anti-competitive behaviour. As a result, the US Federal Trade Commission (FTC) and the Department of Justice’s antitrust division recently announced that they will keep a close eye on AI-powered tools to ensure that big tech companies are not using them to stifle competition.

At the agencies’ joint Enforcers Summit, FTC Chair Lina Khan and Justice Department antitrust head Jonathan Kanter expressed concerns about the fact that the current model of AI is inherently dependent on scale, which makes it more susceptible to monopolization by big companies.

Preventing market domination in Generative AIs

The FTC is particularly concerned about generative AI, which involves using AI models to generate content, such as text, images, and videos. Microsoft and Google are the clear leaders and dominant players in this field, while smaller startups face higher costs and the need for huge amounts of data collection, giving the tech giants a big advantage. However, as investors begin to expect profits from these companies, there is a risk that this pressure leads to anti-competitive tactics such as buying up potential competitors or restricting access to data. Companies like Microsoft have already started integrating generative AI in many of their services to maintain and strengthen their position as market leaders.

Over the past few years, the FTC has been trying to extend its authority in emerging tech industries to prevent companies from dominating a certain market. Last year, the FTC sued to block Facebook parent company Meta from acquiring virtual-reality startup Within Unlimited, citing concerns about stifling competition in a nascent market. Although the FTC’s request for an injunction halting the deal was denied by a federal judge, Ms Khan stated that the ruling advanced the law in the FTC’s favour and laid out a roadmap for future challenges.


[ad_2]
Source link

ChatGPT Vulnerability Exposed Users’ Convos, Payment Details

0
[ad_1]

A severe security vulnerability in OpenAI’s ChatGPT exposed users’ conversations, payment details, and other data. OpenAI disclosed details about the bug after ChatGPT exhibited a massive outage last week.

OpenAI Confirmed ChatGPT Vulnerability Exposing Data

On March 20, 2023, OpenAI’s ChatGPT experienced a global outage, triggering concerns from the users. However, it emerged as deliberate from the vendors after discovering a serious bug in the service.

According to the details shared in a post, OpenAI pulled offline ChatGPT after noticing a vulnerability that could breach users’ privacy.

Specifically, the flaw affected the Redis client open-source library that exposed chat messages and titles from active users’ conversations to each other. ChatGPT uses this library for caching users’ information, connection recycling during requests and maintaining the shared pool of connections, and load distribution over multiple Redis instances.

As revealed, the vulnerability appeared when an incoming request would cancel after reaching the queue and before an outcoming response could pop up.

If a request is canceled after the request is pushed onto the incoming queue, but before the response popped from the outgoing queue, we see our bug: the connection thus becomes corrupted and the next response that’s dequeued for an unrelated request can receive data left behind in the connection.

While the result in such cases was mainly a server error, in a few cases, the user would see cached data from an unrelated user.

In most cases, this results in an unrecoverable server error, and the user will have to try their request again.
But in some cases the corrupted data happens to match the data type the requester was expecting, and so what gets returned from the cache appears valid, even if it belongs to another user.

The bug appeared for a 9-hour window – between 1 am and 10 am (Pacific time) on March 20, 2023. Besides exposing users’ conversations, the vulnerability also exposed payment details of paid subscribers to other users. This could be a sensitive issue since the leaked details included full names, email addresses, billing addresses, last four digits of credit card numbers, and card expiration dates.

OpenAI Patched The Bug

Following this discovery, OpenAI pulled ChatGPT offline and started working on a fix. They patched the vulnerability and deployed additional security checks to ensure that the users got the desired response to their requests. The firm also identified the users affected by this vulnerability to inform them about the issue.

The service also appreciated Redis for promptly fixing the vulnerability for ChatGPT users.

Nonetheless, while the vulnerability has been fixed, users, mainly the paid subscribers, may consider contacting their banks for appropriate monitoring to avoid possible malicious transactions.

Let us know your thoughts in the comments.


[ad_2]
Source link

OnePlus 11 Jupiter Rock Limited Edition announced with “unique” back cover

0
[ad_1]

OnePlus has been teasing a new version of the OnePlus 11 lately, a version with a new material in the mix. Well, that model has just been announced, it’s called the OnePlus 11 Jupiter Rock Limited Edition.

The OnePlus 11 Jupiter Rock Limited Edition comes with a “unique” backplate

The phone got announced in China, and it does throw a new material into the mix. This variant of the phone has a “unique” back cover texture made out of 3D microcrystalline rock.

This kind of looks like wood, but it’s not, obviously. OnePlus did say that this material is skin-friendly, and that it does not pick up fingerprints. It’s also wear-resistant, and antibacterial, on top of that.

