Everybody's Lost Their Minds
Everybody’s Lost Their Minds
大家都疯了
September 16th, 2026 2026年9月16日
Men. Some would rather vomit up a rambling blog post wall of text that nobody’s going to read than go to therapy. So here we are. I’ve seen my share of stupid over the years, but now people with no engineering background have started pitching “industry changing” solutions they cooked up in their agent infested homelab; people’s emails read like bozotic LinkedIn-fluencer posts with punchy “it’s not this, it’s that” single-sentence paragraphs; online articles suffer a similar fate in their own convergence on Meh; and half of the people you interact with have turned into meat proxies. 男人啊。有些人宁愿吐出一篇没人会读的冗长博客文章,也不愿去接受心理治疗。所以,我们现在就处于这种境地。这些年来我见识过不少愚蠢的事,但现在,一些毫无工程背景的人开始兜售他们在充斥着 AI 代理的家庭实验室里捣鼓出来的“改变行业”的解决方案;人们的邮件读起来就像领英上那些愚蠢的网红帖,充斥着“不是这个,而是那个”这种短促的单句段落;在线文章也难逃厄运,纷纷沦为平庸之作;而你接触的人中,有一半已经变成了只会执行指令的“肉身代理”。
Spending upwards of 75% of my time directly or indirectly dealing with AI every day has absolutely robbed me of most of my enjoyment of my work. Most days feel like that Twilight Zone where you wake up and you’re the same, but everyone else is different. (They were all like that.) 每天花费超过 75% 的时间直接或间接地与 AI 打交道,彻底剥夺了我对工作的大部分乐趣。大多数日子感觉就像《阴阳魔界》(Twilight Zone)里的情节:你醒来时还是原来的你,但其他人却都变了。(他们全都变成了那样。)
“Ethics aside…” The cyber hype train has been going “choo choo” for a while, with the main AI companies trying to one-up each other committing crimes and somehow we let them; the conscious choice of anthropomorphic language by the companies is adapted unquestioned by the media, thereby absolving AI companies of their incompetence to secure their programs. “抛开道德不谈……”网络炒作的列车已经轰鸣了一段时间,主要的 AI 公司竞相通过违法行为来压倒对方,而我们竟然默许了这一切;这些公司刻意选择拟人化的语言,媒体对此不加质疑地采纳,从而免除了 AI 公司在保护其程序方面无能的责任。
Built on unapologetic exploitation of intellectual property and concentrating power in the hands of a very small number of US companies and oligarchs, these AI models not only lend themselves to generation of Child Sexual Abuse Material—a product feature for logged-in users—but our continued use of them also directly supports their role in, e.g., military target selection, such as elementary schools. Meanwhile, every single company is happy to “ethics aside…” all of that and spend unimaginable amounts of “tokens”—a made-up currency following the casino model—while staring at you blankly when you ask whether anybody has bothered to check if that support chatbot you vibe coded and which you fed all of your very mediocre at best “documentation” has any ROI. 这些 AI 模型建立在对知识产权毫无歉意的剥削之上,并将权力集中在极少数美国公司和寡头手中。它们不仅被用于生成儿童性虐待材料(这甚至成了登录用户的“产品功能”),而且我们对它们的持续使用也直接支持了它们在军事目标选择(例如小学)中的作用。与此同时,每一家公司都乐于“抛开道德不谈”,花费难以想象的“代币”(一种遵循赌场模式的虚构货币),而当你问及是否有人检查过那个你凭感觉编写、并喂入了一堆充其量只能算平庸的“文档”的客服聊天机器人是否有投资回报率时,他们只会茫然地盯着你。
Project Sisyphus: “Frontier Models” and AI-assisted vulnerability research is another topic with questionable results. Anthropic and OpenAI tried to one-up each other with how dangerous their models are and everybody who considers themselves an industry leader is now part of some mysteriously named “project” (like Glasswing and Daybreak, or Athena and Akrites) or co-signed various open letters to signal just how much they’re totally not left out. 西西弗斯计划:“前沿模型”和 AI 辅助的漏洞研究是另一个结果存疑的话题。Anthropic 和 OpenAI 竞相展示谁的模型更危险,而每一个自认为是行业领袖的人现在都参与了某个名字神秘的“项目”(如 Glasswing、Daybreak、Athena 或 Akrites),或者联署了各种公开信,以表明他们绝对没有被落下。
Every participant in these projects has thrown absolutely incredible amounts of engineering resources at the FOMO-induced, time-limited, “the first one’s free” offer from Anthropic and OpenAI. Dozens of highly-paid security engineers had all of their priorities shifted and spent all of their time on this; the cost of the engineering hours spent on developing and adjusting AI vulnerability discovery harnesses, building new processes and pipelines to shoehorn thousands of findings into their vulnerability management processes, and of course working with the product owners on assessing and fixing the findings… all that must run in the many, many millions of dollars for each organization. 这些项目的每一个参与者都投入了令人难以置信的工程资源,去追逐 Anthropic 和 OpenAI 制造的这种由“错失恐惧症”(FOMO)驱动的、限时的、“首单免费”的诱饵。数十名高薪安全工程师被迫改变工作重心,将所有时间都花在这上面;开发和调整 AI 漏洞发现工具、构建新的流程和管道以将数千个发现结果强行塞入漏洞管理流程,当然还有与产品负责人一起评估和修复这些发现所耗费的工程工时成本……对于每个组织来说,这笔开销肯定高达数百万美元。
