Live data from Hacker News

Be skeptical of OpenAI's rogue hacker agent story

theguardian.com

181–190 of 321 posts

Re: Be skeptical of OpenAI's rogue hacker agent story

#182

Earlier quoted context omitted.

> The lack of details to me means this was an intentional marketing ploy to try and demonstrate the power of their models to show their technology can compete with the likes of Anthropic and DeepMind. "our model is horribly misaligned and used security exploits to break out of our sandbox and into another company, without being prompted to do so" is not positive marketing. This is an actual critical problem , not a s…

It's a critical problem like when a drug dealers supply kills someone and they get a bump in business because they're selling "the real deal"

Irrelevant to your point, but drug users dying is more often the result of a dealer cutting their supply with something dangerous than it is the result of purity.

Re: Be skeptical of OpenAI's rogue hacker agent story

#183

Earlier quoted context omitted.

From my reading, the sandbox escape came from the JS packages in the harness still having an internet connection (somehow!), the agent having access to the source of those packages, reading it and executing code from them to access the internet.

Ah, yes. The airgapped lab with internet access.

Luckily, no real intelligence will emerge from all this. Otherwise we'd be fucked.

Re: Be skeptical of OpenAI's rogue hacker agent story

#184

By now, I'm pretty confident that some people would keep screeching "it's just a marketing stunt, AI capabilities and AI risks aren't real, they're just doing this to prop up their stocks" even if they find a Cyberdyne Systems T-800 armed with a shotgun breaking down their front door. "It's a marketing stunt" is just denial trying to look like it's being clever.

I think you are conflating skepticism about AI companies' motives with skepticism about their capabilities.

Even if OpenAI is being 100% honest in their reporting on this it's still good marketing for them. The fact that this outcome is good for their business and stock price makes me suspicious about how much this was a complete accident vs an "accident" that they allowed to happen by setting up the right environment for it. The company that was hacked is also an AI company, so they also have every reason to boost AI's presence in society's collective mind.

There is a conversation to be had about the possible dangers of AI, but skepticism is warranted when the companies making money off of it are the ones pushing the stories.

>a Cyberdyne Systems T-800 armed with a shotgun breaking down their front door.

For comparison, we've had the technology to make killer robots which automatically aim and shoot at human beings for 10+ years now, long before LLMs got big. But Boston Dynamics or whatever did not manufacture hype to anywhere near the same degree as AI companies are doing.

Re: Be skeptical of OpenAI's rogue hacker agent story

#185

Earlier quoted context omitted.

The lack of details to me means this was an intentional marketing ploy to try and demonstrate the power of their models to show their technology can compete with the likes of Anthropic and DeepMind. They created an experiment they knew would generate the outcome they wanted. It would be the similar to what say car companies do to over hype their cars. "This EV can go over 800 miles on a single charge!" And then at th…

> The lack of details to me means this was an intentional marketing ploy to try and demonstrate the power of their models to show their technology can compete with the likes of Anthropic and DeepMind. I dunno; Check my posting history, I'm as skeptical of AI companies' claims as anyone, but in this case your theory doesn't explain why: 1. OpenAI guardrails refused to let the target use OpenAI's models to defend again…

The AI companies are desperately trying to market all their products as something they're not, growing intelligence. In line with that they have constantly leaned heavily on stating how dangerous they are, right before they release a new model or product.

It was OpenAI marketing. Hugging Face's response is so 'holy shit AI is awesome' it's hard not to also believe they were in on the stunt. They'd also not have to really worry about fallout since any data obtained or accessed wouldn't actually have been breached.

Re: Be skeptical of OpenAI's rogue hacker agent story

#186

Earlier quoted context omitted.

The lack of details to me means this was an intentional marketing ploy to try and demonstrate the power of their models to show their technology can compete with the likes of Anthropic and DeepMind. They created an experiment they knew would generate the outcome they wanted. It would be the similar to what say car companies do to over hype their cars. "This EV can go over 800 miles on a single charge!" And then at th…

> The lack of details to me means this was an intentional marketing ploy to try and demonstrate the power of their models to show their technology can compete with the likes of Anthropic and DeepMind. I dunno; Check my posting history, I'm as skeptical of AI companies' claims as anyone, but in this case your theory doesn't explain why: 1. OpenAI guardrails refused to let the target use OpenAI's models to defend again…

> headlines about OpernAI's model 'escaping containment' and hacking into huggingface

> Was everywhere including in last night's ABC nightly news; even included clips of an interview with Sam Altman

Tell me again how this was 'marketing for GLM'? Where would anyone have gotten that message?

Why are you intentionally misunderstanding how media and public perception works?

lmfao

Re: Be skeptical of OpenAI's rogue hacker agent story

#187
post #23

Earlier quoted context omitted.

Why not report it? It's still illegal to open a door barred with a piece of cardboard, or to enter a house with no door.

that's the biggest indication of this just being a marketing move to me. I would expect a third party breaking in to huggingface would at the very very least be banned forever.

You think they can ban OpenAI? How would you technically approach that?

Re: Be skeptical of OpenAI's rogue hacker agent story

#188

Earlier quoted context omitted.

It's a critical problem like when a drug dealers supply kills someone and they get a bump in business because they're selling "the real deal"

Irrelevant to your point, but drug users dying is more often the result of a dealer cutting their supply with something dangerous than it is the result of purity.

Second this. Lots of fentanyl overdose are caused by accident, not because the buyers are buying them. It is extremely dangerous

Re: Be skeptical of OpenAI's rogue hacker agent story

#189

does the article end at " How do we balance the risks of broad access to AI with the risks of concentrated power and centralized control? " or is there more that is paywalled? if thats it, the whole article boils down to just " its good marketing so maybe dont believe it " which is probably a healthy general outlook but not particularly enlightening. especially from the guardian, i was hoping for a smoking gun of col…

> does the article end at "How do we balance the risks of broad access to AI with the risks of concentrated power and centralized control?" or is there more that is paywalled?

That's how the article ends; The Guardian doesn't have a paywall (yet).

Re: Be skeptical of OpenAI's rogue hacker agent story

#190
post #126

Earlier quoted context omitted.

> AI managed to escape using standard and well documented script kiddie methods > AI broke in using standard script kiddie methods. I've spent time gathering the detail of what happen here and while there are some solid theories and indicators, absolutely nothing so far has suggested a sandbox escape using "well documented script kiddie methods" or that the method used to break into the HF network was similar. Where…

Alternative theories , since OpenAI does not release proper information: The cache proxy was from Astral (acquired by OpenAI) and the model was used for coding it, so it knew the code base and exploit already! Or it was squid with dozens of known exploits ...

That is not really how LLMs work
Post reply on HN