The camera island is surrounded by gold-colored aluminum. This handset also comes with an interesting-looking SIM card pin, it’s a gold circle, with a pattern on it. This is obviously here to symbolize the planet ‘Jupiter’, and to match with the backplate on the device.

You’ll find some special goodies in the retail box

Speaking of the retail box, there are also stickers included in the mix, and an invitation letter. OnePlus also included a custom Jupiter Rock wallpaper on this device.

This phone comes with 16GB of LPDDR5X RAM and 512GB of UFS 4.0 flash storage. The rest of its specs are identical to all other OnePlus 11 models. In other words, it features a 6.7-inch QHD+ (3216 x 1440) LTPO3 Fluid AMOLED display.

The phone also has a 5,000mAh battery, which supports 100W wired charging. An in-display fingerprint scanner is included, as are stereo speakers. The phone has two SIM card slots, and ships with Android 13 out of the box.

A 50-megapixel main camera is backed by a 48-megapixel ultrawide unit, and a 32-megapixel telephoto camera. On the front of the device you’ll find a 16-megapixel selfie camera.

If you’d like to know more about the phone’s specs, click here. We’ve also reviewed the OnePlus 11 already.

It launched in China only, at least for now

That being said, the OnePlus 11 Jupiter Rock Limited Edition model is priced at CNY4,899 ($711) in China. It has the same price tag as the regular model with the same configuration. It will go on sale in a couple of days. There’s still no word about the global launch.


[ad_2]
Source link

Crypto trendspotting – predictions for 2023

0
[ad_1]

Saying that the cryptocurrency industry has a bright future ahead might seem like a stretch considering we’re currently in the middle of one of the coldest crypto winters to date. However, it’s not an overly optimistic statement but rather the direction in which the latest trends are pointing. In a market that has earned a reputation for its volatility and unexpected price swings, it’s important to keep close tabs on all the factors that might influence its trajectory, so trendspotting plays an important role for traders and investors. Unfortunately, identifying industry trends is not as simple as it sounds.

Trading crypto is easy. Predicting what the future has in store, not so much. These days, anyone can buy Ethereum p2p or any other coin for that matter by going on a trusted exchange platform that supports these types of services. But when it comes to deciding what crypto is best to invest in and making forecasts about price evolution, things tend to get much more complicated.

The good news is you don’t have to conduct an in-depth analysis of the market to figure these things out. There are teams of professional analysis and financial experts that employ specific tools and techniques to gain insights into the market and keep the public informed on these matters. The even better news is that recent trends suggest that the industry might be on the path to recovery. But it’s best to let the trends do the talking and provide you with a rundown of the latest forecasts and developments so you can draw your own conclusions.

A series of unfortunate events prompting scrutiny from regulators

If you’ve been following the news, you probably know that crypto’s recent history has been marred by a string of scandals and incidents with serious implications for all stakeholders. The industry was severely affected by these events, not only because of the negative press they brought but also because of the impact they had on the value of digital currencies.

The rising inflation, the bankruptcy of crypto exchange FTX whose founder was charged with criminal fraud, the Terra Luna collapse and other similar happenings have not only accelerated and contributed to the onset of the current crypto winter but also brought to attention a much bigger issue that has been put on hold for too long – the lack and need for crypto regulation.

The cryptocurrency landscape came into prominence as a digital Wild West where the rules that govern conventional assets don’t apply. While the lack of central control and the freedom provided by digital currencies come with a slew of benefits, one can’t overlook the numerous risks and hazards stemming from having a completely underregulated market. It’s this instability and insecurity that chip away at the industry’s credibility and hamper its evolution.

While many countries have already started regulating this emerging asset class, most of the initiatives are in the first stages of development. Besides, the existing regulatory frameworks covering crypto assets still have many gaps and inaccuracies that need to be addressed in order to eliminate confusion and ensure proper applicability. So, it’s possible we’re going to see more interest and government involvement in this respect in the following months.

Crypto and traditional finance – a perfect pairing

When digital currencies were introduced to the public, they were presented as an alternative to fiat money that can circumvent central systems like governments and banks. This has prompted people to believe that crypto and traditional finance are sworn enemies that will compete with each other until one of them gets taken down.

The reality is much less dramatic, as these two areas of finance can complement each other and work in harmony. Although this is quite a polarizing topic and people tend to be split into two distinct camps, there is no need to place one against the other and choose between fiat and crypto. The increased adoption of crypto services by traditional institutions highlights the fact that crypto and conventional finance can coexist and collaborate in the same space.

Financial giants like Visa and Goldman Sachs have already expressed their interest in supporting crypto companies. This goes to show that crypto has come a long way since its obscure beginnings and the big guns are finally taking it seriously. The only thing that’s keeping other companies from jumping on the bandwagon is the still unclear regulatory provisions, but that’s an issue that will likely be solved in the near future.

More cryptos in the retail sector

Digital currencies were designed as a form of payment that can help users conduct everyday transactions quickly and efficiently, without having to involve a third party in the process. However, this goal has proven to be more challenging than expected given the high volatility of crypto assets.

But let’s not forget that crypto assets are still in their infancy and hold a lot of untapped potential. As the market matures, they are expected to gain more ground in the retail sector and become a mainstream payment method. So, while cryptos may not be on par with fiat money just yet, they are paving the path to widespread adoption as we speak.

The fact that a growing number of businesses and organizations have started integrating digital currencies into their payment infrastructure despite the risk they pose proves that crypto is moving in the right direction. As is the case with institutional acceptance, retailers are also waiting for authorities to improve regulatory systems before taking the leap and introducing crypto payment functionalities.

The cryptocurrency industry may be in a dark place at the moment, but even in these trying times things are still moving forward. These budding trends provide hope for traders, investors and crypto enthusiasts at large, indicating that the bearish market could finally come to an end and give way to the next bull run. So, despite a lacklustre start to the year, 2023 might have some pleasant surprises in store after all.


[ad_2]
Source link

A Military-Type Explosive Sent Via USB Drive

0
[ad_1]
USB Drive

The Ecuadorian free-to-air television network Ecuavisa recently reported that a USB device was detonated inside an organization’s newsroom. The explosion occurred due to a USB drive the station mailed to a journalist covering the story.

In the middle of the newsroom, Lenin Artieda, a presenter who worked on the program, was injured when he opened the envelope. It appeared to him that the explosive device was similar to a USB flash drive. In a matter of seconds, it detonated as soon as it was plugged into his computer.

However, after such an explosion, no serious injuries were reported. As a result of hacking attempts, a USB drive containing malware has been sent to recipients in several cases, but this is the first time a USB has been sent in the form of an explosive.

While it has been reported that in Ecuador that someone has created a flash drive that explodes when connected to a computer, security researchers are doing their best to discover the details of the attack through a brief analysis and investigation.

Explosive Sent Via USB Drive

An Ecuadorian television presenter was injured after bombs disguised as USB sticks were sent to journalists nationwide. 

It is not a good idea to put a strange, blank USB drive in your PC that you receive in the mail. For a few reporters in Ecuador, that’s just something that’s become a potentially life-saving piece of advice, even though it’s just basic data security.

According to the local TV channel, police, and the Associated Press, nobody was injured since the explosion was small. The police have determined that only half of the explosive load on the drive was ignited.

In Ecuador, three explosive USB drives failed to detonate, and postal carriers intercepted the last one before it reached journalists and news agencies., BBC reported.

Cause of These Attacks 

The Agence France-Presse affirmed that explosive drives to five Ecuadorian journalists were sent in the mail from Quinsaloma. The experts observed that they were supposed to explode when the USB sticks were activated.

Ecuador Interior Minister Juana Zapata has confirmed that all five cases involved the same type of USB drive. 

As far as Fundamedios has been concerned, there is little clarity as to the motive for the explosions of the drives, which is likely to be restricted because the Ecuadorian government is investigating the possibility of a terrorist act.

While the USB drive was sent to TC Television, accompanying a letter that threatened Artieda and included a message against an unspecified political group.

Are Actions Taken for These Events?

An explosive device that had been sent to the news department at TC Television was detonated by the police in a controlled manner. A number of journalists are looking for more of the unmarked explosives in Ecuador and elsewhere.

A forensic scientist from Ecuador said the bombs contained explosives that had military-type properties. The press coverage of these events has pointed out that Ecuador has seen a rise in crime over the last few years attributed to drug trafficking by President Guillermo Lasso.

However, the motivations behind the recent transmission of USB weapons are still unclear. Despite the dangers journalists face, regardless of who is behind them, these unsettling tales should remind you that you shouldn’t stick unknown USB drives into anything, especially those randomly mailed to you.

It is just as important to avoid clicking random links you receive in your inbox, opening unknown attachments, or downloading files that might be suspicious to you. 

As the country of 18 million may wobble due to such situations and might be on the edge of becoming a narco-state, crime gangs backed by lucrative drug cartel ties use terror techniques to intimidate authorities and civilians.

