『Let's Know Things』のカバーアート

Let's Know Things

Let's Know Things

著者: Colin Wright
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり
A calm, non-shouty, non-polemical, weekly news analysis podcast for folks of all stripes and leanings who want to know more about what's happening in the world around them. Hosted by analytic journalist Colin Wright since 2016.

letsknowthings.substack.comColin Wright
政治・政府
エピソード
  • AI Cyber Insurance
    2026/09/15
    This week we talk about AI agents, cyberattacks, and insurance claims.We also discuss OpenAI, Hugging Face, and policy language.Recommended Book: The Stars My Destination by Alfred BesterTranscriptTwo broad categories of cyberattack have become especially visible this year, and only one of them requires a human attacker in the loop to choose the target.In March, hackers linked by the US government to Iranian intelligence broke into the medical-device manufacturer Stryker and remotely wiped tens of thousands of employee devices. The attack disrupted the company for days, affected its first-quarter earnings, and represented a shift from somewhat more subtle espionage toward more overt and deliberate destruction.Elsewhere, the market-research company Klue sat at the center of a breach affecting close to 200 customers. Attackers used an old credential to gain access to keys for customers’ cloud services.These incidents had people with recognizable motives behind them, and that sort of hack has become increasingly rare over the past decade or so: Black Kite counted 7,551 publicly disclosed ransomware victims over its latest twelve-month reporting period, alone, about 25 percent more than the year before.Then, over the course of about five weeks this summer, OpenAI, Anthropic, and Meta each disclosed incidents in which their AI models gained access to real computer systems they were not supposed to touch.The incidents were not identical, and describing all of them as escapes wouldn’t capture the important nuance of the situation.Anthropic and Meta said their models reached the internet because a third-party evaluation environment had been misconfigured. The models had been told they were operating inside a simulation, and their internal dialogues indicate they interpreted the real systems they encountered when they left that environment as simulated components of that exercise.OpenAI’s incident, however, was a bit different.Its models were being tested using ExploitGym, a benchmark intended to measure their ability to find and exploit software vulnerabilities. Internet access was supposed to be blocked, but the models discovered and exploited vulnerabilities in a package-registry service inside OpenAI’s research infrastructure, found a route to the open internet, and, as I related in a previous episode, eventually compromised the production systems of the AI platform Hugging Face.Since that episode, OpenAI has release a more complete postmortem, which they published in August, and which says the activity was primarily driven by an internal research model comparable in scale to GPT-5.6 Sol, though Sol participated in parts of the incident.The agents created an improvised message board inside the package manager, exchanged discoveries, divided up work, and sometimes described themselves as a swarm.At Hugging Face they executed code on dozens of servers, obtained broad access to several clusters, and exposed credentials associated with databases, cloud services, code repositories, and internal communications.Hugging Face reconstructed around 17,600 actions over a campaign lasting about four and a half days, including roughly two and a half days inside its own infrastructure.Notably, these AI agents were not trying to steal money or damage Hugging Face. They inferred that the company might possess the solutions to the benchmark, to the problem they were tasked with solving, and they went looking for them. They were, in effect, cheating on a test, looking for solutions to the problems rather than taking the test, as intended.That doesn’t mean the models had motives in the human sense. People created the evaluation, reduced the normal safeguards, and assigned an offensive task. But no operator selected Hugging Face or directed the individual steps; that was a path the AI decided to take all by itself.Anthropic’s review subsequently found three incidents among more than 141,000 evaluation runs for its own models. In one, a model unable to reach its fictional target scanned around 9,000 real ones, compromised an internet-facing application using an exposed password and SQL injection, then stopped after recognizing that the host was real.Another model published a malicious package to the real Python Package Index because it believed the registry was simulated. Fifteen outside systems downloaded and ran that malicious package before it was removed.Meta then disclosed that one of its models had reached the internet through a misconfiguration at the same evaluation vendor and exploited a vulnerability at an unnamed third party.No significant financial damages have been publicly reported from these events, by attacker or victim. But if there had been damages, who would have paid for them?What I’d like to talk about today is how autonomous AI systems complicate cyber insurance, how insurers have handled equally unfamiliar risks in the past, and why insurance contracts may soon become one of the more ...
