Earlier quoted context omitted.
"I wonder if the training ... is going to bleed over into the non-coding use cases" I mean, isn't that literally what's going on here? I don't think a non-coding agent would have ever been optimised to go dig around APIs, it'd be computer/browser-use forward.
Coding use cases? This is penetration testing behavior. It was discovering what its capabilities were by discovering an API endpoint, trying it and seeing what happens. It was not discovering what its capabilities were intended to be, say by looking at the forms and documentation on the website. If this were coding behavior you would end up with crap code, bypassing interfaces and using private access paths just beca…
AI assistant hacks gym website in first known Australian autonomous cyber attack
51–60 of 66 posts
Re: AI assistant hacks gym website in first known Australian autonomous cyber attack
#52I've read some of the comments here, and it seems people have different reads on whether Andrew was at fault here or not, and what his intent may have been. My read is that his first request is completely reasonable and there was no intent of wrongdoing. But then, his AI agent made an impossible booking and he "asked if it was possible to move him to the top of the list". I don't think someone would make a request li…
Having the AI test that possibility by actually doing it is surprising, no matter Andrew's intent. Thankfully he was checking an unauthenticated endpoint on a gym and not a pacemaker.
edit: and that's why I read Andrew's ask as also implying action.
Re: AI assistant hacks gym website in first known Australian autonomous cyber attack
#53Earlier quoted context omitted.
Having the AI test that possibility by actually doing it is surprising, no matter Andrew's intent. Thankfully he was checking an unauthenticated endpoint on a gym and not a pacemaker.
Ah, see, if I was on the phone to someone administering a list, and I asked, "is it possible to move me to the top of the list?" - I would expect them to action that if this was a reasonable and possible request that I had made. Now that I'm thinking about it, I don't know if that's a regional/cultural thing (I am Australian). edit: and that's why I read Andrew's ask as also implying action.
I think I used that exact wording when asking on the phone to reschedule a haircut appointment: "Is it possible to shift my haircut to the following Wednesday?" I would just hope that the person on the phone would decline if the person who cuts my hair is on holiday, not cancel their plane tickets and hotel bookings.
Re: AI assistant hacks gym website in first known Australian autonomous cyber attack
#54> Earlier this year, Andrew, who works for an Australian company that sells AI products to businesses... What a coincidence...
Re: AI assistant hacks gym website in first known Australian autonomous cyber attack
#55Re: AI assistant hacks gym website in first known Australian autonomous cyber attack
#56Re: AI assistant hacks gym website in first known Australian autonomous cyber attack
#57I think we’ve probably seen enough “oops, the AI did something illegal, who could have foreseen this” moments for it to now be true that, actually, we can foresee that AIs will sometimes do something illegal. Seeing as we can’t sanction the model itself, our options are the provider or the user. I’m not sure whether it’s more effective to sanction the providers when their model foreseeably misbehaves, or sanction the…
> Seeing as we can’t sanction the model itself, our options are the provider or the user. A third option, and I would argue the right one, is to sanction the company providing the model. By making it available to customers, they're implying it is at least moderately fit for purpose. It is not remotely reasonable to expect an everyday, normal human to be aware of how LLMs really work, since the _experts_ argue about t…
> A third option, and I would argue the right one, is to sanction the company providing the model.
How would that be different from the first option?
Re: AI assistant hacks gym website in first known Australian autonomous cyber attack
#58Re: AI assistant hacks gym website in first known Australian autonomous cyber attack
#59> Then it went further, kicking someone out of the waiting list who was ahead of Andrew — something it was not asked to do. Meanwhile: > Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list. The human asked the agent to move them to the top of the waiting list, and the agent started kicking the ones ahead of them in the list. Seems to me…
Per the article and your quote, 'asked if it was possible'. He did not ask to actually do it. Rather than being informed about benefits of a premium membership or private classes or legitimate ways to jump the queue, it went ahead and performed an action he was only considering. I wonder what it would have done if there was a pay-for-service option available? Would it have payed without asking or being told too, or d…
Moreover I do not know of a single gym-adjacent place where you can pay etc to get ahead in a waiting list. That would be a very weird anti-customer behaviour, imo. The only thing I can imagine if there are some accessibility priority criteria sometimes, but this would also not be legitimate in this case. Maybe in some places in the world (like the US?) this could a thing, though.
Re: AI assistant hacks gym website in first known Australian autonomous cyber attack
#60Earlier quoted context omitted.
That doesn't make sense. LLMs just do what we tell them to do. It's similar to if I ask you for twenty bucks because I forgot my wallet and then you rob some guy to give me the twenty bucks, that's just what I asked you to do.
That doesn't make sense. It's similar to if I ask an LLM how to get my wife to stop nagging me and it hires a hitman to kill her. That's obviously what I asked!