And yet, despite having found literally thousands of new vulnerabilities (only a fraction of which were reported to Open Source projects, by the way), I don’t think that we’re any safer than before. That’s because finding vulnerabilities has never been the bottleneck in information security. The bottleneck isn’t even verifying a vulnerability report and validating its severity, as time consuming as that is. The bottleneck isn’t determining the fix, creating the patch, or publishing a new release. The bottleneck is still, as ever before, getting the goddamn packages updated. Patching is still hard. 然而,尽管确实发现了数以千计的新漏洞(顺便说一句,其中只有一小部分被报告给了开源项目),但我并不认为我们比以前更安全了。这是因为发现漏洞从来都不是信息安全的瓶颈。瓶颈甚至不是验证漏洞报告和确认其严重性,尽管这也很耗时。瓶颈也不是确定修复方案、创建补丁或发布新版本。瓶颈依然像往常一样,是让那些该死的软件包完成更新。打补丁依然很难。
Now imagine that we had spent all these resources on doing the basics: ensuring your organization has an up-to-date and comprehensive asset inventory with fine-grained package listings; building infrastructure that supports regular, frequent, and automated OS and application updates; automatically rebooting systems when they hit, say, 30 days of uptime to ensure these updates are picked up; establishing comprehensive attack surface enumeration across all your IP space as well as all your cloud providers (what a concept!); the list of basic, fundamental defenses that nobody seems to actually do well goes on. 现在想象一下,如果我们把所有这些资源都花在做基础工作上:确保你的组织拥有一个最新且全面的资产清单,并包含细粒度的软件包列表;构建支持定期、频繁且自动化的操作系统和应用程序更新的基础设施;在系统运行达到(比如)30天时自动重启,以确保这些更新生效;在所有 IP 空间以及所有云服务提供商中建立全面的攻击面枚举(这是个多么好的概念!);那些没人能真正做好的基础防御措施清单还有很长。
Having a few dozen senior engineers dedicated for 6 months to overhauling all that, focusing on making patching easier, would, in my book, have been a much better investment, but that’s just not very “cyber” at all. No matter what AI promises, human resources are still a zero-sum game, and every individual feeling super busy in their agentic silo doing a thousand things at once does not, in the end, help solve the kinds of projects that require cross-functional collaboration and team work. 在我看来,让几十名高级工程师花 6 个月时间彻底整改这一切,专注于让打补丁变得更容易,这会是一项好得多的投资,但这在现在看来一点也不“赛博”。无论 AI 承诺什么,人力资源仍然是一个零和游戏,每个人都在自己的代理孤岛中忙得不可开交,同时做着一千件事,这最终并不能帮助解决那些需要跨职能协作和团队合作的项目。
A strange game: At the same time, AI companies are falling over themselves once again facetiously calling for their own regulation because, you know, they could accidentally end all mankind. If you actually thought your product will kill all humans, then you could, you know, like, just stop building the torment nexus. All by yourself, no government regulations required. Nobody’s forcing you to play “Theaterwide Biotoxic and Chemical Warfare” or “Global Thermonuclear War”. I mean, except your future shareholders and your greed. Alas, that wouldn’t cockblock your competition… 一场奇怪的游戏:与此同时,AI 公司再次争先恐后地虚伪地呼吁对自己进行监管,因为,你知道,他们可能会不小心终结全人类。如果你真的认为你的产品会杀死全人类,那么你完全可以,你知道的,停止构建这个“折磨枢纽”。你自己就可以做到,不需要任何政府监管。没有人强迫你去玩“战区生物毒素和化学战”或“全球热核战争”。我是说,除了你未来的股东和你的贪婪之外。唉,但这并不能阻碍你的竞争对手……
But you don’t need to imagine AI destroying all humankind within the next few years via some sort of Skynet or Paperclip Maximizer scenario when in reality AI has of course already been hard at work here. The environmental impact of these companies is staggering. The AI race demands more and more water wasting, air polluting, fossil f… 但你不需要去想象 AI 会在未来几年内通过某种“天网”或“回形针最大化”场景摧毁全人类,因为现实中,AI 当然已经在这一领域“努力工作”了。这些公司对环境的影响是惊人的。AI 竞赛需要越来越多的浪费水资源、污染空气、化石燃料……