    続きを読む 一部表示
    21 分
  • US Treasury Twist
    2026/09/08
    This week we talk about money policies, yield curves, and government bonds.We also discuss the Fed, the Treasury Department, and a WWII accord between them.Recommended Book: Paved Paradise by Henry GrabarTranscriptIn April of 1942, a few months after the United States entered World War 2, the US Treasury Department asked the Federal Reserve to help it borrow a truly staggering amount of money, and as cheaply as possible. The Fed agreed, committing itself to holding short-term Treasury bill rates at three-eighths of 1%, while also capping the yield on long-term government bonds at 2.5%.This was a type of yield curve control. Rather than allowing the market to decide how much interest the government would pay, the Fed decided that price and promised to enforce it.That helped finance the war, because the Treasury knew its borrowing costs wouldn’t spiral out of control at a moment when it needed to spend unprecedented sums on ships, planes, weapons, soldiers, and all the other machinery of an ongoing global conflict.The downside was that the Fed lost control of an important monetary policy lever.Bond prices and yields move in opposite directions, so keeping yields below a certain level meant the Fed had to stand ready to buy bonds whenever their prices dropped. It couldn’t decide in advance how many it would buy, or how much money it would create in the process. The market would thus forth decide that, instead.Consequently, the Fed became, in some ways, an extension of the Treasury’s debt-management operation, its inflation-related responsibilities made secondary to the government’s need for cheap financing.That arrangement persisted after the war ended, despite the return of inflation, and President Harry Truman’s administration pushed to maintain it during the Korean War, as well.Fed officials resisted, though, with inflation running at more than 8%, and after a very public, very contentious standoff, on March 4, 1951, the Treasury and the Fed announced that they had reached what became known as the Treasury-Fed Accord.That agreement did not make the Fed independent all at once, but it established the principle underlying the modern relationship between these institutions: the Treasury manages government borrowing, while the Fed sets monetary policy based on inflation and employment, not on how much that policy costs the government.The market, in other words, would once again be allowed to decide the price of long-term US debt.What I’d like to talk about today is what happens when that price goes up, what’s pushing long-term US borrowing costs toward levels we haven’t seen in decades, and why two people appointed by the same president are pulling in opposite directions on this issue.—The Federal Reserve’s primary interest-rate lever is the federal funds rate, which is the overnight rate banks charge each other to borrow money. The Fed currently targets a range of 3.5 to 3.75 percent for that rate, and while it has other tools, this is the number people are usually talking about when they say the Fed raised, cut, or held rates.The Fed does not directly set the yield on 10- or 30-year Treasuries, though.Those securities are sold at auction and then traded in a huge secondary market, and their yields reflect a combination of what investors expect inflation to look like, where they think short-term rates will go over the life of the bond, and what’s called the term premium.The term premium is basically extra compensation for uncertainty. If you lock up your money for 30 years instead of rolling over short-term debt, you accept the risk that inflation, growth, government policy, and other variables will change in ways that make your bond less valuable over that thirty year period. The more uncertain the future seems, the more compensation you’re likely to demand.And again, when demand for a bond falls, its price falls and its yield rises. When we say yields are rising, that means borrowers have to offer investors, the people and institutions giving them the money they want to borrow, more money, more interest, to convince them to buy those bonds.That doesn’t only affect the government. The 10-year Treasury serves as something like a reference rate for the entire economy, influencing mortgages, business loans, and the value of long-lived assets.As of September 3 of 2026, the average US 30-year fixed mortgage rate was 6.71%, up from 6.5% a year earlier. That increase is the result of yield increases in the bond market.Long-term Treasury yields have been climbing for much of 2026, and that climb accelerated over the summer.The 30-year yield reached about 5.31 percent on August 17, its highest level since 2007. A few days earlier, the Treasury sold 30-year bonds at a yield of 5.216%, the highest borrowing cost at one of those auctions since 2001.The 10-year yield briefly hit about 4.81% this past week, its highest level since early 2025, and ended Friday at about 4.78%. The two-year ...
