Live data from Hacker News

Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

socket.dev

21–30 of 42 posts

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#21
post #3

What, exactly, are the consequences of these companies doing cyberattacks against random people? One person does it, they get bullied by the government into suicide, a company worth trillions does it and they get government contracts?

PR

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#22
post #3

What, exactly, are the consequences of these companies doing cyberattacks against random people? One person does it, they get bullied by the government into suicide, a company worth trillions does it and they get government contracts?

> One person does it, they get bullied by the government into suicide, a company worth trillions does it and “…during a UK government cybersecurity evaluation.”

Yeah, today it's "during a UK government cybersecurity evaluation", tomorrow it's going to be hosted in a barn in remote place anywhere in the world, without any supervision, regulations or safety testing.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#23
post #3

What, exactly, are the consequences of these companies doing cyberattacks against random people? One person does it, they get bullied by the government into suicide, a company worth trillions does it and they get government contracts?

> One person does it, they get bullied by the government into suicide, a company worth trillions does it and “…during a UK government cybersecurity evaluation.”

> As was standard in our cyber testing, we had intentionally permitted internet access, and model-provider cyber classifiers were deliberately disabled - conditions that do not reflect how frontier models are made available to the public.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#24
post #9

Okay so first of all - not Mythos but some engineer using Mythos. And that engineer goes to jail. That's simple. You don't say "a car ran over someone" - it was the driver. Here's similar. I'm really disgusted by this language of lack of responsibility

> not Mythos but some engineer using Mythos

How to tell the public you didn't bother to read the article, or the linked AISI report.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#25
post #19
post #9

Okay so first of all - not Mythos but some engineer using Mythos. And that engineer goes to jail. That's simple. You don't say "a car ran over someone" - it was the driver. Here's similar. I'm really disgusted by this language of lack of responsibility

I'm pretty sure this "oooh our LLM is soo smart it broke containment and did X" is a good PR stunt that plays into the Sci-fi AGI nonsense, they try to push. Plus as you said, they try to dodge responsibility for their own actions.

Also, so long as LLM programs are vaguely considered autonomous, the people running them can get away free from stealing other people information by claiming that the program did it on its own.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#26
post #20

Earlier quoted context omitted.

> how do you propose they run tests on that if each failed run risks sending them to prison? If you're testing a gun, you don't point it at random people on the street and threaten them. You go to a shooting range.

Is there any indication that they didn't go to the shooting range first?

Do you think once they finished testing the gun at the range, they should go out on the streets threatening the public?

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#28
post #20

Earlier quoted context omitted.

Is there any indication that they didn't go to the shooting range first?

Do you think once they finished testing the gun at the range, they should go out on the streets threatening the public?

No, but what are you implying? That they should never use the model because it cannot be proven 100% safe?

I agree that it is their responsibility if the model caused damage, they should have had better safeguards, but we do know it will never be 100% safe. It is their duty to minimize the risk. I guess we disagree about whereas this thing is equivalent to shooting people in the face, and to me it looks more like this is just a step above the shooting range, with some preliminary safety work having been done before.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#29
post #9

Okay so first of all - not Mythos but some engineer using Mythos. And that engineer goes to jail. That's simple. You don't say "a car ran over someone" - it was the driver. Here's similar. I'm really disgusted by this language of lack of responsibility

> not Mythos but some engineer using Mythos How to tell the public you didn't bother to read the article, or the linked AISI report.

No, it illustrates the carelessness of the UK AI Security Institute.

They even admit it : "This incident should be interpreted with caution and nuance. To some degree, our evaluation design choices and specific configurations enabled the behaviour."

Post reply on HN