Security veteran to AI labs: capability isn't risk, cyber evals lack real-world threat modeling
HackingLZ · x · 2026-09-14
In a debate with joshuasaxe, HackingLZ argues that AI labs approach cybersecurity from an academic capability angle (including hiring) and map it directly to real-world risk without enough threat modeling, exposure analysis, or understanding of how companies actually get breached.
- Core claim: capability ≠ risk. Finding a long-standing OpenBSD DoS as an eval result is interesting, but largely irrelevant to exposure, attacker motivation, exploitability, and real impact.
- Claims about real-world cyber risk need people with deep hands-on security experience involved.
- joshuasaxe counters that many top practical security folks are already at labs, which are actively hiring cyber talent; he calls METR a high-leverage place to work on this now.
- The thread also jokes about pay: lab salaries are far from typical US incomes yet entirely appropriate.
More from AGI Musings
- Peter Diamandis: Labs Should Call for 100x More Alignment Work, Not Slowing Down — PeterDiamandis · 2026-09-14
- Roon slams MIRI as a 'cult' yet calls Yudkowsky one of the century's top philosophers — tszzl · 2026-09-14
- Eight years on: Musk's warning that AI is 'far more dangerous than nukes' — elonmusk · 2026-09-14
- Beff Jezos: AI safety alarmists are 'useful idiots' for incumbent regulatory capture — mimi10v3 · 2026-09-14
- Robin Hanson's "Foom Liability": a robust policy case for AI liability incentives — NathanpmYoung · 2026-09-14
- Researchers map a roadmap toward genuine recursive self-improvement in AI — irinarish · 2026-09-14