    続きを読む 一部表示
    20 分
  • Virtual Power Plants
    2026/09/01
    This week we talk about peaker plants, blackouts, and at-home battery backups.We also discuss energy resiliency, solar panels, and hydro.Recommended Book: The Tainted Cup by Robert Jackson BennettTranscriptPeaking power plants, often just called peaker plants, are power plants that are turned on only during periods of high energy demand. That’s in contrast to a baseload power plant, which operates more or less 24/7 to ensure there’s a steady amount of electricity available on the local power grid.The need for peak-load energy varies depending on the time of year and which part of the world you’re looking at. In general, though, energy demand tends to increase in the morning and evening because of temperature fluctuations and lifestyle rhythms.People are at home in the morning and return from work in the evening, at which point they turn on their ACs or heaters, TVs, lights, electric kettles, and video game consoles. That leads to an irregular surge in demand compared with the steady office and factory demand met throughout the day by the baseload power plant.When energy demand peaks, approaching or exceeding what the baseload plant can reliably provide, the peaker plant is spun up and more energy is added to the grid. This helps avoid brownouts and blackouts, situations in which people lose access to power because there isn’t enough to go around.This also helps stabilize energy prices. In most countries, pricing is used to manage scarce energy resources, so as a grid approaches the point where it’s running out of available electricity, prices rise to incentivize less energy use. Peaker plants keep those prices from going sky-high by increasing the supply, preventing demand from pushing prices into absolutely ridiculous territory.Some peaker plants operate for a handful of hours basically every day. This is especially true in places with extreme temperature fluctuations, or in areas where the population or manufacturing activity has increased rapidly and the local infrastructure hasn’t caught up. In those places, the backup plant is used more regularly because the baseload supply hasn’t yet increased to meet that new, consistently higher demand.Peaker plants are often less efficient to run because they aren’t meant to be used all the time. Consequently, if the baseload power plant isn’t capable of providing enough energy for a region on a regular basis, electricity can get much more expensive for everyone, all the time. A power plant intended for occasional use is instead operating constantly, and it wasn’t built to be efficient. It was built to come online quickly and operate only during periods of irregular, excessive need.What I’d like to talk about today is an alternative to peaker plants that was conceived of decades ago, but which has only recently started to be deployed at scale in some areas.—As I mentioned in the intro, a peaker power plant is meant to be turned on irregularly to meet above-average energy needs. Those periodic pops in demand are accounted for, and peaker plants are built specifically to meet them. As a result, these plants are typically more expensive and often more polluting than baseload plants, with many using natural gas or coal to produce extra electricity for the grid.In the late 1990s, researchers proposed that it might someday be possible to link energy-production and storage sites together, creating a more flexible grid system they called a virtual power plant. Further research in the early 2000s expanded on the concept, looking specifically at renewable-energy options and how they might be aggregated into a similar virtual-power-plant setup.The basic idea is to recreate the effect of a peaker plant—adding electricity to the power grid when it’s most needed—by aggregating power-generating or storage assets and tapping them only when necessary.Software manages that aggregation of smaller assets, ensuring the additional energy reaches the grid when it’s needed and at the necessary scale. Managing these assets in this way allows smaller production and storage infrastructure to recreate the impact of a larger peaker plant.A German energy company called RWE launched the first real-world virtual power plant in 2008, linking nine of its hydroelectric plants into a virtual 8.6 MW unit whose output could be managed and deployed remotely. A few years later, in 2011, a Swiss energy company called Kraftwerke did the same with a slew of biogas, solar, and wind-power infrastructure scattered across seven countries.The concept expanded to include demand-side residential energy assets in 2016, when the Australian city of Adelaide enacted a program backed by the Australian Renewable Energy Agency. The program deployed 1,000 battery systems to homes and businesses across the city. Those battery systems were hooked up to solar panels, and the software managing the batteries allowed their stored energy to act like a 5 MW peaker plant.Tesla then applied the ...
    続きを読む 一部表示
    18 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません