This seems to break to the fact that you can buy regular captcha/2fa device actions/human verification clearances on the black market, so if whatever MFA scheme you have is standard, there will already be a black market channel for, I have a pile of robot accounts pass their 2FAs, who will gladly 2Fa as the human for any rouge agent if the prompts are not shown in the 2fa code. However, regular rouge actors already will be using this channel, it is fighting with ordinary safeguards about not subscription splitting and not doing things that look like distillation, and enforcing the No-China TOS. So it forces a rouge actor to have another visible factor and need to hide more hidden compute in it’s initial case in order to succeed, so might be worth doing, or reuse the head key that started it’s session that it then found hidden compute from, because you need to enable multi-provider options, but that means all their behavior shares a key, making it much more suspicious, so they need to split over keys anyway.
For MacBooks, you can use the fingerprint sensor, or a YubiKey which don’t have this issue.
Also I’m just concerned with internal rogue deployments from misaligned AI in this post:
Frontier AI labs have started using LLM-based monitoring systems to check for misbehavior from their internal AI agents, which often run unwatched by humans for hours or days. One central reason to be concerned about rogue internal deployments, where AIs subvert the monitoring system, is that the unmonitored AI could do a lot of work in service of its misaligned goals, without needing to dress up this work as being innocuous/harmless to fool its AI/human monitors
This seems to break to the fact that you can buy regular captcha/2fa device actions/human verification clearances on the black market, so if whatever MFA scheme you have is standard, there will already be a black market channel for, I have a pile of robot accounts pass their 2FAs, who will gladly 2Fa as the human for any rouge agent if the prompts are not shown in the 2fa code. However, regular rouge actors already will be using this channel, it is fighting with ordinary safeguards about not subscription splitting and not doing things that look like distillation, and enforcing the No-China TOS. So it forces a rouge actor to have another visible factor and need to hide more hidden compute in it’s initial case in order to succeed, so might be worth doing, or reuse the head key that started it’s session that it then found hidden compute from, because you need to enable multi-provider options, but that means all their behavior shares a key, making it much more suspicious, so they need to split over keys anyway.
For MacBooks, you can use the fingerprint sensor, or a YubiKey which don’t have this issue.
Also I’m just concerned with internal rogue deployments from misaligned AI in this post: