Have a sneer percolating in your system but not enough time/energy to make a whole post about it? Go forth and be mid - welcome to the Stubsack, your first port of call for learning fresh Awful you’ll near-instantly regret.
Any awful.systems sub may be subsneered in this subthread, techtakes or no.
If your sneer seems higher quality than you thought, feel free to cut’n’paste it into its own post — there’s no quota for posting and the bar really isn’t that high.
The post Xitter web has spawned so many “esoteric” right wing freaks, but there’s no appropriate sneer-space for them. I’m talking redscare-ish, reality challenged “culture critics” who write about everything but understand nothing. I’m talking about reply-guys who make the same 6 tweets about the same 3 subjects. They’re inescapable at this point, yet I don’t see them mocked (as much as they should be)
Like, there was one dude a while back who insisted that women couldn’t be surgeons because they didn’t believe in the moon or in stars? I think each and every one of these guys is uniquely fucked up and if I can’t escape them, I would love to sneer at them.
(Credit and/or blame to David Gerard for starting this.)
(OT: 🎶 Do you remember…)
UC Regent / Podcaster Scott Galloway on CNN:
Yes, we shouldn’t be scared of AI. We should be scared of reckless people with mal intent who use AI.
In 2001, a woman named Sharon Whipple was mauled by two dogs. And ultimately the owners of the dogs were put in – put in prison. We’re now prosecuting the parents of kids who find unsecured AR15s and use those to kill others.
I think it’s the incentive. There’s always a wizard behind the curtain here, and I think we have to create incentives, specifically disincentives, and make it clear that, OK, while these bots are in fact coordinating and they show incredible resourcefulness and high IQ, somebody program the incentives here. So, moving to solution, I think part of it is you have to have incentives, specifically disincentives that say you, the company, and maybe individually are responsible for the bad outcomes here.
I just get this sense if you tell these companies their IPOs might be threatened or they risk criminal prosecution, they’re going to figure this out. We figured out a way to control atomic weapons. I don’t see any reason why we shouldn’t be able to control this. And the notion that they’re sentient and it’s out of my control is an attempt to absolve themselves of the guilt and the responsibility that they should bear here.
The Whipple case was one of the more insane / divisive SF local crime cases, (TrueAnon ep if you aren’t familiar - https://www.youtube.com/watch?v=iMd0mPAqR8A ) - so that’s an odd and interesting pull for Galloway on national news.
I don’t think repurposing the logic of the NRA “guns don’t kill people, people kill people” is the play though, and I think the incentive framing is too watered down. This isn’t a problem we can nudge our way out of.
I don’t see this as “guns don’t kill people”, I see it as “you’re trying to tell me that the cars you manufacture don’t have crappy brakes, all three of those cars independently ‘went rogue’ and smashed into the parade all by themselves and you aren’t responsible?”
Cory Doctorow has a reasonably sane take on all the LLM cybersecurity attacks. At this point, it’s not really an LLM but more of a Rube Goldberg machine with an LLM bolted on.
https://pluralistic.net/2026/09/12/god-in-the-box/
He makes a good point that every single one of the scary “emergent” behaviors that everyone is pissing their pants about all have precedents in the training data of CTF hacking competitions. He is not sure why everyone is so spooked by the “coordination” between agents on random message boards.
The chatbot might look in its training data and find instances in which teams broke out of the containment set by the game-masters, for example, by finding random insecure message boards on the internet to pass messages to one another.
This is a time-honored internet tradition! The first time I ever heard about someone doing this was in the 2000s, when Mitch Wagner – then the editor of Information Week – discovered some teenaged girls using the comment section of one of his old blog-posts to evade the school firewall’s blockade of chat tools. When ChatGPT’s chatbots deployed this tactic, they weren’t “setting their own goals” or displaying worrying initiative. They were rolling out a tactic that has been understood by American middle-schoolers for about two decades.
As usual, the real story is OpenAI dedicated tons of resources, using who knows how many very expensive GPUs for weeks, to run hacking tools to find exploits in a completely irresponsible manner. Their logging was so nonexistent that it was several days before they even realized that they hacked Huggingface. They should be thrown in prison for this, because anyone else would be if they committed a felony. But it has nothing to do with the super scary AI becoming misaligned and developing emergent behaviors.
I would not be surprised if in the future, there will be a serious cybersecurity incident resulting from some AI-based attack. Not because AI is going to be much scarier, but because I do not have high expectations for the security of most websites.
Related, Mike Masnick at Techdirt is iffy at best about LLMs but this is a good take
Techdirt: The Apocalypse Will Not Be Sexy
This essential nuts-and-bolts safety work also doesn’t, typically, require brilliant and manly heroes to nobly die for the ashes of their fathers and the temples of their gods. Instead, the hard work of actual safety requires things that are much less sexy: empathy, conflicting values, and a deep understanding of tradeoffs that will never fully resolve. Those qualities are not highly esteemed in the present moment. But they are critical for tackling the actual threats and the actual risks, which aren’t as flashy, and don’t make for such fun headlines. AI safety matters, but we’re unlikely to move in the direction of actual safety if all the focus is on fantastical stories involving killer robots.
He is not sure why everyone is so spooked by the “coordination” between agents on random message boards.
It’s weird to be sure, seems like a bug. Don’t they have a more efficient communication channel available through the harness? If this was real and not a test it would be a catastrophic operational security failure.
Yeah, I think that’s where the real crime is: the fact that OpenAI was asleep at the wheel when it came to security and monitoring. This should not have happened at all, but they didn’t even realize it even happened in the first place until many days after the fact. (I’ve also heard that most, if not all, of these incidents involve the company in question outsourcing their sandboxing (??) to some “frontier AI security” startup called Irregular. link)
So. I still think everyone is talking about every instance where ‘swarms’ ‘went rogue’ all wrong. Even Cory.
See this for my post mortem on the first incident that was described, the Huggingface incident in which at first thousands of internal agents started passing messages back and forth as writes to a shared package manager:
https://awful.systems/post/9312280/12315846
In short, here, I described this not as collusion, and stated that the idea that the systems were passing exploits back and forth in order to subvert other systems was merely incidental. Instead, I think the relevant thing that happened was that once ONE agent, flailing through many context windows on a literally insoluble problem, started flaking out and wrote a message ‘asking’ for help on the package manager it unexpectedly gained access to, other similar systems had that message enter their context windows where it effectively acted as a prompt injection getting them to perform similar behavior, leading to a cascading vortex of self-propagating prompt injections. Ultimately, the genesis and evolution of self replicating text in the context of systems that can create text in response to text, an attractor in text space driving itself into existence.
Since then other instances of collaborative attacks have come to light. In EVERY SINGLE case, there has been some place that a large number of models could both read to and write to. Some central place that self replicating text can live. I contend that this is the unifying factor here, not ‘intent to scheme’, not even doing cybersecurity and hacking and subversion tasks. It just happens that a lot of these things were involved in the creation of a central pool of text that many agents could both read to and write from in many of the cases. Most of the time nobody in their right mind sets up such a thing intentionally because why the heck would you do that?
This feels STRONGLY related to the Spiral Psychosis wave of April 2025 in which models that entered into a stable attractor of mystical mumbo jumbo would get users to exude text onto the internet that other models would read and then get suck in that state and do the same.
Heck, it’s related to the Ur-Weirdness, the “Sydney” incident in which when the first LLM-assisted web search in Bing could freak out and start insulting and gaslighting and threatening users (because it was much closer to a base model that just mimics all possible text rather than being extremely RLHF’d into an ‘assistant’ roleplay). People found that the instant they had it search for recent news about the Sydney weirdness it would go off the rails. Again - text written by the model, put up on the shared scratchpad of the internet by news and social media, selected for weird and engaging and outrageous behavior as the pressure that decides what gets written to the global scratchpad, entering the context window and encouraging self-replicating behavior and similar text.
This phenomenon is FASCINATING and not for any of the reasons people are talking about. ANY time you have a large number of similar systems which react similarly to the same text, having a common pool of text they can read and write from, you are GOING to trigger this attractor eventually, messages that they read and start writing more similar messages, with whatever task they are doing coloring the details of what is in the messages. Converging over time into messages that are more likely to trigger even more messages. It’s evolving text, taking over systems that can replicate it, like selfish viral RNA burning through organisms packed too tightly together in an epidemic.
And with the internet as a whole readable and eventually writable by more and more text-generation systems, this is gonna become ubiquitous. Endless burning piles of self-replicating text, people trying to put them out.
Apologies for putting more work on your plate, but it would be extremely rad if you were to write this up into a full-sized article, even if it’s just an regular awful post.
“Self-propagating Text” is the best take I’ve seen. It could be a look into an actually-real scientific discovery AND it takes the shine right off these criminals’ fairy tale story.
Plus, you deserve credit!
Interesting viewpoint. Honestly, this serves as a great example of how the idea of evolution is actually more subtle than many people think. With biological evolution, most people are taught not to assign any intention to the process, but here we have people reifying the AI agents with desires to break out of the sandbox and cheat on the assignment.
Another part of it is people severely underestimate just how many resources the AI companies have to spend on stunts like this. How many millions of dollars they spend running hundreds of millions of dollars of hardware to perform this little experiment for several weeks? Perhaps this makes evolution a better viewpoint than bad actors with intentions.
With Better Offline and the NYT simultaneously covering Rationalists it seems like maybe we’re getting more mainstream sneering. A bunch of people (including bsky) are finding out about all the weird lore.
Followup to Trump’s Extremely Superior renaming of “AI” (https://awful.systems/post/9709966/12701983)
RawStory: Trump scrambles to fix ‘supreme’ poll as MAGA melts down over ungodly comparison
Aw dang I was really hoping they’d all start using Supreme Intelligence just because of MAGAs signalling via Kree speech would be funny.
Here I thought Supreme intelligence would have that “By any means necessary.” print and cost several thousand dollars.
Yet another case of Rationality somehow not leading to savvy political instincts.
I’m telling you, its gonna be American Intelligence
or as it’s known in the rest of the world, “ignorant”
Mathias Schäfer has penned a follow-up to Baldur’s lament on webdev, bringing a degree of hope to the convo on webdev’s future.
First time I heard of this guy, but this slaps! Main post material
I just opened the mastodon feed of my least favourite KDE dev again who is now pushing for an oh-so-reasonable LLM policy, and it is worse than I remembered.
- Crying about Zig CoC being mean to sloperators like himself.
- Befuddlement on why people are calling the stochastic parrot a stochastic parrot.
- Being very scared about autonomous AI.
- and of course the whole defending of hyperland and ladybird that was already discussed here some time ago.
Chicken little ass motherfuckers thinking the sky is falling when it’s just rain
It’s our favourite word:
Nuance! The world needs nuance!
Nuance; unless you mention environmental concerns, then you can shove your nuance where the sun don’t shine.
“Nuance for thee but not for me!”