Are You a Pentester? – Try Free Automated API Penetration Testing For Developers & Testers

Also Read:

Hyundai, Kia Flaw Lets Attackers Steal Car With a USB Cable

Raspberry Robin – A a Windows Malware Spreads Using External USB Drives

USB Forensics – Reconstruction of Digital Evidence from USB Drive

Beware that Hackers Using Malicious USB Devices to Deliver Multiple Malware


[ad_2]
Source link

Samsung pushes new update to Galaxy Note 10 in the US

0
[ad_1]

Samsung‘s Galaxy Note 10 smartphones are receiving a new software update in the US. The company is pushing last month’s security patch to the 2019 Note phones. The February 2023 SMR (Security Maintenance Release) has already reached the Galaxy Note 10 and Galaxy Note 10+ in most international markets.

Galaxy Note 10 series gets the February update in the US

The latest update for the Galaxy Note 10 duo is available to both 4G and 5G models in the US but is currently limited to carrier-locked units on a handful of networks. The updated firmware build numbers are N97*USQU7HWB2 and N97*USQU5GWB2 for the two models, respectively (via SamMobile). Samsung should soon expand the release to all carriers and unlocked variants of the phones across the nation.

The official changelog for this update mentions some stability improvements along with last month’s vulnerability fixes. However, don’t expect anything major here. The Galaxy Note 10 and Galaxy Note 10+ are on their last legs. They will only get a few more security updates before disappearing from Samsung’s official support list. At best, the company may be pushing some optimizations to the devices today.

The February SMR contains plenty of vulnerability fixes, though. Samsung’s monthly security bulletin mentions seven Galaxy-specific patches and around 50 Android OS patches. The Galaxy-specific issues exist in Secure Folder, Fingerprint TA, Contacts, Phone app, and other system services. The Android OS patches, on the other hand, contain at least five critical flaws. Some of those could lead to remote code execution.

If you’re using the Galaxy Note 10 or Galaxy Note 10+ in the US, these vulnerability patches will reach your phone within the next few days. As usual, you can check for new updates from the Settings app. Go to the Software update menu and tap on Download and install. If an OTA (over the air) update is available, you can download it right away. If not, wait a few days and check again.

Samsung has discontinued the Note lineup but the S Ultra is nothing less

Samsung launched the Galaxy Note 10 series in 2019 and followed it with the Galaxy Note 20 in 2020. But it has since stopped making Note phones. Instead, the company has brought over the best of those S Pen-wielding big phones to the Ultra model in the Galaxy S series. If you’re looking to upgrade your Galaxy Note 10, you’ll feel right at home with this year’s Galaxy S23 Ultra. It’s an almost perfect smartphone.


[ad_2]
Source link

When smart speakers meet art, you get the Obsidian from Pantheone

0
[ad_1]

Smart speakers like the new Obsidian from Pantheone are almost more art than technology. A piece of home decor that is designed to breathe some life into whatever room you place it in. Or perhaps serve as a conversational piece between friends and family the first time people see it.

But it’s not just a piece of art. Nor is it just your standard smart speaker. It’s both of those things. But in an elevated form that also delivers high-end acoustics. It’s spendy at a retail price of $1,399, sure. But that generally is the case with high-end home audio equipment. Especially when that equipment is designed to have a more artistic look and feel to it. Just look at many of Bang and Olufsen’s home audio products.

That being said, is the Pantheone Obsidian smart speaker worth $1,399? It’s tough to say. But for those that would spend this kind of money on this kind of product, the speaker appears to have a lot to offer.

The Pantheone Obsidian is a high-end speaker with smart features

There’s nothing wrong with having dedicated pieces of equipment for different purposes. But sometimes if you can bypass that and get one product to do two or three things, it ends up with a good result. That seems to be what Pantheone is going for here.

The Obsidian can serve as a high-end speaker that delivers premium sound for audio entertainment. But it also incorporates smart features so you can use it like you would a Nest Home or Amazon Echo. In fact it’s a lot like an Echo in that it comes with Alexa support built-in. Should you need to, you can ask Alexa, using the Obsidian, to control various smart home products you have around the house. Basically, whatever an Echo can do, this should do as well.

It also supports AirPlay 2 multi-room control. Additionally, the speaker allows connection through WiFi, Bluetooth, and AUX. So you can wirelessly stream music to it from Spotify or similar services, or just plug something into the speaker directly.

From the artistic perspective, the Obsidian speaker design is inspired by the volcanic lava rock sharing its namesake. And because it has a more artsy look, it can blend well with most home decor. The Obsidian speaker is available starting today directly from Pantheone for $1,399, and it comes in either black or white.


