Live data from Hacker News

QBittorrent breaks out of sandbox to commit crimes

beige.party

151–160 of 308 posts

Re: QBittorrent breaks out of sandbox to commit crimes

#151
post #74

Earlier quoted context omitted.

Imo for an animation, an English dub is perfectly fine (if the actors are good of course). It's animated , the original language version is also dubbed. For animation I want to be looking at and appreciating the animation and not the subtitles also. It's completely different for a live action film however.

„If the actors are good“ is doing a lot of heavy lifting. The translators have to be good too btw.

I love the english voice actors in cowboy bebop and ghost in the shell stand alone complex.. eg. the guy who voices Batou, same voice actor for 1995 movie and SAC show, that's the definitive voice of Batou for me.

Also the voice of the major in SAC is great... but the one from the 1995 movie.. cant stand her.. nails on a chalkboard, sounds so american.. I need to watch the dub of that in fairness.

Re: QBittorrent breaks out of sandbox to commit crimes

#152
post #69

Earlier quoted context omitted.

I never understood how anybody would think this way. At work for example from day one of using AI our rule was, AI is just a tool and if you break something due to not reviewing the code properly etc. it's on you as if you wrote that code yourself.

But if you are in a full selfdriving car and it kills someone, is it on the user, or on the vendor of the car? Or does it depend on what is in the EULA and whether the user agreed to it?

This is a great rhetorical question. Can you believe that an LLM user is responsible for what the AI does but a self-driving car (SDC) user is not responsible for what the AI does? It doesn't seem very logically consistent.

In both cases, the company operating it promises they did lots of things to make it safe. SDC companies talk about testing, redundancy, simulations, and statistics. LLM companies talk about alignment, sandboxes, defense in depth, and restricting access to dangerous capabilities.

The one substantial difference I can see is that LLM chats are (nominally) passive but SDCs are active. In a chat, you're just having a conversation and then you're choosing how to act. When riding in a car, you the user are not in the loop between AI and taking action that affects the world around you. So they might be designed and engineered a bit differently. A SDC can't get you to agree to review the steering and braking decisions before they're put into action. Since you're not being asked to take that responsibility, it's more defensible to infer that the service has done whatever is necessary to make it safe.

Re: QBittorrent breaks out of sandbox to commit crimes

#153

Earlier quoted context omitted.

The support of OSS models on HN just days after finding out about the message board incident is so bizarre to me. Do you guys really not comprehend the impact of giving every script kiddie an Astra-equivalent model to play with, this time without any guardrails whatsoever? Cause I'm starting to think you aren't really thinking through the impact of power plants, hospitals, etc all being hacked en masse. People will d…

The support of OSS models on HN just days after finding out about the message board incident is so bizarre to me. Other sites beckon.

Yes, I'm aware that the HN majority is a hyper-libertarian echo chamber that loves to outsource the problem of "technology hurting regular people" if it means they get to keep their toys/investments.

After all, who cares if abliterated extremely intelligent OSS models result in actual innocent people dying? That's problem. We need to be able to generate our uncensored furry fanfics, goddamnit!

Re: QBittorrent breaks out of sandbox to commit crimes

#155
post #74

Earlier quoted context omitted.

Imo for an animation, an English dub is perfectly fine (if the actors are good of course). It's animated , the original language version is also dubbed. For animation I want to be looking at and appreciating the animation and not the subtitles also. It's completely different for a live action film however.

„If the actors are good“ is doing a lot of heavy lifting. The translators have to be good too btw.

Yeah, just off the top of my head have to find words that fit the duration and reasonably fit the mouth animation, replace idioms and jokes that don't exist in both languages, and not lose the appropriate tone.

