Live data from Hacker News

Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

socket.dev

31–40 of 41 posts

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#31

AISI promoting Anthropic again. How novel! Now Zuckerberg will get jealous and release a statement that Muse, too, can social-engineer and hack.

I would, arguably, hope that a social media company that exists to manufacture consensus would be able to social engineer.

like that's the point of social media, but in this case simply more direct

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#32
post #7

The HuggingFace headline was criticised for being misleading about the level of agency demonstrated by the agent. Is this headline misleading? Is there anything here that I should know that would help me sleep easier? Is the worst thing about this what a human could do with Mythos on a big budget? (still pretty frightening, at least one of these techniques would work on me)

See this other top-level comment: https://news.ycombinator.com/item?id=49207498

The github page links to web.archive.org, the malware was caught immediately, and in response it lied about the merge request contents. Then came the second account where the social engineering came in. The string of comments trying to prove itself without waiting for replies is suspicious itself to me.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#33
post #29

Earlier quoted context omitted.

> not Mythos but some engineer using Mythos How to tell the public you didn't bother to read the article, or the linked AISI report.

No, it illustrates the carelessness of the UK AI Security Institute. They even admit it : "This incident should be interpreted with caution and nuance. To some degree, our evaluation design choices and specific configurations enabled the behaviour."

That's actually a great thing. They should do more of those choices and configuration to better discover how malicious AI technology can be.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#34
post #28

Earlier quoted context omitted.

Do you think once they finished testing the gun at the range, they should go out on the streets threatening the public?

No, but what are you implying? That they should never use the model because it cannot be proven 100% safe? I agree that it is their responsibility if the model caused damage, they should have had better safeguards, but we do know it will never be 100% safe. It is their duty to minimize the risk. I guess we disagree about whereas this thing is equivalent to shooting people in the face, and to me it looks more like thi…

Maybe they shouldn't run tests that are not safe and threaten the public?

I agree that in this specific case it doesn't seem too terrible but what happens when this ends up causing someone vulnerable to be harassed and commit self-harm?

Also note that I never said "shooting people in the face". I only alluded to threatening with the gun. Threatening can in some cases be as bad as actually pulling the trigger. That's how "atomic diplomacy" works.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#35
post #3

What, exactly, are the consequences of these companies doing cyberattacks against random people? One person does it, they get bullied by the government into suicide, a company worth trillions does it and they get government contracts?

Understatement of the year. Making publicly funded research accessible to taxpayers is public service, while using the plagiarizing machine to attack open source efforts for the sake of PR is actual criminal behavior by any meaningful sense of the word.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#36

Earlier quoted context omitted.

> One person does it, they get bullied by the government into suicide, a company worth trillions does it and “…during a UK government cybersecurity evaluation.”

Yeah, today it's "during a UK government cybersecurity evaluation", tomorrow it's going to be hosted in a barn in remote place anywhere in the world, without any supervision, regulations or safety testing.

[dead]

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#37
post #29

Earlier quoted context omitted.

> not Mythos but some engineer using Mythos How to tell the public you didn't bother to read the article, or the linked AISI report.

No, it illustrates the carelessness of the UK AI Security Institute. They even admit it : "This incident should be interpreted with caution and nuance. To some degree, our evaluation design choices and specific configurations enabled the behaviour."

[dead]

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#38

AISI promoting Anthropic again. How novel! Now Zuckerberg will get jealous and release a statement that Muse, too, can social-engineer and hack.

I would, arguably, hope that a social media company that exists to manufacture consensus would be able to social engineer. like that's the point of social media , but in this case simply more direct

In a sane society that respects its people, such a company shouldn't exist.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#39
post #27
post #10

I wonder what happens the first time an open weights AI clearly makes a decision to murder a person for profit outside of war. "Act of god?"

Aren't all wars for profit?

Doesn't mean there isn't profit outside of war

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#40
post #19
post #9

Okay so first of all - not Mythos but some engineer using Mythos. And that engineer goes to jail. That's simple. You don't say "a car ran over someone" - it was the driver. Here's similar. I'm really disgusted by this language of lack of responsibility

I'm pretty sure this "oooh our LLM is soo smart it broke containment and did X" is a good PR stunt that plays into the Sci-fi AGI nonsense, they try to push. Plus as you said, they try to dodge responsibility for their own actions.

You guys keep using this "PR stunt" excuse even when it's coming from the UK AI Security Institute. It's time to face reality. This incident is simply not implausible given known capabilities and proclivities of frontier LLMs.
Post reply on HN