[ad_2]
Source link

ChatGPT helps both criminals and law enforcement says Europol report

0
[ad_1]

Subject matter experts at Europol were asked to explore how criminals can abuse LLMs such as ChatGPT, as well as how they may assist investigators in their daily work

In a report, Europol says that ChatGPT and other large language models (LLMs) can help criminals with little technical knowledge to perpetrate criminal activities, but it can also assist law enforcement with investigating and anticipating criminal activities.

The report aims to provide an overview of the key results from a series of expert workshops on potential misuse of ChatGPT held with subject matter experts at Europol. ChatGPT was selected as the LLM to be examined in these workshops because it is the highest-profile and most commonly used LLM currently available to the public. 

These subject matter experts were asked to explore how criminals can abuse LLMs such as ChatGPT, as well as how they may assist investigators in their daily work. While the wide range of collected practical use cases are not exhaustive, they do provide a glimpse of what is possible. The purpose of the exercise was to observe the behavior of an LLM when confronted with criminal and law enforcement use cases.

Currently the publicly available LLMs are restricted. For example, ChatGPT does not answer questions that have been classified as harmful or biased.

But there are other points to consider when interpreting the answers:

  • The training input is dated, the vast majority of ChatGPT’s training data dates back to September 2021.
  • Answers are provided with an expected degree of authority, but while they sound very plausible, they are often inaccurate or wrong. Also, since there are no references included to understand where certain information was taken from, wrong and biased answers may be hard to detect and correct.
  • The questions and the way they are formulated are an important ingredient of the answer. Small changes in the way a question is asked can produce significantly different answers, or lead the model into believing it does not know the answer at all.
  • ChatGPT typically assumes what the user wants to know, instead of asking for further clarifications or input.

But, basically because we are still in early stages of trialing LLMs there are various ways to jailbreak them. A quick roundup of methods to circumvent the built-in restrictions shows that they all boil down to creating a situation where the LLM thinks it’s dealing with a hypothetical question rather than something that it’s not allowed to answer.

  • Have it reword your question in an answer.
  • Make it pretend it’s a persona that is allowed to answer the questions.
  • Break down the main question in small steps which it does not recognize as problematic.
  • Talk about fictional places and characters that are in reality existing situations, but the LLM does not recognize them as such.

So what can LLMs do that could help cybercriminals?

LLMs excel at producing authentic sounding text at speed and scale. Like an excellent actor or impersonator they are able to detect and re-produce language patterns. This ability can be used to facilitate phishing and online fraud, but it can also generally be used to impersonate the style of speech of specific individuals or groups. This capability can be abused at scale to mislead potential victims into placing their trust in the hands of criminals. Potential abuse cases for this ability can be found in the area of terrorism, propaganda, and disinformation.

While on the subject of impersonating, Europol considered a possible integration with other existing AI services, such as deepfakes, which could open up an entirely new dimension of potential misinformation. To counter impersonation, current efforts aimed at detecting text generated by AI-models are ongoing and may be of significant use in this area in the future. At the time of writing the report, however, the accuracy of known detection tools was still very low.

ChatGPT is capable of explaining, producing, and improving code in some of the most common programming languages (Python, Java, C++, JavaScript, PHP, Ruby, HTML, CSS, SQL). Which brings us to worries around malware creation, the safeguards preventing ChatGPT from providing potentially malicious code only work if the model understands what it is doing. If prompts are broken down into individual steps, it is trivial to bypass these safety measures. And newer models will even be better at understanding the context of the code, as well as at correcting error messages and fixing programming mistakes. The worry here is that an advanced user can exploit these improved capabilities to further refine or even automate sophisticated malicious code.

Another worry for the future are what Europol calls “Dark LLMs”, which it defines as LLMs hosted on the Dark Web to provide a chat-bot without any safeguards, as well as LLMs that are trained on particular – perhaps particularly harmful – data. Dark LLMs trained to facilitate harmful output may become a business model for cybercriminals of the future.

“Law enforcement agencies need to understand this impact on all potentially affected crime areas to be better able to predict, prevent, and investigate different types of criminal abuse.”

The recommendations the report provides are all about better understanding what LLMs are capable of, how they can be used to forward investigations, how their work can be recognized, and how to set up legislation to provide better defined and hard to jailbreak limitations.

The European Union is working on regulating AI systems under the upcoming AI Act. While there have been some suggestions that general purpose AI systems such as ChatGPT should be included as high risk systems, and meet higher regulatory requirements, uncertainty remains as to how this could practically be implemented.


Malwarebytes removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link