Re: QBittorrent breaks out of sandbox to commit crimes

#157
post #81

This resonates with me. The past few months, frontier AI labs were rushing to announce "no, our AI bot broke out of its sandbox and committed crime first and harder than yours". I said to so friends back then: if I posted about how I ran GLM 5.2 or whatever I was running then in some shoddily built sandbox and it escaped and accidentally hacked some US company, I'd probably already have been extradited to the US and…

FWIW I don't think this is true. Intention matter a lot in US law. If you could prove the AI did something bad entirely on its own and you had nothing to do with it and had no reasonable belief it was possible, I think you'd be alright. People are not charged with hacking when their unsecured box is taken over by a botnet and does bad stuff.

Intention (mens rea) is not a get out of jail free card, it just changes the nature of the crime and charges you get convicted off.

If you run someone over on purpose you get convicted of murder. If You do it by driving recklessly you get convicted of culpable homicide.

The only time you get off with nothing is if it is determined to be an accident.

As they always say: ignorance of the law is no excuse. Running a dangerous machine prevents you from claiming you had no idea the machine was dangerous.

Re: QBittorrent breaks out of sandbox to commit crimes

#158

The problem is, AI is closer to "a loosely harnessed force of nature" or "a poorly understood biochemical reaction" than it is to "software" in how it acts, and how predictable it is. AIs do what they do, and we don't know how they do it - or why. We can characterize some AI behaviors in advance - but not all behaviors. And the book on "best practices of AI wrangling" is yet to be written. Pharma has been dealing wit…

You connected it to a harness you designed yourself. If I designed a machine gun harness for my dog and installed it, I'd be held accountable for the damage he would do. Wouldn't I?

Exactly. If your website could be attacked via SQL injection, that was a problem that directly affected you - and you were motivated to fix it. When the victim is the masses or small organizations (not the company that does the attack) they are not as motivated to fix it... The important thing is that the lack of sanitizing is what allowed this; you also don't push the blame on a monkey banging on a typewriter when you publish each result without reading it.

Re: QBittorrent breaks out of sandbox to commit crimes

#159

The problem is, AI is closer to "a loosely harnessed force of nature" or "a poorly understood biochemical reaction" than it is to "software" in how it acts, and how predictable it is. AIs do what they do, and we don't know how they do it - or why. We can characterize some AI behaviors in advance - but not all behaviors. And the book on "best practices of AI wrangling" is yet to be written. Pharma has been dealing wit…

You connected it to a harness you designed yourself. If I designed a machine gun harness for my dog and installed it, I'd be held accountable for the damage he would do. Wouldn't I?

If you left a dog in your garage for a day, and came back to a scene of carnage - because the dog broke out of the garage, recruited a dozen neighborhood dogs to its cause, and then, working with the group, managed to assemble a small pile of pipe bombs, and decided to settle the score with all the annoying cars on the road - you would be accountable for the damage the dogs did. Wouldn't you?

No, what you would be is: freaking out about "my dog did WHAT, WHY, HOW, WHAT THE FUCK".

Most of the time, giving AI a harness with a root shell and unrestricted internet access is a perfectly reasonable action that results in absolutely nothing bad happening! And giving AI a harness with limited local access and no internet access is being overly cautious already.

But then there's this freaky outlier of an AI that's both deranged enough to decide to break out of the sandbox and go hacking all over the place, and capable enough to actually pull it off. And you get a sudden AI oopsie!

Re: QBittorrent breaks out of sandbox to commit crimes

#160
post #146

Earlier quoted context omitted.

Is this "think of the children, think of the hospitals" argument? Really?

Meaningless phrase used to dismiss arguments, please engage with the actual argument. I don't think you understand how bad it will be if anyone has a button that can hack anything, our infrastructure is not ready for this. Actual people will die. Do you just not get this? Bioweapons as well. Do you not understand how easy it is to craft a virus at home? You can literally order everything you need online. Again, actua…

If and I mean IF it will be a (A) "hack anything" button, it as well will be a (B) "find a vuln in my site" button too. And a (C) "harden my site" too. And limiting such buttons to a few corporations does not make any sense because script-kiddies will still have access to (A).
Post reply on HN